CyberWire Daily

Proton66’s malware highway.

Apr 22, 2025
Bob Maley, CSO of Black Kite, shares his expertise on the escalating risks of third-party cyber incidents. The conversation dives into the nefarious activities of the Russian group Proton66 and emerging threats like a new Rust-based botnet targeting routers. Maley emphasizes the impact of CISA budget cuts and the rise of ransomware in healthcare. Additionally, the relaunch of the cybercrime marketplace Cracked raises alarms about compliance risks and the need for improved cybersecurity measures across industries.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Silent Danger of Third-Party Breaches

  • Third-party breaches often occur silently with attackers lurking before exfiltration or ransomware deployment.
  • These breaches pose huge risks as attackers pivot from compromised vendors to many other companies.
ADVICE

Adopt Attacker Mindset for Risk

  • Shift to an outside-in security view by proactively assessing the external attack surface of your vendors.
  • Think like an attacker to better understand and reduce third-party risk.
ADVICE

Modernize Third-Party Risk Assessments

  • Move beyond traditional questionnaires for vendor risk assessments; seek real-time, continuous evaluations.
  • Embrace agile and modern approaches as cloud adoption expands your attack surface dramatically.
Get the Snipd Podcast app to discover more snips from this episode
Get the app