CyberWire Daily

Stomping out critical bugs.

Nov 6, 2025
Dr. Sasha O'Connell, Senior Director for Cybersecurity Programs at Aspen Digital and former FBI official, delves into the Aspen Cyber Summit's mission and ten years of cybersecurity progress. She discusses pressing issues like critical software vulnerabilities, CISA's controversial layoffs, and the return of Gootloader malware. O'Connell debates the complexities of offensive cyber operations and emphasizes the need for public education on cyber threats. Her insights illuminate the evolving landscape of cybersecurity policy.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Critical Cisco UCCX Vulnerabilities

  • Cisco patched two critical UCCX flaws enabling unauthenticated root and admin-level command execution.
  • Customers should treat these as urgent infrastructure risks even if no active exploitation is reported.
ADVICE

Immediate Fixes For CentOS Web Panel Flaw

  • Patch or isolate affected Control Web Panel (CentOS Web Panel) instances immediately to prevent remote command injection.
  • Restrict access to trusted networks and run compromise assessments if internet-facing CWP is in use.
INSIGHT

Gootloader Returns With New Evasion

  • Gootloader resurfaced using SEO poisoning and sophisticated evasion like custom fonts and malformed zips.
  • Its campaign now delivers loaders, Cobalt Strike, and backdoors tied to ransomware affiliates.
Get the Snipd Podcast app to discover more snips from this episode
Get the app