Daily Security Review
Daily Security Review
Daily Security Review, the premier source for news and information on security threats, Ransomware and vulnerabilities
Author
Daily Security Review
Category
Podcast website
Latest episode
Oct 29, 2025
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
TSMC Insider Threat: Six Arrested in Taiwan Over 2nm Chip Trade Secrets 05.08.2025 1:06:45
In a stunning development, Taiwanese authorities have arrested six individuals suspected of stealing trade secrets from Taiwan Semiconductor Manufacturing Co. (TSMC), the world’s most advanced semiconductor producer. At the heart of the case is TSMC’s 2-nanometer (2nm) chip technology, a crown jewel in the global race for next-generation AI and high-performance computing power. This marks the firs...
Approov Secures £5M to Fortify Mobile App and API Security Against AI-Driven Threats 05.08.2025 55:37
In a major step for mobile and API cybersecurity, Approov, the Edinburgh-based security firm specializing in real-time mobile attestation and API protection, has raised £5 million (approximately $6.7 million) in Series A funding. The round, led by the Investment Fund for Scotland with support from Souter Investments, Lanza techVentures, and Scottish Enterprise, will fuel the expansion of Approov’s...
Pwn2Own Ireland 2025: $1M WhatsApp Exploit Bounty Raises the Stakes 05.08.2025 1:07:32
This October, Pwn2Own Ireland 2025 will take over Cork with one of the most ambitious cybersecurity competitions yet. Co-sponsored by Meta and organized by Trend Micro’s Zero Day Initiative (ZDI), the event is putting record-breaking payouts on the line — including up to $1 million for a zero-click WhatsApp exploit that can deliver remote code execution. From October 21-24, elite hackers and secur...
Nvidia Triton Inference Server Vulnerabilities Expose AI Infrastructure to Attack 05.08.2025 1:02:48
A major warning has hit the AI community: Nvidia’s Triton Inference Server — one of the most widely used open-source platforms for deploying and scaling AI models — has been found to contain critical vulnerabilities that could allow attackers to take complete remote control of affected systems. The discovery, made by cloud security firm Wiz, revealed a chain of flaws that escalate from information...
CISA & FEMA Release $100M in Cybersecurity Grants to Strengthen State, Local, and Tribal Defenses 04.08.2025 43:50
The U.S. Department of Homeland Security, through CISA and FEMA, has announced over $100 million in new cybersecurity grant funding for Fiscal Year 2025 — a critical investment aimed at protecting America’s most vulnerable digital frontlines. The funding is split between the State and Local Cybersecurity Grant Program (SLCGP), allocating $91.7 million, and the Tribal Cybersecurity Grant Program (T...
AI Jailbreaks on the Rise: How Hackers Are Extracting Training Data from LLMs 04.08.2025 1:26:28
In this episode, we examine the rapidly growing threat of AI jailbreaks — a cybersecurity challenge reshaping the landscape of large language models (LLMs) and enterprise chatbots. According to the IBM 2025 Cost of a Data Breach Report, 13% of all data breaches now involve AI systems, with the vast majority stemming from jailbreak attacks that circumvent developer-imposed guardrails. A highlight o...
350,000 Patient Records Exposed: Inside the Northwest Radiologists Data Breach 04.08.2025 40:18
In this episode, we investigate the Northwest Radiologists data breach, a devastating cyberattack that compromised the personal and medical information of approximately 350,000 patients in Washington State between January 20 and January 25, 2025. What began as a so-called “network disruption” was later revealed to be a massive breach that exposed a treasure trove of sensitive data — including name...
Critical Honeywell Experion PKS Vulnerabilities Threaten Global Industrial Control Systems 31.07.2025 1:16:35
In this episode, we analyze the multiple vulnerabilities recently disclosed in Honeywell’s Experion Process Knowledge System (PKS) , a widely deployed industrial control and automation solution that underpins operations in energy, chemical plants, manufacturing, healthcare, and transportation sectors worldwide. Reported by CISA and Positive Technologies , these flaws range from remote code executi...
Auto-Color Linux Malware Exploits SAP Zero-Day CVE-2025-31324 31.07.2025 36:36
In this episode, we uncover the Auto-Color Linux malware, a stealthy and highly persistent Remote Access Trojan (RAT) that is rapidly emerging as one of the most dangerous threats of 2025. First identified by Palo Alto Networks’ Unit 42 and later analyzed by Darktrace, Auto-Color has now been linked to active exploitation of CVE-2025-31324, a critical SAP NetWeaver vulnerability with a perfect CVS...
Inside the July 2025 PyPI Phishing Scam: How Hackers Stole Developer Credentials 31.07.2025 54:17
In this episode, we investigate the growing cybersecurity storm targeting the Python Package Index (PyPI) — the backbone of Python’s software distribution ecosystem. A recent phishing campaign in July 2025 has developers on high alert, as attackers impersonated PyPI using a deceptive domain (pypj.org) to trick maintainers into handing over their credentials. Victims were directed to a convincing P...
IoT Security Crisis: Dahua Smart Camera Vulnerabilities Expose Surveillance Systems 31.07.2025 1:02:05
In this episode, we examine the alarming discovery of critical security vulnerabilities in Dahua smart cameras, one of the world’s most widely deployed surveillance systems. Researchers at Bitdefender uncovered two zero-click flaws — CVE-2025-31700 and CVE-2025-31701 — that allow unauthenticated remote attackers to gain root access to Dahua devices. Exploited through the ONVIF protocol and an undo...
Dropzone AI Secures $37M to Tackle Alert Fatigue with Autonomous SOC Analysts 30.07.2025 17:11
In this episode, we dive into Dropzone AI’s landmark $37 million Series B funding round, bringing the company’s total raised to over $57 million. Backed by major investors, Dropzone AI is accelerating the development of its AI-powered SOC analysts — tools designed to autonomously investigate and resolve security alerts across critical threat categories like phishing, insider threats, and compromis...
Axonius Buys Cynerio for $100M+: Closing Healthcare’s Biggest Cybersecurity Blind Spot 30.07.2025 1:36:30
In this episode, we explore Axonius’s landmark acquisition of Cynerio, a healthcare cybersecurity company specializing in protecting vulnerable medical devices like MRI machines, infusion pumps, and ventilators. The deal — valued at over $100 million in cash and stock — marks Axonius’s first-ever acquisition and signals a major strategic expansion into the healthcare sector. Already valued at $2.6...
Critical Lenovo Firmware Flaws Expose Millions to Persistent UEFI Attacks 30.07.2025 42:00
In this episode, we examine a critical firmware security crisis shaking Lenovo devices worldwide. Security researchers at Binarly have uncovered six serious vulnerabilities in the Insyde BIOS firmware used in Lenovo’s IdeaCentre and Yoga product lines. Four of these flaws, rated high severity, reside in the System Management Mode (SMM) — a privileged execution mode sometimes called “Ring -2.” Expl...
Promptfoo Secures $18.4M to Combat AI Security Threats in Generative AI 30.07.2025 36:50
In this episode, we dive into Promptfoo’s groundbreaking $18.4 million Series A funding round, led by Insight Partners and supported by Andreessen Horowitz, bringing the AI security startup’s total funding to $23.4 million. Founded in 2024, Promptfoo has quickly emerged as a leader in securing Large Language Models (LLMs) and generative AI applications against critical threats like prompt injectio...
1.1 Million Private Messages Leaked: Inside the Tea App Privacy Disaster 29.07.2025 23:58
A platform designed to protect women’s safety in dating has instead become a nightmare for its users. In this episode, we uncover the catastrophic Tea app data breach, which exposed more than 59 GB of highly sensitive user data due to a fundamental security failure: a completely public Firebase storage bucket with no authentication, no encryption, and no internal checks. Among the compromised data...
Job Scams, Corporate Espionage, and Digital Deception: Inside the Deepfake Crisis 29.07.2025 1:16:30
Deepfake technology has evolved from a fringe novelty into one of the most serious cybersecurity and national security threats of our time. In this episode, we examine how artificial intelligence–generated synthetic media is being weaponized to impersonate CEOs, manipulate elections, infiltrate corporate networks, and damage reputations worldwide. We explore shocking real-world cases, including a...
Microsoft Exposes Major macOS Flaws in Transparency, Consent, and Control 29.07.2025 1:23:13
In this episode, we dive deep into Microsoft Threat Intelligence’s latest findings on two critical macOS vulnerabilities that shook Apple’s privacy defenses. The flaws, identified as CVE-2025-31199 (Sploitlight) and CVE-2024-44133 (HM Surf), specifically targeted Apple’s Transparency, Consent, and Control (TCC) framework, the system designed to guard user data and manage app permissions. Sploitlig...
Aeroflot in Chaos: How Hackers Crippled Russia’s Flagship Airline 29.07.2025 24:25
On July 28, 2025, Aeroflot—Russia’s largest state-owned airline—was brought to its knees in one of the most severe cyberattacks since the country’s invasion of Ukraine in 2022. The sophisticated assault, carried out by Ukrainian hacktivist group Silent Crow and the Belarusian Cyber-Partisans , led to the cancellation of more than 100 flights, stranded thousands of passengers across Moscow’s Sherem...
Neferpitou Claims Cyberattack on French Naval Defense Giant 29.07.2025 44:17
French defense contractor Naval Group, a cornerstone of Europe’s naval defense industry, is facing a high-stakes cybersecurity crisis. A threat actor known as “Neferpitou” claims to have exfiltrated 1TB of sensitive data, including combat management system (CMS) source code for submarines and frigates, technical documents, developer virtual machines, and internal communications. Initially demandin...
Root Evidence Launches With $12.5M to Redefine Vulnerability Management 28.07.2025 36:51
In July 2025, a team of seasoned cybersecurity leaders launched Root Evidence, a Boise-based startup with a mission to revolutionize how organizations tackle vulnerability management. Armed with $12.5 million in seed funding led by Ballistic Ventures, founders Jeremiah Grossman, Robert Hansen, Heather Konold, and Lex Arquette are setting out to fix one of cybersecurity’s most persistent problems:...
NASCAR Hit by Medusa Ransomware: 1TB of Data Stolen in April 2025 Cyberattack 28.07.2025 41:21
In April 2025, NASCAR became the latest victim of a major cyberattack, with hackers infiltrating its network between March 31 and April 3. During the breach, personal information—including names and Social Security numbers—was exfiltrated from NASCAR’s systems. In response, the organization has notified affected individuals, activated its incident response plan, engaged a leading cybersecurity fir...
Scattered Spider Strikes Again: Inside the VMware ESXi Ransomware Tactics 28.07.2025 55:59
In this episode, we examine the sophisticated operations of Scattered Spider—also known as Muddled Libra, UNC3944, and Octo Tempest—a financially motivated cybercriminal group that has redefined the ransomware threat landscape. Recently highlighted by Google’s Threat Intelligence Group (GTIG), Scattered Spider has escalated its attacks by targeting VMware vSphere and ESXi environments, seizing con...
Koske Malware Hides in Panda Images, Weaponizes AI to Target Linux 25.07.2025 44:03
A new and highly sophisticated malware strain named Koske is redefining the threat landscape for Linux environments. Suspected to be partially developed using artificial intelligence, Koske introduces novel and highly evasive techniques, blending image files, rootkits, and adaptive cryptomining logic to create a stealthy and persistent backdoor into systems worldwide. What sets Koske apart is its...
Operation Checkmate: BlackSuit Ransomware’s Dark Web Sites Seized 25.07.2025 39:19
BlackSuit, the ransomware strain known for crippling critical sectors and demanding multi-million dollar payouts, has just suffered a devastating blow. In a coordinated international law enforcement operation codenamed "Operation Checkmate," authorities—including the U.S. Department of Justice, Homeland Security Investigations, FBI, Europol, the UK’s NCA, Dutch and German police, and more—have sei...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.