
Cyber Security Headlines
Daily stories from the world of information security. To delve into any daily story, head to CISOseries.com.
Latest episodes

6 snips
Jun 13, 2025 • 8min
Microsoft Entra attack, Thursday’s Cloud outages, Mark Green retires
A significant hacking campaign is targeting Microsoft Entra ID accounts, raising concerns about cloud security. Recent outages at Google Cloud and Cloudflare add to the tension in the cybersecurity landscape. The retirement of House Homeland Chairman Mark Green could influence future cyber legislation. Additionally, a complex ransomware attack highlights vulnerabilities in employee monitoring software. Emerging threats also include spyware aimed at journalists and critical flaws in smart device security, underscoring the need for vigilance in our interconnected world.

Jun 12, 2025 • 8min
CoPilot zero-click, Operation Secure, FIN6 targets recruiters
Discover the latest on a zero-click vulnerability in Copilot and how it impacts data security. Dive into Operation Secure, aimed at dismantling global cybercrime, and learn about the sneaky tactics of the FIN6 group, which exploits job applications for phishing. Explore the recent cybersecurity challenges faced by retailers like Whole Foods and a new bipartisan healthcare bill designed to enhance security. Plus, get insights into malware attacks, including a troubling spam campaign leveraging AI-generated content.

10 snips
Jun 11, 2025 • 8min
40K IoT cameras stream secrets to browsers, Marks & Spencer taking online orders post-cyberattack, PoC Code escalates Roundcube Vuln threat
A shocking revelation as 40,000 IoT cameras are found streaming secrets accessible to anyone online. Major concerns arise from a Windows zero-day vulnerability targeting a significant Turkish defense organization. Marks & Spencer makes a comeback after a cyberattack sidelined their online orders for weeks. The episode also dives into webmail vulnerabilities and the troubling resurgence of stolen Ticketmaster data. This whirlwind of cyber threats highlights the pressing need for better security measures.

8 snips
Jun 10, 2025 • 8min
Cybersecurity News: Brute forcing Google accounts, Guardian's Secure Messaging, UNFI cyberattack
The discussion kicks off with vulnerabilities in Google's account recovery process, revealing alarming brute-force tactics. The Guardian launches a new secure messaging service, aiming to enhance safe communications. A significant cyberattack crippled United Natural Foods, underscoring threats to the food distribution sector. The rise of innovative cyber threats is explored, including Pathwiper malware targeting Ukrainian infrastructure and unique ransomware tactics against Russian firms. Plus, the challenges of striking a balance in security technology are highlighted with Cloudflare's new tools.

8 snips
Jun 9, 2025 • 9min
Cyber executive order, Neuberger’s infrastructure warning, Mirai botnet warning
A new Presidential cyber executive order aims to bolster software security and internet routing. Neuberger highlights alarming vulnerabilities in U.S. infrastructure, raising awareness of cyberattack risks. Meanwhile, a fresh variant of the Mirai botnet is targeting TBK DVR devices. In the realm of AI, OpenAI is combating state-sponsored hacking activities linked to ChatGPT accounts. The danger continues with a supply chain malware attack affecting popular ecosystems, and a significant data breach has exposed billions of records.

14 snips
Jun 6, 2025 • 28min
Week in Review: Senators’ CSRB bid, Deepfakes dodge detection, Microsoft-CrowdStrike collaboration
Rusty Waldron, Chief Business Security Officer at ADP, shares his insights on the rapidly evolving world of cybersecurity. He discusses the alarming rise of deepfakes and their ability to bypass detection, alongside the critical need for a Cyber Safety Review Board. Waldron highlights the innovative partnership between Microsoft and CrowdStrike aimed at improving threat attribution. He also covers the transformative role of AI in cybersecurity and its risks, offering a glimpse into the future of security leadership in this digital age.

7 snips
Jun 6, 2025 • 7min
Kettering data published, Reddit sues Anthropic, North Face breached
Recent data from Kettering Health was published after a ransomware attack, shedding light on the serious implications of cybercrime. Reddit's lawsuit against Anthropic over data scraping raises questions about data ownership and privacy. Additionally, North Face faced a credential stuffing attack, compromising customer accounts. There's also a focus on significant vulnerabilities discovered in Cisco's systems and the ongoing legal ramifications for cybercriminals. Meanwhile, ransomware incidents affecting government digital services underscore the urgency of robust national cybersecurity efforts.

7 snips
Jun 5, 2025 • 7min
Russian bomber maker popped, vishing targets Salesforce, MS helps out governments
Ukraine has claimed credit for a cyberattack on a Russian bomber manufacturer, highlighting the ongoing cyber warfare. A vishing campaign is targeting Salesforce users, showcasing the rise of fraud tactics in the tech world. In response to rising threats, Microsoft is rolling out a new cybersecurity initiative to support European governments. The conversation also delves into malware operations and phishing schemes impersonating well-known brands like booking.com, stressing the importance of source verification for protecting sensitive information.

18 snips
Jun 4, 2025 • 8min
Meta, Yandex take heat on browsing identifiers, Acreed malware makes gains, HPE warns of critical auth bypass
Meta and Yandex face backlash for compromising Android users' web browsing anonymity. Meanwhile, Acreed malware rises as a leading threat, indicating shifting malware trends. In another crucial update, Hewlett Packard Enterprise warns of a significant authentication bypass vulnerability. These developments highlight the ongoing challenges in cybersecurity and the evolving tactics of cybercriminals.

12 snips
Jun 3, 2025 • 8min
MS and CrowdStrike partner, Qualcomm bugs exploited, new CISA cut details
Microsoft and CrowdStrike are joining forces to enhance threat attribution in cybersecurity. Qualcomm has reported active exploitation of vulnerabilities in its Adreno GPUs. Meanwhile, budget cuts affecting CISA raise concerns about future cyber defenses. On the horizon, the BlackOwl hacking group is independently targeting Russian firms, while critical security flaws in certain apps come to light. A new crypto-jacking campaign is posing risks to DevOps web servers, highlighting the important role of AI in empowering cybersecurity analysts.