CISA’s Director Easterly plans to step down in the coming year. DHS issues recommendations for AI in critical infrastructure.Palo Alto Networks confirms active exploitation of a critical zero-day vulnerability in its firewalls. Threat actors exploit Microsoft’s 365 Admin Portal to send sextortion emails. A China-based APT targets a zero-day in Fortinet’s Windows VPN. The EPA reports on vulnerabilities in drinking water systems. A critical authentication bypass vulnerability affects a popular WordPress plugin. Researchers track a rise in the ClickFix social engineering technique. An 18 year old faces up to twenty years behind bars for swatting. Our guest is Rob Boyce, Global Lead, Cyber Resilience at Accenture, discussing SIM swapping services targeting telcos. Nuisance calls are in decline.
Remember to leave us a 5-star rating and review in your favorite podcast app.
Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.
CyberWire Guest
Today, we are joined by Rob Boyce, Global Lead, Cyber Resilience at Accenture, discussing SIM swapping services targeting telcos.
Selected Reading
CISA Director Jen Easterly to depart on Inauguration Day (Nextgov/FCW)
DHS Releases Secure AI Framework for Critical Infrastructure (Dark Reading)
Palo Alto firewalls exploited after critical zero-day vulnerability (Cybernews)
Microsoft 365 Admin portal abused to send sextortion emails (Bleeping Computer)
Fortinet VPN Zero-Day Exploited in Malware Attacks Remains Unpatched: Report (SecurityWeek)
300 Drinking Water Systems in US Exposed to Disruptive, Damaging Hacker Attacks (SecurityWeek)
Security plugin flaw in millions of WordPress sites gives admin access (Bleeping Computer)
Security Brief: ClickFix Social Engineering Technique Floods Threat Landscape (Proofpoint)
Teen serial swatter-for-hire busted, pleads guilty, could face 20 years (The Register)
FTC Records 50% Drop in Nuisance Calls Since 2021 (Infosecurity Magazine)
Share your feedback.
We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show.
Want to hear your company in the show?
You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.
The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Learn more about your ad choices. Visit megaphone.fm/adchoices