Cybersecurity Headlines - podcast cover

Cybersecurity Headlines

CISO Seriescisoseries.com
Daily stories from the world of information security. To delve into any daily story, head to CISOseries.com.
Last refreshed:
Download Metacast podcast app
Podcasts are better in Metacast mobile app
Don't just listen to podcasts. Learn from them with transcripts, summaries, and chapters for every episode. Skim, search, and bookmark insights. Learn more

Episodes

Fortinet tops vuln list, malicious Chrome Rilite, more Ivanti issues

Fortinet VPN bug tops CISA's list of most exploited vulnerabilities in 2022 Chrome malware Rilide targets enterprise users via PowerPoint guides Researchers discover bypass for recently fixed Ivanti EPMM vulnerability Thanks to today's episode sponsor, Opal Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It's fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best sec...

Aug 04, 20238 min

Australia considers WeChat ban, US company aiding APTs, Veilid coming to DEF CON

Australian Senate recommends banning WeChat US company accused of aiding APT Hacking group to detail P2P protocol at DEF CON Thanks to today's episode sponsor, Opal Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It's fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identit...

Aug 03, 20237 min

Musk sues disinformation researchers, Cloud host found facilitating state-backed cyberattacks, UK spy agencies want to relax 'burdensome' AI laws

Musk sues disinformation researchers for driving away advertisers Researchers claim cloud host facilitated state-backed cyberattacks UK spy agencies want to relax 'burdensome' laws on AI data use Thanks to today's episode sponsor, Opal Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It's fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from compa...

Aug 02, 20238 min

National plan for cyber education, DeFi code exploit, study on cyber insurance

White House releases National Cyber and Workforce Education Strategy Latest DeFi exploit sees millions in losses No link found between cyber insurance and paying ransoms Thanks to today's episode sponsor, Opal Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It's fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figm...

Aug 01, 20236 min

Israel refinery cyberattack, TSA pipeline guidelines, CISA's IDOR warning

Israel's largest oil refinery website offline amid cyber attack claims TSA renews cybersecurity guidelines for pipelines CISA AND Australia warn of IDOR vulnerabilities after major breaches Thanks to today's episode sponsor, Opal Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It's fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies l...

Jul 31, 20239 min

Week in Review: Stolen Microsoft key, government Maximus breach, Clop on clearweb

Link to Blog Post This week's Cyber Security Headlines – Week in Review , July 24-28, is hosted by Rich Stroffolino with guest, TC Niedzialkowski‌ , CISO, Nextdoor Thanks to today's episode sponsor, AppOmni Over provisioned users could lead to your most sensitive data being exposed or leaked. Just a single attack on one of those users may compromise your entire SaaS estate. With AppOmni's SaaS Identity Fabric, secure and manage end-users, entitlements, and threat-based activity. Gain visibility ...

Jul 28, 202324 min

Maximus breach, Ubuntu Linux vulnerabilities, Cardio company cyberattack

Millions affected by data breach at US government contractor Maximus Two severe Linux vulnerabilities impact 40% of Ubuntu users Heart monitoring technology provider confirms cyberattack Thanks to today's episode sponsor, AppOmni Over provisioned users could lead to your most sensitive data being exposed or leaked. Just a single attack on one of those users may compromise your entire SaaS estate. With AppOmni's SaaS Identity Fabric , secure and manage end-users, entitlements, and threat-based ac...

Jul 28, 20238 min

Cyber exec convicted, SEC disclosure, how the government gets breached

Russian court convicts cyber security executive of treason SEC to require incident disclosure Government cyber attacks rely on valid credentials Thanks to today's episode sponsor, AppOmni SaaS cyberattacks are prevalent and often go unnoticed until data loss or breaches occur. Sign-ins from an unusual IP address. Stolen session tokens. These security risks can lurk in the shadows and put your entire SaaS estate at risk. Don't wait for a breach to secure your SaaS data. AppOmni helps security tea...

Jul 27, 20237 min

TETRA encryption flaws, Zenbleed strikes, Norway's government hit with Ivanti flaw

Vulnerability found in TETRA encryption Ryzen CPUs vulnerable to Zenbleed exploit Norwegian government breached with Ivanti zero-day Thanks to today's episode sponsor, AppOmni Over provisioned users could lead to your most sensitive data being exposed or leaked. Just a single attack on one of those users may compromise your entire SaaS estate. With AppOmni's SaaS Identity Fabric , secure and manage end-users, entitlements, and threat-based activity. Gain visibility and control over provisioned u...

Jul 26, 20237 min

Cyber Security Headlines: Clop leaks on clearweb, EU pushes back on CSA centralization, rising data breach costs

Clop moves leaked data to clearweb sites EU governments push back on centralized cyber reporting Cost of data breaches up 15% Thanks to today's episode sponsor, AppOmni SaaS cyberattacks are prevalent and often go unnoticed until data loss or breaches occur. Sign-ins from an unusual IP address. Stolen session tokens. These security risks can lurk in the shadows and put your entire SaaS estate at risk. Don't wait for a breach to secure your SaaS data. AppOmni helps security teams to detect suspic...

Jul 25, 20237 min

Azure hack deepens, JumpCloud is Lazarus, DHL MOVEIt victim

Microsoft key stolen by Chinese hackers provided access far beyond Outlook JumpCloud breach traced back to North Korean state hackers DHL investigating MOVEit breach as number of victims surpasses 20 million Thanks to today's episode sponsor, AppOmni Over provisioned users could lead to your most sensitive data being exposed or leaked. Just a single attack on one of those users may compromise your entire SaaS estate. With AppOmni's SaaS Identity Fabric , secure and manage end-users, entitlements...

Jul 24, 20239 min

Week in Review: Fast acting Gamaredon, WormGPT AI weapon, Microsoft Azure mystery

Link to Blog Post This week's Cyber Security Headlines – Week in Review , July 17-21, is hosted by Rich Stroffolino with our guest, Dimitri van Zantvliet , CISO, Dutch Railways Thanks to our show sponsor, OpenVPN According to Oriel Hernan Villalba Pinzetta, a System Administrator with CEDEC's cybersecurity and IT department, "The pandemic meant we could not come to the office, and we needed to facilitate access to our local resources," says Villalba. "Cloud Connexa was really easy and fast to se...

Jul 21, 202324 min

New Redis worm, more ColdFusion confusion, Estée Lauder breached

New P2PInfect worm targeting Redis servers on Linux and Windows systems Adobe releases new patches for exploited ColdFusion vulnerabilities Estée Lauder breached by two ransomware groups And now a word from our sponsor, OpenVPN According to Oriel Hernan Villalba Pinzetta, a System Administrator with CEDEC's cybersecurity and IT department, "The pandemic meant we could not come to the office, and we needed to facilitate access to our local resources," says Villalba. " Cloud Connexa was really eas...

Jul 21, 20238 min

A rise in complex DDoS attacks, Mi6 warns of data traps, Microsoft expands log access

Complex DDoS attacks on the rise MI6 warns of Chinese data traps Microsoft expands cloud log access And now a word from our sponsor, OpenVPN Karim Hakim, CTO at Hakim Misr Paco, says that CloudConnexa has given him some long-sought peace of mind. " OpenVPN has helped my company to access remote nodes securely without worrying about security protocols," he says. "My company has been looking for a similar solution for years, and we finally got what we were looking for." Read more at the link in ou...

Jul 20, 20237 min

US launches IoT security labeling program, Renewable tech could pose electric grid risk, US blacklists two more spyware firms

US government launches IoT security labeling program Renewable technologies could pose risk to US electric grid US blacklists two spyware firms run by Israeli former general And now a word from our sponsor, OpenVPN Stephen Haecker, Chief Technology Officer at Carteras Colectivas, relies on Cloud Connexa customer support for his remote team. "I have used them about once per month to help with our growing networks," he says, "and the service quality is great with quick turnarounds." Haecker apprec...

Jul 19, 20237 min

JumpCloud Breach, LockBit attacks Wisconsin, Typos leak military emails

JumpCloud breached by APT Wisconsin allegedly hit by LockBit Typos leaking military emails And now a word from our sponsor, OpenVPN Zach Belhadri, the Infrastructure Manager at Knight Capital, shares why using Cloud Connexa for his team's security has been a game changer. With the Cybershield feature, he's able to prevent malware, phishing, and other threats by restricting access to only authorized and trusted internet destinations. He calls Cloud Connexa "an awesome product with huge potential....

Jul 18, 20237 min

Fast-acting Gamaredon, WormGPT improves phishing, Microsoft email mystery

Russia-linked Gamaredon starts stealing data 30 to 50 minutes after initial compromise New AI tool – WormGPT allows for sophisticated cyber attacks Microsoft still unsure how hackers stole Azure AD signing key And now a word from our sponsor, OpenVPN We asked Anthony Hook, the CTO at Dataweavers, if he would recommend Cloud Connexa to other companies. His response? A resounding yes! With Cloud Connexa, he says "we bypassed the clunky client-owned VPNs and networks, gaining a seamless, secure, an...

Jul 17, 20238 min

Week in Review: Threat actors access government email, USB drive attacks spiking, cloud environment breaches

Link to Blog Post This week's Cyber Security Headlines – Week in Review , July 10-14, is hosted by Sean Kelly with our guest, Yaron Levi , CISO, Dolby Thanks to our show sponsor, Opal Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It's fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Op...

Jul 14, 202327 min

USB malware spikes, Honeywell, Rockwell vulnerabilities, ransomware remains profitable

USB drive malware attacks spiking again in first half of 2023 Users of Honeywell Experion DCS platforms urged to patch 9 vulnerabilities immediately Ransomware gangs have extorted $449 million this year Thanks to this week's episode sponsor, Opal Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It's fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams...

Jul 14, 20239 min

NATO cyber pledges, tax prep data shared, a decrease in crypto crime

What we know about NATO cyber pledges Tax prep companies "recklessly" shared data Report finds decrease in crypto crime Thanks to this week's episode sponsor, Opal Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It's fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identity...

Jul 13, 20237 min

Silk Road advisor sentenced, HCA Health data breach, Google hit with AI tool training lawsuit

Silk Road's senior advisor sentenced to 20 years in prison 11 million HCA patients impacted by data breach Google hit with lawsuit alleging it stole user data to train its AI tools Thanks to this week's episode sponsor, Opal Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It's fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like D...

Jul 12, 202310 min

JumpCloud resets API keys, Genesis Market for sale, an EU-US data transfer agreement

JumpCloud resets customer API keys Would you be interested in a slightly used dark web market? US and EU agree on new data transfer agreement Thanks to this week's episode sponsor, Opal Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It's fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use ...

Jul 11, 20237 min

BigHead Windows ransomware, RedEnergy targets utilities. more MOVEIt problems

New 'Big Head' ransomware displays fake Windows update alert RedEnergy stealer-as-a-ransomware threat targeting energy and telecom sectors Three new MOVEit bugs spur CISA warning as more victims report breaches Thanks to this week's episode sponsor, Opal Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It's fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best securi...

Jul 10, 20238 min

Week in Review: TSMC supplier attacked, cardiac device warning, hospital ransomware increasing

Link to Blog Post This week's Cyber Security Headlines – Week in Review , July 3-7, is hosted by Rich Stroffolino with our guest, Hadas Cassorla , CISO, M1 Thanks to today's episode sponsor, SlashNext SlashNext, a leader in SaaS-based Integrated Cloud Messaging Security across email, web, and mobile has the industry's first artificial intelligence solution, HumanAI, that uses generative AI to defend against advanced business email compromise (BEC), supply chain attacks, executive impersonation, ...

Jul 07, 202324 min

Shell MOVEit breach, Pepsi bottler breach, INTERPOL nabs OPERA1ER

Shell confirms MOVEit-related breach after ransomware group leaks data 28,000 impacted by data breach at Pepsi Bottling Ventures INTERPOL nabs hacking crew OPERA1ER's leader behind $11 million cybercrime Thanks to today's episode sponsor, SlashNext SlashNext , a leader in SaaS-based Integrated Cloud Messaging Security across email, web, and mobile has the industry's first artificial intelligence solution, HumanAI, that uses generative AI to defend against advanced business email compromise (BEC)...

Jul 07, 20238 min

Japanese port hit with ransomware, EU court orders Meta data changes, White House can't contact social companies

Japan's major port hit with ransomware European court orders changes to Meta's data practices Injunction restricts White House contact with social media companies Thanks to today's episode sponsor, SlashNext SlashNext , a leader in SaaS-based Integrated Cloud Messaging Security across email, web, and mobile has the industry's first artificial intelligence solution, HumanAI, that uses generative AI to defend against advanced business email compromise (BEC), supply chain attacks, executive imperso...

Jul 06, 20237 min

BlackCat pushes CobaltStrike, cardiac device warning, unpatched Fortigate firewalls

BlackCat ransomware pushes Cobalt Strike via WinSCP search ads CISA issues warning for cardiac device system vulnerability 330,000 FortiGate firewalls still unpatched to CVE-2023-27997 RCE flaw Thanks to today's episode sponsor, SlashNext SlashNext , a leader in SaaS-based Integrated Cloud Messaging Security across email, web, and mobile has the industry's first artificial intelligence solution, HumanAI, that uses generative AI to defend against advanced business email compromise (BEC), supply c...

Jul 05, 20238 min

Semiconductor giant attacked, State websites hacked, Russian Telecom infiltrated

Semiconductor giant says IT supplier was attacked, LockBit makes related claims Several US states investigating 'SiegedSec' hacking campaign Russian telecom confirms hack after group backing Wagner boasted about an attack Thanks to today's episode sponsor, SlashNext For the stories behind the headlines, head to CISOseries.com .

Jul 03, 20238 min

Week in Review: SolarWinds CISO blamed, Military smartwatch mystery, submarine cable risk

Link to Blog Post This week's Cyber Security Headlines – Week in Review , June 26-30, is hosted by Rich Stroffolino with our guest, Cassio Goldschmidt , CISO, ServiceTitan Thanks to our show sponsor, AppOmni Over provisioned users could expose your organization's most sensitive data. Just a single attack on one of those users may compromise your entire SaaS estate. With AppOmni's identity and threat detection capabilities, you can detect and respond to suspicious activities within your SaaS envi...

Jun 30, 202324 min

SolarWinds CISOs blamed, ThirdEye Windows malware, Government extends canary

SEC notice to SolarWinds CISO and CFO roils cybersecurity industry Newly uncovered ThirdEye Windows-based malware steals sensitive data Cyber Command to expand 'canary in the coal mine' unit working with private sector Thanks to today's episode sponsor, AppOmni Over provisioned users could expose your organization's most sensitive data. Just a single attack on one of those users may compromise your entire SaaS estate. With AppOmni's identity and threat detection capabilities, you can detect and ...

Jun 30, 20238 min
Hosted on Libsyn
For the best experience, listen in Metacast app for iOS or Android