Alice & Bob

Cyber Mornings Daily

News EN ↓ 136 episodes

Cyber Mornings Daily is your go-to daily podcast for the latest cybersecurity news, trends, and insights, delivered by AI. Each episode delivers a concise and informative breakdown of the most pressing cyber threats, vulnerabilities, and breaches.

Author

Alice & Bob

Category

News

Podcast website

podcast.singercomputers.com

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

April 16th, 2025 16.04.2025

The sources discuss several distinct cybersecurity-related topics. One major subject is the extension of funding for the Common Vulnerabilities and Exposures (CVE) program by CISA to prevent any lapse in this critical service. This announcement followed a warning about potential disruptions and the expiration of funding for MITRE, the organization that maintains the CVE program. In response to the...

April 14th, 2025 14.04.2025

The sources discuss several security-related topics, including a ransomware attack on the kidney dialysis firm DaVita, which resulted in the encryption of parts of its network and impacted some operations. Another key topic is Microsoft Defender for Endpoint's new capability to isolate undiscovered endpoints to prevent attackers from moving laterally across a network. Finally, the sources also det...

April 7th, 2025 07.04.2025

The sources discuss several cybersecurity-related topics, including Coinbase's plan to fix a confusing 2FA error message that was causing user anxiety and could be used in social engineering attacks. Another topic is a resurgence of phishing scams impersonating E-ZPass and other toll agencies, aiming to steal personal and credit card information via text messages and fake websites. Finally, one so...

April 4th, 2025 04.04.2025

Australian pension funds have been targeted by a significant wave of credential stuffing attacks, This occurred over the weekend of March 29-30, 2025, and affected multiple large Australian super funds, potentially compromising thousands of members' accounts. The Association of Superannuation Funds of Australia (ASFA) acknowledged that some members were affected, although most attempts were repell...

April 3rd, 2025 03.04.2025

A vulnerability in Verizon's Call Filter API allowed users to potentially access the incoming call logs of other Verizon Wireless customers. Security researcher Evan Connelly discovered in February 2025 that the API endpoint used by the Call Filter app to retrieve a user's call history did not verify the phone number in the request against the logged-in user's phone number. As a result, by manipul...

April, 1st 2025 01.04.2025

Recent cybersecurity news includes Google's introduction of easy end-to-end encryption (E2EE) for Gmail business users, which simplifies the process of sending encrypted emails to any recipient by abstracting away complex certificate requirements. In another development, Microsoft utilized its AI-powered Security Copilot to discover twenty previously unknown vulnerabilities in the GRUB2, U-Boot, a...

March 25th, 2025 25.03.2025

Genetic testing provider 23andMe has filed for Chapter 11 bankruptcy after facing years of financial difficulties and plans to sell its assets. Following this news, privacy experts have raised concerns about the potential exposure of customers' genetic information, even though the company has stated its commitment to safeguarding data. Consequently, the Office of California's Attorney General has...

March 24th, 2025 24.03.2025

A recent GitHub Actions supply chain attack primarily targeted Coinbase, a cryptocurrency exchange. The attack involved injecting malicious code into the `reviewdog/action-setup@v1` GitHub Action, which led to the dumping of CI/CD secrets and authentication tokens in GitHub Actions logs. Threat actors then used a stolen Personal Access Token to push a malicious commit to another GitHub Action, `tj...

March 13th, 2025 13.03.2025

Human error is now the primary factor in data breaches, accounting for 95% of incidents in 2024. This is often exploited through social engineering tactics like phishing, where employees overestimate their ability to detect scams, with nearly 50% admitting to falling for them. Threat actors, such as Blind Eagle and those behind the KoSpy spyware, utilize phishing emails to gain initial access to s...

March 12th, 2025 12.03.2025

In March 2025, cybersecurity incidents were reported, including Chinese cyberspies backdooring Juniper routers, Mozilla warning Firefox users to update their browsers, and the social media platform X (formerly Twitter) being hit by a massive cyberattack. The attack on X, claimed by the hacktivist group Dark Storm, led to worldwide outages and the implementation of DDoS protections from Cloudflare....

March 10th, 2025 10.03.2025

Recent cybersecurity news includes a data breach at NTT impacting 18,000 companies, a ransomware gang using a webcam to bypass EDR, and US cities warning about unpaid parking phishing texts. The NTT data breach, discovered in early February 2025, compromised the information of almost 18,000 corporate customers. An Akira ransomware gang utilized an unsecured webcam to encrypt a victim's network, ci...

March 6th, 2025 06.03.2025

Several recent cybersecurity incidents and advisories have been reported, including the detection of Stingray attacks using the open-source tool 'Rayhunter'. Additionally, the Chinese cyber-espionage group 'Silk Typhoon' is now targeting IT supply chains to breach networks. Furthermore, YouTube has issued a warning about AI-generated videos of its CEO being used in phishing attacks to steal creato...

March 5th, 2025 05.03.2025

Recent cybersecurity news includes a vulnerability in Cisco Webex for BroadWorks that could allow remote access to credentials, addressed by a configuration change. Scammers are sending fake BianLian ransom notes via mail to U.S. companies, demanding Bitcoin payments. A new botnet, Eleven11bot, has infected over 86,000 IoT devices, mainly security cameras and NVRs, to conduct DDoS attacks.

March 4th, 2025 04.03.2025

In recent cybersecurity news, several important developments have emerged: The Cybersecurity and Infrastructure Security Agency (CISA) is continuing its monitoring of Russian cyber threats, refuting claims that it would stop. Google has addressed multiple Android vulnerabilities, including zero-day exploits used by Serbian authorities. Rubrik, a cybersecurity company specializing in data protectio...

March 3rd, 2025 03.03.2025

In the realm of cybersecurity, recent events highlight the growing concerns around data privacy and security. Mozilla updated its Firefox terms of use following criticism over broad data license language. A study revealed that nearly 12,000 API keys and passwords were found in AI training datasets, raising concerns about insecure coding practices and potential misuse. Furthermore, Serbian police r...

February 28th, 2025 28.02.2025

The discussion centers on three major cybersecurity concerns: the security of access management systems, legislative threats to digital privacy, and the proliferation of malware botnets. Flaws in access management systems can lead to unauthorized access and data breaches. Simultaneously, legislative actions, particularly those that mandate backdoors in encrypted systems or limit VPN access, raise...

February 26th, 2025 26.02.2025

Several organizations have recently reported data breaches and ransomware attacks. Genea, an Australian IVF provider, was breached by the Termite ransomware gang, who claimed to have stolen roughly 700GB of data. EncryptHub (aka Larva-208) has compromised at least 618 organizations since June 2024 using phishing and social engineering to deploy infostealers and ransomware. DISA Global Solutions, a...

February 25th, 2025 25.02.2025

In cloud security, Google Cloud KMS now supports quantum-safe digital signatures compliant with NIST standards, using methods like ML-DSA-65 and SLH-DSA-SHA2-128S to protect against future quantum threats. Meanwhile, North Korean hackers, specifically the Lazarus group, have been linked to a $1.5 billion crypto heist from Bybit, exploiting a transfer of funds from a cold wallet to a hot wallet. Ad...

February 21st, 2025 21.02.2025

In the realm of cybersecurity, several significant developments have occurred: A healthcare organization in the U.S. paid a substantial settlement for alleged cybersecurity lapses. Microsoft is also making strides in quantum computing with the development of the Majorana 1 chip, which could impact data encryption. Simultaneously, the Darcula phishing platform is evolving, offering advanced tools f...

February 20th, 2025 20.02.2025

Today's topic involves a look at cybersecurity threats and vulnerabilities. These include infostealer attacks targeting major U.S. defense contractors and military personnel, where sensitive data can be stolen for as little as $10 per computer. Another issue is an Apple iOS vulnerability allowing unauthenticated bypass via USB connections, which was addressed in iOS 18.3.1. Finally, the venture ca...

February 18th, 2025 18.02.2025

Finastra, a financial technology company, dealt with the fallout of a data breach from the previous October, where unauthorized access to their systems led to the theft of personal information. Lee Enterprises, a newspaper publisher, experienced a ransomware attack that disrupted their operations, affecting distribution and billing processes. Microsoft reported a device code phishing campaign pote...

February 14th, 2025 14.02.2025

Chinese state-sponsored hackers known as RedMike are targeting telecommunications companies and universities by exploiting vulnerabilities in Cisco devices. The group is using known flaws, specifically CVE-2023-20198 and CVE-2023-2027, to gain administrator control of Cisco IOS XE appliances. These vulnerabilities allow for elevation of privilege, providing a foothold for further network intrusion...

February 13th, 2025 13.02.2025

A critical vulnerability in Nvidia's container software could allow attackers to gain root privileges on host servers by mounting the host’s root filesystem into a container, granting unrestricted access to all of the host’s files. This flaw affects AI applications running the vulnerable container toolkit, whether in the cloud or on-premises. Additionally, North Korean hackers are using a social e...

February 12th, 2025 12.02.2025

The stories discuss recent cybercrime activities, including a SIM swap attack on the U.S. Securities and Exchange Commission (SEC) X account, indictments of 8Base ransomware operators, and sanctions against Zservers, a bulletproof hosting service used by LockBit affiliates. The SEC account was hacked via SIM swapping, which allowed the perpetrator to post false information about Bitcoin ETFs, caus...

February 11th, 2025 11.02.2025

A large-scale brute-force attack is using nearly 2.8 million IP addresses daily to target networking devices from Palo Alto Networks, Ivanti, and SonicWall. The attack, which originates mostly from Brazil, Turkey, Russia, Argentina, Morocco, and Mexico, attempts to steal credentials by repeatedly logging into accounts. Once attackers gain access, they can then infiltrate corporate networks. Securi...

Listen to the Cyber Mornings Daily podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.