Daily Security Review
Daily Security Review
Daily Security Review, the premier source for news and information on security threats, Ransomware and vulnerabilities
Author
Daily Security Review
Category
Podcast website
Latest episode
Oct 29, 2025
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Jaguar Land Rover Cyberattack Fallout: £1.5B UK Bailout Sparks Fears of More Attacks 30.09.2025 27:34
Jaguar Land Rover (JLR), one of the UK’s largest exporters and a key anchor of the nation’s automotive supply chain, has been brought to the brink by a devastating cyberattack. With production lines halted, digital operations crippled, and a data breach confirmed, the UK government stepped in with a massive £1.5 billion support package to stabilize JLR’s finances and protect the 120,000 jobs conne...
CISA’s Sunset Clause: What Happens if America’s Cyber Threat Shield Expires? 30.09.2025 24:00
The Cybersecurity Information Sharing Act (CISA), first enacted in 2015, is facing a critical expiration deadline in September 2025. Without reauthorization, the law that shields companies from liability when sharing cyber threat data with the federal government and industry peers will vanish, leaving organizations exposed to lawsuits and reputational risks. This episode dives deep into the high-s...
Crypto Theft on macOS: XCSSET Malware Swaps Wallet Addresses in Real Time 30.09.2025 23:49
A new and more dangerous variant of the XCSSET macOS malware has been uncovered by Microsoft, revealing an expanded arsenal of capabilities aimed at financial theft and deeper system compromise. Originally known for spreading through malicious Xcode projects, XCSSET has steadily evolved into one of the most persistent malware families targeting Apple’s ecosystem. The latest analysis highlights a r...
Nine High-Severity Vulnerabilities Expose Cognex Legacy Cameras to Cyber Threats 29.09.2025 26:21
Cybersecurity researchers at Nozomi Networks have uncovered nine high-severity vulnerabilities in several older models of Cognex industrial cameras, including the widely deployed In-Sight 2000, 7000, 8000, and 9000 series. These machine vision systems are vital for modern manufacturing—guiding robots, inspecting products, and ensuring quality control—but the flaws introduce significant risks rangi...
Microsoft Cuts Services to Israeli Military Unit After Surveillance Revelations 29.09.2025 28:39
Microsoft has taken the unprecedented step of cutting off services to an Israeli military unit after internal and external investigations revealed its cloud and AI products were being used for mass surveillance of Palestinians in Gaza and the West Bank. This dramatic reversal came only after sustained reporting by The Associated Press and The Guardian, which uncovered that Israel’s elite cyber int...
Ghana, Senegal, Ivory Coast at the Center of Interpol’s Multi-Nation Cybercrime Takedown 29.09.2025 27:23
Interpol has announced the results of a sweeping cybercrime operation across 14 African nations, leading to the arrest of 260 individuals behind romance scams and sextortion schemes. The crackdown, conducted in July and August, exposed the alarming scale of digital exploitation sweeping the continent. Victims—more than 1,400 in total—were deceived, blackmailed, and financially drained, with total...
Harrods Data Breach Exposes Customer Details in Third-Party Hack 29.09.2025 22:17
Britain is facing a troubling wave of cyberattacks that has shaken some of its most high-profile organizations. Harrods, the world-renowned luxury retailer, confirmed that customer names and contact details were compromised after attackers infiltrated a third-party vendor’s system. While account passwords and payment data were spared, the breach highlights the risks of vendor supply chain security...
Steam Game BlockBlasters Turns Malicious, Drains $150K in Crypto 24.09.2025 29:37
What happens when a trusted gaming platform becomes a weapon for cybercriminals? That’s exactly what unfolded with BlockBlasters , a free-to-play platformer on Steam that turned from harmless fun into a malicious cryptocurrency-draining scheme. For nearly two months, BlockBlasters appeared safe, even earning “Very Positive” reviews. But in late August, the developers pushed an update containing a...
Beyond the Inbox: The Rising Threat of Non-Email Phishing Attacks 23.09.2025 26:15
Phishing is no longer just an email problem. A new wave of non-email phishing attacks is targeting employees through social media, instant messaging apps, SMS, malicious search engine ads, and even collaboration tools like Slack and Teams . These campaigns are designed to bypass traditional defenses—leaving organizations exposed while attackers exploit overlooked channels of communication. Unlike...
Stellantis Data Breach Exposes Contact Info in Third-Party Provider Attack 23.09.2025 24:09
Automotive giant Stellantis , the world’s fifth-largest automaker, has confirmed a data breach affecting its North American customers after attackers compromised a third-party service provider’s platform. While no financial data was exposed, the company acknowledged that customer contact details were stolen, prompting advisories to remain vigilant against phishing attempts. According to BleepingCo...
HoundBytes Launches WorkHorse to Eliminate SOC Tier 1 Bottlenecks 23.09.2025 20:34
Cybersecurity firm HoundBytes has officially launched WorkHorse , an automated security analyst designed to solve one of the biggest pain points in modern Security Operations Centers (SOCs): the Tier 1 bottleneck. Overwhelmed by a constant flood of raw alerts, Tier 1 analysts often suffer from burnout and slow triage times, putting organizations at risk. WorkHorse is built to replace these repetit...
Toronto’s Mycroft Raises $3.5M to Bring AI Security Officers to Startups 23.09.2025 29:58
Toronto-based cybersecurity startup Mycroft has stepped out of stealth with a bold promise: to give startups and small-to-midsize businesses (SMBs) the kind of enterprise-grade security typically reserved for Fortune 500 companies. Acting as an AI-powered “Security and Compliance Officer,” Mycroft deploys autonomous AI agents that manage an organization’s entire security and IT stack. From cloud a...
FBI Issues Guidance as Fraudsters Pose as IC3 to Extort Victims 23.09.2025 10:29
The FBI has issued a warning to the public about a cyber campaign impersonating the Internet Crime Complaint Center (IC3) , using spoofed websites to trick victims into handing over sensitive information and money. Between December 2023 and February 2025 , the agency received more than 100 reports of malicious activity tied to fake IC3 domains. Threat actors behind this scheme employ domain spoofi...
Fraudulent GitHub Repos Spread Atomic Stealer Malware Targeting macOS Users 22.09.2025 22:08
A new cyber campaign is actively targeting macOS users with the Atomic Stealer (AMOS) malware , leveraging fake GitHub repositories disguised as legitimate software downloads. Security researchers tracking the campaign report that the operators are impersonating trusted brands such as LastPass, 1Password, Dropbox, Notion, and Shopify to lure unsuspecting victims. Using search engine optimization (...
Netskope’s IPO Raises $908M: SASE Leader Surges 18% on First Trading Day 22.09.2025 10:50
Netskope, a California-based cybersecurity firm specializing in secure access service edge (SASE) solutions, has officially gone public in one of the largest cybersecurity IPOs of 2025. Trading on the Nasdaq under the ticker symbol NTSK , the company raised more than $908 million by selling shares at $19 each. Investor enthusiasm was evident as the stock climbed 18% on its first day, closing at $2...
SPLX Exposes AI Exploit: Prompt Injection Tricks ChatGPT Into Solving CAPTCHAs 22.09.2025 24:17
A startling new report from AI security platform SPLX reveals how attackers can bypass the built-in guardrails of AI agents like ChatGPT through a sophisticated exploit involving prompt injection and context poisoning. Traditionally, AI models are programmed to refuse solving CAPTCHAs, one of the most widely deployed tools for distinguishing humans from bots. But SPLX researchers demonstrated that...
Brussels, Berlin, London Hit Hard as Cyber Disruption Sparks Flight Chaos 22.09.2025 23:50
A cyberattack on Collins Aerospace, a U.S.-based provider of passenger check-in and baggage handling software, plunged major European airports into chaos over the weekend. Beginning late Friday, the disruption rippled across hubs in Brussels, Berlin, and London, crippling critical check-in systems and forcing a reversion to manual operations. Brussels Airport was hardest hit, canceling nearly half...
Novakon Ignored Security Reports on ICS Weaknesses, Leaving 40,000+ Devices Exposed 20.09.2025 22:35
A new security report has revealed serious, unpatched vulnerabilities in industrial control system (ICS) products manufactured by Novakon , a Taiwan-based subsidiary of iBASE Technology. Security researchers at CyberDanube identified five categories of flaws affecting Novakon’s Human-Machine Interfaces (HMIs) , including an unauthenticated buffer overflow that allows remote code execution with roo...
RevengeHotels Cybercrime Group Adopts AI and VenomRAT in Hotel Credit Card Theft Campaign 19.09.2025 23:00
The cybercrime group known as RevengeHotels , also tracked as TA558 , has launched a new wave of attacks against the hospitality sector, evolving its tactics with the help of Artificial Intelligence (AI) and a powerful new malware strain, VenomRAT . Active since 2015, RevengeHotels has long targeted hotels, travel agencies, and tourism businesses to steal credit card data from guests and travelers...
ShadowLeak: Server-Side Data Theft Attack Discovered Against ChatGPT Deep Research 19.09.2025 26:15
A groundbreaking new cyberattack dubbed ShadowLeak has been uncovered targeting ChatGPT’s Deep Research capability , marking a dangerous escalation in AI-related threats. Unlike prior exploits such as AgentFlayer and EchoLeak, which operated on the client side, ShadowLeak weaponized OpenAI’s own cloud infrastructure to silently exfiltrate sensitive data—without requiring any user interaction. Disc...
WatchGuard Firebox Vulnerability Could Let Hackers Take Over Networks 19.09.2025 28:50
A new critical vulnerability, CVE-2025-9242 , has been discovered in WatchGuard Firebox firewalls , putting thousands of networks worldwide at risk. The flaw stems from an out-of-bounds write bug in the Fireware OS’s iked process, which could allow a remote, unauthenticated attacker to execute arbitrary code. If exploited, this would grant full control of a device meant to protect the organization...
How SystemBC’s 1,500 Infected VPS Servers Fuel Ransomware and Fraud 19.09.2025 32:02
The SystemBC proxy botnet has quietly become one of the most persistent pillars of the cybercrime ecosystem. First detected in 2019, SystemBC is less about stealth and more about scale. It maintains an average of 1,500 compromised commercial virtual private servers (VPS) around the world, providing a powerful, high-bandwidth proxy network for cybercriminal operations. SystemBC enables a wide range...
Tiffany & Co. Data Breach Exposes Gift Card Details of 2,500+ Customers 18.09.2025 12:33
Tiffany and Company, the iconic luxury jeweler under the LVMH umbrella, has confirmed a serious data breach impacting over 2,500 customers across the United States and Canada. On or around May 12, 2025, hackers infiltrated Tiffany’s internal systems, compromising sensitive customer data tied to gift cards. Exposed information includes names, email addresses, postal addresses, phone numbers, sales...
Lakera’s Gandalf Network Joins Check Point in $300M AI Security Deal 18.09.2025 24:33
In a major strategic move, Check Point Software Technologies has announced the acquisition of Lakera , a Zurich and San Francisco–based AI security firm founded by former Google and Meta AI researchers. Valued at around $300 million , the acquisition will close in late 2025 and serve as the foundation for Check Point’s new Global Center of Excellence for AI Security . This comes at a critical time...
Shai-Hulud Exposes Fragility of the Open-Source Software Supply Chain 17.09.2025 34:50
A major supply chain attack is underway in the npm ecosystem. Dubbed Shai-Hulud , this worm-style campaign began with the compromise of the popular @ctrl/tinycolor package and has since infected at least 187 npm packages, including some published under CrowdStrike’s official account . The malware, designed to spread automatically, abuses the legitimate security tool TruffleHog to scan for API keys...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.