
CyberWire Daily When politics break the firewall.
Oct 1, 2025
Tim Starks, a Senior Reporter at CyberScoop, delves into the alarming findings of a Senate Democrats' report on the Department of Government Efficiency (DOGE). He highlights that DOGE has operated outside privacy and cybersecurity regulations, sparking concerns about agency practices. The discussion also touches on bipartisan oversight efforts and how agencies have reacted to these findings. Starks warns citizens to stay vigilant about cybersecurity issues, emphasizing the importance of public engagement in governance.
AI Snips
Chapters
Transcript
Episode notes
ICE Resumes Bulk Location Purchases
- ICE resumed buying aggregated smartphone location data that can enable warrantless tracking of Americans in sensitive places.
- Critics warn this restores invasive surveillance despite past DHS IG findings of inadequate safeguards.
VMware Flaw Exploited Long-Term
- A VMware privilege-escalation flaw was used as a zero-day since Oct 2024, attributed to UNC5174, and affects OpenVM tools on Linux.
- Broadcom patched the issue without acknowledging exploitation while researchers linked weak regex logic enabling staged malicious binaries.
ClickFix Attacks Cross Platforms
- ClickFix-style attacks surged 631% and expanded to macOS and Linux by abusing helpful UI prompts to trick users into running commands.
- These lures bypass controls by weaponizing user behavior, requiring interpreter and egress monitoring to detect them.

