
 CyberWire Daily Code beneath the sand.
 Sep 17, 2025 
 In this discussion, Abhishek Agrawal, CEO and co-founder of Material Security, delves into the complexities of securing Google Workspace. He highlights the importance of identity as the perimeter and addresses issues like data sprawl and the challenges of built-in data loss prevention tools. Abhishek emphasizes the need for prioritization, automation, and effective use of APIs to strengthen defenses against threats like lateral movement and persistent attacks. It's an enlightening conversation about modern security strategies in a cloud-driven world. 
 AI Snips 
 Chapters 
 Books 
 Transcript 
 Episode notes 
Self‑Propagating NPM Worm Exposes Dev Supply Chain
- The Shai Halud worm self-propagates in NPM by harvesting tokens and publishing poisoned packages.
 - Researchers warn stronger 2FA for package publishing is needed to stop similar outbreaks.
 
Disrupt Phishing By Seizing Infrastructure
- Use legal and technical takedowns to disrupt phishing platforms as Microsoft and Cloudflare did.
 - Track payments and refer leaders to law enforcement to cut off criminal revenue and infrastructure.
 
APTs Abuse Legitimate Cloud Services
- Fancy Bear blends malicious Office macros with legitimate cloud services for stealth and persistence.
 - Attackers use open-source tools and cloud storage to host command-and-control and exfiltrated data.
 



