Alice & Bob
Cyber Mornings Daily
Cyber Mornings Daily is your go-to daily podcast for the latest cybersecurity news, trends, and insights, delivered by AI. Each episode delivers a concise and informative breakdown of the most pressing cyber threats, vulnerabilities, and breaches.
Author
Alice & Bob
Category
Podcast website
Latest episode
Jul 10, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
April 16th, 2025 16.04.2025 9:37
The sources discuss several distinct cybersecurity-related topics. One major subject is the extension of funding for the Common Vulnerabilities and Exposures (CVE) program by CISA to prevent any lapse in this critical service. This announcement followed a warning about potential disruptions and the expiration of funding for MITRE, the organization that maintains the CVE program. In response to the...
April 14th, 2025 14.04.2025 10:16
The sources discuss several security-related topics, including a ransomware attack on the kidney dialysis firm DaVita, which resulted in the encryption of parts of its network and impacted some operations. Another key topic is Microsoft Defender for Endpoint's new capability to isolate undiscovered endpoints to prevent attackers from moving laterally across a network. Finally, the sources also det...
April 7th, 2025 07.04.2025 21:18
The sources discuss several cybersecurity-related topics, including Coinbase's plan to fix a confusing 2FA error message that was causing user anxiety and could be used in social engineering attacks. Another topic is a resurgence of phishing scams impersonating E-ZPass and other toll agencies, aiming to steal personal and credit card information via text messages and fake websites. Finally, one so...
April 4th, 2025 04.04.2025 13:37
Australian pension funds have been targeted by a significant wave of credential stuffing attacks, This occurred over the weekend of March 29-30, 2025, and affected multiple large Australian super funds, potentially compromising thousands of members' accounts. The Association of Superannuation Funds of Australia (ASFA) acknowledged that some members were affected, although most attempts were repell...
April 3rd, 2025 03.04.2025 14:44
A vulnerability in Verizon's Call Filter API allowed users to potentially access the incoming call logs of other Verizon Wireless customers. Security researcher Evan Connelly discovered in February 2025 that the API endpoint used by the Call Filter app to retrieve a user's call history did not verify the phone number in the request against the logged-in user's phone number. As a result, by manipul...
April, 1st 2025 01.04.2025 14:09
Recent cybersecurity news includes Google's introduction of easy end-to-end encryption (E2EE) for Gmail business users, which simplifies the process of sending encrypted emails to any recipient by abstracting away complex certificate requirements. In another development, Microsoft utilized its AI-powered Security Copilot to discover twenty previously unknown vulnerabilities in the GRUB2, U-Boot, a...
March 25th, 2025 25.03.2025 17:40
Genetic testing provider 23andMe has filed for Chapter 11 bankruptcy after facing years of financial difficulties and plans to sell its assets. Following this news, privacy experts have raised concerns about the potential exposure of customers' genetic information, even though the company has stated its commitment to safeguarding data. Consequently, the Office of California's Attorney General has...
March 24th, 2025 24.03.2025 14:24
A recent GitHub Actions supply chain attack primarily targeted Coinbase, a cryptocurrency exchange. The attack involved injecting malicious code into the `reviewdog/action-setup@v1` GitHub Action, which led to the dumping of CI/CD secrets and authentication tokens in GitHub Actions logs. Threat actors then used a stolen Personal Access Token to push a malicious commit to another GitHub Action, `tj...
March 13th, 2025 13.03.2025 13:34
Human error is now the primary factor in data breaches, accounting for 95% of incidents in 2024. This is often exploited through social engineering tactics like phishing, where employees overestimate their ability to detect scams, with nearly 50% admitting to falling for them. Threat actors, such as Blind Eagle and those behind the KoSpy spyware, utilize phishing emails to gain initial access to s...
March 12th, 2025 12.03.2025 12:25
In March 2025, cybersecurity incidents were reported, including Chinese cyberspies backdooring Juniper routers, Mozilla warning Firefox users to update their browsers, and the social media platform X (formerly Twitter) being hit by a massive cyberattack. The attack on X, claimed by the hacktivist group Dark Storm, led to worldwide outages and the implementation of DDoS protections from Cloudflare....
March 10th, 2025 10.03.2025 22:06
Recent cybersecurity news includes a data breach at NTT impacting 18,000 companies, a ransomware gang using a webcam to bypass EDR, and US cities warning about unpaid parking phishing texts. The NTT data breach, discovered in early February 2025, compromised the information of almost 18,000 corporate customers. An Akira ransomware gang utilized an unsecured webcam to encrypt a victim's network, ci...
March 6th, 2025 06.03.2025 13:05
Several recent cybersecurity incidents and advisories have been reported, including the detection of Stingray attacks using the open-source tool 'Rayhunter'. Additionally, the Chinese cyber-espionage group 'Silk Typhoon' is now targeting IT supply chains to breach networks. Furthermore, YouTube has issued a warning about AI-generated videos of its CEO being used in phishing attacks to steal creato...
March 5th, 2025 05.03.2025 15:38
Recent cybersecurity news includes a vulnerability in Cisco Webex for BroadWorks that could allow remote access to credentials, addressed by a configuration change. Scammers are sending fake BianLian ransom notes via mail to U.S. companies, demanding Bitcoin payments. A new botnet, Eleven11bot, has infected over 86,000 IoT devices, mainly security cameras and NVRs, to conduct DDoS attacks.
March 4th, 2025 04.03.2025 14:16
In recent cybersecurity news, several important developments have emerged: The Cybersecurity and Infrastructure Security Agency (CISA) is continuing its monitoring of Russian cyber threats, refuting claims that it would stop. Google has addressed multiple Android vulnerabilities, including zero-day exploits used by Serbian authorities. Rubrik, a cybersecurity company specializing in data protectio...
March 3rd, 2025 03.03.2025 13:36
In the realm of cybersecurity, recent events highlight the growing concerns around data privacy and security. Mozilla updated its Firefox terms of use following criticism over broad data license language. A study revealed that nearly 12,000 API keys and passwords were found in AI training datasets, raising concerns about insecure coding practices and potential misuse. Furthermore, Serbian police r...
February 28th, 2025 28.02.2025 21:07
The discussion centers on three major cybersecurity concerns: the security of access management systems, legislative threats to digital privacy, and the proliferation of malware botnets. Flaws in access management systems can lead to unauthorized access and data breaches. Simultaneously, legislative actions, particularly those that mandate backdoors in encrypted systems or limit VPN access, raise...
February 26th, 2025 26.02.2025 15:35
Several organizations have recently reported data breaches and ransomware attacks. Genea, an Australian IVF provider, was breached by the Termite ransomware gang, who claimed to have stolen roughly 700GB of data. EncryptHub (aka Larva-208) has compromised at least 618 organizations since June 2024 using phishing and social engineering to deploy infostealers and ransomware. DISA Global Solutions, a...
February 25th, 2025 25.02.2025 15:21
In cloud security, Google Cloud KMS now supports quantum-safe digital signatures compliant with NIST standards, using methods like ML-DSA-65 and SLH-DSA-SHA2-128S to protect against future quantum threats. Meanwhile, North Korean hackers, specifically the Lazarus group, have been linked to a $1.5 billion crypto heist from Bybit, exploiting a transfer of funds from a cold wallet to a hot wallet. Ad...
February 21st, 2025 21.02.2025 14:41
In the realm of cybersecurity, several significant developments have occurred: A healthcare organization in the U.S. paid a substantial settlement for alleged cybersecurity lapses. Microsoft is also making strides in quantum computing with the development of the Majorana 1 chip, which could impact data encryption. Simultaneously, the Darcula phishing platform is evolving, offering advanced tools f...
February 20th, 2025 20.02.2025 11:06
Today's topic involves a look at cybersecurity threats and vulnerabilities. These include infostealer attacks targeting major U.S. defense contractors and military personnel, where sensitive data can be stolen for as little as $10 per computer. Another issue is an Apple iOS vulnerability allowing unauthenticated bypass via USB connections, which was addressed in iOS 18.3.1. Finally, the venture ca...
February 18th, 2025 18.02.2025 10:34
Finastra, a financial technology company, dealt with the fallout of a data breach from the previous October, where unauthorized access to their systems led to the theft of personal information. Lee Enterprises, a newspaper publisher, experienced a ransomware attack that disrupted their operations, affecting distribution and billing processes. Microsoft reported a device code phishing campaign pote...
February 14th, 2025 14.02.2025 15:00
Chinese state-sponsored hackers known as RedMike are targeting telecommunications companies and universities by exploiting vulnerabilities in Cisco devices. The group is using known flaws, specifically CVE-2023-20198 and CVE-2023-2027, to gain administrator control of Cisco IOS XE appliances. These vulnerabilities allow for elevation of privilege, providing a foothold for further network intrusion...
February 13th, 2025 13.02.2025 14:51
A critical vulnerability in Nvidia's container software could allow attackers to gain root privileges on host servers by mounting the host’s root filesystem into a container, granting unrestricted access to all of the host’s files. This flaw affects AI applications running the vulnerable container toolkit, whether in the cloud or on-premises. Additionally, North Korean hackers are using a social e...
February 12th, 2025 12.02.2025 10:30
The stories discuss recent cybercrime activities, including a SIM swap attack on the U.S. Securities and Exchange Commission (SEC) X account, indictments of 8Base ransomware operators, and sanctions against Zservers, a bulletproof hosting service used by LockBit affiliates. The SEC account was hacked via SIM swapping, which allowed the perpetrator to post false information about Bitcoin ETFs, caus...
February 11th, 2025 11.02.2025 10:49
A large-scale brute-force attack is using nearly 2.8 million IP addresses daily to target networking devices from Palo Alto Networks, Ivanti, and SonicWall. The attack, which originates mostly from Brazil, Turkey, Russia, Argentina, Morocco, and Mexico, attempts to steal credentials by repeatedly logging into accounts. Once attackers gain access, they can then infiltrate corporate networks. Securi...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.