
CyberWire Daily
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.
Latest episodes

Jul 16, 2025 • 30min
Chrome’s high-risk bug gets squashed.
Google and Microsoft roll out critical updates to address serious cybersecurity vulnerabilities. CISA alerts about a flaw in the Wing FTP Server that’s being actively exploited. A former U.S. Army soldier pleaded guilty to hacking and extortion charges. Alarmingly, malware has been discovered hidden within DNS records. The podcast also tackles rising threats to critical infrastructure, highlighting the need for enhanced cybersecurity legislation and skilled professionals to combat the growing complexities of cyber risks.

5 snips
Jul 15, 2025 • 36min
The Grok that broke the camel’s back.
Ethan Cook, an analyst at N2K, delves into pressing cybersecurity issues. He discusses the recent leak of API keys by a DOGE employee and the alarming rise in malware linked to North Korean hackers. The conversation shifts toward the launch of MITRE's new framework aimed at securing digital financial systems amid looming budget cuts. Cook shares insights on the cybersecurity workforce gap and reflects on inspiring stories, including a hacker who turned hero, emphasizing collaboration and accountability in the industry.

Jul 14, 2025 • 34min
Taxing times for cyber fraudsters.
Cynthia Kaiser, Senior Vice President at Halcyon’s Ransomware Research Center and former FBI Cyber Division leader, dives into the world of cyber fraud. She reveals the tactics of Scattered Spider, a group known for sophisticated social engineering and aggressive business targeting. The discussion extends to vulnerabilities in systems, including a major tax fraud scheme leading to arrests, and the rise of ransomware threats. Kaiser emphasizes the crucial need for enhanced cybersecurity measures as both luxury brands and other sectors face increasing risks.

12 snips
Jul 12, 2025 • 28min
Click here to steal. [Research Saturday]
Selena Larson, a Threat Researcher at Proofpoint and co-host of Only Malware in the Building, dives deep into the world of Amatera Stealer, a sophisticated rebranding of ACR Stealer. She reveals its advanced evasion techniques, including stealthy C2 communication and powerful PowerShell loaders. The discussion uncovers how Amatera employs creative social engineering and blockchain hosting to steal sensitive data, posing serious threats amid changing cybersecurity landscapes. Larson emphasizes the importance of heightened awareness and evolving defenses against such malware threats.

Jul 12, 2025 • 9min
MK Palmore: Lead from where you stand. [CISO] [Career Notes]
MK Palmore, Director of Google Cloud's Office of the CISO, shares his incredible journey from the US Marine Corps to the FBI and into cybersecurity. He opens up about his childhood dreams and the challenges he faced growing up in Washington, D.C. MK underscores the importance of mentorship and resilience in navigating career transitions. He passionately advocates for diversity, equity, and inclusion within the cybersecurity industry, emphasizing the need for leaders to uplift underrepresented voices.

16 snips
Jul 11, 2025 • 32min
Behind the firewall, trouble brews.
Catherine Woneis, VP of Product at Fingerprint, sheds light on the escalating issue of music royalty fraud driven by bots. She reveals how fraudsters use AI-generated music and fake artists to manipulate streaming metrics, raking in millions. The discussion also touches on critical cybersecurity vulnerabilities, including flaws in popular software, and the broader implications of AI on security. Woneis emphasizes the necessity for companies to adopt robust bot detection solutions amid the ongoing digital fraud battle.

60 snips
Jul 10, 2025 • 36min
Cybercrime has a hefty price tag.
Ben Yelin, co-host of the Caveat podcast and a legal expert in technology policy, joins to discuss alarming trends in cybercrime and cybersecurity. UK police have arrested suspects connected to major retail cyberattacks, while international arrests highlight rising geopolitical tensions. Yelin and Ethan Cook dive into Congress' contentious attempt to regulate AI at the federal level, challenging state authority. They also tackle pressing issues like password insecurity, emphasizing the critical need for better governance in the digital age.

9 snips
Jul 9, 2025 • 30min
Plug-ins gone rogue.
Patch Tuesday reveals critical vulnerabilities, urging swift action from IT admins. An Iranian ransomware group targets U.S. and Israeli interests, while new spyware strains exploit Russian industries. Browser extensions are found to have infected millions, posing significant risks. Joe Carrigan sheds light on a savvy phishing scam aimed at CFOs, showcasing evolving tactics in cybercrime. Plus, the surprising question: can our feline friends outsmart algorithms? All this and more makes for a captivating discussion on today’s cybersecurity landscape.

12 snips
Jul 8, 2025 • 31min
Memory leaks and login sneaks.
Discover the latest in cybersecurity as researchers reveal proof-of-concept exploits for CitrixBleed2 and Grafana rolls out urgent patches for critical vulnerabilities. A hacker claims a breach at Spanish telecom giant Telefónica, while a new ransomware group called BERT is on the rise. In an eye-opening discussion, experts highlight security risks in low-code platforms and integrated development environments. Plus, a staggering data leak affects millions of job seekers, raising concerns about personal data security in the digital age.

6 snips
Jul 7, 2025 • 37min
SafePay, unsafe day.
Rob Allen, Chief Product Officer at ThreatLocker, discusses the pressing issue of security fatigue in cybersecurity. He argues that a 'Default Deny' strategy can mitigate this problem by enhancing security without overwhelming users. Recent high-profile cyber incidents, including a ransomware attack on Ingram Micro, highlight the evolving landscape of cybercrime and the need for smarter security measures. Allen also emphasizes the importance of user education in combating insider threats and improving compliance.