CyberWire Daily

Media server mayday.

39 snips
Aug 15, 2025
Randall Degges, Head of Developer and Security Relations at Snyk, sheds light on the perils of underqualified coding support and its potential to invite nation-state threats. He discusses the urgent security vulnerabilities that prompted Plex to advise immediate updates. Delving into critical breaches, he highlights the illicit market for compromised government email accounts. Degges also emphasizes the role of proactive security in software development, warning against prioritizing speed over safety and exploring the twin challenges posed by generative AI.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ADVICE

Patch Immediately On Vendor Urgent Alerts

  • Update Plex Media Server immediately when the vendor issues an urgent patch even if details are withheld.
  • Attackers can reverse-engineer patches to exploit unpatched systems, so patch fast.
ADVICE

Mitigate Cisco RCE By Disabling RADIUS

  • If you run Cisco Secure Firewall Management Center with RADIUS enabled, update immediately and consider disabling RADIUS if you cannot patch.
  • Use local LDAP or SAML authentication as a mitigation because no direct workaround exists.
INSIGHT

ICS Flaws Span Wide Attack Surfaces

  • Industrial control product vulnerabilities span token validation bypass to remote code execution across vendors.
  • Even without reported exploitation, ICS flaws pose systemic risks and demand urgent review.
Get the Snipd Podcast app to discover more snips from this episode
Get the app