
CyberWire Daily Chalk one up for defenders.
Sep 9, 2025
Kevin Magee, Global Director of Cybersecurity Startups at Microsoft Security, discusses the pressing need for cybersecurity education amidst rising threats. He highlights a recent npm supply chain attack and the open source community's rapid response. Magee emphasizes bridging the skills gap in cybersecurity, advocating for specialized pathways to nurture new talent. The conversation also touches on the humorous missteps currently seen in AI, warning against over-reliance on this technology.
AI Snips
Chapters
Transcript
Episode notes
Scanning Spikes Warn Of Potential ASA Flaws
- Researchers saw major scanning spikes against Cisco ASA devices and IOS services, often preceding vulnerability disclosures.
- Admins should patch, enforce MFA, and restrict direct access to reduce exposure.
CISA Pushes Incident-Reporting Rule To 2026
- CISA delayed the incident-reporting rule to May 2026 to harmonize requirements and reduce burden.
- The rule will eventually require 72-hour incident reporting and 24-hour ransomware disclosure across critical infrastructure.
GAO: Federal Cyber Workforce Data Is Unreliable
- GAO found federal cybersecurity workforce data incomplete, with inconsistent role definitions and missing contractor counts.
- GAO recommended standardizing criteria, improving reporting, and assessing workforce effectiveness for better planning.
