

Cybersecurity Headlines
CISO Series
Daily stories from the world of information security. To delve into any daily story, head to CISOseries.com.
Episodes
Mentioned books

8 snips
Apr 11, 2025 • 8min
Krebs probed, Nissan Leaf hack, Typhoon tariff warning
The podcast dives into the abrupt sacking of former CISA Director Chris Krebs and the subsequent investigation. It reveals alarming vulnerabilities in Nissan Leaf cars that could allow for remote spying and control. Experts discuss the potential backlash from China related to tariffs, highlighting rising cybersecurity threats amid geopolitical tensions. The conversation also touches on various ransomware incidents, ongoing vulnerabilities in critical infrastructure, and new efforts to enhance cyber awareness in the community.

16 snips
Apr 10, 2025 • 8min
OCC major incident, Oracle confirms hack, Smokeloader servers seized
A significant email breach at the U.S. Comptroller's office raises alarms in cybersecurity. Oracle faces scrutiny after hackers exploit its outdated servers. Europol takes action by seizing Smokeloader malware servers and arresting key players in the botnet. A discussion on emerging threats reveals the rise of advanced phishing tactics and alarming ransomware trends. AI's potential role in scamming is also explored, shedding light on the evolving landscape of cyber threats.

Apr 9, 2025 • 7min
New WhatsApp vulnerability, Microsoft patches 125 Windows Vulns, Fake Microsoft Office add-in tools push malware
A critical vulnerability in WhatsApp could allow remote code execution, raising alarms for users. Microsoft has patched 125 Windows vulnerabilities, including a dangerous zero-day exploit. Meanwhile, a German defense firm faces backlash for its expensive drones. The podcast also highlights the rising threat of identity-based attacks and malware masquerading as Microsoft Office add-ins, alongside ongoing legislative moves to bolster privacy protections against the backdrop of increasing cyber threats.

8 snips
Apr 8, 2025 • 7min
Apple encryption appeal, Xanthorox AI tool, weaponizing CRM
Apple is making headlines as it fights back against a UK order for encryption back doors. Researchers are raising alarms over an AI-driven hacking tool called Xanthorox, which poses new threats. Meanwhile, the PoisonSeed campaign is being weaponized against CRM systems, targeting users of Coinbase. The discussion also highlights the emergence of malicious VS Code extensions and the critical need for AI integration in cybersecurity practices. Tune in for insights into these pressing issues!

7 snips
Apr 7, 2025 • 7min
NSA Haugh fired, New WinRAR flaw, ChatGPT fake passport
Big changes in cybersecurity leadership unfold with the firing of a top NSA official. A significant vulnerability in WinRAR raises eyebrows, bypassing essential Windows security alerts. A shocking demonstration of identity theft sees a researcher crafting a fake passport using ChatGPT. Elaborate new threats are revealed, including a deceitful cyberattack disguised as a job interview. Meanwhile, credential stuffing attacks on Australian pension funds prompt urgent discussions about security measures.

7 snips
Apr 4, 2025 • 31min
Week in Review: Microsoft's account bypass, CrushFTP CVE clash, 23andMe warning
Howard Holton, COO and industry analyst at GigaOm, joins the discussion on pressing cybersecurity issues. He delves into Microsoft's controversial account bypass removal, raising questions about user freedom. The talk shifts to a critical vulnerability in Crush FTP and its implications on data privacy, especially for companies like 23andMe. They also touch on North Korean cyber operatives impersonating tech employees and the challenges of identity verification in remote work. Finally, the conversation highlights the evolving role of AI in cybersecurity and the importance of fostering a strong security culture.

Apr 4, 2025 • 9min
Google patches Quick Share, ChatGPT temporary outage, UK Mail breach
A recent vulnerability in Google's Quick Share was patched, addressing serious security concerns. In addition, the popular AI tool ChatGPT experienced a brief outage, sparking discussions about its reliability. Meanwhile, the UK's Royal Mail is investigating data leak claims, raising alarms about sensitive information security. Tune in for insights on the latest cybersecurity developments and how these incidents shape the digital landscape!

Apr 3, 2025 • 7min
North Korean IT workers move into Europe, Stripe API skimming unveils theft techniques, Verizon API flaw exposes call history
The podcast dives into the expanding presence of North Korean IT workers in Europe, highlighting significant cybersecurity threats. It also reveals new techniques in a Stripe API skimming campaign, showing how deceitful tech can evolve. Furthermore, a vulnerability in Verizon's API is discussed, exposing users' call history and raising privacy concerns. In addition, the conversation touches on Europol's takedown of a child exploitation network, outlining the fight against such criminal operations and the emerging risks posed by AI-based threats.

8 snips
Apr 2, 2025 • 7min
Mozilla Thunderbird takes on Gmail, surge in scans on PAN GlobalProtect VPNs, Microsoft uncovers bootloader vulnerabilities
Mozilla Thunderbird is stepping up its game with a new email service to rival Gmail, emphasizing user privacy. Meanwhile, reports show a surge in scans targeting PAN GlobalProtect VPNs, suggesting the potential for looming attacks. Microsoft is leveraging AI to uncover critical vulnerabilities in bootloaders, highlighting pressing security concerns. Staffing cuts at the FDA also raise alarms about medical device cybersecurity, illustrating that threats are evolving across various sectors.

8 snips
Apr 1, 2025 • 9min
FTC's warning to 23andMe buyer, global phishing threats, Samsung breach
The FTC raises alarms about genetic data privacy related to a potential 23andMe buyer. A global phishing threat is affecting 88 countries, utilizing clever tactics to lure victims. Meanwhile, Samsung faces scrutiny for a breach connected to outdated stolen credentials. North Korean operatives are exploiting job applications for infiltration, posing significant risks. Lastly, the resurgence of the Quackbot Banking Trojan reveals new deceptive methods, while the EU invests heavily in cybersecurity to combat these evolving threats.


