CyberWire Daily

Code beneath the sand.

Sep 17, 2025
In this discussion, Abhishek Agrawal, CEO and co-founder of Material Security, delves into the complexities of securing Google Workspace. He highlights the importance of identity as the perimeter and addresses issues like data sprawl and the challenges of built-in data loss prevention tools. Abhishek emphasizes the need for prioritization, automation, and effective use of APIs to strengthen defenses against threats like lateral movement and persistent attacks. It's an enlightening conversation about modern security strategies in a cloud-driven world.
Ask episode
AI Snips
Chapters
Books
Transcript
Episode notes
INSIGHT

Self‑Propagating NPM Worm Exposes Dev Supply Chain

  • The Shai Halud worm self-propagates in NPM by harvesting tokens and publishing poisoned packages.
  • Researchers warn stronger 2FA for package publishing is needed to stop similar outbreaks.
ADVICE

Disrupt Phishing By Seizing Infrastructure

  • Use legal and technical takedowns to disrupt phishing platforms as Microsoft and Cloudflare did.
  • Track payments and refer leaders to law enforcement to cut off criminal revenue and infrastructure.
INSIGHT

APTs Abuse Legitimate Cloud Services

  • Fancy Bear blends malicious Office macros with legitimate cloud services for stealth and persistence.
  • Attackers use open-source tools and cloud storage to host command-and-control and exfiltrated data.
Get the Snipd Podcast app to discover more snips from this episode
Get the app