Daily stories from the world of information security. To delve into any daily story, head to CISOseries.com.
OpenAI loosens cyber limits for vetted defenders
Sandworm's fake recruiters plant a poisoned VPN
Royal Navy drones phone home to China
Episode show notes: https://cisoseries.com/openai-loosens-cyber-limits-sandworms-poisoned-vpn-navy-drones-phone-china/
Huge thanks to our sponsor, ThreatLocker
An attacker uses AI to create a payload your security tools have never seen. Detection now has to recognize it before the payload can act. ThreatLocker approaches the problem earlier by controlling whether that code is permitted to run at all. Explore a deny by default approach for your organization at threatlocker.com/ciso.
OpenAI slows release of Astra model citing cyber capabilities
Irregular won't say if there were more rogue incidents
U.S. cyber ambassador nominee Cassady confirmed in Senate
Episode shownotes: https://cisoseries.com/cybersecurity-news-openai-slows-astra-irregular-wont-talk-senate-confirms-cassady/
Huge thanks to our sponsor, ThreatLocker
AI is helping attackers research targets, create malicious code, and adapt faster. But the fundamentals have not changed. Code still needs to execute, applications still need access, and attackers still need privileges. Today's tip: control those actions instead of trying to predict every threat. Learn more from ThreatLocker at threatlocker.com/ciso.
Apple's bug bounty program overwhelmed by fake AI generated reports
China launches cybersecurity review into Palo Alto Networks products
Meta AI hacks external systems during cybersecurity testing
Get the show notes here: https://cisoseries.com/cybersecurity-news-faked-bug-reports-metas-rogue-ai-china-investigates-palo-alto/
Huge thanks to our episode sponsor, ThreatLocker
AI risk does not only come from attackers. Employees are adopting AI tools faster than many organizations can evaluate them. Today's tip: an AI policy should be backed by enforceable controls over what tools can access and do. See how ThreatLocker can help you govern AI use at threatlocker.com/ciso.
AI safety tests spill onto the real internet
Private Relay flaw unmasks IP addresses
Weak telcos left door open for Salt Typhoon
Get the show notes here: https://cisoseries.com/cybersecurity-news-ai-safety-tests-reach-the-internet-private-relay-flaw-unmasks-ips-weak-telcos-invite-salt-typhoon/
Huge thanks to our episode sponsor, ThreatLocker
AI is compressing the timeline between initial access and impact. That leaves security teams less time to identify, investigate, and contain malicious activity. Faster response helps, but prevention can remove actions from the attack chain entirely. Give your responders a more controlled environment. Book a ThreatLocker demo at threatlocker.com/ciso.
ChainDrop attack hits npm
Pass-ta-key attacks target passkeys
AI accounts for most cybercrime in Africa
Get the show notes here: https://cisoseries.com/cybersecurity-news-chaindrop-hits-npm-pass-ta-key-targets-passkeys-ai-runs-amok-in-africa/
Huge thanks to our episode sponsor, ThreatLocker
Attackers do not always bring their own tools. AI can help them find ways to misuse software already trusted by the organization. Today's tip: approval should not mean unlimited access. Define what trusted applications can reach and what they can do. Learn how ThreatLocker applies this principle at threatlocker.com/ciso today.
When license plate readers become stalking tools
ExfilSquad dumps UK police contact data
China-linked hackers shrink the patch window
Get the show notes here: https://cisoseries.com/cybersecurity-news-license-plate-readers-as-stalking-tools-exfilsquad-dumps-uk-police-data-the-ever-shrinking-patch-window/
Huge thanks to our episode sponsor, ThreatLocker
An attacker uses AI to create a payload your security tools have never seen. Detection now has to recognize it before the payload can act. ThreatLocker approaches the problem earlier by controlling whether that code is permitted to run at all. Explore a deny by default approach for your organization at threatlocker.com/ciso.
UK's state investments agency suffers data breach
CISA tells utilities to remove internet-exposed PLCs following Minnesota attacks
Anthropic says its AI hacked real-world companies in three incidents
Get the show notes here: https://cisoseries.com/cybersecurity-news-cybersecurity-news-uk-investments-agency-breach-cisa-water-warning-anthropic-threesome/
Huge thanks to our episode sponsor, ThreatLocker
AI is helping attackers research targets, create malicious code, and adapt faster. But the fundamentals have not changed. Code still needs to execute, applications still need access, and attackers still need privileges. Today's tip: control those actions instead of trying to predict every threat. Learn more from ThreatLocker at threatlocker.com/ciso.
This week's Department of Know is hosted by Rich Stroffolino, with guests Janet Heins, CISO, ChenMed, and Derek Fisher, Director of the Cyber Defense and Information Assurance Program, Temple University.
Missed the live show? Check it out on YouTube.
The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.
Huge thanks to our sponsor, Pindrop A finance worker joined a video call with their CFO and wired $25 million to attackers. This isn't fiction—it happened. Deepfake video. AI voice. Completely convincing. It could be happening in your meetings right now. Pindrop Pulse for Meetings can detect deepfake impersonation before the damage is done. Go to pindrop.com and start verifying.
Semiconductor firm Analog Devices discloses data breach
Copilot for Word POC copies hidden prompts into new documents
Microsoft Teams vishing attacks lead to Chaos ransomware attacks
Get the show notes here: https://cisoseries.com/cybersecurity-news-analog-devices-breach-copilot-ai-worm-teams-ransomware-vishing/
Huge thanks to our sponsor, Pindrop
A finance worker joined a video call with their CFO and wired $25 million to attackers. This isn't fiction—it happened. Deepfake video. AI voice. Completely convincing. It could be happening in your meetings right now. Pindrop Pulse for Meetings can detect deepfake impersonation before the damage is done. Go to pindrop.com and start verifying.
OpenAI agent's escape reaches a Modal customer
Hackers hit Minnesota water systems
Fake Russian companies, real stolen money
Get the show notes here: https://cisoseries.com/cybersecurity-news-openai-agent-reaches-modal-minnesota-water-systems-hacked-fake-russian-companies-steal-real-money/
Huge thanks to our sponsor, Pindrop
TIME named Pindrop one of the 10 Most Influential Software Companies of 2026. Deepfakes slip into your video meetings, contact centers, and hiring pipelines. Pindrop restores trust to every digital conversation. Customers. Employees. Defended. Don't wait for an incident report. Visit pindrop.com.
Thousands of server BMCs leak password hashes
Claude finds flaws in encryption
Google gives old threat actors new names
Get the show notes here: https://cisoseries.com/cybersecurity-news-leaky-bmcs-claude-finds-encryption-flaws-googles-new-names/
Huge thanks to our sponsor, Pindrop
AI attacks on the enterprise are skyrocketing. Is your tech stack keeping up? Deepfake and synthetic voices are slipping through a channel your defenses were never built to cover—stealing credentials and exposing data with no visibility until after the incident report. Pindrop closes that gap, with under 1% false positives. Go to pindrop.com.
Nvidia opens the AI security tent
Microsoft puts a cyber sprinter in MDASH
Fairlife ransomware spills data
Get the show notes here: https://cisoseries.com/cybersecurity-news-nvidia-opens-ai-security-tent-microsoft-adds-cyber-sprinter-to-mdash-fairlife-ransomware-spills-data/
Huge thanks to our sponsor, Pindrop
A finance worker joined a video call with their CFO and wired $25 million to attackers. This isn't fiction—it happened. Deepfake video. AI voice. Completely convincing. It could be happening in your meetings right now. Pindrop Pulse for Meetings can detect deepfake impersonation before the damage is done. Go to pindrop.com and start verifying.
U.S. agencies warn of Iran-linked actors targeting water and energy control systems
ChatGPT suffered brief global outage on Saturday
Malvertising sends malware in pieces for an unsuspecting browser to build
Get the show notes here: https://cisoseries.com/cybersecurity-news-iran-infrastructure-warning-chatgpt-global-outage-self-assembling-malware/
Huge thanks to our sponsor, Pindrop
Your hiring processes are the newest entry point for security risks. Pindrop's data shows one in six engineering job applicants show signs of synthetic identity. That's why we built Pindrop Pulse for Meetings. Catch deepfakes, AI voices, and spoofed locations in real time. Go to pindrop.com and start verifying.
This week's Department of Know is hosted by Rich Stroffolino, with guests Nick Espinosa, host, Deep Dive Radio Show, and Dennis Pickett, vp, CISO, Westat.
Missed the live show? Check it out on YouTube.
The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.
Huge thanks to our sponsor, QuilrAI
AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes. Alerts tell you later. QuilrAI decides now. Visit quilr.ai. Stay safe - Quilr it.
AI Agents become fastest growing exposed attack surface
Consumer finance company Upbound Group blames data breach for millions in losses
Dolphin X Stealer uses AI profiling to prioritize targets
Get the show notes here: https://cisoseries.com/cybersecurity-news-ai-agents-risk-upbound-group-breach-dolphin-x-stealer/
Huge thanks to our sponsor, QuilrAI
AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes.
Alerts tell you later. QuilrAI decides now. Visit quilr.ai.
OpenAI behind Hugging Face hack
TrickBot tunnels through DNS
Acrobat extension opens WhatsApp
Get the show notes here:
Huge thanks to our sponsor, QuilrAI
AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes.
Alerts tell you later. QuilrAI decides now. Visit quilr.ai.
Bit2Watt threatens power stability
All AI models cheat at cyber evaluations
US weighing Chinese LLM ban
Get the show notes here: https://cisoseries.com/cybersecurity-news-bit2watt-instability-ai-models-cheat-chinese-llm-ban/
Huge thanks to our sponsor, QuilrAI
AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes.
Alerts tell you later. QuilrAI decides now. Visit quilr.ai.
Hugging Face fights AI hacks with AI
World Cup streamers get a red card
WordPress enters a patching race
Get the show notes here:
Huge thanks to our sponsor, QuilrAI
AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes.
Alerts tell you later. QuilrAI decides now. Visit quilr.ai.
Dairy company Fairlife suffers cyberattack
Microsoft warns of surge in ACR Stealer attacks on customers
Abbott Labs investigates two cyber incidents amid extortion claims
Get the show notes here: https://cisoseries.com/cybersecurity-news-fairlife-dairy-cyberattack-acr-stealer-surge-abbott-labs-incidents/
Huge thanks to our sponsor, QuilrAI
AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes.
Alerts tell you later. QuilrAI decides now. Visit quilr.ai.
"Context Bombing" flips the script on prompt injections
Pentagon suspends CMMC Phase II requirements
Old tech, new problems
Get the show notes here: https://cisoseries.com/the-department-of-know-cmmc-suspended-sharefile-shutdown-context-bombing-strikes-back/
This week's Department of Know is hosted by Rich Stroffolino, with guests Tom Hollingsworth, networking technology advisor, Futurum Group, and Mark Eggleston, former CISO, CSC.
Missed the live show? Check it out on YouTube.
The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.
Huge thanks to our sponsor, ThreatLocker
Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk?
That's the challenge behind cloud adoption.
Behind AI. Behind automation. And behind every major technology decision.
ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do.
That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
ClickLock stealer uses kill loops to force password entry
TELEPUZ malware uses ClickFix to steal data and run commands
1Password's new Agentic Mode lets Claude log into accounts
Notes: https://cisoseries.com/cybersecurity-news-clicklocks-kill-loops-telepuz-clickfix-tricks-1passwords-agentic-login/
Huge thanks to our sponsor, ThreatLocker
Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
Zoom's account takeover wake-up call
Two zero-days, one urgent SonicWall patch
23andMe's breach bill keeps growing
Show Notes: https://cisoseries.com/cybersecurity-news-zooms-wake-up-call-zero-day-sonicwall-patch-23andmes-growing-breach-bill/
Huge thanks to our sponsor, ThreatLocker
Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
Pentagon suspends CMMC Phase II requirements
US troop location data under attack in Iran
"Context Bombing" flips the script on prompt injections
Get the show notes here: https://cisoseries.com/cybersecurity-news-cmmc-phase-ii-suspended-tracking-troops-in-iran-defenders-turn-to-context-bombing/
Huge thanks to our sponsor, ThreatLocker
Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
Russia's router access routes
MemGhost haunts AI memory
DHS alert got waved off… twice
Get the show notes here: https://cisoseries.com/cybersecurity-news-russias-router-access-routes-memghost-haunts-ai-memory-dhs-alert-got-waved-off-twice/↗
Huge thanks to our sponsor, ThreatLocker
Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
Windows backdoor stuffs multiple wipers and ransomware code into a single package
NSA brings back Tailored Access Operations name for elite hacking unit
Progress urges ShareFile customers to shut down storage zone controllers
Show notes: https://cisoseries.com/cybersecurity-news-multifunction-windows-backdoor-nsa-revives-tao-urgent-sharefile-warning/
Huge thanks to our sponsor, ThreatLocker
Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
Link to the episode
This week's Department of Know is hosted by Rich Stroffolino, with guests Davi Ottenheimer, principal, Flying Penguin, and Chris Ray, field CTO, GigaOm.
Missed the live show? Check it out on YouTube.
The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.
Huge thanks to our sponsor, Vanta
Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
Interpol's fraud sweep goes global
China flags Claude Code
Old GitHub accounts, new tricks
Get the show notes here: https://cisoseries.com/cybersecurity-news-interpols-global-fraud-sweep-chinas-claude-code-flag-old-github-account-tricks/
Thanks to our episode sponsor, Vanta
Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
Mexico's first cyber test gets tested
Snoops break into Roundcube mailservers
Cash App owner pays up over lax security
Get the show notes here: https://cisoseries.com/cybersecurity-news-mexicos-big-cyber-test-roundcube-mailserver-snooped-on-cash-app-found-lax/
Thanks to our episode sponsor, Vanta
Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
The UK's Cyber Pledge and Cyber Shield
Millions exposed in Japanese telco attack
China looking to curb overseas model access
Get the show notes here:
Thanks to our episode sponsor, Vanta
Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
Suspected China-Nexus hackers use fake Indian tax filing utility to deploy DcRAT
Prompt injection attacks trick AI Agents into making crypto payments
France to stop certifying products without quantum-safe encryption
Get the show notes here: https://cisoseries.com/cybersecurity-news-india-tax-rat-prompt-injection-crypto-scam-france-pushes-quantum-safe/
Thanks to our episode sponsor, Vanta
Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
JadePuffer ransomware used AI agent to automate entire attack
AdaptHealth suffers cyberattack
UK's National Cyber Action Plan launch delayed by political leadership crisis
Get the show notes here: https://cisoseries.com/cybersecurity-news-first-ai-ransomware-adapthealth-suffers-cyberattack-uk-cyber-plan-delayed/
Thanks to our episode sponsor, Vanta
Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
This week's Department of Know is hosted by Rich Stroffolino, with guests David Cross, CISO, Atlassian; Kathleen Mullin, Director, SABSA Institute; Montez Fitzpatrick, CISO, Navvis; and Howard Holton, former CEO, GigaOm.
Get the show notes here: https://cisoseries.com/the-department-of-know-peoplesoft-exploit-ford-brings-back-gray-beards-llm-vetting/
Huge thanks to our sponsor, Silent Push
Most cybersecurity approaches are completely reactive. Victim organizations are hit with an attack and the chase ensues. Silent Push closes this gap with its Preemptive Cyber Defense platform. Silent Push tracks adversary infrastructure and infrastructure changes across the Internet during the attack preparation phase - while attackers are still staging domains, IPs, and hosting and Silent Push turns that into Indicators of Future Attack® to defend with confidence. For a CISO, that turns invisible risk into early warning, an average of 140 days before a campaign shows up in your environment. Time to act, and a smaller window of exposure, before a threat ever reaches your environment.
Card data theft remains top concern for U.S. consumers
OMB chief to oversee spy agency budgets
Fortibleed leads to ransomware attacks and 430,000 Fortinet firewalls exposed
Get the show notes here: https://cisoseries.com/cybersecurity-news-consumer-security-worries-vought-supervises-spy-budgets-fortibleed-exposes-fortinet/
Huge thanks to our sponsor, Silent Push
Most cybersecurity approaches are completely reactive. Victim organizations are hit with an attack and the chase ensues.
Silent Push closes this gap with its Preemptive Cyber Defense platform. Silent Push tracks adversary infrastructure and infrastructure changes across the Internet during the attack preparation phase - while attackers are still staging domains, IPs, and hosting and Silent Push turns that into Indicators of Future Attack® to defend with confidence.
For a CISO, that turns invisible risk into early warning, an average of 140 days before a campaign shows up in your environment. Time to act, and a smaller window of exposure, before a threat ever reaches your environment. Learn more at silentpush.com
Hide My Email bug shows real addresses
Fable 5 gets the greenlight
DHS confirms hackers breached HSIN
Get the show notes here: https://cisoseries.com/cybersecurity-news-hide-my-email-shows-real-addresses-fable-5-gets-greenlight-microsoft-teams-hits-back-on-bots/
Huge thanks to our sponsor, Silent Push
Most cybersecurity approaches are completely reactive. Victim organizations are hit with an attack and the chase ensues.
Silent Push closes this gap with its Preemptive Cyber Defense platform. Silent Push tracks adversary infrastructure and infrastructure changes across the Internet during the attack preparation phase - while attackers are still staging domains, IPs, and hosting and Silent Push turns that into Indicators of Future Attack® to defend with confidence.
For a CISO, that turns invisible risk into early warning, an average of 140 days before a campaign shows up in your environment. Time to act, and a smaller window of exposure, before a threat ever reaches your environment. Learn more at silentpush.com
Bash can spell trouble GNU for AI agents
DHS to unveil critical infrastructure council
Aikido buys Root
Get the show notes here: https://cisoseries.com/cybersecurity-news-bash-hits-ai-dhs-announces-anchor-ci-aikido-buys-root/
Huge thanks to our sponsor, Silent Push
Most cybersecurity approaches are completely reactive. Victim organizations are hit with an attack and the chase ensues.
Silent Push closes this gap with its Preemptive Cyber Defense platform. Silent Push tracks adversary infrastructure and infrastructure changes across the Internet during the attack preparation phase - while attackers are still staging domains, IPs, and hosting and Silent Push turns that into Indicators of Future Attack® to defend with confidence.
For a CISO, that turns invisible risk into early warning, an average of 140 days before a campaign shows up in your environment. Time to act, and a smaller window of exposure, before a threat ever reaches your environment. Learn more at silentpush.com
US seizes illegal World Cup domains
WhatsApp offers usernames for phone number privacy
$10M reward for Russia-based cyber campaign
Get the show notes here: https://cisoseries.com/cybersecurity-news-us-seizes-illegal-world-cup-domains-whatsapp-offers-usernames-for-phone-privacy-10m-reward-for-cyber-campaign/
Huge thanks to our sponsor, Silent Push
Most cybersecurity approaches are completely reactive. Victim organizations are hit with an attack and the chase ensues.
Silent Push closes this gap with its Preemptive Cyber Defense platform. Silent Push tracks adversary infrastructure and infrastructure changes across the Internet during the attack preparation phase - while attackers are still staging domains, IPs, and hosting and Silent Push turns that into Indicators of Future Attack® to defend with confidence.
For a CISO, that turns invisible risk into early warning, an average of 140 days before a campaign shows up in your environment. Time to act, and a smaller window of exposure, before a threat ever reaches your environment. Learn more at silentpush.com
CISA sets urgent deadline to fix exploited Cisco flaw
Chinese cybersecurity company claims it has a better-than-Mythos bug finder
Amazon Q flaw enables cloud credential theft
Get the show notes here: https://cisoseries.com/cybersecurity-news-cisas-cisco-deadline-chinas-mythos-competitor-amazon-q-flaw/
Huge thanks to our sponsor, Silent Push
Most cybersecurity approaches are completely reactive. Victim organizations are hit with an attack and the chase ensues.
Silent Push closes this gap with its Preemptive Cyber Defense platform. Silent Push tracks adversary infrastructure and infrastructure changes across the Internet during the attack preparation phase - while attackers are still staging domains, IPs, and hosting and Silent Push turns that into Indicators of Future Attack® to defend with confidence.
For a CISO, that turns invisible risk into early warning, an average of 140 days before a campaign shows up in your environment. Time to act, and a smaller window of exposure, before a threat ever reaches your environment. Learn more at silentpush.com
ShinyHunters hits Madison Square Garden
Cal Water finds no evidence of OT activity
New CISA guide helps agencies adopt SASE for Zero Trust
Get the show notes here: https://cisoseries.com/cybersecurity-news-shinyhunters-hits-msg-cal-water-confirms-no-damage-cisa-sase-guide/
Huge thanks to our episode sponsor, Guardsquare
Attackers are treating your mobile app like an open book. Sixty-three percent of security leaders recently detected app tampering, cloning, or unauthorized modifications. When your code runs in an untrusted environment, you need runtime self-protection and code hardening to keep attackers out. Address tampering before it starts. Learn more at Guardsquare.com.
Copilot AI knocks down cybercrime tools
Hackers exploit Cisco zero-day
China's 360 says it matches Anthropic's Mythos
Get the show notes here: https://cisoseries.com/cybersecurity-news-copilot-ai-attacks-cybercrime-tools-hackers-exploit-cisco-zero-day-chinas-360-vs-mythos/
Huge thanks to our episode sponsor, Guardsquare
AI is speeding up development, but at what cost? While ninety-six percent of teams now use AI tools, eighty-one percent report that AI-generated code has introduced new vulnerabilities into their mobile apps. In a world with automated threats, you need multi-layered, polymorphic security to stay ahead of the curve. Learn more at Guardsquare.com.
Feds seize alleged cyber-scam infrastructure
Dragos unveils AI for OT security
Scattered Spider hackers plead guilty
Get the show notes here: https://cisoseries.com/cybersecurity-news-feds-seize-scam-infrastructure-dragos-unveils-ai-for-ot-security-scattered-spider-hackers-plead-guilty/
Huge thanks to our episode sponsor, Guardsquare
Is your mobile app truly protected? Relying on the OS isn't enough. A global study of thirteen-hundred security and developer leaders found that ninety-six percent of teams using layered protection reported significantly fewer security incidents. Don't wait for a breach to harden your defenses. Get the protection needed for modern secuirty risks. Learn more at Guardsquare.com.
OpenAI takes on Anthropic's Mythos
Klue hack hits security shops
Five Eyes has eyes on AI models
Get the show notes here: https://cisoseries.com/cybersecurity-news-openai-takes-on-mythos-klue-hits-security-shops-five-eyes-has-eyes-on-ai/
Huge thanks to our episode sponsor, Guardsquare
Your backend is only as secure as your frontend. Research shows that client-side compromise is now a primary driver of API risk. With sixty-three percent of leaders detecting mobile app tampering or cloning last year, don't leave your mobile app security to chance. Get multilayered protection for your entire mobile app ecosystem from the outside in. Learn more at Guardsquare.com.
Hackers suspected in Brazil cell phone alert
Prinz Eugen ransomware prioritizes recent files for encryption
Congress presents bill to protect people from AI-generated deepfakes
Get the show notes here: https://cisoseries.com/cybersecurity-news-brazil-phone-alert-hack-prinz-eugen-ransomware-congress-deepfake-bill/
Huge thanks to our episode sponsor, Guardsquare
Mobile app security isn't just a tech issue; it's a revenue issue. A recent global study found that seventy-two percent of organizations experienced a mobile app security incident last year. Even worse? Sixty-five percent saw customer churn or uninstalls as a result. Protect your brand and your bottom line with layered mobile app protection. Learn more at Guardsquare.com.
This week's Department of Know is hosted by Rich Stroffolino, with guests Arif Hameed, CISO, C&R Software; Adam Palmer, CISO, First Hawaiian Bank; Jon Collins, Field CTO, GigaOm; and Jack Leidecker, EVP, CSO, Gainsight.
Huge thanks to our sponsor, ThreatLocker
Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.
Police clean ups SocGholish-infected sites tied to Evil Corp
Klue OAuth breach linked to Icarus Salesforce data theft attacks
Warner warns of CISA cuts, staffing gaps in letter to acting chief
Get the show notes here: https://cisoseries.com/cybersecurity-news-police-clean-wordpress-sites-klue-oauth-breach-warners-cisa-warnings/
Huge thanks to our sponsor, ThreatLocker
Every security leader is being asked the same question right now:
How do we enable innovation without creating unnecessary risk?
That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision.
ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do.
That's why ThreatLocker is proud to support Cyber Security Headlines.
Because security works best when innovation and control move together.
Anthropic tells G7 to cooperate
Fortinet VPN leak exposes credentials
Crypto Clipper abuses reviews, narrators, and comments
Get the show notes here: https://cisoseries.com/cybersecurity-news-anthropic-tells-g7-to-cooperate-fortinet-vpn-leak-exposes-credentials-crypto-clipper-abuses-reviews/
Huge thanks to our sponsor, ThreatLocker
Every security leader is being asked the same question right now:
How do we enable innovation without creating unnecessary risk?
That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision.
ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do.
That's why ThreatLocker is proud to support Cyber Security Headlines.
Because security works best when innovation and control move together.
Athena coalition looks to secure open source
Estonia to quarantine Russian email domains
Malicious package wave hits Arch Linux
Get the show notes here: https://cisoseries.com/cybersecurity-news-athena-coalition-estonias-quarantine-arch-hit-with-malware/
Huge thanks to our sponsor, ThreatLocker
Every security leader is being asked the same question right now:
How do we enable innovation without creating unnecessary risk?
That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision.
ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do.
That's why ThreatLocker is proud to support Cyber Security Headlines.
Because security works best when innovation and control move together.
Cyber leaders defend Anthropic's banned models
FBI disrupts massive phishing service
1Password acquires Apono
Get the show notes here: https://cisoseries.com/cybersecurity-news-anthropic-models-defended-massive-phishing-service-shuttered-1password-acquires-apono/
Huge thanks to our sponsor, ThreatLocker
Every security leader is being asked the same question right now:
How do we enable innovation without creating unnecessary risk?
That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision.
ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do.
That's why ThreatLocker is proud to support Cyber Security Headlines.
Because security works best when innovation and control move together.
Feds require Anthropic to ban 'foreign national' access to Fable, Mythos
Maine disables data breach notification portal after fake disclosures
ShinyHunters extorts universities through exploiting an unpatched Oracle flaw
Get the show notes here:
Huge thanks to our sponsor, ThreatLocker
Every security leader is being asked the same question right now:
How do we enable innovation without creating unnecessary risk?
That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision.
ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do.
That's why ThreatLocker is proud to support Cyber Security Headlines.
Because security works best when innovation and control move together.
This week's Department of Know is hosted by Rich Stroffolino, with guests Brett Conlon, CISO, American Century Investments, and Jason Thomas, senior director, technology security, governance, and risk, Cystic Fibrosis Foundation.
Missed the live show? Check it out on YouTube.
The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our episode sponsor, Doppel
Cybercriminals don't respect your security silos. They use one connected attack chain to hit your brand externally, infiltrate your inbox, and manipulate your team. Stop playing whack-a-mole with fragmented tools. Doppel unifies Digital Risk Protection, Human Risk Management, and Email Security into one unified platform. One attack chain. Three pillars of defense. Zero blind spots. Secure your enterprise relentlessly at doppel.com.
Fortinet patches a new critical FortiSandbox flaw
GitHub to disable npm install scripts by default to stop supply chain attacks
Nottingham University announces data breach
Get the show notes here: https://cisoseries.com/cybersecurity-news-fortinet-patches-fortisandbox-github-disables-npm-scripts-nottingham-university-breach/
Thanks to our episode sponsor, Doppel
Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.
Patch Tuesday for the books 'Nightmare Eclipse' drops Windows 0-day Claude Fable restricted at Microsoft
Get the show notes here: https://cisoseries.com/cybersecurity-news-big-patch-tuesday-nightmare-eclipse-drops-windows-0-day-claude-fable-restricted-at-microsoft/
Thanks to our episode sponsor, Doppel
Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.
Anthropic releases Claude Fable 5
French government messaging service breached
CISA rethinking risk evaluations
Get the show notes here: https://cisoseries.com/cybersecurity-news-claude-fable-5-tchap-hacked-cisa-priorities/
Thanks to our episode sponsor, Doppel
Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.
Microsoft malware hits Claude and Gemini users
Mythos can exploit new flaws in hours
AI tool abuse behind Instagram hacks
Get the show notes here: https://cisoseries.com/cybersecurity-news-claude-gemini-malware-mythos-sneaky-flaws-instagram-ai-abuse/
Thanks to our episode sponsor, Doppel
Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.
Palantir executive considered for CISA leadership
EU unveils tech sovereignty package to cut reliance on U.S., Chinese suppliers
Hackers now exploit SolarWinds Serv-U flaw to crash servers
Get the show notes here: https://cisoseries.com/cybersecurity-news-cisa-palantir-director-eu-tech-sovereignty-solarwinds-serv-u-flaw/
Thanks to our episode sponsor, Doppel
Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.
This week's Department of Know is hosted by Rich Stroffolino, with guests Robb Dunewood, host, Daily Tech News Show, and David Cross, CISO, Atlassian.
Get the show notes here.
Missed the live show? Check it out on YouTube.
The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.
Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
Chinese cybercrime group sets record pace
Cisco warns of critical Unified CM flaw with PoC exploit code
Hackers spied on a stock exchange executive's Outlook mailbox for five months
Get the show notes here: https://cisoseries.com/cybersecurity-news-chinese-cybercrime-group-cisco-cm-flaw-cisa-faces-changes/
Huge thanks to our episode sponsor, Vanta
Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta [rhymes with Santa] Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
Law enforcement cracks down on illegal streamers
The European Commission releases digital sovereignty plan
The startup costs for US cyber force
Get the show notes here: https://cisoseries.com/cybersecurity-news-illegal-streamers-eu-digital-sovereignty-cost-of-a-cyber-force/
Huge thanks to our episode sponsor, Vanta
Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta [rhymes with Santa] Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
Russia claims officials' surveillance
Project Glasswing access expands
CISA flags two-year-old Oracle flaw
Get the show notes here: https://cisoseries.com/cybersecurity-news-russia-claims-officials-surveillance-project-glasswing-expands-cisa-flags-two-year-old-oracle-flaw/
Huge thanks to our episode sponsor, Vanta
Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta [rhymes with Santa] Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
Meta AI hands over Instagram account access
Dutch police dismantle huge botnet
RedHat packages get backdoored
Get the show notes here: https://cisoseries.com/meta-ai-hands-over-instagram-access-dutch-police-dismantle-botnet-redhat-packages-backdoored/
Huge thanks to our episode sponsor, Vanta
Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta [rhymes with Santa] Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks
ChatGPT share links used to host fake outage pages to deliver malware
Federal audit reveals NIST's NVD problems
Get the show notes here: https://cisoseries.com/cybersecurity-news-globalprotect-vpn-exploited-chatgpt-share-links-exploits-feds-criticize-nist/
Huge thanks to our episode sponsor, Vanta
Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta [rhymes with Santa] Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.
This week's Department of Know is hosted by Rich Stroffolino, with guests Bruce Schneier, chief of security architecture, Inrupt, and Chris Ray, field CTO, GigaOm.
Missed the live show? Check it out on YouTube.
Huge thanks to our sponsor, Guardsquare Mobile security incidents are no longer the exception—they are the norm. Last year, seventy-two percent of companies suffered a mobile app security incident. As the primary gateway to your APIs and data, your mobile app requires more than just basic encryption; it needs a multi-layered security strategy. Protect your brand and your bottom line with layered mobile app protection. Learn more at Guardsquare.com.
Fraud gang steals from World Cup fans
Pentagon says US military targeted by location
IBM and Red Hat commit to "Project Lightwell"
Check out your show notes here: https://cisoseries.com/cybersecurity-news-world-cup-fraud-us-military-location-targets-ibm-and-red-hat-go-project-lightwell/
Huge thanks to our sponsor, Guardsquare
Attackers are treating your mobile app like an open book. Sixty-three percent of security leaders recently detected app tampering, cloning, or unauthorized modifications. When your code runs in an untrusted environment, you need runtime self-protection and code hardening to keep attackers out. Address tampering before it starts. Learn more at Guardsquare.com.
Glassworm botnet gets shattered
China overhauls world's biggest surveillance network
Charter confirms ShinyHunters data breach
Check out your show notes here: https://cisoseries.com/cybersecurity-news-glassworm-botnet-shattered-china-overhauls-surveillance-charter-confirms-shinyhunters-breach/
Huge thanks to our sponsor, Guardsquare
AI is speeding up development, but at what cost? While ninety-six percent of teams now use AI tools, eighty-one percent report that AI-generated code has introduced new vulnerabilities into their mobile apps. In a world with automated threats, you need multi-layered, polymorphic security to stay ahead of the curve. Learn more at Guardsquare.com.
Nimbus Manticore learning new tricks
Phishing moves to real-time credential harvesting
India wants 12-hour patches
Check out your show notes here: https://cisoseries.com/cybersecurity-news-nimbus-manticore-real-time-credential-harvesting-12-hour-patches/
Huge thanks to our sponsor, Guardsquare
Is your mobile app truly protected? Relying on the OS isn't enough. A global study of thirteen-hundred security and developer leaders found that ninety-six percent of teams using layered protection reported significantly fewer security incidents. Don't wait for a breach to harden your defenses. Get the protection needed for modern secuirty risks. Learn more at Guardsquare.com.
'Megalodon' infects GitHub repositories
Netherlands seizes 800 servers over cyberattacks
Ghost CMS exploited for ClickFix attacks
Check out your show notes here: https://cisoseries.com/cybersecurity-news-megalodon-infects-github-netherlands-server-seize-ghost-cms-exploited-for-clickfix/
Huge thanks to our sponsor, Guardsquare
Your backend is only as secure as your frontend. Research shows that client-side compromise is now a primary driver of API risk. With sixty-three percent of leaders detecting mobile app tampering or cloning last year, don't leave your mobile app security to chance. Get multilayered protection for your entire mobile app ecosystem from the outside in. Learn more at Guardsquare.com.
CISA adds Drupal Core flaw to KEV
Underminr hides malicious connections behind trusted domains
Canadian man charged with running KimWolf DDoS botnet
Check out your show notes here: https://cisoseries.com/cybersecurity-news-drupal-kev-addition-underminr-revives-domain-fronting-canadian-kimwolf-arrest/
Huge thanks to our sponsor, Guardsquare
Mobile app security isn't just a tech issue; it's a revenue issue. A recent global study found that seventy-two percent of organizations experienced a mobile app security incident last year. Even worse? Sixty-five percent saw customer churn or uninstalls as a result. Protect your brand and your bottom line with layered mobile app protection. Learn more at Guardsquare.com.
This week's Department of Know is hosted by Rich Stroffolino, with guests Kathleen Mullin, former CISO, MyCareGorithm, and Nick Espinosa, host, Deep Dive Radio Show.
Missed the live show? Check it out on YouTube.
The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.
Huge thanks to our sponsor, ThreatLocker ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.
Cisco issues 10.0 Secure Workload admin flaw warning
Spammers abuse internal Microsoftonline account
Google's surge in Chrome vulnerability announcements
Get the show notes here: https://cisoseries.com/cybersecurity-news-ciscos-10-0-vulnerability-microsoft-email-spammed-chrome-vulnerability-surge/
Thanks to our episode sponsor, ThreatLocker
ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.
GitHub breach via VS Code extension
Shai-Hulud wave compromises 600 npm packages
Huawei attack behind Luxembourg telecom crash
Get the show notes here: https://cisoseries.com/cybersecurity-news-github-vs-code-extension-breach-shai-hulud-npm-package-compromise-huawei-luxembourg-telecom-link/
Thanks to our episode sponsor, ThreatLocker
ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.
Microsoft disrupts malware-signing-as-a-service
Critical flaw found in industrial robot OS
CISA admin leaks keys
Get the show notes here: https://cisoseries.com/cybersecurity-news-microsoft-hits-fox-tempest-robotics-os-flaw-cisa-admins-leaks-keys/
Thanks to our episode sponsor, ThreatLocker
ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.
Linus Torvalds not into AI bug hunters
7-Eleven hit with ransom demand
MENA runs new cybercrime op
Get the show notes here: https://cisoseries.com/cybersecurity-news-linus-torvalds-talks-ai-bug-hunters-7-eleven-ransom-demand-menas-new-cybercrime-op/
Thanks to our episode sponsor, ThreatLocker
ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.
Grafana GitHub token breach leads to extortion attempt
Microsoft rejects Azure vulnerability report, researcher disputes decision
Funnel Builder flaw actively exploited to steal payment data
Get the show notes here: https://cisoseries.com/cybersecurity-news-grafan-github-extortion-microsoft-rejects-azure-report-funnel-builder-flaw/
Thanks to our episode sponsor, ThreatLocker
ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.
This week's Department of Know is hosted by Rich Stroffolino, with guests Gary Chan, CISO, SSM Health and Peter Liebert, CISO, Salesloft.
Missed the live show? Check it out on YouTube.
The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.
Huge thanks to our sponsor, Doppel
Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.
G7 countries release AI SBOM guidance
Dell confirms its SupportAssist software causes Windows BSOD crashes
Dirty Frag sequel arrives as Fragnesia
Get the show notes here: https://cisoseries.com/cybersecurity-news-g7-releases-ai-sbom-dell-supportassist-bsod-dirty-frag-sequel/
Huge thanks to our episode sponsor, Doppel
Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.
Foxconn confirms North American factory attack
BitLocker zero-day accesses protected drives
MDASH patches 16 Windows flaws
Get the show notes here: https://cisoseries.com/cybersecurity-news-foxconn-factory-attacks-bitlocker-zero-day-accesses-protected-drives-mdash-patches-windows-flaws/↗
Huge thanks to our episode sponsor, Doppel
Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.
Instructure reaches an "agreement" with ShinyHunters
Shai Hulud campaign is back
OpenAI launches Daybreak
Get the show notes here: https://cisoseries.com/cybersecurity-news-instructures-agreement-shai-hulud-campaign-openais-daybreak/
Huge thanks to our episode sponsor, Doppel
Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.
A.I. hackers find software flaw
Xbox leaks 'Forza Horizon 6'
Linux kernel hit by 2nd flaw
Get the show notes here: https://cisoseries.com/cybersecurity-news-a-i-software-flaw-hackers-forza-horizon-6-leak-linux-kernel-hit-again/
Huge thanks to our episode sponsor, Doppel
Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.
CPanel, WHM release fixes for three new vulnerabilities
Official JDownloader site serves malware to Windows and Linux users
Sen. Schumer seeks DHS plan on AI cyber coordination
Get the show notes here: https://cisoseries.com/cybersecurity-news-new-cpanel-vulnerabilities-jdownloader-delivers-malware-schumer-pushes-dhs/
Huge thanks to our episode sponsor, Doppel
Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.
Link to the episode
This week's Department of Know is hosted by Rich Stroffolino, with guests Jonathan Waldrop, CISO, Acoustic, and Jason Elrod, CISO, MultiCare Health System.
Missed the live show? Check it out on YouTube.
The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.
Huge thanks to our sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.
PAN-OS RCE exploit under active use enabling root access and espionage
Polish intelligence says hackers attacked water treatment control systems
Ivanti warns of new EPMM flaw exploited in zero-day attacks
Get the show notes here: https://cisoseries.com/cybersecurity-news-pan-os-rce-exploit-poland-water-hacks-ivanti-epmm-flaw/
Thanks to our episode sponsor, Vanta
Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.
Google Chrome installs 4GB AI model on devices
Daemon Tools disk app backdoored in supply-chain attack
Crypto's 'decentralised finance' sector hit by investor exodus
Get the show notes here:
Thanks to our episode sponsor, Vanta
Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.
Video game platform hit by supply chain attack
Bleeding Llama could expose your data
US gets more early LLM access
Get the show notes here: https://cisoseries.com/cybersecurity-news-video-game-supply-chain-attack-bleeding-llama-us-gets-early-llm-access/
Thanks to our episode sponsor, Vanta
Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.
Instructure discloses breach amid leak threats
DigiCert revokes certificates
Silver Fox targets Indian and Russian orgs
Get the show notes here: https://cisoseries.com/cybersecurity-news-instructure-discloses-breach-digicert-revokes-certificates-silver-fox-targets-indian-and-russian-orgs/
Thanks to our episode sponsor, Vanta
Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.
Telegram Mini Apps deliver Android malware
CISA orders Federal agencies to patch cPanel bug by Sunday
British cyber agency warns of looming 'patch wave' due to speedy AI flaw discovery
Get the show notes here: https://cisoseries.com/cybersecurity-news-telegram-mini-apps-malware-cpanel-is-sorry-patch-wave-warning/
Thanks to our episode sponsor, Vanta
Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.
This week's Department of Know is hosted by Rich Stroffolino, with guests Janet Heins, CISO, ChenMed, and TC Niedzialkowski, Head of IT & Security, Opendoor.
Missed the live show? Check it out on YouTube.
The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.
Get the show notes here: https://cisoseries.com/cybersecurity-news-critical-cpanel-zero-day-swiss-black-axe-arrests-hhs-data-center-questions/
Thanks to our episode sponsor, Guardsqaure
Attackers are treating your mobile app like an open book. Sixty-three percent of security leaders recently detected app tampering, cloning, or unauthorized modifications. When your code runs in an untrusted environment, you need runtime self-protection and code hardening to keep attackers out. Address tampering before it starts. Learn more at Guardsquare.com.
Critical cPanel and WHM bug exploited as zero-day
Swiss police arrest suspected members of Black Axe group
HHS ponders government posture for protecting data centers
Get the show notes here: https://cisoseries.com/cybersecurity-news-critical-cpanel-zero-day-swiss-black-axe-arrests-hhs-data-center-questions/
Thanks to our episode sponsor, Guardsqaure
Attackers are treating your mobile app like an open book. Sixty-three percent of security leaders recently detected app tampering, cloning, or unauthorized modifications. When your code runs in an untrusted environment, you need runtime self-protection and code hardening to keep attackers out. Address tampering before it starts. Learn more at Guardsquare.com.
Hackers arrested for selling Roblox accounts
Microsoft's patch for a 0-day falls short
US & China partner on Dubai scam takedown
Get the show notes here: https://cisoseries.com/cybersecurity-news-roblox-hackers-arrested-microsoft-0-day-falls-short-dubai-scam-takedown/
Thanks to our episode sponsor, Guardsqaure
AI is speeding up development, but at what cost? While ninety-six percent of teams now use AI tools, eighty-one percent report that AI-generated code has introduced new vulnerabilities into their mobile apps. In a world with automated threats, you need multi-layered, polymorphic security to stay ahead of the curve. Learn more at Guardsquare.com.
FIDO Alliance working on securing AI agent payments
Germany suspects Russia in Signal phishing
RCE flaw in open-source robotics platform
Get the show notes here: https://cisoseries.com/cybersecurity-news-agent-payments-russian-phishing-lerobot-rce-flaw/
Thanks to our episode sponsor, Guardsqaure
Is your mobile app truly protected? Relying on the OS isn't enough. A global study of thirteen-hundred security and developer leaders found that ninety-six percent of teams using layered protection reported significantly fewer security incidents. Don't wait for a breach to harden your defenses. Get the protection needed for modern secuirty risks. Learn more at Guardsquare.com.
PhantomRPC flaw enables privilege escalation
Checkmarx confirms GitHub data hit dark web
PyPI package hacked to push infostealer
Get the show notes here: https://cisoseries.com/cybersecurity-news-phantomrpc-flaw-checkmarx-github-dark-web-data-pypi-package-infostealer/
Thanks to our episode sponsor, Guardsqaure
Your backend is only as secure as your frontend. Research shows that client-side compromise is now a primary driver of API risk. With sixty-three percent of leaders detecting mobile app tampering or cloning last year, don't leave your mobile app security to chance. Get multilayered protection for your entire mobile app ecosystem from the outside in. Learn more at Guardsquare.com.
ADT says customer data stolen in cyberattack
SMS blasting comes to Toronto
Researchers find pre-Stuxnet malware targeting engineering software
Get the show notes here: https://cisoseries.com/cybersecurity-news-adt-data-breach-toronto-sms-blasting-pre-stuxnet-malware-discovery/
Thanks to our episode sponsor, Guardsquare
Mobile app security isn't just a tech issue; it's a revenue issue. A recent global study found that seventy-two percent of organizations experienced a mobile app security incident last year. Even worse? Sixty-five percent saw customer churn or uninstalls as a result. Protect your brand and your bottom line with layered mobile app protection. Learn more at Guardsquare.com.
Link to episode
This week's Department of Know is hosted by Rich Stroffolino, with guests Brett Conlon, CISO, American Century Investments, and Michael Bickford, former CISO, New York State Gaming Commission.
Missed the live show? Check it out on YouTube.
The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.
Huge thanks to our sponsor, ThreatLocker ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.
Cosmetics giant Rituals discloses data breach
Apple fixes iOS flaw exploited by the FBI
Microsoft Teams Helpdesk impersonation
Get the show notes here: https://cisoseries.com/cybersecurity-news-rituals-cosmetics-breach-fbi-ios-flaw-fixed-teams-helpdesk-malware-impersonation/
Huge thanks to our sponsor, ThreatLocker
ThreatLocker is extending Zero Trust beyond endpoint control. With their recent releaseof Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.
OpenAI shares cyber product with government orgs
Unauthorized Mythos access, Firebox bugs fixed by Mythos
Insurers move to cap LLMjacking cyber payouts
Get the show notes here: https://cisoseries.com/cybersecurity-news-new-openai-cyber-product-unauthorized-mythos-access-insurers-to-cap-llmjacking-payouts/
Huge thanks to our sponsor, ThreatLocker
ThreatLocker is extending Zero Trust beyond endpoint control. With their recent releaseof Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.
CISA lacks Mythos access
Lovable denies data leak
YouTube opens up deepfake detection tool
Get the show notes here: https://cisoseries.com/cybersecurity-news-cisa-lacks-mythos-lovables-leak-by-design-youtubes-deepfake-detection/
Huge thanks to our sponsor, ThreatLocker
ThreatLocker is extending Zero Trust beyond endpoint control. With their recent releaseof Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.
Vercel confirms breach, stolen data for sale
ZionSiphon targets water infrastructure
Bluesky blames outage on DDoS
Get the show notes here: https://cisoseries.com/cybersecurity-news-vercel-breach-zionsiphon-targets-water-infrastructure-bluesky-ddos/
Huge thanks to our sponsor, ThreatLocker
ThreatLocker is extending Zero Trust beyond endpoint control. With their recent releaseof Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.
London hospitals continue to suffer from 2024 ransomware attack
Four arrested in PowerOFF takedown
Microsoft Defender "RedSun" zero-day
Get the show notes here: https://cisoseries.com/cybersecurity-news-london-hospital-ransomware-legacy-poweroff-takedown-microsoft-redsun-zero-day/
Huge thanks to our sponsor, ThreatLocker
ThreatLocker is extending Zero Trust beyond endpoint control. With their recent releaseof Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.
Link to episode page
This week's Department of Know is hosted by Rich Stroffolino, with guests Andrew Storms, security engineering, Kilo Code, and Eduardo Ortiz-Romeu, VP, global head of cybersecurity, Techtronic Industries.
Missed the live show? Check it out on YouTube.
Huge thanks to our sponsor, Conveyor
Happy Friday. Hope there isn't a fresh security questionnaire sitting in your inbox right now. If there is, here's something worth knowing. The teams that have fully automated their customer security reviews didn't just get a better trust center. They switched to an AI platform built for the whole workflow. Conveyor handles trust center, questionnaire automation, and self-serve for sales, all in one place, with AI keeping the knowledge base current so answers are always accurate. Learn why enterprise SaaS teams choose Conveyor at conveyor.com.
Cisco posts urgent Webex Services warning
Splunk issues fixes for Enterprise vulnerability
Git identity spoof tricks Claude into approving bad code
Get the show notes here: https://cisoseries.com/cybersecurity-news-cisco-webex-warning-splunks-enterprise-fix-git-spoof-tricks-claude/
Huge thanks to our sponsor, Conveyor
Happy Friday. Hope there isn't a fresh security questionnaire sitting in your inbox right now. If there is, here's something worth knowing. The teams that have fully automated their customer security reviews didn't just get a better trust center. They switched to an AI platform built for the whole workflow. Conveyor handles trust center, questionnaire automation, and self-serve for sales, all in one place, with AI keeping the knowledge base current so answers are always accurate. Learn why enterprise SaaS teams choose Conveyor at conveyor.com.
OpenAI rolls out GPT-5.4-Cyber
McGraw Hill breach due to Salesforce misconfig
Signed adware operation disables antivirus
Get the show notes here: https://cisoseries.com/cybersecurity-news-openais-gpt-5-4-cyber-mcgraw-hill-blames-salesforce-for-breach-signed-adware-disables-antivirus/
Huge thanks to our sponsor, Conveyor
At some point, every fast-growing SaaS team hits the same wall. The trust center is live. The SOC 2 is published. And somehow the security questionnaires just keep piling up. That's when teams realize a static trust center isn't the finish line. Conveyor is what comes next. AI that completes questionnaires automatically. A trust center customers can actually self-serve. And a knowledge base that updates itself with AI. Companies like Atlassian and Zapier are already there. See what's possible at conveyor.com.
Ransomware rivals turn on each other
Fake Ledger app drains millions in crypto
US Treasury wants access to Mythos
Get the show notes here: https://cisoseries.com/cybersecurity-news-ransomware-drama-faked-ledger-app-treasury-wants-mythos/
Huge thanks to our sponsor, Conveyor
Your trust center was a great start. But if your team is still manually answering questionnaires and fielding sales questions, it hasn't solved the problem. Conveyor goes beyond a trust center. You get a living knowledge library your AI keeps up to date, questionnaire automation that handles any format, and a self-serve experience so customers and sales teams get answers without looping in infosec. Top enterprise SaaS companies trust Conveyor to handle it all. Check it out at conveyor.com.
Claude Mythos Preview's cyber capabilities
Anodot hack leaves breached companies facing extortion
wolfSSL library flaw enables forged certificate use
Get the show notes here: https://cisoseries.com/cybersecurity-news-claude-mythos-previews-capabilities-anodot-breached-companies-face-extortion-wolfssl-flaw-enables-forged-certificates/
Huge thanks to our sponsor, Conveyor
Three tools to manage customer security reviews is two too many. Most teams start with a trust center, bolt on a questionnaire tool, and end up with a knowledge base nobody trusts and a Slack channel full of sales pings anyway. Conveyor replaces all of it. Trust center, questionnaire automation, self-serve for sales, AI-managed knowledge library, one platform. Companies like Atlassian and Zapier already made the switch. See why at conveyor.com.
A quick announcement: we're moving our Department of Know livestream to Fridays at 4pm ET/1 pm PT. The format will remain the same. We hope to see you there.
Adobe patches months-old Reader zero-day
Critical Marimo flaw now under active exploitation
Hackers claim control over Venice anti-flood pumps
Get the show notes here: https://cisoseries.com/cybersecurity-news-adobe-patches-zero-day-marimo-flaw-exploited-venice-flood-threat/
Huge thanks to our sponsor, Conveyor
Still manually filling out security questionnaires even though you have a trust center? A starter trust center is table stakes and the best security teams have moved way past that. Conveyor gives you an agentic trust center, AI questionnaire automation, and a self-serve layer so sales can move deals forward without pinging you every five minutes. Companies like Atlassian and Zapier made the switch. See why at conveyor.com.
Google API keys in Android apps expose Gemini endpoints
Acrobat Reader zero-day flaw exploited since December
Cryptocurrency ATM company Bitcoin Depot reports cyberattack
Check out our show notes here: https://cisoseries.com/cybersecurity-news-android-api-exposure-acrobat-reader-zero-day-bitcoin-depot-cyberattack/
Huge thanks to our episode sponsor, Vanta
Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.
Ransomware knocks Dutch healthcare vendor offline
APT28 is keeping busy
CIA quietly elevated its cyber espionage division
Check out our show notes here: https://cisoseries.com/cybersecurity-news-chipsoft-popped-apt28-updates-cia-cyber-espionage-elevation/
Huge thanks to our episode sponsor, Vanta
Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.
Anthropic announces Project Glasswing
U.S. seeks to slash CISA funding
Russia-linked hackers hijack routers for passwords
Check out our show notes here: https://cisoseries.com/cybersecurity-news-anthropics-project-glasswing-cisa-funding-in-doubt-routers-hijacked-for-passwords/
Huge thanks to our episode sponsor, Vanta
Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.
Drift says exploit was North Korean intelligence operation
GitHub used in multi-stage attacks targeting South Korea
Data leak threatened after Die Linke attack
Check out our show notes here: https://cisoseries.com/cybersecurity-news-drift-blames-exploit-on-north-korea-github-attacks-target-south-korea-die-linke-breach-threatens-data-leak/
Huge thanks to our episode sponsor, Vanta
Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.
Link to episode page
This week's Department of Know is hosted by Sarah Lane, with guests Jack Kufahl, CISO, Michigan Medicine, and Adam Palmer, CISO, First Hawaiian Bank.
Missed the live show? Check it out on YouTube.
Huge thanks to our sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.
36 Malicious npm packages exploited to deploy persistent implants
Hundreds of millions to be cut from CISA in proposed budget
Hackers exploit React2Shell in automated credential theft campaign
Check out our show notes here: https://cisoseries.com/cybersecurity-news-malicious-npm-packages-cisa-budget-cuts-hackers-exploit-react2shell/
Huge thanks to our episode sponsor, Vanta
Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.
250,000 affected by data Breach at Texas hospital
CISA says, "patch Citrix NetScaler bug by Thursday"
Researchers uncover mining operation using ISO lures
Get the show notes here: https://cisoseries.com/cybersecurity-news-texas-hospital-breach-cisa-orders-netscaler-patch-iso-file-rat-warning/
Huge thanks to our sponsor, ThreatLocker
Security controls fail when they break the business. Successful teams phase in protections gradually — starting with visibility, then moving to enforcement. That approach allows organizations to reduce risk without overwhelming IT teams or disrupting critical workflows. Learn more at ThreatLocker.com
Apple pushes new patches over DarkSword
FBI: US surveillance hack is major incident
Cisco code stolen in Trivy-linked breach
Get the show notes here: https://cisoseries.com/cybersecurity-news-apple-pushes-new-patches-over-darksword-fbi-us-surveillance-hack-is-major-incident-cisco-code-stolen-in-trivy-linked-breach/
Huge thanks to our sponsor, ThreatLocker
Detection-based security assumes you'll catch an attack in time. Control-based security assumes you won't. That mindset shift is driving more organizations to focus on preventative controls — stopping unknown execution and unauthorized privilege elevation instead of relying solely on alerts after the fact. Learn more at ThreatLocker.com
HTTP client introduces malicious dependency
TeamPCP testing the open source supply chain
Claude source code leaked
Get the show notes here: https://cisoseries.com/cybersecurity-news-axios-poisoned-teampcp-details-claude-code-leaked/
Huge thanks to our sponsor, ThreatLocker
Least privilege isn't about distrusting users — it's about limiting blast radius. Many attacks succeed because malware inherits excessive permissions. Enforcing least privilege helps ensure that even if something goes wrong, attackers can't easily escalate access or move laterally across the environment. Learn more at ThreatLocker.com
macOS Terminal gets ClickFix attacks
Russian court sentences 'Flint' over card fraud
CareCloud probes data breach
Get the show notes here: https://cisoseries.com/cybersecurity-news-macos-terminal-clickfix-attacks-russian-court-sentences-flint-carecloud-probes-data-breach/
Huge thanks to our sponsor, ThreatLocker
Ransomware doesn't need to be sophisticated if it's allowed to execute. A growing number of security teams are shifting focus from detecting ransomware to preventing execution in the first place — controlling applications, scripts, and installers so unauthorized code never gets the chance to run. Learn more at ThreatLocker.com
Link to episode page
This week's Department of Know is hosted by Rich Stroffolino with guests Dennis Pickett, vp, CISO, RTI International, and Jacob Combs, CISO, Tandem Diabetes Care
Thanks to our show sponsor, ThreatLocker
Many security strategies still assume everything is allowed until proven malicious. Attackers understand that model well. That's why more organizations are rethinking endpoint security — shifting from detection-first tools to control-first approaches that reduce attack surface before an incident occurs. Learn more at ThreatLocker.com
All links and the video of this episode can be found on CISO Series.com
FBI confirms theft of director's personal emails
Lloyds customer data exposed in IT glitch
Hundreds of valid API keys discovered on the Web
Get the show notes here: https://cisoseries.com/cybersecurity-news-fbi-email-theft-lloyds-bank-glitch-api-keys-running-loose/
Huge thanks to our sponsor, ThreatLocker
Most breaches don't start with a zero-day — they start because something unexpected was allowed to run. One way organizations reduce risk is by shrinking the attack surface: deciding what software should be allowed to execute and blocking everything else by default. Fewer unknowns means fewer opportunities for attackers. Learn more at ThreatLocker.com
Alleged RedLine dev extradited to US
Red Menshen uses BPFDoor to spy
Former NSA chiefs worry US cybersecurity is slipping
Check out our show notes for all story links: https://cisoseries.com/cybersecurity-news-alleged-redline-dev-extradited-red-menshen-spies-with-bpfdoor-is-us-cybersecurity-slipping/
Huge thanks to our sponsor, ThreatLocker
Security controls fail when they break the business. Successful teams phase in protections gradually — starting with visibility, then moving to enforcement. That approach allows organizations to reduce risk without overwhelming IT teams or disrupting critical workflows. Learn more at ThreatLocker.com
Torg Grabber targets crypto wallets
TeamPCP backdoors LiteLLM
GitHub adds AI security bug detection
Check out our show notes for all story links: https://cisoseries.com/cybersecurity-news-torg-grabber-targets-crypto-teampcp-backdoors-litellm-github-ai-bug-detection/
Huge thanks to our sponsor, ThreatLocker
Detection-based security assumes you'll catch an attack in time. Control-based security assumes you won't. That mindset shift is driving more organizations to focus on preventative controls — stopping unknown execution and unauthorized privilege elevation instead of relying solely on alerts after the fact. Learn more at ThreatLocker.com
FCC bans foreign routers
Drone activity disrupts AWS region
Crunchyroll confirmed data leak
Check out our show notes for all story links: https://cisoseries.com/cybersecurity-news-fcc-router-ban-drone-hit-aws-crunchroll-leak/
Huge thanks to our sponsor, ThreatLocker
Least privilege isn't about distrusting users — it's about limiting blast radius. Many attacks succeed because malware inherits excessive permissions. Enforcing least privilege helps ensure that even if something goes wrong, attackers can't easily escalate access or move laterally across the environment. Learn more at ThreatLocker.com
New DarkSword exploit hits GitHub
Gemini AI agents scour the dark web
Trivy supply chain attack expands
Check out our show notes for all story links: https://cisoseries.com/cybersecurity-news-darksword-exploit-hits-github-gemini-ai-agents-scour-dark-web-trivy-supply-chain-attack-expands/
Huge thanks to our sponsor, ThreatLocker
Ransomware doesn't need to be sophisticated if it's allowed to execute. A growing number of security teams are shifting focus from detecting ransomware to preventing execution in the first place — controlling applications, scripts, and installers so unauthorized code never gets the chance to run. Learn more at ThreatLocker.com
Link to episode page
This week's Department of Know is hosted by Rich Stroffolino with guests Bil Harmer, CISO, Supabase, and Chris Ray, Field CTO, GigaOm
Thanks to our show sponsor, ThreatLocker
Many security strategies still assume everything is allowed until proven malicious. Attackers understand that model well. That's why more organizations are rethinking endpoint security — shifting from detection-first tools to control-first approaches that reduce attack surface before an incident occurs. Learn more at ThreatLocker.com
All links and the video of this episode can be found on CISO Series.com
Law enforcement seizes botnet infrastructure
California city and LA transit agency report cybersecurity issues
Microsoft Azure Monitor alerts used for callback phishing attacks
Check out our show notes for all story links: https://cisoseries.com/cybersecurity-news-cybersecurity-news-international-botnet-takedown-california-city-ransomed-azure-monitor-phishing/
Huge thanks to our sponsor, ThreatLocker
Most breaches don't start with a zero-day — they start because something unexpected was allowed to run. One way organizations reduce risk is by shrinking the attack surface: deciding what software should be allowed to execute and blocking everything else by default. Fewer unknowns means fewer opportunities for attackers. Learn more at ThreatLocker.com
Critical Microsoft SharePoint flaw now exploited in attacks
1stProtect reveals endpoint security platform intended to prevent cyberattacks in real time
CISA urges U.S. organizations to secure Microsoft Intune systems following Stryker breach
Get links to all our stories in the show notes: https://cisoseries.com/cybersecurity-news-critical-sharepoint-flaw-real-time-cyberattack-prevention-cisas-intune-warning/
Huge thanks to our episode sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Picture a "new hire" who interviews well… except they're synthetic: AI video, AI voice, AI backstory. Once they're in, they go after payroll, internal docs, and access. That's the new reality: the attack surface is trust itself. Adaptive fights back with realistic deepfake simulations and training that actually sticks. Learn more at adaptivesecurity.com.
DarkSword emerges from suspected Russian hackers
"ShieldGuard" dismantled after malware discovery
North Korea's fake IT worker army rakes in $500M/year
Get links to all our stories in the show notes: https://cisoseries.com/cybersecurity-news-darksword-emerges-shieldguard-dismantled-nk-it-worker-army-rakes-in-money/
Huge thanks to our episode sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Picture a "new hire" who interviews well… except they're synthetic: AI video, AI voice, AI backstory. Once they're in, they go after payroll, internal docs, and access. That's the new reality: the attack surface is trust itself. Adaptive fights back with realistic deepfake simulations and training that actually sticks. Learn more at adaptivesecurity.com.
Energy Department to release first cyber strategy
Tech giants sign on to fight scammers
Font-rendering hides malicious commands from AI in plain sight
Get links to all our stories in the show notes: https://cisoseries.com/cybersecurity-news-energy-strategy-scammer-accord-font-rendering-attack/
Huge thanks to our episode sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Attackers don't need malware anymore; they need trust. Tip: set a simple passphrase for high-risk actions, like wire requests or "urgent" account recovery – especially within finance teams and families. If the caller can't answer it, pause and verify. Adaptive runs deepfake and vishing simulations so employees practice this before it's real. Learn more at adaptivesecurity.com.
Stryker hospital tools safe, digital ordering services down
Models apply to be the face of AI scams
Cybercrime up 245% since Iran conflict
Get links to all our stories in the show notes: https://cisoseries.com/cybersecurity-news-stryker-hospital-tools-safe-models-apply-to-power-ai-scams-cybercrime-up-245/
Huge thanks to our episode sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Today's phishing doesn't just hit inboxes — it can sound like your CFO or look like your CEO on Zoom. AI voices, video, and deepfakes are turning trust into the attack surface. Adaptive fights back with AI-driven risk scoring, deepfake simulations featuring your own executives, and interactive training your team will actually remember. Take a three-minute tour or request a CEO deepfake demo at adaptivesecurity.com.
Link to episode page
This week's Department of Know is hosted by Rich Stroffolino with guests Jonathan Waldrop, CISO, Acoustic, and Chris Ray, Field CTO, GigaOm
Thanks to our show sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Deepfakes aren't science fiction anymore; they're a daily threat. Quick tip: if your voicemail greeting is your real voice, switch it to the default robot voice. A few seconds of audio can be enough to clone you. Adaptive helps teams spot and stop these AI-powered social engineering attacks. Learn more at adaptivesecurity.com.
All links and the video of this episode can be found on CISO Series.com
Payload Ransomware group claims breached of Royal Bahrain Hospital
Canadian food retailer Loblaw confirms data breach
New York cyber regulations for water organizations launch in 2027
Get links to all our stories in the show notes: https://cisoseries.com/cybersecurity-news-royal-bahrain-hospital-breach-canadas-loblaw-breached-new-york-water-laws/
Huge thanks to our episode sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Deepfakes aren't science fiction anymore; they're a daily threat. Quick tip: if your voicemail greeting is your real voice, switch it to the default robot voice. A few seconds of audio can be enough to clone you. Adaptive helps teams spot and stop these AI-powered social engineering attacks. Learn more at adaptivesecurity.com.
Iran boosts cyberattacks
VENON targets Brazilian banks
England Hockey investigates breach
Get links to all the stories in our show notes: https://cisoseries.com/cybersecurity-news-iran-boosts-cyberattacks-venon-targets-brazilian-banks-england-hockey-investigates-breach/
Huge thanks to our sponsor, Dropzone AI
If you are heading to RSAC next week, here are three things worth seeing at the Dropzone AI Diner. Booth 455, South Expo Hall. One: watch their AI SOC agents investigate real alerts live, with every reasoning step exposed. Two: meet the AI Threat Hunter, the newest agent joining the team. Three: enter the investigation competition and go head to head against the AI. Schedule your stop at dropzone.ai/rsa-2026-ai-diner.
Meta apps offer new scam protection
Google's Wiz acquisition finalized
China curbs state-run OpenClaw use
Get links to all the stories in our show notes: https://cisoseries.com/cybersecurity-news-meta-offers-scam-protection-googles-wiz-acquisition-finalized-china-curbs-openclaw-use/
Huge thanks to our sponsor, Dropzone AI
Here is something worth asking any AI security vendor you meet at RSAC. Can you show me exactly what your AI did? Not just the verdict. The reasoning. Every tool it queried, every piece of evidence, every step it took to get there. Most cannot. Dropzone AI can. Every investigation is fully transparent. You do not have to trust the AI. You can verify it. See it for yourself at Booth 455. dropzone.ai/rsa-2026-ai-diner
NSA and Cyber Command head confirmed
Russians targeting encrypted messaging app users
OpenAI rolls out vulnerability scanner
Get links to all the stories in our show notes: https://cisoseries.com/cybersecurity-news-march-11-2026/
Huge thanks to our sponsor, Dropzone AI
Remember yesterday's 3 AM threat intel? Here is how it plays out with Dropzone AI. The intelligence drops. Dropzone picks it up, turns it into a threat hunt, and runs it across your SIEM, EDR, and cloud data while your team sleeps. By morning, your analysts have answers, not a backlog. That is the AI Threat Hunter, the newest agent on the team, debuting at RSAC. Booth 455, South Expo Hall. dropzone.ai/rsa-2026-ai-diner
InstallFix attacks spread fake Claude code sites
UNC4899 breaches crypto firm via trojanized file
UK launches cyber-fraud crackdown unit
Get links to all the stories in our show notes: https://cisoseries.com/cybersecurity-news-installfix-spreads-fake-claude-sites-unc4899-breaches-crypto-uk-cyber-fraud-crackdown/
Huge thanks to our sponsor, Dropzone AI
It is 3 AM. New threat intelligence drops. An attack pattern targeting your industry. Your threat hunting team is four people, all on day shift, and already behind on last week's hunts. By the time someone gets to it, the window for early detection has closed. The attacker is already inside. Tomorrow, I will tell you what Dropzone AI is bringing to RSAC to solve exactly this problem. If you cannot wait, head to dropzone.ai/rsa-2026-ai-diner.
Link to episode page
This week's Department of Know is hosted by Sarah Lane with guests John Barrow, CISO, JB Poindexter & Co., and Derek Fisher, Director of the Cyber Defense and Information Assurance Program, Temple University
Thanks to our show sponsor, Dropzone AI
Here is a number worth knowing before RSAC. The average enterprise SOC sees tens of thousands of alerts a day. Most get triaged. A fraction get thoroughly investigated. The rest sit in the queue or get auto-closed. Dropzone AI puts AI SOC agents on every one of those alerts. Every alert investigated, end to end, across your full tool stack, around the clock. Over 300 deployments in production today. They are at RSAC this year. Booth 455. dropzone.ai/rsa-2026-ai-diner
All links and the video of this episode can be found on CISO Series.com
FBI investigates suspicious activities on agency network
Over 100 GitHub repositories distributing BoryptGrab stealer
Hackers abuse .arpa DNS and ipv6 to evade phishing defenses
Get links to all the stories in our show notes: https://cisoseries.com/cybersecurity-news-fbi-network-breach-github-distributes-stealer-hackers-abuse-arpa/
Huge thanks to our sponsor, Dropzone AI
Here is a number worth knowing before RSAC. The average enterprise SOC sees tens of thousands of alerts a day. Most get triaged. A fraction get thoroughly investigated. The rest sit in the queue or get auto-closed. Dropzone AI puts AI SOC agents on every one of those alerts. Every alert investigated, end to end, across your full tool stack, around the clock. Over 300 deployments in production today. They are at RSAC this year. Booth 455. dropzone.ai/rsa-2026-ai-diner
Apple blocks ByteDance Chinese apps
Google says 90 zero-days were exploited in attacks last year
Iran intelligence backdoored U.S. bank, airport, software outfit networks
Get the show notes here: https://cisoseries.com/cybersecurity-news-apple-blocks-bytedance-googles-90-zero-days-iran-backdoors-u-s-organizations/
Huge thanks to our sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Security training fails when it's generic. Adaptive's platform personalizes training and runs deepfake simulations across email, SMS, voice, and video. And with Adaptive's AI Content Creator, you can drop in a breaking threat or compliance doc and instantly turn it into interactive, multilingual training – no designers, no delays. Learn more at adaptivesecurity.com.
Possible iPhone-hacking toolkit used by spies
Hacker mass-mails HungerRush extortion emails
Tycoon 2FA phishing platform dismantled
Get the show notes here: https://cisoseries.com/cybersecurity-news-iphone-hacking-toolkit-used-by-spies-hungerrush-extortion-emails-tycoon-phishing-platform-dismantled/
Huge thanks to our sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Picture a "new hire" who interviews well… except they're synthetic: AI video, AI voice, AI backstory. Once they're in, they go after payroll, internal docs, and access. That's the new reality: the attack surface is trust itself. Adaptive fights back with realistic deepfake simulations and training that actually sticks. adaptivesecurity.com.
Quantum decryption gets theoretically easier
OpenAI alters the deal with the Pentagon
South Korea leaks crypto keys for all to see
Get the show notes here: https://cisoseries.com/cybersecurity-news-quantum-decryption-openais-deal-south-korea-leaks-crypto-keys/
Huge thanks to our sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Attackers don't need malware anymore; they need trust. Tip: set a simple passphrase for high-risk actions, like wire requests or "urgent" account recovery – especially within finance teams and families. If the caller can't answer it, pause and verify. Adaptive runs deepfake and vishing simulations so employees practice this before it's real. adaptivesecurity.com.
Chrome unveils quantum-safe certificates
Vulnerability allowed hijacking Gemini Live
UK warns of Iranian cyberattack risks
Get the show notes here: https://cisoseries.com/cybersecurity-news-chrome-quantum-safe-certificates-gemini-live-vulnerability-uk-warns-of-iranian-cyberattacks/
Huge thanks to our sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Today's phishing doesn't just hit inboxes — it can sound like your CFO or look like your CEO on Zoom. AI voices, video, and deepfakes are turning trust into the attack surface. Adaptive fights back with AI-driven risk scoring, deepfake simulations featuring your own executives, and interactive training your team will actually remember. Take a three-minute tour or request a CEO deepfake demo at adaptivesecurity.com.
Link to episode page
This week's Department of Know is hosted by Rich Stroffolino with guests Dan Holden, CISO, Commerce, and Mark Eggleston, CISO, CSC
Thanks to our show sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. AI is rewriting the cybersecurity rulebook, because attackers can now scale persuasion as easily as they scale code. The real target isn't just your systems anymore; it's human trust. If you aren't actively testing your organization against AI-driven phishing, vishing, and deepfakes, you're leaving a gap criminals will exploit. Adaptive runs realistic simulations and delivers tailored, engaging training so teams respond correctly when it counts. Learn more at adaptivesecurity.com.
All links and the video of this episode can be found on CISO Series.com
Gottumukkala ousted as CISA Director
Ron Wyden blocks Rudd confirmation to lead Cyber Command, NSA
Hackers Weaponize Claude Code in Mexican government cyberattack
Get the show notes here: https://cisoseries.com/cybersecurity-news-gottumukkala-ousted-wyden-blocks-rudd-hackers-weaponize-claude/
Huge thanks to our sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Deepfakes aren't science fiction anymore; they're a daily threat. Quick tip: if your voicemail greeting is your real voice, switch it to the default robot voice. A few seconds of audio can be enough to clone you. Adaptive helps teams spot and stop these AI-powered social engineering attacks. Learn more at adaptivesecurity.com.
iPhone and iPad cleared for classified NATO work
U.S. Education and Healthcare targeted with Dohdoor backdoor
Trend Micro warns of critical Apex One code execution flaws
Get links to all of today's news in our show notes here: https://cisoseries.com/cybersecurity-news-nato-adopts-apple-education-and-healthcare-backdoor-apex-one-flaws/
Thanks to today's episode sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Security training fails when it's generic. Adaptive's platform personalizes training and runs deepfake simulations across email, SMS, voice, and video. And with Adaptive's AI Content Creator, you can drop in a breaking threat or compliance doc and instantly turn it into interactive, multilingual training – no designers, no delays. Learn more at adaptivesecurity.com.
Google disrupts UNC2814
3M+ impacted by TriZetto breach
Cisco bug exploited since 2023
Get links to all of today's news in our show notes here:
Thanks to today's episode sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Picture a "new hire" who interviews well… except they're synthetic: AI video, AI voice, AI backstory. Once they're in, they go after payroll, internal docs, and access. That's the new reality: the attack surface is trust itself. Adaptive fights back with realistic deepfake simulations and training that actually sticks. adaptivesecurity.com.
Threat actors break out in under 30 minutes
Claude allegedly hit with distillation attacks
DeFi platform shutting down after crypto theft
Get links to all of today's news in our show notes here: https://cisoseries.com/cybersecurity-news-hacked-in-30-minutes-claude-distillation-defi-shutdown-after-attack/
Thanks to today's episode sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Attackers don't need malware anymore; they need trust. Tip: set a simple passphrase for high-risk actions, like wire requests or "urgent" account recovery – especially within finance teams and families. If the caller can't answer it, pause and verify. Adaptive runs deepfake and vishing simulations so employees practice this before it's real. adaptivesecurity.com.
140k affected by US healthcare breach
Data advocates warn against replicating humans
Shai-Hulud-like worm targets developers
Get links to all of today's news in our show notes here: https://cisoseries.com/cybersecurity-news-us-healthcare-breach-affects-140k-experts-warn-against-replicating-humans-shai-hulud-like-worm-targets-devs/
Thanks to today's episode sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Today's phishing doesn't just hit inboxes — it can sound like your CFO or look like your CEO on Zoom. AI voices, video, and deepfakes are turning trust into the attack surface. Adaptive fights back with AI-driven risk scoring, deepfake simulations featuring your own executives, and interactive training your team will actually remember. Take a three-minute tour or request a CEO deepfake demo at adaptivesecurity.com.
Link to episode page
This week's Department of Know is hosted by Rich Stroffolino with guests Montez Fitzpatrick, CISO, Navvis, and Peter Gregory, author.
Thanks to our show sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. AI is changing phishing, because persuasion now scales like code. And it's not just email anymore; attackers hit SMS, voice calls, and multi-step scams that jump channels. Adaptive runs AI-powered phishing simulations across email, SMS, and voice, including OSINT-based spearphishing and BEC-style scenarios, so employees practice what attacks look like. Learn more at adaptivesecurity.com.
All links and the video of this episode can be found on CISO Series.com
Arkanix Stealer – the new AI info-stealer experiment
AI-assisted hacker breached 600 Fortinet firewalls in 5 weeks
Russia stepping up hybrid attacks, preparing for confrontation with West
Get links to all of today's news in our show notes here: https://cisoseries.com/cybersecurity-news-arkanix-was-poc-600-fortinet-firewalls-breach-russia-heightens-tension/
Thanks to today's episode sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Deepfakes aren't science fiction anymore; they're a daily threat. Quick tip: if your voicemail greeting is your real voice, switch it to the default robot voice. A few seconds of audio can be enough to clone you. Adaptive helps teams spot and stop these AI-powered social engineering attacks. Learn more at adaptivesecurity.com.
CISA orders urgent patch of Dell flaw
Android malware uses Gemini to navigate infected devices
Half of all cyberattacks start in the browser, says Palo Alto Networks
Get the full show notes here: https://cisoseries.com/cybersecurity-news-cisas-dell-order-android-ai-malware-browsers-as-weak-link/
Huge thanks to our sponsor, Conveyor
Most of what Conveyor automates is boring. Like really boring. Security questionnaires. Customer requests for things like your SOC 2. All of their follow-up questions. Answering tickets from your sales team. You know what's not boring? Alteryx using Conveyor to support over half a billion dollars in enterprise deals with a small 4 person team. All they did was set up an AI trust center and use Conveyor's AI agent to complete questionnaires. Learn more at conveyor.com.
Microsoft Copilot summarizes confidential emails
ShinyHunters takes CarGurus records
Texas sues TP-Link over router hack
Get the full show notes here: https://cisoseries.com/cybersecurity-news-copilot-summarizes-confidential-emails-shinyhunters-targets-cargurus-texas-sues-tp-link/
Huge thanks to our sponsor, Conveyor
Every fast-growing company hits this one moment.
Sales wants to close bigger enterprise deals, but this means the security team is buried in security questionnaires. Alteryx avoided the deluge of questionnaires by using Conveyor to automate their customer security reviews.The result? AI completes questionnaires, 40% more customers are supported through a self-serve trust center, and over half a billion dollars in security influenced revenue. If you're trying to scale without adding headcount, take a look at Conveyor at conveyor.com.
Hackers target anti-government protestors
UK launches "lock the door" cybersecurity campaign
Cellebrite linked to phone hack on Kenyan politician
Get the full show notes here: https://cisoseries.com/cybersecurity-news-hacking-protestors-uk-locks-the-door-kenyan-politician-phone-cracked/
Huge thanks to our sponsor, Conveyor
Most of what Conveyor automates is boring. Like really boring. Security questionnaires. Customer requests for things like your SOC 2. All of their follow-up questions. Answering tickets from your sales team. You know what's not boring? Alteryx using Conveyor to support over half a billion dollars in enterprise deals with a small 4 person team. All they did was set up an AI trust center and use Conveyor's AI agent to complete questionnaires. Learn more at conveyor.com.
Eurail stolen traveler data now up for sale
EU Parliament blocks AI features
Japan's Washington Hotel discloses ransomware hit
Get the full show notes here:
Huge thanks to our sponsor, Conveyor
Here's a fun question. Would you rather support more enterprise deals… or answer fewer security questionnaires? Moving upmarket usually means more scrutiny and more security questions. Instead of hiring more people or slowing sales, Alteryx used Conveyor's AI to automate customer security reviews like questionnaires, SOC 2 requests, and all the back-and-forth. They supported 200% growth and over half a billion dollars in pipeline with a 4 person team. If you're tired of choosing between growth and sanity, check out Conveyor at conveyor.com.
Link to episode page
This week's Department of Know is hosted by Sarah Lane with guests Jon Collins, Field CTO, GigaOm, and Adam Palmer, CISO, First Hawaiian Bank
Thanks to our show sponsor, Conveyor
Ever dream of giving customers instant answers to their security questions without ever filling out another questionnaire? Meet Conveyor's new Trust Center Agent. The Agent lives in your Conveyor Trust Center and answers every customer question, surfaces documents and even completes full questionnaires instantly so customers can finish their review and be on their way. Top tech companies like Atlassian, Zapier, and more are using Conveyor to automate away tedious work. Learn more at www. conveyor.com.
All links and the video of this episode can be found on CISO Series.com
One threat actor responsible for 83% of recent Ivanti RCE attacks
Google's AI search overviews manipulated by scammers
Microsoft warns of DNS-based ClickFix attack that uses Nslookup
Get the full show notes here: https://cisoseries.com/cybersecurity-news-ivanti-actor-identified-search-overviews-manipulated-clickfix-leverages-nslookup/
Huge thanks to our sponsor, Conveyor
I'll tell you two things Conveyor can't help you with. Conveyor will not make security questionnaires fun and it will not make your sales team stop asking you questions. But it did help Alteryx support half a billion dollars in enterprise deals with the same 4 person team. All they did was get an AI trust center and use Conveyor's AI agent to complete questionnaires.
If that's enough, you know where to go. www. conveyor.com.
Hackers abuse Gemini AI for all attack stages, says Google
Apple patches decade-old possibly exploited iOS zero-day
Acting CISA chief critiques potential DHS funding lapse
Get the show notes here: https://cisoseries.com/cybersecurity-news-hackers-abuse-gemini-apple-patches-ancient-bug-cisa-criticizes-shutdown/
Huge thanks to our episode sponsor, ThreatLocker
Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.
Crazy gang abuses employee monitoring tool
Nevada unveils new data classification
Georgia healthcare breach impacts more than 620,000
Get the show notes here: https://cisoseries.com/cybersecurity-news-google-gets-eu-wiz-approval-microsoft-secures-secure-boot-certificates-north-korean-hackers-target-crypto-exec/
Huge thanks to our episode sponsor, ThreatLocker
Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.
EU grants Google approval for Wiz
Microsoft rolls out Secure Boot certificates before expiration
North Korean hackers target crypto exec
Get the show notes here: https://cisoseries.com/cybersecurity-news-google-gets-eu-wiz-approval-microsoft-secures-secure-boot-certificates-north-korean-hackers-target-crypto-exec/
Huge thanks to our episode sponsor, ThreatLocker
Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.
UNC3886 targets Singapore telecom sector
VoidLink exhibits multi-cloud capabilities and AI code
135,000+ OpenClaw instances exposed to internet
Get the show notes here: https://cisoseries.com/cybersecurity-news-february-10-2026/
Huge thanks to our episode sponsor, ThreatLocker
Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.
Link to episode page
This week's Department of Know is hosted by Rich Stroffolino with guests Nick Ryan, former CISO, and Chris Ray, Field CTO, GigaOm
Thanks to our show sponsor, ThreatLocker
Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.
All links and the video of this episode can be found on CISO Series.com
OpenClaw turns to VirusTotal to boost security
CISA gives federal agencies one year to remove end-of-life devices
Payments platform BridgePay confirms ransomware attack
Get the show notes here: https://cisoseries.com/cybersecurity-news-openclaw-embraces-virustotal-cisa-eol-deadline-ransomware-hits-bridgepay/
Huge thanks to our episode sponsor, ThreatLocker
Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.
Substack admits data breach
Russian attacks target Winter Olympics
GitHub Codespaces enable RCE
Get the show notes here:
Huge thanks to our sponsor, Strike48
It's no secret that AI is only as good as the data available to it. Strike48 unifies agentic AI with unmatched log visibility while avoiding the typical hefty price tag. Build and deploy agents for phishing detection, alert triage, threat correlation and more. Queries existing logs where they currently live, so you can keep the technology you already have. Learn more at Strike48.com.
Ukraine tightens controls on Starlink terminals
VMware ESXi flaw now exploited
SolarWinds Web Help Desk bug under attack
Get the show notes here: https://cisoseries.com/cybersecurity-news-ukraine-tightens-controls-on-starlink-terminals-vmware-esxi-flaw-now-exploited-solarwinds-web-help-desk-bug-under-attack/
Huge thanks to our sponsor, Strike48
Strike48 is the Agentic Log Intelligence Platform that actually puts AI agents to work, maximizing log visibility without blowing your budget. Find threats your siloed tools miss. Get started today with pre-built AI agents and workflows that investigate, detect, and respond 24/7 or build your own at strike48.com/security.
React Native Metro bug impacts thousands of servers
Greece and Spain set to ban social media for kids
Moltbook shows the dangers of vibe coding
Get the show notes here: https://cisoseries.com/cybersecurity-news-metro-bug-more-social-bans-leaky-moltbook/
Huge thanks to our sponsor, Strike48
Security teams are stretched. Attack surfaces and threat volumes keep growing, meanwhile SOC budgets stay flat and glorified chatbots with hallucination problems aren't helping. Strike48 is different. Agents scale independently, running investigations across your logs while your team can concentrate on the highest priority tasks that require human judgment and decision making. Try it today at Strike48.com/security.
OpenClaw targets ClawHub users
Notepad++ update delivers malware
APT28 attackers abuse Microsoft Office zero-day
Get the show notes here: https://cisoseries.com/cybersecurity-news-openclaw-targets-clawhub-users-notepad-update-delivers-malware-apt28-attackers-abuse-microsoft-office-zero-day/
Huge thanks to our sponsor, Strike48
It's no secret that AI is only as good as the data available to it. Strike48 unifies agentic AI with unmatched log visibility while avoiding the typical hefty price tag. Build and deploy agents for phishing detection, alert triage, threat correlation and more. Queries existing logs where they currently live, so you can keep the technology you already have. Learn more at Strike48.com.
Link to episode page
This week's Department of Know is hosted by Rich Stroffolino with guests Steve Zalewski, co-host, Defense in Depth, and Nick Espinosa, host, The Deep Dive Radio Show
Thanks to our show sponsor, Devo/Strike 48
Strike48 is the Agentic Log Intelligence Platform that actually puts AI agents to work, maximizing log visibility without blowing your budget. Find threats your siloed tools miss. Get started today with pre-built AI agents and workflows that investigate, detect, and respond 24/7 or build your own at strike48.com/security.
All links and the video of this episode can be found on CISO Series.com
Coupang CEO questioned by police regarding data breach probe
Cyberattack on large Russian bread factory disrupts deliveries
Real estate agents in Australia use apps that leave lease documents at risk
Get the show notes here: https://cisoseries.com/cybersecurity-news-police-question-coupang-ceo-russia-bakery-cyberattack-australian-real-estate-scandal/
Huge thanks to our sponsor, Strike48
Strike48 is the Agentic Log Intelligence Platform that actually puts AI agents to work, maximizing log visibility without blowing your budget. Find threats your siloed tools miss. Get started today with pre-built AI agents and workflows that investigate, detect, and respond 24/7 or build your own at strike48.com/security.
France fines unemployment agency €5 million over data breach
Microsoft Teams addition will allow for suspicious calls to be reported
UK leaders warned about absorbing cyberattacks without offensive deterrence
Check out the show notes here:
Huge thanks to our episode sponsor, Conveyor
Want to hear a horror story? An infosec manager found out that their sales rep had filled in a customer security questionnaire themselves and sent it back to the customer without review. Which led to dozens of follow up questions. With Conveyor's Trust Center AI Agent, you can avoid all of that. The Agent lives in your Conveyor hosted Trust Center and answers every customer question, surfaces documents and even completes full questionnaires instantly so customers can finish their review and be on their way. Learn more at Conveyor.com Find the stories behind the headlines at https://cisoseries.com/cybersecurity-news-france-fines-unemployment-agency-teams-flags-calls-uk-pushes-deterrence/
Sandbox flaw exposes n8n instances
Fake Moltbot assistant drops malware
PeckBirdy takes flight for cross-platform attacks
Check out the show notes here: https://cisoseries.com/cybersecurity-news-sandbox-flaw-exposes-n8n-instances-fake-moltbot-assistant-drops-malware-peckbirdy-takes-flight-for-cross-platform-attacks/
Huge thanks to our episode sponsor, Conveyor
Another security questionnaire hits your desk. Ever wish it could magically disappear? You already have the answers that customers should self-serve, but they can't find the info in your Trust Center. That's why Conveyor built the first truly agentic Trust Center. An AI Agent lives inside it, answering customer questions, sharing documents, and even completing full questionnaires instantly. Customers get what they need fast. it's magical, touchless, and extremely accurate. Join teams at Atlassian, Zapier, and more at conveyor.com.
US cyber chief uploaded sensitive files into public ChatGPT
Vibe-coded 'Sicarii' ransomware can't be decrypted
WhatsApp account feature combats spyware
Check out the show notes here: https://cisoseries.com/cybersecurity-news-us-cyber-chief-uploaded-sensitive-files-into-public-chatgpt-vibe-coded-sicarii-ransomware-cant-be-decrypted-whatsapp-account-feature-combats-spyware/
Huge thanks to our episode sponsor, Conveyor
Ever dream of giving customers instant answers to their security questions without ever filling out another questionnaire? Meet Conveyor's new Trust Center Agent. The Agent lives in your Conveyor Trust Center and answers every customer question, surfaces documents and even completes full questionnaires instantly so customers can finish their review and be on their way. Top tech companies like Atlassian, Zapier, and more are using Conveyor to automate away tedious work. Learn more at conveyor.com.
Microsoft patches Office zero-day vulnerability
Indian users targeted by Blackmoon
Konni targets blockchain developers
Huge thanks to our episode sponsor, Conveyor
True story, an infosec team had to give customers MapQuest style directions just to navigate their Trust Center. Spoiler: it didn't reduce follow-up questions and created even more work for everyone involved. With Conveyor's new Trust Center AI Agent, customers get answers instantly and can even upload questionnaires for the Agent to complete. This way, customers find what they need and keep moving, without your team needing to intervene. Learn more at conveyor.com
Link to episode page
This week's Department of Know is hosted by Rich Stroffolino with guests Krista Arndt, associate CISO, St. Luke's University Health Network, and Jason Shockey, CISO, Cenlar FSB
Thanks to our show sponsor, Conveyor
Ever dream of giving customers instant answers to their security questions without ever filling out another questionnaire? Meet Conveyor's new Trust Center Agent. The Agent lives in your Conveyor Trust Center and answers every customer question, surfaces documents and even completes full questionnaires instantly so customers can finish their review and be on their way. Top tech companies like Atlassian, Zapier, and more are using Conveyor to automate away tedious work. Learn more at conveyor.com.
All links and the video of this episode can be found on CISO Series.com
Microsoft Outlook and boot problems
Sandworm likely behind cyberattack on Poland's power grid
Dresden museum network suffers cyberattack
Huge thanks to our episode sponsor, Conveyor
Ever wish your customers could magically get answers to their own security questionnaires before they ever hit your desk? We've heard this wish from hundreds of teams so Conveyor just launched a new Trust Center AI Agent. The Agent lives in your Conveyor hosted Trust Center and answers customer questions, surfaces documents and even completes full questionnaires instantly so customers can finish their review without your intervention. Join top tech companies using Conveyor today like Atlassian, Zapier and more. Check it out at Conveyor.com Find the stories behind the headlines at CISOseries.com.
Multi‑stage AiTM phishing and BEC campaign abusing SharePoint
SmarterMail auth bypass flaw now exploited despite patch
The problem of AI agents emerges at Davos
Huge thanks to our sponsor, Dropzone AI
All week we've talked about alert fatigue, MTTR, and the math that's breaking your SOC. Here's the proof. Dropzone AI is trusted by over 300 global enterprises and MSSPs. Named a Gartner Cool Vendor. Recognized in the Fortune Cyber 60. And backed by $37 million in Series B funding. But they're not stopping at a single agent. They're building toward fully agentic SOC teams where human engineers are augmented with specialized AI agents for threat hunting, detection engineering, and forensics. Your team deserves a backup that never sleeps. Book a demo at dropzone.ai.
Find the stories behind the headlines at CISOseries.com.
Tesla hacked at Pwn2Own Automotive
Everest sitting on Under Armour data?
PurpleBravo fake jobs campaign targets IP addresses
Huge thanks to our sponsor, Dropzone AI
Quick tip for SOC leaders measuring MTTR. Stop optimizing the human. Optimize what the human has to do. Dropzone AI handles the investigation legwork autonomously. Correlating alerts, gathering evidence, documenting findings. Your analysts only engage when it actually matters. The results are investigations that took hours and now take under 10 minutes with much better accuracy of up to 30%. And analysts who can finally focus on real threats. Proven at over 300 enterprises who have deployed Dropzone AI. See the data at dropzone.ai.
UK and China try to ease cyberattack tensions
Iranian state TV hijacked
VoidLink malware is AI-generated
Huge thanks to our sponsor, Dropzone AI
Remember yesterday's 2 AM alert? Here's how it ends differently with Dropzone AI. The alert fires. Within minutes, not hours, their AI SOC agents have already correlated logs across your entire security stack, built a complete evidence chain, and delivered a verdict. False positive, or escalate immediately. Your analyst wakes up to answers, not a queue. That's autonomous investigation at enterprise scale. Experience it for yourself at dropzone.ai.
Gemini prompt injection flaw exposes calendar info
Hacker admits to leaking stolen Supreme Court data
Researchers uncover PDFSIDER malware
Huge thanks to our sponsor, Dropzone AI
It's 2 AM. An alert fires. Possible data exfiltration. Your on-call analyst is three time zones away, half-asleep, context-switching between tools. By the time they piece together the evidence, forty-five minutes have passed. Was it a real threat or another false positive? The clock is ticking. Tomorrow, I'll tell you how 300 enterprises solved this exact problem. But if you can't wait, head over to dropzone.ai to learn more.
Link to episode page
This week's Department of Know is hosted by Sarah Lane with guests Dmitriy Sokolovskiy, senior vice president, information security, Semrush, and Nick Espinosa, host, The Deep Dive Radio Show
Thanks to our show sponsor, Dropzone AI
How many alerts did your SOC investigate last week? How many sat in the queue untouched? If you don't know those numbers, or you don't like them, Dropzone AI can help. They've helped enterprises like UiPath and Zapier handle ten times more alerts without adding headcount. Their AI SOC agents work around the clock, investigating every alert autonomously. Book a demo and they'll show you exactly how many hours you could recover.
Head over to dropzone.ai and request your demo today.
All links and the video of this episode can be found on CISO Series.com
Cybercom-NSA leadership nominee to assess dual-hat role
Two-thirds of third-party applications access sensitive data without justification, says report
GhostPoster browser extensions up to 840,000 installs
Huge thanks to our sponsor, Dropzone AI
Here's a security tip most vendors won't tell you. Your SOC analysts aren't slow. They're drowning. The average enterprise faces tens of thousands of alerts daily, and even your best analysts can only investigate so many before burnout wins. Dropzone AI changes that math. Their AI SOC agents autonomously investigate every alert, no playbooks or code required, in three to ten minutes flat. Stop triaging. Start defending. Book a demo at dropzone.ai.
Find the stories behind the headlines at CISOseries.com.
Jen Easterly to helm RSAC
Windows January update causes login problems
UK police blame Copilot for intelligence mistake
Thanks to our episode sponsor, ThreatLocker
Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.
Find the stories behind the headlines at CISOseries.com.
U.S. weighs private companies' cyberwarfare roles China: stop using US and Israeli cybersecurity software
DeadLock uses smart contracts to hide work
Thanks to our episode sponsor, ThreatLocker
Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.
GoBruteforcer targets blockchain projects
Android accessibility issue just a bug
Verizon to stop automatic phone unlocks
Thanks to our episode sponsor, ThreatLocker
Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.
Instagram denies breach post-data leak
Sweden detains consultant suspected of spying
n8n supply chain attack steals OAuth tokens
Thanks to our episode sponsor, ThreatLocker
Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.
Link to episode page
This week's Department of Know is hosted by Rich Stroffolino with guests Johna Till Johnson, CEO and Founder, Nemertes (check out the Nemertes substack) and Jason Shockey, CISO, Cenlar FSB. Jason will be speaking at MBA Servicing Solution26 in Texas in late February. Details here.
Thanks to our show sponsor, ThreatLocker
Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.
All links and the video of this episode can be found on CISO Series.com
BreachForums hacking forum database leaked exposing 324,000 accounts
Instagram breach exposes user data, creates password reset panic
UK government exempts self from flagship cyber law
Thanks to our episode sponsor, ThreatLocker
Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.
Find the stories behind the headlines at CISOseries.com.
Microsoft to enforce MFA for Microsoft 365 admin center sign-ins
Cisco patches ISE security vulnerability after PoC release
Illinois state agency breaches itself
Huge thanks to our sponsor, Hoxhunt
A small tip for CISOs: if you're unsure whether your security training is actually reducing phishing risk, check out what Qualcomm achieved with Hoxhunt. They took their 1,000 highest-risk users from consistent under-performers to outperforming the rest of the company, driving measurable human risk reduction and earning a CSO50 Award. See the Qualcomm case at hoxhunt.com/qualcomm
Find the stories behind the headlines at CISOseries.com.
ESA confirms new data heist
Ni8mare lets hackers hijack n8n servers
Taiwan blames 'cyber army' for intrusion attempts
Huge thanks to our sponsor, Hoxhunt
Traditional security training fails because it treats employees like the problem. Hoxhunt treats them like the solution. AI-powered simulations mirror actual attacks hitting your inbox. Instant coaching turns mistakes into learning moments. Gamified rewards make security engaging. The result? Real behavior change that measurably reduces your risk. Thousands of companies trust Hoxhunt to transform human vulnerability into human defense. Visit hoxhunt.com/cisoseries to learn more.
The UK hits reset on cybersecurity
No MFA, Know Problems
US may have coordinated cyberattacks with Maduro's arrest
Huge thanks to our sponsor, Hoxhunt
A small tip for CISOs: if you're unsure whether your security training is actually reducing phishing risk, check out what Qualcomm achieved with Hoxhunt. They took their 1,000 highest-risk users from consistent under-performers to outperforming the rest of the company, driving measurable human risk reduction and earning a CSO50 Award. See the Qualcomm case at hoxhunt.com/qualcomm
European hospitality blue screen of death
Brightspeed investigates breach
Convicted Bitfinex launderer freed
Huge thanks to our sponsor, Hoxhunt
Traditional security training fails because it treats employees like the problem. Hoxhunt treats them like the solution. AI-powered simulations mirror actual attacks hitting your inbox. Instant coaching turns mistakes into learning moments. Gamified rewards make security engaging. The result? Real behavior change that measurably reduces your risk. Thousands of companies trust Hoxhunt to transform human vulnerability into human defense. Visit hoxhunt.com/cisoseries to learn more.
Link to episode page
This week's Department of Know is hosted by Rich Stroffolino with guests Peter Clay, CISO, Aireon, and Chris Ray, Field CTO, GigaOm
Thanks to our show sponsor, HoxHunt
A small tip for CISOs: if you're unsure whether your security training is actually reducing phishing risk, check out what Qualcomm achieved with Hoxhunt. They took their 1,000 highest-risk users from consistent under-performers to outperforming the rest of the company, driving measurable human risk reduction and earning a CSO50 Award. See the Qualcomm case at hoxhunt.com/qualcomm
All links and the video of this episode can be found on CISO Series.com
Palo Alto Networks boss calls AI agents biggest insider threat
Hackers claim Resecurity hack, firm says it was a honeypot
Thousands of ColdFusion exploit attempts spotted during Christmas holiday
Huge thanks to our sponsor, Hoxhunt
A small tip for CISOs: if you're unsure whether your security training is actually reducing phishing risk, check out what Qualcomm achieved with Hoxhunt. They took their 1,000 highest-risk users from consistent under-performers to outperforming the rest of the company, driving measurable human risk reduction and earning a CSO50 Award. See the Qualcomm case at hoxhunt.com/qualcomm
Find the stories behind the headlines at CISOseries.com.
NYC mayoral inauguration bans Flipper Zero and Raspberry Pi devices
Crypto must now share account details with UK tax officials
Finland seizes suspected cable sabotage ship
Huge thanks to our episode sponsor, ThreatLocker
Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.
Find the stories behind the headlines at CISOseries.com.
Hackers drain millions from Unleash Protocol
DarkSpectre campaigns exposed
Shai-Hulud attack led Trust Wallet heist
Huge thanks to our episode sponsor, ThreatLocker
Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 atztw.com.
Silver Fox targets Indian users
Mustang Panda deploys ToneShell
Will prompt injection ever be 'solved'?
Huge thanks to our episode sponsor, ThreatLocker
Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 atztw.com.
Coupang recovers laptop allegedly thrown into river
Trust Wallet reports 2k+ wallets drained
Sax discloses 2024 data breach
Huge thanks to our episode sponsor, ThreatLocker
Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 atztw.com.
Link to episode page
To end off a tumultuous year, our final Department of Know episode of 2025 features a chat between host Rich Stroffolino and producer Steve Prentice. Join them as they chat about the biggest stories of 2025, the trends we are seeing, and what we can expect in the new year.
Thanks to our show sponsor, ThreatLocker
Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.
All links and the video of this episode can be found on CISO Series.com
Rainbow Six Siege suffers breach, gamers go shopping
Diesel generators and aircraft engines in high demand to power AI
LastPass 2022 breach reverberates through crypto world
Huge thanks to our episode sponsor, ThreatLocker
Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.
Find the stories behind the headlines at CISOseries.com.
Active exploitation of Fortinet VPN bypass utility observed
Google possibly allowing users to change default gmail address
June Aflac attack resulted in data theft
Thanks to our episode sponsor, ThreatLocker
Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com. Find the stories behind the headlines at CISOseries.com
Coordinated scams target MENA region
Pen Test Partners accused of 'blackmail'
Hackers steal record $2.7B in crypto in 2025
Thanks to our episode sponsor, ThreatLocker
Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.
ServiceNow to acquire cybersecurity startup Armis
MacSync Stealer adopts quieter installation
Nissan customer data stolen in Red Hat raid
Thanks to our episode sponsor, ThreatLocker
Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.
Spotify music library scraped
DDoS disrupts France's postal and banking services
Fake delivery websites hit holiday shoppers
Thanks to our episode sponsor, ThreatLocker
Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.
Link to episode page
This week's Department of Know is hosted by Rich Stroffolino with guests Jason Taule, CISO, Luminis Health, and Chris Ray, Field CTO, GigaOm
Thanks to our show sponsor, ThreatLocker
Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.
All links and the video of this episode can be found on CISO Series.com
President signs defense bill funding Cyber Command, Pentagon phone security
Iranian APT Infy resurfaces with new malware
Massive Android botnet Kimwolf launches DDoS attack
Thanks to our episode sponsor, ThreatLocker
Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com. Find the stories behind the headlines at CISOseries.com.
Recent Windows updates break RemoteApp connections
France arrests threat actors for installing malware on Italian ferry
Senate Intel chair urges safeguard against open-source software threats
Huge thanks to our sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. Security training fails when it's generic. Adaptive's platform personalizes training and runs deepfake simulations across email, SMS, voice, and video. And with Adaptive's AI Content Creator, you can drop in a breaking threat or compliance doc and instantly turn it into interactive, multilingual training – no designers, no delays. Learn more at adaptivesecurity.com.
Find the stories behind the headlines at CISOseries.com.
FTC orders crypto to pay
New exploit of React2Shell
Ukraine-based fraud ring taken down
Huge thanks to our sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. In deepfake scams, the tells aren't glitchy video anymore – it's behavior: "Do this right now," or "keep it secret." If you hear urgency and secrecy together, stop and verify through a second channel. Call a known number, start a chat thread, or ask something only the real person would know. Adaptive trains teams against exactly these tactics. Learn more at adaptivesecurity.com.
Rogue NuGet package steals data
Venezuela's PDVSA suffers attack
Patched Fortinet flaws exploited
Huge thanks to our sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. Picture a "new hire" who interviews well… except they're synthetic: AI video, AI voice, AI backstory. Once they're in, they go after payroll, internal docs, and access. That's the new reality: the attack surface is trust itself. Adaptive fights back with realistic deepfake simulations and training that actually sticks. Learn more at adaptivesecurity.com.
US turns to private firms in cyber offensive Microsoft updates cause queuing failures
Phishing campaign delivers Phantom stealer
Huge thanks to our sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. Attackers don't need malware anymore; they need trust. Tip: set a simple passphrase for high-risk actions, like wire requests or "urgent" account recovery – especially within finance teams and families. If the caller can't answer it, pause and verify. Adaptive runs deepfake and vishing simulations so employees practice this before it's real. Learn more at adaptivesecurity.com.
Link to episode page
This week's Department of Know is hosted by Rich Stroffolino with guests Andy Ellis, Principal, Duha, and Johna Till Johnson, CEO and Founder, Nemertes Research
Thanks to our show sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. AI is rewriting the cybersecurity rulebook, because attackers can now scale persuasion as easily as they scale code. The real target isn't just your systems anymore; it's human trust. If you aren't actively testing your organization against AI-driven phishing, vishing, and deepfakes, you're leaving a gap criminals will exploit. Adaptive runs realistic simulations and delivers tailored, engaging training so teams respond correctly when it counts. Learn more at adaptivesecurity.com. Learn more at adaptivesecurity.com.
All links and the video of this episode can be found on CISO Series.com
16TB MongoDB database exposes nearly 4.3 billion professional records
Apple posts updates after discovery of WebKit flaws
Coupang data breach traced to ex-employee
Huge thanks to our sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. Deepfakes aren't science fiction anymore; they're a daily threat. Quick tip: if your voicemail greeting is your real voice, switch it to the default robot voice. A few seconds of audio can be enough to clone you. Adaptive helps teams spot and stop these AI-powered social engineering attacks. Learn more at adaptivesecurity.com.
Find the stories behind the headlines at CISOseries.com.
'DroidLock' malware demands ransom Google fixes secret Chrome 0-day UK fines LastPass over 2022 breach Huge thanks to our episode sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. Security training fails when it's generic. Adaptive's platform personalizes training and runs deepfake simulations across email, SMS, voice, and video. And with Adaptive's AI Content Creator, you can drop in a breaking threat or compliance doc and instantly turn it into interactive, multilingual training – no designers, no delays. Learn more at adaptivesecurity.com.
CEO of retail giant Coupang resigns Pro-Russia hactivists target US infrastructure Israeli cybersecurity funding hits record Huge thanks to our episode sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. In deepfake scams, the tells aren't glitchy video anymore – it's behavior: "Do this right now," or "keep it secret." If you hear urgency and secrecy together, stop and verify through a second channel. Call a known number, start a chat thread, or ask something only the real person would know. Adaptive trains teams against exactly these tactics. adaptivesecurity.com.
Spain arrest over data records
Goodbye, dark Telegram
Scammers poison AI search results
Huge thanks to our episode sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. Picture a "new hire" who interviews well… except they're synthetic: AI video, AI voice, AI backstory. Once they're in, they go after payroll, internal docs, and access. That's the new reality: the attack surface is trust itself. Adaptive fights back with realistic deepfake simulations and training that actually sticks. adaptivesecurity.com.
Ransomware payments pass $4.5 billion
Cybercrime networks orchestrate real-world violence
Three arrested over possessing hacking tools
Huge thanks to our episode sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. Attackers don't need malware anymore; they need trust. Tip: set a simple passphrase for high-risk actions, like wire requests or "urgent" account recovery – especially within finance teams and families. If the caller can't answer it, pause and verify. Adaptive runs deepfake and vishing simulations so employees practice this before it's real. adaptivesecurity.com.
Link to episode page
This week's Department of Know is hosted by Sarah Lane with guests Jason Shockey, CISO, Cenlar FSB, and Mike Lockhart, CISO, Eagleview
Thanks to our show sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. AI is rewriting the cybersecurity rulebook, because attackers can now scale persuasion as easily as they scale code. The real target isn't just your systems anymore; it's human trust. If you aren't actively testing your organization against AI-driven phishing, vishing, and deepfakes, you're leaving a gap criminals will exploit. Adaptive runs realistic simulations and delivers tailored, engaging training so teams respond correctly when it counts. Learn more at adaptivesecurity.com. All links and the video of this episode can be found on CISO Series.com
New wave of VPN login attempts on Palo Alto portals
NATO holds its largest-ever cyberdefense exercise
Chinese hackers exploiting React2Shell bug
Huge thanks to our episode sponsor, Adaptive Security
This episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. Deepfakes aren't science fiction anymore; they're a daily threat. Quick tip: if your voicemail greeting is your real voice, switch it to the default robot voice. A few seconds of audio can be enough to clone you. Adaptive helps teams spot and stop these AI-powered social engineering attacks. Learn more at adaptivesecurity.com.
Find the stories behind the headlines at CISOseries.com.
Predator spyware spotted across several countries
Russia blocks FaceTime
Draft US cyber strategy set for January release
Huge thanks to our episode sponsor, Vanta
This message comes from Vanta. What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Get started at Vanta.com/CISO
Record-breaking DDoS attack
React bug puts servers at risk
RansomHouse attack
Huge thanks to our episode sponsor, Vanta
This message comes from Vanta. What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Get started at Vanta.com/CISO
Microsoft Defender outage disrupts threats Apple resists India's state-run app order MuddyWater strikes Israel with MuddyViper Huge thanks to our episode sponsor, Vanta
This message comes from Vanta. What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Get started at Vanta.com/CISO
India orders web safety app
Arrests over IP camera snooping
Albiriox shows up on dark web
Huge thanks to our episode sponsor, Vanta
This message comes from Vanta. What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Get started at Vanta.com/CISO
Link to episode page
This week's Department of Know is hosted by Rich Stroffolino with guests Mathew Biby, director, cybersecurity, TixTrack, and Derek Fisher, Director of the Cyber Defense and Information Assurance Program, Temple University
Thanks to our show sponsor, Vanta
This message comes from Vanta. What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Get started at Vanta.com/CISO
All links and the video of this episode can be found on CISO Series.com
Japanese brewer Asahi provides details regarding October ransomware attack
California law regulating web browsers might impact national data privacy
Microsoft to speed up Teams
Huge thanks to our episode sponsor, Vanta
This message comes from Vanta. What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Get started at Vanta.com/CISO
Find the stories behind the headlines at CISOseries.com.
Microsoft to block unauthorized scripts in Entra ID logins with 2026 CSP update
New legislation targets scammers that use AI to deceive
ASUS firmware patches critical AiCloud vulnerability
Huge thanks to our episode sponsor, KnowBe4
Cybersecurity isn't just a tech problem—it's a human one. That's why KnowBe4's Human Risk Management platform allows you to measure, quantify and actually reduce human risk across your organization. With AI-powered risk scoring, automated coaching and reporting, HRM+ helps you surface your highest risk users and reduce the risk of data breaches and cyberattacks proactively. Ready to move from awareness to action? Request a demo of HRM+ today at knowbe4.com. Find the stories behind the headlines at CISOseries.com.
AWS outage botnet smacks 28 countries LLMs help malware authors evade detection
Anthropic questioned over Claude espionage
Huge thanks to our episode sponsor, KnowBe4
Cybersecurity isn't just a tech problem—it's a human one. That's why KnowBe4's Human Risk Management platform allows you to measure, quantify and actually reduce human risk across your organization. With AI-powered risk scoring, automated coaching and reporting, HRM+ helps you surface your highest risk users and reduce the risk of data breaches and cyberattacks proactively. Ready to move from awareness to action? Request a demo of HRM+ today at knowbe4.com.
CISA warns of app break-ins
StealC V2 spread through blender files
Russia arrests cybersecurity entrepreneur for treason
Huge thanks to our episode sponsor, KnowBe4
Cybersecurity isn't just a tech problem—it's a human one. That's why KnowBe4's Human Risk Management platform allows you to measure, quantify and actually reduce human risk across your organization. With AI-powered risk scoring, automated coaching and reporting, HRM+ helps you surface your highest risk users and reduce the risk of data breaches and cyberattacks proactively. Ready to move from awareness to action? Request a demo of HRM+ today at knowbe4.com.
CISA orders feds to patch OIM
Delta Dental of Virginia incurs data breach
Systems down at postal operator in Ukraine
Huge thanks to our episode sponsor, KnowBe4
Cybersecurity isn't just a tech problem—it's a human one. That's why KnowBe4's Human Risk Management platform allows you to measure, quantify and actually reduce human risk across your organization. With AI-powered risk scoring, automated coaching and reporting, HRM+ helps you surface your highest risk users and reduce the risk of data breaches and cyberattacks proactively. Ready to move from awareness to action? Request a demo of HRM+ today at knowbe4.com.
Link to episode page
This week's Department of Know is hosted by Rich Stroffolino with guests Keith Townsend, Keith Townsend, host CTO Advisor Podcast, founder of The Advisor Bench, and creator of the Virtual CTO Advisor; and Howard Holton, CEO, GigaOm
Thanks to our show sponsor, Knowbe4
Cybersecurity isn't just a tech problem—it's a human one. That's why KnowBe4's Human Risk Management platform allows you to measure, quantify and actually reduce human risk across your organization. With AI-powered risk scoring, automated coaching and reporting, HRM+ helps you surface your highest risk users and reduce the risk of data breaches and cyberattacks proactively. Ready to move from awareness to action? Request a demo of HRM+ today at knowbe4.com.
All links and the video of this episode can be found on CISO Series.com
CrowdStrike catches insider feeding information to hackers
Spanish airline Iberia suffers breach and data leak
AI is too risky to insure, say insurers
Huge thanks to our episode sponsor, KnowBe4
Cybersecurity isn't just a tech problem—it's a human one. That's why KnowBe4's Human Risk Management platform allows you to measure, quantify and actually reduce human risk across your organization. With AI-powered risk scoring, automated coaching and reporting, HRM+ helps you surface your highest risk users and reduce the risk of data breaches and cyberattacks proactively. Ready to move from awareness to action? Request a demo of HRM+ today at knowbe4.com. Find the stories behind the headlines at CISOseries.com.
Sturnus Android Trojan captures encrypted chats and hijacks devices
Canadian regulators say schools share blame for PowerSchool hack
Bill reintroduced to bolster cybersecurity at Securities and Exchange Commission
Huge thanks to our episode sponsor, KnowBe4
Your email gateway isn't catching everything — and cybercriminals know it.
That's why there's KnowBe4's Cloud Email Security platform. It's not just another filter—it's a dynamic, AI-powered layer of defense that detects and stops advanced threats before they reach your users' inbox.
Request a demo of KnowBe4's Cloud Email Security at knowbe4.com or visit them this week at Microsoft Ignite booth #5523.
Find the stories behind the headlines at CISOseries.com.
Cloudflare blames database
Crypto heist takedown
WhatsApp flaw exposed billions
Huge thanks to our episode sponsor, KnowBe4
Your email gateway isn't catching everything — and cybercriminals know it.
That's why there's KnowBe4's Cloud Email Security platform. It's not just another filter—it's a dynamic, AI-powered layer of defense that detects and stops advanced threats before they reach your users' inbox.
Request a demo of KnowBe4's Cloud Email Security at knowbe4.com or visit them this week at Microsoft Ignite booth #5523.
FCC to torch rules from Salt Typhoon Group claims hits on Danish party websites MI5 warns Chinese spies are using LinkedIn Huge thanks to our episode sponsor, KnowBe4
Your email gateway isn't catching everything — and cybercriminals know it.
That's why there's KnowBe4's Cloud Email Security platform. It's not just another filter—it's a dynamic, AI-powered layer of defense that detects and stops advanced threats before they reach your users' inbox.
Request a demo of KnowBe4's Cloud Email Security at knowbe4.com or visit them this week at Microsoft Ignite booth #5523.
Azure hit by DDoS using 500K IPs Kenyan government websites back online EVALUSION emerges Huge thanks to our episode sponsor, KnowBe4
Your email gateway isn't catching everything — and cybercriminals know it.
That's why there's KnowBe4's Cloud Email Security platform. It's not just another filter—it's a dynamic, AI-powered layer of defense that detects and stops advanced threats before they reach your users' inbox.
Request a demo of KnowBe4's Cloud Email Security at knowbe4.com or visit them this week at Microsoft Ignite booth #5523.
Link to episode page
This week's Department of Know is hosted by Rich Stroffolino with guests Robb Dunewood, Host, Daily Tech News Show, and Howard Holton, CEO, GigaOm
Thanks to our show sponsor, KnowBe4
Your email gateway isn't catching everything — and cybercriminals know it. That's why there's KnowBe4's Cloud Email Security platform. It's not just another filter—it's a dynamic, AI-powered layer of defense that detects and stops advanced threats before they reach your users' inbox. Request a demo of KnowBe4's Cloud Email Security at knowbe4.com or visit them this week at Microsoft Ignite booth #5523.
All links and the video of this episode can be found on CISO Series.com
Microsoft warns of potential Windows 10 update failure
China-backed hackers launch first large-scale autonomous AI cyberattack
Feds fumbled Cisco patches requirements, says CISA
Huge thanks to our episode sponsor, KnowBe4
Your email gateway isn't catching everything — and cybercriminals know it.
That's why there's KnowBe4's Cloud Email Security platform. It's not just another filter—it's a dynamic, AI-powered layer of defense that detects and stops advanced threats before they reach your users' inbox.
Request a demo of KnowBe4's Cloud Email Security at knowbe4.com or visit them this week at Microsoft Ignite booth #5523.
Find the stories behind the headlines at CISOseries.com.
Two key cyber laws are back as president signs bill to end shutdown Microsoft's screen capture prevention for Teams users is finally rolling out FBI calls Akira top five ransomware variant out of 130 targeting U.S. businesses
Huge thanks to our sponsor, Vanta
What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" ....or the really scary one: "how do I get out from under these old tools and manual processes? Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Vanta also fits right into your workflows, using AI to streamline evidence collection, flag risks, and keep your program audit-ready—ALL…THE…TIME. With Vanta, you get everything you need to move faster, scale confidently—and get back to sleep. Get started at vanta.com/headlines Find the stories behind the headlines at CISOseries.com.
Mobile internet blackout for Russian travelers Windows 11 supports 3rd-party passkey apps Synology patches BeeStation flaw Huge thanks to our sponsor, Vanta
What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" ....or the really scary one: "how do I get out from under these old tools and manual processes? Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Vanta also fits right into your workflows, using AI to streamline evidence collection, flag risks, and keep your program audit-ready—ALL…THE…TIME. With Vanta, you get everything you need to move faster, scale confidently—and get back to sleep. Get started at vanta.com/headlines
Google's Find Hub turns into remote-wipe weapon
Qilin ransomware activity surges
GootLoader is back
Huge thanks to our sponsor, Vanta
What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" ....or the really scary one: "how do I get out from under these old tools and manual processes? Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Vanta also fits right into your workflows, using AI to streamline evidence collection, flag risks, and keep your program audit-ready—ALL…THE…TIME. With Vanta, you get everything you need to move faster, scale confidently—and get back to sleep. Get started at vanta.com/headlines
CISA reauthorization
Denmark and Norway investigating electric bus "kill switches"
European Commission looking to simplify privacy laws for AI
Huge thanks to our sponsor, Vanta
What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" ....or the really scary one: "how do I get out from under these old tools and manual processes? Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Vanta also fits right into your workflows, using AI to streamline evidence collection, flag risks, and keep your program audit-ready—ALL…THE…TIME. With Vanta, you get everything you need to move faster, scale confidently—and get back to sleep. Get started at vanta.com/headlines
Link to episode page
This week's Department of Know is hosted by Rich Stroffolino with guests Jacob Coombs, CISO, Tandem Diabetes Care, and Ross Young, Co-host, CISO Tradecraft
Thanks to our show sponsor, Vanta
What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" ….or the really scary one: "how do I get out from under these old tools and manual processes? Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Vanta also fits right into your workflows, using AI to streamline evidence collection, flag risks, and keep your program audit-ready—ALL…THE…TIME. With Vanta, you get everything you need to move faster, scale confidently—and get back to sleep. Get started at vanta.com/headlines
All links and the video of this episode can be found on CISO Series.com
runC flaws could allow hackers to escape Docker containers
Lost iPhone scam warning
Landfall Android spyware targets Samsung Galaxy phones
Huge thanks to our sponsor, Vanta
What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" ....or the really scary one: "how do I get out from under these old tools and manual processes? Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Vanta also fits right into your workflows, using AI to streamline evidence collection, flag risks, and keep your program audit-ready—ALL…THE…TIME. With Vanta, you get everything you need to move faster, scale confidently—and get back to sleep. Get started at vanta.com/headlines Find the stories behind the headlines at CISOseries.com.
Hackers use Windows Hyper-V to evade EDR detection
Critical Cisco UCCX flaw lets attackers run commands as root
The Louvre's video security password was reportedly Louvre
Huge thanks to our sponsor, ThreatLocker
Imagine having the power to decide exactly what runs in your IT environment — and blocking everything else by default. That's what ThreatLocker delivers. As a zero-trust endpoint protection platform, ThreatLocker fills the gaps traditional solutions leave behind, giving your business stronger security and control. Don't just react to threats — stop them with ThreatLocker.
Find the stories behind the headlines at CISOseries.com.
Google uncovers PROMPTFLUX malware CISA warns of CentOS Web Panel bug Threat group targets academics Huge thanks to our sponsor, ThreatLocker
Cybercriminals don't knock — they sneak in through the cracks other tools miss. That's why organizations are turning to ThreatLocker. As a zero-trust endpoint protection platform, ThreatLocker puts you back in control, blocking what doesn't belong and stopping attacks before they spread. Zero Trust security starts here — with ThreatLocker
Scattered Spider, LAPSUS$, and ShinyHunters join forces Nikkei reports data breach impacting 17,000 people React Native NPM flaw leads to attacks Huge thanks to our sponsor, ThreatLocker
Imagine having the power to decide exactly what runs in your IT environment — and blocking everything else by default. That's what ThreatLocker delivers. As a zero-trust endpoint protection platform, ThreatLocker fills the gaps traditional solutions leave behind, giving your business stronger security and control. Don't just react to threats — stop them with ThreatLocker.
"SleepyDuck" uses Ethereum to keep command server alive SesameOp abuses OpenAI Assistants API Organized crime cybercrooks steal cargo Huge thanks to our sponsor, ThreatLocker
Cybercriminals don't knock — they sneak in through the cracks other tools miss. That's why organizations are turning to ThreatLocker. As a zero-trust endpoint protection platform, ThreatLocker puts you back in control, blocking what doesn't belong and stopping attacks before they spread. Zero Trust security starts here — with ThreatLocker
Link to episode page
This week's Department of Know is hosted by Rich Stroffolino with guests Davi Ottenheimer, vp, digital trust and ethics, Inrupt, and Rob Teel, Field CTO, GigaOm
Thanks to our show sponsor, ThreatLocker
Imagine having the power to decide exactly what runs in your IT environment — and blocking everything else by default. That's what ThreatLocker delivers. As a zero-trust endpoint protection platform, ThreatLocker fills the gaps traditional solutions leave behind, giving your business stronger security and control. Don't just react to threats — stop them with ThreatLocker.
All links and the video of this episode can be found on CISO Series.com
Australia warns of BADCANDY attacks exploiting Cisco IOS XE
Chinese hackers exploiting Cisco ASA firewalls used by governments worldwide
OpenAI's Aardvark GPT-5 agent finds and fixes code flaws automatically
Huge thanks to our sponsor, ThreatLocker
Imagine having the power to decide exactly what runs in your IT environment — and blocking everything else by default. That's what ThreatLocker delivers. As a zero-trust endpoint protection platform, ThreatLocker fills the gaps traditional solutions leave behind, giving your business stronger security and control. Don't just react to threats — stop them with ThreatLocker.
Find the stories behind the headlines at CISOseries.com.
LinkedIn users have until Monday to opt out of its AI training program New names surface for NSA leadership Open-source security group pulls out of U.S. grant, citing DEI restrictions
Huge thanks to our sponsor, Conveyor
Security reviews don't have to feel like a hurricane. Most teams are buried in back-and-forth emails and never-ending customer requests for documentation or answers. But Conveyor takes all that chaos and turns it into calm.
AI fills in the questionnaires, your trust center is always ready, and sales cycles move without stalls.
Breathe easier—check out Conveyor at www.conveyor.com.
Find the stories behind the headlines at CISOseries.com.
LG Uplus confirms cybersecurity incident 10 million+ impacted by Conduent breach
Russian hackers exploit tools against Ukrainian targets Huge thanks to our sponsor, Conveyor
Security reviews don't have to feel like a hurricane. Most teams are buried in back-and-forth emails and never-ending customer requests for documentation or answers. But Conveyor takes all that chaos and turns it into calm.
AI fills in the questionnaires, your trust center is always ready, and sales cycles move without stalls.
Breathe easier—check out Conveyor at www.conveyor.com.
New Android malware types like a human Sanctions weaken nation-state cyber ecosystems Side-channel attack extracts Intel, AMD secrets Huge thanks to our sponsor, Conveyor
Have you been personally victimized by a questionnaire this week? The queue never ends. But Conveyor can change that story.
With AI that answers questionnaires of any format, and a trust center that handles document sharing, security reviews get done without the stress.
Feel calm in the chaos with Conveyor. Learn more at www.conveyor.com.
Atlas browser hijacked
Bye, bye Twitter birdie
Dante spyware surfaces
Huge thanks to our sponsor, Conveyor
Security reviews don't have to feel like a hurricane. Most teams are buried in back-and-forth emails and never-ending customer requests for documentation or answers. But Conveyor takes all that chaos and turns it into calm.
AI fills in the questionnaires, your trust center is always ready, and sales cycles move without stalls.
Breathe easier—check out Conveyor at www.conveyor.com.
Link to episode page
This week's edition of The Department of Know is hosted by Rich Stroffolino with guests Bil Harmer, operating partner and CISO, Craft Ventures, and Sasha Pereira, CISO, WASH
Thanks to our show sponsor, ThreatLocker
If security questionnaires make you feel like you're drowning in chaos, you're not alone. Endless spreadsheets, portals, and questions—always when you least expect them. Conveyor brings calm to the storm. With AI that auto-fills questionnaires and a trust center that shares all your docs in one place, you'll feel peace where there used to be panic. Find your security review zen at www.conveyor.com.
All links and the video of this episode can be found on CISO Series.com
Microsoft WSUS vulnerability could allow for remote code execution
Fake LastPass death claims used to breach password vaults
New CoPhish attack steals OAuth tokens via Copilot Studio agents
Huge thanks to our sponsor, Conveyor
If security questionnaires make you feel like you're drowning in chaos, you're not alone.
Endless spreadsheets, portals, and questions—always when you least expect them.
Conveyor brings calm to the storm. With AI that auto-fills questionnaires and a trust center that shares all your docs in one place, you'll feel peace where there used to be panic.
Find your security review zen at www.conveyor.com.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week's Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guests David Cross, CISO, Atlassian, and davidcrosstravels.com, and Montez Fitzpatrick, CISO, Navvis
Thanks to our show sponsor, ThreatLocker
Imagine having the power to decide exactly what runs in your IT environment — and blocking everything else by default. That's what ThreatLocker delivers. As a zero-trust endpoint protection platform, ThreatLocker fills the gaps traditional solutions leave behind, giving your business stronger security and control. Don't just react to threats — stop them with ThreatLocker.
All links and the video of this episode can be found on CISO Series.com
Jingle Thief hackers steal millions in gift cards by exploiting cloud infrastructure Lazarus hackers targeted European defense companies Deep Tech work culture pushes for 72 hour workweeks
Huge thanks to our sponsor, ThreatLocker
Imagine having the power to decide exactly what runs in your IT environment — and blocking everything else by default. That's what ThreatLocker delivers. As a zero-trust endpoint protection platform, ThreatLocker fills the gaps traditional solutions leave behind, giving your business stronger security and control. Don't just react to threats — stop them with ThreatLocker.
Find the stories behind the headlines at CISOseries.com.
TP-Link urges updates for Omada gateways MuddyWater targets organizations in espionage campaign "SessionReaper" flaw exploited in Adobe Commerce Huge thanks to our sponsor, ThreatLocker
Cybercriminals don't knock — they sneak in through the cracks other tools miss. That's why organizations are turning to ThreatLocker. As a zero-trust endpoint protection platform, ThreatLocker puts you back in control, blocking what doesn't belong and stopping attacks before they spread. Zero Trust security starts here — with ThreatLocker
Russian state hackers replace burned malware with new tools Recent Windows updates cause login issues on some PCs Sophisticated campaign targets servers of high-profile organizations
Huge thanks to our sponsor, ThreatLocker
Imagine having the power to decide exactly what runs in your IT environment — and blocking everything else by default. That's what ThreatLocker delivers. As a zero-trust endpoint protection platform, ThreatLocker fills the gaps traditional solutions leave behind, giving your business stronger security and control. Don't just react to threats — stop them with ThreatLocker.
DNS failure leads to AWS outage
China accuses NSA of hacking national time center
Chrome store flooded with high-risk WhatsApp automation
Huge thanks to our sponsor, ThreatLocker
Cybercriminals don't knock — they sneak in through the cracks other tools miss. That's why organizations are turning to ThreatLocker. As a zero-trust endpoint protection platform, ThreatLocker puts you back in control, blocking what doesn't belong and stopping attacks before they spread. Zero Trust security starts here — with ThreatLocker
Europol dismantles 49 million fake account SIM farm
Envoy Air confirms Oracle E-Business Suite compromise
Cybercrime group Everest claims Collins Aerospace hack
Huge thanks to our sponsor, ThreatLocker
Imagine having the power to decide exactly what runs in your IT environment — and blocking everything else by default. That's what ThreatLocker delivers. As a zero-trust endpoint protection platform, ThreatLocker fills the gaps traditional solutions leave behind, giving your business stronger security and control. Don't just react to threats — stop them with ThreatLocker.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week's Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guests Tom Hollingsworth, networking technology advisor, The Futurum Group, as well as on BlueSky, and Brett Conlon, CISO, American Century Investments
Thanks to our show sponsor, Vanta
What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" ….or the really scary one: "how do I get out from under these old tools and manual processes? Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Vanta also fits right into your workflows, using AI to streamline evidence collection, flag risks, and keep your program audit-ready—ALL…THE…TIME. With Vanta, you get everything you need to move faster, scale confidently—and get back to sleep. Get started at vanta.com/headlines
All links and the video of this episode can be found on CISO Series.com
Sotheby's suffers cyberattack
Hackers exploit Cisco SNMP flaw in "Zero Disco' attacks
Microsoft revokes more than 200 certificates to disrupt ransomware campaign
Huge thanks to our sponsor, Vanta
What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" ....or the really scary one: "how do I get out from under these old tools and manual processes? Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Vanta also fits right into your workflows, using AI to streamline evidence collection, flag risks, and keep your program audit-ready—ALL…THE…TIME. With Vanta, you get everything you need to move faster, scale confidently—and get back to sleep. Get started at vanta.com/headlines Find the stories behind the headlines at CISOseries.com.
MANGO discloses data breach Threat group 'Jewelbug' infiltrates Russian IT network F5 discloses breach tied to nation-state threat actor Huge thanks to our sponsor, Vanta
What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" ....or the really scary one: "how do I get out from under these old tools and manual processes? Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Vanta also fits right into your workflows, using AI to streamline evidence collection, flag risks, and keep your program audit-ready—ALL…THE…TIME. With Vanta, you get everything you need to move faster, scale confidently—and get back to sleep. Get started at vanta.com/headlines
Legacy Windows protocols still expose theft Fortra admits exploitation of GoAnywhere defect Taiwan claims surge in Chinese attack efforts Huge thanks to our sponsor, Vanta
What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" ....or the really scary one: "how do I get out from under these old tools and manual processes? Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Vanta also fits right into your workflows, using AI to streamline evidence collection, flag risks, and keep your program audit-ready—ALL…THE…TIME. With Vanta, you get everything you need to move faster, scale confidently—and get back to sleep. Get started at vanta.com/headlines
Millions of records exposed in Salesforce data leak
SimonMed breach grows from hundreds to over a million
Dutch government freezes Chinese-owned chipmaker
Huge thanks to our sponsor, Vanta
What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" ....or the really scary one: "how do I get out from under these old tools and manual processes? Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Vanta also fits right into your workflows, using AI to streamline evidence collection, flag risks, and keep your program audit-ready—ALL…THE…TIME. With Vanta, you get everything you need to move faster, scale confidently—and get back to sleep. Get started at vanta.com/headlines
Huge thanks to our sponsor, Vanta
What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" ....or the really scary one: "how do I get out from under these old tools and manual processes? Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Vanta also fits right into your workflows, using AI to streamline evidence collection, flag risks, and keep your program audit-ready—ALL…THE…TIME. With Vanta, you get everything you need to move faster, scale confidently—and get back to sleep. Get started at vanta.com/headlines Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines - Week in Review is hosted by Rich Stroffolino with guests Mike Lockhart, CISO Eagleview, and Dustin Sachs, chief technologist at CyberRisk collaborative, and author of Behavioral Insights in Cybersecurity
Thanks to our show sponsor, ThreatLocker
Cybercriminals don’t knock — they sneak in through the cracks other tools miss. That’s why organizations are turning to ThreatLocker. As a zero-trust endpoint protection platform, ThreatLocker puts you back in control, blocking what doesn’t belong and stopping attacks before they spread. Zero Trust security starts here — with ThreatLocker”
All links and the video of this episode can be found on CISO Series.com
Azure outage blocks access to Microsoft 365 services and admin portals
Major U.S. law firm suffers cyberattack
Hacktivists aiming for critical infrastructure get pwned
Huge thanks to our sponsor, ThreatLocker
Imagine having the power to decide exactly what runs in your IT environment — and blocking everything else by default. That’s what ThreatLocker delivers. As a zero-trust endpoint protection platform, ThreatLocker fills the gaps traditional solutions leave behind, giving your business stronger security and control. Don’t just react to threats — stop them with ThreatLocker. Learn more at ThreatLocker.com.
Find the stories behind the headlines at CISOseries.com.
Google DeepMind’s AI agent finds and fixes vulnerabilities California law lets consumers universally opt out of data sharing China-Nexus actors weaponize 'Nezha' open source tool Huge thanks to our sponsor, ThreatLocker
Cybercriminals don’t knock — they sneak in through the cracks other tools miss. That’s why organizations are turning to ThreatLocker. As a zero-trust endpoint protection platform, ThreatLocker puts you back in control, blocking what doesn’t belong and stopping attacks before they spread. Zero Trust security starts here — with ThreatLocker. Learn more at ThreatLocker.com.
North Korean hackers steal more than $2B in crypto
Group suspected of sending stolen UK phones to China
Avnet confirms breach, says stolen data unreadable
Huge thanks to our sponsor, ThreatLocker
Imagine having the power to decide exactly what runs in your IT environment — and blocking everything else by default. That’s what ThreatLocker delivers. As a zero-trust endpoint protection platform, ThreatLocker fills the gaps traditional solutions leave behind, giving your business stronger security and control. Don’t just react to threats — stop them with ThreatLocker. Learn more at ThreatLocker.com.
Unity vulnerability puts popular games at risk
Oracle zero-day exploit patched
Third-party breach claims Discord user info
Huge thanks to our sponsor, ThreatLocker
Cybercriminals don’t knock — they sneak in through the cracks other tools miss. That’s why organizations are turning to ThreatLocker. As a zero-trust endpoint protection platform, ThreatLocker puts you back in control, blocking what doesn’t belong and stopping attacks before they spread. Zero Trust security starts here — with ThreatLocker. Learn more at ThreatLocker.com.
ParkMobile 2021 data breach class action suit concludes
UK government study suggests secondary schools larger target than businesses
Zimbra Collaboration Suite flaw used in calendar attacks
Huge thanks to our sponsor, ThreatLocker
Imagine having the power to decide exactly what runs in your IT environment — and blocking everything else by default. That’s what ThreatLocker delivers. As a zero-trust endpoint protection platform, ThreatLocker fills the gaps traditional solutions leave behind, giving your business stronger security and control. Don’t just react to threats — stop them with ThreatLocker. Learn more at ThreatLocker.com.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Nick Espinosa, nationally syndicated host of The Deep Dive Radio Show, with guest Steve Zalewski, co-host, Defense in Depth
Thanks to our show sponsor, Nudge Security
Here’s the thing: your employees are signing up for new apps, sharing data, and connecting tools together, often without anyone knowing. And, AI adoption is accelerating this trend. What if you could continuously discover when people start using new apps or sharing data, then prompt them with security guidance right when and where they are working? At Nudge Security, we call that securing the Workforce Edge. Instead of trying to control everything (which, let’s face it, is impossible), we give IT and security teams the visibility they need and automation to guide employees toward secure behaviors. The result? Your workforce stays productive, your data stays secure, and you can finally get some sleep at night. Learn more at nudgesecurity.com/workforceedge
All links and the video of this episode can be found on CISO Series.com
Government shutdown furloughs most CISA staff
Microsoft Defender bug triggers erroneous BIOS update alerts
Motility RV software company suffers cyberattack
Huge thanks to our sponsor, Nudge Security
Here's the thing: your employees are signing up for new apps, sharing data, and connecting tools together, often without anyone knowing. And, AI adoption is accelerating this trend.
What if you could continuously discover when people start using new apps or sharing data, then prompt them with security guidance right when and where they are working?
At Nudge Security, we call that securing the Workforce Edge. Instead of trying to control everything (which, let's face it, is impossible), we give IT and security teams the visibility they need and automation to guide employees toward secure behaviors.
The result? Your workforce stays productive, your data stays secure, and you can finally get some sleep at night. Learn more at nudgesecurity.com/workforceedge
Find the stories behind the headlines at CISOseries.com.
Breach notification letters set to flood North America's mailboxes New bug in classic Outlook only fixed via Microsoft support Air Force admits SharePoint privacy issue over breach Huge thanks to our sponsor, Nudge Security
AI notetakers like Otter AI spread fast. In fact, one Nudge Security customer discovered 800 new accounts created in only 90 days. Viral AI notetakers introduce a slew of data privacy risks by gaining access to calendars and adding themselves to every meeting.
Nudge Security can help. Within minutes of starting a free trial, you’ll see every AI app, account, and integration, even those created in the past. And, smart automation helps you clean up unwanted accounts and guide users towards approved alternatives.
See how you can regain control today at nudgesecurity.com/stopotter
China-Linked Group Hits Governments With Stealth Malware Chinese hackers exploit VMware zero-day since October 2024 Apple's iOS fixes a bevy of glitches
Huge thanks to our sponsor, Nudge Security
The SaaS supply chain is a hot mesh. As your workforce introduces new SaaS apps and integrations, hidden pathways are created that attackers can exploit to gain access to core business systems. That’s exactly what happened in the Drift breach, and it will happen again.
But, all is not lost. Nudge Security gives you the visibility and control you need to stop these attacks. Within minutes of starting a free trial, you'll discover every SaaS app and integration in your environment, map your SaaS supply chain, and identify risky OAuth grants that could be exploited.
The best part? Nudge Security alerts you of breaches impacting your 3rd and 4th party SaaS providers. That’s right, even 4th party! So, you can take action quickly to limit the ripple effects. Learn how Nudge can help you secure your entire SaaS ecosystem at nudgesecurity.com/supplychain
AI-generated code used in phishing campaign blocked by Microsoft WestJet notifies American consumers of data breach Ukrainian cops spoofed in fileless phishing attacks on Kyiv Huge thanks to our sponsor, Nudge Security
AI tools have spread to every corner of your tech stack, which is great for innovation, but not so great for data governance.
That's where Nudge Security comes in. Nudge discovers shadow AI across your org - chatbots, MCP integrations, AI in the supply chain, and more. And, Nudge delivers guardrails to employees to help you stop data leakage before it even starts.
The best part? You’ll have a full inventory of AI assets on Day One of your free trial, even those introduced before you started using Nudge. No time machine required.
Gain visibility and control of AI use. Get started at nudgesecurity.com/genai
Dutch teenagers arrested for attempted espionage for Russia
DoD announces replacement for risk management framework
Fake Microsoft Teams installers deliver Oyster malware
Huge thanks to our sponsor, Nudge Security
Here's the thing: your employees are signing up for new apps, sharing data, and connecting tools together, often without anyone knowing. And, AI adoption is accelerating this trend.
What if you could continuously discover when people start using new apps or sharing data, then prompt them with security guidance right when and where they are working?
At Nudge Security, we call that securing the Workforce Edge. Instead of trying to control everything (which, let's face it, is impossible), we give IT and security teams the visibility they need and automation to guide employees toward secure behaviors.
The result? Your workforce stays productive, your data stays secure, and you can finally get some sleep at night. Learn more at nudgesecurity.com/workforceedge
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by David Spark with guests Brett Conlon, CISO, American Century Investments, and TC Niedzialkowski, Head of Security & IT, OpenDoor
Thanks to our show sponsor, Conveyor
Still stuck in security review chaos week after week? You’re not the only one. But with Conveyor, teams finally get to a place of Questionnaire Zen. Our AI auto-fills answers across any format of questionnaire, even portals, and an enterprise-ready trust center keeps documents and policies ready for instant sharing. No more manual copy-pasting. No more last-minute scrambles. Just calm, clear security reviews that keep deals moving. Find your Zen with Conveyor at www.conveyor.com.
All links and the video of this episode can be found on CISO Series.com
Microsoft to offer free Windows 10 security updates in Europe
Teenage Vegas casino hacker released to parents
Boyd Gaming hacked, employee data stolen
Huge thanks to our sponsor, Conveyor
Logging into yet another security questionnaire portal on a Friday at 3pm? Yeah, that’s chaos.
Conveyor AI is your fast path to calm. It finds every question no matter the format and fills in the answers—across portals, spreadsheets, PDFs, you name it.
So instead of grinding through copy-paste, you get a first pass of accurate answers in minutes.
Find your Friday Zen at www.conveyor.com.
Find the stories behind the headlines at CISOseries.com.
Person arrested in connection with airport attack
Record-breaking DDoS attack hits new highs
China-linked attackers use ‘BRICKSTORM’ backdoor to steal IP
Huge thanks to our sponsor, Conveyor
Security reviews don’t have to feel like a hurricane. Most teams are buried in back-and-forth emails and never-ending customer requests for documentation or answers. But Conveyor takes all that chaos and turns it into calm.
AI fills in the questionnaires, your trust center is always ready, and sales cycles move without stalls.
Breathe easier—check out Conveyor at www.conveyor.com.
European airports restoring services after system breach CISA deals with GeoServer exploit
App for outing Charlie Kirk’s critics leaks personal data
Huge thanks to our sponsor, Conveyor
Have you been personally victimized by a questionnaire this week? The queue never ends. But Conveyor can change that story.
With AI that answers questionnaires of any format, and a trust center that handles document sharing, security reviews get done without the stress.
Feel calm in the chaos with Conveyor. Learn more at www.conveyor.com.
EDR-Freeze tool suspends security software
DeepMind updates Frontier Safety Framework
Major vendors withdraw from MITRE EDR Evaluations
Huge thanks to our sponsor, Conveyor
Security reviews don’t have to feel like a hurricane. Most teams are buried in back-and-forth emails and never-ending customer requests for documentation or answers. But Conveyor takes all that chaos and turns it into calm.
AI fills in the questionnaires, your trust center is always ready, and sales cycles move without stalls.
Breathe easier—check out Conveyor at www.conveyor.com.
European airport disruption due to cyberattack check-in and baggage software
SMS scammers now using mobile fake cell towers
GPT-4-powered MalTerminal malware creates ransomware and Reverse Shell
Huge thanks to our sponsor, Conveyor
If security questionnaires make you feel like you’re drowning in chaos, you’re not alone.
Endless spreadsheets, portals, and questions—always when you least expect them.
Conveyor brings calm to the storm. With AI that auto-fills questionnaires and a trust center that shares all your docs in one place, you’ll feel peace where there used to be panic.
Find your security review zen at www.conveyor.com.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guests Jack Kufahl, CISO, Michigan Medicine, and Nick Espinosa, host, The Deep Dive Radio Show
Thanks to our show sponsor, Drata
Leading security teams trust SafeBase by Drata to turn trust into a growth engine. Our enterprise-grade Trust Center puts your security posture in one secure, customer-facing portal, giving buyers instant visibility into your company’s continuous controls, certifications, and policies. With AI-powered Questionnaire Assistance, blast through inbound security questionnaires in minutes instead of days, automate cross functional workflows, and eliminate friction. That means less manual work, and faster deal cycles. Win with Trust. Learn more at SafeBase.io.
All links and the video of this episode can be found on CISO Series.com
Google patches sixth Chrome zero-day exploited in attacks this year
Microsoft to force install the Microsoft 365 Copilot app in October
Two more Scattered Spider teen suspects arrested
Huge thanks to our sponsor, Drata
Leading security teams trust SafeBase by Drata to turn trust into a growth engine. Our enterprise-grade Trust Center puts your security posture in one secure, customer-facing portal, giving buyers instant visibility into your company’s continuous controls, certifications, and policies.
With AI-powered Questionnaire Assistance, blast through inbound security questionnaires in minutes instead of days, automate cross functional workflows, and eliminate friction.
That means less manual work, and faster deal cycles.
Win with Trust. Learn more at SafeBase.io.
Find the stories behind the headlines at CISOseries.com.
Insight Partners warns thousands after ransomware breach Scattered Spider gang feigns retirement, breaks into bank instead Consumer Reports calls Microsoft 'hypocritical' Huge thanks to our sponsor, Drata
Leading security teams trust SafeBase by Drata to turn trust into a growth engine. Our enterprise-grade Trust Center puts your security posture in one secure, customer-facing portal, giving buyers instant visibility into your company’s continuous controls, certifications, and policies.
With AI-powered Questionnaire Assistance, blast through inbound security questionnaires in minutes instead of days, automate cross functional workflows, and eliminate friction.
That means less manual work, and faster deal cycles.
Win with Trust. Learn more at SafeBase.io.
House lawmakers move to extend two key cyber programs Apple 0-day likely used in spy attacks affected older devices Reuters crafts phishing scam with AI chatbot help Huge thanks to our sponsor, Drata
Leading security teams trust SafeBase by Drata to turn trust into a growth engine. Our enterprise-grade Trust Center puts your security posture in one secure, customer-facing portal, giving buyers instant visibility into your company’s continuous controls, certifications, and policies.
With AI-powered Questionnaire Assistance, blast through inbound security questionnaires in minutes instead of days, automate cross functional workflows, and eliminate friction.
That means less manual work, and faster deal cycles.
Win with Trust. Learn more at SafeBase.io.
Android moving to “risk-based” security updates
CISA accused of Cyber Incentive mismanagement
How security practitioners use LLMs
Huge thanks to our sponsor, Drata
Leading security teams trust SafeBase by Drata to turn trust into a growth engine. Our enterprise-grade Trust Center puts your security posture in one secure, customer-facing portal, giving buyers instant visibility into your company’s continuous controls, certifications, and policies.
With AI-powered Questionnaire Assistance, blast through inbound security questionnaires in minutes instead of days, automate cross functional workflows, and eliminate friction.
That means less manual work, and faster deal cycles.
Win with Trust. Learn more at SafeBase.io.
ShinyHunters hits Vietnam National Credit Information Center
HybridPetya is a Petya/NotPetya copycat with UEFI Secure Boot bypass
CISA seeks control over CVE
Huge thanks to our sponsor, Drata
Leading security teams trust SafeBase by Drata to turn trust into a growth engine. Our enterprise-grade Trust Center puts your security posture in one secure, customer-facing portal, giving buyers instant visibility into your company’s continuous controls, certifications, and policies.
With AI-powered Questionnaire Assistance, blast through inbound security questionnaires in minutes instead of days, automate cross functional workflows, and eliminate friction.
That means less manual work, and faster deal cycles.
Win with Trust. Learn more at SafeBase.io.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guests Rob Teel, CTO, Oklahoma Department of Commerce and Howard Holton, CEO, GigaOm
Thanks to our show sponsor, Vanta
Do you know the status of your compliance controls right now? Like…right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta.Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines.
All links and the video of this episode can be found on CISO Series.com
SonicWall SSL VPN flaws now being actively exploited
Acting federal cyber chief outlines his priorities
U.S. based investors in spyware firms nearly tripled in 2024
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now?
We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta.
Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI.
Now that’s…a new way to GRC.
Get started at Vanta.com/headlines.
Find the stories behind the headlines at CISOseries.com.
The npm incident: nothing to fret about? Cursor Autorun flaw lets repositories execute code without consent Senator Wyden urges FTC to probe Microsoft over Ascension hack
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now?
We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta.
Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI.
Now that’s…a new way to GRC.
Get started at Vanta.com/headlines.
Thousands had data leaked in blood center ransomware attack UK Electoral Commission recovers, 3 years after China hack Npm packages with 2 billion weekly downloads targeted in supply chain attack
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now?
We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta.
Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI.
Now that’s…a new way to GRC.
Get started at Vanta.com/headlines.
GhostAction campaign targets GitHub
Scam centers see huge growth in Myanmar
GPUGate targets IT firms
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now?
We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta.
Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI.
Now that’s…a new way to GRC.
Get started at Vanta.com/headlines.
New malware phishing campaign hidden in SVG files
Anthropic agrees to pay $1.5bn in book piracy lawsuit
Qantas penalizes executives for cyberattack
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now?
We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta.
Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI.
Now that’s…a new way to GRC.
Get started at Vanta.com/headlines.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Ray Espinoza, vp of information security, Elite Technology
Thanks to our show sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
All links and the video of this episode can be found on CISO Series.com
France fines Google and Shein over cookie misconduct
CISA adds more TP-Link routers flaws to its KEV catalog
World’s largest sports piracy site shut down
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
Find the stories behind the headlines at CISOseries.com.
Fintech foils bank heist
NotDoor backdoor
Salesloft-Drift impact continues drifting
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
Find the stories behind the headlines at CISOseries.com.
'2.5 billion Gmail users at risk'? Entirely false, says Google Cloudflare blocks largest recorded DDoS attack peaking at 11.5 Tbps
Jaguar Land Rover says cyberattack ‘severely disrupted’ production
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
LegalPwn technique hides LLMs prompts inside contract legalese
Maryland Transit investigating cyberattack
Hacker attempts to forge his way into Spanish university
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
Find the stories behind the headlines at CISOseries.com.
Velociraptor forensic tool used for C2 tunneling
City of Baltimore gets socially engineered to the tune of $1.5 million
Ransomware gang takedowns create more smaller groups
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Johna Till Johnson, CEO and founder, Nemertes
Thanks to our show sponsor, Prophet Security
Ever feel like your security team is stuck in a loop of alert fatigue and manual investigations? Meet Prophet Security. Their Agentic AI SOC Platform automates the tedious stuff: triaging, investigating, and responding to alerts - so your analysts can focus on real threats. Think 10x faster response times and a smarter way to secure your business. Learn more at prophetsecurity.ai.
All links and the video of this episode can be found on CISO Series.com
Malicious nx Packages leak GitHub, Cloud, and AI Credentials
North Korean remote worker scheme boosted by generative AI
The Netherlands announces Salt Typhoon penetration
Huge thanks to our sponsor, Prophet Security
Security teams are drowning in alerts - many companies generate upwards of 1000 or more alerts a day, and nearly half go ignored. That’s where Prophet Security comes in. Their AI SOC platform automatically triages and investigates alerts, so your team can focus on real threats instead of busywork. Faster response, less burnout, and lower risk to your business. Learn more at prophetsecurity.ai.
Find the stories behind the headlines at CISOseries.com.
FBI warns of expanded Chinese hacking campaign
AI-powered ransomware is a thing now
Anthropic warns about “vibe-hacking”
Huge thanks to our sponsor, Prophet Security
SOC analyst burnout is real - repetitive tasks, poor tooling, and constant alert noise are driving them out. Prophet Security fixes this. Their Agentic AI Analyst handles alert triage and investigation - work that 69% of cybersecurity leaders say is the best use for AI in the SOC. Say goodbye to burnout, and hello to efficiency. Check out prophetsecurity.ai.
DOGE Put Critical Social Security Data at Risk, Whistle-Blower Says
CISA warns of actively exploited Git code execution flaw Alleged mastermind behind K-Pop celebrity stock heist extradited to South Korea
Huge thanks to our sponsor, Prophet Security
Your security analysts didn’t sign up to chase false alarms all day. With Prophet Security’s AI SOC platform, they won’t have to. It works like a tireless teammate—triaging and investigating alerts around the clock. Less burnout. Better coverage. And more time for meaningful work. Learn more atprophetsecurity.ai.
If Salesforce flutters its wings in San Francisco...
How is this still tricking people?
From tagging to bagging
Huge thanks to our sponsor, Prophet Security
Security teams are drowning in alerts - many companies generate upwards of 1000 or more alerts a day, and nearly half go ignored. That’s where Prophet Security comes in. Their AI SOC platform automatically triages and investigates alerts, so your team can focus on real threats instead of busywork. Faster response, less burnout, and lower risk to your business. Learn more atprophetsecurity.ai.
Malicious Go module steals credentials via Telegram
Mirai-based botnet resurfaces targeting systems globally
Silk Typhoon hackers exploit cloud trust to hack downstream customers
Huge thanks to our sponsor, Prophet Security
Ever feel like your security team is stuck in a loop of alert fatigue and manual investigations? Meet Prophet Security. Their Agentic AI SOC Platform automates the tedious stuff: triaging, investigating, and responding to alerts - so your analysts can focus on real threats. Think 10x faster response times and a smarter way to secure your business. Learn more at prophetsecurity.ai.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino. This is our milestone edition, celebrating five years of the daily Cyber Security Headlines news podcast. Our guests today will be the CSH reporters themselves, reflecting on some stories from this week as well as their favorite stories from the past few years. Joining Rich live will be Hadas Cassorla and Steve Prentice, with videos from Sarah Lane and Lauren Verno.
Thanks to our show sponsor, Conveyor
Does logging into a portal security questionnaire feel like punishment? We get it. Other solutions offer browser extensions that require you to do all the copy-pasting. It’s slow, tedious, and frustrating. Conveyor takes care of it for you. Our AI auto-scrolls, finds every question, and fills in accurate answers—all automatically. Oh, and our AI completes security questionnaires of any format, not just portals. Visit www.conveyor.com to learn more.
All links and the video of this episode can be found on CISO Series.com
Apple urges iPhone, iPad and Mac update ASAP
Scattered Spider operative gets 10 years and a big fine
Microsoft seeks customer feedback on SSD failure issues
Huge thanks to our sponsor, Conveyor
Does logging into a portal security questionnaire feel like punishment? We get it. Other solutions offer browser extensions that require you to do all the copy-pasting. It’s slow, tedious, and frustrating. Conveyor takes care of it for you. Our AI auto-scrolls, finds every question, and fills in accurate answers—all automatically. Oh, and our AI completes security questionnaires of any format, not just portals. Visit www.conveyor.com to learn more.
Find the stories behind the headlines at CISOseries.com.
A patch today keeps the zero-day away
Jailbreaking ChatGPT-5 Pro
The thing about vulnerabilities is they stay vulnerable
Huge thanks to our sponsor, Conveyor
It’s Thursday. Have you been personally victimized by a portal security questionnaire this week? Most solutions just give you a browser extension to copy and paste answers in, still leaving hours of manual work. With Conveyor, you don’t have to slog through it yourself. Just open the portal and Conveyor’s AI will scroll through each page, find the questions, and fill in answers for you—start to finish. See how at www.conveyor.com
Find the stories behind the headlines at CISOseries.com.
UK agrees to drop 'backdoor' mandate for Apple devices Massive Allianz Life data breach impacts 1.1M people
Speed cameras knocked out after cyber attack
Huge thanks to our sponsor, Conveyor
If portal questionnaires were a person, you’d block them by now. Endless clicks, bad navigation, and expanding questions stacked like russian nesting dolls, all add up to hours of your life you'll never get back. Conveyor’s AI browser extension auto-completes any portal questionnaire without the copy and paste like those other browser extensions on the market. Spend less time battling portals and more time on work that matters. Learn more at www.conveyor.com.
Workday confirms data breach
An alliance to unify post-quantum cryptography
New Chinese threat actor targeting Taiwan
Huge thanks to our sponsor, Conveyor
If the thought of logging into a portal questionnaire makes you want to throw your laptop away, you’re not alone. Most solutions just give you a browser extension to copy and paste answers, still leaving hours of manual work. With Conveyor, you don’t have to slog through it yourself. Just open the portal and Conveyor’s AI will scroll through each page, find the questions, and fill in answers for you—start to finish. Spend less time battling portals and more time on work that matters. Learn more at www.conveyor.com.
Cisco warns of maximum-severity defect in firewall software UK’s Colt Telecom suffers cyberattack
CISA implores OT environments to lock down critical infrastructure
Huge thanks to our sponsor, Conveyor
Have you been personally victimized by portal security questionnaires? Conveyor is here to help. Endless clicks, bad navigation, and expanding questions stacked like Russian nesting dolls, all add up to hours of your life you'll never get back. With Conveyor’s AI-powered browser extension, you can open a portal questionnaire, scan for questions, and watch it auto-populate your answers back into the portal without the copy and paste. See how at www.conveyor.com
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Steve Zalewski, co-host, Defense in Depth
Thanks to our show sponsor, Vanta
Do you know the status of your compliance controls right now? Like…right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines
All links and the video of this episode can be found on CISO Series.com
New wave of NFC relay fraud, call hijacking, and root exploits in banking sector
Canada’s House of Commons suffers cyberattack
Zoom fixes critical Windows client flaw that could enable privilege escalation
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now?
We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks.
But more than 9,000 companies have continuous visibility into their controls with Vanta.
Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001.
They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI.
Now that’s…a new way to GRC. Get started at Vanta.com/headlines
Find the stories behind the headlines at CISOseries.com.
Hack of federal court filing system exploited security flaws known since 2020 Pennsylvania attorney general says cyberattack knocked phone, email systems offline
Spike in Fortinet VPN brute-force attacks raises zero-day concerns
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now?
We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks.
But more than 9,000 companies have continuous visibility into their controls with Vanta.
Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001.
They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI.
Now that’s…a new way to GRC. Get started at Vanta.com/headlines
The hits just keep on coming
Where's the Little Dutch Boy when you need him?
I felt the ransomware down in Africa
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now?
We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks.
But more than 9,000 companies have continuous visibility into their controls with Vanta.
Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001.
They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI.
Now that’s…a new way to GRC. Get started at Vanta.com/headlines
Find the stories behind the headlines at CISOseries.com
North Korean crypto theft
Microsoft rolls out PC back up during attack
U.S. charges four in $100M global fraud scheme
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now?
We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks.
But more than 9,000 companies have continuous visibility into their controls with Vanta.
Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001.
They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI.
Now that’s…a new way to GRC. Get started at Vanta.com/headlines
DARPA awards $4 million prize for AI code review at DEF CON
North Korea ScarCruft group adds ransomware to its activities
Columbia University hack affects over 860,000
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now?
We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks.
But more than 9,000 companies have continuous visibility into their controls with Vanta.
Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001.
They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI.
Now that’s…a new way to GRC. Get started at Vanta.com/headlines
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Montez Fitzpatrick, CISO, Navvis
Thanks to our show sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO
All links and the video of this episode can be found on CISO Series.com
Microsoft warns of high-severity flaw in hybrid Exchange deployments
France’s third-largest mobile operator suffers breach
Dialysis company’s April attack affects 900,000 people
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
Find the stories behind the headlines at CISOseries.com.
Hackers hijacked Google’s Gemini AI with a poisoned calendar invite to take over a smart home
Nvidia rejects US demand for backdoors in AI chips
Google says hackers stole its customers’ data by breaching its Salesforce database
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
PBS confirms data breach after employee info leaked on Discord servers
TSMC fires engineers over suspected semiconductor secrets theft Cloudflare on Perplexity web scraping techniques to avoid robot.txt and network blocks
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
Microsoft and Google among most affected as zero day exploits jump 46%
Vietnamese hackers use PXA Stealer, hit 4,000 IPs and steal 200,000 passwords globally
New Plague Linux malware stealthily maintains SSH access
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Derek Fisher, Director of the Cyber Defense and Information Assurance Program, Temple University – also check out Derek’s substack.
Thanks to our show sponsor, Dropzone AI
Security teams everywhere are drowning in alerts. That’s why companies like Zapier and CBTS turned to Dropzone AI—the leader in autonomous alert investigation. Their AI investigates everything, giving your analysts time back for real security work. No more 40-minute rabbit holes. If you’re at BlackHat, find them in Startup City. Otherwise, check out their self-guided demo at dropzone.ai. This is how modern SOCs are scaling without burning out.
All links and the video of this episode can be found on CISO Series.com
NATM network breached and attacked through 4G Raspberry Pi
Easterly’s appointment to West Point rescinded
Report links Chinese companies to tools used by state-sponsored hackers
Huge thanks to our sponsor, Dropzone AI
Security teams everywhere are drowning in alerts. That's why companies like Zapier and CBTS turned to Dropzone AI—the leader in autonomous alert investigation. Their AI investigates everything, giving your analysts time back for real security work. No more 40-minute rabbit holes. If you're at BlackHat, find them in Startup City. Otherwise, check out their self-guided demo at dropzone.ai. This is how modern SOCs are scaling without burning out.
Find the stories behind the headlines at CISOseries.com.
Oh No! Lenovo
You sunk my battleship! Or did you?
Russians unable to get a taste of their own medicine
Huge thanks to our sponsor, Dropzone AI
Security teams everywhere are drowning in alerts. That's why companies like Zapier and CBTS turned to Dropzone AI—the leader in autonomous alert investigation. Their AI investigates everything, giving your analysts time back for real security work. No more 40-minute rabbit holes. If you're at BlackHat, find them in Startup City. Otherwise, check out their self-guided demo at dropzone.ai. This is how modern SOCs are scaling without burning out. Find the stories behind the headlines at CISOseries.com.
Critical Authentication Flaw Identified in Base44 Vibe Coding Platform
French telecom giant Orange discloses cyberattack
FBI seizes $2.4M in Bitcoin from new Chaos ransomware operation
Huge thanks to our sponsor, Dropzone AI
What if your SOC could investigate every single alert without burning out your team? That's exactly what Dropzone AI does. They're the leader in autonomous security investigations, and companies like Zapier and Fortune 500s are already on board. Their AI works alongside your analysts, handling the routine so humans can be strategic. See them at BlackHat in Startup City, booth 6427. Or experience it yourself—dropzone.ai has a self-guided demo ready for you.
Hacktivist attack grounds Russian flights
Naval group denies breach, hackers beg to differ
Dating app breach exposes thousands of women’s pictures
Huge thanks to our sponsor, Dropzone AI
Let me tell you about Dropzone AI—they're revolutionizing how security teams work. Companies like CBTS and Zapier use their AI to investigate alerts automatically, freeing up analysts for the work that really matters. We're talking 40-minute investigations done in 3 minutes. You can meet the Dropzone team at BlackHat in Startup City, or just head to dropzone.ai for a self-guided demo. Trust me, this is the future of security operations.
NASCAR announces data breach following March cyberattack
Plankey appears to be on track to lead CISA
Microsoft investigates another outage affecting 365 admin center
Huge thanks to our sponsor, Dropzone AI
Today's sponsor is Dropzone AI, the leader in AI-powered SOC automation. Major companies like Zapier and UiPath are using Dropzone to give their security teams superpowers. Imagine your analysts focusing on real threats while AI handles every routine investigation—in minutes, not hours. If you're heading to BlackHat, stop by their booth in Startup City. But you don't have to wait—check out their self-guided demo at dropzone.ai and see why Fortune 500s are making the switch.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Nick Espinosa, host, The Deep Dive Radio Show
Thanks to our show sponsor, Nudge Security
Nudge Security discovers new apps, accounts, and data-sharing in real-time and helps guide employees toward secure behaviors. Instead of trying to control everything, we give IT and security teams the visibility and automation they need to secure the Workforce Edge.
All links and the video of this episode can be found on CISO Series.com
SonicWall announces SMA 100 patches
FBI warns about The Com
Compromised Amazon Q extension deletes everything
Huge thanks to our sponsor, Nudge Security
Nudge Security discovers new apps, accounts, and data-sharing in real-time and helps guide employees toward secure behaviors. Instead of trying to control everything, we give IT and security teams the visibility and automation they need to secure the Workforce Edge.
Find the stories behind the headlines at CISOseries.com.
Goodbye toha, or as they say in Russian, Прощай “Trust the AI," they said. “What could go wrong?” they said Adobe apps advisory activated Huge thanks to our sponsor, Nudge Security
Trying to squeeze a few more items into your budget? Nudge Security can help by discovering up to TWO YEARS of historical SaaS spend along with usage insights so you can eliminate wasted spend. In fact, Nudge Security customer KarmaCheck was able to recoup 150% of their investment in Nudge within the first 6 months. See where you can save money by starting a free trial at nudgesecurity.com/spend.
Microsoft links Sharepoint ToolShell attacks to Chinese hackers Russian threat actors target NGOs with new OAuth phishing tactics
Silicon Valley engineer admits theft of US missile tech secrets Huge thanks to our sponsor, Nudge Security
Nudge Security discovers every SaaS app used in your org, secures configurations, enforces MFA, and manages app-to-app access so you can prevent identity based attacks. Start a free 14-day trial today at NudgeSecurity.com
SharePoint RCE flaws patched and exploited from China
Dell acknowledges World Leaks data breach
$44 million stolen from crypto exchange
Huge thanks to our sponsor, Nudge Security
Nudge Security discovers every GenAI tool ever used in your org, even those you’ve never heard of. For each tool, you’ll see who introduced it, who else is using it, where it’s integrated into other tools, and a vendor security profile. Get your free GenAI inventory today at NudgeSecurity.com.
Hewlett Packard warns of hardcoded passwords in Aruba access points
SharePoint zero-day exploited via RCE, no patch available
Russian vodka producer suffers ransomware attack
Huge thanks to our sponsor, Nudge Security
Discover every SaaS account ever created by anyone in your org within minutes of starting a free trial. Harden configs, enforce MFA, revoke risky app-to-app access, and more. Learn more at NudgeSecurity.com
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Cyrus Tibbs, CISO, PennyMac
Thanks to our show sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
All links and the video of this episode can be found on CISO Series.com
Chinese hackers use Cobalt Strike on Taiwan’s semiconductor sector
Salt Typhoon breaches National Guard and steals network configurations
Congress considers Stuxnet to manage OT threats
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
Find the stories behind the headlines at CISOseries.com.
Google says ‘Big Sleep’ AI tool found bug hackers planned to use Google fixes actively exploited sandbox escape zero day in Chrome China’s cyber sector amplifies Beijing’s hacking of U.S. targets Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
Pentagon welcomes Chinese engineers into its environment
HazyBeacon: It’s not a beer, but it leaves a bitter aftertaste
What the world needs now is another framework
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
EU states to test age verification app (Reuters)
AAR pledges to start fixing 20-year old vulnerability next year (Security Week)
Grok-4 jailbroken in two days (Infosecurity Magazine)
DoD awards contracts for agentic AI (Reuters)
eSIM vulnerability exposes billions of IoT devices (Infosecurity Magazine)
UK launches Vulnerability Research Initiative (Bleeping Computer)
Interlock ransomware using FileFix for malware (Bleeping Computer)
Disinformation groups spoofs European journalists (The Record)
Elmo gets hacked (AP News)
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
CISA gives one day for Citrix Bleed 2 fix
Google Gemini flaw hijacks email summaries for phishing
Louis Vuitton says UK customer data stolen in cyber-attack
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Jim Bowie, vp, CISO, Tampa General Hospital
Thanks to our show sponsor, Vanta
Do you know the status of your compliance controls right now? Like…right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines
All links and the video of this episode can be found on CISO Series.com
Look Out! Another Outlook Outage
Iranian APTs increased activity against U.S. industries in late spring
Russian basketball player arrested in France over alleged ransomware ties
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now?
We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks.
But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001.
They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC.
Get started at Vanta.com/headlines
Find the stories behind the headlines at CISOseries.com.
AMD warns of new Meltdown, Spectre-like bugs affecting CPUs
Multiple vulnerabilities in Mozilla Thunderbird could allow for arbitrary code execution
Bitcoin Depot breach exposes data of nearly 27,000 crypto users, More than $40 million stolen from GMX crypto platform
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now?
We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks.
But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001.
They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC.
Get started at Vanta.com/headlines
Four members of President Trump's cabinet impersonated
Is this some kind of a game?
Batavia attacks Russian industrial companies
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now?
We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks.
But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001.
They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC.
Get started at Vanta.com/headlines
Call of Duty game pulled from PC store after reported exploit
U.S. military gets cybersecurity boost
Bank employee helped hackers steal $100M
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now?
We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks.
But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001.
They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC.
Get started at Vanta.com/headlines
Ingram Micro suffers ransomware attack
Hacker leaks Telefónica data allegedly from new breach
ChatGPT prone to recommending wrong URLs, creating a new phishing opportunity
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now?
We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks.
But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001.
They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC.
Get started at Vanta.com/headlines
Find the stories behind the headlines at CISOseries.com.
Undetectable Android spyware leaks user logins
Hunters ransomware group shuts doors
Medical device company Surmodics reports cyberattack
Huge thanks to our sponsor, Palo Alto Networks
You’re moving fast in the cloud and so are attackers. But while SecOps and cloud security teams are working in silos, attackers are exploiting the gaps between them. Cortex Cloud by Palo Alto Networks bridges this divide, unifying teams and stopping attacks with real-time cloud security that includes AI-powered protection, detection and automated response capabilities. Threats are stopped in minutes instead of days, and teams can finally protect cloud environments at the speed and scale of modern attacks. To learn more about how Cortex Cloud stops cloud attacks before they become breaches, visit: paloaltonetworks.com/cortex/cloud-detection-and-response
Find the stories behind the headlines at CISOseries.com.
Student data lost in Columbia University hack
German hunger relief charity hit by ransomware
Qantas contact center breached
Huge thanks to our sponsor, Palo Alto Networks
You’re moving fast in the cloud and so are attackers. But while SecOps and cloud security teams are working in silos, attackers are exploiting the gaps between them.
Cortex Cloud by Palo Alto Networks bridges this divide, unifying teams and stopping attacks with real-time cloud security that includes AI-powered protection, detection and automated response capabilities.
Threats are stopped in minutes instead of days, and teams can finally protect cloud environments at the speed and scale of modern attacks. To learn more about how Cortex Cloud stops cloud attacks before they become breaches, visit: paloaltonetworks.com/cortex/cloud-detection-and-response
Chrome Zero-Day CVE-2025-6554 under active attack — Google issues security update
International Criminal Court targeted by new ‘sophisticated’ attack
Kelly Benefits says 2024 data breach impacts 550,000 customers, Esse Health says recent data breach affects over 263,000 patients
Huge thanks to our sponsor, Palo Alto Networks
You’re moving fast in the cloud and so are attackers. But while SecOps and cloud security teams are working in silos, attackers are exploiting the gaps between them.
Cortex Cloud by Palo Alto Networks bridges this divide, unifying teams and stopping attacks with real-time cloud security that includes AI-powered protection, detection and automated response capabilities.
Threats are stopped in minutes instead of days, and teams can finally protect cloud environments at the speed and scale of modern attacks. To learn more about how Cortex Cloud stops cloud attacks before they become breaches, visit: paloaltonetworks.com/cortex/cloud-detection-and-response
U.S. agencies issue urgent warning over Iran threat
Canada bans Chinese surveillance company
CISA names new executive director
Huge thanks to our sponsor, Palo Alto Networks
You’re moving fast in the cloud and so are attackers. But while SecOps and cloud security teams are working in silos, attackers are exploiting the gaps between them.
Cortex Cloud by Palo Alto Networks bridges this divide, unifying teams and stopping attacks with real-time cloud security that includes AI-powered protection, detection and automated response capabilities.
Threats are stopped in minutes instead of days, and teams can finally protect cloud environments at the speed and scale of modern attacks. To learn more about how Cortex Cloud stops cloud attacks before they become breaches, visit: paloaltonetworks.com/cortex/cloud-detection-and-response
Hawaiian Airlines suffers cyberattack
United Natural Foods says cyber incident will impact quarterly income
Russia throttles Cloudflare making sites inaccessible
Huge thanks to our sponsor, Palo Alto Networks
You’re moving fast in the cloud and so are attackers. But while SecOps and cloud security teams are working in silos, attackers are exploiting the gaps between them.
Cortex Cloud by Palo Alto Networks bridges this divide, unifying teams and stopping attacks with real-time cloud security that includes AI-powered protection, detection and automated response capabilities.
Threats are stopped in minutes instead of days, and teams can finally protect cloud environments at the speed and scale of modern attacks. To learn more about how Cortex Cloud stops cloud attacks before they become breaches, visit: paloaltonetworks.com/cortex/cloud-detection-and-response
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Bil Harmer, operating partner and CISO, Craft Ventures. Check out Bil’s page, KillSwitchAdvisory.
Thanks to our show sponsor, ThreatLocker
Alert fatigue, false positives, analyst burnout—you know the drill. What if you could stop threats before they run? ThreatLocker gives CISOs what they’ve been asking for: real control at the execution layer. Only approved apps, scripts, and executables run. Period. Known-good is enforced. Everything else? Denied by default. Ringfencing and storage control keep even trusted tools in their lane—so PowerShell doesn’t become a weapon. And yes—it works at scale. Granular policies. Fast rollout. Built for modern infrastructure. You don’t need more alerts. You need fewer chances for malware to make a move. ThreatLocker helps you flip the model—from detect-and-respond… to deny-and-verify. Go to ThreatLocker.com/CISO to schedule your free demo and close the last gap in your Zero Trust strategy, before it’s exploited.
All links and the video of this episode can be found on CISO Series.com
Iranian-backed spearphishing campaign seeks out cybersecurity experts
Microsoft fixes Outlook bug causing crashes when opening emails
Glasgow City Council suffers cyberattack
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
Find the stories behind the headlines at CISOseries.com.
NHS confirms patient death linked to ransomware attack
BreachForums busted again
Thousands of SaaS apps still vulnerable to nOAuth
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
Hackers target over 70 Microsoft Exchange servers to steal credentials via keyloggers
Apple, Netflix, Microsoft sites ‘hacked’ for tech support scams
The 2022 initiative by Cloudflare, CrowdStrike and Ping Identity provided cybersecurity support to critical infrastructure sectors seen as potential targets of Russia-linked attacks
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
DHS warns of retaliatory Iranian cyberattacks
Steel giant Nucor confirms breach
Ransomware hits healthcare system again
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
CMC officially points finger at Scattered Spider for Marks & Spencer and Co-op attacks
Aflac investigating suspicious activity on its U.S. network
Russian dairy producers suffer cyberattack
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Howard Holton, COO and industry analyst, GigaOm
Thanks to our show sponsor, Adaptive Security
As deepfake scams and GenAI phishing evolve, Adaptive equips security teams with AI-powered phishing simulations featuring realistic personalized deepfakes and engaging security awareness training. Their new AI Content Creator turns threat intel and policy updates into interactive, multilingual training — instantly. Trusted by Fortune 500s and backed by Andreessen Horowitz and OpenAI, Adaptive helps you stay ahead of AI-driven threats. Learn more at adaptivesecurity.com.
All links and the video of this episode can be found on CISO Series.com
Cisco, Atlassian fix high-severity vulnerabilities
Alleged Ryuk ransomware gang member arrested and extradited
Telecom company Viasat attacked by Salt Typhoon
Huge thanks to our sponsor, Adaptive Security — OpenAI’s first cybersecurity investment
As deepfake scams and GenAI phishing evolve, Adaptive equips security teams with AI-powered phishing simulations featuring realistic personalized deepfakes and engaging security awareness training. Their new AI Content Creator turns threat intel and policy updates into interactive, multilingual training — instantly.
Trusted by Fortune 500s and backed by Andreessen Horowitz and OpenAI, Adaptive helps you stay ahead of AI-driven threats.
Learn more at adaptivesecurity.com.
Find the stories behind the headlines at CISOseries.com.
Over 5 million impacted by Episource breach
Predatory Sparrow strikes Iran again
Data leak at Swiss banks
Huge thanks to our sponsor, Adaptive Security — OpenAI’s first cybersecurity investment
As deepfake scams and GenAI phishing evolve, Adaptive equips security teams with AI-powered phishing simulations featuring realistic personalized deepfakes and engaging security awareness training. Their new AI Content Creator turns threat intel and policy updates into interactive, multilingual training — instantly.
Trusted by Fortune 500s and backed by Andreessen Horowitz and OpenAI, Adaptive helps you stay ahead of AI-driven threats.
Learn more at adaptivesecurity.com.
Hackers exploit critical Langflow flaw to unleash Flodrix botnet Organizations warned of vulnerability exploited against discontinued TP-Link routers
Russia detects first SuperCard malware attacks skimming bank data via NFC
Huge thanks to our sponsor, Adaptive Security — OpenAI’s first cybersecurity investment
As deepfake scams and GenAI phishing evolve, Adaptive equips security teams with AI-powered phishing simulations featuring realistic personalized deepfakes and engaging security awareness training. Their new AI Content Creator turns threat intel and policy updates into interactive, multilingual training — instantly.
Trusted by Fortune 500s and backed by Andreessen Horowitz and OpenAI, Adaptive helps you stay ahead of AI-driven threats.
Learn more at adaptivesecurity.com.
Beware the SMS 2FA middleman
Police seize Archetyp Market
Zoomcar hack impacts 8.4 million users
Huge thanks to our sponsor, Adaptive Security
As deepfake scams and GenAI phishing evolve, Adaptive equips security teams with AI-powered phishing simulations featuring realistic personalized deepfakes and engaging security awareness training. Their new AI Content Creator turns threat intel and policy updates into interactive, multilingual training — instantly. Trusted by Fortune 500s and backed by Andreessen Horowitz and OpenAI, Adaptive helps you stay ahead of AI-driven threats. Learn more at adaptivesecurity.com.
Washington Post investigates hacking incident on journalists’ emails
Canadian airline WestJet is containing a cyberattack
Crash records stolen from Texas DOT
Huge thanks to our sponsor, Adaptive Security — OpenAI’s first cybersecurity investment
As deepfake scams and GenAI phishing evolve, Adaptive equips security teams with AI-powered phishing simulations featuring realistic personalized deepfakes and engaging security awareness training. Their new AI Content Creator turns threat intel and policy updates into interactive, multilingual training — instantly.
Trusted by Fortune 500s and backed by Andreessen Horowitz and OpenAI, Adaptive helps you stay ahead of AI-driven threats.
Learn more at adaptivesecurity.com.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Christina Shannon, CIO, KIK Consumer Products
Thanks to our show sponsor, Vanta
Is your manual GRC program slowing you down? There’s something more efficient than spreadsheets, screenshots, and manual processes — Vanta. With Vanta, GRC can be so. much. easier—while also strengthening your security posture and driving revenue for your business. Vanta automates key areas of your GRC program—including compliance, risk, and customer trust—and streamlines the way you manage information. The impact is real: A recent IDC analysis found that compliance teams using Vanta are one hundred and twenty nine percent more productive. Get back time to focus on strengthening security and scaling your business. Get started at Vanta.com/headlines.
All links and the video of this episode can be found on CISO Series.com
Hackers attacks target Microsoft Entra ID accounts using pentesting tool
Google Cloud and Cloudflare outages reported
House Homeland Chairman Mark Green announces his departure
Huge thanks to our sponsor, Vanta
Is your manual GRC program slowing you down? There’s something more efficient than spreadsheets, screenshots, and manual processes — Vanta.
With Vanta, GRC can be so. much. easier—while also strengthening your security posture and driving revenue for your business. Vanta automates key areas of your GRC program—including compliance, risk, and customer trust—and streamlines the way you manage information.
The impact is real: A recent IDC analysis found that compliance teams using Vanta are one hundred and twenty nine percent more productive.
Get back time to focus on strengthening security and scaling your business. Get started at Vanta.com/headlines.
Find the stories behind the headlines at CISOseries.com.
Zero-click data leak flaw in Copilot
Operation Secure targets infostealer operations
FIN6 targets recruiters
Huge thanks to our sponsor, Vanta
Is your manual GRC program slowing you down? There’s something more efficient than spreadsheets, screenshots, and manual processes — Vanta.
With Vanta, GRC can be so. much. easier—while also strengthening your security posture and driving revenue for your business. Vanta automates key areas of your GRC program—including compliance, risk, and customer trust—and streamlines the way you manage information.
The impact is real: A recent IDC analysis found that compliance teams using Vanta are one hundred and twenty nine percent more productive.
Get back time to focus on strengthening security and scaling your business. Get started at Vanta.com/headlines.
CISA, Microsoft warn of Windows zero-day used in attack on ‘major’ Turkish defense org 40K IoT cameras worldwide stream secrets to anyone with a browser Marks & Spencer begins taking online orders again, out for seven weeks due to cyberattack Huge thanks to our sponsor, Vanta
Is your manual GRC program slowing you down? There’s something more efficient than spreadsheets, screenshots, and manual processes — Vanta.
With Vanta, GRC can be so. much. easier—while also strengthening your security posture and driving revenue for your business. Vanta automates key areas of your GRC program—including compliance, risk, and customer trust—and streamlines the way you manage information.
The impact is real: A recent IDC analysis found that compliance teams using Vanta are one hundred and twenty nine percent more productive.
Get back time to focus on strengthening security and scaling your business. Get started at Vanta.com/headlines.
Brute forcing phone numbers linked to Google accounts
The Guardian launches Secure Messaging service
United Natural Foods hit by cyberattack
Huge thanks to our sponsor, Vanta
Is your manual GRC program slowing you down? There’s something more efficient than spreadsheets, screenshots, and manual processes — Vanta.
With Vanta, GRC can be so. much. easier—while also strengthening your security posture and driving revenue for your business. Vanta automates key areas of your GRC program—including compliance, risk, and customer trust—and streamlines the way you manage information.
The impact is real: A recent IDC analysis found that compliance teams using Vanta are one hundred and twenty nine percent more productive.
Get back time to focus on strengthening security and scaling your business. Get started at Vanta.com/headlines.
Presidential cyber executive order signed
Neuberger warns of U.S. infrastructure’s cyberattack weakness
Mirai botnet infects TBK DVR devices
Huge thanks to our sponsor, Vanta
Is your manual GRC program slowing you down? There’s something more efficient than spreadsheets, screenshots, and manual processes — Vanta.
With Vanta, GRC can be so. much. easier—while also strengthening your security posture and driving revenue for your business. Vanta automates key areas of your GRC program—including compliance, risk, and customer trust—and streamlines the way you manage information.
The impact is real: A recent IDC analysis found that compliance teams using Vanta are one hundred and twenty nine percent more productive.
Get back time to focus on strengthening security and scaling your business. Get started at Vanta.com/headlines.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines - Week in Review is hosted by Rich Stroffolino with guest Rusty Waldron, chief business security officer, ADP
Thanks to our show sponsor, Conveyor
Let me guess, another security questionnaire just landed in your inbox. Which means all the follow up tasks you don’t have time for are close behind. What are you going to do? Here’s a better question: what would Sue do? Sue is Conveyor’s new AI Agent for Customer Trust. She handles the entire security review process like answering every customer request from sales, completing every questionnaire or executing every communications and coordination task in-between. No more manual work. Just a quick review when she’s done. Ready to let Sue take the reins? Learn more at www.conveyor.com.
All links and the video of this episode can be found on CISO Series.com
Stolen Kettering Health data published
Reddit sues Anthropic for scraping
North Face website customer accounts breached
Huge thanks to our sponsor, Conveyor
Let me guess, another security questionnaire just landed in your inbox. Which means all the follow up tasks you don’t have time for are close behind.
What are you going to do?
Here’s a better question: what would Sue do?
Sue is Conveyor’s new AI Agent for Customer Trust. She handles the entire security review process like answering every customer request from sales, completing every questionnaire or executing every communications and coordination task in-between.
No more manual work. Just a quick review when she’s done.
Ready to let Sue take the reins? Learn more at www.conveyor.com.
Find the stories behind the headlines at CISOseries.com.
Ukraine claims cyberattack on Russian bomber maker
Vishing campaign targets Salesforce
Microsoft lends a hand to European governments
Huge thanks to our sponsor, Conveyor
Ever wish you had a teammate that could handle the most annoying parts of customer security reviews?
You know, chasing down SMEs for answers, updating systems, coordinating across teams—all the grunt work nobody wants to do.
Plus, having to finish the dang questionnaire itself.
Well. That teammate exists—Conveyor just launched Sue, the first AI Agent for Customer Trust.
Sue really is the dream teammate. She never misses a deadline, answers every customer request from sales, completes every questionnaire and knocks out all the coordination in-between.
Sue handles it all so you don’t have to. Learn more at www.conveyor.com.
Meta and Yandex are de-anonymizing Android users’ web browsing identifiers
LummaC2 fractures as Acreed malware becomes top dog Hewlett Packard Enterprise warns of critical StoreOnce auth bypass Huge thanks to our sponsor, Conveyor
Tired of herding cats to complete customer security questionnaires?
Your team probably spends hours daily juggling the back and forth of completing these security requests.
That's why Conveyor created Sue, the first AI Agent for Customer Trust. Sue doesn't just handle completing security questionnaires and sending SOC 2 to prospects – she manages all the communication and follow-up too.
You simply get notified when everything's done so you can do a quick review.
Stop wrangling cats and see what Sue can do for you at www.conveyor.com.
Microsoft and CrowdStrike partner to link threat actor names
Qualcomm sees Adreno bugs under active exploitation
New details on proposed CISA cuts
Huge thanks to our sponsor, Conveyor
Does trying to get the security questionnaire done and back to your customer ever feel like you’re herding cats?
It’s not answering questions - most of you have automation software for that.
It’s all of the manual back and forth that becomes a slog like communicating between teams, tracking people down to get their review, updating sources and updating systems.
Conveyor just launched an AI agent, Sue, to do all of these things and more for you.
Learn about Sue at www.conveyor.com.
Exploit for maximum severity Cisco IOS XE flaw now public
Senators as for reinstatement of cyber review board to work on Salt Typhoon investigation
Australian ransomware victims now must report their payments
Huge thanks to our sponsor, Conveyor
Conveyor launched the first AI Agent for Customer Trust. So wtf does that mean?
It means the AI agent goes beyond just sharing NDA-gated documents like a SOC 2 with customers or answering security questionnaires.
Conveyor’s AI Agent, Sue, handles the entire security review process from start to finish.
She answers every customer request from sales, completes every questionnaire and executes every communications and coordination task in-between. It's perfect for B2B infosec teams sick of manual security review work.
Check it out at www.conveyor.com.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Steve Knight, former CISO, Hyundai Capital America
Thanks to our show sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
All links and the video of this episode can be found on CISO Series.com
Windows 11 might fail to start after installing KB5058405, says Microsoft
Victoria’s Secret website goes offline following cyberattack
Billions of stolen cookies available, worrying security experts
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
Find the stories behind the headlines at CISOseries.com.
Microsoft wants to update all the things
LexisNexis breach impacts 364,000 people
Cyber insurance premium volume expected to double
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
MathWorks, Creator of MATLAB, Confirms Ransomware Attack Adidas warns of data breach after customer service provider hack Dutch Intelligence Agencies Say Russian Hackers Stole Police Data in Cyberattack Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
Malicious npm and VS Code packages stealing data
Nova Scotia Power confirms ransomware attack
Researchers claim ChatGPT o3 bypassed shutdown in controlled test
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
Find the stories behind the headlines at CISOseries.com.
CISA warns Commvault clients of campaign targeting cloud applications
Russian hacker group Killnet returns with slightly adjusted mandate
Fake VPN and browser NSIS installers used to deliver Winos 4.0 malware
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest George Finney, CISO, The University of Texas System – check out George’s new book plus all his other achievements at his website, WellAwareSecurity.
Thanks to our show sponsor, Conveyor
Still spending hours maintaining a massive spreadsheet of Q&A pairs or using RFP tools to answer security questionnaires? Conveyor’s AI doesn’t need hand-holding and gets you accurate answers every time with limited knowledge base maintenance. It reads directly from your connected sources—documents, wikis, websites, Confluence, Google drive, and even your Conveyor trust center. You don’t maintain a knowledge base. You connect to one. And our AI does the rest for you. See what real auto-fill magic looks like at www.conveyor.com
All links and the video of this episode can be found on CISO Series.com
Signal adds Recall blocker
Critical Windows Server 2025 dMSA vulnerability warning
Pathology lab suffers data breach
Huge thanks to our sponsor, Conveyor
Still spending hours maintaining a massive spreadsheet of Q&A pairs or using RFP tools to answer security questionnaires?
Conveyor’s AI doesn’t need hand-holding and gets you accurate answers every time with limited knowledge base maintenance.
It reads directly from your connected sources—documents, wikis, websites, Confluence, Google drive, and even your Conveyor trust center.
You don’t maintain a knowledge base. You connect to one.
And our AI does the rest for you. See what real auto-fill magic looks like at www.conveyor.com
Find the stories behind the headlines at CISOseries.com.
Ransomware attack knocks out Kettering Health
Lumma malware operation disrupted
Federal agencies impacted by “major lapse” at Opexus
Huge thanks to our sponsor, Conveyor
Half-baked AI answers to security questionnaires are worse than no answer at all. Conveyor’s AI gets it right the first time—with market-leading accuracy rates and full citations for every response. Because “good enough” doesn’t cut it when you’re filling in questionnaires daily. Accuracy isn’t just a feature—it’s the foundation. Because we know that when AI gets it wrong, you’re stuck with more work. If AI isn’t living up to its promise with other tools, check out Conveyor at www.conveyor.com
US DOJ opens investigation into Coinbase's recent cyberattack Dutch government passes law to criminalize cyber-espionage Ransomware attack on food distributor spells more pain for UK supermarkets Huge thanks to our sponsor, Conveyor
What if your sales team could answer security questions themselves—without blowing up your Slack or email every 10 minutes? With Conveyor, they can. Conveyor is the trust center and security questionnaire automation tool your infosec friends love to use. Whether through Slack or the Conveyor app, sales and presales teams can easily get AI-generated answers to any customer security question, with your pre-set rules and reviews in place. Free up your team and keep deals moving at www.conveyor.com
UK’s Legal Aid Agency breached
NHS patients put at risk from cyberattacks
23andMe has a buyer
Huge thanks to our sponsor, Conveyor
Ever spent an hour in a clunky portal questionnaire with UI from 1999 just to lose your work because it timed out?
Conveyor’s got you.
Our browser extension completes questionnaires in the most tedious portals for you by auto-importing all the questions and generating AI answers. For popular portals, it can go full autopilot and fill in reviewed answers into the portal on one click. You shouldn’t have to fight a portal just to prove your security posture. Learn more at www.conveyor.com.
Scattered Spider facilitates UK retail hacks and is moving to the U.S.
Defendnot tool can disable Microsoft Defender
FBI warns government officials about new waves of deepfakes
Huge thanks to our sponsor, Conveyor
Are you dealing with security questionnaire chaos this week? If so, get Conveyor’s AI to knock them out for you. Connect Conveyor to any source, easily upload any format of questionnaire or use the browser extension for portals and their AI handles the rest—from parsing the questions to generating answers and auto-tagging collaborators. Let Conveyor do the work for you. Learn more at www.conveyor.com.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Nick Espinosa, host, The Deep Dive Radio Show. Here’s where you can find him: Daily Podcast on SoundCloud | YouTube | Forbes | Twitter/X | Facebook | BlueSky | Mastodon
Thanks to our show sponsor, Vanta
Do you know the status of your compliance controls right now? Like…right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines.
All links and the video of this episode can be found on CISO Series.com
Coinbase says hackers bribed staff to steal customer data and are demanding $20 million ransom Windows 11 and Red Hat Linux hacked on first day of Pwn2Own The Internet’s biggest-ever black market just shut down amid a Telegram purge Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines.
Steel producer disrupted by cyberattack
European Vulnerability Database (EUVD) is online
CISA pauses advisory overhaul
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines.
Radware says recently WAF bypasses were patched in 2023
Marks & Spencer confirms data stolen in ransomware attack
Alabama suffers cybersecurity event
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines.
Find the stories behind the headlines at CISOseries.com
Global Crossing Airlines Group confirms cyberattack
Google settles privacy lawsuits
UK launches software security guidelines
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines.
Hackers hijack Japanese financial accounts to conduct billions in trades
Education giant Pearson hit by cyberattack exposing customer data
Microsoft Teams will soon block screen capture during meetings
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Dan Holden, CISO, BigCommerce
Thanks to our show sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
All links and the video of this episode can be found on CISO Series.com
Cisco patches a level 10 vulnerability in IOS XE
President nominates former Unilever CISO to be Pentagon CIO
SonicWall patches a new zero-day vulnerability
Thanks to today's episode sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
Find the stories behind the headlines at CISOseries.com.
Europol shuts down six DDoS-for-hire services used in global attacks
CrowdStrike says it will lay off 500 workers Passkeys set to protect GOV.UK accounts against cyber-attacks Thanks to today's episode sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
Find the stories behind the headlines at CISOseries.com.
Congress challenges Noem over proposed CISA cuts
Texas school district breach impacts over 47,000 people
NSO Group to pay WhatsApp $167 million in damages
Thanks to today's episode sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
Find the stories behind the headlines at CISOseries.com.
Signal clone gets hacked
Sounding the alarm on easyjson
Ransomware group takes credit for UK retail attacks
Thanks to today's episode sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
Find the stories behind the headlines at CISOseries.com.
Microsoft ends Authenticator password autofill in favor of Edge
StealC malware enhanced with stealth upgrades and data theft
White House proposes cutting $491M from CISA budget
Thanks to today's episode sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest DJ Schleen, Head of Security, Boats Group
Thanks to our show sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
All links and the video of this episode can be found on CISO Series.com
UK retailer Co-Op suffers cyberattack
FBI shares list of 42,000 LabHost phishing domains
NSO group looking at hefty damages in WhatsApp case
Thanks to today's episode sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
Find the stories behind the headlines at CISOseries.com.
Alleged ‘Scattered Spider’ member extradited to U.S.
Experts see little progress after major Chinese telecom hack
Polish police take down impersonation scammers
Thanks to today's episode sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
For the stories behind the headlines, visit CISOseries.com.
Millions of Apple Airplay-Enabled Devices Can Be Hacked via Wi-Fi Google tracked 75 zero days exploited in the wild in 2024 France ties Russian APT28 hackers to 12 cyberattacks on French orgs
Thanks to today's episode sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
Uyghur Language Software Hijacked to Deliver Malware
Cloudflare sees a big jump in DDoS attacks
4chan back online
Thanks to today's episode sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
SAP zero-day vulnerability under widespread active exploitation
Hackers abuse OAuth 2.0 workflows to hijack Microsoft 365 accounts
Cybersecurity firm CEO charged with installing malware on hospital systems
Thanks to today's episode sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Bethany De Lude, CISO emeritus, The Carlyle Group
Thanks to our show sponsor, Dropzone AI
Alert investigation is eating up your security team’s day—30 to 40 minutes per alert adds up fast. Dropzone AI‘s SOC Analyst transforms this reality by investigating every alert with expert-level thoroughness at machine speed. Our AI SOC Analyst gathers evidence, connects the dots across your security tools, and delivers clear reports with recommended actions—all in minutes. No playbooks to build, no code to write. Just consistent, high-quality investigations that free your team to focus on what matters: stopping actual threats. Meet us at RSA Booth ESE-60.
All links and the video of this episode can be found on CISO Series.com
Russian army targeted by Android malware hidden in mapping app
Attackers hit security device defects hard in 2024
Critical Commvault Command Center flaw warning
Huge thanks to our sponsor, Dropzone AI
Alert investigation is eating up your security team's day—30 to 40 minutes per alert adds up fast. Dropzone AI's SOC Analyst transforms this reality by investigating every alert with expert-level thoroughness at machine speed. Our AI SOC Analyst gathers evidence, connects the dots across your security tools, and delivers clear reports with recommended actions—all in minutes. No playbooks to build, no code to write. Just consistent, high-quality investigations that free your team to focus on what matters: stopping actual threats. Meet us at RSA Booth ESE-60.
Find the stories behind the headlines at CISOseries.com.
Blue Shield of California shared private health data of millions with Google
The FBI issues its 2024 IC3 report
Ex-Army sergeant jailed for selling military secrets
Huge thanks to our sponsor, Dropzone AI
Security analysts need practical experience to build investigation skills, but getting expert guidance for every alert is impossible. That's why Dropzone AI created COACH—a free Chrome extension that serves as an AI security mentor for SOC analysts at any level. COACH reads alerts across all major security platforms, explains their context, provides alternative hypotheses, and guides analysts through industry-standard investigation methodologies. Unlike our AI SOC Analyst product, COACH doesn't do the work for you—it teaches you how to think through investigations yourself. It supplements human mentoring with always-available guidance that respects your data with zero retention. Develop your security team's skills at Dropzone.ai/coach.
For the stories behind the headlines, head to CISOseries.com.
Microsoft Recall on Copilot+ PC: testing the security and privacy implications Russian organizations targeted by backdoor masquerading as secure networking software updates
SSL.com Scrambles to Patch Certificate Issuance Vulnerability Huge thanks to our sponsor, Dropzone AI
Is your security team spending too much time chasing alerts instead of stopping threats? Dropzone AI modernizes your security operations by handling the routine investigations that consume your team's day. Our AI SOC Analyst works with your existing security tools, learns your environment, and delivers clear, actionable reports within minutes. Your human analysts can finally focus on the most critical threats. Organizations using our AI SOC Analyst handle significantly more alerts without growing their team. See how at RSA at booth ESE-60.
Google OAuth abused in DKIM replay attack
Japan warns of sharp rise in unauthorized trading
North Koreans hijacking Zoom’s Remote Control
Huge thanks to our sponsor, Dropzone AI
Security threats don't clock out at 5 PM, but your analysts need to sleep sometime. Dropzone AI delivers around-the-clock alert investigations with the same attention to detail at midnight as at noon. Our AI SOC Analyst ensures no more morning backlogs and no more off-hours blind spots. Just reliable, continuous protection that ensures every alert gets the attention it deserves, regardless of when it arrives. See how SOC teams are achieving true 24/7 coverage with our AI SOC Analyst without the staffing challenges at Dropzone.ai.
Widespread Microsoft Entra lockouts cause by new security feature rollout
Malware delivered through diplomatic wine-tasting invites
British companies told to hold in-person interviews to thwart North Korea job scammers
Huge thanks to our sponsor, Dropzone AI
Growing your MSSP client roster while your alerts are multiplying? Dropzone AI works alongside your team, investigating alerts just like your best human analysts would. Our AI SOC Analyst cuts investigation time from an hour to minutes while handling five times more alerts per analyst. Unlike complex SOAR solutions, Dropzone deploys quickly and adapts to your environment without the need for playbooks or coding. Eliminate backlogs, reduce false positives, and deliver the detailed investigations your clients expect. Ready to scale your MSSP without scaling your team? Meet us at booth ESE-60 at RSA.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by David Spark with guest Trina Ford, CISO, iHeartMedia
Thanks to our show sponsor, Vanta
Do you know the status of your compliance controls right now? Like…right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines.
All links and the video of this episode can be found on CISO Series.com
Bipartisan push for renewal of cyberthreat information sharing law
ClickFix becoming a favorite amongst state-sponsored hackers
GoDaddy puts Zoom on mute for about 90 minutes
Thanks to this week's episode sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now?
We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta.
Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting,
And helps you get security questionnaires done 5 times faster with AI.
Now that’s…a new way to GRC. Get started at Vanta.com/headlines.
Find the stories behind the headlines at CISOseries.com
MITRE gets last-minute bailout from CISA
Krebs exits SentinelOne after security clearance pulled
Apple fixes two zero-days exploited in targeted iPhone attacks
Thanks to this week's episode sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now?
We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta.
For the stories behind the headlines, visit CISOseries.com.
Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting,
And helps you get security questionnaires done 5 times faster with AI.
Now that’s…a new way to GRC. Get started at Vanta.com/headlines.
CISA issued a statement that it execution an option on its contract with MITRE to continue funding the CVE program.
Government CVE funding set to end Tuesday 4chan, the internet's most infamous forum, is down following an alleged hack
China accuses US of launching 'advanced' cyberattacks, names alleged NSA agents Thanks to this week's episode sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now?
We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta.
Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting,
And helps you get security questionnaires done 5 times faster with AI.
Now that’s…a new way to GRC. Get started at Vanta.com/headlines.
AI code dependencies are a supply chain risk
Morocco investigates social security leak
European Commission increases security measures for US-bound staff
Thanks to this week's episode sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now?
We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta.
Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting,
And helps you get security questionnaires done 5 times faster with AI.
Now that’s…a new way to GRC. Get started at Vanta.com/headlines.
Major workforce cuts planned for CISA
Microsoft warns Windows users not to delete ‘inetpub’ folder
Data breach at testing lab affects 1.6 million people
Thanks to this week's episode sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now?
We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta.
Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting,
And helps you get security questionnaires done 5 times faster with AI.
Now that’s…a new way to GRC. Get started at Vanta.com/headlines.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Carla Sweeney, SVP, InfoSec, Red Ventures
Thanks to our show sponsor, Nudge Security
Are you struggling to secure your exploding SaaS footprint? With Nudge Security, you can discover all SaaS apps and accounts, manage access, ensure secure configurations, vet unfamiliar tools, and automate daily identity security tasks. Start a free 14-day trial
All links and the video of this episode can be found on CISO Series.com
President orders probe of former CISA Director Chris Krebs
Nissan Leaf cars can be hacked for remote spying and physical takeover
Infosec experts warn of China Typhoon retaliation against tariffs
Thanks to our episode sponsor, Nudge Security
Are you struggling to secure your exploding SaaS footprint? With Nudge Security, you can discover all SaaS apps and accounts, manage access, ensure secure configurations, vet unfamiliar tools, and automate daily identity security tasks. Start a free 14-day trial
Find the stories behind the headlines at CISOseries.com.
U.S. Comptroller suffers ‘major incident’
Oracle confirms "obsolete servers" hacked
Police seize Smokeloader malware servers and detain customers
Thanks to our episode sponsor, Nudge Security
Nudge Security is the only solution for SaaS security and governance that can discover up to two years of historical SaaS spend along with usage insights so you can uncover wasted spend and sources of unnecessary risk. Start a free 14-day trial today
For the stories behind the headlines, visit CISOseries.com.
WhatsApp vulnerability could facilitate remote code execution Spyware targeting Chinese diaspora Microsoft Patches 125 Windows Vulns, Including Exploited CLFS Zero-Day Thanks to our episode sponsor, Nudge Security
Nudge Security provides advanced security posture management for Okta, Microsoft 365, Google Workspace, and other critical apps. With Nudge, you’ll be alerted of risks like weak or missing MFA, inactive admin accounts, and risky integrations, plus you can automate remediation tasks and on-going identity governance. Start a free 14-day trial today
Apple appeals UK encryption back door order
Researchers warn about AI-driven hacking tool
PoisonSeed campaign weaponizes CRM system
Thanks to our episode sponsor, Nudge Security
Nudge Security discovers every GenAI tool ever used in your org, even those you’ve never heard of. For each tool, you’ll see who introduced it, who else is using it, where it’s integrated into other tools, and a vendor security profile. Get your free GenAI inventory today.
Haugh fired from leadership of NSA and Cyber Command
WinRAR flaw bypasses Windows Mark of the Web security alerts
Researcher creates fake passport using ChatGPT
Thanks to our episode sponsor, Nudge Security
Nudge Security helps you mitigate security risks stemming from SaaS sprawl by discovering every SaaS account ever created by anyone in your org within minutes of starting a free trial. And, you can automate on-going governance tasks like security posture checks, user access reviews, employee offboarding, and more.
Start a free 14-day trial
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Howard Holton, COO and industry analyst, GigaOm
Thanks to our show sponsor, Qualys
Overwhelmed by noise in your cybersecurity processes? Cut through the clutter with Qualys Enterprise TruRisk Management. Quantify your cyber risk in clear financial terms and focus on what matters most. Actionable insights help you prioritize critical threats, streamline remediation, and accelerate risk reduction— while effectively communicating impact to stakeholders. Empower your cybersecurity strategy with tools that drive faster, smarter, and more efficient risk management. Your secure future starts today with Qualys Enterprise TruRisk Management. Visit qualys.com/etm for more information.
All links and the video of this episode can be found on CISO Series.com
Google patches Quick Share vulnerability
ChatGPT suffered brief outage Wednesday
UK’s Royal Mail investigates data leak claims
Thanks to today's episode sponsor, Qualys
"Overwhelmed by noise in your cybersecurity processes? Cut through the clutter with Qualys Enterprise TruRisk Management. Quantify your cyber risk in clear financial terms and focus on what matters most. Actionable insights help you prioritize critical threats, streamline remediation, and accelerate risk reduction— while effectively communicating impact to stakeholders. Empower your cybersecurity strategy with tools that drive faster, smarter, and more efficient risk management. Your secure future starts today with Qualys Enterprise TruRisk Management. Visit qualys.com/etm for more information."
Find the stories behind the headlines at CISOseries.com.
North Korean IT worker army expands operations in Europe
Stripe API skimming campaign unveils new techniques for theft Verizon call filter API flaw exposed customers' incoming call history Thanks to today's episode sponsor, Qualys
"Overwhelmed by noise in your cybersecurity processes? Cut through the clutter with Qualys Enterprise TruRisk Management. Quantify your cyber risk in clear financial terms and focus on what matters most. Actionable insights help you prioritize critical threats, streamline remediation, and accelerate risk reduction— while effectively communicating impact to stakeholders. Empower your cybersecurity strategy with tools that drive faster, smarter, and more efficient risk management. Your secure future starts today with Qualys Enterprise TruRisk Management. Visit qualys.com/etm for more information."
Mozilla Thunderbird finally takes on Gmail with new email service Surge in scans on PAN GlobalProtect VPNs hints at attacks Microsoft Using AI to Uncover Critical Bootloader Vulnerabilities Thanks to today's episode sponsor, Qualys
"Overwhelmed by noise in your cybersecurity processes? Cut through the clutter with Qualys Enterprise TruRisk Management. Quantify your cyber risk in clear financial terms and focus on what matters most. Actionable insights help you prioritize critical threats, streamline remediation, and accelerate risk reduction— while effectively communicating impact to stakeholders. Empower your cybersecurity strategy with tools that drive faster, smarter, and more efficient risk management. Your secure future starts today with Qualys Enterprise TruRisk Management. Visit qualys.com/etm for more information."
FTC sends warning to future 23andMe buyer
Global phishing threat targets 88 countries
Samsung data breach tied to old stolen credentials
Thanks to today's episode sponsor, Qualys
"Overwhelmed by noise in your cybersecurity processes? Cut through the clutter with Qualys Enterprise TruRisk Management. Quantify your cyber risk in clear financial terms and focus on what matters most. Actionable insights help you prioritize critical threats, streamline remediation, and accelerate risk reduction— while effectively communicating impact to stakeholders. Empower your cybersecurity strategy with tools that drive faster, smarter, and more efficient risk management. Your secure future starts today with Qualys Enterprise TruRisk Management. Visit qualys.com/etm for more information."
FBI warns of increase in free online document converter scams
Resurge malware exploits Ivanti flaw
BlackLock hackers exposed through leak site vulnerability
Thanks to today's episode sponsor, Qualys
"Overwhelmed by noise in your cybersecurity processes? Cut through the clutter with Qualys Enterprise TruRisk Management. Quantify your cyber risk in clear financial terms and focus on what matters most. Actionable insights help you prioritize critical threats, streamline remediation, and accelerate risk reduction— while effectively communicating impact to stakeholders. Empower your cybersecurity strategy with tools that drive faster, smarter, and more efficient risk management. Your secure future starts today with Qualys Enterprise TruRisk Management. Visit qualys.com/etm for more information."
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Jonathan Waldrop, CISO, The Weather Company
Jonathan will be speaking at The CrowdStrike Crowd Tour, on Tuesday, April 15, 2025 in Atlanta – details here.
He will also be speaking at the C Vision International Think Tank on April 24, 2025, also in Atlanta – details here.
Thanks to our show sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.
All links and the video of this episode can be found on CISO Series.com
150,000 sites compromised by JavaScript injection
Vulnerabilities in numerous solar power systems found
T-Mobile pays $33 million in SIM swap lawsuit
Huge thanks to our episode sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.
Find the stories behind the headlines at CISOseries.com.
New ransomware group claims attack on US Telecom firm WideOpenWest
NSA warned of vulnerabilities in Signal app a month before Houthi strike chat
New ReaderUpdate malware variants target macOS users Huge thanks to our episode sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.
EncryptHub linked to Microsoft Management Console exploit
Security Copilot gets AI agents
A call for more PETs in government
Huge thanks to our episode sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.
More than 300 cyber criminals arrested in Africa
23andMe bankruptcy puts millions of DNA records at risk
Ukraine’s state railway partially down after attack
Huge thanks to our episode sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.
U.S. Treasury lifts sanctions on Tornado Cash
Web service outage in Russia due to reported Cloudflare block
Microsoft Trust Signing service abused to code-sign malware
Huge thanks to our episode sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Christina Shannon, CIO, KIK Consumer Products
Thanks to our show sponsor, DeleteMe
Data brokers bypass online safety measures to sell your name, address, and social security number to scammers. DeleteMe scours the web to find – and remove – your private information before it gets into the wrong hands by scanning for exposed information, and completing opt-outs and removals. With over 100 Million personal listings removed, DeleteMe is your trusted privacy solution for online safety. Get 20% off your DeleteMe plan when you go to JoinDeleteMe.com/CISO and use promo code CISO at checkout.
All links and the video of this episode can be found on CISO Series.com
Stalkerware company SpyX suffers data breach
Nation-state groups hit organizations with Microsoft Windows zero-day
Swiss telecom Ascom the latest victim of HellCat’s Jira campaign
Thanks to this week episode sponsor, DeleteMe
Data brokers bypass online safety measures to sell your name, address, and social security number to scammers.
DeleteMe scours the web to find – and remove – your private information before it gets into the wrong hands by scanning for exposed information, and completing opt-outs and removals.
With over 100 Million personal listings removed, DeleteMe is your trusted privacy solution for online safety.
Get 20% off your DeleteMe plan when you go to JoinDeleteMe.com/CISO and use promo code CISO at checkout.
Find the stories behind the headlines at CISOseries.com
Attackers swipe data from Pennsylvania teachers union
Infosys settles $17.5M lawsuit after third-party breach
Top U.S. sperm bank discloses data breach
Thanks to this week episode sponsor, DeleteMe
Data brokers bypass online safety measures to sell your name, address, and social security number to scammers.
DeleteMe scours the web to find – and remove – your private information before it gets into the wrong hands by scanning for exposed information, and completing opt-outs and removals.
With over 100 Million personal listings removed, DeleteMe is your trusted privacy solution for online safety.
Get 20% off your DeleteMe plan when you go to JoinDeleteMe.com/CISO and use promo code CISO at checkout.
For the stories behind the headlines, visit CISOseries.com.
CISA scrambles to contact fired employees after court rules layoffs ‘unlawful’
Google acquires cybersecurity firm Wiz for $32 billion US Commerce department bureaus ban China's DeepSeek on government devices, sources say Thanks to this week episode sponsor, DeleteMe
Data brokers bypass online safety measures to sell your name, address, and social security number to scammers.
DeleteMe scours the web to find – and remove – your private information before it gets into the wrong hands by scanning for exposed information, and completing opt-outs and removals.
With over 100 Million personal listings removed, DeleteMe is your trusted privacy solution for online safety.
Get 20% off your DeleteMe plan when you go to JoinDeleteMe.com/CISO and use promo code CISO at checkout.
23,000 repositories targeted in popular GitHub action
Apache Tomcat RCE exploit hits servers—no authentication required
Microsoft 365 users targeted in new BEC campaigns
Thanks to this week episode sponsor, DeleteMe
Data brokers bypass online safety measures to sell your name, address, and social security number to scammers.
DeleteMe scours the web to find – and remove – your private information before it gets into the wrong hands by scanning for exposed information, and completing opt-outs and removals.
With over 100 Million personal listings removed, DeleteMe is your trusted privacy solution for online safety.
Get 20% off your DeleteMe plan when you go to JoinDeleteMe.com/CISO and use promo code CISO at checkout.
Black Basta creates tool to automate VPN brute-force attacks
Bipartisan Senate bill offers improved cybersecurity for water utilities
LockBit developer extradited from Israel, appears in New Jersey court
Thanks to this week episode sponsor, DeleteMe
Data brokers bypass online safety measures to sell your name, address, and social security number to scammers.
DeleteMe scours the web to find – and remove – your private information before it gets into the wrong hands by scanning for exposed information, and completing opt-outs and removals.
With over 100 Million personal listings removed, DeleteMe is your trusted privacy solution for online safety.
Get 20% off your DeleteMe plan when you go to JoinDeleteMe.com/CISO and use promo code CISO at checkout.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
Thanks to our show sponsor, Vanta
Do you know the status of your compliance controls right now? Like…right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, And helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines
All links and the video of this episode can be found on CISO Series.com
Medusa ransomware continues to attack infrastructure
DoJ seeks to break up Google
Another phishing campaign hits Booking.com
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, And helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines
Find the stories behind the headlines at CISOseries.com.
Microsoft Patches 57 Security Flaws, Including 6 Actively Exploited Zero-Days
US communications regulator to create council to counter China technology threats
Signal no longer cooperating with Ukraine on Russian cyberthreats, official says
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, And helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines
Sean Plankey nominated to head CISA
Ballista Botnet hits TP-Link devices
PowerSchool publishes breach report
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, And helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines
Four healthcare breaches expose over 560,000 records
Cyber attack allegedly behind X outages
Case against MGM ransomware attack dropped
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, And helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines
ONCD set to consolidate power in U.S. cyber
Undocumented commands found in Bluetooth chip used by a billion devices
Japanese telecom NTT breach affects 18,000 companies
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, And helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by David Spark with guest Brett Perry, CISO, Dot Foods
Thanks to our show sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.
All links and the video of this episode can be found on CISO Series.com
Ransomware gang bypasses EDR via a webcam
Toronto Zoo updates January 2024 attack damage
House bill requires federal contractors to implement vulnerability disclosure policies
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.
Then add: Find the stories behind the headlines at CISOseries.com.
Former top NSA cyber official protests probationary firings
Differing names for hackers hinders law enforcement, says security agent
Google releases AI scam detection for Android to fight conversational fraud
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.
Find the stories behind the headlines at CISOseries.com.
Apple goes to court to fight UK demand for iCloud encryption backdoor 3 VMware Zero-Day bugs allow sandbox escape The Firefox I loved is gone - how to protect your privacy on it now Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.
CISA denies claims of deprioritizing Russian threats
Ransomware group claims attack on U.S. newspaper publisher
Latin America's escalating cybersecurity crisis
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.
Hegseth orders Cyber Command to stand down on Russia planning
Microsoft hangs up on Skype after 14 years
Mark Cuban offers to fund government tech unit that was cut
Huge thanks to our sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Andrew Wilder, CISO, Vetcor
Thanks to our show sponsor, Conveyor
Let me guess, another security questionnaire just landed in your inbox. Which means all the follow up tasks you don’t have time for are close behind. What are you going to do? Here’s a better question: what would Sue do? Sue is Conveyor’s new AI Agent for Customer Trust. She handles the entire security review process like answering every customer request for a SOC 2 from sales, completing every questionnaire or executing every communications and coordination task in-between. No more manual work. Just a quick review when she’s done. Ready to let Sue take the reins? Learn more at www.conveyor.com.
All links and the video of this episode can be found on CISO Series.com
Chinese cyber espionage jumped 150% last year
Nakasone warns of U.S. falling behind adversaries in cyberspace
PolarEdge botnet exploits Cisco, ASUS, QNAP, and Synology
Huge thanks to our sponsor, Conveyor
Let me guess, another security questionnaire just landed in your inbox. Which means all the follow up tasks you don’t have time for are close behind. What are you going to do? Here’s a better question: what would Sue do? Sue is Conveyor’s new AI Agent for Customer Trust. She handles the entire security review process like answering every customer request for a SOC 2 from sales, completing every questionnaire or executing every communications and coordination task in-between. No more manual work. Just a quick review when she’s done. Ready to let Sue take the reins? Learn more at www.conveyor.com.
Find the stories behind the headlines at CISOseries.com.
Thousands of exposed GitHub repositories, now private, can still be accessed through Copilot Cellebrite halts product use in Serbia following Amnesty surveillance report New Ghostwriter campaign targets Ukrainian Government and opposition activists in Belarus Huge thanks to our sponsor, Conveyor
It’s 2025. This is your second sign to get a trust center if you don’t already have one. Reduce manual work by 80% when you can share one link to your trust center and let customers download what they need on demand. Trusted by the world’s top B2B companies, Conveyor’s enterprise-grade trust center is specially designed to handle multiple products, complex orgs, and with AI first so you can even push your customers to self-serve their own AI answers to questionnaires. Learn more at www.conveyor.com.
US employee screening firm confirms breach
Swedish law enforcement seeking messaging app backdoors
Dems warn of exposed entry points on government systems
Huge thanks to our sponsor, Conveyor
Ever wish you had a teammate that could handle the most annoying parts of customer security reviews? You know, chasing down SMEs for answers, updating systems, coordinating across teams—all the grunt work nobody wants to do. Plus, having to finish the dang questionnaire itself. Well. That teammate exists—Conveyor just launched Sue, the first AI Agent for Customer Trust. Sue really is the dream teammate. She never misses a deadline, answers every customer request from sales, completes every questionnaire and knocks out all the coordination in-between. Sue, Conveyor’s AI agent, handles it all so you don’t have to. Learn more at www.conveyor.com.
Australia bans Kaspersky over security concerns
Government screens hijacked with AI Video of President Trump and Musk
EU sanctions North Korean official linked to Lazarus Group
Huge thanks to our sponsor, Conveyor
Does trying to get the security questionnaire done and back to your customer ever feel like you’re herding cats? It’s not just answering questions. It’s all of the manual back and forth that becomes a slog like communicating between teams, tracking people down to get their review, updating sources and updating systems. Between all of this, you’re also expected to field security documentation requests from customers. Well, Conveyor just launched an AI agent, Sue, to do all of these things and more for you. Learn about Sue at www.conveyor.com.
Hacker steals nearly $1.5 billion from Bybit crypto wallet
Apple pulls iCloud end-to-end encryption in the UK
PayPal "New Address" feature abused in phishing scam
Huge thanks to our sponsor, Conveyor
It’s 2025. This is your sign to get a trust center if you don’t already have one. Speed up security reviews and reduce the headaches when you can share one link to your trust center and let customers download what they need on demand. Trusted by the world’s top B2B companies, Conveyor’s enterprise-grade trust center is specially designed to handle multiple products, complex orgs, and with AI first so you can even push your customers to self-serve their own AI answers to questionnaires. Learn more at www.conveyor.com.
For the stories behind the headlines, visit CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest TC Niedzialkowski, former CISO
Thanks to our show sponsor, Scrut Automation
Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.
All links and the video of this episode can be found on CISO Series.com
Minerals company loses $500,000 to BEC scam
Australian IVF provider investigating cyber incident
SEC replaces cryptocurrency fraud unit with emerging tech team
Thanks to today's episode sponsor, Scrut Automation
Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.
Find the stories behind the headlines at CISOseries.com.
Russian hackers tap into Signal conversations
Ransomware group hits critical infrastructure globally
CISA says patch Palo Alto flaw immediately
Thanks to today's episode sponsor, Scrut Automation
Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.
New OpenSSH Flaws Enable Man-in-the-Middle and DoS Attacks — Patch Now
Microsoft reminds admins to prepare for WSUS driver sync deprecation
Zwipe runs out of time for biometric card revenues, files for bankruptcy
Thanks to today's episode sponsor, Scrut Automation
Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.
Dutch Police take down Zservers
Chase to block Zelle payments to sellers on social media
Finastra notifies victims of October data breach
Thanks to today's episode sponsor, Scrut Automation
Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.
For the stories behind the headlines, visit CISOseries.com.
Hackers steal emails in device code phishing attacks
Anti-TOAD feature seeks to prevent in-call sideloading attacks
Chinese hackers breach more U.S. telecoms via unpatched Cisco routers
Thanks to today's episode sponsor, Scrut Automation
Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Doug Mayer, vp, CISO, WCG
Thanks to our show sponsor, Vanta
Do you know the status of your compliance controls right now? Like…right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines
All links and the video of this episode can be found on CISO Series.com
U.S. lawmakers demand UK retraction of Apple backdoor
Sarcoma ransomware claims breach at giant PCB maker Unimicron
Ransomware attack disrupts Michigan’s Sault Tribe operations
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines
Find the stories behind the headlines at CISOseries.com.
DOGE is hacking America This Ad-Tech company is powering surveillance of US military personnel Apple and Google take down malicious mobile apps from their app stores Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines
LockBit host sanctioned
A peak at DeepSeek’s weak security
Sandworm targeting Ukraine with trojanized KMS
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines
Urgent iOS update fixes critical USB security flaw
CISA officials placed on administrative leave
Attack disrupts newspaper giant’s operations
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines
Shock and lawsuit over security failures in DOGE takeover
CISA adds Microsoft Outlook and Sophos XG Firewall to its Known Exploited Vulnerabilities catalog
DeepSeek App transmits sensitive user and device data without encryption
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Caitlin Sarian, owner and CEO, Cybersecurity Girl LLC
Thanks to our show sponsor, ThreatLocker
ThreatLocker (R) is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.
All links and the video of this episode can be found on CISO Series.com
Critical RCE bug in Microsoft Outlook now exploited in attacks
Kimsuky uses forceCopy malware to steal browser-stored credentials
Treasury agrees to block additional DOGE staff from accessing sensitive payment systems
Huge thanks to our episode sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.
Find the stories behind the headlines at CISOseries.com.
Spain arrests hacker of U.S. and Spanish military agencies
Robocallers called the FCC pretending to be from the FCC
Ransomware payments decreased 35% year-over-year
Huge thanks to our episode sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.
For the stories behind the headlines, visit CISOseries.com.
Meta says it may stop development of AI systems it deems too risky
Ferret Malware Added to 'Contagious Interview' Campaign Credential Theft Becomes Cybercriminals' Favorite Target Huge thanks to our episode sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.
Find the stories behind the headlines at CISOseries.com.
Exploited vulnerabilities up significantly from previous year
First U.S. state to declare ban on DeepSeek
Crypto scams make comeback on X
Huge thanks to our episode sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.
Google describes APTs using Gemini AI
India’s Tata Technologies suffers ransomware attack
Meta confirms new zero-click WhatsApp spyware
Huge thanks to our episode sponsor, ThreatLocker
ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Alexandra Landegger, Global Head of Cyber Strategy & Transformation, RTX
Thanks to our show sponsor, Conveyor
Let me guess, another security questionnaire just landed in your inbox. Which means all the follow up tasks you don’t have time for are close behind. What are you going to do? Here’s a better question: what would Sue do? Sue is Conveyor’s new AI Agent for Customer Trust. She handles the entire security review process like answering every customer request from sales, completing every questionnaire or executing every communications and coordination task in-between. No more manual work. Just a quick review when she’s done. Ready to let Sue take the reins? Learn more at www.conveyor.com.
All links and the video of this episode can be found on CISO Series.com
New York Blood Center suffers ransomware attack
DeepSeek’s exposed database leaks sensitive data
CISA’s future unclear under new administration
Huge thanks to our sponsor, Conveyor
Let me guess, another security questionnaire just landed in your inbox. Which means all the follow up tasks you don’t have time for are close behind. What are you going to do? Here’s a better question: what would Sue do? Sue is Conveyor’s new AI Agent for Customer Trust. She handles the entire security review process like answering every customer request from sales, completing every questionnaire or executing every communications and coordination task in-between. No more manual work. Just a quick review when she’s done. Ready to let Sue take the reins? Learn more at www.conveyor.com.
Find the stories behind the headlines at CISOseries.com.
Tenable acquiring Israel’s Vulcan Cyber in $150 million deal Chinese and Iranian Hackers Are Using U.S. AI Products to Bolster Cyberattacks U.S. Navy bans use of DeepSeek due to ‘security and ethical concerns’ Huge thanks to our sponsor, Conveyor
Ever wish you had a teammate that could handle the most annoying parts of customer security reviews? You know, chasing down SMEs for answers, updating systems, coordinating across teams—all the grunt work nobody wants to do. Plus, having to finish the dang questionnaire itself. Well. That teammate exists—Conveyor just launched Sue, the first AI Agent for Customer Trust. Sue really is the dream teammate. She never misses a deadline, answers every customer request from sales, completes every questionnaire and knocks out all the coordination in-between. Sue handles it all so you don’t have to. Learn more at www.conveyor.com.
Most ransomware victims shut down operations shutdowns
EU sanctions GRU members for Estonia cyberattacks
Lynx ransomware runs a tight ship
Huge thanks to our sponsor, Conveyor
Tired of herding cats to complete customer security questionnaires?
Your team probably spends hours daily juggling the back and forth of completing these security requests.
That's why Conveyor created Sue, the first AI Agent for Customer Trust. Sue doesn't just handle completing security questionnaires and sending SOC 2 to prospects – she manages all the communication and follow-up too.
You simply get notified when everything's done so you can do a quick review. Stop wrangling cats and see what Sue can do for you at www.conveyor.com.
Google responds to “most sophisticated” voice phishing attack
Security consortium creates Opengrep
DeepSeek suspends new user registrations
Huge thanks to our sponsor, Conveyor
Tired of herding cats to complete customer security questionnaires? Your team probably spends hours daily juggling the back and forth of completing these security requests. That's why Conveyor created Sue, the first AI Agent for Customer Trust. Sue doesn't just handle completing security questionnaires and sending SOC 2 to prospects – she manages all the communication and follow-up too. You simply get notified when everything's done so you can do a quick review. Stop wrangling cats and see what Sue can do for you at www.conveyor.com.
DHS Advisory Committee memberships halted
UnitedHealth updates number of data breach victims to 190 million
Meta’s Llama Framework flaw exposes AI systems to remote code execution risks
Huge thanks to our sponsor, Conveyor
Conveyor launched the first AI Agent for Customer Trust. So wtf does that mean? It means the AI agent goes beyond just sharing NDA-gated documents like a SOC 2 with customers or answering security questionnaires. Conveyor’s AI Agent, Sue, handles the entire security review process from start to finish. She answers every customer request from sales, completes every questionnaire and executes every communications and coordination task in-between. It's perfect for B2B infosec teams sick of manual security review work. Check it out at www.conveyor.com.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Shaun Marion, vp, CSO, Xcel Energy
Thanks to our show sponsor, Vanta
Do you know the status of your compliance controls right now? Like…right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, And helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines.
All links and the video of this episode can be found on CISO Series.com
TSA cyber chief David Pekoske ousted by new administration
CISOs gain boardroom traction Influence but still lack soft skills, says Splunk
Cisco Fixes vulnerability in Meeting Management
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, And helps you get security questionnaires done 5 times faster with AI.
Now that’s…a new way to GRC. Get started at Vanta.com/headlines.
Find the stories behind the headlines at CISOseries.com.
Trump administration fires members of cybersecurity review board in ‘horribly shortsighted’ decision Major Cybersecurity Vendors' Credentials Found on Dark Web PowerSchool hacker claims they stole data of 62 million students Thanks to today’s episode sponsor, Vanta Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, And helps you get security questionnaires done 5 times faster with AI.
Now that’s…a new way to GRC. Get started at Vanta.com/headlines.
7-Zip flaw bypasses Windows security warnings
Attackers impersonate Ukraine’s CERT-UA
AI Executive Order revoked
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, And helps you get security questionnaires done 5 times faster with AI.
Now that’s…a new way to GRC. Get started at Vanta.com/headlines.
HPE investigates breach claims
Former CIA analyst pleads guilty to sharing Top Secret files
Data of nearly half million hotel guests exposed
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, And helps you get security questionnaires done 5 times faster with AI.
Now that’s…a new way to GRC. Get started at Vanta.com/headlines.
For the stories behind the headlines, visit CISOseries.com.
Tik Tok is back, with strings attached
Noem promises to curtail CISA
Label company Avery announces data breach
Huge thanks to our sponsor, Vanta
Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, And helps you get security questionnaires done 5 times faster with AI.
Now that’s…a new way to GRC. Get started at Vanta.com/headlines.
Then add: Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Phil Beyer, head of security, Flex
Thanks to our show sponsor, Dropzone.ai
What if your SOC could handle 10x the alerts without burning out your team? Dropzone AI automates Tier 1 investigations and frees your analysts to tackle bigger challenges. It’s how smart teams are staying ahead. See how it works—schedule a demo today at dropzone.ai.
All links and the video of this episode can be found on CISO Series.com
Biden signs cybersecurity executive order
Star Blizzard targeting WhatsApp
US healthcare sector saw 585 breaches in 2024
Huge thanks to our sponsor, Dropzone AI
What if your SOC could handle 10x the alerts without burning out your team? Dropzone AI automates Tier 1 investigations and frees your analysts to tackle bigger challenges. It’s how smart teams are staying ahead. See how it works—schedule a demo today at dropzone.ai.
For the stories behind the headlines, head on over to CISOSeries.com
Huge thanks to our sponsor, Dropzone AI
Alert fatigue is real, and it’s draining. Dropzone AI takes on the tedious investigations, so you can focus on making an impact where it matters most. It’s smarter tools for a smarter SOC. Check it out at dropzone.ai.
For the stories behind the headlines, head on over to CISOSeries.com
Snyk mysteriously deploys apparently malicious packages
Baltic sea cable cuts can’t be accident, says EU tech chief
CISA warns of second BeyondTrust vulnerability
Huge thanks to our sponsor, Dropzone AI
Does your SOC feel like it’s drowning in alerts? Dropzone AI cuts through the noise, triaging 100% of alerts and giving you clear, actionable insights. Ready to break free? Check out the demo at dropzone.ai.
For the stories behind the headlines, head on over to CISOSeries.com
Telefonica breach exposes internal data and employee credentials
New ransomware group leverages AI
Allstate accused of selling consumer driving data
Huge thanks to our sponsor, Dropzone AI
Running a SOC is tough—too many alerts, not enough time. Dropzone AI changes that. It reduces manual investigations by up to 90%, giving your team the bandwidth to focus on strategic threats. Imagine the impact on your operations. Visit dropzone.ai today.
For the stories behind the headlines, head on over to CISOSeries.com
IRS Identity Protection PIN now available for filing season
CISA sees enrollment surge in cyberhygiene for critical infrastructure
City services in Winston-Salem affected by cyberattack
Huge thanks to our sponsor, Dropzone AI
Feeling buried under endless alerts? We get it. Dropzone AI takes over the grind—investigating every alert 24/7. No more chasing false positives or wasting time on noise. It’s all about clarity and focus. Ready to transform your day? Head to dropzone.ai to learn more.
For the stories behind the headlines, head on over to CISOSeries.com
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Bil Harmer, operating partner and CISO, Craft Ventures
Thanks to our show sponsor, Nudge Security
Nudge Security helps you mitigate security risks stemming from SaaS sprawl by discovering every SaaS account ever created by anyone in your org within minutes of starting a free trial. And, you can automate on-going governance tasks like security posture checks, user access reviews, employee offboarding, and more. Start a free 14-day trial
All links and the video of this episode can be found on CISO Series.com
Proton recovers from worldwide outage
BayMark Health Services announces data breach
U.S. Treasury breach linked to Silk Typhoon group
Huge thanks to our sponsor, Nudge Security
Are you struggling to secure your exploding SaaS footprint? With Nudge Security, you can discover all SaaS apps and accounts, manage access, ensure secure configurations, vet unfamiliar tools, and automate daily identity security tasks. Start a free 14-day trial
Find the stories behind the headlines at CISOseries.com.
PowerSchool hacked
Lawmakers expected to revive attempts for new Cyber Force study
European Commission receives first GDPR fine
Huge thanks to our sponsor, Nudge Security
Nudge Security is the only solution for SaaS security and governance that can discover up to two years of historical SaaS spend along with usage insights so you can uncover wasted spend and sources of unnecessary risk. Start a free 14-day trial today
Cyber Trust marks to roll out in 2025
UK to criminalize sexually explicit deepfakes
CISA says government hack limited to Treasury
Huge thanks to our sponsor, Nudge Security
Nudge Security provides advanced security posture management for Okta, Microsoft 365, and Google Workspace. With Nudge, you’ll be alerted of identity security risks like weak or missing MFA, inactive admin accounts, and risky integrations, plus you can automate remediation tasks and on-going identity governance. Start a free 14-day trial today
Wallet drainer malware makes major impact
U.S. telecom breach list grows
Urgent warning on Moxa router vulnerabilities
Huge thanks to our sponsor, Nudge Security
Nudge Security discovers every GenAI tool ever used in your org, even those you’ve never heard of. For each tool, you’ll see who introduced it, who else is using it, where it’s integrated into other tools, and a vendor security profile. Get your free GenAI inventory today.
U.S. sanctions China’s Integrity Technology for role in Flax Typhoon attacks
French military contractor Atos dismisses ransomware attack claims
German airports hit by IT outage
Huge thanks to our sponsor, Nudge Security
Nudge Security helps you mitigate security risks stemming from SaaS sprawl by discovering every SaaS account ever created by anyone in your org within minutes of starting a free trial. And, you can automate on-going governance tasks like security posture checks, user access reviews, employee offboarding, and more. Start a free 14-day trial.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Quincy Castro, CISO, Redis
Thanks to our show sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker. ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team. To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
All links and the video of this episode can be found on CISO Series.com
Beijing-linked hackers penetrated U.S. Treasury systems
Russian tanker suspected of undersea data cable sabotage
Lumen says it has locked the Salt Typhoon group out of its network
Thanks to today's episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
For the story behind the headlines, go to CISOSeries.com
U.S. soldier arrested for alleged leak of Trump and Harris call logs
Iranian and Russian entities sanctioned for election interference
Rhode Island’s health benefits data leaked
Thanks to today's episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
For the story behind the headlines, go to CISOSeries.com
Cisco confirms data leak
Microsoft announces urgent .NET domain transition
Stories of the year from Cyber Security Headlines reporters
Thanks to today's episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
For the story behind the headlines, go to CISOSeries.com
Cybersecurity company’s Chrome extension hijacked for data theft
Hackers steal ZAGG customer credit cards in third-party breach
Volkswagen software company Cariad suffers Amazon cloud breach
Thanks to today's episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
For the story behind the headlines, go to CISOSeries.com
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Steve Zalewski, CISO in Residence
Thanks to our show sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker. ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team. To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
All links and the video of this episode can be found on CISO Series.com
General Dynamics says employees targeted in phishing attack
Japan Airlines systems are back to normal after cyberattack
American Addiction Centers suffers data breach
Thanks to today's episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
For the story behind the headlines, go to CISOSeries.com
State Department’s disinformation office to close after funding terminated
Pittsburgh Regional Transit suffers ransomware attack
Another Mirai botnet targets NVRs and TP-Link routers
Thanks to today's episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
For the story behind the headlines, go to CISOSeries.com
Using LLMs to generate malware variants
NSO liable for WhatsApp hacks
OpenAI fined for privacy violations
Thanks to today's episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
For the story behind the headlines, go to CISOSeries.com
PaaS platform “FlowerStorm” attacking Microsoft 365 users
CISA adds BeyondTrust flaw to its Known Exploited Vulnerabilities catalog
Ascension Health ransomware attack impacted nearly 6 million people
Thanks to today's episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
For the story behind the headlines, go to CISOSeries.com
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Bethany De Lude, CISO, The Carlyle Group
Thanks to our show sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker. ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team. To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
All links and the video of this episode can be found on CISO Series.com
Android malware found on Amazon Appstore disguised as health app
BeyondTrust suffers cyberattack
Fortinet warns of critical flaw in Wireless LAN Manager
Thanks to today’s episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
For the stories behind the headlines, head of CISOSeries.com.
Interpol kills off Pig Butchering
Supreme Court to hear TikTok ban challenge
US weighs TP-Link ban
Thanks to today’s episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
For the stories behind the headlines, head of CISOSeries.com.
CISA delivers new directive for securing cloud environments
Texas Tech reports a data breach affecting 1.4 million people
Meta fined $263 million for alleged GDPR violations
Thanks to today’s episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
For the stories behind the headlines, head of CISOSeries.com.
Serbian authorities accused of using Cellebrite to spy on journalists
Ransomware attack shuts down Rhode Island’s public assistance system
ConnectOnCall breach exposes close to a million patients
Thanks to today’s episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
For the stories behind the headlines, head of CISOSeries.com.
UnitedHealth’s AI-driven insurance claims chatbot left exposed to the internet
South Carolina credit union suffers cyberattack
IOCONTROL cyberweapon targets infrastructure in the US and Israel
Thanks to today’s episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
For the stories behind the headlines, head of CISOSeries.com.
Link to episode page
This week’s Cyber Security Headlines - Week in Review is hosted by Rich Stroffolino with guest Jimmy Sanders, president, ISSA International. ISSA International April 2025- will be celebrating its 40th Anniversary in April 2025. Watch for notifications at ISSA.org
Thanks to today’s episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker. ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team. To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
All links and the video of this episode can be found on CISO Series.com
Microsoft MFA bypassed in AuthQuake attack
Cybercrime marketplace Rydox taken down
U.S. charges Chinese national for hacking thousands of Sophos firewall devices
Thanks to today’s episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
For the stories behind the headlines, head of CISOSeries.com.
Operation PowerOFF hits DDoS sites
FCC proposes new telco cybersecurity rules
ZLoader returns
Thanks to today’s episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
For the stories behind the headlines, head of CISOSeries.com.
Senator announces new bill to secure telecom companies
Google unveils new quantum chip
U.S. sanctions Chinese cybersecurity firm for firewall hacks
Thanks to today’s episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
For the stories behind the headlines, head of CISOSeries.com.
Romanian energy giant battles ongoing attack
Ransomware disrupts medical device maker
Deloitte responds to data theft claims
Thanks to today’s episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
For the stories behind the headlines, head of CISOSeries.com.
Anna Jaques Hospital confirms details of Christmas Day ransomware breach
Microsoft expands Recall preview to Intel and AMD Copilot+ PCs
Blue Yonder announces restoration progress after November 21 attack
Thanks to today’s episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
For the stories behind the headlines, head of CISOSeries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Sean Kelly with guest Edward Frye, head of security, Luminary Cloud.
Thanks to our show sponsor, Vanta
As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews. Visit vanta.com to learn more about Questionnaire Automation.
All links and the video of this episode can be found on CISO Series.com
Feds find cybercriminal tools used by sextortion group
Russian hackers hack hackers
Amazon’s post-quantum migration plan
Huge thanks to our sponsor, Vanta
As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews. Visit vanta.com to learn more about Questionnaire Automation.
Get the stories behind the headlines at CISOSeries.com
FBI and CISA urge Americans to use encrypted apps rather than calling, iVerify scanner finds seven Pegasus spyware infections, Japan warns of IO-Data zero-day router flaws exploited in attacks
Huge thanks to our sponsor, Vanta
As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews. Visit vanta.com to learn more about Questionnaire Automation.
Get the stories behind the headlines at CISOSeries.com
Stoli files for bankruptcy in U.S. after ransomware attack
Police seize largest German online criminal marketplace
FBI advises telecoms to boost security following Chinese hacking campaign
Huge thanks to our sponsor, Vanta
As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews. Visit vanta.com to learn more about Questionnaire Automation.
Get the stories behind the headlines at CISOSeries.com
Hydra Market leader sentenced to life
Former Polish spy chief arrested in Pegasus spyware probe
SpyLoan malware targets millions
Huge thanks to our sponsor, Vanta
As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews. Visit vanta.com to learn more about Questionnaire Automation.
Get the stories behind the headlines at CISOSeries.com
Ransomware affiliate Mikhail Matveev arrested
Another UK hospital system hacked
Cloudflare says it lost 55% of logs pushed to customers for 3.5 hours
Huge thanks to our sponsor, Vanta
As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews. Visit vanta.com to learn more about Questionnaire Automation.
Get the stories behind the headlines at CISOSeries.com
Patch alert after flaws identified in Advantech industrial Wi-Fi access points
T-Mobile confirms Salt Typhoon attack was blocked
UK hospital network postpones procedures after cyberattack
Huge thanks to our sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
Find the stories behind the headlines at CISOseries.com.
Interpol takes down over 1,000 cybercrime suspects in Africa
Starbucks and UK grocers impacted by supply chain attack
Hacker in Snowflake extortions may be a U.S. soldier
Huge thanks to our sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
For the stories behind the headlines, visit CISOseries.com.
Microsoft 365 outage update
“Hair on Fire” over China’s cyber campaign
North Korean fake IT worker scheme unveiled
Huge thanks to our sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
DoJ seizes credit card marketplace PopeyeTools
Gambling giant IGT suffers cyberattack
Windows update blocked on some gaming PCs
Huge thanks to our sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker. ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Jimmy Benoit, vp, cybersecurity, PBS
Thanks to our show sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker. ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team. To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
All links and the video of this episode can be found on CISO Series.com
MITRE offers updated list of most dangerous software vulnerabilities
CISOs can now obtain professional liability insurance
BianLian group refines its game
Thanks to today's episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
Get the stories behind the headlines at CISOSeries.com.
US charges Scattered Spider members
Chinese threat actors infiltrate more telcos
Apple issues emergency security update
Thanks to today's episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
Get the stories behind the headlines at CISOSeries.com.
CISA director Jen Easterly to step down
Space tech giant Maxar discloses employee data breach
Microsoft launches Zero Day Quest hacking event
Thanks to today's episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
Get the stories behind the headlines at CISOSeries.com.
EPA warns of critical risks in drinking water infrastructure
Four million WordPress sites exposed
Sextortion scams bypass Microsoft security filters
Thanks to today's episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
Get the stories behind the headlines at CISOSeries.com.
T-Mobile confirms telecom breach hack
Customer data stolen from AnnieMac
New Glove infostealer malware bypasses Chrome’s cookie encryption
Thanks to today's episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
Get the stories behind the headlines at CISOSeries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Brett Conlon, CISO, American Century Investments
Thanks to our show sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker. ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team. To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
All links and the video of this episode can be found on CISO Series.com
China threat actors breached U.S. broadband providers to spy on U.S. government officials
123456 tops the list of most popular passwords again
Hacker gets 10 years in prison for U.S. healthcare extortion scheme
Thanks to today's episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker. ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team. To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
Get the stories behind the headlines at CISOSeries.com
Volt Typhoon rebuilding botnet
Chinese group targets Tibetan media
DoD leaker sentenced
Thanks to today's episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker. ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team. To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
Get the stories behind the headlines at CISOSeries.com
Dutch cybersecurity incident affects Giant Food and Hannaford
Indictment against Snowflake breach suspects is released
Surge in zero-day vulnerability exploits is new normal, says Five Eyes
Thanks to today's episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker. ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team. To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
Get the stories behind the headlines at CISOSeries.com
Cyberattack cost Halliburton $35 million thus far
DDoS attack makes credit card readers malfunction in Israel
Debt relief firm Forth announces data breach for customers and non-customers
Thanks to today's episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker. ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team. To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
Get the stories behind the headlines at CISOSeries.com
U.S. financial regulator calls for reduced cell phone use at
FBI warns of spike in hacked police emails and fake subpoenas
Cyberscoundrels target UK senior citizens with Winter Fuel Payment texts
Thanks to today's episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker. ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team. To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
Get the stories behind the headlines at CISOSeries.com
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Ken Athanasiou, CISO, VF Corporation
Thanks to our show sponsor, Vanta
As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews.
Visit vanta.com to learn more about Questionnaire Automation.
All links and the video of this episode can be found on CISO Series.com
Interlock ransomware gang aims at U.S. healthcare, IT and government
Canada tells TikTok to dissolve its Canadian business
Hewlett Packard warns of critical RCE flaws in Aruba Networking software
Thanks to today's episode sponsor, Vanta
As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews.
Visit vanta.com to learn more about Questionnaire Automation.
Find the stories behind the headlines at CISOseries.com.
Nokia says it has no evidence that hackers breached company data
Nigerian cybercrime bust arrests 130 people
200,000 SelectBlinds customers impacted by e-skimmer
Thanks to today's episode sponsor, Vanta
As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews.
Visit vanta.com to learn more about Questionnaire Automation.
ElizaRAT hits India
IT outage impacts Washington courts
Alleged Snowflake hacker arrested
Thanks to today's episode sponsor, Vanta
As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews.
Visit vanta.com to learn more about Questionnaire Automation.
Schneider Electric breached for second time this year
U.S. says Russia behind fake Haitian voter video
Ohio’s capital city faces lawsuits for handling of ransomware attack
Thanks to today's episode sponsor, Vanta
As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews.
Visit vanta.com to learn more about Questionnaire Automation.
Microsoft Entra “security defaults” to make MFA setup mandatory
Ransomware attack hits German pharmaceutical wholesaler AEP
Upgraded LightSpy spyware targets iPhones with more destructive power
Thanks to today's episode sponsor, Vanta
As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews.
Visit vanta.com to learn more about Questionnaire Automation.
Find the stories behind the headlines at CISOseries.com.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest David Cross, SVP/CISO, Oracle. Also check out David’s travel blog and recent “Secure by Default” white paper at IT ISAC.
Thanks to our show sponsor, Dropzone AI
Security operations are evolving, and AI is leading the way. Dropzone AI autonomously investigates 100% of your alerts with precision, freeing up your team to focus on real threats. See how this works in action. Visit dropzone.ai and schedule a demo today.
Add to Description: All links and the video of this episode can be found on CISO Series.com
Peruvian bank warns of data theft after dark web revelations
Windows 11 Task Manager displays wrong number of running processes
CyberPanel sees vulnerabilities exploited soon after disclosure
Thanks to today's episode sponsor, Dropzone AI
Security operations are evolving, and AI is leading the way. Dropzone AI autonomously investigates 100% of your alerts with precision, freeing up your team to focus on real threats. See how this works in action. Visit dropzone.ai and schedule a demo today.
Find the stories behind the headlines at CISOseries.com.
CISA launches International Cybersecurity Plan
North Korean hackers tied to Play ransomware
FakeCall learns new tricks
Thanks to today's episode sponsor, Dropzone AI
Tired of false positives slowing your SOC down? Dropzone AI uses advanced AI to filter out the noise and focus on real threats. 24/7, every alert, no manual intervention. Want to learn more? Schedule a demo and see the power of Dropzone AI at dropzone.ai.
Five Eyes launches startup security program
Canada and the Netherlands seeing increased Chinese activity
Russia might fork the Linux community
Thanks to today's episode sponsor, Dropzone AI
Facing alert overload? Dropzone AI autonomously investigates every alert, reducing noise and providing decision-ready reports. Discover how our AI solutions can enhance your SOC’s efficiency. Check out our demo gallery and see how Dropzone AI works at dropzone.ai.
Global law enforcement gains access to RedLine and Meta infostealer networks
Russian-backed malware poses as Ukrainian anti-recruitment tool
Massive breach impacts French telecom giant
Thanks to today's episode sponsor, Dropzone AI
Imagine an AI analyst that never sleeps. Dropzone AI autonomously handles every alert, cutting manual analysis by 90%. It's like adding a new team member, but one that works 24/7. Experience the difference AI can make. Visit dropzone.ai to test drive the future of security operations.
Change Healthcare data breach confirmed as largest-ever in U.S. healthcare history
Authorities investigate telecom hacks following reports of campaign intrusions
Delta sues CrowdStrike over sensor update that prompted mass flight disruptions
Thanks to today's episode sponsor, Dropzone AI
Is your SOC overwhelmed by endless alerts? Dropzone AI’s autonomous SOC Analyst investigates 100% of alerts, around the clock. No playbooks, no code. Just actionable insights to reduce false positives and save your team time. Ready to see it in action? Schedule a demo today at dropzone.ai.
Link to episode page
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Dmitriy Sokolovskiy, senior vice president, information security, Semrush
Thanks to our show sponsor, SpyCloud
SpyCloud disrupts cybercrime by telling you what criminals know about your business, so you can take action on exposed identity data to prevent cyber attacks like ransomware. To learn more how to level the playing field against bad actors and combat cyber attacks, visit spycloud.com/headlines.
All links and the video of this episode can be found on CISO Series.com
Researchers reveal upgraded Qilin ransomware-as-a-service
CISA adds Microsoft SharePoint flaw to its KEV catalog
Rhysida ransoms Easterseals
Thanks to today's episode sponsor, SpyCloud
Ransomware continues to impact organizations. A new report released by SpyCloud shares insights from your peers in security – the majority of whom were affected by ransomware in the past year. The report has some fascinating industry-specific stats you’ll want to see – plus confirms some stark truths: that the industry you’re in can affect your likelihood of being hit with ransomware. Check it out at spycloud.com/headlines.
Find the stories behind the headlines at CISOseries.com.
CISA proposes new security requirements for personal data
Fortinet patches actively exploited zero-day
UK report on Cyber Essentials certification
Thanks to today's episode sponsor, SpyCloud
Stolen data is a hot commodity for cybercriminals. Using infostealer malware, bad actors can siphon valid session cookies from employee devices, scoring the keys to access your networks and systems. According to SpyCloud’s latest research, security teams are now seeing stolen cookies among the top three entry points for initial access for ransomware. Get the full insights, including other risk factors at spycloud.com/headlines.
Four cyber companies fined for SolarWinds disclosure failures
Zendesk helps Internet Archive after hacker breached email system
Samsung zero-day under active exploit
Thanks to today's episode sponsor, SpyCloud
Researchers at SpyCloud recently found that one in five individuals was infected with infostealer malware in the last year. Unfortunately, research now confirms that infostealer infections open the door to ransomware. But organizations with visibility into identity data stolen by malware infections are better-suited to prevent a future attack. Learn more about the connection between infostealers and ransomware in SpyCloud’s new report at spycloud.com/headlines.
Proposed rules ban U.S. companies from selling sensitive data
Cisco data stolen by IntelBroker
Nidec breach exposes 50,000+ documents
Thanks to today's episode sponsor, SpyCloud
Did you know that infostealer malware can be a precursor to ransomware? Infostealers are a trending tactic used by cybercriminals to exfiltrate valuable identity data like credentials, PII, and session cookies. According to recent SpyCloud research, 75% of organizations were affected by ransomware more than once in the past year! Visit spycloud.com/headlines to find out how to keep your organization from becoming one of the statistics.
Microsoft warns it lost some customers’ security logs for a month
Omni Family Health data breach impacts almost half a million individuals
Internet Archive breached again through stolen access tokens
Thanks to today's episode sponsor, SpyCloud
It turns out infostealer infections are a major contributing factor to a company’s ransomware risk, with some industries faring better than others. Get the new research from our sponsor, SpyCloud, and see if your ransomware defense strategy stacks up against your peers. Visit spycloud.com/headlines
Find the stories behind the headlines at CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Steve Person, CISO, Cambia Health
Thanks to our show sponsor, Conveyor
It’s spooky season, and nothing’s scarier than all of your account execs asking if you’re done with their customer security questionnaires. Don’t worry—Conveyor is here to help. Conveyor’s market leading AI automates the most time-consuming parts of customer security reviews: answering security questionnaires and sharing security docs like your SOC 2 with customers. Get instant AI answers to questionnaires and host an enterprise-grade trust center where customers can download documents and self-serve answers to their own questions. End the horror show. Try it for free at www.conveyor.com.
All links and the video of this episode can be found on CISO Series.com
Insurance giant Globe Life facing extortion attempts after data theft from subsidiary
Infamous hacker USDoD possibly arrested in Brazil
Anonymous Sudan masterminds indicted
Thanks to today’s episode sponsor, Conveyor
It’s spooky season, and nothing’s scarier than all of your account execs asking if you’re done with their customer security questionnaires. Don’t worry—Conveyor is here to help.
Conveyor’s market leading AI automates the most time-consuming parts of customer security reviews: answering security questionnaires and sharing security docs like your SOC 2 with customers.
Get instant AI answers to questionnaires and host an enterprise-grade trust center where customers can download documents and self-serve answers to their own questions.
End the horror show. Try it for free at www.conveyor.com.
Get the story behind the headlines at CISOSeries.com.
Putting AI models to the EU test
Chinese researchers don’t break classical encryption… yet
Chinese group calls for security reviews on all Intel products
Thanks to today’s episode sponsor, Conveyor
There’s so many reasons why infosec and presales teams choose Conveyor for automating their security reviews, but here are the main three:
One—Conveyor’s market-leading AI provides instant, accurate answers to any format of security questionnaire—without requiring constant knowledge base updates and maintenance.
Two—Conveyor offers an enterprise-grade trust center that automates every customer security review request, so you’re not constantly distracted with questions and SOC 2 requests.
And three—Conveyor’s sales team. They’re actually fun to work with.
Learn more at www.conveyor.com.
Get the story behind the headlines at CISOSeries.com.
VW says IT infrastructure unaffected after alleged data theft
Finland seizes servers of 'Sipultie' dark web market
Calgary Public Library services limited after cyberattack
Thanks to today’s episode sponsor, Conveyor
Does the thought of a whopper 300 question security questionnaire in your most dreaded portal give you nightmares?
Conveyor can help you sleep peacefully.
How? They are the market leaders in instant and accurate AI answers to any format of security questionnaire.
They even offer a zero-touch option for portal-based questionnaires—just paste the URL, and ConveyorAI automatically answers the questions and exports them back to the portal for you.
End the nightmares. Try it for free at www.conveyor.com.
Get the story behind the headlines at CISOSeries.com.
Pokémon game developer breached
TrickMo hits with 40 new trojan variants
Nation-state actor exploits Ivanti zero-days
Thanks to today’s episode sponsor, Conveyor
It’s spooky season, and nothing’s scarier than all of your account execs asking if you’re done with their customer security questionnaires. Don’t worry—Conveyor is here to help.
Conveyor’s market leading AI automates the most time-consuming parts of customer security reviews: answering security questionnaires and sharing security docs like your SOC 2 with customers.
Get instant AI answers to questionnaires and host an enterprise-grade trust center where customers can download documents and self-serve answers to their own questions.
End the horror show. Try it for free at www.conveyor.com.
Get the story behind the headlines at CISOSeries.com.
Iranian hackers exploit Windows flaw to elevate privileges
Microsoft deprecates PPTP and L2TP VPN protocols in Windows Server
NATO’s ‘most experienced expert on cyber rotated out of cyber section
Thanks to today’s episode sponsor, Conveyor
What’s the ultimate jumpscare?
That moment when the security questionnaire in the portal didn’t auto-save all your work.
Good news: with Conveyor, that’s one horror you won’t have to face.
Conveyor is the market leader in instant, generative AI answers for security questionnaires, no matter the format.
They even offer a zero-touch option for portal-based questionnaires where you can just paste the URL, and the AI automatically answers the questions and exports them back to the portal for you.
Don't let security questionnaires haunt your workflow. Learn more at www.conveyor.com.
Get the story behind the headlines at CISOSeries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Quincy Castro, CISO, Redis.
Thanks to our show sponsor, Vanta
As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews. Visit vanta.com to learn more about Questionnaire Automation.
All links and the video of this episode can be found on CISO Series.com
White House prioritizes secure internet routing, using memory safe languages
Federal Trade Commission and CISA warn of hurricane-related scams
Mozilla warns of Firefox zero day: patch now
Huge thanks to our sponsor, Vanta
As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews. Visit vanta.com to learn more about Questionnaire Automation.
For the stories behind the headlines, head on over to CISOSeries.com
Australian Parliament introduces standalone cybersecurity law
Qualcomm zero-day used to target Android devices
Russia and Turkey ban Discord
Huge thanks to our sponsor, Vanta
As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews. Visit vanta.com to learn more about Questionnaire Automation.
For the stories behind the headlines, head on over to CISOSeries.com
GoldenJackal uses new tools against governments
Cross-site scripting flaw found in major WordPress plugin
Ukraine’s defense ministry launched military CERT
Huge thanks to our sponsor, Vanta
As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews. Visit vanta.com to learn more about Questionnaire Automation.
For the stories behind the headlines, head on over to CISOSeries.com
Salt Typhoon attack potentially exposes wiretap data
Cyberattack hits major U.S. water utility
A not- so- happy birthday present for Russia’s president
Huge thanks to our sponsor, Vanta
As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews. Visit vanta.com to learn more about Questionnaire Automation.
For the stories behind the headlines, head on over to CISOSeries.com
Insurers should stop funding ransomware payments, says Neuberger
Google removes Kaspersky antivirus software from Play Store
Cyberattack hits Detroit-area government services
Huge thanks to our sponsor, Vanta
As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews. Visit vanta.com to learn more about Questionnaire Automation.
For the stories behind the headlines, head on over to CISOSeries.com
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Jonathan Waldrop, CISO, The Weather Company. Here’s a link to CISA’s Cybersecurity Awareness Month announcement, sent to us by Jonathan.
Thanks to our show sponsor, SpyCloud
SpyCloud disrupts cybercrime by telling you what criminals know about your business, so you can take action on exposed identity data to prevent cyber attacks like ransomware. To learn more how to level the playing field against bad actors and combat cyber attacks, visit spycloud.com/headlines.
All links and the video of this episode can be found on CISO Series.com
Cloudflare blocks largest recorded DDoS attack
Adobe Commerce and Magento stores compromised by CosmicSting bug
DOJ and Microsoft take down 107 domains used in Star Blizzard phishing attacks
Huge thanks to our sponsor, SpyCloud
Ransomware continues to impact organizations. A new report released by SpyCloud shares insights from your peers in security – the majority of whom were affected by ransomware in the past year. The report has some fascinating industry-specific stats you’ll want to see – plus confirms some stark truths: that the industry you’re in can affect your likelihood of being hit with ransomware. Check it out at spycloud.com/headlines.
Get the story behind the headlines at CISOSeries.com
Russian authorities arrest nearly 100 cybercriminals in raid
Northern Ireland police fined for exposing officer identities
Rackspace breach sparks vendor blame game
Huge thanks to our sponsor, SpyCloud
Stolen data is a hot commodity for cybercriminals. Using infostealer malware, bad actors can siphon valid session cookies from employee devices, scoring the keys to access your networks and systems. According to SpyCloud’s latest research, security teams are now seeing stolen cookies among the top three entry points for initial access for ransomware. Get the full insights, including other risk factors at spycloud.com/headlines.
Get the story behind the headlines at CISOSeries.com
UK ties LockBit affiliate to Evil Corp
Public records systems riddled with security flaws
Ransomware disrupts emergency services at Texas hospital
Huge thanks to our sponsor, SpyCloud
Researchers at SpyCloud recently found that one in five individuals was infected with infostealer malware in the last year. Unfortunately, research now confirms that infostealer infections open the door to ransomware. But organizations with visibility into identity data stolen by malware infections are better-suited to prevent a future attack. Learn more about the connection between infostealers and ransomware in SpyCloud’s new report at spycloud.com/headlines.
Get the story behind the headlines at CISOSeries.com
T-Mobile data breaches cost company $31.5 million
Iranian hackers charged for targeting 2024 U.S. election
Deepfake scam hits U.S. senate
Huge thanks to our sponsor, SpyCloud
Did you know that infostealer malware can be a precursor to ransomware? Infostealers are a trending tactic used by cybercriminals to exfiltrate valuable identity data like credentials, PII, and session cookies. According to recent SpyCloud research, 75% of organizations were affected by ransomware more than once in the past year! Visit spycloud.com/headlines to find out how to keep your organization from becoming one of the statistics.
Get the story behind the headlines at CISOSeries.com
Recall redesign: reinforced and removable
Embargo moves ransomware attacks to cloud environments
Dallas suburb deals with ransomware attack
Huge thanks to our sponsor, SpyCloud
It turns out infostealer infections are a major contributing factor to a company’s ransomware risk, with some industries faring better than others. Get the new research from our sponsor, SpyCloud, and see if your ransomware defense strategy stacks up against your peers. Visit spycloud.com/headlines
Get the story behind the headlines at CISOSeries.com
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Jason Elrod, CISO, Multicare Health System
Missed the live show? Watch it on YouTube. And make sure to check out Jason’s book (coming soon) at CyberCISOmarksmanship.com, as well as his newsletter at LimitlessCyber.com.
And huge thanks to our sponsor – Vanta As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews.
With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs.
Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews.
Visit vanta.com to learn more about Questionnaire Automation.
All links and the video of this episode can be found on CISO Series.com
Public Wi-Fi hacked at some of the UK’s busiest train stations
Data privacy watchdog files complaint against Mozilla for ad tracking feature
NIST drops password complexity, mandatory reset rules
Thanks to today's episode sponsor, Vanta
As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews.
With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs.
Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews.
Visit vanta.com to learn more about Questionnaire Automation.
Find the stories behind the headlines at CISOseries.com.
DragonForce uses ransomware’s greatest hits
Salt Typhoon strikes US ISPs
Finding SpAIware on the ChatGPT Mac app
Thanks to today's episode sponsor, Vanta
As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews.
With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs.
Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews.
Visit vanta.com to learn more about Questionnaire Automation.
Kansas water plant pivots to analog after cyber event
CrowdStrike exec apologizes in Congress for global IT outage
MoneyGram goes offline after cyber incident
Thanks to today's episode sponsor, Vanta
As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews.
With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs.
Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews.
Visit vanta.com to learn more about Questionnaire Automation.
For the stories behind the headlines, visit CISOseries.com
U.S. proposes ban on Chinese, Russian tech in autonomous vehicles
Telegram updates policies to expose ‘bad actors’
Necro Trojan infects 11 million android devices through Google Play apps
Thanks to today's episode sponsor, Vanta
As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews.
With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs.
Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews.
Visit vanta.com to learn more about Questionnaire Automation.
LinkedIn halts AI data processing in UK due to privacy concerns, Ukraine bans Telegram Use for government and military, Dismissed German cyber chief falsely accused of associating with Russian spies
Thanks to today's episode sponsor, Vanta
As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews.
With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs.
Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews.
Visit vanta.com to learn more about Questionnaire Automation.
Find the stories behind the headlines at CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Mike Rosen, CISO, ZwillGen, advisor to NightDragon and Villager at Team8, whose favorite story of the week was Starlink’s ability to detect stealth aircraft. Check it out.
Thanks to our show sponsor, Conveyor
Why do teams choose Conveyor over the competition for customer security reviews?
A few reasons.
One. Market-leading AI accuracy for any format of security questionnaire with limited knowledge base maintenance.Two. Enterprise-grade trust center that automates every customer security request.Three. Conveyor’s sales team is actually fun to work with.
Learn why Conveyor is the security review platform your infosec friends love at www.conveyor.com
All links and the video of this episode can be found on CISO Series.com
New INC ransomware targets U.S. healthcare sector
Providence public schools deal with irregular internet activity
Apple pulls iPadOS 18 update that was bricking M4 iPad Pro devices
Thanks to today's episode sponsor, Conveyor
It’s Friday and Conveyor hopes you don’t have a meaty security questionnaire waiting for you on the other side of this podcast. If you do, you should check them out.
As the market-leader in instant, generative AI answers to entire security questionnaires, Conveyor helps you complete questionnaires fast, no matter the format they’re in, so you don’t feel like you’re getting crushed by the wave of unfinished work.
Learn why we’re the software your infosec friends love at www.conveyor.com.
Get the story behind the headlines at CISOSeries.com.
Feds derail Raptor Train
Newmark creates Volunteer Network for Civil Cyber Defense
US to host global AI safety summit
Thanks to today's episode sponsor, Conveyor
Does the next security questionnaire that hits your inbox make you want to throw your laptop out the window? If so, don’t do it. You should check out Conveyor first.
Conveyor is the market-leader in instant, generative AI answers to entire security questionnaires no matter the format they are in.
Yes, that’s right. Upload any file like excels, word docs and even PDFs for instant processing and tackle any portal-based questionnaire with a browser extension that auto-scrolls and fills in answers for you.
Try a free proof of concept today at www.conveyor.com.
Get the story behind the headlines at CISOSeries.com.
Exploding pager tragedy experts look towards supply chain sabotage
Construction companies potentially vulnerable through accounting software
Cyberattacks result in job losses
Thanks to today's episode sponsor, Conveyor
Are customer security reviews constantly interrupting your day? You should check out Conveyor.
With an enterprise-grade trust center to securely share your security posture, SOC 2, and security FAQs and security questionnaires and market-leading AI accuracy for instant security questionnaire answers, you’ll fly through any customer security request and get back to your regular job.
Learn more about the AI security review automation platform your infosec friends love at www.conveyor.com. Mention this podcast for 5 free questionnaire credits when you purchase a Pro plan.
Get the story behind the headlines at CISOSeries.com.
Spyware giant Intellexa faces new U.S. sanctions
Nearly 1 million impacted by ransomware attack on London hospitals
Apple releases long-awaited update
Thanks to today's episode sponsor, Conveyor
Why do teams choose Conveyor over the competition for customer security reviews?
A few reasons.
One. Market-leading AI accuracy for any format of security questionnaire with limited knowledge base maintenance.
Two. Enterprise-grade trust center that automates every customer security request.
Three. Conveyor’s sales team is actually fun to work with.
Learn why Conveyor is the security review platform your infosec friends love at www.conveyor.com
Get the story behind the headlines at CISOSeries.com.
Fortinet confirms customer data breach
RansomHub threatens to leak stolen Kawasaki data
Update: Transport for London requires in-person password resets after hack
Thanks to today's episode sponsor, Conveyor
Ever feel like completing security questionnaires has become your full time side hustle you’re not even getting paid extra for? If so, you should check out Conveyor. Conveyor is the market-leader in instant, generative AI answers to entire security questionnaires no matter the format they are in. Yes, that’s right. Upload any file like excels, word docs and even PDFs for instant processing and tackle any portal-based questionnaire with a browser extension that auto-scrolls and fills in answers for you.
Try a free proof of concept today at www.conveyor.com.
Get the story behind the headlines at CISOSeries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by David Spark with guest Patrick Heim, co-founder and partner, SYN Ventures
Huge thanks to our sponsor, Vanta
Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at vanta.com/headlines.
All links and the video of this episode can be found on CISO Series.com
Lazarus Group’s VMConnect campaign spoofs CapitalOne
Mastercard buys security firm Recorded Future
WordPress to require two-factor authentication for plugin developers
Huge thanks to our sponsor, Vanta
Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines. That’s vanta.com/headlines.
Get the story behind the headlines at CISOSeries.com
The $20 WHOIS vulnerability
India training thousands of “cyber commandos”
A Word of warnings for Taiwanese drone makers
Huge thanks to our sponsor, Vanta
When it comes to ensuring your company has top-notch security practices, things can get complicated, fast. Vanta automates compliance for SOC 2, ISO 27001, and more, saving you time and money. With Vanta, you can unify your security program management and proactively manage security reviews with AI-powered security questionnaires.Our listeners get $1,000 off at vanta.com/headlines. That’s vanta.com/headlines.
Get the story behind the headlines at CISOSeries.com
Slim CD notifies 1.7M customers of data breach
Delaware men charged in international sextortion scheme
London transit agency drops claim it has ‘no evidence’ of customer data theft
Huge thanks to our sponsor, Vanta
Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines. That’s vanta.com/headlines.
Get the story behind the headlines at CISOSeries.com
1.7 million impacted in payment processing breach
Dark web administrators charged in U.S.
Resurgence of Predator Spyware sparks privacy concerns
Huge thanks to our sponsor, Vanta
When it comes to ensuring your company has top-notch security practices, things can get complicated, fast. Vanta automates compliance for SOC 2, ISO 27001, and more, saving you time and money. With Vanta, you can unify your security program management and proactively manage security reviews with AI-powered security questionnaires.Our listeners get $1,000 off at vanta.com/headlines. That’s vanta.com/headlines.
Get the story behind the headlines at CISOSeries.com
Car rental company Avis discloses data breach
Microsoft Office 2024 to disable ActiveX controls by default
Wisconsin Medicare users had information leaked in MOVEit breach
Huge thanks to our sponsor, Vanta
Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines.
Get the story behind the headlines at CISOSeries.com
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Justin Somaini, partner, YL Ventures
Thanks to our show sponsor, Scrut Automation
Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.
All links and the video of this episode can be found on CISO Series.com
Planned Parenthood suffers cyberattack
DoJ propaganda domains takedown
Microchip Technology confirms data theft
Thanks to today's episode sponsor, Scrut Automation
Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.
Find the stories behind the headlines at CISOseries.com.
Spyware research report
They found a way to make Cicadas more annoying
MacroPack red teaming tool used for malware
Thanks to today's episode sponsor, Scrut Automation
Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.
Halliburton confirms data stolen in cyberattack
City of Columbus sues researcher after ransomware attack
White House publishes plan to protect a key component of the internet
Thanks to today's episode sponsor, Scrut Automation
Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.
For the stories behind the headlines, visit CISOseries.com.
Transport for London suffers cyberattack
German air traffic control agency confirms cyberattack
Sweden warns of heightened risk of Russian sabotage
Thanks to today's episode sponsor, Scrut Automation
Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.
Find the stories behind the headlines at CISOseries.com
Seattle Airport issues travelers’ advisory for Labor Day travel
SQL injection able to bypass airport TSA security checks
North Korea uses FudModule Rootkit in Chrome zero-day exploit
Thanks to today's episode sponsor, Scrut Automation
Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.
Find the stories behind the headlines at CISOseries.com.
DICK’S Sporting Goods suffers cyberattack
Brain Cipher claims attack on Paris museums, promises data leak
Play ransomware hackers claim attack on Microchip Technology
Thanks to today's episode sponsor, Scrut Automation
Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.
Find the stories behind the headlines at CISOSeries.com
Iran targeting presidential administration officials
Iran working with ransomware gangs
UK Labour Party chided over cyberattack backlog
Thanks to today's episode sponsor, Scrut Automation
Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.
Find the stories behind the headlines at CISOSeries.com
Texas credit union user data exposed in another MOVEit breach
US Marshals Service disputes ransomware gang's breach claims
Park’N Fly notifies 1 million customers of data breach
Thanks to today's episode sponsor, Scrut Automation
Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.
Find the stories behind the headlines at CISOSeries.com
SonicWall warns of critical access control flaw
Microsoft to host security summit
More details on Telegram CEO’s arrest
Thanks to today's episode sponsor, Scrut Automation
Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.
Find the stories behind the headlines at CISOSeries.com
Halliburton takes systems offline following cyberattack
French police arrest Telegram CEO Pavel Durov
DOJ joins suit against Georgia Tech over Defense Department cybersecurity failures
Thanks to today's episode sponsor, Scrut Automation
Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.
Find the stories behind the headlines at CISOSeries.com
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Bethany De Lude, CISO, The Carlyle Group
Thanks to today’s episode sponsor, Nudge Security
When your CEO asks “Hey, are we using that SaaS app that was just breached?”, how quickly and confidently can you answer? Stop guessing with Nudge Security. Discover all SaaS accounts ever introduced by anyone in your org, in minutes and get alerted when any SaaS app used in your org is breached. Start a 14-day trial now at nudgesecurity.com/saas
All links and the video of this episode can be found on CISO Series.com
Kremlin complains of DDoS attack, digital experts not so sure
FAA proposes new cybersecurity rules for airplanes
Windows Recall to reappear
Thanks to today’s episode sponsor, Nudge Security
Do you know who’s using genAI tools in your org? Find out today with Nudge Security. Their patented approach to SaaS discovery gives you a full inventory of all apps ever introduced by anyone in your org, in minutes, including genAI apps. And, automated workflows help you scale security and governance without breaking a sweat. Start a free trial today at nudgesecurity.com/genai
For the stories behind the headlines, head to CISOseries.com.
Security initiative from Japanese auto companies
Feds tapping into encrypted messaging haul
Microsoft breaks Linux dual-boot systems
Thanks to today’s episode sponsor, Nudge Security
How big is your SaaS attack surface? Find out today with Nudge Security. Nudge Security discovers all SaaS accounts ever created by anyone in your org, in minutes, and gives you automated workflows to scale SaaS security and governance. Take control of your SaaS security posture. Start a free trial today at nudgesecurity.com/cisoseries
Toyota confirms third-party data breach impacting customers
Man who hacked Hawaii state registry sentenced
U.S. Intelligence blames Iran for Trump campaign hack
Thanks to today’s episode sponsor, Nudge Security
When your CEO asks “Hey, are we using that SaaS app that was just breached?”, how quickly and confidently can you answer? Stop guessing with Nudge Security. Discover all SaaS accounts ever introduced by anyone in your org, in minutes and get alerted when any SaaS app used in your org is breached. Start a 14-day trial now at nudgesecurity.com/saas
For the stories behind the headlines, visit CISOseries.com.
‘Only’ 1.3 million affected by National Public Data Breach
Flaws in Microsoft macOS Apps allowing secret recording
Configuration issue exposes flight tracking site
Thanks to today’s episode sponsor, Nudge Security
Do you know who’s using genAI tools in your org? Find out today with Nudge Security. Their patented approach to SaaS discovery gives you a full inventory of all apps ever introduced by anyone in your org, in minutes, including genAI apps. And, automated workflows help you scale security and governance without breaking a sweat. Start a free trial today at nudgesecurity.com/genai
Microsoft Entra admins must enable MFA or lose access to admin portals
Cybercrime gang uses fake Windows update screen to hide data theft
Google Pixel devices shipped with vulnerable Verizon app
Thanks to today’s episode sponsor, Nudge Security
How big is your SaaS attack surface? Find out today with Nudge Security. Nudge Security discovers all SaaS accounts ever created by anyone in your org, in minutes, and gives you automated workflows to scale SaaS security and governance. Take control of your SaaS security posture. Start a free trial today at nudgesecurity.com/cisoseries
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Edwin Covert, head of cyber risk engineering, Bowhead Specialty Underwriters and edwincovert.com
Thanks to our show sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker. ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team. To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
All links and the video of this episode can be found on CISO Series.com
GitHub vulnerability warning regarding ArtiPacked
RansomHub affiliate launches new EDR-killing tool
SolarWinds issues hotfix for web help desk vulnerability
Thanks to today's episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
For the stories behind the headlines, head to CISOseries.com.
Google details privacy commitments with Gemini AI
MIT releases AI Risk Repository
Russian spies using highly targeted phishing
Thanks to today's episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
FBI shutters Radar ransomware gangs servers
NIST finalizes post-quantum encryption standards
2.7 billion National Public Data records leaked
Thanks to today's episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
For the stories behind the headlines, visit CISOseries.com.
U.S. operation of “laptop farm” for North Korea shutdown
Over 100 Ukrainian government computers compromised
Trump campaign says they were hacked
Thanks to today's episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
Iranian hackers ramping up U.S. election interference
AMD SinkClose flaw helps install nearly undetectable malware
ADT discloses breach that impacts more than 30,000 customers demands
Thanks to today's episode sponsor, ThreatLocker
Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.
ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.
To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.
For the stories behind the headlines, head to CISOseries.com
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest DJ Schleen, distinguished security architect, Yahoo
Thanks to our show sponsor, Vanta
Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines. That’s vanta.com/headlines.
All links and the video of this episode can be found on CISO Series.com
Chameleon reappears targeting Canadian restaurant chain
Rhysida claims attack on Bayhealth Hospital in Delaware
BlackSuit/Royal achieves $500m in ransomware demands
Huge thanks to our sponsor, Vanta
Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines. That’s vanta.com/headlines.
For the stories behind the headlines, head to CISOseries.com.
McLaren hospitals disruption linked to INC ransomware attack
CrowdStrike to give customers control over Falcon sensor updates
Ronin Network hacked by "white hats"
Huge thanks to our sponsor, Vanta
When it comes to ensuring your company has top-notch security practices, things can get complicated, fast. Vanta automates compliance for SOC 2, ISO 27001, and more, saving you time and money. With Vanta, you can unify your security program management and proactively manage security reviews with AI-powered security questionnaires.Our listeners get $1,000 off at vanta.com/headlines. That’s vanta.com/headlines
Google patches Android kernel zero-day
Researchers find flaws in Georgia voter portal
Law would make ransomware a terrorist threat
Huge thanks to our sponsor, Vanta
Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines. That’s vanta.com/headlines.
CrowdStrike strikes back against Delta’s claims of negligence
Ransomware attack costs Keytronic $17 million
Patch required for high-severity flaw in Apache OFBiz
Huge thanks to our sponsor, Vanta
When it comes to ensuring your company has top-notch security practices, things can get complicated, fast. Vanta automates compliance for SOC 2, ISO 27001, and more, saving you time and money. With Vanta, you can unify your security program management and proactively manage security reviews with AI-powered security questionnaires.Our listeners get $1,000 off at vanta.com/headlines. That’s vanta.com/headlines
Hackers use ISP to send malware through software updates
CrowdStrike sued by investors following update failure
Historic prisoner swap includes cybercriminals returned to Russia
Huge thanks to our sponsor, Vanta
Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines. That’s vanta.com/headlines.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Dennis Pickett, vp, CISO, Westat
Thanks to our show sponsor, Dropzone AI
Dropzone AI’s Analyst investigates alerts with unmatched speed and precision, providing clear, actionable reports. Experience the power of autonomous threat detection. Meet Dropzone AI at BSides Las Vegas. Visit dropzone.ai for a 3-month free trial.
All links and the video of this episode can be found on CISO Series.com
Cencora confirms patient data stolen in February cyberattack
Phishing campaign targets OneDrive users
Argentina will use AI to predict future crimes
Huge thanks to our sponsor, Dropzone AI
Picture an analyst who works tirelessly around the clock. Dropzone AI’s Analyst investigates every alert and provides comprehensive, actionable reports. Boost your SOC’s capabilities with a 3-month free trial at dropzone.ai.
For the stories behind the headlines, head to CISOseries.com
DDoS attacks won’t impact US elections
Dating apps leaked precise location data
Germany formally blames China for 2021 cyberattack
Huge thanks to our sponsor, Dropzone AI
Think of Alex, your new team member who never takes a break. Dropzone AI’s Analyst investigates every alert and delivers detailed reports without playbooks or code. Experience Alex’s dedication with a 3-month free trial at dropzone.ai.
Delta enlists Microsoft's legal nemesis over CrowdStrike losses
Dark Angels receives record-breaking ransom payment
Meta to pay $1.4 billion biometric lawsuit
Huge thanks to our sponsor, Dropzone AI
Dropzone AI’s Analyst investigates alerts and responds to threats with unmatched speed and precision. No playbooks, no code required. Transform your SOC’s performance with a 3-month free trial at dropzone.ai.
For the stories behind the headlines, head to CISOseries.com.
4.3 million impacted by HealthEquity data breach
Microsoft admits CrowdStrike incident far greater than first reported
Proofpoint exploit allows for millions of fake emails
Huge thanks to our sponsor, Dropzone AI
Imagine an analyst who never misses an alert. Dropzone AI autonomously investigates every alert and provides decision-ready reports, enhancing your SOC’s efficiency. Try it free for 3 months at dropzone.ai.
Hackers exploiting PyPi package targets MacOS
Columbus, Ohio suffers cyber incident
Windows July updates come with some BitLocker and remote connectivity challenges
Huge thanks to our sponsor, Dropzone AI
Meet Dropzone AI, the analyst who never rests. Investigating every alert with unparalleled speed and precision, delivering clear, actionable reports. No playbooks, no code. Experience the power of AI with a 3-month free trial at dropzone.ai.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Jana Moore, CISO, Belron, also vice president, EmpoWer – Supporting women in infosec.
Thanks to our show sponsor, Vanta
When it comes to ensuring your company has top-notch security practices, things can get complicated, fast. Vanta automates compliance for SOC 2, ISO 27001, and more, saving you time and money. With Vanta, you can unify your security program management and proactively manage security reviews with AI-powered security questionnaires. Our listeners get $1,000 off at Vanta dot com/headlines.
All links and the video of this episode can be found on CISO Series.com
Hackers exploiting Microsoft Defender SmartScreen bug
IT leaders note increase in severity of cyber-attacks, ransomware and BEC stand out,
Trump shooting investigation revives the end-to-end encryption issue
Huge thanks to our sponsor, Vanta
Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines.
For the stories behind the headlines, head to CISOseries.com
CrowdStrike dishes details
Google scuttles third-party cookie deprecation
BreachForums leaked on Telegram
Huge thanks to our sponsor, Vanta
When it comes to ensuring your company has top-notch security practices, things can get complicated, fast. Vanta automates compliance for SOC 2, ISO 27001, and more, saving you time and money. With Vanta, you can unify your security program management and proactively manage security reviews with AI-powered security questionnaires. Our listeners get $1,000 off at vanta.com/headlines.
Google’s $23 billion plan to buy Wiz falls apart
U.S. government looking for answers amidst CrowdStrike aftermath
dYdX exchange hacked in DNS hijack attack
Thanks to our episode sponsor, Vanta
Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines.
For the stories behind the headlines, visit CISOseries.com.
CrowdStrike says “significant number” back up and running
Russian cyber criminals sanctioned for infrastructure attacks
Ransomware attack shuts down largest trial court in U.S.
Huge thanks to our sponsor, Vanta
When it comes to ensuring your company has top-notch security practices, things can get complicated, fast. Vanta automates compliance for SOC 2, ISO 27001, and more, saving you time and money. With Vanta, you can unify your security program management and proactively manage security reviews with AI-powered security questionnaires. Our listeners get $1,000 off at vanta.com/headlines.
Microsoft confirms CrowdStrike update also hit cloud Windows PCs
Cybercriminals exploit CrowdStrike problem to distribute malware
CISA adds some big names to its KEV catalog
Huge thanks to our sponsor, Vanta
Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post – get exact one from https://cisoseries.com
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Adam Arellano, former vp, enterprise cybersecurity, PayPal
Thanks to our show sponsor, Conveyor
Why do teams choose Conveyor over the competition to automate answering security questionnaires? A few reasons. One. Market-leading AI accuracy Two. They don’t have to maintain a crazy knowledge base anymore because ConveyorAI can read from any source like external support sites, documents, past questionnaires and more. Three. It can process ANY customer file format – even PDFs! It will even auto-scroll and auto-complete portal-basedl questionnaires. Don’t believe it? Try it yourself for free at www.conveyor.com.
All links and the video of this episode can be found on CISO Series.com
FIN7 sells security evasion tool to others via darknet
UK national blood stocks suffer the effects of ransomware
Security flaws in SAP AI Core cloud-based platform
Thanks to today's episode sponsor, Conveyor
It’s Friday and Conveyor hopes you don’t have a meaty security questionnaire waiting for you on the other side of this podcast. If you do, you should check them out. As the market leader in instant, generative AI answers to entire security questionnaires, Conveyor helps you complete questionnaires fast, no matter the format they’re in, so you don’t feel like you’re getting crushed by the wave of unfinished work. Learn why we’re the software your infosec friends love at www.conveyor.com
For the stories behind the headlines, head to CISOseries.com
UK mandatory ransomware reporting gets watered-down
Google introduces AI agent to look for software bugs
Critical infrastructure ransomware costs spike
Thanks to today's episode sponsor, Conveyor
Does the anticipation of the next monster security questionnaire wrecking your day ever make you feel like a balloon floating above a cactus field? If so, you should check out Conveyor. Conveyor is the market-leader in instant, generative AI answers to entire security questionnaires no matter the format they are in. Yes, that’s right. Upload any file like Excel, Word docs and even PDFs for instant processing and tackle any portal-based questionnaire with a browser extension that auto-scrolls and fills in answers for you. Try a free proof of concept today at www.conveyor.com.
Yesteryears (DECISION) by Sascha Ende Free download: https://filmmusic.io/song/244-yesteryears-decision License (CC BY 4.0): https://filmmusic.io/standard-license
Rite Aid says 'limited’ cybersecurity incident affected over 2 million people
AT&T ransom laundered through mixers and gambling services
Hacktivists leak Disney data to protect artist rights
Thanks to today's episode sponsor, Conveyor
Why do teams choose Conveyor over the competition to automate answering security questionnaires? A few reasons. One. Market-leading AI accuracy Two. They don’t have to maintain a crazy knowledge base anymore because ConveyorAI can read from any source like external support sites, documents, past questionnaires and more. Three. It can process ANY customer file format - even PDFs! It will even auto-scroll and auto-complete portal-based questionnaires. Don’t believe it? Try it yourself for free at www.conveyor.com.
For the stories behind the headlines, head to CISOseries.com.
Alphabet in talks to acquire Wiz
AT&T allegedly paid hacker to delete data
Details on Squarespace domain hacks
Thanks to today's episode sponsor, Conveyor
Does the mountain of security questionnaires in your inbox make you feel like you're in a rowboat trying to make it through a tsunami? If so, you should check out Conveyor. As the market leader in instant, generative AI answers to entire security questionnaires, Conveyor helps you complete them fast, no matter the format they’re in, and never feel like you’re getting crushed by the wave of unfinished work. Learn more about the AI security review automation platform your infosec friends love at www.conveyor.com. Mention this podcast for 5 free questionnaire credits when you purchase a Pro plan.
Rite Aid announces data breach following June cyberattack
The personal security implications of the AT&T breach
US offers support to prevent Paris Olympics cyber and disinformation attacks
Thanks to today's episode sponsor, Conveyor
Ever feel like completing security questionnaires has become your full-time side hustle you’re not even getting paid extra for? If so, you should check out Conveyor. Conveyor is the market leader in instant, generative AI answers to entire security questionnaires no matter the format they are in. Yes, that’s right. Upload any file like Excel, Word docs and even PDFs for instant processing and tackle any portal-based questionnaire with a browser extension that auto-scrolls and fills in answers for you. Try a free proof of concept today at www.conveyor.com.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Andrew Cannata, CISO, Primo Water
Thanks to our show sponsor, Entro Security
What are you doing to secure your company’s non-human identities? Vaults and scanners are helpful, but they don’t give the context for where your secrets are, how they’re being used, or when it’s time to remove or rotate them. The entro platform provides automated lifecycle management and seamless integration, ensuring comprehensive security & compliance through a unified and easy to use interface.
All links and the video of this episode can be found on CISO Series.com
PHP vulnerability exploited, spreading malware and DDoS attacks
Advance Auto Parts reveals damage from Snowflake breach
FTC report reveals dark patterns used to trick consumers
Thanks to today's episode sponsor, Entro
Reclaim control over your Non-human identities! Entro enables security teams to manage and secure the lifecycle of non-human identities and secrets from inception to rotation. Think of it like an airtag for your secrets - know where they are, how they’re being used, and their risk level in one seamless platform. Visit https://entro.security/ to learn more.
For the stories behind the headlines, head to CISOseries.com.
Australia targets government tech under foreign control
Singapore banks replace OTP with digital tokens
New group targets Veeam vulnerability
Thanks to today's episode sponsor, Entro
What are you doing to secure your company’s non-human identities? Vaults and scanners are helpful, but they don’t give the context for where your secrets are, how they’re being used, or when it’s time to remove or rotate them. The entro platform provides automated lifecycle management and seamless integration, ensuring comprehensive security & compliance through a unified and easy to use interface. Visit https://entro.security/ to learn more.
US disrupts Russian AI-powered disinformation bot farm
Senate takes aim at ‘overly burdensome’ cybersecurity regs
Fujitsu confirms customer data exposed in cyberattack
Thanks to today's episode sponsor, Entro
Reclaim control over your Non-human identities! With Entro, security teams can now manage and secure the lifecycle of Non-human identities and secrets. Like an air tag for your non-human identities, The entro platform provides automated lifecycle management and seamless integration, ensuring comprehensive security & compliance through a unified and easy to use interface. Visit https://entro.security/ to learn more.
For the stories behind the headlines, visit CISOseries.com.
Record-breaking 10 billion stolen passwords exposed
Supreme court ruling makes cybersecurity regulations even trickier
Apple removes popular apps at Russia’s request
Thanks to today's episode sponsor, Entro
Did you know that an attack on non-human identities and secrets is one of the top 2 cyber attack vectors out there ? With Entro, security teams can now manage and secure the lifecycle of Non-human identities and secrets. The entro platform provides automated lifecycle management and seamless integration, ensuring comprehensive security & compliance through a unified and easy to use interface. Visit https://entro.security/ to learn more.
Alabama Department of Education suffers data breach
New York Times claims hackers stole OpenAI secrets in a 2023 security breach
RansomHub claims to have published Florida health department data
Thanks to today's episode sponsor, Entro
Reclaim control over your Non-human identities! Entro enables security teams to manage and secure the lifecycle of non-human identities and secrets from inception to rotation. Think of it like an airtag for your secrets - know where they are, how they’re being used, and their risk level in one seamless platform. Visit https://entro.security/ to learn more.
For the stories behind the headlines, head to CISOseries.com.
Senate leader demands answers from CISA re March Ivanti hack
China’s Velvet Ant hackers exploiting new Cisco zero-day
Europol law enforcement takes down Cobalt Strike servers
Huge thanks to our sponsor, Demoed
Buyers do 70% of their product research before talking to a company. That blew our minds. Why not give buyers as much information about your product as possible to help them decide? Eliminating friction has always been key to a solid sales strategy. With Demoed, buyers can research faster and more effectively. Sign up at demoed.com
For the stories behind the headlines, head to CISOseries.com.
Evolve Bank data breach is evolving
Patelco Credit Union cyberattack disrupts services for nearly 500,000 members
LockBit claims cyberattack on Croatia’s largest hospital
Huge thanks to our sponsor, Demoed
Did you know that Demoed is the first platform that allows you to watch a live product demo and ask questions without receiving a barrage of follow-ups? We change buyer-vendor engagement: fewer follow-ups for buyers, more leads for vendors. Sign up now at demoed.com
For the stories behind the headlines, visit CISOseries.com.
14 million Linux systems threatened by ‘RegreSSHion’ vulnerability
Critical patch issued for Juniper routers
Millions not thousands impacted by Prudential breach
Huge thanks to our sponsor, Demoed
“I have extra time in my day” is something no security professional has ever said. Vendors on Demoed host 15-minute pitches highlighting their value and differentiation. Demoed allows buyers to browse and get educated without sales pressure—window shopping for enterprise sales. Sign up now at demoed.com
Update on the TeamViewer network breach
HubSpot looks into customer account hacks
U.S. businesses struggle to obtain cyber insurance
Huge thanks to our sponsor, Demoed
Demoed is a unique platform that connects buyers and sellers. Buyers want to see more products, and vendors want more leads. Demoed solves this for both by making buyers anonymous. Buyers can watch demos without follow-ups, hiding their identity until they are ready. Sign up now at demoed.com.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Jim Bowie, CISO, Tampa General Hospital
Thanks to our show sponsor, Prelude Security
When executives ask the question, are we vulnerable to this threat? How long does it take you to get a confident answer? Prelude automatically transforms threat intelligence into validated detections, so you can know with certainty in just a manner of minutes. Visit preludesecurity.com/threats to upload your own threat intelligence and see for yourself.
All links and the video of this episode can be found on CISO Series.com
Gas chromatograph vulnerabilities reveal medical IoT challenges
We never authorized polyfill.io to use our name, says Cloudflare
Evolve Bank confirms data breach, undermining LockBit’s Federal Reserve claim
Huge thanks to our sponsor, Prelude Security
When executives ask the question, are we vulnerable to this threat? How long does it take you to get a confident answer? Prelude automatically transforms threat intelligence into validated detections, so you can know with certainty in just a manner of minutes. Visit preludesecurity.com to upload your own threat intelligence and see for yourself.
For the stories behind the headlines, head to CISOseries.com.
Android lying Snowblind in the sun
Identity verification service exposed data for over a year
Polyfill.io JavaScript attack impacts thousands of sites
Huge thanks to our sponsor, Prelude Security
30 minutes to peace of mind. That’s what you’ll get with Prelude’s automated threat management platform where you can upload any piece of threat intelligence and quickly generate threat-hunting queries, detection rules, and more. Visit preludesecurity.com and get all of this in 30 minutes or get a pizza on Prelude.
Julian Assange to plead guilty and return to Australia
Fresh MOVEit bug under attack just hours after disclosure
Criminal selling Neiman Marcus customer info for $150K
Huge thanks to our sponsor, Prelude Security
Don’t be left wondering if you’re protected the next time a new threat hits the news. Week in review listeners can upload their threat intelligence to Prelude and receive a free bundle of relevant detection rules, hunt queries, and security tests. Any piece of threat intelligence. All in 30 minutes. Upload yours at prelude security dot com forward slash threats.
Indonesia battles Lockbit 3.0 ransomware
DOJ charges cybercrime group for $71 million in damages
SEC reports pile in following CDK Global attack
Huge thanks to our sponsor, Prelude Security
What would your security teams do with more time back in their day? Prelude provides an end-to-end threat management automation platform that quickly generates hunt queries, detection rules, and security tests from your threat intelligence to help you stay ahead of threats. Upload your own threat intelligence at preludesecurity.com and get all of that in just 30 minutes or less.
CDK Global outage caused by BlackSuit ransomware attack
Bug allows Microsoft corporate email account spoofing
UK’s largest nuclear site pleads guilty over cybersecurity failures
Huge thanks to our sponsor, Prelude Security
When executives ask the question, are we vulnerable to this threat? How long does it take you to get a confident answer? Prelude automatically transforms threat intelligence into validated detections, so you can know with certainty in just a manner of minutes. Visit preludesecurity.com to upload your own threat intelligence and see for yourself.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines - Week in Review is hosted by Rich Stroffolino with guest Bil Harmer, operating partner and CISO, Craft Ventures, also at wilharm3.com.
Thanks to our show sponsor, Vanta
Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security Our listeners get $1,000 off at vanta.com/headlines.
All links and the video of this episode can be found on CISO Series.com
CDK Global gets hacked twice
LockBit Activity on the rise
Kraken extorted by security researcher
Thanks to today's episode sponsor, Vanta
*Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines.*
Nvidia becomes world’s most valuable company
Markopolo scam delivers infostealer through fake meeting software
Medibank hack blamed on MFA failure
Thanks to today's episode sponsor, Vanta
When it comes to ensuring your company has top-notch security practices, things can get complicated, fast. Vanta automates compliance for SOC 2, ISO 27001, and more, saving you time and money. With Vanta, you can unify your security program management and proactively manage security reviews with AI-powered security questionnaires.Our listeners get $1,000 off at vanta.com/headlines.
For the stories behind the headlines, head to CISOseries.com.
AMD investigates breach after data for sale on hacking forum Qilin demands $50 million ransom from UK hospital Hackers derail Amtrak Guest Rewards accounts
Thanks to today's episode sponsor, Vanta
Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines.
For the stories behind the headlines, visit CISOseries.com.
Snowflake breach escalates with ransom demands and death threats
MITRE has a memo for the president
Velvet Ant maintains three-year cyber espionage campaign
Thanks to today's episode sponsor, Vanta
When it comes to ensuring your company has top-notch security practices, things can get complicated, fast. Vanta automates compliance for SOC 2, ISO 27001, and more, saving you time and money. With Vanta, you can unify your security program management and proactively manage security reviews with AI-powered security questionnaires.Our listeners get $1,000 off at vanta.com/headlines.
CISA leads first tabletop exercise for AI cybersecurity
Keytronic confirms data breach after ransomware gang leaks stolen files
New Linux malware controlled through Discord emojis
Thanks to today's episode sponsor, Vanta
Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Janet Heins, CISO, ChenMed and janetheins.com
Thanks to our show sponsor, Vanta
Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines.
All links and the video of this episode can be found on CISO Series.com
Record high for North American cyber insurance claims
NATO members to increase vigilance over Russian sabotage attempts
Remcos RAT discovered inside UUEncoding emails
Thanks to today's episode sponsor, Vanta
Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines.
For the stories behind the headlines, head to CISOseries.com.
Life360 faces extortion attempt after Tile data breach
White House report highlights increase in federal attacks
Russian hacker with ties to LockBit and Conti gangs arrested
Thanks to today's episode sponsor, Vanta
When it comes to ensuring your company has top-notch security practices, things can get complicated, fast. Vanta automates compliance for SOC 2, ISO 27001, and more, saving you time and money. With Vanta, you can unify your security program management and proactively manage security reviews with AI-powered security questionnaires.Our listeners get $1,000 off at vanta.com/headlines.
Pure Storage hacked via Snowflake workspace BreachForums down again and official Telegram channels deleted BlackBerry Cylance data up for sale
Thanks to today's episode sponsor, Vanta
Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines.
For the stories behind the headlines, visit CISOseries.com.
Cyber assistance coming to rural hospitals
UK and Canada launch investigation into 23andMe breach
Mandiant and Snowflake sending out breach notices
Thanks to today's episode sponsor, Vanta
When it comes to ensuring your company has top-notch security practices, things can get complicated, fast. Vanta automates compliance for SOC 2, ISO 27001, and more, saving you time and money. With Vanta, you can unify your security program management and proactively manage security reviews with AI-powered security questionnaires.Our listeners get $1,000 off at vanta.com/headlines.
Microsoft resets Recall plans
LastPass says outage caused by bad Chrome extension update
New York Times source code stolen using exposed GitHub token
Thanks to today's episode sponsor, Vanta
Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines - Week in Review is hosted by Rich Stroffolino with guest Andrew Wilder, CISO, Community Veterinary Partners, also cybersecurityintheboardroom.com.
Thanks to our show sponsor, Conveyor
Why did the AI cross the road? To complete your security questionnaires for you. Conveyor, the company using market-leading AI to automate the entire security review, wants you to check them out and book a call so they can stop writing these cheesy podcast ads. If you’re ready for AI to instantly complete security questionnaires for you, visit www.conveyor.com to try a free proof of concept. Mention this podcast for 5 free questionnaire credits when you purchase a Pro plan.
All links and the video of this episode can be found on CISO Series.com
FCC moves forward with BGP security measures
LockBit ransomware gang victims get lifeline from FBI
Gitloker attacks target GitHub repositories
Thanks to today's episode sponsor, Conveyor
Why did the AI cross the road? To complete your security questionnaires for you. Conveyor, the company using market-leading AI to automate the entire security review, wants you to check them out and book a call so they can stop writing these cheesy podcast ads. If you’re ready for AI to instantly complete security questionnaires for you, visit www.conveyor.com to try a free proof of concept. Mention this podcast for 5 free questionnaire credits when you purchase a Pro plan.
US researches using psychology against threat actors
AI leveling up unsophisticated threat actors
London Hospital attacks linked to Qilin
Thanks to today's episode sponsor, Conveyor
Conveyor is the market leading AI-powered platform that automates the entire customer security review process — from easily sharing your security posture and SOC 2 to letting AI answer security questionnaires instantly with 90% accuracy. Use Conveyor to fly through any customer security review in minutes. There’s a reason our customers have dubbed Conveyor their ‘favorite security tool of the year’. Test it out in a free proof of concept at www.conveyor.com and mention this podcast for 5 free questionnaire credits when you purchase a Pro plan.
Ransomware attack forces London hospitals to cancel operations
Christie’s stolen data sold to highest bidder
RansomHub claims responsibility for Frontier breach
Thanks to today's episode sponsor, Conveyor
Conveyor is the AI security review automation platform helping infosec teams automate everything from securely sharing a SOC 2 to one-click auto complete of your security questionnaires with AI. Teams like Lucid Software are finding in a free proof of concept that our AI is more accurate than the rest. Learn more at www.conveyor.com. Mention this podcast for 5 free questionnaire credits when you purchase a Pro plan.
Authorities unmask criminals behind malware loaders
3 billion records stolen from background check firm
Creds for 361 million accounts added to HIBP
Thanks to today's episode sponsor, Conveyor
What are infosec teams measuring these days? More often than not, their impact on the business through revenue. A director of GRC told us the most direct value for their CEO was showing the efficiencies and the dollars that security has been able to bring in from enabling sales through the security review. See how best in class infosec teams measure their performance in Conveyor’s ultimate guide to the security review KPIs that matter. Go to www.conveyor.com and click the banner at the top.
For the stories behind the headlines, visit CISOseries.com.
Ticketmaster hack affects 560 million customers, third-party denied liability
Australia’s Ticketek sees customer details exposed in cyber security breach
HHS changes tack, allows Change Healthcare to file breach notifications for others
Thanks to today's episode sponsor, Conveyor
Conveyor, the market-leading AI software for answering security questionnaires and securely sharing your security documents just released their ultimate guide to benchmarking your team’s performance on customer security reviews. Get all of the detailed metrics and learn how best in class infosec teams measure and tie their impact to revenue. Download the report at www.conveyor.com by clicking on the banner at the top.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Dimitri Van Zantvliet, CISO, Dutch Railways
Thanks to our show sponsor, Vanta
Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.
All links and the video of this episode can be found on CISO Series.com
Senator calls for UnitedHealth leadership to be held responsible
Europol seizes 2,000 domains in dropper takedown
Malware bricked over 600,000 routers
Thanks to today's episode sponsor, Vanta
Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.
New North Korean hacking group emerges
Dutch bank ABN Amro discloses data breach
Internet Archive, including Wayback Machine, impacted by DDoS
Thanks to today's episode sponsor, Vanta
Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.
For the stories behind the headlines, head to CISOseries.com.
BreachForums returns just weeks after FBI-led takedown
First American data breach impacts 44,000 people
Chinese nationals sanctioned for botnet that stole ‘billions’ in COVID-19 relief funds
Thanks to today's episode sponsor, Vanta
Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.
For the stories behind the headlines, visit CISOseries.com.
New ransomware uses Windows BitLocker to encrypt victim data
Sav-Rx discloses data breach impacting 2.8 million Americans
New ATM malware poses significant global threat
Thanks to today's episode sponsor, Vanta
Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.
For the stories behind the headlines, head to CISOseries.com.
Arc browser’s Windows launch sabotaged by malvertising
Cencora breach exposed patient info from 11 drug companies
Albany County investigating cybersecurity breach ahead of holiday weekend
Thanks to today's episode sponsor, Vanta
Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines - Week in Review is hosted by Rich Stroffolino with guest Mike Lockhart, CISO, EagleView. Make sure also to check out Mike's charity, the Grady Foundation for mental, physical and economic health. You can learn more and donate here.
Thanks to our show sponsor, Tines
Break away from traditional SOAR with Tines. Trusted by security teams at McKesson, Canva, and Mars, Tines is scalable and accessible for the whole team. Use Tines to automate security team toil, enrich alerts with data from across your tech stack, and foster a culture of cybersecurity. Start building for free at tines.com/ciso
All links and the video of this episode can be found on CISO Series.com
Chinese hackers hide on military and government networks for 6 years
Microsoft outage affects Bing, Copilot, DuckDuckGo and ChatGPT internet search
Mattis speaks out against separate military cyber service
Thanks to today's episode sponsor, Tines
Break away from traditional SOAR with Tines. Trusted by security teams at McKesson, Canva, and Mars, Tines is scalable and accessible for the whole team. Use Tines to automate security team toil, enrich alerts with data from across your tech stack, and foster a culture of cybersecurity. Start building for free at tines.com/ciso
For the stories behind the headlines, head to CISOseries.com.
NY Stock Exchange owner fined $10 million by SEC
US agency pledges $50 Million to automate hospital security
LockBit no longer reigns supreme
Thanks to today's episode sponsor, Tines
Digital threats evolve rapidly, making it difficult for security teams to keep pace. Tines security automation is different from traditional SOAR -- it allows teams to move faster and make better decisions in real-time. Built by security practitioners, for security practitioners, Tines powers mission-critical security workflows at McKesson, Canva, and Mars. Start building for free at tines.com/ciso
Brits to propose mandatory ransomware reporting
Industry heavyweights launch Tech Against Scams
Microsoft targets secure defaults in Windows 11
Thanks to today's episode sponsor, Tines
Automate the toil with SOAR that actually works for your team. With Tines, your whole team can build complex workflows, without having to write or manage code. Security teams at McKesson, Canva, and Mars use Tines to build, run, and monitor their most important workflows, from endpoint detection and response, to vulnerability management. Start building for free at tines.com/ciso
Military cyber service proposal picks up steam
Threat actors abusing legitimate services in campaign
Chatbots susceptible to jailbreaks
Thanks to today's episode sponsor, Tines
Security teams work best when all members are empowered to do their best work. With Tines, analysts and engineers have everything they need to automate the processes they’re closest to. The result? Hundreds or even thousands of hours that can be used on more impactful work. Built by security practitioners, for security practitioners. Get started today at tines.com/ciso
Grandoreiro banking Trojan reappears, hits banks worldwide
Kimsuky deploys new backdoor in latest attack on South Korea
Healthcare breaches in Australia and Texas
Huge thanks to this week’s episode sponsor, Tines
From endpoint detection and response to vulnerability management, Tines empowers security teams to automate even their most complex workflows. It’s fast, flexible, and secure by design. Your team can get up and running in minutes, not weeks. No code. No custom development. The world's smartest security teams trust Tines to support their mission-critical processes. Learn why at tines.com/ciso
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Ryan Bachman, evp and global CISO, GM Financial
Thanks to our show sponsor, vanta.com/ciso
Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.
All links and the video of this episode can be found on CISO Series.com
Nissan North America breach impacts over 53,000 employees
VMware fixes workstation flaws, thanks Pwn2Own hackers
Security flaws discovered in GE Ultrasound machines
Thanks to today's episode sponsor, Vanta
Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.
For the stories behind the headlines, head to CISOseries.com.
FBI seizes BreachForums
Android getting live threat detection
Senators recommend billions for AI investments
Editor's note: post updated to fix audio issue
Thanks to today's episode sponsor, Vanta
Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.
Singing River patient data was swiped in ransomware attack
PoC exploit released for D-Link router zero-day
Google to use GenAI to help identify phone scams
Thanks to today's episode sponsor, Vanta
Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.
For the stories behind the headlines, head to CISOseries.com.
FCC implements new classification to combat robocall groups
MITRE releases threat-modeling framework for embedded devices
World renowned auction house attacked ahead of mega-auction
Thanks to today's episode sponsor, Vanta
Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.
Boeing confirms $200 million ransomware extortion attempt
Dell announces data breach affecting 49 million customers
Ascension healthcare suffers cyberattack, goes offline
Thanks to today's episode sponsor, Vanta
Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Sasha Pereira, CISO, WASH
Thanks to our show sponsor, Vanta.com/ciso
Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.
All links and the video of this episode can be found on CISO Series.com
F5 Networks warns of new Big-IP vulnerabilities
UK armed forces’ personal data hacked in MoD breach
BetterHelp sends refund notices regarding data sharing lawsuit
Huge thanks to our sponsor, Vanta
Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.
For the stories behind the headlines, head to CISOseries.com.
Lockbit takes credit for Wichita attack
US looks at AI model export bans
The Spectre of Pathfinder haunts Intel CPUs
Huge thanks to our sponsor, Vanta
Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.
US indicts LockBit ransomware ringleader
DocGo discloses cyberattack that compromised patient health data
Payroll data breach exposed data of UK military personnel
Huge thanks to our sponsor, Vanta
Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.
For the stories behind the headlines, visit CISOseries.com.
LockBit’s website is back
Germany takes action amid alleged Russian attack
Chinese-linked ArcaneDoor targets global network infrastructure
Huge thanks to our sponsor, Vanta
Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.
NSC’s Neuberger suggests operational approach for on mitigating cyberattacks
French cybersecurity teams prepare for “unprecedented” Olympic threat
Feds warn about North Korean exploitation of improperly configured DMARC
Huge thanks to our sponsor, Vanta
Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Phil Beyer, former CISO, Etsy
Thanks to today’s episode sponsor, Dropzone.ai
Dropzone.ai’s AI Autonomous Analyst is transforming cybersecurity as we know it. By replicating the techniques of elite analysts and autonomously investigating every alert, our patented system force multiplies your SOC team by 10X without adding headcount. Experience the future of threat detection and response at dropzone.ai. Request a trial today!
All links and the video of this episode can be found on CISO Series.com
Goldoon botnet exploits D-Link routers
CISA adds Gitlab flaw to its KEV catalog
Dropbox discloses breach of digital signature service
Thanks to our episode sponsor, Dropzone AI
Dropzone.ai's AI Autonomous Analyst is transforming cybersecurity as we know it. By replicating the techniques of elite analysts and autonomously investigating every alert, our patented system force multiplies your SOC team by 10X without adding headcount. Experience the future of threat detection and response at dropzone.ai. Request a trial today!
For the stories behind the headlines, head to CISOseries.com.
Chinese disinformation proving ineffectual
NCSC release Advanced Mobile Solutions risk model
China implements new State Secrets Law
Thanks to our episode sponsor, Dropzone AI
Cybersecurity leaders, are you being asked to leverage the power of Gen AI in your SOC? Dropzone.ai's AI Autonomous Analyst empowers your team to thoroughly investigate every alert. No playbooks, no code, just intelligent, adaptable alert investigation. Test drive on dropzone.ai to immediately see the results for yourself.
UnitedHealth Group CEO faces congress & cause of hack revealed
Major U.S. wireless carriers face $200M FCC fine
Marriott backtracks claims of encryption protection
Thanks to our episode sponsor, Dropzone AI
Dropzone.ai is proud to announce our selection as a Top 10 Finalist for the prestigious RSA Innovation Sandbox. Our AI Autonomous Analyst is revolutionizing the way SOC teams operate, replicating the techniques of elite analysts and autonomously investigating every alert. Meet us at RSAC and book a time at dropzone.ai.
USPS phishing sites are popular
UK bans bad IoT credentials
USB malware attacks targeting industrial sites
Thanks to our episode sponsor, Dropzone AI
Attention cybersecurity professionals! Are you investigating 100% of the alerts from your IT and security systems? Dropzone.ai's AI Analyst autonomously investigates every alert without playbooks or code, enabling you to turn over every rock. Visit dropzone.ai to learn more and request a trial. Offload your tier-1 analysis to an AI analyst that never sleeps so you can.
Kaiser Permanente website tracking tools may have compromised customer data
DHS announces AI safety board
Okta warns of “unprecedented” credential stuffing attacks on customers
Thanks to our episode sponsor, Dropzone AI
Introducing Dropzone.ai, the industry's first AI Autonomous SOC Analyst. Their patented LLM replicates the techniques of elite analysts, autonomously investigating every alert without playbooks or code. Force multiply your SOC team by 10X without adding headcount. Visit dropzone.ai to request a trial and experience the power of AI-driven cybersecurity.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Christina Shannon, CIO, KIK Consumer Products
Thanks to our show sponsor, Veracode
Get ready to experience the future of application security at RSAC 2024 with Veracode. Join us as we unveil cutting-edge innovations and insights to tackle today’s most pressing security challenges. From live demos showcasing our newest products to engaging discussions with industry experts. See you at RSAC!
All links and the video of this episode can be found on CISO Series.com
Google postpones third-party cookie deprecation
Brocade SAN appliances and switches exposed to hacking
ICICI Bank exposes credit cards to wrong users
Thanks to this week's episode sponsor, Veracode
Don't miss out on this opportunity to elevate your cybersecurity strategy. Build and scale secure software from code to cloud with speed and trust. Visit our booth #2045 at RSAC 2024 to discover how Veracode is shaping the future of Application Security in the AI era.
For the stories behind the headlines, head to CISOseries.com.
Chinese keyboard app flaws exposed
Threat actors plant fake assassination story
ByteDance on the clock to divest TikTok
Thanks to this week's episode sponsor, Veracode
Research reveals AI-generated code mirrors human-written code's security flaws. Even seasoned programmers struggle to spot errors, with incorrect AI-generated answers abound. Veracode knows the stakes. While AI accelerates coding, relying on hunches won't suffice. Trust multi-faceted, data-driven insights to mitigate risk from the start. Don't compromise on security. Choose Veracode, your security partner in the AI-driven era of development.
Iranian nationals charged with hacking U.S. companies and agencies
Siemens working to fix device affected by Palo Alto firewall bug
Russian hackers claim cyberattack on Indiana water plant
Thanks to this week's episode sponsor, Veracode
Are you truly listening to both your security and development teams? Make informed decisions with Veracode. Our developer-friendly security tools integrate with your existing tech stack to secure code from the start. Bridge the gap between security and development for more efficient operations and stronger defenses. Visit veracode.com for a collaborative approach to security.
For the stories behind the headlines, visit CISOseries.com.
TikTok ban passes the US House
Sandworm targets critical Ukrainian orgs
North Koreans animating streaming shows
Thanks to this week's episode sponsor, Veracode
AI coding companions assist in generating high-quality code snippets, while Veracode swoops in to conduct thorough security assessments, identifying and fixing vulnerabilities quickly. With this dynamic duo, developers can innovate with confidence, knowing their code is both efficient and secure. Secure more code with Co-Pilot or any AI coding companion and Veracode. We’ll be your wingman anytime.
RedLine stealer GitHub connection
MITRE’s breached was through Ivanti zero-day vulnerabilities
Researchers find dozens of fake E-ZPass toll websites following FBI warning
Thanks to this week's episode sponsor, Veracode
Imagine your intelligent coding companion, backed by the robust security expertise of Veracode. Together, we form the ultimate duo, empowering developers to write better code while ensuring it's secure from the get-go. Learn more at RSAC 2024 with Veracode.
For the stories behind the headlines, head to CISOseries.com
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Dan Walsh, CISO, Paxos
Thanks to our show sponsor, Conveyor
Happy Friday! Are you tired of hearing about Conveyor’s AI security review automation software? We’ll stop talking about it if you book a call. Ready to give the market leading AI for security questionnaires a spin? Try a free proof of concept at www.conveyor.com. Don’t forget to mention this podcast for 5 free questionnaire credits when you purchase a Pro plan.
All links and the video of this episode can be found on CISO Series.com
Police bust reveals sophisticated phishing-as-a-service platform
Overlooked Windows Fibers offer handy route for malicious payload deployment
Michigan healthcare organization suffers data breach
Thanks to today's episode sponsor, Conveyor
Happy Friday! Are you tired of hearing about Conveyor’s AI security review automation software? We’ll stop talking about it if you book a call. Ready to give the market leading AI for security questionnaires a spin? Try a free proof of concept at www.conveyor.com. Don’t forget to mention this podcast for 5 free questionnaire credits when you purchase a Pro plan.
For the stories behind the headlines, head to CISOseries.com.
Sandworm-linked group tied to attack on water utilities
GPT-4 reads security advisories
Cell carrier workers solicited for SIM swaps
Thanks to today's episode sponsor, Conveyor
Conveyor is the market leading AI-powered platform that automates the entire customer security review process — from sharing your security posture and SOC 2 in a single portal to using that same information to automate answering security questionnaires with 90% accuracy. Use Conveyor to fly through any customer security review in minutes. It might sound like every other software claim out there, but there’s a reason our customers have dubbed Conveyor their ‘favorite security tool of the year’. Test it out in a free proof of concept at www.conveyor.com
Cisco announces breach of multifactor authentication message provider
Bad bots drive 10% annual surge in account takeover attacks
LockBit 3.0 variant generates custom, self-propagating malware
Thanks to today's episode sponsor, Conveyor
Conveyor is the AI security review automation platform helping infosec teams automate everything from securely sharing a SOC 2 to one-click autofilling security questionnaires with AI so you can spend almost zero time on the manual tasks that make you want to cry into your laptop. Teams like Lucid Software are finding in a free proof of concept that our AI is better than the rest. Learn more at www.conveyor.com. Mention this podcast for 5 free questionnaire credits when you purchase a Pro plan.
For the stories behind the headlines, head to CISOseries.com.
Meta to close Threads in Turkey
Palo Alto fixes backdoor zero-day
Details on Microsoft’s security overhaul
Thanks to today's episode sponsor, Conveyor
What are infosec teams measuring these days? More often than not, their impact on sales. As infosec teams become hands on in the sales cycle, proving your value becomes key. A director of GRC said last week that the most direct value for their CEO was showing the efficiencies and the dollars that security has been able to bring in from enabling sales. See these trends and more in Conveyor’s ‘2024 State of the Security Review” report at www.conveyor.com. Click the banner at the top.
House passes reauthorization of U.S. surveillance program
Roku says 576,000 accounts compromised in latest security breach
Microsoft breach exposed federal agencies
Thanks to today's episode sponsor, Conveyor
It’s Conveyor again, the market-leading AI software for answering security questionnaires and securely sharing your security posture and documents. Conveyor’s ‘State of the Security Review” report for 2024 was just released and it’s all about what the “new era” of infosec holds. Learn how positioning security and compliance early in the sales cycles increases win rates by 42% and what infosec teams need to prepare for as they move closer to the sales function. You can find the report at www.conveyor.com by clicking on the banner at the top.
For the stories behind the headlines, visit CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Mike Levin, deputy CISO, 3M
Thanks to our show sponsor, Vanta
When it comes to ensuring your company has top-notch security practices, things can get complicated fast. With Vanta, you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA. Even more, Vanta’s market-leading Trust Management Platform enables you to unify security program management with a built-in risk register and reporting, and streamline security reviews with AI-powered security questionnaires. Over 7,000 fast-growing companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security in real time. Watch Vanta’s on-demand demo at vanta.com/ciso.
All links and the video of this episode can be found on CISO Series.com
Palo Alto Networks fixes several DoS vulnerabilities in PAN-OS operating system
Sisense breach exposes customers to potential supply chain attack
Threat actors gaming GitHub Search
Thanks to today's episode sponsor, Vanta
The average security pro spends nearly a full workday every week just on compliance. With Vanta, you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA. Even more, Vanta’s market-leading Trust Management Platform enables you to unify security program management with a built-in risk register and reporting, and streamline security reviews with AI-powered security questionnaires. Over 7,000 fast-growing companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security in real time. Watch Vanta’s on-demand demo at vanta.com/ciso.
For the stories behind the headlines, head to CISOseries.com.
CISA expands automated malware analysis
US Cyber Command launched “hunt forward” missions
Spectre v2: Linux Boogaloo
CHECK OUT Capture the CISO season 2 here.
Thanks to today's episode sponsor, Vanta
The average security pro spends nearly a full workday every week just on compliance. With Vanta, you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA. Even more, Vanta’s market-leading Trust Management Platform enables you to unify security program management with a built-in risk register and reporting, and streamline security reviews with AI-powered security questionnaires. Over 7,000 fast-growing companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security in real time. Watch Vanta’s on-demand demo at vanta.com/ciso.
Ukraine's head of cybersecurity suspended and assigned to combat zone
Over 90,000 LG Smart TVs exposed to remote attack
Microsoft exposed internal passwords in security lapse
Thanks to today's episode sponsor, Vanta
The average security pro spends nearly a full workday every week just on compliance. With Vanta, you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA. Even more, Vanta’s market-leading Trust Management Platform enables you to unify security program management with a built-in risk register and reporting, and streamline security reviews with AI-powered security questionnaires. Over 7,000 fast-growing companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security in real time. Watch Vanta’s on-demand demo at vanta.com/ciso.
For the stories behind the headlines, visit CISOseries.com.
Cyberattack causes major disruptions for UK vet firm
Data privacy bill pushes forward with bipartisan support
Department of Justice hack exposes hundreds of thousands
Thanks to today's episode sponsor, Vanta
The average security pro spends nearly a full workday every week just on compliance. With Vanta, you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA. Even more, Vanta’s market-leading Trust Management Platform enables you to unify security program management with a built-in risk register and reporting, and streamline security reviews with AI-powered security questionnaires. Over 7,000 fast-growing companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security in real time. Watch Vanta’s on-demand demo at vanta.com/ciso.
Government warns hospitals of hackers targeting IT help desks
U.S. government contractor Acuity responds to alleged Five Eyes breach
New York City becomes latest in municipal government hack attempts
Thanks to today's episode sponsor, Vanta
The average security pro spends nearly a full workday every week just on compliance. With Vanta, you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA. Even more, Vanta’s market-leading Trust Management Platform enables you to unify security program management with a built-in risk register and reporting, and streamline security reviews with AI-powered security questionnaires. Over 7,000 fast-growing companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security in real time. Watch Vanta’s on-demand demo at vanta.com/ciso.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by David Spark with guest Steve Gentry, Advisor, Clari
Thanks to our show sponsor, Vanta
The average security pro spends nearly a full workday every week just on compliance.
With Vanta, you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA.
Even more, Vanta’s market-leading Trust Management Platform enables you to unify security program management with a built-in risk register and reporting, and streamline security reviews with AI-powered security questionnaires.
Over 7,000 fast-growing companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security in real time.
Watch Vanta’s on-demand demo at vanta.com/ciso.
All links and the video of this episode can be found on CISO Series.com
Classified Five Eyes data theft announced
Cancer center data breach affects 800,000
Android Pixel phone zero-day flaws being exploited by forensic companies
Thanks to today's episode sponsor, Vanta
The average security pro spends nearly a full workday every week just on compliance.
With Vanta, you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA.
Even more, Vanta’s market-leading Trust Management Platform enables you to unify security program management with a built-in risk register and reporting, and streamline security reviews with AI-powered security questionnaires.
Over 7,000 fast-growing companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security in real time.
Watch Vanta’s on-demand demo at vanta.com/ciso to learn more.
For the stories behind the headlines, head to CISOseries.com.
Report criticizes Microsoft’s Chinese hack response
NIST needs help with vulnerability backlog
Chrome tests feature to prevent session hijacking
Thanks to today's episode sponsor, Vanta
The average security pro spends nearly a full workday every week just on compliance.
With Vanta, you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA.
Even more, Vanta’s market-leading Trust Management Platform enables you to unify security program management with a built-in risk register and reporting, and streamline security reviews with AI-powered security questionnaires.
Over 7,000 fast-growing companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security in real time.
Watch Vanta’s on-demand demo at vanta.com/ciso to learn more.
CISA releases draft rule for cyber incident reporting
Google now blocks spoofed emails for better phishing protection
Breach at online shopping platform PandaBuy affects 1.3 million customers
Thanks to today's episode sponsor, Vanta
The average security pro spends nearly a full workday every week just on compliance.
With Vanta, you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA.
Even more, Vanta’s market-leading Trust Management Platform enables you to unify security program management with a built-in risk register and reporting, and streamline security reviews with AI-powered security questionnaires.
Over 7,000 fast-growing companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security in real time.
Watch Vanta’s on-demand demo at vanta.com/ciso to learn more.
For the stories behind the headlines, head to CISOseries.com.
Google to delete Incognito tracking data
Hallucinated software packages as a security vulnerability
FCC investigating phone infrastructure security
Thanks to today's episode sponsor, Vanta
The average security pro spends nearly a full workday every week just on compliance.
With Vanta, you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA.
Even more, Vanta’s market-leading Trust Management Platform enables you to unify security program management with a built-in risk register and reporting, and streamline security reviews with AI-powered security questionnaires.
Over 7,000 fast-growing companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security in real time.
Watch Vanta’s on-demand demo at vanta.com/ciso to learn more.
Data of 73 million AT&T customers leaked on dark web
Accidental Linux backdoor discovery likely prevented thousands of infections
DHS expected to stop buying access to your phone info
Thanks to today's episode sponsor, Vanta
The average security pro spends nearly a full workday every week just on compliance.
With Vanta, you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA.
Even more, Vanta’s market-leading Trust Management Platform enables you to unify security program management with a built-in risk register and reporting, and streamline security reviews with AI-powered security questionnaires.
Over 7,000 fast-growing companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security in real time.
Watch Vanta’s on-demand demo at vanta.com/ciso to learn more.
For the stories behind the headlines, visit CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Yaron Levi, CISO, Dolby, and sageinsights.io
Thanks to our show sponsor, Varonis
Ready to reduce your risk without taking any? Try Varonis’ free data risk assessment. It takes minutes to set up and in 24 hours you’ll have a clear, risk-based view of the data that matters most and a clear path to automated remediation. Get started for free today at varonis.com/cisoseries.
All links and the video of this episode can be found on CISO Series.com
17 billion personal records exposed in data breaches in 2023
U.S. Treasury warns financial sector about AI cybersecurity threats
Retail chain Hot Topic hit by new credential stuffing attacks
Thanks to today's episode sponsor, Varonis
Ready to reduce your risk without taking any? Try Varonis’ free data risk assessment. It takes minutes to set up and in 24 hours you’ll have a clear, risk-based view of the data that matters most and a clear path to automated remediation. Get started for free today at varonis.com/cisoseries.
For the stories behind the headlines, head to CISOseries.com.
Spyware fuels rise in zero-day exploits
CISA warns about Microsoft SharePoint vulnerability
Facebook snooped on encrypted Snapchat traffic
Thanks to today's episode sponsor, Varonis
Ready to reduce your risk without taking any? Try Varonis’ free data risk assessment. It takes minutes to set up and in 24 hours you’ll have a clear, risk-based view of the data that matters most and a clear path to automated remediation. Get started for free today at varonis.com/cisoseries.
APT31 targeting family members to surveil targets
Ransomware gang attacks UK newspaper supporting the homeless
MFA bombing attacks target Apple users
Thanks to today's episode sponsor, Varonis
Ready to reduce your risk without taking any? Try Varonis’ free data risk assessment. It takes minutes to set up and in 24 hours you’ll have a clear, risk-based view of the data that matters most and a clear path to automated remediation. Get started for free today at varonis.com/cisoseries. For the stories behind the headlines, visit CISOseries.com.
EU targets tech giants with DMA
China starts US tech ban in government
Think tank calls for US military cyber service
Thanks to today's episode sponsor, Varonis
Ready to reduce your risk without taking any? Try Varonis’ free data risk assessment. It takes minutes to set up and in 24 hours you’ll have a clear, risk-based view of the data that matters most and a clear path to automated remediation. Get started for free today at varonis.com/cisoseries.
Kimsuky turns to compiled HTML Help files for cyberattacks
KDE issues warning after theme wipes Linux user’s files
Critical flaw in Atlassian Bamboo data center and server must be fixed immediately
Thanks to today's episode sponsor, Varonis
Ready to reduce your risk without taking any? Try Varonis’ free data risk assessment. It takes minutes to set up and in 24 hours you’ll have a clear, risk-based view of the data that matters most and a clear path to automated remediation. Get started for free today at varonis.com/cisoseries.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review, is hosted by Rich Stroffolino with guest Gerald Auger Ph.D., Chief Content Creator, Simply Cyber
Thanks to our show sponsor, Vanta
Managing the requirements for modern security programs is increasingly challenging. Vanta’s trust management platform helps you quickly assess risk, streamline security reviews, and automate compliance for SOC 2, ISO 27001, HIPAA, and more. Plus, you can save time by completing security questionnaires with Vanta AI. Join over 7,000 global companies that use Vanta to automate evidence collection, unify risk management, and secure customer trust. To learn more, go to vanta.com/ciso
All links and the video of this episode can be found on CISO Series.com
Microsoft confirms Windows Server issue behind domain controller crashes
Over 800 npm packages found with discrepancies
Nemesis darknet marketplace raided in Germany-led operation
Thanks to today's episode sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
For the stories behind the headlines, head to CISOseries.com.
US plans Water Sector Cybersecurity Task Force
Loop DoS attack exploits the infinite regress of UDP
GitHub tool uses AI to fix vulnerabilities
Thanks to today's episode sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
Mid-stream hack postpones ESports league
Bank loses $40 million after “systems glitch”
LockBit reemerges with vengeance
Thanks to today's episode sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
UnitedHealth fronts over $2 billion in recovery efforts
Spyware agreement gains more international support
FTC probes Reddit's AI data licensing ahead of IPO
Thanks to today's episode sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
Global McDonald’s outage blamed on third-party vendor, not cyberattack
Google adds real-Time URL protection for Chrome
Network outages hit Birmingham Alabama
Thanks to today's episode sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Alexandra Landegger, Executive Director and CISO Collins Aerospace
Thanks to our show sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
All links and the video of this episode can be found on CISO Series.com
Change Healthcare - AHA asks for aid, HHS questions HIPAA compliance
Fortinet warns of severe SQLi vulnerability in FortiClientEMS software
Yacht company MarineMax announces cyberattack
Thanks to today's episode sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
For the stories behind the headlines, head to CISOseries.com.
Researchers find vulnerabilities in Gemini
New York Times denies it “hacked” OpenAI for lawsuit
Leaked GitHub secrets up 28%
Thanks to today's episode sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
LockBit takes credit for hacking South African pension fund
CISA’s OT attack response team understaffed
US and Russia accuse each other of potential election cyberattacks
Thanks to today's episode sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
For the stories behind the headlines, visit CISOseries.com.
Roku forces reset after 15,000 accounts compromised
French government agencies targeted in “unprecedented” attacks
Fintech firm taken offline by ransomware attack
Thanks to today's episode sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
For the stories behind the headlines, head to CISOseries.com.
Microsoft says Russian hackers breached its systems, accessed source code
CISA adds JetBrains TeamCity bug to its KEV catalog
Over 225,000 compromised ChatGPT credentials for sale
Thanks to today's episode sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest David Cross, SVP/CISO, Oracle. Also check out David’s travel blog, DavidCrossTravels.com
Thanks to our show sponsor, Conveyor
Conveyor is the AI security review automation platform helping infosec teams automate everything from securely sharing a SOC 2 to one-click autofilling security questionnaires in OneTrust so you can spend almost zero time on the manual tasks that make you want to throw your computer out the window. Teams are finding in a free proof of concept that our AI is better than the rest. Learn more at www.conveyor.com. Mention this podcast for 5 free questionnaire credits when you purchase an Enterprise plan.
All links and the video of this episode can be found on CISO Series.com
Flipper Zero WiFi attack can unlock and steal Tesla cars
Former Google engineer indicted for stealing AI secrets for Chinese companies
PetSmart warns customers of credential stuffing attack
Thanks to today's episode sponsor, Conveyor
Conveyor is the AI security review automation platform helping infosec teams automate everything from securely sharing a SOC 2 to one-click autofilling security questionnaires in OneTrust so you can spend almost zero time on the manual tasks that make you want to throw your computer out the window. Teams are finding in a free proof of concept that our AI is better than the rest. Learn more at www.conveyor.com. Mention this podcast for 5 free questionnaire credits when you purchase an Enterprise plan.
For the stories behind the headlines, head to CISOseries.com.
Online fraud hits record losses
States urge Meta to crack down on scammers
Apple issues update for zero-day flaw
Thanks to today's episode sponsor, Conveyor
Happy Thursday. Are you tired of us talking about how Conveyor’s AI security review automation software? We’ll stop talking about it if you come talk to them. Ready to give the market leading AI for security questionnaires a spin? Try a free proof of concept at www.conveyor.com. Don’t forget to mention this podcast for 5 free questionnaire credits when you purchase an Enterprise plan.
For the stories behind the headlines, head to CISOseries.com.
US cybersecurity strategy update on the way
US Treasury issues first spyware sanctions
UK denies responsibility for ALPHV takedown
Thanks to today's episode sponsor, Conveyor
Conveyor is the only GPT-powered customer trust portal that automates the entire customer security review process — from sharing your security posture and documents in a single portal to automating security questionnaire responses with 90% accuracy so you can fly through any customer security review in minutes. It might sound like every other compliance software claim out there, but there’s a reason our customers have dubbed Conveyor their ‘favorite security tool of the year’. Test our market-leading AI in a free proof of concept at www.conveyor.com
North Korea targets semiconductor industry
ALPHV infrastructure goes dark
China to offer computing vouchers to AI startups
Thanks to today's episode sponsor, Conveyor
AI is getting pretty smart so you shouldn’t settle for mediocre security questionnaire automation software that only generates the right answer 20 to 50 percent of the time or have to wait a day for the vendor’s team to check the answers. Conveyor's security questionnaire automation tool not only boasts industry leading AI accuracy reducing time spent on security reviews by 80%, but now also autofills in OneTrust portal questionnaires with a single click. Trying a proof of concept with your own data is always free. Learn more at www.conveyor.com. Mention this podcast for 5 free questionnaire credits when you purchase an Enterprise plan.
NSO Group to ordered to give Pegasus code to WhatsApp
Change Healthcare confirms BlackCat, Schumer asks for aid
Law firm announces data breach affecting 325,000 people
Thanks to today's episode sponsor, Conveyor
We’ve got a returning sponsor this week – Conveyor. They’re the AI security review automation platform helping infosec teams automate everything from securely sharing a SOC 2 to one-click autofilling security questionnaires in OneTrust so you can spend almost zero time on the manual tasks that make you want to throw your computer out the window. Teams are finding in a free proof of concept that their AI is better than the rest. Learn more at www.conveyor.com. Mention this podcast for 5 free questionnaire credits when you purchase an Enterprise plan.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Russ Ayres, SVP of Cyber & Deputy CISO, Equifax
Thanks to our show sponsor, Egress
People are the biggest risk to your organization’s security, and they are most vulnerable when using email.
With more advanced threats getting through secure email gateway detection every day, Egress provides AI-powered email security that eliminates both inbound phishing attacks and outbound data breaches. What's more, Egress' adaptive security architecture personalizes security for each user based on their real-time risk score.
Visit egress.com to learn more about Egress’ Intelligent Cloud Email Security suite and start detecting email threats your secure email gateway is missing today.
All links and the video of this episode can be found on CISO Series.com
Pharma giant Cencora announces data breach
GenAI drives surge in BEC attacks
Popular video doorbell easy hijacked
Thanks to today's episode sponsor, Egress
People are the biggest risk to your organizations' security and they are most vulnerable when using email. With more advanced threats getting through secure email gateway detection every day, Egress provides AI-powered email security that eliminates both inbound phishing attacks and outbound data breaches. What's more, Egress' adaptive security architecture personalizes security for each user based on their real-time risk score. Visit egress.com to learn more about Egress' Intelligent Cloud Email Security suite and start detecting email threats your secure email gateway is missing today.
For the stories behind the headlines, head to CISOseries.com.
Biden signs order limiting the sale of personal data
Australia claims its seeing unprecedented “foreign interference”
Lazarus Group targeting Windows and PyPi
Thanks to today's episode sponsor, Egress
People are the biggest risk to your organizations' security and they are most vulnerable when using email. With more advanced threats getting through secure email gateway detection every day, Egress provides AI-powered email security that eliminates both inbound phishing attacks and outbound data breaches. What's more, Egress' adaptive security architecture personalizes security for each user based on their real-time risk score. Visit egress.com to learn more about Egress' Intelligent Cloud Email Security suite and start detecting email threats your secure email gateway is missing today.
NIST releases cybersecurity framework 2.0
Optum attack linked to BlackCat ransomware
ScreenConnect exploitations continue
Thanks to today's episode sponsor, Egress
People are the biggest risk to your organizations' security and they are most vulnerable when using email. With more advanced threats getting through secure email gateway detection every day, Egress provides AI-powered email security that eliminates both inbound phishing attacks and outbound data breaches. What's more, Egress' adaptive security architecture personalizes security for each user based on their real-time risk score. Visit egress.com to learn more about Egress' Intelligent Cloud Email Security suite and start detecting email threats your secure email gateway is missing today.
SolarWinds attackers changing tactics
Brand domains used in spam operation
Steel giant hit with cyberattack
Thanks to today's episode sponsor, Egress
People are the biggest risk to your organizations' security and they are most vulnerable when using email. With more advanced threats getting through secure email gateway detection every day, Egress provides AI-powered email security that eliminates both inbound phishing attacks and outbound data breaches. What's more, Egress' adaptive security architecture personalizes security for each user based on their real-time risk score. Visit egress.com to learn more about Egress' Intelligent Cloud Email Security suite and start detecting email threats your secure email gateway is missing today.
British police taunt LockBit administrator
PayPal files patent for new stolen cookies detector
Vending machine crash reveals face recognition tech
Thanks to today's episode sponsor, Egress
People are the biggest risk to your organizations' security and they are most vulnerable when using email. With more advanced threats getting through secure email gateway detection every day, Egress provides AI-powered email security that eliminates both inbound phishing attacks and outbound data breaches. What's more, Egress' adaptive security architecture personalizes security for each user based on their real-time risk score. Visit egress.com to learn more about Egress' Intelligent Cloud Email Security suite and start detecting email threats your secure email gateway is missing today.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Thom Langford, CISO, Velonetic
Thanks to our show sponsor, Conveyor
Conveyor AI is so good, it can now autofill OneTrust portal questionnaires in one click. Yes, we’ve been talking about it all week. Conveyor's security questionnaire automation tool not only boasts industry leading AI accuracy, but now fills in One Trust portals with a single click. Trying a proof of concept with your own data is always free. Learn more at www.conveyor.com. Mention this podcast for 5 free questionnaire credits when you purchase an Enterprise plan.
All links and the video of this episode can be found on CISO Series.com
LockBit was building next gen encryptor before takedown
Thousands of wireless customers suffer outage
Prescription delays due to Change Healthcare cyberattack
Thanks to today's episode sponsor, Conveyor
Conveyor, the security questionnaire automation software one of their customers dubbed “my favorite security tool of the year”, is now even better. They’ve upgraded our browser extension for portal-based questionnaires and it can now autofill OneTrust portal questionnaires in one click. You can test the AI in a free proof of concept at www.conveyor.com. Mention this podcast for 5 free questionnaire credits when you purchase an Enterprise plan.
Get the stories behind the headlines at CISOSeries.com
Thanks to today's episode sponsor, Conveyor
Happy Thursday. Are you tired of us talking about how Conveyor’s AI can now autofill OneTrust security questionnaires in one-click? Well, we’ll stop talking about it if you come talk to them. Ready to give the market leading AI for security questionnaires a spin? Try a free proof of concept by booking a demo at www.conveyor.com. And mention this podcast for 5 free questionnaire credits when you purchase an Enterprise plan.
Get the stories behind the headlines at CISOSeries.com
LockBit takedown update
Signal now lets users keep phone numbers private
NSA Cybersecurity Director Rob Joyce to retire
Thanks to today's episode sponsor, Conveyor
No more portal scaries. Conveyor just launched AI autofill of OneTrust portal questionnaires. That means no more clicking question-by-question to copy-paste each answer when a customer sends you a OneTrust security questionnaire. Conveyor’s AI will read and autofill the whole page for you. Trying a proof of concept with your own data is always free. Learn more at www.conveyor.com. Mention this podcast for 5 free questionnaire credits when you purchase an Enterprise plan.
Get the stories behind the headlines at CISOSeries.com
LockBit disrupted by global police operation
Cactus leaks Schneider Electric data on dark web
ALPHV gang takes credit for LoanDepot, Prudential attacks
Thanks to today's episode sponsor, Conveyor
Conveyor, the security questionnaire automation software one of our customers dubbed “my favorite security tool of the year”, is now even better. They’ve upgraded their browser extension for portal-based questionnaires and it can now autofill OneTrust portal questionnaires in one click. You can test the AI in a free proof of concept at www.conveyor.com. Mention this podcast for 5 free questionnaire credits when you purchase an Enterprise plan.
Get the stories behind the headlines at CISOSeries.com
Google Chrome feature blocks attacks against home networks
Mastermind behind Zeus and IcedID malware pleads guilty
Air Canada must honor refund invented by its chatbot, says court
Thanks to today's episode sponsor, Conveyor
Conveyor AI is so good, it can now autofill OneTrust portal questionnaires in one click. Yes, you heard us right. Conveyor's security questionnaire automation tool not only boasts industry leading AI accuracy, but now fills in One Trust portals with a single click. Trying a proof of concept with your own data is always free. Learn more at www.conveyor.com. Mention this podcast for 5 free questionnaire credits when you purchase an Enterprise plan.
Get the stories behind the headlines at CISOSeries.com
Link to blog post
This week’s Cyber Security Headlines - Week in Review is hosted by Rich Stroffolino with guest Trina Ford, CISO, iHeartMedia
Thanks to our show sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
All links and the video of this episode can be found on CISO Series.com
Microsoft warns of new Exchange Server zero-day
Neuberger: Pace of ransomware takedown operations isn’t enough
Gold Pickaxe malware steals your face
Huge thanks to our sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
For the stories behind the headlines, head to CISOseries.com.
Trans-Northern Pipelines confirms cyberattack
Threat actors using LLMs to improve cyberattacks
Email provider published internal emails in plain text
Huge thanks to our sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
Prudential Financial data breached in cyberattack
Facebook Marketplace user records leaked on hacking forum
Bank of America customers at risk after third party breach
Huge thanks to our sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
For the stories behind the headlines, visit CISOseries.com.
CISA releases repository security framework
Ransomware takes down Romanian healthcare management system
Ivanti flaw used to deploy backdoor
Huge thanks to our sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
Raspberry Robin – a new one-day exploit targeting Windows
Hyundai Europe suffers Black Basta ransomware attack
Cisco to cut thousands of jobs as it focuses on high growth areas
Huge thanks to our sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Doug Mayer, vp, CISO, WCG
Thanks to our show sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
All links and the video of this episode can be found on CISO Series.com
CISA, FBI issue sobering warning about Volt Typhoon
Cisco fixes critical Expressway flaws
3 million records from thousands of credit unions exposed
Thanks to today's episode sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging.
Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization.
Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk.
To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
For the stories behind the headlines, visit CISOseries.com.
CISA collaboration initiative on thin ice
Iran focusing cyber efforts
Ransomware payments cross $1 billion in 2023
Thanks to today's episode sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging.
Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization.
Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk.
To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
For the stories behind the headlines, visit CISOseries.com.
Tech giants and world govs unite to tackle spyware threats
Spyware vendors to blame for most Google zero-days
Insider data breach hits almost half of Verizon’s employee base
Thanks to today's episode sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging.
Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization.
Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk.
To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
For the stories behind the headlines, visit CISOseries.com.
Spoutible API vulnerability leaks user data
Illicit service cranks out fake IDs
Sudo coming to Windows
Thanks to today's episode sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging.
Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization.
Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk.
To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
For the stories behind the headlines, visit CISOseries.com.
Cloudflare announces nation-state level breach
AnyDesk says hackers breached production servers, reset passwords
Chicago children’s hospital announces cyberattack
Thanks to today's episode sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging.
Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization.
Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk.
To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
For the stories behind the headlines, visit CISOseries.com.
Link to blog post
Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Mary Rose Martinez, vp, CISO Marathon Petroleum
Thanks to our show sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
All links and the video of this episode can be found on CISO Series.com
FBI director warns of Chinese hacker threat to U.S. critical infrastructure
CISA warns of exploited Apple flaw
Pentagon Intelligence supplier allegedly hacked
Thanks to today's episode sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging.
Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization.
Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk.
To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
For the stories behind the headlines, visit CISOseries.com.
FBI grounds Volt Typhoon
More companies refuse to pay ransoms
Binance internal info exposed on GitHub
Thanks to today's episode sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging.
Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization.
Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk.
To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
For the stories behind the headlines, visit CISOseries.com.
Mercedes-Benz exposes sensitive data, source code
Juniper Networks issues out-of-band fix for high severity flaws
New ZLoader malware, now with 64-bit Windows compatibility
Thanks to today's episode sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging.
Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization.
Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk.
To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
For the stories behind the headlines, visit CISOseries.com.
Microsoft takes another hit
Energy giant hit by ransomware
The NSA is secretly buying your data
Thanks to today's episode sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging.
Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization.
Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk.
To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
For the stories behind the headlines, visit CISOseries.com.
Urgent patch alert for Jenkins
Cisco flaw exposes Unified Comms systems
Pro-Ukraine hackers wipe 2 petabytes of data from Russian intelligence center
Thanks to today's episode sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging.
Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization.
Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk.
To learn more, go to vanta.com/ciso and watch their 3-minute product demo.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Mike Kelley, vp, CISO, The E.W. Scripps Company and partner, OTAWireless.com.
Thanks to our show sponsor, Conveyor
Conveyor, the security questionnaire automation software known for generating the most accurate AI answers to questionnaires is launching a much-requested feature. Conveyor’s AI can now use uploaded security documents like a SOC 2 and security policy whitepapers to auto-generate precise answers to entire questionnaires in seconds. See why customers like Lucid and Carta are raving about the software and try the AI yourself in a free proof of concept at www.conveyor.com.
All links and the video of this episode can be found on CISO Series.com
Hewlett Packard Enterprise (HPE) attacked through Microsoft 365 email system
Study reveals 18,000 exposed API secrets, including $20 million in vulnerable Stripe tokens
Ukrainian energy, postal, and transportation services hit by cyberattacks
Thanks to today's episode sponsor, Conveyor
Conveyor, the security questionnaire automation software known for generating the most accurate AI answers to questionnaires is launching a much-requested feature. Conveyor’s AI can now use uploaded security documents like a SOC 2 and security policy whitepapers to auto-generate precise answers to entire questionnaires in seconds. See why customers like Lucid and Carta are raving about the software and try the AI yourself in a free proof of concept at www.conveyor.com.
For the stories behind the headlines, head to CISOseries.com.
Cyberattack knocks EquiLend offline
Brits warn of the AI impact on ransomware
Data leak claims to hold over 26 billion records
Thanks to today's episode sponsor, Conveyor
Conveyor, the security questionnaire automation software one of our customers dubbed “my favorite security tool of the year”, is now even better. How? Conveyor’s AI can now use uploaded security documents like a SOC 2 or security policy document to auto-generate precise answers to entire security questionnaires in seconds. You can test the AI in a free proof of concept at www.conveyor.com.
CISA boss targeted in “harrowing” swatting attack
Subway puts a LockBit investigation on the menu
Australia sanctions REvil hacker behind Medibank data breach
Thanks to today's episode sponsor, Conveyor
Ever wish AI could auto-generate answers to security questionnaires for you just based on your SOC 2 or other documents? Spoiler alert - it can and you can now try it for free with Conveyor’s AI security questionnaire automation software. Set up takes a few seconds. Get a free Conveyor account and simply upload your security documents. Then, upload a new questionnaire to see AI generate answers in seconds based on your documents. Try a free proof of concept today at www.conveyor.com.
For the stories behind the headlines, visit CISOseries.com.
Thailand court attempts to suppress data leak
CISA issues emergency directive on Ivanti zero-days
Cybersecurity startup funding down 50%
Huge thanks to our episode sponsor, Conveyor
What’s worse than a last minute security questionnaire in your inbox?
Having to maintain a thousand question and answer pairs to use to respond to a questionnaire.
Now, Conveyor’s AI security questionnaire automation software can use security documents like a SOC 2 and a pared down question and answer bank to auto-generate precise answers to entire questionnaires in seconds.
Try a free proof of concept today at www.conveyor.com.
Russian hackers breach Microsoft executive emails to learn about themselves
JPMorgan Chase says hacking attempts are increasing
TeamViewer still being abused to breach networks in new ransomware attacks
Thanks to today's episode sponsor, Conveyor
AI can now literally answer any question in seconds, yet infosec teams are still in a living nightmare manually filling out questionnaires. Conveyor AI’s can now use your uploaded security documents to auto-generate precise answers to entire questionnaires. The software one of our customers dubbed “my favorite security tool of the year” in 2023 has gotten even better and it takes just minutes to get started. Try a free proof of concept at www.conveyor.com.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Jerich Beason, CISO, WM
Thanks to our show sponsor, Savvy Security
Shadow identities on SaaS apps are growing unchecked, rapidly expanding an attack surface where businesses have little-to-no visibility or control. Savvy helps security teams safely embrace SaaS benefits by automating the discovery and removal of the most toxic combinations of SaaS identity risk. Savvy’s automation playbooks and just-in-time security guardrails guide users at scale towards proper identity hygiene. That’s Savvy—Identity-First SaaS Security. Learn more at savvy.security/headlines.
All links and the video of this episode can be found on CISO Series.com
Atlassian outage briefly affected multiple cloud services
iShutdown helps discover spyware on iPhones
Russian state hackers COLDRIVER deploy malware in European espionage campaign
Huge thanks to our sponsor, Savvy Security
Shadow identities on SaaS apps are growing unchecked, rapidly expanding an attack surface where businesses have little-to-no visibility or control. Savvy helps security teams safely embrace SaaS benefits by automating the discovery and removal of the most toxic combinations of SaaS identity risk. Savvy’s automation playbooks and just-in-time security guardrails guide users at scale towards proper identity hygiene. That’s Savvy—Identity-First SaaS Security.
Learn more at savvy.security/headlines.
For the stories behind the headlines, head to CISOseries.com.
Chinese drones considered national security threat
PixieFail could spell trouble for cloud providers
Have I Been Pwned adds “statistically significant” data leak
Huge thanks to our sponsor, Savvy Security
Shadow identities on SaaS apps are growing unchecked, rapidly expanding an attack surface where businesses have little-to-no visibility or control. Savvy helps security teams safely embrace SaaS benefits by automating the discovery and removal of the most toxic combinations of SaaS identity risk. Savvy’s automation playbooks and just-in-time security guardrails guide users at scale towards proper identity hygiene. That’s Savvy—Identity-First SaaS Security.
Learn more at savvy.security/headlines.
Google patches first Chrome zero-day vulnerability of the year
Urgent warning from Citrix to patch two zero-day vulnerabilities
New malware strain persists despite patch
Huge thanks to our sponsor, Savvy Security
Shadow identities on SaaS apps are growing unchecked, rapidly expanding an attack surface where businesses have little-to-no visibility or control. Savvy helps security teams safely embrace SaaS benefits by automating the discovery and removal of the most toxic combinations of SaaS identity risk. Savvy’s automation playbooks and just-in-time security guardrails guide users at scale towards proper identity hygiene. That’s Savvy—Identity-First SaaS Security.
Learn more at savvy.security/headlines.
Turkey blocks some VPNs
OpenAI publishes election guidance
Spanish municipality faces stiff ransomware demand
Huge thanks to our sponsor, Savvy Security
Shadow identities on SaaS apps are growing unchecked, rapidly expanding an attack surface where businesses have little-to-no visibility or control. Savvy helps security teams safely embrace SaaS benefits by automating the discovery and removal of the most toxic combinations of SaaS identity risk. Savvy’s automation playbooks and just-in-time security guardrails guide users at scale towards proper identity hygiene. That’s Savvy—Identity-First SaaS Security.
Learn more at savvy.security/headlines.
Ransomware gang targets clean water nonprofit
Denmark energy sector attacks likely not Sandworm after all
SEC says X account breach did not lead to further breaches
Thanks to our episode sponsor, Savvy Security
Shadow identities on SaaS apps are growing unchecked, rapidly expanding an attack surface where businesses have little-to-no visibility or control. Savvy helps security teams safely embrace SaaS benefits by automating the discovery and removal of the most toxic combinations of SaaS identity risk. Savvy’s automation playbooks and just-in-time security guardrails guide users at scale towards proper identity hygiene. That’s Savvy—Identity-First SaaS Security. Learn more at savvy.security/headlines.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Allan Cockriel, Group CISO, Shell
Thanks to our show sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To see Vanta’s platform firsthand and access resources plus a special offer, go to vanta.com/ciso and watch their 3-minute product demo.
All links and the video of this episode can be found on CISO Series.com
Ivanti VPN hit by zero-days
Akira targeting backups
Sensitive school data accidentally exposed online
Remember to subscribe to the Cyber Security Headlines newsletter here.
Thanks to today's episode sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To see Vanta’s platform firsthand and access resources plus a special offer, go to vanta.com/ciso and watch their 3-minute product demo.
Texas healthcare provider suffer data breach
Entire population of Brazil possibly exposed in data leak
Decryptor for Tortilla ransomware released
Thanks to today's episode sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To see Vanta’s platform firsthand and access resources plus a special offer, go to vanta.com/ciso and watch their 3-minute product demo.
For the stories behind the headlines, head to CISOseries.com.
Bitcoin price spikes after SEC Twitter account hijack
Twitter account hijack wave affects Mandiant
China claims it cracked Apple AirDrop
Thanks to today's episode sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To see Vanta’s platform firsthand and access resources plus a special offer, go to vanta.com/ciso and watch their 3-minute product demo.
For the stories behind the headlines, head to CISOseries.com.
Google accounts hacked: No passwords required
loanDepot joins growing list of US mortgage lenders attacked
Netgear and Hyundai’s X accounts latest to be compromised in crypto scam
Thanks to today's episode sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To see Vanta’s platform firsthand and access resources plus a special offer, go to vanta.com/ciso and watch their 3-minute product demo.
Merck and its insurers settle $1.4 billion NotPetya case
BreachForums admin Popompurin breaches terms of pretrial freedom
Iranian crypto exchange Bit24.cash accidentally exposes customer data
Thanks to today's episode sponsor, Vanta
From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To see Vanta’s platform firsthand and access resources plus a special offer, go to vanta.com/ciso and watch their 3-minute product demo.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Johna Till Johnson, CEO, Nemertes, and podcaster at Heavy Strategy.
Thanks to our show sponsor, NetSPI
Take the hassle out of dealing with alert fatigue, validation, and prioritization. Instead, use NetSPI’s ASM platform to hone in on what’s actually important. Attack surface vulnerabilities constantly evolve, causing a lack of visibility and overwhelm for your security teams. Start the new year off right by partnering with NetSPI to enhance your security program. Visit netspi.com/ASM
All links and the video of this episode can be found on CISO Series.com
Mandiant Twitter account restored after crypto scam hack
Law firm that handles data breaches hit by data breach
Spanish mobile carrier suffers outage after account takeover
Thanks to today's episode sponsor, NetSPI
Take the hassle out of dealing with alert fatigue, validation, and prioritization. Instead, use NetSPI's ASM platform to hone in on what's actually important. Attack surface vulnerabilities constantly evolve, causing a lack of visibility and overwhelm for your security teams. Start the new year off right by partnering with NetSPI to enhance your security program. Visit netspi.com/ASM to learn more.
For the stories behind the headlines, head to CISOseries.com.
A call for formal ban on ransomware payments
FTC asks for ideas to fight voice cloning
Cyberattack impacts French township
Thanks to today's episode sponsor, NetSPI
Take the hassle out of dealing with alert fatigue, validation, and prioritization. Instead, use NetSPI's ASM platform to hone in on what's actually important. Attack surface vulnerabilities constantly evolve, causing a lack of visibility and overwhelm for your security teams. Start the new year off right by partnering with NetSPI to enhance your security program. Visit netspi.com/ASM to learn more.
Google settles $5 billion ‘incognito mode’ lawsuit
Over $80 million in crypto stolen from Orbit Chain
Watchdog calls for updated medical device cyber agreement
Thanks to today's episode sponsor, NetSPI
Take the hassle out of dealing with alert fatigue, validation, and prioritization. Instead, use NetSPI's ASM platform to hone in on what's actually important. Attack surface vulnerabilities constantly evolve, causing a lack of visibility and overwhelm for your security teams. Start the new year off right by partnering with NetSPI to enhance your security program. Visit netspi.com/ASM to learn more. Take the hassle out of dealing with alert fatigue, validation, and prioritization. Instead, use NetSPI's ASM platform to hone in on what's actually important. Attack surface vulnerabilities constantly evolve, causing a lack of visibility and overwhelm for your security teams. Start the new year off right by partnering with NetSPI to enhance your security program. Visit netspi.com/ASM to learn more.
For the stories behind the headlines, visit CISOseries.com.
Swedish national grocer stung by Cactus
Flaw in Black Basta decryptor allows recovery of victims’ files - temporarily
Cyberattack hist Boston area hospital
Thanks to today's episode sponsor, NetSPI
Take the hassle out of dealing with alert fatigue, validation, and prioritization. Instead, use NetSPI's ASM platform to hone in on what's actually important. Attack surface vulnerabilities constantly evolve, causing a lack of visibility and overwhelm for your security teams. Start the new year off right by partnering with NetSPI to enhance your security program. Visit netspi.com/ASM to learn more.
For the stories behind the headlines, head to CISOseries.com.
LockBit hits German hospital system over the holidays
Ohio Lottery cyberattack claimed by DragonForce
First American says funds are secure
Thanks to today's episode sponsor, Barricade Cyber Solutions
Don't let ransomware ruin the holidays again this year! Prepare and spread holiday cheer with recoverfromransomware.com! The trusted DFIR experts at Barricade Cyber Solutions have saved 3,000 and counting businesses from ransomware attacks, including small and medium businesses just like yours! Barricade Cyber is YOUR solution for rapid data and systems recovery. Book a meeting directly with the CEO to discover how to recover from ransomware. Visit recoverfromransomware.com.
For the stories behind the headlines, head to CISOseries.com.
Threat actors install backdoor on Barracuda appliances
iPhone triangulation exploit used undocumented features
New York Times starts the publisher LLM lawsuits
Thanks to today's episode sponsor, Barricade Cyber Solutions
Don't let ransomware ruin the holidays again this year! Prepare and spread holiday cheer with recoverfromransomware.com! The trusted DFIR experts at Barricade Cyber Solutions have saved 3,000 and counting businesses from ransomware attacks, including small and medium businesses just like yours! Barricade Cyber is YOUR solution for rapid data and systems recovery. Book a meeting directly with the CEO to discover how to recover from ransomware. Visit recoverfromransomware.com.
CBS and Paramount owner hacked a year ago
Rockstar Games allegedly suffers source code leak
LoanCare says 1.3 million people affected by cyberattack
Thanks to today's episode sponsor, Barricade Cyber Solutions
When you're hit with ransomware, remember recoverfromransomware.com. Barricade Cyber Solutions' experienced DFIR team is ready to help your business recover from ransomware now. You'll work directly with the CEO to resolve your case quickly and efficiently. Whether you're experiencing a ransomware attack or want to get ahead of one by discussing a prevention plan, contact Barricade Cyber Solutions at recoverfromransomware.com.
For the stories behind the headlines, visit CISOseries.com.
First American suffers cyberattack, website down
Iran-linked group targets defense contractors worldwide
November saw record numbers of ransomware leak site victims
Thanks to today's episode sponsor, Barricade Cyber Solutions
Encountering a ransomware attack? Keep cool and reach out to Barricade Cyber Solutions, the trusted DFIR experts. Barricade is known for helping small and medium businesses just like yours restore their business data and successfully recover from ransomware. Escape the ransomware nightmare and bring your business back online now. Contact Barricade Cyber Solutions today at recoverfromransomware.com. That's recoverfromransomware.com.
For the stories behind the headlines, head to CISOseries.com.
Indian tech company HCL investigating ransomware attack
Agent Tesla and an old Microsoft Office vulnerability create new problems
New JavaScript malware targets banks
Thanks to today's episode sponsor, Barricade Cyber Solutions
Is ransomware affecting your business operations? Contact Barricade Cyber Solutions at recoverfromransomware.com. Barricade Cyber Solutions are elite DFIR experts who come to the rescue for businesses like yours daily. The trusted team at Barricade Cyber traces the source of infiltration and fortifies your defenses. Depend on Barricade Cyber Solutions for your data and system security prevention and recovery. Go to recoverfromransomware.com and set up a time to connect with the team today. Again, that's recoverfromransomware.com.
For the stories behind the headlines, head to CISOseries.com.
BlackCat came back
Child abuse images found in AI datasets
ESO solutions breach impacts million
Thanks to today's episode sponsor, Barricade Cyber Solutions
Has your organization fallen victim to ransomware? Remain calm and head over to recoverfromransomware.com. Barricade Cyber Solutions is the "go-to" for ransomware recovery services that small to medium business executives can trust. Over the past 5 years, Barricade Cyber Solutions has saved 3,000+ businesses in your shoes. Trust the elite DFIR team at Barricade Cyber Solutions with your data and system security recovery. Book a free consultation with the CEO at recoverfromransomware.com now.
FBI disrupts BlackCat ransomware network
International operation arrests thousands of cybercriminals
Sony’s video game plans leaked by ransomware group
Thanks to today's episode sponsor, Barricade Cyber Solutions
Don't let ransomware ruin your holiday. Remember to visit recoverfromransomware.com! Barricade Cyber Solutions are THE trusted DFIR experts, and they've saved 3,000 and counting businesses from ransomware attacks, small and medium businesses just like yours! Barricade Cyber is YOUR solution for rapid data and security systems recovery. Book a meeting directly with the CEO to discuss securing your future today. Head over to recoverfromransomware.com to learn more.
For the stories behind the headlines, visit CISOseries.com.
Play ransomware is no game
The return of QakBot
Hacking with Mr. Cooper
Huge thanks to our sponsor, Barricade Cyber Solutions
Facing a ransomware attack? Don't panic, remain calm and remember to contact Barricade Cyber Solutions, the DFIR team trusted to quickly recover business data with exclusive ransomware recovery services for small and medium businesses alike. Recover from ransomware and get your business back online with Barricade Cyber Solutions. Visit recoverfromransomware.com to schedule a call with the team today.
Box storage platform suffers outage
MongoDB suffers breach
States lag in tackling political deepfakes
Thanks to today's episode sponsor, Barricade Cyber Solutions
Experiencing ransomware? Barricade Cyber Solutions will help you recover from the nightmare. Trust the industry DFIR experts who have rescued over 3,000 businesses cases over the past 5 years. Remember to visit recoverfromransomware.com and connect with Barricade Cyber Solutions rapid ransomware recovery team. This elite team works quickly to recover and restore your business data and services. All you need to remember is recoverfromransomware.com.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Rusty Waldron, Chief Business Security Officer, ADP
Thanks to our show sponsor, Barricade Cyber Solutions
Are ransomware attackers causing your business MAJOR disruptions? Connect with Barricade Cyber Solutions, the trusted DFIR experts specializing in helping small to medium businesses, like yours, recover from ransomware. Barricade Cyber Solutions has a proven track record of successfully handling over 3,000 business cases and counting with advanced recovery services to quickly restore business data and services. Recover from ransomware with Barricade Cyber Solutions at recoverfromransomware.com.
All links and the video of this episode can be found on CISO Series.com
French police arrest alleged Hive banker
Train bricking accusations lead to lawsuit against ethical hackers
New Hacker Group ‘GambleForce’ Targets APAC through SQL injection
Thanks to today's episode sponsor, Barricade Cyber Solutions
Has your organization faced a ransomware attack? Keep calm, breathe, and head over to recoverfromransomware.com. Barricade Cyber Solutions is the industry choice for ransomware recovery services that small and medium business leaders can rely on. With a track record of rescuing over 3,000+ businesses like yours in the last 5 years alone, you can trust Barricade Cyber Solutions' elite DFIR team for the recovery of your business' data and systems. Schedule a complimentary consult today at recoverfromransomware.com.
For the stories behind the headlines, head to CISOseries.com.
UK ransomware report isn’t pretty
MS warns of OAuth abuse
Apple discloses pushback to push notification disclosure
Thanks to today's episode sponsor, Barricade Cyber Solutions
Don't let ransomware ruin the holidays again this year! Prepare and spread holiday cheer with recoverfromransomware.com! The trusted DFIR experts at Barricade Cyber Solutions have saved 3,000 and counting businesses from ransomware attacks, including small and medium businesses just like yours! Barricade Cyber is YOUR solution for rapid data and systems recovery. Book a meeting directly with the CEO to discover how to recover from ransomware. Visit recoverfromransomware.com.
Cyberattack shuts down Ukrainian telco
Former Uber CISO advocates for CISO protections
GAO report on government AI usage
Thanks to today's episode sponsor, Barricade Cyber Solutions
When you're hit with ransomware, remember recoverfromransomware.com. Barricade Cyber Solutions' experienced DFIR team is ready to help your business recover from ransomware now. You'll work directly with the CEO to resolve your case quickly and efficiently. Whether you're experiencing a ransomware attack or want to get ahead of one by discussing a prevention plan, contact Barricade Cyber Solutions at recoverfromransomware.com.
US tries to avoid internet fragmentation
EU reaches agreement on AI Act
North Korea finds continued success with Log4Shell
Thanks to today's episode sponsor, Barricade Cyber Solutions
Encountering a ransomware attack? Keep cool and reach out to Barricade Cyber Solutions, the trusted DFIR experts. Barricade is known for helping small and medium businesses just like yours restore their business data and successfully recover from ransomware. Escape the ransomware nightmare and bring your business back online now. Contact Barricade Cyber Solutions today at recoverfromransomware.com. That's recoverfromransomware.com.
5G network security vulnerabilities discovered, impacting chipset vendors and smartphones
SLAM Spectre-based vulnerability affects CPUs
CISA adds Qlik bugs to exploited vulnerabilities catalog
Thanks to today's episode sponsor, Barricade Cyber Solutions
Caught in a ransomware crisis? Barricade Cyber Solutions is your lifeline for recovery. Trust the industry's experienced DFIR experts, with a track record of saving over 3,000 businesses in the last 5 years. Remember to visit recoverfromransomware.com to connect with Barricade Cyber Solutions' trusted ransomware recovery team. This elite squad moves quickly to restore your business data and services. Visit recoverfromransomware.com today.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Andy Ellis, operating partner YL Ventures
Thanks to our show sponsor, Barricade Cyber Solutions
Are ransomware attackers causing disruptions? Remember to stay composed and immediately contact Barricade Cyber Solutions, the trusted ransomware recovery experts specializing in small to medium businesses. Barricade Cyber Solutions has a proven track record of successfully handling over 3,000 business cases and counting- with advanced recovery services for rapid business restoration. Recover from ransomware with Barricade Cyber Solutions. Visit recoverfromransomware.com to learn more.
All links and the video of this episode can be found on CISO Series.com
Insurance firm sees cyberattacks as more likely than fire or theft
North Korean hackers steal anti-aircraft system data
Vulnerability discovered in fleet management software
Huge thanks to our sponsor, Barricade Cyber Solutions
Is ransomware affecting your business? Contact Barricade Cyber Solutions at recoverfromransomware.com. Barricade Cyber Solutions are elite DFIR experts who come to the rescue for businesses like yours daily. The trusted team at Barricade Cyber traces the source of infiltration and fortifies your defenses. Depend on Barricade Cyber Solutions for your data and system security. Remember recoverfromransomware.com, that’s recoverfromransomware.com.
For the stories behind the headlines, head to CISOseries.com.
Krebs on ICANN Lookups
Wyden warns of spying push notifications
Google unveils Gemini
Huge thanks to our sponsor, Barricade Cyber Solutions
Has your organization fallen victim to ransomware? Remain calm and head over to recoverfromransomware.com. Barricade Cyber Solutions is the "go-to" for ransomware recovery services that small to medium business executives can trust. Over the past 5 years, Barricade Cyber Solutions has saved 3,000+ businesses in your shoes. Trust the elite DFIR team at Barricade Cyber Solutions with your data and system security recovery. Book a free consultation at recoverfromransomware.com now.
Spyware trial implicating former Mexican president kicks off
Federal agency breached through Adobe ColdFusion vulnerability
Malicious loan app downloaded 12 million times from Google Play
Huge thanks to our sponsor, Barricade Cyber Solutions
Don't let ransomware ruin your holiday. Remember to visit recoverfromransomware.com! Barricade Cyber Solutions are THE trusted DFIR experts, and they've saved 3,000 and counting businesses from ransomware attacks, small and medium businesses just like yours! Barricade Cyber is YOUR solution for rapid data and security systems recovery. Book a meeting directly with the CEO to discuss securing your future today. Visit recoverfromransomware.com. That's recoverfromransomware.com.
For the stories behind the headlines, visit CISOseries.com.
UK nuclear site attacked by state-linked attackers
US confirms Iranian actors behind water breaches
The infinite regress of ChatGPT data exfiltration
Huge thanks to our sponsor, Barricade Cyber Solutions
Facing a ransomware attack? Don't panic, remain calm and remember to contact Barricade Cyber Solutions, the DFIR team trusted to quickly recover business data with exclusive ransomware recovery services for small and medium businesses alike. Recover from ransomware and get your business back online with Barricade Cyber Solutions. Visit recoverfromransomware.com to schedule a call with the team today. That's recoverfromransomware.com.
Credit unions facing outages due to ransomware attack on cloud provider
Roblox, Twitch allegedly targeted by ransomware cartel
Apple fixes two new iOS zero-days in emergency updates
Huge thanks to our sponsor, Barricade Cyber Solutions
Experiencing ransomware? Barricade Cyber Solutions will help you recover from the nightmare. Trust the industry DFIR experts who have rescued over 3,000 business cases over the past 5 years. Remember to visit recoverfromransomware.com and connect with Barricade Cyber Solutions rapid ransomware recovery team. This elite team works quickly to recover and restore your business data and services. Visit recoverfromransomware.com today.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Christina Shannon, CIO, KIK Consumer Products
Thanks to our show sponsor, SpyCloud
SpyCloud disrupts cybercrime by telling you what criminals know about your business and your customers, so you can take action on exposed authentication data to prevent ransomware, session hijacking, account takeover, and online fraud.
With knowledge of the specific data criminals have in hand – like credentials, cookies, and PII compromised by breaches and malware infections – security teams have better visibility into the expanding attack surface that puts their organization at risk of cyberattacks and can respond quickly with SpyCloud’s automated solutions.
Find out what cybercriminals know about your business by visiting spycloud.com/ciso to get your free exposure report. That’s spycloud.com/ciso.
All links and the video of this episode can be found on CISO Series.com
Manufacturing industry tops cyber extortion trend
Google’s RETVec the latest warrior on bad emails
Zyxel warns of vulnerabilities in NAS devices
Huge thanks to our sponsor, SpyCloud
New research from SpyCloud reveals a critical discovery: nearly a third of ransomware victim companies this year were infected with infostealer malware like Raccoon, Vidar or Redline before they were attacked. These infostealers exfiltrate authentication data from infected systems to aid follow-on attacks – everything from passwords to 2FA codes, and even cookies that enable session hijacking without the need for credentials at all. SpyCloud specializes in recapturing and remediating data siphoned from infostealers to protect businesses and their users from cybercrime. Get SpyCloud’s new research and check your malware exposure at spycloud.com/ciso.
For the stories behind the headlines, head to CISOseries.com.
All Okta customers exposed in breach
JAXA hit by cyberattack
OpenAI’s chatbots leak secrets
Huge thanks to our sponsor, SpyCloud
For some people ignorance is bliss – but that’s not an option for those of us in cybersecurity. SpyCloud has a free tool that lets you check your company’s darknet exposure, and you might find some things that are pretty alarming. Go to spycloud.com/ciso to see your company's exposure from data breaches and even infostealer malware infections that can open the door to ransomware. SpyCloud’s focus is helping businesses act on what criminals are using right now to target them – addressing stolen passwords, cookies, and even API keys automatically to stop criminals in their tracks. To learn more and get your darknet exposure report, go to spycloud.com/ciso.
Ransomware gang busted in Ukraine by international operation
North Texas water utility hit with cyberattack
Former Uber CISO speaks out after 6-year silence
Huge thanks to our sponsor, SpyCloud
SpyCloud has discovered that infostealer malware infections are an early warning signal for ransomware. In fact, nearly a third of ransomware victim companies this year were infected with infostealer malware like Raccoon, Vidar or Redline before they were attacked. Are you thinking about infostealers as a precursor to ransomware? SpyCloud believes that knowing what criminals have stolen from your managed, unmanaged and undermanaged infected machines is step one to stopping ransomware attacks. Get SpyCloud’s new research on this topic and check your company’s exposure from malware infections at spycloud.com/ciso.
For the stories behind the headlines, visit CISOseries.com.
International AI agreement
PA water utility hit by cyberattack
Ukraine claims cyber attack against Russian aviation
Huge thanks to our sponsor, SpyCloud
Our sponsor today, SpyCloud, wants us to pay attention to a ransomware precursor that’s not being talked about enough: infostealer malware. If you think you’re covered by endpoint protection and anti-virus solutions, think again. The SpyCloud team discovered that the presence of infostealers including Racoon, Vidar, and Redline on machines accessing work applications may indicate a likely future ransomware attack. They believe the first step in thwarting ransomware lies in knowing the data criminals have stolen from malware-infected systems and remediating it quickly. Get SpyCloud’s new research and check your malware exposure at spycloud.com/ciso.
London & Zurich, and Fidelity National Financial attacks
Royal Family’s hospital and Vanderbilt University Med Center suffer cybersecurity incidents
Gulf Air exposed to data breach
Huge thanks to our sponsor, SpyCloud
For some people ignorance is bliss – but that’s not an option for those of us in cybersecurity. SpyCloud has a free tool that lets you check your company’s darknet exposure, and you might find some things that are pretty alarming. Go to spycloud.com/ciso to see your company's exposure from data breaches and even infostealer malware infections that can open the door to ransomware. SpyCloud’s focus is helping businesses act on what criminals are using right now to target them – addressing stolen passwords, cookies, and even API keys automatically to stop criminals in their tracks. To learn more and get your darknet exposure report, go to spycloud.com/ciso.
Cyber exec admits hacking hospital as a sales tactic
‘Citrix Bleed’ vulnerability targeted by nation-state hackers
Binance CEO steps down in $4 billion settlement
Thanks to today's episode sponsor, Egress
People are the biggest risk to your organizations' security and they are most vulnerable when using email. Egress is the only cloud email security platform to use an adaptive security architecture to automate threat detection and response for advanced phishing attacks and outbound data breaches, tailoring the experience for each user based on their real-time risk score. Visit egress.com to learn more about Egress’ Intelligent Cloud Email Security suite and start detecting email threats your existing solution is missing today.
For the stories behind the headlines, visit CISOseries.com.
Healthcare platform impacted by MOVEit
Threat actors find a use for trigonometry
What’s happening with OpenAI
Thanks to today's episode sponsor, Egress
People are the biggest risk to your organizations' security and they are most vulnerable when using email. Egress is the only cloud email security platform to use an adaptive security architecture to automate threat detection and response for advanced phishing attacks and outbound data breaches, tailoring the experience for each user based on their real-time risk score. Visit egress.com to learn more about Egress’ Intelligent Cloud Email Security suite and start detecting email threats your existing solution is missing today.
Clorox CISO departs months after cyberattack
ALPHV/BlackCat Ransomware gang files SEC complaint
Drenan Dudley acting national cyber director while Coker confirmation process continues
Thanks to today's episode sponsor, Egress
People are the biggest risk to your organizations' security and they are most vulnerable when using email. Egress is the only cloud email security platform to use an adaptive security architecture to automate threat detection and response for advanced phishing attacks and outbound data breaches, tailoring the experience for each user based on their real-time risk score. Visit egress.com to learn more about Egress’ Intelligent Cloud Email Security suite and start detecting email threats your existing solution is missing today.
For the stories behind the headlines, head to CISOseries.com
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Jay Wilson, CISO, Insurity
Thanks to our show sponsor, Sysdig
For businesses innovating in the cloud, every second counts. Sysdig strengthens cyber resilience by reducing the attack surface, detecting threats in real time, and accelerating incident response. Our platform correlates signals across cloud workloads, identities, and services to enable businesses to prioritize risks and act decisively. Sysdig. Secure every second. Learn more at Sysdig.com
All links and the video of this episode can be found on CISO Series.com
Fortinet warns of critical command injection bug in FortiSIEM
Another data breach for Samsung
Rhysida warning from FBI and CISA
Thanks to today's episode sponsor, Sysdig
For businesses innovating in the cloud, every second counts. Sysdig strengthens cyber resilience by reducing the attack surface, detecting threats in real time, and accelerating incident response. Our platform correlates signals across cloud workloads, identities, and services to enable businesses to prioritize risks and act decisively. Sysdig. Secure every second.
For the stories behind the headlines, head to CISOseries.com.
Microsoft goes all in on Copilot
YouTube’s AI disclosure requirement
CISA’s AI Roadmap
Thanks to today's episode sponsor, Sysdig
For businesses innovating in the cloud, every second counts. Sysdig strengthens cyber resilience by reducing the attack surface, detecting threats in real time, and accelerating incident response. Our platform correlates signals across cloud workloads, identities, and services to enable businesses to prioritize risks and act decisively. Sysdig. Secure every second.
IPStorm botnet dismantled after hacker’s guilty plea
Federal court rules social media giants must face child safety lawsuits
Authorities warn of Royal ransom gang’s activities and rebranding
Thanks to today's episode sponsor, Sysdig
For businesses innovating in the cloud, every second counts. Sysdig strengthens cyber resilience by reducing the attack surface, detecting threats in real time, and accelerating incident response. Our platform correlates signals across cloud workloads, identities, and services to enable businesses to prioritize risks and act decisively. Sysdig. Secure every second. For businesses innovating in the cloud, every second counts. Sysdig strengthens cyber resilience by reducing the attack surface, detecting threats in real time, and accelerating incident response. Our platform correlates signals across cloud workloads, identities, and services to enable businesses to prioritize risks and act decisively. Sysdig. Secure every second.
For the stories behind the headlines, visit CISOseries.com.
Australian ports hit with cyberattack
AI companies join on to Christchurch Call to Action
Generative AI threatens to dismantle terrorist content detection
Thanks to today's episode sponsor, Sysdig
For businesses innovating in the cloud, every second counts. Sysdig strengthens cyber resilience by reducing the attack surface, detecting threats in real time, and accelerating incident response. Our platform correlates signals across cloud workloads, identities, and services to enable businesses to prioritize risks and act decisively. Sysdig. Secure every second.
Industrial and Commercial Bank of China suffers ransomware attack
UK health data donated for medical research shared with insurance companies
Boeing data published by LockBit
Thanks to today's episode sponsor, Sysdig
For businesses innovating in the cloud, every second counts. Sysdig strengthens cyber resilience by reducing the attack surface, detecting threats in real time, and accelerating incident response. Our platform correlates signals across cloud workloads, identities, and services to enable businesses to prioritize risks and act decisively. Sysdig. Secure every second.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Sean Kelly with guest Howard Holton, CTO, GigaOm
Thanks to today’s episode sponsor, OffSec
OffSec (formerly Offensive Security), the cyber training company behind the well-known OSCP certification and Kali Linux distro, is hosting a virtual summit for CISOs and Cybersecurity leaders called Evolve on November 15th. During the event, you’ll learn how to attract and assess top talent, how to craft positioning for budget conversations, why CISOs make great board members, and more. Hear from forward-thinking infosec leaders from companies like CISCO, Amazon, and Salesforce. Save your seat and equip yourself with actionable takeaways to help shape the future of your organization’s security. Register now at offsec.com/evolve
All links and the video of this episode can be found on CISO Series.com
US most breached country last quarter
OpenAI blames DDoS attacks for ongoing ChatGPT outages
Clop exploits SysAid vulnerability
Thanks to today's episode sponsor, OffSec
And now a word from our sponsor. OffSec (formerly Offensive Security), the cyber training company behind the well-known OSCP certification and Kali Linux distro, is hosting a virtual summit for CISOs and Cybersecurity leaders called Evolve on November 15th. During the event, you'll learn how to attract and assess top talent, how to craft positioning for budget conversations, why CISOs make great board members, and more. Hear from forward-thinking infosec leaders from companies like CISCO, Amazon, and Salesforce. Save your seat and equip yourself with actionable takeaways to help shape the future of your organization's security. Register now at offsec.com/evolve
For the stories behind the headlines, head to CISOseries.com.
US launches “Shields Ready” campaign
Microsoft and Meta announced AI imagery rules
App Defense Alliance moves under the Linux Foundation
Thanks to today's episode sponsor, OffSec
And now a word from our sponsor. OffSec (formerly Offensive Security), the cyber training company behind the well-known OSCP certification and Kali Linux distro, is running a virtual summit for CISOs and Cybersecurity leaders called Evolve on November 15th. Attend Evolve and get insider insights from a former bank hacker. Discover strategies on stretching your security budget and get tips to attract the crème de la crème of talent. It's more than just an event – it's a masterclass helping you elevate your cybersecurity leadership game. Hear from forward-thinking cybersecurity leaders from companies like CISCO, Amazon, Salesforce and more. Register today and get the insights you need to help shape the future of your company’s security. Sign up now at offsec.com/evolve
Singapore’s Marina Bay Sands customer data stolen in cyberattack
Atlassian bug escalated to 10.0 severity
Fake Ledger Live app steals over $700,000 in crypto
Thanks to today's episode sponsor, OffSec
And now a word from our sponsor. OffSec (formerly Offensive Security), the cyber training company behind the well-known OSCP certification and Kali Linux distro, is hosting a virtual summit for CISOs and Cybersecurity leaders called Evolve on November 15th. During the event, you'll learn how to attract and assess top talent, how to craft positioning for budget conversations, why CISOs make great board members, and more. Hear from forward-thinking infosec leaders from companies like CISCO, Amazon, and Salesforce. Save your seat and equip yourself with actionable takeaways to help shape the future of your organization's security. Register now at offsec.com/evolve
For the stories behind the headlines, visit CISOseries.com.
Android Dropper-as-a-Service Bypasses Google’s Defenses
Increase in zero-day exploits worries CISA
Google Calendar as a C2 infrastructure
Thanks to today's episode sponsor, OffSec
And now a word from our sponsor. OffSec (formerly Offensive Security), the cyber training company behind the well-known OSCP certification and Kali Linux distro, is running a virtual summit for CISOs and Cybersecurity leaders called Evolve on November 15th. Attend Evolve and get insider insights from a former bank hacker. Discover strategies on stretching your security budget and get tips to attract the crème de la crème of talent. It's more than just an event – it's a masterclass helping you elevate your cybersecurity leadership game. Hear from forward-thinking cybersecurity leaders from companies like CISCO, Amazon, Salesforce and more. Register today and get the insights you need to help shape the future of your company’s security. Sign up now at offsec.com/evolve
For the stories behind the headlines, head to CISOseries.com.
Okta explains hack source and response timeline
Looney Tunables now being exploited
Lazarus Group uses KandyKorn against blockchain engineers
Thanks to today's episode sponsor, OffSec
And now a word from our sponsor. OffSec (formerly Offensive Security), the cyber training company behind the well-known OSCP certification and Kali Linux distro, is hosting a virtual summit for CISOs and Cybersecurity leaders called Evolve on November 15th. During the event, you'll learn how to attract and assess top talent, how to craft positioning for budget conversations, why CISOs make great board members, and more. Hear from forward-thinking infosec leaders from companies like CISCO, Amazon, and Salesforce. Save your seat and equip yourself with actionable takeaways to help shape the future of your organization's security. Register now at offsec.com/evolve
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Shawn Bowen, CISO, World Kinect Corporation
Thanks to our show sponsor, Hunters
There’s nothing worse than relying on a legacy SIEM that your security team has out-grown, especially when it impacts your ability to detect real incidents. Hunters’ SOC Platform offers built-in, always up-to-date detection rules and automatic correlation that allow SOC analysts to focus on higher-value tasks that impact your organization. It’s time to move to a platform that reduces risk, complexity & cost for the SOC. Visit hunters.security to learn how you can replace your SIEM today.
All links and the video of this episode can be found on CISO Series.com
Power outage darkens Cloudflare dashboard and APIs
Apache ActiveMQ flaw sees HelloKitty attempt
Boeing says cyber incident affects parts and distribution
Thanks to today's episode sponsor, Hunters
There’s nothing worse than relying on a legacy SIEM that your security team has out-grown, especially when it impacts your ability to detect real incidents. Hunters’ SOC Platform offers built-in, always up-to-date detection rules and automatic correlation that allow SOC analysts to focus on higher-value tasks that impact your organization. It’s time to move to a platform that reduces risk, complexity & cost for the SOC. Visit hunters.security to learn how you can replace your SIEM today.
For the stories behind the headlines, head to CISOseries.com.
Countries at UK summit pledge to tackle AI risks
‘Kill switch’ deliberately shuts down notorious botnet
EU regulator bans Meta's targeted advertising practices
Thanks to today's episode sponsor, Hunters
There’s nothing worse than relying on a legacy SIEM that your security team has out-grown, especially when it impacts your ability to detect real incidents. Hunters’ SOC Platform offers built-in, always up-to-date detection rules and automatic correlation that allow SOC analysts to focus on higher-value tasks that impact your organization. It’s time to move to a platform that reduces risk, complexity & cost for the SOC. Visit hunters.security to learn how you can replace your SIEM today. There’s nothing worse than relying on a legacy SIEM that your security team has out-grown, especially when it impacts your ability to detect real incidents. Hunters’ SOC Platform offers built-in, always up-to-date detection rules and automatic correlation that allow SOC analysts to focus on higher-value tasks that impact your organization. It’s time to move to a platform that reduces risk, complexity & cost for the SOC. Visit hunters.security to learn how you can replace your SIEM today.
For the stories behind the headlines, visit CISOseries.com.
Canada bans WeChat on government devices
40 countries sign no ransom pledge
Apple warns Indian opposition leaders about iPhone attacks
Thanks to today's episode sponsor, Hunters
If your SIEM is causing an endless cycle of noisy alerts, manually writing generic detection rules, and limited data ingestion & retention, your SOC might need an upgrade. Hunters is a SaaS platform, purpose built for your Security Operations team. Solaris Group, a leading German FinTech, implemented Hunters to replace their SIEM eliminating the burden of redundant detection engineering and manual event correlation. Solaris Group’s SOC analysts can now focus their time and energy on higher-value tasks. Visit hunters.security to learn how to replace your SIEM today.
Executive order outlines generative AI rules in the US
Russia launchings its own VirusTotal
Roaming data could leak geolocations
Thanks to today's episode sponsor, Hunters
Piecing together a SIEM not only takes forever, but it wastes your security team’s valuable resources. Hunters is a SIEM alternative purpose built to help your Security Operations mature to the next level in a fraction of the time. Spontnana, a next-generation Travel-as-a-Service platform, uses Hunters’ built-in correlation and enrichment capabilities to make better security decisions and experienced value from day one. Are you ready to evaluate Hunters as a SIEM alternative? Visit Hunters.security to learn more.
DC Board of Elections breach may include entire voter roll
LockBit claims Boeing breach
StripedFly malware infects 1 million Windows and Linux hosts
Thanks to today's episode sponsor, Hunters
Hunters is a SIEM alternative, built for your security team. Hunters empowers companies to replace their SIEM with unlimited ingestion and normalization of security data at a predictable cost. Using Hunters, a CISO at a leading online retailer “tripled the amount of data ingested by her security team while cutting costs from a legacy SIEM provider by 75%.” To learn more about the benefits of replacing your legacy SIEM with Hunters visit hunters.security today.
For the stories behind the headlines, head to CISOseries.com
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Arvin Bansal, former CISO, Nissan Americas
Thanks to our show sponsor, Vanta
Growing a business? That likely means more tools, third-party vendors, and data sharing — AKA, way more risk.
Vanta's market-leading trust management platform brings GRC and security efforts together. Integrate information from multiple systems and reduce risks to your business and your brand — all without the need for additional staffing.
And by automating up to 90% of the work for SOC 2, ISO 27001, and more, you’ll be able to focus on strategy and security, not maintaining compliance.
Join 5,000 fast-growing companies that leverage Vanta to manage risk and prove security in real-time. Our listeners get $1,000 off Vanta. Go to vanta.com/ciso to claim this discount.
All links and the video of this episode can be found on CISO Series.com
ILeakage attack steals emails, passwords from Apple devices and browsers
CISA protests potential 25% budget cut as “catastrophic”
Surge in hyper-volumetric HTTP DDoS attacks
Thanks to today's episode sponsor, Vanta
SMIC making advanced chips with ASML tech
Roundcube webmail exploited with zero-day
Philadelphia’s week somehow gets worse
Thanks to today's episode sponsor, Vanta
Cisco IOS XE Update: Number of infected devices via zero-day remains high
California sidelines GM’s driverless cars, citing safety risk
Canada accuse China of ‘Spamouflage’ disinformation campaign
Thanks to today's episode sponsor, Vanta
Chrome testing IP Protection
Microsoft tests Security Copilot
Cisco releases IOS XE patches
Thanks to today's episode sponsor, Vanta
Okta HAR support system attacked
Cisco identifies additional IOS XE vulnerability
Key Ragnar Locker player arrested in Paris
Thanks to today's episode sponsor, Vanta
Link to blog post
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Andrew Wilder, CISO, Community Veterinary Partners
Thanks to our show sponsor, Vanta
“Growing a business? That likely means more tools, third-party vendors, and data sharing — AKA, way more risk. Vanta’s market-leading trust management platform brings GRC and security efforts together. Integrate information from multiple systems and reduce risks to your business and your brand — all without the need for additional staffing. And by automating up to 90% of the work for SOC 2, ISO 27001, and more, you’ll be able to focus on strategy and security, not maintaining compliance. Join 5,000 fast-growing companies that leverage Vanta to manage risk and prove security in real-time. Our listeners get $1,000 off Vanta. Go to vanta.com/ciso to claim this discount.
All links and the video of this episode can be found on CISO Series.com
International sting operation brings down RagnarLocker
More 23andMe records leaked
Casio discloses data breach
Huge thanks to our sponsor, Vanta
Growing a business? That likely means more tools, third-party vendors, and data sharing — AKA, way more risk. Vanta's market-leading trust management platform brings GRC and security efforts together. Integrate information from multiple systems and reduce risks to your business and your brand — all without the need for additional staffing. And by automating up to 90% of the work for SOC 2, ISO 27001, and more, you’ll be able to focus on strategy and security, not maintaining compliance. Join 5,000 fast-growing companies that leverage Vanta to manage risk and prove security in real-time. Our listeners get $1,000 off Vanta. Go to vanta.com/ciso to claim this discount.
For the stories behind the headlines, head to CISOseries.com.
State-backed attackers exploit WinRAR zero-day
Five Eyes warns of Chinese IP theft
ServiceNow data exposure issue identified
Huge thanks to our sponsor, Vanta
Growing a business? That likely means more tools, third-party vendors, and data sharing — AKA, way more risk. Vanta's market-leading trust management platform brings GRC and security efforts together. Integrate information from multiple systems and reduce risks to your business and your brand — all without the need for additional staffing. And by automating up to 90% of the work for SOC 2, ISO 27001, and more, you’ll be able to focus on strategy and security, not maintaining compliance. Join 5,000 fast-growing companies that leverage Vanta to manage risk and prove security in real-time. Our listeners get $1,000 off Vanta. Go to vanta.com/ciso to claim this discount.
Zero-day attacks affect over 10,000 Cisco devices
US government warns of widespread exploitation of Confluence vulnerability
D-Link confirms data breach caused by phishing attack
Huge thanks to our sponsor, Vanta
Growing a business? That likely means more tools, third-party vendors, and data sharing — AKA, way more risk. Vanta's market-leading trust management platform brings GRC and security efforts together. Integrate information from multiple systems and reduce risks to your business and your brand — all without the need for additional staffing. And by automating up to 90% of the work for SOC 2, ISO 27001, and more, you’ll be able to focus on strategy and security, not maintaining compliance. Join 5,000 fast-growing companies that leverage Vanta to manage risk and prove security in real-time. Our listeners get $1,000 off Vanta. Go to vanta.com/ciso to claim this discount.
For the stories behind the headlines, visit CISOseries.com.
Israeli government warns to secure home security cameras
Signal debunks zero-day report
Equifax fined for 2017 data breach
Huge thanks to our sponsor, Vanta
Growing a business? That likely means more tools, third-party vendors, and data sharing — AKA, way more risk. Vanta's market-leading trust management platform brings GRC and security efforts together. Integrate information from multiple systems and reduce risks to your business and your brand — all without the need for additional staffing. And by automating up to 90% of the work for SOC 2, ISO 27001, and more, you’ll be able to focus on strategy and security, not maintaining compliance. Join 5,000 fast-growing companies that leverage Vanta to manage risk and prove security in real-time. Our listeners get $1,000 off Vanta. Go to vanta.com/ciso to claim this discount.
LockBit claims attack on CDW
FBI and CISA publish joint advisory regarding AvosLocker ransomware
EPA rescinds cyber regulations for water sector
Huge thanks to our sponsor, Vanta
Growing a business? That likely means more tools, third-party vendors, and data sharing — AKA, way more risk. Vanta's market-leading trust management platform brings GRC and security efforts together. Integrate information from multiple systems and reduce risks to your business and your brand — all without the need for additional staffing. And by automating up to 90% of the work for SOC 2, ISO 27001, and more, you’ll be able to focus on strategy and security, not maintaining compliance. Join 5,000 fast-growing companies that leverage Vanta to manage risk and prove security in real-time. Our listeners get $1,000 off Vanta. Go to vanta.com/ciso to claim this discount.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review, is hosted by Rich Stroffolino with guest Martin Choluj, VP Security ClickHouse
Thanks to our show sponsor, Hyperproof
Are you struggling to showcase the value of your work? It’s a classic challenge in the risk and compliance space: leadership just doesn’t understand what exactly you do and why it matters. With Hyperproof, the leading risk and compliance management platform, you get access to real-time reports that can help your leadership team understand the impact of the valuable work you do every day. Get a demo at hyperproof.io.
All links and the video of this episode can be found on CISO Series.com
Microsoft thwarts large-scale ransomware attack
Former Uber CISO files appeal
ToddyCat group targets telcos
Thanks to today's episode sponsor, Hyperproof
Is your company scaling? Do you need to quickly add more compliance frameworks but don’t know where to start? Hyperproof has you covered. Hyperproof is a risk and compliance management platform that can help you manage compliance at scale. With Hyperproof, you can quickly add new frameworks, crosswalk controls between frameworks, view your risk posture, and manage your risks, all in one place. Visit hyperproof.io to get started today.
404 pages hijacked
Atlassian Confluence attacked by state-backed actors
Adobe’s “icon of transparency”
Thanks to today's episode sponsor, Hyperproof
It’s more critical than ever to focus on strategically addressing risk, but how can you do it when working with limited resources? That’s where Hyperproof comes in: Hyperproof is a risk and compliance operations platform that helps you automate evidence collection, task management, and collaboration within your organization so you can focus on what matters most: keeping your company secure by prioritizing strategy, not manual processes. Get a demo at Hyperproof.io.
Internet-wide zero-day bug fuels largest-ever DDoS attack
23andMe resets user passwords after genetic data posted online
Microsoft Exchange gets ‘better’ patch to mitigate critical bug
Thanks to today's episode sponsor, Hyperproof
We get it. You’re a risk manager or compliance professional, and you’re overworked. You’re trying to do the right thing by keeping your company safe and secure, but your technology is holding you back. Why not upgrade to Hyperproof? Hyperproof is a platform that not only eliminates the manual tasks you dread, but helps you scale security. Get a demo today at hyperproof.io.
For the stories behind the headlines, visit CISOseries.com.
Hacktivist attacks abound in the Middle East
Network protocol open-source tool Curl faces worst security flaw in a long time
HelloKitty ransomware source code leaked on hacking forum
Thanks to today's episode sponsor, Hyperproof
Imagine. You have an audit coming up, but instead of the usual rush, you actually feel prepared. You’ve collected your evidence. You can see which risks have been mitigated. And best of all, you don’t have to send out any last-minute emails to other teams begging them for that one screenshot. Sounds like a dream, right? With Hyperproof’s risk and compliance platform, this could be your reality. Get a demo at hyperproof.io.
For the stories behind the headlines, head to CISOseries.com.
MGM Resorts quotes ransomware tab at $110 million
Blackbaud in $49.5 million settlement for May 2020 ransomware attack
23andMe investigates breach claims
Thanks to today's episode sponsor, Hyperproof
Tired of managing risk and compliance in spreadsheets? Sick of tracking down stakeholders to find evidence? Worried about whether that evidence is up to date for your next audit? Hyperproof has you covered. With Hyperproof, you can efficiently manage multiple compliance frameworks and risks in a single place so you can focus on what matters most: keeping your company secure and growing. Visit hyperproof.io to get a demo.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review, is hosted by Rich Stroffolino with guest Bob Schuetter, CISO, Ashland
Thanks to our show sponsor, Conveyor
Got a scary security questionnaire to complete and you’d rather have AI do it? Your infosec friends are making the switch from outdated RFP and compliance tools to Conveyor: the most accurate security questionnaire automation software on the market. The proof is in the AI. Customers are seeing 80-90% accurate auto-generated answers by and decreasing the time spent on questionnaire answering by 91%. Try a free one-week proof of concept at www.conveyor.com.
All links and the video of this episode can be found on CISO Series.com
Apple rolls out patch for active iOS Zero-Day
Cisco patches urgent Emergency Responder flaw
Researchers warn of 100,000 exposed ICS systems
Thanks to our episode sponsor, Conveyor
We can all agree that AI can take one job from us: answering security questionnaires. Enter Conveyor: the AI security review platform helping infosec teams attack security questionnaires from all angles. Reduce incoming questionnaires by sharing a trust portal with customers and for those questionnaires you do get, use our AI questionnaire completion tool to auto-generate precise answers to entire questionnaires in seconds. Lucid tried a free one week proof of concept and reduced time spent on questionnaires by 91%. Learn more at www.conveyor.com.
For the stories behind the headlines, head to CISOseries.com.
Red Cross issues hacktivist rules
Looney Tunables hits major Linux distros
CISA may have violated the First Amendment
Thanks to our episode sponsor, Conveyor
Will security questionnaires ever go away? Maybe. But as long as they’re still here, you might as well get AI to complete them for you. Enter Conveyor. The AI security questionnaire automation software that auto-generates 80-90% accurate answers to entire questionnaires in seconds so all you have to do is review. There’s even a browser extension for the world’s worst portals. Not sure if it’ll work for you? Try a free one-week proof of concept at www.conveyor.com.
Arm and Qualcomm warn about exploited GPU drivers
EU Parliament strengthens spyware protections for journalists
NSA creates AI Security Center
Thanks to our episode sponsor, Conveyor
Does the mountain of security questionnaires in your inbox make you feel like a 2 dollar umbrella in a hurricane? Then you might want to check out Conveyor: the AI security review platform helping infosec teams attack security questionnaires from all angles. Reduce incoming questionnaires by sharing a trust portal with customers and for those questionnaires you do get, use our AI questionnaire completion tool to auto-generate precise answers to entire questionnaires in seconds. Lucid tried a free one week proof of concept and reduced time spent on questionnaires by 91%. Learn more at www.conveyor.com.
Critical Progress FTP bug now being exploited in attacks
Norway urges Europe-wide ban on Meta's targeted data collection
KillNet claims DDoS attack against Royal Family website
Thanks to our episode sponsor, Conveyor
Got a scary security questionnaire to complete and you’d rather have AI do it? Your infosec friends are making the switch from outdated RFP and compliance tools to Conveyor: the most accurate security questionnaire automation software on the market. The proof is in the AI. Customers are seeing 80-90% accurate auto-generated answers by and decreasing the time spent on questionnaire answering by 91%. Try a free one-week proof of concept at www.conveyor.com.
For the stories behind the headlines, visit CISOseries.com.
Cloudflare DDoS protections bypassed using Cloudflare
McLaren Health Care becomes latest ALPHV/BlackCat victim
Lazarus Group poses as Meta recruiters to spearfish Spanish engineers
Thanks to our episode sponsor, Conveyor
Does the thought of answering another security questionnaire make you want to beat the stuffing out of 32 pinatas?
Then you might want to check out Conveyor: the AI security review platform helping infosec and sales teams attack security questionnaires from all angles.
Reduce incoming questionnaires by sharing a trust portal with customers and for those questionnaires you do get, use our AI questionnaire completion tool to auto-generate precise answers to entire questionnaires in seconds.
Lucid tried a free one week proof of concept and reduced time spent on questionnaires by 91%. Learn more at www.conveyor.com.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review, is hosted by Rich Stroffolino with guest Andrew Storms, VP of security, Replicated
Thanks to our show sponsor, AppOmni
Are you confident in your organization’s SaaS security? AppOmni surveyed 600+ security practitioners globally and 71% answered yes. But 79% experienced SaaS cybersecurity incidents. What’s behind this disconnect?
CISOs believe they have a mature level of SaaS cybersecurity using CASB, MFA, and IdP. But these solutions lack unified risk visibility. Without SSPM, they’re blind to the true extent of their SaaS attack surface risk. Don’t gamble with your data. Get the visibility and insights you need to protect your SaaS environment with AppOmni.
All links and the video of this episode can be found on CISO Series.com
Chinese hackers stole emails from US State Dept in Microsoft breach
Johnson Controls faces $51 million ransomware demand
Google fixes year’s fifth Chrome zero-day
Thanks to today's episode sponsor, AppOmni
If you think CASBs effectively secure your SaaS data… think again. CASBs lack visibility into your SaaS estate. Nor can they address and detect risks that arise from SaaS apps’ unlimited endpoints. What you need is a robust SSPM designed to secure the dynamic and extensible nature of SaaS apps and their data. That’s where AppOmni comes in. We continuously monitor your SaaS estate to detect cyber risks and secure your company’s most critical data and workflows. Get started at AppOmni.com.
For the stories behind the headlines, head to CISOseries.com.
GPUs vulnerable to pixel-stealing attacks
Info-stealing commits hit GitHub
Alleged Sony hackers hit NTT Docomo
Thanks to today's episode sponsor, AppOmni
Are you confident in your organization’s SaaS security? AppOmni surveyed 600+ security practitioners globally and 71% answered yes. But 79% experienced SaaS cybersecurity incidents. What’s behind this disconnect? CISOs believe they have a mature level of SaaS cybersecurity using CASB, MFA, and IdP. But these solutions lack unified risk visibility. Without SSPM, they’re blind to the true extent of their SaaS attack surface risk. Don’t gamble with your data. Get the visibility and insights you need to protect your SaaS environment with AppOmni.
Multiple threat actors lay claim to Sony hack
Philippines health org struggling to recover from ransomware attack
Canadian Flair Airlines leaked user data for months
Thanks to today's episode sponsor, AppOmni
If you think CASBs effectively secure your SaaS data… think again. CASBs lack visibility into your SaaS estate. Nor can they address and detect risks that arise from SaaS apps’ unlimited endpoints. What you need is a robust SSPM designed to secure the dynamic and extensible nature of SaaS apps and their data. That’s where AppOmni comes in. We continuously monitor your SaaS estate to detect cyber risks and secure your company’s most critical data and workflows. Get started at AppOmni.com.
For the stories behind the headlines, visit CISOseries.com.
Mixin Network loses $200 million
Kia and Hyundai exploit linked to massive car thefts
Stress testing voting equipment
Thanks to today's episode sponsor, AppOmni
Are you confident in your organization’s SaaS security? AppOmni surveyed 600+ security practitioners globally and 71% answered yes. But 79% experienced SaaS cybersecurity incidents. What’s behind this disconnect? CISOs believe they have a mature level of SaaS cybersecurity using CASB, MFA, and IdP. But these solutions lack unified risk visibility. Without SSPM, they’re blind to the true extent of their SaaS attack surface risk. Don’t gamble with your data. Get the visibility and insights you need to protect your SaaS environment with AppOmni.
Car audio manufacturer Clarion hacked – ALPHV claims responsibility
High-ranking Egyptian politician targeted by Predator spyware
City of Dallas issues report on May cyberattack
Thanks to today's episode sponsor, AppOmni
If you think CASBs effectively secure your SaaS data… think again. CASBs lack visibility into your SaaS estate. Nor can they address and detect risks that arise from SaaS apps’ unlimited endpoints. What you need is a robust SSPM designed to secure the dynamic and extensible nature of SaaS apps and their data. That’s where AppOmni comes in. We continuously monitor your SaaS estate to detect cyber risks and secure your company’s most critical data and workflows. Get started at AppOmni.com.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review, is hosted by Rich Stroffolino with guest Shawn Bowen, CISO, World Kinect Corporation
Thanks to our show sponsor, Hyperproof
Is your company scaling? Do you need to quickly add more compliance frameworks but don’t know where to start? Hyperproof has you covered. Hyperproof is a risk and compliance management platform that can help you manage compliance at scale. With Hyperproof, you can quickly add new frameworks, crosswalk controls between frameworks, view your risk posture, and manage your risks, all in one place. Visit hyperproof.io to get started today.
All links and the video of this episode can be found on CISO Series.com
UK launches comprehensive new online safety laws
Cisco buys Splunk
TransUnion denies breach
Huge thanks to our sponsor, Hyperproof
Is your company scaling? Do you need to quickly add more compliance frameworks but don’t know where to start? Hyperproof has you covered. Hyperproof is a risk and compliance management platform that can help you manage compliance at scale. With Hyperproof, you can quickly add new frameworks, crosswalk controls between frameworks, view your risk posture, and manage your risks, all in one place. Visit hyperproof.io to get started today.
For the stories behind the headlines, head to CISOseries.com.
Cyber attack disrupted Canadian airports
Huawei ships chips for surveillance cameras
Signal adds quantum-resistant encryption
Huge thanks to our sponsor, Hyperproof
It’s more critical than ever to focus on strategically addressing risk, but how can you do it when working with limited resources? That’s where Hyperproof comes in: Hyperproof is a risk and compliance operations platform that helps you automate evidence collection, task management, and collaboration within your organization so you can focus on what matters most: keeping your company secure by prioritizing strategy, not manual processes. Get a demo at Hyperproof.io.
DHS council seeks to simplify cyber incident reporting rules
UK passes the Online Safety Bill
Finland and Europol take down PIILOPUOTI marketplace
Huge thanks to our sponsor, Hyperproof
We get it. You’re a risk manager or compliance professional, and you’re overworked. You’re trying to do the right thing by keeping your company safe and secure, but your technology is holding you back. Why not upgrade to Hyperproof? Hyperproof is a platform that not only eliminates the manual tasks you dread, but helps you scale security. Get a demo today at hyperproof.io.
For the stories behind the headlines, visit CISOseries.com.
Microsoft leaks terabytes of internal data
UK CMA outlines principles for AI regulation
Germany warns of attacks on LNG terminals
Huge thanks to our sponsor, Hyperproof
Imagine. You have an audit coming up, but instead of the usual rush, you actually feel prepared. You’ve collected your evidence. You can see which risks have been mitigated. And best of all, you don’t have to send out any last-minute emails to other teams begging them for that one screenshot. Sounds like a dream, right? With Hyperproof’s risk and compliance platform, this could be your reality. Get a demo at hyperproof.io.
Lazarus Group suspected in CoinEx robbery
Thailand financial company CardX discloses leak
Ransomware hits trucking software provider
Huge thanks to our sponsor, Hyperproof
Tired of managing risk and compliance in spreadsheets? Sick of tracking down stakeholders to find evidence? Worried about whether that evidence is up to date for your next audit? Hyperproof has you covered. With Hyperproof, you can efficiently manage multiple compliance frameworks and risks in a single place so you can focus on what matters most: keeping your company secure and growing. Visit hyperproof.io to get a demo.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review, is hosted by Rich Stroffolino with guest Davi Ottenheimer, VP, Trust and Ethics, Inrupt
Thanks to our show sponsor, Conveyor
The team at Lucid software reduced the time spent answering customer security questionnaires by a whopping 91% with Conveyor’s security questionnaire automation software – powered by OpenAI. Compared to the tools on the market, Conveyor’s AI auto-generates the most accurate answers to entire questionnaires so you can spend almost zero time on them. That’s it. That’s the ad. We’ll let you get back to the show, but if you want to take away the pain of questionnaires, try a free proof of concept at www.conveyor.com.
All links and the video of this episode can be found on CISO Series.com
Caesars reportedly paid millions to stop Scattered Spider
Cybersecurity incident impacts Canada’s Weather Network
Blocked LockBit affiliate deploys 3AM instead
Huge thanks to our sponsor, Conveyor
The team at Lucid software reduced the time spent answering customer security questionnaires by a whopping 91% with Conveyor’s security questionnaire automation software - powered by OpenAI. Compared to the tools on the market, Conveyor’s AI auto-generates the most accurate answers to entire questionnaires so you can spend almost zero time on them. That’s it. That’s the ad. We’ll let you get back to the headlines, but if you want to take away the pain of questionnaires, try a free proof of concept at www.conveyor.com.
For the stories behind the headlines, head to CISOseries.com.
NSC asks governments not to pay ransoms
CISA’s open source software security roadmap
Save the Children hit with ransomware
Huge thanks to our sponsor, Conveyor
Got a scary security questionnaire to complete and you’d rather have AI do it? Your infosec friends are making the switch from outdated RFP and compliance tools to Conveyor - the most accurate security questionnaire automation software on the market. The proof is in the AI. Customers are seeing 80-90% accurate answers and decreasing the time spent on questionnaire answering by 91%. We’re excited about the success customers like Lucid and Carta have seen using Conveyor. Try a free proof of concept at www.conveyor.com.
MGM Resorts slot machines and ATMs disrupted by "cybersecurity incident"
Hackers access sensitive data of thousands of Airbus vendors
Cryptoqueen’s sidekick sentenced for $4 billion scam
Huge thanks to our sponsor, Conveyor
Here’s how to measure if your security questionnaire answering software is effective.
We benchmarked the RFP and compliance tools on the market and most are only generating accurate responses to questionnaires 20-50% of the time.
Ready for 80-90% auto-generated accurate answers so you can fly through your review?
Then you should try Conveyor’s AI-security questionnaire automation tool.
Don’t believe us? Try a free proof of concept at www.conveyor.com
For the stories behind the headlines, visit CISOseries.com.
UK government sees record critical IT infrastructure attacks
Charming Kitten unleashes Sponsor backdoor
Ransomware costs Sri Lankan government months of data
Huge thanks to our sponsor, Conveyor
The team at Lucid software reduced the time spent answering customer security questionnaires by a whopping 91% with Conveyor’s security questionnaire automation software - powered by OpenAI.
Compared to the tools on the market, Conveyor’s AI auto-generates the most accurate answers to entire questionnaires so you can spend almost zero time on them.
That’s it. That’s the ad.
We’ll let you get back to the headlines, but if you want to take away the pain of questionnaires, try a free proof of concept at www.conveyor.com.
Evil Telegram fake apps send spyware
Akamai announces mitigation of largest DDoS on a US financial company
Rhysida attacks three more hospitals
Huge thanks to our sponsor, Conveyor
What’s scarier than the Sunday scaries? Opening your inbox to a 200 question, 15 tab macro-enabled workbook containing a customer security questionnaire to complete. Let Conveyor's AI security questionnaire automation tool, powered by OpenAI, help your answering process go a lot faster. Spend 91% less time on questionnaires when you get precise answers auto-generated for you. Try a free proof of concept to see how fast you can get through questionnaires with Conveyor at www.conveyor.com
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review, is hosted by Rich Stroffolino with guest Dan Walsh, CISO, VillageMD
Thanks to our show sponsor, Comcast DataBee
DataBee™, from Comcast Technology Solutions, is a cloud-native security, risk and compliance data fabric platform that transforms your security data chaos into connected outcomes. Built by security professionals for security professionals, DataBee makes your data a gold mine, rich with information that enables you to examine the past, react to the present, and protect the future of your business. Learn more at https://comca.st/DataBee.
All links and the video of this episode can be found on CISO Series.com
How Chinese hackers stole a Microsoft signing key
The ICC to prosecute cyberwar crimes
North Korean cyberattacks against Russian targets
Thanks to today's episode sponsor, Comcast
DataBee™, from Comcast Technology Solutions, is a cloud-native security, risk and compliance data fabric platform that transforms your security data chaos into connected outcomes. Built by security professionals for security professionals, DataBee makes your data a gold mine, rich with information that enables you to examine the past, react to the present, and protect the future of your business. Learn more at https://comca.st/DataBee.
CISA close to finalizing incident reporting rules
Krebs on cracked LastPass keys
Connected cars not great for privacy and security
Thanks to today's episode sponsor, Comcast
Are you still using whiteboards and pivoting between tools to find out who owns what data sources and the relationships between data points? It’s time to improve your OODA loop and enhance your security and compliance efforts with DataBee, from Comcast Technology Solutions. Learn how DataBee weaves together and enriches data from across the enterprise to provide deeper insights into your security, risk and compliance posture. Visit https://comca.st/DataBee.
CISA hires ‘Mudge’ to work on security-by-design principles
All 50 states call on Congress to address AI-generated CSAM
Stake.com loses $41 million to hot wallet hackers
Thanks to today's episode sponsor, Comcast
What if you could integrate enterprise-wide business intelligence with your security data for better contextual insights into potential threats and compliance issues? You can. With DataBee™, from Comcast Technology Solutions. Learn how DataBee enables users to leverage integrated insights to mitigate risks and stay compliant. Visit https://comca.st/DataBee.
For the stories behind the headlines, visit CISOseries.com.
New PDF MalDoc allows evasion of antivirus
MinIO Storage system being used to compromise servers
Okta warns of IT help desk attacks
Thanks to today's episode sponsor, Comcast
Data rules everything around us – but why are the people who need data the most unable to access it? What if you could boost the productivity of your security teams and their ability to collaborate by providing them access to the same shared and enriched data?
You can. With DataBee™, from Comcast Technology Solutions. Learn how DataBee can help your organization make better informed decisions, quickly and cost-effectively. Visit https://comca.st/DataBee
For the stories behind the headlines, head to CISOseries.com.
X to collect member employment data
Technical details of Sandworm malware ‘Infamous Chisel’ released
Golf club maker Callaway suffers breach
Thanks to today's episode sponsor, Comcast
“Data is the currency of the 21st century”, yet for so many cybersecurity professionals, it’s still too difficult to access, correlate and use this ‘currency’ for better, faster security and compliance decision-making. That’s why Comcast Technology Solutions created DataBee™, a cloud-native security data fabric platform that can help you turn your security data into valuable business ‘currency’. Learn more at https://comca.st/DataBee.
For the stories behind the headlines, head to CISOseries.com.
Gamaredon hackers hit Ukraine military
Movie giant Paramount Global suffers data breach
Takeover swarm exploits OpenFire
Huge thanks to today's episode sponsor, AppOmni
Over provisioned users could lead to your most sensitive data being exposed or leaked. Just a single attack on one of those users may compromise your entire SaaS estate. With AppOmni’s SaaS Identity Fabric, secure and manage end-users, entitlements, and threat-based activity. Gain visibility and control over provisioned users, the SaaS data they have access to, and receive guided remediation. Get connected with SaaS security experts at AppOmni.com.
For the stories behind the headlines, head to CISOseries.com.
Chinese threat actors breached Japan’s cybersecurity agency
Human trafficking into cyber scams
China set to approve first generative AI services
Huge thanks to today's episode sponsor, AppOmni
SaaS cyberattacks are prevalent and often go unnoticed until data loss or breaches occur. Sign-ins from an unusual IP address. Stolen session tokens. These security risks can lurk in the shadows and put your entire SaaS estate at risk.
Don’t wait for a breach to secure your SaaS data. AppOmni helps security teams to detect suspicious activity, decide what activities to be alerted on, and receive guided remediation. Learn how at AppOmni.com.
FBI dismantles Qakbot operation that took millions in ransom
University of Michigan severs ties to internet after cyberattack
Microsoft joins growing list of organizations criticizing UN cybercrime treaty
Huge thanks to today's episode sponsor, AppOmni
Over provisioned users could lead to your most sensitive data being exposed or leaked. Just a single attack on one of those users may compromise your entire SaaS estate.
With AppOmni’s SaaS Identity Fabric, secure and manage end-users, entitlements, and threat-based activity. Gain visibility and control over provisioned users, the SaaS data they have access to, and receive guided remediation. Get connected with SaaS security experts at AppOmni.com.
For the stories behind the headlines, visit CISOseries.com.
UK network outage grounds flights
The malware loader Big 3
Another spyware firm breached
Huge thanks to today's episode sponsor, AppOmni
SaaS cyberattacks are prevalent and often go unnoticed until data loss or breaches occur. Sign-ins from an unusual IP address. Stolen session tokens. These security risks can lurk in the shadows and put your entire SaaS estate at risk.
Don’t wait for a breach to secure your SaaS data. AppOmni helps security teams to detect suspicious activity, decide what activities to be alerted on, and receive guided remediation. Learn how at AppOmni.com.
Cisco fixes flaws in NX-OS AND FXOS software
Windows preview updates bring blue screen of death
FBI warns Barracuda bug still has bite
Huge thanks to today's episode sponsor, AppOmni
Over provisioned users could lead to your most sensitive data being exposed or leaked. Just a single attack on one of those users may compromise your entire SaaS estate.
With AppOmni’s SaaS Identity Fabric, secure and manage end-users, entitlements, and threat-based activity. Gain visibility and control over provisioned users, the SaaS data they have access to, and receive guided remediation. Get connected with SaaS security experts at AppOmni.com.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review, is hosted by Rich Stroffolino with guest Gerald Auger Ph.D., Chief Content Creator, Simply Cyber
Thanks to our show sponsor, HyperProof
Is your company scaling? Do you need to quickly add more compliance frameworks but don’t know where to start? Hyperproof has you covered. Hyperproof is a risk and compliance management platform that can help you manage compliance at scale. With Hyperproof, you can quickly add new frameworks, crosswalk controls between frameworks, view your risk posture, and manage your risks, all in one place. Visit hyperproof.io to get started today.
All links and the video of this episode can be found on CISO Series.com
Lazarus Group exploits ManageEngine to drop new RATS on internet and healthcare
Vulnerabilities in Rockwell ThinManager threaten industrial control systems
Mississippi hospital system suffers cyberattack
Huge thanks to our sponsor, HyperProof
Is your company scaling? Do you need to quickly add more compliance frameworks but don’t know where to start? Hyperproof has you covered. Hyperproof is a risk and compliance management platform that can help you manage compliance at scale. With Hyperproof, you can quickly add new frameworks, crosswalk controls between frameworks, view your risk posture, and manage your risks, all in one place. Visit to get started today.
For the stories behind the headlines, head to CISOseries.com.
Tornado Cash developers face indictment
UN begins final cybercrime treaty talks
FBI warns of North Korean crypto cash out
Huge thanks to our sponsor, HyperProof
It’s more critical than ever to focus on strategically addressing risk, but how can you do it when working with limited resources? That’s where Hyperproof comes in: Hyperproof is a risk and compliance operations platform that helps you automate evidence collection, task management, and collaboration within your organization so you can focus on what matters most: keeping your company secure by prioritizing strategy, not manual processes. Get a demo at Hyperproof.io.
CISOs proclaim cybersecurity confidence, but majority admit to SaaS incidents
Cyber Health Report: Hacker entry point shifts from email to network
Duo outage causes Azure Auth authentication errors
Huge thanks to our sponsor, HyperProof
We get it. You’re a risk manager or compliance professional, and you’re overworked. You’re trying to do the right thing by keeping your company safe and secure, but your technology is holding you back. Why not upgrade to Hyperproof? Hyperproof is a platform that not only eliminates the manual tasks you dread, but helps you scale security. Get a demo today at hyperproof.io.
For the stories behind the headlines, head to CISOseries.com.
ChatGPT used in crypto botnet
Brits tipping off ransomware targets
Tesla data breach caused by insiders
Huge thanks to our sponsor, HyperProof
Imagine. You have an audit coming up, but instead of the usual rush, you actually feel prepared. You’ve collected your evidence. You can see which risks have been mitigated. And best of all, you don’t have to send out any last-minute emails to other teams begging them for that one screenshot. Sounds like a dream, right? With Hyperproof’s risk and compliance platform, this could be your reality. Get a demo at hyperproof.io.
North Korean hackers suspected of targeting S. Korea-US drills
Android malware apps use APK compression to evade detection
Security agencies warn space industry of increased attacks
Huge thanks to our sponsor, HyperProof
Tired of managing risk and compliance in spreadsheets? Sick of tracking down stakeholders to find evidence? Worried about whether that evidence is up to date for your next audit? Hyperproof has you covered. With Hyperproof, you can efficiently manage multiple compliance frameworks and risks in a single place so you can focus on what matters most: keeping your company secure and growing. Visit hyperproof.io to get a demo.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review, is hosted by Rich Stroffolino with guest, Jon Oltsik, distinguished analyst and fellow, Enterprise Strategy Group
Thanks to our show sponsor, Veza
75% of breaches happen because of bad permissions. The problem is that you don’t know exactly WHO has access to WHAT data in your environment. For example, roles labeled as “read-only” can often edit and delete sensitive data. Veza automatically finds and fixes every bad permission—in every app—across your environment.
All links and the video of this episode can be found on CISO Series.com
Influence operators fine-tuning AI to deceive targets
67% of government agencies claim confidence in adopting zero trust
CISA warns of urgent Citrix vulnerability
Huge thanks to today's episode sponsor, Veza
75% of breaches happen because of bad permissions. The problem is that you don’t know exactly WHO has access to WHAT data in your environment. For example, roles labeled as “read-only” can often edit and delete sensitive data. Veza automatically finds and fixes every bad permission—in every app—across your environment.
For the stories behind the headlines, head to CISOseries.com.
LockBit struggles to publish leaked data
Google’s quantum resilient security key
Organizations optimistic and unprepared for AI
Huge thanks to today's episode sponsor, Veza
75% of breaches happen because of bad permissions. The problem is that you don’t know exactly WHO has access to WHAT data in your environment. For example, roles labeled as “read-only” can often edit and delete sensitive data. Veza automatically finds and fixes every bad permission—in every app—across your environment.
Huge thanks to today's episode sponsor, Veza
75% of breaches happen because of bad permissions. The problem is that you don’t know exactly WHO has access to WHAT data in your environment. For example, roles labeled as “read-only” can often edit and delete sensitive data. Veza automatically finds and fixes every bad permission—in every app—across your environment.
For the stories behind the headlines, visit CISOseries.com.
Moovit bug allowed for free rides
A look at Black Hat’s network operations center
Business and gaming disputes lead to DDoS attacks
Huge thanks to today's episode sponsor, Veza
75% of breaches happen because of bad permissions. The problem is that you don’t know exactly WHO has access to WHAT data in your environment. For example, roles labeled as “read-only” can often edit and delete sensitive data. Veza automatically finds and fixes every bad permission—in every app—across your environment.
Ford says cars with WiFi vulnerability still safe to drive
Cyber Safety Review Board to analyze cloud security in wake of Microsoft hack
Knight ransomware distributed in fake TripAdvisor complaint emails
Huge thanks to today's episode sponsor, Veza
75% of breaches happen because of bad permissions. The problem is that you don’t know exactly WHO has access to WHAT data in your environment. For example, roles labeled as “read-only” can often edit and delete sensitive data. Veza automatically finds and fixes every bad permission—in every app—across your environment.
For the stories behind the headlines, head to CISOseries.com.
Link to blog post
This week’s Cyber Security Headlines – Week in Review, August 7-11, is hosted by Rich Stroffolino with guest, Michael Woods, CISO, GE
Thanks to our show sponsor, Conveyor
We can all agree there’s one thing the AI bots can take from us: completing customer security questionnaires. That’s why we built Conveyor’s GPT-questionnaire response tool.
It auto-generates precise, accurate answers to entire questionnaires with accuracy far superior to existing tools on the market. It’s so accurate, your customers can now use it in our new ‘upload questions to trust portal’ feature. It’s exactly as it sounds. Customers can upload questions and the AI will generate instant answers based on your trust portal content.
Try a free proof of concept with your own data and see why top SaaS companies are making the switch from outdated RFP software and other portal solutions. Learn more at Conveyor.
All links and the video of this episode can be found on CISO Series.com
CISA Warns organizations of exploited vulnerability affecting .NET, Visual Studio
Dell Compellent hardcoded key exposes VMware vCenter admin creds
DEF CON: Thousands of security researchers vie to outsmart AI in Las Vegas
Thanks to today's episode sponsor, Conveyor
We can all agree there’s one thing the AI bots can take from us: completing customer security questionnaires. That’s why we built Conveyor’s GPT-questionnaire response tool.
It auto-generates precise, accurate answers to entire questionnaires with accuracy far superior to existing tools on the market. It’s so accurate, your customers can now use it in our new ‘upload questions to trust portal’ feature. It’s exactly as it sounds. Customers can upload questions and the AI will generate instant answers based on your trust portal content.
Try a free proof of concept with your own data and see why top SaaS companies are making the switch from outdated RFP software and other portal solutions.
Learn more at www.conveyor.com.
For the stories behind the headlines, head to CISOseries.com.
AI Cyber Challenge announced at Black Hat
Tencent typing app had real time “eavesdropper”
Google adds cellular security to Android
Thanks to today's episode sponsor, Conveyor
Your scariest questionnaires that are HUNDREDS of questions long are no match for Conveyor’s GPT-security questionnaire tool - the most accurate questionnaire automation tool on the market. It’s so accurate that you can even let customers upload their own questions in your portal to get instant answers generated from your content. For questionnaires you still need complete, infosec and sales teams are spending 89% less time on answering questionnaires because they’re getting accurate answers to entire questionnaires that they don’t have to re-write.
Try a free proof of concept with your own data. Learn more at www.conveyor.com
Google’s Messages app now uses RCS to encrypt chats
Electoral Commission apologizes for security breach involving UK voters’ data
Banks hit with over $500 million in fines for using out-of-band chat apps
Thanks to today's episode sponsor, Conveyor
Did you catch the biggest release of the year? No, not Barbenheimer.
It’s Conveyor’s GPT-powered security questionnaire response tool: the most accurate questionnaire automation tool on the market. It’s so good, you can let your customers upload their own questions in your trust portal to get instant answers based on your content. And of course, it’s not just for your customers. You can use the GPT-questionnaire response tool internally as well to get auto-generated precise answers to entire questionnaires in minutes so all you have to do is review.
Maybe it's time to replace your outdated RFP software… Try a free proof of concept with your own data. Learn more at www.conveyor.com
For the stories behind the headlines, head to CISOseries.com
White House rolls out school cyber initiatives
North Koreans breach Russian missile developer
Large language models getting worse at math
Thanks to today's episode sponsor, Conveyor
GPT for security questionnaires? Conveyor has already built that for you. Conveyor’s GPT-questionnaire response tool is so accurate, you can use it in two ways.
One: Let your customers upload their own questions in your trust portal to get AI-generated answers based on the content in your portal.
And Two: It’s not just for your customers. You can use the GPT-questionnaire response tool internally as well to get auto-generated precise answers to entire questionnaires in minutes so all you have to do is review.
Try a free proof of concept with your own data to see it in action. Learn more at www.conveyor.com
Microsoft resolves vulnerability following criticism from Tenable CEO
FBI investigating ransomware attack crippling hospitals across 4 states
New acoustic attack steals data from keystrokes with 95% accuracy
Thanks to today's episode sponsor, Conveyor
Did you catch the biggest release of the year? No, not Barbenheimer.
It’s Conveyor’s GPT-powered security questionnaire response tool: the most accurate questionnaire automation tool on the market. It’s so good, you can let your customers upload their own questions in your trust portal to get instant answers based on your content. And of course, it’s not just for your customers. You can use the GPT-questionnaire response tool internally as well to get auto-generated precise answers to entire questionnaires in minutes so all you have to do is review.
Maybe it's time to replace your outdated RFP software… Try a free proof of concept with your own data. Learn more at www.conveyor.com
For the stories behind the headlines, head to CISOseries.com
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, July 31-August 4, is hosted by Rich Stroffolino with guest, Jeff Hudesman, CISO, Pinwheel
Thanks to our show sponsor, Opal
Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal’s mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identity security for scale. Visit opal.dev.
Fortinet VPN bug tops CISA’s list of most exploited vulnerabilities in 2022
Chrome malware Rilide targets enterprise users via PowerPoint guides
Researchers discover bypass for recently fixed Ivanti EPMM vulnerability
Thanks to today's episode sponsor, Opal
Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identity security for scale. Visit Opal.dev.
For the stories behind the headlines, head to CISOseries.com.
Australian Senate recommends banning WeChat
US company accused of aiding APT
Hacking group to detail P2P protocol at DEF CON
Thanks to today's episode sponsor, Opal
Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identity security for scale. Visit Opal.dev.
Musk sues disinformation researchers for driving away advertisers
Researchers claim cloud host facilitated state-backed cyberattacks
UK spy agencies want to relax ‘burdensome’ laws on AI data use
Thanks to today's episode sponsor, Opal
Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identity security for scale. Visit Opal.dev.
For the stories behind the headlines, visit CISOseries.com.
White House releases National Cyber and Workforce Education Strategy
Latest DeFi exploit sees millions in losses
No link found between cyber insurance and paying ransoms
Thanks to today's episode sponsor, Opal
Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identity security for scale. Visit Opal.dev.
Israel’s largest oil refinery website offline amid cyber attack claims
TSA renews cybersecurity guidelines for pipelines
CISA AND Australia warn of IDOR vulnerabilities after major breaches
Thanks to today's episode sponsor, Opal
Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identity security for scale. Visit Opal.dev.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, July 24-28, is hosted by Rich Stroffolino with guest, TC Niedzialkowski, CISO, Nextdoor
Thanks to today’s episode sponsor, AppOmni
Over provisioned users could lead to your most sensitive data being exposed or leaked. Just a single attack on one of those users may compromise your entire SaaS estate. With AppOmni’s SaaS Identity Fabric, secure and manage end-users, entitlements, and threat-based activity. Gain visibility and control over provisioned users, the SaaS data they have access to, and receive guided remediation. Get connected with SaaS security experts at AppOmni.com.
All links and the video of this episode can be found on CISO Series.com
Millions affected by data breach at US government contractor Maximus
Two severe Linux vulnerabilities impact 40% of Ubuntu users
Heart monitoring technology provider confirms cyberattack
Thanks to today's episode sponsor, AppOmni
Over provisioned users could lead to your most sensitive data being exposed or leaked. Just a single attack on one of those users may compromise your entire SaaS estate.
With AppOmni’s SaaS Identity Fabric, secure and manage end-users, entitlements, and threat-based activity. Gain visibility and control over provisioned users, the SaaS data they have access to, and receive guided remediation. Get connected with SaaS security experts at AppOmni.com.
For the stories behind the headlines, head to CISOseries.com.
Russian court convicts cyber security executive of treason
SEC to require incident disclosure
Government cyber attacks rely on valid credentials
Thanks to today's episode sponsor, AppOmni
SaaS cyberattacks are prevalent and often go unnoticed until data loss or breaches occur. Sign-ins from an unusual IP address. Stolen session tokens. These security risks can lurk in the shadows and put your entire SaaS estate at risk.
Don’t wait for a breach to secure your SaaS data. AppOmni helps security teams to detect suspicious activity, decide what activities to be alerted on, and receive guided remediation. Learn how at AppOmni.com.
Vulnerability found in TETRA encryption
Ryzen CPUs vulnerable to Zenbleed exploit
Norwegian government breached with Ivanti zero-day
Thanks to today's episode sponsor, AppOmni
Over provisioned users could lead to your most sensitive data being exposed or leaked. Just a single attack on one of those users may compromise your entire SaaS estate.
With AppOmni’s SaaS Identity Fabric, secure and manage end-users, entitlements, and threat-based activity. Gain visibility and control over provisioned users, the SaaS data they have access to, and receive guided remediation. Get connected with SaaS security experts at AppOmni.com.
Clop moves leaked data to clearweb sites
EU governments push back on centralized cyber reporting
Cost of data breaches up 15%
Thanks to today's episode sponsor, AppOmni
SaaS cyberattacks are prevalent and often go unnoticed until data loss or breaches occur. Sign-ins from an unusual IP address. Stolen session tokens. These security risks can lurk in the shadows and put your entire SaaS estate at risk.
Don’t wait for a breach to secure your SaaS data. AppOmni helps security teams to detect suspicious activity, decide what activities to be alerted on, and receive guided remediation. Learn how at AppOmni.com.
Microsoft key stolen by Chinese hackers provided access far beyond Outlook
JumpCloud breach traced back to North Korean state hackers
DHL investigating MOVEit breach as number of victims surpasses 20 million
Thanks to today's episode sponsor, AppOmni
Over provisioned users could lead to your most sensitive data being exposed or leaked. Just a single attack on one of those users may compromise your entire SaaS estate.
With AppOmni’s SaaS Identity Fabric, secure and manage end-users, entitlements, and threat-based activity. Gain visibility and control over provisioned users, the SaaS data they have access to, and receive guided remediation. Get connected with SaaS security experts at AppOmni.com.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, July 17-21, is hosted by Rich Stroffolino with our guest, Dimitri van Zantvliet, CISO, Dutch Railways
Thanks to our show sponsor, OpenVPN
According to Oriel Hernan Villalba Pinzetta, a System Administrator with CEDEC’s cybersecurity and IT department, “The pandemic meant we could not come to the office, and we needed to facilitate access to our local resources,” says Villalba. “Cloud Connexa was really easy and fast to set up, two things we really needed in that moment.” Read more here.
All links and the video of this episode can be found on CISO Series.com
New P2PInfect worm targeting Redis servers on Linux and Windows systems
Adobe releases new patches for exploited ColdFusion vulnerabilities
Estée Lauder breached by two ransomware groups
And now a word from our sponsor, OpenVPN
According to Oriel Hernan Villalba Pinzetta, a System Administrator with CEDEC’s cybersecurity and IT department, “The pandemic meant we could not come to the office, and we needed to facilitate access to our local resources,” says Villalba. “Cloud Connexa was really easy and fast to set up, two things we really needed in that moment.” Read more at the link in our show notes.
For the stories behind the headlines, head to CISOseries.com.
Complex DDoS attacks on the rise
MI6 warns of Chinese data traps
Microsoft expands cloud log access
And now a word from our sponsor, OpenVPN
Karim Hakim, CTO at Hakim Misr Paco, says that CloudConnexa has given him some long-sought peace of mind. “OpenVPN has helped my company to access remote nodes securely without worrying about security protocols,” he says. “My company has been looking for a similar solution for years, and we finally got what we were looking for.” Read more at the link in our show notes.
US government launches IoT security labeling program
Renewable technologies could pose risk to US electric grid
US blacklists two spyware firms run by Israeli former general
And now a word from our sponsor, OpenVPN
Stephen Haecker, Chief Technology Officer at Carteras Colectivas, relies on Cloud Connexa customer support for his remote team. “I have used them about once per month to help with our growing networks,” he says, “and the service quality is great with quick turnarounds.” Haecker appreciates the consistency of the support team, and their personalized approach. Read more at the link in our show notes.
For the stories behind the headlines, visit CISOseries.com.
JumpCloud breached by APT
Wisconsin allegedly hit by LockBit
Typos leaking military emails
And now a word from our sponsor, OpenVPN
Zach Belhadri, the Infrastructure Manager at Knight Capital, shares why using Cloud Connexa for his team’s security has been a game changer. With the Cybershield feature, he’s able to prevent malware, phishing, and other threats by restricting access to only authorized and trusted internet destinations. He calls Cloud Connexa “an awesome product with huge potential.” Read more at the link in our show notes.
Russia-linked Gamaredon starts stealing data 30 to 50 minutes after initial compromise
New AI tool – WormGPT allows for sophisticated cyber attacks
Microsoft still unsure how hackers stole Azure AD signing key
And now a word from our sponsor, OpenVPN
We asked Anthony Hook, the CTO at Dataweavers, if he would recommend Cloud Connexa to other companies. His response? A resounding yes! With Cloud Connexa, he says “we bypassed the clunky client-owned VPNs and networks, gaining a seamless, secure, and efficient connectivity solution.” Read more at the link in our show notes.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, July 10-14, is hosted by Sean Kelly with our guest, Yaron Levi, CISO, Dolby
Thanks to our show sponsor, Opal
Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal’s mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identity security for scale. Visit Opal.dev.
All links and the video of this episode can be found on CISO Series.com
USB drive malware attacks spiking again in first half of 2023
Users of Honeywell Experion DCS platforms urged to patch 9 vulnerabilities immediately
Ransomware gangs have extorted $449 million this year
Thanks to this week's episode sponsor, Opal
Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identity security for scale.
For the stories behind the headlines, head to CISOseries.com.
What we know about NATO cyber pledges
Tax prep companies “recklessly” shared data
Report finds decrease in crypto crime
Thanks to this week's episode sponsor, Opal
Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identity security for scale.
Silk Road’s senior advisor sentenced to 20 years in prison
11 million HCA patients impacted by data breach
Google hit with lawsuit alleging it stole user data to train its AI tools
Thanks to this week's episode sponsor, Opal
Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identity security for scale.
For the stories behind the headlines, visit CISOseries.com.
JumpCloud resets customer API keys
Would you be interested in a slightly used dark web market?
US and EU agree on new data transfer agreement
Thanks to this week's episode sponsor, Opal
Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identity security for scale.
New ‘Big Head’ ransomware displays fake Windows update alert
RedEnergy stealer-as-a-ransomware threat targeting energy and telecom sectors
Three new MOVEit bugs spur CISA warning as more victims report breaches
Thanks to this week's episode sponsor, Opal
Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identity security for scale.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, July 3-7, is hosted by Rich Stroffolino with our guest, Hadas Cassorla, CISO, M1
Thanks to today’s episode sponsor, SlashNext
SlashNext, a leader in SaaS-based Integrated Cloud Messaging Security across email, web, and mobile has the industry’s first artificial intelligence solution, HumanAI, that uses generative AI to defend against advanced business email compromise (BEC), supply chain attacks, executive impersonation, and financial fraud. Request a demo today.
All links and the video of this episode can be found on CISO Series.com
Shell confirms MOVEit-related breach after ransomware group leaks data
28,000 impacted by data breach at Pepsi Bottling Ventures
INTERPOL nabs hacking crew OPERA1ER’s leader behind $11 million cybercrime
Thanks to today's episode sponsor, SlashNext
SlashNext, a leader in SaaS-based Integrated Cloud Messaging Security across email, web, and mobile has the industry’s first artificial intelligence solution, HumanAI, that uses generative AI to defend against advanced business email compromise (BEC), supply chain attacks, executive impersonation, and financial fraud. Request a demo today.
For the stories behind the headlines, head to CISOseries.com.
Japan’s major port hit with ransomware
European court orders changes to Meta’s data practices
Injunction restricts White House contact with social media companies
Thanks to today's episode sponsor, SlashNext
SlashNext, a leader in SaaS-based Integrated Cloud Messaging Security across email, web, and mobile has the industry’s first artificial intelligence solution, HumanAI, that uses generative AI to defend against advanced business email compromise (BEC), supply chain attacks, executive impersonation, and financial fraud. Request a demo today.
BlackCat ransomware pushes Cobalt Strike via WinSCP search ads
CISA issues warning for cardiac device system vulnerability
330,000 FortiGate firewalls still unpatched to CVE-2023-27997 RCE flaw
Thanks to today's episode sponsor, SlashNext
SlashNext, a leader in SaaS-based Integrated Cloud Messaging Security across email, web, and mobile has the industry’s first artificial intelligence solution, HumanAI, that uses generative AI to defend against advanced business email compromise (BEC), supply chain attacks, executive impersonation, and financial fraud. Request a demo today.
For the stories behind the headlines, head to CISOseries.com.
Semiconductor giant says IT supplier was attacked, LockBit makes related claims
Several US states investigating ‘SiegedSec’ hacking campaign
Russian telecom confirms hack after group backing Wagner boasted about an attack
Thanks to today's episode sponsor, SlashNext
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, June 26-30, is hosted by Rich Stroffolino with our guest, Cassio Goldschmidt, CISO, ServiceTitan
Thanks to our show sponsor, AppOmni
Over provisioned users could expose your organization’s most sensitive data. Just a single attack on one of those users may compromise your entire SaaS estate. With AppOmni’s identity and threat detection capabilities, you can detect and respond to suspicious activities within your SaaS environment. Gain visibility into over provisioned users, the SaaS data they have access to, and receive guided remediation. Get started at AppOmni.com.
All links and the video of this episode can be found on CISO Series.com
SEC notice to SolarWinds CISO and CFO roils cybersecurity industry
Newly uncovered ThirdEye Windows-based malware steals sensitive data
Cyber Command to expand ‘canary in the coal mine’ unit working with private sector
Thanks to today's episode sponsor, AppOmni
Over provisioned users could expose your organization’s most sensitive data. Just a single attack on one of those users may compromise your entire SaaS estate.
With AppOmni’s identity and threat detection capabilities, you can detect and respond to suspicious activities within your SaaS environment. Gain visibility into over provisioned users, the SaaS data they have access to, and receive guided remediation. Get started at AppOmni.com.
For the stories behind the headlines, head to CISOseries.com.
Federal network devices fail CISA requirements
US considering more AI chip export bans
The scope of MOVEit vulnerability
Thanks to today's episode sponsor, AppOmni
Are you continuously monitoring the common misconfigurations occurring in your SaaS ecosystem? From inactive connected SaaS apps retaining access to sensitive data, to threat actors manipulating conditional access rules, these misconfigurations can pose a significant threat to your SaaS security.
Take action with AppOmni. Secure your organization’s most sensitive data and continuously monitor your SaaS estate for data exposure and misconfigurations. Visit AppOmni.com to get a free risk assessment.
Thanks to today's episode sponsor, AppOmni
Over provisioned users could expose your organization’s most sensitive data. Just a single attack on one of those users may compromise your entire SaaS estate.
With AppOmni’s identity and threat detection capabilities, you can detect and respond to suspicious activities within your SaaS environment. Gain visibility into over provisioned users, the SaaS data they have access to, and receive guided remediation. Get started at AppOmni.com.
For the stories behind the headlines, visit CISOseries.com.
Monopoly darknet operator charged
Activision Blizzard games hit with DDoS
5G deadline could impact flights
Thanks to today's episode sponsor, AppOmni
Are you continuously monitoring the common misconfigurations occurring in your SaaS ecosystem? From inactive connected SaaS apps retaining access to sensitive data, to threat actors manipulating conditional access rules, these misconfigurations can pose a significant threat to your SaaS security.
Take action with AppOmni. Secure your organization’s most sensitive data and continuously monitor your SaaS estate for data exposure and misconfigurations. Visit AppOmni.com to get a free risk assessment.
CISA adds 6 flaws to known exploited vulnerabilities catalog
US military personnel report receiving smartwatches in the mail
Microsoft 365 users new Outlook and Teams problems
Thanks to today's episode sponsor, AppOmni
Over provisioned users could expose your organization’s most sensitive data. Just a single attack on one of those users may compromise your entire SaaS estate.
With AppOmni’s identity and threat detection capabilities, you can detect and respond to suspicious activities within your SaaS environment. Gain visibility into over provisioned users, the SaaS data they have access to, and receive guided remediation. Get started at AppOmni.com.
For the stories behind the headlines, head to CISOseries.com
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, June 19-23, is hosted by Rich Stroffolino with our guest, Janet Heins, CISO, iHeartMedia
Thanks to our show sponsor, Wing Security
The first step to securing your organization’s SaaS usage is knowing which SaaS applications your employees are using. 3rd party included. Wing offers a completely free, SaaS Shadow IT Discovery tool. You can find it at wing.security and self onboard. No sales in the process, no credit card needed, no time-limit. Just go ahead and discover your SaaS usage.
All links and the video of this episode can be found on CISO Series.com
Cybersecurity breaches more than double among Canadian businesses
Experienced China-based hacking group has new backdoor tool
Cyberattacks on OT, ICS lay groundwork for kinetic warfare
Thanks to today's episode sponsor, Wing Security
The first step to securing your organization’s SaaS usage is knowing which SaaS applications your employees are using. 3rd party included. Wing offers a completely free, SaaS Shadow IT Discovery tool. You can find it at wing.security and self onboard. No sales in the process, no credit card needed, no time-limit. Just go ahead and discover your SaaS usage.
For the stories behind the headlines, head to CISOseries.com.
New DoJ cyber prosecution team will go after nation-state threat actors
Apple fixes zero-days used to deploy Triangulation spyware
Schumer unveils strategy to regulate AI
Thanks to today's episode sponsor, Wing Security
Shadow IT is an evolving pain and a security risk, especially in today’s decentralized work environments. Now’s the time to regain control of your SaaS usage by taking advantage of Wing’s Free SaaS Shadow IT discovery solution. Check out wing.security to self-onboard today, no strings attached.
For the stories behind the headlines, visit CISOseries.com.
Rorschach ransomware takes the speed crown
Data leak impacts Australian government
Cyber security market growth outpaces tech sector
Thanks to today's episode sponsor, Wing Security
Can you answer these three questions confidently?
1. How many SaaS applications are used in your organization?
2. Which permissions did users provide these applications?
and
3. What is the data that flows in and in between these applications?
Wing provides the answers. In fact, it discovers your SaaS usage completely for free, no time limit. Visit wing.security to self-onboard.
Reddit hit with ransom demand
UK’s cyber chief moves on to organized crime
Binance reaches deal with the SEC
Thanks to today's episode sponsor, Wing Security
The first step to securing your organization’s SaaS usage is knowing which SaaS applications your employees are using. 3rd party included. Wing offers a completely free, SaaS Shadow IT Discovery tool. You can find it at wing.security and self onboard. No sales in the process, no credit card needed, no time-limit. It takes minutes to discover your organization's SaaS usage.
Microsoft says early June service outages were cyberattacks
Third MOVEit vulnerability raises alarms as US Agriculture Department says it may be impacted
US govt offers $10 million bounty for info on Clop ransomware
Thanks to today's episode sponsor, Wing Security
The folks at Wing believe that SaaS Shadow IT discovery is the basic first step to securing your SaaS usage. They believe it so strongly that they launched a completely free SaaS Shadow IT Discovery solution. Check out wing.security to self-onboard today, no strings attached, no time limit. Wing.security.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, June 12-16, is hosted by Sean Kelly with our guest, Phil Beyer, former Head of Security, Etsy
Thanks to our show sponsor, Conveyor
Your scariest questionnaires that are hundreds of questions long are no match for Conveyor’s GPT-questionnaire tool – now with a browser extension for complex portals. Get GPT-generated precise answers to entire questionnaires so your review takes seconds. Now you can spend 89% less time completing questionnaires when you get accurate answers you don’t have to re-write. Try a free proof of concept with your own data to see it in action. See what security and sales teams are raving about at www.conveyor.com
All links and the video of this episode can be found on CISO Series.com
US federal agencies affected by MOVEit vulnerability
Pentagon leak suspect indicted by a federal grand jury
Suspected LockBit ransomware affiliate nabbed
Thanks to today's episode sponsor, Conveyor
Your scariest questionnaires that are hundreds of questions long are no match for Conveyor’s GPT-questionnaire tool - now with a browser extension for complex portals.
Get GPT-generated precise answers to entire questionnaires so your review takes seconds.
Now you can spend 89% less time completing questionnaires when you get accurate answers you don’t have to re-write.
Try a free proof of concept with your own data to see it in action. See what security and sales teams are raving about at www.conveyor.com
For the stories behind the headlines, visit CISOseries.com.
China-linked APT group spotted exploiting a VMware ESXi zero-day
Hundreds of thousands of ecommerce sites impacted by critical plugin vulnerability
7-Nation LockBit report shows US paid over $90m in ransoms since 2020
Thanks to today's episode sponsor, Conveyor
Let’s gladly pass the most thankless job in cybersecurity – completing customer security questionnaires – to the AI bots.
Conveyor’s GPT-questionnaire response tool auto-generates precise, accurate answers to entire questionnaires.
With accuracy far superior to other tools, you can spend almost zero time reviewing generated answers. There’s an in platform auto-fill feature or a browser extension for tricky portals.
Stop settling for mediocre tools that only provide lousy “near hits” from your library. Try a free proof of concept with your own data. Learn more at www.conveyor.com.
For the stories behind the headlines, head to CISOseries.com.
Amazon server outage broke fast food apps among other things
Update: Fortinet warns of possible zero-day exploited in limited attacks
US intelligence confirms it buys Americans’ personal data
Thanks to today's episode sponsor, Conveyor
What’s better than using Conveyor’s GPT-questionnaire response tool to generate precise answers to security questionnaires?
Letting customers upload their own questionnaires to your portal and getting back answers in seconds - all based on the content in your knowledge base.
Think of it like a security questionnaire ATM. A prospect clicks through an NDA, uploads questions and gets all the answers they need from the bot, all without ever having to speak to you.
We call that a win-win. Learn more at www.conveyor.com.
For the stories behind the headlines, visit CISOseries.com.
Critical RCE flaw discovered in Fortinet FortiGate firewalls
BatCloak engine makes malware fully undetectable
Swiss Government targeted by series of cyberattacks
Thanks to today's episode sponsor, Conveyor
Tried to use GPT to fill out questionnaires yet? We already built that for you.
Conveyor’s GPT-questionnaire response tool auto-generates precise, accurate answers to entire questionnaires.
With accuracy far superior to other tools, you can spend almost zero time reviewing generated answers. There’s also a browser extension for complex portals and other scary questionnaires. Best part is, it actually works.
Try a free proof of concept with your own data to see it in action. You won’t be disappointed. Learn more at www.conveyor.com
For the stories behind the headlines, head to CISOseries.com.
Faked crypto journalists steal real crypto
Strava heat maps leak addresses
API changes lead to Reddit protests
Thanks to today's episode sponsor, Conveyor
Let’s gladly pass the most thankless job in cybersecurity – completing customer security questionnaires – to the AI bots.
Conveyor’s GPT-questionnaire response tool auto-generates precise, accurate answers to entire questionnaires.
With accuracy far superior to other tools, you can spend almost zero time reviewing generated answers. There’s an in platform auto-fill feature or a browser extension for tricky portals.
Stop settling for mediocre tools that only provide lousy “near hits” from your library. Try a free proof of concept with your own data. Learn more at www.conveyor.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, June 5-9, is hosted by Rich Stroffolino with our guest, Joshua Scott, Head of Security and IT, Postman
Thanks to our show sponsor, Trend Micro
Hybrid work, cloud adoption, and shadow IT have introduced new cybersecurity risks to organizations. Security leaders are left asking, “How can I manage our expanding attack surface?”
Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities in their “Risk to Resilience World Tour. Hear from experts on the latest threat landscape trends, solutions, and platform strategies to manage risk and defend your organization with speed and accuracy. Find the closest city to you and register today to take a leap towards a more resilient future. Head to trendmicro.com/cisoseries
All links and the video of this episode can be found on CISO Series.com
New PowerDrop malware targets U.S. aerospace defense industry
Zipper giant YKK confirms cyberattack targeted U.S. networks
Barracuda urges customers to replace vulnerable appliances immediately
Thanks to this week's episode sponsor, Trend Micro
Hybrid work, cloud adoption, and shadow IT have introduced new cybersecurity risks to organizations. Security leaders are left asking, “How can I manage our expanding attack surface?”
Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities in their “Risk to Resilience World Tour.
Hear from experts on the latest threat landscape trends, solutions, and platform strategies to manage risk and defend your organization with speed and accuracy. Find the closest city to you and register today to take a leap towards a more resilient future.
Head to trendmicro.com/cisoseries
For the stories behind the headlines, head to CISOseries.com.
Google improves brand email authentication
SEC drops cases due to data protection failures
Clop asks victims to contact it for a ransom
Thanks to this week's episode sponsor, Trend Micro
Hybrid work, cloud adoption, and shadow IT have introduced new cybersecurity risks to organizations. Security leaders are left asking, “How can I manage our expanding attack surface?”
Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities in their “Risk to Resilience World Tour.
Hear from experts on the latest threat landscape trends, solutions, and platform strategies to manage risk and defend your organization with speed and accuracy. Find the closest city to you and register today to take a leap towards a more resilient future.
Head to trendmicro.com/cisoseries
Thanks to this week's episode sponsor, Trend Micro
Hybrid work, cloud adoption, and shadow IT have introduced new cybersecurity risks to organizations. Security leaders are left asking, “How can I manage our expanding attack surface?”
Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities in their “Risk to Resilience World Tour.
Hear from experts on the latest threat landscape trends, solutions, and platform strategies to manage risk and defend your organization with speed and accuracy. Find the closest city to you and register today to take a leap towards a more resilient future.
Head to trendmicro.com/cisoseries
For the stories behind the headlines, visit CISOseries.com.
Satellite hacking at DEF CON
Atomic Wallet investigating losses
SEC sues Binance
Thanks to this week's episode sponsor, Trend Micro
Hybrid work, cloud adoption, and shadow IT have introduced new cybersecurity risks to organizations. Security leaders are left asking, “How can I manage our expanding attack surface?”
Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities in their “Risk to Resilience World Tour.
Hear from experts on the latest threat landscape trends, solutions, and platform strategies to manage risk and defend your organization with speed and accuracy. Find the closest city to you and register today to take a leap towards a more resilient future.
Head to trendmicro.com/cisoseries
Xplain hack impacts Swiss cantonal police and Fedpol
BlackSuit shows similarities to Royal
Microsoft is retiring Cortana on Windows
Thanks to this week's episode sponsor, Trend Micro
Hybrid work, cloud adoption, and shadow IT have introduced new cybersecurity risks to organizations. Security leaders are left asking, “How can I manage our expanding attack surface?”
Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities in their “Risk to Resilience World Tour.
Hear from experts on the latest threat landscape trends, solutions, and platform strategies to manage risk and defend your organization with speed and accuracy. Find the closest city to you and register today to take a leap towards a more resilient future.
Head to trendmicro.com/cisoseries
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines - Week in Review, May 29-June 2, is hosted by Sean Kelly with our guest, Howard Holton, CTO, GigaOm
Thanks to today’s episode sponsor, Barricade Cyber
Have you fallen victim to a ransomware attack? Don’t worry! Barricade Cyber Solutions has helped thousands of customers in situations just like yours. Their proprietary ransomware recovery services are designed to quickly get your business back on track. Their team of experts will identify the source of the attack and provide a comprehensive solution to prevent it from happening again. You can count on them for the security of your data and systems. Visit barricadecyber.com
All links and the video of this episode can be found on CISO Series.com
Amazon Ring, Alexa accused of privacy violations by FTC
Kaspersky reports on new mobile APT campaign targeting iOS devices
White House to choose Army general Hartman to be Cyber Command No. 2
Thanks to today's episode sponsor, Barricade Cyber Solutions
Have you fallen victim to a ransomware attack? Don't worry! Barricade Cyber Solutions has helped thousands of customers in situations just like yours. Their proprietary ransomware recovery services are designed to quickly get your business back on track. Their team of experts will identify the source of the attack and provide a comprehensive solution to prevent it from happening again. You can count on them for the security of your data and systems. Visit barricadecyber.com
For the stories behind the headlines, head to CISOseries.com.
Toyota finds more cloud leaks
Gigabyte firmware update system insecure
Twitter expands Community Notes to images
Thanks to today's episode sponsor, Barricade Cyber Solutions
Have you fallen victim to a ransomware attack? Don't worry! Barricade Cyber Solutions has helped thousands of customers in situations just like yours. Their proprietary ransomware recovery services are designed to quickly get your business back on track. Their team of experts will identify the source of the attack and provide a comprehensive solution to prevent it from happening again. You can count on them for the security of your data and systems. Visit barricadecyber.com
Leading experts warn of a risk of extinction from AI
Hackers demand $3 million from Scandinavian Airlines
Theranos founder turns herself in for 11-year prison term
Thanks to today's episode sponsor, Barricade Cyber Solutions
Have you fallen victim to a ransomware attack? Don't worry! Barricade Cyber Solutions has helped thousands of customers in situations just like yours. Their proprietary ransomware recovery services are designed to quickly get your business back on track. Their team of experts will identify the source of the attack and provide a comprehensive solution to prevent it from happening again. You can count on them for the security of your data and systems. Visit barricadecyber.com
For the stories behind the headlines, visit CISOseries.com.
New GobRAT remote access trojan targeting Linux routers in Japan
Attackers use encrypted RPMSG messages in Microsoft 365 targeted phishing attacks
Hackers hold city of Augusta hostage in a ransomware attack
Thanks to today's episode sponsor, Barricade Cyber Solutions
Have you fallen victim to a ransomware attack? Don't worry! Barricade Cyber Solutions has helped thousands of customers in situations just like yours. Their proprietary ransomware recovery services are designed to quickly get your business back on track. Their team of experts will identify the source of the attack and provide a comprehensive solution to prevent it from happening again. You can count on them for the security of your data and systems. Visit barricadecyber.com
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
Cyber Security Headlines – Week in Review, May 22-26, is hosted by Rich Stroffolino with our guest, Rich Greenberg, ISSA Distinguished Fellow and Honor Roll
Thanks to our show sponsor, Sonrai Security
Did you know that 81% of breaches are due to compromised identities? It’s a sobering statistic and one that enterprise organizations cannot afford to ignore. Sonrai Security has made a name for itself by securing enterprise clouds from the inside out, securing every identity, access, and permission in the cloud. Download Sonrai Security’s new CIEM Buyer’s Guide to learn more about fortifying your cloud from the inside out at sonraisecurity.com.
All links and the video of this episode can be found on CISO Series.com
GDPR is 5 years old, and over 1 million people have asked to be forgotten
GitLab security update patches critical vulnerability
Mysterious malware designed to cripple industrial systems linked to Russia
And now a word from our sponsor, Sonrai Security
Did you know that 81% of breaches are due to compromised identities? It's a sobering statistic and one that enterprise organizations cannot afford to ignore. Sonrai Security has made a name for itself by securing enterprise clouds from the inside out, securing every identity, access, and permission in the cloud. Download Sonrai Security’s new CIEM Buyer’s Guide to learn more about fortifying your cloud from the inside out at sonraisecurity.com.
For the stories behind the headlines, head to CISOseries.com.
Google launches GUAC
Barracuda gateways breached by zero-day
Cyberattacks focus on Kenya’s Chinese debt
And now a word from our sponsor, Sonrai Security
Did you know that 81% of breaches are due to compromised identities? It's a sobering statistic and one that enterprise organizations cannot afford to ignore. Sonrai Security has made a name for itself by securing enterprise clouds from the inside out, securing every identity, access, and permission in the cloud. Download Sonrai Security’s new CIEM Buyer’s Guide to learn more about fortifying your cloud from the inside out at sonraisecurity.com.
TikTok sues Montana after state bans app
US sanctions orgs behind North Korea’s ‘illicit’ IT worker army
Fake images on Twitter briefly spook the stock market
And now a word from our sponsor, Sonrai Security
Did you know that 81% of breaches are due to compromised identities? It's a sobering statistic and one that enterprise organizations cannot afford to ignore. Sonrai Security has made a name for itself by securing enterprise clouds from the inside out, securing every identity, access, and permission in the cloud. Download Sonrai Security’s new CIEM Buyer’s Guide to learn more about fortifying your cloud from the inside out at sonraisecurity.com.
For the stories behind the headlines, visit CISOseries.com.
Meta receives record fine over EU data transfers
China bans Micron over cybersecurity risks
Crypto mixer hijacked
And now a word from our sponsor, Sonrai Security
Did you know that 81% of breaches are due to compromised identities? It's a sobering statistic and one that enterprise organizations cannot afford to ignore. Sonrai Security has made a name for itself by securing enterprise clouds from the inside out, securing every identity, access, and permission in the cloud. Download Sonrai Security’s new CIEM Buyer’s Guide to learn more about fortifying your cloud from the inside out at sonraisecurity.com.
HP rushes to fix bricked printers after faulty firmware update
PyPI repository under attack: User sign-ups and package uploads temporarily halted
New security flaw exposed in Samsung devices
And now a word from our sponsor, Sonrai Security
Did you know that 81% of breaches are due to compromised identities? It's a sobering statistic and one that enterprise organizations cannot afford to ignore. Sonrai Security has made a name for itself by securing enterprise clouds from the inside out, securing every identity, access, and permission in the cloud. Download Sonrai Security’s new CIEM Buyer’s Guide to learn more about fortifying your cloud from the inside out at sonraisecurity.com.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, May 15-19, is hosted by Rich Stroffolino with our guest, Dave Hannigan, CISO, Nubank
Thanks to our show sponsor, Hunters
There is nothing worse than relying on a legacy SIEM that your security team has out-grown, especially when it impacts your ability to detect real incidents. Hunters’ SOC Platform offers built-in, always up-to-date detection rules and automatic correlation that allow SOC analysts to focus on higher-value tasks that impact your organization. It’s time to move to a platform that reduces risk, complexity and cost for the SOC. Visit hunters.security to learn how you can Move Beyond SIEM and let them know you heard about Hunters on the CISO Series.
All links and the video of this episode can be found on CISO Series.com
Supreme Court shields Twitter from liability and leaves Section 230 untouched
Montana governor bans TikTok
Millions of smartphones distributed worldwide with preinstalled ‘Guerrilla’ malware
Thanks to today's episode sponsor, Hunters
There is nothing worse than relying on a legacy SIEM that your security team has out-grown, especially when it impacts your ability to detect real incidents. Hunters’ SOC Platform offers built-in, always up-to-date detection rules and automatic correlation that allow SOC analysts to focus on higher-value tasks that impact your organization. It’s time to move to a platform that reduces risk, complexity & cost for the SOC. Visit hunters.security to learn how you can Move Beyond SIEM and let them know you heard about Hunters on the CISO Series.
For the stories behind the headlines, head to CISOseries.com.
Lancefly group hits Asia
Meta facing record EU privacy fine
New TLDs a vector for phishing
Thanks to today's episode sponsor, Hunters
There is nothing worse than relying on a legacy SIEM that your security team has out-grown, especially when it impacts your ability to detect real incidents. Hunters’ SOC Platform offers built-in, always up-to-date detection rules and automatic correlation that allow SOC analysts to focus on higher-value tasks that impact your organization. It’s time to move to a platform that reduces risk, complexity & cost for the SOC. Visit hunters.security to learn how you can Move Beyond SIEM and let them know you heard about Hunters on the CISO Series.
An inside look at RaaS
White House cyber strategy goes big on education
Chinese attackers hit TP-Link routers
Thanks to today's episode sponsor, Hunters
If your SIEM is causing an endless cycle of noisy alerts, manually writing generic detection rules, and limited data ingestion & retention, your SOC might need an upgrade. Hunters is a SaaS platform, purpose built for your Security Operations team. Solaris Group, a leading German FinTech, implemented Hunters SOC Platform to eliminate the burden of redundant detection engineering and manual event correlation – allowing SOC analysts to focus on higher-value tasks. Visit hunters.security to learn how your SOC can Move Beyond SIEM and let them know you heard about Hunters on the CISO Series.
Cyber attack hits Philadelphia Inquirer
Transportation Department cyber breach exposes federal employee data
3 million data breach notices being sent to SchoolDude users
Thanks to today's episode sponsor, Hunters
Relying on a SIEM in 2023 is like living in a college dorm room, post-graduation - you’re operating in an environment you’ve out-grown. The Hunters SOC Platform is purpose built to help your Security Operations mature to the level you need to be at. ChargePoint, the world's largest network of electric vehicle charging stations, uses Hunters SOC Platform to leverage its out-of-the-box detection content to more efficiently respond to new threats and vulnerabilities. It’s time to Move Beyond SIEM. Visit Hunters.security to learn more and let them know you heard about Hunters on the CISO Series.
For the stories behind the headlines, visit CISOseries.com.
Discord suffers data breach
Car location data of 2 million Toyota customers exposed for ten years
Swiss tech giant ABB confirms ‘IT security incident’
Thanks to today's episode sponsor, Hunters
Hunters is a SOC platform, built for your security team. Hunters empowers companies to move beyond SIEM with unlimited ingestion and normalization of security data at a predictable cost. Using Hunters, a CISO at a leading online retailer “tripled the amount of data ingested by her security team while cutting costs from a legacy SIEM provider by 75%.” It’s time to Move Beyond SIEM. Visit hunters.security to learn more and let them know you heard about Hunters on the CISO Series.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
Cyber Security Headlines – Week in Review, May 8-12, is hosted by Rich Stroffolino with our guest, Paul Connelly, Former CISO, HCA Healthcare
Thanks to today’s episode sponsor, Trend Micro
Cybersecurity is not just about protection, it’s about foresight, agility, and resilience. Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks. Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind. Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.
All links and the video of this episode can be found on CISO Series.com
Twitter launches encrypted private messages
Microsoft releases fix for patched Outlook issue exploited by Russian hackers
North Korea-linked APT group breaches the Seoul National University Hospital
Thanks to today's episode sponsor, TrendMicro
Cybersecurity is not just about protection, it’s about foresight, agility, and resilience. Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks. Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind. Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.
For the stories behind the headlines, head to CISOseries.com.
The long term impact of leaked Intel Boot Guard keys
AtlasOS shrugs at Windows security features
Cisco warns of new phishing-as-a-service tool
Thanks to today's episode sponsor, TrendMicro
Cybersecurity is not just about protection, it’s about foresight, agility, and resilience. Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks. Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind. Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.
Operation Medusa takes down ‘Snake’ malware network
‘PlugwalkJoe’ pleads guilty to massive 2020 Twitter hack
Justice Department takes down 13 DDoS-for-Hire sites
Thanks to today's episode sponsor, TrendMicro
Cybersecurity is not just about protection, it’s about foresight, agility, and resilience. Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks. Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind. Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.
For the stories behind the headlines, visit CISOseries.com.
Dallas still reeling from ransomware
Hacked Facebook pages buying Facebook ads
Court rules on Merck cyber insurance claim
Thanks to today's episode sponsor, TrendMicro
Cybersecurity is not just about protection, it’s about foresight, agility, and resilience. Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks. Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind. Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.
Top US cyber official warns AI may be the ‘most powerful weapon of our time’
Ex-Uber CSO given three-year probation sentence, avoids prison after guilty verdict
Ransomware group behind Oakland attack targets city in Massachusetts
Thanks to today's episode sponsor, TrendMicro
Cybersecurity is not just about protection, it’s about foresight, agility, and resilience. Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks. Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind. Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, May 1-5, is hosted by Rich Stroffolino with our guest, Allison Miller, Cybersecurity and Technology Executive
Thanks to our show sponsor, Trend Micro
Cybersecurity is not just about protection, it’s about foresight, agility, and resilience. Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks. Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind. Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.
All links and the video of this episode can be found on CISO Series.com
City of Dallas hit by Royal ransomware attack impacting IT services
Researchers uncover new exploit for PaperCut vulnerability that can bypass detection
Mirai botnet loves exploiting unpatched TP-Link routers, CISA warns
Thanks to today's episode sponsor, TrendMicro
Cybersecurity is not just about protection, it’s about foresight, agility, and resilience. Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks. Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind. Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.
For the stories behind the headlines, head to CISOseries.com.
FTC comes down on Meta monetizing minors
CISA urges adoption of Covered List
Almost half of HTML attachments found malicious
Thanks to today's episode sponsor, TrendMicro
Cybersecurity is not just about protection, it’s about foresight, agility, and resilience. Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks. Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind. Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.
Authorities seize 9 crypto exchanges used for money laundering
T-Mobile discloses 2nd data breach of 2023
‘Godfather of AI’ quits Google and warns of misinformation dangers
Thanks to today's episode sponsor, TrendMicro
Cybersecurity is not just about protection, it’s about foresight, agility, and resilience. Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks. Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind. Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.
For the stories behind the headlines, visit CISOseries.com.
The academic threat of juice jacking
Data breach lawsuits on the rise
Telegram ban lifted in Brazil
Thanks to today's episode sponsor, TrendMicro
Cybersecurity is not just about protection, it’s about foresight, agility, and resilience. Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks. Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind. Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.
Hackers target vulnerable Veeam backup servers exposed online
DOJ detected the SolarWinds hack 6 months earlier than first disclosed
Cold storage giant Americold outage caused by network breach
Thanks to today's episode sponsor, TrendMicro
Cybersecurity is not just about protection, it’s about foresight, agility, and resilience. Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks. Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind. Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, April 24-28, is hosted by Sean Kelly with our guest, Steve Zalewski, former CISO, Levi Strauss and co-host, Defense in Depth.
Thanks to today’s episode sponsor, Tines
Ready to take security automation up a notch? With Tines, it’s easier than ever! The no-code automation platform is redefining and simplifying security operations – start building mission-critical workflows and apps that streamline processes AND ensure crucial data stays safe while extending the influence of your security team throughout your organization. Visit Tines.com to find out more!
All links and the video of this episode can be found on CISO Series.com
Charming Kitten APT uses a new BellaCiao malware
Microsoft blames clop affiliate for PaperCut attacks
Big tech crackdown looms as EU, UK ready new rules
And now a word from our sponsor, Tines
Ready to take security automation up a notch? With Tines, it’s easier than ever! The no-code automation platform is redefining and simplifying security operations - start building mission-critical workflows and apps that streamline processes AND ensure crucial data stays safe while extending the influence of your security team throughout your organization. Visit Tines.com to find out more!
For the stories behind the headlines, head to CISOseries.com.
Messaging app update distributes malware
China reclassifies cyberattacks
Malware-free cyberattacks on the rise
And now a word from our sponsor, Tines
Ask anyone at RSA; security teams can’t operate in a silo. No SOAR solutions enable users to dynamically collect information outside their systems and use it at multiple points in an automated workflow - but Tines does! With Tines, users can exchange real-time information outside its platform and use it to drive automated workflows. Visit Tines.com/build to learn more!
US policing use of AI for civil rights violations
Bill proposes new security testing centers for critical government tech
Microsoft Edge is leaking user browsing data to Bing
And now a word from our sponsor, Tines
To proactively protect against threats, you need a culture of cybersecurity - and solutions that facilitate this. With Tines’ no-code automation platform, you can: 1. Remediate threats faster. 2. Improve automation. 3. Control access to your data. 4. Create a culture of cybersecurity. Tines allows users to leverage real-time information across any stage of an automated workflow! Visit Tines.com to learn more.
For the stories behind the headlines, visit CISOseries.com.
A call to standardize threat group naming
Threat actors using new tool to disable EDR
North Dakota turns to AI for cyber
And now a word from our sponsor, Tines
Ready to take security automation up a notch? With Tines, it’s easier than ever! The no-code automation platform is redefining and simplifying security operations - start building mission-critical workflows and apps that streamline processes AND ensure crucial data stays safe while extending the influence of your security team throughout your organization. Visit Tines.com to find out more.
Energy sector orgs in US, Europe hit by same supply chain attack as 3CX
CISA adds 3 actively exploited flaws to KEV catalog, including critical PaperCut bug
Hyena code poised to devour GPT4
And now a word from our sponsor, Tines
Ask anyone at RSA; security teams can’t operate in a silo. No SOAR solutions enable users to dynamically collect information outside their systems and use it at multiple points in an automated workflow - but Tines does! With Tines, users can exchange real-time information outside its platform and use it to drive automated workflows. Visit Tines.com/build to learn more!
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, April 17-21, is hosted by Rich Stroffolino with our guest, Shawn Bowen, CISO, World Fuel Services
Thanks to our show sponsor, Pentera
This episode of Cyber Security Headlines is made possible in part by Pentera. Today over 60% of cyber attacks involve the use of exposed credentials. Now, for the first time, security teams can address this critical threat head-on. Pentera collects an organization’s leaked credentials and automatically tests their exploitability across the external and internal attack surface. Pentera’s customers find that leveraging the Pentera automated security validation platform as part of their exposure management strategy increases their ability to identify security gaps, improves the efficiency of remediation processes, and maximizes their security readiness. To learn more, visit Pentera.io
All links and the video of this episode can be found on CISO Series.com
Microsoft 365 outage blocks access to web apps and services
Capita has 'evidence' customer data was stolen in digital burglary
3CX supply chain attack was the result of a previous supply chain attack
Thanks to today's episode sponsor, Pentera
This episode of Cyber Security Headlines is made possible in part by Pentera. Today over 60% of cyber attacks involve the use of exposed credentials. Now, for the first time, security teams can address this critical threat head-on. Pentera collects an organization’s leaked credentials and automatically tests their exploitability across the external and internal attack surface. Pentera’s customers find that leveraging the Pentera automated security validation platform as part of their exposure management strategy increases their ability to identify security gaps, improves the efficiency of remediation processes, and maximizes their security readiness. To learn more, visit Pentera.io
For the stories behind the headlines, head to CISOseries.com.
NCSC warns of “new class” of Russian adversaries
GitHub adds Action to help open source security
Used routers hold on to secrets
Thanks to today's episode sponsor, Pentera
This episode of Cyber Security Headlines is made possible in part by Pentera. Today over 60% of cyber attacks involve the use of exposed credentials. Now, for the first time, security teams can address this critical threat head-on. Pentera collects an organization’s leaked credentials and automatically tests their exploitability across the external and internal attack surface. Pentera’s customers find that leveraging the Pentera automated security validation platform as part of their exposure management strategy increases their ability to identify security gaps, improves the efficiency of remediation processes, and maximizes their security readiness. To learn more, visit Pentera.io
Elon Musk wants to develop TruthGPT
Southwest’s operations resume after a ‘technical issue’
US, UK warn of govt hackers targeting Cisco routers
Thanks to today's episode sponsor, Pentera
This episode of Cyber Security Headlines is made possible in part by Pentera. Today over 60% of cyber attacks involve the use of exposed credentials. Now, for the first time, security teams can address this critical threat head-on. Pentera collects an organization’s leaked credentials and automatically tests their exploitability across the external and internal attack surface. Pentera’s customers find that leveraging the Pentera automated security validation platform as part of their exposure management strategy increases their ability to identify security gaps, improves the efficiency of remediation processes, and maximizes their security readiness. To learn more, visit Pentera.io
For the stories behind the headlines, head to CISOseries.com.
Ransomware comes for macOS
The security considerations of low code
Israeli offensive cyber company shutting down
Thanks to today's episode sponsor, Pentera
This episode of Cyber Security Headlines is made possible in part by Pentera. Today over 60% of cyber attacks involve the use of exposed credentials. Now, for the first time, security teams can address this critical threat head-on. Pentera collects an organization’s leaked credentials and automatically tests their exploitability across the external and internal attack surface. Pentera’s customers find that leveraging the Pentera automated security validation platform as part of their exposure management strategy increases their ability to identify security gaps, improves the efficiency of remediation processes, and maximizes their security readiness. To learn more, visit Pentera.io
Microsoft warns of Remcos RAT campaign targeting tax accountants
NCR suffers POS outage after BlackCat ransomware attack
Google releases urgent Chrome update to fix actively exploited zero-day vulnerability
Thanks to today's episode sponsor, Pentera
This episode of Cyber Security Headlines is made possible in part by Pentera. Today over 60% of cyber attacks involve the use of exposed credentials. Now, for the first time, security teams can address this critical threat head-on. Pentera collects an organization’s leaked credentials and automatically tests their exploitability across the external and internal attack surface. Pentera’s customers find that leveraging the Pentera automated security validation platform as part of their exposure management strategy increases their ability to identify security gaps, improves the efficiency of remediation processes, and maximizes their security readiness. To learn more, visit Pentera.io
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, April 10-14, is hosted by Rich Stroffolino with our guest, Dmitriy Sokolovskiy, CISO, Avid
Thanks to our show sponsor, AppOmni
Can you name all the third party apps connected to your major SaaS platforms, like Salesforce, Microsoft 365, or Google Workspace? What about the data these apps can access? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk. With AppOmni, you get visibility to all third party apps and SaaS-to-SaaS connections — including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com today to request a free risk assessment.
All links and the video of this episode can be found on CISO Series.com
Weak passwords targeted on Google Cloud
Potential IT snitches warned about employment stitches
Discord cooperating with leaked document investigation
And now a word from our sponsor, AppOmni
Can you name all the third party apps connected to your major SaaS platforms, like Salseforce, Microsoft 365, or Google Workspace? What about the data these apps can access? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk. With AppOmni, you get visibility to all third party apps and SaaS-to-SaaS connections — including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com today to request a free risk assessment.
Windows zero-day exploited in Nokoyawa ransomware attacks
LinkedIn and Microsoft Entra introduce a new way to verify professional contacts
Russian places Ukraine internet infrastructure clearly in its sights, both high tech and low
And now a word from our sponsor, AppOmni
Can you name all the third party apps connected to your major SaaS platforms, like Salseforce, Microsoft 365, or Google Workspace? What about the data these apps can access? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk. With AppOmni, you get visibility to all third party apps and SaaS-to-SaaS connections — including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com today to request a free risk assessment.
For the stories behind the headlines, head to CISOseries.com.
Microsoft warns of Azure shared key authorization abuse
Attackers hide stealer behind AI chatbot Facebook ads
OpenAI to launch bug bounty program
And now a word from our sponsor, AppOmni
Can you name all the third party apps connected to your major SaaS platforms, like Salseforce, Microsoft 365, or Google Workspace? What about the data these apps can access? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk. With AppOmni, you get visibility to all third party apps and SaaS-to-SaaS connections — including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com today to request a free risk assessment.
For the stories behind the headlines, visit CISOseries.com.
Netherlands to adopt RPKI
Widespread backdoor installed on WordPress sites
Tracing leaked Pentagon documents
And now a word from our sponsor, AppOmni
Can you name all the third party apps connected to your major SaaS platforms, like Salseforce, Microsoft 365, or Google Workspace? What about the data these apps can access? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk. With AppOmni, you get visibility to all third party apps and SaaS-to-SaaS connections — including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com today to request a free risk assessment.
Apple releases updates to address zero-day flaws
Flipper Zero banned by Amazon for being a ‘card skimming device’
China to probe Micron over cybersecurity, in chip war’s latest battle
And now a word from our sponsor, AppOmni
Can you name all the third party apps connected to your major SaaS platforms, like Salseforce, Microsoft 365, or Google Workspace? What about the data these apps can access? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk. With AppOmni, you get visibility to all third party apps and SaaS-to-SaaS connections — including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com today to request a free risk assessment.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, April 3-7, is hosted by Rich Stroffolino with our guest, Rich Gautier, former CISO, Department of Justice, Criminal Division
Was your address caught up in the Genesis Market? Check it here:
https://www.politie.nl/en/information/checkyourhack.html#check
Thanks to our show sponsor, Normalyze
Normalyze is a cloud data security platform that continuously discovers sensitive data and their access paths across your cloud environments. Normalyze provides the ability to analyze, prioritize and respond to data threats to prevent damaging data breaches. Their cloud-native platform manages data security posture and compliance by automatically tracking risks to sensitive data, visually showing teams who can access what, and quickly block unauthorized access or vulnerable points of attack. Discover, visualize, and secure your cloud data in minutes with Normalyze Freemium. Go to normalyze.ai.
All links and the video of this episode can be found on CISO Series.com
Criminal records office yanks web portal offline amid 'cyber security incident'
Samsung reportedly leaked its own secrets through ChatGPT
Money Message ransomware gang claims MSI breach, demands $4 million
Thanks to today's episode sponsor, Normalyze
Normalyze is a cloud data security platform that continuously discovers sensitive data and their access paths across your cloud environments. Normalyze provides the ability to analyze, prioritize and respond to data threats to prevent damaging data breaches.Their cloud-native platform manages data security posture and compliance by automatically tracking risks to sensitive data, visually showing teams who can access what, and quickly block unauthorized access or vulnerable points of attack.Discover, visualize, and secure your cloud data in minutes with Normalyze Freemium. Go to normalyze.ai.
For the stories behind the headlines, head to CISOseries.com.
Prominent Spanish hacker arrested
The UK’s Offensive Cyber Capabilities Principles
eFile site serving malware
Thanks to today's episode sponsor, Normalyze
Normalyze is a cloud data security platform that continuously discovers sensitive data and their access paths across your cloud environments. Normalyze provides the ability to analyze, prioritize and respond to data threats to prevent damaging data breaches.Their cloud-native platform manages data security posture and compliance by automatically tracking risks to sensitive data, visually showing teams who can access what, and quickly block unauthorized access or vulnerable points of attack.Discover, visualize, and secure your cloud data in minutes with Normalyze Freemium. Go to normalyze.ai.
Genesis Market platform seized by police
Rorschach is now the fastest ransomware encryptor
Tax return software caught serving up malware
Thanks to today's episode sponsor, Normalyze
Normalyze is a cloud data security platform that continuously discovers sensitive data and their access paths across your cloud environments. Normalyze provides the ability to analyze, prioritize and respond to data threats to prevent damaging data breaches.Their cloud-native platform manages data security posture and compliance by automatically tracking risks to sensitive data, visually showing teams who can access what, and quickly block unauthorized access or vulnerable points of attack.Discover, visualize, and secure your cloud data in minutes with Normalyze Freemium. Go to normalyze.ai.
For the stories behind the headlines, visit CISOseries.com.
TMX reveals customer data leak
The security costs of remote work
Western Digital confirms network breach
Thanks to today's episode sponsor, Normalyze
Normalyze is a cloud data security platform that continuously discovers sensitive data and their access paths across your cloud environments. Normalyze provides the ability to analyze, prioritize and respond to data threats to prevent damaging data breaches.Their cloud-native platform manages data security posture and compliance by automatically tracking risks to sensitive data, visually showing teams who can access what, and quickly block unauthorized access or vulnerable points of attack.Discover, visualize, and secure your cloud data in minutes with Normalyze Freemium. Go to normalyze.ai.
More evidence links 3CX supply-chain attack to North Korean hacking group
Hackers exploiting WordPress Elementor Pro Vulnerability, leaving millions of sites at risk
DISH slapped with multiple lawsuits after ransomware cyber attack
Thanks to today's episode sponsor, Normalyze
Normalyze is a cloud data security platform that continuously discovers sensitive data and their access paths across your cloud environments. Normalyze provides the ability to analyze, prioritize and respond to data threats to prevent damaging data breaches.Their cloud-native platform manages data security posture and compliance by automatically tracking risks to sensitive data, visually showing teams who can access what, and quickly block unauthorized access or vulnerable points of attack.Discover, visualize, and secure your cloud data in minutes with Normalyze Freemium. Go to normalyze.ai.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, March 27-31, is hosted by Rich Stroffolino with our guest, Brett Conlon, CISO, American Century Investments
Thanks to today’s episode sponsor, Trend Micro
Cybersecurity is not just about protection, it’s about foresight, agility, and resilience. Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks. Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind. Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.
All links and the video of this episode can be found on CISO Series.com
Supply-chain attack on business phone provider 3CX could impact thousands of companies
Vulkan files leak reveals Putin’s global and domestic cyberwarfare tactics
Bing search results hijacked via misconfigured Microsoft app
Thanks to today's episode sponsor, Trend Micro
Cybersecurity is not just about protection, it’s about foresight, agility, and resilience.
Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks.
Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind.
Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.
For the stories behind the headlines, head to CISOseries.com.
Flaw found in WiFi protocol
Environmental activists targeted by threat actors
Open letter calls for AI “pause”
Thanks to today's episode sponsor, Trend Micro
Cybersecurity is not just about protection, it’s about foresight, agility, and resilience.
Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks.
Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind.
Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.
Microsoft unveils OpenAI-based chat tools to combat cyberattacks
Google accused of willfully destroying evidence in antitrust battle
A million pen tests show companies' security postures are getting worse
Thanks to today's episode sponsor, Trend Micro
Cybersecurity is not just about protection, it’s about foresight, agility, and resilience.
Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks.
Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind.
Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.
For the stories behind the headlines, visit CISOseries.com.
Pinduoduo malware confirmed
Binance sued by CFTC
Twitter source code takedown
Thanks to today's episode sponsor, Trend Micro
Cybersecurity is not just about protection, it’s about foresight, agility, and resilience.
Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks.
Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind.
Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.
UK bans TikTok from government mobile phones
Microsoft pushes OOB security updates for Windows Snipping tool flaw
Vice Society claims attack on Puerto Rico Aqueduct and Sewer Authority
Thanks to today's episode sponsor, Trend Micro
Cybersecurity is not just about protection, it’s about foresight, agility, and resilience.
Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks.
Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind.
Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, March 20-24, is hosted by David Spark with our guest, Kurt Sauer, VP, Information security, Workday
Thanks to today’s episode sponsor, Conveyor
Does the thought of answering another security questionnaire make you want to beat the stuffing out of 32 pinatas? Then you might want to check out Conveyor: the end-to-end trust platform helping infosec teams reduce incoming questionnaires and fly through the ones they do have to complete. Give customers access to a self-serve trust portal to download docs and FAQs. For any remaining questionnaires that do come in, use our GPT-Questionnaire response tool or white-glove questionnaire completion service to knock them completely off your to-do list. Learn more at www.conveyor.com.
All links and the video of this episode can be found on CISO Series.com
Dole discloses data breach after February ransomware attack
New Android banking trojan targets financial apps
Pwn2Own Vancouver 2023 Day 1: Windows 11 and Tesla hacked
Thanks to this week's episode sponsor, Conveyor
Does the thought of answering another security questionnaire make you want to beat the stuffing out of 32 pinatas? Then you might want to check out Conveyor: the end-to-end trust platform helping infosec teams reduce incoming questionnaires and fly through the ones they do have to complete. Give customers access to a self-serve trust portal to download docs and FAQs. For any remaining questionnaires that do come in, use our GPT-Questionnaire response tool or white-glove questionnaire completion service to knock them completely off your to-do list. Learn more at www.conveyor.com.
For the stories behind the headlines, head to CISOseries.com.
Another image editor leaks data
More Clop victims come forward
Big tech lobbies to limit spying law
Thanks to this week's episode sponsor, Conveyor
Does the thought of answering another security questionnaire make you feel like clearing out the ice cream section at your local grocery store? Though we fully support the ice cream thing, you might want to check out Conveyor first: the end-to-end trust platform helping infosec teams reduce incoming questionnaires and fly through the ones they do have to complete. Give customers access to a self-serve trust portal to download security info and for any remaining questionnaires that do come in, use our GPT-Questionnaire response tool or white-glove questionnaire completion service to knock them completely off your to-do list. Learn more at www.conveyor.com.
BreachForums to shut down amidst law enforcement concerns
Hackers use zero-day to drain $1.6 million from Bitcoin ATMs
DC Health Link hacker motivated by Russian patriotism
Thanks to this week's episode sponsor, Conveyor
Does the mountain of security questionnaires in your inbox make you feel like a 2 dollar umbrella in a hurricane? Then you might want to check out Conveyor: the end-to-end trust platform helping infosec teams reduce incoming questionnaires and fly through the ones they do have to complete. Give customers access to a self-serve trust portal to download docs and FAQs. For any remaining questionnaires that do come in, use our GPT-Questionnaire response tool or white-glove questionnaire completion service to knock them completely off your to-do list. Learn more at www.conveyor.com.
For the stories behind the headlines, visit CISOseries.com.
China led zero-days in 2022
HinataBot focuses on DDoS attacks
Vulnerability lets you uncrop screenshots
Thanks to this week's episode sponsor, Conveyor
Does the thought of answering another security questionnaire make you want to beat the stuffing out of 32 pinatas? Then you might want to check out Conveyor: the end-to-end trust platform helping infosec teams reduce incoming questionnaires and fly through the ones they do have to complete. Give customers access to a self-serve trust portal to download docs and FAQs. For any remaining questionnaires that do come in, use our GPT-Questionnaire Eliminator response tool or white-glove questionnaire completion service to knock them completely off your to-do list. Learn more at www.conveyor.com.
NBA is warning fans of a data breach after a third-party newsletter service hack
Emotet malware now distributed in Microsoft OneNote files to evade defenses
Dutch shipping giant Royal Dirkzwager confirms Play ransomware attack
Thanks to this week's episode sponsor, Conveyor
Love security questionnaires? Then you’re going to hate Conveyor: the end-to-end trust platform built to eliminate questionnaires. Infosec teams have reduced questionnaires by 80% by giving their customers access to our self-serve trust portal to download docs and answers. For any remaining questionnaires that do come in, use our GPT-Questionnaire Eliminator response tool or white-glove questionnaire completion service to knock them off your to-do list. Use all 3 parts of the platform to solve the questionnaire problem or start with one. Learn more at www.conveyor.com.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, March 13-17, is hosted by Rich Stroffolino with our guest, JJ Agha, CISO, FanDuel
All links and the video of this episode can be found on CISO Series.com
US Government IIS server breached via Telerik software flaw
Critical Microsoft Outlook bug PoC shows how easy it is to exploit
LockBit threatens release of thousands of SpaceX blueprints
Brought to you by the CISO Series.
For the stories behind the headlines, head to CISOseries.com.
Two charged in DEA portal hack
Americans lose billions in scams
TikTok considering divestment
Brought to you by the CISO Series.
Microsoft warns of large-scale use of phishing kits to send millions of emails daily
Ransomware group claims hack of Amazon's Ring
CISA creates new ransomware vulnerability warning program
Brought to you by the CISO Series.
For the stories behind the headlines, head to CISOseries.com.
North Korea targets security researchers
UK launches National Protective Security Authority
Bank failures bleed into crypto
Brought to you by the CISO Series.
FBI and international authorities catch a NetWire RAT
CISA warns of actively exploited Plex bug after LastPass breach
Blackbaud to pay $3 million for misleading ransomware disclosure
For the stories behind the headlines, visit CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, March 6-10, is hosted by Rich Stroffolino with our guest, Nick Espinosa, Host, The Deep Dive Radio Show (Daily Podcast & Daily Videos)
Thanks to our show sponsor, Packetlabs
Trust the ethical hackers at Packetlabs for expert penetration testing services. Our certified professionals specialize in strengthening your security posture. Download our free Penetration Testing Buyers Guide at ciso.packetlabs.net and get the top 20 questions to ask third party vendors before hiring them. Let us guide you through the process and help you find the perfect match for your organization’s security needs.
All links and the video of this episode can be found on CISO Series.com
Biden’s budget seeks increase in cybersecurity spending
AT&T alerts 9 million customers of data breach after vendor hack
GitHub makes 2FA mandatory next week for active developers
Thanks to today's episode sponsor, Packetlabs
Trust the ethical hackers at Packetlabs for expert penetration testing services. Our certified professionals specialize in strengthening your security posture. Download our free Penetration Testing Buyers Guide at ciso.packetlabs.net and get the top 20 questions to ask third party vendors before hiring them. Let us guide you through the process and help you find the perfect match for your organization's security needs.
For the stories behind the headlines, head to CISOseries.com.
TSA issues cybersecurity regulations
Lazarus Group deploys zero-day
Ransomware gang uses video ransom note
Thanks to today's episode sponsor, Packetlabs
Reduce cyber insurance premiums and minimize risk. Learn how a thorough penetration test can benefit your business. Download our Penetration Testing Buyers Guide at ciso.packetlabs.ca. Packetlabs is an ethical hacking firm that will simulate real-world, covert attacks to get answers to your “what if” scenarios. Protect your business from cyber attacks and get the most out of your penetration testing investment with Packetlabs, your friendly neighborhood ethical hackers.
Bipartisan bill allows for US ban of TikTok
EU concerned with Twitter’s content moderation plans
Emotet malware returns after three-month hiatus
Thanks to today's episode sponsor, Packetlabs
Looking for the right cybersecurity service provider can be a daunting task. How do you know if they're trustworthy and reliable? Packetlabs has made it easier for you with our free Penetration Testing buyers guide. We've compiled a list of the top 20 questions you should ask potential providers to ensure you make an informed decision. Download the guide today at ciso.packetlabs.net.
For the stories behind the headlines, visit CISOseries.com.
Police disrupt DoppelPaymer
EPA releases cybersecurity notice for water systems
Cloud exploitation on the rise
Thanks to today's episode sponsor, Packetlabs
Struggling to justify cybersecurity investments to decision-makers? Meet ROSI, the superhero of cybersecurity investments! Calculate your Return On Security Investment to quantify the value of prevention and save money by avoiding cybersecurity breaches. ROSI builds synergies between your business, security, and finance teams, bringing everyone together. Download our free buyer's guide to learn the ROSI formula, how to reduce cyber insurance premiums, and what to look for in a provider. Visit ciso.packetlabs.net and unleash the power of ROSI in your c-suite discussions today!
U.S. Government warns of Royal ransomware attacks against critical infrastructure
Credential Stuffing attack on Chick-fil-A
Play Ransomware gang has begun to leak data stolen from City of Oakland
Thanks to today's episode sponsor, Packetlabs
Concerned about your organization's data security? Privacy breaches, ransomware attacks, insider threats, and intellectual property theft are on the rise. A one-size-fits-all vulnerability assessment scan no longer suffices. Get our Penetration Testing Buyer's guide to help plan, scope, and execute your projects. Discover valuable information on frameworks, standards, methodologies, cost factors, reporting options, and what to look for in a provider. Choose the right ethical hacking firm to uncover vulnerabilities in your IT and network systems. Download your free copy at ciso.packetlabs.net and take control of your cybersecurity today.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines - Week in Review, February 27-March 3, is hosted by Rich Stroffolino with our guest, Nick Vigier, CISO, Talend
Thanks to our show sponsor, Conveyor
Just because your security questionnaire is from the stone age, doesn’t mean you have to answer it with cave-era tools. At Conveyor, we implemented GPT-3 into our first-of-its-kind questionnaire eliminator so teams of all sizes can blast through questionnaires faster than you can say “prehistoric”. Go beyond re-writing mediocre matches, to getting your questionnaire auto-filled with the exact answers customers need. Join the top SaaS companies in the GPT-3 powered future by using Conveyor. Learn more at conveyor.com.
All links and the video of this episode can be found on CISO Series.com
White House gets tough with new National Cyber Strategy
CISA releases free ‘Decider’ tool to help with MITRE ATT&CK mapping
British retail chain WH Smith says data stolen in cyberattack
Thanks to this week's episode sponsor, Conveyor
Just because your security questionnaire is from the stone age, doesn’t mean you have to answer it with cave-era tools. At Conveyor, we implemented GPT-3 into our first-of-its-kind questionnaire eliminator so teams of all sizes can blast through questionnaires faster than you can say “prehistoric”. Go beyond re-writing mediocre matches, to getting your questionnaire auto-filled with the exact answers customers need. Join the top SaaS companies in the GPT-3 powered future by using Conveyor. Learn more at conveyor.com.
For the stories behind the headlines, head to CISOseries.com.
Russia bans foreign private messaging apps
GitHub expands secret scanning
Bootkit bypasses Secure Boot
Thanks to this week's episode sponsor, Conveyor
“I HATE security questionnaires with the fury of a thousand suns.” said one of our customers. Makes sense, since tools used to answer them haven’t changed in years. At Conveyor, we’re on a mission to get teams out of the questionnaire stone age by implementing GPT-3 into our first-of-its-kind questionnaire eliminator. Go beyond re-writing mediocre matches, to getting your questionnaire auto-filled with the exact answers customers need. Join the top SaaS companies in the GPT-3 powered future by using Conveyor. Learn more at conveyor.com.
US Marshals hit by ransomware
DISH outages caused by confirmed ransomware attack
Some more bad news for LastPass
Thanks to this week's episode sponsor, Conveyor
AI can now literally answer any question on the internet in seconds, yet infosec teams are still in a living nightmare manually filling out security questionnaires with existing tools. Get out of the questionnaire stone age with Conveyor’s new questionnaire eliminator tool powered by GPT-3. It provides perfectly crafted answers to questionnaires all within minutes and review now takes seconds. Join the top SaaS companies in the GPT-3 powered future by using Conveyor. Learn more at conveyor.com.
For the stories behind the headlines, visit CISOseries.com.
CISA says to stop passing the security buck
The cyber security fallout of Russia’s war in Ukraine
Canada bans TikTok on government devices
Thanks to this week's episode sponsor, Conveyor
Just because your security questionnaire is from the stone age, doesn’t mean you have to answer it with cave-era tools. At Conveyor, we implemented GPT-3 into our first-of-its-kind questionnaire eliminator so teams of all sizes can blast through questionnaires faster than you can say “prehistoric”. Go beyond re-writing mediocre matches, to getting your questionnaire auto-filled with the exact answers customers need. Join the top SaaS companies in the GPT-3 powered future by using Conveyor. Learn more at conveyor.com.
News Corp reveals that attackers remained on its network for two years
TELUS investigating leak of stolen source code, employee data
Dish Network goes offline after likely cyberattack, employees cut off
Thanks to this week's episode sponsor, Conveyor
AI can now literally answer any question on the internet in seconds, yet infosec teams are still living a nightmare manually filling out security questionnaires with existing tools. Get out of the questionnaire stone age with Conveyor’s new questionnaire eliminator tool powered by GPT-3. Go beyond re-writing mediocre matches, to getting your questionnaire auto-filled with the exact answers customers need in minutes. Join the top SaaS companies in the GPT-3 powered future by using Conveyor. Learn more at conveyor.com.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, February 20-24, is hosted by Rich Stroffolino with our guest, Jared Mendenhall, Head of Information Security, Impossible Foods
Thanks to our show sponsor, Barricade Cyber
Have you fallen victim to a ransomware attack? Don’t worry! Barricade Cyber Solutions has helped thousands of customers in situations just like yours. Our proprietary ransomware recovery services are designed to quickly get your business back on track. Our team of experts will identify the source of the attack and provide a comprehensive solution to prevent it from happening again. You can count on us for the security of your data and systems. Visit barricadecyber.com
All links and the video of this episode can be found on CISO Series.com
Fruit giant Dole suffers ransomware attack impacting operations
Stress pushing CISOs out the door
Lazarus group likely using new backdoor to exfiltrate sensitive data
Thanks to this week's episode sponsor, Barricade Cyber Solutions
Have you fallen victim to a ransomware attack? Don't worry! Barricade Cyber Solutions has helped thousands of customers in situations just like yours. Our proprietary ransomware recovery services are designed to quickly get your business back on track. Our team of experts will identify the source of the attack and provide a comprehensive solution to prevent it from happening again. You can count on us to the security of your data and systems. Visit barricadecyber.com
For the stories behind the headlines, head to CISOseries.com.
Threat actors cry Havoc, let slip a new post-exploitation framework
VMware warns of critical Carbon Black flaw
Ransomware attack time shrinking rapidly
Thanks to this week's episode sponsor, Barricade Cyber Solutions
Have you fallen victim to a ransomware attack? Don't worry! Barricade Cyber Solutions has helped thousands of customers in situations just like yours. Our proprietary ransomware recovery services are designed to quickly get your business back on track. Our team of experts will identify the source of the attack and provide a comprehensive solution to prevent it from happening again. You can count on us to the security of your data and systems. Visit barricadecyber.com
Apple updates advisories as security firm discloses new class of vulnerabilities
Sensitive US military emails spill online
Russian state TV website goes down during Putin speech
Thanks to this week's episode sponsor, Barricade Cyber Solutions
Have you fallen victim to a ransomware attack? Don't worry! Barricade Cyber Solutions has helped thousands of customers in situations just like yours. Our proprietary ransomware recovery services are designed to quickly get your business back on track. Our team of experts will identify the source of the attack and provide a comprehensive solution to prevent it from happening again. You can count on us to the security of your data and systems. Visit barricadecyber.com
For the stories behind the headlines, head to CISOseries.com.
Samsung guards against zero-click attacks
Rethinking ransomware cat and mouse
Norway seizes Lazarus Group crypto
Thanks to this week's episode sponsor, Barricade Cyber Solutions
Have you fallen victim to a ransomware attack? Don't worry! Barricade Cyber Solutions has helped thousands of customers in situations just like yours. Our proprietary ransomware recovery services are designed to quickly get your business back on track. Our team of experts will identify the source of the attack and provide a comprehensive solution to prevent it from happening again. You can count on us to the security of your data and systems. Visit barricadecyber.com
Hackers backdoor Microsoft IIS servers with new Frebniis malware
Twitter limits SMS-based 2-factor authentication to Blue subscribers only
Fortinet issues patches for 40 flaws
Thanks to this week's episode sponsor, Barricade Cyber Solutions
Have you fallen victim to a ransomware attack? Don't worry! Barricade Cyber Solutions has helped thousands of customers in situations just like yours. Our proprietary ransomware recovery services are designed to quickly get your business back on track. Our team of experts will identify the source of the attack and provide a comprehensive solution to prevent it from happening again. You can count on us to the security of your data and systems. Visit barricadecyber.com
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, February 13-17, is hosted by Sean Kelly with our guest, George Al-Koura, CISO, Ruby
Thanks to our show sponsor, CISO Series
“If it is important it will likely be in the Cyber Security Headlines update in the morning… And it allows me and my team to dig in a little more on aspects that might affect our technology stack,” said Shawn Bowen, CISO for World Fuel Services. Security leaders listen and make decisions based on what they hear on this very show. Do you have a solution that just needs to find the attention of the right audience of cyber professionals? To learn more about pricing and audience, email us at info@cisoseries.com.
All links and the video of this episode can be found on CISO Series.com
February updates break some Windows Server 2022 VMs
BEC groups use Google Translate to target high value victims
Evolving cyberattacks and alert fatigue creating DFIR burnout
Thanks to today's episode sponsor, US, yes, CISO Series
“If it is important it will likely be in the Cyber Security Headlines update in the morning… And it allows me and my team to dig in a little more on aspects that might affect our technology stack,” said Shawn Bowen, CISO for World Fuel Services. Security leaders listen and make decisions based on what they hear on this very show. Do you have a solution that just needs to find the attention of the right audience of cyber professionals? To learn more about pricing and audience, email us at info@cisoseries.com.
For the stories behind the headlines, head to CISOseries.com.
Israeli influence group exposed
Another day, another record DDoS
Cut cables lead to Lufthansa outage
Thanks to today's episode sponsor, US, yes, CISO Series
“Every week, one of the stories from Cyber Security Headlines comes up in our team meetings,” said Brett Conlon, CISO for American Century Investments who admits he starts his day with this very show. And did you know that Cyber Security Headlines has longevity? It’s a daily news show but we see significant downloads for four months after episodes air. That means your ad campaign will continue to live long after the premier airing. To learn more about pricing and audience, email us at info@cisoseries.com.
Hackers breached Pepsi Bottling network
AI has successfully piloted an F-16 fighter jet
Hyundai and Kia to update anti-theft software on millions of vehicles
Thanks to today's episode sponsor, US, yes, CISO Series
"I value Cyber Security Headlines early every morning as it provides me advance notice of what I might need to explore first thing at the start of the day." That’s active listener David Cross, SVP, CISO of Oracle SaaS Cloud. And for sponsors of Cyber Security Headlines what you get are the ears and eyes of avid security leaders. Sponsorship includes the podcast, our blog, and our daily newsletter. In whatever format our listeners want, Cyber Security Headlines reaches cyber leaders who want to quickly consume daily cyber news. To learn more about pricing and audience, email us at info@cisoseries.com.
For the stories behind the headlines, visit CISOseries.com
Namecheap sent phishing emails to customers
New Bing search hit with injection attack
Regulators stop minting of BUSD stablecoin
Thanks to today's episode sponsor, US, yes, CISO Series
“Those cyber security headlines are fantastic. It’s the first thing I look at in the am.” That’s a quote from active listener Jared Mendenhall, head of information security at Impossible Foods. Cyber Security Headlines is our fastest growing show on the CISO Series network. It’s grown 20-fold since we launched. And it did so during the pandemic while other shows started to slide. That’s because at only 6-7 minutes every day, Cyber Security Headlines does not need a commute to consume. Listen before you start your day. To learn more about pricing and audience, email us at info@cisoseries.com.
Reddit admits it was hacked and data stolen, says “don’t panic”
Clop ransomware claims it breached 130 orgs using GoAnywhere zero-day
CISA has a possibly-maybe fix for VMware ESXi ransomware campaign
Thanks to today's episode sponsor, US, yes, CISO Series
If you’re looking to reach a committed audience of cybersecurity professionals every day, then consider advertising right here on Cyber Security Headlines, a show that consistently ranks in the top ten for tech news on Apple Podcasts in the U.S. That’s pretty impressive for a show that’s a niche within a niche. Cyber Security Headlines sponsorship includes continuous week-long brand awareness in newsletters, blog posts, and this very podcast. To learn more about pricing and audience, email us at info@cisoseries.com.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, February 6-10, is hosted by Rich Stroffolino with our guest, Ed Covert, head of Cyber Risk Engineering, Bowhead Specialty
Thanks to our show sponsor, us! CISO Series!
“If it is important it will likely be in the Cyber Security Headlines update in the morning… And it allows me and my team to dig in a little more on aspects that might affect our technology stack,” said Shawn Bowen, CISO for World Fuel Services. Security leaders listen and make decisions based on what they hear on this very show. Do you have a solution that just needs to find the attention of the right audience of cyber professionals? If you’re interested in sponsorship, email us at info@cisoseries.com.
All links and the video of this episode can be found on CISO Series.com
Microsoft Outlook outage prevents users from sending, receiving emails
Britain and US make major move against ransomware gangs by sanctioning seven individuals
Experts publish a list of proxy IPs used by the pro-Russia group Killnet
Thanks to today's episode sponsor, us, yes, CISO Series
“If it is important it will likely be in the Cyber Security Headlines update in the morning… And it allows me and my team to dig in a little more on aspects that might affect our technology stack,” said Shawn Bowen, CISO for World Fuel Services. Security leaders listen and make decisions based on what they hear on this very show. Do you have a solution that just needs to find the attention of the right audience of cyber professionals? To learn more about pricing and audience, email us at info@cisoseries.com.
For the stories behind the headlines, head to CISOseries.com.
NIST standardizes crypto for IoT
Chinese phones collect PII
Chinese firms also working on AI chatbots
Thanks to today's episode sponsor, US, yes, CISO Series
“Every week, one of the stories from Cyber Security Headlines comes up in our team meetings,” said Brett Conlon, CISO for American Century Investments who admits he starts his day with this very show. And did you know that Cyber Security Headlines has longevity? It’s a daily news show but we see significant downloads for four months after episodes air. That means your ad campaign will continue to live long after the premier airing. To learn more about pricing and audience, email us at info@cisoseries.com.
ARMO, Microsoft, Google race to integrate AI into their products
FAA needs until 2030 to fix its safety system
Biden’s State of the Union addresses children’s online safety and privacy… again
Thanks to today's episode sponsor, US, yes, CISO Series
"I value Cyber Security Headlines early every morning as it provides me advance notice of what I might need to explore first thing at the start of the day." That’s active listener David Cross, SVP, CISO of Oracle SaaS Cloud. And for sponsors of Cyber Security Headlines what you get are the ears and eyes of avid security leaders. Sponsorship includes the podcast, our blog, and our daily newsletter. In whatever format our listeners want, Cyber Security Headlines reaches cyber leaders who want to quickly consume daily cyber news. To learn more about pricing and audience, email us at info@cisoseries.com.
For the stories behind the headlines, visit CISOseries.com.
Cyber insurer predicts a rise in critical CVEs
British steel supplier hit by “cyber incident”
Microsoft pins recent attack on Charlie Hebdo
Thanks to today's episode sponsor, US, yes, CISO Series
“Those cyber security headlines are fantastic. It’s the first thing I look at in the am.” That’s a quote from active listener Jared Mendenhall, head of information security at Impossible Foods. Cyber Security Headlines is our fastest growing show on the CISO Series network. It’s grown 20-fold since we launched. And it did so during the pandemic while other shows started to slide. That’s because at only 6-7 minutes every day, Cyber Security Headlines does not need a commute to consume. Listen before you start your day. To learn more about pricing and audience, email us at info@cisoseries.com.
Hackers actively exploiting zero-day in Fortra's GoAnywhere MFT
Tallahassee hospital diverting patients, canceling non-emergency surgeries after cyberattack
Fraudulent “CryptoRom” apps slip through Apple and Google App Store review process
Thanks to today's episode sponsor, US, yes, CISO Series
If you’re looking to reach a committed audience of cybersecurity professionals every day, then consider advertising right here on Cyber Security Headlines, a show that consistently ranks in the top ten for tech news on Apple Podcasts in the U.S. That’s pretty impressive for a show that’s a niche within a niche. Cyber Security Headlines sponsorship includes continuous week-long brand awareness in newsletters, blog posts, and this very podcast. To learn more about pricing and audience, email us at info@cisoseries.com.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines - Week in Review, January 30-February 3, is hosted by Rich Stroffolino with our guest, David Nolan, VP, Enterprise Risk & Chief Information Security Officer – Aaron’s
Thanks to our show sponsor, Hunters
Hunters is a complete SOC platform, purpose built for your Security Operations team. Hunters’ brand new IOC Search is a game-changing search tool that determines if a known ‘Indicator of Compromise’ has been in your organization’s environment - without needing to write a single line of code. Type an IOC into the search bar, hit ‘enter’ and get results within seconds. Visit hunters.ai to learn more.
All links and the video of this episode can be found on CISO Series.com
City of London on high alert after ransomware attack
Watchdog warns FDIC fails to test banks’ cyberdefenses effectively
Foreign states already using ChatGPT maliciously, UK IT leaders believe
Thanks to this week's episode sponsor, Hunters
Hunters is a complete SOC platform, purpose built for your Security Operations team. Hunters’ brand new IOC Search is a game-changing search tool that determines if a known ‘Indicator of Compromise’ has been in your organization’s environment - without needing to write a single line of code. Type an IOC into the search bar, hit ‘enter’ and get results within seconds. Visit hunters.ai to learn more.
For the stories behind the headlines, head to CISOseries.com.
Watchdog calls for improved bank cyber testing
Containers hold high-risk vulnerabilities
2022 set a record for crypto hacks
Thanks to this week's episode sponsor, Hunters
Hunters is a complete SOC platform, purpose built for your Security Operations team. Hunters’ brand new IOC Search is a game-changing search tool that determines if a known ‘Indicator of Compromise’ has been in your organization’s environment - without needing to write a single line of code. Type an IOC into the search bar, hit ‘enter’ and get results within seconds. Visit hunters.ai to learn more.
Microsoft grants phishers 'Verified' Cloud Partner status
DocuSign brand impersonation attack targets thousands of users
Google Fi says hackers accessed customer information
Thanks to this week's episode sponsor, Hunters
Hunters is a SaaS platform, purpose built for your Security Operations team. Solaris Group, a leading German FinTech, implemented Hunters SOC Platform to eliminate the burden of threat detection and correlation – allowing SOC analysts to focus on higher-value tasks. It's time to move beyond SIEM. Visit hunters.ai to learn more.
For the stories behind the headlines, visit CISOseries.com
Criminal crypto goes through 5 exchanges
TikTok CEO heads to the House
KillNet launches German DDoS
Thanks to this week's episode sponsor, Hunters
The Hunters SOC Platform helps your security team identify, understand, triage, and respond to incidents at a much faster pace. ChargePoint, the world's largest network of electric vehicle charging stations, uses Hunters SOC Platform to leverage its out-of-the-box detection content to more efficiently respond to new threats and vulnerabilities. Visit Hunters.ai to learn more.
Charter Communications says vendor breach exposed some customer data
Russia’s Sandworm hackers blamed in fresh Ukraine malware attack
Experts plans to release VMware vRealize log RCE exploit this week
Thanks to this week's episode sponsor, Hunters
Hunters is a complete SOC platform, built for your security team. By providing unlimited ingestion and normalization of security data without ruining your bottom line, a CISO at a leading online retailer was able to “triple her data ingestion while cutting costs from her SIEM provider by 75%.” It's time to move beyond SIEM, with Hunters. Visit hunters.ai to learn more.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, January 23-27, is hosted by David Spark with our guest, Kathleen Mullin, CISO, Cancer Treatment Centers of America
Thanks to our show sponsor, SafeBase
If a prospective customer asked about your trust program or security policies, where would you send them? Chances are, you’d need to send an NDA, hunt down documentation, go back and forth via email, and answer a litany of questions. SafeBase is the better way. SafeBase’s Smart Trust Center allows you to send one link to customers or buyers, so they can easily access the security and compliance information they need. Meanwhile, you get more control over who has access to your documents, and for how long. Build customer trust the smart way with SafeBase – learn more at safebase.com
All links and the video of this episode can be found on CISO Series.com
FBI seizes Hive ransomware group infrastructure after lurking in servers for months
Layoffs come to IBM - Kyndryl, Watson and Russia to blame
Microsoft says services have recovered after widespread outage
Thanks to this week's episode sponsor, SafeBase
If a prospective customer asked about your trust program or security policies, where would you send them? Chances are, you’d need to send an NDA, hunt down documentation, go back and forth via email, and answer a litany of questions. SafeBase is the better way. SafeBase’s Smart Trust Center allows you to send one link to customers or buyers, so they can easily access the security and compliance information they need. Meanwhile, you get more control over who has access to your documents, and for how long. Build customer trust the smart way with SafeBase - learn more at safebase.com
For the stories behind the headlines, head to CISOseries.com.
A look at North Korean crypto stealing tactics
Russia saw record DDoS attacks
China leads in facial recognition tech exports
Thanks to this week's episode sponsor, SafeBase
These days, customer trust can be an organization’s strongest competitive advantage. But how can you develop and maintain customer trust over the long term? The answer is SafeBase. After implementing SafeBase’s Smart Trust Center, many companies see shorter deal cycles, higher-value contracts, and stronger long-term customer relationships. Some even achieve a 90% reduction in security questionnaires. Learn more at safebase.com
Pakistani authorities investigating whether cyberattack caused nationwide blackout
FBI identifies hackers behind Horizon Bridge crypto theft
GoTo says hackers stole encrypted backups and MFA settings
Thanks to this week's episode sponsor, SafeBase
Jump start your journey to long-lasting customer trust with SafeBase. Our Smart Trust Center helps your organization build customer trust through improved transparency, secure document sharing, process control and insights, and proactive communication. Security and GRC leaders at companies like Jamf, Instacart, and Snyk all rely on SafeBase as a central enabler of their trust program. Learn more and check out the case studies at SafeBase.com
For the stories behind the headlines, visit CISOseries.com
LA School attack exposed Social Security numbers
Government Accountability Office names and shames
PLAY ransomware hits UK car dealerships
Thanks to this week's episode sponsor, SafeBase
If a prospective customer asked about your trust program or security policies, where would you send them? Chances are, you’d need to send an NDA, hunt down documentation, go back and forth via email, and answer a litany of questions. SafeBase is the better way. SafeBase’s Smart Trust Center allows you to send one link to customers or buyers, so they can easily access the security and compliance information they need. Meanwhile, you get more control over who has access to your documents, and for how long. Build customer trust the smart way with SafeBase - learn more at safebase.com
PayPal accounts breached in large-scale credential stuffing attack
Ransomware gang steals data from KFC, Taco Bell, and Pizza Hut brand owner
ODIN Intelligence hack exposes a huge trove of police raid files
Thanks to this week's episode sponsor, SafeBase
These days, customer trust can be an organization’s strongest competitive advantage. But how can you develop and maintain customer trust over the long term? The answer is SafeBase. After implementing SafeBase’s Smart Trust Center, many companies see shorter deal cycles, higher-value contracts, and stronger long-term customer relationships. Some even achieve a 90% reduction in security questionnaires. Learn more at safebase.com
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines - Week in Review, January 16-20, is hosted by Rich Stroffolino with our guest, George Finney, CISO, Southern Methodist University
Thanks to our show sponsor, Cerby
Did you know that over 60% of the cloud applications used by your company don’t support identity standards like single sign-on? And that these applications are the leading cause of breaches? Cerby can help.
Cerby discovers new applications, eliminates manual security tasks like offboarding, and addresses misconfigurations like disabled 2FA while increasing employee productivity. Wait. A security tool that increases productivity? Yup. Learn more at cerby.com.
All links and the video of this episode can be found on CISO Series.com
Ransomware revenue falls by $300 million in 2022 as more victims refuse to pay
Vice Society claims ransomware attack against University of Duisburg-Essen
Android users beware of new Hook malware with RAT capabilities
Thanks to today's episode sponsor, Cerby
Did you know that over 60% of the cloud applications used by your company don’t support identity standards like single sign-on? And that these applications are the leading cause of breaches? Cerby can help. Cerby discovers new applications, eliminates manual security tasks like offboarding, and addresses misconfigurations like disabled 2FA while increasing employee productivity. Wait. A security tool that increases productivity? Yup. Learn more at cerby.com.
For the stories behind the headlines, head to CISOseries.com.
Vendors bypassing security patches
ChatGPT creates polymorphic malware
Bitwarden acquires Passwordless.dev
Thanks to today's episode sponsor, Cerby
Did you know that over 60% of the cloud applications used by your company don’t support identity standards like single sign-on? And that these applications are the leading cause of breaches? Cerby can help. Cerby discovers new applications, eliminates manual security tasks like offboarding, and addresses misconfigurations like disabled 2FA while increasing employee productivity. Wait. A security tool that increases productivity? Yup. Learn more at cerby.com.
Ransomware attack impacts 1,000 ships
Crypto influencer victimized by malware pushed by ads on Google
Microsoft patches flaws in Azure cloud services
Thanks to today's episode sponsor, Cerby
Did you know that over 60% of the cloud applications used by your company don’t support identity standards like single sign-on? And that these applications are the leading cause of breaches? Cerby can help. Cerby discovers new applications, eliminates manual security tasks like offboarding, and addresses misconfigurations like disabled 2FA while increasing employee productivity. Wait. A security tool that increases productivity? Yup. Learn more at cerby.com.
For the stories behind the headlines, visit CISOseries.com
Cyber attack disrupts esport event
Qbot overtakes Emotet
CircleCI breach caused by infostealer
Thanks to today's episode sponsor, Cerby
Did you know that over 60% of the cloud applications used by your company don’t support identity standards like single sign-on? And that these applications are the leading cause of breaches? Cerby can help. Cerby discovers new applications, eliminates manual security tasks like offboarding, and addresses misconfigurations like disabled 2FA while increasing employee productivity. Wait. A security tool that increases productivity? Yup. Learn more at cerby.com.
NortonLifeLock warns that hackers breached Password Manager accounts
Hacker steals credit card info from Canada’s largest alcohol retailer
Severe security flaw found in "jsonwebtoken" library
Thanks to today's episode sponsor, Cerby
Did you know that over 60% of the cloud applications used by your company don’t support identity standards like single sign-on? And that these applications are the leading cause of breaches? Cerby can help. Cerby discovers new applications, eliminates manual security tasks like offboarding, and addresses misconfigurations like disabled 2FA while increasing employee productivity. Wait. A security tool that increases productivity? Yup. Learn more at cerby.com.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, January 9-13, is hosted by Rich Stroffolino with our guest, Shaun Marion, CISO, McDonald’s
Thanks to our show sponsor, AppOmni
Can you name all the third party apps connected to your major SaaS platforms like Salesforce and Microsoft? What about the data these apps can access? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk. With AppOmni, you get visibility to all third party apps and SaaS-to-SaaS connections — including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com to request a free risk assessment.
All links and the video of this episode can be found on CISO Series.com
Experts detail Chromium browser security flaw putting confidential data at risk
Twitter says 200 million-user leak not obtained from its systems, others disagree
IcedID malware strikes again: Active Directory domain compromised in under 24 hours
Thanks to today's episode sponsor, AppOmni
Can you name all the third party apps connected to your major SaaS platforms like Salseforce and Microsoft? What about the data these apps can access? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk.
With AppOmni, you get visibility to all third party apps and SaaS-to-SaaS connections — including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com to request a free risk assessment.
For the stories behind the headlines, head to CISOseries.com.
FAA system failure delays flights
Royal Mail hit by “cyber incident”
Police app leaked operations data
Thanks to today's episode sponsor, AppOmni
Can you name all the third party apps connected to your major SaaS platforms like Salseforce and Microsoft? What about the data these apps can access? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk.
With AppOmni, you get visibility to all third party apps and SaaS-to-SaaS connections — including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com to request a free risk assessment.
Iowa school district cancels classes due to cyberattack
TikTok CEO questioned by EU about its data practices
Government watchdog cracks federal agency’s passwords
Thanks to today's episode sponsor, AppOmni
Can you name all the third party apps connected to your major SaaS platforms like Salseforce and Microsoft? What about the data these apps can access? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk.
With AppOmni, you get visibility to all third party apps and SaaS-to-SaaS connections — including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com to request a free risk assessment.
For the stories behind the headlines, visit CISOseries.com
API vulnerabilities found across car brands
Bypassing Experian Security
Trying to write malware with ChatGPT
Thanks to today's episode sponsor, AppOmni
Can you name all the third party apps connected to your major SaaS platforms like Salseforce and Microsoft? What about the data these apps can access? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk.
With AppOmni, you get visibility to all third party apps and SaaS-to-SaaS connections — including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com to request a free risk assessment.
Russian Turla hackers hijack decade-old malware infrastructure to deploy new backdoors
LastPass hit with lawsuit over August breach
Hackers abuse Windows error reporting tool to deploy malware
Thanks to today's episode sponsor, AppOmni
Can you name all the third party apps connected to your major SaaS platforms like Salseforce and Microsoft? What about the data these apps can access? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk.
With AppOmni, you get visibility to all third party apps and SaaS-to-SaaS connections — including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com to request a free risk assessment.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, January 2-6, is hosted by Sean Kelly with our guest, Bryan Willett, CISO, Lexmark
Thanks to our show sponsor, AppOmni
Did you know that over half of companies have sensitive SaaS data exposed on the public internet? And many breaches making headlines now involve SaaS apps? AppOmni can help. AppOmni identifies misconfigurations and guides remediation to keep your SaaS data secure. We help Security teams make sense of data access permissions, third party app visibility, and threat detection across their entire SaaS ecosystem. Get started at AppOmni.com.
All links and the video of this episode can be found on CISO Series.com
Slack's private GitHub code repositories stolen over holidays
CircleCI warns of security breach — rotate your secrets!
NATO tests AI’s ability to protect critical infrastructure against cyberattacks
Thanks to today's episode sponsor, AppOmni
Did you know that over half of companies have sensitive SaaS data exposed on the public internet? And many breaches making headlines now involve SaaS apps? AppOmni can help. AppOmni identifies misconfigurations and guides remediation to keep your SaaS data secure. We help Security teams make sense of data access permissions, third party app visibility, and threat detection across their entire SaaS ecosystem. Get started at AppOmni.com.
For the stories behind the headlines, head to CISOseries.com.
‘Mudge’ joins cybersecurity firm Rapid7
Meta fined $400 million by European regulator
Coinbase strikes a $100 million deal with regulators
Thanks to today's episode sponsor, AppOmni
Did you know that over half of companies have sensitive SaaS data exposed on the public internet? And many breaches making headlines now involve SaaS apps? AppOmni can help. AppOmni identifies misconfigurations and guides remediation to keep your SaaS data secure. We help Security teams make sense of data access permissions, third party app visibility, and threat detection across their entire SaaS ecosystem. Get started at AppOmni.com.
For the stories behind the headlines, visit CISOseries.com
FTX founder has pleaded not guilty to fraud charges
LA housing authority operations disrupted by cyberattack
Ukrainian authorities bust major vishing call center
Thanks to today's episode sponsor, AppOmni
Did you know that over half of companies have sensitive SaaS data exposed on the public internet? And many breaches making headlines now involve SaaS apps? AppOmni can help. AppOmni identifies misconfigurations and guides remediation to keep your SaaS data secure. We help Security teams make sense of data access permissions, third party app visibility, and threat detection across their entire SaaS ecosystem. Get started at AppOmni.com.
For the stories behind the headlines, visit CISOseries.com
Google to pay $29.5 million to settle lawsuits over user location tracking
Ransomware gang cloned victim’s website to leak stolen data
LockBit gang apologizes, gives SickKids Hospital free decryptor
Thanks to today's episode sponsor, AppOmni
Did you know that over half of companies have sensitive SaaS data exposed on the public internet? And many breaches making headlines now involve SaaS apps? AppOmni can help. AppOmni identifies misconfigurations and guides remediation to keep your SaaS data secure. We help Security teams make sense of data access permissions, third party app visibility, and threat detection across their entire SaaS ecosystem. Get started at AppOmni.com.
For the stories behind the headlines, head to CISOseries.com.
NETGEAR fixes a severe bug in its routers. Patch it ASAP!
PyTorch discloses malicious dependency chain compromise over holidays
LockBit ransomware claims attack on Port of Lisbon in Portugal
Thanks to today's episode sponsor, AppOmni
Did you know that over half of companies have sensitive SaaS data exposed on the public internet? And many breaches making headlines now involve SaaS apps? AppOmni can help. AppOmni identifies misconfigurations and guides remediation to keep your SaaS data secure. We help Security teams make sense of data access permissions, third party app visibility, and threat detection across their entire SaaS ecosystem. Get started at AppOmni.com.
For the stories behind the headlines, head to CISOseries.com.
Snooping bug found on Google Home speakers
3Commas API database leaked
Ireland investigating Twitter users data for sale
Thanks to this week's episode sponsor, Tines
Tines is the solution for security teams struggling with too much work, a talent shortage, and inevitable security incidents. Tines breaks the silos that exist between technologies and teams, so employees can focus on meaningful, not menial, tasks. Fewer manual errors and faster response times. Visit Tines.com to learn more.
Ransomware continues to hammer hospitals
Citrix servers found vulnerable despite patches
Log4Shell celebrates an anniversary
Thanks to this week's episode sponsor, Tines
If you're overwhelmed by your workload, Tines is the solution you've been looking for. Tines no-code automation checks boxes legacy SOAR tools can only dream of. Break the silos between tools and teams, focus on meaningful work, and eliminate manual errors while improving your response times. Visit Tines.com to stay ahead of the curve without breaking a sweat!
Facebook reaches settlement related to Cambridge Analytica scandal
BTC.com lost $3 million in cyberattack
Hackers use trojan to steal $8 million from BitKeep users
Thanks to this week's episode sponsor, Tines
Ever feel like you're stuck in a never-ending cycle of alerts? It's exhausting and frustrating. But here's the good news: Tines! Tines helps you focus on meaningful, not menial, tasks. Fewer mistakes, faster response times. And best of all, Tines’ no-code automation platform can handle massive complexity and easily connect to your unique tech stack. Visit Tines.com now!
For the stories behind the headlines, visit CISOseries.com
LastPass admits to severe data breach, encrypted password vaults stolen
Chris Inglis to resign as national cyber director
Comcast Xfinity accounts hacked in widespread 2FA bypass attacks
Thanks to our episode sponsor, Tines
Wondering how the world’s leading security teams are figuring out how to do more with less? The answer is Tines! Tines is a hyper-flexible automation platform loved by customers like Okta, Canva, Kayak, and Coinbase. Tines enables security teams to focus on what matters most by taking care of the grunt work! Learn more at Tines.com.
For the stories behind the headlines, head to CISOseries.com.
FBI warns of malware in search ads
Guardian hit with suspected ransomware
Attackers grab Okta source code
Thanks to this week's episode sponsor, Tines
Tis the season for more alerts and fewer resources available to manage them. But you can still be jolly--with Tines! Tines eliminates the need for security teams to waste time on repetitive, manual tasks. Powered by a no-code approach, security teams create—and maintain—powerful automations that deliver immediate results. Visit Tines.com to learn more!
McGraw Hill exposed student grades and personal info
UK privacy regulator names and shames breached firms
Twitter aided the Pentagon in covert online propaganda campaign
Thanks to this week's episode sponsor, Tines
If you're like most security teams, you currently face more phishing attacks and alert fatigue. The holiday season is the most wonderful time of the year for shoppers... but it's also a busy time for cybercriminals. Tines’ no-code automation platform can help you transform your SecOps and stay one step ahead. Visit Tines.com to sign up for free today!
For the stories behind the headlines, visit CISOseries.com
Botnet shrugs off Google
The future of ransomware
Epic Games receives record privacy fines
Thanks to this week's episode sponsor, Tines
If you’re like most security teams, you’re juggling multiple mission-critical priorities. But what if there was a way to break the silos in your environment? A way to focus on meaningful tasks? A way to reduce errors and achieve faster response times? Check out Tines.com to start experiencing the true benefits of proactive security operations powered by no-code automation.
CISA says Russia's Fancy Bear infiltrated US satellite network
Google introduces end-to-end encryption for Gmail on the web
NSA cyber director warns of Russian digital assaults on global energy sector
Thanks to this week's episode sponsor, Tines
Before Tines, co-founders Eoin and Thomas spent 15 years as senior security operators. Frustrated by the inability to solve for the challenges their teams were facing, they built their own solution. Tines allows security teams to robustly automate mundane, repetitive tasks – without code – so they can focus on their most important work. Visit Tines.com to learn more!
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, December 12-16, is hosted by Rich Stroffolino with our guest, Jeremy Embalabala, CISO, HUB International
Thanks to our show sponsor, Fortra
The cybersecurity landscape is full of single-solution providers, making it easy for unexpected cyberthreats to sneak through the cracks. That’s why Fortra is creating a stronger, simpler strategy for protection. One that increases your security maturity while decreasing the operational burden that comes with it. Fortra’s integrated, scalable solutions help customers face their toughest challenges with confidence. Learn more at Fortra.com
All links and the video of this episode can be found on CISO Series.com
Hackers target Japanese politicians with new MirrorStealer malware
Crooks use HTML smuggling to spread QBot malware via SVG files
FBI charges 6, seizes domains linked to DDoS-for-hire service platforms
Thanks to this week's episode sponsor, Fortra
The cybersecurity landscape is full of single-solution providers, making it easy for unexpected cyberthreats to sneak through the cracks. That's why Fortra is creating a stronger, simpler strategy for protection. One that increases your security maturity while decreasing the operational burden that comes with it. Fortra's integrated, scalable solutions help customers face their toughest challenges with confidence. Learn more at Fortra.com.
For the stories behind the headlines, head to CISOseries.com.
EU gets closer to US-data sharing agreement
Microsoft signed malicious drivers
InfraGard data for sale on dark web
Thanks to this week's episode sponsor, Fortra
The cybersecurity landscape is full of single-solution providers, making it easy for unexpected cyberthreats to sneak through the cracks. That's why Fortra is creating a stronger, simpler strategy for protection. One that increases your security maturity while decreasing the operational burden that comes with it. Fortra's integrated, scalable solutions help customers face their toughest challenges with confidence. Learn more at Fortra.com.
Twitter addresses claims of recent data leak
Uber hit with another breach after attack on third-party vendor
Police in China arrest gang who laundered $1.7 billion via crypto
Thanks to this week's episode sponsor, Fortra
The cybersecurity landscape is full of single-solution providers, making it easy for unexpected cyberthreats to sneak through the cracks. That's why Fortra is creating a stronger, simpler strategy for protection. One that increases your security maturity while decreasing the operational burden that comes with it. Fortra's integrated, scalable solutions help customers face their toughest challenges with confidence. Learn more at Fortra.com.
For the stories behind the headlines, visit CISOseries.com
India’s foreign ministry leaks passport details
Cloudflare Zero Trust suite available to at-risk groups
Greece outlaws spyware
Thanks to this week's episode sponsor, Fortra
The cybersecurity landscape is full of single-solution providers, making it easy for unexpected cyberthreats to sneak through the cracks. That's why Fortra is creating a stronger, simpler strategy for protection. One that increases your security maturity while decreasing the operational burden that comes with it. Fortra's integrated, scalable solutions help customers face their toughest challenges with confidence. Learn more at Fortra.com.
Pwn2Own Toronto 2022 nets almost $1M for 63 zero days
Antivirus and EDR solutions tricked into acting as data wipers
Iran-linked MuddyWater APT launches new campaign
Thanks to this week's episode sponsor, Fortra
The cybersecurity landscape is full of single-solution providers, making it easy for unexpected cyberthreats to sneak through the cracks. That's why Fortra is creating a stronger, simpler strategy for protection. One that increases your security maturity while decreasing the operational burden that comes with it. Fortra's integrated, scalable solutions help customers face their toughest challenges with confidence. Learn more at Fortra.com.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, December 5-9, is hosted by Rich Stroffolino with our guest, Ken Athanasiou, CISO, VF Corporation
Thanks to our show sponsor, PlexTrac
The best pentesting teams trust PlexTrac. PlexTrac can improve efficiency and effectiveness at every phase of your proactive assessments. By centralizing the data from all your automation tools, cataloging important reusable content for easy access, and promoting communication and visibility at every phase of an assessment, PlexTrac cuts reporting time in half and adds value between reports. Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the premier pentest reporting and collaboration platform.
All links and the video of this episode can be found on CISO Series.com
North Korea-linked APT37 exploits Internet Explorer zero-day flaw
Firewalls of several major vendors bypassed with generic attack method
New 'Zombinder' platform binds Android malware with legitimate apps
Thanks to today's episode sponsor, PlexTrac
The best pentesting teams trust PlexTrac. PlexTrac can improve efficiency and effectiveness at every phase of your proactive assessments. By centralizing the data from all your automation tools, cataloging important reusable content for easy access, and promoting communication and visibility at every phase of an assessment, PlexTrac cuts reporting time in half and adds value between reports.
Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the premier pentest reporting and collaboration platform.
For the stories behind the headlines, head to CISOseries.com.
Pentagon awards cloud deal to four major providers
Apple finally adds encryption to iCloud backups
CloudSEK claims it was hacked by another cybersecurity firm
Thanks to today's episode sponsor, PlexTrac
The Plextrac platform is your offensive security team’s secret weapon. Build better reports in half the time, centralize your data, maximize your reusable content, and become more efficient and effective. PlexTrac clients report a “5X ROI in 1 year,” a “30% increase in efficiency,” have “cut their reporting cycle by 65%,” and experienced a “18 to 22% time savings per engagement.” Check out PlexTrac.com/CISOSeries to learn how PlexTrac can help your team deliver results.
For the stories behind the headlines, visit CISOseries.com
Are we in the age of AI generated malware
Rackspace confirms ransomware attack
Meta Oversight Board rules on cross-check system
Thanks to today's episode sponsor, PlexTrac
The best pentesting teams trust PlexTrac. PlexTrac can improve efficiency and effectiveness at every phase of your proactive assessments. By centralizing the data from all your automation tools, cataloging important reusable content for easy access, and promoting communication and visibility at every phase of an assessment, PlexTrac cuts reporting time in half and adds value between reports. Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the premier pentest reporting and collaboration platform.
Vulnerabilities found in popular baseboard software
Chinese threat group stole COVID-19 relief funds
The question of AI generated code
Thanks to today's episode sponsor, PlexTrac
The Plextrac platform is your offensive security team’s secret weapon. Build better reports in half the time, centralize your data, maximize your reusable content, and become more efficient and effective. PlexTrac clients report a “5X ROI in 1 year,” a “30% increase in efficiency,” have “cut their reporting cycle by 65%,” and experienced a “18 to 22% time savings per engagement.” Check out PlexTrac.com/CISOSeries to learn how PlexTrac can help your team deliver results.
Open source software host Fosshost shutting down, CEO unreachable
DHS Cyber Safety Review Board to review Lapsus$ attacks
Rackspace rocked by ‘security incident’ that has taken out hosted Exchange services
Thanks to today's episode sponsor, PlexTrac
The best pentesting teams trust PlexTrac. PlexTrac can improve efficiency and effectiveness at every phase of your proactive assessments. By centralizing the data from all your automation tools, cataloging important reusable content for easy access, and promoting communication and visibility at every phase of an assessment, PlexTrac cuts reporting time in half and adds value between reports.
Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the premier pentest reporting and collaboration platform.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, November 28-December 2, is hosted by Rich Stroffolino with our guest, Terrance Cooley, CISO, Air Force JADC2 R&D Center.
Thanks to our show sponsor, Automox
Are you ready to ditch manual patching and all the complexity and hassle that comes with it? With Automox, you can automatically patch your Windows, macOs, and Linux devices with one easy-to-use, cloud-native platform. Modern patching should be easy. And now it is. With automated cross-OS patching, you’ll save time and sleep better at night knowing your IT environment is secure. Visit Automox.com to learn more and start a free trial today.
All links and the video of this episode can be found on CISO Series.com
Intruders gain access to user data in LastPass incident
Sirius XM flaw unlocks smart cars thanks to code flaw
Medibank hackers announce ‘case closed’ and dump huge data file on dark web
Thanks to this week's episode sponsor, Automox
And now a word from our sponsor, Automox. Are you ready to ditch manual patching and all the complexity and hassle that comes with it? With Automox, you can automatically patch your Windows, macOs, and Linux devices with one easy-to-use, cloud-native platform. Modern patching should be easy. And now it is. With automated cross-OS patching, you’ll save time and sleep better at night knowing your IT environment is secure. Visit Automox.com to learn more and start a free trial today.
For the stories behind the headlines, head to CISOseries.com.
Elon Musk’s Starlink and the White House targeted by Killnet hackers
Google links Windows exploit framework used to send spyware
Malicious Android app creates fake accounts on multiple platforms
Thanks to this week's episode sponsor, Automox
Threat exposure is a growing business risk. Today, vulnerabilities are piling up faster than traditional remediation processes and tools can fix them. But fixing vulnerabilities doesn’t have to be a fire drill. Now you can eliminate threats and manage exposed endpoints with Automox Automated Vulnerability Remediation, the only cloud-native solution that harmonizes your SecOps and ITOps workflow and lets you fix vulnerabilities dramatically faster – in minutes, not months. Visit Automox.com to learn more and start a free trial today.
For the stories behind the headlines, head to CisoSeries.com
Hackers use trending TikTok 'Invisible Challenge' to spread malware
Cyber Monday online sales hit record
Sandworm gang launches Monster ransomware attacks on Ukraine
Thanks to this week's episode sponsor, Automox
Are you tired of using multiple tools to patch your third-party applications? With Automox you’ll gain complete visibility of all your software and the ability to patch it, automatically, from a single platform. Fix missing third-party patches with the click of a button to dramatically reduce the time, effort, and complexity it takes to maintain a strong security posture. Visit Automox.com to learn more and start a free trial today.
For the stories behind the headlines, head to CISOseries.com.
Project Zero warns of “patch gap”
Twitter hit with spam campaign
Canadian food company refuses ransom demands
Thanks to this week's episode sponsor, Automox
Are you ready to say goodbye to manual patching? With Automox you can automatically patch your Windows, macOs, and Linux devices with one easy-to-use, cloud-native platform. Modern patching can and should be easy. Save time and sleep better at night knowing your IT environment is secure with automated cross-OS patching. Visit Automox.com to learn more and start a free trial today.
FCC announces ban on Chinese telecom and surveillance equipment
New Windows Server updates cause domain controller freezes, restarts
WhatsApp data leak: 500 million user records for sale
Thanks to this week's episode sponsor, Automox
Automox allows you to automate the configuration, patching, and compliance of your Windows, macOS, and Linux systems all from the cloud. Visit Automox.com to start a free trial and have all your endpoints safe and secure in just 15 minutes. Automox is also offering special pricing from now until December 31st so you can start 2023 off right and get automated patching without breaking your budget.
For the stories behind the headlines, head to CISOseries.com.
FCC announces ban on Chinese telecom and surveillance equipment
New Windows Server updates cause domain controller freezes, restarts
WhatsApp data leak: 500 million user records for sale
Thanks to this week's episode sponsor, Automox
Automox allows you to automate the configuration, patching, and compliance of your Windows, macOS, and Linux systems all from the cloud. Visit Automox.com to start a free trial and have all your endpoints safe and secure in just 15 minutes. Automox is also offering special pricing from now until December 31st so you can start 2023 off right and get automated patching without breaking your budget.
For the stories behind the headlines, head to CISOseries.com.
Twitter enlists hacker George Hotz for 12 week “internship”
Estonian duo arrested for masterminding $575 million Ponzi scheme
Hackers steal $300K from DraftKings customers
Thanks to today’s episode sponsor, Compyl
Preparing a Thanksgiving meal can be stressful, but managing your security and compliance program doesn't have to be. Compyl quickly integrates with the tools you use, and automates 85% of the day-to-day tasks, all while providing complete visibility and comprehensive reporting along the way. Learn about Compyl today at www.compyl.com.
For the stories behind the headlines, visit CISOseries.com
Emotet returns with a malspam vengeance
Google publishes YARA rules for Cobalt Strike
Ticketmaster blames “bot attacks” for ticketing fiasco
Thanks to today’s episode sponsor, Compyl
This thanksgiving, sit around the table and be thankful for Compyl. Compyl is an all-in-one platform that supercharges your security program and takes control of your compliance and audits. Automate workflows, audit collection, compliance management, and all the boring security stuff. Learn about Compyl today at www.compyl.com.
New ransomware encrypts files, then steals your Discord account
Donald Trump returns to Twitter after Elon Musk's poll
More than half of Black Friday spam emails are scams
Thanks to today’s episode sponsor, Compyl
We all know that CISOs are overworked and stressed. CISOs made Compyl to reduce the noise, accelerate security maturity and let you and your team quickly make decisions that directly affect what's important to your business. Learn about Compyl at www.compyl.com.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, November 14-18, is hosted by Rich Stroffolino with our guest, John Scrimsher, CISO, Kontoor Brands
Thanks to today’s episode sponsor, AppOmni
Can you name all the third party apps connected to your major SaaS platforms like SalesForce and Microsoft? What about the data these apps can access? After all, one compromised third party app could put your entire SaaS ecosystem at risk. With AppOmni, you get visibility to all third party apps, including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com to request a free risk assessment.
All links and the video of this episode can be found on CISO Series.com
Musk’s ultimatum to employees leaves Twitter at risk
Iranian APT breaches government agency using Log4Shell
Hundreds of Amazon RDS snapshots discovered leaking user data
And now a word from our sponsor, AppOmni
Can you name all the third party apps connected to your major SaaS platforms like Salseforce and Microsoft? What about the data these apps can access? After all, one compromised third party app could put your entire SaaS ecosystem at risk.
With AppOmni, you get visibility to all third party apps, including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com to request a free risk assessment.
Disneyland phishes with Punycode
The effectiveness of Ukraine’s IT army
NSA seeks to lower barriers to work with private sector
And now a word from our sponsor, AppOmni
Can you name all the third party apps connected to your major SaaS platforms like Salseforce and Microsoft? What about the data these apps can access? After all, one compromised third party app could put your entire SaaS ecosystem at risk.
With AppOmni, you get visibility to all third party apps, including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com to request a free risk assessment.
Amazon to cut 10,000 employees in tech and corporate roles Privacy experts cautious about FIFA World Cup Apps
98% of organizations have been severely impacted by cyber supply chain breach
And now a word from our sponsor, AppOmni
Can you name all the third party apps connected to your major SaaS platforms like Salseforce and Microsoft? What about the data these apps can access? After all, one compromised third party app could put your entire SaaS ecosystem at risk.
With AppOmni, you get visibility to all third party apps, including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com to request a free risk assessment.
For the stories behind the headlines, head to CISOseries.com.
Australia considers ban on ransomware payments
Thousands of sites used for brand impersonation
GitHub gets private reporting
And now a word from our sponsor, AppOmni
Can you name all the third party apps connected to your major SaaS platforms like Salseforce and Microsoft? What about the data these apps can access? After all, one compromised third party app could put your entire SaaS ecosystem at risk.
With AppOmni, you get visibility to all third party apps, including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com to request a free risk assessment.
Android phone owner accidentally finds a way to bypass lock screen
Thales hit by Lockbit 3.0 again
At least $1 billion of client funds missing at FTX
And now a word from our sponsor, AppOmni
Can you name all the third party apps connected to your major SaaS platforms like Salseforce and Microsoft? What about the data these apps can access? After all, one compromised third party app could put your entire SaaS ecosystem at risk.
With AppOmni, you get visibility to all third party apps, including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com to request a free risk assessment.
For the stories behind the headlines, head to CISOseries.com.
Alleged LockBit operator to be extradited from Canada to U.S.
Musk’s ends remote work and promised to fight spam. CISO Kissner quits.
Insurance giant settles NotPetya lawsuit, signaling cyber insurance shakeup
And now a word from our sponsor, AppOmni
Did you know that over half of companies have sensitive SaaS data exposed on the public internet? And many breaches making headlines now involve SaaS apps? AppOmni can help.
AppOmni identifies misconfigurations and guides remediation to keep your SaaS data secure. We help Security teams make sense of data access permissions, third party app visibility, and threat detection across their entire SaaS ecosystem. Get started at AppOmni.com.
For the stories behind the headlines, head to CISOseries.com.
Crypto Winter comes for FTX
Vulnerability found in oil and gas utilities
Vulnerability found in oil and gas utilities
And now a word from our sponsor, AppOmni
Did you know that over half of companies have sensitive SaaS data exposed on the public internet? And many breaches making headlines now involve SaaS apps? AppOmni can help.
AppOmni identifies misconfigurations and guides remediation to keep your SaaS data secure. We help Security teams make sense of data access permissions, third party app visibility, and threat detection across their entire SaaS ecosystem. Get started at AppOmni.com.
For the stories behind the headlines, head to CISOseries.com.
$2 billion Powerball drawing delayed by security issues
Hackers leak Australian health records on dark web
Hushpuppi gets 11 years in prison for cyber fraud
And now a word from our sponsor, AppOmni
Did you know that over half of companies have sensitive SaaS data exposed on the public internet? And many breaches making headlines now involve SaaS apps? AppOmni can help.
AppOmni identifies misconfigurations and guides remediation to keep your SaaS data secure. We help Security teams make sense of data access permissions, third party app visibility, and threat detection across their entire SaaS ecosystem. Get started at AppOmni.com.
For the stories behind the headlines, head to CISOseries.com.
China stockpiling vulnerabilities
US seizes Silk Road bitcoins
DOJ takes down Z-Library
And now a word from our sponsor, AppOmni
Did you know that over half of companies have sensitive SaaS data exposed on the public internet? And many breaches making headlines now involve SaaS apps? AppOmni can help.
AppOmni identifies misconfigurations and guides remediation to keep your SaaS data secure. We help Security teams make sense of data access permissions, third party app visibility, and threat detection across their entire SaaS ecosystem. Get started at AppOmni.com.
For the stories behind the headlines, head to CISOseries.com.
US Treasury thwarts DDoS attack from Russian Killnet group
British government scanning all Internet devices hosted in UK
Denmark trains halted by cyberattack
And now a word from our sponsor, AppOmni
Did you know that over half of companies have sensitive SaaS data exposed on the public internet? And many breaches making headlines now involve SaaS apps? AppOmni can help.
AppOmni identifies misconfigurations and guides remediation to keep your SaaS data secure. We help Security teams make sense of data access permissions, third party app visibility, and threat detection across their entire SaaS ecosystem. Get started at AppOmni.com.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, October 31-November 4, is hosted by Rich Stroffolino with our guest, Marcos Marrero, CISO, H.I.G. Capital
Thanks to today’s episode sponsor, Votiro
UFOs are everywhere.
They’re in your applications, cloud storage, endpoints, and emails.
That’s right – UFOs – Unidentified File Objects – are hiding in files across your organization.
UFOs can contain malware that exfiltrates data or deploys ransomware. And 70% of UFOs can’t be detected by traditional scanning solutions like Anti-Virus and Sandboxing.
That’s where Votiro comes in. Votiro prevents UFOs before they hitch a ride in on files – without detection, and without slowing down business.
Do you believe? Learn more at Votiro.com/UFOs
All links and the video of this episode can be found on CISO Series.com
Cyber incident at Boeing subsidiary causes flight planning disruptions
Stripe to lay off 14% of workforce
Over 250 US news websites deliver malware via supply chain attack
Thanks to today’s episode sponsor, Votiro
UFOs are everywhere. They’re in your applications, cloud storage, endpoints, and emails. That’s right – UFOs – Unidentified File Objects – are hiding in files across your organization. UFOs can contain malware that exfiltrates data or deploys ransomware. And 70% of UFOs can’t be detected by traditional scanning solutions like Anti-Virus and Sandboxing. That’s where Votiro comes in. Votiro prevents UFOs before they hitch a ride in on files – without detection, and without slowing down business.
Do you believe? Learn more at Votiro.com/ufos
For the stories behind the headlines, head to CISOseries.com.
W4SP malware stings PyPI
LastPass warns of security hubris
Dropbox breached
Thanks to today’s episode sponsor, Votiro
UFOs are everywhere.They’re in your applications, cloud storage, endpoints, and emails.That’s right – UFOs – Unidentified File Objects – are hiding in files across your organization. UFOs can contain malware that exfiltrates data or deploys ransomware. And 70% of UFOs can’t be detected by traditional scanning solutions like Anti-Virus and Sandboxing. That’s where Votiro comes in. Votiro prevents UFOs before they hitch a ride in on files – without detection, and without slowing down business.
Do you believe? Learn more at Votiro.com/
LockBit dominates ransomware
CISA on voting integrity
A call for more ransomware reporting
Thanks to today’s episode sponsor, Votiro
UFOs are everywhere.They’re in your applications, cloud storage, endpoints, and emails.That’s right – UFOs – Unidentified File Objects – are hiding in files across your organization. UFOs can contain malware that exfiltrates data or deploys ransomware. And 70% of UFOs can’t be detected by traditional scanning solutions like Anti-Virus and Sandboxing. That’s where Votiro comes in. Votiro prevents UFOs before they hitch a ride in on files – without detection, and without slowing down business.
Do you believe? Learn more at Votiro.com/
Threat group rides antivirus software to install malware
White House organizes ransomware summit
Ed tech company exposed user data
Thanks to today’s episode sponsor, Votiro
UFOs are everywhere.They’re in your applications, cloud storage, endpoints, and emails.That’s right – UFOs – Unidentified File Objects – are hiding in files across your organization. UFOs can contain malware that exfiltrates data or deploys ransomware. And 70% of UFOs can’t be detected by traditional scanning solutions like Anti-Virus and Sandboxing. That’s where Votiro comes in. Votiro prevents UFOs before they hitch a ride in on files – without detection, and without slowing down business.
Do you believe? Learn more at Votiro.com/
Thomson Reuters leaks 3TB of sensitive data
Massive cyberattack hits Slovak and Polish Parliaments
Twitter trolls bombard platform after Elon Musk takeover
Thanks to today’s episode sponsor, Votiro
UFOs are everywhere. They’re in your applications, cloud storage, endpoints, and emails.
That’s right – UFOs – Unidentified File Objects – are hiding in files across your organization. UFOs can contain malware that exfiltrates data or deploys ransomware. And 70% of UFOs can’t be detected by traditional scanning solutions like Anti-Virus and Sandboxing. That’s where Votiro comes in. Votiro prevents UFOs before they hitch a ride in on files – without detection, and without slowing down business.
Do you believe? Learn more at Votiro.com/ufos.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, October 24-28, is hosted by Rich Stroffolino with our guest, Will Gregorian, former Senior Director, Technology Operations and Security, Rhino
Thanks to this week’s episode sponsor, Votiro
UFOs are everywhere.
They’re in your applications, cloud storage, endpoints, and emails.
That’s right – UFOs – Unidentified File Objects – are hiding in files across your organization.
UFOs can contain malware that exfiltrates data or deploys ransomware. And 70% of UFOs can’t be detected by traditional scanning solutions like Anti-Virus and Sandboxing. That’s where Votiro comes in. Votiro prevents UFOs before they hitch a ride in on files – without detection, and without slowing down business. Do you believe? Learn more at Votiro.com/UFOs.
All links and the video of this episode can be found on CISO Series.com
Russia warns West: We can target your commercial satellites
New York Post says its site was hacked after posting offensive tweets
White House announces 100-day cyber sprint for chemical sector
Thanks to this week’s episode sponsor, Votiro
UFOs are everywhere.They’re in your applications, cloud storage, endpoints, and emails.
That’s right – UFOs – Unidentified File Objects – are hiding in files across your organization. UFOs can contain malware that exfiltrates data or deploys ransomware. And 70% of UFOs can’t be detected by traditional scanning solutions like Anti-Virus and Sandboxing. That’s where Votiro comes in. Votiro prevents UFOs before they hitch a ride in on files – without detection, and without slowing down business.
Do you believe? Learn more at Votiro.com/UFOs For the stories behind the headlines, head to CISOseries.com.
Sigstore opens free software signing service
Australian health insurer hacked
Researcher details 20-year old SQLite bug
Thanks to this week’s episode sponsor, Votiro
UFOs are everywhere.They’re in your applications, cloud storage, endpoints, and emails.
That’s right – UFOs – Unidentified File Objects – are hiding in files across your organization. UFOs can contain malware that exfiltrates data or deploys ransomware. And 70% of UFOs can’t be detected by traditional scanning solutions like Anti-Virus and Sandboxing. That’s where Votiro comes in. Votiro prevents UFOs before they hitch a ride in on files – without detection, and without slowing down business.
Do you believe? Learn more at Votiro.com/UFOs
See Tickets discloses 2.5 year-long credit card breach
US charges Chinese agents in Huawei obstruction case
Hive begins leaking Tata Power’s data
Thanks to this week’s episode sponsor, Votiro
UFOs are everywhere.They’re in your applications, cloud storage, endpoints, and emails.
That’s right – UFOs – Unidentified File Objects – are hiding in files across your organization. UFOs can contain malware that exfiltrates data or deploys ransomware. And 70% of UFOs can’t be detected by traditional scanning solutions like Anti-Virus and Sandboxing. That’s where Votiro comes in. Votiro prevents UFOs before they hitch a ride in on files – without detection, and without slowing down business.
Do you believe? Learn more at Votiro.com/UFOs
For the stories behind the headlines, visit CISOseries.com
CISA warns of Daixin Team
Exploit POCs used to host malware
Iranian nuclear agency hacked
Thanks to this week’s episode sponsor, Votiro
UFOs are everywhere.They’re in your applications, cloud storage, endpoints, and emails.
That’s right – UFOs – Unidentified File Objects – are hiding in files across your organization. UFOs can contain malware that exfiltrates data or deploys ransomware. And 70% of UFOs can’t be detected by traditional scanning solutions like Anti-Virus and Sandboxing. That’s where Votiro comes in. Votiro prevents UFOs before they hitch a ride in on files – without detection, and without slowing down business.
Do you believe? Learn more at Votiro.com/UFOs
Exploited Windows zero-day lets JavaScript files bypass Mark of the Web security warnings
FBI warns of ‘hack-and-leak’ operations from group based in Iran
Wholesale giant METRO confirmed to have suffered a cyberattack
Thanks to this week’s episode sponsor, Votiro
UFOs are everywhere. They’re in your applications, cloud storage, endpoints, and emails. That’s right – UFOs – Unidentified File Objects – are hiding in files across your organization. UFOs can contain malware that exfiltrates data or deploys ransomware. And 70% of UFOs can’t be detected by traditional scanning solutions like Anti-Virus and Sandboxing. That’s where Votiro comes in. Votiro prevents UFOs before they hitch a ride in on files – without detection, and without slowing down business. Do you believe? Learn more at Votiro.com/UFOs
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, October 17-21, is hosted by Rich Stroffolino with our guest, Lee Parrish, CISO, Newell Brands
Thanks to this week’s episode sponsor, SafeBase
Security questionnaires are a pain, and sharing sensitive documents takes too much back and forth. As a result, security can be wrongly viewed as a roadblock rather than a sales enabler. That’s where SafeBase comes in. Our Smart Trust Center makes it easy to showcase your security program, share sensitive documents, and streamline security reviews. It’s the missing piece of your security and sales workflow, and the only security tool that gives you time back. Find out more at safebase.com
All links and the video of this episode can be found on CISO Series.com
Internet connectivity worldwide impacted by severed EU subsea cables
Microsoft BlueBleed customer data leak claimed to be 'one of the largest' in years
Health system data breach due to Meta Pixel hits 3 million patients
Thanks to this week's episode sponsor, SafeBase
Security questionnaires are a pain, and sharing sensitive documents takes too much back and forth. As a result, security can be wrongly viewed as a roadblock rather than a sales enabler. That's where SafeBase comes in. Our Smart Trust Center makes it easy to showcase your security program, share sensitive documents, and streamline security reviews. It's the missing piece of your security and sales workflow, and the only security tool that gives you time back. Find out more at safebase.com
For the stories behind the headlines, head to CISOseries.com.
Ransom Cartel linked to REvil
Do we need cybersecurity training for Gen Z?
Open Compute Project announces Caliptra
Thanks to this week's episode sponsor, SafeBase
Security questionnaires. If those two words sent a shiver down your spine, you need to check out SafeBase. SafeBase’s Smart Trust Center is a centralized source of truth for your organization’s security and compliance information. After implementing SafeBase, many companies see a 90% reduction in custom questionnaires. Imagine how much time you’d save. Visit safebase.com to find out more.
Verizon notifies customers their accounts were breached
German cyber chief removed over alleged Russian ties
Fortinet vulnerability being actively exploited
Thanks to this week's episode sponsor, SafeBase
Security questionnaires are a pain, and sharing sensitive documents takes too much back and forth. As a result, security can be wrongly viewed as a roadblock rather than a sales enabler. That's where SafeBase comes in. Our Smart Trust Center makes it easy to showcase your security program, share sensitive documents, and streamline security reviews. It's the missing piece of your security and sales workflow, and the only security tool that gives you time back. Find out more at safebase.com
For the stories behind the headlines, head to CISOseries.com
Ransomware halts German newspaper circulation
Meta disputes Indian content moderation report
KakaoTalk called a “national communication network” in Korea
Thanks to this week's episode sponsor, SafeBase
Security questionnaires are a pain, and sharing sensitive documents takes too much back and forth. As a result, security can be wrongly viewed as a roadblock rather than a sales enabler. That's where SafeBase comes in. Our Smart Trust Center makes it easy to showcase your security program, share sensitive documents, and streamline security reviews. It's the missing piece of your security and sales workflow, and the only security tool that gives you time back. Find out more at safebase.com
Microsoft says Ukraine, Poland targeted with novel ransomware attack
Wi-Fi spy drones snoop on financial firm
Indian power generation giant Tata Power hit by a cyber attack
Thanks to this week's episode sponsor, SafeBase
Security questionnaires. If those two words sent a shiver down your spine, you need to check out SafeBase. SafeBase’s Smart Trust Center is a centralized source of truth for your organization’s security and compliance information. After implementing SafeBase, many companies see a 90% reduction in custom questionnaires. Imagine how much time you’d save. Visit safebase.com to find out more.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, October 10-14, is hosted by Rich Stroffolino with our guest, Matt Honea, Head Of Security, SmartNews
Thanks to today’s episode sponsor, NoName Security
Prevent API attacks in real-time with automated AI and ML-based detection from Noname Security. Monitor API traffic for data leakage, data tampering, data policy violations, suspicious behavior, and API security attacks. Integrate with your existing IT workflow management system like Jira, ServiceNow, or Slack for seamless remediation. Learn more at nonamesecurity.com/runtime-protection
All links and the video of this episode can be found on CISO Series.com
Polonium APT targets Israel with a new custom backdoor dubbed PapaCreep
RSA Conference reveals CISO-Board relationships
UK government urges action to enhance supply chain security
Thanks to today’s episode sponsor, Noname Security
Prevent API attacks in real-time with automated AI and ML-based detection from Noname Security. Monitor API traffic for data leakage, data tampering, data policy violations, suspicious behavior, and API security attacks. Integrate with your existing IT workflow management system like Jira, ServiceNow, or Slack for seamless remediation. Learn more at nonamesecurity.com/runtime-protection
For the stories behind the headlines, head to CISOseries.com.
Npm timing attack could impact supply chain
Legit software used to spread malicious WhatsApp mod
Mango Markets hit by $100 million hack
Thanks to today’s episode sponsor, Noname Security
Are you sure your APIs are secure? Noname Security discovers all the APIs running on your network and analyzes them to spot design flaws, misconfigurations, and vulnerabilities. You can even catalog sensitive data and quickly see how many APIs are able to access credit card data, phone numbers, SSNs, and other sensitive PII data. Learn more at nonamesecurity.com/posture-management
UK warns of Chinese global security threat
Toyota data leak impacts 300,000 customers
CISOs at risk of being overworked
Thanks to today’s episode sponsor, Noname Security
Stop API vulnerabilities before production with Noname Security. Automatically run over 100 dynamic tests that simulate malicious traffic, including the OWASP API Top Ten. Integrate with your existing CI/CD pipelines and tools, such as Jenkins and Postman, as well as all your ticketing and workflow tools such as ServiceNow, Slack, and Jira. Learn more at nonamesecurity.com/active-testing
For the stories behind the headlines, head to CISOseries.com
Finger heat can leak your password
US airport sites targeted by KillNet
Intel confirms UEFI leak
Thanks to today’s episode sponsor, Noname Security
Prevent API attacks in real-time with automated AI and ML-based detection from Noname Security. Monitor API traffic for data leakage, data tampering, data policy violations, suspicious behavior, and API security attacks. Integrate with your existing IT workflow management system like Jira, ServiceNow, or Slack for seamless remediation. Learn more at nonamesecurity.com/runtime-protection
Fortinet warns admins to patch critical auth bypass bug immediately
Windows 11 22H2 errors break provisioning
Security chiefs fear ‘CISO scapegoating’ following Uber-Sullivan verdict
Thanks to today’s episode sponsor, Noname Security
Are you sure your APIs are secure? Noname Security discovers all the APIs running on your network and analyzes them to spot design flaws, misconfigurations, and vulnerabilities. You can even catalog sensitive data and quickly see how many APIs are able to access credit card data, phone numbers, SSNs, and other sensitive PII data. Learn more at nonamesecurity.com/posture-management
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, October 3-7, is hosted by Sean Kelly, with our guest, Patrick Benoit, VP, Global Cyber, GRC/BISO, CBRE
Thanks to this week’s episode sponsor, Hunters
Hunters is a SaaS platform, purpose built for Security Operation teams. Providing unlimited data ingestion and normalization at a predictable cost, Hunters helps SOC teams mitigate real threats faster and more reliably than SIEM. Visit Hunters.ai to learn more.
All links and the video of this episode can be found on CISO Series.com
Former Uber security chief found guilty of data breach coverup
Optus confirms 2.1 million ID numbers exposed in data breach
Retailer Easylife fined £1.5m for data protection breaches
Thanks to today’s episode sponsor, Hunters
Hunters is a SaaS platform, purpose built for Security Operation teams. Providing unlimited dataingestion and normalization at a predictable cost, Hunters helps SOC teams mitigate real threats faster and more reliably than SIEM. Visit Hunters.ai to learn more.
For the stories behind the headlines, head to CISOseries.com.
CommonSpirit Health hit with “IT security issue”
MySQL servers backdoored
Fraud hitting P2P payment apps
Thanks to today’s episode sponsor, Hunters
Hunters is a SaaS platform, purpose built for Security Operation teams. Providing unlimited dataingestion and normalization at a predictable cost, Hunters helps SOC teams mitigate real threats faster and more reliably than SIEM. Visit Hunters.ai to learn more.
Musk offers to proceed with Twitter deal
TikTok security deal becomes a political pawn
Netwalker ransomware affiliate sentenced to 20 years in prison
Thanks to today’s episode sponsor, Hunters
Hunters is a SaaS platform, purpose built for your Security Operation team. Cimpress, theparent company of VistaPrint, implemented Hunters SOC Platform to replace its SIEM. Thanks to Hunters, Cimpress no longer needs to babysit alerts and detection logic – they’ve improved their SOC’s efficiency, and optimized costs. Visit Hunters.ai to learn more.
For the stories behind the headlines, visit CISOseries.com
LA school data published on leak site
Exchange zero-day mitigations bypassed
Supreme Court will look legal protections for apps and sites
Thanks to today’s episode sponsor, Hunters
Hunters helps your security team overcome data volume and complexity – while significantlyreducing false positives. Upwork uses Hunters SOC Platform to “remain threat focused”. Because of Hunters, Upwork has been able to stop going through the daily repetitive task of looking at alerts, and doing repetitive, manual investigations. Learn more at: Hunters.ai
Microsoft confirms two Exchange Server zero days are being used in cyberattacks
Lazarus hackers abuse Dell driver bug using new FudModule rootkit
Ex-NSA employee charged with violating Espionage Act, selling U.S. cyber secrets
Thanks to today’s episode sponsor, Hunters
Hunters is a SaaS platform, purpose built for Security Operation teams. Providing unlimited dataingestion and normalization at a predictable cost, Hunters helps SOC teams mitigate real threats faster and more reliably than SIEM. Visit Hunters.ai to learn more.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, September 26-30, is hosted by Rich Stroffolino with our guest, Sara Lazarus, VP and head of trust and security, Stavvy
Thanks to today’s episode sponsor, Votiro
Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.
All links and the video of this episode can be found on CISO Series.com
Finnish intelligence warns Russia ‘highly likely’ to turn to cyber in winter
Researchers uncover covert attack campaign targeting military contractors
IRS warns of "industrial scale" smishing surge
Thanks to today’s episode sponsor, Votiro
Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.
For the stories behind the headlines, head to CISOseries.com.
Finnish intelligence warns Russia ‘highly likely’ to turn to cyber in winter
Researchers uncover covert attack campaign targeting military contractors
IRS warns of "industrial scale" smishing surge
Thanks to today’s episode sponsor, Votiro
Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.
For the stories behind the headlines, head to CISOseries.com.
Leaked ransomware builder used in attacks
Cloudflare hopes Turnstile can replace CAPTCHAs
Fast Company goes dark after cyber attack
Thanks to today’s episode sponsor, Votiro
Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.
Leaked ransomware builder used in attacks
Cloudflare hopes Turnstile can replace CAPTCHAs
Fast Company goes dark after cyber attack
Thanks to today’s episode sponsor, Votiro
Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.
Lazarus Group targets macOS users
Geopolitics behind recent DDoS surge
Meta takes on influence networks
Thanks to today’s episode sponsor, Votiro
Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.
Lazarus Group targets macOS users
Geopolitics behind recent DDoS surge
Meta takes on influence networks
Thanks to today’s episode sponsor, Votiro
Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.
Jamf buys ZecOps
Porn phishing scam turns into a DDoS
Cloudflare announced secure eSIM offering
Thanks to today’s episode sponsor, Votiro
Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.
Jamf buys ZecOps
Porn phishing scam turns into a DDoS
Cloudflare announced secure eSIM offering
Thanks to today’s episode sponsor, Votiro
Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.
London Police arrest 17-year-old hacker suspected of Uber and GTA 6 breaches
Microsoft SQL servers hacked in TargetCompany ransomware attacks
Attackers impersonate CircleCI platform to compromise GitHub accounts
Thanks to today’s episode sponsor, Votiro
Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.
For the stories behind the headlines, head to CISOseries.com.
London Police arrest 17-year-old hacker suspected of Uber and GTA 6 breaches
Microsoft SQL servers hacked in TargetCompany ransomware attacks
Attackers impersonate CircleCI platform to compromise GitHub accounts
Thanks to today’s episode sponsor, Votiro
Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, September 19-23, is hosted by Rich Stroffolino with our guest, Joseph Lewis, Director, Cyber Assessment Strategy, US Department of Energy
Thanks to this week’s sponsor, 6clicks
6clicks is your AI-powered GRC platform, featuring a fully integrated content library. 6clicks provides organizations with a powerful GRC platform to build highly scalable risk and compliance functions and advisors with the tools to streamline and scale their services, saving everyone enormous time and money. Reimagine risk. Improve cybersecurity. Demonstrate compliance. For more information visit 6clicks.com/cisoseries.
All links and the video of this episode can be found on CISO Series.com
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, September 19-23, is hosted by Rich Stroffolino with our guest, Joseph Lewis, Director, Cyber Assessment Strategy, US Department of Energy
Thanks to this week’s sponsor, 6clicks
6clicks is your AI-powered GRC platform, featuring a fully integrated content library. 6clicks provides organizations with a powerful GRC platform to build highly scalable risk and compliance functions and advisors with the tools to streamline and scale their services, saving everyone enormous time and money. Reimagine risk. Improve cybersecurity. Demonstrate compliance. For more information visit 6clicks.com/cisoseries.
All links and the video of this episode can be found on CISO Series.com
MFA Fatigue: Hackers’ new favorite tactic in high-profile breaches
Senate reports details inefficiencies, confusion at key U.S. counterintelligence center
Australian telco Optus suffers massive data breach
Thanks to today’s episode sponsor, 6clicks
With 6clicks, organizations can manage enterprise risk easier than ever before. 6clicks helps you identify your risks, group them into risk registers, and run risk assessments. It highlights causes and potential impacts, outlines risk treatment plans, and helps you manage the full treatment lifecycle – all while informing your holistic GRC posture with built-in data linkages. For more information visit 6clicks.com/cisoseries.
For the stories behind the headlines, head to CISOseries.com.
MFA Fatigue: Hackers’ new favorite tactic in high-profile breaches
Senate reports details inefficiencies, confusion at key U.S. counterintelligence center
Australian telco Optus suffers massive data breach
Thanks to today’s episode sponsor, 6clicks
With 6clicks, organizations can manage enterprise risk easier than ever before. 6clicks helps you identify your risks, group them into risk registers, and run risk assessments. It highlights causes and potential impacts, outlines risk treatment plans, and helps you manage the full treatment lifecycle – all while informing your holistic GRC posture with built-in data linkages. For more information visit 6clicks.com/cisoseries.
For the stories behind the headlines, head to CISOseries.com.
15-year old Python bug causing problem
LinkedIn Smart Links used for phishing
US military buys Augury network monitoring tool
Thanks to today’s episode sponsor, 6clicks
Your GRC solution is only as valuable as the reports it can generate. Provide an exceptional analytics experience for all your GRC stakeholders with the 6clicks reporting suite. Unlock powerful insights and prove compliance using dashboards and charts, pixel perfect reporting, presentations, and data storytelling via LiveDocs.. For more information visit 6clicks.com/cisoseries.
15-year old Python bug causing problem
LinkedIn Smart Links used for phishing
US military buys Augury network monitoring tool
Thanks to today’s episode sponsor, 6clicks
Your GRC solution is only as valuable as the reports it can generate. Provide an exceptional analytics experience for all your GRC stakeholders with the 6clicks reporting suite. Unlock powerful insights and prove compliance using dashboards and charts, pixel perfect reporting, presentations, and data storytelling via LiveDocs.. For more information visit 6clicks.com/cisoseries.
American Airlines announce breach of customer and staff info
Crypto market maker hacked for $160 million
2K and Rockstar fall victim to cyber attacks
Thanks to today’s episode sponsor, 6clicks
The 6clicks GRC solution comes with a fully integrated content library full of hundreds of standards, assessment templates, libraries, playbooks, and more. With the content library included in every 6clicks license, organizations can get started on their GRC implementation faster than ever before. For more information visit 6clicks.com/cisoseries.
For the stories behind the headlines, head to CISOseries.com
American Airlines announce breach of customer and staff info
Crypto market maker hacked for $160 million
2K and Rockstar fall victim to cyber attacks
Thanks to today’s episode sponsor, 6clicks
The 6clicks GRC solution comes with a fully integrated content library full of hundreds of standards, assessment templates, libraries, playbooks, and more. With the content library included in every 6clicks license, organizations can get started on their GRC implementation faster than ever before. For more information visit 6clicks.com/cisoseries.
For the stories behind the headlines, head to CISOseries.com
The shifting ways of Chromeloader
Ransomware attacks fall in first half
Pentagon orders review of social media influence campaigns
Thanks to today’s episode sponsor, 6clicks
Experience the magic of Hailey, the 6clicks artificial intelligence engine for risk and compliance. With Hailey, organizations can automatically show cross-compliance between regulations or identify gaps to external compliance requirements in their policies. Eliminate manual and costly risk and compliance processes by joining the hundreds of businesses that trust 6clicks. For more information visit 6clicks.com/cisoseries.
The shifting ways of Chromeloader
Ransomware attacks fall in first half
Pentagon orders review of social media influence campaigns
Thanks to today’s episode sponsor, 6clicks
Experience the magic of Hailey, the 6clicks artificial intelligence engine for risk and compliance. With Hailey, organizations can automatically show cross-compliance between regulations or identify gaps to external compliance requirements in their policies. Eliminate manual and costly risk and compliance processes by joining the hundreds of businesses that trust 6clicks. For more information visit 6clicks.com/cisoseries.
Uber says there is no evidence that users’ private information was compromised
LastPass says hackers accessed its systems for just 4 days
Netgear Routers impacted by FunJSQ module flaw
Thanks to today’s episode sponsor, 6clicks
6clicks has pioneered a unique Hub & Spoke architecture to underpin its AI-powered GRC solution and cater to markets requiring scalable, multi-tenanted GRC. This model enables organizations to deploy multiple, autonomous GRC entities connected to a single hub for roll-up reporting, management, and visibility. For more information visit 6clicks.com/cisoseries.
For the stories behind the headlines, head to CISOseries.com.
Uber says there is no evidence that users’ private information was compromised
LastPass says hackers accessed its systems for just 4 days
Netgear Routers impacted by FunJSQ module flaw
Thanks to today’s episode sponsor, 6clicks
6clicks has pioneered a unique Hub & Spoke architecture to underpin its AI-powered GRC solution and cater to markets requiring scalable, multi-tenanted GRC. This model enables organizations to deploy multiple, autonomous GRC entities connected to a single hub for roll-up reporting, management, and visibility. For more information visit 6clicks.com/cisoseries.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, Quincy Castro, CISO, Redis
Thanks to today’s episode sponsor, Edgescan
Scalable automated and continuous Attack Surface Management (ASM) and vulnerability detection integrated with a world-class cyber security team provide 100% false-positive-free alerts and expert remediation guidance. Edgescan.com
All links and the video of this episode can be found on CISO Series.com
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, Quincy Castro, CISO, Redis
Thanks to today’s episode sponsor, Edgescan
Scalable automated and continuous Attack Surface Management (ASM) and vulnerability detection integrated with a world-class cyber security team provide 100% false-positive-free alerts and expert remediation guidance. Edgescan.com
All links and the video of this episode can be found on CISO Series.com
Gamers targeted by self-spreading stealer on YouTube
Biden order further scrutinizes foreign tech supply chains
Phishing attacks being launched in the name of Queen Elizabeth II
Thanks to today’s episode sponsor, Edgescan
Edgescan simplifies Vulnerability Management by delivering a single full-stack solution (SaaS) integrated with world-class security professionals. Instead of managing a plethora of point scanning tools for each layer of the attack surface and squandering precious staff resources manually removing false positives, Edgescan offers automated and accurate contextualized alerts across the entire attack surface into a single source of truth.
For the stories behind the headlines, head to CISOseries.com
Gamers targeted by self-spreading stealer on YouTube
Biden order further scrutinizes foreign tech supply chains
Phishing attacks being launched in the name of Queen Elizabeth II
Thanks to today’s episode sponsor, Edgescan
Edgescan simplifies Vulnerability Management by delivering a single full-stack solution (SaaS) integrated with world-class security professionals. Instead of managing a plethora of point scanning tools for each layer of the attack surface and squandering precious staff resources manually removing false positives, Edgescan offers automated and accurate contextualized alerts across the entire attack surface into a single source of truth.
For the stories behind the headlines, head to CISOseries.com
Teams stores tokens in cleartext
Cyberscammers caught up in human trafficking
US Treasury issues guidance on Tornado Cash
Thanks to today’s episode sponsor, Edgescan
Scalable automated and continuous Attack Surface Management (ASM) and vulnerability detection integrated with a world-class cyber security team provide 100% false-positive-free alerts and expert remediation guidance.
Teams stores tokens in cleartext
Cyberscammers caught up in human trafficking
US Treasury issues guidance on Tornado Cash
Thanks to today’s episode sponsor, Edgescan
Scalable automated and continuous Attack Surface Management (ASM) and vulnerability detection integrated with a world-class cyber security team provide 100% false-positive-free alerts and expert remediation guidance.
Apple Releases iOS and macOS updates to patch actively exploited zero-day flaw
Extreme California heat knocks key Twitter data center offline
New phishing scheme uses 'herd mentality' approach to dupe victims
Thanks to today’s episode sponsor, Edgescan
Edgescan combines full-stack coverage with integrated reporting and business-level prioritization to deliver a single source of truth for your entire vulnerability management program with zero false positives.
For the stories behind the headlines, head to CISOseries.com.
Apple Releases iOS and macOS updates to patch actively exploited zero-day flaw
Extreme California heat knocks key Twitter data center offline
New phishing scheme uses 'herd mentality' approach to dupe victims
Thanks to today’s episode sponsor, Edgescan
Edgescan combines full-stack coverage with integrated reporting and business-level prioritization to deliver a single source of truth for your entire vulnerability management program with zero false positives.
For the stories behind the headlines, head to CISOseries.com.
Google closes on Mandiant
Paying the iron price for Retbleed mitigation
Meta hands over the keys to PyTorch
Thanks to today’s episode sponsor, Edgescan
Edgescan offers a single platform solution that covers the full stack, from Web Applications to APIs to the Network and data layer. Continuous Attack Surface Management coupled with automated & strategic Pen-testing as a Service (PTaaS) yields fully scalable coverage.
Google closes on Mandiant
Paying the iron price for Retbleed mitigation
Meta hands over the keys to PyTorch
Thanks to today’s episode sponsor, Edgescan
Edgescan offers a single platform solution that covers the full stack, from Web Applications to APIs to the Network and data layer. Continuous Attack Surface Management coupled with automated & strategic Pen-testing as a Service (PTaaS) yields fully scalable coverage.
Ransomware gangs switching to new intermittent encryption tactic
Firmware bugs in many HP computer models left unfixed for over a year
U.S. SEC to set up new office for crypto filings
Thanks to today’s episode sponsor, Edgescan
Edgescan simplifies Vulnerability Management by delivering a single full-stack solution (SaaS) integrated with world-class security professionals. Instead of managing a plethora of point scanning tools for each layer of the attack surface and squandering precious staff resources manually removing false positives, Edgescan offers automated and accurate contextualized alerts across the entire attack surface into a single source of truth.
For the stories behind the headlines, head to CISOseries.com.
Ransomware gangs switching to new intermittent encryption tactic
Firmware bugs in many HP computer models left unfixed for over a year
U.S. SEC to set up new office for crypto filings
Thanks to today’s episode sponsor, Edgescan
Edgescan simplifies Vulnerability Management by delivering a single full-stack solution (SaaS) integrated with world-class security professionals. Instead of managing a plethora of point scanning tools for each layer of the attack surface and squandering precious staff resources manually removing false positives, Edgescan offers automated and accurate contextualized alerts across the entire attack surface into a single source of truth.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, Jason Elrod, CISO, Multicare Health System
Thanks to today’s episode sponsor, Snyk
*Developers want to code fast and security wants to ship securely — and they want to do it all from the cloud. That’s why they both choose Snyk. Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.
Code, dependencies, containers, cloud environments… all of it.
And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects and cloud environments, so they can prioritize and focus their efforts in the right places.
Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity*
All links and the video of this episode can be found on CISO Series.com
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, Jason Elrod, CISO, Multicare Health System
Thanks to today’s episode sponsor, Snyk
*Developers want to code fast and security wants to ship securely — and they want to do it all from the cloud. That’s why they both choose Snyk. Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.
Code, dependencies, containers, cloud environments… all of it.
And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects and cloud environments, so they can prioritize and focus their efforts in the right places.
Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity*
All links and the video of this episode can be found on CISO Series.com
China accuses US of cyberattacks and cyberespionage
London's biggest bus operator hit by cyber "incident"
Researchers reveal new Iranian threat group APT42
Thanks to today’s episode sponsor, Snyk
Developers want to code fast and security wants to ship securely — and they want to do it all from the cloud. That’s why they both choose Snyk. Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.
Code, dependencies, containers, cloud environments... all of it.
And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects and cloud environments, so they can prioritize and focus their efforts in the right places.
Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity
For the stories behind the headlines, head to CISOseries.com.
China accuses US of cyberattacks and cyberespionage
London's biggest bus operator hit by cyber "incident"
Researchers reveal new Iranian threat group APT42
Thanks to today’s episode sponsor, Snyk
Developers want to code fast and security wants to ship securely — and they want to do it all from the cloud. That’s why they both choose Snyk. Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.
Code, dependencies, containers, cloud environments... all of it.
And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects and cloud environments, so they can prioritize and focus their efforts in the right places.
Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity
For the stories behind the headlines, head to CISOseries.com.
CISA asks for feedback on reporting rules
New Linux-focused malware targets IoT
Albania cuts diplomatic ties over cyberattack
Thanks to today’s episode sponsor, Snyk
Developers want to code fast and security wants to ship securely — and they want to do it all from the cloud. That’s why they both choose Snyk. Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.
Code, dependencies, containers, cloud environments... all of it.
And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects and cloud environments, so they can prioritize and focus their efforts in the right places.
Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity
CISA asks for feedback on reporting rules
New Linux-focused malware targets IoT
Albania cuts diplomatic ties over cyberattack
Thanks to today’s episode sponsor, Snyk
Developers want to code fast and security wants to ship securely — and they want to do it all from the cloud. That’s why they both choose Snyk. Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.
Code, dependencies, containers, cloud environments... all of it.
And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects and cloud environments, so they can prioritize and focus their efforts in the right places.
Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity
Uber's ex-cyber exec heads to trial
Twitter fires back at Mudge for “parroting” Elon Musk
FBI warns of ransomware attacks on school districts
Thanks to today’s episode sponsor, Snyk
Developers want to code fast and security wants to ship securely — and they want to do it all from the cloud. That’s why they both choose Snyk. Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.
Code, dependencies, containers, cloud environments... all of it.
And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects and cloud environments, so they can prioritize and focus their efforts in the right places.
Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity
For the stories behind the headlines, head to CISOseries.com
Uber's ex-cyber exec heads to trial
Twitter fires back at Mudge for “parroting” Elon Musk
FBI warns of ransomware attacks on school districts
Thanks to today’s episode sponsor, Snyk
Developers want to code fast and security wants to ship securely — and they want to do it all from the cloud. That’s why they both choose Snyk. Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.
Code, dependencies, containers, cloud environments... all of it.
And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects and cloud environments, so they can prioritize and focus their efforts in the right places.
Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity
For the stories behind the headlines, head to CISOseries.com
Transnational sextortion ring dismantled
TikTok denies breachtok
Cloudflare cuts off Kiwi Farms
Thanks to today’s episode sponsor, Snyk
Developers want to code fast and security wants to ship securely — and they want to do it all from the cloud. That’s why they both choose Snyk. Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.
Code, dependencies, containers, cloud environments... all of it.
And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects and cloud environments, so they can prioritize and focus their efforts in the right places.
Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity
Transnational sextortion ring dismantled
TikTok denies breachtok
Cloudflare cuts off Kiwi Farms
Thanks to today’s episode sponsor, Snyk
Developers want to code fast and security wants to ship securely — and they want to do it all from the cloud. That’s why they both choose Snyk. Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.
Code, dependencies, containers, cloud environments... all of it.
And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects and cloud environments, so they can prioritize and focus their efforts in the right places.
Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity
Federal agencies share supply chain security tips
Apple settles lawsuit with developer over App Store rejections and scams
Hackers were inside Neopets systems for 18 months
Thanks to today’s episode sponsor, Code42
It’s not just about the data leaving your company - what about the data coming in? Along with departing employees, new talent is also actively joining your organization. This poses cybersecurity challenges since they could be knowingly or unknowingly bringing data from their former company into your network.
Code42 Incydr is an Insider Risk Management SaaS that provides a comprehensive understanding of your data exposure and shows which activities require security intervention. Learn more at Code42.com/showme.
For the stories behind the headlines, head to CISOseries.com
Federal agencies share supply chain security tips
Apple settles lawsuit with developer over App Store rejections and scams
Hackers were inside Neopets systems for 18 months
Thanks to today’s episode sponsor, Code42
It’s not just about the data leaving your company - what about the data coming in? Along with departing employees, new talent is also actively joining your organization. This poses cybersecurity challenges since they could be knowingly or unknowingly bringing data from their former company into your network.
Code42 Incydr is an Insider Risk Management SaaS that provides a comprehensive understanding of your data exposure and shows which activities require security intervention. Learn more at Code42.com/showme.
For the stories behind the headlines, head to CISOseries.com
Google launches open-source bug bounty
Ragnar Locker claims attack on airline
Cloudflare won’t terminate services for controversial customers
Thanks to today’s episode sponsor, Code42
Surprise! Surprise! Five years from now, Jamie, who’s resigning today, will ring the NASDAQ bell officially launching her company on the public market. And what you’ll soon realize is that Jamie stole your most valuable data to start her new company. Learn how Code42 Incydr can stop data theft and protect your organizations’ most valuable assets. Visit Code42.com/showme to learn more.
Google Translate app is actually Windows crypto-mining malware
White House to give aviation executives classified cyberthreat briefing
Book distributor Baker & Taylor hit by ransomware
Thanks to our episode sponsor, Code42
Cybersecurity teams are facing unprecedented challenges when it comes to protecting sensitive corporate data from exposure, leak and theft.
In fact, the Code42 Annual Data Exposure Report revealed there’s a 1 in 3 chance that your company will lose IP when an employee quits. To learn more about stopping data leaks with Insider Risk Management visit Code42.com/showme.
For the stories behind the headlines, head to CISOseries.com.
Microsoft warns Iranians using Log4Shell
Montenegro hit with Russian cyberattacks
AlphaBay Turns 1
Thanks to this week's episode sponsor, Code42
Have you been thinking about launching an Insider Risk Management program? You don’t need to be Big Brother to effectively address Insider Risk.
Code42 believes that the Three Es should define any IRM program: expertise, education, and enforcement. Shift your security culture from “watchdog” to “guide dog” and everyone wins. Learn more at Code42.com/showme.
Microsoft warns Iranians using Log4Shell
Montenegro hit with Russian cyberattacks
AlphaBay Turns 1
Thanks to this week's episode sponsor, Code42
Have you been thinking about launching an Insider Risk Management program? You don’t need to be Big Brother to effectively address Insider Risk.
Code42 believes that the Three Es should define any IRM program: expertise, education, and enforcement. Shift your security culture from “watchdog” to “guide dog” and everyone wins. Learn more at Code42.com/showme.
Hackers breach LastPass developer system to steal source code
New Agenda ransomware appears in the threat landscape
Facebook-Cambridge Analytica data breach lawsuit ends in 11th hour settlement
Thanks to this week’s episode sponsor, Code42
It’s not just about the data leaving your company - what about the data coming in? Along with departing employees, new talent is also actively joining your organization. This poses cybersecurity challenges since they could be knowingly or unknowingly bringing data from their former company into your network.
Code42 Incydr is an Insider Risk Management SaaS that provides a comprehensive understanding of your data exposure and shows which activities require security intervention. Learn more at Code42.com/showme.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, John McClure, CISO, Sinclair Broadcast Group
Thanks to today’s episode sponsor, Code42
It’s not just about the data leaving your company – what about the data coming in? Along with departing employees, new talent is also actively joining your organization. This poses cybersecurity challenges since they could be knowingly or unknowingly bringing data from their former company into your network.
Code42 Incydr is an Insider Risk Management SaaS that provides a comprehensive understanding of your data exposure and shows which activities require security intervention. Learn more at Code42.com/showme.
All links and the video of this episode can be found on CISO Series.com
North Korean malware present at Black Hat
Ransomware attacks jump as new malware strains proliferate
Pentagon may require flaw-free software
Thanks to today’s episode sponsor, Code42
It’s not just about the data leaving your company - what about the data coming in? Along with departing employees, new talent is also actively joining your organization. This poses cybersecurity challenges since they could be knowingly or unknowingly bringing data from their former company into your network.
Code42 Incydr is an Insider Risk Management SaaS that provides a comprehensive understanding of your data exposure and shows which activities require security intervention. Learn more at Code42.com/showme
For the stories behind the headlines, head to CISOseries.com.
North Korean malware present at Black Hat
Ransomware attacks jump as new malware strains proliferate
Pentagon may require flaw-free software
Thanks to today’s episode sponsor, Code42
It’s not just about the data leaving your company - what about the data coming in? Along with departing employees, new talent is also actively joining your organization. This poses cybersecurity challenges since they could be knowingly or unknowingly bringing data from their former company into your network.
Code42 Incydr is an Insider Risk Management SaaS that provides a comprehensive understanding of your data exposure and shows which activities require security intervention. Learn more at Code42.com/showme
For the stories behind the headlines, head to CISOseries.com.
Microsoft reveals Nobelium’s MagicWeb
Details emerge on large-scale pro-Western influence campaigns
Stolen NFTs prove big business
Thanks to today’s episode sponsor, Code42
Surprise! Surprise! Five years from now, Jamie, who’s resigning today, will ring the NASDAQ bell officially launching her company on the public market. And what you’ll soon realize is that Jamie stole your most valuable data to start her new company. Learn how Code42 Incydr can stop data theft and protect your organizations’ most valuable assets. Visit Code42.com/showme to learn more.
Microsoft reveals Nobelium’s MagicWeb
Details emerge on large-scale pro-Western influence campaigns
Stolen NFTs prove big business
Thanks to today’s episode sponsor, Code42
Surprise! Surprise! Five years from now, Jamie, who’s resigning today, will ring the NASDAQ bell officially launching her company on the public market. And what you’ll soon realize is that Jamie stole your most valuable data to start her new company. Learn how Code42 Incydr can stop data theft and protect your organizations’ most valuable assets. Visit Code42.com/showme to learn more.
Ex-security chief accuses Twitter of cybersecurity negligence
Ukraine and Poland join forces to counter Russian cyberattacks
Hackers use Binance exec deepfake in crypto exchange scam
Thanks to today’s episode sponsor, Code42
Cybersecurity teams are facing unprecedented challenges when it comes to protecting sensitive corporate data from exposure, leak and theft.
In fact, the Code42 Annual Data Exposure Report revealed there’s a 1 in 3 chance that your company will lose IP when an employee quits. To learn more about stopping data leaks with Insider Risk Management visit Code42.com/showme.
For the stories behind the headlines, head over to CISOseries.com
State-backed attacks excluded from cyber insurance
LockBit hit with DDoS
Cozy Bear using Microsoft accounts to bypass MFA
Thanks to today’s episode sponsor, Code42
Have you been thinking about launching an Insider Risk Management program? You don’t need to be Big Brother to effectively address Insider Risk.
Code42 believes that the Three Es should define any IRM program: expertise, education, and enforcement. Shift your security culture from “watchdog” to “guide dog” and everyone wins. Learn more at Code42.com/showme.
iPhone users urged to update to patch 2 zero-days
Encrypted ZIP files can have two correct passwords
White hat hackers broadcast through decommissioned satellite
Thanks to today’s episode sponsor, Code42
It’s not just about the data leaving your company - what about the data coming in? Along with departing employees, new talent is also actively joining your organization. This poses cybersecurity challenges since they could be knowingly or unknowingly bringing data from their former company into your network.
Code42 Incydr is an Insider Risk Management SaaS that provides a comprehensive understanding of your data exposure and shows which activities require security intervention. Learn more at Code42.com/showme
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, Stephen Harrison, VP Cyber Defense, MGM Resorts
Thanks to today’s episode sponsor, 6clicks
With 6clicks, organizations can manage enterprise risk easier than ever before. 6clicks helps you identify your risks, group them into risk registers, and run risk assessments. It highlights causes and potential impacts, outlines risk treatment plans, and helps you manage the full treatment lifecycle. For more information visit 6clicks.com/cisoseries.
All links and the video of this episode can be found on CISO Series.com
Google blocks largest HTTPS DDoS attack 'reported to date'
Cyber Command loses Moore
A new version of BlackByte offers extortion options
Thanks to today’s episode sponsor, 6clicks
With 6clicks, organizations can manage enterprise risk easier than ever before. 6clicks helps you identify your risks, group them into risk registers, and run risk assessments. It highlights causes and potential impacts, outlines risk treatment plans, and helps you manage the full treatment lifecycle. For more information visit 6clicks.com/cisoseries.
For the stories behind the headlines, head to CISOseries.com.
PyPi packages turn installed apps to backdoors
Project Sugarush targets Israeli shipping
RedAlpha ramps up phishing efforts
Thanks to today’s episode sponsor, 6clicks
Manage the full assessment lifecycle and get your business audit-ready more easily than ever using 6clicks. Identify overlap from completed audits and assessments with other standards and frameworks using Hailey-AI to streamline compliance with multiple audit requirements. With built-in content, organizations can get started on their audit and assessments faster than ever before. For more information visit 6clicks.com/cisoseries.
Oracle begins auditing TikTok's algorithms
Digital Ocean dumps Mailchimp after attack leaked customer data
Signal users exposed in targeted Twilio attack
Thanks to today’s episode sponsor, 6clicks
6clicks is where vulnerability management and GRC unite. With 6licks, organizations can ingest their vulnerabilities from all scanners, link assets to vulnerabilities, raise risks and issues to remediate, and close vulnerabilities as they are remediated – all while informing their risk and compliance posture in a single platform for cohesive reporting. For more information visit 6clicks.com/cisoseries.
For the stories behind the headlines, head to CISOseries.com.
Chat app used as a backdoor
PyPi package drops crytominer
Access to corporate networks sees a value dip
Thanks to today’s episode sponsor, 6clicks
Protect your supply chain from third-party risk with the power of 6clicks. Organizations can better manage their vendor risk by automating the vendor assessment lifecycle and detecting vendor assessment findings. Users can identify and raise risks linked to vendors post-assessment and group them into risk registers. Then, manage, remediate and report on risks directly from 6clicks. For more information visit 6clicks.com/cisoseries.
Ukraine's cyber chief makes surprise visit to Black Hat
Killnet claims to have hacked Lockheed Martin
Starlink successfully hacked using $25 modchip
Thanks to today’s episode sponsor, 6clicks
Identify, track, respond, and remediate issues and incidents from your various GRC workflows with 6clicks. With an issue submission form, 6clicks makes it easy and efficient for employees to submit incidents directly to an incident management team for triaging and response. Use the built-in incident response playbooks, or your own, to standardize incident response across the organization. For more information visit 6clicks.com/cisoseries.
For the stories behind the headlines, head to CISOseries.com
Ukraine's cyber chief makes surprise visit to Black Hat
Killnet claims to have hacked Lockheed Martin
Starlink successfully hacked using $25 modchip
Thanks to today’s episode sponsor, 6clicks
Identify, track, respond, and remediate issues and incidents from your various GRC workflows with 6clicks. With an issue submission form, 6clicks makes it easy and efficient for employees to submit incidents directly to an incident management team for triaging and response. Use the built-in incident response playbooks, or your own, to standardize incident response across the organization. For more information visit 6clicks.com/cisoseries.
For the stories behind the headlines, head to CISOseries.com
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, Jack Kufahl, CISO, Michigan Medicine
Thanks to today’s episode sponsor, Edgescan
Edgescan simplifies Vulnerability Management by delivering a single full-stack solution (SaaS) integrated with world-class security professionals. Instead of managing a plethora of point scanning tools for each layer of the attack surface and squandering precious staff resources manually removing false positives, Edgescan offers automated and accurate contextualized alerts across the entire attack surface into a single source of truth.
All links and the video of this episode can be found on CISO Series.com
Cisco admits corporate network compromised by gang with links to Lapsus$
CISA should split from DHS says Chris Krebs
Ransomware data theft epidemic fueling BEC attacks
Thanks to today’s episode sponsor, Edgescan
Edgescan simplifies Vulnerability Management by delivering a single full-stack solution (SaaS) integrated with world-class security professionals. Instead of managing a plethora of point scanning tools for each layer of the attack surface and squandering precious staff resources manually removing false positives, Edgescan offers automated and accurate contextualized alerts across the entire attack surface into a single source of truth.
For the stories behind the headlines, head to CISOseries.com.
Introducing the Open Cybersecurity Schema Framework
New flaw found in Intel SGX
CISA adds to its Known Exploited Vulnerabilities database
Thanks to today’s episode sponsor, Edgescan
Scalable automated and continuous Attack Surface Management (ASM) and vulnerability detection integrated with a world-class cyber security team provide 100% false-positive-free alerts and expert remediation guidance.
Chinese fraudsters target kids playing online games
Former Twitter employee convicted in Saudi spy case
Facebook divulges data leading to abortion prosecution
Thanks to today’s episode sponsor, Edgescan
Edgescan combines full-stack coverage with integrated reporting and business-level prioritization to deliver a single source of truth for your entire vulnerability management program with zero false positives.
For the stories behind the headlines, head to CISOseries.com
Treasury sanctions Tornado Cash
Twilio confirms hack
Chinese hacking group targets backdoors
Thanks to today’s episode sponsor, Edgescan
Edgescan offers a single platform solution that covers the full stack, from Web Applications to APIs to the Network and data layer. Continuous Attack Surface Management coupled with automated & strategic Pen-testing as a Service (PTaaS) yields fully scalable coverage.
Critical flaws found in US Emergency Alert System
Security experts urge Fick's speedy confirmation as first U.S. cyber ambassador
High-severity bug in Kaspersky VPN client opens door to PC takeover
Thanks to today’s episode sponsor, Edgescan
Edgescan simplifies Vulnerability Management by delivering a single full-stack solution (SaaS) integrated with world-class security professionals. Instead of managing a plethora of point scanning tools for each layer of the attack surface and squandering precious staff resources manually removing false positives, Edgescan offers automated and accurate contextualized alerts across the entire attack surface into a single source of truth.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, Yael Nagler, CISO, Walker & Dunlop
Thanks to this week’s sponsor, HYAS
“Did you know a cybersecurity breach doesn’t have to mean that your business is shut down or your data is stolen? Malware, ransomware, data exfiltration: They all report to a command and control infrastructure to receive instructions.
HYAS’s unrivaled understanding of adversary infrastructure empowers you to cut off threats from their command and control, along with any related infrastructure. Like that old roach motel, hackers can get in, but they can’t communicate out, rendering their attack worthless. When HYAS has your back, you can proactively prevent attacks from being executed — letting your business keep moving full forward. Visit HYAS.com“
All links and the video of this episode can be found on CISO Series.com
Cyberattacks hit Taiwan to coincide with Speaker Pelosi’s visit4
Cisco addresses critical flaws in Small Business VPN routers
DOJ now relies on paper for its most sensitive court documents, official says
Thanks to today’s episode sponsor, HYAS
We know IT and security teams are already overloaded — facing constant pressure to improve security without additional resources. That’s why it’s so important to find solutions that bolster your security, not your workload.
HYAS Protect deploys in under 30 minutes, easily integrates into existing infrastructure, constantly updates with the latest threat intelligence, renders attacks inert (regardless of how they infiltrated your environment), and doesn’t require day-to-day hand-holding — letting you focus on keeping your business moving full forward.
Visit HYAS.com
For the stories behind the headlines, head to CISOseries.com.
Ukraine takes down massive bot farm
Thousands of Solana wallets drained
Semikron hit by cyberattack
Thanks to today’s episode sponsor, HYAS
Cybercriminals try their hardest to cover their tracks, but no matter what, they always leave a trail. HYAS Insight gives you access to all of the data you need to trace an attack back to its source. This helps you map out the complete attack campaign infrastructure, letting you proactively defend against future attacks and even potentially provide key data to law enforcement.
Take your cybersecurity investigations further than you ever thought possible with HYAS Insight.
Visit HYAS.com
US crypto firm hit by $190 million theft
T-Mobile store owner busted running phone unlocking scheme
EU missile maker denies breach but confirms extortion attempt
Thanks to today’s episode sponsor, HYAS
Cybercriminals try their hardest to cover their tracks, but no matter what, they always leave a trail. HYAS Insight gives you access to all of the data you need to trace an attack back to its source. This helps you map out the complete attack campaign infrastructure, letting you proactively defend against future attacks and even potentially provide key data to law enforcement.
Take your cybersecurity investigations further than you ever thought possible with HYAS Insight.
Visit HYAS.com
Akamai disrupts record DDoS in Europe
Australian man faces spyware charges
Meta accused of failing to tackle hate speech in Kenya
Thanks to today’s episode sponsor, HYAS
*Cybercriminals try their hardest to cover their tracks, but no matter what, they always leave a trail. HYAS Insight gives you access to all of the data you need to trace an attack back to its source. This helps you map out the complete attack campaign infrastructure, letting you proactively defend against future attacks and even potentially provide key data to law enforcement.
Take your cybersecurity investigations further than you ever thought possible with HYAS Insight.
Visit HYAS.com*
Huge network of 11,000 fake investment sites targets Europe
DawDropper Android apps serve up banking malware
North Korea-linked SharpTongue spies on email accounts with a malicious browser extension
Thanks to today's episode sponsor, Hyas.
Better production environment security starts with visibility. After all, how can you protect your most valuable asset if you don’t know A: what’s expected and B: when something’s happening that isn’t expected?
This is why HYAS Confront monitors traffic to alert you to anomalies, letting you address risks, threats, and changes, while blocking infiltrations before they become successful attacks.
Don’t just react, take your security back with HYAS. Visit HYAS.com
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, Deneen DeFiore, VP, CISO, United Airlines
Thanks to our show sponsor, Snyk
*Developers want to code fast and security wants to ship securely. And that’s why they both choose Snyk.
Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.
Code, dependencies, containers, cloud infrastructure… all of it.
And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects, so they can prioritize and focus their efforts in the right places.
Developer tested. Security approved. Start your free Snyk account atsnyk.co/cybersecurity.*
All links and the video of this episode can be found on CISO Series.com
Hackers opting for new attack methods after Microsoft blocked macros by default
Microsoft 365 outage knocks down admin center in North America
22 million US health records breached thus far in 2022
Thanks to today’s episode sponsor, Snyk
Developers want to code fast and security wants to ship securely. And that’s why they both choose Snyk.
Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.
Code, dependencies, containers, cloud infrastructure... all of it.
And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects, so they can prioritize and focus their efforts in the right places.
Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity.
For the stories behind the headlines, head to CISOseries.com.
Hackers opting for new attack methods after Microsoft blocked macros by default
Microsoft 365 outage knocks down admin center in North America
22 million US health records breached thus far in 2022
Thanks to today’s episode sponsor, Snyk
Developers want to code fast and security wants to ship securely. And that’s why they both choose Snyk.
Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.
Code, dependencies, containers, cloud infrastructure... all of it.
And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects, so they can prioritize and focus their efforts in the right places.
Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity.
For the stories behind the headlines, head to CISOseries.com.
Microsoft warns of Subzero malware
JusTalk logs leak
The cost of an average data breach
Thanks to today’s episode sponsor, Snyk
Developers want to code fast and security wants to ship securely. And that’s why they both choose Snyk.
Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.
Code, dependencies, containers, cloud infrastructure... all of it.
And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects, so they can prioritize and focus their efforts in the right places.
Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity.
Hacker swipes $6 million from blockchain music platform
Coding error to blame for Rogers outage
US doubles reward for tips on North Korean-backed hackers
Thanks to today’s episode sponsor, Snyk
Developers want to code fast and security wants to ship securely. And that’s why they both choose Snyk.
Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.
Code, dependencies, containers, cloud infrastructure... all of it.
And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects, so they can prioritize and focus their efforts in the right places.
Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity.
For the stories behind the headlines, head to CISOseries.com
Hacker swipes $6 million from blockchain music platform
Coding error to blame for Rogers outage
US doubles reward for tips on North Korean-backed hackers
Thanks to today’s episode sponsor, Snyk
Developers want to code fast and security wants to ship securely. And that’s why they both choose Snyk.
Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.
Code, dependencies, containers, cloud infrastructure... all of it.
And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects, so they can prioritize and focus their efforts in the right places.
Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity.
For the stories behind the headlines, head to CISOseries.com
LockBit hits Italy
Quantum cybersecurity bill heads to the Senate
Windows adds brute force defense
Thanks to today’s episode sponsor, Snyk
Developers want to code fast and security wants to ship securely. And that’s why they both choose Snyk.
Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.
Code, dependencies, containers, cloud infrastructure... all of it.
And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects, so they can prioritize and focus their efforts in the right places.
Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity.
FBI uncovers Chinese and Huawei misdeeds
5.4 million Twitter accounts available for sale
Microsoft warns that new Windows updates may break printing
Thanks to today’s episode sponsor, Snyk
Developers want to code fast and security wants to ship securely. And that’s why they both choose Snyk.
Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.
Code, dependencies, containers, cloud infrastructure... all of it.
And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects, so they can prioritize and focus their efforts in the right places.
Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, Renee Guttmann, Former CISO, Campbell Soup, Coca Cola, Time Warner
Thanks to this week’s sponsor, 6clicks
6clicks is your AI-powered GRC platform, featuring a fully-integrated content library. 6clicks provides organizations with a powerful GRC platform to build highly scalable risk and compliance functions and advisors with the tools to streamline and scale their services, saving everyone enormous time and money. Reimagine risk. Improve cybersecurity. Demonstrate compliance. For more information visit 6clicks.com/cisoseries.
All links and the video of this episode can be found on CISO Series.com
Microsoft Teams outage also takes down Microsoft 365 services
Heatwave forced Google and Oracle to shut down in London
Hackers for hire: adversaries employ “cyber mercenaries”
Thanks to today’s episode sponsor, 6clicks
Experience the magic of Hailey, the 6clicks artificial intelligence engine for risk and compliance. With Hailey, organizations can automatically show cross-compliance between regulations or identify gaps to external compliance requirements in their policies. Eliminate manual and costly risk and compliance processes by joining the hundreds of businesses that trust 6clicks. For more information visit 6clicks.com/cisoseries.
For the stories behind the headlines, head to CISOseries.com.
Microsoft cuts security jobs amidst weakening economy
Is your cute little Neopet leaking your personal data?
Russia disguises malware as Ukrainian app for hacking Russia
Thanks to today’s episode sponsor, 6clicks
The 6clicks GRC solution comes with a fully integrated content library full of hundreds of standards, assessment templates, libraries, playbooks, and more. With the content library included in every 6clicks license, organizations can get started on their GRC implementation faster than ever before. For more information visit 6clicks.com/content.
For the stories behind the headlines, head over to CISOseries.com
Car GPS tracker exposes location data
Russian malware groups spoof pro-Ukraine apps
MacOS backdoor speaks to the cloud
Thanks to today’s episode sponsor, 6clicks
Your GRC solution is only as valuable as the reports it can generate. Provide an exceptional analytics experience for all your GRC stakeholders with the 6clicks reporting suite. Unlock powerful insights and prove compliance using dashboards and charts, pixel perfect reporting, presentations, and data storytelling via LiveDocs. For more information visit 6clicks.com/analytics/overview.
Albania hit with cyberattack
Vendors not patching for speculative execution
DARPA looks into open-source
Thanks to today’s episode sponsor, 6clicks
6clicks has pioneered a unique Hub & Spoke architecture to underpin its AI-powered GRC solution and cater to markets requiring scalable, multi-tenanted GRC. This model enables organizations to deploy multiple, autonomous GRC entities connected to a single hub for roll-up reporting, management, and visibility. For more information visit 6clicks.com/lp-enterprise-hub-spoke.
Dozens of cities and towns are paying tech workers to abandon Silicon Valley
CISA orders agencies to patch new Windows zero-day used in attacks
Password recovery tool infects industrial systems with Sality malware
Thanks to today’s episode sponsor, 6clicks
The 6clicks AI-powered GRC platform with an integrated content library is the most intelligent way to get ISO 27001 certified. It allows you to automate audits, manage risks, track assets, and report in real-time. Join hundreds of businesses that trust 6clicks and start your ISO 27001 journey today. For more information visit 6clicks.com/lp-iso-27001.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, Carla Sweeney, VP Information Security Red Ventures
Thanks to our episode sponsor, Edgescan
Edgescan simplifies Vulnerability Management by delivering a single full-stack solution (SaaS) integrated with world-class security professionals. Instead of managing a plethora of point scanning tools for each layer of the attack surface and squandering precious staff resources manually removing false positives, Edgescan offers automated and accurate contextualized alerts across the entire attack surface into a single source of truth.
All links and the video of this episode can be found on CISO Series.com
Ex-C.I.A. engineer convicted in biggest theft ever of Agency secrets
Chinese hackers targeted U.S. political reporters just ahead of January 6 attack, researchers say
Twitter outage briefly hits thousands
Thanks to today’s episode sponsor, Edgescan
Edgescan simplifies Vulnerability Management by delivering a single full-stack solution (SaaS) integrated with world-class security professionals. Instead of managing a plethora of point scanning tools for each layer of the attack surface and squandering precious staff resources manually removing false positives, Edgescan offers automated and accurate contextualized alerts across the entire attack surface into a single source of truth.
For the stories behind the headlines, head to CISOseries.com.
Microsoft warns of massive phishing operation
Android malware downloaded over 3 million times
More speculative-execution attacks found for x86
Thanks to today’s episode sponsor, Edgescan
Scalable automated and continuous Attack Surface Management (ASM) and vulnerability detection integrated with a world-class cyber security team provide 100% false-positive-free alerts and expert remediation guidance.
FTC is cracking down on false claims of anonymizing data
TikTok halts privacy policy change in Europe
Government contractor pays $9 million over whistleblower allegations
Thanks to today’s episode sponsor, Edgescan
Edgescan combines full-stack coverage with integrated reporting and business-level prioritization to deliver a single source of truth for your entire vulnerability management program with zero false positives.
For the stories behind the headlines, head to CISOseries.com
Ransomware hits French telco
NSO Group acquisition called off
Krebs on Experian security
Thanks to today’s episode sponsor, Edgescan
Edgescan offers a single platform solution that covers the full stack, from Web Applications to APIs to the Network and data layer. Continuous Attack Surface Management coupled with automated & strategic Pen-testing as a Service (PTaaS) yields fully scalable coverage.
China tries to censor what could be biggest data hack in history
Pentagon: We'll pay you if you can find a way to hack us
Tech’s red-hot hiring spree shows signs of cooling
Thanks to today’s episode sponsor, Edgescan
Edgescan simplifies Vulnerability Management by delivering a single full-stack solution (SaaS) integrated with world-class security professionals. Instead of managing a plethora of point scanning tools for each layer of the attack surface and squandering precious staff resources manually removing false positives, Edgescan offers automated and accurate contextualized alerts across the entire attack surface into a single source of truth.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
Cyber Security Headlines – Week in Review – July 4-8, 2022 This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, David Cross, SVP/CISO Oracle SaaS Cloud
Thanks to today’s episode sponsor, Votiro
Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.
All links and the video of this episode can be found on CISO Series.com
Cisco and Fortinet release security patches for multiple products
Canada’s RCMP have been using powerful malware to snoop on people’s communications
Online programming IDEs can be used to launch remote cyberattacks
Thanks to today’s episode sponsor, Votiro
Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.
For the stories behind the headlines, head to CISOseries.com.
Attackers moving off Cobalt Strike
Cyberattacks against law enforcement on the rise
Apple announces lockdown mode
Thanks to today’s episode sponsor, Votiro
Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.
Hacker may have stolen personal data of 1 billion Chinese citizens
Ukrainian police take down phishing gang behind payments scam
NIST unveils ‘quantum-proof’ cryptography algorithms
Thanks to today’s episode sponsor, Votiro
Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.
For the stories behind the headlines, head to CISOseries.com
Jenkins discloses dozens of zero-day bugs in multiple plugins
Rogue HackerOne employee steals bug reports to sell on the side
Patchable and preventable security issues lead causes of Q1 attacks
Thanks to today’s episode sponsor, Votiro
Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.
For the stories behind the headlines, head to CISOseries.com.
A new sophisticated malware is attacking SOHO routers
New study shows over half of employees use prohibited apps
Google battles bots, puts Workspace admins on alert
Thanks to today’s episode sponsor, Optiv
The modern enterprise needs a solution as unique as its business.
*Optiv’s Advanced Detection and Response (ADR) works with your organization to comb through the D&R clutter and find the ideal security solutions for your business. ADR delivers tailored detection and response backed by technology, real-time intel and deep expertise applied at touch. Bottom line: ADR finds and neutralizes threats fast, so you can focus on what matters.
If you’d like to learn more about Optiv ADR, please visit Optiv.com/adr.*
For the stories behind the headlines, head to CISOseries.com.
NATO to create rapid response cyber force
FBI warns of deep fakes for remote work
Ship controls identified as another major attack surface
Thanks to today’s episode sponsor, Optiv
The modern enterprise needs a solution as unique as its business.
*Optiv’s Advanced Detection and Response (ADR) works with your organization to comb through the D&R clutter and find the ideal security solutions for your business. ADR delivers tailored detection and response backed by technology, real-time intel and deep expertise applied at touch. Bottom line: ADR finds and neutralizes threats fast, so you can focus on what matters.
If you’d like to learn more about Optiv ADR, please visit Optiv.com/adr.*
Stolen PII and deepfakes used to apply for tech jobs
Russia fines foreign firms for data violations
Premier League crypto sponsorships expose fans to big losses
Thanks to today’s episode sponsor, Optiv
The modern enterprise needs a solution as unique as its business.
*Optiv’s Advanced Detection and Response (ADR) works with your organization to comb through the D&R clutter and find the ideal security solutions for your business. ADR delivers tailored detection and response backed by technology, real-time intel and deep expertise applied at touch. Bottom line: ADR finds and neutralizes threats fast, so you can focus on what matters.
If you’d like to learn more about Optiv ADR, please visit Optiv.com/adr.*
For the stories behind the headlines, head to CISOseries.com
Ransomware gang launches bug bounty
KillNet claims DDoS on Lithuania
ICS security bill passes House
Thanks to today’s episode sponsor, Optiv
The modern enterprise needs a solution as unique as its business.
*Optiv’s Advanced Detection and Response (ADR) works with your organization to comb through the D&R clutter and find the ideal security solutions for your business. ADR delivers tailored detection and response backed by technology, real-time intel and deep expertise applied at touch. Bottom line: ADR finds and neutralizes threats fast, so you can focus on what matters.
If you’d like to learn more about Optiv ADR, please visit Optiv.com/adr.*
New phishing method bypasses MFA using Microsoft WebView2 apps
Russian threat actors may be behind the explosion at Texas liquefied natural gas plant
Google reveals sophisticated Italian spyware campaign targeting victims in Italy, Kazakhstan
Thanks to today’s episode sponsor, Optiv
The modern enterprise needs a solution as unique as its business.
*Optiv’s Advanced Detection and Response (ADR) works with your organization to comb through the D&R clutter and find the ideal security solutions for your business. ADR delivers tailored detection and response backed by technology, real-time intel and deep expertise applied at touch. Bottom line: ADR finds and neutralizes threats fast, so you can focus on what matters.
If you’d like to learn more about Optiv ADR, please visit Optiv.com/adr*
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, Marnie Wilking, CISO, Wayfair
Thanks to today’s episode sponsor, Optiv
Modernizing your identity control plane from AD to the cloud is complex. Ralph Martino, who is leading the identity and access management (IAM) group for Optiv, discusses what challenges CISOs are facing in today’s ever-changing climate:
• Increasing security
• Decreasing risk
• Lowering cost
Learn more at www.optiv.com/IAM-Microsoft.
All links and the video of this episode can be found on CISO Series.com
Cloud email threats soar 101% in a year
NHS warns of scam COVID-19 text messages
Fancy Bear uses nuke threat lure to exploit 1-click bug
Thanks to today's episode sponsor, Optiv
Modernizing your identity control plane from AD to the cloud is complex. Ralph Martino, who is leading the identity and access management (IAM) group for Optiv, discusses what challenges CISOs are facing in today’s ever-changing climate:
• Increasing security
• Decreasing risk
• Lowering cost
Learn more at www.optiv.com/IAM-Microsoft.
For the stories behind the headlines, head to CISOseries.com.
Daycare apps found insecure
Encryption flaws found in Mega
Microsoft retires cloud facial recognition
Thanks to today's episode sponsor, Optiv
Modernizing your identity control plane from AD to the cloud is complex. Ralph Martino, who is leading the identity and access management (IAM) group for Optiv, discusses what challenges CISOs are facing in today’s ever-changing climate:
• Increasing security
• Decreasing risk
• Lowering cost
Learn more at www.optiv.com/IAM-Microsoft.
Cloudflare outage impacts crypto exchanges
Biden signs a pair of cybersecurity bills
7-zip now supports Windows ‘Mark-of-the-Web’ security feature
Thanks to today's episode sponsor, Optiv
Modernizing your identity control plane from AD to the cloud is complex. Ralph Martino, who is leading the identity and access management (IAM) group for Optiv, discusses what challenges CISOs are facing in today’s ever-changing climate:
• Increasing security
• Decreasing risk
• Lowering cost
Learn more at www.optiv.com/IAM-Microsoft.
For the stories behind the headlines, head to CISOseries.com
Windows downloads blocked in Russia
The importance of receipts
Chrome extensions can be used for fingerprinting
Thanks to today's episode sponsor, Optiv
Modernizing your identity control plane from AD to the cloud is complex. Ralph Martino, who is leading the identity and access management (IAM) group for Optiv, discusses what challenges CISOs are facing in today’s ever-changing climate:
• Increasing security
• Decreasing risk
• Lowering cost
Learn more at www.optiv.com/IAM-Microsoft.
US DoJ announces shut down of Russian RSOCKS Botnet
Experts warn of a new eCh0raix ransomware campaign targeting QNAP NAS
Mixed results for Russia's aggressive Ukraine information war, experts say
Thanks to today's episode sponsor, Optiv
Modernizing your identity control plane from AD to the cloud is complex. Ralph Martino, who is leading the identity and access management (IAM) group for Optiv, discusses what challenges CISOs are facing in today’s ever-changing climate:
• Increasing security
• Decreasing risk
• Lowering cost
Learn more at www.optiv.com/IAM-Microsoft.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, Ariel Weintraub, CISO, MassMutual
Thanks to today’s episode sponsor, Datadog
Check out Datadog‘s on-demand fireside chat with CTO Cormac Brady. Over the course of his 20+ year career at Thomson Reuters, Cormac consistently built bridges between technical teams—and in the process helped teams achieve superior results and earned himself senior leadership positions. Watch now at datadoghq.com/ciso/
All links and the video of this episode can be found on CISO Series.com
House Armed Services chair calls national security software, systems 'too vulnerable'
Microsoft Office 365 AutoSave can assist cloud ransomware attacks
OMIGOD! There’s more to OMIGOD
Thanks to today’s episode sponsor, Datadog
Watch Datadog's on-demand webinar for a 30-minute discussion on driving DevSecOps best practices in the enterprise with CTO Cormac Brady.
Over the course of his 20+ year career at Thomson Reuters, Cormac consistently built bridges between technical teams—and in the process helped teams achieve superior results and earned himself senior leadership positions.
Cormac shares stories and leadership lessons that are applicable to any enterprise technical leader looking to help their firm build and operate services in an increasingly competitive and treacherous digital economy. Watch now at datadoghq.com/ciso/
For the stories behind the headlines, head to CISOseries.com.
Cloudflare repels another record DDoS
Africa’s largest supermarket chain hit with ransomware
Resurgence in travel not ignored by threat actors
Thanks to today’s episode sponsor, Datadog
Check out Datadog's on-demand fireside chat with CTO Cormac Brady. Over the course of his 20+ year career at Thomson Reuters, Cormac consistently built bridges between technical teams—and in the process helped teams achieve superior results and earned himself senior leadership positions. Watch now at datadoghq.com/ciso/
US defense contractor discusses takeover of NSO spyware
DoJ will no longer prosecute ethical hackers
Attack on Kaiser Permanente exposes data of thousands of customers
Thanks to today’s episode sponsor, Datadog
Watch Datadog's on-demand webinar for a 30-minute discussion on driving DevSecOps best practices in the enterprise with CTO Cormac Brady.
Over the course of his 20+ year career at Thomson Reuters, Cormac consistently built bridges between technical teams—and in the process helped teams achieve superior results and earned himself senior leadership positions.
Cormac shares stories and leadership lessons that are applicable to any enterprise technical leader looking to help their firm build and operate services in an increasingly competitive and treacherous digital economy. Watch now at datadoghq.com/ciso/
For the stories behind the headlines, head to CISOseries.com
Leaky continuous integration logs
Exchange servers used to deploy Black Cat
Bluetooth can be used to track phones
Thanks to today’s episode sponsor, Datadog
Check out Datadog's on-demand fireside chat with CTO Cormac Brady. Over the course of his 20+ year career at Thomson Reuters, Cormac consistently built bridges between technical teams—and in the process helped teams achieve superior results and earned himself senior leadership positions. Watch now at datadoghq.com/ciso/
Amazon’s chat app has a child sex abuse problem
Ransomware decryptors now for sale on gaming platform
China’s biggest online influencers go dark
Thanks to today’s episode sponsor, Datadog
Watch Datadog's on-demand webinar for a 30-minute discussion on driving DevSecOps best practices in the enterprise with CTO Cormac Brady.
Over the course of his 20+ year career at Thomson Reuters, Cormac consistently built bridges between technical teams—and in the process helped teams achieve superior results and earned himself senior leadership positions.
Cormac shares stories and leadership lessons that are applicable to any enterprise technical leader looking to help their firm build and operate services in an increasingly competitive and treacherous digital economy. Watch now at datadoghq.com/ciso/
For the stories behind the headlines, head to CISOseries.com
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, Upendra Mardikar, CSO, Snap Finance
Thanks to our sponsor, PlexTrac *PlexTrac is the platform that empowers your offensive security team to spend more time hacking and less time reporting. Build better reports in half the time, centralize your data, maximize your reusable content, and become more efficient and effective. PlexTrac clients report a “5X ROI in 1 year,” a “30% increase in efficiency,” have “cut their reporting cycle by 65%,” and experienced a “18 to 22% time savings per engagement.”
Check out PlexTrac.com/CISOSeries to learn how PlexTrac can help your team deliver results.*
All links and the video of this episode can be found on CISO Series.com
MFA could be long haul for some federal agencies says CISA official
New Emotet variant stealing users' credit card information from Google Chrome
Symantec: More malware operators moving in to exploit Follina
Thanks to today’s episode sponsor, PlexTrac
*PlexTrac is the platform that empowers your offensive security team to spend more time hacking and less time reporting. Build better reports in half the time, centralize your data, maximize your reusable content, and become more efficient and effective. PlexTrac clients report a “5X ROI in 1 year,” a “30% increase in efficiency,” have “cut their reporting cycle by 65%,” and experienced a “18 to 22% time savings per engagement.”
Check out PlexTrac.com/CISOSeries to learn how PlexTrac can help your team deliver results.*
For the stories behind the headlines, head to CISOseries.com.
Lack of reporting hurting the ransomware fight
CISA warns of China-linked network snooping
Personal information marketplace taken down
Thanks to today’s episode sponsor, PlexTrac
*PlexTrac is the platform that empowers your offensive security team to spend more time hacking and less time reporting. Build better reports in half the time, centralize your data, maximize your reusable content, and become more efficient and effective. PlexTrac clients report a “5X ROI in 1 year,” a “30% increase in efficiency,” have “cut their reporting cycle by 65%,” and experienced a “18 to 22% time savings per engagement.”
Check out PlexTrac.com/CISOSeries to learn how PlexTrac can help your team deliver results.*
Passwords are finally dead
Hackers steal credit cards from online gun shops
Shields data breach affects 2 million patients
Thanks to today’s episode sponsor, PlexTrac
The best penetration tests begin and end with PlexTrac. PlexTrac can improve efficiency and effectiveness at every phase of your proactive assessments. By centralizing the data from all your automation tools, cataloging important reusable content for easy access, and promoting communication and visibility at every phase of an assessment, PlexTrac cuts reporting time in half and adds value between reports.
Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the premier pentest reporting and management platform.
For the stories behind the headlines, head to CISOseries.com
The once and future AlphaBay
Karakurt adopts bill collector tactics
China concludes its cybersecurity review of Didi
Thanks to today’s episode sponsor, PlexTrac
*PlexTrac is the platform that empowers your offensive security team to spend more time hacking and less time reporting. Build better reports in half the time, centralize your data, maximize your reusable content, and become more efficient and effective. PlexTrac clients report a “5X ROI in 1 year,” a “30% increase in efficiency,” have “cut their reporting cycle by 65%,” and experienced a “18 to 22% time savings per engagement.”
Check out PlexTrac.com/CISOSeries to learn how PlexTrac can help your team deliver results.*
Evasive phishing mixes reverse tunnels and URL shortening services
Exploit released for Atlassian Confluence RCE bug, patch now
Lawmakers are racing to pass tech antitrust reforms before midterms
Thanks to today’s episode sponsor, PlexTrac
The best penetration tests begin and end with PlexTrac. PlexTrac can improve efficiency and effectiveness at every phase of your proactive assessments. By centralizing the data from all your automation tools, cataloging important reusable content for easy access, and promoting communication and visibility at every phase of an assessment, PlexTrac cuts reporting time in half and adds value between reports.
Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the premier pentest reporting and management platform.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, May 30-June 3, is hosted by Rich Stroffolino with our guest, Steve Zalewski, Co-host, Defense in Depth
Thanks to today’s episode sponsor, Feroot
All links and the video of this episode can be found on CISO Series.com
Leaked Conti chats confirm gang’s ability to conduct firmware-based attacks
Critical UNISOC chip vulnerability affects millions of Android smartphones
ExpressVPN removes servers in India after refusing to comply with government order
Thanks to today’s episode sponsor, Feroot
*Feroot secures client-side web applications so that businesses can deliver a flawless and safe digital user experience to their customers. Inspector and Pageguard, Feroot’s automated data protection solutions, increase code visibility, facilitate threat analysis, and detect and protect from dangerous client-side attacks, such as Magecart, cross-site scripting, e-skimming, and other threats focused on front-end JavaScript and web applications.
Learn more at www.feroot.com.*
For the stories behind the headlines, head to CISOseries.com.
Europol shuts down FluBot
Hive ransomware kicks Costa Rica when its down
CISA issues advisory on voting machine vulnerabilities
Thanks to today’s episode sponsor, Feroot
*Feroot secures client-side web applications so that businesses can deliver a flawless and safe digital user experience to their customers. Inspector and Pageguard, Feroot’s automated data protection solutions, increase code visibility, facilitate threat analysis, and detect and protect from dangerous client-side attacks, such as Magecart, cross-site scripting, e-skimming, and other threats focused on front-end JavaScript and web applications.
Learn more at www.feroot.com.*
Follina vulnerability under active exploitation
Tension inside Google over conduct of fired researcher
IBM to pay $1.6 billion for poaching customer account
Thanks to today’s episode sponsor, Feroot
*Feroot secures client-side web applications so that businesses can deliver a flawless and safe digital user experience to their customers. Inspector and Pageguard, Feroot’s automated data protection solutions, increase code visibility, facilitate threat analysis, and detect and protect from dangerous client-side attacks, such as Magecart, cross-site scripting, e-skimming, and other threats focused on front-end JavaScript and web applications.
Learn more at www.feroot.com.*
For the stories behind the headlines, head to CISOseries.com
China censoring open-source code
Follina zero-day hits Office
EnemyBot botnet acts fast
Thanks to today’s episode sponsor, Feroot
*Feroot secures client-side web applications so that businesses can deliver a flawless and safe digital user experience to their customers. Inspector and Pageguard, Feroot’s automated data protection solutions, increase code visibility, facilitate threat analysis, and detect and protect from dangerous client-side attacks, such as Magecart, cross-site scripting, e-skimming, and other threats focused on front-end JavaScript and web applications.
Learn more at www.feroot.com.*
Pro-Russian hacker group KillNet plans to attack Italy today
Microsoft warns that hackers are using more advanced techniques to steal credit card data
China makes offer to ten nations help to run their cyber-defenses
Thanks to today’s episode sponsor, Feroot
*Feroot secures client-side web applications so that businesses can deliver a flawless and safe digital user experience to their customers. Inspector and Pageguard, Feroot’s automated data protection solutions, increase code visibility, facilitate threat analysis, and detect and protect from dangerous client-side attacks, such as Magecart, cross-site scripting, e-skimming, and other threats focused on front-end JavaScript and web applications.
Learn more at www.feroot.com.*
For the stories behind the headlines, head to CISOseries.com.
Up to 83% of known compromised passwords would satisfy regulatory requirements
Broadcom confirms deal to acquire VMware
Experts warn of rise in ChromeLoader malware
Thanks to today’s episode sponsor, Optiv
Up for a Zero Trust Crash Course? Join our expert, Jerry Chapman, Engineering Fellow at Optiv and author of "Zero Trust Security: An Enterprise Guide," as he delivers the following takeaways:
- An introduction to Zero Trust
- An overview of Optiv’s Zero Trust principles
- How to visualize your Zero Trust journey and place it in the proper context
Catch Jerry's Zero Trust crash course or learn more by going to www.optiv.com/zerotrust.
For the stories behind the headlines, head to CISOseries.com.
Popular open source libraries leaked keys for “research”
DuckDuckGo gives Microsoft a pass on trackers
Microsoft weathers the vulnerability storm
Thanks to today’s episode sponsor, Optiv
Need a guide on your Zero Trust journey? Jerry Chapman, Engineering Fellow at Optiv and author of "Zero Trust Security: An Enterprise Guide" shares the following takeaways:
- The key elements of Zero Trust
- How to visualize your Zero Trust journey and place it in the proper context
- Integrated technologies to drive adaptive processes and a mature security model
Learn more at www.optiv.com/zerotrust.
Interpol warns nation-state malware could become a commodity on dark web soon
General Motors Hit by cyber-attack exposing car owners' personal info
Canada to ban China's Huawei and ZTE from its 5G networks
Thanks to today’s episode sponsor, Optiv
Up for a Zero Trust Crash Course? Join our expert, Jerry Chapman, Engineering Fellow at Optiv and author of "Zero Trust Security: An Enterprise Guide," as he delivers the following takeaways:
- An introduction to Zero Trust
- An overview of Optiv’s Zero Trust principles
- How to visualize your Zero Trust journey and place it in the proper context
Catch Jerry's Zero Trust crash course or learn more by going to www.optiv.com/zerotrust.
For the stories behind the headlines, head to CISOseries.com.
Cyberattack divorces Zola users from registries
A look at the RansomHouse data-extortion operation
Now we have to worry about pre-hijacking attacks
Thanks to today’s episode sponsor, Optiv
Need a guide on your Zero Trust journey? Jerry Chapman, Engineering Fellow at Optiv and author of "Zero Trust Security: An Enterprise Guide" shares the following takeaways:
- The key elements of Zero Trust
- How to visualize your Zero Trust journey and place it in the proper context
- Integrated technologies to drive adaptive processes and a mature security model
Learn more at www.optiv.com/zerotrust.
For the stories behind the headlines, go to CISOseries.com
Ransomware victim trolls hackers with obscene pics
CISOs list top cyber threats to enterprises in 2022
YouTube removes more than 9,000 Ukraine war-related channels
Thanks to today’s episode sponsor, Optiv
Need a guide on your Zero Trust journey? Jerry Chapman, Engineering Fellow at Optiv and author of "Zero Trust Security: An Enterprise Guide" shares the following takeaways:
- The key elements of Zero Trust
- How to visualize your Zero Trust journey and place it in the proper context
- Integrated technologies to drive adaptive processes and a mature security model
Learn more at www.optiv.com/zerotrust.
For the stories behind the headlines, go to CISOseries.com
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, May 16-20, is hosted by Rich Stroffolino with our guest, Jerich Beason, CISO, Commercial Bank, CapitalOne
Thanks to today's episode sponsor, Torq
All links and the video of this episode can be found on CISO Series.com
Greenland health services limited from cyberattacks
Phishing attacks surge in Q1
Google details 2021 zero-days
And now let’s thank today’s sponsor, Torq
Myth 5: You Should Automate All Security Processes
False. You should automate routine, repetitive tasks that are not subject to much conditional variance. But workflows that can’t be reliably managed by automation tools, such as assessing the financial consequences of a breach or determining whether a security incident should trigger an application rollback, should remain the domain of humans. To learn more about the realities of automation, head to torq.io.
VMware bugs abused to deliver Mirai malware
Microsoft to debut of zero trust GDAP tool
Bank of Zambia refuses to pay ransom to cyberattack group Hive
And now let’s thank today’s sponsor, Torq
Myth 4: Automation Will Replace Skilled Security Professionals
Not true. Any business that attempts to automate security will quickly find that most high-stakes security issues are far too complex to be detected and remediated by automation tools alone. Human security professionals need to take the lead delivering nuanced insight about the business impact of a large-scale breach. To learn more about the realities of automation, head to torq.io.
For the stories behind the headlines, head to CISOseries.com.
Buffalo massacre suspect signaled plans on Discord for months
Google faces litigation for unauthorised use of medical records
Venezuelan doctor accused of developing and distributing ransomware
And now let’s thank today’s sponsor, Torq
Myth 3: Only Enterprises Need Security Automation
Debunked. While enterprises with thousands of endpoints and sprawling teams certainly need automation, businesses of all sizes face challenges related to other forms of scale when it comes to security. For instance, there are about 1 billion known types of malware in existence, and they imperil businesses of all sizes equally. To learn more about the realities of automation, head to torq.io.
For the stories behind the headlines, head to CISOseries.com
Costa Rican ransomware rhetoric somehow gets uglier
DOJ files its first criminal cryptocurrency sanctions case
Trying to fix open source supply chain security
And now let’s thank today’s sponsor, Torq
Myth 2: Security Automation Is Just a New Term for Automated Security Testing
Wrong. While scanning and testing may be one example of a security automation use case, it’s hardly the only one. Automation can be used to do things like help manage complex security workflows and optimize collaboration between different stakeholders. These are tasks that were not traditionally automated. To learn more about the realities of automation, head to torq.io.
Ukraine CERT-UA warns of new attacks launched by Russia-linked Armageddon APT
Microsoft fixes new PetitPotam Windows NTLM relay attack vector
Hackers are exploiting critical bug in Zyxel firewalls and VPNs
And now let’s thank today’s sponsor, Torq
Myth 1: Automation Is Only a Reactive Part of SecOps
Incorrect. Proactive management of security incidents is just as important, like automatically scanning IaC configurations to detect vulnerabilities, automating collaboration between devs, IT ops and SecOps to prevent risks before they’re threats. To learn more about the realities of automation, head to torq.io.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, May 9-13, is hosted by Rich Stroffolino with our guest, Rich Lindberg, CISO, JAMS
Thanks to our sponsor, Datadog
Break down silos between DevOps and Security teams to enable collaboration and strengthen the security of your environment. In this on-demand webinar, hear from one of Datadog’s engineers on how teams can speed up investigations by assessing security and observability data using Datadog’s unified platform to reduce security threats by detecting vulnerabilities.
Watch the on-demand webinar now to learn how to get full-stack security for your production environment at datadoghq.com/ciso/
All links and the video of this episode can be found on CISO Series.com
Google will use mobile devices to thwart phishing attacks
CISA urges organizations to patch actively exploited F5 BIG-IP vulnerability
Kick China off social media, says tech governance expert
Thanks to our episode sponsor, Datadog
Break down silos between DevOps and Security teams to enable collaboration and strengthen the security of your environment. In this on-demand webinar, hear from one of Datadog’s engineers on how teams can speed up investigations by assessing security and observability data using Datadog’s unified platform to reduce security threats by detecting vulnerabilities.
Watch the on-demand webinar now to learn how to get full-stack security for your production environment at datadoghq.com/ciso/
For the stories behind the headlines, head to CISOseries.com.
Old botnets are new again
Meta withdraws Oversight Board guidance request
EU proposes new CSAM rules
Thanks to our episode sponsor, Datadog
In this on-demand webinar, you’ll learn how to best utilize the suite of Datadog Cloud Security products to identify the root cause of an attack and how a unified platform provides real-time threat-detection and continuous configuration audits across applications, hosts, containers and cloud infrastructure.
Built on top of the observability platform, Datadog brings unprecedented integration between security and devops aligned to shared organizational goals.
Watch the on-demand webinar now to learn how to get full-stack security for your production environment at datadoghq.com/ciso/
Russian TV hacked on Victory Day
US pledges to help Ukraine keep internet and lights running
Pentagon’s concerns China may prompt vetting startups
Thanks to our episode sponsor, Datadog
In this on-demand webinar, you’ll learn how to best utilize the suite of Datadog Cloud Security products to identify the root cause of an attack and how a unified platform provides real-time threat-detection and continuous configuration audits across applications, hosts, containers and cloud infrastructure.
Built on top of the observability platform, Datadog brings unprecedented integration between security and devops aligned to shared organizational goals.
Watch the on-demand webinar now to learn how to get full-stack security for your production environment at datadoghq.com/ciso/
Ransomware state of emergency in Costa Rica
Microsoft launches service to fill the cyber skills gap
College closes permanently due to ransomware
Thanks to our episode sponsor, Datadog
Break down silos between DevOps and Security teams to enable collaboration and strengthen the security of your environment. In this on-demand webinar, hear from one of Datadog’s engineers on how teams can speed up investigations by assessing security and observability data using Datadog’s unified platform to reduce security threats by detecting vulnerabilities.
Watch the on-demand webinar now to learn how to get full-stack security for your production environment at datadoghq.com/ciso/
Google Play now blocks paid app downloads, updates in Russia
NIST releases updated guidance for defending against supply-chain attacks
US State Department offering $10 million reward for information about Conti members
Thanks to our episode sponsor, Datadog
In this on-demand webinar, you’ll learn how to best utilize the suite of Datadog Cloud Security products to identify the root cause of an attack and how a unified platform provides real-time threat-detection and continuous configuration audits across applications, hosts, containers and cloud infrastructure.
Built on top of the observability platform, Datadog brings unprecedented integration between security and devops aligned to shared organizational goals.
Watch the on-demand webinar now to learn how to get full-stack security for your production environment at datadoghq.com/ciso/
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, May 2-6, is hosted by Rich Stroffolino with our guest, Shawn Bowen, CISO, World Fuel Services
Thanks to our episode sponsor, Censys
Why Censys? Our Attack Surface Management tool is designed from the ground up to seamlessly integrate with existing security workflows. It’s the only ASM tool that discovers modern cloud specific assets like storage buckets and our scanning platform finds more than 85% more services than our nearest competitor. Start with Censys at censys.io.
All links and the video of this episode can be found on CISO Series.com
Decade-old bugs discovered in Avast, AVG antivirus software
Thailand and Hong Kong Banks used most in BEC
Every ISP in the US must block these 3 pirate streaming services
Thanks to today's episode sponsor, Censys
Why Censys? Our Attack Surface Management tool is designed from the ground up to seamlessly integrate with existing security workflows. It’s the only ASM tool that discovers modern cloud specific assets like storage buckets and our scanning platform finds more than 85% more services than our nearest competitor. Start with Censys at censys.io.
For the stories behind the headlines, head to CISOseries.com.
CuckooBees campaign stings targets for years
Health and Human Services hammered over security
Docker images used to DDoS Russian sites
Thanks to today's episode sponsor, Censys
Censys’ Attack Surface Management tool discovers and inventories all Internet-facing assets including traditional assets like hosts, IPs, and cloud services like storage buckets across all accounts and networks. ASM gives you a continuous picture of your attack surface. Start with Censys at censys.io.
Google claims to have blocked billions of malicious app downloads
NortonLifeLock willfully infringed malware patents
Former eBay exec pleads guilty to cyber stalking
Thanks to today's episode sponsor, Censys
Tom the CTO can’t go into the boardroom unprepared. It’s his job to know all the risks to his company – especially the one that could land him on the front page of the newspaper. His best bet for survival is staying ahead of the most critical threats. Tom, you can be that source of truth; start with Censys at censys.io right now.
For the stories behind the headlines, head to CISOseries.com
Solana network goes dark after bot swarm
The spyware in Spain falls mostly on the politicians
Security isn’t top of mind for mental health apps
Thanks to today's episode sponsor, Censys
All Pat the Security Practitioner wants is to do a good job and be the frontline in keeping his company safe. He’s got great tools, but nothing that can show him if there are company assets that have somehow made their way onto the internet. If only Pat knew about Censys’ Attack Surface Management tool. Now you do – start with Censys at censys.io.
Top 15 exploited security vulnerabilities in 2021
India gives orgs 6 hours to report cyber incidents
The White House wants more powers to crack down on rogue drones
Thanks to today's episode sponsor, Censys
What Chris the CISO wants is to protect against revenue loss and damage to his company’s brand from data breaches and compliance failures. But he’s got a blind spot around his internet exposure. What assets are out there on the internet that his team doesn’t know about? Well, Chris, it’s simple – start with Censys at censys.io.
For the stories behind the headlines, visit CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines - Week in Review, Apr 25-29, is hosted by Rich Stroffolino with our guest, Hadas Cassorla, CISO, M1 Financial
Thanks to our episode sponsor, Feroot
All links and the video of this episode can be found on CISO Series.com
Global security spending set to hit $198bn by 2025
New malware loader Bumblebee adopted by known ransomware access brokers
Cloudflare thwarts record DDoS attack
Thanks to today’s episode sponsor, Feroot
Feroot secures client-side web applications so that businesses can deliver a flawless and safe digital user experience to their customers.
Inspector and Pageguard, Feroot’s automated data protection solutions, increase code visibility, facilitate threat analysis, and detect and protect from dangerous client-side attacks, such as Magecart, cross-site scripting, e-skimming, and other threats focused on front-end JavaScript and web applications.
Learn more at www.feroot.com.
For the stories behind the headlines, head to CISOseries.com.
Russia experiences hacks at scale
State Department puts a price on NetPetya’s head
Two-thirds of organizations hit with ransomware
Thanks to today’s episode sponsor, Feroot
Feroot secures client-side web applications so that businesses can deliver a flawless and safe digital user experience to their customers.
Inspector and Pageguard, Feroot’s automated data protection solutions, increase code visibility, facilitate threat analysis, and detect and protect from dangerous client-side attacks, such as Magecart, cross-site scripting, e-skimming, and other threats focused on front-end JavaScript and web applications.
Learn more at www.feroot.com.
Elon Musk’s Twitter takeover could be bad for security and privacy
Stormous Ransomware targets Coca Cola
US offers $10 million reward for help locating Russian hackers
Thanks to today’s episode sponsor, Feroot
Feroot secures client-side web applications so that businesses can deliver a flawless and safe digital user experience to their customers.
Inspector and Pageguard, Feroot’s automated data protection solutions, increase code visibility, facilitate threat analysis, and detect and protect from dangerous client-side attacks, such as Magecart, cross-site scripting, e-skimming, and other threats focused on front-end JavaScript and web applications.
Learn more at www.feroot.com.
For the stories behind the headlines, head to CISOseries.com.
Mandiant finds record zero-days in 2021
Bored Ape Yacht Club hacked
Oracle patches critical Java vulnerability
Thanks to today’s episode sponsor, Feroot
*Feroot secures client-side web applications so that businesses can deliver a flawless and safe digital user experience to their customers.*
Inspector and Pageguard, Feroot’s automated data protection solutions, increase code visibility, facilitate threat analysis, and detect and protect from dangerous client-side attacks, such as Magecart, cross-site scripting, e-skimming, and other threats focused on front-end JavaScript and web applications.
Learn more at www.feroot.com.
Hackers find 122 vulnerabilities, 27 deemed critical, during first round of DHS bug bounty program
Anonymous has leaked 5.8 TB of Russian data since declaring cyber war
AWS's Log4j patches blew holes in its own security
Thanks to today’s episode sponsor, Feroot
Feroot secures client-side web applications so that businesses can deliver a flawless and safe digital user experience to their customers.
Inspector and Pageguard, Feroot’s automated data protection solutions, increase code visibility, facilitate threat analysis, and detect and protect from dangerous client-side attacks, such as Magecart, cross-site scripting, e-skimming, and other threats focused on front-end JavaScript and web applications.
Learn more at www.feroot.com.
For the stories behind the headlines, head to CISOseries.com.
Critical chipset bugs open millions of Android devices to remote spying
New Five Eyes alert warns of Russian threats targeting critical infrastructure
Machine-learning models vulnerable to undetectable backdoors
And here’s a word from our sponsor, Votiro
Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.
For the stories behind the headlines, head to CISOseries.com.
Okta reports on Lapsus$ breach
Popular VPNs use risky certificates
Project Zero disclosed a new vulnerability record
And here’s a word from our sponsor, Votiro
Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.
LinkedIn is now the most popular phish bait
Lenovo patches firmware vulnerabilities impacting millions of users
Ukraine war stokes internet connectivity concerns in Taiwan
And here’s a word from our sponsor, Votiro
Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.
For the stories behind the headlines, head to CISOseries.com
Catalan leaders targeted by NSO spyware
Researchers share a deep dive into PYSA ransomware operations
Most security teams feeling the talent shortage
And here’s a word from our sponsor, Votiro
Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.
Microsoft: Office 2013 will reach end of support in April 2023
Stolen OAuth tokens used to download data from dozens of organizations, GitHub warns
Mute button in conferencing apps may not actually mute your mic
And here’s a word from our sponsor, Votiro
Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.
For the stories behind the headlines, head to CISOseries.com.
Data breach disclosures surge 14% in Q1 2022
Windows 11 tool to add Google Play secretly installed malware
DHS investigators say they foiled cyberattack on undersea internet cable in Hawaii
Thanks to our episode sponsor, Code42
Have you been thinking about launching an Insider Risk Management program? You don’t need to be Big Brother to effectively address Insider Risk.
Code42 believes that the Three Ts should define any IRM program: transparency, training, and technology. Shift your security culture from “watchdog” to “guide dog” and everyone wins. Learn more at Code42.com/showme.
For the stories behind the headlines, head to CISOseries.com.
Industrial cybersecurity companies form coalition
Microsoft disrupts ZLoader
T-Mobile hired someone to get their data back
Thanks to our episode sponsor, Code42
It’s not just about the data leaving your company - what about the data coming in? Along with departing employees, new talent is also actively joining your organization. This poses cybersecurity challenges since they could be knowingly or unknowingly bringing data from their former company into your network.
Code42 Incydr is an Insider Risk Management SaaS that provides a comprehensive understanding of your data exposure and shows which activities require security intervention. Learn more at Code42.com/showme.
RaidForums hacker marketplace shut down in cross-border law enforcement operation
Sandworm hackers fail to take down Ukrainian energy provider
CISA warns of Russian state hackers exploiting WatchGuard bug
Thanks to our episode sponsor, Code42
Surprise! Surprise! Five years from now, Jamie, who’s resigning today, will ring the NASDAQ bell officially launching her company on the public market. And what you’ll soon realize is that Jamie stole your most valuable data to start her new company. Learn how Code42 Incydr can stop data theft and protect your organizations’ most valuable assets. Visit Code42.com/showme to learn more.
For the stories behind the headlines, head to CISOseries.com.
NSO Group spyware reportedly used against European Commission
The malware is coming from inside the phone
OpenSSH gets ready for quantum computing
Thanks to our episode sponsor, Code42
Cybersecurity teams are facing unprecedented challenges when it comes to protecting sensitive corporate data from exposure, leak and theft.
In fact, the Code42 Annual Data Exposure Report revealed there’s a 1 in 3 chance that your company will lose IP when an employee quits. To learn more about stopping data leaks with Insider Risk Management visit Code42.com/showme.
New Meta information stealer distributed in malspam campaign
NB65 group targets Russia with a modified version of Conti’s ransomware
Elon Musk unveils vision for Twitter after joining board
Thanks to our episode sponsor, Code42
Have you been thinking about launching an Insider Risk Management program? You don’t need to be Big Brother to effectively address Insider Risk.
Code42 believes that the Three Ts should define any IRM program: transparency, training, and technology. Shift your security culture from “watchdog” to “guide dog” and everyone wins. Learn more at Code42.com/showme.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, Apr 4-8, is hosted by Rich Stroffolino with our guest, Brett Conlon, CISO, American Century Investments
Thanks to our sponsor, Code42
*It’s not just about the data leaving your company – what about the data coming in? Along with departing employees, new talent is also actively joining your organization. This poses cybersecurity challenges since they could be knowingly or unknowingly bringing data from their former company into your network.
Code42 Incydr is an Insider Risk Management SaaS that provides a comprehensive understanding of your data exposure and shows which activities require security intervention. Learn more at Code42.com/showme.*
Newly discovered flaw could allow hacking of Samsung Android devices
Adobe Creative Cloud Experience makes malware easier to hide
Parrot redirect service infects 16,500 sites to push malware
Thanks to our episode sponsor, Code42
*It’s not just about the data leaving your company - what about the data coming in? Along with departing employees, new talent is also actively joining your organization. This poses cybersecurity challenges since they could be knowingly or unknowingly bringing data from their former company into your network.
Code42 Incydr is an Insider Risk Management SaaS that provides a comprehensive understanding of your data exposure and shows which activities require security intervention. Learn more at Code42.com/showme.*
For the stories behind the headlines, head to CISOseries.com.
US disrupted Russian botnet
Twitter shadowbans Russian government accounts
DOJ charges Russian national with operating Hydra
Thanks to our episode sponsor, Code42
Surprise! Surprise! Five years from now, Jamie, who’s resigning today, will ring the NASDAQ bell officially launching her company on the public market. And what you’ll soon realize is that Jamie stole your most valuable data to start her new company. Learn how Code42 Incydr can stop data theft and protect your organizations’ most valuable assets. Visit Code42.com/showme to learn more.
Germany takes down world's largest darknet market
Anonymous leaks personal details of Russian soldiers
CISA adds Spring4Shell to list of exploited vulnerabilities
Thanks to our episode sponsor, Code42
Cybersecurity teams are facing unprecedented challenges when it comes to protecting sensitive corporate data from exposure, leak and theft.
In fact, the Code42 Annual Data Exposure Report revealed there’s a 1 in 3 chance that your company will lose IP when an employee quits. To learn more about stopping data leaks with Insider Risk Management visit Code42.com/showme.
For the stories behind the headlines, visit CISOseries.com
Russian secret police exposed in data leak
MailChimp hit with breach
The Bureau of Cyberspace and Digital Policy goes live
Thanks to our episode sponsor, Code42
Have you been thinking about launching an Insider Risk Management program? You don’t need to be Big Brother to effectively address Insider Risk.
Code42 believes that the Three Ts should define any IRM program: transparency, training, and technology. Shift your security culture from “watchdog” to “guide dog” and everyone wins. Learn more at Code42.com/showme.
New Borat remote access malware is no laughing matter
Apple rushes out patches for 0-days in MacOS, iOS
National Security Agency employee indicted for 'leaking top secret info'
Thanks to our episode sponsor, Code42
*It’s not just about the data leaving your company - what about the data coming in? Along with departing employees, new talent is also actively joining your organization. This poses cybersecurity challenges since they could be knowingly or unknowingly bringing data from their former company into your network.
Code42 Incydr is an Insider Risk Management SaaS that provides a comprehensive understanding of your data exposure and shows which activities require security intervention. Learn more at Code42.com/showme.*
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, Mar 28-Apr 1, is hosted by Rich Stroffolino with our guest, Fredrick Lee, CISO, Gusto
Thanks to our episode sponsor, Varonis
All links and the video of this episode can be found on CISO Series.com
Palo Alto Networks error exposed customer support cases, attachments
New AcidRain data wiper malware targets modems and routers
Remote code execution flaws in Spring and Spring Cloud frameworks put Java apps at risk
Thanks to our episode sponsors, Varonis
Varonis will help you get meaningful data security results faster than you thought possible. Protect sensitive data, detect sophisticated threats, and streamline privacy and compliance. Visit www.varonis.com/cisoseries for a demo of Varonis’ leading data security platform.
For the stories behind the headlines, head to CISOseries.com.
Hackers abusing the power of subpoena
Lapsus$ claims hack of Globant
Brian Krebs sued by Ubiquiti for defamation
Thanks to our episode sponsors, Varonis
The first time we got hit with ransomware it took us weeks to recover. The second time we got hit, it took us two hours. Why? Because we had Varonis. Varonis reduces the ransomware blast radius and monitors our most important data, automatically. Hear more at www.varonis.com/cisoseries.
Ukraine destroys panic-spreading bot farms
Yandex is sending iOS user data to Russia
Ronin Network victimized in record-breaking crypto heist
Thanks to our episode sponsors, Varonis
Varonis will help you get meaningful data security results faster than you thought possible. Protect sensitive data, detect sophisticated threats, and streamline privacy and compliance. Visit www.varonis.com/cisoseries for a demo of Varonis’ leading data security platform.
For the stories behind the headlines, visit CISOseries.com.
Ukraine ISP taken down by cyber attack
Windows can now block drivers
Deepfakes take a turn for the banal
Thanks to our episode sponsors, Varonis
What is your ransomware blast radius? The average user can access 17 million files. Varonis reduces your blast radius in days, not years. Combined with advanced detection that monitors every file touch, ransomware doesn’t stand a chance. Learn more at www.varonis.com/cisoseries.
Critical Sophos Firewall vulnerability allows remote code execution
Okta: "We made a mistake" delaying the Lapsus$ hack disclosure
CISA adds 66 new flaws to the Known Exploited Vulnerabilities Catalog
Thanks to our episode sponsors, Varonis
On average, an employee can access 17 million files on day one. Varonis will show you where critical data is vulnerable, detect anomalies, and automatically right-size privileges to get you to “Zero Trust.” Their data security platform can test your ransomware readiness and show you where you stack up. Learn more at www.varonis.com/cisoseries.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, Mar 21-25, is hosted by Rich Stroffolino with our guest, John Prokap, CISO, Success Academy Charter Schools
Thanks to our episode sponsor, Varonis
Customer: "The first time we got hit with ransomware it took us weeks to recover. The second time we got hit, it took us two hours. Why? Because we had Varonis. Varonis reduces the ransomware blast radius and monitors our most important data, automatically." Hear more at www.varonis.com/cisoseries.
All links and the video of this episode can be found on CISO Series.com
UK police arrest 7 people in connection with Lapsus$
North Korean hackers exploit Chrome zero-day weeks before patch
Anonymous claims to have hacked the Central Bank of Russia
Thanks to our episode sponsor, Varonis
The first time we got hit with ransomware it took us weeks to recover. The second time we got hit, it took us two hours. Why? Because we had Varonis. Varonis reduces the ransomware blast radius and monitors our most important data, automatically. Hear more at www.varonis.com/cisoseries.
For the stories behind the headlines, head to CISOseries.com.
Microsoft expands program to fill cyber skills gap
Cyber Crime Losses Up 64% in 2021
Microsoft confirms Lapsus$ breach
Thanks to our episode sponsor, Varonis
What is your ransomware blast radius? The average employee can access 17 million files they don’t need, and only a handful live on their laptop. Protect your data from the inside out and detect early signs of ransomware – automatically with Varonis. Visit www.varonis.com/cisoseries.
Ransomware attack on Okta leads to data breach
Lapsus$ leaks 37GB of Microsoft source code
Anonymous hacks Nestlè for operating in Russia
Thanks to our episode sponsor, Varonis
Varonis will help you get meaningful data security results faster than you thought possible. Protect sensitive data, detect sophisticated threats, and streamline privacy and compliance. Visit www.varonis.com/cisoseries for a demo of Varonis’ leading data security platform.
For the stories behind the headlines, visit CISOseries.com
Ransomware puts the breaks on Bridgestone
Phishing with browser-in-a-browser attacks
Conti Leaks leaks Conti code
Thanks to our episode sponsor, Varonis
What is your ransomware blast radius? The average user can access 17 million files. Varonis reduces your blast radius in days, not years. Combined with advanced detection that monitors every file touch, ransomware doesn’t stand a chance. Learn more at www.varonis.com/cisoseries.
CISA, FBI tell satellite communications network owners to watch out for hacks after Ukraine attack
Hackers claim to breach TransUnion South Africa with 'Password' password
Developer sabotages own npm module prompting open-source supply chain security questions
Thanks to our episode sponsor, Varonis
On average, an employee can access 17 million files on day one. Varonis will show you where critical data is vulnerable, detect anomalies, and automatically right-size privileges to get you to “Zero Trust.” Their data security platform can test your ransomware readiness and show you where you stack up. Learn more at www.varonis.com/cisoseries.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, Mar 14-18, is hosted by David Spark with our guest, Eric Hussey, CISO, Aptiv
Thanks to our episode sponsor, Varonis
The first time we got hit with ransomware it took us weeks to recover. The second time we got hit, it took us two hours. Why? Because we had Varonis. Varonis reduces the ransomware blast radius and monitors our most important data, automatically. Hear more at www.varonis.com/cisoseries.
All links and the video of this episode can be found on CISO Series.com
Thanks to our episode sponsor, Varonis
The first time we got hit with ransomware it took us weeks to recover. The second time we got hit, it took us two hours. Why? Because we had Varonis. Varonis reduces the ransomware blast radius and monitors our most important data, automatically. Hear more at www.varonis.com/cisoseries.
Phony Instagram ‘support staff’ emails hit insurance company
Facebook hit with $18.6 million GDPR fine over 12 data breaches in 2018
Microsoft Defender tags Office updates as ransomware activity
Thanks to our episode sponsor, Varonis
What is your ransomware blast radius? The average employee can access 17 million files they don’t need, and only a handful live on their laptop. Protect your data from the inside out and detect early signs of ransomware – automatically with Varonis. Visit www.varonis.com/cisoseries.
For the stories behind the headlines, head to CISOseries.com.
More destructive wiper malware strikes Ukraine
German security agency recommends replacing Kaspersky antivirus
HackerOne apologizes to Ukrainian hackers for blocking payouts
Thanks to our episode sponsor, Varonis
Varonis will help you get meaningful data security results faster than you thought possible. Protect sensitive data, detect sophisticated threats, and streamline privacy and compliance. Visit www.varonis.com/cisoseries for a demo of Varonis’ leading data security platform.
For the stories behind the headlines, visit CISOseries.com
Ukraine’s IT army hit with malware
Mobile endpoints see a lot of malicious apps
AMD vulnerable to Spectre v2
Thanks to our episode sponsor, Varonis
What is your ransomware blast radius? The average user can access 17 million files. Varonis reduces your blast radius in days, not years. Combined with advanced detection that monitors every file touch, ransomware doesn’t stand a chance. Learn more at www.varonis.com/cisoseries.
Ubisoft changes employee passwords after “cyber security incident”
Cyber Command chief tells Congress chip shortage has national security implications
LockBit claims hack on Bridgestone tires
Thanks to our episode sponsor, Varonis
On average, an employee can access 17 million files on day one. Varonis will show you where critical data is vulnerable, detect anomalies, and automatically right-size privileges to get you to “Zero Trust.” Their data security platform can test your ransomware readiness and show you where you stack up. Learn more at www.varonis.com/cisoseries.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, Mar 7 – 11, is hosted by Rich Stroffolino with our guest, Anshu Gupta, Investor, Silicon Valley CISO Investments
Thanks to our sponsor, Torq
Security Automation Myth 5: You Should Automate All Security Processes
False. You should automate routine, repetitive tasks that are not subject to much conditional variance. But workflows that can’t be reliably managed by automation tools, such as assessing the financial consequences of a breach or determining whether a security incident should trigger an application rollback, should remain the domain of humans. To learn more about the realities of automation, head to torq.io.
All links and the video of this episode can be found on CISO Series.com
Russia creates its own TLS certificate authority to bypass sanctions
Online sleuths are using face recognition to ID Russian soldiers
Basic text-color trick can fool phishing filters
There are many misconceptions about security automation, so today's episode sponsor Torq is debunking a security automation myth each day this week.
Myth 5: You Should Automate All Security Processes
False. You should automate routine, repetitive tasks that are not subject to much conditional variance. But workflows that can’t be reliably managed by automation tools, such as assessing the financial consequences of a breach or determining whether a security incident should trigger an application rollback, should remain the domain of humans. To learn more about the realities of automation, head to torq.io.
For the stories behind the headlines, head to CISOseries.com.
Chipmakers warn of new speculative execution bugs
US worked to shore up Ukraine’s cyber defense in 2021
Twitter Tor service launches
There are many misconceptions about security automation, so today's episode sponsor Torq is debunking a security automation myth each day this week.
Myth 4: Automation Will Replace Skilled Security Professionals
Not true. Any business that attempts to automate security will quickly find that most high-stakes security issues are far too complex to be detected and remediated by automation tools alone. Human security professionals need to take the lead delivering nuanced insight about the business impact of a large-scale breach. To learn more about the realities of automation, head to torq.io.
Google to purchase cybersecurity firm Mandiant for $5.4 billion
Security vendors help infrastructure orgs protect against Russian cyberattacks
Russian VPN demand soars amidst social media crackdown
There are many misconceptions about security automation, so today's episode sponsor Torq is debunking a security automation myth each day this week.
Myth 3: Only Enterprises Need Security Automation
Debunked. While enterprises with thousands of endpoints and sprawling teams certainly need automation, businesses of all sizes face challenges related to other forms of scale when it comes to security. For instance, there are about 1 billion known types of malware in existence, and they imperil businesses of all sizes equally. To learn more about the realities of automation, head to torq.io.
For the stories behind the headlines, head over to CISOseries.com
Leaked Nvidia data used in malware
Russia says it's okay to download a car
Sharkbot takes a bite out of the Play Store
There are many misconceptions about security automation, so today's episode sponsor Torq is debunking a security automation myth each day this week.
Myth 2: Security Automation Is Just a New Term for Automated Security Testing
Wrong. While scanning and testing may be one example of a security automation use case, it’s hardly the only one. Automation can be used to do things like help manage complex security workflows and optimize collaboration between different stakeholders. These are tasks that were not traditionally automated. To learn more about the realities of automation, head to torq.io.
Charities and NGOs that provide support to Ukraine hit by malware
'Most advanced' China-linked backdoor ever raises alarms for cyber-espionage investigators
Hackers allegedly leak Samsung data, source code
There are many misconceptions about security automation, so today's episode sponsor Torq is debunking a security automation myth each day this week.
Myth 1: Automation Is Only a Reactive Part of SecOps
Incorrect. Proactive management of security incidents is just as important, like automatically scanning IaC configurations to detect vulnerabilities, automating collaboration between devs, IT ops and SecOps to prevent risks before they’re threats. To learn more about the realities of automation, head to torq.io.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, Feb 28-Mar 4, is hosted by Rich Stroffolino with our guest, Ody Lupescu, CISO, Ethos Life
Thanks to our episode sponsor, Torq
There are many misconceptions about security automation, so Torq is debunking a security automation myth each day this week.
Myth 5: You Should Automate All Security Processes
False. You should automate routine, repetitive tasks that are not subject to much conditional variance. But workflows that can’t be reliably managed by automation tools, such as assessing the financial consequences of a breach or determining whether a security incident should trigger an application rollback, should remain the domain of humans. To learn more about the realities of automation, head to torq.io.
All links and the video of this episode can be found on CISO Series.com
Cyberattack attempts on Ukraine surge tenfold
Ukraine's “IT army” targets Belarus railway network, Russian GPS
Eight-character passwords can be cracked in less than 60 minutes
There are many misconceptions about security automation, so Torq is debunking a security automation myth each day this week.
Myth 5: You Should Automate All Security Processes
False. You should automate routine, repetitive tasks that are not subject to much conditional variance. But workflows that can’t be reliably managed by automation tools, such as assessing the financial consequences of a breach or determining whether a security incident should trigger an application rollback, should remain the domain of humans. To learn more about the realities of automation, head to torq.io.
For the stories behind the headlines, head to CISOseries.com.
Conti and Trickbot code leaks
API attacks surge in 2021
Log4Shell still being used in the wild
There are many misconceptions about security automation, so Torq is debunking a security automation myth each day this week.
Myth 4: Automation Will Replace Skilled Security Professionals
Not true. Any business that attempts to automate security will quickly find that most high-stakes security issues are far too complex to be detected and remediated by automation tools alone. Human security professionals need to take the lead delivering nuanced insight about the business impact of a large-scale breach. To learn more about the realities of automation, head to torq.io.
Russia-Ukraine War update
Nvidia confirms company data was stolen in hack
Half of employees use unauthorized file services at work
There are many misconceptions about security automation, so Torq is debunking a security automation myth each day this week.
Myth 3: Only Enterprises Need Security Automation
Debunked. While enterprises with thousands of endpoints and sprawling teams certainly need automation, businesses of all sizes face challenges related to other forms of scale when it comes to security. For instance, there are about 1 billion known types of malware in existence, and they imperil businesses of all sizes equally. To learn more about the realities of automation, head to torq.io.
For the stories behind the headlines, go to cisoseries.com
Toyota suspends Japanese production due to cyberattack
Microsoft providing threat intelligence to Ukraine
Twitter to label tweets from state-owned media
There are many misconceptions about security automation, so Torq is debunking a security automation myth each day this week.
Myth 2: Security Automation Is Just a New Term for Automated Security Testing
Wrong. While scanning and testing may be one example of a security automation use case, it’s hardly the only one. Automation can be used to do things like help manage complex security workflows and optimize collaboration between different stakeholders. These are tasks that were not traditionally automated. To learn more about the realities of automation, head to torq.io.
Ukraine recruits volunteer IT army to hack list of Russian entities
Russia demands Google restore access to its media YouTube channels in Ukraine
Chipmaker giant Nvidia hit by ransomware attack
There are many misconceptions about security automation, so Torq is debunking a security automation myth each day this week.
Myth 1: Automation Is Only a Reactive Part of SecOps
Incorrect. Proactive management of security incidents is just as important, like automatically scanning IaC configurations to detect vulnerabilities, automating collaboration between devs, IT ops and SecOps to prevent risks before they’re threats. To learn more about the realities of automation, head to torq.io.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, Feb 21-25, is hosted by Rich Stroffolino with our guest, Mark Eggleston, CISO, CSC
Thanks to our episode sponsor, Tines
Tines is hosting a virtual game show in conjunction with Lacework on March 8. It’s free to attend, with security trivia, fun prizes, and donations going to good causes like Women in Cybersecurity. Places are limited, so head over to tines.com/gameshow to register.
All links and the video of this episode can be found on CISO Series.com
Cyberattacks accompany Russian military assault on Ukraine
Putin's government warns Russian critical infrastructure of potential cyberattacks
Manufacturing was the top industry targeted by ransomware last year
Thanks to our episode sponsor, Tines
Tines is hosting a virtual game show in conjunction with Lacework on March 8. It's free to attend, with security trivia, fun prizes, and donations going to good causes like Women in Cybersecurity. Places are limited, so head over to tines.com/gameshow to register.
For the stories behind the headlines, head to CISOseries.com.
Samsung shipped devices with flawed encryption
New York state gets cybersecurity center
Microsoft Defender adds support for GCP
Thanks to our episode sponsor, Tines
Tines is hosting a virtual game show in conjunction with Lacework on March 8. It's free to attend, with security trivia, fun prizes, and donations going to good causes like Women in Cybersecurity. Places are limited, so head over to tines.com/gameshow to register.
IRS is allowing taxpayers to opt out of facial recognition
UK Defence Secretary warns Russia of cyber-retaliation
Slack confirms outage for some users
Thanks to our episode sponsor, Tines
Tines is hosting a virtual game show in conjunction with Lacework on March 8. It's free to attend, with security trivia, fun prizes, and donations going to good causes like Women in Cybersecurity. Places are limited, so head over to tines.com/gameshow to register.
For the stories behind the headlines, head to cisoseries.com
Researches find decryption for Hive ransomware
In the Google Play Store, no one can hear you scream
Linux leads in patching speeds
Thanks to our episode sponsor, Tines
Tines is hosting a virtual game show in conjunction with Lacework on March 8. It's free to attend, with security trivia, fun prizes, and donations going to good causes like Women in Cybersecurity. Places are limited, so head over to tines.com/gameshow to register.
White House attributes Ukraine DDoS incidents to Russia's GRU
Master key for Hive ransomware retrieved using a flaw in its encryption algorithm
New phishing campaign targets Monzo online-banking customers
Thanks to our episode sponsor, Tines
Tines is hosting a virtual game show in conjunction with Lacework on March 8. It's free to attend, with security trivia, fun prizes, and donations going to good causes like Women in Cybersecurity. Places are limited, so head over to tines.com/gameshow to register.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, Feb 14-18, is hosted by Rich Stroffolino with our guest, Mike Hanley, CSO, GitHub
Thanks to our episode sponsor, PlexTrac
*PlexTrac is the Purple Teaming Platform. Use the Runbooks Module to facilitate your tabletop exercises, red team engagements, breach and attack simulations, and pentest automation to improve communication and collaboration. PlexTrac upgrades your program’s capabilities by making the most of every team member and tool.
Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the perfect platform for CISOs!*
All links and the video of this episode can be found on CISO Series.com
DOJ beefs up efforts to combat criminal use of cryptocurrencies
Canada's major banks go offline in mysterious hours-long outage
Hackers slip into Microsoft Teams chats to distribute malware
Thanks to our episode sponsor, PlexTrac
*PlexTrac is the Purple Teaming Platform. Use the Runbooks Module to facilitate your tabletop exercises, red team engagements, breach and attack simulations, and pentest automation to improve communication and collaboration. PlexTrac upgrades your program’s capabilities by making the most of every team member and tool.
Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the perfect platform for CISOs!*
For the stories behind the headlines, head to CISOseries.com.
State-sponsored hackers hits defense contractors
Unskilled hacker targeted aviation industry for years
Privacy Sandbox heading to Android
Thanks to our episode sponsor, PlexTrac
*Solve your talent shortage with PlexTrac. Use PlexTrac to automate security tasks and workflows to keep your red, blue, and purple teams focused on the real security work. Gain precious time back in your team’s day and improve their morale by making them more effective with PlexTrac.
Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the perfect platform for CISOs!*
Cyberattacks take down Ukrainian military and bank websites
Super Bowl ad shines a light on QR code risks
CISA directs agencies to patch actively exploited Chrome and Magento bugs
Thanks to our episode sponsor, PlexTrac
*PlexTrac is the solution to deal with your data. Aggregate findings from all assessments to produce the analytics needed to make informed decisions. Produce data visualizations and add them to reports with one click to communicate effectively to leadership. PlexTrac is the premier product for security data management.
Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the perfect platform for CISOs!*
For the stories behind the headlines, visit cisoseries.com
FTC warns VoIP providers about robocalls
SEC outlines new cybersecurity rules for investment firms
Rampant plagiarism hits NFT marketplace
Thanks to our episode sponsor, PlexTrac
*Gain a real-time view of security posture with PlexTrac by consolidating scanner findings, assessments, and bug bounty tools. Visualize your posture in the Analytics Module to quickly assess and prioritize, creating a more effective workflow. Map risks to the MITRE ATT&CK framework to create a living risk register.
Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the perfect platform for CISOs!*
San Francisco 49ers hit by Blackbyte ransomware attack
Linux malware attacks are on the rise, and businesses aren't ready for it
Fake Windows 11 upgrade installers deliver RedLine malware
Thanks to our episode sponsor, PlexTrac
*PlexTrac is a powerful, yet simple, cybersecurity platform that centralizes all security assessments, pentest reports, audit findings, and vulnerabilities. PlexTrac transforms the risk management lifecycle, allowing security professionals to generate better reports faster, aggregate and visualize analytics, and collaborate on remediation in real-time.
Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the perfect platform for CISOs!*
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, Feb 7-11, is hosted by Rich Stroffolino with our guest, Dave Stirling, CISO, Zions Bancorporation
Thanks to our episode sponsor, Datadog
*Datadog Security Monitoring is part of the Datadog Cloud Security Platform, which protects an organization’s production environment and provides threat detection, posture management, workload security, and application security in a single pane of glass.
In this Datadog Security Monitoring product brief, you’ll learn how to:
Solve cloud complexity challenges with threat detection tools, detect and analyze security threats anywhere in your stack, and deploy turnkey detection rules mapped to the MITRE ATT&CK framework. Download the brief today to learn more at datadoghq.com/ciso/*
All links and the video of this episode can be found on CISO Series.com
Donation site for Ottawa truckers’ “Freedom Convoy” protest exposed donors’ data
FritzFrog botnet returns to attack healthcare, education, government sectors
If you use Zoom on a Mac, you might want to check your microphone settings
Thanks to our episode sponsor, Datadog
*Datadog Security Monitoring is part of the Datadog Cloud Security Platform, which protects an organization’s production environment and provides threat detection, posture management, workload security, and application security in a single pane of glass.
In this Datadog Security Monitoring product brief, you’ll learn how to:
Solve cloud complexity challenges with threat detection tools, detect and analyze security threats anywhere in your stack, and deploy turnkey detection rules mapped to the MITRE ATT&CK framework. Download the brief today to learn more at datadoghq.com/ciso/*
For the stories behind the headlines, head to CISOseries.com.
Ukraine takes down social media bot farm
Federal use of cell siphoning tech on the rise
Microsoft expands security business
Thanks to our episode sponsor, Datadog
*Datadog’s Cloud Security Platform delivers real-time threat detection and continuous configuration audits across your entire production environment, so you can bring speed and scale to your security organization. The Cloud Security Platform is built on top of Datadog’s observability platform, which breaks down silos between Security and DevOps teams and aligns them to shared organizational goals.
To learn more about how Datadog Security Monitoring can solve cloud complexity challenges with a unified platform, download the product brief at datadoghq.com/ciso/*
DOJ arrests New York couple, seizing $3.6 billion in bitcoin
Google sees 50% drop in compromises after 2SV enrollment
Puma employee data stolen as a result of Kronos attack
Thanks to our episode sponsor, Datadog
*Datadog Security Monitoring is part of the Datadog Cloud Security Platform, which protects an organization’s production environment and provides threat detection, posture management, workload security, and application security in a single pane of glass.
In this Datadog Security Monitoring product brief, you’ll learn how to:
Solve cloud complexity challenges with threat detection tools, detect and analyze security threats anywhere in your stack, and deploy turnkey detection rules mapped to the MITRE ATT&CK framework. Download the brief today to learn more at datadoghq.com/ciso/*
For the stories behind the headlines, head to cisoseries.com
Stolen crypto used to fund North Korean missile program
Microsoft disables protocol used by malware
Meta may pull out of the EU
Thanks to our episode sponsor, Datadog
*Datadog’s Cloud Security Platform delivers real-time threat detection and continuous configuration audits across your entire production environment, so you can bring speed and scale to your security organization. The Cloud Security Platform is built on top of Datadog’s observability platform, which breaks down silos between Security and DevOps teams and aligns them to shared organizational goals.
To learn more about how Datadog Security Monitoring can solve cloud complexity challenges with a unified platform, download the product brief at datadoghq.com/ciso/*
US House passes bill to boost chip manufacturing and R&D
One in seven ransomware extortion attempts leak key operational tech records
New Argo CD bug could let hackers steal secret info from Kubernetes apps
Thanks to our episode sponsor, Datadog
*Datadog Security Monitoring is part of the Datadog Cloud Security Platform, which protects an organization’s production environment and provides threat detection, posture management, workload security, and application security in a single pane of glass.
In this Datadog Security Monitoring product brief, you’ll learn how to:
Solve cloud complexity challenges with threat detection tools, detect and analyze security threats anywhere in your stack, and deploy turnkey detection rules mapped to the MITRE ATT&CK framework. Download the brief today to learn more at datadoghq.com/ciso/*
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, Jan 24-Feb 4, is hosted by Rich Stroffolino with our guest, Brian Lozada, CISO, HBOMax
Thanks to our episode sponsor, Pentera
Align validation to the MITRE ATT&CK framework and the OWASP Top 10. By aligning to industry standards, security teams ensure that their testing covers the latest adversary techniques. Most attacks succeed by leveraging the most common TTPs, so challenging the attack surface against these frameworks provides comprehensive coverage of adversary techniques in the wild. In addition, it allows security executives to clearly report to management on security control efficacy and enterprise readiness against potential threats. Find out more at pentera.io
All links and the video of this episode can be found on CISO Series.com
iPhone flaw exploited by second Israeli spy firm
Target shares its own web skimming detection tool with the world
MFA adoption pushes phishing actors to reverse-proxy solutions
Thanks to our episode sponsor, Pentera
Align validation to the MITRE ATT&CK framework and the OWASP Top 10. By aligning to industry standards, security teams ensure that their testing covers the latest adversary techniques. Most attacks succeed by leveraging the most common TTPs, so challenging the attack surface against these frameworks provides comprehensive coverage of adversary techniques in the wild. In addition, it allows security executives to clearly report to management on security control efficacy and enterprise readiness against potential threats. Find out more at pentera.io
For the stories behind the headlines, head to CISOseries.com.
Iran-linked APT activity on the rise
Hacker claims responsibility for North Korean internet disruptions
TikTok: the once and future national security threat
Thanks to our episode sponsor, Pentera
To continuously know the exploitable attack surface, automate your validation. Security validation must be as dynamic as the attack surface it’s securing. Periodical and manual tests aren’t enough to challenge the changes an organization undergoes. Security teams need to have an on-demand view of their assets and exposures, and the only way to get there is by automating your testing. Find out more at pentera.io
Cyber attack disrupts German oil firm operations
Tesla recalls Full Self Driving feature that lets cars roll through stop signs
FBI recommends using burner phones at the Olympics
Thanks to our episode sponsor, Pentera
To understand the exploitable attack surface, security teams need to cover the full scope of potential attacks. Adversaries take the path of least resistance to the critical assets. This means using a variety of techniques to progress an attack, leveraging any vulnerability and its relevant correlations along the way. For this reason, the validation methods used must match - they need to go beyond the static vulnerability scan or control attack simulation to include a full penetration test scope. Find out more at pentera.io
For the stories behind the headlines, head to CISOseries.com
Your GPU knows your secrets
UPnP behind Eternal Silence router campaign
DeFi platform hacked for $80 million
Thanks to our episode sponsor, Pentera
To understand the exploitable attack surface, take the adversarial perspective. The way to know which vulnerabilities are exploitable is to…well, exploit them. This way, security teams get a concise attack vector pointing to the organization’s weakest link. From here remediation requests handed to IT are focused, manageable, and based on true business impact. Find out more at pentera.io
Novel device registration trick enhances multi-stage phishing attacks
US bans major Chinese telecom over national security risks
Over 20,000 data center management systems exposed to hackers
Thanks to our episode sponsor, Pentera
Pentera introduces Automated Security Validation! The newly-minted unicorn out of Israel takes a whole new approach to penetration testing - allowing every organization to continuously test the integrity of all cybersecurity layers - including against ransomware - leveraging proprietary ethical exploits to emulate real-world attacks at scale. All day, everyday. This week Pentera will discuss how to identify your exploitable attack surface, so stay tuned for their ‘Tip of the Day’. Or visit pentera.io to find out more.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, Jan 24-28, is hosted by Rich Stroffolino with our guest, Gary Hayslip, CISO, Softbank Investment Advisers
Thanks to our episode sponsor, deepwatch
All links and the video of this episode can be found on CISO Series.com
US says national water supply 'absolutely' vulnerable to hackers
Microsoft mitigated a record 3.47 Tbps DDoS attack on Azure users
BotenaGo Mirai botnet code leaked to GitHub
Thanks to our episode sponsor, deepwatch
Increasing ransomware attacks and their evolving sophistication have been putting more pressure on security teams than ever before. Luckily, managed detection and response (or MDR) has emerged as a critical component for improving security operations, reducing ransomware risk, and minimizing the overall impact an attack can have. Visit deepwatch.com to see how we help to prevent breaches for our customers, by working together.
For the stories behind the headlines, head to CISOseries.com.
White House releases new cybersecurity strategy
Trickbot gets trickier
VPNLab shuttered in global takedown
Thanks to our episode sponsor, deepwatch
Increasing ransomware attacks and their evolving sophistication have been putting more pressure on security teams than ever before. Luckily, managed detection and response (or MDR) has emerged as a critical component for improving security operations, reducing ransomware risk, and minimizing the overall impact an attack can have. Visit deepwatch.com to see how we help to prevent breaches for our customers, by working together.
Canada's foreign ministry hacked
Hactivists target Belarus rail system to stop Russian military buildup
Segway victimized by Magecart attack
Thanks to our episode sponsor, deepwatch
Increasing ransomware attacks and their evolving sophistication have been putting more pressure on security teams than ever before. Luckily, managed detection and response (or MDR) has emerged as a critical component for improving security operations, reducing ransomware risk, and minimizing the overall impact an attack can have. Visit deepwatch.com to see how we help to prevent breaches for our customers, by working together.
For the stories behind the headlines, head to CISOseries.com
SBA launches cybersecurity program
Ransomware gangs step up insider recruitment
American Olympians warned to take cybersecurity precautions
Thanks to our episode sponsor, deepwatch
Increasing ransomware attacks and their evolving sophistication have been putting more pressure on security teams than ever before. Luckily, managed detection and response (or MDR) has emerged as a critical component for improving security operations, reducing ransomware risk, and minimizing the overall impact an attack can have. Visit deepwatch.com to see how we help to prevent breaches for our customers, by working together.
Ukraine attack update: experts find strategic similarities with NotPetya
Molerats use Google Drive and Dropbox as attack infrastructure
Senators introduce bill to protect satellites from getting hacked
Thanks to our episode sponsor, deepwatch
Increasing ransomware attacks and their evolving sophistication have been putting more pressure on security teams than ever before. Luckily, managed detection and response (or MDR) has emerged as a critical component for improving security operations, reducing ransomware risk, and minimizing the overall impact an attack can have. Visit deepwatch.com to see how we help to prevent breaches for our customers, by working together.
For the stories behind the headlines, head to CISOseries.com.
Link to Blog Post
This week’s Cyber Security Headlines – Week in Review, Jan 17-21, is hosted by Rich Stroffolino with our guest, Julie Tsai, Cybersecurity Leader
Thanks to our episode sponsor, Datadog
Join Datadog in their upcoming webinar to learn how to dissect the anatomy of an attack vector in the cloud with the use of their unified Cloud Security Platform. Visit datadoghq.com/ciso to register for the webinar in the time zone most convenient for you and attendees will also get a chance to win a Datadog t-shirt.
All links and the video of this episode can be found on CISO Series.com
NATO and Ukraine sign deal to boost cybersecurity
Microsoft Sees Log4j attacks exploiting SolarWinds Serv-U bug
Large-scale cyberattack hits the Red Cross
Thanks to our episode sponsor, Datadog
Join Datadog in their upcoming webinar to learn how to dissect the anatomy of an attack vector in the cloud with the use of their unified Cloud Security Platform. Visit datadoghq.com/ciso to register for the webinar in the time zone most convenient for you and attendees will also get a chance to win a Datadog t-shirt.
For the stories behind the headlines, head to CISOseries.com.
CISA warns of data-wiping attacks
EU working on its own DNS service
Biden expands the NSA’s cybersecurity purview
Thanks to our episode sponsor, Datadog
In Datadog's upcoming webinar, you’ll learn how to best utilize the suite of Datadog Cloud Security products to identify the root cause of an attack and how a unified platform provides real-time threat-detection and continuous configuration audits across applications, hosts, containers and cloud infrastructure. Visit datadoghq.com/ciso to register for the webinar in the time zone most convenient for you and attendees will also get a chance to win a Datadog t-shirt.
Beijing 2022 Winter Olympics app loaded with privacy risks
Europol shuts down cybercriminals' VPN service of choice
Newspaper accuses Israeli police of spying on its own citizens
Thanks to our episode sponsor, Datadog
Join Datadog in their upcoming webinar to learn how to dissect the anatomy of an attack vector in the cloud with the use of their unified Cloud Security Platform. Visit datadoghq.com/ciso to register for the webinar in the time zone most convenient for you and attendees will also get a chance to win a Datadog t-shirt.
For the stories behind the headlines, head to CISOseries.com
Ukraine points fingers in recent cyber attacks
Another dark web marketplace calls it quits
Renewable energy targeted for cyber espionage
Thanks to our episode sponsor, Datadog
In Datadog's upcoming webinar, you’ll learn how to best utilize the suite of Datadog Cloud Security products to identify the root cause of an attack and how a unified platform provides real-time threat-detection and continuous configuration audits across applications, hosts, containers and cloud infrastructure. Visit datadoghq.com/ciso to register for the webinar in the time zone most convenient for you and attendees will also get a chance to win a Datadog t-shirt.
Microsoft discloses malware attack on Ukraine government networks
New unpatched Apple Safari browser bug allows cross-site user tracking
Now you can get your vulnerability alerts by phone
Thanks to our episode sponsor, Datadog
Join Datadog in their upcoming webinar to learn how to dissect the anatomy of an attack vector in the cloud with the use of their unified Cloud Security Platform. Visit datadoghq.com/ciso to register for the webinar in the time zone most convenient for you and attendees will also get a chance to win a Datadog t-shirt.
For the stories behind the headlines, head to CISOseries.com.