CyberWire Daily

Open source, open target.

27 snips
Jul 31, 2025
In this discussion, Ann Galchutt, Technical Lead at CISA, sheds light on their groundbreaking open-source eviction strategy tool aimed at enhancing cyber incident response. She reveals how the tool addresses vulnerabilities exposed by major malware campaigns, including those from North Korea's Lazarus Group. The conversation also highlights the importance of community collaboration and proactive measures in refining incident response strategies. Jermaine Roebuck from CISA joins her to emphasize a new approach to tackling emerging cyber threats, including clever mobile malware.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Lazarus Group Targets Open Source

  • North Korea's Lazarus Group targets open source ecosystems with espionage malware.
  • Developers' habit of installing packages without vetting creates a new key cyber battleground.
INSIGHT

Prompt Injection Threat in LLMs

  • Browser extensions can inject malicious prompts into AI tools, leading to data leaks.
  • Traditional security tools cannot detect this, making it a major blind spot in LLM security.
INSIGHT

New Attribution Framework Enhances Clarity

  • Unit 42's new attribution framework systematizes cyber threat attribution with scoring and evidence.
  • It seeks to improve consistency and reduce analyst confusion in threat naming.
Get the Snipd Podcast app to discover more snips from this episode
Get the app