

Cyber Security Headlines
CISO Series
Daily stories from the world of information security. To delve into any daily story, head to CISOseries.com.
Episodes
Mentioned books

16 snips
Jul 10, 2025 • 8min
AMD has CPU meltdown, Mozilla Thunderbird has vulnerabilities, Indian defense sector attacked
AMD has issued a warning about new vulnerabilities in their CPUs similar to Meltdown and Spectre. Mozilla Thunderbird is facing issues that could lead to arbitrary code execution. In the cryptocurrency world, a breach at Bitcoin Depot compromises the data of nearly 27,000 users, while over $40 million was stolen from the GMX platform. Additionally, the Indian defense sector has been targeted in a sophisticated phishing campaign, raising alarms about national security in the region.

8 snips
Jul 9, 2025 • 9min
Rubio Spoofed, RondoDox Botnet, Batavia Spyware
In a gripping discussion, the podcast dives into the alarming impersonation of Cabinet members using advanced AI. It reveals the stealthy RondoDocs botnet unleashing denial-of-service attacks and highlights Batavia's deceptive campaign targeting Russian industries through phishing. The conversation also touches on a sophisticated phishing operation discovered by Kaspersky and ongoing legal battles involving SolarWinds. Furthermore, vulnerabilities in Google's Gemini and a ransomware incident with Marks & Spencer showcase the ever-evolving landscape of cyber threats.

8 snips
Jul 8, 2025 • 9min
Call of Duty game pulled, U.S. military gets cybersecurity boost, Bank employee helped hackers
A popular game was yanked from a PC store due to a dangerous exploit. Meanwhile, the U.S. military received a significant boost in cybersecurity funding. In a shocking twist, a bank employee was arrested for helping hackers steal a staggering $100 million. The podcast also delves into rising threats like the BERT ransomware group and fraudulent domains popping up during high-traffic events. It wraps up with an exploration of the challenges faced by large language models in combating such evolving cyber threats.

5 snips
Jul 7, 2025 • 8min
Ingram Micro cyberattack, Telefonica possible breach, LLM URL recommendation problem
Ingram Micro faces a severe ransomware attack, raising alarms about evolving cyber threats. A potential data breach at Telefonica adds to the worries, hinting at vulnerabilities in telecom security. Meanwhile, ChatGPT's tendency to suggest incorrect URLs opens up new avenues for phishing scams. These incidents underscore the increasing need for robust cybersecurity measures in our digital landscape.

8 snips
Jul 4, 2025 • 9min
Undetectable Android spyware is detectable, Hunters ransomware quits, Salt Typhoon dormant
Undetectable Android spyware has made headlines by leaking user logins, raising concerns for privacy. In a surprising turn, the Hunters ransomware group has shut down operations. Meanwhile, the medical device company Surmodics faces a cyberattack, highlighting vulnerabilities in critical sectors. The discussion emphasizes the ongoing challenges in cybersecurity and the need for unified security measures to counter rapid advancements in attacks.

10 snips
Jul 3, 2025 • 7min
Columbia hack, hunger relief ransomware, Qantas breach
Tune in to hear about the alarming hack at Columbia University that led to a significant data loss. The conversation shifts to a ransomware attack on a German hunger relief charity, exposing vulnerabilities in nonprofits. Qantas faced a breach affecting millions, adding to the growing list of cybersecurity incidents. Emerging threats are also discussed, including a harmful SMS stealer in Uzbekistan and cloned crypto wallet extensions that trick users, highlighting the relentless challenges in maintaining digital safety.

7 snips
Jul 2, 2025 • 7min
Google issues Chrome security update, ICC targeted by new attack, Microsoft nixes Authenticator password management
A critical security update from Google addresses a zero-day vulnerability in Chrome, as threats escalate. The International Criminal Court faces a new sophisticated cyber attack, highlighting rising global risks. Two major data breaches affect over 800,000 individuals, stressing the need for vigilance. In tech shifts, Microsoft is moving toward passwordless authentication, while new AI web scraping policies from Cloudflare aim to protect creators' rights. As attacks evolve, the need for cohesive defense strategies becomes paramount.

10 snips
Jul 1, 2025 • 8min
New Iran warning, Chinese surveillance company banned, CISA names new executive director
U.S. agencies issue a stark warning about Iranian hackers targeting defense contractors. Canada takes a stand by banning a Chinese surveillance company, while the U.S. cracks down on North Korean IT workers involved in identity theft. A law enforcement operation successfully dismantles laptop farms and fraudulent cryptocurrency activities. In a separate incident, a significant ransomware attack hits a Swiss non-profit. Meanwhile, new enhancements in Microsoft Defender promise to bolster protections against email bombing attacks.

8 snips
Jun 30, 2025 • 8min
Hawaiian Airlines cyberattack, United Natural Foods update, Russia throttles Cloudflare
Hawaiian Airlines has fallen victim to a cyberattack, raising significant concerns in the aviation sector. Meanwhile, United Natural Foods faces financial impact from a cyber incident. In Russia, Cloudflare is being throttled, disrupting access to various sites. The podcast also highlights alarming trends in cybersecurity, including social engineering scams in healthcare and the environmental impact of AI. A gripping story unfolds about a hacker linked to the Sinaloa cartel, bringing witness safety into question.

6 snips
Jun 27, 2025 • 25min
Week in Review: Qilin adds lawyers, Iranian spearphishing campaign, Microsoft Direct Send hack
In this discussion, Bil Harmer, Operating Partner and CISO at Craft Ventures, dives into the rapidly evolving landscape of cybersecurity. He highlights alarming new tactics used by ransomware groups, including involving legal counsel in ransom negotiations. The conversation also sheds light on the targeted Iranian spear phishing campaigns and their implications for healthcare data security. Additionally, they discuss vulnerabilities in Microsoft 365 and password security challenges, emphasizing the importance of robust cybersecurity practices and policies to combat these threats.