

Cyber Security Headlines
CISO Series
Daily stories from the world of information security. To delve into any daily story, head to CISOseries.com.
Episodes
Mentioned books

7 snips
Dec 1, 2025 • 7min
Asahi ransomware details, California browser law, Windows Teams accelerated
Asahi reveals the fallout from a ransomware attack affecting 1.5 million customers, raising privacy concerns. California's new law mandates web browsers to offer opt-out tools, potentially reshaping national data privacy practices. Microsoft prepares to enhance Teams performance, streamlining call handling with a new handler. Additionally, a data breach at the French Soccer Federation exposes members' personal information. Finally, leaders discuss the implications of data centers on local elections and energy costs.

7 snips
Nov 28, 2025 • 8min
Microsoft blocks Entra, AI scammer legislation, ASUS patches AiCloud
Microsoft plans to block unauthorized scripts for Entra ID sign-ins in 2026. New legislation aims to crack down on AI-assisted scams with tougher penalties. ASUS has patched a critical vulnerability in AiCloud with a set of firmware fixes. In other news, OpenAI cut ties with Mixpanel following a data breach, while three London councils experienced a shared IT outage. Dartmouth faced a significant data theft affecting 35,000 people, and Microsoft dealt with an Exchange Online outage impacting Outlook access.

22 snips
Nov 27, 2025 • 7min
AWS outage botnet smacks 28 countries, LLMs help malware authors evade detection, Anthropic pressed over Claude espionage
A massive AWS outage allowed the Shadow V2 botnet to spread across 28 countries, showcasing its IoT-focused malware tactics. Meanwhile, attackers are leveraging large language models to rewrite code, helping malware evade detection. In a heated House hearing, Anthropic's CEO faced scrutiny for potential espionage linked to their AI, Claude. Additionally, serious vulnerabilities in package management systems were exposed, highlighting the ongoing cyber threat landscape.

15 snips
Nov 26, 2025 • 7min
CISA warns of app break-ins, StealC V2 spread through blender files, Russian entrepreneur arrested for treason
CISA issues a warning about state-backed actors hijacking messaging apps with spoofed versions. New findings reveal SteelC V2 malware spreading through weaponized Blender files. A Russian entrepreneur faces treason charges after criticizing a state-backed messaging app. Meanwhile, account takeover fraud has resulted in a staggering $262 million in losses. Attackers are also exploiting vulnerabilities in legacy devices from SonicWall, showcasing the ever-evolving landscape of cyber threats.

17 snips
Nov 25, 2025 • 8min
CISA orders feds to patch OIM, Delta Dental incurs breach, Ukraine postal operator systems down
CISA has ordered federal agencies to patch a critical zero-day vulnerability in Oracle's OIM following alarming exploitation activities. Delta Dental suffers a breach, affecting the personal and health data of 146,000 customers. In Ukraine, cyberattacks have severely impacted postal services, leaving systems offline. Amazon's AI agents are on the hunt for software vulnerabilities, while the Shadowray 2.0 malware exploits cloud clusters for cryptomining. Additionally, actionable security advice is emphasized against outdated myths, showcasing the evolving landscape of cybersecurity.

9 snips
Nov 25, 2025 • 42min
Department of Know: Overconfidence new zero-day, FCC torches Salt Typhoon rules, AI uninsurable
In this engaging discussion, Keith Townsend, a seasoned CTO advisor, and Howard Holton, CEO of GigaOm, tackle a range of pressing topics. They critique the FCC's decision to scrap Salt Typhoon security rules, emphasizing the need for regulatory protections. The duo also explores the issue of overconfidence in security teams, citing a report that highlights the gap between perception and preparedness. Lastly, they delve into the risks of AI, with insurers looking to exclude AI liabilities, raising questions about accountability in tech mishaps.

16 snips
Nov 24, 2025 • 8min
CrowdStrike insider catch, Spanish airline breach, AI not insurable
An insider at CrowdStrike leaked internal information but didn’t compromise customer data. Iberia faced a breach due to a supplier, exposing names and emails, though payment info remained safe. Insurers are pushing to exclude liabilities for AI risks, citing the unpredictable nature of AI systems. Salesforce issued a warning about unusual activity tied to third-party apps. In other news, a Nordex manager was sentenced for using wind turbines to mine cryptocurrency. Ransomware also hit law enforcement agencies, disrupting essential services.

18 snips
Nov 21, 2025 • 9min
Sturnus captures encrypted chats, PowerSchool schools blamed, SEC security bill
A new Android Trojan called Sturnus is causing chaos by capturing encrypted chat content and hijacking devices. Canadian regulators are pointing fingers at schools for their lackluster security that led to a PowerSchool hack. Meanwhile, cybersecurity takes a front seat as a new bipartisan bill aims to enhance data protection at the SEC. Plus, urgent directives are issued to patch critical vulnerabilities, while guidance on evasion attacks emerges from Germany's BSI. Stay informed and secure!

11 snips
Nov 20, 2025 • 8min
Cloudflare blames database, Crypto heist takedown, WhatsApp flaw exposed billions
A major outage at Cloudflare was traced back to a database permissions change, impacting services like X and Canva. A California man pleaded guilty to laundering millions from a significant crypto heist. Researchers revealed a critical flaw in WhatsApp that exposed data of over 3.5 billion users. Meanwhile, Amazon reported cyber-enabled reconnaissance linked to Iran before missile attacks. A crackdown uncovered €47 million in piracy crypto and targeted Russian hosting providers supporting ransomware. Plus, a new ransomware player, Shiny Spider, emerges with a unique negotiation tactic.

8 snips
Nov 19, 2025 • 8min
FCC to torch Salt Typhoon rules, Group claims Danish party website hits, MI5 warns Chinese spies are on LinkedIn
The FCC plans to scrap telecom security mandates from the Salt Typhoon initiative, favoring a voluntary approach. A group has launched DDoS attacks on Danish party websites just before elections, highlighting a rise in cyber nuisance. MI5 warns of Chinese spies using LinkedIn to target UK officials. New findings reveal malicious NPM packages redirecting users to crypto scams, and a sneaky 2FA phishing kit employs BitBee pop-ups to evade detection. Emergency patches have been released for two serious Chrome vulnerabilities.


