Security Now (Audio)

SN 1047: RediShell's CVSS 10.0 - The Rise of Mega Botnets

20 snips
Oct 15, 2025
Texas may require Apple and Google to enforce strict age verification for app downloads, sparking privacy concerns. The EU has postponed a controversial chat control vote, while Salesforce refuses to pay a ransomware demand, leading to a data leak. A Discord breach exposes 70,000 government IDs, and Microsoft prepares to move GitHub to Azure. Plus, a massive botnet targets U.S. RDP services, and experts critique the usability of iOS 26's new interface. Finally, a critical vulnerability in Redis servers demands urgent attention.
Ask episode
AI Snips
Chapters
Books
Transcript
Episode notes
ADVICE

Refuse Ransom Payments

  • Do not pay ransomware extortion demands as a matter of policy; Salesforce refused to pay.
  • Expect data to be leaked after public extortion, so prepare incident response and notify affected customers.
INSIGHT

Third-Party Support Risk

  • Attackers used a compromised BPO support account to access Discord's support platform and exfiltrate 1.6 TB of tickets.
  • API integrations magnified the breach by enabling mass queries into Discord's internal systems.
ADVICE

Turn On Global Privacy Control

  • Enable Global Privacy Control (GPC) or use a browser that emits it to signal opt-out preferences.
  • Expect enforcement to follow legal adoption, so browsers should implement GPC support proactively.
Get the Snipd Podcast app to discover more snips from this episode
Get the app