Daily Security Review
Daily Security Review
Daily Security Review, the premier source for news and information on security threats, Ransomware and vulnerabilities
Author
Daily Security Review
Category
Podcast website
Latest episode
Oct 29, 2025
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Coyote Malware Exploits Microsoft UI Automation in First-Ever Wild Attack 25.07.2025 34:14
A new banking trojan called Coyote has emerged as a groundbreaking cyber threat, becoming the first known malware in the wild to exploit Microsoft’s User Interface Automation (UIA) framework—an accessibility tool originally designed to help users interact with Windows interfaces. But in the hands of attackers, UIA becomes a weapon of stealth and precision. Primarily targeting Brazilian banking and...
No Fix Coming: Remote Code Execution Flaw in 1,300 LG Security Cameras 25.07.2025 31:12
A newly disclosed critical vulnerability, CVE-2025-7742, is putting hundreds of LG Innotek LNV5110R security cameras at risk around the world—including within critical infrastructure. This high-severity authentication bypass flaw allows remote attackers to gain full administrative control without credentials, giving them access to live camera feeds, the ability to disable or disrupt device functio...
ToolShell Exploited: China-Linked Hackers Breach NNSA and U.S. Government Networks 24.07.2025 1:14:36
In one of the most concerning state-sponsored cyber incidents of the year, Chinese hackers exploited zero-day vulnerabilities in Microsoft SharePoint to breach the networks of the National Nuclear Security Administration (NNSA)—the U.S. agency responsible for managing the nation's nuclear arsenal. The attackers, part of a suspected Chinese state-sponsored group, used a sophisticated chain of vulne...
Massive NPM Breach: Malicious Packages Spread via Compromised Maintainer Accounts 24.07.2025 41:44
In this episode, we expose the alarming supply chain attack that compromised millions of JavaScript projects across the globe. This sophisticated breach targeted the NPM ecosystem, infecting widely-used packages like eslint-config-prettier and is, through a coordinated phishing campaign and the exploitation of non-expiring legacy access tokens. Attackers began by impersonating the official npm reg...
Clorox Sues Cognizant Over $356M Cyberattack: Who's Really to Blame? 24.07.2025 44:38
In one of the most dramatic cybersecurity legal battles of the past year, Clorox has filed a lawsuit against IT services giant Cognizant, accusing the company of gross negligence that allegedly enabled a catastrophic 2023 cyberattack. The breach wreaked havoc on Clorox's operations—causing widespread product shortages, a multibillion-dollar hit to its market cap, and an estimated $356 million in d...
HeroDevs Secures $125M to Extend Life of Critical Open Source Software 24.07.2025 35:36
In this episode, we dive deep into HeroDevs' recent $125 million strategic growth investment, a move that signals a major expansion in the fight against the vulnerabilities of end-of-life (EOL) open source software. Based in Salt Lake City, HeroDevs has carved out a critical niche—providing "Never-Ending Support" (NES) to ensure security, compliance, and functionality for deprecated OSS widely use...
UK Moves to Ban Ransomware Payments for Public Sector and Critical Infrastructure 23.07.2025 48:22
In a landmark move to disrupt the financial engine powering ransomware attacks, the United Kingdom is pushing forward with legislation that would ban ransom payments across the public sector and critical national infrastructure (CNI). This sweeping proposal covers everything from local councils and schools to healthcare providers like the NHS, aiming to make essential public services less attracti...
New SysAid Vulnerabilities Added to CISA’s KEV List: XXE Flaws Could Enable RCE 23.07.2025 26:10
Two newly added vulnerabilities in SysAid’s On-Prem IT support software — CVE-2025-2775 and CVE-2025-2776 — have officially joined the Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, signaling increased concern around their potential abuse. While there are no confirmed reports of public exploitation or ransomware involvement to date, history...
Lumma Stealer Returns: Malware-as-a-Service Resurges After Global Takedown 23.07.2025 44:16
In this episode, we unpack the rapid and concerning resurgence of Lumma Stealer , a sophisticated Malware-as-a-Service (MaaS) platform, just months after a major international takedown. Despite Microsoft, the FBI, Europol, and global partners dismantling over 2,500 malicious domains and seizing critical infrastructure in May 2025, Lumma Stealer has come roaring back. The cybercriminal group behind...
Cisco ISE Critical Flaws Now Actively Exploited: No Workarounds, Just Root Access 23.07.2025 37:32
Hackers are actively exploiting a trio of critical zero-day vulnerabilities in Cisco’s Identity Services Engine (ISE) and Passive Identity Connector (ISE-PIC), prompting urgent patching directives from the company. The flaws — CVE-2025-20281, CVE-2025-20282, and CVE-2025-20337 — each carry a maximum CVSS severity score of 10.0, indicating the highest possible risk. These vulnerabilities allow remo...
ToolShell: SharePoint Zero-Day Chain Gives Hackers Full Remote Access 22.07.2025 58:23
A new wave of zero-day attacks—collectively known as ToolShell—is actively targeting Microsoft SharePoint servers, with two vulnerabilities (CVE-2025-53770 and CVE-2025-53771) allowing unauthenticated remote code execution and identity control bypass. First observed in high-value targets across government, critical infrastructure, and manufacturing sectors, the ToolShell exploit chain has since ex...
CVE-2025-54309: CrushFTP Zero-Day Exploited in Global Admin Access Attacks 22.07.2025 22:13
A critical zero-day vulnerability in CrushFTP (CVE-2025-54309) is being actively exploited, giving attackers administrative access to over a thousand unpatched servers globally. This severe security flaw—caused by improper validation in the AS2 protocol—has exposed enterprise-managed file transfer (MFT) systems across the US, Europe, and Canada. Security experts are sounding the alarm, and organiz...
Dell Breach by World Leaks: Extortion Attempt Hits Demo Platform 22.07.2025 23:49
Dell Technologies is the latest target in a growing trend of data extortion attacks as threat actors pivot away from traditional ransomware. The cybercrime group known as World Leaks—a rebrand of the former Hunters International gang—has claimed responsibility for breaching Dell’s Customer Solution Centers (CSC), a sandbox environment used primarily for product demonstrations and proofs of concept...
Critical VPN Vulnerability: ExpressVPN Exposed IPs via RDP Misrouting 22.07.2025 59:16
A critical vulnerability in ExpressVPN’s Windows client has put a spotlight on the often-overlooked dangers of debug code making its way into production software. This episode dives into how a debug configuration error allowed Remote Desktop Protocol (RDP) traffic to bypass the VPN tunnel, potentially exposing users’ real IP addresses and compromising their privacy. While encryption remained intac...
Dior Data Breach Exposes U.S. Customer Info in LVMH Vendor Attack 22.07.2025 41:11
In this episode, we unpack the January 2025 data breach at Dior, the iconic luxury fashion house, which exposed sensitive personal information of U.S. customers—including names, addresses, and even Social Security and passport numbers. Although payment data remained secure, the incident's impact is substantial, both in terms of customer trust and corporate accountability. What makes this breach es...
StrongestLayer Raises $5.2M to Fight AI-Powered Phishing with TRACE 21.07.2025 52:49
In an era where generative AI is being used not just for productivity but for precision cybercrime, a San Francisco-based startup, StrongestLayer, is taking a bold stand. Backed by $5.2 million in seed funding from Sorenson Capital and others, the company is pioneering a radically new approach to cybersecurity with its AI-native platform TRACE (Threat Reasoning AI Correlation Engine). This episode...
750,000 Records Exposed: Inside the TADTS Data Breach by BianLian 21.07.2025 1:03:29
In July 2024, The Alcohol & Drug Testing Service (TADTS), a Texas-based company handling sensitive employment-related data, suffered a catastrophic data breach. Nearly 750,000 individuals had personal information compromised—Social Security numbers, financial data, driver’s licenses, health insurance info, and even biometric identifiers. The attack was claimed by the BianLian ransomware group,...
SS7 Is Still Broken: How Surveillance Firms Are Bypassing Telco Defenses 21.07.2025 50:12
A new attack technique is exposing just how vulnerable global mobile networks remain in 2025. Cybersecurity firm Enea has discovered a surveillance operation that bypasses SS7 firewalls by exploiting a subtle weakness in the TCAP encoding layer—allowing stealth location tracking of mobile users across borders. The method? Tampering with the IMSI field in ProvideSubscriberInfo (PSI) requests to hid...
The UNFI Cyberattack: How Hackers Disrupted the U.S. Food Supply Chain 17.07.2025 23:30
In June 2025, United Natural Foods, Inc. (UNFI)—the primary distributor for Whole Foods and tens of thousands of retailers across North America—suffered a major cyberattack that halted deliveries, emptied shelves, and forced core operations offline. The financial damage? Between $350 and $400 million in net sales lost, and up to $60 million in reduced income for fiscal year 2025. In this episode,...
Zuckerberg on Trial: The $8 Billion Data Privacy Reckoning 17.07.2025 21:28
More than five years after the Cambridge Analytica scandal, the legal and financial consequences are still playing out—this time in Delaware’s Chancery Court, where Mark Zuckerberg and Meta executives are being sued by investors seeking over $8 billion in damages. This landmark class-action lawsuit argues that Meta’s leadership knowingly violated a 2012 FTC consent order, misled users and regulato...
Operation Eastwood: Inside the Takedown of NoName057(16) 17.07.2025 21:17
A major Europol-led crackdown—Operation Eastwood—has disrupted one of the most active pro-Russian hacktivist collectives in Europe: NoName057(16). Known for a relentless barrage of DDoS attacks targeting NATO allies and Ukraine-supporting nations, this ideologically driven group ran a global network powered by gamified recruitment, cryptocurrency incentives, and Telegram coordination. In this epis...
Phished and Exposed: What the Co-op Hack Reveals About Retail Cybersecurity 17.07.2025 21:37
In April 2025, The Co-op—one of the UK’s largest retailers—confirmed a data breach that exposed the personal information of 6.5 million members. No financial data was taken, but the attack hit at the core of trust, with CEO Shirine Khoury-Haq calling it a “personal attack on our members and colleagues.” This wasn’t just a technical failure—it was a masterclass in social engineering, executed by at...
FileFix Attacks Are Here: How Interlock’s Ransomware is Skipping Your Defenses 16.07.2025 21:52
In this episode, we break down how Interlock, a fast-moving ransomware group launched in late 2024, has evolved from using web injectors and clipboard tricks (like ClickFix) to an even more covert social engineering technique that abuses Windows File Explorer’s address bar to execute malicious code without triggering security prompts or downloads. Key topics include: How FileFix works: The attacke...
Ontinue Uncovers SVG-Based Phishing: Why Your Browser Could Be the Weak Link 16.07.2025 23:58
Ontinue has uncovered a stealthy new phishing campaign that’s flipping conventional defenses on their head—weaponizing SVG image files to silently redirect victims to malicious websites, without requiring file downloads, macros, or even user clicks. In this episode, we break down how attackers are exploiting the JavaScript-capable structure of Scalable Vector Graphics (SVG) to embed obfuscated scr...
Exein Raises €70M: Defending the IoT-AI Frontier with Embedded Security 16.07.2025 17:35
Exein, the Italian cybersecurity company specializing in embedded IoT defense, has raised €70 million in Series C funding, marking a significant milestone in the race to secure AI-connected infrastructure. Backed by Balderton and a roster of prominent investors, this round pushes Exein’s total funding past $106 million and fuels its global expansion into the U.S. and Asia, while laying the groundw...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.