CyberWire Daily

The oversized file that stalled the internet.

Nov 19, 2025
Rotem Tsadok, Director of Security Operations and Forensics at Varonis, shares insights from thousands of investigations in cybersecurity. He discusses a massive Cloudflare outage caused by a configuration error, and the alarming tactics used by China to target lawmakers through LinkedIn. Rotem highlights the rising challenges AI poses to security, including issues with LLMs and AI-driven phishing threats. He recommends immediate actions like enforcing MFA and aggressive patching to combat vulnerabilities. AI's potential for threat detection also gets a nod!
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Software Updates Turned Into Attack Vector

  • PlushDaemon hijacks software updates by redirecting DNS on compromised devices to attacker-controlled servers.
  • The group delivers staged payloads culminating in a backdoor through update supply-chain attacks.
INSIGHT

WhatsApp Directory Exposed At Scale

  • Researchers found WhatsApp's global directory of 3.5 billion accounts was accessible online without protection.
  • The dataset exposed phone numbers, profile data, public keys, and profile photos at scale.
ANECDOTE

Ransomware Hits LG Energy Solution

  • LG Energy Solution confirmed a ransomware attack after Akira listed stolen data on its leak site.
  • The group claims 1.7 TB of corporate and employee data were taken from an overseas facility.
Get the Snipd Podcast app to discover more snips from this episode
Get the app