Daily Security Review
Daily Security Review
Daily Security Review, the premier source for news and information on security threats, Ransomware and vulnerabilities
Author
Daily Security Review
Category
Podcast website
Latest episode
Oct 29, 2025
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Cyberattack Roundup: Lessons from the Latest Breaches & Ransomware Strikes 26.03.2025 4:50
From data breaches at major banks to ransomware crippling healthcare and tech companies, cyber threats are hitting harder than ever. In this episode, we break down the latest wave of attacks, the vulnerabilities being exploited, and what organizations can do to protect their data. Key Takeaways: 🔹 Breaking down the latest cyberattacks – Who was hit and how it happened 🔹 Ransomware, supply chain...
Mastering Incident Response: A Guide to Building a Resilient Plan 26.03.2025 18:41
Cyber threats are inevitable, but a strong incident response plan can make all the difference. In this episode, we explore the essential steps for creating an effective incident response strategy, helping organizations detect, respond to, and recover from cyber incidents with minimal disruption. Key Takeaways: 🔹 What is an Incident Response Plan? – Why every organization needs one 🔹 Key componen...
No More Warnings? The Risks of Losing CIPAC’s Cyber Threat Coordination 20.03.2025 15:49
The Department of Homeland Security (DHS) has abruptly shut down the Critical Infrastructure Partnership Advisory Council (CIPAC) , the central hub for cybersecurity collaboration between the government and private sector. Why was it shut down? No one knows. What happens next? That’s the real concern. In this episode, we break down why CIPAC was crucial for national cybersecurity, the risks of los...
517,000 Victims: How a Ransomware Gang Targeted Pennsylvania’s Largest Educators’ Union 20.03.2025 11:52
Over 517,000 individuals are now at risk after the Pennsylvania State Education Association (PSEA) suffered a massive data breach in July 2024—claimed by the Rhysida ransomware gang . Personal, financial, and health data, including Social Security numbers and payment details, were stolen, putting educators and union members at serious risk. In this episode, we break down: 🔹 How Rhysida ransomwar...
DollyWay: The 8-Year WordPress Malware Campaign Infecting 20,000 Sites 20.03.2025 14:04
For nearly a decade, a malware campaign dubbed DollyWay has silently compromised over 20,000 WordPress websites, evolving from a ransomware and banking trojan distributor to a sophisticated scam redirection network. Researchers at GoDaddy have now uncovered the full scale of this operation, which generates 10 million fraudulent ad impressions per month by redirecting site visitors to fake crypto,...
MegaRAC CVE-2024-54085 Vulnerability: Critical BMC Flaw Threatening Data Centers 19.03.2025 11:02
A newly discovered critical vulnerability (CVE-2024-54085) in AMI’s MegaRAC Baseboard Management Controller (BMC) software puts thousands of servers at risk—including those from HPE, Asus, and ASRockRack. This flaw allows remote attackers to bypass authentication and take full control of affected servers, enabling malware deployment, firmware tampering, indefinite reboot loops, and even physical d...
Microsoft Windows March Update Wipes Out Copilot 19.03.2025 9:22
Microsoft’s latest Windows 10 and 11 updates (KB5053598 and KB5053606) have accidentally uninstalled Copilot, the AI assistant, from some users' systems—leaving many relieved rather than frustrated. In this episode, we break down Microsoft’s response, the temporary workaround, and what this says about the ongoing struggles of AI integration in Windows. We’ll discuss: How the Windows update mistake...
Hackers Flip the Script: How a Fake Coinbase Email Could Empty Your Wallet 18.03.2025 20:22
A new and incredibly deceptive phishing campaign is targeting Coinbase users —but this isn’t your typical scam. Instead of stealing your recovery phrase, attackers are handing you one —a pre-generated phrase they control—tricking users into creating wallets the hackers can drain instantly. Disguised as an official Coinbase email, the attack bypasses traditional security checks , using a convincing...
Brute-Force on Autopilot: Black Basta’s 'BRUTED' VPN Tool for Ransomware Expansion 17.03.2025 12:52
Black Basta, one of the most notorious ransomware gangs, has taken brute-force attacks to the next level with BRUTED—an automated framework designed to breach VPNs, firewalls, and remote access tools. In this episode, we break down how BRUTED works, its key targets—including Cisco AnyConnect, Fortinet SSL VPN, and Palo Alto GlobalProtect—and why this tool is a game-changer for ransomware operation...
GitHub Action Hijacked: The Supply Chain Attack That Exposed 23,000 Repositories 17.03.2025 14:09
In this episode, we unpack a major supply chain attack that compromised the widely used GitHub Action ‘tj-actions/changed-files’ , affecting over 23,000 repositories . Attackers injected malicious code that exposed CI/CD secrets in build logs, creating a potential goldmine for further attacks . We’ll break down: 🔹 How the attack happened – The use of a compromised GitHub Personal Access Token (P...
Bridging the Gap: Developers vs. Security in the Cloud 14.03.2025 19:33
In this episode of The Deep Dive , we explore the ongoing tension between development and security teams in cloud environments. While developers prioritize speed and agility, security teams focus on risk mitigation—leading to friction that can hinder innovation. We discuss how platform teams act as a bridge, aligning both sides to create a secure yet efficient workflow. With insights from industry...
Exploring the Dark Web: Unveiling the Hidden Internet 🌐💻 13.03.2025 11:01
Ever wondered what lies beneath the surface of the internet? 🤔 In this deep dive, we uncover the mysteries of the Dark Web —a hidden part of the internet that isn't accessible through regular search engines. But what exactly is the Dark Web, and how does it work? Is it really as dangerous as it seems, or is there more to the story? 🚀 In this video, we’ll explore: ✅ What the Dark Web is and how...
Security vulnerabilities: Key Steps for secure Workflows 12.03.2025 15:17
Ever wondered how sensitive credentials—like API keys, passwords, and certificates—end up scattered across your systems? 🤔 This hidden cybersecurity risk, known as secret sprawl , makes organizations an easy target for cybercriminals. 🚨 In this episode, we uncover: ✅ The root causes of secret sprawl 🔍 ✅ Why traditional security methods aren’t enough ❌ ✅ How attackers exploit exposed secre...
The Hidden Threat of Wi-Fi Tracking: How Your Devices Reveal Your Location 12.03.2025 10:22
Did you know your phone is constantly mapping Wi-Fi hotspots around you—even when you're not using GPS? In this deep dive, we uncover the unsettling world of Wi-Fi positioning systems, how they track your movements, and the serious privacy risks involved. From global router databases to potential surveillance threats, we explore the implications of this hidden technology. Plus, we share practical...
Zero Trust & Data Security: The Future of Protecting Government Information 11.03.2025 6:06
In this episode, we dive into a crucial topic—data security for government agencies. With evolving cyber threats, traditional security measures no longer cut it. We explore the rise of Zero Trust Security , its impact, and how organizations like StoneFly provide encryption, granular access controls, and backup solutions to safeguard critical data. Plus, we discuss why cybersecurity isn’t just for...
Japanese telco NTT Communications hacked hackers accessed details of almost 18,000 organizations 10.03.2025 5:41
panese telecommunications giant NTT Communications Corporation (NTT Com) has disclosed a data breach affecting information from nearly 18,000 corporate clients. The breach was identified on February 5, 2025, when suspicious activity was detected in the company's internal Order Information Distribution System. Immediate measures were taken to restrict access to the compromised system. However, on F...
1 Million Devices Hit: Inside the Massive Malvertising Campaign 07.03.2025 25:10
A massive malvertising campaign has compromised one million devices worldwide, using malicious ads on illegal streaming websites to distribute malware. Dubbed Storm-0408 , this cybercrime operation leveraged GitHub, Dropbox, and Discord to host payloads, deploying information stealers like Lumma and Doenerium alongside remote access trojans (RATs) like NetSupport . By exploiting Living-off-the-Lan...
Inside the $635K Taylor Swift Ticket Heist: Cybercrime, Loopholes, and Insider Threats 07.03.2025 13:10
A cybercrime operation involving the theft and resale of $635,000 worth of concert tickets—primarily for Taylor Swift’s Eras Tour —has been uncovered. New York prosecutors revealed that two employees of a third-party StubHub contractor exploited a vulnerability in the ticketing system, intercepting over 350 ticket orders. By redirecting digital ticket links to themselves and their co-conspirators,...
Silk Typhoon Strikes: From Direct Breaches to Stealthy Supply Chain Attacks 06.03.2025 18:35
In this episode, we take an in-depth look at Silk Typhoon, the Chinese state-sponsored cyber espionage group that’s radically shifting its tactics. Moving away from direct breaches, Silk Typhoon is now targeting IT supply chains—exploiting remote management tools, identity systems, and cloud services to infiltrate organizations more stealthily and at scale. We explore how the group leverages stole...
Tracking Stingrays: How Rayhunter Shields Your Mobile Privacy 06.03.2025 11:48
In this episode, we dive into Rayhunter —an open source tool from the EFF designed to detect Stingray devices (cell-site simulators) that compromise your mobile privacy. We break down how Rayhunter leverages an affordable Orbic RC400L mobile hotspot to intercept and analyze control traffic between your device and cell towers, alerting you to suspicious activities like forced 2G downgrades or unusu...
BackConnect, Microsoft Teams, & Social Engineering—How Ransomware is Adapting 05.03.2025 13:28
The ransomware landscape is shifting, and Black Basta and Cactus are at the center of it. In this episode, we break down the connections between these two ransomware gangs, their shared tactics, and the use of BackConnect malware for stealthy post-exploitation access. We explore how both groups use social engineering via Microsoft Teams—posing as IT help desk personnel—to trick employees into gran...
OnlyFans Cyberattacks: Fake CAPTCHAs and Malware Distribution Threaten Users 04.03.2025 12:46
Cyberattacks are increasingly targeting OnlyFans users through sophisticated phishing schemes. These attacks leverage fake Cloudflare CAPTCHAs to trick users into running malicious scripts that install malware, such as remote access trojans and keyloggers, and they distribute malware through deceptive links. These links often masquerade as legitimate login pages or special offers, leading to the d...
9 Million Downloads, Now Banned: VSCode Extensions Under Fire 27.02.2025 17:22
In a shocking move, Microsoft has banned the popular Material Theme – Free and Material Theme Icons – Free extensions from the Visual Studio Marketplace, removing them from millions of VSCode instances after cybersecurity researchers discovered potentially malicious code. With nearly 9 million downloads , these extensions were a staple for developers—until now. What went wrong? In this episode, we...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.