CyberWire Daily

Exchange hybrid flaw raises cloud alarm.

15 snips
Aug 7, 2025
Ryan Whelan, Managing Director and Global Head of Cyber Intelligence at Accenture, joins to discuss critical cybersecurity topics emerging from Black Hat. He highlights a severe vulnerability in Microsoft Exchange Server and its implications for hybrid deployments. The alarming rise in data breaches affecting major organizations, including a Dutch airline and a French telecom, is addressed. Whelan also shares insights on evolving cyber threats like zero-click attacks and the notorious VexTrio cybercrime network, emphasizing the importance of community collaboration in cybersecurity.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Exchange Hybrid Vulnerability Risk

  • Microsoft warns of a high-severity vulnerability in hybrid Exchange Server setups that enables privilege escalation to Exchange Online.
  • Attackers can exploit shared service principals to forge tokens undetected, bypassing cloud security logs.
INSIGHT

HTTP Request Smuggling Impact

  • New HTTP request smuggling variants exploit desyncs between front-end and back-end servers to inject malicious code.
  • These attacks impact major organizations and CDNs, enabling session theft and cache poisoning.
INSIGHT

Spyware Company Evades Sanctions

  • Israeli spyware maker Kandiru may have rebranded to evade U.S. sanctions while continuing operations globally.
  • Such spyware firms use tactics like rebranding and jurisdiction hopping to circumvent export controls.
Get the Snipd Podcast app to discover more snips from this episode
Get the app