CyberWire Daily

Chalk one up for defenders.

Sep 9, 2025
Kevin Magee, Global Director of Cybersecurity Startups at Microsoft Security, discusses the pressing need for cybersecurity education amidst rising threats. He highlights a recent npm supply chain attack and the open source community's rapid response. Magee emphasizes bridging the skills gap in cybersecurity, advocating for specialized pathways to nurture new talent. The conversation also touches on the humorous missteps currently seen in AI, warning against over-reliance on this technology.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Open-Source Response Prevented Major NPM Losses

  • Rapid community response limited a major npm supply-chain attack to hours and minimal losses.
  • Open-source collaboration proved a strong defense against sophisticated malicious package pushes.
INSIGHT

Sanctions Target Scam Centers And Forced Labor

  • The U.S. Treasury sanctioned networks behind billion-dollar scam centers tied to forced labor in Myanmar and Cambodia.
  • Sanctions target operators profiting from human trafficking and industrial-scale fraud operations.
INSIGHT

Calendar Invites Used To Evade Filters

  • Scammers abused iCloud calendar invites to embed fake payment alerts that bypass spam filters.
  • Apple warns users to treat calendar invites with the same suspicion as emails to avoid callback phishing scams.
Get the Snipd Podcast app to discover more snips from this episode
Get the app