

Cybersecurity Headlines
CISO Series
Daily stories from the world of information security. To delve into any daily story, head to CISOseries.com.
Episodes
Mentioned books

Dec 27, 2024 • 8min
General Dynamics phished, Japan Airlines attack, Addiction Centers breach
A phishing attack targeted employees at General Dynamics, raising concerns about workplace vulnerabilities. Meanwhile, Japan Airlines has returned to normal operations following a disruptive cyberattack. The American Addiction Centers suffered a major data breach, exposing personal details of over 400,000 individuals, potentially linked to the Ryceda ransomware gang. The landscape of cyber threats is evolving, with Microsoft highlighting a Windows 11 issue and new malware like Luma InfoStealer on the rise. Explore the implications of these breaches on security strategies.

Dec 26, 2024 • 7min
Disinformation office closes, Pittsburgh Transit cyberattack, Mirai NNVR botnet
The disbandment of the State Department's disinformation office raises questions about the fight against misinformation. A ransomware attack on Pittsburgh Regional Transit showcases the vulnerabilities in public infrastructure. Meanwhile, the Mirai botnet continues to exploit NVRs and TP-Link routers, highlighting the ongoing cybersecurity menace. Recent vulnerabilities in Apache software and Rui OS devices add to urgent security concerns, while North Korean hackers and the Charming Kitten group reveal the ever-evolving threat landscape.

Dec 24, 2024 • 7min
Government to name witness in encrypted chat sting
Explore the alarming use of large language models by threat actors to create undetectable malware. Learn about a federal ruling against the NSO Group and fines on OpenAI for privacy breaches. Discover Apple's efforts to help spyware victims and Microsoft's patches for subscription issues. Dive into the court case involving the Anom encrypted app and its implications for law enforcement. Lastly, understand the escalating cybersecurity threats posed by North Korean hackers targeting sensitive organizations.

Dec 23, 2024 • 8min
FlowerStorm attacks Microsoft 365, BeyondTrust on KEV, Ascension Health fallout
A new phishing platform called FlowerStorm is targeting Microsoft 365 users with advanced tactics. BeyondTrust has vulnerabilities added to the Known Exploited Vulnerabilities catalog, raising alarms in cybersecurity. The ransomware attack on Ascension Health has impacted nearly 6 million people, showcasing severe threats in the healthcare sector. Legal measures against cybercriminals are gaining traction as cryptocurrency thefts by North Korean hackers continue to escalate, illustrating the persistent dangers in the world of cybercrime.

5 snips
Dec 20, 2024 • 28min
Week in Review: Data breach impact study, US weighs TP-Link ban, BeyondTrust cyberattack
Bethany De Lude, CISO at The Carlyle Group, dives into the surge of data breaches and their lasting impacts on businesses. She highlights the pressing challenges faced by CISOs, particularly the evolving security landscape and risks tied to identity security. The conversation touches on the national security concerns surrounding TP-Link and the threats of zero-day exploits. De Lude also discusses the importance of upgrading hardware in critical infrastructure and addresses online scam terminology, focusing on empathy for victims.

6 snips
Dec 20, 2024 • 8min
Amazon health malware, BeyondTrust suffers cyberattack, FortiNet wireless vulnerability
A health app malware was discovered on the Amazon Appstore, raising alarms about security in digital health. BeyondTrust faced a significant cyberattack that exposed sensitive data. Fortinet issued warnings about a critical flaw in its Wireless LAN Manager product that could enable remote attacks. The podcast also covers the resignation of a key DHS official, the spike in Mirai malware targeting Juniper routers, and emphasizes the importance of proactive cybersecurity measures for organizations.

Dec 19, 2024 • 8min
Interpol romance baiting, TikTok at court, TP-Link investigation
Discover Interpol's clever rebranding of scams as 'romance baiting' to help victims feel less ashamed. Dive into the Supreme Court's consideration of a TikTok ban over national security concerns. Learn about troubling investigations into TP-Link routers and their implications. Additionally, catch up on significant cybersecurity events like a data breach at Cisco and ongoing credential theft campaigns in Europe. The complexities of decentralized social platforms also come under scrutiny.

7 snips
Dec 18, 2024 • 8min
CISA cloud directive, Texas Tech breach, Meta GDPR fine
Discover the latest CISA directive aimed at bolstering cloud security for federal agencies. Texas Tech University faces a significant data breach affecting 1.4 million individuals. Meta's hefty $263 million fine for GDPR violations raises questions about data compliance. Explore how social engineering and phishing scams target software developers, especially through platforms like Microsoft Teams. Stay informed about crucial software vulnerabilities and legal challenges shaping today's cybersecurity landscape.

Dec 17, 2024 • 9min
Serbian authorities use spyware, Ransomware impacts Rhode Island, ConnectOnCall breach
Serbian authorities are under fire for allegedly using spyware to monitor journalists. A ransomware attack has wreaked havoc on Rhode Island’s public assistance system, leaving many in the lurch. Meanwhile, a breach at ConnectOnCall has exposed the data of nearly one million patients. The podcast delves into the escalating threat of ransomware, including its impact on organizations like SRP Federal Credit Union and Telecom Namibia's refusal to pay ransom demands amid data leaks. Cybersecurity remains a pressing concern!

7 snips
Dec 16, 2024 • 8min
Health chatbot exposed, credit union cyberattack, infrastructure cyberweapon attack
A vulnerable AI chatbot from UnitedHealth has left sensitive data exposed to potential hackers. Meanwhile, a South Carolina credit union faces a serious cyberattack, highlighting the risks for financial institutions. The emergence of a new cyberweapon, I.O. Control, threatens critical infrastructure in the U.S. and Israel. Recent malware developments are affecting everyday devices, leading to widespread security concerns. Additionally, a networking event in San Diego aims to unite cybersecurity professionals to tackle these escalating threats.


