Daily Security Review

Daily Security Review

Daily Security Review, the premier source for news and information on security threats, Ransomware and vulnerabilities

Author

Daily Security Review

Category

Technology

Podcast website

dailysecurityreview.com

Latest episode

Oct 29, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

BreachRx Raises $15M to Automate the Chaos of Incident Response 20.05.2025

In this episode, we dive into BreachRx’s $15 million Series A raise — and what it means for the future of enterprise cybersecurity incident response. The intelligent SaaS platform promises to replace outdated, reactive playbooks with automated, tailored response plans that span legal, security, IT, and executive teams. With participation from top cybersecurity VCs and the addition of industry gian...

110,000+ Records Compromised: The NRS Cybersecurity Failure 19.05.2025

In this episode, we unpack the 2024 cybersecurity incident that rocked the debt collection and healthcare sectors: the massive data breach at Nationwide Recovery Services (NRS), a third-party collections agency and subsidiary of ACCSCIENT. Between July 5 and July 11, 2024, threat actors gained unauthorized access to NRS’s systems, exfiltrating sensitive personal and medical data belonging to indiv...

CISA Flags Chrome Vulnerability CVE-2025-4664: Patch Before June 5th 19.05.2025

In this episode, we break down the recently discovered and actively exploited Chrome vulnerability CVE-2025-4664—a high-severity flaw stemming from insufficient policy enforcement in Chrome’s Loader component. This vulnerability allows attackers to leak cross-origin data, including sensitive query parameters and session information, via crafted HTML pages. Even more alarming: it's not limited to C...

483,000 Patients at Risk: Catholic Health Vendor Breach Exposes Critical Data 19.05.2025

In this episode, we dive deep into a newly disclosed healthcare data breach affecting over 483,000 patients of Catholic Health, stemming from a misconfigured Elasticsearch database maintained by third-party vendor Serviceaide. From September 19 to November 5, 2024, the database was inadvertently exposed to the public internet, putting highly sensitive information—including names, Social Security n...

Chrome's New Vulnerability CVE-2025-4664: A Security Flaw That Can Lead to Account Takeover 16.05.2025

In this episode, we take an in-depth look at the newly discovered CVE-2025-4664 vulnerability in Google Chrome’s Loader component. This high-severity security flaw is affecting not only Chrome but also other Chromium-based browsers, including Microsoft Edge, Brave, Opera, and Vivaldi. The issue lies in insufficient policy enforcement within the browser’s Loader, enabling attackers to manipulate th...

Scattered Spider Targets UK and US Retailers: The Growing Threat to Major Brands 16.05.2025

In this episode, we dive deep into the recent wave of cyberattacks plaguing major UK retailers such as Marks & Spencer, Co-op, and Harrods, with a special focus on the threat group behind them: Scattered Spider (also known as UNC3944, Muddled Libra, and several other aliases). We'll explore how this loosely coordinated cybercriminal group has expanded its operations from targeting casinos to n...

Proofpoint Acquires Hornetsecurity for $1B: A New Era in Microsoft 365 Security 16.05.2025

 In a major move within the cybersecurity space, Proofpoint has announced the acquisition of Hornetsecurity for over $1 billion. This deal significantly strengthens Proofpoint’s foothold in Microsoft 365 security, while expanding its reach into the small and mid-sized business (SMB) market through Hornetsecurity’s extensive network of managed service providers (MSPs) in Europe. In today’s episode,...

Exploited in the Wild: SAP NetWeaver Zero-Days Hit Fortune 500 14.05.2025

In this episode, we dive into the active exploitation of two critical zero-day vulnerabilities in SAP NetWeaver—CVE-2025-31324 and CVE-2025-42999. Threat actors have been leveraging these flaws since January 2025 to gain unauthenticated access, upload malicious web shells, and ultimately achieve remote code execution by chaining an insecure deserialization bug. With over 2,000 vulnerable SAP NetWe...

Checkout Chaos: Inside the £3.5 Million-a-Day M&S Cyber-Shutdown 14.05.2025

The recent ransomware attack on Marks & Spencer (M&S) is a sobering example of the evolving cyber threat landscape confronting the retail industry. In this episode, we unpack how one of the UK's most iconic retailers fell victim to a sophisticated cybercriminal group known as Scattered Spider. This group, recognized for its advanced social engineering tactics, reportedly infiltrated M&...

Targeted iOS Attacks: The Zero-Days Apple Had to Patch Fast 14.05.2025

In this episode, we break down Apple’s massive May 2025 security update blitz—a sweeping patch release that spanned iOS, macOS, iPadOS, tvOS, visionOS, and watchOS. The urgency? Two zero-day vulnerabilities, CVE-2025-31200 (Core Audio) and CVE-2025-31201 (Core Media), were already under active exploitation in what experts are calling “extremely sophisticated, targeted attacks.” We’ll dig into the...

Texas vs Google: The $1.4 Billion Wake-Up Call for Data Privacy Violations 13.05.2025

In this episode, we unpack the groundbreaking $1.4 billion privacy settlement between Google and the state of Texas—now the largest of its kind in U.S. history. This isn't just about numbers; it's about how data privacy enforcement is shifting dramatically at the state level in the absence of federal legislation. We dive deep into the Texas Capture or Use of Biometric Identifier Act (CUBI), the co...

Marbled Dust's Zero-Day Exploit: Unveiling a Türkiye-linked Espionage Campaign Against Kurdish Forces 13.05.2025

In April 2024, a sophisticated cyber espionage campaign orchestrated by the Türkiye-linked hacker group, Marbled Dust, began exploiting a previously unknown zero-day vulnerability in the Output Messenger platform—a self-hosted enterprise chat application. This vulnerability (CVE-2025-27920) resides in the Output Messenger Server Manager and allows attackers to upload malicious files, such as GoLan...

TeleMessage Exploit: Inside the Messaging Flaw That Hit Coinbase and CBP 13.05.2025

In this episode, we dissect CVE-2025-47729, a critical vulnerability in TeleMessage , a message archiving app recently thrust into the spotlight due to its use by former National Security Advisor Mike Waltz. Following Waltz’s controversial tenure—marked by the "Signalgate" leak and the subsequent appearance of TeleMessage on his phone—researchers uncovered a major flaw: a lack of end-to-end encryp...

Backdoored by ‘Cheap’ AI: How Fake npm Packages Compromised Cursor IDE 12.05.2025

A new supply chain attack has emerged—this time targeting macOS users of the Cursor AI code editor through rogue npm packages. In this episode, we break down how threat actors published malicious modules—sw-cur, sw-cur1, and aiide-cur—promising cheap access to Cursor's AI features. Once installed, these packages function as backdoors, stealing credentials, modifying critical application files like...

160,000 Victims Later: The Aspire USA Breach Under Valsoft’s Watch 12.05.2025

In this episode, we break down the February 2025 data breach that hit Valsoft Corporation, operating under the name AllTrust, through its subsidiary Aspire USA. Over 160,000 individuals are potentially impacted, with exposed data including Social Security numbers, driver’s license information, and financial account details. We explore how the breach unfolded over a three-day window, the steps Aspi...

rand-user-agent: The NPM Package That Opened a Backdoor 12.05.2025

In this episode, we break down the recent compromise of the rand-user-agent NPM package—an attack that quietly turned a once-trusted JavaScript library into a delivery mechanism for a Remote Access Trojan (RAT). The attacker exploited the package’s deprecated but still-popular status, publishing malicious versions that never appeared in the GitHub repo. We discuss how the threat actor used obfusca...

PipeMagic, Procdump, and Privilege Escalation: Tracking the Windows CLFS Exploit Chain 08.05.2025

A zero-day vulnerability in the Windows Common Log File System (CLFS), tracked as CVE-2025-29824 , became the center of a global cybersecurity storm when it was exploited in the wild before Microsoft patched it on April 8, 2025. In this episode, we take a deep dive into how this elevation of privilege exploit allowed attackers to gain SYSTEM-level access and deploy ransomware payloads —including t...

Pegasus Spyware, WhatsApp v. NSO Group, and the Global Battle for Data Privacy 08.05.2025

In this episode, we dive deep into the legal, technical, and geopolitical implications of the U.S. court ruling in WhatsApp v. NSO Group —a landmark case in the global effort to hold spyware developers accountable. The conversation unpacks the court’s decision to award over $167 million in damages to WhatsApp for the unauthorized deployment of Pegasus spyware, highlighting violations of anti-hacki...

How CodeAnt AI is Automating Code Reviews for 50+ Dev Teams 08.05.2025

AI tools are generating more code than ever — but who’s reviewing it? In this episode, we spotlight CodeAnt AI, the fast-growing platform built to solve the growing code review bottleneck created by AI-assisted development. You’ll learn how CodeAnt AI: Cuts review time and post-deployment bugs by over 50% Uses a proprietary language-agnostic AST engine to analyze 30+ programming languages Powers o...

The Langflow Breach: How a Popular AI Tool Opened the Door to Hackers 07.05.2025

A newly disclosed zero-day vulnerability, CVE-2025-3248, is being actively exploited in the wild—and it's targeting Langflow, a popular open-source framework for building AI-powered applications. In this episode, we unpack how a missing authentication check in the /api/v1/validate/code endpoint allowed remote attackers to run arbitrary code on unpatched servers. With a critical CVSS score of 9.8 a...

Mirai Reloaded: Why CVE-2024-7399 Still Haunts Samsung Servers 07.05.2025

In this episode, we break down the active exploitation of CVE-2024-7399, a critical path traversal and arbitrary file upload vulnerability in Samsung MagicINFO 9 Server. Despite a patch released in August 2024 (version 21.1050 and later), many systems remain exposed — and threat actors are taking full advantage. We explore how attackers are exploiting this flaw to gain system-level access, upload...

CVE-2025-31324: A Critical SAP Zero-Day in Active Exploitation 07.05.2025

A critical zero-day vulnerability — CVE-2025-31324 — is shaking the enterprise tech world.  In this episode, we dive deep into the alarming exploit targeting SAP NetWeaver Java systems, specifically the Visual Composer component, now under active attack. This vulnerability enables unauthorized file uploads, which attackers are using to deploy webshells, cryptominers (like XMRig), and potential inf...

Another Day, Another Commvault Zero-Day: RCE, Path Traversal, and KEV Inclusions 06.05.2025

In this episode, we break down the anatomy of some of the most critical vulnerabilities threatening enterprise systems in 2025 — and the real-world attacks already exploiting them. We explore how seemingly small issues like path traversal can escalate into full remote code execution (RCE), and how threat actors are chaining vulnerabilities to bypass authentication and compromise systems. We’ll exa...

Kelly Benefits Breach: What 413,000 Exposed Records Teach Us About Cybersecurity 06.05.2025

In this episode, we dive deep into the massive data breach at Kelly Benefits, a payroll and benefits administrator that exposed the sensitive personal data of over 413,000 individuals. We break down what happened, what data was compromised, and how the breach escalated from 32,000 initially impacted people to hundreds of thousands across the country. We also explore the broader implications of the...

$491M Budget Cut: The White House Move That Could Reshape CISA 06.05.2025

 In this episode, we unpack the rising tensions surrounding the Cybersecurity and Infrastructure Security Agency (CISA) as it faces proposed budget cuts, looming layoffs, and growing criticism over alleged mission overreach. While CISA continues to champion its role in defending national infrastructure and guiding cyber resilience, reports of domestic speech monitoring—particularly around election...

Listen to the Daily Security Review podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.