CyberWire Daily

Deadlines in the cloud.

29 snips
Aug 11, 2025
Steve Deitz, President of MANTECH's Federal Civilian Sector, delves into the innovative concept of cell-based Security Operations Centers (SOC). He highlights the urgent need for quick compliance, especially in light of the recent Microsoft Exchange vulnerabilities. The conversation also touches on the shift from espionage to financial crime by hackers, and how community efforts like the Franklin Project are bolstering cybersecurity. A humorous cautionary tale reveals the pitfalls of AI dietary advice—reminding listeners of the potential quirks of technology.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

WinRAR Path-Traversal Exploit Used

  • RomCom abused a WinRAR path traversal to extract files to attacker-defined locations via alternate data streams.
  • ESET disclosed the flaw and WinRAR released a patch after seeing resume-themed spearphishing attempts.
INSIGHT

Webcams Reflash Can Persist Infections

  • Researchers showed Linux webcams can be reflashed without physical access, creating persistent reinfection vectors.
  • Eclipsium warns other USB peripherals may share the unsigned firmware risk and Lenovo patched affected models.
ANECDOTE

Volunteers Harden Small Water Utilities

  • The Franklin Project mobilized 350 volunteers to secure five U.S. water utilities at no cost.
  • Tasks ranged from MFA and password changes to OT assessments and threat education for small, under-resourced systems.
Get the Snipd Podcast app to discover more snips from this episode
Get the app