Alice & Bob
Cyber Mornings Daily
Cyber Mornings Daily is your go-to daily podcast for the latest cybersecurity news, trends, and insights, delivered by AI. Each episode delivers a concise and informative breakdown of the most pressing cyber threats, vulnerabilities, and breaches.
Author
Alice & Bob
Category
Podcast website
Latest episode
Jul 10, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
February 7th, 2025 07.02.2025 21:42
Recent cybersecurity news includes information on a critical Cisco ISE bug, a former Google engineer charged with stealing AI trade secrets, and Kimsuky hackers using a new custom RDP Wrapper for remote access. A critical vulnerability in Cisco's Identity Services Engine (ISE) allows attackers with read-only admin privileges to execute arbitrary commands as root. This vulnerability is due to insec...
February 6th, 2025 06.02.2025 11:37
Several cybersecurity incidents have been reported recently, including a breach at British engineering firm IMI, a critical vulnerability in Microsoft's Azure AI Face service, and the arrest of a hacker in Spain for attacks on various organizations. IMI disclosed a security breach after detecting unauthorized access to its systems and is working with cybersecurity experts to investigate the incide...
February 4th, 2025 04.02.2025 13:37
Cybercriminals are using increasingly sophisticated methods, including phishing toolkits and AI, to conduct attacks. Business email compromise (BEC) schemes are a common tactic, where criminals trick companies into making payments to fraudulent accounts. Additionally, state-sponsored actors are using AI tools such as Google's Gemini to streamline their hacking activities, spanning reconnaissance t...
February 3rd, 2025 03.02.2025 18:10
A new Mirai-based botnet, Aquabotv3, is exploiting a vulnerability in Mitel internet-connected phones to create a platform for DDoS attacks. Tata Technologies, an Indian tech firm, experienced a ransomware attack that temporarily suspended some IT services, although client delivery remained operational. Mizuno USA, a sporting goods manufacturer, had its network breached for two months by attackers...
January 31st, 2025 31.01.2025 16:25
A vulnerability called "Time Bandit" can be used to jailbreak the ChatGPT-4o model by creating "time line confusion". This is done by using prompts that refer to a specific time period and then shifting to forbidden topics. The model may then provide instructions or code related to these topics because it is responding in the context of the earlier time period. The Time Bandit vulnerability can be...
January 30th, 2025 30.01.2025 13:10
The FBI seized the domains of the hacking forums Cracked.io and Nulled.to as part of "Operation Talent," a joint law enforcement effort. These forums were known for cybercrime, including password theft and credential stuffing. The FBI also seized domains used by MySellIX, SellIX, and StarkRDP. The UK's NCSC has suggested classifying vulnerabilities as either "forgivable" or "unforgivable," with "f...
January 29th, 2025 29.01.2025 13:40
Microsoft is testing a new "scareware blocker" feature for the Edge browser that uses machine learning to detect tech support scams. This feature adds a first line of defense by using computer vision to compare full screen pages to thousands of sample scams and alerts users when a scam page is detected. Additionally, new side-channel vulnerabilities in Apple processors, named FLOP and SLAP, can st...
January 28th, 2025 28.01.2025 9:12
The sources discuss several cybersecurity topics, including zero-day vulnerabilities in Apple products, a new security measure implemented by Bitwarden to protect password vaults, and a cyberattack against the DeepSeek AI platform. The Apple zero-day, tracked as CVE-2025-24085, is a privilege escalation flaw in the Core Media framework that has been actively exploited. Bitwarden is now requiring e...
January 27th, 2025 27.01.2025 18:21
Today's news includes information about several cybersecurity incidents. Ivanti appliances are vulnerable to chained exploits, where attackers combine multiple flaws to gain significant access. PayPal was fined $2 million for failing to secure customer data, specifically Social Security numbers, due to issues with their 1099 tax form system and inadequate security protocols. TalkTalk, a UK telecom...
January 24th, 2025 24.01.2025 17:16
Multiple security vulnerabilities and flaws have been discovered recently. A flaw in Cloudflare's content delivery network (CDN) could expose a person's general location by sending them an image. Security vendor Eclypsium found several security flaws impacting Palo Alto Networks firewalls, including issues that could allow attackers to evade Secure Boot and modify device firmware. SonicWall is urg...
January 23rd, 2025 23.01.2025 11:27
A cyberattack campaign is using a fake Homebrew site promoted through Google ads to distribute the Amos infostealer malware to macOS and Linux users. The campaign redirects users from a legitimate-looking Homebrew ad to a fake site, "brewe.sh". This malware targets technical users likely to use Homebrew who may have cryptocurrency wallets or sensitive work credentials. A vulnerability in the 7-Zip...
January 21st, 2025 21.01.2025 9:07
The Federal Trade Commission (FTC) is taking action against GoDaddy, a major web hosting company, for alleged lax data security practices that put its customers at risk. The FTC claims that GoDaddy failed to implement adequate security measures, leading to multiple security breaches between 2019 and 2022. In a separate incident, Hewlett Packard Enterprise (HPE) is investigating claims of a data br...
January 17th, 2025 - Special Executive Order Edition 17.01.2025 23:06
President Biden's January 16, 2025 Executive Order focuses on enhancing the nation's cybersecurity. It mandates numerous actions to improve the security of federal systems and software supply chains, particularly targeting threats from China. Key initiatives include strengthening software development practices, improving federal identity management, and promoting the use of AI in cybersecurity. Th...
January 16th, 2025 16.01.2025 13:47
A hacking group known as the "Belsen Group" has leaked configuration files, IP addresses, and VPN credentials for over 15,000 FortiGate devices. This data was leaked on the dark web, making it readily available to other cybercriminals. The leak is believed to be related to a 2022 zero-day vulnerability known as CVE-2022–40684, which was exploited before a fix was available. The leaked configuratio...
January 15th, 2025 15.01.2025 11:52
First, the FBI's operation to remove the Chinese PlugX malware, which was found on thousands of computers in the United States. This malware was linked to a Chinese cyber espionage group known as Mustang Panda and was capable of spreading through USB drives. Next, a flaw in Google's OAuth system that could allow attackers to access abandoned accounts by registering the domains of defunct startups....
January 14th, 2025 14.01.2025 17:41
Today's articles highlight the serious impact cybersecurity vulnerabilities can have on organizations and individuals. A critical flaw in the Aviatrix Controller was exploited in the wild, leading to cryptojacking and backdoor deployment. This incident emphasizes the need for prompt patching and thorough API security testing. A ransomware attack on OneBlood exposed the names and Social Security nu...
January 13th, 2025 13.01.2025 22:26
FunkSec, a new ransomware group, stands out for its use of AI in crafting its code, potentially indicating a new level of sophistication in ransomware development. This group, despite its apparent inexperience and hacktivist roots, has rapidly gained notoriety, claiming an alarming number of victims in a short period. Beyond ransomware, the stories detail other significant cyber threats. Telefónic...
January 10th, 2025 10.01.2025 14:21
One notable incident involves a class action lawsuit against Google, alleging the company collected user data even after users opted out. The case went to trial in August 2025, highlighting the ongoing tension between data collection practices and user privacy expectations. Another high-profile incident involved BayMark Health Services, North America's largest addiction treatment provider, which s...
January 9th, 2025 09.01.2025 11:37
First, a phishing scheme where attackers used legitimate PayPal email addresses to gain control of users' accounts. This scheme involved creating an email distribution list with an attacker-controlled address and using PayPal to send a payment request to that address, ultimately linking the victim’s account to the attacker’s email. Next, over 4,000 abandoned web backdoors were hijacked by register...
January 8th, 2025 08.01.2025 11:06
First, a new Mirai botnet exploiting zero-day vulnerabilities in industrial routers and smart home devices to launch DDoS attacks. Next, a data breach at the International Civil Aviation Organization (ICAO), exposing approximately 42,000 recruitment records. Finally, the U.S. government's launch of a cybersecurity safety label, the U.S. Cyber Trust Mark, for consumer smart devices to improve their...
January 7th, 2025 07.01.2025 12:32
One story reports on Chinese state-sponsored hackers breaching multiple US telecommunication companies, including Charter and Windstream, leading to government action and calls for improved network security. Another describes a data breach targeting the Green Bay Packers' online store, resulting in the theft of customer payment information and prompting credit monitoring services for affected indi...
January, 6th, 2025 06.01.2025 11:26
ESET is urging Windows 10 users to upgrade to Windows 11 or Linux to avoid security issues. Windows 10's end of support is October 14th, 2025. After that date, the operating system will no longer receive free security updates, leaving users vulnerable. About 63% of Windows users worldwide are still using Windows 10, which is more than were using Windows 10 before Windows 7 reached end of support....
January 3rd, 2025 03.01.2025 15:23
The first explores how government intervention will shape the future of cybersecurity and artificial intelligence. The second highlights the ongoing struggle against cyber threats, with a major company denying involvement in a ransomware attack. The third focuses on the critical issue of data privacy, with a tech giant facing legal consequences for potential misuse of user data. These headlines co...
January 2nd, 2025 02.01.2025 17:43
A year-end review of 2024's major cybersecurity events details significant breaches affecting various organizations, including the US Treasury Department, Microsoft, and Internet Archive. The show highlights impactful ransomware attacks like those targeting CDK Global and Change Healthcare, and discusses the rise of infostealers and the impact of compromised edge devices. Furthermore, it covers ge...
December 31st, 2024 31.12.2024 19:21
A Christmas Day supply chain attack compromised popular Chrome extensions, potentially impacting millions of users. This incident highlights the vulnerability of software ecosystems and the critical need for robust security measures throughout the entire software development lifecycle. Meanwhile, a wave of massive healthcare breaches has spurred the US government to consider a significant overhaul...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.