Daily Security Review

Daily Security Review

Daily Security Review, the premier source for news and information on security threats, Ransomware and vulnerabilities

Author

Daily Security Review

Category

Technology

Podcast website

dailysecurityreview.com

Latest episode

Oct 29, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

TikTok Fined €530M: GDPR Breach Over Data Transfers to China 05.05.2025

The Irish Data Protection Commission (DPC) has fined TikTok a staggering €530 million ($601 million) for violating the GDPR by transferring European user data to China without ensuring equivalent protection standards. This landmark decision marks one of the largest fines under GDPR and places a spotlight on the persistent challenge of cross-border data transfers—particularly to jurisdictions like...

Endor Labs Raises $93M to Cut AppSec Noise and Secure the Software Supply Chain 05.05.2025

In this episode, we explore the security challenges of the AI-driven software era and how Endor Labs is reshaping application security for the modern development landscape. With $93 million raised in an oversubscribed Series B round and 30x ARR growth in just 18 months, Endor Labs is rapidly emerging as a market leader in securing AI-generated and open-source code. We dive into the platform’s uniq...

CVE-2025-3928: How One Vulnerability Breached Commvault’s Azure Stack 05.05.2025

In this episode, we take a deep dive into CVE-2025-3928—a critical vulnerability in the Commvault Web Server that enables remote attackers to deploy and execute webshells after obtaining valid credentials. This flaw, rated 8.8 on the CVSS 3.1 scale, was exploited as a zero-day by a suspected nation-state actor in February 2025 to breach Commvault’s Azure cloud environment. We unpack how the attack...

Nova Scotia Power, a Canadian Utility, Breached: A Global Warning for Critical Infrastructure 02.05.2025

On April 25, 2025, Nova Scotia Power, the province’s primary electricity provider, confirmed what many suspected: a cyber incident involving unauthorized access had compromised customer data. But what looked at first like an isolated disruption is, in reality, a single node in a much broader—and much more dangerous—global pattern. In this episode, we dive deep into the Nova Scotia Power breach, ex...

SentinelOne Discloses Ongoing Attacks by Nation-State Hackers and Ransomware Gangs 02.05.2025

In a rare move, SentinelOne has publicly confirmed that it is under persistent attack from nation-state threat actors and ransomware gangs. This episode breaks down their recent report detailing how these adversaries—some believed to be backed by China and North Korea—are targeting SentinelOne to gain insight into how thousands of environments are protected. We explore how these campaigns go beyon...

OpenEoX and the Future of End-of-Life Standardization in IT 02.05.2025

In this episode, we unpack the evolving landscape of Product Lifecycle Management (PLM) and why it's become a strategic cornerstone in modern IT environments. From conception to retirement, managing a product’s lifecycle is now about more than just operations—it's about security, compliance, innovation, and cost. We explore the critical milestones of End-of-Life (EOL) and End-of-Support (EOS)—mome...

LayerX Secures $45M Total to Battle Data Leaks, One Browser at a Time 30.04.2025

LayerX just raised another $11 million — and it’s not to build another antivirus. With $45 million in total funding, the company is betting that your browser is the most vulnerable—and most overlooked—part of your cybersecurity stack. In this episode, we explore how LayerX turns everyday browsers like Chrome and Firefox into intelligent defense agents using machine learning. Their extension monito...

$10.5M to Fight AI-Phishing: The Rise of Pistachio’s Cybersecurity Training Platform 30.04.2025

In this episode, we dive into the story of Pistachio , the Norwegian cybersecurity startup that just raised $7 million in new funding—bringing its total to $10.5 million. Pistachio isn’t building another firewall or antivirus tool; it’s targeting the weakest link in most security systems: people . With AI-powered phishing attacks becoming increasingly personalized and harder to detect, Pistachio’s...

AirBorne: How a Zero-Click Bug Threatens Millions of Apple and Third-Party Devices 30.04.2025

In this episode, we dive deep into AirBorne — a critical set of vulnerabilities in Apple’s AirPlay protocol and SDK, recently uncovered by security researchers at Oligo. These flaws enable zero-click, wormable remote code execution (RCE) attacks across iPhones, Macs, Apple TVs, CarPlay systems, and millions of third-party devices. Even more alarming: attackers don’t need physical access or user in...

The Silent Majority: Why 51% of Internet Traffic Is Now Bots 29.04.2025

The bots have taken over—and they’re not just crawling your website. In this episode, we dig into the alarming reality that automated bots now generate over half of all internet traffic. Armed with artificial intelligence and cloaked in residential proxies, these bots are evolving beyond simple scripts into highly evasive, persistent threats targeting every industry. We break down the latest findi...

From 1,382 to 4 Million: What VeriSource Didn’t Know (or Say) 29.04.2025

In this episode, we investigate the massive data breach at VeriSource Services, Inc. (VSI), a Houston-based HR outsourcing and employee benefits administrator. Initially reported as affecting fewer than 2,000 individuals, the breach has now ballooned to a confirmed 4 million affected people. We trace the timeline from the initial detection of suspicious network activity on February 28, 2024, to th...

Actively Exploited: Commvault Web Shells, Active! mail RCE, and Brocade Code Injection Now in KEV 29.04.2025

Three actively exploited vulnerabilities—CVE-2025-42599 (Qualitia Active! mail), CVE-2025-3928 (Commvault Web Server), and CVE-2025-1976 (Broadcom Brocade Fabric OS)—have been added to CISA’s KEV catalog. The Qualitia flaw is a remote stack-based buffer overflow (CVSS 9.8) allowing code execution without authentication. Commvault's vulnerability permits authenticated attackers to deploy web shells...

Hard-Coded Havoc: The Fatal Flaws in Planet’s Network Devices 28.04.2025

A wave of critical vulnerabilities in Planet Technology’s industrial switches and network management systems could let attackers hijack devices, steal data, and sabotage industrial networks—with no credentials required. In this urgent episode, we dissect: 🔓 The 5 worst flaws (CVSS 9.3+)—from hard-coded database passwords to pre-auth command injection—discovered by Immersive Labs’ Kev Breen. 🏭 Wh...

Craft CMS Crisis: The 10.0-Rated RCE Flaw Every Developer Must Patch Now 28.04.2025

A critical, actively exploited vulnerability (CVE-2025-32432) is wreaking havoc on Craft CMS—allowing attackers to execute arbitrary PHP code on unpatched servers with no authentication required . In this urgent episode, we break down: 💥 Why this flaw scores a perfect 10.0 CVSS—the highest severity rating possible. 🔍 How hackers are exploiting it: From stealing data to uploading PHP web shells (...

Policy Puppetry: How a Single Prompt Can Trick ChatGPT, Gemini & More Into Revealing Secrets 28.04.2025

Recent research by HiddenLayer has uncovered a shocking new AI vulnerability—dubbed the "Policy Puppetry Attack"—that can bypass safety guardrails in all major LLMs, including ChatGPT, Gemini, Claude, and more. In this episode, we dive deep into: 🔓 How a single, cleverly crafted prompt can trick AI into generating harmful content—from bomb-making guides to uranium enrichment. 💻 The scary simplic...

Lazarus Strikes Again: Inside Operation SyncHole and the 1-Day Exploitation Crisis 25.04.2025

In this episode, we break down the most urgent cybersecurity developments from late April 2025—including the Lazarus Group’s high-profile “Operation SyncHole” targeting South Korean industries. Discover how attackers are exploiting newly disclosed vulnerabilities faster than ever, with nearly 1 in 3 CVEs weaponized within 24 hours of publication. We dive deep into the Lazarus Group's tactics, incl...

OAuth Phishing and Microsoft 365: The Hidden Threats SMBs Can't Ignore 25.04.2025

In this episode, we dissect the real-world challenges of securing Microsoft 365 environments—especially for small and medium-sized businesses—amid rising threats and licensing limitations. From Reddit frustrations to official Microsoft documentation, we explore the harsh truth: many essential security features, like alerting on suspicious logins, require Azure AD Premium or Defender for Cloud Apps...

Why Outlook Is Eating Your CPU — And What Microsoft Says About It 25.04.2025

Microsoft has acknowledged a serious issue affecting users of classic Outlook for Windows: CPU usage spikes up to 50% just from typing emails. First appearing in builds released since November 2024, this bug is now hitting users across several update channels—including Current, Monthly Enterprise, and Insider—leading to power drain, sluggish performance, and user frustration. In this episode, we u...

Trojan Map App: Spyware Targets Russian Soldiers via Alpine Quest 24.04.2025

A newly discovered Android spyware campaign is targeting Russian military personnel by weaponizing a popular mapping app. Disguised as a cracked version of Alpine Quest Pro , this trojanized app delivers Android. Spy.1292.origin —a powerful surveillance tool that steals data, tracks location in real-time, and downloads secondary payloads to extract confidential files from apps like Telegram and Wh...

Blue Shield Breach: 4.7 Million Health Records Leaked via Google Analytics 24.04.2025

Blue Shield of California has confirmed a data breach affecting 4.7 million members—caused not by hackers, but by a misconfigured Google Analytics setup. Sensitive health information was inadvertently exposed to Google’s ad platforms between April 2021 and January 2024. In this episode, we break down what went wrong, what data was leaked, and what this means for privacy, compliance, and trust in h...

$16.6 Billion Lost: The True Cost of Cybercrime in America 24.04.2025

Cybercrime in the U.S. has reached new, record-breaking heights. In this episode, we dive deep into the FBI's 2024 Internet Crime Complaint Center (IC3) report — a comprehensive look at the economic and human toll of cybercrime in America. With $16.6 billion in reported losses , a 33% increase year-over-year , and 859,532 complaints filed , the data paints a grim picture of just how widespread and...

The Second Scam: FBI Warns of IC3 Impersonators Targeting Fraud Victims 22.04.2025

The FBI has issued a stark warning about a growing scam targeting individuals who’ve already been victimized. In this episode, we unpack how fraudsters are impersonating employees of the FBI's Internet Crime Complaint Center (IC3), promising to help victims recover lost funds — only to scam them again. We’ll break down: How the scam works and why it’s spreading The tactics scammers use to build tr...

Inside the Breach: What Recent Cyberattacks Reveal About Your Data Security 16.04.2025

Cyberattacks are no longer rare shocks—they're a constant drumbeat in the background of our digital lives. In this episode, we take you on a deep dive into some of the most alarming recent data breaches , unpacking how they happened, what went wrong, and what you need to know to stay protected. We kick off with the Western Sydney University breach , where personal data of thousands of students end...

Inside Security News : GitHub Supply Chain Attacks, Ransomware Defense, and Cloud Security 15.04.2025

In this deep-dive episode, we untangle some of today’s most critical cybersecurity threats—from GitHub’s complex quadruple supply chain attack to the rising concerns over Kubernetes vulnerabilities and serious flaws in Next.js. 🧠💻 We kick things off with an inside look at StoneFly’s robust approach to data protection, from immutable air-gapped backups to ransomware-resistant infrastructure. Then...

Next.js Security Vulnerability: Middleware Bypass (CVE-2025-29927) 14.04.2025

Is your web app truly secure? In this episode, we break down a critical NextJS vulnerability (CVE-2025-29927) that could allow attackers to bypass authentication and access sensitive data—impacting millions of websites. We explain what went wrong, what it means for your projects, and exactly how to fix it (even if you can’t upgrade yet). Then, we pivot to something equally vital: disaster recovery...

Listen to the Daily Security Review podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.