Daily Security Review

Daily Security Review

Daily Security Review, the premier source for news and information on security threats, Ransomware and vulnerabilities

Author

Daily Security Review

Category

Technology

Podcast website

dailysecurityreview.com

Latest episode

Oct 29, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Workday Breach Tied to Third-Party CRM Hack in ShinyHunters Campaign 18.08.2025

Workday, one of the world’s leading providers of human resources and financial management software, has confirmed a data breach that exposed business contact information through a third-party CRM platform, not its core HR or financial systems. Discovered on August 6, 2025, the breach revealed names, email addresses, and phone numbers—data that, while not highly sensitive, could be leveraged in fut...

DOJ Brings Down Zeppelin Ransomware Operator, Seizes Millions in Crypto 18.08.2025

The U.S. Department of Justice has successfully dismantled a major operator behind the notorious Zeppelin ransomware , charging Russian national Ianis Aleksandrovich Antropenko with conspiracy to commit computer fraud, money laundering, and extortion. Antropenko, known online as “china.helper,” allegedly deployed Zeppelin ransomware in targeted campaigns against victims worldwide—encrypting their...

U.S. Sanctions Grinex, the Russian Crypto Exchange Born from Garantex’s Ashes 16.08.2025

The U.S. Department of the Treasury has announced sweeping sanctions against Grinex , a Russian-linked cryptocurrency exchange identified as the direct successor to the previously sanctioned Garantex . Garantex, operational since 2019, was a major hub for laundering billions of dollars in criminal proceeds, including payments from some of the world’s most prolific ransomware gangs—Conti, LockBit,...

Canadian House of Commons Breach Tied to Microsoft SharePoint Zero-Day 15.08.2025

On August 8th, 2025, hackers breached the Canadian House of Commons by exploiting a critical Microsoft SharePoint zero-day vulnerability—CVE-2025-53770—with a severity score of 9.8. The attack compromised a database containing sensitive employee information, including names, job titles, office locations, email addresses, and technical details about House-managed computers and mobile devices. While...

Norwegian Authorities Blame Pro-Russian Hackers for Critical Infrastructure Breach 15.08.2025

In April 2025, Norway experienced a chilling reminder of the risks facing its critical infrastructure when pro-Russian hackers took control of the Lake Risevatnet dam near Svelgen. For four hours, the attackers manipulated the dam’s outflow valves, releasing 500 liters of water per second into the surrounding river. While the incident caused no physical damage—the riverbed could handle far greater...

MadeYouReset: New HTTP/2 Flaw Could Unleash Massive DDoS Storms 15.08.2025

A newly disclosed HTTP/2 vulnerability—dubbed MadeYouReset (CVE-2025-8671)—is making waves across the cybersecurity community for its potential to power devastating Denial-of-Service attacks. Building on the 2023 “Rapid Reset” flaw, this attack vector exploits a design oversight where servers keep processing backend requests even after a stream is canceled. By tricking the server into initiating i...

Cybersecurity Budgets Hit Historic Slowdown as Global Tensions Mount 15.08.2025

Global cybersecurity strategies are being tested like never before as organizations face the dual pressure of escalating cyber threats and shrinking budgets. Both IANS and Swimlane report that cybersecurity budget growth has slowed to its lowest point in five years—just 4%—driven by global economic instability, inflation, shifting interest rates, and mounting geopolitical tensions. These cuts are...

CVE-2025-53786: The Microsoft Exchange Hybrid Flaw That Could Take Down Your Domain 14.08.2025

A critical security flaw, tracked as CVE-2025-53786, is putting tens of thousands of organizations at risk — and U.S. federal agencies are under orders to patch it immediately. This high-severity vulnerability affects Microsoft Exchange Server in hybrid configurations, where on-premises deployments are connected to Microsoft 365 cloud environments. Here’s why security experts are sounding the alar...

Allianz Life Breach: 2.8 Million Records Leaked in Salesforce Hack 14.08.2025

On July 16, 2025, Allianz Life Insurance Company of North America confirmed a major data breach that exposed up to 2.8 million sensitive records belonging to customers, financial professionals, business partners, and even some employees. But the company’s internal systems weren’t the target — instead, attackers compromised a third-party, cloud-based CRM platform, widely reported to be Salesforce,...

Charon Ransomware Targets Middle East Government and Aviation Sectors 13.08.2025

A newly discovered ransomware family named Charon is making waves in the cybersecurity world — and not for good reasons. Targeting government agencies and the aviation industry in the Middle East, Charon blends the disruptive financial motives of ransomware with the stealth and persistence usually reserved for Advanced Persistent Threat (APT) operations. This dangerous hybrid approach is raising a...

August 2025 Patch Tuesday: Microsoft and Adobe Fix Over 170 Security Flaws 13.08.2025

August 2025’s Patch Tuesday brought major security updates from two of the biggest names in technology — Microsoft and Adobe — addressing a combined 170+ vulnerabilities across widely used products. The scale and severity of these updates make them critical for IT teams and security leaders to implement without delay. Microsoft’s security release fixed 107 vulnerabilities, including one publicly d...

RansomHub Hits Michigan’s Manpower — Data Breach Exposes 140,000 Individuals 13.08.2025

Manpower, a major staffing company based in Lansing, Michigan, has confirmed a ransomware attack that exposed the personal data of approximately 140,000 individuals. The breach, attributed to the notorious RansomHub group, went undetected for weeks — from late December 2024 to mid-January 2025 — during which attackers maintained access to Manpower’s network and exfiltrated over 500 GB of sensitive...

Security Firms Warn GPT-5 Is Wide Open to Jailbreaks and Prompt Attacks 12.08.2025

Two independent security assessments have revealed serious vulnerabilities in GPT-5, the latest large language model release. NeuralTrust’s red team demonstrated a “storytelling” jailbreak, a multi-turn conversational exploit that gradually steers the AI toward producing harmful instructions without triggering its single-prompt safeguards. By embedding malicious goals into a fictional narrative an...

Germany’s Top Court Limits Police Spyware to Serious Crimes Only 11.08.2025

Germany’s Federal Constitutional Court has issued a landmark ruling sharply restricting the use of state spyware by law enforcement. The decision directly addresses 2017 regulations that allowed police to monitor encrypted communications with few limitations. Now, spyware may only be deployed in investigations of serious crimes punishable by at least three years in prison. The court emphasized tha...

BadCam: Lenovo Webcam Flaw Turns Everyday Cameras into Remote BadUSB Attack Tools 11.08.2025

A new hardware security warning has emerged with the discovery of BadCam, a set of vulnerabilities in certain Lenovo webcams that could allow attackers to transform them into BadUSB devices. Uncovered by Eclypsium researchers, the flaw shows that attackers no longer need physical access to a USB peripheral to compromise it — they can now remotely reprogram its firmware. Once weaponized, the webcam...

Free Wi-Fi Loophole Lets Hackers Breach Smart Bus Control Systems 11.08.2025

A new cybersecurity investigation has revealed that the same free passenger Wi-Fi offered on many smart buses is directly connected to critical onboard systems — creating a massive, exploitable security gap. Researchers demonstrated that, with no network segmentation in place, anyone on the free Wi-Fi could pivot into systems controlling driver assistance, GPS tracking, and operational data. Once...

ReVault: Critical Dell Firmware Flaws Allow Windows Login Bypass and Persistent Implants 08.08.2025

In a powerful reminder that hardware security is just as critical as software defense, Cisco Talos researchers have uncovered “ReVault,” a collection of five high-severity firmware vulnerabilities in Dell’s ControlVault3 subsystem. These flaws impact over 100 Dell laptop models, including the Latitude, Precision, and XPS series—devices used widely across enterprise, government, and high-security e...

Air France–KLM Data Breach Exposes Customer Info via Compromised Third-Party Platform 07.08.2025

The aviation industry has suffered yet another major cybersecurity incident. Air France and KLM have confirmed a data breach impacting customer records via an external customer service platform. While no sensitive financial or identity documents were compromised, attackers successfully accessed unspecified customer data—prompting both airlines to notify authorities and warn affected individuals to...

Critical Flaws in CyberArk Conjur and HashiCorp Vault Put Enterprise Secrets at Risk 07.08.2025

Enterprise secrets managers—long considered the most secure components in modern infrastructure—are now under fire. In a groundbreaking report, cybersecurity firm Cyata revealed 14 critical zero-day vulnerabilities across CyberArk Conjur and HashiCorp Vault, exposing flaws that allow unauthenticated attackers to achieve remote code execution (RCE), privilege escalation, and even full system takeov...

Prompt Injection Nightmare: Critical AI Vulnerabilities in ChatGPT, Copilot, Gemini & More 07.08.2025

Enterprise AI assistants are revolutionizing productivity—but they’re also opening new doors for cyberattacks. In this episode, we explore explosive research from Zenity Labs, which reveals that leading AI tools like ChatGPT, Microsoft Copilot, Google Gemini, Cursor, and Salesforce Einstein are vulnerable to prompt injection attacks—a class of exploit that can silently hijack these systems without...

From Google to LVMH: ShinyHunters’ Salesforce Breaches Spark Global Ransom Crisis 07.08.2025

A new wave of cyber extortion is sweeping across global enterprises, and the battlefield is Salesforce CRM. The notorious **ShinyHunters group—tracked internally by Google as UNC6040/UNC6240—**has launched a coordinated series of breaches using vishing (voice phishing) to compromise employee credentials, exfiltrate sensitive customer data, and demand ransoms to prevent public leaks. Among the vict...

Cisco Hit by Vishing Attack: CRM Breach Exposes Millions of User Profiles 06.08.2025

Cisco has confirmed a new data breach after a vishing (voice phishing) attack tricked a company representative into exposing access to a third-party CRM system. Detected on July 24, 2025, the breach compromised basic user details such as names, emails, and phone numbers of Cisco.com registrants. While the data was non-sensitive, the incident underscores a rising and dangerous trend: cybercriminals...

Ox Security Unveils Agent Ox: AI Tool That Writes Tailored Fixes for Software Vulnerabilities 06.08.2025

The world of application security is shifting dramatically as AI begins to move from simply flagging vulnerabilities to actively fixing them. Ox Security has launched Agent Ox, a groundbreaking AI-powered extension designed to automate secure, organization-specific code fixes. Unlike generic coding assistants that offer boilerplate advice, Agent Ox analyzes each company’s unique codebase and runti...

Meta Deletes 6.8 Million Scam Accounts as AI-Powered Fraud Rings Exploit WhatsApp 06.08.2025

Meta has removed 6.8 million accounts tied to criminal scam centers in the first half of 2025, marking one of the most aggressive crackdowns on digital fraud in the company’s history. The move comes amid an alarming surge in online scams that cost global victims $16.6 billion in 2024 alone, a 33% increase from the year before. Many of these scams are linked to transnational criminal networks opera...

Meta Found Liable: Jury Rules Against Tech Giant in Flo Health Privacy Case 06.08.2025

In a landmark decision, a California jury has ruled Meta guilty of violating user privacy laws in a class-action lawsuit tied to the popular Flo Health period tracking app. Plaintiffs alleged that Meta, through embedded software tools and tracking pixels, collected deeply personal menstrual and fertility data — from period dates to pregnancy goals — without user consent, weaponizing it for targete...

Listen to the Daily Security Review podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.