CyberWire Daily

CISA’s steady hand in a stalled senate.

Oct 31, 2025
Emily Austin, a Principal Security Researcher at Censys, sheds light on the alarming trends of nation-state attacks targeting critical infrastructure. She discusses how exposed devices and default credentials make these systems enticing targets. Key points include the dangers of remote access and the risks posed by specific devices like PLCs and building controls. Emily emphasizes the importance of proactive measures such as using VPNs and eliminating internet exposure to protect against these sophisticated threats.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Information Sharing Hasn't Collapsed

  • Information sharing between federal agencies and the private sector remains steady despite the lapse of CISA 2015.
  • CISA's reputation and long-term partnerships sustain cooperation, but reauthorization is considered vital to national cyber risk management.
ADVICE

Harden And Decommission Exchange Servers

  • Harden Microsoft Exchange by enabling MFA, limiting admin access, and enforcing TLS.
  • Decommission unsupported or hybrid Exchange servers after migration to reduce breach risk.
INSIGHT

Critical Linux NF Tables Exploited

  • A high-severity Linux netfilter (NF Tables) use-after-free is being exploited in ransomware campaigns to gain root.
  • Organizations unable to patch should block NF tables, restrict user namespaces, or load kernel runtime guard modules.
Get the Snipd Podcast app to discover more snips from this episode
Get the app