Cybersecurity Headlines - podcast cover

Cybersecurity Headlines

CISO Seriescisoseries.com
Daily stories from the world of information security. To delve into any daily story, head to CISOseries.com.
Last refreshed:
Download Metacast podcast app
Podcasts are better in Metacast mobile app
Don't just listen to podcasts. Learn from them with transcripts, summaries, and chapters for every episode. Skim, search, and bookmark insights. Learn more

Episodes

Week in Review: Microsoft MSA answers, Keystroke monitoring software, G-Man Mudge

Link to blog post This week's Cyber Security Headlines – Week in Review , is hosted by Rich Stroffolino with guest Dan Walsh , CISO, VillageMD Thanks to our show sponsor, Comcast DataBee DataBee™, from Comcast Technology Solutions, is a cloud-native security, risk and compliance data fabric platform that transforms your security data chaos into connected outcomes. Built by security professionals for security professionals, DataBee makes your data a gold mine, rich with information that enables y...

Sep 08, 202323 min

China's MSA key hack, cyberwar crimes, North Korea targeting Russia

How Chinese hackers stole a Microsoft signing key The ICC to prosecute cyberwar crimes North Korean cyberattacks against Russian targets Thanks to today's episode sponsor, Comcast DataBee™, from Comcast Technology Solutions , is a cloud-native security, risk and compliance data fabric platform that transforms your security data chaos into connected outcomes. Built by security professionals for security professionals, DataBee makes your data a gold mine, rich with information that enables you to ...

Sep 08, 20236 min

CISA reporting rules, LastPass key crack, connected cars fail on privacy

CISA close to finalizing incident reporting rules Krebs on cracked LastPass keys Connected cars not great for privacy and security Thanks to today's episode sponsor, Comcast Are you still using whiteboards and pivoting between tools to find out who owns what data sources and the relationships between data points? It's time to improve your OODA loop and enhance your security and compliance efforts with DataBee, from Comcast Technology Solutions . Learn how DataBee weaves together and enriches dat...

Sep 07, 20237 min

CISA hires 'Mudge', Call for Congress to address AI-generated CSAM, Stake.com loses $41 million in crypto

CISA hires 'Mudge' to work on security-by-design principles All 50 states call on Congress to address AI-generated CSAM Stake.com loses $41 million to hot wallet hackers Thanks to today's episode sponsor, Comcast What if you could integrate enterprise-wide business intelligence with your security data for better contextual insights into potential threats and compliance issues? You can. With DataBee™, from Comcast Technology Solutions . Learn how DataBee enables users to leverage integrated insig...

Sep 06, 20238 min

PDF MalDoc warning, MinIO storage compromises, Okta helpdesk attacks

New PDF MalDoc allows evasion of antivirus MinIO Storage system being used to compromise servers Okta warns of IT help desk attacks Thanks to today's episode sponsor, Comcast Data rules everything around us – but why are the people who need data the most unable to access it? What if you could boost the productivity of your security teams and their ability to collaborate by providing them access to the same shared and enriched data? You can. With DataBee™, from Comcast Technology Solutions . Lear...

Sep 05, 20237 min

X collects employment histories, Sandworm Chisel analysis, Callaway breach

X to collect member employment data Technical details of Sandworm malware 'Infamous Chisel' released Golf club maker Callaway suffers breach Thanks to today's episode sponsor, Comcast DataBee "Data is the currency of the 21st century", yet for so many cybersecurity professionals, it's still too difficult to access, correlate and use this 'currency' for better, faster security and compliance decision-making. That's why Comcast Technology Solutions created DataBee™ , a cloud-native security data f...

Sep 04, 20238 min

Gamaredon hits Ukraine, Paramount suffers breach, OpenFire gets swarmed

Gamaredon hackers hit Ukraine military Movie giant Paramount Global suffers data breach Takeover swarm exploits OpenFire Huge thanks to today's episode sponsor, AppOmni Over provisioned users could lead to your most sensitive data being exposed or leaked. Just a single attack on one of those users may compromise your entire SaaS estate. With AppOmni's SaaS Identity Fabric , secure and manage end-users, entitlements, and threat-based activity. Gain visibility and control over provisioned users, t...

Sep 01, 20237 min

China hacked Japan's NISC, trafficking fuels cyber scams, China approves generative AI

Chinese threat actors breached Japan's cybersecurity agency Human trafficking into cyber scams China set to approve first generative AI services Huge thanks to today's episode sponsor, AppOmni SaaS cyberattacks are prevalent and often go unnoticed until data loss or breaches occur. Sign-ins from an unusual IP address. Stolen session tokens. These security risks can lurk in the shadows and put your entire SaaS estate at risk. Don't wait for a breach to secure your SaaS data. AppOmni helps securit...

Aug 31, 20237 min

FBI dismantles Qakbot operation, University of Michigan cuts internet after cyberattack, Microsoft criticizes UN cybercrime treaty

FBI dismantles Qakbot operation that took millions in ransom University of Michigan severs ties to internet after cyberattack Microsoft joins growing list of organizations criticizing UN cybercrime treaty Huge thanks to today's episode sponsor, AppOmni Over provisioned users could lead to your most sensitive data being exposed or leaked. Just a single attack on one of those users may compromise your entire SaaS estate. With AppOmni's SaaS Identity Fabric , secure and manage end-users, entitlemen...

Aug 30, 20238 min

UK flight outage, the malware Big 3, spyware firm breached

UK network outage grounds flights The malware loader Big 3 Another spyware firm breached Huge thanks to today's episode sponsor, AppOmni SaaS cyberattacks are prevalent and often go unnoticed until data loss or breaches occur. Sign-ins from an unusual IP address. Stolen session tokens. These security risks can lurk in the shadows and put your entire SaaS estate at risk. Don't wait for a breach to secure your SaaS data. AppOmni helps security teams to detect suspicious activity, decide what activ...

Aug 29, 20237 min

Cisco fixes flaws, Windows BSOD reappears, FBI Barracuda warning

Cisco fixes flaws in NX-OS AND FXOS software Windows preview updates bring blue screen of death FBI warns Barracuda bug still has bite Huge thanks to today's episode sponsor, AppOmni Over provisioned users could lead to your most sensitive data being exposed or leaked. Just a single attack on one of those users may compromise your entire SaaS estate. With AppOmni's SaaS Identity Fabric , secure and manage end-users, entitlements, and threat-based activity. Gain visibility and control over provis...

Aug 28, 20238 min

Week in Review: Health hackers evolve, generative AI cyberattacks, NK spooks drills

Link to blog post This week's Cyber Security Headlines – Week in Review , is hosted by Rich Stroffolino with guest Gerald Auger Ph.D ., Chief Content Creator, Simply Cyber Thanks to our show sponsor, HyperProof Is your company scaling? Do you need to quickly add more compliance frameworks but don't know where to start? Hyperproof has you covered. Hyperproof is a risk and compliance management platform that can help you manage compliance at scale. With Hyperproof, you can quickly add new framewor...

Aug 25, 202332 min

Lazarus exploits ManageEngine, Rockwell ThinManager vulnerabilities, Mississippi hospital attack

Lazarus Group exploits ManageEngine to drop new RATS on internet and healthcare Vulnerabilities in Rockwell ThinManager threaten industrial control systems Mississippi hospital system suffers cyberattack Huge thanks to our sponsor, HyperProof Is your company scaling? Do you need to quickly add more compliance frameworks but don't know where to start? Hyperproof has you covered. Hyperproof is a risk and compliance management platform that can help you manage compliance at scale. With Hyperproof ,...

Aug 25, 20238 min

Tornado Cash indictment, UN cybercrime treaty, Lazarus crypto cashout

Tornado Cash developers face indictment UN begins final cybercrime treaty talks FBI warns of North Korean crypto cash out Huge thanks to our sponsor, HyperProof It's more critical than ever to focus on strategically addressing risk, but how can you do it when working with limited resources? That's where Hyperproof comes in: Hyperproof is a risk and compliance operations platform that helps you automate evidence collection, task management, and collaboration within your organization so you can fo...

Aug 24, 20237 min

CISOs' cybersecurity confidence, Healthcare cyberbreach report, Duo outage

CISOs proclaim cybersecurity confidence, but majority admit to SaaS incidents Cyber Health Report: Hacker entry point shifts from email to network Duo outage causes Azure Auth authentication errors Huge thanks to our sponsor, HyperProof We get it. You're a risk manager or compliance professional, and you're overworked. You're trying to do the right thing by keeping your company safe and secure, but your technology is holding you back. Why not upgrade to Hyperproof ? Hyperproof is a platform that...

Aug 23, 20239 min

ChatGPT botnet, Brits tip ransomware targets, Tesla's insider breach

ChatGPT used in crypto botnet Brits tipping off ransomware targets Tesla data breach caused by insiders Huge thanks to our sponsor, HyperProof Imagine. You have an audit coming up, but instead of the usual rush, you actually feel prepared. You've collected your evidence. You can see which risks have been mitigated. And best of all, you don't have to send out any last-minute emails to other teams begging them for that one screenshot. Sounds like a dream, right? With Hyperproof's risk and complian...

Aug 22, 20237 min

NK attacks drills, Android APK malware, space industry warning

North Korean hackers suspected of targeting S. Korea-US drills Android malware apps use APK compression to evade detection Security agencies warn space industry of increased attacks Huge thanks to our sponsor, HyperProof Tired of managing risk and compliance in spreadsheets? Sick of tracking down stakeholders to find evidence? Worried about whether that evidence is up to date for your next audit? Hyperproof has you covered. With Hyperproof , you can efficiently manage multiple compliance framewo...

Aug 21, 20237 min

Week in Review: Ford WiFi vulnerability, LockBit's publication struggle, Government ZeroTrust confidence

Link to blog post This week's Cyber Security Headlines – Week in Review , is hosted by Rich Stroffolino with guest, Jon Oltsik , distinguished analyst and fellow, Enterprise Strategy Group Thanks to our show sponsor, Veza 75% of breaches happen because of bad permissions. The problem is that you don't know exactly WHO has access to WHAT data in your environment. For example, roles labeled as "read-only" can often edit and delete sensitive data. Veza automatically finds and fixes every bad permis...

Aug 18, 202326 min

Cybercriminals finetune AI, Government ZeroTrust confidence, Citrix vulnerability warning

Influence operators fine-tuning AI to deceive targets 67% of government agencies claim confidence in adopting zero trust CISA warns of urgent Citrix vulnerability Huge thanks to today's episode sponsor, Veza 75% of breaches happen because of bad permissions. The problem is that you don't know exactly WHO has access to WHAT data in your environment. For example, roles labeled as "read-only" can often edit and delete sensitive data. Veza automatically finds and fixes every bad permission—in every ...

Aug 18, 20237 min

LockBit struggles, Google's quantum resilient key, orgs excitedly unprepared for AI

LockBit struggles to publish leaked data Google's quantum resilient security key Organizations optimistic and unprepared for AI Huge thanks to today's episode sponsor, Veza 75% of breaches happen because of bad permissions. The problem is that you don't know exactly WHO has access to WHAT data in your environment. For example, roles labeled as "read-only" can often edit and delete sensitive data. Veza automatically finds and fixes every bad permission—in every app—across your environment....

Aug 17, 20237 min

LinkedIn accounts hijacked, Chinese spies hack US congressman's email, US watchdog plans to regulate data brokers

Huge thanks to today's episode sponsor, Veza 75% of breaches happen because of bad permissions. The problem is that you don't know exactly WHO has access to WHAT data in your environment. For example, roles labeled as "read-only" can often edit and delete sensitive data. Veza automatically finds and fixes every bad permission—in every app—across your environment. For the stories behind the headlines, visit CISOseries.com....

Aug 16, 20237 min

Moovit bug, Black Hat's NOC, DDoS origins

Moovit bug allowed for free rides A look at Black Hat's network operations center Business and gaming disputes lead to DDoS attacks Huge thanks to today's episode sponsor, Veza 75% of breaches happen because of bad permissions. The problem is that you don't know exactly WHO has access to WHAT data in your environment. For example, roles labeled as "read-only" can often edit and delete sensitive data. Veza automatically finds and fixes every bad permission—in every app—across your environment....

Aug 15, 20237 min

Ford WiFi vulnerability, Government reviews Azure hack, TripAdvisor ransomware

Ford says cars with WiFi vulnerability still safe to drive Cyber Safety Review Board to analyze cloud security in wake of Microsoft hack Knight ransomware distributed in fake TripAdvisor complaint emails Huge thanks to today's episode sponsor, Veza 75% of breaches happen because of bad permissions. The problem is that you don't know exactly WHO has access to WHAT data in your environment. For example, roles labeled as "read-only" can often edit and delete sensitive data. Veza automatically finds...

Aug 14, 20239 min

Week in Review: Microsoft slapped by Tenable, Tampa Hospital lawsuit, Zoom's AI decision

Link to blog post This week's Cyber Security Headlines – Week in Review , August 7-11, is hosted by Rich Stroffolino with guest, Michael Woods , CISO, GE Thanks to our show sponsor, Conveyor We can all agree there's one thing the AI bots can take from us: completing customer security questionnaires. That's why we built Conveyor's GPT-questionnaire response tool. It auto-generates precise, accurate answers to entire questionnaires with accuracy far superior to existing tools on the market. It's s...

Aug 11, 202325 min

CISA's .NET warning, Compellent exposes VMWare, DEFCON AI challenge

CISA Warns organizations of exploited vulnerability affecting .NET, Visual Studio Dell Compellent hardcoded key exposes VMware vCenter admin creds DEF CON: Thousands of security researchers vie to outsmart AI in Las Vegas Thanks to today's episode sponsor, Conveyor We can all agree there's one thing the AI bots can take from us: completing customer security questionnaires. That's why we built Conveyor's GPT-questionnaire response tool. It auto-generates precise, accurate answers to entire questi...

Aug 11, 20238 min

AI Cyber Challenge, eavesdropping typing app, Android cellular security

AI Cyber Challenge announced at Black Hat Tencent typing app had real time "eavesdropper" Google adds cellular security to Android Thanks to today's episode sponsor, Conveyor Your scariest questionnaires that are HUNDREDS of questions long are no match for Conveyor's GPT-security questionnaire tool - the most accurate questionnaire automation tool on the market. It's so accurate that you can even let customers upload their own questions in your portal to get instant answers generated from your c...

Aug 10, 20237 min

Google's Messages app now encrypts chats, Electoral Commission apologizes to UK voters, Banks hit with fines for using chat apps

Google's Messages app now uses RCS to encrypt chats Electoral Commission apologizes for security breach involving UK voters' data Banks hit with over $500 million in fines for using out-of-band chat apps Thanks to today's episode sponsor, Conveyor Did you catch the biggest release of the year? No, not Barbenheimer. It's Conveyor's GPT-powered security questionnaire response tool: the most accurate questionnaire automation tool on the market. It's so good, you can let your customers upload their ...

Aug 09, 20239 min

K-12 cyber initiatives, Russian missile contractor breached, LLMs getting worse

White House rolls out school cyber initiatives North Koreans breach Russian missile developer Large language models getting worse at math Thanks to today's episode sponsor, Conveyor GPT for security questionnaires? Conveyor has already built that for you. Conveyor's GPT-questionnaire response tool is so accurate, you can use it in two ways. One: Let your customers upload their own questions in your trust portal to get AI-generated answers based on the content in your portal. And Two: It's not ju...

Aug 08, 20237 min

Tenable smacks Microsoft, hospital ransomware attacks, accurate acoustic spyware

Microsoft resolves vulnerability following criticism from Tenable CEO FBI investigating ransomware attack crippling hospitals across 4 states New acoustic attack steals data from keystrokes with 95% accuracy Thanks to today's episode sponsor, Conveyor Did you catch the biggest release of the year? No, not Barbenheimer. It's Conveyor's GPT-powered security questionnaire response tool: the most accurate questionnaire automation tool on the market. It's so good, you can let your customers upload th...

Aug 07, 20238 min

Week in Review: IDOR vulnerability warning, Israel refinery cyberattack, spies bemoan AI training

Link to Blog Post This week's Cyber Security Headlines – Week in Review , July 31-August 4, is hosted by Rich Stroffolino with guest, Jeff Hudesman , CISO, Pinwheel Thanks to our show sponsor, Opal Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It's fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, an...

Aug 04, 202323 min
Hosted on Libsyn
For the best experience, listen in Metacast app for iOS or Android