

Cybersecurity Headlines
CISO Series
Daily stories from the world of information security. To delve into any daily story, head to CISOseries.com.
Episodes
Mentioned books

Aug 30, 2024 • 8min
DICK'S Sporting Goods cyberattack, Brain Cipher hacked Paris
DICK'S Sporting Goods faces a significant cyberattack, raising concerns about retail cybersecurity. Meanwhile, the Brain Cipher group claims responsibility for striking Paris museums and threatens data leaks. The Play Ransomware Gang targets Microchip Technology, underlining the increasing dangers in digital security. A disgruntled former employee engages in an alarming extortion plot, and new tools emerge to combat evolving cyber threats. As tactics and scams become more sophisticated, the world of cybercrime keeps us on our toes.

Aug 29, 2024 • 8min
Iran hacking, Labour Party backlog, more Telegram warrants
Iran's Islamic Revolutionary Guard Corps is intensifying phishing attacks, specifically targeting U.S. officials. The discussion also highlights the UK Labour Party's delays in addressing cyber vulnerabilities. Investigations reveal setbacks in their response to cyber incidents, prompting concerns. Additionally, critical vulnerabilities in Hitachi Energy's systems are flagged, while Google boosts its bug bounty for Chrome. Meanwhile, ongoing issues with Telegram in France underscore growing digital security challenges in today's political climate.

Aug 28, 2024 • 8min
Another MOVEit incident, U.S. Marshals disputes breach, Park'N Fly data swiped
In a recent cybersecurity incident, Texas credit union user data was exposed in yet another MOVEit breach. The U.S. Marshals Service is contesting claims made by a ransomware gang regarding a breach. Meanwhile, Park’N Fly has alerted 1 million customers about a significant data breach. Additionally, discussions on innovative cybersecurity responses include using AirTags for crime prevention and addressing vulnerabilities that could be exploited by foreign actors.

Aug 27, 2024 • 7min
SonicWall access flaw, Microsoft security summit, Telegram details
SonicWall highlights a critical access control flaw in its firewalls, raising serious security concerns. Microsoft is gearing up for a significant security summit to address current challenges. Meanwhile, the arrest of Telegram's CEO spotlights ongoing issues with content moderation and digital safety. The discussion also dives into emerging malware threats, particularly Engate targeting banks, alongside a chilling ransomware case study involving the American Radio Relay League.

Aug 26, 2024 • 7min
Halliburton suffers cyberattack, Telegram CEO arrested, Georgia Tech lawsuit
Pavel Durov, CEO of Telegram, discusses his recent arrest by French police amidst a backdrop of rising cyber threats. The conversation highlights Halliburton's proactive measures in response to a cyberattack, illustrating the increasing risks in the corporate world. They delve into the Justice Department's vigorous lawsuit against Georgia Tech regarding cybersecurity failures. Furthermore, listeners learn about alarming trends such as new Linux malware targeting financial data and the sophisticated tactics employed in recent ransomware attacks.

Aug 23, 2024 • 31min
Week in Review: NPD breach update, Hawaii hacker sentenced, Poisoned LLM coders
Bethany De Lude, the Chief Information Security Officer at The Carlyle Group, joins the conversation to unpack a significant data breach affecting 1.3 million individuals. The duo discusses the normalization of cyber incidents and vulnerabilities in technology, particularly with Google Pixel devices. They dive into the sentencing of a hacker linked to the Hawaii Death Registry and the pressing need for secure application practices. Plus, they explore the impact of evolving collaborative tools and the potential pitfalls of large language models in generating insecure code.

Aug 23, 2024 • 8min
Russia's questionable DDoS, FAA's cybersecurity proposal, Windows Recall reappears
The Kremlin's claims of a DDoS attack are met with skepticism by experts. Meanwhile, the FAA is pushing for new cybersecurity standards for airplanes. Microsoft revives its Recall feature, focusing on enhancing security. The discussion also touches on cryptocurrency extortion and the ongoing threat from state-sponsored exploitation of vulnerabilities like Log4Shell. A new app from Microsoft aims to simplify account management while improving cybersecurity.

Aug 22, 2024 • 7min
Japanese auto security, Feds tap encrypted messages, Microsoft breaks Linux dual-booting
Japanese automakers are collaborating to enhance vehicle security, a significant move in the industry. Meanwhile, U.S. authorities are increasing their ability to access encrypted communications, raising privacy concerns. In tech, Microsoft has disrupted Linux dual-booting systems, creating a stir among users. The conversation also touches on recent cyber incidents affecting chipmakers and GitHub, along with new ransomware defenses from QNAP. These topics spotlight the evolving landscape of cybersecurity challenges and innovations.

Aug 21, 2024 • 8min
Toyota third-party breach, Hawaii registry hack, Iran disrupting campaigns
Toyota faces a significant data breach affecting customer information, linked to the Zero7 Group. A Kentucky man receives sentencing for hacking Hawaii's death registry in a desperate bid to dodge payments. U.S. intelligence indicates Iran's involvement in cyber attacks aimed at disrupting Trump campaign activities. The discussion expands to cover emerging threats, including foreign hacking of personal emails and new scams targeting mobile banking users, as well as key vulnerabilities in technology.

Aug 20, 2024 • 8min
National Public Data breach update, Flaws in macOS apps, FlightTracker configuration issue
A recent data breach affects 1.3 million individuals, highlighting vulnerabilities in Microsoft macOS apps that allow secret recordings. Additionally, a configuration mishap exposes sensitive flight tracking information. The discussion also covers the complexities of cybersecurity and the urgent need for federal attention on significant vulnerabilities, including one in Jenkins. Lastly, there's a look into the evolving role of Chief Information Security Officers and the challenges they face in maintaining technical competence against emerging threats.


