Cybersecurity Headlines - podcast cover

Cybersecurity Headlines

CISO Seriescisoseries.com
Daily stories from the world of information security. To delve into any daily story, head to CISOseries.com.
Last refreshed:
Download Metacast podcast app
Podcasts are better in Metacast mobile app
Don't just listen to podcasts. Learn from them with transcripts, summaries, and chapters for every episode. Skim, search, and bookmark insights. Learn more

Episodes

LockBit's website is back, Germany takes action amid alleged Russian attack, Chinese-linked ArcaneDoor targets infrastructure

LockBit's website is back Germany takes action amid alleged Russian attack Chinese-linked ArcaneDoor targets global network infrastructure Huge thanks to our sponsor, Vanta Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide...

May 07, 20249 min

Neuberger proposes improvements, Olympic cybersecurity preparations, Microsoft VPN warning

NSC's Neuberger suggests operational approach for on mitigating cyberattacks French cybersecurity teams prepare for "unprecedented" Olympic threat Feds warn about North Korean exploitation of improperly configured DMARC Huge thanks to our sponsor, Vanta Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstr...

May 06, 20248 min

Week in Review: Dropbox Sign breach, Cybersecurity consultant arrested, Ukraine Microsoft hack

Link to blog post This week's Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Phil Beyer , former CISO, Etsy Thanks to today's episode sponsor, Dropzone.ai Dropzone.ai's AI Autonomous Analyst is transforming cybersecurity as we know it. By replicating the techniques of elite analysts and autonomously investigating every alert, our patented system force multiplies your SOC team by 10X without adding headcount. Experience the future of threat detection and respon...

May 03, 202426 min

Goldoon exploits D-Link, CISA GitLab warning, Dropbox Sign breach

Goldoon botnet exploits D-Link routers CISA adds Gitlab flaw to its KEV catalog Dropbox discloses breach of digital signature service Thanks to our episode sponsor, Dropzone AI Dropzone.ai's AI Autonomous Analyst is transforming cybersecurity as we know it. By replicating the techniques of elite analysts and autonomously investigating every alert, our patented system force multiplies your SOC team by 10X without adding headcount. Experience the future of threat detection and response at dropzone...

May 03, 20249 min

Chinese disinformation, NCSC AMS, new State Secrets law

Chinese disinformation proving ineffectual NCSC release Advanced Mobile Solutions risk model China implements new State Secrets Law Thanks to our episode sponsor, Dropzone AI Cybersecurity leaders, are you being asked to leverage the power of Gen AI in your SOC? Dropzone.ai's AI Autonomous Analyst empowers your team to thoroughly investigate every alert. No playbooks, no code, just intelligent, adaptable alert investigation. Test drive on dropzone.ai to immediately see the results for yourself....

May 02, 20247 min

UnitedHealth Group CEO faces congress, U.S. wireless carriers face majors fine, Marriott backtracks protection claims

UnitedHealth Group CEO faces congress & cause of hack revealed Major U.S. wireless carriers face $200M FCC fine Marriott backtracks claims of encryption protection Thanks to our episode sponsor, Dropzone AI Dropzone.ai is proud to announce our selection as a Top 10 Finalist for the prestigious RSA Innovation Sandbox. Our AI Autonomous Analyst is revolutionizing the way SOC teams operate, replicating the techniques of elite analysts and autonomously investigating every alert. Meet us at RSAC ...

May 01, 202410 min

USPS phishing, UK IoT law, industrial USB attacks

USPS phishing sites are popular UK bans bad IoT credentials USB malware attacks targeting industrial sites Thanks to our episode sponsor, Dropzone AI Attention cybersecurity professionals! Are you investigating 100% of the alerts from your IT and security systems? Dropzone.ai's AI Analyst autonomously investigates every alert without playbooks or code, enabling you to turn over every rock. Visit dropzone.ai to learn more and request a trial. Offload your tier-1 analysis to an AI analyst that nev...

Apr 30, 20247 min

Kaiser Permanente breach, DSH Safety Board, Okta stuffing attack

Kaiser Permanente website tracking tools may have compromised customer data DHS announces AI safety board Okta warns of "unprecedented" credential stuffing attacks on customers Thanks to our episode sponsor, Dropzone AI Introducing Dropzone.ai , the industry's first AI Autonomous SOC Analyst. Their patented LLM replicates the techniques of elite analysts, autonomously investigating every alert without playbooks or code. Force multiply your SOC team by 10X without adding headcount. Visit dropzone...

Apr 29, 20248 min

Week in Review: GitHub comments abused, networkless" attack techniques, Police bodycam AI reports

Link to blog post This week's Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Christina Shannon , CIO, KIK Consumer Products Thanks to our show sponsor, Veracode Get ready to experience the future of application security at RSAC 2024 with Veracode . Join us as we unveil cutting-edge innovations and insights to tackle today's most pressing security challenges. From live demos showcasing our newest products to engaging discussions with industry experts. See you a...

Apr 26, 202423 min

Google postpones cookies, Brocade vulnerability warning, ICICI card gaffe

Google postpones third-party cookie deprecation Brocade SAN appliances and switches exposed to hacking ICICI Bank exposes credit cards to wrong users Thanks to this week's episode sponsor, Veracode Don't miss out on this opportunity to elevate your cybersecurity strategy. Build and scale secure software from code to cloud with speed and trust. Visit our booth #2045 at RSAC 2024 to discover how Veracode is shaping the future of Application Security in the AI era. For the stories behind the headli...

Apr 26, 20248 min

Chinese keyboard flaws, hacked news story, TikTok on the clock

Chinese keyboard app flaws exposed Threat actors plant fake assassination story ByteDance on the clock to divest TikTok Thanks to this week's episode sponsor, Veracode Research reveals AI-generated code mirrors human-written code's security flaws. Even seasoned programmers struggle to spot errors, with incorrect AI-generated answers abound. Veracode knows the stakes. While AI accelerates coding, relying on hunches won't suffice. Trust multi-faceted, data-driven insights to mitigate risk from the...

Apr 25, 20247 min

Iranian hackers charged, Siemens fixing Palo bug, Russia hacks water plant

Iranian nationals charged with hacking U.S. companies and agencies Siemens working to fix device affected by Palo Alto firewall bug Russian hackers claim cyberattack on Indiana water plant Thanks to this week's episode sponsor, Veracode Are you truly listening to both your security and development teams? Make informed decisions with Veracode . Our developer-friendly security tools integrate with your existing tech stack to secure code from the start. Bridge the gap between security and developme...

Apr 24, 20248 min

TikTok ban update, Sandworm hits Ukraine, North Korean streaming animators

TikTok ban passes the US House Sandworm targets critical Ukrainian orgs North Koreans animating streaming shows Thanks to this week's episode sponsor, Veracode AI coding companions assist in generating high-quality code snippets, while Veracode swoops in to conduct thorough security assessments, identifying and fixing vulnerabilities quickly. With this dynamic duo, developers can innovate with confidence, knowing their code is both efficient and secure. Secure more code with Co-Pilot or any AI c...

Apr 23, 20247 min

RedLine GitHub connection, MITRE Ivanti breach, E-ZPass spoof sites

RedLine stealer GitHub connection MITRE's breached was through Ivanti zero-day vulnerabilities Researchers find dozens of fake E-ZPass toll websites following FBI warning Thanks to this week's episode sponsor, Veracode Imagine your intelligent coding companion, backed by the robust security expertise of Veracode . Together, we form the ultimate duo, empowering developers to write better code while ensuring it's secure from the get-go. Learn more at RSAC 2024 with Veracode . For the stories behin...

Apr 22, 20247 min

Week in Review: Cisco MFA breach, Bad bots surge, Microsoft mail breach fallout

Link to blog post This week's Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Dan Walsh , CISO, Paxos Thanks to our show sponsor, Conveyor Happy Friday! Are you tired of hearing about Conveyor's AI security review automation software? We'll stop talking about it if you book a call. Ready to give the market leading AI for security questionnaires a spin? Try a free proof of concept at www.conveyor.com . Don't forget to mention this podcast for 5 free questionnair...

Apr 19, 202427 min

LabHost police bust, Michigan healthcare attack, Windows Fibers vulnerability

Police bust reveals sophisticated phishing-as-a-service platform Overlooked Windows Fibers offer handy route for malicious payload deployment Michigan healthcare organization suffers data breach Thanks to today's episode sponsor, Conveyor Happy Friday! Are you tired of hearing about Conveyor's AI security review automation software? We'll stop talking about it if you book a call. Ready to give the market leading AI for security questionnaires a spin? Try a free proof of concept at www.conveyor.c...

Apr 19, 20247 min

Water utility threats, GPT-4 hacking, SIM swap solicitation

Sandworm-linked group tied to attack on water utilities GPT-4 reads security advisories Cell carrier workers solicited for SIM swaps Thanks to today's episode sponsor, Conveyor Conveyor is the market leading AI-powered platform that automates the entire customer security review process — from sharing your security posture and SOC 2 in a single portal to using that same information to automate answering security questionnaires with 90% accuracy. Use Conveyor to fly through any customer security r...

Apr 18, 20247 min

Cisco MFA breach, Bad Bots surge, LockBit 3.0 propagates

Cisco announces breach of multifactor authentication message provider Bad bots drive 10% annual surge in account takeover attacks LockBit 3.0 variant generates custom, self-propagating malware Thanks to today's episode sponsor, Conveyor Conveyor is the AI security review automation platform helping infosec teams automate everything from securely sharing a SOC 2 to one-click autofilling security questionnaires with AI so you can spend almost zero time on the manual tasks that make you want to cry...

Apr 17, 202410 min

Threads out in Turkey, Palo Alto backdoor, Microsoft' security overhaul

Meta to close Threads in Turkey Palo Alto fixes backdoor zero-day Details on Microsoft's security overhaul Thanks to today's episode sponsor, Conveyor What are infosec teams measuring these days? More often than not, their impact on sales. As infosec teams become hands on in the sales cycle, proving your value becomes key. A director of GRC said last week that the most direct value for their CEO was showing the efficiencies and the dollars that security has been able to bring in from enabling sa...

Apr 16, 20248 min

U.S. surveillance reauthorization, Roku breach update, Microsoft breach exposed agencies

House passes reauthorization of U.S. surveillance program Roku says 576,000 accounts compromised in latest security breach Microsoft breach exposed federal agencies Thanks to today's episode sponsor, Conveyor It's Conveyor again, the market-leading AI software for answering security questionnaires and securely sharing your security posture and documents. Conveyor's 'State of the Security Review" report for 2024 was just released and it's all about what the "new era" of infosec holds. Learn how p...

Apr 15, 20248 min

Week in Review: Government hospital warning, Sisence breach, Financial firms lose $12b

Link to blog post This week's Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Mike Levin , deputy CISO, 3M Thanks to our show sponsor, Vanta When it comes to ensuring your company has top-notch security practices, things can get complicated fast. With Vanta , you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA. Even more, Vanta's market-leading Trust Management Platform enables you to unify security program management with a bu...

Apr 12, 202424 min

Palo Alto patches, CISA's Sisense warning, GitHub repos gamed

Palo Alto Networks fixes several DoS vulnerabilities in PAN-OS operating system Sisense breach exposes customers to potential supply chain attack Threat actors gaming GitHub Search Thanks to today's episode sponsor, Vanta The average security pro spends nearly a full workday every week just on compliance. With Vanta , you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA. Even more, Vanta's market-leading Trust Management Platform enables you to unify security pro...

Apr 12, 20249 min

CISA malware analysis, "hunt forward" missions, Spectre v2

CISA expands automated malware analysis US Cyber Command launched "hunt forward" missions Spectre v2: Linux Boogaloo CHECK OUT Capture the CISO season 2 here . Thanks to today's episode sponsor, Vanta The average security pro spends nearly a full workday every week just on compliance. With Vanta , you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA. Even more, Vanta's market-leading Trust Management Platform enables you to unify security program management with ...

Apr 11, 20247 min

Ukraine cyber head suspended, LG TV vulns, Microsoft exposed passwords

Ukraine's head of cybersecurity suspended and assigned to combat zone Over 90,000 LG Smart TVs exposed to remote attack Microsoft exposed internal passwords in security lapse Thanks to today's episode sponsor, Vanta The average security pro spends nearly a full workday every week just on compliance. With Vanta , you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA. Even more, Vanta's market-leading Trust Management Platform enables you to unify security program m...

Apr 10, 20249 min

Cyberattack impacts vet firm, data privacy bill movement, DOJ hack exposes thousands

Cyberattack causes major disruptions for UK vet firm Data privacy bill pushes forward with bipartisan support Department of Justice hack exposes hundreds of thousands Thanks to today's episode sponsor, Vanta The average security pro spends nearly a full workday every week just on compliance. With Vanta , you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA. Even more, Vanta's market-leading Trust Management Platform enables you to unify security program managemen...

Apr 09, 20249 min

Hospital hack warning, Five Eyes follow-up, NYC municipal hack

Government warns hospitals of hackers targeting IT help desks U.S. government contractor Acuity responds to alleged Five Eyes breach New York City becomes latest in municipal government hack attempts Thanks to today's episode sponsor, Vanta The average security pro spends nearly a full workday every week just on compliance. With Vanta , you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA. Even more, Vanta's market-leading Trust Management Platform enables you to...

Apr 08, 20249 min

Week in Review: Five Eyes breach, Microsoft's Chinese hack response, AT&T customer breach

Link to blog post This week's Cyber Security Headlines – Week in Review is hosted by David Spark with guest Steve Gentry , Advisor, Clari Thanks to our show sponsor, Vanta The average security pro spends nearly a full workday every week just on compliance. With Vanta, you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA. Even more, Vanta's market-leading Trust Management Platform enables you to unify security program management with a built-in risk register and r...

Apr 05, 202428 min

Five Eyes breach, cancer center breach, Pixel zero-day flaw

Classified Five Eyes data theft announced Cancer center data breach affects 800,000 Android Pixel phone zero-day flaws being exploited by forensic companies Thanks to today's episode sponsor, Vanta The average security pro spends nearly a full workday every week just on compliance. With Vanta , you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA. Even more, Vanta's market-leading Trust Management Platform enables you to unify security program management with a b...

Apr 05, 20248 min

Microsoft security failings, NIST NVD backlog, Chrome DBSC beta

Report criticizes Microsoft's Chinese hack response NIST needs help with vulnerability backlog Chrome tests feature to prevent session hijacking Thanks to today's episode sponsor, Vanta The average security pro spends nearly a full workday every week just on compliance. With Vanta , you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA. Even more, Vanta's market-leading Trust Management Platform enables you to unify security program management with a built-in risk...

Apr 04, 20248 min

Cyber incident reporting rule, Google blocks spoofed emails, PandaBuy breach

CISA releases draft rule for cyber incident reporting Google now blocks spoofed emails for better phishing protection Breach at online shopping platform PandaBuy affects 1.3 million customers Thanks to today's episode sponsor, Vanta The average security pro spends nearly a full workday every week just on compliance. With Vanta , you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA. Even more, Vanta's market-leading Trust Management Platform enables you to unify s...

Apr 03, 20247 min
Hosted on Libsyn
For the best experience, listen in Metacast app for iOS or Android