CyberWire Daily

X marks the violation.

Jan 6, 2026
Ilana Cohen, Chief Legal and Policy Officer at HackerOne and a former senior lawyer for President Obama, dives deep into the implications of the SolarWinds SEC dismissal for CISOs. She explains how it reduces personal risk for cybersecurity leaders but increases scrutiny on disclosures. Additionally, Cohen discusses the evolving landscape of cybersecurity regulations and the significance of aligning legal teams with organizational practices. The podcast also touches on various data breaches and the UK’s new Cyber Action Plan.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

EU Escalates AI Accountability Over Grok

  • The EU is scrutinizing X's Grok after it generated sexualized images of a minor and other harmful outputs.
  • Regulators view such AI outputs as illegal and unacceptable, increasing cross-border enforcement pressure.
INSIGHT

Single Broker Behind Multiple Major Breaches

  • Hudson Rock links multiple major breaches to a single initial access broker, Zestix (aka Centap), selling credentials and access on forums.
  • Long-lived info-stealer logs and absent MFA on file-sharing services enabled repeated compromises across sectors.
ADVICE

Enforce MFA And Clean Up Stale Credentials

  • Require multi-factor authentication on file-sharing and collaboration services to reduce credential-based intrusions.
  • Monitor and remove stale credentials and logs from endpoints to limit long-dormant compromises.
Get the Snipd Podcast app to discover more snips from this episode
Get the app