Search this show’s transcripts

CyberWire Daily

en us
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.
More details
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.
Sources and links

Episodes

Page 22 · 50 per page

Director of Security Engineering at Marqeta and Host of Hacker Valley Studio podcast Chris Cochran describes his transitions throughout the cybersecurity industry, from an intelligence job with the Marine Corps, to starting the intelligence apparatus for the House of Representatives, then on to leading Netflix's threat intelligence capability. Chris points out that when pivoting to different roles and responsibilities, you must rely on your own strengths to move forward and bring value to your work Our thanks to Chris for sharing his story with us.

More description

Director of Security Engineering at Marqeta and Host of Hacker Valley Studio podcast Chris Cochran describes his transitions throughout the cybersecurity industry, from an intelligence job with the Marine Corps, to starting the intelligence apparatus for the House of Representatives, then on to leading Netflix's threat intelligence capability. Chris points out that when pivoting to different roles and responsibilities, you must rely on your own strengths to move forward and bring value to your work Our thanks to Chris for sharing his story with us.

Extract Knowledge
Listen elsewhere

Assaf Dahan and Daniel Frank from Palo Alto Networks Cortex sit down with Dave to talk about their research "Manic Menagerie 2.0: The Evolution of a Highly Motivated Threat Actor." From late 2020 to late 2022, Unit 42 researchers discovered an active campaign that targeted several web hosting and IT providers in the United States and European Union.

The research states "They have further deepened their foothold in victims’ environments by mass deployment of web shells, which granted them sustained access, as well as access to internal resources of the compromised websites."

The research can be found here:

More description

Assaf Dahan and Daniel Frank from Palo Alto Networks Cortex sit down with Dave to talk about their research "Manic Menagerie 2.0: The Evolution of a Highly Motivated Threat Actor." From late 2020 to late 2022, Unit 42 researchers discovered an active campaign that targeted several web hosting and IT providers in the United States and European Union.

The research states "They have further deepened their foothold in victims’ environments by mass deployment of web shells, which granted them sustained access, as well as access to internal resources of the compromised websites."

The research can be found here:

Extract Knowledge
Listen elsewhere

The FTC fines Avast over privacy violations. ConnectWise's ScreenConnect is under active exploitation. AT&T restores services nationwide. An Australian telecom provider suffers a data breach. EU Member States publish a cybersecurity and resilience report. Microsoft unleashes a PyRIT. A new infostealer targets the oil and gas sector. A cyberattack cripples a major US healthcare provider. Our guest is Kevin Magee from Microsoft Canada with insights on why cybersecurity startups in Ireland are having so much success building new companies there. And  a USB device is buzzing with malware.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Guest Kevin Magee from Microsoft Canada talks about recently meeting 15 cybersecurity startups in Ireland and finding out why they are having so much success building new companies there. 


Selected Reading

FTC Order Will Ban Avast from Selling Browsing Data for Advertising Purposes, Require It to Pay $16.5 Million Over Charges the Firm Sold Browsing Data After Claiming Its Products Would Block Online Tracking (FTC)

Cybercriminal groups actively exploiting ‘catastrophic’ ScreenConnect bug (The Record)

AT&T services resume, company blames "incorrect process" (Data Center Dynamics)

230k Individuals Impacted by Data Breach at Australian Telco Tangerine (SecurityWeek)

EU releases comprehensive risk assessment report on cybersecurity, resilience of communication networks (Industrial Cyber)

Microsoft Releases Red Teaming Tool for Generative AI (SecurityWeek)

New Infostealer Malware Attacking Oil and Gas Industry (GB Hackers on Security)

UnitedHealth says Change Healthcare hacked by nation state, as US pharmacy outages drag on (TechCrunch)

Vibrator virus steals your personal information (Malwarebytes)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

The FTC fines Avast over privacy violations. ConnectWise's ScreenConnect is under active exploitation. AT&T restores services nationwide. An Australian telecom provider suffers a data breach. EU Member States publish a cybersecurity and resilience report. Microsoft unleashes a PyRIT. A new infostealer targets the oil and gas sector. A cyberattack cripples a major US healthcare provider. Our guest is Kevin Magee from Microsoft Canada with insights on why cybersecurity startups in Ireland are having so much success building new companies there. And  a USB device is buzzing with malware.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Guest Kevin Magee from Microsoft Canada talks about recently meeting 15 cybersecurity startups in Ireland and finding out why they are having so much success building new companies there. 


Selected Reading

FTC Order Will Ban Avast from Selling Browsing Data for Advertising Purposes, Require It to Pay $16.5 Million Over Charges the Firm Sold Browsing Data After Claiming Its Products Would Block Online Tracking (FTC)

Cybercriminal groups actively exploiting ‘catastrophic’ ScreenConnect bug (The Record)

AT&T services resume, company blames "incorrect process" (Data Center Dynamics)

230k Individuals Impacted by Data Breach at Australian Telco Tangerine (SecurityWeek)

EU releases comprehensive risk assessment report on cybersecurity, resilience of communication networks (Industrial Cyber)

Microsoft Releases Red Teaming Tool for Generative AI (SecurityWeek)

New Infostealer Malware Attacking Oil and Gas Industry (GB Hackers on Security)

UnitedHealth says Change Healthcare hacked by nation state, as US pharmacy outages drag on (TechCrunch)

Vibrator virus steals your personal information (Malwarebytes)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2024-02-22

AT&T outage leaves major cities offline.

24 min
View

AT&T experiences a major outage. The LockBit takedown continues. An updated Doppelgänger is spreading misinformation. A roundup of critical infrastructure initiatives. Toshiba and Orange make a quantum leap. An eyecare provider hack comes into focus. A phony iphone repair scheme leads to convictions. In our Learning Layer segment, Sam Meisenberg shares the latest learning science research. And we are shocked - shocked! - to discover that phone chargers can be used to attack our devices. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

On this month’s Learning Layer segment, host Sam Meisenberg of N2K discusses learning science research. Sam breaks down research about quizzes and their impact on learner motivation and long term retention. Want to know more? Sam suggests you check out The Value of Using Tests in Education as Tools for Learning—Not Just for Assessment.


Selected Reading

AT&T, Verizon and T-Mobile customers hit by widespread cellular outages in U.S. (NBC News)

US Offering $10M for LockBit Leaders as Law Enforcement Taunts Cybercriminals (SecurityWeek)

LockBit Group Prepped New Crypto-Locker Before Takedown (Gov Info Security)

Ukraine arrests father-son duo in Lockbit cybercrime bust (Reuters)

Russian Cyberwarfare campaign (ClearSky Cyber Security)

US Coast Guard issues cybersecurity directive for Chinese-made cranes after Biden's Executive Order (Industrial Cyber) 

US agencies release joint fact sheet to strengthen cybersecurity in water and wastewater systems (Industrial Cyber) 

E-ISAC 2023 report highlights cybersecurity triumphs and challenges in electricity sector (Industrial Cyber) 

Toshiba and Orange test quantum encryption on traditional network (Computer Weekly)

Hack at Services Firm Hits 2.4 Million Eye Doctor Patients (Gov Info Security)

Chinese Duo Found Guilty of $3m Apple Fraud Plot (Infosecurity Magazine)

VoltSchemer attacks use wireless chargers to inject voice commands, fry phones (BleepingComputer) 


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

AT&T experiences a major outage. The LockBit takedown continues. An updated Doppelgänger is spreading misinformation. A roundup of critical infrastructure initiatives. Toshiba and Orange make a quantum leap. An eyecare provider hack comes into focus. A phony iphone repair scheme leads to convictions. In our Learning Layer segment, Sam Meisenberg shares the latest learning science research. And we are shocked - shocked! - to discover that phone chargers can be used to attack our devices. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

On this month’s Learning Layer segment, host Sam Meisenberg of N2K discusses learning science research. Sam breaks down research about quizzes and their impact on learner motivation and long term retention. Want to know more? Sam suggests you check out The Value of Using Tests in Education as Tools for Learning—Not Just for Assessment.


Selected Reading

AT&T, Verizon and T-Mobile customers hit by widespread cellular outages in U.S. (NBC News)

US Offering $10M for LockBit Leaders as Law Enforcement Taunts Cybercriminals (SecurityWeek)

LockBit Group Prepped New Crypto-Locker Before Takedown (Gov Info Security)

Ukraine arrests father-son duo in Lockbit cybercrime bust (Reuters)

Russian Cyberwarfare campaign (ClearSky Cyber Security)

US Coast Guard issues cybersecurity directive for Chinese-made cranes after Biden's Executive Order (Industrial Cyber) 

US agencies release joint fact sheet to strengthen cybersecurity in water and wastewater systems (Industrial Cyber) 

E-ISAC 2023 report highlights cybersecurity triumphs and challenges in electricity sector (Industrial Cyber) 

Toshiba and Orange test quantum encryption on traditional network (Computer Weekly)

Hack at Services Firm Hits 2.4 Million Eye Doctor Patients (Gov Info Security)

Chinese Duo Found Guilty of $3m Apple Fraud Plot (Infosecurity Magazine)

VoltSchemer attacks use wireless chargers to inject voice commands, fry phones (BleepingComputer) 


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2024-02-21

Anchoring security for US ports.

30 min
View

President Biden to sign EO to bolster maritime port security. Apple announces post-quantum encryption for iMessage. Malwarebytes examines the i-Soon data leak. Law enforcement airs LockBit’s dirty laundry. Varonis highlights vulnerabilities affecting Salesforce platforms. An appeals court overturns a $1 billion piracy verdict. NSA’s Rob Joyce announces his retirement. Anne Neuberger chats with WIRED.  A leading staffing firm finds its data for sale on the dark web. In our sponsored Industry Voices segment, Navneet Singh, VP of Marketing Network Security at Palo Alto Networks, discusses the transition to the cloud and shares some examples from healthcare. Hackers and hobbyists push back on the proposed Flipper Zero ban. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

On our Industry Voices segment, Navneet Singh, VP of Marketing Network Security at Palo Alto Networks, discusses the transition to the cloud and shares some examples in healthcare.


Selected Reading

Biden to sign executive order to give Coast Guard added authority over maritime cyber threats (CyberScoop)

Apple Announces 'Groundbreaking' New Security Protocol for iMessage (MacRumors)

A first analysis of the i-Soon data leak (Malwarebytes)

Cops turn LockBit ransomware gang's countdown timers against them (The Register)

Security Vulnerabilities in Apex Code Could Leak Salesforce Data (Varonis)

Court blocks $1 billion copyright ruling that punished ISP for its users’ piracy (Ars Technica)

NSA cyber director to step down after 34 years of service (Nextgov/FCW)

Anne Neuberger, a Top White House Cyber Official, Is Staying Surprisingly Optimistic (WIRED)

Critical flaw found in deprecated VMware EAP. Uninstall it immediately (Security Affairs)

Hackers Claim Data Breach at Staffing Giant Robert Half, Sell Sensitive Data (HackRead)

Save Flipper (Save Flipper)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

President Biden to sign EO to bolster maritime port security. Apple announces post-quantum encryption for iMessage. Malwarebytes examines the i-Soon data leak. Law enforcement airs LockBit’s dirty laundry. Varonis highlights vulnerabilities affecting Salesforce platforms. An appeals court overturns a $1 billion piracy verdict. NSA’s Rob Joyce announces his retirement. Anne Neuberger chats with WIRED.  A leading staffing firm finds its data for sale on the dark web. In our sponsored Industry Voices segment, Navneet Singh, VP of Marketing Network Security at Palo Alto Networks, discusses the transition to the cloud and shares some examples from healthcare. Hackers and hobbyists push back on the proposed Flipper Zero ban. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

On our Industry Voices segment, Navneet Singh, VP of Marketing Network Security at Palo Alto Networks, discusses the transition to the cloud and shares some examples in healthcare.


Selected Reading

Biden to sign executive order to give Coast Guard added authority over maritime cyber threats (CyberScoop)

Apple Announces 'Groundbreaking' New Security Protocol for iMessage (MacRumors)

A first analysis of the i-Soon data leak (Malwarebytes)

Cops turn LockBit ransomware gang's countdown timers against them (The Register)

Security Vulnerabilities in Apex Code Could Leak Salesforce Data (Varonis)

Court blocks $1 billion copyright ruling that punished ISP for its users’ piracy (Ars Technica)

NSA cyber director to step down after 34 years of service (Nextgov/FCW)

Anne Neuberger, a Top White House Cyber Official, Is Staying Surprisingly Optimistic (WIRED)

Critical flaw found in deprecated VMware EAP. Uninstall it immediately (Security Affairs)

Hackers Claim Data Breach at Staffing Giant Robert Half, Sell Sensitive Data (HackRead)

Save Flipper (Save Flipper)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2024-02-20

The reign of digital terror ends.

24 min
View

Operation Cronos leaves LockBit operations on borrowed time. An alleged leak reveals internal operations from the Chinese Ministry of Public Security. An Israeli airline thwarts communications hijacking attempts. The alleged Raccoon Infostealer operator has been extradited to the US. ConnectWise patches critical vulnerabilities. Schneider Electric confirms a Cactus ransomware attack. Alleged Maryland money launderers face indictments. Russian hackers target media outlets in Ukraine. Our guest is Tomislav Pericin, Chief Software Architect at Reversing Labs , on the rise of software supply chain attacks. and Tinder hopes to reel in the catfish.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Guest is Tomislav Pericin, ReversingLabs Chief Software Architect, talking about the rise of software supply chain attacks. Learn more in their 2024 State of Software Supply Chain Security Report


Selected Reading

Police arrests LockBit ransomware members, release decryptor in global crackdown (BleepingComputer)

U.S. and U.K. Disrupt LockBit Ransomware Variant (US Justice Department)

Chinese Ministry Of Public Security Breach: Data On GitHub (The Cyber Express)

Massive “i-Soon” leak reveals Chinese firm's hacking tools, targets, including NATO (The Stack)

I-S00N Leaked Chinese foreign government infiltration intel on Github : r/cybersecurity (Reddit)

Israeli Aircraft Survive “Cyber-Hijacking” Attempts (Infosecurity Magazine)

Raccoon Infostealer operator extradited to the United States (Malwarebytes)

Critical ConnectWise ScreenConnect vulnerabilities fixed, patch ASAP! (Help Net Security)

Schneider Electric confirms data was stolen in Cactus ransomware attack (IT Pro)

Maryland Busts $9.5 Million #BEC Money Laundering Ring (CyberCrime & Doing Time)

Several Ukrainian media outlets attacked by Russian hackers (The Record)

Tinder Expands ID Checks Amid Rise in AI Scams, Dating Crimes (Bloomberg)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

Operation Cronos leaves LockBit operations on borrowed time. An alleged leak reveals internal operations from the Chinese Ministry of Public Security. An Israeli airline thwarts communications hijacking attempts. The alleged Raccoon Infostealer operator has been extradited to the US. ConnectWise patches critical vulnerabilities. Schneider Electric confirms a Cactus ransomware attack. Alleged Maryland money launderers face indictments. Russian hackers target media outlets in Ukraine. Our guest is Tomislav Pericin, Chief Software Architect at Reversing Labs , on the rise of software supply chain attacks. and Tinder hopes to reel in the catfish.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Guest is Tomislav Pericin, ReversingLabs Chief Software Architect, talking about the rise of software supply chain attacks. Learn more in their 2024 State of Software Supply Chain Security Report


Selected Reading

Police arrests LockBit ransomware members, release decryptor in global crackdown (BleepingComputer)

U.S. and U.K. Disrupt LockBit Ransomware Variant (US Justice Department)

Chinese Ministry Of Public Security Breach: Data On GitHub (The Cyber Express)

Massive “i-Soon” leak reveals Chinese firm's hacking tools, targets, including NATO (The Stack)

I-S00N Leaked Chinese foreign government infiltration intel on Github : r/cybersecurity (Reddit)

Israeli Aircraft Survive “Cyber-Hijacking” Attempts (Infosecurity Magazine)

Raccoon Infostealer operator extradited to the United States (Malwarebytes)

Critical ConnectWise ScreenConnect vulnerabilities fixed, patch ASAP! (Help Net Security)

Schneider Electric confirms data was stolen in Cactus ransomware attack (IT Pro)

Maryland Busts $9.5 Million #BEC Money Laundering Ring (CyberCrime & Doing Time)

Several Ukrainian media outlets attacked by Russian hackers (The Record)

Tinder Expands ID Checks Amid Rise in AI Scams, Dating Crimes (Bloomberg)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere

Kathy O’Donnell is the leader of Space Solutions Architecture for AWS Aerospace and Satellite. In this extended conversation, we dive into how AWS is supporting generative AI in the space domain. She walks us through some incredible case studies with AWS customers who are using generative AI and space technologies to improve life here on Earth.

Learn more about generative AI use cases for space at AWS re:Invent.

AWS in Orbit is a podcast collaboration between N2K Networks and AWS to offer listeners an in-depth look at the transformative intersection of cloud computing, space technologies, and generative AI. You can learn more about AWS in Orbit at space.n2k.com/aws.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our weekly intelligence roundup, Signals and Space, and you’ll never miss a beat. And be sure to follow T-Minus on LinkedIn and Instagram.

Selected Reading

AWS successfully runs AWS compute and machine learning services on an orbiting satellite in a first-of-its kind space experiment | AWS Public Sector Blog

AWS re:Invent 2022 - Accelerate Geospatial ML with Amazon SageMaker (AER204) 

AWS re:Invent 2023

Audience Survey

We want to hear from you! Please complete our 4 question survey. It’ll help us get better and deliver you the most mission-critical space intel every day.

Want to join us for an interview?

Please send your pitch to space-editor@n2k.com and include your name, affiliation, and topic proposal.

T-Minus is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

Kathy O’Donnell is the leader of Space Solutions Architecture for AWS Aerospace and Satellite. In this extended conversation, we dive into how AWS is supporting generative AI in the space domain. She walks us through some incredible case studies with AWS customers who are using generative AI and space technologies to improve life here on Earth.

Learn more about generative AI use cases for space at AWS re:Invent.

AWS in Orbit is a podcast collaboration between N2K Networks and AWS to offer listeners an in-depth look at the transformative intersection of cloud computing, space technologies, and generative AI. You can learn more about AWS in Orbit at space.n2k.com/aws.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our weekly intelligence roundup, Signals and Space, and you’ll never miss a beat. And be sure to follow T-Minus on LinkedIn and Instagram.

Selected Reading

AWS successfully runs AWS compute and machine learning services on an orbiting satellite in a first-of-its kind space experiment | AWS Public Sector Blog

AWS re:Invent 2022 - Accelerate Geospatial ML with Amazon SageMaker (AER204) 

AWS re:Invent 2023

Audience Survey

We want to hear from you! Please complete our 4 question survey. It’ll help us get better and deliver you the most mission-critical space intel every day.

Want to join us for an interview?

Please send your pitch to space-editor@n2k.com and include your name, affiliation, and topic proposal.

T-Minus is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere

In this episode of CyberWire-X, N2K’s CSO, Chief Analyst, and Senior Fellow, Rick Howard, is joined by Tim Miller, Technical Marketing Engineer for Panoptica, Cisco's Cloud Application Security solution, (Panoptica is the result of Cisco's incubation engine (Outshift) for new products and markets), and Kevin Ford, Esri’s CISO. They discuss the complexity reduction need that Cloud-Native Application Protection Platforms (CNAPPs) provide. Outshift by Cisco is our CyberWire-X episode sponsor.

To learn more about Cloud-Native Application Protection Platforms, check out Panoptica’s website at https://panoptica.app and consider attending the Cisco Live EMEA in Amsterdam, February 5-8, 2024.

More description

In this episode of CyberWire-X, N2K’s CSO, Chief Analyst, and Senior Fellow, Rick Howard, is joined by Tim Miller, Technical Marketing Engineer for Panoptica, Cisco's Cloud Application Security solution, (Panoptica is the result of Cisco's incubation engine (Outshift) for new products and markets), and Kevin Ford, Esri’s CISO. They discuss the complexity reduction need that Cloud-Native Application Protection Platforms (CNAPPs) provide. Outshift by Cisco is our CyberWire-X episode sponsor.

To learn more about Cloud-Native Application Protection Platforms, check out Panoptica’s website at https://panoptica.app and consider attending the Cisco Live EMEA in Amsterdam, February 5-8, 2024.

Extract Knowledge
Listen elsewhere

Privacy and data security lawyer, Dominique Shelton Leipzig shares that she has always wanted to be a lawyer, ever since she was a little girl. She talks about what her role is with clients in protecting and managing their data, sometimes adhering to up to 134 different data protection laws for global companies. Learn that not a lot has changed for an African-American woman partner at an Amlaw 100 firm as far as diversity during Dominique's career, and how Dominique suggests young lawyers should address those odds. Our thanks to Dominque for sharing her story with us. 

More description

Privacy and data security lawyer, Dominique Shelton Leipzig shares that she has always wanted to be a lawyer, ever since she was a little girl. She talks about what her role is with clients in protecting and managing their data, sometimes adhering to up to 134 different data protection laws for global companies. Learn that not a lot has changed for an African-American woman partner at an Amlaw 100 firm as far as diversity during Dominique's career, and how Dominique suggests young lawyers should address those odds. Our thanks to Dominque for sharing her story with us. 

Extract Knowledge
Listen elsewhere

Ori David from Akamai is sharing their research "Frog4Shell — FritzFrog Botnet Adds One-Days to Its Arsenal." FritzFrog takes advantage of the fact that only internet facing applications were prioritized for Log4Shell patching and targets internal hosts, meaning that a breach of any asset in the network by FritzFrog can expose unpatched internal assets to exploitation. 

The research states "FritzFrog has traditionally hopped around by using SSH brute force, and has successfully compromised thousands of targets over the years as a result." Over the years Akamai has seen more than 20,000 FritzFrog attacks, and 1,500+ victims.

The research can be found here:

More description

Ori David from Akamai is sharing their research "Frog4Shell — FritzFrog Botnet Adds One-Days to Its Arsenal." FritzFrog takes advantage of the fact that only internet facing applications were prioritized for Log4Shell patching and targets internal hosts, meaning that a breach of any asset in the network by FritzFrog can expose unpatched internal assets to exploitation. 

The research states "FritzFrog has traditionally hopped around by using SSH brute force, and has successfully compromised thousands of targets over the years as a result." Over the years Akamai has seen more than 20,000 FritzFrog attacks, and 1,500+ victims.

The research can be found here:

Extract Knowledge
Listen elsewhere
Published 2024-02-16

FBI initiates router revolution.

29 min
View

The FBI kicks Moobot out of small business routers. Sensitive data has been stolen from a state government network. AMC proposes a multi-million-dollar settlement after improperly sharing subscriber’s viewing habits. The U.S. targets an Iranian military ship in the Red Sea with a cyberattack. Lawmakers propose transparency in the use of algorithms in criminal trials. CERT-EU highlights a spear phishing spike. An infamous Zeus and IcedID operator pleads guilty. Our guests are Dr. Josh Brunty, Head Coach, and Brad Wolfenden, Program Director, of US Cyber Games join us to share the details of how their 2024 season is shaping up. And AI comes to video.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Dr. Josh Brunty, Head Coach, and Brad Wolfenden, Program Director, of US Cyber Games join us to share the details of how the 2024 season is shaping up.


Selected Reading

US disrupts Russian hacking campaign that infiltrated home, small business routers: DOJ (ABC News) 

U.S. State Government Network Hacked Via Former Employee Account (Cyber Security News)

CISA Urges Patching of Cisco ASA Flaw Exploited in Ransomware Attacks (SecurityWeek)

AMC to pay $8M for allegedly violating 1988 law with use of Meta Pixel (Ars Technica)

U.S. conducted cyberattack on suspected Iranian spy ship (NBC News)

New bill would let defendants inspect algorithms used against them in court (The Verge)

Hackers Exploit EU Agenda in Spear Phishing Campaigns (Infosecurity Magazine)

Ukrainian Hacker Pleads Guilty for Leading Zeus & IcedID Malware Attacks (GBHackers on security)

OpenAI introduces Sora, its text-to-video AI model  (The Verge) 


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

The FBI kicks Moobot out of small business routers. Sensitive data has been stolen from a state government network. AMC proposes a multi-million-dollar settlement after improperly sharing subscriber’s viewing habits. The U.S. targets an Iranian military ship in the Red Sea with a cyberattack. Lawmakers propose transparency in the use of algorithms in criminal trials. CERT-EU highlights a spear phishing spike. An infamous Zeus and IcedID operator pleads guilty. Our guests are Dr. Josh Brunty, Head Coach, and Brad Wolfenden, Program Director, of US Cyber Games join us to share the details of how their 2024 season is shaping up. And AI comes to video.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Dr. Josh Brunty, Head Coach, and Brad Wolfenden, Program Director, of US Cyber Games join us to share the details of how the 2024 season is shaping up.


Selected Reading

US disrupts Russian hacking campaign that infiltrated home, small business routers: DOJ (ABC News) 

U.S. State Government Network Hacked Via Former Employee Account (Cyber Security News)

CISA Urges Patching of Cisco ASA Flaw Exploited in Ransomware Attacks (SecurityWeek)

AMC to pay $8M for allegedly violating 1988 law with use of Meta Pixel (Ars Technica)

U.S. conducted cyberattack on suspected Iranian spy ship (NBC News)

New bill would let defendants inspect algorithms used against them in court (The Verge)

Hackers Exploit EU Agenda in Spear Phishing Campaigns (Infosecurity Magazine)

Ukrainian Hacker Pleads Guilty for Leading Zeus & IcedID Malware Attacks (GBHackers on security)

OpenAI introduces Sora, its text-to-video AI model  (The Verge) 


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2024-02-15

An AI arms race.

24 min
View

Microsoft highlights adversaries experiments with AI LLMs. A misconfiguration exposes a decades worth of emails. SentinelOne describes Kryptina ransomware as a service. The European Court of Human Rights rules against backdoors. Senator Wyden calls out a location data broker. GoldFactory steals facial scans to bypass bank security. The Glow fertility app exposes the data of twenty five million users. Qakbot returns. Our Guest Rob Boyce from Accenture talks about tailored extortion. And hacking the airport taxi line leads to prison. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Guest Rob Boyce from Accenture talks about tailored extortion as actors continue to shift to pure data extortion, with old and new tactics.


Selected Reading

State-backed hackers are experimenting with OpenAI models (Cyberscoop)

Staying ahead of threat actors in the age of AI (Microsoft)

U.S. Internet Leaked Years of Internal, Customer Emails (Krebs on security)

Kryptina RaaS | From Underground Commodity to Open Source Threat  (SentinelOne)

Backdoors that let cops decrypt messages violate human rights, EU court says (Arstechnica)

A company tracked visits to 600 Planned Parenthood locations for anti-abortion ads, senator says (POLITICO)

Cybercriminals are stealing Face ID scans to break into mobile banking accounts (theregister)

Fertility tracker Glow fixes bug that exposed users’ personal data (TechCrunch)

New Qbot malware variant uses fake Adobe installer popup for evasion (bleepingcomputer)

Duo headed to prison for charging cabbies to skip JFK Airport line with Russian hackers' aid (nydailynews)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

Microsoft highlights adversaries experiments with AI LLMs. A misconfiguration exposes a decades worth of emails. SentinelOne describes Kryptina ransomware as a service. The European Court of Human Rights rules against backdoors. Senator Wyden calls out a location data broker. GoldFactory steals facial scans to bypass bank security. The Glow fertility app exposes the data of twenty five million users. Qakbot returns. Our Guest Rob Boyce from Accenture talks about tailored extortion. And hacking the airport taxi line leads to prison. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Guest Rob Boyce from Accenture talks about tailored extortion as actors continue to shift to pure data extortion, with old and new tactics.


Selected Reading

State-backed hackers are experimenting with OpenAI models (Cyberscoop)

Staying ahead of threat actors in the age of AI (Microsoft)

U.S. Internet Leaked Years of Internal, Customer Emails (Krebs on security)

Kryptina RaaS | From Underground Commodity to Open Source Threat  (SentinelOne)

Backdoors that let cops decrypt messages violate human rights, EU court says (Arstechnica)

A company tracked visits to 600 Planned Parenthood locations for anti-abortion ads, senator says (POLITICO)

Cybercriminals are stealing Face ID scans to break into mobile banking accounts (theregister)

Fertility tracker Glow fixes bug that exposed users’ personal data (TechCrunch)

New Qbot malware variant uses fake Adobe installer popup for evasion (bleepingcomputer)

Duo headed to prison for charging cabbies to skip JFK Airport line with Russian hackers' aid (nydailynews)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere

It’s always DNS, but that may just be FUD. The DoD notifies victims of a cloud email server leak. New Jersey cops sue online data brokers. Crooks use WiFi jammers to thwart security systems. A copyright case against OpenAI is partially dismissed. Patch Tuesday includes two actively exploited zero days. CharmingCypress gathers political intelligence. Ann Johnson from Microsoft Security’s Afternoon Cyber Tea podcast talks with Frank Cilluffo, Director for Cyber and Critical Infrastructure Security at the McCrary Institute of Auburn University, about cyber and critical infrastructure. And beware Cupid’s misleading arrow.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Ann Johnson from Microsoft Security’s Afternoon Cyber Tea podcast talks with Frank Cilluffo, Director for Cyber and Critical Infrastructure Security at the McCrary Institute of Auburn University, about cyber and critical infrastructure. Check out the episode with the full conversation between Ann and Frank here


Selected Reading

KeyTrap DNS Attack Could Disable Large Parts of Internet: Researchers (SecurityWeek)

US military notifies 20,000 of data breach after cloud email leak (TechCrunch)

New Jersey law enforcement officers sue 118 data brokers for not removing personal info (The Record)

Minnesota burglars are using Wi-Fi jammers to disable home security systems (TechSpot)

Sarah Silverman’s lawsuit against OpenAI partially dismissed (The Verge)

Microsoft February 2024 Patch Tuesday fixes 2 zero-days, 73 flaws (BleepingComputer)

DarkMe Malware Targets Traders Using Microsoft SmartScreen Zero-Day Vulnerability (The Hacker News)

CharmingCypress Use Poisoned VPN Apps to Install Backdoor (Cyber Security News)

Beyond the Hype: Questioning FUD in Cybersecurity Marketing  (SecurityWeek)

Valentine's Day Scams Woo the Lonely-Hearted (Security Boulevard) 


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

It’s always DNS, but that may just be FUD. The DoD notifies victims of a cloud email server leak. New Jersey cops sue online data brokers. Crooks use WiFi jammers to thwart security systems. A copyright case against OpenAI is partially dismissed. Patch Tuesday includes two actively exploited zero days. CharmingCypress gathers political intelligence. Ann Johnson from Microsoft Security’s Afternoon Cyber Tea podcast talks with Frank Cilluffo, Director for Cyber and Critical Infrastructure Security at the McCrary Institute of Auburn University, about cyber and critical infrastructure. And beware Cupid’s misleading arrow.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Ann Johnson from Microsoft Security’s Afternoon Cyber Tea podcast talks with Frank Cilluffo, Director for Cyber and Critical Infrastructure Security at the McCrary Institute of Auburn University, about cyber and critical infrastructure. Check out the episode with the full conversation between Ann and Frank here


Selected Reading

KeyTrap DNS Attack Could Disable Large Parts of Internet: Researchers (SecurityWeek)

US military notifies 20,000 of data breach after cloud email leak (TechCrunch)

New Jersey law enforcement officers sue 118 data brokers for not removing personal info (The Record)

Minnesota burglars are using Wi-Fi jammers to disable home security systems (TechSpot)

Sarah Silverman’s lawsuit against OpenAI partially dismissed (The Verge)

Microsoft February 2024 Patch Tuesday fixes 2 zero-days, 73 flaws (BleepingComputer)

DarkMe Malware Targets Traders Using Microsoft SmartScreen Zero-Day Vulnerability (The Hacker News)

CharmingCypress Use Poisoned VPN Apps to Install Backdoor (Cyber Security News)

Beyond the Hype: Questioning FUD in Cybersecurity Marketing  (SecurityWeek)

Valentine's Day Scams Woo the Lonely-Hearted (Security Boulevard) 


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2024-02-13

Phishing threats unleashed.

30 min
View

Attackers lock up Azure accounts with MFA. Bank of America alerts customers to a third party data breach. Malicious cyber activity targets elections worldwide. CISA highlights a vulnerability in Roundcube Webmail. Lawmakers introduce a bipartisan bill to enhance healthcare cybersecurity. Siemens and Schneider Electric address multiple industrial vulnerabilities. Perception in tech gender parity still has a ways to go. Dave Bittner speaks with Guests Andrew Scott, Associate Director of China Operations at CISA, and Brett Leatherman, Section Chief for Cyber at the FBI, about Chinese threat actor Volt Typhoon. And the scourge of online obituary spam. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Guests Andrew Scott, Associate Director of China Operations at CISA, and Brett Leatherman, Section Chief at FBI, discussing  PRC/Volt Typhoon advisory and living off the land guidance. Read the press release on “U.S. and International Partners Publish Cybersecurity Advisory on People’s Republic of China State-Sponsored Hacking of U.S. Critical Infrastructure.”


Selected Reading

Ongoing campaign compromises senior execs’ Azure accounts, locks them using MFA (Ars Technica) 

Bank of America warns customers of data breach after vendor hack (BleepingComputer)

Global Malicious Activity Targeting Elections is Skyrocketing (Security Affairs)

CISA Warns Of Active Attacks on Roundcube Webmail XSS Vulnerability (CISA)

Bipartisan Senate Bill Requires HHS to Bolster Cyber Efforts (Gov Info Security)

ICS Patch Tuesday: Siemens Addresses 270 Vulnerabilities (SecurityWeek) 

Four in five men in tech say women are treated equally, as women criticise ‘invisible challenges’ (Euronews)

The rise of obituary spam (The Verge) 


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

Attackers lock up Azure accounts with MFA. Bank of America alerts customers to a third party data breach. Malicious cyber activity targets elections worldwide. CISA highlights a vulnerability in Roundcube Webmail. Lawmakers introduce a bipartisan bill to enhance healthcare cybersecurity. Siemens and Schneider Electric address multiple industrial vulnerabilities. Perception in tech gender parity still has a ways to go. Dave Bittner speaks with Guests Andrew Scott, Associate Director of China Operations at CISA, and Brett Leatherman, Section Chief for Cyber at the FBI, about Chinese threat actor Volt Typhoon. And the scourge of online obituary spam. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Guests Andrew Scott, Associate Director of China Operations at CISA, and Brett Leatherman, Section Chief at FBI, discussing  PRC/Volt Typhoon advisory and living off the land guidance. Read the press release on “U.S. and International Partners Publish Cybersecurity Advisory on People’s Republic of China State-Sponsored Hacking of U.S. Critical Infrastructure.”


Selected Reading

Ongoing campaign compromises senior execs’ Azure accounts, locks them using MFA (Ars Technica) 

Bank of America warns customers of data breach after vendor hack (BleepingComputer)

Global Malicious Activity Targeting Elections is Skyrocketing (Security Affairs)

CISA Warns Of Active Attacks on Roundcube Webmail XSS Vulnerability (CISA)

Bipartisan Senate Bill Requires HHS to Bolster Cyber Efforts (Gov Info Security)

ICS Patch Tuesday: Siemens Addresses 270 Vulnerabilities (SecurityWeek) 

Four in five men in tech say women are treated equally, as women criticise ‘invisible challenges’ (Euronews)

The rise of obituary spam (The Verge) 


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2024-02-12

DOJ strikes justice.

30 min
View

The DOJ shuts down the Warzone rat. Ransomware hits over twenty Romanian hospitals, and Rysida gets a decryptor. Canada may ban the Flipper Zero. Chinese espionage claims against the US are light on facts. Australia looks to criminalize doxxing. Federal IT leaders seek better coordination with CISA and the JCDC. Wired looks at the effect of cyberattacks on inequality. Our guest is Manny Felix, Founder and CEO of US Cyber Initiative, sharing their work in unlocking cyber career opportunities for young people. And this thumb drive will self-destruct in five seconds.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Manuel "Manny" Felix, Founder and CEO of US Cyber Initiative, sharing their work in unlocking career opportunities for young people who are interested in cyber and emergent technology. US Cyber Initiative grew out of AZ Cyber. Learn more about AZ Cyber here


Selected Reading

DOJ shuts down ‘Warzone’ malware vendor and charges two in connection (The Record)

Ransomware attack forces 18 Romanian hospitals to go offline (BleepingComputer)

Decryptor for Rhysida ransomware is available (Help Net Security)

Canada moves to ban the Flipper Zero amid rising auto theft concerns (TECHSPOT)

China’s Cyber Revenge | Why the PRC Fails to Back Its Claims of Western Espionage (SentinelOne)

‘Doxxing’ laws to be brought forward after Jewish WhatsApp leak  (The Sydney Morning Herald)

Exclusive: Duke Energy to remove Chinese battery giant CATL from Marine Corps Base (Reuters)

Federal IT officials call on CISA for tougher standards, more coordination (FedScoop)

Priorities of the Joint Cyber Defense Collaborative for 2024 (CISA)

The Hidden Injustice of Cyberattacks (WIRED)

Ovrdrive USB stick with data-hiding and overheating self-destruct features nears crowdfunding goal (TechSpot)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

The DOJ shuts down the Warzone rat. Ransomware hits over twenty Romanian hospitals, and Rysida gets a decryptor. Canada may ban the Flipper Zero. Chinese espionage claims against the US are light on facts. Australia looks to criminalize doxxing. Federal IT leaders seek better coordination with CISA and the JCDC. Wired looks at the effect of cyberattacks on inequality. Our guest is Manny Felix, Founder and CEO of US Cyber Initiative, sharing their work in unlocking cyber career opportunities for young people. And this thumb drive will self-destruct in five seconds.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Manuel "Manny" Felix, Founder and CEO of US Cyber Initiative, sharing their work in unlocking career opportunities for young people who are interested in cyber and emergent technology. US Cyber Initiative grew out of AZ Cyber. Learn more about AZ Cyber here


Selected Reading

DOJ shuts down ‘Warzone’ malware vendor and charges two in connection (The Record)

Ransomware attack forces 18 Romanian hospitals to go offline (BleepingComputer)

Decryptor for Rhysida ransomware is available (Help Net Security)

Canada moves to ban the Flipper Zero amid rising auto theft concerns (TECHSPOT)

China’s Cyber Revenge | Why the PRC Fails to Back Its Claims of Western Espionage (SentinelOne)

‘Doxxing’ laws to be brought forward after Jewish WhatsApp leak  (The Sydney Morning Herald)

Exclusive: Duke Energy to remove Chinese battery giant CATL from Marine Corps Base (Reuters)

Federal IT officials call on CISA for tougher standards, more coordination (FedScoop)

Priorities of the Joint Cyber Defense Collaborative for 2024 (CISA)

The Hidden Injustice of Cyberattacks (WIRED)

Ovrdrive USB stick with data-hiding and overheating self-destruct features nears crowdfunding goal (TechSpot)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere

Computer security writer, podcaster and public speaker Graham Cluley describes learning to program on his own from magazines, creating text adventure games for donations, and his journey from programming to presenting and writing with a bit of tap dancing on the side. Along the way, Graham collaborated with others and learned to communicate so that all could understand, not just techies. Our thanks to Graham for sharing his story with us. 

More description

Computer security writer, podcaster and public speaker Graham Cluley describes learning to program on his own from magazines, creating text adventure games for donations, and his journey from programming to presenting and writing with a bit of tap dancing on the side. Along the way, Graham collaborated with others and learned to communicate so that all could understand, not just techies. Our thanks to Graham for sharing his story with us. 

Extract Knowledge
Listen elsewhere
Published 2024-02-10

Ransomware is coming. [Research Saturday]

28 min
View

Jon DiMaggio, Chief Security Strategist for Analyst1, is discussing his research on "Ransomware Diaries Volume 4: Ransomed and Exposed - The Story of RansomedVC." While there is evidence to support that RansomedVC runs cybercrime operations, Jon questions the claims it made regarding the authenticity of the data it stole and the methods it used to extort victims.

The research states "I uncovered sensitive information about the group's leader, Ransomed Support (also known as Impotent), relating to secrets from his past." In this episode John shares his 6 key findings after spending months engaging with the lead criminal who runs RansomedVC.

The research can be found here:

More description

Jon DiMaggio, Chief Security Strategist for Analyst1, is discussing his research on "Ransomware Diaries Volume 4: Ransomed and Exposed - The Story of RansomedVC." While there is evidence to support that RansomedVC runs cybercrime operations, Jon questions the claims it made regarding the authenticity of the data it stole and the methods it used to extort victims.

The research states "I uncovered sensitive information about the group's leader, Ransomed Support (also known as Impotent), relating to secrets from his past." In this episode John shares his 6 key findings after spending months engaging with the lead criminal who runs RansomedVC.

The research can be found here:

Extract Knowledge
Listen elsewhere
Published 2024-02-09

Imitation game: LastPass vs LassPass.

29 min
View

A LastPass imitator sneaks its way past Apple’s app store review. Bitdefender identifies a new macOS backdoor. The Air Force and Space Force collaborate for stronger cyber defense. CISA offers an election security advisory program. The FCC bans AI robocalls. The Feds put a bounty on the Hive ransomware group. Senators introduce a bipartisan drone security act. Cisco Talos IDs a new cyber espionage campaign. Fighting the good fight against software bloat. On our Solution Spotlight, N2K President Simone Petrella talks with Amy Kardel, Senior Vice President for Strategic Workforce Relationships at CompTIA about the cyber talent gap. And sports fans check your passwords. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

On our Solution Spotlight, N2K President Simone Petrella talks with Amy Kardel, Senior Vice President for Strategic Workforce Relationships at CompTIA about their perspectives and initiatives in response to the cyber talent gap.


Selected Reading

Fake LastPass App Sneaks Past Apple's Review Team (MacRumors)

Warning: Fraudulent App Impersonating LastPass Currently Available in Apple App Store (LastPass)

New Rust-Based macOS Backdoor Steals Files, Linked to Ransomware Groups (HACKREAD)

New Department of Air Force partnership brings cyber, space and information units closer (DefenseScoop)

Federal Cybersecurity Agency Launches Program to Boost Support for State, Local Election Offices (SecurityWeek)

FCC votes to outlaw scam robocalls that use AI-generated voices (CNN Business)

US offers $10 million for tips on Hive ransomware leadership (Bleeping Computer)

New legislation would give NIST drone cybersecurity responsibilities (FedScoop) 

New Zardoor backdoor used in long-term cyber espionage operation targeting an Islamic organization (Talos Intelligence)

Why Bloat Is Still Software’s Biggest Vulnerability (IEEE Spectrum)

Super Bowl of Passwords: Chiefs vs. 49ers in the Battle of Cybersecurity (Security Boulevard)

Taylor Swift's Influence on Cybersecurity (Enzoic)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

A LastPass imitator sneaks its way past Apple’s app store review. Bitdefender identifies a new macOS backdoor. The Air Force and Space Force collaborate for stronger cyber defense. CISA offers an election security advisory program. The FCC bans AI robocalls. The Feds put a bounty on the Hive ransomware group. Senators introduce a bipartisan drone security act. Cisco Talos IDs a new cyber espionage campaign. Fighting the good fight against software bloat. On our Solution Spotlight, N2K President Simone Petrella talks with Amy Kardel, Senior Vice President for Strategic Workforce Relationships at CompTIA about the cyber talent gap. And sports fans check your passwords. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

On our Solution Spotlight, N2K President Simone Petrella talks with Amy Kardel, Senior Vice President for Strategic Workforce Relationships at CompTIA about their perspectives and initiatives in response to the cyber talent gap.


Selected Reading

Fake LastPass App Sneaks Past Apple's Review Team (MacRumors)

Warning: Fraudulent App Impersonating LastPass Currently Available in Apple App Store (LastPass)

New Rust-Based macOS Backdoor Steals Files, Linked to Ransomware Groups (HACKREAD)

New Department of Air Force partnership brings cyber, space and information units closer (DefenseScoop)

Federal Cybersecurity Agency Launches Program to Boost Support for State, Local Election Offices (SecurityWeek)

FCC votes to outlaw scam robocalls that use AI-generated voices (CNN Business)

US offers $10 million for tips on Hive ransomware leadership (Bleeping Computer)

New legislation would give NIST drone cybersecurity responsibilities (FedScoop) 

New Zardoor backdoor used in long-term cyber espionage operation targeting an Islamic organization (Talos Intelligence)

Why Bloat Is Still Software’s Biggest Vulnerability (IEEE Spectrum)

Super Bowl of Passwords: Chiefs vs. 49ers in the Battle of Cybersecurity (Security Boulevard)

Taylor Swift's Influence on Cybersecurity (Enzoic)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere

A joint advisory warns of Volt Typhoon’s extended network infiltration. Check your Cisco devices for patches. Fortinet clarifies its latest vulnerabilities. Internet outages plague Pakistan on election day. Kaspersky describes the new Coyote banking trojan. Cyber insurance is projected to reach new heights. The White House appoints a leader for the AI Safety Institute, and sees pushback on proposed reporting regulations. Can we hold AI liable for its foreseeable harms? Joe Carrigan joins us with insights on the Mother of All Data Breaches. The potential of Passkeys versus the comfort of passwords.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Podcast partner and Hacking Humans co-host Joe Carrigan stops by today to discuss the mother of all data breaches.


Selected Reading

Chinese hackers hid in US infrastructure network for 5 years (BleepingComputer) 

Akira, LockBit actively searching for vulnerable Cisco ASA devices (Help Net Security)

Cisco fixes critical Expressway Series CSRF vulnerabilities (SecurityAffairs)

Fortinet warns of new FortiSIEM RCE bugs in confusing disclosure (BleepingComputer) 

Pakistani telcos suffer widespread Internet blackouts on election day (DCD)

Coyote: A multi-stage banking Trojan abusing the Squirrel installer (Securelist)

Cyber insurance market growing dramatically, Triple-I Finds (AI-TechPark)

Biden Administration Names a Director of the New AI Safety Institute (SecurityWeek)

No one's happy with latest US cyber incident reporting plan (The Register)

DHS Is Recruiting Techies for the AI Corps (BankInfoSecurity)

Can the courts save us from dangerous AI? (Vox)

I Stopped Using Passwords. It's Great—and a Total Mess (WIRED)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

A joint advisory warns of Volt Typhoon’s extended network infiltration. Check your Cisco devices for patches. Fortinet clarifies its latest vulnerabilities. Internet outages plague Pakistan on election day. Kaspersky describes the new Coyote banking trojan. Cyber insurance is projected to reach new heights. The White House appoints a leader for the AI Safety Institute, and sees pushback on proposed reporting regulations. Can we hold AI liable for its foreseeable harms? Joe Carrigan joins us with insights on the Mother of All Data Breaches. The potential of Passkeys versus the comfort of passwords.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Podcast partner and Hacking Humans co-host Joe Carrigan stops by today to discuss the mother of all data breaches.


Selected Reading

Chinese hackers hid in US infrastructure network for 5 years (BleepingComputer) 

Akira, LockBit actively searching for vulnerable Cisco ASA devices (Help Net Security)

Cisco fixes critical Expressway Series CSRF vulnerabilities (SecurityAffairs)

Fortinet warns of new FortiSIEM RCE bugs in confusing disclosure (BleepingComputer) 

Pakistani telcos suffer widespread Internet blackouts on election day (DCD)

Coyote: A multi-stage banking Trojan abusing the Squirrel installer (Securelist)

Cyber insurance market growing dramatically, Triple-I Finds (AI-TechPark)

Biden Administration Names a Director of the New AI Safety Institute (SecurityWeek)

No one's happy with latest US cyber incident reporting plan (The Register)

DHS Is Recruiting Techies for the AI Corps (BankInfoSecurity)

Can the courts save us from dangerous AI? (Vox)

I Stopped Using Passwords. It's Great—and a Total Mess (WIRED)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2024-02-07

Taking a bite out of Apple.

31 min
View

A security researcher has been charged in an alleged multi-million dollar theft scheme targeting Apple. A House committee hearing explores OT security. Fortinet withdraws accidental CVEs. 2023 saw record highs in ransomware payments. A youtuber finds a cheap and easy bypass for Bitlocker encryption. Political pressure proves challenging for the JCDC. New Hampshire tracks down those fake Biden robocalls. European security agencies bolster warnings about Ivanti devices. HHS fines a New York medical center millions over an identity theft ring. On our sponsored Industry Voices segment, Navneet Singh, Vice President of Marketing Network Security at Palo Alto Networks, shares some practical examples of healthcare organizations transitioning to the cloud. Giving that toothbrush story the brushoff.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

On our Industry Voices segment, Navneet Singh, Vice President of Marketing Network Security at Palo Alto Networks, discusses the transition to the cloud and shares some practical examples in healthcare.


Selected Reading

A Security Researcher Allegedly Scammed Apple (404 Media)

US House Homeland Security subcommittee addresses OT threats, CISA's role in securing OT - Industrial Cyber (Industrial Cyber)

Operational Technology disruptions: An eye on the water sector. Robert M. Lee’s opening statement to before the U.S. Congressional Subcommittee on Cybersecurity and Infrastructure Protection. (Control Loop podcast)

Securing Operational Technology: A Deep Dive into the Water Sector (Homeland Security Events YouTube)

Fortinet Patches Critical Vulnerabilities in FortiSIEM (SecurityWeek)

Fortinet snafu: Critical FortiSIEM CVEs are duplicates, issued in error (Bleeping Computer)

Ransomware hackers raked in $1 billion last year from victims (NBC News)

BitLocker encryption broken in 43 seconds with sub-$10 Raspberry Pi Pico — key can be sniffed when using an external TPM (Tom’s Hardware)

The far right is scaring away Washington's private hacker army (POLITICO)

N.H. attorney general says he found source of fake Biden robocalls (NBC News)

European security agencies publish joint statement on Ivanti Connect Secure, Policy Secure vulnerabilities (Industrial Cyber)

Medical Center Fined $4.75M in Insider ID Theft Incident (GovInfoSecurity)

Surprising 3 Million Hacked Toothbrushes Story Goes Viral—Is It True? (Forbes)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

A security researcher has been charged in an alleged multi-million dollar theft scheme targeting Apple. A House committee hearing explores OT security. Fortinet withdraws accidental CVEs. 2023 saw record highs in ransomware payments. A youtuber finds a cheap and easy bypass for Bitlocker encryption. Political pressure proves challenging for the JCDC. New Hampshire tracks down those fake Biden robocalls. European security agencies bolster warnings about Ivanti devices. HHS fines a New York medical center millions over an identity theft ring. On our sponsored Industry Voices segment, Navneet Singh, Vice President of Marketing Network Security at Palo Alto Networks, shares some practical examples of healthcare organizations transitioning to the cloud. Giving that toothbrush story the brushoff.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

On our Industry Voices segment, Navneet Singh, Vice President of Marketing Network Security at Palo Alto Networks, discusses the transition to the cloud and shares some practical examples in healthcare.


Selected Reading

A Security Researcher Allegedly Scammed Apple (404 Media)

US House Homeland Security subcommittee addresses OT threats, CISA's role in securing OT - Industrial Cyber (Industrial Cyber)

Operational Technology disruptions: An eye on the water sector. Robert M. Lee’s opening statement to before the U.S. Congressional Subcommittee on Cybersecurity and Infrastructure Protection. (Control Loop podcast)

Securing Operational Technology: A Deep Dive into the Water Sector (Homeland Security Events YouTube)

Fortinet Patches Critical Vulnerabilities in FortiSIEM (SecurityWeek)

Fortinet snafu: Critical FortiSIEM CVEs are duplicates, issued in error (Bleeping Computer)

Ransomware hackers raked in $1 billion last year from victims (NBC News)

BitLocker encryption broken in 43 seconds with sub-$10 Raspberry Pi Pico — key can be sniffed when using an external TPM (Tom’s Hardware)

The far right is scaring away Washington's private hacker army (POLITICO)

N.H. attorney general says he found source of fake Biden robocalls (NBC News)

European security agencies publish joint statement on Ivanti Connect Secure, Policy Secure vulnerabilities (Industrial Cyber)

Medical Center Fined $4.75M in Insider ID Theft Incident (GovInfoSecurity)

Surprising 3 Million Hacked Toothbrushes Story Goes Viral—Is It True? (Forbes)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2024-02-06

Cracking down on spyware.

27 min
View

The global community confronts spyware. Canon patches critical vulnerabilities in printers. Barracuda recommends mitigations for Web Application Firewall issues. Group-IB warns of ResumeLooters. Millions are at risk after a data breach in France. Research from the UK reveals contradictory approaches to cybersecurity. Meta’s Oversight Board recommends updates to Facebook’s Manipulated Media policy. We’ve got a special segment from the Threat Vector podcast examining Ivanti's Connect Secure and Policy Secure products. And it’s time to brush up on IOT security. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

In a special segment from Palo Alto Networks’ Threat Vector podcast, host David Moulton, Director of Thought Leadership at Unit 42, along with guests Sam Rubin, VP, Global Head of Operations, and Ingrid Parker, Senior Manager of the Intel Response Unit, dives deep into the critical vulnerabilities found in Ivanti's Connect Secure and Policy Secure products. You can check out the full conversation here


Selected Reading

US to restrict visas for those who misuse commercial spyware (Reuters)

Britain and France assemble diplomats for international agreement on spyware (The Record)

Israeli government absent from London spyware conference and pledge (The Record)

Government hackers targeted iPhones owners with zero-days, Google says (TechCrunch)

Google agrees to pay $350 million settlement in security lapse case (Washington Post)

Canon Patches 7 Critical Vulnerabilities in Small Office Printers  (SecurityWeek)

Barracuda Disclosed Critical Vulnerabilities in WAF, Affecting File Upload and JSON Protection (SOCRadar)

ResumeLooters target job search sites in extensive data heist (Help Net Security)

Millions at risk of fraud after massive health data hack in France (The Connexion)

Fragmented cybersecurity vendor landscape is exacerbating risks and compounding skills shortages, SenseOn research reveals (IT Security Guru)

Meta’s Oversight Board Urges a Policy Change After a Fake Biden Video (InfoSecurity Magazine)

Toothbrushes are a cybersecurity risk, too: millions participate in DDoS attacks (Cybernews)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

The global community confronts spyware. Canon patches critical vulnerabilities in printers. Barracuda recommends mitigations for Web Application Firewall issues. Group-IB warns of ResumeLooters. Millions are at risk after a data breach in France. Research from the UK reveals contradictory approaches to cybersecurity. Meta’s Oversight Board recommends updates to Facebook’s Manipulated Media policy. We’ve got a special segment from the Threat Vector podcast examining Ivanti's Connect Secure and Policy Secure products. And it’s time to brush up on IOT security. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

In a special segment from Palo Alto Networks’ Threat Vector podcast, host David Moulton, Director of Thought Leadership at Unit 42, along with guests Sam Rubin, VP, Global Head of Operations, and Ingrid Parker, Senior Manager of the Intel Response Unit, dives deep into the critical vulnerabilities found in Ivanti's Connect Secure and Policy Secure products. You can check out the full conversation here


Selected Reading

US to restrict visas for those who misuse commercial spyware (Reuters)

Britain and France assemble diplomats for international agreement on spyware (The Record)

Israeli government absent from London spyware conference and pledge (The Record)

Government hackers targeted iPhones owners with zero-days, Google says (TechCrunch)

Google agrees to pay $350 million settlement in security lapse case (Washington Post)

Canon Patches 7 Critical Vulnerabilities in Small Office Printers  (SecurityWeek)

Barracuda Disclosed Critical Vulnerabilities in WAF, Affecting File Upload and JSON Protection (SOCRadar)

ResumeLooters target job search sites in extensive data heist (Help Net Security)

Millions at risk of fraud after massive health data hack in France (The Connexion)

Fragmented cybersecurity vendor landscape is exacerbating risks and compounding skills shortages, SenseOn research reveals (IT Security Guru)

Meta’s Oversight Board Urges a Policy Change After a Fake Biden Video (InfoSecurity Magazine)

Toothbrushes are a cybersecurity risk, too: millions participate in DDoS attacks (Cybernews)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2024-02-05

A serious breach showdown.

30 min
View

Anydesk confirms a serious breach. Clorox and Johnson Controls file cyber incidents with the SEC. There’s already a potential Apple Vision Pro kernel exploit. A $25 million deepfake scam. Akamai research hops on the FritzFrog botnet. The US sanctions Iranians for attacks on American water plants. Commando Cat targets Docker API endpoints. Pennsylvania courts fall victim to a DDoS attack. A new leader takes the reins at US Cyber Command and the NSA. Our guest is Dr. Heather Monthie from N2K Networks, with insights on the White House's recent easing of education requirements for federal contract jobs. And remembering one of the great cryptology communicators. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Guest Heather Monthie from N2K Networks shares some insight into the White House's recent easing of education requirements for federal contract jobs. You can find the background to that in our Selected Reading section. 


Selected Reading

AnyDesk, an enterprise remote software platform used by major firms including Raytheon and Samsung, suffered a security breach - here’s what you need to know (IT Pro)

Clorox and Johnson Controls Reveal $76m Cyber-Attack Bill (Infosecurity Magazine)

MIT student claims to hack Apple Vision Pro on launch day (Cybernews)

Finance worker pays out $25 million after video call with deepfake ‘chief financial officer’ (CNN)

FritzFrog botnet is exploiting Log4Shell bug now, experts say (The Record)

US sanctions Iranian officials over cyber-attacks on water plants (BBC)

The Nine Lives of Commando Cat: Analysing a Novel Malware Campaign Targeting Docker  (Cado Security)

Pennsylvania court agency's website hit by disabling cyberattack, officials say (ABC News)

Cyber Command, NSA usher in Haugh as new chief (The Record)

White House moves to ease education requirements for federal cyber contracting jobs (CyberScoop)

White House moves to ease education requirements for federal cyber contracting jobs (GAO)

David Kahn, historian who cracked the code of cryptology, dies at 93 (Washington Post)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

Anydesk confirms a serious breach. Clorox and Johnson Controls file cyber incidents with the SEC. There’s already a potential Apple Vision Pro kernel exploit. A $25 million deepfake scam. Akamai research hops on the FritzFrog botnet. The US sanctions Iranians for attacks on American water plants. Commando Cat targets Docker API endpoints. Pennsylvania courts fall victim to a DDoS attack. A new leader takes the reins at US Cyber Command and the NSA. Our guest is Dr. Heather Monthie from N2K Networks, with insights on the White House's recent easing of education requirements for federal contract jobs. And remembering one of the great cryptology communicators. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

CyberWire Guest

Guest Heather Monthie from N2K Networks shares some insight into the White House's recent easing of education requirements for federal contract jobs. You can find the background to that in our Selected Reading section. 


Selected Reading

AnyDesk, an enterprise remote software platform used by major firms including Raytheon and Samsung, suffered a security breach - here’s what you need to know (IT Pro)

Clorox and Johnson Controls Reveal $76m Cyber-Attack Bill (Infosecurity Magazine)

MIT student claims to hack Apple Vision Pro on launch day (Cybernews)

Finance worker pays out $25 million after video call with deepfake ‘chief financial officer’ (CNN)

FritzFrog botnet is exploiting Log4Shell bug now, experts say (The Record)

US sanctions Iranian officials over cyber-attacks on water plants (BBC)

The Nine Lives of Commando Cat: Analysing a Novel Malware Campaign Targeting Docker  (Cado Security)

Pennsylvania court agency's website hit by disabling cyberattack, officials say (ABC News)

Cyber Command, NSA usher in Haugh as new chief (The Record)

White House moves to ease education requirements for federal cyber contracting jobs (CyberScoop)

White House moves to ease education requirements for federal cyber contracting jobs (GAO)

David Kahn, historian who cracked the code of cryptology, dies at 93 (Washington Post)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere

Cybersecurity and disinformation researcher Bilyana Lilly shares her career path from studying where she was always a foreigner to an expert on the Russian perspective. While studying international law in Kosovo, Bilyana realized there are no winners in war. Through her work, she hopes to bring a greater understanding of Russia's strategic thinking. Our thanks to Bilyana for sharing her story with us. 

More description

Cybersecurity and disinformation researcher Bilyana Lilly shares her career path from studying where she was always a foreigner to an expert on the Russian perspective. While studying international law in Kosovo, Bilyana realized there are no winners in war. Through her work, she hopes to bring a greater understanding of Russia's strategic thinking. Our thanks to Bilyana for sharing her story with us. 

Extract Knowledge
Listen elsewhere

Johannes Ullrich from SANS talking about the Internet Storm Center and how they do research. Internet Storm Center was created as a mix of manual reports submitted by security analysts during Y2K and automated firewall collection started by DShield.

The research shares how SANS used their "agile honeypots" to "zoom in" on events to more effectively collect data targeting specific vulnerabilities. Internet Storm Center has been noted on three separate attacks that were observed.

The research can be found here:

More description

Johannes Ullrich from SANS talking about the Internet Storm Center and how they do research. Internet Storm Center was created as a mix of manual reports submitted by security analysts during Y2K and automated firewall collection started by DShield.

The research shares how SANS used their "agile honeypots" to "zoom in" on events to more effectively collect data targeting specific vulnerabilities. Internet Storm Center has been noted on three separate attacks that were observed.

The research can be found here:

Extract Knowledge
Listen elsewhere

Former CIA leaker sentenced to 40 years. Interpol arrests suspected cybercriminals and takes down servers. Cloudflare discloses a Thanksgiving Day data breach. The FBI removes malware from outdated routers. President Biden plans to veto a Republican-led bill overturning cyber disclosure rules. Attackers target poorly managed Linux systems. Infected USB devices take advantage of popular websites for malware distribution. Blackbaud faces a data deletion mandate from the FTC. Our guest is Adam Marré, CISO of Arctic Wolf, to kick off our continuing discussion of 2024 election security. A cybersecurity incident in Georgia leads to a murder suspect on the run.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Guest Adam Marré, CISO of Arctic Wolf, joins us to begin our discussion of election security in 2024. Adam will be sharing their Election Cybersecurity Survey outlining key cybersecurity threats to the 2024 election season. 


Selected Reading

40 years in prison for ex-CIA coder who leaked hacking tools to WikiLeaks (Digital Journey)

Interpol arrests more than 30 cybercriminals in global ‘Synergia’ operation (The Record)

Cloudflare Hacked After State Actor Leverages Okta Breach (HACKREAD)

FBI removes malware from hundreds of routers across the US (Malwarebytes)

Biden to Veto Attempt to Overturn SEC Cyber Incident Disclosure Rules (SecurityWeek)

Threat Actors Installing Linux Backdoor Accounts (ASEC)

USB Malware Chained with Text Strings on Legitimate Websites Attacks Users (Cybersecurity News)

FTC settles with Blackbaud over poor data practices leading to massive hack (The Record)

Murder suspect mistakenly released from jail after 'cybersecurity incident'  (ABC News)  


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

Former CIA leaker sentenced to 40 years. Interpol arrests suspected cybercriminals and takes down servers. Cloudflare discloses a Thanksgiving Day data breach. The FBI removes malware from outdated routers. President Biden plans to veto a Republican-led bill overturning cyber disclosure rules. Attackers target poorly managed Linux systems. Infected USB devices take advantage of popular websites for malware distribution. Blackbaud faces a data deletion mandate from the FTC. Our guest is Adam Marré, CISO of Arctic Wolf, to kick off our continuing discussion of 2024 election security. A cybersecurity incident in Georgia leads to a murder suspect on the run.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Guest Adam Marré, CISO of Arctic Wolf, joins us to begin our discussion of election security in 2024. Adam will be sharing their Election Cybersecurity Survey outlining key cybersecurity threats to the 2024 election season. 


Selected Reading

40 years in prison for ex-CIA coder who leaked hacking tools to WikiLeaks (Digital Journey)

Interpol arrests more than 30 cybercriminals in global ‘Synergia’ operation (The Record)

Cloudflare Hacked After State Actor Leverages Okta Breach (HACKREAD)

FBI removes malware from hundreds of routers across the US (Malwarebytes)

Biden to Veto Attempt to Overturn SEC Cyber Incident Disclosure Rules (SecurityWeek)

Threat Actors Installing Linux Backdoor Accounts (ASEC)

USB Malware Chained with Text Strings on Legitimate Websites Attacks Users (Cybersecurity News)

FTC settles with Blackbaud over poor data practices leading to massive hack (The Record)

Murder suspect mistakenly released from jail after 'cybersecurity incident'  (ABC News)  


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere

Directors Wray and Easterly warn congress of threats from Chinese hackers. Myanmar authorities extradite pig butchering suspects. Automation remains a challenge. Snyk Security Labs plugs holes in “Leaky Vessels.” Pegasus spyware targets human rights groups in Jordan. Subtle-paws scratch at Ukrainian military personnel. White Phoenix brings your ransomed files back from the ashes. In today’s Threat Vector, host David Moulton, Director of Thought Leadership at Unit 42, speaks with MDR Senior Manager Oded Awaskar, about how AI might change the world of security operations and threat-hunting. A wee lil trick for bypassing Chat GPT guardrails.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

In today’s segment of Threat Vector, host David Moulton, Director of Thought Leadership at Unit 42, speaks with Oded Awaskar, an MDR Senior Manager, about threat-hunting and how AI and ML might change the world of security operations and threat-hunting. Tune in to Palo Alto Networks’ biweekly Threat Vector podcast on our network for the full conversation.

If you are interested to learn more about Unit 42 World-Renowned threat hunters, visit https://www.paloaltonetworks.com/unit42/respond/managed-threat-hunting and https://www.paloaltonetworks.com/unit42/respond/managed-detection-response

In coming episodes, David will discuss the impact of the SEC Cyber Rules with Jacqueline Wudyka and share a conversation with Sam Rubin, Global Head of Operations for Unit 42, about his testimony at the Congressional hearing on the growing threat of ransomware.


Selected Reading

Wray warns Chinese hackers are aiming to 'wreak havoc' on U.S. critical infrastructure (NPR)

FBI director warns Chinese hackers aim to 'wreak havoc' on U.S. critical infrastructure (NBC News)

Opening Statement by CISA Director Jen Easterly (CISA on YouTube)

FBI issues dramatic public warning: Chinese hackers are preparing to 'wreak havoc' on the US (CNN on YouTube) 

CISA orders federal agencies to disconnect Ivanti VPN appliances by Saturday (Bleeping Computer)

iPhone Under Attack: U.S. Government Issues 21 Days To Comply Warning (Forbes)

Why Are Cybersecurity Automation Projects Failing? (Security Week)

Crime bosses behind Myanmar cyber ‘fraud dens’ handed over to Chinese government (The Record)

Leaky Vessels: Docker and runc Container Breakout Vulnerabilities (Snyk)

At Least 30 Journalists, Lawyers and Activists Hacked With Pegasus in Jordan, Forensic Probe Finds (SecurityWeek)

Online ransomware decryptor helps recover partially encrypted files (Bleeping Computer)

Analysis and Detection of STEADY#URSA Attack Campaign Targeting Ukraine Military Dropping New Covert SUBTLE-PAWS PowerShell Backdoor (Securonix)

OpenAI's GPT-4 safety systems broken by Scots Gaelic (The Register)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

Directors Wray and Easterly warn congress of threats from Chinese hackers. Myanmar authorities extradite pig butchering suspects. Automation remains a challenge. Snyk Security Labs plugs holes in “Leaky Vessels.” Pegasus spyware targets human rights groups in Jordan. Subtle-paws scratch at Ukrainian military personnel. White Phoenix brings your ransomed files back from the ashes. In today’s Threat Vector, host David Moulton, Director of Thought Leadership at Unit 42, speaks with MDR Senior Manager Oded Awaskar, about how AI might change the world of security operations and threat-hunting. A wee lil trick for bypassing Chat GPT guardrails.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

In today’s segment of Threat Vector, host David Moulton, Director of Thought Leadership at Unit 42, speaks with Oded Awaskar, an MDR Senior Manager, about threat-hunting and how AI and ML might change the world of security operations and threat-hunting. Tune in to Palo Alto Networks’ biweekly Threat Vector podcast on our network for the full conversation.

If you are interested to learn more about Unit 42 World-Renowned threat hunters, visit https://www.paloaltonetworks.com/unit42/respond/managed-threat-hunting and https://www.paloaltonetworks.com/unit42/respond/managed-detection-response

In coming episodes, David will discuss the impact of the SEC Cyber Rules with Jacqueline Wudyka and share a conversation with Sam Rubin, Global Head of Operations for Unit 42, about his testimony at the Congressional hearing on the growing threat of ransomware.


Selected Reading

Wray warns Chinese hackers are aiming to 'wreak havoc' on U.S. critical infrastructure (NPR)

FBI director warns Chinese hackers aim to 'wreak havoc' on U.S. critical infrastructure (NBC News)

Opening Statement by CISA Director Jen Easterly (CISA on YouTube)

FBI issues dramatic public warning: Chinese hackers are preparing to 'wreak havoc' on the US (CNN on YouTube) 

CISA orders federal agencies to disconnect Ivanti VPN appliances by Saturday (Bleeping Computer)

iPhone Under Attack: U.S. Government Issues 21 Days To Comply Warning (Forbes)

Why Are Cybersecurity Automation Projects Failing? (Security Week)

Crime bosses behind Myanmar cyber ‘fraud dens’ handed over to Chinese government (The Record)

Leaky Vessels: Docker and runc Container Breakout Vulnerabilities (Snyk)

At Least 30 Journalists, Lawyers and Activists Hacked With Pegasus in Jordan, Forensic Probe Finds (SecurityWeek)

Online ransomware decryptor helps recover partially encrypted files (Bleeping Computer)

Analysis and Detection of STEADY#URSA Attack Campaign Targeting Ukraine Military Dropping New Covert SUBTLE-PAWS PowerShell Backdoor (Securonix)

OpenAI's GPT-4 safety systems broken by Scots Gaelic (The Register)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2024-01-31

VPN compromise causes concerns.

28 min
View

Global Affairs Canada investigates a major data breach. New York sues Citibank over inadequate online security. Alpha ransomware launches a dedicated leak site on the dark web. A leaked database with 50 million records may or may not be real. CISA and the FBI provide guidance for SOHO routers.Patch ‘em if ya got ‘em. Krustyloader exploits Ivanti weaknesses. Unit 42 tracks a large-scale scareware campaign. Alex Stamos calls Microsoft’s security strategies “morally indefensible.” Our guests are Gianna Whitver and Maria Velasquez from the Cybersecurity Marketing Society to talk about their new podcast "Breaking Through in Cybersecurity Marketing." And do you have what it takes to protect his majesty’s royal laptop?

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Guests Gianna Whitver and Maria Velasquez from the Cybersecurity Marketing Society join Dave to share about their podcast "Breaking Through in Cybersecurity Marketing" that is joining the N2K network. You can listen to their newest episode on our network. 


Selected Reading

Global Affairs investigating 'malicious' hack after VPN compromised for over one month (National Post) 

Lawsuit: Citibank refused to reimburse scam victims who lost “life savings”  (Ars Technica)

Unveiling Alpha Ransomware: A Deep Dive into Its Operations (Netenrich)

Nearly 50 million Europcar customer records put up for sale on the dark web – or were they? (ITPro)

Apple and Google Just Patched Their First Zero-Day Flaws of the Year (WIRED)

Threat actors exploit Ivanti VPN bugs to deploy KrustyLoader Malware (Security Affairs)

ApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign (Palo Alto Networks)

Microsoft's Dangerous Addiction To Security Revenue (LinkedIn)

Be the Royal Family’s Cybersecurity Manager, and get a cut-price honey dipper! (Graham Cluley) 


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

Global Affairs Canada investigates a major data breach. New York sues Citibank over inadequate online security. Alpha ransomware launches a dedicated leak site on the dark web. A leaked database with 50 million records may or may not be real. CISA and the FBI provide guidance for SOHO routers.Patch ‘em if ya got ‘em. Krustyloader exploits Ivanti weaknesses. Unit 42 tracks a large-scale scareware campaign. Alex Stamos calls Microsoft’s security strategies “morally indefensible.” Our guests are Gianna Whitver and Maria Velasquez from the Cybersecurity Marketing Society to talk about their new podcast "Breaking Through in Cybersecurity Marketing." And do you have what it takes to protect his majesty’s royal laptop?

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Guests Gianna Whitver and Maria Velasquez from the Cybersecurity Marketing Society join Dave to share about their podcast "Breaking Through in Cybersecurity Marketing" that is joining the N2K network. You can listen to their newest episode on our network. 


Selected Reading

Global Affairs investigating 'malicious' hack after VPN compromised for over one month (National Post) 

Lawsuit: Citibank refused to reimburse scam victims who lost “life savings”  (Ars Technica)

Unveiling Alpha Ransomware: A Deep Dive into Its Operations (Netenrich)

Nearly 50 million Europcar customer records put up for sale on the dark web – or were they? (ITPro)

Apple and Google Just Patched Their First Zero-Day Flaws of the Year (WIRED)

Threat actors exploit Ivanti VPN bugs to deploy KrustyLoader Malware (Security Affairs)

ApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign (Palo Alto Networks)

Microsoft's Dangerous Addiction To Security Revenue (LinkedIn)

Be the Royal Family’s Cybersecurity Manager, and get a cut-price honey dipper! (Graham Cluley) 


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2024-01-30

A Typhoon counter.

23 min
View

The U.S. counters a Chinese hacking campaign. Juniper issues out of band patches. Schneider Electric suffers a ransomware attack. Over a million and a half individuals are affected by an insurance consulting firm breach. AT&T finds DarkGate malware leveraging Microsoft teams. The White House is set to require AI developers to share safety test results. Resecurity finds high level credentials posted online. Zscaler says Zloader malware is back. The Georgia county prosecuting former President Trump got hit with a cyberattack. Microsoft’s Ann Johnson speaks with guest Deneen DeFiore, Vice President and Chief Information Security Officer at United Airlines, about cybersecurity at 35,000 feet. And yesterday’s airborne joker is off the hook. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Ann Johnson, host of Microsoft Security’s Afternoon Cyber Tea podcast, talks with guest Deneen DeFiore, Vice President and Chief Information Security Officer at United Airlines, about cybersecurity at 35,000 feet.


Selected Reading

Exclusive: US disabled Chinese hacking network targeting critical infrastructure (Reuters)

China-Linked Hackers Target Myanmar's Top Ministries with Backdoor Blitz (The Hacker News)

Juniper Networks Releases Urgent Junos OS Updates for High-Severity Flaws (The Hacker News)

Schneider Electric confirms it was hit by ransomware attack (Silicon Republic)

1.5 Million Affected by Data Breach at Insurance Broker Keenan & Associates (SecurityWeek)

DarkGate malware delivered via Microsoft Teams - detection and response (AT&T)

AI companies will need to start reporting their safety tests to the US government (AP)

Hundreds of network operators’ credentials found circulating in Dark Web (Security Affairs)

New ZLoader Malware Variant Surfaces with 64-bit Windows Compatibility (The Hacker News)

Cyberattack Hits Georgia County Where Trump Is Charged (Bloomberg)

British man acquitted over London-Spain flight bomb hoax (BBC)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show.


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

The U.S. counters a Chinese hacking campaign. Juniper issues out of band patches. Schneider Electric suffers a ransomware attack. Over a million and a half individuals are affected by an insurance consulting firm breach. AT&T finds DarkGate malware leveraging Microsoft teams. The White House is set to require AI developers to share safety test results. Resecurity finds high level credentials posted online. Zscaler says Zloader malware is back. The Georgia county prosecuting former President Trump got hit with a cyberattack. Microsoft’s Ann Johnson speaks with guest Deneen DeFiore, Vice President and Chief Information Security Officer at United Airlines, about cybersecurity at 35,000 feet. And yesterday’s airborne joker is off the hook. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Ann Johnson, host of Microsoft Security’s Afternoon Cyber Tea podcast, talks with guest Deneen DeFiore, Vice President and Chief Information Security Officer at United Airlines, about cybersecurity at 35,000 feet.


Selected Reading

Exclusive: US disabled Chinese hacking network targeting critical infrastructure (Reuters)

China-Linked Hackers Target Myanmar's Top Ministries with Backdoor Blitz (The Hacker News)

Juniper Networks Releases Urgent Junos OS Updates for High-Severity Flaws (The Hacker News)

Schneider Electric confirms it was hit by ransomware attack (Silicon Republic)

1.5 Million Affected by Data Breach at Insurance Broker Keenan & Associates (SecurityWeek)

DarkGate malware delivered via Microsoft Teams - detection and response (AT&T)

AI companies will need to start reporting their safety tests to the US government (AP)

Hundreds of network operators’ credentials found circulating in Dark Web (Security Affairs)

New ZLoader Malware Variant Surfaces with 64-bit Windows Compatibility (The Hacker News)

Cyberattack Hits Georgia County Where Trump Is Charged (Bloomberg)

British man acquitted over London-Spain flight bomb hoax (BBC)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show.


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2024-01-29

Seeking dismissal of SEC allegations.

24 min
View

Solarwinds seeks dismissal of SEC allegations. Urgent calls to implement fixes for Jenkins open-source software automation tools. A New Jersey township closes schools and offices after a cyberattack. The Centre for Cybersecurity Belgium warns of a critical vulnerability in GitLab. The FBI arrests a notorious swatter. HHS releases cybersecurity performance goals. The feds remind organizations to preserve online messaging. Mercedes-Benz exposes data after an authentication token was left unsecured. A dark web drug dealer pleads guilty. Our guest is Caleb Barlow from Cyberbit, discussing hacker celebrities and why yours truly did not make the list. And threats of airport terrorism on public WiFi is no joking matter.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Podcast partner Caleb Barlow, CEO of Cyberbit, discusses hacker celebrities and why our own Dave Bittner did not make the list.


Selected Reading

SolarWinds Seeks Dismissal of ‘Unfounded’ SEC Cybersecurity Suit  (Bloomberg Law)

Fix Available for Critical Jenkins Flaw That Leads to RCE Attacks (Security Boulevard)

Freehold Township district: All schools and offices closed Monday due to cybersecurity incident (News12 New Jersey)

WARNING: CRITICAL ARBITRARY FILE WRITE VULNERABILITY IN GITLAB CE/EE, PATCH IMMEDIATELY! (Centre for Cybersecurity Belgium)

Police Arrest Teen Said to Be Linked to Hundreds of Swatting Attacks (WIRED)

HHS debuts voluntary cybersecurity performance goals to enhance healthcare sector resilience (Industrial Cyber)

Don’t Delete Slack or Signal Chats, US Agencies Warn Companies (Bloomberg Law)

How a mistakenly published password exposed Mercedes-Benz source code (TechCrunch)

Dark Web Drugs Vendor Forfeits $150m After Guilty Plea (Infosecurity Magazine)

‘On My Way to Blow Up the Plane’: Teen Faces Huge Fine After Joke Leads to Fighter Jets Scrambling (Gizmodo)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

Solarwinds seeks dismissal of SEC allegations. Urgent calls to implement fixes for Jenkins open-source software automation tools. A New Jersey township closes schools and offices after a cyberattack. The Centre for Cybersecurity Belgium warns of a critical vulnerability in GitLab. The FBI arrests a notorious swatter. HHS releases cybersecurity performance goals. The feds remind organizations to preserve online messaging. Mercedes-Benz exposes data after an authentication token was left unsecured. A dark web drug dealer pleads guilty. Our guest is Caleb Barlow from Cyberbit, discussing hacker celebrities and why yours truly did not make the list. And threats of airport terrorism on public WiFi is no joking matter.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Podcast partner Caleb Barlow, CEO of Cyberbit, discusses hacker celebrities and why our own Dave Bittner did not make the list.


Selected Reading

SolarWinds Seeks Dismissal of ‘Unfounded’ SEC Cybersecurity Suit  (Bloomberg Law)

Fix Available for Critical Jenkins Flaw That Leads to RCE Attacks (Security Boulevard)

Freehold Township district: All schools and offices closed Monday due to cybersecurity incident (News12 New Jersey)

WARNING: CRITICAL ARBITRARY FILE WRITE VULNERABILITY IN GITLAB CE/EE, PATCH IMMEDIATELY! (Centre for Cybersecurity Belgium)

Police Arrest Teen Said to Be Linked to Hundreds of Swatting Attacks (WIRED)

HHS debuts voluntary cybersecurity performance goals to enhance healthcare sector resilience (Industrial Cyber)

Don’t Delete Slack or Signal Chats, US Agencies Warn Companies (Bloomberg Law)

How a mistakenly published password exposed Mercedes-Benz source code (TechCrunch)

Dark Web Drugs Vendor Forfeits $150m After Guilty Plea (Infosecurity Magazine)

‘On My Way to Blow Up the Plane’: Teen Faces Huge Fine After Joke Leads to Fighter Jets Scrambling (Gizmodo)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere

Rashmi Bharathan, an Information Technology Internal Auditor from Wintrust Financial Corporation sits down to share her story as a woman with 10 years in the IT industry and how she got her start. From childhood Rashmi always wanted to be a good leader, helping those around her, now she shares how helping people is a passion of hers and spends a lot of her time volunteering to help those coming into this industry. She says "It's all about, you should know your connections. That is more important. So I would say that networking and volunteering is really going to help you to grow in your career," sharing that community is the key to her success and working hard to network has been a great help to her to get her where she is today. We thank Rashmi for sharing her story with us.

More description

Rashmi Bharathan, an Information Technology Internal Auditor from Wintrust Financial Corporation sits down to share her story as a woman with 10 years in the IT industry and how she got her start. From childhood Rashmi always wanted to be a good leader, helping those around her, now she shares how helping people is a passion of hers and spends a lot of her time volunteering to help those coming into this industry. She says "It's all about, you should know your connections. That is more important. So I would say that networking and volunteering is really going to help you to grow in your career," sharing that community is the key to her success and working hard to network has been a great help to her to get her where she is today. We thank Rashmi for sharing her story with us.

Extract Knowledge
Listen elsewhere

In this episode of CyberWire-X, N2K’s CSO, Chief Analyst, and Senior Fellow, Rick Howard, is joined by Tim Miller, Technical Marketing Engineer for Panoptica, Cisco's Cloud Application Security solution, (Panoptica is the result of Cisco's incubation engine (Outshift) for new products and markets), and Kevin Ford, Esri’s CISO. They discuss the complexity reduction need that Cloud-Native Application Protection Platforms (CNAPPs) provide. Outshift by Cisco is our CyberWire-X episode sponsor.

To learn more about Cloud-Native Application Protection Platforms, check out Panoptica’s website at https://panoptica.app and consider attending the Cisco Live EMEA in Amsterdam, February 5-8, 2024.

More description

In this episode of CyberWire-X, N2K’s CSO, Chief Analyst, and Senior Fellow, Rick Howard, is joined by Tim Miller, Technical Marketing Engineer for Panoptica, Cisco's Cloud Application Security solution, (Panoptica is the result of Cisco's incubation engine (Outshift) for new products and markets), and Kevin Ford, Esri’s CISO. They discuss the complexity reduction need that Cloud-Native Application Protection Platforms (CNAPPs) provide. Outshift by Cisco is our CyberWire-X episode sponsor.

To learn more about Cloud-Native Application Protection Platforms, check out Panoptica’s website at https://panoptica.app and consider attending the Cisco Live EMEA in Amsterdam, February 5-8, 2024.

Extract Knowledge
Listen elsewhere

Jaron Bradley from Jamf Threat Labs is sharing their work on "Jamf Threat Labs discovers new malware embedded in pirated applications." Jamf Threat Labs has detected a series of pirated macOS applications that have been modified to communicate to attacker infrastructure.

The research states "These applications are being hosted on Chinese pirating websites in order to gain victims." The discovery marks new and advanced malware, similar to the ZuRu malware, first discovered by Objective-See in 2021 within the iTerm2 application.

The research can be found here:

More description

Jaron Bradley from Jamf Threat Labs is sharing their work on "Jamf Threat Labs discovers new malware embedded in pirated applications." Jamf Threat Labs has detected a series of pirated macOS applications that have been modified to communicate to attacker infrastructure.

The research states "These applications are being hosted on Chinese pirating websites in order to gain victims." The discovery marks new and advanced malware, similar to the ZuRu malware, first discovered by Objective-See in 2021 within the iTerm2 application.

The research can be found here:

Extract Knowledge
Listen elsewhere
Published 2024-01-26

A new purchase is cause for a call out.

26 min
View

Senator Wyden calls out the NSA for purchasing American’s internet records. Senators look to add IT and ICS environments to federal employee cyber competitions. The FTC asks big tech about their investments in AI. Turns out the GSA bought a bunch of Chinese security cameras. Akira ransomware claims a breach of Lush cosmetics. ESET reports on the Blackwood cyberespionage group. Wired looks at Predatory Sparrow. The U.S. stands firm on the United Nations Cybercrime Treaty. Our guest is Tony Surak, CMO & Operating Partner from DataTribe, with insights on the state of venture capital in cyber. And a Trickbot gang member will be doing some time.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Guest Tony Surak from DataTribe joins us to share his take on the state of the VC cyber market.


Selected Reading

Wyden Releases Documents Confirming the NSA Buys Americans’ Internet Browsing Records; Calls on Intelligence Community to Stop Buying U.S. Data Obtained Unlawfully From Data Brokers, Violating Recent FTC Order 

Senate Committee debuts bipartisan bill to add OT, ICS environments to federal employee cyber competition 

FTC officially asks Big Tech about their AI deals | Cybernews 

GSA Sparks Security Fears After Buying Risky Chinese Cameras

Akira ransomware gang says it stole passport scans from Lush • The Register

Elusive Chinese Cyberspy Group Hijacks Software Updates to Deliver Malware - SecurityWeek

How a Group of Israel-Linked Hackers Has Pushed the Limits of Cyberwar | WIRED

On eve of final negotiations, US says consensus growing around ‘narrow’ UN cybercrime treaty

Trickbot malware developer sentenced to 5 years behind bars • The Register


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

Senator Wyden calls out the NSA for purchasing American’s internet records. Senators look to add IT and ICS environments to federal employee cyber competitions. The FTC asks big tech about their investments in AI. Turns out the GSA bought a bunch of Chinese security cameras. Akira ransomware claims a breach of Lush cosmetics. ESET reports on the Blackwood cyberespionage group. Wired looks at Predatory Sparrow. The U.S. stands firm on the United Nations Cybercrime Treaty. Our guest is Tony Surak, CMO & Operating Partner from DataTribe, with insights on the state of venture capital in cyber. And a Trickbot gang member will be doing some time.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Guest Tony Surak from DataTribe joins us to share his take on the state of the VC cyber market.


Selected Reading

Wyden Releases Documents Confirming the NSA Buys Americans’ Internet Browsing Records; Calls on Intelligence Community to Stop Buying U.S. Data Obtained Unlawfully From Data Brokers, Violating Recent FTC Order 

Senate Committee debuts bipartisan bill to add OT, ICS environments to federal employee cyber competition 

FTC officially asks Big Tech about their AI deals | Cybernews 

GSA Sparks Security Fears After Buying Risky Chinese Cameras

Akira ransomware gang says it stole passport scans from Lush • The Register

Elusive Chinese Cyberspy Group Hijacks Software Updates to Deliver Malware - SecurityWeek

How a Group of Israel-Linked Hackers Has Pushed the Limits of Cyberwar | WIRED

On eve of final negotiations, US says consensus growing around ‘narrow’ UN cybercrime treaty

Trickbot malware developer sentenced to 5 years behind bars • The Register


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2024-01-25

Another day, another Blizzard attack.

29 min
View

Cozy Bear breaches Hewlett Packard Enterprise. An investigation reveals global surveillance based on digital advertising. Cisco patches critical vulnerabilities. Meta aims to enhance the online safety of minors.  iOS notifications are exploited for tracking. EquiLend’s systems go offline after a cyberattack.  A DC theater faced financial crisis after seeing their bank account drained. Critical infrastructure is targeted in Ukraine.  The latest insights on ransomware. Guest Lance Hood joins us from TransUnion to share how fraud attacks on financial industry call centers are rising. And Teslas get POwned in Tokyo.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Guest Lance Hood joins us from TransUnion to share how fraud attacks on financial industry call centers are rising.


Selected Reading

Hewlett Packard Enterprise tells SEC it was breached by Russia’s 'Cozy Bear' hackers (The Record)

Inside a Global Phone Spy Tool Monitoring Billions (404 Media)

Cisco Patches Critical Vulnerability in Enterprise Collaboration Products (SecurityWeek)

Instagram and Facebook will now prevent strangers from messaging minors by default (The Verge)

Research Reveals How iPhone Push Notifications Leak User Data (MacRumors)

Financial tech firm EquiLend says recovery after cyberattack ‘may take several days’ (The Record)

'No gift is too small' | GALA Hispanic Theater asking for donations after hackers drain bank accounts (WUSA9)

Ukrainian energy giant, postal service, transportation agencies hit by cyberattacks (The Record)

The 2024 Ransomware Threat Landscape (Symantec Enterprise Blogs)

Who pays, and why: A researcher examines the ransomware victim’s mindset (The Record)

Tesla Hack Earns Researchers $100,000 at Pwn2Own Automotive - SecurityWeek (SecurityWeek)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

Cozy Bear breaches Hewlett Packard Enterprise. An investigation reveals global surveillance based on digital advertising. Cisco patches critical vulnerabilities. Meta aims to enhance the online safety of minors.  iOS notifications are exploited for tracking. EquiLend’s systems go offline after a cyberattack.  A DC theater faced financial crisis after seeing their bank account drained. Critical infrastructure is targeted in Ukraine.  The latest insights on ransomware. Guest Lance Hood joins us from TransUnion to share how fraud attacks on financial industry call centers are rising. And Teslas get POwned in Tokyo.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Guest Lance Hood joins us from TransUnion to share how fraud attacks on financial industry call centers are rising.


Selected Reading

Hewlett Packard Enterprise tells SEC it was breached by Russia’s 'Cozy Bear' hackers (The Record)

Inside a Global Phone Spy Tool Monitoring Billions (404 Media)

Cisco Patches Critical Vulnerability in Enterprise Collaboration Products (SecurityWeek)

Instagram and Facebook will now prevent strangers from messaging minors by default (The Verge)

Research Reveals How iPhone Push Notifications Leak User Data (MacRumors)

Financial tech firm EquiLend says recovery after cyberattack ‘may take several days’ (The Record)

'No gift is too small' | GALA Hispanic Theater asking for donations after hackers drain bank accounts (WUSA9)

Ukrainian energy giant, postal service, transportation agencies hit by cyberattacks (The Record)

The 2024 Ransomware Threat Landscape (Symantec Enterprise Blogs)

Who pays, and why: A researcher examines the ransomware victim’s mindset (The Record)

Tesla Hack Earns Researchers $100,000 at Pwn2Own Automotive - SecurityWeek (SecurityWeek)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2024-01-24

The fight against exploiting Americans.

32 min
View

Biden prepares executive order on foreign access to data. Britain’s NCSC warns of a significant ransomware increase. Cisco Talos confirms ransomware surge. BuyGoods.com leaks PII and KYC data. Fortra faces scrutiny over slow disclosure. AI fights financial fraud. Intel471 highlights bulletproof hosting. NSO Group lobbies to revamp their image. Tussling in Missouri over election security. Integrating cyber education. Our guests are N2K President Simone Petrella and WiCyS Executive Director Lynn Dohm talking about a new partnership for a comprehensive Cyber Talent Study. And the moral panic of Furbies.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Today’s guests are N2K President Simone Petrella and WiCyS Executive Director Lynn Dohm talking with Dave Bittner about a new partnership for a comprehensive Cyber Talent Study to deepen the collective understanding of cybersecurity competencies within the industry.


Selected Reading

Biden Seeks to Stop Countries From Exploiting Americans’ Data for Espionage (Bloomberg)

British intelligence warns AI will cause surge in ransomware volume and impact (The Record)

Significant increase in ransomware activity found in Talos IR engagements, while education remains one of the most-targeted sectors (Talos)

Global Retailer BuyGoods.com Leaks 198GB of Internal and User PII, KYC data (HACKREAD)

Fortra blasted over slow response to critical GoAnywhere file transfer bug (SC Media)

Gen AI Expected to Bring Big Changes to Banking Sector (GovInfo Security)

Why Bulletproof Hosting is Key to Cybercrime-as-a-Service (Infosecurity Magazine)

Notorious Spyware Maker NSO Group Is Quietly Plotting a Comeback (WIRED)

Missouri secretary of state accused of withholding cybersecurity reviews of election authorities (StateScoop)

Cybersecurity education from childhood is a vital tool: 72% of children worldwide have experienced at least one type of cyber threat (Check Point) 

These Are the Notorious NSA Furby Documents Showing Spy Agency Freaking Out About Embedded AI in Children's Toy (404 Media)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

Biden prepares executive order on foreign access to data. Britain’s NCSC warns of a significant ransomware increase. Cisco Talos confirms ransomware surge. BuyGoods.com leaks PII and KYC data. Fortra faces scrutiny over slow disclosure. AI fights financial fraud. Intel471 highlights bulletproof hosting. NSO Group lobbies to revamp their image. Tussling in Missouri over election security. Integrating cyber education. Our guests are N2K President Simone Petrella and WiCyS Executive Director Lynn Dohm talking about a new partnership for a comprehensive Cyber Talent Study. And the moral panic of Furbies.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Today’s guests are N2K President Simone Petrella and WiCyS Executive Director Lynn Dohm talking with Dave Bittner about a new partnership for a comprehensive Cyber Talent Study to deepen the collective understanding of cybersecurity competencies within the industry.


Selected Reading

Biden Seeks to Stop Countries From Exploiting Americans’ Data for Espionage (Bloomberg)

British intelligence warns AI will cause surge in ransomware volume and impact (The Record)

Significant increase in ransomware activity found in Talos IR engagements, while education remains one of the most-targeted sectors (Talos)

Global Retailer BuyGoods.com Leaks 198GB of Internal and User PII, KYC data (HACKREAD)

Fortra blasted over slow response to critical GoAnywhere file transfer bug (SC Media)

Gen AI Expected to Bring Big Changes to Banking Sector (GovInfo Security)

Why Bulletproof Hosting is Key to Cybercrime-as-a-Service (Infosecurity Magazine)

Notorious Spyware Maker NSO Group Is Quietly Plotting a Comeback (WIRED)

Missouri secretary of state accused of withholding cybersecurity reviews of election authorities (StateScoop)

Cybersecurity education from childhood is a vital tool: 72% of children worldwide have experienced at least one type of cyber threat (Check Point) 

These Are the Notorious NSA Furby Documents Showing Spy Agency Freaking Out About Embedded AI in Children's Toy (404 Media)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2024-01-23

The mother of all data breaches.

25 min
View

The mother of all data breaches. CISA director Easterly is the victim of a swatting incident. An AI robocall in New Hampshire seeks to sway the election. Australia sanctions an alleged Russian cyber-crime operator. Atlassian Confluence servers are under active exploitation. Apple patches a webkit zero-day. Black Basta hits a major UK water provider. Hackers who targeted an Indian ISP launch and online search portal. A Massachusetts hospital suffered a Christmas day ransomware attack. Ann Johnson host of the Afternoon Cyber Tea podcast, speaks with Caitlin Sarian, known to many as Cybersecurity Girl. And HP claims bricked printers are a security feature, not a bug. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Microsoft Security’s Afternoon Cyber Tea podcast host, Ann Johnson, speaks with Caitlin Sarian, known to many as Cybersecurity Girl, a leading influencer with a cybersecurity-focused social presence. Listen to the full interview here


Selected Reading

Mother of All Breaches: ​a Historic Data Leak Reveals 26 Billion Records (Cybernews)

CISA’s Easterly the target of ‘harrowing’ swatting incident (The Record)

AI robocalls impersonate President Biden in an apparent attempt to suppress votes in New Hampshire (PBS NewsHour)

Hear fake Biden robocall urging voters not to vote in New Hampshire (YouTube)

Medibank hack: Russian sanctioned over Australia's worst data breach (BBC)

Hackers start exploiting critical Atlassian Confluence RCE flaw (BleepingComputer)

iOS 17.3 and macOS Sonoma 14.3 Patch WebKit Vulnerability That May Have Been Exploited (MacRumors)

UK water company that serves millions confirms system attackIndian ISP Hathway Data Breach (The Record)

Hacker Leaks 4 Million Users, KYC Data (HACKREAD)

Massachusetts hospital claimed to be targeted by Money Message ransomware (SC Media)

HP's CEO spells it out: You're a 'bad investment' if you don't buy HP supplies (The Register)

HP CEO evokes James Bond-style hack via ink cartridges (Ars Technica)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

The mother of all data breaches. CISA director Easterly is the victim of a swatting incident. An AI robocall in New Hampshire seeks to sway the election. Australia sanctions an alleged Russian cyber-crime operator. Atlassian Confluence servers are under active exploitation. Apple patches a webkit zero-day. Black Basta hits a major UK water provider. Hackers who targeted an Indian ISP launch and online search portal. A Massachusetts hospital suffered a Christmas day ransomware attack. Ann Johnson host of the Afternoon Cyber Tea podcast, speaks with Caitlin Sarian, known to many as Cybersecurity Girl. And HP claims bricked printers are a security feature, not a bug. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Microsoft Security’s Afternoon Cyber Tea podcast host, Ann Johnson, speaks with Caitlin Sarian, known to many as Cybersecurity Girl, a leading influencer with a cybersecurity-focused social presence. Listen to the full interview here


Selected Reading

Mother of All Breaches: ​a Historic Data Leak Reveals 26 Billion Records (Cybernews)

CISA’s Easterly the target of ‘harrowing’ swatting incident (The Record)

AI robocalls impersonate President Biden in an apparent attempt to suppress votes in New Hampshire (PBS NewsHour)

Hear fake Biden robocall urging voters not to vote in New Hampshire (YouTube)

Medibank hack: Russian sanctioned over Australia's worst data breach (BBC)

Hackers start exploiting critical Atlassian Confluence RCE flaw (BleepingComputer)

iOS 17.3 and macOS Sonoma 14.3 Patch WebKit Vulnerability That May Have Been Exploited (MacRumors)

UK water company that serves millions confirms system attackIndian ISP Hathway Data Breach (The Record)

Hacker Leaks 4 Million Users, KYC Data (HACKREAD)

Massachusetts hospital claimed to be targeted by Money Message ransomware (SC Media)

HP's CEO spells it out: You're a 'bad investment' if you don't buy HP supplies (The Register)

HP CEO evokes James Bond-style hack via ink cartridges (Ars Technica)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2024-01-22

Midnight Blizzard brings the storm.

23 min
View

Russian state hackers breach Microsoft. LockBit claims Subway restaurants hack. A Swedish datacenter is hit with ransomware. VMware patches a vulnerability targeted by Chinese espionage groups. Sentinel Labs warns of North Korean APTs focus on cybersecurity pros. FTC order another data broker to restrict location data. US Feds release security guidance for water and wastewater sectors. Senators question the DOJ on facial recognition technology. Ukraine’s Monobank gets DDoSed. N2K’s CSO Rick Howard joins us to share some insight into what he and the Hash Table are cooking up for the upcoming season of his CSO Perspectives podcast. The passing of a Time Lord. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

N2K’s CSO Rick Howard joins us to share some insight into what he and the Hash Table are cooking up for the upcoming season of his CSO Perspectives podcast launching next month.   


Selected Reading

Microsoft: Russian Hackers Had Access to Executives' Emails (GovInfo Security)

LockBit ransomware gang claims the attack on the sandwich chain Subway (Security Affairs)

Ransomware hits cloud service Tietoevry; numerous Swedish customers affected (The Record)

Chinese Espionage Group UNC3886 Found Exploiting CVE-2023-34048 Since Late 2021 (Mandiant)

North Korea’s ScarCruft APT group targets infosec pros (CSO Online)

FTC Order Will Ban InMarket from Selling Precise Consumer Location Data (Federal Trade Commission)

US Gov Publishes Cybersecurity Guidance for Water and Wastewater Utilities (SecurityWeek)

Ukraine’s Monobank hit with massive DDoS attack (Silicon Republic)

Senators ask DOJ to investigate whether facial recognition tech violates Civil Rights Act (The Record)

RIP, Internet’s Time Lord (On My Om)

Network Time Protocol (NTP) attack (noun) (Word Notes podcast)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

Russian state hackers breach Microsoft. LockBit claims Subway restaurants hack. A Swedish datacenter is hit with ransomware. VMware patches a vulnerability targeted by Chinese espionage groups. Sentinel Labs warns of North Korean APTs focus on cybersecurity pros. FTC order another data broker to restrict location data. US Feds release security guidance for water and wastewater sectors. Senators question the DOJ on facial recognition technology. Ukraine’s Monobank gets DDoSed. N2K’s CSO Rick Howard joins us to share some insight into what he and the Hash Table are cooking up for the upcoming season of his CSO Perspectives podcast. The passing of a Time Lord. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

N2K’s CSO Rick Howard joins us to share some insight into what he and the Hash Table are cooking up for the upcoming season of his CSO Perspectives podcast launching next month.   


Selected Reading

Microsoft: Russian Hackers Had Access to Executives' Emails (GovInfo Security)

LockBit ransomware gang claims the attack on the sandwich chain Subway (Security Affairs)

Ransomware hits cloud service Tietoevry; numerous Swedish customers affected (The Record)

Chinese Espionage Group UNC3886 Found Exploiting CVE-2023-34048 Since Late 2021 (Mandiant)

North Korea’s ScarCruft APT group targets infosec pros (CSO Online)

FTC Order Will Ban InMarket from Selling Precise Consumer Location Data (Federal Trade Commission)

US Gov Publishes Cybersecurity Guidance for Water and Wastewater Utilities (SecurityWeek)

Ukraine’s Monobank hit with massive DDoS attack (Silicon Republic)

Senators ask DOJ to investigate whether facial recognition tech violates Civil Rights Act (The Record)

RIP, Internet’s Time Lord (On My Om)

Network Time Protocol (NTP) attack (noun) (Word Notes podcast)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere

CEO, Matt Devost, describes many firsts in his career including hacking into systems on an aircraft carrier at sea. He shares how he enjoys solving hard problems and the red teamer perspective, and how he was able to translate those into a career. For those interested in cybersecurity, Matt advises opportunities for self-directed learning including heading down to your basement and building your own lab. Our thanks to Matt for sharing his story with us. 

More description

CEO, Matt Devost, describes many firsts in his career including hacking into systems on an aircraft carrier at sea. He shares how he enjoys solving hard problems and the red teamer perspective, and how he was able to translate those into a career. For those interested in cybersecurity, Matt advises opportunities for self-directed learning including heading down to your basement and building your own lab. Our thanks to Matt for sharing his story with us. 

Extract Knowledge
Listen elsewhere

Earlier this month, the White House released the National Cybersecurity Strategy, the first issued since 2018. The strategy refocuses roles, responsibilities, and resource allocations in the digital ecosystem, with a five pillar approach. Those pillars are: defending critical infrastructure, disrupting threat actors, shaping market forces to drive security and resilience, investing in a resilient future, and forging international partnerships.

We wanted to delve into the strategy and its intended effects further, so Dave Bittner spoke with representatives from industry and inside government. Dave first speaks with Adam Isles, Principal and Head of Cybersecurity Practice at The Chertoff Group, sharing industry's take on the strategy. Following that conversation, Dave had a discussion with Steve Kelly, Special Assistant to the President and Senior Director for Cybersecurity and Emerging Technology at the National Security Council, for a look at the strategy from inside the White House.

Links to resources:

More description

Earlier this month, the White House released the National Cybersecurity Strategy, the first issued since 2018. The strategy refocuses roles, responsibilities, and resource allocations in the digital ecosystem, with a five pillar approach. Those pillars are: defending critical infrastructure, disrupting threat actors, shaping market forces to drive security and resilience, investing in a resilient future, and forging international partnerships.

We wanted to delve into the strategy and its intended effects further, so Dave Bittner spoke with representatives from industry and inside government. Dave first speaks with Adam Isles, Principal and Head of Cybersecurity Practice at The Chertoff Group, sharing industry's take on the strategy. Following that conversation, Dave had a discussion with Steve Kelly, Special Assistant to the President and Senior Director for Cybersecurity and Emerging Technology at the National Security Council, for a look at the strategy from inside the White House.

Links to resources:

Extract Knowledge
Listen elsewhere

Jon Williams from Bishop Fox is sharing their research on "It’s 2024 and Over 178,000 SonicWall Firewalls are Publicly Exploitable." SonicWall published advisories for CVE-2022-22274 and CVE-2023-0656 a year apart after finding that NGFW series 6 and 7 devices are affected by two unauthenticated denial-of-service vulnerabilities.

The research states "Our research found that the two issues are fundamentally the same but exploitable at different HTTP URI paths due to reuse of a vulnerable code pattern." They also found that when they scanned SonicWall firewalls with management interfaces exposed to the internet, they found that 76% are vulnerable to one or both issues.

The research can be found here:

More description

Jon Williams from Bishop Fox is sharing their research on "It’s 2024 and Over 178,000 SonicWall Firewalls are Publicly Exploitable." SonicWall published advisories for CVE-2022-22274 and CVE-2023-0656 a year apart after finding that NGFW series 6 and 7 devices are affected by two unauthenticated denial-of-service vulnerabilities.

The research states "Our research found that the two issues are fundamentally the same but exploitable at different HTTP URI paths due to reuse of a vulnerable code pattern." They also found that when they scanned SonicWall firewalls with management interfaces exposed to the internet, they found that 76% are vulnerable to one or both issues.

The research can be found here:

Extract Knowledge
Listen elsewhere
Published 2024-01-19

New malware, new threats.

26 min
View

Microsoft warns of an Iranian cyberespionage group. The CyberSafety Review Board receives critical reviews of its own. VMWare warns of active product exploitation. Tax info gets leaked in accounting firm breach. Kansas State University reports a cyber incident. CISA adds Citrix Netscaler vulnerabilities to its Known Exploited Vulnerabilities catalog. Councils in the UK suffer online disruptions. Cyber insurance can be a double edged sword. More email security breaches lead to firings. In our Solution Spotlight, N2K President Simone Petrella speaks with Michelle Amante of the Partnership for Public Service With an update on the Cybersecurity Talent Initiative. And it’s shields up for Generation Z.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

On the Solution Spotlight, N2K President Simone Petrella speaks with Michelle Amante of the Partnership for Public Service sharing an update on the Cybersecurity Talent Initiative and how federal agencies and early career existing talent that may be interested in the program’s offerings.


Selected Reading

Microsoft: Iranian hackers target researchers with new MediaPl malware (Bleeping Computer)

Cyber Safety Review Board needs stronger authorities, more independence, experts say (Cyberscoop)

VMware vCenter Server Vulnerability Exploited in Wild (SecurityWeek)

ELO accounting data breach sparks tax fraud (Cybernews)

Cyber attacks on Kent councils disrupt online services (BBC)

Kansas State University suffered a serious cybersecurity incident (SecurityAffairs)

CISA urges urgent patching of two actively exploited Citrix NetScaler vulnerabilities (Malwarebytes)

Cyber Insurance in the Age of Ransomware: Protection or Provocation? (SOCRadar)

Four-in-ten employees sacked over email security breaches as firms tackle “truly staggering” increase in attacks (IT Pro)

Think boomers are most vulnerable to cybersecurity attacks? Wrong. It's actually Gen Z (CBC)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2024 N2K Networks, Inc.

More description

Microsoft warns of an Iranian cyberespionage group. The CyberSafety Review Board receives critical reviews of its own. VMWare warns of active product exploitation. Tax info gets leaked in accounting firm breach. Kansas State University reports a cyber incident. CISA adds Citrix Netscaler vulnerabilities to its Known Exploited Vulnerabilities catalog. Councils in the UK suffer online disruptions. Cyber insurance can be a double edged sword. More email security breaches lead to firings. In our Solution Spotlight, N2K President Simone Petrella speaks with Michelle Amante of the Partnership for Public Service With an update on the Cybersecurity Talent Initiative. And it’s shields up for Generation Z.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

On the Solution Spotlight, N2K President Simone Petrella speaks with Michelle Amante of the Partnership for Public Service sharing an update on the Cybersecurity Talent Initiative and how federal agencies and early career existing talent that may be interested in the program’s offerings.


Selected Reading

Microsoft: Iranian hackers target researchers with new MediaPl malware (Bleeping Computer)

Cyber Safety Review Board needs stronger authorities, more independence, experts say (Cyberscoop)

VMware vCenter Server Vulnerability Exploited in Wild (SecurityWeek)

ELO accounting data breach sparks tax fraud (Cybernews)

Cyber attacks on Kent councils disrupt online services (BBC)

Kansas State University suffered a serious cybersecurity incident (SecurityAffairs)

CISA urges urgent patching of two actively exploited Citrix NetScaler vulnerabilities (Malwarebytes)

Cyber Insurance in the Age of Ransomware: Protection or Provocation? (SOCRadar)

Four-in-ten employees sacked over email security breaches as firms tackle “truly staggering” increase in attacks (IT Pro)

Think boomers are most vulnerable to cybersecurity attacks? Wrong. It's actually Gen Z (CBC)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2024 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere

A massive credential dump hits the online underground. CISA and the FBI issue joint guidance on drones. TensorFlow frameworks are prone to misconfigurations. Swiss federal agencies are targets of nuisance DDoS. Cybercriminals hit vulnerable Docker servers. Quarkslab identifies PixieFAIL in UEFI implementations. Google patches Chrome zero-day. The Bigpanzi botnet infects smart TVs. Proofpoint notes the return of TA866. In our Threat Vector segment, David Moulton dives into the evolving world of AI in cybersecurity with Kyle Wilhoit, director of threat research at Unit 42. And we are shocked- SHOCKED! - to learn that Facebook is tracking us. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

This segment of Threat Vector dives into the evolving world of AI in cybersecurity with Kyle Wilhoit, director of threat research at Unit 42. This thought-provoking discussion, hosted by David Moulton, director of thought leadership at Unit 42, ffocuses on the current state and future trends of AI in cyberthreats. Discover how AI is reshaping the landscape of cyberattacks, the role of generative AI in threat actor tactics, and the challenges of attribution in AI-driven cyberattacks. Visit Unit 42 by Palo Alto Networks to learn more. 

Check out the Threat Vector podcast and follow it on your favorite podcast app. 


Selected Reading

Researcher uncovers one of the biggest password dumps in recent history (Ars Technica)

Troy Hunt: Inside the Massive Naz.API Credential Stuffing List (Troy Hunt)

Feds warn China-made drones pose risk to US critical infrastructure (SC Media)

TensorFlow CI/CD Flaw Exposed Supply Chain to Poisoning Attacks (The Hacker News)

Swiss Government Reports Nuisance-Level DDoS Disruptions (Data Breach Today)

Malware Exploits 9Hits, Turns Docker Servers into Traffic Boosted Crypto Miners (HACKREAD)

PixieFail: Nine flaws in UEFI open-source reference implementation (Security Affairs)

Update Chrome! Google patches actively exploited zero-day vulnerability (Malwarebytes)

Cybercrime crew infects 172,000 smart TVs and set-top boxes (Risky Biz News)

Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware (Google Threat Analysis Group)

Security Brief: TA866 Returns with a Large Email Campaign (Proofpoint)

Each Facebook User Is Monitored by Thousands of Companies (Consumer Reports)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

A massive credential dump hits the online underground. CISA and the FBI issue joint guidance on drones. TensorFlow frameworks are prone to misconfigurations. Swiss federal agencies are targets of nuisance DDoS. Cybercriminals hit vulnerable Docker servers. Quarkslab identifies PixieFAIL in UEFI implementations. Google patches Chrome zero-day. The Bigpanzi botnet infects smart TVs. Proofpoint notes the return of TA866. In our Threat Vector segment, David Moulton dives into the evolving world of AI in cybersecurity with Kyle Wilhoit, director of threat research at Unit 42. And we are shocked- SHOCKED! - to learn that Facebook is tracking us. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

This segment of Threat Vector dives into the evolving world of AI in cybersecurity with Kyle Wilhoit, director of threat research at Unit 42. This thought-provoking discussion, hosted by David Moulton, director of thought leadership at Unit 42, ffocuses on the current state and future trends of AI in cyberthreats. Discover how AI is reshaping the landscape of cyberattacks, the role of generative AI in threat actor tactics, and the challenges of attribution in AI-driven cyberattacks. Visit Unit 42 by Palo Alto Networks to learn more. 

Check out the Threat Vector podcast and follow it on your favorite podcast app. 


Selected Reading

Researcher uncovers one of the biggest password dumps in recent history (Ars Technica)

Troy Hunt: Inside the Massive Naz.API Credential Stuffing List (Troy Hunt)

Feds warn China-made drones pose risk to US critical infrastructure (SC Media)

TensorFlow CI/CD Flaw Exposed Supply Chain to Poisoning Attacks (The Hacker News)

Swiss Government Reports Nuisance-Level DDoS Disruptions (Data Breach Today)

Malware Exploits 9Hits, Turns Docker Servers into Traffic Boosted Crypto Miners (HACKREAD)

PixieFail: Nine flaws in UEFI open-source reference implementation (Security Affairs)

Update Chrome! Google patches actively exploited zero-day vulnerability (Malwarebytes)

Cybercrime crew infects 172,000 smart TVs and set-top boxes (Risky Biz News)

Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware (Google Threat Analysis Group)

Security Brief: TA866 Returns with a Large Email Campaign (Proofpoint)

Each Facebook User Is Monitored by Thousands of Companies (Consumer Reports)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere

Bryce Kennedy, President of the Association of Commercial Space Professionals (ACSP), is sharing what is on horizon in space law. Bryce is also a space lawyer and a regular contributor to our T-Minus daily space podcast right here on the N2K podcast network.

You can hear more from the T-Minus space daily show here.

While this show covers legal topics, and Ben is a lawyer, the views expressed do not constitute legal advice. For official legal advice on any of the topics we cover, please contact your attorney. 

Caveat Briefing

A companion weekly newsletter is available CyberWire Pro members on the CyberWire's website. If you are a member, make sure you subscribe to receive our weekly wrap-up of privacy, policy, and research news, focused on incidents, techniques, tips, compliance, rights, trends, threats, policy, and influence ops delivered to you inbox each Thursday.

Got a question you'd like us to answer on our show? You can send your audio file to caveat@thecyberwire.com. Hope to hear from you.

More description

Bryce Kennedy, President of the Association of Commercial Space Professionals (ACSP), is sharing what is on horizon in space law. Bryce is also a space lawyer and a regular contributor to our T-Minus daily space podcast right here on the N2K podcast network.

You can hear more from the T-Minus space daily show here.

While this show covers legal topics, and Ben is a lawyer, the views expressed do not constitute legal advice. For official legal advice on any of the topics we cover, please contact your attorney. 

Caveat Briefing

A companion weekly newsletter is available CyberWire Pro members on the CyberWire's website. If you are a member, make sure you subscribe to receive our weekly wrap-up of privacy, policy, and research news, focused on incidents, techniques, tips, compliance, rights, trends, threats, policy, and influence ops delivered to you inbox each Thursday.

Got a question you'd like us to answer on our show? You can send your audio file to caveat@thecyberwire.com. Hope to hear from you.

Extract Knowledge
Listen elsewhere

Atlassian issues critical updates. CISA and the FBI warn of AndroxGh0st. A GPU vulnerability hits major manufacturers. A Foxconn subsidiary in Taiwan gets hacked. Australians suffer breached credit cards through credential stuffing. A parade of horrible hackers and scammers. CISO accountability is highlighted at ShmooCon. Cybersecurity VC funding plummets. On the Learning Layer, N2K’s Executive Director of Product Innovation Sam Meisenberg lets us in on an A+ tutoring session. Don’t ask ChatGPT to handle your Amazon product listings. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

On the Learning Layer with N2K’s Executive Director of Product Innovation Sam Meisenberg lets us in on an A+ tutoring session he held with Jaden Dicks.


Selected Reading

Atlassian’s Confluence Data Center and Server Affected by Critical RCE Vulnerability, CVE-2023-22527: Patch Now (SOCRadar)

FBI, CISA warn of AndroxGh0st botnet for victim identification and exploitation (Security Affairs)

A new vulnerability affecting Apple, AMD, and Qualcomm GPUs could expose AI data (TechSpot)

Taiwan’s Foxconn subsidiary faces cyberattack (Taiwan News)

15,000 Aussies Affected After Binge, The Iconic Hacked (Pedestrian)

Hackers post disturbing videos to online forum used by UC Irvine students (ABC7)

Heartless scammers prey on hundreds of lost pet owners, demanding ransoms or else… (Bitdefender)

As hacks worsen, SEC turns up the heat on CISOs (TechCrunch)

Cybersecurity Startup Funding Hits 5-Year Low, Drops 50% From 2022 (Crunchbase)

Amazon Is Selling Products With AI-Generated Names Like "I Cannot Fulfill This Request It Goes Against OpenAI Use Policy" (Futurism)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

Atlassian issues critical updates. CISA and the FBI warn of AndroxGh0st. A GPU vulnerability hits major manufacturers. A Foxconn subsidiary in Taiwan gets hacked. Australians suffer breached credit cards through credential stuffing. A parade of horrible hackers and scammers. CISO accountability is highlighted at ShmooCon. Cybersecurity VC funding plummets. On the Learning Layer, N2K’s Executive Director of Product Innovation Sam Meisenberg lets us in on an A+ tutoring session. Don’t ask ChatGPT to handle your Amazon product listings. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

On the Learning Layer with N2K’s Executive Director of Product Innovation Sam Meisenberg lets us in on an A+ tutoring session he held with Jaden Dicks.


Selected Reading

Atlassian’s Confluence Data Center and Server Affected by Critical RCE Vulnerability, CVE-2023-22527: Patch Now (SOCRadar)

FBI, CISA warn of AndroxGh0st botnet for victim identification and exploitation (Security Affairs)

A new vulnerability affecting Apple, AMD, and Qualcomm GPUs could expose AI data (TechSpot)

Taiwan’s Foxconn subsidiary faces cyberattack (Taiwan News)

15,000 Aussies Affected After Binge, The Iconic Hacked (Pedestrian)

Hackers post disturbing videos to online forum used by UC Irvine students (ABC7)

Heartless scammers prey on hundreds of lost pet owners, demanding ransoms or else… (Bitdefender)

As hacks worsen, SEC turns up the heat on CISOs (TechCrunch)

Cybersecurity Startup Funding Hits 5-Year Low, Drops 50% From 2022 (Crunchbase)

Amazon Is Selling Products With AI-Generated Names Like "I Cannot Fulfill This Request It Goes Against OpenAI Use Policy" (Futurism)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Published 2024-01-16

Vulnerabilities and security risks.

26 min
View

Ivanti products are under active zero-day exploitation. Phemedrone is a new open-source info-stealer. Bishop Fox finds exposed SonicWall firewalls. GitLab and VMware patch critical vulnerabilities. The Secret Service foils a phishing scam. Europol shuts down a cryptojacking campaign. Ransomware hits a Majorca municipality. RUSI looks at ransomware. Ben Yelin explains the New York Times going after OpenAI over the data scraping. And the sad case of an Ohio lottery winner. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Guest and partner Ben Yelin joins us today to discuss “The Most Critical Elements of the FTC’s Health Breach Rulemaking.” Ben is the Program Director for Public Policy & External Affairs at the University of Maryland Center for Health and Homeland Security and Co-Host of N2K’s Caveat Podcast.


Selected Reading

Ivanti Connect Secure zero-days now under mass exploitation (Bleeping Computer)

Windows SmartScreen flaw exploited to drop Phemedrone malware (Bleeping Computer)

Over 178,000 SonicWall next-generation firewalls (NGFW) online exposed to hack (Security Affairs)

GitLab Fixes Password Reset Bug That Allows Account Takeover (Security Boulevard)

Patches Available for a Critical Vulnerability in VMware Aria Automation: CVE-2023-34063 (Malware News)

US court docs expose fake antivirus renewal phishing tactics (Bleeping Computer)

Hacker spins up 1 million virtual servers to illegally mine crypto (Bleeping Computer)

Ransomware gang demands €10 million after attacking Spanish council (The Record)

Ransomware: Victim Insights on Harms to Individuals, Organisations and Society (Royal United Services Institute)

Cybersecurity incident delays payouts for big Ohio Lottery winners (Beacon Journal)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

Ivanti products are under active zero-day exploitation. Phemedrone is a new open-source info-stealer. Bishop Fox finds exposed SonicWall firewalls. GitLab and VMware patch critical vulnerabilities. The Secret Service foils a phishing scam. Europol shuts down a cryptojacking campaign. Ransomware hits a Majorca municipality. RUSI looks at ransomware. Ben Yelin explains the New York Times going after OpenAI over the data scraping. And the sad case of an Ohio lottery winner. 

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

Guest and partner Ben Yelin joins us today to discuss “The Most Critical Elements of the FTC’s Health Breach Rulemaking.” Ben is the Program Director for Public Policy & External Affairs at the University of Maryland Center for Health and Homeland Security and Co-Host of N2K’s Caveat Podcast.


Selected Reading

Ivanti Connect Secure zero-days now under mass exploitation (Bleeping Computer)

Windows SmartScreen flaw exploited to drop Phemedrone malware (Bleeping Computer)

Over 178,000 SonicWall next-generation firewalls (NGFW) online exposed to hack (Security Affairs)

GitLab Fixes Password Reset Bug That Allows Account Takeover (Security Boulevard)

Patches Available for a Critical Vulnerability in VMware Aria Automation: CVE-2023-34063 (Malware News)

US court docs expose fake antivirus renewal phishing tactics (Bleeping Computer)

Hacker spins up 1 million virtual servers to illegally mine crypto (Bleeping Computer)

Ransomware gang demands €10 million after attacking Spanish council (The Record)

Ransomware: Victim Insights on Harms to Individuals, Organisations and Society (Royal United Services Institute)

Cybersecurity incident delays payouts for big Ohio Lottery winners (Beacon Journal)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere

In this special edition of Solution Spotlight, N2K President, Simone Petrella is talking with ISC2 CEO Clar Rosso about putting a dent in the cybersecurity workforce gap through empowerment, breaking down barriers and expanding DE&I initiatives.

More description

In this special edition of Solution Spotlight, N2K President, Simone Petrella is talking with ISC2 CEO Clar Rosso about putting a dent in the cybersecurity workforce gap through empowerment, breaking down barriers and expanding DE&I initiatives.

Extract Knowledge
Listen elsewhere

In this encore episode of CyberWire-X, N2K’s CSO, Chief Analyst, and Senior Fellow, Rick Howard, is joined by guest Rohit Dhamankar, Fortra's Vice President of Product Strategy, and Hash Table member Steve Winterfeld, Akamai's Advisory CISO to discuss CISO initiatives such as vendor consolidation, automation, and attack surface management as a way to determine if it’s possible to achieve both increased security maturity and decreased operational load. This session covers common mistakes when adopting security technologies, including the pros and cons of AI, and how to better collaborate together.

More description

In this encore episode of CyberWire-X, N2K’s CSO, Chief Analyst, and Senior Fellow, Rick Howard, is joined by guest Rohit Dhamankar, Fortra's Vice President of Product Strategy, and Hash Table member Steve Winterfeld, Akamai's Advisory CISO to discuss CISO initiatives such as vendor consolidation, automation, and attack surface management as a way to determine if it’s possible to achieve both increased security maturity and decreased operational load. This session covers common mistakes when adopting security technologies, including the pros and cons of AI, and how to better collaborate together.

Extract Knowledge
Listen elsewhere

Vice President of Marketing, Kathleen Booth, shares her career path from political science and international development to marketing for a cybersecurity company. Early dreams of acting morphed into goals of making the world a better place. Chief marketer and podcaster Kathleen is doing just that. She shares how proving your worth can lead to success. Listen for Kathleen's advice on getting your foot in the door. Our thanks to Kathleen for sharing her story with us. 

More description

Vice President of Marketing, Kathleen Booth, shares her career path from political science and international development to marketing for a cybersecurity company. Early dreams of acting morphed into goals of making the world a better place. Chief marketer and podcaster Kathleen is doing just that. She shares how proving your worth can lead to success. Listen for Kathleen's advice on getting your foot in the door. Our thanks to Kathleen for sharing her story with us. 

Extract Knowledge
Listen elsewhere

Ryan Westman, Senior Manager, Threat Intelligence, eSentire's Threat Response Unit (TRU), is discussing their research "Two Russian-speaking cyber gangs attack employees from 23 different companies." They are using malicious Google ads, promoting popular business software such as Zoom, Slack, and Adobe.

The customers targeted are companies in the manufacturing, software, legal, retail and healthcare industries. The attacking threat actors belong to the Russian-speaking Malware-as-a-Service (MaaS) groups called BatLoader and FakeBat.

The research can be found here:

More description

Ryan Westman, Senior Manager, Threat Intelligence, eSentire's Threat Response Unit (TRU), is discussing their research "Two Russian-speaking cyber gangs attack employees from 23 different companies." They are using malicious Google ads, promoting popular business software such as Zoom, Slack, and Adobe.

The customers targeted are companies in the manufacturing, software, legal, retail and healthcare industries. The attacking threat actors belong to the Russian-speaking Malware-as-a-Service (MaaS) groups called BatLoader and FakeBat.

The research can be found here:

Extract Knowledge
Listen elsewhere
Published 2024-01-12

Casting a wider hiring net.

29 min
View

The Feds look to cast a wider hiring net. Legislators focus on deepfakes. Cookie stealers bypass MFA on Google accounts. A Fast food hiring chat bot got hacked. Medusa casts her gaze toward extortion. Akira ransomware is active in Finland. GitLab patches critical vulnerabilities. Bosch thermostats are vulnerable to some hot firmware. CSAM vendors’ crypto sophistication grows. CISA released ICS advisories. On our Solution Spotlight, N2K’s Simone Petrella speaks with Kim Jones, Director of Intuit's CyberCRAFT team, about the SEC's heightened focus on cybersecurity. And a little listener feedback, Karaoke style.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

On our Solution Spotlight, N2K’s Simone Petrella discusses a possible hurdle with Kim Jones, Director of Intuit's CyberCRAFT team. They talk about the SEC's heightened focus on cybersecurity.


Selected Reading

An analysis of cyberattacks against Danish energy infrastructure. Cryptomining campaign targets weak SSH passwords. (CyberWire)

White House moves to ease education requirements for federal cyber contracting jobs (CyberScoop)

State Legislators Tighten A.I. Rules to Combat Deceptive Election Ads (New York Times)

Info-stealers can steal cookies for permanent access to your Google account (Malwarebytes)

Hackers Break into AI Hiring Chatbot, Could Hire and Reject Fast Food Applicants (404 Media)

Medusa Ransomware Turning Your Files into Stone (Unit 42 by Palo Alto Networks)

Akira ransomware attackers are wiping NAS and tape backups  (Help Net Security)

Urgent: GitLab Releases Patch for Critical Vulnerabilities - Update ASAP (The Hacker News)

Vulnerability Puts Bosch Smart Thermostats at Risk of Compromise (Infosecurity Magazine)

Child Abusers Are Getting Better at Using Crypto to Cover Their Tracks (WIRED)

CISA Releases Nine Industrial Control Systems Advisories (CISA)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

More description

The Feds look to cast a wider hiring net. Legislators focus on deepfakes. Cookie stealers bypass MFA on Google accounts. A Fast food hiring chat bot got hacked. Medusa casts her gaze toward extortion. Akira ransomware is active in Finland. GitLab patches critical vulnerabilities. Bosch thermostats are vulnerable to some hot firmware. CSAM vendors’ crypto sophistication grows. CISA released ICS advisories. On our Solution Spotlight, N2K’s Simone Petrella speaks with Kim Jones, Director of Intuit's CyberCRAFT team, about the SEC's heightened focus on cybersecurity. And a little listener feedback, Karaoke style.

Remember to leave us a 5-star rating and review in your favorite podcast app.

Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.


CyberWire Guest

On our Solution Spotlight, N2K’s Simone Petrella discusses a possible hurdle with Kim Jones, Director of Intuit's CyberCRAFT team. They talk about the SEC's heightened focus on cybersecurity.


Selected Reading

An analysis of cyberattacks against Danish energy infrastructure. Cryptomining campaign targets weak SSH passwords. (CyberWire)

White House moves to ease education requirements for federal cyber contracting jobs (CyberScoop)

State Legislators Tighten A.I. Rules to Combat Deceptive Election Ads (New York Times)

Info-stealers can steal cookies for permanent access to your Google account (Malwarebytes)

Hackers Break into AI Hiring Chatbot, Could Hire and Reject Fast Food Applicants (404 Media)

Medusa Ransomware Turning Your Files into Stone (Unit 42 by Palo Alto Networks)

Akira ransomware attackers are wiping NAS and tape backups  (Help Net Security)

Urgent: GitLab Releases Patch for Critical Vulnerabilities - Update ASAP (The Hacker News)

Vulnerability Puts Bosch Smart Thermostats at Risk of Compromise (Infosecurity Magazine)

Child Abusers Are Getting Better at Using Crypto to Cover Their Tracks (WIRED)

CISA Releases Nine Industrial Control Systems Advisories (CISA)


Share your feedback.

We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 


Want to hear your company in the show?

You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.

The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Extract Knowledge
Listen elsewhere
Show details
Episodes
3784
Transcripts
67
2% coverage
Missing transcripts
3717
With chapters
0