

Cybersecurity Headlines
CISO Series
Daily stories from the world of information security. To delve into any daily story, head to CISOseries.com.
Episodes
Mentioned books

Sep 11, 2024 • 8min
Slim CD data breach, International sextortion bust, TfL mixed messages
A significant data breach at Slim CD has affected 1.7 million customers, raising alarms about cybersecurity. Authorities recently charged two men in a massive international sextortion scheme, highlighting the global nature of such crimes. Meanwhile, London’s transit agency faces scrutiny as it claims no evidence of customer data theft despite continuing cyber challenges. Additionally, the podcast delves into evolving tactics employed by cybercriminals, including credential harvesting and vulnerabilities in major software updates.

Sep 10, 2024 • 8min
Payment processing breach, dark web admins charged, Predator spyware resurges
A staggering 1.7 million individuals are affected by a recent payment processing breach. Meanwhile, dark web administrators have been charged, shedding light on the underground cyber landscape. The resurgence of Predator spyware raises alarming privacy concerns, posing new threats to personal security. As organizations grapple with these evolving challenges, the discussion emphasizes the dire need for enhanced cybersecurity measures.

Sep 9, 2024 • 8min
Avis rentals breach, Microsoft disables ActiveX, Wisconsin Medicare breach
Avis Rentals faces a significant data breach, raising concerns about user privacy. Microsoft takes a proactive step by disabling ActiveX controls in Office 2024 to bolster security. Wisconsin Medicare users are affected by the MOVEit breach, leading to potential data exposure. The podcast also addresses alarming trends like Quishing and North Korean hackers utilizing job scams on LinkedIn. Notably, it reveals a unique data exfiltration method called Rambo, which steals information from air-gapped computers through electromagnetic radiation.

Sep 6, 2024 • 25min
Week in Review: MFA bypass bust, Airport security SQL, GitHub help malware
Justin Somaini, a partner at YL Ventures, joins the discussion to delve into urgent cybersecurity threats. They tackle the fallout from the guilty pleas of MFA bypass service operators and a dangerous SQL injection that threatened airport security. The importance of employee education and third-party risk management comes into focus alongside the alarming trend of ransomware, especially relating to ethical dilemmas faced by researchers. Somaini cautions against complacency in digital spaces, emphasizing the need for robust cybersecurity practices.

Sep 6, 2024 • 8min
Planned Parenthood cyberattack, DoJ propaganda takedown, Microchip Technology theft
A cyberattack on Planned Parenthood reveals the rising threat of ransomware in healthcare. The takedown of propaganda domains shows the Justice Department's crackdown on disinformation. Microchip Technology confirms a significant data breach affecting semiconductor supply chains. Additionally, troubling vulnerabilities in Cisco and DRATEK software pose risks to sensitive information. With emerging malware targeting platforms like OnlyFans, the landscape of cybersecurity continues to evolve rapidly.

Sep 5, 2024 • 7min
Spyware research, Cicada rebrand, MacroPack malware
Spyware research report They found a way to make Cicadas more annoying MacroPack red teaming tool used for malware Thanks to today's episode sponsor, Scrut Automation Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That's www.scrut.io.

Sep 4, 2024 • 9min
Halliburton data stolen, Columbus sues researcher, White House protects internet
Halliburton confirms data stolen in cyberattack City of Columbus sues researcher after ransomware attack White House publishes plan to protect a key component of the internet Thanks to today's episode sponsor, Scrut Automation Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That's www.scrut.io. For the stories behind the headlines, visit CISOseries.com.

Sep 3, 2024 • 8min
London transport cyberattack, German ATC attack, Sweden's heightened risk
A recent cyberattack on Transport for London raises alarms about global transportation security. Meanwhile, Germany's air traffic control agency confirms its own cyber incident, reflecting a worrying trend. Sweden cautions against heightened risks of Russian sabotage, underscoring the geopolitical stakes involved. Additionally, discussions on lax security measures in companies and the rise of ransomware threats highlight the ongoing battle against cybercrime. Legal developments in online fraud and espionage tactics reveal the complexities of trust in today’s cybersecurity landscape.

Sep 2, 2024 • 8min
Seattle airport woes, aircraft cockpit SQL, North Korea's FudModule
Listeners dive into the recent cybersecurity threats at Seattle-Tacoma International Airport, where a major attack disrupted operations. The vulnerabilities in aircraft security are highlighted, along with a concerning SQL injection bypassing TSA checks. North Korea's sophisticated use of the FudModule rootkit in exploiting Chrome zero-days raises alarms. The discussion also touches on a dangerous fake fix solution aiming to steal data and innovative initiatives like Tabletop the Vote to enhance election security.

Aug 30, 2024 • 8min
DICK'S Sporting Goods cyberattack, Brain Cipher hacked Paris
DICK'S Sporting Goods faces a significant cyberattack, raising concerns about retail cybersecurity. Meanwhile, the Brain Cipher group claims responsibility for striking Paris museums and threatens data leaks. The Play Ransomware Gang targets Microchip Technology, underlining the increasing dangers in digital security. A disgruntled former employee engages in an alarming extortion plot, and new tools emerge to combat evolving cyber threats. As tactics and scams become more sophisticated, the world of cybercrime keeps us on our toes.


