Daily Security Review
Daily Security Review
Daily Security Review, the premier source for news and information on security threats, Ransomware and vulnerabilities
Autor
Daily Security Review
Categoría
Web del podcast
Último episodio
29 de oct. de 2025
¿Dónde escuchar?
Podcasts en la app Replaio Radio Muy prontoLos podcasts llegarán muy pronto a la app. Instálala ahora y sé el primero en descubrir una forma totalmente nueva de vivir los podcasts
Episodios
Pwn2Own Automotive 2026: $3 Million Bounty Targets Tesla and EV Infrastructure Flaws 21.10.2025 24:29
The upcoming Pwn2Own Automotive 2026 hacking contest, hosted by Trend Micro’s Zero Day Initiative (ZDI), is set to redefine the economics of automotive cybersecurity. With a record-breaking $3 million prize pool, the event provides a transparent, market-driven valuation of the most dangerous vulnerabilities facing the connected vehicle ecosystem. Through six major competition categories — includin...
China Claims NSA Breached National Time Network, Threatening Finance and Defense Stability 20.10.2025 24:09
China’s Ministry of State Security (MSS) has publicly accused the U.S. National Security Agency (NSA) of conducting a multi-year cyber espionage campaign targeting its National Time Service Center, a critical component of China’s national infrastructure responsible for maintaining and distributing standard time. According to China, the attacks — allegedly conducted between 2022 and 2024 — involved...
Cl0p Ransomware Targets Oracle E-Business Suite in Global Data Extortion Spree 20.10.2025 17:57
A new wave of Cl0p ransomware attacks has struck organizations worldwide by exploiting vulnerabilities in Oracle’s E-Business Suite (EBS) — a mission-critical enterprise management platform used by corporations and universities across the globe. The ongoing campaign, attributed to FIN11, highlights the group’s shift toward exploiting high-value business systems for maximum leverage in data extorti...
WhatsApp Wins Landmark Case Against NSO Group Over Spyware Attacks 20.10.2025 24:02
After six years of intense litigation, WhatsApp has secured a decisive legal victory against the NSO Group, the controversial spyware maker accused of exploiting a zero-day vulnerability to infect more than 1,400 users with surveillance malware. On October 17, 2025, a U.S. District Court issued a permanent injunction that bars NSO from targeting WhatsApp users, reverse engineering the app, or crea...
Google Project Zero Exposes Dolby Decoder Flaw Enabling Zero-Click Android Exploits 20.10.2025 21:44
A newly discovered vulnerability in Dolby’s Unified Decoder has sent shockwaves through the cybersecurity world. Tracked as CVE-2025-54957 , the flaw — uncovered by Google Project Zero — is a critical out-of-bounds write vulnerability that allows remote code execution (RCE) when a specially crafted audio file is decoded. The issue stems from an integer overflow in the decoder’s buffer length calcu...
AISLE Launches AI Cyber Reasoning System to Shrink Patch Times from Weeks to Minute 17.10.2025 23:54
AISLE has entered the cybersecurity arena with an AI-native Cyber Reasoning System (CRS) built to do what most tools don’t: fix vulnerabilities—fast. While attackers increasingly use AI to weaponize new flaws in roughly five days, most organizations still average ~45 days to remediate critical issues. AISLE’s answer is an autonomous remediation pipeline that identifies, prioritizes, generates patc...
Microsoft Blunts “Vanilla Tempest”: 200 Malicious Certificates Revoked 17.10.2025 20:27
In early October 2025, Microsoft executed a targeted disruption against Vanilla Tempest—the threat actor also tracked as Vice Society—after uncovering a streamlined, high-impact campaign that deployed Rhysida ransomware through a cleverly staged infection chain. The operation leaned on SEO poisoning to funnel victims searching for “Microsoft Teams” installers to attacker-controlled domains (e.g.,...
The “Shotgun” Botnet: How RondoDox Hijacks Routers, Cameras, and Servers Worldwide 14.10.2025 23:28
A new and fast-growing botnet dubbed RondoDox is shaking up the global cybersecurity landscape with its “shotgun” exploitation strategy, targeting over 50 known and unknown vulnerabilities across a vast array of internet-connected devices. First detected in mid-2025, the botnet has expanded rapidly, infecting routers, servers, cameras, and DVRs from more than 30 different vendors. Researchers at T...
“Inflation Refund” Scam: How Fraudsters Are Stealing Identities Through Texts 13.10.2025 19:01
A widespread smishing campaign is sweeping across New York, luring residents with fraudulent text messages about an “Inflation Refund” from the Department of Taxation and Finance. These deceptive messages claim that recipients are eligible for a refund and must click a link to “process” it — a ploy designed to harvest personal and financial information. Once clicked, the link leads victims to a ph...
Juniper Networks Patches 220 Vulnerabilities in Massive October Security Update 13.10.2025 23:29
In one of the year’s most extensive patch cycles, Juniper Networks has released its October 2025 security advisories, addressing a staggering 220 vulnerabilities across its product suite — including Junos OS, Junos Space, Junos Space Security Director, and Junos OS Evolved. Of these, nine critical flaws in Junos Space and Security Director stood out, most notably a Cross-Site Scripting (XSS) vulne...
Linked Exploitation Campaigns Target Cisco, Fortinet, and Palo Alto Networks Devices 13.10.2025 25:08
Cyber intelligence firm GreyNoise has uncovered what appears to be a coordinated exploitation effort targeting network edge appliances from three major security vendors: Cisco, Fortinet, and Palo Alto Networks. After analyzing overlapping IP subnets, identical TCP fingerprints, and synchronized attack patterns, GreyNoise assessed with high confidence that these separate waves of scanning and brute...
Salesforce Refuses Ransom as Scattered LAPSUS$ Hunters Leak Millions of Records 13.10.2025 27:29
A new wave of cyber extortion has rocked the enterprise world as the Scattered LAPSUS$ Hunters—a coalition formed from the notorious Lapsus$, Scattered Spider, and ShinyHunters groups—attempted to ransom Salesforce, claiming to have stolen data from 39 of its customers. When Salesforce refused to negotiate, the hackers retaliated by publishing the records of six companies, including Fujifilm, Albe...
Oneleet Secures $33M Series A to Revolutionize Integrated Cybersecurity 07.10.2025 28:08
Amsterdam-based cybersecurity startup Oneleet has raised $33 million in Series A funding, bringing its total capital to $35 million and positioning itself as one of Europe’s most ambitious new players in the security technology space. Founded in 2022, Oneleet is tackling one of cybersecurity’s biggest pain points: tool fragmentation. Its integrated platform aims to replace the clutter of multiple...
ParkMobile Data Breach Ends in $32.8M Settlement — and a $1 Payout 06.10.2025 27:55
The final chapter in the ParkMobile data breach saga has arrived—nearly four years after the 2021 cyberattack that compromised the personal information of 22 million users. The class-action lawsuit over the breach has concluded with a $32.8 million settlement, but for most victims, the payout is almost symbolic: a $1.00 credit, split into four $0.25 discounts on service fees, redeemable only throu...
Discord Confirms Data Breach Linked to Third-Party Support Vendor 06.10.2025 25:58
Discord has confirmed a significant data breach affecting users who interacted with its customer support teams, after hackers compromised a third-party service provider on September 20. The attack exposed a range of personally identifiable information (PII), including names, email addresses, messages, and, for a small number of users, photos of government-issued IDs such as passports and driver’s...
Weather Station Gateway Exploited: CISA Adds Meteobridge Bug to KEV List 06.10.2025 23:11
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a stark warning following confirmation that a command injection vulnerability in Meteobridge weather station devices is now being actively exploited. Tracked as CVE-2025-4008, the flaw allows attackers to execute arbitrary commands via an unauthenticated web interface endpoint, exploiting unsanitized user input. While Meteobrid...
DrayTek Issues Critical Patch for Router RCE Flaw (CVE-2025-10547) 06.10.2025 25:30
A serious unauthenticated remote code execution (RCE) flaw, identified as CVE-2025-10547, has been uncovered in DrayTek’s DrayOS routers. This vulnerability allows attackers to send crafted HTTP or HTTPS requests to the router’s web management interface, potentially leading to memory corruption, system crashes, or full device takeover. The flaw affects 35 models of DrayTek’s Vigor routers, devices...
FTC vs. Sendit: Lawsuit Alleges Data Theft, Fake Messages, and Subscription Traps 02.10.2025 27:25
The Federal Trade Commission (FTC) has filed a high-profile lawsuit against Sendit , a social media companion app popular among teenagers, and its CEO. The case accuses the company of breaking three major U.S. laws designed to protect consumers and children online. First, the FTC alleges that Sendit violated the Children’s Online Privacy Protection Act (COPPA) by knowingly collecting personal data...
Broadcom Patches VMware Zero-Day: CVE-2025-41244 Exploited by China-Linked UNC5174 01.10.2025 25:16
Broadcom has released a critical security update addressing six vulnerabilities across VMware products , including four rated high-severity. At the center of the update is CVE-2025-41244 , a local privilege escalation flaw affecting VMware Tools and Aria Operations . What makes this vulnerability particularly alarming is that it was actively exploited in the wild as a zero-day since mid-October 20...
Seven Years, £5.5 Billion, 128,000 Victims – The Case of Yadi Zhang 01.10.2025 29:12
In a historic case that has captured global attention, UK authorities have secured a conviction against Zhimin Qian (also known as Yadi Zhang) , the Chinese national at the center of one of the largest financial crime investigations of the decade. Following a seven-year probe by the Metropolitan Police , investigators uncovered an elaborate fraud and laundering scheme that culminated in the seizur...
Cisco ASA/FTD Flaws Under Siege: 50,000 Devices at Risk from Active Exploits 01.10.2025 31:52
Two newly disclosed critical vulnerabilities— CVE-2025-20333 and CVE-2025-20362 —are wreaking havoc across the global cybersecurity landscape, with nearly 50,000 Cisco ASA and FTD appliances actively under threat. These flaws enable unauthenticated remote code execution and VPN access compromise , giving attackers an immediate foothold into critical infrastructure. Despite Cisco issuing warnings a...
MatrixPDF: The New Phishing Toolkit That Turns Safe PDFs into Cyber Weapons 01.10.2025 16:12
A new cybercrime toolkit called MatrixPDF is changing the phishing landscape by weaponizing one of the most trusted file formats: PDFs. Marketed on cybercrime forums as an “elite document builder” for phishing simulations and blackteaming, MatrixPDF enables attackers to transform ordinary PDFs into highly convincing phishing lures that bypass email security filters—including Gmail’s native protect...
Asahi Brewery Cyberattack Halts Domestic Operations Across Japan 01.10.2025 27:07
Asahi Group Holdings, Ltd.—the brewer behind some of the world’s most iconic beers, including Peroni and Grolsch—has been hit by a crippling cyberattack that froze its Japan-based operations . Ordering and shipping have been suspended, customer call centers and service desks are offline, and the company has been forced into damage control. While Asahi’s global operations remain unaffected, this in...
Akira Ransomware Exploits SonicWall Flaw with Record-Breaking Speed 30.09.2025 23:58
The Akira ransomware group has once again raised the stakes in cybercrime by exploiting a critical SonicWall vulnerability— CVE-2024-40766 —to infiltrate corporate networks through SSL VPN accounts, even those secured with one-time password multi-factor authentication. Once inside, Akira’s affiliates execute one of the most dangerous tactics in modern ransomware: Living Off the Land . By hijacking...
Ex-Hacktivist “Sabu” Backs SafeHill’s $2.6M Bet on Continuous Threat Management 30.09.2025 28:04
A new cybersecurity startup with an infamous name attached is making headlines. SafeHill—formerly known as Tacticly—has secured $2.6 million in pre-seed funding to accelerate the development of its continuous threat exposure management (CTEM) platform, SecureIQ . Designed to overcome the shortcomings of traditional, point-in-time penetration testing, SecureIQ blends AI-driven continuous asset disc...
Podcasts similares
Replaio no es editor de podcasts; los nombres de los programas, las portadas y el audio pertenecen a sus autores y se distribuyen a través de canales RSS públicos