Cyber Security Headlines

Week in Review: Disabling Microsoft Defender, corrupted power inverters, bipartisan training bill

7 snips
May 23, 2025
In this engaging conversation, George Finney, CISO at The University of Texas System and author focused on cybersecurity habits, tackles pressing issues in the field. He discusses the need for a zero trust approach, particularly in the wake of malware evasion tactics. The episode sheds light on vulnerabilities in Chinese-made power inverters that threaten national security. Furthermore, Finney emphasizes the integration of cybersecurity in HR practices and the importance of enhancing cybersecurity training to combat insider threats and other evolving risks.
Ask episode
AI Snips
Chapters
Books
Transcript
Episode notes
INSIGHT

Windows Defender Loophole Exploited

  • Microsoft Defender can be disabled by registering a fake antivirus using an undocumented Windows Security Center API.
  • This loophole highlights Windows disabling Defender automatically to avoid conflicts, which attackers may exploit.
INSIGHT

Chinese Power Inverters Security Risk

  • Chinese-made power inverters in US solar farms include hidden kill switches and cellular radios not in documentation.
  • This poses a national security risk allowing remote disabling of critical infrastructure during conflict.
ADVICE

Cybersecurity Training for HR

  • Train HR teams specifically to understand cybersecurity threats, including vetting resumes and interviews.
  • Incorporate cybersecurity awareness early in hiring to prevent risks from fake accounts and deepfakes.
Get the Snipd Podcast app to discover more snips from this episode
Get the app