Daily Security Review

Daily Security Review

Daily Security Review, the premier source for news and information on security threats, Ransomware and vulnerabilities

Author

Daily Security Review

Category

Technology

Podcast website

dailysecurityreview.com

Latest episode

Oct 29, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

ChatGPT Calendar Vulnerability Exposes User Emails in New AI Attack 17.09.2025

A critical vulnerability has been uncovered in ChatGPT’s new calendar integration , exposing how attackers could exfiltrate sensitive user data—particularly emails—through a deceptively simple exploit. Security researchers at EdisonWatch , led by Eito Miyamura, demonstrated how a malicious calendar invitation could contain hidden instructions that ChatGPT would execute when a user checked their ca...

CrowdStrike Acquires Pangea to Launch AI Detection and Response (AIDR) 17.09.2025

At Fal. Con 2025, CrowdStrike announced one of its boldest moves yet: the acquisition of AI security startup Pangea . The deal signals CrowdStrike’s intent to redefine the future of cybersecurity by protecting not just endpoints and networks, but the entire AI lifecycle . Pangea, founded in 2021, is known for cutting-edge tools like AI Guard , which prevents sensitive data leaks from generative AI...

RaccoonO365: $100K Phishing-as-a-Service Scheme Taken Down 17.09.2025

Microsoft and Cloudflare have successfully dismantled RaccoonO365 , a global phishing-as-a-service (PhaaS) operation that had been running for over a year. This criminal platform, marketed on Telegram and used by up to 200 subscribers, enabled attackers to craft realistic Microsoft 365 phishing campaigns, complete with fake login pages, email lures, and QR code traps. The operation facilitated the...

AI-Generated Phishing and Deepfakes Supercharge Social Engineering Attacks 17.09.2025

Social engineering has reclaimed center stage as today’s most reliable intrusion vector—and it’s not just email anymore. Recent warnings from law enforcement and national cyber centers underscore how adversaries exploit human psychology to “log in, not hack in,” bypassing hardened perimeters with phishing, vishing (voice phishing) against IT help desks, smishing, and polished impersonation. These...

Phoenix Attack Breaks DDR5 Rowhammer Defenses: Root in 109 Seconds 16.09.2025

The infamous Rowhammer vulnerability, long thought to be contained by new DRAM protections, has resurfaced with devastating force. Academic researchers, working with Google, have unveiled the Phoenix attack , a breakthrough Rowhammer variant that shatters the defenses of DDR5 memory chips. Despite the industry’s investment in Target Row Refresh (TRR) and Error Correcting Codes (ECC), Phoenix explo...

Silent Push Raises $10M Series B to Expand Threat Intelligence Platform 16.09.2025

Cybercriminals aren’t just breaking in—they’re borrowing your brand to do it. This episode dives into the critical intersection of brand protection, threat intelligence, and external attack surface management (EASM) and lays out a practical, intelligence-driven blueprint you can start applying today. We begin with the state of brand abuse: a sharp year-over-year surge in online scams ranging from...

Google Accused of Shadow Lobbying Against California Privacy Opt-Out Law 16.09.2025

California’s Assembly Bill 566 (AB 566) has become one of the most hotly contested pieces of privacy legislation in the country. The bill would require universal “opt-out preference signals” in web browsers and mobile operating systems, allowing consumers to automatically block the sale and sharing of their personal data across the internet. Proponents—including the California Privacy Protection A...

FinWise Bank Data Breach Exposes 700K Customers Amid Predatory Lending Allegations 16.09.2025

FinWise Bank is facing a double crisis—one of data security and another of public trust. Nearly 700,000 customers of American First Finance (AFF), a FinWise partner, were impacted by a massive data breach after a former employee improperly accessed sensitive records. The bank has responded with offers of free credit monitoring, but the damage to consumer trust is already done. At the same time, Fi...

The “s1ngularity” Attack: How Hackers Hijacked Nx and Leaked Thousands of Repositories 09.09.2025

In late August 2025, the open-source software ecosystem was rocked by a sophisticated two-phase supply chain attack , now known as “s1ngularity.” The incident began when attackers exploited a flaw in GitHub Actions workflows for the Nx repository , stealing an NPM publishing token and using it to release malicious versions of Nx packages. These packages carried a hidden malware script— telemetry.j...

Canadian Investment Giant Wealthsimple Hit by Vendor Compromise 08.09.2025

Wealthsimple, one of Canada’s largest online investment platforms, has confirmed a data breach that exposed the sensitive information of fewer than 1% of its three million clients. The incident, detected on August 30, 2025 , originated from a supply chain attack : a trusted third-party vendor’s compromised software package served as the entry point for attackers. While Wealthsimple quickly contain...

FireCompass Raises $20M to Scale AI-Powered Offensive Security 08.09.2025

In a year when cybercrime is projected to cost the world over $10.5 trillion, FireCompass has emerged as one of the most closely watched AI-driven cybersecurity innovators. The startup, founded in 2019, just secured $20 million in new funding—bringing its total raised to nearly $30 million. Backed in part by EC-Council’s Cybersecurity Innovation Fund, this investment is aimed at accelerating resea...

CVE-2025-42957: Active Exploits Target SAP S/4HANA Systems 08.09.2025

A newly uncovered critical vulnerability, tracked as CVE-2025-42957, is sending shockwaves through the enterprise technology world. Affecting all SAP S/4HANA deployments, both on-premise and in private cloud environments, this ABAP code injection flaw carries a near-maximum CVSS score of 9.9. What makes it especially dangerous is its low complexity: attackers armed with only low-privileged credent...

Fake Job Interviews, Real Hacks: How North Korean Spies Steal Billions in Crypto 08.09.2025

North Korean cybercriminals have escalated their social engineering operations, deploying a wave of sophisticated campaigns designed to infiltrate cryptocurrency and decentralized finance (DeFi) organizations. At the center of these operations is the “Contagious Interview” campaign, where hackers impersonate recruiters and trick job seekers into downloading malicious software under the guise of sk...

Cato Networks Acquires Aim Security to Bolster AI Defense in SASE 05.09.2025

Cato Networks, a leader in Secure Access Service Edge (SASE) , has made its first acquisition , purchasing Aim Security , an AI security startup founded in 2022. The acquisition, valued at an estimated $300–350 million , represents a major step in addressing the growing risks tied to generative AI adoption in enterprises . As organizations increasingly embrace AI, a phenomenon known as “shadow AI”...

Tidal Cyber Secures $10M to Advance Threat-Informed Defense 04.09.2025

Cybersecurity startup Tidal Cyber , founded in 2022 by three former MITRE experts, has raised $10 million in Series A funding , bringing its total capital to $15 million . The funding will accelerate the company’s product innovation and expansion , advancing its mission to operationalize the MITRE ATT&CK framework and empower organizations with threat-informed defense . Unlike traditional secu...

Disney Fined $10M for COPPA Violations Over Mislabeling Kids’ Content on YouTube 04.09.2025

Disney has reached a $10 million settlement with the U.S. Federal Trade Commission (FTC) after being found in violation of the Children’s Online Privacy Protection Act (COPPA) . At the heart of the case is Disney’s failure to properly label child-directed content on YouTube as “Made for Kids” (MFK) . Instead, many videos — including clips from Frozen, Moana, Cars, Tangled, Toy Story, and other bel...

Google Patches 111 Android Flaws in September 2025, Including Two Zero-Days Under Attack 04.09.2025

Google has released its September 2025 Android security patches , addressing a staggering 111 unique vulnerabilities , including two actively exploited zero-day flaws that are already being used in targeted attacks. These zero-days — CVE-2025-38352 , a Linux kernel race condition , and CVE-2025-48543 , a flaw in the Android Runtime — allow attackers to escalate privileges and potentially take cont...

Google Warns of Sitecore Zero-Day: ViewState Deserialization Under Fire 04.09.2025

A critical zero-day vulnerability, CVE-2025-53690 , is being actively exploited in the wild, targeting Sitecore Experience Manager (XM) and Experience Platform (XP) systems deployed with outdated ASP.NET machine keys . Google and Microsoft threat intelligence teams have confirmed that attackers are leveraging ViewState deserialization attacks to achieve remote code execution (RCE) , enabling full...

Brokewell Malware Targets Android Users via Fake TradingView Ads on Meta 03.09.2025

A new and highly sophisticated Android malware campaign, dubbed Brokewell , has emerged as one of the most dangerous mobile threats of 2024–2025. First spotted in April 2024 disguised as fake browser updates, Brokewell has since evolved into a fully featured spyware and remote access trojan (RAT), delivered through deceptive Meta (Facebook) advertisements. The latest campaign, active since July 20...

Von der Leyen and Shapps Flights Hit by Suspected Russian Electronic Warfare 02.09.2025

Aviation safety and geopolitics collided when multiple flights carrying high-ranking European and UK officials were hit by suspected Russian GPS jamming. European Commission President Ursula von der Leyen’s flight to Bulgaria experienced a severe GPS outage, forcing a manual landing. EU officials immediately pointed the finger at Moscow, calling the incident “blatant interference.” Around the same...

Salesforce and Google Workspace Compromised in Largest SaaS Breach 02.09.2025

In August 2025, the largest SaaS breach of the year shook the enterprise world when a newly identified threat actor, UNC6395, orchestrated a supply-chain attack through compromised Salesloft Drift and Drift Email applications. By stealing OAuth tokens, the attackers gained unauthorized access to Salesforce and Google Workspace environments of more than 700 companies—an attack scale ten times great...

Chained Zero-Days: WhatsApp and Apple Exploits Used in Sophisticated Spyware Attacks 02.09.2025

A pair of newly discovered zero-day vulnerabilities—CVE-2025-43300 in Apple’s ImageIO framework and CVE-2025-55177 in WhatsApp—have been confirmed as part of a sophisticated spyware campaign targeting both iPhone and Android users. Security researchers revealed that attackers chained these flaws together in seamless zero-click exploits, requiring no user interaction to compromise devices. The Appl...

Miljödata Cyberattack: 80% of Swedish Municipalities Hit in Extortion Strike 29.08.2025

Sweden is reeling from one of the largest public sector cyber incidents in its history. A ransomware attack on Miljödata , an IT services provider supporting nearly 80% of Sweden’s municipalities and several regions, has left critical systems inaccessible and raised fears of a massive leak of sensitive personal data . The stolen information could include medical certificates, labor law cases, reha...

PromptLock Ransomware: How AI is Lowering the Bar for Cybercrime 29.08.2025

The cybersecurity world has entered a new era: AI-powered ransomware . Researchers recently uncovered PromptLock , a proof-of-concept malware that uses OpenAI’s gpt-oss:20b model and Lua scripting to autonomously generate malicious code, encrypt data, and exfiltrate files across Windows, Linux, and macOS . While still experimental, PromptLock demonstrates just how quickly artificial intelligence c...

Hybrid AD at Risk: Storm-0501 Exploits Entra ID for Cloud-Native Ransomware 28.08.2025

The 2025 Purple Knight Report paints a stark picture of enterprise identity security: the average security assessment score for hybrid Active Directory (AD) and Entra ID environments has plummeted to just 61%—a failing grade and an 11-point decline since 2023. This troubling trend underscores the persistent challenges organizations face in protecting their most critical authentication and authoriz...

Listen to the Daily Security Review podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.