Daily Security Review
Daily Security Review
Daily Security Review, the premier source for news and information on security threats, Ransomware and vulnerabilities
Author
Daily Security Review
Category
Podcast website
Latest episode
Oct 29, 2025
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Salt Typhoon Strikes Again: National Guard, Telecoms, and a Crisis in U.S. Cyber Defense 16.07.2025 21:58
Salt Typhoon, a sophisticated Chinese state-sponsored cyber threat actor, is conducting one of the most aggressive and sustained espionage campaigns ever uncovered against U.S. critical infrastructure. This episode explores how the group—linked to China's Ministry of State Security—compromised a U.S. state’s Army National Guard, infiltrated telecom giants like AT&T, Verizon, and T-Mobile, and...
DragonForce Ransomware Hits Belk: 150GB Data Leak and Operational Chaos 15.07.2025 1:20:33
In this episode, we dive into the May 2025 ransomware attack on Belk, the iconic U.S. department store chain, orchestrated by the DragonForce ransomware group—a fast-rising player in the ransomware-as-a-service (RaaS) ecosystem. The cyberattack brought down Belk’s online and in-store operations for days, exfiltrated over 156GB of sensitive data, and sparked legal action following the delayed breac...
NVIDIA Issues Urgent Rowhammer Warning: Enable ECC or Risk AI Integrity 15.07.2025 40:39
In this episode, we dissect a major hardware-level cybersecurity warning issued by NVIDIA, one that directly affects data center operators, AI researchers, and enterprise IT teams using GPU infrastructure. The threat: Rowhammer —a physical DRAM vulnerability that’s now been successfully exploited on GPUs through a new attack method known as GPUHammer . Developed by researchers at the University of...
Zip Security Secures $13.5M to Simplify and Scale Cyber Defense 15.07.2025 48:43
In this episode, we spotlight Zip Security , a rising New York-based cybersecurity startup that just closed a $13.5 million Series A funding round , led by Ballistic Ventures. This brings the company’s total raised to $21 million , underscoring growing investor confidence in Zip’s mission: to make enterprise-grade cybersecurity accessible, automated, and affordable —especially for the 95% of busin...
Century Support Services Breach: 160,000 Identities Compromised in Silent Cyberattack 15.07.2025 32:03
In this episode, we examine the major data breach at Century Support Services—also operating under the name Next Level Finance Partners—that exposed the personal information of over 160,000 individuals. While the company discovered indicators of a cyberattack as early as November 2023, it wasn’t until May 2024 that investigators confirmed sensitive data had likely been accessed or exfiltrated. The...
TikTok, China, and the EU: The Battle Over Data Sovereignty 11.07.2025 58:06
In this episode, we explore the mounting scrutiny TikTok faces over its handling of European user data, with the EU’s Data Protection Commission (DPC) launching a fresh investigation into alleged transfers of data to China. TikTok, owned by Beijing-based ByteDance, is once again in the crosshairs for possible violations of the General Data Protection Regulation (GDPR) — this time following revelat...
Booz Allen Invests in Corsha: Defending Machine-to-Machine Communication at Scale 11.07.2025 33:00
As the cybersecurity landscape shifts toward hyperautomation and AI-driven autonomy, a new frontier has emerged: the identity and access security of machines . In this episode, we explore Booz Allen Ventures’ strategic investment in Corsha , a company at the forefront of Machine Identity Provider (mIDP) technology. Their collaboration marks a pivotal moment in redefining how we secure machine-to-m...
WSUS Meltdown: Global Sync Failures and the Shift Toward Cloud Patch Management 11.07.2025 27:45
Windows Server Update Services (WSUS) has long been a cornerstone of enterprise patch management—but recent global synchronization failures have raised serious questions about its future viability. In this episode, we dissect the widespread outage that left organizations unable to sync critical Windows updates, unpacking both the technical cause and the broader implications for IT teams worldwide....
Cracking eSIM: Exposing the Hidden Threats in Next-Gen Mobile Security 11.07.2025 16:43
eSIM technology has transformed the way we connect—but has it also introduced new vulnerabilities into the heart of modern telecommunications? In this deep-dive episode, we dissect the security architecture, remote provisioning systems, and critical attack surfaces of embedded SIM (eSIM) technology , now deployed in billions of mobile, consumer, and IoT devices worldwide. While eSIMs offer conveni...
Qantas Breach and Beyond: Cybersecurity Risks in Australia’s Digital Supply Chains 10.07.2025 1:03:23
As Australia contends with a growing wave of cybersecurity incidents, this episode explores the intersection of national privacy laws, global supply chain vulnerabilities, and public trust in digital security . The recent Qantas data breach—affecting over 5 million customers—was the latest high-profile case to expose how fragile third-party service relationships can compromise even the most reputa...
Taiwan Sounds the Alarm: TikTok, WeChat, and the Chinese Data Threat 09.07.2025 1:06:28
In this episode, we examine Taiwan’s growing alarm over Chinese mobile applications , especially TikTok and WeChat, in light of rising global concern over data privacy and foreign surveillance. A recent inspection by Taiwan’s National Security Bureau (NSB) revealed that these apps aggressively collect personal data and transmit it to servers located in mainland China—where national laws require th...
The Evolution of Atomic macOS Stealer: Backdoors, Keyloggers, and Persistent Threats 08.07.2025 45:00
This episode exposes the growing menace of Atomic macOS Stealer (AMOS) — a rapidly evolving malware-as-a-service (MaaS) platform targeting macOS users worldwide. Once seen as a simple data stealer, AMOS has matured into a potent, long-term threat featuring keyloggers , a persistent backdoor , and system-level access , all designed to exfiltrate data and maintain control over compromised systems. A...
CitrixBleed Returns: CVE-2025-5777 and the Exploitation of NetScaler Devices 08.07.2025 1:02:21
In this episode, we dissect CitrixBleed 2 —a newly disclosed and actively exploited vulnerability affecting Citrix NetScaler ADC and Gateway appliances. Tracked as CVE-2025-5777 (and possibly also CVE-2025-6543), this critical flaw mirrors the notorious original CitrixBleed by allowing attackers to extract sensitive memory content , including user session tokens , through crafted POST login reques...
SAP’s July 2025 Patch Day: Critical Flaws, CVE-2025-30012, and Ransomware Risk 08.07.2025 1:02:01
In this episode, we break down SAP’s July 2025 Security Patch Day—a high-stakes moment for any enterprise relying on SAP’s core business applications. With 27 new and 4 updated security notes released, including seven rated as critical , this patch cycle directly targets some of the most serious vulnerabilities seen in SAP environments in recent memory. At the center of this month’s update is CVE-...
106GB Exposed? Telefónica, HellCat, and the Silent Data Breach 07.07.2025 50:33
In this episode, we explore a shadowy and unconfirmed—but highly consequential—data breach at Spanish telecommunications giant Telefónica. Allegedly orchestrated by the HellCat ransomware group, the breach involves a staggering 106GB of exfiltrated data, including internal communications, customer records, and employee information. Telefónica has yet to acknowledge the breach publicly, while the t...
Ingram Micro’s SafePay Ransomware Breach: Human-Operated Threats and Supply Chain Fallout 07.07.2025 59:56
The recent ransomware attack on Ingram Micro , a global technology distribution giant, reveals not only a sophisticated human-operated cyber assault—but also the fragile state of modern supply chain cybersecurity. In this episode, we break down how attackers, believed to be affiliated with the SafePay ransomware group , penetrated Ingram Micro’s infrastructure, reportedly by exploiting a Palo Alto...
The Illusion of Shutdowns: What Hunters International's Closure Really Means 07.07.2025 42:41
In a sudden and cryptic announcement, the notorious ransomware group Hunters International has declared its shutdown, citing “recent developments” and pledging to release decryption keys to victims. Active since late 2022 and suspected to be a rebrand of the earlier Hive ransomware gang , Hunters International has been responsible for attacks on nearly 300 organizations across various industries....
CISA Flags CVE-2025-6554: Patching Chrome’s Critical Flaw Before It’s Too Late 07.07.2025 40:49
A newly discovered and actively exploited zero-day vulnerability in Google Chrome has sent ripples through the cybersecurity community. Known as CVE-2025-6554 , this critical type confusion flaw in Chrome’s V8 JavaScript and WebAssembly engine enables remote attackers to perform arbitrary read/write operations or execute code via a single malicious webpage. With active exploitation confirmed and i...
ANSSI vs. Houken: France Battles Advanced Chinese Hacking Threat 04.07.2025 33:16
In this episode, we uncover a high-stakes cyber campaign targeting the heart of French digital infrastructure. ANSSI , France’s national cybersecurity agency, has exposed a Chinese-linked hacking group known as Houken (UNC5174 or Uteus) responsible for a widespread espionage operation since late 2024. This state-adjacent threat actor infiltrated critical sectors including government, media, transp...
Psychological Manipulation and AI Fraud: How Spain Exposed a $12M Scam 04.07.2025 17:21
In this episode, we examine a growing threat reshaping financial crime in Europe: sophisticated, technology-driven investment fraud. Spanish law enforcement has recently dismantled a fraud operation that spanned multiple years, deceived over 300 victims, and resulted in more than $11.8 million in losses. What made this case particularly notable was the use of high-pressure call centers inside Spai...
CVE-2025-20309: Critical Cisco Root Access Flaw Threatens VoIP Security 04.07.2025 41:32
A devastating vulnerability— CVE-2025-20309 —has been discovered in Cisco’s Unified Communications Manager (Unified CM) and its Session Management Edition (SME), threatening the security of over a thousand internet-exposed VoIP systems globally. In this episode, we break down this critical flaw , which scores a perfect CVSS 10.0 , and explore why it's one of the most dangerous telecom vulnerabilit...
macOS Under Siege: NimDoor Malware Targets Telegram, Wallets, and Keychains 03.07.2025 43:09
A new, highly advanced malware strain— NimDoor —has emerged as the latest cyber weapon in the arsenal of North Korean state-sponsored hackers, specifically targeting macOS systems used by cryptocurrency and Web3 organizations. This episode explores the complex tactics and alarming capabilities of NimDoor, a malware family showcasing a blend of C++ and Nim programming , stealthy persistence mechani...
Cisco Unified CM Vulnerability: Root Access Risk for Enterprise VoIP Networks 03.07.2025 56:02
A newly disclosed vulnerability— CVE-2025-20309 —in Cisco's Unified Communications Manager (Unified CM) and Session Management Edition has sent shockwaves through enterprise VoIP and IT security teams. The flaw stems from hardcoded root SSH credentials that could allow unauthenticated remote attackers to gain full control of affected systems. In this episode, we unpack the gravity of this vulnerab...
Forminator Flaw Exposes WordPress Sites to Takeover Attacks: Vulnerability Threatens 600,000+ Sites 03.07.2025 50:32
A critical new WordPress vulnerability— CVE-2025-6463 —has been discovered in the widely used Forminator plugin , affecting over 600,000 active installations and putting hundreds of thousands of websites at risk of full compromise. In this episode, we dive deep into the mechanics, risks, and remediation of this arbitrary file deletion flaw and explain what every WordPress administrator, developer,...
Kelly Benefits Breach: Over 550,000 Victims and the Rising Identity Theft Crisis 03.07.2025 1:08:04
In one of the latest large-scale data breaches to hit the U.S. private sector, Kelly Benefits , a provider of payroll and benefits administration services, disclosed a significant cybersecurity incident impacting over 553,000 individuals . The breach, which occurred in December 2024 but was only revealed in April 2025 , exposed sensitive personal information—including names, Social Security number...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.