CyberWire Daily

One flaw to rule the root.

Sep 30, 2025
CISA sounds the alarm over a critical sudo vulnerability that could lead to privilege escalation. South Korea escalates its cyber threat level after a data center fire raises concerns. Microsoft disrupts an AI-enhanced phishing campaign using malicious SVGs, while landlords face accusations of scraping sensitive payroll data. Cybercriminals prepare for potential FIFA fraud leading up to 2026. Plus, insights into the evolution of hacker culture and the burnout impacting cybersecurity professionals.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ADVICE

Urgent Sudo Patch Action

  • Identify systems running vulnerable sudo versions and apply vendor patches immediately or disable the chroot option until fixes are available.
  • Treat CISA's listing as mandatory mitigation and meet the October 20th remediation deadline.
INSIGHT

VMware Still A High-Value Target

  • VMware products continue to be frequent targets for state-sponsored groups and cybercrime gangs.
  • Patching NSX, vCenter, and related tools remains critical due to username enumeration and privilege risks.
ANECDOTE

Nation Raises Threat After Datacenter Fire

  • South Korea raised its national cyber threat level after a data center fire damaged hundreds of government systems.
  • The president apologized for poor backups as restoration of destroyed systems will take weeks.
Get the Snipd Podcast app to discover more snips from this episode
Get the app