CyberWire Daily

No quick fix for a ClickFix attack.

6 snips
May 12, 2025
Tim Starks, Senior Reporter at CyberScoop, sheds light on the recent ClickFix social engineering attack impacting a major student platform. He discusses Google’s hefty privacy settlement with Texas and alarming data breaches affecting healthcare providers. The conversation dives into the zero-day vulnerabilities in SAP and cybersecurity threats facing IT admins. Additionally, Starks analyzes congressional reactions to proposed CISA budget cuts and their potential consequences on national security amid escalating cyber threats.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

ClickFix Attack on iClicker

  • The iClicker student engagement platform was compromised by a ClickFix social engineering attack using a fake CAPTCHA.
  • The attack installed malware by tricking users into running a malicious PowerShell script that stole credentials and browser data.
INSIGHT

CISA Budget Cut Controversy

  • The Biden administration proposes a nearly 17% budget cut to CISA, stirring criticism and confusion among lawmakers.
  • Lawmakers doubt the rationale behind cuts citing ongoing cyber threats from China and Russia that require robust cybersecurity.
INSIGHT

Potential Illegality of CISA Cuts

  • Senator Murphy claims the proposed cuts to CISA could be illegal because they ignore congressional mandates.
  • Cuts already affecting personnel and programs show a concerning pattern of underfunding this critical cyber defense agency.
Get the Snipd Podcast app to discover more snips from this episode
Get the app