Cybersecurity Headlines

CISO Series
undefined
8 snips
Jan 19, 2026 • 8min

NSA dual-hat question, third-party report, GhostPoster extension continues

A nominee is set to evaluate the complex dual-hat leadership at Cyber Command and NSA, potentially reshaping cybersecurity strategy. A staggering 64% of third-party apps mishandle sensitive data, raising alarm bells. GhostPoster browser extensions have hit 840,000 installs, with malicious activities lurking within. Meanwhile, law enforcement targets Black Basta operators, and a major phishing breach impacts 750,000 Canadian investors. Grubhub admits to a data theft and extortion incident, further highlighting rising cyber threats.
undefined
13 snips
Jan 16, 2026 • 8min

Easterly helms RSAC, Windows update problems, Police Copilot gaffe

Jen Easterly is set to lead the RSA Conference, promising fresh insights. A recent Windows update caused major login issues for Azure Virtual Desktop users, creating headaches for IT teams. Meanwhile, the UK police mistakenly attributed an intelligence error to AI Copilot, sparking debates about AI's reliability. Guidance on securely connecting industrial control systems is highlighted by top agencies, and Kyo-won's ransomware incident has raised alarms over data exposure. Plus, a new technique reveals vulnerabilities in Copilot's session data.
undefined
20 snips
Jan 15, 2026 • 8min

U.S. weighs cyberwarfare options, DeadLock uses smart contracts to hide work, China says stop using US and Israeli cybersecurity software

The U.S. is exploring the possibility of allowing private companies to engage in offensive cyber operations, raising intriguing legal questions. Meanwhile, China has ordered its firms to stop using cybersecurity software from the U.S. and Israel. DeadLock is making waves by employing smart contracts to obscure its operations and threaten to sell stolen data. In other news, Microsoft has taken action against fraud stemming from the RedVDS platform, which has impacted real estate transactions severely. Finally, Poland successfully stopped a cyberattack aimed at its power grid, preventing a potential blackout.
undefined
Jan 14, 2026 • 7min

GoBruteforcer targets blockchain projects, Android bug causes volume key issues, Verizon to stop automatic phone unlocks

Cybersecurity issues abound as GoBruteforcer targets exposed Linux services to steal crypto from blockchain projects. A new Android bug disrupts accessibility features, causing volume keys to malfunction. In another twist, Verizon announces a halt to automatic phone unlocks, impacting new device activations. The landscape of digital security is ever-changing, and these updates are crucial for staying informed.
undefined
8 snips
Jan 13, 2026 • 9min

Instagram denies breach, Sweden detains spying suspect, n8n attack steals OAuth tokens

Instagram faces scrutiny as it denies a large-scale breach, labeling recent issues as bugs instead. In Sweden, a former IT consultant is detained over alleged spying activities tied to Russian intelligence. The n8n supply chain attack raises alarms as OAuth tokens are stolen via malicious packages. Other headlines include a ransomware attack's devastating impact on the University of Hawaii Cancer Center and insights into exposed LLM services vulnerable to attacks. Stay informed with the latest cybersecurity news and insights!
undefined
7 snips
Jan 12, 2026 • 25min

Department of Know: Brightspeed investigates breach, Prompt injection woes

Join Johna Till Johnson, CEO of Nemertes, a leading research firm, and Jason Shockey, CISO at Cenlar FSB, as they dive into critical cybersecurity concerns. They discuss the implications of the Brightspeed breach, emphasizing the importance of containment and communication. They also tackle the urgency of MFA enforcement for Microsoft 365 admins, and the rising risks associated with phishing tactics and AI vulnerabilities. Their insights into incident response strategies and securing agent communication are must-hears for cybersecurity leaders.
undefined
9 snips
Jan 12, 2026 • 8min

BreachForums database leaked, Instagram breach worries, UK government exempts self

A massive leak from BreachForums exposes the accounts of 324,000 users, raising concerns about security. An Instagram data breach leads to a surge in password resets, causing anxiety among users. The UK government faces backlash for exempting itself from a key cybersecurity law, igniting debate over accountability. Additionally, there's news about Microsoft testing a policy to allow the removal of Copilot, while North Korean spearphishing campaigns are on the rise, targeting governments and academia.
undefined
Jan 9, 2026 • 8min

Microsoft enforces admin MFA, Cisco patches ISE, Illinois breaches self

Microsoft is tightening security by enforcing multi-factor authentication for admin sign-ins starting soon. Cisco has addressed a medium-severity vulnerability in its ISE system following public disclosure. Meanwhile, an Illinois state agency accidentally exposed sensitive data of 700,000 residents online for years. Additional discussions cover prompt-injection risks targeting AI systems and phishing tactics using internal email spoofing. Veeam has also issued a critical update to fix a serious remote code execution vulnerability.
undefined
16 snips
Jan 8, 2026 • 7min

ESA confirms new data heist, Ni8mare lets hackers hijack n8n servers, Taiwan blames 'cyber army' for intrusion attempts

ESA faces a major data breach, losing 500GB of spacecraft and contractor data. Hackers exploit a severe flaw in n8n servers, allowing potentially crippling access. Taiwan reports increased cyber incursions, attributing them to a 'cyber army' and highlighting targeted sectors like telecom and semiconductors. A stalkerware developer pleads guilty, bringing attention to privacy concerns. Meanwhile, dangerous malware like PKR-MTSI and GhostTap rises, emphasizing the urgent need for better security practices.
undefined
8 snips
Jan 7, 2026 • 7min

UK cyber reset, no MFA is a problem, US cyberattacks on display

The UK is revamping its cybersecurity approach with a new centralized unit, moving from guidance to mandatory rules. The absence of multi-factor authentication has made cloud accounts vulnerable, as highlighted by troubling findings from credential logins. Meanwhile, the US may have played a role in recent cyberattacks during Maduro's arrest, with reports of targeted power outages in Caracas. Additionally, significant economic impacts are projected for Jaguar Land Rover due to cyber threats, emphasizing the far-reaching consequences of security breaches.

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app