Daily Security Review
Daily Security Review
Daily Security Review, the premier source for news and information on security threats, Ransomware and vulnerabilities
Author
Daily Security Review
Category
Podcast website
Latest episode
Oct 29, 2025
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Multi-Stage Phishing Attacks Now Use Google Infrastructure—Here’s How 02.06.2025 13:51
Recent phishing campaigns have entered a new phase—one where trust is weaponized. In this episode, we break down how cybercriminals are exploiting legitimate services like Google Apps Script and Google Firebase Storage to host phishing pages, evade detection, and steal credentials. Using cleverly crafted lures such as fake DocuSign notifications, invoice alerts, and even deceptive CAPTCHA prompts,...
Inside the AVCheck Takedown: How Law Enforcement Disrupted a Key Cybercrime Tool 02.06.2025 17:34
In this episode, we unpack the international takedown of AVCheck, one of the largest counter antivirus (CAV) services used by cybercriminals to test and fine-tune malware before deployment. Led by Dutch authorities and supported by agencies from the U.S., Germany, France, and others, this operation marks a major win in Operation Endgame—a sweeping initiative targeting malware infrastructure, ranso...
ConnectWise Breach: Nation-State Exploits CVE-2025-3935 in ScreenConnect 30.05.2025 15:06
ConnectWise has confirmed a cyberattack targeting ScreenConnect, its remote access solution used by thousands of Managed Service Providers (MSPs). The breach is reportedly tied to a sophisticated nation-state actor and linked to CVE-2025-3935, a critical ViewState code injection vulnerability that could allow Remote Code Execution (RCE). In this episode, we dissect what happened, why it matters, a...
Browser vs. GPU: Firefox 139 Collides with NVIDIA Drivers 30.05.2025 14:10
In this episode, we dive into the graphical corruption saga triggered by Firefox version 139, released on May 27, 2025. Aimed at uncovering what went wrong, we review reports from across the web detailing how the update wreaked havoc for Windows users running NVIDIA graphics cards—particularly those with multi-monitor setups using mixed refresh rates. We discuss the symptoms users experienced: sev...
Unbound Raises $4M to Secure Generative AI in the Enterprise 30.05.2025 20:08
In this episode, we break down the recent $4 million seed funding round for Unbound, a startup tackling one of the biggest unsolved problems in enterprise AI: how to stop employees from leaking sensitive data through ungoverned use of Generative AI tools. Unbound’s AI Gateway aims to be the missing link between rapid AI adoption and responsible usage—offering real-time redaction of sensitive promp...
Windows Updates, Reimagined: Inside Microsoft’s Unified Orchestration Push 29.05.2025 16:18
Microsoft is taking direct aim at one of the biggest pain points in the Windows ecosystem: update fragmentation. In this episode, we dive deep into the details of Microsoft’s newly announced Windows-native update orchestration platform , currently in private preview. We explore how this unified infrastructure aims to centralize updates for all apps, drivers, and core OS components under the famili...
Systemd as a Weapon: How PumaBot Exploits Linux Persistence 29.05.2025 18:38
Linux systems are under siege—particularly in the world of IoT and internet-exposed servers. In this episode, we dissect PumaBot, a new GoLang-based botnet that's turning Linux IoT devices into cryptomining workhorses. We’ll break down how attackers brute-force SSH credentials, install malware disguised as legitimate services, and use systemd for stealthy persistence. We dive deep into ATT&CK...
The LexisNexis Breach: 364,000 Records Exposed via GitHub 29.05.2025 17:22
On December 25, 2024, while most businesses were offline, a serious data breach struck LexisNexis Risk Solutions—exposing the personal data of over 360,000 individuals. The twist? The attack vector wasn’t a direct hack, but an indirect compromise through a third-party GitHub repository. Even more concerning, the breach went undetected until April 1, 2025. In this episode, we break down the timelin...
Ransomware Hits MathWorks: Week-Long Outage Disrupts Millions 28.05.2025 12:30
On this episode, we dissect the ransomware attack that brought MathWorks—a cornerstone software provider for engineers, scientists, and educators—to a grinding halt. The attack, which began on May 18, 2025, and was officially confirmed on May 26, crippled a wide range of customer-facing and internal systems, from MATLAB Online and ThingSpeak to license distribution and downloads. We examine the ti...
Zscaler Acquires Red Canary: What It Means for AI-Powered Security Operations 28.05.2025 14:27
The cybersecurity market is booming, projected to triple in size from $215 billion in 2025 to $697 billion by 2035. This explosive growth is being fueled by rising cyber threats, the digital transformation of global businesses, and an urgent need for advanced security operations. One of the clearest signals of this momentum? Zscaler’s acquisition of Red Canary—a leading Managed Detection and Respo...
DragonForce Breaches MSPs via SimpleHelp Flaws: Inside CVE-2024-57726 28.05.2025 16:47
In this episode, we unpack a critical supply chain breach that’s rattled the cybersecurity world: the exploitation of multiple zero-day vulnerabilities in SimpleHelp Remote Support Software — most notably CVE-2024-57726, a privilege escalation flaw scored 9.9 by the NVD. Threat actors linked to the DragonForce ransomware operation and the Scattered Spider group are actively leveraging these vulner...
Fentanyl, Firearms, and $200M in Crypto: Dark Web Crime Meets Global Law Enforcement 27.05.2025 13:50
This episode dives deep into Operation RapTor, one of the largest international crackdowns on dark web crime to date. We analyze how coordinated law enforcement actions across ten countries led to the arrest of 270 individuals, the seizure of $200 million in currency and digital assets, and the dismantling of major darknet marketplaces including Incognito, Tor2Door, and Bohemia. We explore the per...
Marlboro-Chesterfield Pathology Ransomware Breach: 235,000 Patients Affected 27.05.2025 12:27
In this episode, we take a deep dive into the recent Marlboro-Chesterfield Pathology (MCP) ransomware attack—one of the most significant healthcare breaches of 2025. On January 16th, MCP detected unauthorized activity on its internal systems. Just days later, the SAFEPAY ransomware group claimed responsibility, posting stolen data—over 30GB of sensitive information affecting 235,911 individuals—on...
How Infostealers Like Stealc Use TikTok Accounts to Exfiltrate Stolen Data 27.05.2025 22:54
In this episode, we dive deep into the underground cybercrime ecosystem powering the surge of modern infostealers—Stealc, Vidar, and LummaC2. These malware strains aren't just code—they're full-service products sold as Malware-as-a-Service (MaaS), giving even low-skilled attackers access to powerful data theft tools. We break down how these stealers are delivered through clever deception tactics l...
The Great Screenshot Scandal: Microsoft Recall and Signal’s DRM Shield 26.05.2025 28:34
In this episode, we dive deep into the growing tension between AI innovation and data privacy through the lens of a major controversy: Microsoft’s Windows 11 Recall feature. Designed to screenshot nearly everything a user does every few seconds, Recall creates a searchable visual archive of on-screen activity. But while Microsoft claims it enhances productivity, critics call it “spyware,” “creepy,...
Bumblebee Malware Returns: IT Pros Targeted Through SEO Poisoning and Typosquatting 26.05.2025 28:48
In this episode, we break down the resurgence of the Bumblebee malware loader and its latest distribution method: blackhat SEO campaigns and trojanized software installers. By mimicking legitimate download pages through typosquatted domains and poisoning Bing search results, attackers are tricking IT professionals into unknowingly infecting their own networks. We explore how malware is being embed...
FBI Warns of Luna Moth Tactics: Inside the Silent Ransom Group’s Law Firm Attacks 26.05.2025 14:45
In this episode, we dive into the evolving tactics of the Silent Ransom Group (SRG)—also known as Luna Moth—a cybercriminal outfit that has shifted from traditional phishing to a new, more deceptive strategy: impersonating IT support over the phone. Their latest victims? U.S. law firms, targeted for the sensitive data they hold and the large financial transactions they handle. We explore how SRG u...
Trust Exploited: Unpacking the macOS Malware Attacking Ledger Wallets 23.05.2025 25:57
A growing cyber threat is targeting macOS users who rely on Ledger cold wallets to secure their cryptocurrency. In this episode, we dissect the anti-Ledger malware campaign—an increasingly sophisticated phishing operation that impersonates the trusted Ledger Live application to trick users into revealing their 24-word recovery phrases. Once entered, these phrases give attackers full access to empt...
$21M Seized and DanaBot, Qakbot, and Bumblebee Disrupted in Operation Endgame Takedown 23.05.2025 11:23
In this episode, we break down the latest and most impactful phase of Operation Endgame, the international law enforcement campaign targeting the backbone of the ransomware ecosystem. Between May 19–22, authorities executed a sweeping takedown of 300 servers, neutralized 650 domains, and seized €3.5 million in cryptocurrency, adding to a total of €21.2 million seized over the course of the operati...
From TikTok to Total Compromise: The Rise of Social Media Infostealers 23.05.2025 18:50
In this episode, we dive into the alarming surge of infostealer malware campaigns leveraging social media platforms, particularly TikTok, as their distribution vector. Threat actors are exploiting trending content—especially around AI tools like Sora, ChatGPT, and Google Gemini AI, and popular software like CapCut and MidJourney—to bait unsuspecting users into executing malicious PowerShell comman...
Kettering Health Breached: What the Interlock Ransomware Group Did and Why It Matters 22.05.2025 23:33
In this episode, we dive into the ransomware attack that struck Kettering Health, a major healthcare provider, and the evolving tactics of the Interlock ransomware group behind it. Interlock, active since late 2024, has adopted advanced techniques including double extortion, credential theft, and PowerShell-based backdoors to compromise healthcare systems. The attack on Kettering Health disrupted...
Deepfake Threats, Mobile Biometrics, and the Future of Trust 22.05.2025 17:01
As digital deception evolves, so must our defenses. In this episode, we dive deep into the escalating battle for trust in our increasingly connected world. From nation-state-level authentication models to real-time behavioral biometrics on your mobile device, the tools to verify identity are becoming more sophisticated—and more essential—than ever. We unpack the concept of a Pervasive Trusted Ecos...
119,000 ICS Devices Exposed: The Internet’s Hidden Infrastructure Risk 22.05.2025 20:00
In this episode, we dive into a growing cybersecurity crisis: the exposure of Industrial Control Systems (ICS) on the public internet. These systems power our electric grids, water supplies, and industrial automation—but thousands are reachable online, often unsecured. We explore how researchers are working to distinguish between real ICS devices and honeypots—decoys used to bait cyber attackers....
Arla Foods Upahl Site Hit by Cyberattack—What It Means for Food Supply Chains 20.05.2025 17:58
In May 2025, a cyberattack disrupted operations at Arla Foods’ major dairy facility in Upahl, Germany—halting skyr production, impacting local IT systems, and forcing product delivery delays. This episode explores how a ransomware incident brought one of Europe’s leading food manufacturers to a standstill, revealing how vulnerable the food industry is to modern cyber threats. We examine the critic...
Bypassing Antivirus: What Defendnot Reveals About the Weak Spots in Windows Security 20.05.2025 19:52
In this episode, we dissect one of the most advanced Windows security evasion tools released in recent memory: Defendnot . Designed to exploit undocumented Windows Security Center APIs, this tool disables Windows Defender by impersonating a trusted antivirus and injecting its code into Microsoft-signed Task Manager. We explore how Defendnot bypasses Protected Process Light and security signatures,...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.