Cyber Security Headlines: Recent Episodes

CISO Series

Daily stories from the world of information security. To delve into any daily story, head to CISOseries.com.

View Details

OpenAI loosens cyber limits for vetted defenders

Sandworm's fake recruiters plant a poisoned VPN

Royal Navy drones phone home to China

Episode show notes: https://cisoseries.com/openai-loosens-cyber-limits-sandworms-poisoned-vpn-navy-drones-phone-china/

Huge thanks to our sponsor, ThreatLocker

An attacker uses AI to create a payload your security tools have never seen. Detection now has to recognize it before the payload can act. ThreatLocker approaches the problem earlier by controlling whether that code is permitted to run at all. Explore a deny by default approach for your organization at threatlocker.com/ciso.

View Details

OpenAI slows release of Astra model citing cyber capabilities

Irregular won't say if there were more rogue incidents

U.S. cyber ambassador nominee Cassady confirmed in Senate

Episode shownotes: https://cisoseries.com/cybersecurity-news-openai-slows-astra-irregular-wont-talk-senate-confirms-cassady/

Huge thanks to our sponsor, ThreatLocker

AI is helping attackers research targets, create malicious code, and adapt faster. But the fundamentals have not changed. Code still needs to execute, applications still need access, and attackers still need privileges. Today's tip: control those actions instead of trying to predict every threat. Learn more from ThreatLocker at threatlocker.com/ciso.

View Details

Apple's bug bounty program overwhelmed by fake AI generated reports

China launches cybersecurity review into Palo Alto Networks products

Meta AI hacks external systems during cybersecurity testing

Get the show notes here: https://cisoseries.com/cybersecurity-news-faked-bug-reports-metas-rogue-ai-china-investigates-palo-alto/

Huge thanks to our episode sponsor, ThreatLocker

AI risk does not only come from attackers. Employees are adopting AI tools faster than many organizations can evaluate them. Today's tip: an AI policy should be backed by enforceable controls over what tools can access and do. See how ThreatLocker can help you govern AI use at threatlocker.com/ciso.

View Details

AI safety tests spill onto the real internet

Private Relay flaw unmasks IP addresses

Weak telcos left door open for Salt Typhoon

Get the show notes here: https://cisoseries.com/cybersecurity-news-ai-safety-tests-reach-the-internet-private-relay-flaw-unmasks-ips-weak-telcos-invite-salt-typhoon/

Huge thanks to our episode sponsor, ThreatLocker

AI is compressing the timeline between initial access and impact. That leaves security teams less time to identify, investigate, and contain malicious activity. Faster response helps, but prevention can remove actions from the attack chain entirely. Give your responders a more controlled environment. Book a ThreatLocker demo at threatlocker.com/ciso.

View Details

ChainDrop attack hits npm

Pass-ta-key attacks target passkeys

AI accounts for most cybercrime in Africa

Get the show notes here: https://cisoseries.com/cybersecurity-news-chaindrop-hits-npm-pass-ta-key-targets-passkeys-ai-runs-amok-in-africa/

Huge thanks to our episode sponsor, ThreatLocker

Attackers do not always bring their own tools. AI can help them find ways to misuse software already trusted by the organization. Today's tip: approval should not mean unlimited access. Define what trusted applications can reach and what they can do. Learn how ThreatLocker applies this principle at threatlocker.com/ciso today.

View Details

When license plate readers become stalking tools

ExfilSquad dumps UK police contact data

China-linked hackers shrink the patch window

Get the show notes here: https://cisoseries.com/cybersecurity-news-license-plate-readers-as-stalking-tools-exfilsquad-dumps-uk-police-data-the-ever-shrinking-patch-window/

Huge thanks to our episode sponsor, ThreatLocker

An attacker uses AI to create a payload your security tools have never seen. Detection now has to recognize it before the payload can act. ThreatLocker approaches the problem earlier by controlling whether that code is permitted to run at all. Explore a deny by default approach for your organization at threatlocker.com/ciso.

View Details

UK's state investments agency suffers data breach

CISA tells utilities to remove internet-exposed PLCs following Minnesota attacks

Anthropic says its AI hacked real-world companies in three incidents

Get the show notes here: https://cisoseries.com/cybersecurity-news-cybersecurity-news-uk-investments-agency-breach-cisa-water-warning-anthropic-threesome/

Huge thanks to our episode sponsor, ThreatLocker

AI is helping attackers research targets, create malicious code, and adapt faster. But the fundamentals have not changed. Code still needs to execute, applications still need access, and attackers still need privileges. Today's tip: control those actions instead of trying to predict every threat. Learn more from ThreatLocker at threatlocker.com/ciso.

View Details

This week's Department of Know is hosted by Rich Stroffolino, with guests Janet Heins, CISO, ChenMed, and Derek Fisher, Director of the Cyber Defense and Information Assurance Program, Temple University.

Missed the live show? Check it out on YouTube.

The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.

Huge thanks to our sponsor, Pindrop A finance worker joined a video call with their CFO and wired $25 million to attackers. This isn't fiction—it happened. Deepfake video. AI voice. Completely convincing. It could be happening in your meetings right now. Pindrop Pulse for Meetings can detect deepfake impersonation before the damage is done. Go to pindrop.com and start verifying.

View Details

Semiconductor firm Analog Devices discloses data breach

Copilot for Word POC copies hidden prompts into new documents

Microsoft Teams vishing attacks lead to Chaos ransomware attacks

Get the show notes here: https://cisoseries.com/cybersecurity-news-analog-devices-breach-copilot-ai-worm-teams-ransomware-vishing/

Huge thanks to our sponsor, Pindrop

A finance worker joined a video call with their CFO and wired $25 million to attackers. This isn't fiction—it happened. Deepfake video. AI voice. Completely convincing. It could be happening in your meetings right now. Pindrop Pulse for Meetings can detect deepfake impersonation before the damage is done. Go to pindrop.com and start verifying.

View Details

OpenAI agent's escape reaches a Modal customer

Hackers hit Minnesota water systems

Fake Russian companies, real stolen money

Get the show notes here: https://cisoseries.com/cybersecurity-news-openai-agent-reaches-modal-minnesota-water-systems-hacked-fake-russian-companies-steal-real-money/

Huge thanks to our sponsor, Pindrop

TIME named Pindrop one of the 10 Most Influential Software Companies of 2026. Deepfakes slip into your video meetings, contact centers, and hiring pipelines. Pindrop restores trust to every digital conversation. Customers. Employees. Defended. Don't wait for an incident report. Visit pindrop.com.

View Details

Thousands of server BMCs leak password hashes

Claude finds flaws in encryption

Google gives old threat actors new names

Get the show notes here: https://cisoseries.com/cybersecurity-news-leaky-bmcs-claude-finds-encryption-flaws-googles-new-names/

Huge thanks to our sponsor, Pindrop

AI attacks on the enterprise are skyrocketing. Is your tech stack keeping up? Deepfake and synthetic voices are slipping through a channel your defenses were never built to cover—stealing credentials and exposing data with no visibility until after the incident report. Pindrop closes that gap, with under 1% false positives. Go to pindrop.com.

View Details

Nvidia opens the AI security tent

Microsoft puts a cyber sprinter in MDASH

Fairlife ransomware spills data

Get the show notes here: https://cisoseries.com/cybersecurity-news-nvidia-opens-ai-security-tent-microsoft-adds-cyber-sprinter-to-mdash-fairlife-ransomware-spills-data/

Huge thanks to our sponsor, Pindrop

A finance worker joined a video call with their CFO and wired $25 million to attackers. This isn't fiction—it happened. Deepfake video. AI voice. Completely convincing. It could be happening in your meetings right now. Pindrop Pulse for Meetings can detect deepfake impersonation before the damage is done. Go to pindrop.com and start verifying.

View Details

U.S. agencies warn of Iran-linked actors targeting water and energy control systems

ChatGPT suffered brief global outage on Saturday

Malvertising sends malware in pieces for an unsuspecting browser to build

Get the show notes here: https://cisoseries.com/cybersecurity-news-iran-infrastructure-warning-chatgpt-global-outage-self-assembling-malware/

Huge thanks to our sponsor, Pindrop

Your hiring processes are the newest entry point for security risks. Pindrop's data shows one in six engineering job applicants show signs of synthetic identity. That's why we built Pindrop Pulse for Meetings. Catch deepfakes, AI voices, and spoofed locations in real time. Go to pindrop.com and start verifying.

View Details

This week's Department of Know is hosted by Rich Stroffolino, with guests Nick Espinosa, host, Deep Dive Radio Show, and Dennis Pickett, vp, CISO, Westat.

Missed the live show? Check it out on YouTube.

The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.

Huge thanks to our sponsor, QuilrAI

AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes. Alerts tell you later. QuilrAI decides now. Visit quilr.ai. Stay safe - Quilr it.

View Details

AI Agents become fastest growing exposed attack surface

Consumer finance company Upbound Group blames data breach for millions in losses

Dolphin X Stealer uses AI profiling to prioritize targets

Get the show notes here: https://cisoseries.com/cybersecurity-news-ai-agents-risk-upbound-group-breach-dolphin-x-stealer/

Huge thanks to our sponsor, QuilrAI

AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes.

Alerts tell you later. QuilrAI decides now. Visit quilr.ai.

View Details

OpenAI behind Hugging Face hack

TrickBot tunnels through DNS

Acrobat extension opens WhatsApp

Get the show notes here:

Huge thanks to our sponsor, QuilrAI

AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes.

Alerts tell you later. QuilrAI decides now. Visit quilr.ai.

View Details

Bit2Watt threatens power stability

All AI models cheat at cyber evaluations

US weighing Chinese LLM ban

Get the show notes here: https://cisoseries.com/cybersecurity-news-bit2watt-instability-ai-models-cheat-chinese-llm-ban/

Huge thanks to our sponsor, QuilrAI

AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes.

Alerts tell you later. QuilrAI decides now. Visit quilr.ai.

View Details

Hugging Face fights AI hacks with AI

World Cup streamers get a red card

WordPress enters a patching race

Get the show notes here:

Huge thanks to our sponsor, QuilrAI

AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes.

Alerts tell you later. QuilrAI decides now. Visit quilr.ai.

View Details

Dairy company Fairlife suffers cyberattack

Microsoft warns of surge in ACR Stealer attacks on customers

Abbott Labs investigates two cyber incidents amid extortion claims

Get the show notes here: https://cisoseries.com/cybersecurity-news-fairlife-dairy-cyberattack-acr-stealer-surge-abbott-labs-incidents/

Huge thanks to our sponsor, QuilrAI

AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes.

Alerts tell you later. QuilrAI decides now. Visit quilr.ai.

View Details

"Context Bombing" flips the script on prompt injections

Pentagon suspends CMMC Phase II requirements

Old tech, new problems

Get the show notes here: https://cisoseries.com/the-department-of-know-cmmc-suspended-sharefile-shutdown-context-bombing-strikes-back/

This week's Department of Know is hosted by Rich Stroffolino, with guests Tom Hollingsworth, networking technology advisor, Futurum Group, and Mark Eggleston, former CISO, CSC.

Missed the live show? Check it out on YouTube.

The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.

Huge thanks to our sponsor, ThreatLocker

Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk?

That's the challenge behind cloud adoption.

Behind AI. Behind automation. And behind every major technology decision.

ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do.

That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.

View Details

ClickLock stealer uses kill loops to force password entry

TELEPUZ malware uses ClickFix to steal data and run commands

1Password's new Agentic Mode lets Claude log into accounts

Notes: https://cisoseries.com/cybersecurity-news-clicklocks-kill-loops-telepuz-clickfix-tricks-1passwords-agentic-login/

Huge thanks to our sponsor, ThreatLocker

Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.

View Details

Zoom's account takeover wake-up call

Two zero-days, one urgent SonicWall patch

23andMe's breach bill keeps growing

Show Notes: https://cisoseries.com/cybersecurity-news-zooms-wake-up-call-zero-day-sonicwall-patch-23andmes-growing-breach-bill/

Huge thanks to our sponsor, ThreatLocker

Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.

View Details

Pentagon suspends CMMC Phase II requirements

US troop location data under attack in Iran

"Context Bombing" flips the script on prompt injections

Get the show notes here: https://cisoseries.com/cybersecurity-news-cmmc-phase-ii-suspended-tracking-troops-in-iran-defenders-turn-to-context-bombing/

Huge thanks to our sponsor, ThreatLocker

Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.

View Details

Russia's router access routes

MemGhost haunts AI memory

DHS alert got waved off… twice

Get the show notes here: https://cisoseries.com/cybersecurity-news-russias-router-access-routes-memghost-haunts-ai-memory-dhs-alert-got-waved-off-twice/↗

Huge thanks to our sponsor, ThreatLocker

Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.

View Details

Windows backdoor stuffs multiple wipers and ransomware code into a single package

NSA brings back Tailored Access Operations name for elite hacking unit

Progress urges ShareFile customers to shut down storage zone controllers

Show notes: https://cisoseries.com/cybersecurity-news-multifunction-windows-backdoor-nsa-revives-tao-urgent-sharefile-warning/

Huge thanks to our sponsor, ThreatLocker

Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.

View Details

Link to the episode

This week's Department of Know is hosted by Rich Stroffolino, with guests Davi Ottenheimer, principal, Flying Penguin, and Chris Ray, field CTO, GigaOm.

Missed the live show? Check it out on YouTube.

The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.

Huge thanks to our sponsor, Vanta

Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.

View Details

Interpol's fraud sweep goes global

China flags Claude Code

Old GitHub accounts, new tricks

Get the show notes here: https://cisoseries.com/cybersecurity-news-interpols-global-fraud-sweep-chinas-claude-code-flag-old-github-account-tricks/

Thanks to our episode sponsor, Vanta

Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.

View Details

Mexico's first cyber test gets tested

Snoops break into Roundcube mailservers

Cash App owner pays up over lax security

Get the show notes here: https://cisoseries.com/cybersecurity-news-mexicos-big-cyber-test-roundcube-mailserver-snooped-on-cash-app-found-lax/

Thanks to our episode sponsor, Vanta

Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.

View Details

The UK's Cyber Pledge and Cyber Shield

Millions exposed in Japanese telco attack

China looking to curb overseas model access

Get the show notes here:

Thanks to our episode sponsor, Vanta

Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.

View Details

Suspected China-Nexus hackers use fake Indian tax filing utility to deploy DcRAT

Prompt injection attacks trick AI Agents into making crypto payments

France to stop certifying products without quantum-safe encryption

Get the show notes here: https://cisoseries.com/cybersecurity-news-india-tax-rat-prompt-injection-crypto-scam-france-pushes-quantum-safe/

Thanks to our episode sponsor, Vanta

Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.

View Details

JadePuffer ransomware used AI agent to automate entire attack

AdaptHealth suffers cyberattack

UK's National Cyber Action Plan launch delayed by political leadership crisis

Get the show notes here: https://cisoseries.com/cybersecurity-news-first-ai-ransomware-adapthealth-suffers-cyberattack-uk-cyber-plan-delayed/

Thanks to our episode sponsor, Vanta

Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.

View Details

This week's Department of Know is hosted by Rich Stroffolino, with guests David Cross, CISO, Atlassian; Kathleen Mullin, Director, SABSA Institute; Montez Fitzpatrick, CISO, Navvis; and Howard Holton, former CEO, GigaOm.

Get the show notes here: https://cisoseries.com/the-department-of-know-peoplesoft-exploit-ford-brings-back-gray-beards-llm-vetting/

Huge thanks to our sponsor, Silent Push

Most cybersecurity approaches are completely reactive. Victim organizations are hit with an attack and the chase ensues. Silent Push closes this gap with its Preemptive Cyber Defense platform. Silent Push tracks adversary infrastructure and infrastructure changes across the Internet during the attack preparation phase - while attackers are still staging domains, IPs, and hosting and Silent Push turns that into Indicators of Future Attack® to defend with confidence. For a CISO, that turns invisible risk into early warning, an average of 140 days before a campaign shows up in your environment. Time to act, and a smaller window of exposure, before a threat ever reaches your environment.

View Details

Card data theft remains top concern for U.S. consumers

OMB chief to oversee spy agency budgets

Fortibleed leads to ransomware attacks and 430,000 Fortinet firewalls exposed

Get the show notes here: https://cisoseries.com/cybersecurity-news-consumer-security-worries-vought-supervises-spy-budgets-fortibleed-exposes-fortinet/

Huge thanks to our sponsor, Silent Push

Most cybersecurity approaches are completely reactive. Victim organizations are hit with an attack and the chase ensues.

Silent Push closes this gap with its Preemptive Cyber Defense platform. Silent Push tracks adversary infrastructure and infrastructure changes across the Internet during the attack preparation phase - while attackers are still staging domains, IPs, and hosting and Silent Push turns that into Indicators of Future Attack® to defend with confidence.

For a CISO, that turns invisible risk into early warning, an average of 140 days before a campaign shows up in your environment. Time to act, and a smaller window of exposure, before a threat ever reaches your environment. Learn more at silentpush.com

View Details

Hide My Email bug shows real addresses

Fable 5 gets the greenlight

DHS confirms hackers breached HSIN

Get the show notes here: https://cisoseries.com/cybersecurity-news-hide-my-email-shows-real-addresses-fable-5-gets-greenlight-microsoft-teams-hits-back-on-bots/

Huge thanks to our sponsor, Silent Push

Most cybersecurity approaches are completely reactive. Victim organizations are hit with an attack and the chase ensues.

Silent Push closes this gap with its Preemptive Cyber Defense platform. Silent Push tracks adversary infrastructure and infrastructure changes across the Internet during the attack preparation phase - while attackers are still staging domains, IPs, and hosting and Silent Push turns that into Indicators of Future Attack® to defend with confidence.

For a CISO, that turns invisible risk into early warning, an average of 140 days before a campaign shows up in your environment. Time to act, and a smaller window of exposure, before a threat ever reaches your environment. Learn more at silentpush.com

View Details

Bash can spell trouble GNU for AI agents

DHS to unveil critical infrastructure council

Aikido buys Root

Get the show notes here: https://cisoseries.com/cybersecurity-news-bash-hits-ai-dhs-announces-anchor-ci-aikido-buys-root/

Huge thanks to our sponsor, Silent Push

Most cybersecurity approaches are completely reactive. Victim organizations are hit with an attack and the chase ensues.

Silent Push closes this gap with its Preemptive Cyber Defense platform. Silent Push tracks adversary infrastructure and infrastructure changes across the Internet during the attack preparation phase - while attackers are still staging domains, IPs, and hosting and Silent Push turns that into Indicators of Future Attack® to defend with confidence.

For a CISO, that turns invisible risk into early warning, an average of 140 days before a campaign shows up in your environment. Time to act, and a smaller window of exposure, before a threat ever reaches your environment. Learn more at silentpush.com

View Details

US seizes illegal World Cup domains

WhatsApp offers usernames for phone number privacy

$10M reward for Russia-based cyber campaign

Get the show notes here: https://cisoseries.com/cybersecurity-news-us-seizes-illegal-world-cup-domains-whatsapp-offers-usernames-for-phone-privacy-10m-reward-for-cyber-campaign/

Huge thanks to our sponsor, Silent Push

Most cybersecurity approaches are completely reactive. Victim organizations are hit with an attack and the chase ensues.

Silent Push closes this gap with its Preemptive Cyber Defense platform. Silent Push tracks adversary infrastructure and infrastructure changes across the Internet during the attack preparation phase - while attackers are still staging domains, IPs, and hosting and Silent Push turns that into Indicators of Future Attack® to defend with confidence.

For a CISO, that turns invisible risk into early warning, an average of 140 days before a campaign shows up in your environment. Time to act, and a smaller window of exposure, before a threat ever reaches your environment. Learn more at silentpush.com

View Details

CISA sets urgent deadline to fix exploited Cisco flaw

Chinese cybersecurity company claims it has a better-than-Mythos bug finder

Amazon Q flaw enables cloud credential theft

Get the show notes here: https://cisoseries.com/cybersecurity-news-cisas-cisco-deadline-chinas-mythos-competitor-amazon-q-flaw/

Huge thanks to our sponsor, Silent Push

Most cybersecurity approaches are completely reactive. Victim organizations are hit with an attack and the chase ensues.

Silent Push closes this gap with its Preemptive Cyber Defense platform. Silent Push tracks adversary infrastructure and infrastructure changes across the Internet during the attack preparation phase - while attackers are still staging domains, IPs, and hosting and Silent Push turns that into Indicators of Future Attack® to defend with confidence.

For a CISO, that turns invisible risk into early warning, an average of 140 days before a campaign shows up in your environment. Time to act, and a smaller window of exposure, before a threat ever reaches your environment. Learn more at silentpush.com

View Details

ShinyHunters hits Madison Square Garden

Cal Water finds no evidence of OT activity

New CISA guide helps agencies adopt SASE for Zero Trust

Get the show notes here: https://cisoseries.com/cybersecurity-news-shinyhunters-hits-msg-cal-water-confirms-no-damage-cisa-sase-guide/

Huge thanks to our episode sponsor, Guardsquare

Attackers are treating your mobile app like an open book. Sixty-three percent of security leaders recently detected app tampering, cloning, or unauthorized modifications. When your code runs in an untrusted environment, you need runtime self-protection and code hardening to keep attackers out. Address tampering before it starts. Learn more at Guardsquare.com.

View Details

Copilot AI knocks down cybercrime tools

Hackers exploit Cisco zero-day

China's 360 says it matches Anthropic's Mythos

Get the show notes here: https://cisoseries.com/cybersecurity-news-copilot-ai-attacks-cybercrime-tools-hackers-exploit-cisco-zero-day-chinas-360-vs-mythos/

Huge thanks to our episode sponsor, Guardsquare

AI is speeding up development, but at what cost? While ninety-six percent of teams now use AI tools, eighty-one percent report that AI-generated code has introduced new vulnerabilities into their mobile apps. In a world with automated threats, you need multi-layered, polymorphic security to stay ahead of the curve. Learn more at Guardsquare.com.

View Details

Feds seize alleged cyber-scam infrastructure

Dragos unveils AI for OT security

Scattered Spider hackers plead guilty

Get the show notes here: https://cisoseries.com/cybersecurity-news-feds-seize-scam-infrastructure-dragos-unveils-ai-for-ot-security-scattered-spider-hackers-plead-guilty/

Huge thanks to our episode sponsor, Guardsquare

Is your mobile app truly protected? Relying on the OS isn't enough. A global study of thirteen-hundred security and developer leaders found that ninety-six percent of teams using layered protection reported significantly fewer security incidents. Don't wait for a breach to harden your defenses. Get the protection needed for modern secuirty risks. Learn more at Guardsquare.com.

View Details

OpenAI takes on Anthropic's Mythos

Klue hack hits security shops

Five Eyes has eyes on AI models

Get the show notes here: https://cisoseries.com/cybersecurity-news-openai-takes-on-mythos-klue-hits-security-shops-five-eyes-has-eyes-on-ai/

Huge thanks to our episode sponsor, Guardsquare

Your backend is only as secure as your frontend. Research shows that client-side compromise is now a primary driver of API risk. With sixty-three percent of leaders detecting mobile app tampering or cloning last year, don't leave your mobile app security to chance. Get multilayered protection for your entire mobile app ecosystem from the outside in. Learn more at Guardsquare.com.

View Details

Hackers suspected in Brazil cell phone alert

Prinz Eugen ransomware prioritizes recent files for encryption

Congress presents bill to protect people from AI-generated deepfakes

Get the show notes here: https://cisoseries.com/cybersecurity-news-brazil-phone-alert-hack-prinz-eugen-ransomware-congress-deepfake-bill/

Huge thanks to our episode sponsor, Guardsquare

Mobile app security isn't just a tech issue; it's a revenue issue. A recent global study found that seventy-two percent of organizations experienced a mobile app security incident last year. Even worse? Sixty-five percent saw customer churn or uninstalls as a result. Protect your brand and your bottom line with layered mobile app protection. Learn more at Guardsquare.com.

View Details

This week's Department of Know is hosted by Rich Stroffolino, with guests Arif Hameed, CISO, C&R Software; Adam Palmer, CISO, First Hawaiian Bank; Jon Collins, Field CTO, GigaOm; and Jack Leidecker, EVP, CSO, Gainsight.

Huge thanks to our sponsor, ThreatLocker

Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision. ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support Cyber Security Headlines. Because security works best when innovation and control move together.

View Details

Police clean ups SocGholish-infected sites tied to Evil Corp

Klue OAuth breach linked to Icarus Salesforce data theft attacks

Warner warns of CISA cuts, staffing gaps in letter to acting chief

Get the show notes here: https://cisoseries.com/cybersecurity-news-police-clean-wordpress-sites-klue-oauth-breach-warners-cisa-warnings/

Huge thanks to our sponsor, ThreatLocker

Every security leader is being asked the same question right now:

How do we enable innovation without creating unnecessary risk?

That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision.

ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do.

That's why ThreatLocker is proud to support Cyber Security Headlines.

Because security works best when innovation and control move together.

View Details

Anthropic tells G7 to cooperate

Fortinet VPN leak exposes credentials

Crypto Clipper abuses reviews, narrators, and comments

Get the show notes here: https://cisoseries.com/cybersecurity-news-anthropic-tells-g7-to-cooperate-fortinet-vpn-leak-exposes-credentials-crypto-clipper-abuses-reviews/

Huge thanks to our sponsor, ThreatLocker

Every security leader is being asked the same question right now:

How do we enable innovation without creating unnecessary risk?

That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision.

ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do.

That's why ThreatLocker is proud to support Cyber Security Headlines.

Because security works best when innovation and control move together.

View Details

Athena coalition looks to secure open source

Estonia to quarantine Russian email domains

Malicious package wave hits Arch Linux

Get the show notes here: https://cisoseries.com/cybersecurity-news-athena-coalition-estonias-quarantine-arch-hit-with-malware/

Huge thanks to our sponsor, ThreatLocker

Every security leader is being asked the same question right now:

How do we enable innovation without creating unnecessary risk?

That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision.

ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do.

That's why ThreatLocker is proud to support Cyber Security Headlines.

Because security works best when innovation and control move together.

View Details

Cyber leaders defend Anthropic's banned models

FBI disrupts massive phishing service

1Password acquires Apono

Get the show notes here: https://cisoseries.com/cybersecurity-news-anthropic-models-defended-massive-phishing-service-shuttered-1password-acquires-apono/

Huge thanks to our sponsor, ThreatLocker

Every security leader is being asked the same question right now:

How do we enable innovation without creating unnecessary risk?

That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision.

ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do.

That's why ThreatLocker is proud to support Cyber Security Headlines.

Because security works best when innovation and control move together.

View Details

Feds require Anthropic to ban 'foreign national' access to Fable, Mythos

Maine disables data breach notification portal after fake disclosures

ShinyHunters extorts universities through exploiting an unpatched Oracle flaw

Get the show notes here:

Huge thanks to our sponsor, ThreatLocker

Every security leader is being asked the same question right now:

How do we enable innovation without creating unnecessary risk?

That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind every major technology decision.

ThreatLocker helps organizations take a Zero Trust approach to that challenge—giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do.

That's why ThreatLocker is proud to support Cyber Security Headlines.

Because security works best when innovation and control move together.

View Details

This week's Department of Know is hosted by Rich Stroffolino, with guests Brett Conlon, CISO, American Century Investments, and Jason Thomas, senior director, technology security, governance, and risk, Cystic Fibrosis Foundation.

Missed the live show? Check it out on YouTube.

The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our episode sponsor, Doppel

Cybercriminals don't respect your security silos. They use one connected attack chain to hit your brand externally, infiltrate your inbox, and manipulate your team. Stop playing whack-a-mole with fragmented tools. Doppel unifies Digital Risk Protection, Human Risk Management, and Email Security into one unified platform. One attack chain. Three pillars of defense. Zero blind spots. Secure your enterprise relentlessly at doppel.com.

View Details

Fortinet patches a new critical FortiSandbox flaw

GitHub to disable npm install scripts by default to stop supply chain attacks

Nottingham University announces data breach

Get the show notes here: https://cisoseries.com/cybersecurity-news-fortinet-patches-fortisandbox-github-disables-npm-scripts-nottingham-university-breach/

Thanks to our episode sponsor, Doppel

Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.

View Details

Patch Tuesday for the books 'Nightmare Eclipse' drops Windows 0-day Claude Fable restricted at Microsoft

Get the show notes here: https://cisoseries.com/cybersecurity-news-big-patch-tuesday-nightmare-eclipse-drops-windows-0-day-claude-fable-restricted-at-microsoft/

Thanks to our episode sponsor, Doppel

Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.

View Details

Anthropic releases Claude Fable 5

French government messaging service breached

CISA rethinking risk evaluations

Get the show notes here: https://cisoseries.com/cybersecurity-news-claude-fable-5-tchap-hacked-cisa-priorities/

Thanks to our episode sponsor, Doppel

Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.

View Details

Microsoft malware hits Claude and Gemini users

Mythos can exploit new flaws in hours

AI tool abuse behind Instagram hacks

Get the show notes here: https://cisoseries.com/cybersecurity-news-claude-gemini-malware-mythos-sneaky-flaws-instagram-ai-abuse/

Thanks to our episode sponsor, Doppel

Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.

View Details

Palantir executive considered for CISA leadership

EU unveils tech sovereignty package to cut reliance on U.S., Chinese suppliers

Hackers now exploit SolarWinds Serv-U flaw to crash servers

Get the show notes here: https://cisoseries.com/cybersecurity-news-cisa-palantir-director-eu-tech-sovereignty-solarwinds-serv-u-flaw/

Thanks to our episode sponsor, Doppel

Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.

View Details

This week's Department of Know is hosted by Rich Stroffolino, with guests Robb Dunewood, host, Daily Tech News Show, and David Cross, CISO, Atlassian.

Get the show notes here.

Missed the live show? Check it out on YouTube.

The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.

Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.

View Details

Chinese cybercrime group sets record pace

Cisco warns of critical Unified CM flaw with PoC exploit code

Hackers spied on a stock exchange executive's Outlook mailbox for five months

Get the show notes here: https://cisoseries.com/cybersecurity-news-chinese-cybercrime-group-cisco-cm-flaw-cisa-faces-changes/

Huge thanks to our episode sponsor, Vanta

Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta [rhymes with Santa] Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.

View Details

Law enforcement cracks down on illegal streamers

The European Commission releases digital sovereignty plan

The startup costs for US cyber force

Get the show notes here: https://cisoseries.com/cybersecurity-news-illegal-streamers-eu-digital-sovereignty-cost-of-a-cyber-force/

Huge thanks to our episode sponsor, Vanta

Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta [rhymes with Santa] Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.

View Details

Russia claims officials' surveillance

Project Glasswing access expands

CISA flags two-year-old Oracle flaw

Get the show notes here: https://cisoseries.com/cybersecurity-news-russia-claims-officials-surveillance-project-glasswing-expands-cisa-flags-two-year-old-oracle-flaw/

Huge thanks to our episode sponsor, Vanta

Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta [rhymes with Santa] Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.

View Details

Meta AI hands over Instagram account access

Dutch police dismantle huge botnet

RedHat packages get backdoored

Get the show notes here: https://cisoseries.com/meta-ai-hands-over-instagram-access-dutch-police-dismantle-botnet-redhat-packages-backdoored/

Huge thanks to our episode sponsor, Vanta

Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta [rhymes with Santa] Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.

View Details

Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks

ChatGPT share links used to host fake outage pages to deliver malware

Federal audit reveals NIST's NVD problems

Get the show notes here: https://cisoseries.com/cybersecurity-news-globalprotect-vpn-exploited-chatgpt-share-links-exploits-feds-criticize-nist/

Huge thanks to our episode sponsor, Vanta

Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta [rhymes with Santa] Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk, and drafting fixes for you. Vanta is the platform used by over sixteen thousand fast-moving companies like Ramp, Cursor, and Harvey who are shaping the future with AI, AND staying ahead of AI risk. Get started at vanta.com/headlines.

View Details

This week's Department of Know is hosted by Rich Stroffolino, with guests Bruce Schneier, chief of security architecture, Inrupt, and Chris Ray, field CTO, GigaOm.

Missed the live show? Check it out on YouTube.

Huge thanks to our sponsor, Guardsquare Mobile security incidents are no longer the exception—they are the norm. Last year, seventy-two percent of companies suffered a mobile app security incident. As the primary gateway to your APIs and data, your mobile app requires more than just basic encryption; it needs a multi-layered security strategy. Protect your brand and your bottom line with layered mobile app protection. Learn more at Guardsquare.com.

View Details

Fraud gang steals from World Cup fans

Pentagon says US military targeted by location

IBM and Red Hat commit to "Project Lightwell"

Check out your show notes here: https://cisoseries.com/cybersecurity-news-world-cup-fraud-us-military-location-targets-ibm-and-red-hat-go-project-lightwell/

Huge thanks to our sponsor, Guardsquare

Attackers are treating your mobile app like an open book. Sixty-three percent of security leaders recently detected app tampering, cloning, or unauthorized modifications. When your code runs in an untrusted environment, you need runtime self-protection and code hardening to keep attackers out. Address tampering before it starts. Learn more at Guardsquare.com.

View Details

Glassworm botnet gets shattered

China overhauls world's biggest surveillance network

Charter confirms ShinyHunters data breach

Check out your show notes here: https://cisoseries.com/cybersecurity-news-glassworm-botnet-shattered-china-overhauls-surveillance-charter-confirms-shinyhunters-breach/

Huge thanks to our sponsor, Guardsquare

AI is speeding up development, but at what cost? While ninety-six percent of teams now use AI tools, eighty-one percent report that AI-generated code has introduced new vulnerabilities into their mobile apps. In a world with automated threats, you need multi-layered, polymorphic security to stay ahead of the curve. Learn more at Guardsquare.com.

View Details

Nimbus Manticore learning new tricks

Phishing moves to real-time credential harvesting

India wants 12-hour patches

Check out your show notes here: https://cisoseries.com/cybersecurity-news-nimbus-manticore-real-time-credential-harvesting-12-hour-patches/

Huge thanks to our sponsor, Guardsquare

Is your mobile app truly protected? Relying on the OS isn't enough. A global study of thirteen-hundred security and developer leaders found that ninety-six percent of teams using layered protection reported significantly fewer security incidents. Don't wait for a breach to harden your defenses. Get the protection needed for modern secuirty risks. Learn more at Guardsquare.com.

View Details

'Megalodon' infects GitHub repositories

Netherlands seizes 800 servers over cyberattacks

Ghost CMS exploited for ClickFix attacks

Check out your show notes here: https://cisoseries.com/cybersecurity-news-megalodon-infects-github-netherlands-server-seize-ghost-cms-exploited-for-clickfix/

Huge thanks to our sponsor, Guardsquare

Your backend is only as secure as your frontend. Research shows that client-side compromise is now a primary driver of API risk. With sixty-three percent of leaders detecting mobile app tampering or cloning last year, don't leave your mobile app security to chance. Get multilayered protection for your entire mobile app ecosystem from the outside in. Learn more at Guardsquare.com.

View Details

CISA adds Drupal Core flaw to KEV

Underminr hides malicious connections behind trusted domains

Canadian man charged with running KimWolf DDoS botnet

Check out your show notes here: https://cisoseries.com/cybersecurity-news-drupal-kev-addition-underminr-revives-domain-fronting-canadian-kimwolf-arrest/

Huge thanks to our sponsor, Guardsquare

Mobile app security isn't just a tech issue; it's a revenue issue. A recent global study found that seventy-two percent of organizations experienced a mobile app security incident last year. Even worse? Sixty-five percent saw customer churn or uninstalls as a result. Protect your brand and your bottom line with layered mobile app protection. Learn more at Guardsquare.com.

View Details

This week's Department of Know is hosted by Rich Stroffolino, with guests Kathleen Mullin, former CISO, MyCareGorithm, and Nick Espinosa, host, Deep Dive Radio Show.

Missed the live show? Check it out on YouTube.

The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.

Huge thanks to our sponsor, ThreatLocker ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.

View Details

Cisco issues 10.0 Secure Workload admin flaw warning

Spammers abuse internal Microsoftonline account

Google's surge in Chrome vulnerability announcements

Get the show notes here: https://cisoseries.com/cybersecurity-news-ciscos-10-0-vulnerability-microsoft-email-spammed-chrome-vulnerability-surge/

Thanks to our episode sponsor, ThreatLocker

ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.

View Details

GitHub breach via VS Code extension

Shai-Hulud wave compromises 600 npm packages

Huawei attack behind Luxembourg telecom crash

Get the show notes here: https://cisoseries.com/cybersecurity-news-github-vs-code-extension-breach-shai-hulud-npm-package-compromise-huawei-luxembourg-telecom-link/

Thanks to our episode sponsor, ThreatLocker

ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.

View Details

Microsoft disrupts malware-signing-as-a-service

Critical flaw found in industrial robot OS

CISA admin leaks keys

Get the show notes here: https://cisoseries.com/cybersecurity-news-microsoft-hits-fox-tempest-robotics-os-flaw-cisa-admins-leaks-keys/

Thanks to our episode sponsor, ThreatLocker

ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.

View Details

Linus Torvalds not into AI bug hunters

7-Eleven hit with ransom demand

MENA runs new cybercrime op

Get the show notes here: https://cisoseries.com/cybersecurity-news-linus-torvalds-talks-ai-bug-hunters-7-eleven-ransom-demand-menas-new-cybercrime-op/

Thanks to our episode sponsor, ThreatLocker

ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.

View Details

Grafana GitHub token breach leads to extortion attempt

Microsoft rejects Azure vulnerability report, researcher disputes decision

Funnel Builder flaw actively exploited to steal payment data

Get the show notes here: https://cisoseries.com/cybersecurity-news-grafan-github-extortion-microsoft-rejects-azure-report-funnel-builder-flaw/

Thanks to our episode sponsor, ThreatLocker

ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.

View Details

This week's Department of Know is hosted by Rich Stroffolino, with guests Gary Chan, CISO, SSM Health and Peter Liebert, CISO, Salesloft.

Missed the live show? Check it out on YouTube.

The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.

Huge thanks to our sponsor, Doppel

Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.

View Details

G7 countries release AI SBOM guidance

Dell confirms its SupportAssist software causes Windows BSOD crashes

Dirty Frag sequel arrives as Fragnesia

Get the show notes here: https://cisoseries.com/cybersecurity-news-g7-releases-ai-sbom-dell-supportassist-bsod-dirty-frag-sequel/

Huge thanks to our episode sponsor, Doppel

Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.

View Details

Foxconn confirms North American factory attack

BitLocker zero-day accesses protected drives

MDASH patches 16 Windows flaws

Get the show notes here: https://cisoseries.com/cybersecurity-news-foxconn-factory-attacks-bitlocker-zero-day-accesses-protected-drives-mdash-patches-windows-flaws/↗

Huge thanks to our episode sponsor, Doppel

Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.

View Details

Instructure reaches an "agreement" with ShinyHunters

Shai Hulud campaign is back

OpenAI launches Daybreak

Get the show notes here: https://cisoseries.com/cybersecurity-news-instructures-agreement-shai-hulud-campaign-openais-daybreak/

Huge thanks to our episode sponsor, Doppel

Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.

View Details

A.I. hackers find software flaw

Xbox leaks 'Forza Horizon 6'

Linux kernel hit by 2nd flaw

Get the show notes here: https://cisoseries.com/cybersecurity-news-a-i-software-flaw-hackers-forza-horizon-6-leak-linux-kernel-hit-again/

Huge thanks to our episode sponsor, Doppel

Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.

View Details

CPanel, WHM release fixes for three new vulnerabilities

Official JDownloader site serves malware to Windows and Linux users

Sen. Schumer seeks DHS plan on AI cyber coordination

Get the show notes here: https://cisoseries.com/cybersecurity-news-new-cpanel-vulnerabilities-jdownloader-delivers-malware-schumer-pushes-dhs/

Huge thanks to our episode sponsor, Doppel

Social engineering attacks look trustworthy — a routine request, an internal email, a familiar face on a call. But Doppel sees through the disguise. Our AI-native platform detects and disrupts attacks across every channel, while training employees to recognize deepfakes and deception. We fight relentlessly to protect your business, brand, and people. Doppel. Outpacing what's next in social engineering. Learn more at doppel.com.

View Details

Link to the episode

This week's Department of Know is hosted by Rich Stroffolino, with guests Jonathan Waldrop, CISO, Acoustic, and Jason Elrod, CISO, MultiCare Health System.

Missed the live show? Check it out on YouTube.

The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.

Huge thanks to our sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

View Details

PAN-OS RCE exploit under active use enabling root access and espionage

Polish intelligence says hackers attacked water treatment control systems

Ivanti warns of new EPMM flaw exploited in zero-day attacks

Get the show notes here: https://cisoseries.com/cybersecurity-news-pan-os-rce-exploit-poland-water-hacks-ivanti-epmm-flaw/

Thanks to our episode sponsor, Vanta

Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

View Details

Google Chrome installs 4GB AI model on devices

Daemon Tools disk app backdoored in supply-chain attack

Crypto's 'decentralised finance' sector hit by investor exodus

Get the show notes here:

Thanks to our episode sponsor, Vanta

Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

View Details

Video game platform hit by supply chain attack

Bleeding Llama could expose your data

US gets more early LLM access

Get the show notes here: https://cisoseries.com/cybersecurity-news-video-game-supply-chain-attack-bleeding-llama-us-gets-early-llm-access/

Thanks to our episode sponsor, Vanta

Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

View Details

Instructure discloses breach amid leak threats

DigiCert revokes certificates

Silver Fox targets Indian and Russian orgs

Get the show notes here: https://cisoseries.com/cybersecurity-news-instructure-discloses-breach-digicert-revokes-certificates-silver-fox-targets-indian-and-russian-orgs/

Thanks to our episode sponsor, Vanta

Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

View Details

Telegram Mini Apps deliver Android malware

CISA orders Federal agencies to patch cPanel bug by Sunday

British cyber agency warns of looming 'patch wave' due to speedy AI flaw discovery

Get the show notes here: https://cisoseries.com/cybersecurity-news-telegram-mini-apps-malware-cpanel-is-sorry-patch-wave-warning/

Thanks to our episode sponsor, Vanta

Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

View Details

This week's Department of Know is hosted by Rich Stroffolino, with guests Janet Heins, CISO, ChenMed, and TC Niedzialkowski, Head of IT & Security, Opendoor.

Missed the live show? Check it out on YouTube.

The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.

Get the show notes here: https://cisoseries.com/cybersecurity-news-critical-cpanel-zero-day-swiss-black-axe-arrests-hhs-data-center-questions/

Thanks to our episode sponsor, Guardsqaure

Attackers are treating your mobile app like an open book. Sixty-three percent of security leaders recently detected app tampering, cloning, or unauthorized modifications. When your code runs in an untrusted environment, you need runtime self-protection and code hardening to keep attackers out. Address tampering before it starts. Learn more at Guardsquare.com.

View Details

Critical cPanel and WHM bug exploited as zero-day

Swiss police arrest suspected members of Black Axe group

HHS ponders government posture for protecting data centers

Get the show notes here: https://cisoseries.com/cybersecurity-news-critical-cpanel-zero-day-swiss-black-axe-arrests-hhs-data-center-questions/

Thanks to our episode sponsor, Guardsqaure

Attackers are treating your mobile app like an open book. Sixty-three percent of security leaders recently detected app tampering, cloning, or unauthorized modifications. When your code runs in an untrusted environment, you need runtime self-protection and code hardening to keep attackers out. Address tampering before it starts. Learn more at Guardsquare.com.

View Details

Hackers arrested for selling Roblox accounts

Microsoft's patch for a 0-day falls short

US & China partner on Dubai scam takedown

Get the show notes here: https://cisoseries.com/cybersecurity-news-roblox-hackers-arrested-microsoft-0-day-falls-short-dubai-scam-takedown/

Thanks to our episode sponsor, Guardsqaure

AI is speeding up development, but at what cost? While ninety-six percent of teams now use AI tools, eighty-one percent report that AI-generated code has introduced new vulnerabilities into their mobile apps. In a world with automated threats, you need multi-layered, polymorphic security to stay ahead of the curve. Learn more at Guardsquare.com.

View Details

FIDO Alliance working on securing AI agent payments

Germany suspects Russia in Signal phishing

RCE flaw in open-source robotics platform

Get the show notes here: https://cisoseries.com/cybersecurity-news-agent-payments-russian-phishing-lerobot-rce-flaw/

Thanks to our episode sponsor, Guardsqaure

Is your mobile app truly protected? Relying on the OS isn't enough. A global study of thirteen-hundred security and developer leaders found that ninety-six percent of teams using layered protection reported significantly fewer security incidents. Don't wait for a breach to harden your defenses. Get the protection needed for modern secuirty risks. Learn more at Guardsquare.com.

View Details

PhantomRPC flaw enables privilege escalation

Checkmarx confirms GitHub data hit dark web

PyPI package hacked to push infostealer

Get the show notes here: https://cisoseries.com/cybersecurity-news-phantomrpc-flaw-checkmarx-github-dark-web-data-pypi-package-infostealer/

Thanks to our episode sponsor, Guardsqaure

Your backend is only as secure as your frontend. Research shows that client-side compromise is now a primary driver of API risk. With sixty-three percent of leaders detecting mobile app tampering or cloning last year, don't leave your mobile app security to chance. Get multilayered protection for your entire mobile app ecosystem from the outside in. Learn more at Guardsquare.com.

View Details

ADT says customer data stolen in cyberattack

SMS blasting comes to Toronto

Researchers find pre-Stuxnet malware targeting engineering software

Get the show notes here: https://cisoseries.com/cybersecurity-news-adt-data-breach-toronto-sms-blasting-pre-stuxnet-malware-discovery/

Thanks to our episode sponsor, Guardsquare

Mobile app security isn't just a tech issue; it's a revenue issue. A recent global study found that seventy-two percent of organizations experienced a mobile app security incident last year. Even worse? Sixty-five percent saw customer churn or uninstalls as a result. Protect your brand and your bottom line with layered mobile app protection. Learn more at Guardsquare.com.

View Details

Link to episode

This week's Department of Know is hosted by Rich Stroffolino, with guests Brett Conlon, CISO, American Century Investments, and Michael Bickford, former CISO, New York State Gaming Commission.

Missed the live show? Check it out on YouTube.

The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com.

Huge thanks to our sponsor, ThreatLocker ThreatLocker is extending Zero Trust beyond endpoint control. With their recent release of Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.

View Details

Cosmetics giant Rituals discloses data breach

Apple fixes iOS flaw exploited by the FBI

Microsoft Teams Helpdesk impersonation

Get the show notes here: https://cisoseries.com/cybersecurity-news-rituals-cosmetics-breach-fbi-ios-flaw-fixed-teams-helpdesk-malware-impersonation/

Huge thanks to our sponsor, ThreatLocker

ThreatLocker is extending Zero Trust beyond endpoint control. With their recent releaseof Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.

View Details

OpenAI shares cyber product with government orgs

Unauthorized Mythos access, Firebox bugs fixed by Mythos

Insurers move to cap LLMjacking cyber payouts

Get the show notes here: https://cisoseries.com/cybersecurity-news-new-openai-cyber-product-unauthorized-mythos-access-insurers-to-cap-llmjacking-payouts/

Huge thanks to our sponsor, ThreatLocker

ThreatLocker is extending Zero Trust beyond endpoint control. With their recent releaseof Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.

View Details

CISA lacks Mythos access

Lovable denies data leak

YouTube opens up deepfake detection tool

Get the show notes here: https://cisoseries.com/cybersecurity-news-cisa-lacks-mythos-lovables-leak-by-design-youtubes-deepfake-detection/

Huge thanks to our sponsor, ThreatLocker

ThreatLocker is extending Zero Trust beyond endpoint control. With their recent releaseof Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.

View Details

Vercel confirms breach, stolen data for sale

ZionSiphon targets water infrastructure

Bluesky blames outage on DDoS

Get the show notes here: https://cisoseries.com/cybersecurity-news-vercel-breach-zionsiphon-targets-water-infrastructure-bluesky-ddos/

Huge thanks to our sponsor, ThreatLocker

ThreatLocker is extending Zero Trust beyond endpoint control. With their recent releaseof Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.

View Details

London hospitals continue to suffer from 2024 ransomware attack

Four arrested in PowerOFF takedown

Microsoft Defender "RedSun" zero-day

Get the show notes here: https://cisoseries.com/cybersecurity-news-london-hospital-ransomware-legacy-poweroff-takedown-microsoft-redsun-zero-day/

Huge thanks to our sponsor, ThreatLocker

ThreatLocker is extending Zero Trust beyond endpoint control. With their recent releaseof Zero Trust Network Access and Zero Trust Cloud Access, access isn't based on credentials alone, it requires the right user, the right device, and the right conditions. Because as we've seen in recent large-scale CRM breaches, stolen credentials and misconfigurations can expose massive amounts of data. With ThreatLocker, nothing is exposed, and access is limited to exactly what's needed. Learn more and start your free trial today at ThreatLocker.com/CISO.

View Details

Link to episode page

This week's Department of Know is hosted by Rich Stroffolino, with guests Andrew Storms, security engineering, Kilo Code, and Eduardo Ortiz-Romeu, VP, global head of cybersecurity, Techtronic Industries.

Missed the live show? Check it out on YouTube.

Huge thanks to our sponsor, Conveyor

Happy Friday. Hope there isn't a fresh security questionnaire sitting in your inbox right now. If there is, here's something worth knowing. The teams that have fully automated their customer security reviews didn't just get a better trust center. They switched to an AI platform built for the whole workflow. Conveyor handles trust center, questionnaire automation, and self-serve for sales, all in one place, with AI keeping the knowledge base current so answers are always accurate. Learn why enterprise SaaS teams choose Conveyor at conveyor.com.

View Details

Cisco posts urgent Webex Services warning

Splunk issues fixes for Enterprise vulnerability

Git identity spoof tricks Claude into approving bad code

Get the show notes here: https://cisoseries.com/cybersecurity-news-cisco-webex-warning-splunks-enterprise-fix-git-spoof-tricks-claude/

Huge thanks to our sponsor, Conveyor

Happy Friday. Hope there isn't a fresh security questionnaire sitting in your inbox right now. If there is, here's something worth knowing. The teams that have fully automated their customer security reviews didn't just get a better trust center. They switched to an AI platform built for the whole workflow. Conveyor handles trust center, questionnaire automation, and self-serve for sales, all in one place, with AI keeping the knowledge base current so answers are always accurate. Learn why enterprise SaaS teams choose Conveyor at conveyor.com.

View Details

OpenAI rolls out GPT-5.4-Cyber

McGraw Hill breach due to Salesforce misconfig

Signed adware operation disables antivirus

Get the show notes here: https://cisoseries.com/cybersecurity-news-openais-gpt-5-4-cyber-mcgraw-hill-blames-salesforce-for-breach-signed-adware-disables-antivirus/

Huge thanks to our sponsor, Conveyor

At some point, every fast-growing SaaS team hits the same wall. The trust center is live. The SOC 2 is published. And somehow the security questionnaires just keep piling up. That's when teams realize a static trust center isn't the finish line. Conveyor is what comes next. AI that completes questionnaires automatically. A trust center customers can actually self-serve. And a knowledge base that updates itself with AI. Companies like Atlassian and Zapier are already there. See what's possible at conveyor.com.

View Details

Ransomware rivals turn on each other

Fake Ledger app drains millions in crypto

US Treasury wants access to Mythos

Get the show notes here: https://cisoseries.com/cybersecurity-news-ransomware-drama-faked-ledger-app-treasury-wants-mythos/

Huge thanks to our sponsor, Conveyor

Your trust center was a great start. But if your team is still manually answering questionnaires and fielding sales questions, it hasn't solved the problem. Conveyor goes beyond a trust center. You get a living knowledge library your AI keeps up to date, questionnaire automation that handles any format, and a self-serve experience so customers and sales teams get answers without looping in infosec. Top enterprise SaaS companies trust Conveyor to handle it all. Check it out at conveyor.com.

View Details

Claude Mythos Preview's cyber capabilities

Anodot hack leaves breached companies facing extortion

wolfSSL library flaw enables forged certificate use

Get the show notes here: https://cisoseries.com/cybersecurity-news-claude-mythos-previews-capabilities-anodot-breached-companies-face-extortion-wolfssl-flaw-enables-forged-certificates/

Huge thanks to our sponsor, Conveyor

Three tools to manage customer security reviews is two too many. Most teams start with a trust center, bolt on a questionnaire tool, and end up with a knowledge base nobody trusts and a Slack channel full of sales pings anyway. Conveyor replaces all of it. Trust center, questionnaire automation, self-serve for sales, AI-managed knowledge library, one platform. Companies like Atlassian and Zapier already made the switch. See why at conveyor.com.

View Details

A quick announcement: we're moving our Department of Know livestream to Fridays at 4pm ET/1 pm PT. The format will remain the same. We hope to see you there.

View Details

Adobe patches months-old Reader zero-day

Critical Marimo flaw now under active exploitation

Hackers claim control over Venice anti-flood pumps

Get the show notes here: https://cisoseries.com/cybersecurity-news-adobe-patches-zero-day-marimo-flaw-exploited-venice-flood-threat/

Huge thanks to our sponsor, Conveyor

Still manually filling out security questionnaires even though you have a trust center? A starter trust center is table stakes and the best security teams have moved way past that. Conveyor gives you an agentic trust center, AI questionnaire automation, and a self-serve layer so sales can move deals forward without pinging you every five minutes. Companies like Atlassian and Zapier made the switch. See why at conveyor.com.

View Details

Google API keys in Android apps expose Gemini endpoints

Acrobat Reader zero-day flaw exploited since December

Cryptocurrency ATM company Bitcoin Depot reports cyberattack

Check out our show notes here: https://cisoseries.com/cybersecurity-news-android-api-exposure-acrobat-reader-zero-day-bitcoin-depot-cyberattack/

Huge thanks to our episode sponsor, Vanta

Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

View Details

Ransomware knocks Dutch healthcare vendor offline

APT28 is keeping busy

CIA quietly elevated its cyber espionage division

Check out our show notes here: https://cisoseries.com/cybersecurity-news-chipsoft-popped-apt28-updates-cia-cyber-espionage-elevation/

Huge thanks to our episode sponsor, Vanta

Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

View Details

Anthropic announces Project Glasswing

U.S. seeks to slash CISA funding

Russia-linked hackers hijack routers for passwords

Check out our show notes here: https://cisoseries.com/cybersecurity-news-anthropics-project-glasswing-cisa-funding-in-doubt-routers-hijacked-for-passwords/

Huge thanks to our episode sponsor, Vanta

Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

View Details

Drift says exploit was North Korean intelligence operation

GitHub used in multi-stage attacks targeting South Korea

Data leak threatened after Die Linke attack

Check out our show notes here: https://cisoseries.com/cybersecurity-news-drift-blames-exploit-on-north-korea-github-attacks-target-south-korea-die-linke-breach-threatens-data-leak/

Huge thanks to our episode sponsor, Vanta

Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

View Details

Link to episode page

This week's Department of Know is hosted by Sarah Lane, with guests Jack Kufahl, CISO, Michigan Medicine, and Adam Palmer, CISO, First Hawaiian Bank.

Missed the live show? Check it out on YouTube.

Huge thanks to our sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

View Details

36 Malicious npm packages exploited to deploy persistent implants

Hundreds of millions to be cut from CISA in proposed budget

Hackers exploit React2Shell in automated credential theft campaign

Check out our show notes here: https://cisoseries.com/cybersecurity-news-malicious-npm-packages-cisa-budget-cuts-hackers-exploit-react2shell/

Huge thanks to our episode sponsor, Vanta

Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps your deals moving. Learn more at vanta.com/ciso.

View Details

250,000 affected by data Breach at Texas hospital

CISA says, "patch Citrix NetScaler bug by Thursday"

Researchers uncover mining operation using ISO lures

Get the show notes here: https://cisoseries.com/cybersecurity-news-texas-hospital-breach-cisa-orders-netscaler-patch-iso-file-rat-warning/

Huge thanks to our sponsor, ThreatLocker

Security controls fail when they break the business. Successful teams phase in protections gradually — starting with visibility, then moving to enforcement. That approach allows organizations to reduce risk without overwhelming IT teams or disrupting critical workflows. Learn more at ThreatLocker.com

View Details

Apple pushes new patches over DarkSword

FBI: US surveillance hack is major incident

Cisco code stolen in Trivy-linked breach

Get the show notes here: https://cisoseries.com/cybersecurity-news-apple-pushes-new-patches-over-darksword-fbi-us-surveillance-hack-is-major-incident-cisco-code-stolen-in-trivy-linked-breach/

Huge thanks to our sponsor, ThreatLocker

Detection-based security assumes you'll catch an attack in time. Control-based security assumes you won't. That mindset shift is driving more organizations to focus on preventative controls — stopping unknown execution and unauthorized privilege elevation instead of relying solely on alerts after the fact. Learn more at ThreatLocker.com

View Details

HTTP client introduces malicious dependency

TeamPCP testing the open source supply chain

Claude source code leaked

Get the show notes here: https://cisoseries.com/cybersecurity-news-axios-poisoned-teampcp-details-claude-code-leaked/

Huge thanks to our sponsor, ThreatLocker

Least privilege isn't about distrusting users — it's about limiting blast radius. Many attacks succeed because malware inherits excessive permissions. Enforcing least privilege helps ensure that even if something goes wrong, attackers can't easily escalate access or move laterally across the environment. Learn more at ThreatLocker.com

View Details

macOS Terminal gets ClickFix attacks

Russian court sentences 'Flint' over card fraud

CareCloud probes data breach

Get the show notes here: https://cisoseries.com/cybersecurity-news-macos-terminal-clickfix-attacks-russian-court-sentences-flint-carecloud-probes-data-breach/

Huge thanks to our sponsor, ThreatLocker

Ransomware doesn't need to be sophisticated if it's allowed to execute. A growing number of security teams are shifting focus from detecting ransomware to preventing execution in the first place — controlling applications, scripts, and installers so unauthorized code never gets the chance to run. Learn more at ThreatLocker.com

View Details

Link to episode page

This week's Department of Know is hosted by Rich Stroffolino with guests Dennis Pickett, vp, CISO, RTI International, and Jacob Combs, CISO, Tandem Diabetes Care

Thanks to our show sponsor, ThreatLocker

Many security strategies still assume everything is allowed until proven malicious. Attackers understand that model well. That's why more organizations are rethinking endpoint security — shifting from detection-first tools to control-first approaches that reduce attack surface before an incident occurs. Learn more at ThreatLocker.com

All links and the video of this episode can be found on CISO Series.com

View Details

FBI confirms theft of director's personal emails

Lloyds customer data exposed in IT glitch

Hundreds of valid API keys discovered on the Web

Get the show notes here: https://cisoseries.com/cybersecurity-news-fbi-email-theft-lloyds-bank-glitch-api-keys-running-loose/

Huge thanks to our sponsor, ThreatLocker

Most breaches don't start with a zero-day — they start because something unexpected was allowed to run. One way organizations reduce risk is by shrinking the attack surface: deciding what software should be allowed to execute and blocking everything else by default. Fewer unknowns means fewer opportunities for attackers. Learn more at ThreatLocker.com

View Details

Alleged RedLine dev extradited to US

Red Menshen uses BPFDoor to spy

Former NSA chiefs worry US cybersecurity is slipping

Check out our show notes for all story links: https://cisoseries.com/cybersecurity-news-alleged-redline-dev-extradited-red-menshen-spies-with-bpfdoor-is-us-cybersecurity-slipping/

Huge thanks to our sponsor, ThreatLocker

Security controls fail when they break the business. Successful teams phase in protections gradually — starting with visibility, then moving to enforcement. That approach allows organizations to reduce risk without overwhelming IT teams or disrupting critical workflows. Learn more at ThreatLocker.com

View Details

Torg Grabber targets crypto wallets

TeamPCP backdoors LiteLLM

GitHub adds AI security bug detection

Check out our show notes for all story links: https://cisoseries.com/cybersecurity-news-torg-grabber-targets-crypto-teampcp-backdoors-litellm-github-ai-bug-detection/

Huge thanks to our sponsor, ThreatLocker

Detection-based security assumes you'll catch an attack in time. Control-based security assumes you won't. That mindset shift is driving more organizations to focus on preventative controls — stopping unknown execution and unauthorized privilege elevation instead of relying solely on alerts after the fact. Learn more at ThreatLocker.com

View Details

FCC bans foreign routers

Drone activity disrupts AWS region

Crunchyroll confirmed data leak

Check out our show notes for all story links: https://cisoseries.com/cybersecurity-news-fcc-router-ban-drone-hit-aws-crunchroll-leak/

Huge thanks to our sponsor, ThreatLocker

Least privilege isn't about distrusting users — it's about limiting blast radius. Many attacks succeed because malware inherits excessive permissions. Enforcing least privilege helps ensure that even if something goes wrong, attackers can't easily escalate access or move laterally across the environment. Learn more at ThreatLocker.com

View Details

New DarkSword exploit hits GitHub

Gemini AI agents scour the dark web

Trivy supply chain attack expands

Check out our show notes for all story links: https://cisoseries.com/cybersecurity-news-darksword-exploit-hits-github-gemini-ai-agents-scour-dark-web-trivy-supply-chain-attack-expands/

Huge thanks to our sponsor, ThreatLocker

Ransomware doesn't need to be sophisticated if it's allowed to execute. A growing number of security teams are shifting focus from detecting ransomware to preventing execution in the first place — controlling applications, scripts, and installers so unauthorized code never gets the chance to run. Learn more at ThreatLocker.com

View Details

Link to episode page

This week's Department of Know is hosted by Rich Stroffolino with guests Bil Harmer, CISO, Supabase, and Chris Ray, Field CTO, GigaOm

Thanks to our show sponsor, ThreatLocker

Many security strategies still assume everything is allowed until proven malicious. Attackers understand that model well. That's why more organizations are rethinking endpoint security — shifting from detection-first tools to control-first approaches that reduce attack surface before an incident occurs. Learn more at ThreatLocker.com

All links and the video of this episode can be found on CISO Series.com

View Details

Law enforcement seizes botnet infrastructure

California city and LA transit agency report cybersecurity issues

Microsoft Azure Monitor alerts used for callback phishing attacks

Check out our show notes for all story links: https://cisoseries.com/cybersecurity-news-cybersecurity-news-international-botnet-takedown-california-city-ransomed-azure-monitor-phishing/

Huge thanks to our sponsor, ThreatLocker

Most breaches don't start with a zero-day — they start because something unexpected was allowed to run. One way organizations reduce risk is by shrinking the attack surface: deciding what software should be allowed to execute and blocking everything else by default. Fewer unknowns means fewer opportunities for attackers. Learn more at ThreatLocker.com

View Details

Critical Microsoft SharePoint flaw now exploited in attacks

1stProtect reveals endpoint security platform intended to prevent cyberattacks in real time

CISA urges U.S. organizations to secure Microsoft Intune systems following Stryker breach

Get links to all our stories in the show notes: https://cisoseries.com/cybersecurity-news-critical-sharepoint-flaw-real-time-cyberattack-prevention-cisas-intune-warning/

Huge thanks to our episode sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Picture a "new hire" who interviews well… except they're synthetic: AI video, AI voice, AI backstory. Once they're in, they go after payroll, internal docs, and access. That's the new reality: the attack surface is trust itself. Adaptive fights back with realistic deepfake simulations and training that actually sticks. Learn more at adaptivesecurity.com.

View Details

DarkSword emerges from suspected Russian hackers

"ShieldGuard" dismantled after malware discovery

North Korea's fake IT worker army rakes in $500M/year

Get links to all our stories in the show notes: https://cisoseries.com/cybersecurity-news-darksword-emerges-shieldguard-dismantled-nk-it-worker-army-rakes-in-money/

Huge thanks to our episode sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Picture a "new hire" who interviews well… except they're synthetic: AI video, AI voice, AI backstory. Once they're in, they go after payroll, internal docs, and access. That's the new reality: the attack surface is trust itself. Adaptive fights back with realistic deepfake simulations and training that actually sticks. Learn more at adaptivesecurity.com.

View Details

Energy Department to release first cyber strategy

Tech giants sign on to fight scammers

Font-rendering hides malicious commands from AI in plain sight

Get links to all our stories in the show notes: https://cisoseries.com/cybersecurity-news-energy-strategy-scammer-accord-font-rendering-attack/

Huge thanks to our episode sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Attackers don't need malware anymore; they need trust. Tip: set a simple passphrase for high-risk actions, like wire requests or "urgent" account recovery – especially within finance teams and families. If the caller can't answer it, pause and verify. Adaptive runs deepfake and vishing simulations so employees practice this before it's real. Learn more at adaptivesecurity.com.

View Details

Stryker hospital tools safe, digital ordering services down

Models apply to be the face of AI scams

Cybercrime up 245% since Iran conflict

Get links to all our stories in the show notes: https://cisoseries.com/cybersecurity-news-stryker-hospital-tools-safe-models-apply-to-power-ai-scams-cybercrime-up-245/

Huge thanks to our episode sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Today's phishing doesn't just hit inboxes — it can sound like your CFO or look like your CEO on Zoom. AI voices, video, and deepfakes are turning trust into the attack surface. Adaptive fights back with AI-driven risk scoring, deepfake simulations featuring your own executives, and interactive training your team will actually remember. Take a three-minute tour or request a CEO deepfake demo at adaptivesecurity.com.

View Details

Link to episode page

This week's Department of Know is hosted by Rich Stroffolino with guests Jonathan Waldrop, CISO, Acoustic, and Chris Ray, Field CTO, GigaOm

Thanks to our show sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Deepfakes aren't science fiction anymore; they're a daily threat. Quick tip: if your voicemail greeting is your real voice, switch it to the default robot voice. A few seconds of audio can be enough to clone you. Adaptive helps teams spot and stop these AI-powered social engineering attacks. Learn more at adaptivesecurity.com.

All links and the video of this episode can be found on CISO Series.com

View Details

Payload Ransomware group claims breached of Royal Bahrain Hospital

Canadian food retailer Loblaw confirms data breach

New York cyber regulations for water organizations launch in 2027

Get links to all our stories in the show notes: https://cisoseries.com/cybersecurity-news-royal-bahrain-hospital-breach-canadas-loblaw-breached-new-york-water-laws/

Huge thanks to our episode sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Deepfakes aren't science fiction anymore; they're a daily threat. Quick tip: if your voicemail greeting is your real voice, switch it to the default robot voice. A few seconds of audio can be enough to clone you. Adaptive helps teams spot and stop these AI-powered social engineering attacks. Learn more at adaptivesecurity.com.

View Details

Iran boosts cyberattacks

VENON targets Brazilian banks

England Hockey investigates breach

Get links to all the stories in our show notes: https://cisoseries.com/cybersecurity-news-iran-boosts-cyberattacks-venon-targets-brazilian-banks-england-hockey-investigates-breach/

Huge thanks to our sponsor, Dropzone AI

If you are heading to RSAC next week, here are three things worth seeing at the Dropzone AI Diner. Booth 455, South Expo Hall. One: watch their AI SOC agents investigate real alerts live, with every reasoning step exposed. Two: meet the AI Threat Hunter, the newest agent joining the team. Three: enter the investigation competition and go head to head against the AI. Schedule your stop at dropzone.ai/rsa-2026-ai-diner.

View Details

Meta apps offer new scam protection

Google's Wiz acquisition finalized

China curbs state-run OpenClaw use

Get links to all the stories in our show notes: https://cisoseries.com/cybersecurity-news-meta-offers-scam-protection-googles-wiz-acquisition-finalized-china-curbs-openclaw-use/

Huge thanks to our sponsor, Dropzone AI

Here is something worth asking any AI security vendor you meet at RSAC. Can you show me exactly what your AI did? Not just the verdict. The reasoning. Every tool it queried, every piece of evidence, every step it took to get there. Most cannot. Dropzone AI can. Every investigation is fully transparent. You do not have to trust the AI. You can verify it. See it for yourself at Booth 455. dropzone.ai/rsa-2026-ai-diner

View Details

NSA and Cyber Command head confirmed

Russians targeting encrypted messaging app users

OpenAI rolls out vulnerability scanner

Get links to all the stories in our show notes: https://cisoseries.com/cybersecurity-news-march-11-2026/

Huge thanks to our sponsor, Dropzone AI

Remember yesterday's 3 AM threat intel? Here is how it plays out with Dropzone AI. The intelligence drops. Dropzone picks it up, turns it into a threat hunt, and runs it across your SIEM, EDR, and cloud data while your team sleeps. By morning, your analysts have answers, not a backlog. That is the AI Threat Hunter, the newest agent on the team, debuting at RSAC. Booth 455, South Expo Hall. dropzone.ai/rsa-2026-ai-diner

View Details

InstallFix attacks spread fake Claude code sites

UNC4899 breaches crypto firm via trojanized file

UK launches cyber-fraud crackdown unit

Get links to all the stories in our show notes: https://cisoseries.com/cybersecurity-news-installfix-spreads-fake-claude-sites-unc4899-breaches-crypto-uk-cyber-fraud-crackdown/

Huge thanks to our sponsor, Dropzone AI

It is 3 AM. New threat intelligence drops. An attack pattern targeting your industry. Your threat hunting team is four people, all on day shift, and already behind on last week's hunts. By the time someone gets to it, the window for early detection has closed. The attacker is already inside. Tomorrow, I will tell you what Dropzone AI is bringing to RSAC to solve exactly this problem. If you cannot wait, head to dropzone.ai/rsa-2026-ai-diner.

View Details

Link to episode page

This week's Department of Know is hosted by Sarah Lane with guests John Barrow, CISO, JB Poindexter & Co., and Derek Fisher, Director of the Cyber Defense and Information Assurance Program, Temple University

Thanks to our show sponsor, Dropzone AI

Here is a number worth knowing before RSAC. The average enterprise SOC sees tens of thousands of alerts a day. Most get triaged. A fraction get thoroughly investigated. The rest sit in the queue or get auto-closed. Dropzone AI puts AI SOC agents on every one of those alerts. Every alert investigated, end to end, across your full tool stack, around the clock. Over 300 deployments in production today. They are at RSAC this year. Booth 455. dropzone.ai/rsa-2026-ai-diner

All links and the video of this episode can be found on CISO Series.com

View Details

FBI investigates suspicious activities on agency network

Over 100 GitHub repositories distributing BoryptGrab stealer

Hackers abuse .arpa DNS and ipv6 to evade phishing defenses

Get links to all the stories in our show notes: https://cisoseries.com/cybersecurity-news-fbi-network-breach-github-distributes-stealer-hackers-abuse-arpa/

Huge thanks to our sponsor, Dropzone AI

Here is a number worth knowing before RSAC. The average enterprise SOC sees tens of thousands of alerts a day. Most get triaged. A fraction get thoroughly investigated. The rest sit in the queue or get auto-closed. Dropzone AI puts AI SOC agents on every one of those alerts. Every alert investigated, end to end, across your full tool stack, around the clock. Over 300 deployments in production today. They are at RSAC this year. Booth 455. dropzone.ai/rsa-2026-ai-diner

View Details

Apple blocks ByteDance Chinese apps

Google says 90 zero-days were exploited in attacks last year

Iran intelligence backdoored U.S. bank, airport, software outfit networks

Get the show notes here: https://cisoseries.com/cybersecurity-news-apple-blocks-bytedance-googles-90-zero-days-iran-backdoors-u-s-organizations/

Huge thanks to our sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Security training fails when it's generic. Adaptive's platform personalizes training and runs deepfake simulations across email, SMS, voice, and video. And with Adaptive's AI Content Creator, you can drop in a breaking threat or compliance doc and instantly turn it into interactive, multilingual training – no designers, no delays. Learn more at adaptivesecurity.com.

View Details

Possible iPhone-hacking toolkit used by spies

Hacker mass-mails HungerRush extortion emails

Tycoon 2FA phishing platform dismantled

Get the show notes here: https://cisoseries.com/cybersecurity-news-iphone-hacking-toolkit-used-by-spies-hungerrush-extortion-emails-tycoon-phishing-platform-dismantled/

Huge thanks to our sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Picture a "new hire" who interviews well… except they're synthetic: AI video, AI voice, AI backstory. Once they're in, they go after payroll, internal docs, and access. That's the new reality: the attack surface is trust itself. Adaptive fights back with realistic deepfake simulations and training that actually sticks. adaptivesecurity.com.

View Details

Quantum decryption gets theoretically easier

OpenAI alters the deal with the Pentagon

South Korea leaks crypto keys for all to see

Get the show notes here: https://cisoseries.com/cybersecurity-news-quantum-decryption-openais-deal-south-korea-leaks-crypto-keys/

Huge thanks to our sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Attackers don't need malware anymore; they need trust. Tip: set a simple passphrase for high-risk actions, like wire requests or "urgent" account recovery – especially within finance teams and families. If the caller can't answer it, pause and verify. Adaptive runs deepfake and vishing simulations so employees practice this before it's real. adaptivesecurity.com.

View Details

Chrome unveils quantum-safe certificates

Vulnerability allowed hijacking Gemini Live

UK warns of Iranian cyberattack risks

Get the show notes here: https://cisoseries.com/cybersecurity-news-chrome-quantum-safe-certificates-gemini-live-vulnerability-uk-warns-of-iranian-cyberattacks/

Huge thanks to our sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Today's phishing doesn't just hit inboxes — it can sound like your CFO or look like your CEO on Zoom. AI voices, video, and deepfakes are turning trust into the attack surface. Adaptive fights back with AI-driven risk scoring, deepfake simulations featuring your own executives, and interactive training your team will actually remember. Take a three-minute tour or request a CEO deepfake demo at adaptivesecurity.com.

View Details

Link to episode page

This week's Department of Know is hosted by Rich Stroffolino with guests Dan Holden, CISO, Commerce, and Mark Eggleston, CISO, CSC

Thanks to our show sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. AI is rewriting the cybersecurity rulebook, because attackers can now scale persuasion as easily as they scale code. The real target isn't just your systems anymore; it's human trust. If you aren't actively testing your organization against AI-driven phishing, vishing, and deepfakes, you're leaving a gap criminals will exploit. Adaptive runs realistic simulations and delivers tailored, engaging training so teams respond correctly when it counts. Learn more at adaptivesecurity.com.

All links and the video of this episode can be found on CISO Series.com

View Details

Gottumukkala ousted as CISA Director

Ron Wyden blocks Rudd confirmation to lead Cyber Command, NSA

Hackers Weaponize Claude Code in Mexican government cyberattack

Get the show notes here: https://cisoseries.com/cybersecurity-news-gottumukkala-ousted-wyden-blocks-rudd-hackers-weaponize-claude/

Huge thanks to our sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Deepfakes aren't science fiction anymore; they're a daily threat. Quick tip: if your voicemail greeting is your real voice, switch it to the default robot voice. A few seconds of audio can be enough to clone you. Adaptive helps teams spot and stop these AI-powered social engineering attacks. Learn more at adaptivesecurity.com.

View Details

iPhone and iPad cleared for classified NATO work

U.S. Education and Healthcare targeted with Dohdoor backdoor

Trend Micro warns of critical Apex One code execution flaws

Get links to all of today's news in our show notes here: https://cisoseries.com/cybersecurity-news-nato-adopts-apple-education-and-healthcare-backdoor-apex-one-flaws/

Thanks to today's episode sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Security training fails when it's generic. Adaptive's platform personalizes training and runs deepfake simulations across email, SMS, voice, and video. And with Adaptive's AI Content Creator, you can drop in a breaking threat or compliance doc and instantly turn it into interactive, multilingual training – no designers, no delays. Learn more at adaptivesecurity.com.

View Details

Google disrupts UNC2814

3M+ impacted by TriZetto breach

Cisco bug exploited since 2023

Get links to all of today's news in our show notes here:

Thanks to today's episode sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Picture a "new hire" who interviews well… except they're synthetic: AI video, AI voice, AI backstory. Once they're in, they go after payroll, internal docs, and access. That's the new reality: the attack surface is trust itself. Adaptive fights back with realistic deepfake simulations and training that actually sticks. adaptivesecurity.com.

View Details

Threat actors break out in under 30 minutes

Claude allegedly hit with distillation attacks

DeFi platform shutting down after crypto theft

Get links to all of today's news in our show notes here: https://cisoseries.com/cybersecurity-news-hacked-in-30-minutes-claude-distillation-defi-shutdown-after-attack/

Thanks to today's episode sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Attackers don't need malware anymore; they need trust. Tip: set a simple passphrase for high-risk actions, like wire requests or "urgent" account recovery – especially within finance teams and families. If the caller can't answer it, pause and verify. Adaptive runs deepfake and vishing simulations so employees practice this before it's real. adaptivesecurity.com.

View Details

140k affected by US healthcare breach

Data advocates warn against replicating humans

Shai-Hulud-like worm targets developers

Get links to all of today's news in our show notes here: https://cisoseries.com/cybersecurity-news-us-healthcare-breach-affects-140k-experts-warn-against-replicating-humans-shai-hulud-like-worm-targets-devs/

Thanks to today's episode sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Today's phishing doesn't just hit inboxes — it can sound like your CFO or look like your CEO on Zoom. AI voices, video, and deepfakes are turning trust into the attack surface. Adaptive fights back with AI-driven risk scoring, deepfake simulations featuring your own executives, and interactive training your team will actually remember. Take a three-minute tour or request a CEO deepfake demo at adaptivesecurity.com.

View Details

Link to episode page

This week's Department of Know is hosted by Rich Stroffolino with guests Montez Fitzpatrick, CISO, Navvis, and Peter Gregory, author.

Thanks to our show sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. AI is changing phishing, because persuasion now scales like code. And it's not just email anymore; attackers hit SMS, voice calls, and multi-step scams that jump channels. Adaptive runs AI-powered phishing simulations across email, SMS, and voice, including OSINT-based spearphishing and BEC-style scenarios, so employees practice what attacks look like. Learn more at adaptivesecurity.com.

All links and the video of this episode can be found on CISO Series.com

View Details

Arkanix Stealer – the new AI info-stealer experiment

AI-assisted hacker breached 600 Fortinet firewalls in 5 weeks

Russia stepping up hybrid attacks, preparing for confrontation with West

Get links to all of today's news in our show notes here: https://cisoseries.com/cybersecurity-news-arkanix-was-poc-600-fortinet-firewalls-breach-russia-heightens-tension/

Thanks to today's episode sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first security awareness platform built to stop AI-powered social engineering. Deepfakes aren't science fiction anymore; they're a daily threat. Quick tip: if your voicemail greeting is your real voice, switch it to the default robot voice. A few seconds of audio can be enough to clone you. Adaptive helps teams spot and stop these AI-powered social engineering attacks. Learn more at adaptivesecurity.com.

View Details

CISA orders urgent patch of Dell flaw

Android malware uses Gemini to navigate infected devices

Half of all cyberattacks start in the browser, says Palo Alto Networks

Get the full show notes here: https://cisoseries.com/cybersecurity-news-cisas-dell-order-android-ai-malware-browsers-as-weak-link/

Huge thanks to our sponsor, Conveyor

Most of what Conveyor automates is boring. Like really boring. Security questionnaires. Customer requests for things like your SOC 2. All of their follow-up questions. Answering tickets from your sales team. You know what's not boring? Alteryx using Conveyor to support over half a billion dollars in enterprise deals with a small 4 person team. All they did was set up an AI trust center and use Conveyor's AI agent to complete questionnaires. Learn more at conveyor.com.

View Details

Microsoft Copilot summarizes confidential emails

ShinyHunters takes CarGurus records

Texas sues TP-Link over router hack

Get the full show notes here: https://cisoseries.com/cybersecurity-news-copilot-summarizes-confidential-emails-shinyhunters-targets-cargurus-texas-sues-tp-link/

Huge thanks to our sponsor, Conveyor

Every fast-growing company hits this one moment.

Sales wants to close bigger enterprise deals, but this means the security team is buried in security questionnaires. Alteryx avoided the deluge of questionnaires by using Conveyor to automate their customer security reviews.The result? AI completes questionnaires, 40% more customers are supported through a self-serve trust center, and over half a billion dollars in security influenced revenue. If you're trying to scale without adding headcount, take a look at Conveyor at conveyor.com.

View Details

Hackers target anti-government protestors

UK launches "lock the door" cybersecurity campaign

Cellebrite linked to phone hack on Kenyan politician

Get the full show notes here: https://cisoseries.com/cybersecurity-news-hacking-protestors-uk-locks-the-door-kenyan-politician-phone-cracked/

Huge thanks to our sponsor, Conveyor

Most of what Conveyor automates is boring. Like really boring. Security questionnaires. Customer requests for things like your SOC 2. All of their follow-up questions. Answering tickets from your sales team. You know what's not boring? Alteryx using Conveyor to support over half a billion dollars in enterprise deals with a small 4 person team. All they did was set up an AI trust center and use Conveyor's AI agent to complete questionnaires. Learn more at conveyor.com.

View Details

Eurail stolen traveler data now up for sale

EU Parliament blocks AI features

Japan's Washington Hotel discloses ransomware hit

Get the full show notes here:

Huge thanks to our sponsor, Conveyor

Here's a fun question. Would you rather support more enterprise deals… or answer fewer security questionnaires? Moving upmarket usually means more scrutiny and more security questions. Instead of hiring more people or slowing sales, Alteryx used Conveyor's AI to automate customer security reviews like questionnaires, SOC 2 requests, and all the back-and-forth. They supported 200% growth and over half a billion dollars in pipeline with a 4 person team. If you're tired of choosing between growth and sanity, check out Conveyor at conveyor.com.

View Details

Link to episode page

This week's Department of Know is hosted by Sarah Lane with guests Jon Collins, Field CTO, GigaOm, and Adam Palmer, CISO, First Hawaiian Bank

Thanks to our show sponsor, Conveyor

Ever dream of giving customers instant answers to their security questions without ever filling out another questionnaire? Meet Conveyor's new Trust Center Agent. The Agent lives in your Conveyor Trust Center and answers every customer question, surfaces documents and even completes full questionnaires instantly so customers can finish their review and be on their way. Top tech companies like Atlassian, Zapier, and more are using Conveyor to automate away tedious work. Learn more at www. conveyor.com.

All links and the video of this episode can be found on CISO Series.com

View Details

One threat actor responsible for 83% of recent Ivanti RCE attacks

Google's AI search overviews manipulated by scammers

Microsoft warns of DNS-based ClickFix attack that uses Nslookup

Get the full show notes here: https://cisoseries.com/cybersecurity-news-ivanti-actor-identified-search-overviews-manipulated-clickfix-leverages-nslookup/

Huge thanks to our sponsor, Conveyor

I'll tell you two things Conveyor can't help you with. Conveyor will not make security questionnaires fun and it will not make your sales team stop asking you questions. But it did help Alteryx support half a billion dollars in enterprise deals with the same 4 person team. All they did was get an AI trust center and use Conveyor's AI agent to complete questionnaires.

If that's enough, you know where to go. www. conveyor.com.

View Details

Hackers abuse Gemini AI for all attack stages, says Google

Apple patches decade-old possibly exploited iOS zero-day

Acting CISA chief critiques potential DHS funding lapse

Get the show notes here: https://cisoseries.com/cybersecurity-news-hackers-abuse-gemini-apple-patches-ancient-bug-cisa-criticizes-shutdown/

Huge thanks to our episode sponsor, ThreatLocker

Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.

View Details

Crazy gang abuses employee monitoring tool

Nevada unveils new data classification

Georgia healthcare breach impacts more than 620,000

Get the show notes here: https://cisoseries.com/cybersecurity-news-google-gets-eu-wiz-approval-microsoft-secures-secure-boot-certificates-north-korean-hackers-target-crypto-exec/

Huge thanks to our episode sponsor, ThreatLocker

Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.

View Details

EU grants Google approval for Wiz

Microsoft rolls out Secure Boot certificates before expiration

North Korean hackers target crypto exec

Get the show notes here: https://cisoseries.com/cybersecurity-news-google-gets-eu-wiz-approval-microsoft-secures-secure-boot-certificates-north-korean-hackers-target-crypto-exec/

Huge thanks to our episode sponsor, ThreatLocker

Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.

View Details

UNC3886 targets Singapore telecom sector

VoidLink exhibits multi-cloud capabilities and AI code

135,000+ OpenClaw instances exposed to internet

Get the show notes here: https://cisoseries.com/cybersecurity-news-february-10-2026/

Huge thanks to our episode sponsor, ThreatLocker

Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.

View Details

Link to episode page

This week's Department of Know is hosted by Rich Stroffolino with guests Nick Ryan, former CISO, and Chris Ray, Field CTO, GigaOm

Thanks to our show sponsor, ThreatLocker

Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.

All links and the video of this episode can be found on CISO Series.com

View Details

OpenClaw turns to VirusTotal to boost security

CISA gives federal agencies one year to remove end-of-life devices

Payments platform BridgePay confirms ransomware attack

Get the show notes here: https://cisoseries.com/cybersecurity-news-openclaw-embraces-virustotal-cisa-eol-deadline-ransomware-hits-bridgepay/

Huge thanks to our episode sponsor, ThreatLocker

Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.

View Details

Substack admits data breach

Russian attacks target Winter Olympics

GitHub Codespaces enable RCE

Get the show notes here:

Huge thanks to our sponsor, Strike48

It's no secret that AI is only as good as the data available to it. Strike48 unifies agentic AI with unmatched log visibility while avoiding the typical hefty price tag. Build and deploy agents for phishing detection, alert triage, threat correlation and more. Queries existing logs where they currently live, so you can keep the technology you already have. Learn more at Strike48.com.

View Details

Ukraine tightens controls on Starlink terminals

VMware ESXi flaw now exploited

SolarWinds Web Help Desk bug under attack

Get the show notes here: https://cisoseries.com/cybersecurity-news-ukraine-tightens-controls-on-starlink-terminals-vmware-esxi-flaw-now-exploited-solarwinds-web-help-desk-bug-under-attack/

Huge thanks to our sponsor, Strike48

Strike48 is the Agentic Log Intelligence Platform that actually puts AI agents to work, maximizing log visibility without blowing your budget. Find threats your siloed tools miss. Get started today with pre-built AI agents and workflows that investigate, detect, and respond 24/7 or build your own at strike48.com/security.

View Details

React Native Metro bug impacts thousands of servers

Greece and Spain set to ban social media for kids

Moltbook shows the dangers of vibe coding

Get the show notes here: https://cisoseries.com/cybersecurity-news-metro-bug-more-social-bans-leaky-moltbook/

Huge thanks to our sponsor, Strike48

Security teams are stretched. Attack surfaces and threat volumes keep growing, meanwhile SOC budgets stay flat and glorified chatbots with hallucination problems aren't helping. Strike48 is different. Agents scale independently, running investigations across your logs while your team can concentrate on the highest priority tasks that require human judgment and decision making. Try it today at Strike48.com/security.

View Details

OpenClaw targets ClawHub users

Notepad++ update delivers malware

APT28 attackers abuse Microsoft Office zero-day

Get the show notes here: https://cisoseries.com/cybersecurity-news-openclaw-targets-clawhub-users-notepad-update-delivers-malware-apt28-attackers-abuse-microsoft-office-zero-day/

Huge thanks to our sponsor, Strike48

It's no secret that AI is only as good as the data available to it. Strike48 unifies agentic AI with unmatched log visibility while avoiding the typical hefty price tag. Build and deploy agents for phishing detection, alert triage, threat correlation and more. Queries existing logs where they currently live, so you can keep the technology you already have. Learn more at Strike48.com.

View Details

Link to episode page

This week's Department of Know is hosted by Rich Stroffolino with guests Steve Zalewski, co-host, Defense in Depth, and Nick Espinosa, host, The Deep Dive Radio Show

Thanks to our show sponsor, Devo/Strike 48

Strike48 is the Agentic Log Intelligence Platform that actually puts AI agents to work, maximizing log visibility without blowing your budget. Find threats your siloed tools miss. Get started today with pre-built AI agents and workflows that investigate, detect, and respond 24/7 or build your own at strike48.com/security.

All links and the video of this episode can be found on CISO Series.com

View Details

Coupang CEO questioned by police regarding data breach probe

Cyberattack on large Russian bread factory disrupts deliveries

Real estate agents in Australia use apps that leave lease documents at risk

Get the show notes here: https://cisoseries.com/cybersecurity-news-police-question-coupang-ceo-russia-bakery-cyberattack-australian-real-estate-scandal/

Huge thanks to our sponsor, Strike48

Strike48 is the Agentic Log Intelligence Platform that actually puts AI agents to work, maximizing log visibility without blowing your budget. Find threats your siloed tools miss. Get started today with pre-built AI agents and workflows that investigate, detect, and respond 24/7 or build your own at strike48.com/security.

View Details

France fines unemployment agency €5 million over data breach

Microsoft Teams addition will allow for suspicious calls to be reported

UK leaders warned about absorbing cyberattacks without offensive deterrence

Check out the show notes here:

Huge thanks to our episode sponsor, Conveyor

Want to hear a horror story? An infosec manager found out that their sales rep had filled in a customer security questionnaire themselves and sent it back to the customer without review. Which led to dozens of follow up questions. With Conveyor's Trust Center AI Agent, you can avoid all of that. The Agent lives in your Conveyor hosted Trust Center and answers every customer question, surfaces documents and even completes full questionnaires instantly so customers can finish their review and be on their way. Learn more at Conveyor.com Find the stories behind the headlines at https://cisoseries.com/cybersecurity-news-france-fines-unemployment-agency-teams-flags-calls-uk-pushes-deterrence/

View Details

Sandbox flaw exposes n8n instances

Fake Moltbot assistant drops malware

PeckBirdy takes flight for cross-platform attacks

Check out the show notes here: https://cisoseries.com/cybersecurity-news-sandbox-flaw-exposes-n8n-instances-fake-moltbot-assistant-drops-malware-peckbirdy-takes-flight-for-cross-platform-attacks/

Huge thanks to our episode sponsor, Conveyor

Another security questionnaire hits your desk. Ever wish it could magically disappear? You already have the answers that customers should self-serve, but they can't find the info in your Trust Center. That's why Conveyor built the first truly agentic Trust Center. An AI Agent lives inside it, answering customer questions, sharing documents, and even completing full questionnaires instantly. Customers get what they need fast. it's magical, touchless, and extremely accurate. Join teams at Atlassian, Zapier, and more at conveyor.com.

View Details

US cyber chief uploaded sensitive files into public ChatGPT

Vibe-coded 'Sicarii' ransomware can't be decrypted

WhatsApp account feature combats spyware

Check out the show notes here: https://cisoseries.com/cybersecurity-news-us-cyber-chief-uploaded-sensitive-files-into-public-chatgpt-vibe-coded-sicarii-ransomware-cant-be-decrypted-whatsapp-account-feature-combats-spyware/

Huge thanks to our episode sponsor, Conveyor

Ever dream of giving customers instant answers to their security questions without ever filling out another questionnaire? Meet Conveyor's new Trust Center Agent. The Agent lives in your Conveyor Trust Center and answers every customer question, surfaces documents and even completes full questionnaires instantly so customers can finish their review and be on their way. Top tech companies like Atlassian, Zapier, and more are using Conveyor to automate away tedious work. Learn more at conveyor.com.

View Details

Microsoft patches Office zero-day vulnerability

Indian users targeted by Blackmoon

Konni targets blockchain developers

Huge thanks to our episode sponsor, Conveyor

True story, an infosec team had to give customers MapQuest style directions just to navigate their Trust Center. Spoiler: it didn't reduce follow-up questions and created even more work for everyone involved. With Conveyor's new Trust Center AI Agent, customers get answers instantly and can even upload questionnaires for the Agent to complete. This way, customers find what they need and keep moving, without your team needing to intervene. Learn more at conveyor.com

View Details

Link to episode page

This week's Department of Know is hosted by Rich Stroffolino with guests Krista Arndt, associate CISO, St. Luke's University Health Network, and Jason Shockey, CISO, Cenlar FSB

Thanks to our show sponsor, Conveyor

Ever dream of giving customers instant answers to their security questions without ever filling out another questionnaire? Meet Conveyor's new Trust Center Agent. The Agent lives in your Conveyor Trust Center and answers every customer question, surfaces documents and even completes full questionnaires instantly so customers can finish their review and be on their way. Top tech companies like Atlassian, Zapier, and more are using Conveyor to automate away tedious work. Learn more at conveyor.com.

All links and the video of this episode can be found on CISO Series.com

View Details

Microsoft Outlook and boot problems

Sandworm likely behind cyberattack on Poland's power grid

Dresden museum network suffers cyberattack

Huge thanks to our episode sponsor, Conveyor

Ever wish your customers could magically get answers to their own security questionnaires before they ever hit your desk? We've heard this wish from hundreds of teams so Conveyor just launched a new Trust Center AI Agent. The Agent lives in your Conveyor hosted Trust Center and answers customer questions, surfaces documents and even completes full questionnaires instantly so customers can finish their review without your intervention. Join top tech companies using Conveyor today like Atlassian, Zapier and more. Check it out at Conveyor.com Find the stories behind the headlines at CISOseries.com.

View Details

Multi‑stage AiTM phishing and BEC campaign abusing SharePoint

SmarterMail auth bypass flaw now exploited despite patch

The problem of AI agents emerges at Davos

Huge thanks to our sponsor, Dropzone AI

All week we've talked about alert fatigue, MTTR, and the math that's breaking your SOC. Here's the proof. Dropzone AI is trusted by over 300 global enterprises and MSSPs. Named a Gartner Cool Vendor. Recognized in the Fortune Cyber 60. And backed by $37 million in Series B funding. But they're not stopping at a single agent. They're building toward fully agentic SOC teams where human engineers are augmented with specialized AI agents for threat hunting, detection engineering, and forensics. Your team deserves a backup that never sleeps. Book a demo at dropzone.ai.

Find the stories behind the headlines at CISOseries.com.

View Details

Tesla hacked at Pwn2Own Automotive

Everest sitting on Under Armour data?

PurpleBravo fake jobs campaign targets IP addresses

Huge thanks to our sponsor, Dropzone AI

Quick tip for SOC leaders measuring MTTR. Stop optimizing the human. Optimize what the human has to do. Dropzone AI handles the investigation legwork autonomously. Correlating alerts, gathering evidence, documenting findings. Your analysts only engage when it actually matters. The results are investigations that took hours and now take under 10 minutes with much better accuracy of up to 30%. And analysts who can finally focus on real threats. Proven at over 300 enterprises who have deployed Dropzone AI. See the data at dropzone.ai.

View Details

UK and China try to ease cyberattack tensions

Iranian state TV hijacked

VoidLink malware is AI-generated

Huge thanks to our sponsor, Dropzone AI

Remember yesterday's 2 AM alert? Here's how it ends differently with Dropzone AI. The alert fires. Within minutes, not hours, their AI SOC agents have already correlated logs across your entire security stack, built a complete evidence chain, and delivered a verdict. False positive, or escalate immediately. Your analyst wakes up to answers, not a queue. That's autonomous investigation at enterprise scale. Experience it for yourself at dropzone.ai.

View Details

Gemini prompt injection flaw exposes calendar info

Hacker admits to leaking stolen Supreme Court data

Researchers uncover PDFSIDER malware

Huge thanks to our sponsor, Dropzone AI

It's 2 AM. An alert fires. Possible data exfiltration. Your on-call analyst is three time zones away, half-asleep, context-switching between tools. By the time they piece together the evidence, forty-five minutes have passed. Was it a real threat or another false positive? The clock is ticking. Tomorrow, I'll tell you how 300 enterprises solved this exact problem. But if you can't wait, head over to dropzone.ai to learn more.

View Details

Link to episode page

This week's Department of Know is hosted by Sarah Lane with guests Dmitriy Sokolovskiy, senior vice president, information security, Semrush, and Nick Espinosa, host, The Deep Dive Radio Show

Thanks to our show sponsor, Dropzone AI

How many alerts did your SOC investigate last week? How many sat in the queue untouched? If you don't know those numbers, or you don't like them, Dropzone AI can help. They've helped enterprises like UiPath and Zapier handle ten times more alerts without adding headcount. Their AI SOC agents work around the clock, investigating every alert autonomously. Book a demo and they'll show you exactly how many hours you could recover.

Head over to dropzone.ai and request your demo today.

All links and the video of this episode can be found on CISO Series.com

View Details

Cybercom-NSA leadership nominee to assess dual-hat role

Two-thirds of third-party applications access sensitive data without justification, says report

GhostPoster browser extensions up to 840,000 installs

Huge thanks to our sponsor, Dropzone AI

Here's a security tip most vendors won't tell you. Your SOC analysts aren't slow. They're drowning. The average enterprise faces tens of thousands of alerts daily, and even your best analysts can only investigate so many before burnout wins. Dropzone AI changes that math. Their AI SOC agents autonomously investigate every alert, no playbooks or code required, in three to ten minutes flat. Stop triaging. Start defending. Book a demo at dropzone.ai.

Find the stories behind the headlines at CISOseries.com.

View Details

Jen Easterly to helm RSAC

Windows January update causes login problems

UK police blame Copilot for intelligence mistake

Thanks to our episode sponsor, ThreatLocker

Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.

Find the stories behind the headlines at CISOseries.com.

View Details

U.S. weighs private companies' cyberwarfare roles China: stop using US and Israeli cybersecurity software

DeadLock uses smart contracts to hide work

Thanks to our episode sponsor, ThreatLocker

Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.

View Details

GoBruteforcer targets blockchain projects

Android accessibility issue just a bug

Verizon to stop automatic phone unlocks

Thanks to our episode sponsor, ThreatLocker

Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.

View Details

Instagram denies breach post-data leak

Sweden detains consultant suspected of spying

n8n supply chain attack steals OAuth tokens

Thanks to our episode sponsor, ThreatLocker

Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.

View Details

Link to episode page

This week's Department of Know is hosted by Rich Stroffolino with guests Johna Till Johnson, CEO and Founder, Nemertes (check out the Nemertes substack) and Jason Shockey, CISO, Cenlar FSB. Jason will be speaking at MBA Servicing Solution26 in Texas in late February. Details here.

Thanks to our show sponsor, ThreatLocker

Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.

All links and the video of this episode can be found on CISO Series.com

View Details

BreachForums hacking forum database leaked exposing 324,000 accounts

Instagram breach exposes user data, creates password reset panic

UK government exempts self from flagship cyber law

Thanks to our episode sponsor, ThreatLocker

Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.

Find the stories behind the headlines at CISOseries.com.

View Details

Microsoft to enforce MFA for Microsoft 365 admin center sign-ins

Cisco patches ISE security vulnerability after PoC release

Illinois state agency breaches itself

Huge thanks to our sponsor, Hoxhunt

A small tip for CISOs: if you're unsure whether your security training is actually reducing phishing risk, check out what Qualcomm achieved with Hoxhunt. They took their 1,000 highest-risk users from consistent under-performers to outperforming the rest of the company, driving measurable human risk reduction and earning a CSO50 Award. See the Qualcomm case at hoxhunt.com/qualcomm

Find the stories behind the headlines at CISOseries.com.

View Details

ESA confirms new data heist

Ni8mare lets hackers hijack n8n servers

Taiwan blames 'cyber army' for intrusion attempts

Huge thanks to our sponsor, Hoxhunt

Traditional security training fails because it treats employees like the problem. Hoxhunt treats them like the solution. AI-powered simulations mirror actual attacks hitting your inbox. Instant coaching turns mistakes into learning moments. Gamified rewards make security engaging. The result? Real behavior change that measurably reduces your risk. Thousands of companies trust Hoxhunt to transform human vulnerability into human defense. Visit hoxhunt.com/cisoseries to learn more.

View Details

The UK hits reset on cybersecurity

No MFA, Know Problems

US may have coordinated cyberattacks with Maduro's arrest

Huge thanks to our sponsor, Hoxhunt

A small tip for CISOs: if you're unsure whether your security training is actually reducing phishing risk, check out what Qualcomm achieved with Hoxhunt. They took their 1,000 highest-risk users from consistent under-performers to outperforming the rest of the company, driving measurable human risk reduction and earning a CSO50 Award. See the Qualcomm case at hoxhunt.com/qualcomm

View Details

European hospitality blue screen of death

Brightspeed investigates breach

Convicted Bitfinex launderer freed

Huge thanks to our sponsor, Hoxhunt

Traditional security training fails because it treats employees like the problem. Hoxhunt treats them like the solution. AI-powered simulations mirror actual attacks hitting your inbox. Instant coaching turns mistakes into learning moments. Gamified rewards make security engaging. The result? Real behavior change that measurably reduces your risk. Thousands of companies trust Hoxhunt to transform human vulnerability into human defense. Visit hoxhunt.com/cisoseries to learn more.

View Details

Link to episode page

This week's Department of Know is hosted by Rich Stroffolino with guests Peter Clay, CISO, Aireon, and Chris Ray, Field CTO, GigaOm

Thanks to our show sponsor, HoxHunt

A small tip for CISOs: if you're unsure whether your security training is actually reducing phishing risk, check out what Qualcomm achieved with Hoxhunt. They took their 1,000 highest-risk users from consistent under-performers to outperforming the rest of the company, driving measurable human risk reduction and earning a CSO50 Award. See the Qualcomm case at hoxhunt.com/qualcomm

All links and the video of this episode can be found on CISO Series.com

View Details

Palo Alto Networks boss calls AI agents biggest insider threat

Hackers claim Resecurity hack, firm says it was a honeypot

Thousands of ColdFusion exploit attempts spotted during Christmas holiday

Huge thanks to our sponsor, Hoxhunt

A small tip for CISOs: if you're unsure whether your security training is actually reducing phishing risk, check out what Qualcomm achieved with Hoxhunt. They took their 1,000 highest-risk users from consistent under-performers to outperforming the rest of the company, driving measurable human risk reduction and earning a CSO50 Award. See the Qualcomm case at hoxhunt.com/qualcomm

Find the stories behind the headlines at CISOseries.com.

View Details

NYC mayoral inauguration bans Flipper Zero and Raspberry Pi devices

Crypto must now share account details with UK tax officials

Finland seizes suspected cable sabotage ship

Huge thanks to our episode sponsor, ThreatLocker

Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.

Find the stories behind the headlines at CISOseries.com.

View Details

Hackers drain millions from Unleash Protocol

DarkSpectre campaigns exposed

Shai-Hulud attack led Trust Wallet heist

Huge thanks to our episode sponsor, ThreatLocker

Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 atztw.com.

View Details

Silver Fox targets Indian users

Mustang Panda deploys ToneShell

Will prompt injection ever be 'solved'?

Huge thanks to our episode sponsor, ThreatLocker

Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 atztw.com.

View Details

Coupang recovers laptop allegedly thrown into river

Trust Wallet reports 2k+ wallets drained

Sax discloses 2024 data breach

Huge thanks to our episode sponsor, ThreatLocker

Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 atztw.com.

View Details

Link to episode page

To end off a tumultuous year, our final Department of Know episode of 2025 features a chat between host Rich Stroffolino and producer Steve Prentice. Join them as they chat about the biggest stories of 2025, the trends we are seeing, and what we can expect in the new year.

Thanks to our show sponsor, ThreatLocker

Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.

All links and the video of this episode can be found on CISO Series.com

View Details

Rainbow Six Siege suffers breach, gamers go shopping

Diesel generators and aircraft engines in high demand to power AI

LastPass 2022 breach reverberates through crypto world

Huge thanks to our episode sponsor, ThreatLocker

Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.

Find the stories behind the headlines at CISOseries.com.

View Details

Active exploitation of Fortinet VPN bypass utility observed

Google possibly allowing users to change default gmail address

June Aflac attack resulted in data theft

Thanks to our episode sponsor, ThreatLocker

Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com. Find the stories behind the headlines at CISOseries.com

View Details

Coordinated scams target MENA region

Pen Test Partners accused of 'blackmail'

Hackers steal record $2.7B in crypto in 2025

Thanks to our episode sponsor, ThreatLocker

Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.

View Details

ServiceNow to acquire cybersecurity startup Armis

MacSync Stealer adopts quieter installation

Nissan customer data stolen in Red Hat raid

Thanks to our episode sponsor, ThreatLocker

Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.

View Details

Spotify music library scraped

DDoS disrupts France's postal and banking services

Fake delivery websites hit holiday shoppers

Thanks to our episode sponsor, ThreatLocker

Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.

View Details

Link to episode page

This week's Department of Know is hosted by Rich Stroffolino with guests Jason Taule, CISO, Luminis Health, and Chris Ray, Field CTO, GigaOm

Thanks to our show sponsor, ThreatLocker

Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com.

All links and the video of this episode can be found on CISO Series.com

View Details

President signs defense bill funding Cyber Command, Pentagon phone security

Iranian APT Infy resurfaces with new malware

Massive Android botnet Kimwolf launches DDoS attack

Thanks to our episode sponsor, ThreatLocker

Want real Zero Trust training? Zero Trust World 2026 delivers hands-on labs and workshops that show CISOs exactly how to implement and maintain Zero Trust in real environments. Join us March 4–6 in Orlando, plus a live CISO Series episode on March 6. Get $200 off with ZTWCISO26 at ztw.com. Find the stories behind the headlines at CISOseries.com.

View Details

Recent Windows updates break RemoteApp connections

France arrests threat actors for installing malware on Italian ferry

Senate Intel chair urges safeguard against open-source software threats

Huge thanks to our sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. Security training fails when it's generic. Adaptive's platform personalizes training and runs deepfake simulations across email, SMS, voice, and video. And with Adaptive's AI Content Creator, you can drop in a breaking threat or compliance doc and instantly turn it into interactive, multilingual training – no designers, no delays. Learn more at adaptivesecurity.com.

Find the stories behind the headlines at CISOseries.com.

View Details

FTC orders crypto to pay

New exploit of React2Shell

Ukraine-based fraud ring taken down

Huge thanks to our sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. In deepfake scams, the tells aren't glitchy video anymore – it's behavior: "Do this right now," or "keep it secret." If you hear urgency and secrecy together, stop and verify through a second channel. Call a known number, start a chat thread, or ask something only the real person would know. Adaptive trains teams against exactly these tactics. Learn more at adaptivesecurity.com.

View Details

Rogue NuGet package steals data

Venezuela's PDVSA suffers attack

Patched Fortinet flaws exploited

Huge thanks to our sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. Picture a "new hire" who interviews well… except they're synthetic: AI video, AI voice, AI backstory. Once they're in, they go after payroll, internal docs, and access. That's the new reality: the attack surface is trust itself. Adaptive fights back with realistic deepfake simulations and training that actually sticks. Learn more at adaptivesecurity.com.

View Details

US turns to private firms in cyber offensive Microsoft updates cause queuing failures

Phishing campaign delivers Phantom stealer

Huge thanks to our sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. Attackers don't need malware anymore; they need trust. Tip: set a simple passphrase for high-risk actions, like wire requests or "urgent" account recovery – especially within finance teams and families. If the caller can't answer it, pause and verify. Adaptive runs deepfake and vishing simulations so employees practice this before it's real. Learn more at adaptivesecurity.com.

View Details

Link to episode page

This week's Department of Know is hosted by Rich Stroffolino with guests Andy Ellis, Principal, Duha, and Johna Till Johnson, CEO and Founder, Nemertes Research

Thanks to our show sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. AI is rewriting the cybersecurity rulebook, because attackers can now scale persuasion as easily as they scale code. The real target isn't just your systems anymore; it's human trust. If you aren't actively testing your organization against AI-driven phishing, vishing, and deepfakes, you're leaving a gap criminals will exploit. Adaptive runs realistic simulations and delivers tailored, engaging training so teams respond correctly when it counts. Learn more at adaptivesecurity.com. Learn more at adaptivesecurity.com.

All links and the video of this episode can be found on CISO Series.com

View Details

16TB MongoDB database exposes nearly 4.3 billion professional records

Apple posts updates after discovery of WebKit flaws

Coupang data breach traced to ex-employee

Huge thanks to our sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. Deepfakes aren't science fiction anymore; they're a daily threat. Quick tip: if your voicemail greeting is your real voice, switch it to the default robot voice. A few seconds of audio can be enough to clone you. Adaptive helps teams spot and stop these AI-powered social engineering attacks. Learn more at adaptivesecurity.com.

Find the stories behind the headlines at CISOseries.com.

View Details

'DroidLock' malware demands ransom Google fixes secret Chrome 0-day UK fines LastPass over 2022 breach Huge thanks to our episode sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. Security training fails when it's generic. Adaptive's platform personalizes training and runs deepfake simulations across email, SMS, voice, and video. And with Adaptive's AI Content Creator, you can drop in a breaking threat or compliance doc and instantly turn it into interactive, multilingual training – no designers, no delays. Learn more at adaptivesecurity.com.

View Details

CEO of retail giant Coupang resigns Pro-Russia hactivists target US infrastructure Israeli cybersecurity funding hits record Huge thanks to our episode sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. In deepfake scams, the tells aren't glitchy video anymore – it's behavior: "Do this right now," or "keep it secret." If you hear urgency and secrecy together, stop and verify through a second channel. Call a known number, start a chat thread, or ask something only the real person would know. Adaptive trains teams against exactly these tactics. adaptivesecurity.com.

View Details

Spain arrest over data records

Goodbye, dark Telegram

Scammers poison AI search results

Huge thanks to our episode sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. Picture a "new hire" who interviews well… except they're synthetic: AI video, AI voice, AI backstory. Once they're in, they go after payroll, internal docs, and access. That's the new reality: the attack surface is trust itself. Adaptive fights back with realistic deepfake simulations and training that actually sticks. adaptivesecurity.com.

View Details

Ransomware payments pass $4.5 billion

Cybercrime networks orchestrate real-world violence

Three arrested over possessing hacking tools

Huge thanks to our episode sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. Attackers don't need malware anymore; they need trust. Tip: set a simple passphrase for high-risk actions, like wire requests or "urgent" account recovery – especially within finance teams and families. If the caller can't answer it, pause and verify. Adaptive runs deepfake and vishing simulations so employees practice this before it's real. adaptivesecurity.com.

View Details

Link to episode page

This week's Department of Know is hosted by Sarah Lane with guests Jason Shockey, CISO, Cenlar FSB, and Mike Lockhart, CISO, Eagleview

Thanks to our show sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. AI is rewriting the cybersecurity rulebook, because attackers can now scale persuasion as easily as they scale code. The real target isn't just your systems anymore; it's human trust. If you aren't actively testing your organization against AI-driven phishing, vishing, and deepfakes, you're leaving a gap criminals will exploit. Adaptive runs realistic simulations and delivers tailored, engaging training so teams respond correctly when it counts. Learn more at adaptivesecurity.com. All links and the video of this episode can be found on CISO Series.com

View Details

New wave of VPN login attempts on Palo Alto portals

NATO holds its largest-ever cyberdefense exercise

Chinese hackers exploiting React2Shell bug

Huge thanks to our episode sponsor, Adaptive Security

This episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. Deepfakes aren't science fiction anymore; they're a daily threat. Quick tip: if your voicemail greeting is your real voice, switch it to the default robot voice. A few seconds of audio can be enough to clone you. Adaptive helps teams spot and stop these AI-powered social engineering attacks. Learn more at adaptivesecurity.com.

Find the stories behind the headlines at CISOseries.com.

View Details

Predator spyware spotted across several countries

Russia blocks FaceTime

Draft US cyber strategy set for January release

Huge thanks to our episode sponsor, Vanta

This message comes from Vanta. What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Get started at Vanta.com/CISO

View Details

Record-breaking DDoS attack

React bug puts servers at risk

RansomHouse attack

Huge thanks to our episode sponsor, Vanta

This message comes from Vanta. What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Get started at Vanta.com/CISO

View Details

Microsoft Defender outage disrupts threats Apple resists India's state-run app order MuddyWater strikes Israel with MuddyViper Huge thanks to our episode sponsor, Vanta

This message comes from Vanta. What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Get started at Vanta.com/CISO

View Details

India orders web safety app

Arrests over IP camera snooping

Albiriox shows up on dark web

Huge thanks to our episode sponsor, Vanta

This message comes from Vanta. What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Get started at Vanta.com/CISO

View Details

Link to episode page

This week's Department of Know is hosted by Rich Stroffolino with guests Mathew Biby, director, cybersecurity, TixTrack, and Derek Fisher, Director of the Cyber Defense and Information Assurance Program, Temple University

Thanks to our show sponsor, Vanta

This message comes from Vanta. What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Get started at Vanta.com/CISO

All links and the video of this episode can be found on CISO Series.com

View Details

Japanese brewer Asahi provides details regarding October ransomware attack

California law regulating web browsers might impact national data privacy

Microsoft to speed up Teams

Huge thanks to our episode sponsor, Vanta

This message comes from Vanta. What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Get started at Vanta.com/CISO

Find the stories behind the headlines at CISOseries.com.

View Details

Microsoft to block unauthorized scripts in Entra ID logins with 2026 CSP update

New legislation targets scammers that use AI to deceive

ASUS firmware patches critical AiCloud vulnerability

Huge thanks to our episode sponsor, KnowBe4

Cybersecurity isn't just a tech problem—it's a human one. That's why KnowBe4's Human Risk Management platform allows you to measure, quantify and actually reduce human risk across your organization. With AI-powered risk scoring, automated coaching and reporting, HRM+ helps you surface your highest risk users and reduce the risk of data breaches and cyberattacks proactively. Ready to move from awareness to action? Request a demo of HRM+ today at knowbe4.com. Find the stories behind the headlines at CISOseries.com.

View Details

AWS outage botnet smacks 28 countries LLMs help malware authors evade detection

Anthropic questioned over Claude espionage

Huge thanks to our episode sponsor, KnowBe4

Cybersecurity isn't just a tech problem—it's a human one. That's why KnowBe4's Human Risk Management platform allows you to measure, quantify and actually reduce human risk across your organization. With AI-powered risk scoring, automated coaching and reporting, HRM+ helps you surface your highest risk users and reduce the risk of data breaches and cyberattacks proactively. Ready to move from awareness to action? Request a demo of HRM+ today at knowbe4.com.

View Details

CISA warns of app break-ins

StealC V2 spread through blender files

Russia arrests cybersecurity entrepreneur for treason

Huge thanks to our episode sponsor, KnowBe4

Cybersecurity isn't just a tech problem—it's a human one. That's why KnowBe4's Human Risk Management platform allows you to measure, quantify and actually reduce human risk across your organization. With AI-powered risk scoring, automated coaching and reporting, HRM+ helps you surface your highest risk users and reduce the risk of data breaches and cyberattacks proactively. Ready to move from awareness to action? Request a demo of HRM+ today at knowbe4.com.

View Details

CISA orders feds to patch OIM

Delta Dental of Virginia incurs data breach

Systems down at postal operator in Ukraine

Huge thanks to our episode sponsor, KnowBe4

Cybersecurity isn't just a tech problem—it's a human one. That's why KnowBe4's Human Risk Management platform allows you to measure, quantify and actually reduce human risk across your organization. With AI-powered risk scoring, automated coaching and reporting, HRM+ helps you surface your highest risk users and reduce the risk of data breaches and cyberattacks proactively. Ready to move from awareness to action? Request a demo of HRM+ today at knowbe4.com.

View Details

Link to episode page

This week's Department of Know is hosted by Rich Stroffolino with guests Keith Townsend, Keith Townsend, host CTO Advisor Podcast, founder of The Advisor Bench, and creator of the Virtual CTO Advisor; and Howard Holton, CEO, GigaOm

Thanks to our show sponsor, Knowbe4

Cybersecurity isn't just a tech problem—it's a human one. That's why KnowBe4's Human Risk Management platform allows you to measure, quantify and actually reduce human risk across your organization. With AI-powered risk scoring, automated coaching and reporting, HRM+ helps you surface your highest risk users and reduce the risk of data breaches and cyberattacks proactively. Ready to move from awareness to action? Request a demo of HRM+ today at knowbe4.com.

All links and the video of this episode can be found on CISO Series.com

View Details

CrowdStrike catches insider feeding information to hackers

Spanish airline Iberia suffers breach and data leak

AI is too risky to insure, say insurers

Huge thanks to our episode sponsor, KnowBe4

Cybersecurity isn't just a tech problem—it's a human one. That's why KnowBe4's Human Risk Management platform allows you to measure, quantify and actually reduce human risk across your organization. With AI-powered risk scoring, automated coaching and reporting, HRM+ helps you surface your highest risk users and reduce the risk of data breaches and cyberattacks proactively. Ready to move from awareness to action? Request a demo of HRM+ today at knowbe4.com. Find the stories behind the headlines at CISOseries.com.

View Details

Sturnus Android Trojan captures encrypted chats and hijacks devices

Canadian regulators say schools share blame for PowerSchool hack

Bill reintroduced to bolster cybersecurity at Securities and Exchange Commission

Huge thanks to our episode sponsor, KnowBe4

Your email gateway isn't catching everything — and cybercriminals know it.

That's why there's KnowBe4's Cloud Email Security platform. It's not just another filter—it's a dynamic, AI-powered layer of defense that detects and stops advanced threats before they reach your users' inbox.

Request a demo of KnowBe4's Cloud Email Security at knowbe4.com or visit them this week at Microsoft Ignite booth #5523.

Find the stories behind the headlines at CISOseries.com.

View Details

Cloudflare blames database

Crypto heist takedown

WhatsApp flaw exposed billions

Huge thanks to our episode sponsor, KnowBe4

Your email gateway isn't catching everything — and cybercriminals know it.

That's why there's KnowBe4's Cloud Email Security platform. It's not just another filter—it's a dynamic, AI-powered layer of defense that detects and stops advanced threats before they reach your users' inbox.

Request a demo of KnowBe4's Cloud Email Security at knowbe4.com or visit them this week at Microsoft Ignite booth #5523.

View Details

FCC to torch rules from Salt Typhoon Group claims hits on Danish party websites MI5 warns Chinese spies are using LinkedIn Huge thanks to our episode sponsor, KnowBe4

Your email gateway isn't catching everything — and cybercriminals know it.

That's why there's KnowBe4's Cloud Email Security platform. It's not just another filter—it's a dynamic, AI-powered layer of defense that detects and stops advanced threats before they reach your users' inbox.

Request a demo of KnowBe4's Cloud Email Security at knowbe4.com or visit them this week at Microsoft Ignite booth #5523.

View Details

Azure hit by DDoS using 500K IPs Kenyan government websites back online EVALUSION emerges Huge thanks to our episode sponsor, KnowBe4

Your email gateway isn't catching everything — and cybercriminals know it.

That's why there's KnowBe4's Cloud Email Security platform. It's not just another filter—it's a dynamic, AI-powered layer of defense that detects and stops advanced threats before they reach your users' inbox.

Request a demo of KnowBe4's Cloud Email Security at knowbe4.com or visit them this week at Microsoft Ignite booth #5523.

View Details

Link to episode page

This week's Department of Know is hosted by Rich Stroffolino with guests Robb Dunewood, Host, Daily Tech News Show, and Howard Holton, CEO, GigaOm

Thanks to our show sponsor, KnowBe4

Your email gateway isn't catching everything — and cybercriminals know it. That's why there's KnowBe4's Cloud Email Security platform. It's not just another filter—it's a dynamic, AI-powered layer of defense that detects and stops advanced threats before they reach your users' inbox. Request a demo of KnowBe4's Cloud Email Security at knowbe4.com or visit them this week at Microsoft Ignite booth #5523.

All links and the video of this episode can be found on CISO Series.com

View Details

Microsoft warns of potential Windows 10 update failure

China-backed hackers launch first large-scale autonomous AI cyberattack

Feds fumbled Cisco patches requirements, says CISA

Huge thanks to our episode sponsor, KnowBe4

Your email gateway isn't catching everything — and cybercriminals know it.

That's why there's KnowBe4's Cloud Email Security platform. It's not just another filter—it's a dynamic, AI-powered layer of defense that detects and stops advanced threats before they reach your users' inbox.

Request a demo of KnowBe4's Cloud Email Security at knowbe4.com or visit them this week at Microsoft Ignite booth #5523.

Find the stories behind the headlines at CISOseries.com.

View Details

Two key cyber laws are back as president signs bill to end shutdown Microsoft's screen capture prevention for Teams users is finally rolling out FBI calls Akira top five ransomware variant out of 130 targeting U.S. businesses

Huge thanks to our sponsor, Vanta

What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" ....or the really scary one: "how do I get out from under these old tools and manual processes? Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Vanta also fits right into your workflows, using AI to streamline evidence collection, flag risks, and keep your program audit-ready—ALL…THE…TIME. With Vanta, you get everything you need to move faster, scale confidently—and get back to sleep. Get started at vanta.com/headlines Find the stories behind the headlines at CISOseries.com.

View Details

Mobile internet blackout for Russian travelers Windows 11 supports 3rd-party passkey apps Synology patches BeeStation flaw Huge thanks to our sponsor, Vanta

What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" ....or the really scary one: "how do I get out from under these old tools and manual processes? Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Vanta also fits right into your workflows, using AI to streamline evidence collection, flag risks, and keep your program audit-ready—ALL…THE…TIME. With Vanta, you get everything you need to move faster, scale confidently—and get back to sleep. Get started at vanta.com/headlines

View Details

Google's Find Hub turns into remote-wipe weapon

Qilin ransomware activity surges

GootLoader is back

Huge thanks to our sponsor, Vanta

What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" ....or the really scary one: "how do I get out from under these old tools and manual processes? Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Vanta also fits right into your workflows, using AI to streamline evidence collection, flag risks, and keep your program audit-ready—ALL…THE…TIME. With Vanta, you get everything you need to move faster, scale confidently—and get back to sleep. Get started at vanta.com/headlines

View Details

CISA reauthorization

Denmark and Norway investigating electric bus "kill switches"

European Commission looking to simplify privacy laws for AI

Huge thanks to our sponsor, Vanta

What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" ....or the really scary one: "how do I get out from under these old tools and manual processes? Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Vanta also fits right into your workflows, using AI to streamline evidence collection, flag risks, and keep your program audit-ready—ALL…THE…TIME. With Vanta, you get everything you need to move faster, scale confidently—and get back to sleep. Get started at vanta.com/headlines

View Details

Link to episode page

This week's Department of Know is hosted by Rich Stroffolino with guests Jacob Coombs, CISO, Tandem Diabetes Care, and Ross Young, Co-host, CISO Tradecraft

Thanks to our show sponsor, Vanta

What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" ….or the really scary one: "how do I get out from under these old tools and manual processes? Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Vanta also fits right into your workflows, using AI to streamline evidence collection, flag risks, and keep your program audit-ready—ALL…THE…TIME. With Vanta, you get everything you need to move faster, scale confidently—and get back to sleep. Get started at vanta.com/headlines

All links and the video of this episode can be found on CISO Series.com

View Details

runC flaws could allow hackers to escape Docker containers

Lost iPhone scam warning

Landfall Android spyware targets Samsung Galaxy phones

Huge thanks to our sponsor, Vanta

What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" ....or the really scary one: "how do I get out from under these old tools and manual processes? Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Vanta also fits right into your workflows, using AI to streamline evidence collection, flag risks, and keep your program audit-ready—ALL…THE…TIME. With Vanta, you get everything you need to move faster, scale confidently—and get back to sleep. Get started at vanta.com/headlines Find the stories behind the headlines at CISOseries.com.

View Details

Hackers use Windows Hyper-V to evade EDR detection

Critical Cisco UCCX flaw lets attackers run commands as root

The Louvre's video security password was reportedly Louvre

Huge thanks to our sponsor, ThreatLocker

Imagine having the power to decide exactly what runs in your IT environment — and blocking everything else by default. That's what ThreatLocker delivers. As a zero-trust endpoint protection platform, ThreatLocker fills the gaps traditional solutions leave behind, giving your business stronger security and control. Don't just react to threats — stop them with ThreatLocker.

Find the stories behind the headlines at CISOseries.com.

View Details

Google uncovers PROMPTFLUX malware CISA warns of CentOS Web Panel bug Threat group targets academics Huge thanks to our sponsor, ThreatLocker

Cybercriminals don't knock — they sneak in through the cracks other tools miss. That's why organizations are turning to ThreatLocker. As a zero-trust endpoint protection platform, ThreatLocker puts you back in control, blocking what doesn't belong and stopping attacks before they spread. Zero Trust security starts here — with ThreatLocker

View Details

Scattered Spider, LAPSUS$, and ShinyHunters join forces Nikkei reports data breach impacting 17,000 people React Native NPM flaw leads to attacks Huge thanks to our sponsor, ThreatLocker

Imagine having the power to decide exactly what runs in your IT environment — and blocking everything else by default. That's what ThreatLocker delivers. As a zero-trust endpoint protection platform, ThreatLocker fills the gaps traditional solutions leave behind, giving your business stronger security and control. Don't just react to threats — stop them with ThreatLocker.

View Details

"SleepyDuck" uses Ethereum to keep command server alive SesameOp abuses OpenAI Assistants API Organized crime cybercrooks steal cargo Huge thanks to our sponsor, ThreatLocker

Cybercriminals don't knock — they sneak in through the cracks other tools miss. That's why organizations are turning to ThreatLocker. As a zero-trust endpoint protection platform, ThreatLocker puts you back in control, blocking what doesn't belong and stopping attacks before they spread. Zero Trust security starts here — with ThreatLocker

View Details

Link to episode page

This week's Department of Know is hosted by Rich Stroffolino with guests Davi Ottenheimer, vp, digital trust and ethics, Inrupt, and Rob Teel, Field CTO, GigaOm

Thanks to our show sponsor, ThreatLocker

Imagine having the power to decide exactly what runs in your IT environment — and blocking everything else by default. That's what ThreatLocker delivers. As a zero-trust endpoint protection platform, ThreatLocker fills the gaps traditional solutions leave behind, giving your business stronger security and control. Don't just react to threats — stop them with ThreatLocker.

All links and the video of this episode can be found on CISO Series.com

View Details

Australia warns of BADCANDY attacks exploiting Cisco IOS XE

Chinese hackers exploiting Cisco ASA firewalls used by governments worldwide

OpenAI's Aardvark GPT-5 agent finds and fixes code flaws automatically

Huge thanks to our sponsor, ThreatLocker

Imagine having the power to decide exactly what runs in your IT environment — and blocking everything else by default. That's what ThreatLocker delivers. As a zero-trust endpoint protection platform, ThreatLocker fills the gaps traditional solutions leave behind, giving your business stronger security and control. Don't just react to threats — stop them with ThreatLocker.

Find the stories behind the headlines at CISOseries.com.

View Details

LinkedIn users have until Monday to opt out of its AI training program New names surface for NSA leadership Open-source security group pulls out of U.S. grant, citing DEI restrictions

Huge thanks to our sponsor, Conveyor

Security reviews don't have to feel like a hurricane. Most teams are buried in back-and-forth emails and never-ending customer requests for documentation or answers. But Conveyor takes all that chaos and turns it into calm.

AI fills in the questionnaires, your trust center is always ready, and sales cycles move without stalls.

Breathe easier—check out Conveyor at www.conveyor.com.

Find the stories behind the headlines at CISOseries.com.

View Details

LG Uplus confirms cybersecurity incident 10 million+ impacted by Conduent breach

Russian hackers exploit tools against Ukrainian targets Huge thanks to our sponsor, Conveyor

Security reviews don't have to feel like a hurricane. Most teams are buried in back-and-forth emails and never-ending customer requests for documentation or answers. But Conveyor takes all that chaos and turns it into calm.

AI fills in the questionnaires, your trust center is always ready, and sales cycles move without stalls.

Breathe easier—check out Conveyor at www.conveyor.com.

View Details

New Android malware types like a human Sanctions weaken nation-state cyber ecosystems Side-channel attack extracts Intel, AMD secrets Huge thanks to our sponsor, Conveyor

Have you been personally victimized by a questionnaire this week? The queue never ends. But Conveyor can change that story.

With AI that answers questionnaires of any format, and a trust center that handles document sharing, security reviews get done without the stress.

Feel calm in the chaos with Conveyor. Learn more at www.conveyor.com.

View Details

Atlas browser hijacked

Bye, bye Twitter birdie

Dante spyware surfaces

Huge thanks to our sponsor, Conveyor

Security reviews don't have to feel like a hurricane. Most teams are buried in back-and-forth emails and never-ending customer requests for documentation or answers. But Conveyor takes all that chaos and turns it into calm.

AI fills in the questionnaires, your trust center is always ready, and sales cycles move without stalls.

Breathe easier—check out Conveyor at www.conveyor.com.

View Details

Link to episode page

This week's edition of The Department of Know is hosted by Rich Stroffolino with guests Bil Harmer, operating partner and CISO, Craft Ventures, and Sasha Pereira, CISO, WASH

Thanks to our show sponsor, ThreatLocker

If security questionnaires make you feel like you're drowning in chaos, you're not alone. Endless spreadsheets, portals, and questions—always when you least expect them. Conveyor brings calm to the storm. With AI that auto-fills questionnaires and a trust center that shares all your docs in one place, you'll feel peace where there used to be panic. Find your security review zen at www.conveyor.com.

All links and the video of this episode can be found on CISO Series.com

View Details

Microsoft WSUS vulnerability could allow for remote code execution

Fake LastPass death claims used to breach password vaults

New CoPhish attack steals OAuth tokens via Copilot Studio agents

Huge thanks to our sponsor, Conveyor

If security questionnaires make you feel like you're drowning in chaos, you're not alone.

Endless spreadsheets, portals, and questions—always when you least expect them.

Conveyor brings calm to the storm. With AI that auto-fills questionnaires and a trust center that shares all your docs in one place, you'll feel peace where there used to be panic.

Find your security review zen at www.conveyor.com.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week's Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guests David Cross, CISO, Atlassian, and davidcrosstravels.com, and Montez Fitzpatrick, CISO, Navvis

Thanks to our show sponsor, ThreatLocker

Imagine having the power to decide exactly what runs in your IT environment — and blocking everything else by default. That's what ThreatLocker delivers. As a zero-trust endpoint protection platform, ThreatLocker fills the gaps traditional solutions leave behind, giving your business stronger security and control. Don't just react to threats — stop them with ThreatLocker.

All links and the video of this episode can be found on CISO Series.com

View Details

Jingle Thief hackers steal millions in gift cards by exploiting cloud infrastructure Lazarus hackers targeted European defense companies Deep Tech work culture pushes for 72 hour workweeks

Huge thanks to our sponsor, ThreatLocker

Imagine having the power to decide exactly what runs in your IT environment — and blocking everything else by default. That's what ThreatLocker delivers. As a zero-trust endpoint protection platform, ThreatLocker fills the gaps traditional solutions leave behind, giving your business stronger security and control. Don't just react to threats — stop them with ThreatLocker.

Find the stories behind the headlines at CISOseries.com.

View Details

TP-Link urges updates for Omada gateways MuddyWater targets organizations in espionage campaign "SessionReaper" flaw exploited in Adobe Commerce Huge thanks to our sponsor, ThreatLocker

Cybercriminals don't knock — they sneak in through the cracks other tools miss. That's why organizations are turning to ThreatLocker. As a zero-trust endpoint protection platform, ThreatLocker puts you back in control, blocking what doesn't belong and stopping attacks before they spread. Zero Trust security starts here — with ThreatLocker

View Details

Russian state hackers replace burned malware with new tools Recent Windows updates cause login issues on some PCs Sophisticated campaign targets servers of high-profile organizations

Huge thanks to our sponsor, ThreatLocker

Imagine having the power to decide exactly what runs in your IT environment — and blocking everything else by default. That's what ThreatLocker delivers. As a zero-trust endpoint protection platform, ThreatLocker fills the gaps traditional solutions leave behind, giving your business stronger security and control. Don't just react to threats — stop them with ThreatLocker.

View Details

DNS failure leads to AWS outage

China accuses NSA of hacking national time center

Chrome store flooded with high-risk WhatsApp automation

Huge thanks to our sponsor, ThreatLocker

Cybercriminals don't knock — they sneak in through the cracks other tools miss. That's why organizations are turning to ThreatLocker. As a zero-trust endpoint protection platform, ThreatLocker puts you back in control, blocking what doesn't belong and stopping attacks before they spread. Zero Trust security starts here — with ThreatLocker

View Details

Europol dismantles 49 million fake account SIM farm

Envoy Air confirms Oracle E-Business Suite compromise

Cybercrime group Everest claims Collins Aerospace hack

Huge thanks to our sponsor, ThreatLocker

Imagine having the power to decide exactly what runs in your IT environment — and blocking everything else by default. That's what ThreatLocker delivers. As a zero-trust endpoint protection platform, ThreatLocker fills the gaps traditional solutions leave behind, giving your business stronger security and control. Don't just react to threats — stop them with ThreatLocker.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week's Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guests Tom Hollingsworth, networking technology advisor, The Futurum Group, as well as on BlueSky, and Brett Conlon, CISO, American Century Investments

Thanks to our show sponsor, Vanta

What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" ….or the really scary one: "how do I get out from under these old tools and manual processes? Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Vanta also fits right into your workflows, using AI to streamline evidence collection, flag risks, and keep your program audit-ready—ALL…THE…TIME. With Vanta, you get everything you need to move faster, scale confidently—and get back to sleep. Get started at vanta.com/headlines

All links and the video of this episode can be found on CISO Series.com

View Details

Sotheby's suffers cyberattack

Hackers exploit Cisco SNMP flaw in "Zero Disco' attacks

Microsoft revokes more than 200 certificates to disrupt ransomware campaign

Huge thanks to our sponsor, Vanta

What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" ....or the really scary one: "how do I get out from under these old tools and manual processes? Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Vanta also fits right into your workflows, using AI to streamline evidence collection, flag risks, and keep your program audit-ready—ALL…THE…TIME. With Vanta, you get everything you need to move faster, scale confidently—and get back to sleep. Get started at vanta.com/headlines Find the stories behind the headlines at CISOseries.com.

View Details

MANGO discloses data breach Threat group 'Jewelbug' infiltrates Russian IT network F5 discloses breach tied to nation-state threat actor Huge thanks to our sponsor, Vanta

What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" ....or the really scary one: "how do I get out from under these old tools and manual processes? Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Vanta also fits right into your workflows, using AI to streamline evidence collection, flag risks, and keep your program audit-ready—ALL…THE…TIME. With Vanta, you get everything you need to move faster, scale confidently—and get back to sleep. Get started at vanta.com/headlines

View Details

Legacy Windows protocols still expose theft Fortra admits exploitation of GoAnywhere defect Taiwan claims surge in Chinese attack efforts Huge thanks to our sponsor, Vanta

What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" ....or the really scary one: "how do I get out from under these old tools and manual processes? Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Vanta also fits right into your workflows, using AI to streamline evidence collection, flag risks, and keep your program audit-ready—ALL…THE…TIME. With Vanta, you get everything you need to move faster, scale confidently—and get back to sleep. Get started at vanta.com/headlines

View Details

Millions of records exposed in Salesforce data leak

SimonMed breach grows from hundreds to over a million

Dutch government freezes Chinese-owned chipmaker

Huge thanks to our sponsor, Vanta

What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" ....or the really scary one: "how do I get out from under these old tools and manual processes? Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Vanta also fits right into your workflows, using AI to streamline evidence collection, flag risks, and keep your program audit-ready—ALL…THE…TIME. With Vanta, you get everything you need to move faster, scale confidently—and get back to sleep. Get started at vanta.com/headlines

View Details

Huge thanks to our sponsor, Vanta

What's your 2 AM security worry? Is it "Do I have the right controls in place?" Or "Are my vendors secure?" ....or the really scary one: "how do I get out from under these old tools and manual processes? Enter Vanta. Vanta automates manual work, so you can stop sweating over spreadsheets, chasing audit evidence, and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data, and simplifies your security at scale. Vanta also fits right into your workflows, using AI to streamline evidence collection, flag risks, and keep your program audit-ready—ALL…THE…TIME. With Vanta, you get everything you need to move faster, scale confidently—and get back to sleep. Get started at vanta.com/headlines Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines - Week in Review is hosted by Rich Stroffolino with guests Mike Lockhart, CISO Eagleview, and Dustin Sachs, chief technologist at CyberRisk collaborative, and author of Behavioral Insights in Cybersecurity

Thanks to our show sponsor, ThreatLocker

Cybercriminals don’t knock — they sneak in through the cracks other tools miss. That’s why organizations are turning to ThreatLocker. As a zero-trust endpoint protection platform, ThreatLocker puts you back in control, blocking what doesn’t belong and stopping attacks before they spread. Zero Trust security starts here — with ThreatLocker”

All links and the video of this episode can be found on CISO Series.com

View Details

Azure outage blocks access to Microsoft 365 services and admin portals

Major U.S. law firm suffers cyberattack

Hacktivists aiming for critical infrastructure get pwned

Huge thanks to our sponsor, ThreatLocker

Imagine having the power to decide exactly what runs in your IT environment — and blocking everything else by default. That’s what ThreatLocker delivers. As a zero-trust endpoint protection platform, ThreatLocker fills the gaps traditional solutions leave behind, giving your business stronger security and control. Don’t just react to threats — stop them with ThreatLocker. Learn more at ThreatLocker.com.

Find the stories behind the headlines at CISOseries.com.

View Details

Google DeepMind’s AI agent finds and fixes vulnerabilities California law lets consumers universally opt out of data sharing China-Nexus actors weaponize 'Nezha' open source tool Huge thanks to our sponsor, ThreatLocker

Cybercriminals don’t knock — they sneak in through the cracks other tools miss. That’s why organizations are turning to ThreatLocker. As a zero-trust endpoint protection platform, ThreatLocker puts you back in control, blocking what doesn’t belong and stopping attacks before they spread. Zero Trust security starts here — with ThreatLocker. Learn more at ThreatLocker.com.

View Details

North Korean hackers steal more than $2B in crypto

Group suspected of sending stolen UK phones to China

Avnet confirms breach, says stolen data unreadable

Huge thanks to our sponsor, ThreatLocker

Imagine having the power to decide exactly what runs in your IT environment — and blocking everything else by default. That’s what ThreatLocker delivers. As a zero-trust endpoint protection platform, ThreatLocker fills the gaps traditional solutions leave behind, giving your business stronger security and control. Don’t just react to threats — stop them with ThreatLocker. Learn more at ThreatLocker.com.

View Details

Unity vulnerability puts popular games at risk

Oracle zero-day exploit patched

Third-party breach claims Discord user info

Huge thanks to our sponsor, ThreatLocker

Cybercriminals don’t knock — they sneak in through the cracks other tools miss. That’s why organizations are turning to ThreatLocker. As a zero-trust endpoint protection platform, ThreatLocker puts you back in control, blocking what doesn’t belong and stopping attacks before they spread. Zero Trust security starts here — with ThreatLocker. Learn more at ThreatLocker.com.

View Details

ParkMobile 2021 data breach class action suit concludes

UK government study suggests secondary schools larger target than businesses

Zimbra Collaboration Suite flaw used in calendar attacks

Huge thanks to our sponsor, ThreatLocker

Imagine having the power to decide exactly what runs in your IT environment — and blocking everything else by default. That’s what ThreatLocker delivers. As a zero-trust endpoint protection platform, ThreatLocker fills the gaps traditional solutions leave behind, giving your business stronger security and control. Don’t just react to threats — stop them with ThreatLocker. Learn more at ThreatLocker.com.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Nick Espinosa, nationally syndicated host of The Deep Dive Radio Show, with guest Steve Zalewski, co-host, Defense in Depth

Thanks to our show sponsor, Nudge Security

Here’s the thing: your employees are signing up for new apps, sharing data, and connecting tools together, often without anyone knowing. And, AI adoption is accelerating this trend. What if you could continuously discover when people start using new apps or sharing data, then prompt them with security guidance right when and where they are working? At Nudge Security, we call that securing the Workforce Edge. Instead of trying to control everything (which, let’s face it, is impossible), we give IT and security teams the visibility they need and automation to guide employees toward secure behaviors. The result? Your workforce stays productive, your data stays secure, and you can finally get some sleep at night. Learn more at nudgesecurity.com/workforceedge

All links and the video of this episode can be found on CISO Series.com

View Details

Government shutdown furloughs most CISA staff

Microsoft Defender bug triggers erroneous BIOS update alerts

Motility RV software company suffers cyberattack

Huge thanks to our sponsor, Nudge Security

Here's the thing: your employees are signing up for new apps, sharing data, and connecting tools together, often without anyone knowing. And, AI adoption is accelerating this trend.

What if you could continuously discover when people start using new apps or sharing data, then prompt them with security guidance right when and where they are working?

At Nudge Security, we call that securing the Workforce Edge. Instead of trying to control everything (which, let's face it, is impossible), we give IT and security teams the visibility they need and automation to guide employees toward secure behaviors.

The result? Your workforce stays productive, your data stays secure, and you can finally get some sleep at night. Learn more at nudgesecurity.com/workforceedge

Find the stories behind the headlines at CISOseries.com.

View Details

Breach notification letters set to flood North America's mailboxes New bug in classic Outlook only fixed via Microsoft support Air Force admits SharePoint privacy issue over breach Huge thanks to our sponsor, Nudge Security

AI notetakers like Otter AI spread fast. In fact, one Nudge Security customer discovered 800 new accounts created in only 90 days. Viral AI notetakers introduce a slew of data privacy risks by gaining access to calendars and adding themselves to every meeting.

Nudge Security can help. Within minutes of starting a free trial, you’ll see every AI app, account, and integration, even those created in the past. And, smart automation helps you clean up unwanted accounts and guide users towards approved alternatives.

See how you can regain control today at nudgesecurity.com/stopotter

View Details

China-Linked Group Hits Governments With Stealth Malware Chinese hackers exploit VMware zero-day since October 2024 Apple's iOS fixes a bevy of glitches

Huge thanks to our sponsor, Nudge Security

The SaaS supply chain is a hot mesh. As your workforce introduces new SaaS apps and integrations, hidden pathways are created that attackers can exploit to gain access to core business systems. That’s exactly what happened in the Drift breach, and it will happen again.

But, all is not lost. Nudge Security gives you the visibility and control you need to stop these attacks. Within minutes of starting a free trial, you'll discover every SaaS app and integration in your environment, map your SaaS supply chain, and identify risky OAuth grants that could be exploited.

The best part? Nudge Security alerts you of breaches impacting your 3rd and 4th party SaaS providers. That’s right, even 4th party! So, you can take action quickly to limit the ripple effects. Learn how Nudge can help you secure your entire SaaS ecosystem at nudgesecurity.com/supplychain

View Details

AI-generated code used in phishing campaign blocked by Microsoft WestJet notifies American consumers of data breach Ukrainian cops spoofed in fileless phishing attacks on Kyiv Huge thanks to our sponsor, Nudge Security

AI tools have spread to every corner of your tech stack, which is great for innovation, but not so great for data governance.

That's where Nudge Security comes in. Nudge discovers shadow AI across your org - chatbots, MCP integrations, AI in the supply chain, and more. And, Nudge delivers guardrails to employees to help you stop data leakage before it even starts.

The best part? You’ll have a full inventory of AI assets on Day One of your free trial, even those introduced before you started using Nudge. No time machine required.

Gain visibility and control of AI use. Get started at nudgesecurity.com/genai

View Details

Dutch teenagers arrested for attempted espionage for Russia

DoD announces replacement for risk management framework

Fake Microsoft Teams installers deliver Oyster malware

Huge thanks to our sponsor, Nudge Security

Here's the thing: your employees are signing up for new apps, sharing data, and connecting tools together, often without anyone knowing. And, AI adoption is accelerating this trend.

What if you could continuously discover when people start using new apps or sharing data, then prompt them with security guidance right when and where they are working?

At Nudge Security, we call that securing the Workforce Edge. Instead of trying to control everything (which, let's face it, is impossible), we give IT and security teams the visibility they need and automation to guide employees toward secure behaviors.

The result? Your workforce stays productive, your data stays secure, and you can finally get some sleep at night. Learn more at nudgesecurity.com/workforceedge

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by David Spark with guests Brett Conlon, CISO, American Century Investments, and TC Niedzialkowski, Head of Security & IT, OpenDoor

Thanks to our show sponsor, Conveyor

Still stuck in security review chaos week after week? You’re not the only one. But with Conveyor, teams finally get to a place of Questionnaire Zen. Our AI auto-fills answers across any format of questionnaire, even portals, and an enterprise-ready trust center keeps documents and policies ready for instant sharing. No more manual copy-pasting. No more last-minute scrambles. Just calm, clear security reviews that keep deals moving. Find your Zen with Conveyor at www.conveyor.com.

All links and the video of this episode can be found on CISO Series.com

View Details

Microsoft to offer free Windows 10 security updates in Europe

Teenage Vegas casino hacker released to parents

Boyd Gaming hacked, employee data stolen

Huge thanks to our sponsor, Conveyor

Logging into yet another security questionnaire portal on a Friday at 3pm? Yeah, that’s chaos.

Conveyor AI is your fast path to calm. It finds every question no matter the format and fills in the answers—across portals, spreadsheets, PDFs, you name it.

So instead of grinding through copy-paste, you get a first pass of accurate answers in minutes.

Find your Friday Zen at www.conveyor.com.

Find the stories behind the headlines at CISOseries.com.

View Details

Person arrested in connection with airport attack

Record-breaking DDoS attack hits new highs

China-linked attackers use ‘BRICKSTORM’ backdoor to steal IP

Huge thanks to our sponsor, Conveyor

Security reviews don’t have to feel like a hurricane. Most teams are buried in back-and-forth emails and never-ending customer requests for documentation or answers. But Conveyor takes all that chaos and turns it into calm.

AI fills in the questionnaires, your trust center is always ready, and sales cycles move without stalls.

Breathe easier—check out Conveyor at www.conveyor.com.

View Details

European airports restoring services after system breach CISA deals with GeoServer exploit

App for outing Charlie Kirk’s critics leaks personal data

Huge thanks to our sponsor, Conveyor

Have you been personally victimized by a questionnaire this week? The queue never ends. But Conveyor can change that story.

With AI that answers questionnaires of any format, and a trust center that handles document sharing, security reviews get done without the stress.

Feel calm in the chaos with Conveyor. Learn more at www.conveyor.com.

View Details

EDR-Freeze tool suspends security software

DeepMind updates Frontier Safety Framework

Major vendors withdraw from MITRE EDR Evaluations

Huge thanks to our sponsor, Conveyor

Security reviews don’t have to feel like a hurricane. Most teams are buried in back-and-forth emails and never-ending customer requests for documentation or answers. But Conveyor takes all that chaos and turns it into calm.

AI fills in the questionnaires, your trust center is always ready, and sales cycles move without stalls.

Breathe easier—check out Conveyor at www.conveyor.com.

View Details

European airport disruption due to cyberattack check-in and baggage software

SMS scammers now using mobile fake cell towers

GPT-4-powered MalTerminal malware creates ransomware and Reverse Shell

Huge thanks to our sponsor, Conveyor

If security questionnaires make you feel like you’re drowning in chaos, you’re not alone.

Endless spreadsheets, portals, and questions—always when you least expect them.

Conveyor brings calm to the storm. With AI that auto-fills questionnaires and a trust center that shares all your docs in one place, you’ll feel peace where there used to be panic.

Find your security review zen at www.conveyor.com.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guests Jack Kufahl, CISO, Michigan Medicine, and Nick Espinosa, host, The Deep Dive Radio Show

Thanks to our show sponsor, Drata

Leading security teams trust SafeBase by Drata to turn trust into a growth engine. Our enterprise-grade Trust Center puts your security posture in one secure, customer-facing portal, giving buyers instant visibility into your company’s continuous controls, certifications, and policies. With AI-powered Questionnaire Assistance, blast through inbound security questionnaires in minutes instead of days, automate cross functional workflows, and eliminate friction. That means less manual work, and faster deal cycles. Win with Trust. Learn more at SafeBase.io.

All links and the video of this episode can be found on CISO Series.com

View Details

Google patches sixth Chrome zero-day exploited in attacks this year

Microsoft to force install the Microsoft 365 Copilot app in October

Two more Scattered Spider teen suspects arrested

Huge thanks to our sponsor, Drata

Leading security teams trust SafeBase by Drata to turn trust into a growth engine. Our enterprise-grade Trust Center puts your security posture in one secure, customer-facing portal, giving buyers instant visibility into your company’s continuous controls, certifications, and policies.

With AI-powered Questionnaire Assistance, blast through inbound security questionnaires in minutes instead of days, automate cross functional workflows, and eliminate friction.

That means less manual work, and faster deal cycles.

Win with Trust. Learn more at SafeBase.io.

Find the stories behind the headlines at CISOseries.com.

View Details

Insight Partners warns thousands after ransomware breach Scattered Spider gang feigns retirement, breaks into bank instead Consumer Reports calls Microsoft 'hypocritical' Huge thanks to our sponsor, Drata

Leading security teams trust SafeBase by Drata to turn trust into a growth engine. Our enterprise-grade Trust Center puts your security posture in one secure, customer-facing portal, giving buyers instant visibility into your company’s continuous controls, certifications, and policies.

With AI-powered Questionnaire Assistance, blast through inbound security questionnaires in minutes instead of days, automate cross functional workflows, and eliminate friction.

That means less manual work, and faster deal cycles.

Win with Trust. Learn more at SafeBase.io.

View Details

House lawmakers move to extend two key cyber programs Apple 0-day likely used in spy attacks affected older devices Reuters crafts phishing scam with AI chatbot help Huge thanks to our sponsor, Drata

Leading security teams trust SafeBase by Drata to turn trust into a growth engine. Our enterprise-grade Trust Center puts your security posture in one secure, customer-facing portal, giving buyers instant visibility into your company’s continuous controls, certifications, and policies.

With AI-powered Questionnaire Assistance, blast through inbound security questionnaires in minutes instead of days, automate cross functional workflows, and eliminate friction.

That means less manual work, and faster deal cycles.

Win with Trust. Learn more at SafeBase.io.

View Details

Android moving to “risk-based” security updates

CISA accused of Cyber Incentive mismanagement

How security practitioners use LLMs

Huge thanks to our sponsor, Drata

Leading security teams trust SafeBase by Drata to turn trust into a growth engine. Our enterprise-grade Trust Center puts your security posture in one secure, customer-facing portal, giving buyers instant visibility into your company’s continuous controls, certifications, and policies.

With AI-powered Questionnaire Assistance, blast through inbound security questionnaires in minutes instead of days, automate cross functional workflows, and eliminate friction.

That means less manual work, and faster deal cycles.

Win with Trust. Learn more at SafeBase.io.

View Details

ShinyHunters hits Vietnam National Credit Information Center

HybridPetya is a Petya/NotPetya copycat with UEFI Secure Boot bypass

CISA seeks control over CVE

Huge thanks to our sponsor, Drata

Leading security teams trust SafeBase by Drata to turn trust into a growth engine. Our enterprise-grade Trust Center puts your security posture in one secure, customer-facing portal, giving buyers instant visibility into your company’s continuous controls, certifications, and policies.

With AI-powered Questionnaire Assistance, blast through inbound security questionnaires in minutes instead of days, automate cross functional workflows, and eliminate friction.

That means less manual work, and faster deal cycles.

Win with Trust. Learn more at SafeBase.io.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guests Rob Teel, CTO, Oklahoma Department of Commerce and Howard Holton, CEO, GigaOm

Thanks to our show sponsor, Vanta

Do you know the status of your compliance controls right now? Like…right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta.Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines.

All links and the video of this episode can be found on CISO Series.com

View Details

SonicWall SSL VPN flaws now being actively exploited

Acting federal cyber chief outlines his priorities

U.S. based investors in spyware firms nearly tripled in 2024

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now?

We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta.

Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI.

Now that’s…a new way to GRC.

Get started at Vanta.com/headlines.

Find the stories behind the headlines at CISOseries.com.

View Details

The npm incident: nothing to fret about? Cursor Autorun flaw lets repositories execute code without consent Senator Wyden urges FTC to probe Microsoft over Ascension hack

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now?

We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta.

Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI.

Now that’s…a new way to GRC.

Get started at Vanta.com/headlines.

View Details

Thousands had data leaked in blood center ransomware attack UK Electoral Commission recovers, 3 years after China hack Npm packages with 2 billion weekly downloads targeted in supply chain attack

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now?

We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta.

Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI.

Now that’s…a new way to GRC.

Get started at Vanta.com/headlines.

View Details

GhostAction campaign targets GitHub

Scam centers see huge growth in Myanmar

GPUGate targets IT firms

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now?

We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta.

Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI.

Now that’s…a new way to GRC.

Get started at Vanta.com/headlines.

View Details

New malware phishing campaign hidden in SVG files

Anthropic agrees to pay $1.5bn in book piracy lawsuit

Qantas penalizes executives for cyberattack

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now?

We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta.

Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI.

Now that’s…a new way to GRC.

Get started at Vanta.com/headlines.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Ray Espinoza, vp of information security, Elite Technology

Thanks to our show sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

All links and the video of this episode can be found on CISO Series.com

View Details

France fines Google and Shein over cookie misconduct

CISA adds more TP-Link routers flaws to its KEV catalog

World’s largest sports piracy site shut down

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

Find the stories behind the headlines at CISOseries.com.

View Details

Fintech foils bank heist

NotDoor backdoor

Salesloft-Drift impact continues drifting

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

Find the stories behind the headlines at CISOseries.com.

View Details

'2.5 billion Gmail users at risk'? Entirely false, says Google Cloudflare blocks largest recorded DDoS attack peaking at 11.5 Tbps

Jaguar Land Rover says cyberattack ‘severely disrupted’ production

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

View Details

LegalPwn technique hides LLMs prompts inside contract legalese

Maryland Transit investigating cyberattack

Hacker attempts to forge his way into Spanish university

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

Find the stories behind the headlines at CISOseries.com.

View Details

Velociraptor forensic tool used for C2 tunneling

City of Baltimore gets socially engineered to the tune of $1.5 million

Ransomware gang takedowns create more smaller groups

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Johna Till Johnson, CEO and founder, Nemertes

Thanks to our show sponsor, Prophet Security

Ever feel like your security team is stuck in a loop of alert fatigue and manual investigations? Meet Prophet Security. Their Agentic AI SOC Platform automates the tedious stuff: triaging, investigating, and responding to alerts - so your analysts can focus on real threats. Think 10x faster response times and a smarter way to secure your business. Learn more at prophetsecurity.ai.

All links and the video of this episode can be found on CISO Series.com

View Details

Malicious nx Packages leak GitHub, Cloud, and AI Credentials

North Korean remote worker scheme boosted by generative AI

The Netherlands announces Salt Typhoon penetration

Huge thanks to our sponsor, Prophet Security

Security teams are drowning in alerts - many companies generate upwards of 1000 or more alerts a day, and nearly half go ignored. That’s where Prophet Security comes in. Their AI SOC platform automatically triages and investigates alerts, so your team can focus on real threats instead of busywork. Faster response, less burnout, and lower risk to your business. Learn more at prophetsecurity.ai.

Find the stories behind the headlines at CISOseries.com.

View Details

FBI warns of expanded Chinese hacking campaign

AI-powered ransomware is a thing now

Anthropic warns about “vibe-hacking”

Huge thanks to our sponsor, Prophet Security

SOC analyst burnout is real - repetitive tasks, poor tooling, and constant alert noise are driving them out. Prophet Security fixes this. Their Agentic AI Analyst handles alert triage and investigation - work that 69% of cybersecurity leaders say is the best use for AI in the SOC. Say goodbye to burnout, and hello to efficiency. Check out prophetsecurity.ai.

View Details

DOGE Put Critical Social Security Data at Risk, Whistle-Blower Says

CISA warns of actively exploited Git code execution flaw Alleged mastermind behind K-Pop celebrity stock heist extradited to South Korea

Huge thanks to our sponsor, Prophet Security

Your security analysts didn’t sign up to chase false alarms all day. With Prophet Security’s AI SOC platform, they won’t have to. It works like a tireless teammate—triaging and investigating alerts around the clock. Less burnout. Better coverage. And more time for meaningful work. Learn more atprophetsecurity.ai.

View Details

If Salesforce flutters its wings in San Francisco...

How is this still tricking people?

From tagging to bagging

Huge thanks to our sponsor, Prophet Security

Security teams are drowning in alerts - many companies generate upwards of 1000 or more alerts a day, and nearly half go ignored. That’s where Prophet Security comes in. Their AI SOC platform automatically triages and investigates alerts, so your team can focus on real threats instead of busywork. Faster response, less burnout, and lower risk to your business. Learn more atprophetsecurity.ai.

View Details

Malicious Go module steals credentials via Telegram

Mirai-based botnet resurfaces targeting systems globally

Silk Typhoon hackers exploit cloud trust to hack downstream customers

Huge thanks to our sponsor, Prophet Security

Ever feel like your security team is stuck in a loop of alert fatigue and manual investigations? Meet Prophet Security. Their Agentic AI SOC Platform automates the tedious stuff: triaging, investigating, and responding to alerts - so your analysts can focus on real threats. Think 10x faster response times and a smarter way to secure your business. Learn more at prophetsecurity.ai.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino. This is our milestone edition, celebrating five years of the daily Cyber Security Headlines news podcast. Our guests today will be the CSH reporters themselves, reflecting on some stories from this week as well as their favorite stories from the past few years. Joining Rich live will be Hadas Cassorla and Steve Prentice, with videos from Sarah Lane and Lauren Verno.

Thanks to our show sponsor, Conveyor

Does logging into a portal security questionnaire feel like punishment? We get it. Other solutions offer browser extensions that require you to do all the copy-pasting. It’s slow, tedious, and frustrating. Conveyor takes care of it for you. Our AI auto-scrolls, finds every question, and fills in accurate answers—all automatically. Oh, and our AI completes security questionnaires of any format, not just portals. Visit www.conveyor.com to learn more.

All links and the video of this episode can be found on CISO Series.com

View Details

Apple urges iPhone, iPad and Mac update ASAP

Scattered Spider operative gets 10 years and a big fine

Microsoft seeks customer feedback on SSD failure issues

Huge thanks to our sponsor, Conveyor

Does logging into a portal security questionnaire feel like punishment? We get it. Other solutions offer browser extensions that require you to do all the copy-pasting. It’s slow, tedious, and frustrating. Conveyor takes care of it for you. Our AI auto-scrolls, finds every question, and fills in accurate answers—all automatically. Oh, and our AI completes security questionnaires of any format, not just portals. Visit www.conveyor.com to learn more.

Find the stories behind the headlines at CISOseries.com.

View Details

A patch today keeps the zero-day away

Jailbreaking ChatGPT-5 Pro

The thing about vulnerabilities is they stay vulnerable

Huge thanks to our sponsor, Conveyor

It’s Thursday. Have you been personally victimized by a portal security questionnaire this week? Most solutions just give you a browser extension to copy and paste answers in, still leaving hours of manual work. With Conveyor, you don’t have to slog through it yourself. Just open the portal and Conveyor’s AI will scroll through each page, find the questions, and fill in answers for you—start to finish. See how at www.conveyor.com

Find the stories behind the headlines at CISOseries.com.

View Details

UK agrees to drop 'backdoor' mandate for Apple devices Massive Allianz Life data breach impacts 1.1M people

Speed cameras knocked out after cyber attack

Huge thanks to our sponsor, Conveyor

If portal questionnaires were a person, you’d block them by now. Endless clicks, bad navigation, and expanding questions stacked like russian nesting dolls, all add up to hours of your life you'll never get back. Conveyor’s AI browser extension auto-completes any portal questionnaire without the copy and paste like those other browser extensions on the market. Spend less time battling portals and more time on work that matters. Learn more at www.conveyor.com.

View Details

Workday confirms data breach

An alliance to unify post-quantum cryptography

New Chinese threat actor targeting Taiwan

Huge thanks to our sponsor, Conveyor

If the thought of logging into a portal questionnaire makes you want to throw your laptop away, you’re not alone. Most solutions just give you a browser extension to copy and paste answers, still leaving hours of manual work. With Conveyor, you don’t have to slog through it yourself. Just open the portal and Conveyor’s AI will scroll through each page, find the questions, and fill in answers for you—start to finish. Spend less time battling portals and more time on work that matters. Learn more at www.conveyor.com.

View Details

Cisco warns of maximum-severity defect in firewall software UK’s Colt Telecom suffers cyberattack

CISA implores OT environments to lock down critical infrastructure

Huge thanks to our sponsor, Conveyor

Have you been personally victimized by portal security questionnaires? Conveyor is here to help. Endless clicks, bad navigation, and expanding questions stacked like Russian nesting dolls, all add up to hours of your life you'll never get back. With Conveyor’s AI-powered browser extension, you can open a portal questionnaire, scan for questions, and watch it auto-populate your answers back into the portal without the copy and paste. See how at www.conveyor.com

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Steve Zalewski, co-host, Defense in Depth

Thanks to our show sponsor, Vanta

Do you know the status of your compliance controls right now? Like…right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines

All links and the video of this episode can be found on CISO Series.com

View Details

New wave of NFC relay fraud, call hijacking, and root exploits in banking sector

Canada’s House of Commons suffers cyberattack

Zoom fixes critical Windows client flaw that could enable privilege escalation

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now?

We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks.

But more than 9,000 companies have continuous visibility into their controls with Vanta.

Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001.

They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI.

Now that’s…a new way to GRC. Get started at Vanta.com/headlines

Find the stories behind the headlines at CISOseries.com.

View Details

Hack of federal court filing system exploited security flaws known since 2020 Pennsylvania attorney general says cyberattack knocked phone, email systems offline

Spike in Fortinet VPN brute-force attacks raises zero-day concerns

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now?

We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks.

But more than 9,000 companies have continuous visibility into their controls with Vanta.

Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001.

They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI.

Now that’s…a new way to GRC. Get started at Vanta.com/headlines

View Details

The hits just keep on coming

Where's the Little Dutch Boy when you need him?

I felt the ransomware down in Africa

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now?

We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks.

But more than 9,000 companies have continuous visibility into their controls with Vanta.

Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001.

They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI.

Now that’s…a new way to GRC. Get started at Vanta.com/headlines

Find the stories behind the headlines at CISOseries.com

View Details

North Korean crypto theft

Microsoft rolls out PC back up during attack

U.S. charges four in $100M global fraud scheme

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now?

We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks.

But more than 9,000 companies have continuous visibility into their controls with Vanta.

Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001.

They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI.

Now that’s…a new way to GRC. Get started at Vanta.com/headlines

View Details

DARPA awards $4 million prize for AI code review at DEF CON

North Korea ScarCruft group adds ransomware to its activities

Columbia University hack affects over 860,000

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now?

We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks.

But more than 9,000 companies have continuous visibility into their controls with Vanta.

Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001.

They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI.

Now that’s…a new way to GRC. Get started at Vanta.com/headlines

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Montez Fitzpatrick, CISO, Navvis

Thanks to our show sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO

All links and the video of this episode can be found on CISO Series.com

View Details

Microsoft warns of high-severity flaw in hybrid Exchange deployments

France’s third-largest mobile operator suffers breach

Dialysis company’s April attack affects 900,000 people

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

Find the stories behind the headlines at CISOseries.com.

View Details

Hackers hijacked Google’s Gemini AI with a poisoned calendar invite to take over a smart home

Nvidia rejects US demand for backdoors in AI chips

Google says hackers stole its customers’ data by breaching its Salesforce database

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

View Details

PBS confirms data breach after employee info leaked on Discord servers

TSMC fires engineers over suspected semiconductor secrets theft Cloudflare on Perplexity web scraping techniques to avoid robot.txt and network blocks

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

View Details

Microsoft and Google among most affected as zero day exploits jump 46%

Vietnamese hackers use PXA Stealer, hit 4,000 IPs and steal 200,000 passwords globally

New Plague Linux malware stealthily maintains SSH access

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

View Details

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Derek Fisher, Director of the Cyber Defense and Information Assurance Program, Temple University – also check out Derek’s substack.

Thanks to our show sponsor, Dropzone AI

Security teams everywhere are drowning in alerts. That’s why companies like Zapier and CBTS turned to Dropzone AI—the leader in autonomous alert investigation. Their AI investigates everything, giving your analysts time back for real security work. No more 40-minute rabbit holes. If you’re at BlackHat, find them in Startup City. Otherwise, check out their self-guided demo at dropzone.ai. This is how modern SOCs are scaling without burning out.

All links and the video of this episode can be found on CISO Series.com

View Details

NATM network breached and attacked through 4G Raspberry Pi

Easterly’s appointment to West Point rescinded

Report links Chinese companies to tools used by state-sponsored hackers

Huge thanks to our sponsor, Dropzone AI

Security teams everywhere are drowning in alerts. That's why companies like Zapier and CBTS turned to Dropzone AI—the leader in autonomous alert investigation. Their AI investigates everything, giving your analysts time back for real security work. No more 40-minute rabbit holes. If you're at BlackHat, find them in Startup City. Otherwise, check out their self-guided demo at dropzone.ai. This is how modern SOCs are scaling without burning out.

Find the stories behind the headlines at CISOseries.com.

View Details

Oh No! Lenovo

You sunk my battleship! Or did you?

Russians unable to get a taste of their own medicine

Huge thanks to our sponsor, Dropzone AI

Security teams everywhere are drowning in alerts. That's why companies like Zapier and CBTS turned to Dropzone AI—the leader in autonomous alert investigation. Their AI investigates everything, giving your analysts time back for real security work. No more 40-minute rabbit holes. If you're at BlackHat, find them in Startup City. Otherwise, check out their self-guided demo at dropzone.ai. This is how modern SOCs are scaling without burning out. Find the stories behind the headlines at CISOseries.com.

View Details

Critical Authentication Flaw Identified in Base44 Vibe Coding Platform

French telecom giant Orange discloses cyberattack

FBI seizes $2.4M in Bitcoin from new Chaos ransomware operation

Huge thanks to our sponsor, Dropzone AI

What if your SOC could investigate every single alert without burning out your team? That's exactly what Dropzone AI does. They're the leader in autonomous security investigations, and companies like Zapier and Fortune 500s are already on board. Their AI works alongside your analysts, handling the routine so humans can be strategic. See them at BlackHat in Startup City, booth 6427. Or experience it yourself—dropzone.ai has a self-guided demo ready for you.

View Details

Hacktivist attack grounds Russian flights

Naval group denies breach, hackers beg to differ

Dating app breach exposes thousands of women’s pictures

Huge thanks to our sponsor, Dropzone AI

Let me tell you about Dropzone AI—they're revolutionizing how security teams work. Companies like CBTS and Zapier use their AI to investigate alerts automatically, freeing up analysts for the work that really matters. We're talking 40-minute investigations done in 3 minutes. You can meet the Dropzone team at BlackHat in Startup City, or just head to dropzone.ai for a self-guided demo. Trust me, this is the future of security operations.

View Details

NASCAR announces data breach following March cyberattack

Plankey appears to be on track to lead CISA

Microsoft investigates another outage affecting 365 admin center

Huge thanks to our sponsor, Dropzone AI

Today's sponsor is Dropzone AI, the leader in AI-powered SOC automation. Major companies like Zapier and UiPath are using Dropzone to give their security teams superpowers. Imagine your analysts focusing on real threats while AI handles every routine investigation—in minutes, not hours. If you're heading to BlackHat, stop by their booth in Startup City. But you don't have to wait—check out their self-guided demo at dropzone.ai and see why Fortune 500s are making the switch.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Nick Espinosa, host, The Deep Dive Radio Show

Thanks to our show sponsor, Nudge Security

Nudge Security discovers new apps, accounts, and data-sharing in real-time and helps guide employees toward secure behaviors. Instead of trying to control everything, we give IT and security teams the visibility and automation they need to secure the Workforce Edge.

All links and the video of this episode can be found on CISO Series.com

View Details

SonicWall announces SMA 100 patches

FBI warns about The Com

Compromised Amazon Q extension deletes everything

Huge thanks to our sponsor, Nudge Security

Nudge Security discovers new apps, accounts, and data-sharing in real-time and helps guide employees toward secure behaviors. Instead of trying to control everything, we give IT and security teams the visibility and automation they need to secure the Workforce Edge.

Find the stories behind the headlines at CISOseries.com.

View Details

Goodbye toha, or as they say in Russian, Прощай “Trust the AI," they said. “What could go wrong?” they said Adobe apps advisory activated Huge thanks to our sponsor, Nudge Security

Trying to squeeze a few more items into your budget? Nudge Security can help by discovering up to TWO YEARS of historical SaaS spend along with usage insights so you can eliminate wasted spend. In fact, Nudge Security customer KarmaCheck was able to recoup 150% of their investment in Nudge within the first 6 months. See where you can save money by starting a free trial at nudgesecurity.com/spend.

View Details

Microsoft links Sharepoint ToolShell attacks to Chinese hackers Russian threat actors target NGOs with new OAuth phishing tactics

Silicon Valley engineer admits theft of US missile tech secrets Huge thanks to our sponsor, Nudge Security

Nudge Security discovers every SaaS app used in your org, secures configurations, enforces MFA, and manages app-to-app access so you can prevent identity based attacks. Start a free 14-day trial today at NudgeSecurity.com

View Details

SharePoint RCE flaws patched and exploited from China

Dell acknowledges World Leaks data breach

$44 million stolen from crypto exchange

Huge thanks to our sponsor, Nudge Security

Nudge Security discovers every GenAI tool ever used in your org, even those you’ve never heard of. For each tool, you’ll see who introduced it, who else is using it, where it’s integrated into other tools, and a vendor security profile. Get your free GenAI inventory today at NudgeSecurity.com.

View Details

Hewlett Packard warns of hardcoded passwords in Aruba access points

SharePoint zero-day exploited via RCE, no patch available

Russian vodka producer suffers ransomware attack

Huge thanks to our sponsor, Nudge Security

Discover every SaaS account ever created by anyone in your org within minutes of starting a free trial. Harden configs, enforce MFA, revoke risky app-to-app access, and more. Learn more at NudgeSecurity.com

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Cyrus Tibbs, CISO, PennyMac

Thanks to our show sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

All links and the video of this episode can be found on CISO Series.com

View Details

Chinese hackers use Cobalt Strike on Taiwan’s semiconductor sector

Salt Typhoon breaches National Guard and steals network configurations

Congress considers Stuxnet to manage OT threats

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

Find the stories behind the headlines at CISOseries.com.

View Details

Google says ‘Big Sleep’ AI tool found bug hackers planned to use Google fixes actively exploited sandbox escape zero day in Chrome China’s cyber sector amplifies Beijing’s hacking of U.S. targets Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

View Details

Pentagon welcomes Chinese engineers into its environment

HazyBeacon: It’s not a beer, but it leaves a bitter aftertaste

What the world needs now is another framework

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

View Details

EU states to test age verification app (Reuters)

AAR pledges to start fixing 20-year old vulnerability next year (Security Week)

Grok-4 jailbroken in two days (Infosecurity Magazine)

DoD awards contracts for agentic AI (Reuters)

eSIM vulnerability exposes billions of IoT devices (Infosecurity Magazine)

UK launches Vulnerability Research Initiative (Bleeping Computer)

Interlock ransomware using FileFix for malware (Bleeping Computer)

Disinformation groups spoofs European journalists (The Record)

Elmo gets hacked (AP News)

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

View Details

CISA gives one day for Citrix Bleed 2 fix

Google Gemini flaw hijacks email summaries for phishing

Louis Vuitton says UK customer data stolen in cyber-attack

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Jim Bowie, vp, CISO, Tampa General Hospital

Thanks to our show sponsor, Vanta

Do you know the status of your compliance controls right now? Like…right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines

All links and the video of this episode can be found on CISO Series.com

View Details

Look Out! Another Outlook Outage

Iranian APTs increased activity against U.S. industries in late spring

Russian basketball player arrested in France over alleged ransomware ties

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now?

We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks.

But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001.

They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC.

Get started at Vanta.com/headlines

Find the stories behind the headlines at CISOseries.com.

View Details

AMD warns of new Meltdown, Spectre-like bugs affecting CPUs

Multiple vulnerabilities in Mozilla Thunderbird could allow for arbitrary code execution

Bitcoin Depot breach exposes data of nearly 27,000 crypto users, More than $40 million stolen from GMX crypto platform

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now?

We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks.

But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001.

They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC.

Get started at Vanta.com/headlines

View Details

Four members of President Trump's cabinet impersonated

Is this some kind of a game?

Batavia attacks Russian industrial companies

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now?

We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks.

But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001.

They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC.

Get started at Vanta.com/headlines

View Details

Call of Duty game pulled from PC store after reported exploit

U.S. military gets cybersecurity boost

Bank employee helped hackers steal $100M

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now?

We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks.

But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001.

They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC.

Get started at Vanta.com/headlines

View Details

Ingram Micro suffers ransomware attack

Hacker leaks Telefónica data allegedly from new breach

ChatGPT prone to recommending wrong URLs, creating a new phishing opportunity

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now?

We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks.

But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001.

They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC.

Get started at Vanta.com/headlines

Find the stories behind the headlines at CISOseries.com.

View Details

Undetectable Android spyware leaks user logins

Hunters ransomware group shuts doors

Medical device company Surmodics reports cyberattack

Huge thanks to our sponsor, Palo Alto Networks

You’re moving fast in the cloud and so are attackers. But while SecOps and cloud security teams are working in silos, attackers are exploiting the gaps between them. Cortex Cloud by Palo Alto Networks bridges this divide, unifying teams and stopping attacks with real-time cloud security that includes AI-powered protection, detection and automated response capabilities. Threats are stopped in minutes instead of days, and teams can finally protect cloud environments at the speed and scale of modern attacks. To learn more about how Cortex Cloud stops cloud attacks before they become breaches, visit: paloaltonetworks.com/cortex/cloud-detection-and-response

Find the stories behind the headlines at CISOseries.com.

View Details

Student data lost in Columbia University hack

German hunger relief charity hit by ransomware

Qantas contact center breached

Huge thanks to our sponsor, Palo Alto Networks

You’re moving fast in the cloud and so are attackers. But while SecOps and cloud security teams are working in silos, attackers are exploiting the gaps between them.

Cortex Cloud by Palo Alto Networks bridges this divide, unifying teams and stopping attacks with real-time cloud security that includes AI-powered protection, detection and automated response capabilities.

Threats are stopped in minutes instead of days, and teams can finally protect cloud environments at the speed and scale of modern attacks. To learn more about how Cortex Cloud stops cloud attacks before they become breaches, visit: paloaltonetworks.com/cortex/cloud-detection-and-response

View Details

Chrome Zero-Day CVE-2025-6554 under active attack — Google issues security update

International Criminal Court targeted by new ‘sophisticated’ attack

Kelly Benefits says 2024 data breach impacts 550,000 customers, Esse Health says recent data breach affects over 263,000 patients

Huge thanks to our sponsor, Palo Alto Networks

You’re moving fast in the cloud and so are attackers. But while SecOps and cloud security teams are working in silos, attackers are exploiting the gaps between them.

Cortex Cloud by Palo Alto Networks bridges this divide, unifying teams and stopping attacks with real-time cloud security that includes AI-powered protection, detection and automated response capabilities.

Threats are stopped in minutes instead of days, and teams can finally protect cloud environments at the speed and scale of modern attacks. To learn more about how Cortex Cloud stops cloud attacks before they become breaches, visit: paloaltonetworks.com/cortex/cloud-detection-and-response

View Details

U.S. agencies issue urgent warning over Iran threat

Canada bans Chinese surveillance company

CISA names new executive director

Huge thanks to our sponsor, Palo Alto Networks

You’re moving fast in the cloud and so are attackers. But while SecOps and cloud security teams are working in silos, attackers are exploiting the gaps between them.

Cortex Cloud by Palo Alto Networks bridges this divide, unifying teams and stopping attacks with real-time cloud security that includes AI-powered protection, detection and automated response capabilities.

Threats are stopped in minutes instead of days, and teams can finally protect cloud environments at the speed and scale of modern attacks. To learn more about how Cortex Cloud stops cloud attacks before they become breaches, visit: paloaltonetworks.com/cortex/cloud-detection-and-response

View Details

Hawaiian Airlines suffers cyberattack

United Natural Foods says cyber incident will impact quarterly income

Russia throttles Cloudflare making sites inaccessible

Huge thanks to our sponsor, Palo Alto Networks

You’re moving fast in the cloud and so are attackers. But while SecOps and cloud security teams are working in silos, attackers are exploiting the gaps between them.

Cortex Cloud by Palo Alto Networks bridges this divide, unifying teams and stopping attacks with real-time cloud security that includes AI-powered protection, detection and automated response capabilities.

Threats are stopped in minutes instead of days, and teams can finally protect cloud environments at the speed and scale of modern attacks. To learn more about how Cortex Cloud stops cloud attacks before they become breaches, visit: paloaltonetworks.com/cortex/cloud-detection-and-response

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Bil Harmer, operating partner and CISO, Craft Ventures. Check out Bil’s page, KillSwitchAdvisory.

Thanks to our show sponsor, ThreatLocker

Alert fatigue, false positives, analyst burnout—you know the drill. What if you could stop threats before they run? ThreatLocker gives CISOs what they’ve been asking for: real control at the execution layer. Only approved apps, scripts, and executables run. Period. Known-good is enforced. Everything else? Denied by default. Ringfencing and storage control keep even trusted tools in their lane—so PowerShell doesn’t become a weapon. And yes—it works at scale. Granular policies. Fast rollout. Built for modern infrastructure. You don’t need more alerts. You need fewer chances for malware to make a move. ThreatLocker helps you flip the model—from detect-and-respond… to deny-and-verify. Go to ThreatLocker.com/CISO to schedule your free demo and close the last gap in your Zero Trust strategy, before it’s exploited.

All links and the video of this episode can be found on CISO Series.com

View Details

Iranian-backed spearphishing campaign seeks out cybersecurity experts

Microsoft fixes Outlook bug causing crashes when opening emails

Glasgow City Council suffers cyberattack

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

Find the stories behind the headlines at CISOseries.com.

View Details

NHS confirms patient death linked to ransomware attack

BreachForums busted again

Thousands of SaaS apps still vulnerable to nOAuth

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

View Details

Hackers target over 70 Microsoft Exchange servers to steal credentials via keyloggers

Apple, Netflix, Microsoft sites ‘hacked’ for tech support scams

The 2022 initiative by Cloudflare, CrowdStrike and Ping Identity provided cybersecurity support to critical infrastructure sectors seen as potential targets of Russia-linked attacks

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

View Details

DHS warns of retaliatory Iranian cyberattacks

Steel giant Nucor confirms breach

Ransomware hits healthcare system again

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

View Details

CMC officially points finger at Scattered Spider for Marks & Spencer and Co-op attacks

Aflac investigating suspicious activity on its U.S. network

Russian dairy producers suffer cyberattack

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Howard Holton, COO and industry analyst, GigaOm

Thanks to our show sponsor, Adaptive Security

As deepfake scams and GenAI phishing evolve, Adaptive equips security teams with AI-powered phishing simulations featuring realistic personalized deepfakes and engaging security awareness training. Their new AI Content Creator turns threat intel and policy updates into interactive, multilingual training — instantly. Trusted by Fortune 500s and backed by Andreessen Horowitz and OpenAI, Adaptive helps you stay ahead of AI-driven threats. Learn more at adaptivesecurity.com.

All links and the video of this episode can be found on CISO Series.com

View Details

Cisco, Atlassian fix high-severity vulnerabilities

Alleged Ryuk ransomware gang member arrested and extradited

Telecom company Viasat attacked by Salt Typhoon

Huge thanks to our sponsor, Adaptive Security — OpenAI’s first cybersecurity investment

As deepfake scams and GenAI phishing evolve, Adaptive equips security teams with AI-powered phishing simulations featuring realistic personalized deepfakes and engaging security awareness training. Their new AI Content Creator turns threat intel and policy updates into interactive, multilingual training — instantly.

Trusted by Fortune 500s and backed by Andreessen Horowitz and OpenAI, Adaptive helps you stay ahead of AI-driven threats.

Learn more at adaptivesecurity.com.

Find the stories behind the headlines at CISOseries.com.

View Details

Over 5 million impacted by Episource breach

Predatory Sparrow strikes Iran again

Data leak at Swiss banks

Huge thanks to our sponsor, Adaptive Security — OpenAI’s first cybersecurity investment

As deepfake scams and GenAI phishing evolve, Adaptive equips security teams with AI-powered phishing simulations featuring realistic personalized deepfakes and engaging security awareness training. Their new AI Content Creator turns threat intel and policy updates into interactive, multilingual training — instantly.

Trusted by Fortune 500s and backed by Andreessen Horowitz and OpenAI, Adaptive helps you stay ahead of AI-driven threats.

Learn more at adaptivesecurity.com.

View Details

Hackers exploit critical Langflow flaw to unleash Flodrix botnet Organizations warned of vulnerability exploited against discontinued TP-Link routers

Russia detects first SuperCard malware attacks skimming bank data via NFC

Huge thanks to our sponsor, Adaptive Security — OpenAI’s first cybersecurity investment

As deepfake scams and GenAI phishing evolve, Adaptive equips security teams with AI-powered phishing simulations featuring realistic personalized deepfakes and engaging security awareness training. Their new AI Content Creator turns threat intel and policy updates into interactive, multilingual training — instantly.

Trusted by Fortune 500s and backed by Andreessen Horowitz and OpenAI, Adaptive helps you stay ahead of AI-driven threats.

Learn more at adaptivesecurity.com.

View Details

Beware the SMS 2FA middleman

Police seize Archetyp Market

Zoomcar hack impacts 8.4 million users

Huge thanks to our sponsor, Adaptive Security

As deepfake scams and GenAI phishing evolve, Adaptive equips security teams with AI-powered phishing simulations featuring realistic personalized deepfakes and engaging security awareness training. Their new AI Content Creator turns threat intel and policy updates into interactive, multilingual training — instantly. Trusted by Fortune 500s and backed by Andreessen Horowitz and OpenAI, Adaptive helps you stay ahead of AI-driven threats. Learn more at adaptivesecurity.com.

View Details

Washington Post investigates hacking incident on journalists’ emails

Canadian airline WestJet is containing a cyberattack

Crash records stolen from Texas DOT

Huge thanks to our sponsor, Adaptive Security — OpenAI’s first cybersecurity investment

As deepfake scams and GenAI phishing evolve, Adaptive equips security teams with AI-powered phishing simulations featuring realistic personalized deepfakes and engaging security awareness training. Their new AI Content Creator turns threat intel and policy updates into interactive, multilingual training — instantly.

Trusted by Fortune 500s and backed by Andreessen Horowitz and OpenAI, Adaptive helps you stay ahead of AI-driven threats.

Learn more at adaptivesecurity.com.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Christina Shannon, CIO, KIK Consumer Products

Thanks to our show sponsor, Vanta

Is your manual GRC program slowing you down? There’s something more efficient than spreadsheets, screenshots, and manual processes — Vanta. With Vanta, GRC can be so. much. easier—while also strengthening your security posture and driving revenue for your business. Vanta automates key areas of your GRC program—including compliance, risk, and customer trust—and streamlines the way you manage information. The impact is real: A recent IDC analysis found that compliance teams using Vanta are one hundred and twenty nine percent more productive. Get back time to focus on strengthening security and scaling your business. Get started at Vanta.com/headlines.

All links and the video of this episode can be found on CISO Series.com

View Details

Hackers attacks target Microsoft Entra ID accounts using pentesting tool

Google Cloud and Cloudflare outages reported

House Homeland Chairman Mark Green announces his departure

Huge thanks to our sponsor, Vanta

Is your manual GRC program slowing you down? There’s something more efficient than spreadsheets, screenshots, and manual processes — Vanta.

With Vanta, GRC can be so. much. easier—while also strengthening your security posture and driving revenue for your business. Vanta automates key areas of your GRC program—including compliance, risk, and customer trust—and streamlines the way you manage information.

The impact is real: A recent IDC analysis found that compliance teams using Vanta are one hundred and twenty nine percent more productive.

Get back time to focus on strengthening security and scaling your business. Get started at Vanta.com/headlines.

Find the stories behind the headlines at CISOseries.com.

View Details

Zero-click data leak flaw in Copilot

Operation Secure targets infostealer operations

FIN6 targets recruiters

Huge thanks to our sponsor, Vanta

Is your manual GRC program slowing you down? There’s something more efficient than spreadsheets, screenshots, and manual processes — Vanta.

With Vanta, GRC can be so. much. easier—while also strengthening your security posture and driving revenue for your business. Vanta automates key areas of your GRC program—including compliance, risk, and customer trust—and streamlines the way you manage information.

The impact is real: A recent IDC analysis found that compliance teams using Vanta are one hundred and twenty nine percent more productive.

Get back time to focus on strengthening security and scaling your business. Get started at Vanta.com/headlines.

View Details

CISA, Microsoft warn of Windows zero-day used in attack on ‘major’ Turkish defense org 40K IoT cameras worldwide stream secrets to anyone with a browser Marks & Spencer begins taking online orders again, out for seven weeks due to cyberattack Huge thanks to our sponsor, Vanta

Is your manual GRC program slowing you down? There’s something more efficient than spreadsheets, screenshots, and manual processes — Vanta.

With Vanta, GRC can be so. much. easier—while also strengthening your security posture and driving revenue for your business. Vanta automates key areas of your GRC program—including compliance, risk, and customer trust—and streamlines the way you manage information.

The impact is real: A recent IDC analysis found that compliance teams using Vanta are one hundred and twenty nine percent more productive.

Get back time to focus on strengthening security and scaling your business. Get started at Vanta.com/headlines.

View Details

Brute forcing phone numbers linked to Google accounts

The Guardian launches Secure Messaging service

United Natural Foods hit by cyberattack

Huge thanks to our sponsor, Vanta

Is your manual GRC program slowing you down? There’s something more efficient than spreadsheets, screenshots, and manual processes — Vanta.

With Vanta, GRC can be so. much. easier—while also strengthening your security posture and driving revenue for your business. Vanta automates key areas of your GRC program—including compliance, risk, and customer trust—and streamlines the way you manage information.

The impact is real: A recent IDC analysis found that compliance teams using Vanta are one hundred and twenty nine percent more productive.

Get back time to focus on strengthening security and scaling your business. Get started at Vanta.com/headlines.

View Details

Presidential cyber executive order signed

Neuberger warns of U.S. infrastructure’s cyberattack weakness

Mirai botnet infects TBK DVR devices

Huge thanks to our sponsor, Vanta

Is your manual GRC program slowing you down? There’s something more efficient than spreadsheets, screenshots, and manual processes — Vanta.

With Vanta, GRC can be so. much. easier—while also strengthening your security posture and driving revenue for your business. Vanta automates key areas of your GRC program—including compliance, risk, and customer trust—and streamlines the way you manage information.

The impact is real: A recent IDC analysis found that compliance teams using Vanta are one hundred and twenty nine percent more productive.

Get back time to focus on strengthening security and scaling your business. Get started at Vanta.com/headlines.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines - Week in Review is hosted by Rich Stroffolino with guest Rusty Waldron, chief business security officer, ADP

Thanks to our show sponsor, Conveyor

Let me guess, another security questionnaire just landed in your inbox. Which means all the follow up tasks you don’t have time for are close behind. What are you going to do? Here’s a better question: what would Sue do? Sue is Conveyor’s new AI Agent for Customer Trust. She handles the entire security review process like answering every customer request from sales, completing every questionnaire or executing every communications and coordination task in-between. No more manual work. Just a quick review when she’s done. Ready to let Sue take the reins? Learn more at www.conveyor.com.

All links and the video of this episode can be found on CISO Series.com

View Details

Stolen Kettering Health data published

Reddit sues Anthropic for scraping

North Face website customer accounts breached

Huge thanks to our sponsor, Conveyor

Let me guess, another security questionnaire just landed in your inbox. Which means all the follow up tasks you don’t have time for are close behind.

What are you going to do?

Here’s a better question: what would Sue do?

Sue is Conveyor’s new AI Agent for Customer Trust. She handles the entire security review process like answering every customer request from sales, completing every questionnaire or executing every communications and coordination task in-between.

No more manual work. Just a quick review when she’s done.

Ready to let Sue take the reins? Learn more at www.conveyor.com.

Find the stories behind the headlines at CISOseries.com.

View Details

Ukraine claims cyberattack on Russian bomber maker

Vishing campaign targets Salesforce

Microsoft lends a hand to European governments

Huge thanks to our sponsor, Conveyor

Ever wish you had a teammate that could handle the most annoying parts of customer security reviews?

You know, chasing down SMEs for answers, updating systems, coordinating across teams—all the grunt work nobody wants to do.

Plus, having to finish the dang questionnaire itself.

Well. That teammate exists—Conveyor just launched Sue, the first AI Agent for Customer Trust.

Sue really is the dream teammate. She never misses a deadline, answers every customer request from sales, completes every questionnaire and knocks out all the coordination in-between.

Sue handles it all so you don’t have to. Learn more at www.conveyor.com.

View Details

Meta and Yandex are de-anonymizing Android users’ web browsing identifiers

LummaC2 fractures as Acreed malware becomes top dog Hewlett Packard Enterprise warns of critical StoreOnce auth bypass Huge thanks to our sponsor, Conveyor

Tired of herding cats to complete customer security questionnaires?

Your team probably spends hours daily juggling the back and forth of completing these security requests.

That's why Conveyor created Sue, the first AI Agent for Customer Trust. Sue doesn't just handle completing security questionnaires and sending SOC 2 to prospects – she manages all the communication and follow-up too.

You simply get notified when everything's done so you can do a quick review.

Stop wrangling cats and see what Sue can do for you at www.conveyor.com.

View Details

Microsoft and CrowdStrike partner to link threat actor names

Qualcomm sees Adreno bugs under active exploitation

New details on proposed CISA cuts

Huge thanks to our sponsor, Conveyor

Does trying to get the security questionnaire done and back to your customer ever feel like you’re herding cats?

It’s not answering questions - most of you have automation software for that.

It’s all of the manual back and forth that becomes a slog like communicating between teams, tracking people down to get their review, updating sources and updating systems.

Conveyor just launched an AI agent, Sue, to do all of these things and more for you.

Learn about Sue at www.conveyor.com.

View Details

Exploit for maximum severity Cisco IOS XE flaw now public

Senators as for reinstatement of cyber review board to work on Salt Typhoon investigation

Australian ransomware victims now must report their payments

Huge thanks to our sponsor, Conveyor

Conveyor launched the first AI Agent for Customer Trust. So wtf does that mean?

It means the AI agent goes beyond just sharing NDA-gated documents like a SOC 2 with customers or answering security questionnaires.

Conveyor’s AI Agent, Sue, handles the entire security review process from start to finish.

She answers every customer request from sales, completes every questionnaire and executes every communications and coordination task in-between. It's perfect for B2B infosec teams sick of manual security review work.

Check it out at www.conveyor.com.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Steve Knight, former CISO, Hyundai Capital America

Thanks to our show sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

All links and the video of this episode can be found on CISO Series.com

View Details

Windows 11 might fail to start after installing KB5058405, says Microsoft

Victoria’s Secret website goes offline following cyberattack

Billions of stolen cookies available, worrying security experts

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

Find the stories behind the headlines at CISOseries.com.

View Details

Microsoft wants to update all the things

LexisNexis breach impacts 364,000 people

Cyber insurance premium volume expected to double

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

View Details

MathWorks, Creator of MATLAB, Confirms Ransomware Attack Adidas warns of data breach after customer service provider hack Dutch Intelligence Agencies Say Russian Hackers Stole Police Data in Cyberattack Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

View Details

Malicious npm and VS Code packages stealing data

Nova Scotia Power confirms ransomware attack

Researchers claim ChatGPT o3 bypassed shutdown in controlled test

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

Find the stories behind the headlines at CISOseries.com.

View Details

CISA warns Commvault clients of campaign targeting cloud applications

Russian hacker group Killnet returns with slightly adjusted mandate

Fake VPN and browser NSIS installers used to deliver Winos 4.0 malware

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest George Finney, CISO, The University of Texas System – check out George’s new book plus all his other achievements at his website, WellAwareSecurity.

Thanks to our show sponsor, Conveyor

Still spending hours maintaining a massive spreadsheet of Q&A pairs or using RFP tools to answer security questionnaires? Conveyor’s AI doesn’t need hand-holding and gets you accurate answers every time with limited knowledge base maintenance. It reads directly from your connected sources—documents, wikis, websites, Confluence, Google drive, and even your Conveyor trust center. You don’t maintain a knowledge base. You connect to one. And our AI does the rest for you. See what real auto-fill magic looks like at www.conveyor.com

All links and the video of this episode can be found on CISO Series.com

View Details

Signal adds Recall blocker

Critical Windows Server 2025 dMSA vulnerability warning

Pathology lab suffers data breach

Huge thanks to our sponsor, Conveyor

Still spending hours maintaining a massive spreadsheet of Q&A pairs or using RFP tools to answer security questionnaires?

Conveyor’s AI doesn’t need hand-holding and gets you accurate answers every time with limited knowledge base maintenance.

It reads directly from your connected sources—documents, wikis, websites, Confluence, Google drive, and even your Conveyor trust center.

You don’t maintain a knowledge base. You connect to one.

And our AI does the rest for you. See what real auto-fill magic looks like at www.conveyor.com

Find the stories behind the headlines at CISOseries.com.

View Details

Ransomware attack knocks out Kettering Health

Lumma malware operation disrupted

Federal agencies impacted by “major lapse” at Opexus

Huge thanks to our sponsor, Conveyor

Half-baked AI answers to security questionnaires are worse than no answer at all. Conveyor’s AI gets it right the first time—with market-leading accuracy rates and full citations for every response. Because “good enough” doesn’t cut it when you’re filling in questionnaires daily. Accuracy isn’t just a feature—it’s the foundation. Because we know that when AI gets it wrong, you’re stuck with more work. If AI isn’t living up to its promise with other tools, check out Conveyor at www.conveyor.com

View Details

US DOJ opens investigation into Coinbase's recent cyberattack Dutch government passes law to criminalize cyber-espionage Ransomware attack on food distributor spells more pain for UK supermarkets Huge thanks to our sponsor, Conveyor

What if your sales team could answer security questions themselves—without blowing up your Slack or email every 10 minutes? With Conveyor, they can. Conveyor is the trust center and security questionnaire automation tool your infosec friends love to use. Whether through Slack or the Conveyor app, sales and presales teams can easily get AI-generated answers to any customer security question, with your pre-set rules and reviews in place. Free up your team and keep deals moving at www.conveyor.com

View Details

UK’s Legal Aid Agency breached

NHS patients put at risk from cyberattacks

23andMe has a buyer

Huge thanks to our sponsor, Conveyor

Ever spent an hour in a clunky portal questionnaire with UI from 1999 just to lose your work because it timed out?

Conveyor’s got you.

Our browser extension completes questionnaires in the most tedious portals for you by auto-importing all the questions and generating AI answers. For popular portals, it can go full autopilot and fill in reviewed answers into the portal on one click. You shouldn’t have to fight a portal just to prove your security posture. Learn more at www.conveyor.com.

View Details

Scattered Spider facilitates UK retail hacks and is moving to the U.S.

Defendnot tool can disable Microsoft Defender

FBI warns government officials about new waves of deepfakes

Huge thanks to our sponsor, Conveyor

Are you dealing with security questionnaire chaos this week? If so, get Conveyor’s AI to knock them out for you. Connect Conveyor to any source, easily upload any format of questionnaire or use the browser extension for portals and their AI handles the rest—from parsing the questions to generating answers and auto-tagging collaborators. Let Conveyor do the work for you. Learn more at www.conveyor.com.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Nick Espinosa, host, The Deep Dive Radio Show. Here’s where you can find him: Daily Podcast on SoundCloud | YouTube | Forbes | Twitter/X | Facebook | BlueSky | Mastodon

Thanks to our show sponsor, Vanta

Do you know the status of your compliance controls right now? Like…right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines.

All links and the video of this episode can be found on CISO Series.com

View Details

Coinbase says hackers bribed staff to steal customer data and are demanding $20 million ransom Windows 11 and Red Hat Linux hacked on first day of Pwn2Own The Internet’s biggest-ever black market just shut down amid a Telegram purge Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines.

View Details

Steel producer disrupted by cyberattack

European Vulnerability Database (EUVD) is online

CISA pauses advisory overhaul

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines.

View Details

Radware says recently WAF bypasses were patched in 2023

Marks & Spencer confirms data stolen in ransomware attack

Alabama suffers cybersecurity event

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines.

Find the stories behind the headlines at CISOseries.com

View Details

Global Crossing Airlines Group confirms cyberattack

Google settles privacy lawsuits

UK launches software security guidelines

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines.

View Details

Hackers hijack Japanese financial accounts to conduct billions in trades

Education giant Pearson hit by cyberattack exposing customer data

Microsoft Teams will soon block screen capture during meetings

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Dan Holden, CISO, BigCommerce

Thanks to our show sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

All links and the video of this episode can be found on CISO Series.com

View Details

Cisco patches a level 10 vulnerability in IOS XE

President nominates former Unilever CISO to be Pentagon CIO

SonicWall patches a new zero-day vulnerability

Thanks to today's episode sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

Find the stories behind the headlines at CISOseries.com.

View Details

Europol shuts down six DDoS-for-hire services used in global attacks

CrowdStrike says it will lay off 500 workers Passkeys set to protect GOV.UK accounts against cyber-attacks Thanks to today's episode sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

Find the stories behind the headlines at CISOseries.com.

View Details

Congress challenges Noem over proposed CISA cuts

Texas school district breach impacts over 47,000 people

NSO Group to pay WhatsApp $167 million in damages

Thanks to today's episode sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

Find the stories behind the headlines at CISOseries.com.

View Details

Signal clone gets hacked

Sounding the alarm on easyjson

Ransomware group takes credit for UK retail attacks

Thanks to today's episode sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

Find the stories behind the headlines at CISOseries.com.

View Details

Microsoft ends Authenticator password autofill in favor of Edge

StealC malware enhanced with stealth upgrades and data theft

White House proposes cutting $491M from CISA budget

Thanks to today's episode sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest DJ Schleen, Head of Security, Boats Group

Thanks to our show sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

All links and the video of this episode can be found on CISO Series.com

View Details

UK retailer Co-Op suffers cyberattack

FBI shares list of 42,000 LabHost phishing domains

NSO group looking at hefty damages in WhatsApp case

Thanks to today's episode sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

Find the stories behind the headlines at CISOseries.com.

View Details

Alleged ‘Scattered Spider’ member extradited to U.S.

Experts see little progress after major Chinese telecom hack

Polish police take down impersonation scammers

Thanks to today's episode sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

For the stories behind the headlines, visit CISOseries.com.

View Details

Millions of Apple Airplay-Enabled Devices Can Be Hacked via Wi-Fi Google tracked 75 zero days exploited in the wild in 2024 France ties Russian APT28 hackers to 12 cyberattacks on French orgs

Thanks to today's episode sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

View Details

Uyghur Language Software Hijacked to Deliver Malware

Cloudflare sees a big jump in DDoS attacks

4chan back online

Thanks to today's episode sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

View Details

SAP zero-day vulnerability under widespread active exploitation

Hackers abuse OAuth 2.0 workflows to hijack Microsoft 365 accounts

Cybersecurity firm CEO charged with installing malware on hospital systems

Thanks to today's episode sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com/CISO.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Bethany De Lude, CISO emeritus, The Carlyle Group

Thanks to our show sponsor, Dropzone AI

Alert investigation is eating up your security team’s day—30 to 40 minutes per alert adds up fast. Dropzone AI‘s SOC Analyst transforms this reality by investigating every alert with expert-level thoroughness at machine speed. Our AI SOC Analyst gathers evidence, connects the dots across your security tools, and delivers clear reports with recommended actions—all in minutes. No playbooks to build, no code to write. Just consistent, high-quality investigations that free your team to focus on what matters: stopping actual threats. Meet us at RSA Booth ESE-60.

All links and the video of this episode can be found on CISO Series.com

View Details

Russian army targeted by Android malware hidden in mapping app

Attackers hit security device defects hard in 2024

Critical Commvault Command Center flaw warning

Huge thanks to our sponsor, Dropzone AI

Alert investigation is eating up your security team's day—30 to 40 minutes per alert adds up fast. Dropzone AI's SOC Analyst transforms this reality by investigating every alert with expert-level thoroughness at machine speed. Our AI SOC Analyst gathers evidence, connects the dots across your security tools, and delivers clear reports with recommended actions—all in minutes. No playbooks to build, no code to write. Just consistent, high-quality investigations that free your team to focus on what matters: stopping actual threats. Meet us at RSA Booth ESE-60.

Find the stories behind the headlines at CISOseries.com.

View Details

Blue Shield of California shared private health data of millions with Google

The FBI issues its 2024 IC3 report

Ex-Army sergeant jailed for selling military secrets

Huge thanks to our sponsor, Dropzone AI

Security analysts need practical experience to build investigation skills, but getting expert guidance for every alert is impossible. That's why Dropzone AI created COACH—a free Chrome extension that serves as an AI security mentor for SOC analysts at any level. COACH reads alerts across all major security platforms, explains their context, provides alternative hypotheses, and guides analysts through industry-standard investigation methodologies. Unlike our AI SOC Analyst product, COACH doesn't do the work for you—it teaches you how to think through investigations yourself. It supplements human mentoring with always-available guidance that respects your data with zero retention. Develop your security team's skills at Dropzone.ai/coach.

For the stories behind the headlines, head to CISOseries.com.

View Details

Microsoft Recall on Copilot+ PC: testing the security and privacy implications Russian organizations targeted by backdoor masquerading as secure networking software updates

SSL.com Scrambles to Patch Certificate Issuance Vulnerability Huge thanks to our sponsor, Dropzone AI

Is your security team spending too much time chasing alerts instead of stopping threats? Dropzone AI modernizes your security operations by handling the routine investigations that consume your team's day. Our AI SOC Analyst works with your existing security tools, learns your environment, and delivers clear, actionable reports within minutes. Your human analysts can finally focus on the most critical threats. Organizations using our AI SOC Analyst handle significantly more alerts without growing their team. See how at RSA at booth ESE-60.

View Details

Google OAuth abused in DKIM replay attack

Japan warns of sharp rise in unauthorized trading

North Koreans hijacking Zoom’s Remote Control

Huge thanks to our sponsor, Dropzone AI

Security threats don't clock out at 5 PM, but your analysts need to sleep sometime. Dropzone AI delivers around-the-clock alert investigations with the same attention to detail at midnight as at noon. Our AI SOC Analyst ensures no more morning backlogs and no more off-hours blind spots. Just reliable, continuous protection that ensures every alert gets the attention it deserves, regardless of when it arrives. See how SOC teams are achieving true 24/7 coverage with our AI SOC Analyst without the staffing challenges at Dropzone.ai.

View Details

Widespread Microsoft Entra lockouts cause by new security feature rollout

Malware delivered through diplomatic wine-tasting invites

British companies told to hold in-person interviews to thwart North Korea job scammers

Huge thanks to our sponsor, Dropzone AI

Growing your MSSP client roster while your alerts are multiplying? Dropzone AI works alongside your team, investigating alerts just like your best human analysts would. Our AI SOC Analyst cuts investigation time from an hour to minutes while handling five times more alerts per analyst. Unlike complex SOAR solutions, Dropzone deploys quickly and adapts to your environment without the need for playbooks or coding. Eliminate backlogs, reduce false positives, and deliver the detailed investigations your clients expect. Ready to scale your MSSP without scaling your team? Meet us at booth ESE-60 at RSA.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by David Spark with guest Trina Ford, CISO, iHeartMedia

Thanks to our show sponsor, Vanta

Do you know the status of your compliance controls right now? Like…right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines.

All links and the video of this episode can be found on CISO Series.com

View Details

Bipartisan push for renewal of cyberthreat information sharing law

ClickFix becoming a favorite amongst state-sponsored hackers

GoDaddy puts Zoom on mute for about 90 minutes

Thanks to this week's episode sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now?

We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta.

Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting,

And helps you get security questionnaires done 5 times faster with AI.

Now that’s…a new way to GRC. Get started at Vanta.com/headlines.

Find the stories behind the headlines at CISOseries.com

View Details

MITRE gets last-minute bailout from CISA

Krebs exits SentinelOne after security clearance pulled

Apple fixes two zero-days exploited in targeted iPhone attacks

Thanks to this week's episode sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now?

We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta.

For the stories behind the headlines, visit CISOseries.com.

Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting,

And helps you get security questionnaires done 5 times faster with AI.

Now that’s…a new way to GRC. Get started at Vanta.com/headlines.

View Details

CISA issued a statement that it execution an option on its contract with MITRE to continue funding the CVE program.

View Details

Government CVE funding set to end Tuesday 4chan, the internet's most infamous forum, is down following an alleged hack

China accuses US of launching 'advanced' cyberattacks, names alleged NSA agents Thanks to this week's episode sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now?

We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta.

Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting,

And helps you get security questionnaires done 5 times faster with AI.

Now that’s…a new way to GRC. Get started at Vanta.com/headlines.

View Details

AI code dependencies are a supply chain risk

Morocco investigates social security leak

European Commission increases security measures for US-bound staff

Thanks to this week's episode sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now?

We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta.

Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting,

And helps you get security questionnaires done 5 times faster with AI.

Now that’s…a new way to GRC. Get started at Vanta.com/headlines.

View Details

Major workforce cuts planned for CISA

Microsoft warns Windows users not to delete ‘inetpub’ folder

Data breach at testing lab affects 1.6 million people

Thanks to this week's episode sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now?

We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta.

Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting,

And helps you get security questionnaires done 5 times faster with AI.

Now that’s…a new way to GRC. Get started at Vanta.com/headlines.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Carla Sweeney, SVP, InfoSec, Red Ventures

Thanks to our show sponsor, Nudge Security

Are you struggling to secure your exploding SaaS footprint? With Nudge Security, you can discover all SaaS apps and accounts, manage access, ensure secure configurations, vet unfamiliar tools, and automate daily identity security tasks. Start a free 14-day trial

All links and the video of this episode can be found on CISO Series.com

View Details

President orders probe of former CISA Director Chris Krebs

Nissan Leaf cars can be hacked for remote spying and physical takeover

Infosec experts warn of China Typhoon retaliation against tariffs

Thanks to our episode sponsor, Nudge Security

Are you struggling to secure your exploding SaaS footprint? With Nudge Security, you can discover all SaaS apps and accounts, manage access, ensure secure configurations, vet unfamiliar tools, and automate daily identity security tasks. Start a free 14-day trial

Find the stories behind the headlines at CISOseries.com.

View Details

U.S. Comptroller suffers ‘major incident’

Oracle confirms "obsolete servers" hacked

Police seize Smokeloader malware servers and detain customers

Thanks to our episode sponsor, Nudge Security

Nudge Security is the only solution for SaaS security and governance that can discover up to two years of historical SaaS spend along with usage insights so you can uncover wasted spend and sources of unnecessary risk. Start a free 14-day trial today

For the stories behind the headlines, visit CISOseries.com.

View Details

WhatsApp vulnerability could facilitate remote code execution Spyware targeting Chinese diaspora Microsoft Patches 125 Windows Vulns, Including Exploited CLFS Zero-Day Thanks to our episode sponsor, Nudge Security

Nudge Security provides advanced security posture management for Okta, Microsoft 365, Google Workspace, and other critical apps. With Nudge, you’ll be alerted of risks like weak or missing MFA, inactive admin accounts, and risky integrations, plus you can automate remediation tasks and on-going identity governance. Start a free 14-day trial today

View Details

Apple appeals UK encryption back door order

Researchers warn about AI-driven hacking tool

PoisonSeed campaign weaponizes CRM system

Thanks to our episode sponsor, Nudge Security

Nudge Security discovers every GenAI tool ever used in your org, even those you’ve never heard of. For each tool, you’ll see who introduced it, who else is using it, where it’s integrated into other tools, and a vendor security profile. Get your free GenAI inventory today.

View Details

Haugh fired from leadership of NSA and Cyber Command

WinRAR flaw bypasses Windows Mark of the Web security alerts

Researcher creates fake passport using ChatGPT

Thanks to our episode sponsor, Nudge Security

Nudge Security helps you mitigate security risks stemming from SaaS sprawl by discovering every SaaS account ever created by anyone in your org within minutes of starting a free trial. And, you can automate on-going governance tasks like security posture checks, user access reviews, employee offboarding, and more.

Start a free 14-day trial

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Howard Holton, COO and industry analyst, GigaOm

Thanks to our show sponsor, Qualys

Overwhelmed by noise in your cybersecurity processes? Cut through the clutter with Qualys Enterprise TruRisk Management. Quantify your cyber risk in clear financial terms and focus on what matters most. Actionable insights help you prioritize critical threats, streamline remediation, and accelerate risk reduction— while effectively communicating impact to stakeholders. Empower your cybersecurity strategy with tools that drive faster, smarter, and more efficient risk management. Your secure future starts today with Qualys Enterprise TruRisk Management. Visit qualys.com/etm for more information.

All links and the video of this episode can be found on CISO Series.com

View Details

Google patches Quick Share vulnerability

ChatGPT suffered brief outage Wednesday

UK’s Royal Mail investigates data leak claims

Thanks to today's episode sponsor, Qualys

"Overwhelmed by noise in your cybersecurity processes? Cut through the clutter with Qualys Enterprise TruRisk Management. Quantify your cyber risk in clear financial terms and focus on what matters most. Actionable insights help you prioritize critical threats, streamline remediation, and accelerate risk reduction— while effectively communicating impact to stakeholders. Empower your cybersecurity strategy with tools that drive faster, smarter, and more efficient risk management. Your secure future starts today with Qualys Enterprise TruRisk Management. Visit qualys.com/etm for more information."

Find the stories behind the headlines at CISOseries.com.

View Details

North Korean IT worker army expands operations in Europe

Stripe API skimming campaign unveils new techniques for theft Verizon call filter API flaw exposed customers' incoming call history Thanks to today's episode sponsor, Qualys

"Overwhelmed by noise in your cybersecurity processes? Cut through the clutter with Qualys Enterprise TruRisk Management. Quantify your cyber risk in clear financial terms and focus on what matters most. Actionable insights help you prioritize critical threats, streamline remediation, and accelerate risk reduction— while effectively communicating impact to stakeholders. Empower your cybersecurity strategy with tools that drive faster, smarter, and more efficient risk management. Your secure future starts today with Qualys Enterprise TruRisk Management. Visit qualys.com/etm for more information."

View Details

Mozilla Thunderbird finally takes on Gmail with new email service Surge in scans on PAN GlobalProtect VPNs hints at attacks Microsoft Using AI to Uncover Critical Bootloader Vulnerabilities Thanks to today's episode sponsor, Qualys

"Overwhelmed by noise in your cybersecurity processes? Cut through the clutter with Qualys Enterprise TruRisk Management. Quantify your cyber risk in clear financial terms and focus on what matters most. Actionable insights help you prioritize critical threats, streamline remediation, and accelerate risk reduction— while effectively communicating impact to stakeholders. Empower your cybersecurity strategy with tools that drive faster, smarter, and more efficient risk management. Your secure future starts today with Qualys Enterprise TruRisk Management. Visit qualys.com/etm for more information."

View Details

FTC sends warning to future 23andMe buyer

Global phishing threat targets 88 countries

Samsung data breach tied to old stolen credentials

Thanks to today's episode sponsor, Qualys

"Overwhelmed by noise in your cybersecurity processes? Cut through the clutter with Qualys Enterprise TruRisk Management. Quantify your cyber risk in clear financial terms and focus on what matters most. Actionable insights help you prioritize critical threats, streamline remediation, and accelerate risk reduction— while effectively communicating impact to stakeholders. Empower your cybersecurity strategy with tools that drive faster, smarter, and more efficient risk management. Your secure future starts today with Qualys Enterprise TruRisk Management. Visit qualys.com/etm for more information."

View Details

FBI warns of increase in free online document converter scams

Resurge malware exploits Ivanti flaw

BlackLock hackers exposed through leak site vulnerability

Thanks to today's episode sponsor, Qualys

"Overwhelmed by noise in your cybersecurity processes? Cut through the clutter with Qualys Enterprise TruRisk Management. Quantify your cyber risk in clear financial terms and focus on what matters most. Actionable insights help you prioritize critical threats, streamline remediation, and accelerate risk reduction— while effectively communicating impact to stakeholders. Empower your cybersecurity strategy with tools that drive faster, smarter, and more efficient risk management. Your secure future starts today with Qualys Enterprise TruRisk Management. Visit qualys.com/etm for more information."

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Jonathan Waldrop, CISO, The Weather Company

Jonathan will be speaking at The CrowdStrike Crowd Tour, on Tuesday, April 15, 2025 in Atlanta – details here.

He will also be speaking at the C Vision International Think Tank on April 24, 2025, also in Atlanta – details here.

Thanks to our show sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

All links and the video of this episode can be found on CISO Series.com

View Details

150,000 sites compromised by JavaScript injection

Vulnerabilities in numerous solar power systems found

T-Mobile pays $33 million in SIM swap lawsuit

Huge thanks to our episode sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

Find the stories behind the headlines at CISOseries.com.

View Details

New ransomware group claims attack on US Telecom firm WideOpenWest

NSA warned of vulnerabilities in Signal app a month before Houthi strike chat

New ReaderUpdate malware variants target macOS users Huge thanks to our episode sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

View Details

EncryptHub linked to Microsoft Management Console exploit

Security Copilot gets AI agents

A call for more PETs in government

Huge thanks to our episode sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

View Details

More than 300 cyber criminals arrested in Africa

23andMe bankruptcy puts millions of DNA records at risk

Ukraine’s state railway partially down after attack

Huge thanks to our episode sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

View Details

U.S. Treasury lifts sanctions on Tornado Cash

Web service outage in Russia due to reported Cloudflare block

Microsoft Trust Signing service abused to code-sign malware

Huge thanks to our episode sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Christina Shannon, CIO, KIK Consumer Products

Thanks to our show sponsor, DeleteMe

Data brokers bypass online safety measures to sell your name, address, and social security number to scammers. DeleteMe scours the web to find – and remove – your private information before it gets into the wrong hands by scanning for exposed information, and completing opt-outs and removals. With over 100 Million personal listings removed, DeleteMe is your trusted privacy solution for online safety. Get 20% off your DeleteMe plan when you go to JoinDeleteMe.com/CISO and use promo code CISO at checkout.

All links and the video of this episode can be found on CISO Series.com

View Details

Stalkerware company SpyX suffers data breach

Nation-state groups hit organizations with Microsoft Windows zero-day

Swiss telecom Ascom the latest victim of HellCat’s Jira campaign

Thanks to this week episode sponsor, DeleteMe

Data brokers bypass online safety measures to sell your name, address, and social security number to scammers.

DeleteMe scours the web to find – and remove – your private information before it gets into the wrong hands by scanning for exposed information, and completing opt-outs and removals.

With over 100 Million personal listings removed, DeleteMe is your trusted privacy solution for online safety.

Get 20% off your DeleteMe plan when you go to JoinDeleteMe.com/CISO and use promo code CISO at checkout.

Find the stories behind the headlines at CISOseries.com

View Details

Attackers swipe data from Pennsylvania teachers union

Infosys settles $17.5M lawsuit after third-party breach

Top U.S. sperm bank discloses data breach

Thanks to this week episode sponsor, DeleteMe

Data brokers bypass online safety measures to sell your name, address, and social security number to scammers.

DeleteMe scours the web to find – and remove – your private information before it gets into the wrong hands by scanning for exposed information, and completing opt-outs and removals.

With over 100 Million personal listings removed, DeleteMe is your trusted privacy solution for online safety.

Get 20% off your DeleteMe plan when you go to JoinDeleteMe.com/CISO and use promo code CISO at checkout.

For the stories behind the headlines, visit CISOseries.com.

View Details

CISA scrambles to contact fired employees after court rules layoffs ‘unlawful’

Google acquires cybersecurity firm Wiz for $32 billion US Commerce department bureaus ban China's DeepSeek on government devices, sources say Thanks to this week episode sponsor, DeleteMe

Data brokers bypass online safety measures to sell your name, address, and social security number to scammers.

DeleteMe scours the web to find – and remove – your private information before it gets into the wrong hands by scanning for exposed information, and completing opt-outs and removals.

With over 100 Million personal listings removed, DeleteMe is your trusted privacy solution for online safety.

Get 20% off your DeleteMe plan when you go to JoinDeleteMe.com/CISO and use promo code CISO at checkout.

View Details

23,000 repositories targeted in popular GitHub action

Apache Tomcat RCE exploit hits servers—no authentication required

Microsoft 365 users targeted in new BEC campaigns

Thanks to this week episode sponsor, DeleteMe

Data brokers bypass online safety measures to sell your name, address, and social security number to scammers.

DeleteMe scours the web to find – and remove – your private information before it gets into the wrong hands by scanning for exposed information, and completing opt-outs and removals.

With over 100 Million personal listings removed, DeleteMe is your trusted privacy solution for online safety.

Get 20% off your DeleteMe plan when you go to JoinDeleteMe.com/CISO and use promo code CISO at checkout.

View Details

Black Basta creates tool to automate VPN brute-force attacks

Bipartisan Senate bill offers improved cybersecurity for water utilities

LockBit developer extradited from Israel, appears in New Jersey court

Thanks to this week episode sponsor, DeleteMe

Data brokers bypass online safety measures to sell your name, address, and social security number to scammers.

DeleteMe scours the web to find – and remove – your private information before it gets into the wrong hands by scanning for exposed information, and completing opt-outs and removals.

With over 100 Million personal listings removed, DeleteMe is your trusted privacy solution for online safety.

Get 20% off your DeleteMe plan when you go to JoinDeleteMe.com/CISO and use promo code CISO at checkout.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

Thanks to our show sponsor, Vanta

Do you know the status of your compliance controls right now? Like…right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, And helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines

All links and the video of this episode can be found on CISO Series.com

View Details

Medusa ransomware continues to attack infrastructure

DoJ seeks to break up Google

Another phishing campaign hits Booking.com

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, And helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines

Find the stories behind the headlines at CISOseries.com.

View Details

Microsoft Patches 57 Security Flaws, Including 6 Actively Exploited Zero-Days

US communications regulator to create council to counter China technology threats

Signal no longer cooperating with Ukraine on Russian cyberthreats, official says

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, And helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines

View Details

Sean Plankey nominated to head CISA

Ballista Botnet hits TP-Link devices

PowerSchool publishes breach report

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, And helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines

View Details

Four healthcare breaches expose over 560,000 records

Cyber attack allegedly behind X outages

Case against MGM ransomware attack dropped

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, And helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines

View Details

ONCD set to consolidate power in U.S. cyber

Undocumented commands found in Bluetooth chip used by a billion devices

Japanese telecom NTT breach affects 18,000 companies

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, And helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by David Spark with guest Brett Perry, CISO, Dot Foods

Thanks to our show sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

All links and the video of this episode can be found on CISO Series.com

View Details

Ransomware gang bypasses EDR via a webcam

Toronto Zoo updates January 2024 attack damage

House bill requires federal contractors to implement vulnerability disclosure policies

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

Then add: Find the stories behind the headlines at CISOseries.com.

View Details

Former top NSA cyber official protests probationary firings

Differing names for hackers hinders law enforcement, says security agent

Google releases AI scam detection for Android to fight conversational fraud

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

Find the stories behind the headlines at CISOseries.com.

View Details

Apple goes to court to fight UK demand for iCloud encryption backdoor 3 VMware Zero-Day bugs allow sandbox escape The Firefox I loved is gone - how to protect your privacy on it now Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

View Details

CISA denies claims of deprioritizing Russian threats

Ransomware group claims attack on U.S. newspaper publisher

Latin America's escalating cybersecurity crisis

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

View Details

Hegseth orders Cyber Command to stand down on Russia planning

Microsoft hangs up on Skype after 14 years

Mark Cuban offers to fund government tech unit that was cut

Huge thanks to our sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Andrew Wilder, CISO, Vetcor

Thanks to our show sponsor, Conveyor

Let me guess, another security questionnaire just landed in your inbox. Which means all the follow up tasks you don’t have time for are close behind. What are you going to do? Here’s a better question: what would Sue do? Sue is Conveyor’s new AI Agent for Customer Trust. She handles the entire security review process like answering every customer request for a SOC 2 from sales, completing every questionnaire or executing every communications and coordination task in-between. No more manual work. Just a quick review when she’s done. Ready to let Sue take the reins? Learn more at www.conveyor.com.

All links and the video of this episode can be found on CISO Series.com

View Details

Chinese cyber espionage jumped 150% last year

Nakasone warns of U.S. falling behind adversaries in cyberspace

PolarEdge botnet exploits Cisco, ASUS, QNAP, and Synology

Huge thanks to our sponsor, Conveyor

Let me guess, another security questionnaire just landed in your inbox. Which means all the follow up tasks you don’t have time for are close behind. What are you going to do? Here’s a better question: what would Sue do? Sue is Conveyor’s new AI Agent for Customer Trust. She handles the entire security review process like answering every customer request for a SOC 2 from sales, completing every questionnaire or executing every communications and coordination task in-between. No more manual work. Just a quick review when she’s done. Ready to let Sue take the reins? Learn more at www.conveyor.com.

Find the stories behind the headlines at CISOseries.com.

View Details

Thousands of exposed GitHub repositories, now private, can still be accessed through Copilot Cellebrite halts product use in Serbia following Amnesty surveillance report New Ghostwriter campaign targets Ukrainian Government and opposition activists in Belarus Huge thanks to our sponsor, Conveyor

It’s 2025. This is your second sign to get a trust center if you don’t already have one. Reduce manual work by 80% when you can share one link to your trust center and let customers download what they need on demand. Trusted by the world’s top B2B companies, Conveyor’s enterprise-grade trust center is specially designed to handle multiple products, complex orgs, and with AI first so you can even push your customers to self-serve their own AI answers to questionnaires. Learn more at www.conveyor.com.

View Details

US employee screening firm confirms breach

Swedish law enforcement seeking messaging app backdoors

Dems warn of exposed entry points on government systems

Huge thanks to our sponsor, Conveyor

Ever wish you had a teammate that could handle the most annoying parts of customer security reviews? You know, chasing down SMEs for answers, updating systems, coordinating across teams—all the grunt work nobody wants to do. Plus, having to finish the dang questionnaire itself. Well. That teammate exists—Conveyor just launched Sue, the first AI Agent for Customer Trust. Sue really is the dream teammate. She never misses a deadline, answers every customer request from sales, completes every questionnaire and knocks out all the coordination in-between. Sue, Conveyor’s AI agent, handles it all so you don’t have to. Learn more at www.conveyor.com.

View Details

Australia bans Kaspersky over security concerns

Government screens hijacked with AI Video of President Trump and Musk

EU sanctions North Korean official linked to Lazarus Group

Huge thanks to our sponsor, Conveyor

Does trying to get the security questionnaire done and back to your customer ever feel like you’re herding cats? It’s not just answering questions. It’s all of the manual back and forth that becomes a slog like communicating between teams, tracking people down to get their review, updating sources and updating systems. Between all of this, you’re also expected to field security documentation requests from customers. Well, Conveyor just launched an AI agent, Sue, to do all of these things and more for you. Learn about Sue at www.conveyor.com.

View Details

Hacker steals nearly $1.5 billion from Bybit crypto wallet

Apple pulls iCloud end-to-end encryption in the UK

PayPal "New Address" feature abused in phishing scam

Huge thanks to our sponsor, Conveyor

It’s 2025. This is your sign to get a trust center if you don’t already have one. Speed up security reviews and reduce the headaches when you can share one link to your trust center and let customers download what they need on demand. Trusted by the world’s top B2B companies, Conveyor’s enterprise-grade trust center is specially designed to handle multiple products, complex orgs, and with AI first so you can even push your customers to self-serve their own AI answers to questionnaires. Learn more at www.conveyor.com.

For the stories behind the headlines, visit CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest TC Niedzialkowski, former CISO

Thanks to our show sponsor, Scrut Automation

Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.

All links and the video of this episode can be found on CISO Series.com

View Details

Minerals company loses $500,000 to BEC scam

Australian IVF provider investigating cyber incident

SEC replaces cryptocurrency fraud unit with emerging tech team

Thanks to today's episode sponsor, Scrut Automation

Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.

Find the stories behind the headlines at CISOseries.com.

View Details

Russian hackers tap into Signal conversations

Ransomware group hits critical infrastructure globally

CISA says patch Palo Alto flaw immediately

Thanks to today's episode sponsor, Scrut Automation

Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.

View Details

New OpenSSH Flaws Enable Man-in-the-Middle and DoS Attacks — Patch Now

Microsoft reminds admins to prepare for WSUS driver sync deprecation

Zwipe runs out of time for biometric card revenues, files for bankruptcy

Thanks to today's episode sponsor, Scrut Automation

Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.

View Details

Dutch Police take down Zservers

Chase to block Zelle payments to sellers on social media

Finastra notifies victims of October data breach

Thanks to today's episode sponsor, Scrut Automation

Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.

For the stories behind the headlines, visit CISOseries.com.

View Details

Hackers steal emails in device code phishing attacks

Anti-TOAD feature seeks to prevent in-call sideloading attacks

Chinese hackers breach more U.S. telecoms via unpatched Cisco routers

Thanks to today's episode sponsor, Scrut Automation

Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Doug Mayer, vp, CISO, WCG

Thanks to our show sponsor, Vanta

Do you know the status of your compliance controls right now? Like…right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines

All links and the video of this episode can be found on CISO Series.com

View Details

U.S. lawmakers demand UK retraction of Apple backdoor

Sarcoma ransomware claims breach at giant PCB maker Unimicron

Ransomware attack disrupts Michigan’s Sault Tribe operations

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines

Find the stories behind the headlines at CISOseries.com.

View Details

DOGE is hacking America This Ad-Tech company is powering surveillance of US military personnel Apple and Google take down malicious mobile apps from their app stores Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines

View Details

LockBit host sanctioned

A peak at DeepSeek’s weak security

Sandworm targeting Ukraine with trojanized KMS

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines

View Details

Urgent iOS update fixes critical USB security flaw

CISA officials placed on administrative leave

Attack disrupts newspaper giant’s operations

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines

View Details

Shock and lawsuit over security failures in DOGE takeover

CISA adds Microsoft Outlook and Sophos XG Firewall to its Known Exploited Vulnerabilities catalog

DeepSeek App transmits sensitive user and device data without encryption

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, and helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Caitlin Sarian, owner and CEO, Cybersecurity Girl LLC

Thanks to our show sponsor, ThreatLocker

ThreatLocker (R) is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

All links and the video of this episode can be found on CISO Series.com

View Details

Critical RCE bug in Microsoft Outlook now exploited in attacks

Kimsuky uses forceCopy malware to steal browser-stored credentials

Treasury agrees to block additional DOGE staff from accessing sensitive payment systems

Huge thanks to our episode sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

Find the stories behind the headlines at CISOseries.com.

View Details

Spain arrests hacker of U.S. and Spanish military agencies

Robocallers called the FCC pretending to be from the FCC

Ransomware payments decreased 35% year-over-year

Huge thanks to our episode sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

For the stories behind the headlines, visit CISOseries.com.

View Details

Meta says it may stop development of AI systems it deems too risky

Ferret Malware Added to 'Contagious Interview' Campaign Credential Theft Becomes Cybercriminals' Favorite Target Huge thanks to our episode sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

Find the stories behind the headlines at CISOseries.com.

View Details

Exploited vulnerabilities up significantly from previous year

First U.S. state to declare ban on DeepSeek

Crypto scams make comeback on X

Huge thanks to our episode sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

View Details

Google describes APTs using Gemini AI

India’s Tata Technologies suffers ransomware attack

Meta confirms new zero-click WhatsApp spyware

Huge thanks to our episode sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Alexandra Landegger, Global Head of Cyber Strategy & Transformation, RTX

Thanks to our show sponsor, Conveyor

Let me guess, another security questionnaire just landed in your inbox. Which means all the follow up tasks you don’t have time for are close behind. What are you going to do? Here’s a better question: what would Sue do? Sue is Conveyor’s new AI Agent for Customer Trust. She handles the entire security review process like answering every customer request from sales, completing every questionnaire or executing every communications and coordination task in-between. No more manual work. Just a quick review when she’s done. Ready to let Sue take the reins? Learn more at www.conveyor.com.

All links and the video of this episode can be found on CISO Series.com

View Details

New York Blood Center suffers ransomware attack

DeepSeek’s exposed database leaks sensitive data

CISA’s future unclear under new administration

Huge thanks to our sponsor, Conveyor

Let me guess, another security questionnaire just landed in your inbox. Which means all the follow up tasks you don’t have time for are close behind. What are you going to do? Here’s a better question: what would Sue do? Sue is Conveyor’s new AI Agent for Customer Trust. She handles the entire security review process like answering every customer request from sales, completing every questionnaire or executing every communications and coordination task in-between. No more manual work. Just a quick review when she’s done. Ready to let Sue take the reins? Learn more at www.conveyor.com.

Find the stories behind the headlines at CISOseries.com.

View Details

Tenable acquiring Israel’s Vulcan Cyber in $150 million deal Chinese and Iranian Hackers Are Using U.S. AI Products to Bolster Cyberattacks U.S. Navy bans use of DeepSeek due to ‘security and ethical concerns’ Huge thanks to our sponsor, Conveyor

Ever wish you had a teammate that could handle the most annoying parts of customer security reviews? You know, chasing down SMEs for answers, updating systems, coordinating across teams—all the grunt work nobody wants to do. Plus, having to finish the dang questionnaire itself. Well. That teammate exists—Conveyor just launched Sue, the first AI Agent for Customer Trust. Sue really is the dream teammate. She never misses a deadline, answers every customer request from sales, completes every questionnaire and knocks out all the coordination in-between. Sue handles it all so you don’t have to. Learn more at www.conveyor.com.

View Details

Most ransomware victims shut down operations shutdowns

EU sanctions GRU members for Estonia cyberattacks

Lynx ransomware runs a tight ship

Huge thanks to our sponsor, Conveyor

Tired of herding cats to complete customer security questionnaires?

Your team probably spends hours daily juggling the back and forth of completing these security requests.

That's why Conveyor created Sue, the first AI Agent for Customer Trust. Sue doesn't just handle completing security questionnaires and sending SOC 2 to prospects – she manages all the communication and follow-up too.

You simply get notified when everything's done so you can do a quick review. Stop wrangling cats and see what Sue can do for you at www.conveyor.com.

View Details

Google responds to “most sophisticated” voice phishing attack

Security consortium creates Opengrep

DeepSeek suspends new user registrations

Huge thanks to our sponsor, Conveyor

Tired of herding cats to complete customer security questionnaires? Your team probably spends hours daily juggling the back and forth of completing these security requests. That's why Conveyor created Sue, the first AI Agent for Customer Trust. Sue doesn't just handle completing security questionnaires and sending SOC 2 to prospects – she manages all the communication and follow-up too. You simply get notified when everything's done so you can do a quick review. Stop wrangling cats and see what Sue can do for you at www.conveyor.com.

View Details

DHS Advisory Committee memberships halted

UnitedHealth updates number of data breach victims to 190 million

Meta’s Llama Framework flaw exposes AI systems to remote code execution risks

Huge thanks to our sponsor, Conveyor

Conveyor launched the first AI Agent for Customer Trust. So wtf does that mean? It means the AI agent goes beyond just sharing NDA-gated documents like a SOC 2 with customers or answering security questionnaires. Conveyor’s AI Agent, Sue, handles the entire security review process from start to finish. She answers every customer request from sales, completes every questionnaire and executes every communications and coordination task in-between. It's perfect for B2B infosec teams sick of manual security review work. Check it out at www.conveyor.com.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Shaun Marion, vp, CSO, Xcel Energy

Thanks to our show sponsor, Vanta

Do you know the status of your compliance controls right now? Like…right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, And helps you get security questionnaires done 5 times faster with AI. Now that’s…a new way to GRC. Get started at Vanta.com/headlines.

All links and the video of this episode can be found on CISO Series.com

View Details

TSA cyber chief David Pekoske ousted by new administration

CISOs gain boardroom traction Influence but still lack soft skills, says Splunk

Cisco Fixes vulnerability in Meeting Management

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, And helps you get security questionnaires done 5 times faster with AI.

Now that’s…a new way to GRC. Get started at Vanta.com/headlines.

Find the stories behind the headlines at CISOseries.com.

View Details

Trump administration fires members of cybersecurity review board in ‘horribly shortsighted’ decision Major Cybersecurity Vendors' Credentials Found on Dark Web PowerSchool hacker claims they stole data of 62 million students Thanks to today’s episode sponsor, Vanta Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, And helps you get security questionnaires done 5 times faster with AI.

Now that’s…a new way to GRC. Get started at Vanta.com/headlines.

View Details

7-Zip flaw bypasses Windows security warnings

Attackers impersonate Ukraine’s CERT-UA

AI Executive Order revoked

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, And helps you get security questionnaires done 5 times faster with AI.

Now that’s…a new way to GRC. Get started at Vanta.com/headlines.

View Details

HPE investigates breach claims

Former CIA analyst pleads guilty to sharing Top Secret files

Data of nearly half million hotel guests exposed

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, And helps you get security questionnaires done 5 times faster with AI.

Now that’s…a new way to GRC. Get started at Vanta.com/headlines.

For the stories behind the headlines, visit CISOseries.com.

View Details

Tik Tok is back, with strings attached

Noem promises to curtail CISA

Label company Avery announces data breach

Huge thanks to our sponsor, Vanta

Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews, and reporting, And helps you get security questionnaires done 5 times faster with AI.

Now that’s…a new way to GRC. Get started at Vanta.com/headlines.

Then add: Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Phil Beyer, head of security, Flex

Thanks to our show sponsor, Dropzone.ai

What if your SOC could handle 10x the alerts without burning out your team? Dropzone AI automates Tier 1 investigations and frees your analysts to tackle bigger challenges. It’s how smart teams are staying ahead. See how it works—schedule a demo today at dropzone.ai.

All links and the video of this episode can be found on CISO Series.com

View Details

Biden signs cybersecurity executive order

Star Blizzard targeting WhatsApp

US healthcare sector saw 585 breaches in 2024

Huge thanks to our sponsor, Dropzone AI

What if your SOC could handle 10x the alerts without burning out your team? Dropzone AI automates Tier 1 investigations and frees your analysts to tackle bigger challenges. It’s how smart teams are staying ahead. See how it works—schedule a demo today at dropzone.ai.

For the stories behind the headlines, head on over to CISOSeries.com

View Details

  • How to delete Facebook, Messenger, or Instagram - if you want Meta out of your life
  • GoDaddy slapped with wet lettuce for years of lax security and 'several major breaches’
  • TikTok could possibly stay alive after Sunday’s upcoming ban

Huge thanks to our sponsor, Dropzone AI

Alert fatigue is real, and it’s draining. Dropzone AI takes on the tedious investigations, so you can focus on making an impact where it matters most. It’s smarter tools for a smarter SOC. Check it out at dropzone.ai.

For the stories behind the headlines, head on over to CISOSeries.com

View Details

Snyk mysteriously deploys apparently malicious packages

Baltic sea cable cuts can’t be accident, says EU tech chief

CISA warns of second BeyondTrust vulnerability

Huge thanks to our sponsor, Dropzone AI

Does your SOC feel like it’s drowning in alerts? Dropzone AI cuts through the noise, triaging 100% of alerts and giving you clear, actionable insights. Ready to break free? Check out the demo at dropzone.ai.

For the stories behind the headlines, head on over to CISOSeries.com

View Details

Telefonica breach exposes internal data and employee credentials

New ransomware group leverages AI

Allstate accused of selling consumer driving data

Huge thanks to our sponsor, Dropzone AI

Running a SOC is tough—too many alerts, not enough time. Dropzone AI changes that. It reduces manual investigations by up to 90%, giving your team the bandwidth to focus on strategic threats. Imagine the impact on your operations. Visit dropzone.ai today.

For the stories behind the headlines, head on over to CISOSeries.com

View Details

IRS Identity Protection PIN now available for filing season

CISA sees enrollment surge in cyberhygiene for critical infrastructure

City services in Winston-Salem affected by cyberattack

Huge thanks to our sponsor, Dropzone AI

Feeling buried under endless alerts? We get it. Dropzone AI takes over the grind—investigating every alert 24/7. No more chasing false positives or wasting time on noise. It’s all about clarity and focus. Ready to transform your day? Head to dropzone.ai to learn more.

For the stories behind the headlines, head on over to CISOSeries.com

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Bil Harmer, operating partner and CISO, Craft Ventures

Thanks to our show sponsor, Nudge Security

Nudge Security helps you mitigate security risks stemming from SaaS sprawl by discovering every SaaS account ever created by anyone in your org within minutes of starting a free trial. And, you can automate on-going governance tasks like security posture checks, user access reviews, employee offboarding, and more. Start a free 14-day trial

All links and the video of this episode can be found on CISO Series.com

View Details

Proton recovers from worldwide outage

BayMark Health Services announces data breach

U.S. Treasury breach linked to Silk Typhoon group

Huge thanks to our sponsor, Nudge Security

Are you struggling to secure your exploding SaaS footprint? With Nudge Security, you can discover all SaaS apps and accounts, manage access, ensure secure configurations, vet unfamiliar tools, and automate daily identity security tasks. Start a free 14-day trial

Find the stories behind the headlines at CISOseries.com.

View Details

PowerSchool hacked

Lawmakers expected to revive attempts for new Cyber Force study

European Commission receives first GDPR fine

Huge thanks to our sponsor, Nudge Security

Nudge Security is the only solution for SaaS security and governance that can discover up to two years of historical SaaS spend along with usage insights so you can uncover wasted spend and sources of unnecessary risk. Start a free 14-day trial today

View Details

Cyber Trust marks to roll out in 2025

UK to criminalize sexually explicit deepfakes

CISA says government hack limited to Treasury

Huge thanks to our sponsor, Nudge Security

Nudge Security provides advanced security posture management for Okta, Microsoft 365, and Google Workspace. With Nudge, you’ll be alerted of identity security risks like weak or missing MFA, inactive admin accounts, and risky integrations, plus you can automate remediation tasks and on-going identity governance. Start a free 14-day trial today

View Details

Wallet drainer malware makes major impact

U.S. telecom breach list grows

Urgent warning on Moxa router vulnerabilities

Huge thanks to our sponsor, Nudge Security

Nudge Security discovers every GenAI tool ever used in your org, even those you’ve never heard of. For each tool, you’ll see who introduced it, who else is using it, where it’s integrated into other tools, and a vendor security profile. Get your free GenAI inventory today.

View Details

U.S. sanctions China’s Integrity Technology for role in Flax Typhoon attacks

French military contractor Atos dismisses ransomware attack claims

German airports hit by IT outage

Huge thanks to our sponsor, Nudge Security

Nudge Security helps you mitigate security risks stemming from SaaS sprawl by discovering every SaaS account ever created by anyone in your org within minutes of starting a free trial. And, you can automate on-going governance tasks like security posture checks, user access reviews, employee offboarding, and more. Start a free 14-day trial.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Quincy Castro, CISO, Redis

Thanks to our show sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker. ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team. To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

All links and the video of this episode can be found on CISO Series.com

View Details

Beijing-linked hackers penetrated U.S. Treasury systems

Russian tanker suspected of undersea data cable sabotage

Lumen says it has locked the Salt Typhoon group out of its network

Thanks to today's episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

For the story behind the headlines, go to CISOSeries.com

View Details

U.S. soldier arrested for alleged leak of Trump and Harris call logs

Iranian and Russian entities sanctioned for election interference

Rhode Island’s health benefits data leaked

Thanks to today's episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

For the story behind the headlines, go to CISOSeries.com

View Details

Cisco confirms data leak

Microsoft announces urgent .NET domain transition

Stories of the year from Cyber Security Headlines reporters

Thanks to today's episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

For the story behind the headlines, go to CISOSeries.com

View Details

Cybersecurity company’s Chrome extension hijacked for data theft

Hackers steal ZAGG customer credit cards in third-party breach

Volkswagen software company Cariad suffers Amazon cloud breach

Thanks to today's episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

For the story behind the headlines, go to CISOSeries.com

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Steve Zalewski, CISO in Residence

Thanks to our show sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker. ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team. To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

All links and the video of this episode can be found on CISO Series.com

View Details

General Dynamics says employees targeted in phishing attack

Japan Airlines systems are back to normal after cyberattack

American Addiction Centers suffers data breach

Thanks to today's episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

For the story behind the headlines, go to CISOSeries.com

View Details

State Department’s disinformation office to close after funding terminated

Pittsburgh Regional Transit suffers ransomware attack

Another Mirai botnet targets NVRs and TP-Link routers

Thanks to today's episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

For the story behind the headlines, go to CISOSeries.com

View Details

Using LLMs to generate malware variants

NSO liable for WhatsApp hacks

OpenAI fined for privacy violations

Thanks to today's episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

For the story behind the headlines, go to CISOSeries.com

View Details

PaaS platform “FlowerStorm” attacking Microsoft 365 users

CISA adds BeyondTrust flaw to its Known Exploited Vulnerabilities catalog

Ascension Health ransomware attack impacted nearly 6 million people

Thanks to today's episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

For the story behind the headlines, go to CISOSeries.com

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Bethany De Lude, CISO, The Carlyle Group

Thanks to our show sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker. ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team. To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

All links and the video of this episode can be found on CISO Series.com

View Details

Android malware found on Amazon Appstore disguised as health app

BeyondTrust suffers cyberattack

Fortinet warns of critical flaw in Wireless LAN Manager

Thanks to today’s episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

For the stories behind the headlines, head of CISOSeries.com.

View Details

Interpol kills off Pig Butchering

Supreme Court to hear TikTok ban challenge

US weighs TP-Link ban

Thanks to today’s episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

For the stories behind the headlines, head of CISOSeries.com.

View Details

CISA delivers new directive for securing cloud environments

Texas Tech reports a data breach affecting 1.4 million people

Meta fined $263 million for alleged GDPR violations

Thanks to today’s episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

For the stories behind the headlines, head of CISOSeries.com.

View Details

Serbian authorities accused of using Cellebrite to spy on journalists

Ransomware attack shuts down Rhode Island’s public assistance system

ConnectOnCall breach exposes close to a million patients

Thanks to today’s episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

For the stories behind the headlines, head of CISOSeries.com.

View Details

UnitedHealth’s AI-driven insurance claims chatbot left exposed to the internet

South Carolina credit union suffers cyberattack

IOCONTROL cyberweapon targets infrastructure in the US and Israel

Thanks to today’s episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

For the stories behind the headlines, head of CISOSeries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines - Week in Review is hosted by Rich Stroffolino with guest Jimmy Sanders, president, ISSA International. ISSA International April 2025- will be celebrating its 40th Anniversary in April 2025. Watch for notifications at ISSA.org

Thanks to today’s episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker. ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team. To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

All links and the video of this episode can be found on CISO Series.com

View Details

Microsoft MFA bypassed in AuthQuake attack

Cybercrime marketplace Rydox taken down

U.S. charges Chinese national for hacking thousands of Sophos firewall devices

Thanks to today’s episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

For the stories behind the headlines, head of CISOSeries.com.

View Details

Operation PowerOFF hits DDoS sites

FCC proposes new telco cybersecurity rules

ZLoader returns

Thanks to today’s episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

For the stories behind the headlines, head of CISOSeries.com.

View Details

Senator announces new bill to secure telecom companies

Google unveils new quantum chip

U.S. sanctions Chinese cybersecurity firm for firewall hacks

Thanks to today’s episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

For the stories behind the headlines, head of CISOSeries.com.

View Details

Romanian energy giant battles ongoing attack

Ransomware disrupts medical device maker

Deloitte responds to data theft claims

Thanks to today’s episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

For the stories behind the headlines, head of CISOSeries.com.

View Details

Anna Jaques Hospital confirms details of Christmas Day ransomware breach

Microsoft expands Recall preview to Intel and AMD Copilot+ PCs

Blue Yonder announces restoration progress after November 21 attack

Thanks to today’s episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

For the stories behind the headlines, head of CISOSeries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Sean Kelly with guest Edward Frye, head of security, Luminary Cloud.

Thanks to our show sponsor, Vanta

As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews. Visit vanta.com to learn more about Questionnaire Automation.

All links and the video of this episode can be found on CISO Series.com

View Details

Feds find cybercriminal tools used by sextortion group

Russian hackers hack hackers

Amazon’s post-quantum migration plan

Huge thanks to our sponsor, Vanta

As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews. Visit vanta.com to learn more about Questionnaire Automation.

Get the stories behind the headlines at CISOSeries.com

View Details

FBI and CISA urge Americans to use encrypted apps rather than calling, iVerify scanner finds seven Pegasus spyware infections, Japan warns of IO-Data zero-day router flaws exploited in attacks

Huge thanks to our sponsor, Vanta

As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews. Visit vanta.com to learn more about Questionnaire Automation.

Get the stories behind the headlines at CISOSeries.com

View Details

Stoli files for bankruptcy in U.S. after ransomware attack

Police seize largest German online criminal marketplace

FBI advises telecoms to boost security following Chinese hacking campaign

Huge thanks to our sponsor, Vanta

As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews. Visit vanta.com to learn more about Questionnaire Automation.

Get the stories behind the headlines at CISOSeries.com

View Details

Hydra Market leader sentenced to life

Former Polish spy chief arrested in Pegasus spyware probe

SpyLoan malware targets millions

Huge thanks to our sponsor, Vanta

As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews. Visit vanta.com to learn more about Questionnaire Automation.

Get the stories behind the headlines at CISOSeries.com

View Details

Ransomware affiliate Mikhail Matveev arrested

Another UK hospital system hacked

Cloudflare says it lost 55% of logs pushed to customers for 3.5 hours

Huge thanks to our sponsor, Vanta

As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews. Visit vanta.com to learn more about Questionnaire Automation.

Get the stories behind the headlines at CISOSeries.com

View Details

Patch alert after flaws identified in Advantech industrial Wi-Fi access points

T-Mobile confirms Salt Typhoon attack was blocked

UK hospital network postpones procedures after cyberattack

Huge thanks to our sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

Find the stories behind the headlines at CISOseries.com.

View Details

Interpol takes down over 1,000 cybercrime suspects in Africa

Starbucks and UK grocers impacted by supply chain attack

Hacker in Snowflake extortions may be a U.S. soldier

Huge thanks to our sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

For the stories behind the headlines, visit CISOseries.com.

View Details

Microsoft 365 outage update

“Hair on Fire” over China’s cyber campaign

North Korean fake IT worker scheme unveiled

Huge thanks to our sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

View Details

DoJ seizes credit card marketplace PopeyeTools

Gambling giant IGT suffers cyberattack

Windows update blocked on some gaming PCs

Huge thanks to our sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker. ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Jimmy Benoit, vp, cybersecurity, PBS

Thanks to our show sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker. ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team. To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

All links and the video of this episode can be found on CISO Series.com

View Details

MITRE offers updated list of most dangerous software vulnerabilities

CISOs can now obtain professional liability insurance

BianLian group refines its game

Thanks to today's episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

Get the stories behind the headlines at CISOSeries.com.

View Details

US charges Scattered Spider members

Chinese threat actors infiltrate more telcos

Apple issues emergency security update

Thanks to today's episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

Get the stories behind the headlines at CISOSeries.com.

View Details

CISA director Jen Easterly to step down

Space tech giant Maxar discloses employee data breach

Microsoft launches Zero Day Quest hacking event

Thanks to today's episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

Get the stories behind the headlines at CISOSeries.com.

View Details

EPA warns of critical risks in drinking water infrastructure

Four million WordPress sites exposed

Sextortion scams bypass Microsoft security filters

Thanks to today's episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

Get the stories behind the headlines at CISOSeries.com.

View Details

T-Mobile confirms telecom breach hack

Customer data stolen from AnnieMac

New Glove infostealer malware bypasses Chrome’s cookie encryption

Thanks to today's episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

Get the stories behind the headlines at CISOSeries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Brett Conlon, CISO, American Century Investments

Thanks to our show sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker. ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team. To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

All links and the video of this episode can be found on CISO Series.com

View Details

China threat actors breached U.S. broadband providers to spy on U.S. government officials

123456 tops the list of most popular passwords again

Hacker gets 10 years in prison for U.S. healthcare extortion scheme

Thanks to today's episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker. ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team. To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

Get the stories behind the headlines at CISOSeries.com

View Details

Volt Typhoon rebuilding botnet

Chinese group targets Tibetan media

DoD leaker sentenced

Thanks to today's episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker. ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team. To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

Get the stories behind the headlines at CISOSeries.com

View Details

Dutch cybersecurity incident affects Giant Food and Hannaford

Indictment against Snowflake breach suspects is released

Surge in zero-day vulnerability exploits is new normal, says Five Eyes

Thanks to today's episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker. ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team. To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

Get the stories behind the headlines at CISOSeries.com

View Details

Cyberattack cost Halliburton $35 million thus far

DDoS attack makes credit card readers malfunction in Israel

Debt relief firm Forth announces data breach for customers and non-customers

Thanks to today's episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker. ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team. To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

Get the stories behind the headlines at CISOSeries.com

View Details

U.S. financial regulator calls for reduced cell phone use at

FBI warns of spike in hacked police emails and fake subpoenas

Cyberscoundrels target UK senior citizens with Winter Fuel Payment texts

Thanks to today's episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker. ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team. To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

Get the stories behind the headlines at CISOSeries.com

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Ken Athanasiou, CISO, VF Corporation

Thanks to our show sponsor, Vanta

As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews.

Visit vanta.com to learn more about Questionnaire Automation.

All links and the video of this episode can be found on CISO Series.com

View Details

Interlock ransomware gang aims at U.S. healthcare, IT and government

Canada tells TikTok to dissolve its Canadian business

Hewlett Packard warns of critical RCE flaws in Aruba Networking software

Thanks to today's episode sponsor, Vanta

As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews.

Visit vanta.com to learn more about Questionnaire Automation.

Find the stories behind the headlines at CISOseries.com.

View Details

Nokia says it has no evidence that hackers breached company data

Nigerian cybercrime bust arrests 130 people

200,000 SelectBlinds customers impacted by e-skimmer

Thanks to today's episode sponsor, Vanta

As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews.

Visit vanta.com to learn more about Questionnaire Automation.

View Details

ElizaRAT hits India

IT outage impacts Washington courts

Alleged Snowflake hacker arrested

Thanks to today's episode sponsor, Vanta

As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews.

Visit vanta.com to learn more about Questionnaire Automation.

View Details

Schneider Electric breached for second time this year

U.S. says Russia behind fake Haitian voter video

Ohio’s capital city faces lawsuits for handling of ransomware attack

Thanks to today's episode sponsor, Vanta

As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews.

Visit vanta.com to learn more about Questionnaire Automation.

View Details

Microsoft Entra “security defaults” to make MFA setup mandatory

Ransomware attack hits German pharmaceutical wholesaler AEP

Upgraded LightSpy spyware targets iPhones with more destructive power

Thanks to today's episode sponsor, Vanta

As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews.

Visit vanta.com to learn more about Questionnaire Automation.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest David Cross, SVP/CISO, Oracle. Also check out David’s travel blog and recent “Secure by Default” white paper at IT ISAC.

Thanks to our show sponsor, Dropzone AI

Security operations are evolving, and AI is leading the way. Dropzone AI autonomously investigates 100% of your alerts with precision, freeing up your team to focus on real threats. See how this works in action. Visit dropzone.ai and schedule a demo today.

Add to Description: All links and the video of this episode can be found on CISO Series.com

View Details

Peruvian bank warns of data theft after dark web revelations

Windows 11 Task Manager displays wrong number of running processes

CyberPanel sees vulnerabilities exploited soon after disclosure

Thanks to today's episode sponsor, Dropzone AI

Security operations are evolving, and AI is leading the way. Dropzone AI autonomously investigates 100% of your alerts with precision, freeing up your team to focus on real threats. See how this works in action. Visit dropzone.ai and schedule a demo today.

Find the stories behind the headlines at CISOseries.com.

View Details

CISA launches International Cybersecurity Plan

North Korean hackers tied to Play ransomware

FakeCall learns new tricks

Thanks to today's episode sponsor, Dropzone AI

Tired of false positives slowing your SOC down? Dropzone AI uses advanced AI to filter out the noise and focus on real threats. 24/7, every alert, no manual intervention. Want to learn more? Schedule a demo and see the power of Dropzone AI at dropzone.ai.

View Details

Five Eyes launches startup security program

Canada and the Netherlands seeing increased Chinese activity

Russia might fork the Linux community

Thanks to today's episode sponsor, Dropzone AI

Facing alert overload? Dropzone AI autonomously investigates every alert, reducing noise and providing decision-ready reports. Discover how our AI solutions can enhance your SOC’s efficiency. Check out our demo gallery and see how Dropzone AI works at dropzone.ai.

View Details

Global law enforcement gains access to RedLine and Meta infostealer networks

Russian-backed malware poses as Ukrainian anti-recruitment tool

Massive breach impacts French telecom giant

Thanks to today's episode sponsor, Dropzone AI

Imagine an AI analyst that never sleeps. Dropzone AI autonomously handles every alert, cutting manual analysis by 90%. It's like adding a new team member, but one that works 24/7. Experience the difference AI can make. Visit dropzone.ai to test drive the future of security operations.

View Details

Change Healthcare data breach confirmed as largest-ever in U.S. healthcare history

Authorities investigate telecom hacks following reports of campaign intrusions

Delta sues CrowdStrike over sensor update that prompted mass flight disruptions

Thanks to today's episode sponsor, Dropzone AI

Is your SOC overwhelmed by endless alerts? Dropzone AI’s autonomous SOC Analyst investigates 100% of alerts, around the clock. No playbooks, no code. Just actionable insights to reduce false positives and save your team time. Ready to see it in action? Schedule a demo today at dropzone.ai.

View Details

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Dmitriy Sokolovskiy, senior vice president, information security, Semrush

Thanks to our show sponsor, SpyCloud

SpyCloud disrupts cybercrime by telling you what criminals know about your business, so you can take action on exposed identity data to prevent cyber attacks like ransomware. To learn more how to level the playing field against bad actors and combat cyber attacks, visit spycloud.com/headlines.

All links and the video of this episode can be found on CISO Series.com

View Details

Researchers reveal upgraded Qilin ransomware-as-a-service

CISA adds Microsoft SharePoint flaw to its KEV catalog

Rhysida ransoms Easterseals

Thanks to today's episode sponsor, SpyCloud

Ransomware continues to impact organizations. A new report released by SpyCloud shares insights from your peers in security – the majority of whom were affected by ransomware in the past year. The report has some fascinating industry-specific stats you’ll want to see – plus confirms some stark truths: that the industry you’re in can affect your likelihood of being hit with ransomware. Check it out at spycloud.com/headlines.

Find the stories behind the headlines at CISOseries.com.

View Details

CISA proposes new security requirements for personal data

Fortinet patches actively exploited zero-day

UK report on Cyber Essentials certification

Thanks to today's episode sponsor, SpyCloud

Stolen data is a hot commodity for cybercriminals. Using infostealer malware, bad actors can siphon valid session cookies from employee devices, scoring the keys to access your networks and systems. According to SpyCloud’s latest research, security teams are now seeing stolen cookies among the top three entry points for initial access for ransomware. Get the full insights, including other risk factors at spycloud.com/headlines.

View Details

Four cyber companies fined for SolarWinds disclosure failures

Zendesk helps Internet Archive after hacker breached email system

Samsung zero-day under active exploit

Thanks to today's episode sponsor, SpyCloud

Researchers at SpyCloud recently found that one in five individuals was infected with infostealer malware in the last year. Unfortunately, research now confirms that infostealer infections open the door to ransomware. But organizations with visibility into identity data stolen by malware infections are better-suited to prevent a future attack. Learn more about the connection between infostealers and ransomware in SpyCloud’s new report at spycloud.com/headlines.

View Details

Proposed rules ban U.S. companies from selling sensitive data

Cisco data stolen by IntelBroker

Nidec breach exposes 50,000+ documents

Thanks to today's episode sponsor, SpyCloud

Did you know that infostealer malware can be a precursor to ransomware? Infostealers are a trending tactic used by cybercriminals to exfiltrate valuable identity data like credentials, PII, and session cookies. According to recent SpyCloud research, 75% of organizations were affected by ransomware more than once in the past year! Visit spycloud.com/headlines to find out how to keep your organization from becoming one of the statistics.

View Details

Microsoft warns it lost some customers’ security logs for a month

Omni Family Health data breach impacts almost half a million individuals

Internet Archive breached again through stolen access tokens

Thanks to today's episode sponsor, SpyCloud

It turns out infostealer infections are a major contributing factor to a company’s ransomware risk, with some industries faring better than others. Get the new research from our sponsor, SpyCloud, and see if your ransomware defense strategy stacks up against your peers. Visit spycloud.com/headlines

Find the stories behind the headlines at CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Steve Person, CISO, Cambia Health

Thanks to our show sponsor, Conveyor

It’s spooky season, and nothing’s scarier than all of your account execs asking if you’re done with their customer security questionnaires. Don’t worry—Conveyor is here to help. Conveyor’s market leading AI automates the most time-consuming parts of customer security reviews: answering security questionnaires and sharing security docs like your SOC 2 with customers. Get instant AI answers to questionnaires and host an enterprise-grade trust center where customers can download documents and self-serve answers to their own questions. End the horror show. Try it for free at www.conveyor.com.

All links and the video of this episode can be found on CISO Series.com

View Details

Insurance giant Globe Life facing extortion attempts after data theft from subsidiary

Infamous hacker USDoD possibly arrested in Brazil

Anonymous Sudan masterminds indicted

Thanks to today’s episode sponsor, Conveyor

It’s spooky season, and nothing’s scarier than all of your account execs asking if you’re done with their customer security questionnaires. Don’t worry—Conveyor is here to help.

Conveyor’s market leading AI automates the most time-consuming parts of customer security reviews: answering security questionnaires and sharing security docs like your SOC 2 with customers.

Get instant AI answers to questionnaires and host an enterprise-grade trust center where customers can download documents and self-serve answers to their own questions.

End the horror show. Try it for free at www.conveyor.com.

Get the story behind the headlines at CISOSeries.com.

View Details

Putting AI models to the EU test

Chinese researchers don’t break classical encryption… yet

Chinese group calls for security reviews on all Intel products

Thanks to today’s episode sponsor, Conveyor

There’s so many reasons why infosec and presales teams choose Conveyor for automating their security reviews, but here are the main three:

One—Conveyor’s market-leading AI provides instant, accurate answers to any format of security questionnaire—without requiring constant knowledge base updates and maintenance.

Two—Conveyor offers an enterprise-grade trust center that automates every customer security review request, so you’re not constantly distracted with questions and SOC 2 requests.

And three—Conveyor’s sales team. They’re actually fun to work with.

Learn more at www.conveyor.com.

Get the story behind the headlines at CISOSeries.com.

View Details

VW says IT infrastructure unaffected after alleged data theft

Finland seizes servers of 'Sipultie' dark web market

Calgary Public Library services limited after cyberattack

Thanks to today’s episode sponsor, Conveyor

Does the thought of a whopper 300 question security questionnaire in your most dreaded portal give you nightmares?

Conveyor can help you sleep peacefully.

How? They are the market leaders in instant and accurate AI answers to any format of security questionnaire.

They even offer a zero-touch option for portal-based questionnaires—just paste the URL, and ConveyorAI automatically answers the questions and exports them back to the portal for you.

End the nightmares. Try it for free at www.conveyor.com.

Get the story behind the headlines at CISOSeries.com.

View Details

Pokémon game developer breached

TrickMo hits with 40 new trojan variants

Nation-state actor exploits Ivanti zero-days

Thanks to today’s episode sponsor, Conveyor

It’s spooky season, and nothing’s scarier than all of your account execs asking if you’re done with their customer security questionnaires. Don’t worry—Conveyor is here to help.

Conveyor’s market leading AI automates the most time-consuming parts of customer security reviews: answering security questionnaires and sharing security docs like your SOC 2 with customers.

Get instant AI answers to questionnaires and host an enterprise-grade trust center where customers can download documents and self-serve answers to their own questions.

End the horror show. Try it for free at www.conveyor.com.

Get the story behind the headlines at CISOSeries.com.

View Details

Iranian hackers exploit Windows flaw to elevate privileges

Microsoft deprecates PPTP and L2TP VPN protocols in Windows Server

NATO’s ‘most experienced expert on cyber rotated out of cyber section

Thanks to today’s episode sponsor, Conveyor

What’s the ultimate jumpscare?

That moment when the security questionnaire in the portal didn’t auto-save all your work.

Good news: with Conveyor, that’s one horror you won’t have to face.

Conveyor is the market leader in instant, generative AI answers for security questionnaires, no matter the format.

They even offer a zero-touch option for portal-based questionnaires where you can just paste the URL, and the AI automatically answers the questions and exports them back to the portal for you.

Don't let security questionnaires haunt your workflow. Learn more at www.conveyor.com.

Get the story behind the headlines at CISOSeries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Quincy Castro, CISO, Redis.

Thanks to our show sponsor, Vanta

As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews. Visit vanta.com to learn more about Questionnaire Automation.

All links and the video of this episode can be found on CISO Series.com

View Details

White House prioritizes secure internet routing, using memory safe languages

Federal Trade Commission and CISA warn of hurricane-related scams

Mozilla warns of Firefox zero day: patch now

Huge thanks to our sponsor, Vanta

As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews. Visit vanta.com to learn more about Questionnaire Automation.

For the stories behind the headlines, head on over to CISOSeries.com

View Details

Australian Parliament introduces standalone cybersecurity law

Qualcomm zero-day used to target Android devices

Russia and Turkey ban Discord

Huge thanks to our sponsor, Vanta

As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews. Visit vanta.com to learn more about Questionnaire Automation.

For the stories behind the headlines, head on over to CISOSeries.com

View Details

GoldenJackal uses new tools against governments

Cross-site scripting flaw found in major WordPress plugin

Ukraine’s defense ministry launched military CERT

Huge thanks to our sponsor, Vanta

As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews. Visit vanta.com to learn more about Questionnaire Automation.

For the stories behind the headlines, head on over to CISOSeries.com

View Details

Salt Typhoon attack potentially exposes wiretap data

Cyberattack hits major U.S. water utility

A not- so- happy birthday present for Russia’s president

Huge thanks to our sponsor, Vanta

As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews. Visit vanta.com to learn more about Questionnaire Automation.

For the stories behind the headlines, head on over to CISOSeries.com

View Details

Insurers should stop funding ransomware payments, says Neuberger

Google removes Kaspersky antivirus software from Play Store

Cyberattack hits Detroit-area government services

Huge thanks to our sponsor, Vanta

As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews. With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs. Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews. Visit vanta.com to learn more about Questionnaire Automation.

For the stories behind the headlines, head on over to CISOSeries.com

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Jonathan Waldrop, CISO, The Weather Company. Here’s a link to CISA’s Cybersecurity Awareness Month announcement, sent to us by Jonathan.

Thanks to our show sponsor, SpyCloud

SpyCloud disrupts cybercrime by telling you what criminals know about your business, so you can take action on exposed identity data to prevent cyber attacks like ransomware. To learn more how to level the playing field against bad actors and combat cyber attacks, visit spycloud.com/headlines.

All links and the video of this episode can be found on CISO Series.com

View Details

Cloudflare blocks largest recorded DDoS attack

Adobe Commerce and Magento stores compromised by CosmicSting bug

DOJ and Microsoft take down 107 domains used in Star Blizzard phishing attacks

Huge thanks to our sponsor, SpyCloud

Ransomware continues to impact organizations. A new report released by SpyCloud shares insights from your peers in security – the majority of whom were affected by ransomware in the past year. The report has some fascinating industry-specific stats you’ll want to see – plus confirms some stark truths: that the industry you’re in can affect your likelihood of being hit with ransomware. Check it out at spycloud.com/headlines.

Get the story behind the headlines at CISOSeries.com

View Details

Russian authorities arrest nearly 100 cybercriminals in raid

Northern Ireland police fined for exposing officer identities

Rackspace breach sparks vendor blame game

Huge thanks to our sponsor, SpyCloud

Stolen data is a hot commodity for cybercriminals. Using infostealer malware, bad actors can siphon valid session cookies from employee devices, scoring the keys to access your networks and systems. According to SpyCloud’s latest research, security teams are now seeing stolen cookies among the top three entry points for initial access for ransomware. Get the full insights, including other risk factors at spycloud.com/headlines.

Get the story behind the headlines at CISOSeries.com

View Details

UK ties LockBit affiliate to Evil Corp

Public records systems riddled with security flaws

Ransomware disrupts emergency services at Texas hospital

Huge thanks to our sponsor, SpyCloud

Researchers at SpyCloud recently found that one in five individuals was infected with infostealer malware in the last year. Unfortunately, research now confirms that infostealer infections open the door to ransomware. But organizations with visibility into identity data stolen by malware infections are better-suited to prevent a future attack. Learn more about the connection between infostealers and ransomware in SpyCloud’s new report at spycloud.com/headlines.

Get the story behind the headlines at CISOSeries.com

View Details

T-Mobile data breaches cost company $31.5 million

Iranian hackers charged for targeting 2024 U.S. election

Deepfake scam hits U.S. senate

Huge thanks to our sponsor, SpyCloud

Did you know that infostealer malware can be a precursor to ransomware? Infostealers are a trending tactic used by cybercriminals to exfiltrate valuable identity data like credentials, PII, and session cookies. According to recent SpyCloud research, 75% of organizations were affected by ransomware more than once in the past year! Visit spycloud.com/headlines to find out how to keep your organization from becoming one of the statistics.

Get the story behind the headlines at CISOSeries.com

View Details

Recall redesign: reinforced and removable

Embargo moves ransomware attacks to cloud environments

Dallas suburb deals with ransomware attack

Huge thanks to our sponsor, SpyCloud

It turns out infostealer infections are a major contributing factor to a company’s ransomware risk, with some industries faring better than others. Get the new research from our sponsor, SpyCloud, and see if your ransomware defense strategy stacks up against your peers. Visit spycloud.com/headlines

Get the story behind the headlines at CISOSeries.com

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Jason Elrod, CISO, Multicare Health System

Missed the live show? Watch it on YouTube. And make sure to check out Jason’s book (coming soon) at CyberCISOmarksmanship.com, as well as his newsletter at LimitlessCyber.com.

And huge thanks to our sponsor – Vanta As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews.

With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs.

Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews.

Visit vanta.com to learn more about Questionnaire Automation.

All links and the video of this episode can be found on CISO Series.com

View Details

Public Wi-Fi hacked at some of the UK’s busiest train stations

Data privacy watchdog files complaint against Mozilla for ad tracking feature

NIST drops password complexity, mandatory reset rules

Thanks to today's episode sponsor, Vanta

As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews.

With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs.

Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews.

Visit vanta.com to learn more about Questionnaire Automation.

Find the stories behind the headlines at CISOseries.com.

View Details

DragonForce uses ransomware’s greatest hits

Salt Typhoon strikes US ISPs

Finding SpAIware on the ChatGPT Mac app

Thanks to today's episode sponsor, Vanta

As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews.

With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs.

Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews.

Visit vanta.com to learn more about Questionnaire Automation.

View Details

Kansas water plant pivots to analog after cyber event

CrowdStrike exec apologizes in Congress for global IT outage

MoneyGram goes offline after cyber incident

Thanks to today's episode sponsor, Vanta

As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews.

With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs.

Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews.

Visit vanta.com to learn more about Questionnaire Automation.

For the stories behind the headlines, visit CISOseries.com

View Details

U.S. proposes ban on Chinese, Russian tech in autonomous vehicles

Telegram updates policies to expose ‘bad actors’

Necro Trojan infects 11 million android devices through Google Play apps

Thanks to today's episode sponsor, Vanta

As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews.

With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs.

Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews.

Visit vanta.com to learn more about Questionnaire Automation.

View Details

LinkedIn halts AI data processing in UK due to privacy concerns, Ukraine bans Telegram Use for government and military, Dismissed German cyber chief falsely accused of associating with Russian spies

Thanks to today's episode sponsor, Vanta

As third-party breaches continue to rise, companies are increasingly vigilant, which means more time spent on manual security reviews.

With Vanta Questionnaire Automation, security & compliance teams can complete security reviews up to 5 times faster, giving you time back to focus on running your security & compliance programs.

Over 8,000 global companies like ZoomInfo, SmartRecruiters and Noibu use Vanta to save time on security reviews.

Visit vanta.com to learn more about Questionnaire Automation.

Find the stories behind the headlines at CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Mike Rosen, CISO, ZwillGen, advisor to NightDragon and Villager at Team8, whose favorite story of the week was Starlink’s ability to detect stealth aircraft. Check it out.

Thanks to our show sponsor, Conveyor

Why do teams choose Conveyor over the competition for customer security reviews?

A few reasons.

One. Market-leading AI accuracy for any format of security questionnaire with limited knowledge base maintenance.Two. Enterprise-grade trust center that automates every customer security request.Three. Conveyor’s sales team is actually fun to work with.

Learn why Conveyor is the security review platform your infosec friends love at www.conveyor.com

All links and the video of this episode can be found on CISO Series.com

View Details

New INC ransomware targets U.S. healthcare sector

Providence public schools deal with irregular internet activity

Apple pulls iPadOS 18 update that was bricking M4 iPad Pro devices

Thanks to today's episode sponsor, Conveyor

It’s Friday and Conveyor hopes you don’t have a meaty security questionnaire waiting for you on the other side of this podcast. If you do, you should check them out.

As the market-leader in instant, generative AI answers to entire security questionnaires, Conveyor helps you complete questionnaires fast, no matter the format they’re in, so you don’t feel like you’re getting crushed by the wave of unfinished work.

Learn why we’re the software your infosec friends love at www.conveyor.com.

Get the story behind the headlines at CISOSeries.com.

View Details

Feds derail Raptor Train

Newmark creates Volunteer Network for Civil Cyber Defense

US to host global AI safety summit

Thanks to today's episode sponsor, Conveyor

Does the next security questionnaire that hits your inbox make you want to throw your laptop out the window? If so, don’t do it. You should check out Conveyor first.

Conveyor is the market-leader in instant, generative AI answers to entire security questionnaires no matter the format they are in.

Yes, that’s right. Upload any file like excels, word docs and even PDFs for instant processing and tackle any portal-based questionnaire with a browser extension that auto-scrolls and fills in answers for you.

Try a free proof of concept today at www.conveyor.com.

Get the story behind the headlines at CISOSeries.com.

View Details

Exploding pager tragedy experts look towards supply chain sabotage

Construction companies potentially vulnerable through accounting software

Cyberattacks result in job losses

Thanks to today's episode sponsor, Conveyor

Are customer security reviews constantly interrupting your day? You should check out Conveyor.

With an enterprise-grade trust center to securely share your security posture, SOC 2, and security FAQs and security questionnaires and market-leading AI accuracy for instant security questionnaire answers, you’ll fly through any customer security request and get back to your regular job.

Learn more about the AI security review automation platform your infosec friends love at www.conveyor.com. Mention this podcast for 5 free questionnaire credits when you purchase a Pro plan.

Get the story behind the headlines at CISOSeries.com.

View Details

Spyware giant Intellexa faces new U.S. sanctions

Nearly 1 million impacted by ransomware attack on London hospitals

Apple releases long-awaited update

Thanks to today's episode sponsor, Conveyor

Why do teams choose Conveyor over the competition for customer security reviews?

A few reasons.

One. Market-leading AI accuracy for any format of security questionnaire with limited knowledge base maintenance.

Two. Enterprise-grade trust center that automates every customer security request.

Three. Conveyor’s sales team is actually fun to work with.

Learn why Conveyor is the security review platform your infosec friends love at www.conveyor.com

Get the story behind the headlines at CISOSeries.com.

View Details

Fortinet confirms customer data breach

RansomHub threatens to leak stolen Kawasaki data

Update: Transport for London requires in-person password resets after hack

Thanks to today's episode sponsor, Conveyor

Ever feel like completing security questionnaires has become your full time side hustle you’re not even getting paid extra for? If so, you should check out Conveyor. Conveyor is the market-leader in instant, generative AI answers to entire security questionnaires no matter the format they are in. Yes, that’s right. Upload any file like excels, word docs and even PDFs for instant processing and tackle any portal-based questionnaire with a browser extension that auto-scrolls and fills in answers for you.

Try a free proof of concept today at www.conveyor.com.

Get the story behind the headlines at CISOSeries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by David Spark with guest Patrick Heim, co-founder and partner, SYN Ventures

Huge thanks to our sponsor, Vanta

Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at vanta.com/headlines.

All links and the video of this episode can be found on CISO Series.com

View Details

Lazarus Group’s VMConnect campaign spoofs CapitalOne

Mastercard buys security firm Recorded Future

WordPress to require two-factor authentication for plugin developers

Huge thanks to our sponsor, Vanta

Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines. That’s vanta.com/headlines.

Get the story behind the headlines at CISOSeries.com

View Details

The $20 WHOIS vulnerability

India training thousands of “cyber commandos”

A Word of warnings for Taiwanese drone makers

Huge thanks to our sponsor, Vanta

When it comes to ensuring your company has top-notch security practices, things can get complicated, fast. Vanta automates compliance for SOC 2, ISO 27001, and more, saving you time and money. With Vanta, you can unify your security program management and proactively manage security reviews with AI-powered security questionnaires.Our listeners get $1,000 off at vanta.com/headlines. That’s vanta.com/headlines.

Get the story behind the headlines at CISOSeries.com

View Details

Slim CD notifies 1.7M customers of data breach

Delaware men charged in international sextortion scheme

London transit agency drops claim it has ‘no evidence’ of customer data theft

Huge thanks to our sponsor, Vanta

Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines. That’s vanta.com/headlines.

Get the story behind the headlines at CISOSeries.com

View Details

1.7 million impacted in payment processing breach

Dark web administrators charged in U.S.

Resurgence of Predator Spyware sparks privacy concerns

Huge thanks to our sponsor, Vanta

When it comes to ensuring your company has top-notch security practices, things can get complicated, fast. Vanta automates compliance for SOC 2, ISO 27001, and more, saving you time and money. With Vanta, you can unify your security program management and proactively manage security reviews with AI-powered security questionnaires.Our listeners get $1,000 off at vanta.com/headlines. That’s vanta.com/headlines.

Get the story behind the headlines at CISOSeries.com

View Details

Car rental company Avis discloses data breach

Microsoft Office 2024 to disable ActiveX controls by default

Wisconsin Medicare users had information leaked in MOVEit breach

Huge thanks to our sponsor, Vanta

Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines.

Get the story behind the headlines at CISOSeries.com

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Justin Somaini, partner, YL Ventures

Thanks to our show sponsor, Scrut Automation

Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.

All links and the video of this episode can be found on CISO Series.com

View Details

Planned Parenthood suffers cyberattack

DoJ propaganda domains takedown

Microchip Technology confirms data theft

Thanks to today's episode sponsor, Scrut Automation

Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.

Find the stories behind the headlines at CISOseries.com.

View Details

Spyware research report

They found a way to make Cicadas more annoying

MacroPack red teaming tool used for malware

Thanks to today's episode sponsor, Scrut Automation

Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.

View Details

Halliburton confirms data stolen in cyberattack

City of Columbus sues researcher after ransomware attack

White House publishes plan to protect a key component of the internet

Thanks to today's episode sponsor, Scrut Automation

Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.

For the stories behind the headlines, visit CISOseries.com.

View Details

Transport for London suffers cyberattack

German air traffic control agency confirms cyberattack

Sweden warns of heightened risk of Russian sabotage

Thanks to today's episode sponsor, Scrut Automation

Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.

Find the stories behind the headlines at CISOseries.com

View Details

Seattle Airport issues travelers’ advisory for Labor Day travel

SQL injection able to bypass airport TSA security checks

North Korea uses FudModule Rootkit in Chrome zero-day exploit

Thanks to today's episode sponsor, Scrut Automation

Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.

Find the stories behind the headlines at CISOseries.com.

View Details

DICK’S Sporting Goods suffers cyberattack

Brain Cipher claims attack on Paris museums, promises data leak

Play ransomware hackers claim attack on Microchip Technology

Thanks to today's episode sponsor, Scrut Automation

Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.

Find the stories behind the headlines at CISOSeries.com

View Details

Iran targeting presidential administration officials

Iran working with ransomware gangs

UK Labour Party chided over cyberattack backlog

Thanks to today's episode sponsor, Scrut Automation

Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.

Find the stories behind the headlines at CISOSeries.com

View Details

Texas credit union user data exposed in another MOVEit breach

US Marshals Service disputes ransomware gang's breach claims

Park’N Fly notifies 1 million customers of data breach

Thanks to today's episode sponsor, Scrut Automation

Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.

Find the stories behind the headlines at CISOSeries.com

View Details

SonicWall warns of critical access control flaw

Microsoft to host security summit

More details on Telegram CEO’s arrest

Thanks to today's episode sponsor, Scrut Automation

Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.

Find the stories behind the headlines at CISOSeries.com

View Details

Halliburton takes systems offline following cyberattack

French police arrest Telegram CEO Pavel Durov

DOJ joins suit against Georgia Tech over Defense Department cybersecurity failures

Thanks to today's episode sponsor, Scrut Automation

Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Their best-in-class features like process automation, AI, and over 75 native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit scrut.io to schedule a demo or learn more. That’s www.scrut.io.

Find the stories behind the headlines at CISOSeries.com

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Bethany De Lude, CISO, The Carlyle Group

Thanks to today’s episode sponsor, Nudge Security

When your CEO asks “Hey, are we using that SaaS app that was just breached?”, how quickly and confidently can you answer? Stop guessing with Nudge Security. Discover all SaaS accounts ever introduced by anyone in your org, in minutes and get alerted when any SaaS app used in your org is breached. Start a 14-day trial now at nudgesecurity.com/saas

All links and the video of this episode can be found on CISO Series.com

View Details

Kremlin complains of DDoS attack, digital experts not so sure

FAA proposes new cybersecurity rules for airplanes

Windows Recall to reappear

Thanks to today’s episode sponsor, Nudge Security

Do you know who’s using genAI tools in your org? Find out today with Nudge Security. Their patented approach to SaaS discovery gives you a full inventory of all apps ever introduced by anyone in your org, in minutes, including genAI apps. And, automated workflows help you scale security and governance without breaking a sweat. Start a free trial today at nudgesecurity.com/genai

For the stories behind the headlines, head to CISOseries.com.

View Details

Security initiative from Japanese auto companies

Feds tapping into encrypted messaging haul

Microsoft breaks Linux dual-boot systems

Thanks to today’s episode sponsor, Nudge Security

How big is your SaaS attack surface? Find out today with Nudge Security. Nudge Security discovers all SaaS accounts ever created by anyone in your org, in minutes, and gives you automated workflows to scale SaaS security and governance. Take control of your SaaS security posture. Start a free trial today at nudgesecurity.com/cisoseries

View Details

Toyota confirms third-party data breach impacting customers

Man who hacked Hawaii state registry sentenced

U.S. Intelligence blames Iran for Trump campaign hack

Thanks to today’s episode sponsor, Nudge Security

When your CEO asks “Hey, are we using that SaaS app that was just breached?”, how quickly and confidently can you answer? Stop guessing with Nudge Security. Discover all SaaS accounts ever introduced by anyone in your org, in minutes and get alerted when any SaaS app used in your org is breached. Start a 14-day trial now at nudgesecurity.com/saas

For the stories behind the headlines, visit CISOseries.com.

View Details

‘Only’ 1.3 million affected by National Public Data Breach

Flaws in Microsoft macOS Apps allowing secret recording

Configuration issue exposes flight tracking site

Thanks to today’s episode sponsor, Nudge Security

Do you know who’s using genAI tools in your org? Find out today with Nudge Security. Their patented approach to SaaS discovery gives you a full inventory of all apps ever introduced by anyone in your org, in minutes, including genAI apps. And, automated workflows help you scale security and governance without breaking a sweat. Start a free trial today at nudgesecurity.com/genai

View Details

Microsoft Entra admins must enable MFA or lose access to admin portals

Cybercrime gang uses fake Windows update screen to hide data theft

Google Pixel devices shipped with vulnerable Verizon app

Thanks to today’s episode sponsor, Nudge Security

How big is your SaaS attack surface? Find out today with Nudge Security. Nudge Security discovers all SaaS accounts ever created by anyone in your org, in minutes, and gives you automated workflows to scale SaaS security and governance. Take control of your SaaS security posture. Start a free trial today at nudgesecurity.com/cisoseries

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Edwin Covert, head of cyber risk engineering, Bowhead Specialty Underwriters and edwincovert.com

Thanks to our show sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker. ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team. To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

All links and the video of this episode can be found on CISO Series.com

View Details

GitHub vulnerability warning regarding ArtiPacked

RansomHub affiliate launches new EDR-killing tool

SolarWinds issues hotfix for web help desk vulnerability

Thanks to today's episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Google details privacy commitments with Gemini AI

MIT releases AI Risk Repository

Russian spies using highly targeted phishing

Thanks to today's episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

View Details

FBI shutters Radar ransomware gangs servers

NIST finalizes post-quantum encryption standards

2.7 billion National Public Data records leaked

Thanks to today's episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

For the stories behind the headlines, visit CISOseries.com.

View Details

U.S. operation of “laptop farm” for North Korea shutdown

Over 100 Ukrainian government computers compromised

Trump campaign says they were hacked

Thanks to today's episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

View Details

Iranian hackers ramping up U.S. election interference

AMD SinkClose flaw helps install nearly undetectable malware

ADT discloses breach that impacts more than 30,000 customers demands

Thanks to today's episode sponsor, ThreatLocker

Do zero-day exploits and supply chain attacks keep you up at night? Worry no more; you can harden your security with ThreatLocker.

ThreatLocker helps you take a proactive, default-deny approach to cybersecurity and provides a full audit of every action, allowed or blocked, for risk management and compliance. Onboarding and operation are fully supported by their US-based support team.

To learn more about how ThreatLocker can help keep your organization running efficiently and protected from ransomware, visit ThreatLocker.com.

For the stories behind the headlines, head to CISOseries.com

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest DJ Schleen, distinguished security architect, Yahoo

Thanks to our show sponsor, Vanta

Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines. That’s vanta.com/headlines.

All links and the video of this episode can be found on CISO Series.com

View Details

Chameleon reappears targeting Canadian restaurant chain

Rhysida claims attack on Bayhealth Hospital in Delaware

BlackSuit/Royal achieves $500m in ransomware demands

Huge thanks to our sponsor, Vanta

Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines. That’s vanta.com/headlines.

For the stories behind the headlines, head to CISOseries.com.

View Details

McLaren hospitals disruption linked to INC ransomware attack

CrowdStrike to give customers control over Falcon sensor updates

Ronin Network hacked by "white hats"

Huge thanks to our sponsor, Vanta

When it comes to ensuring your company has top-notch security practices, things can get complicated, fast. Vanta automates compliance for SOC 2, ISO 27001, and more, saving you time and money. With Vanta, you can unify your security program management and proactively manage security reviews with AI-powered security questionnaires.Our listeners get $1,000 off at vanta.com/headlines. That’s vanta.com/headlines

View Details

Google patches Android kernel zero-day

Researchers find flaws in Georgia voter portal

Law would make ransomware a terrorist threat

Huge thanks to our sponsor, Vanta

Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines. That’s vanta.com/headlines.

View Details

CrowdStrike strikes back against Delta’s claims of negligence

Ransomware attack costs Keytronic $17 million

Patch required for high-severity flaw in Apache OFBiz

Huge thanks to our sponsor, Vanta

When it comes to ensuring your company has top-notch security practices, things can get complicated, fast. Vanta automates compliance for SOC 2, ISO 27001, and more, saving you time and money. With Vanta, you can unify your security program management and proactively manage security reviews with AI-powered security questionnaires.Our listeners get $1,000 off at vanta.com/headlines. That’s vanta.com/headlines

View Details

Hackers use ISP to send malware through software updates

CrowdStrike sued by investors following update failure

Historic prisoner swap includes cybercriminals returned to Russia

Huge thanks to our sponsor, Vanta

Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines. That’s vanta.com/headlines.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Dennis Pickett, vp, CISO, Westat

Thanks to our show sponsor, Dropzone AI

Dropzone AI’s Analyst investigates alerts with unmatched speed and precision, providing clear, actionable reports. Experience the power of autonomous threat detection. Meet Dropzone AI at BSides Las Vegas. Visit dropzone.ai for a 3-month free trial.

All links and the video of this episode can be found on CISO Series.com

View Details

Cencora confirms patient data stolen in February cyberattack

Phishing campaign targets OneDrive users

Argentina will use AI to predict future crimes

Huge thanks to our sponsor, Dropzone AI

Picture an analyst who works tirelessly around the clock. Dropzone AI’s Analyst investigates every alert and provides comprehensive, actionable reports. Boost your SOC’s capabilities with a 3-month free trial at dropzone.ai.

For the stories behind the headlines, head to CISOseries.com

View Details

DDoS attacks won’t impact US elections

Dating apps leaked precise location data

Germany formally blames China for 2021 cyberattack

Huge thanks to our sponsor, Dropzone AI

Think of Alex, your new team member who never takes a break. Dropzone AI’s Analyst investigates every alert and delivers detailed reports without playbooks or code. Experience Alex’s dedication with a 3-month free trial at dropzone.ai.

View Details

Delta enlists Microsoft's legal nemesis over CrowdStrike losses

Dark Angels receives record-breaking ransom payment

Meta to pay $1.4 billion biometric lawsuit

Huge thanks to our sponsor, Dropzone AI

Dropzone AI’s Analyst investigates alerts and responds to threats with unmatched speed and precision. No playbooks, no code required. Transform your SOC’s performance with a 3-month free trial at dropzone.ai.

For the stories behind the headlines, head to CISOseries.com.

View Details

4.3 million impacted by HealthEquity data breach

Microsoft admits CrowdStrike incident far greater than first reported

Proofpoint exploit allows for millions of fake emails

Huge thanks to our sponsor, Dropzone AI

Imagine an analyst who never misses an alert. Dropzone AI autonomously investigates every alert and provides decision-ready reports, enhancing your SOC’s efficiency. Try it free for 3 months at dropzone.ai.

View Details

Hackers exploiting PyPi package targets MacOS

Columbus, Ohio suffers cyber incident

Windows July updates come with some BitLocker and remote connectivity challenges

Huge thanks to our sponsor, Dropzone AI

Meet Dropzone AI, the analyst who never rests. Investigating every alert with unparalleled speed and precision, delivering clear, actionable reports. No playbooks, no code. Experience the power of AI with a 3-month free trial at dropzone.ai.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Jana Moore, CISO, Belron, also vice president, EmpoWer – Supporting women in infosec.

Thanks to our show sponsor, Vanta

When it comes to ensuring your company has top-notch security practices, things can get complicated, fast. Vanta automates compliance for SOC 2, ISO 27001, and more, saving you time and money. With Vanta, you can unify your security program management and proactively manage security reviews with AI-powered security questionnaires. Our listeners get $1,000 off at Vanta dot com/headlines.

All links and the video of this episode can be found on CISO Series.com

View Details

Hackers exploiting Microsoft Defender SmartScreen bug

IT leaders note increase in severity of cyber-attacks, ransomware and BEC stand out,

Trump shooting investigation revives the end-to-end encryption issue

Huge thanks to our sponsor, Vanta

Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines.

For the stories behind the headlines, head to CISOseries.com

View Details

CrowdStrike dishes details

Google scuttles third-party cookie deprecation

BreachForums leaked on Telegram

Huge thanks to our sponsor, Vanta

When it comes to ensuring your company has top-notch security practices, things can get complicated, fast. Vanta automates compliance for SOC 2, ISO 27001, and more, saving you time and money. With Vanta, you can unify your security program management and proactively manage security reviews with AI-powered security questionnaires. Our listeners get $1,000 off at vanta.com/headlines.

View Details

Google’s $23 billion plan to buy Wiz falls apart

U.S. government looking for answers amidst CrowdStrike aftermath

dYdX exchange hacked in DNS hijack attack

Thanks to our episode sponsor, Vanta

Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines.

For the stories behind the headlines, visit CISOseries.com.

View Details

CrowdStrike says “significant number” back up and running

Russian cyber criminals sanctioned for infrastructure attacks

Ransomware attack shuts down largest trial court in U.S.

Huge thanks to our sponsor, Vanta

When it comes to ensuring your company has top-notch security practices, things can get complicated, fast. Vanta automates compliance for SOC 2, ISO 27001, and more, saving you time and money. With Vanta, you can unify your security program management and proactively manage security reviews with AI-powered security questionnaires. Our listeners get $1,000 off at vanta.com/headlines.

View Details

Microsoft confirms CrowdStrike update also hit cloud Windows PCs

Cybercriminals exploit CrowdStrike problem to distribute malware

CISA adds some big names to its KEV catalog

Huge thanks to our sponsor, Vanta

Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post – get exact one from https://cisoseries.com

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Adam Arellano, former vp, enterprise cybersecurity, PayPal

Thanks to our show sponsor, Conveyor

Why do teams choose Conveyor over the competition to automate answering security questionnaires? A few reasons. One. Market-leading AI accuracy Two. They don’t have to maintain a crazy knowledge base anymore because ConveyorAI can read from any source like external support sites, documents, past questionnaires and more. Three. It can process ANY customer file format – even PDFs! It will even auto-scroll and auto-complete portal-basedl questionnaires. Don’t believe it? Try it yourself for free at www.conveyor.com.

All links and the video of this episode can be found on CISO Series.com

View Details

FIN7 sells security evasion tool to others via darknet

UK national blood stocks suffer the effects of ransomware

Security flaws in SAP AI Core cloud-based platform

Thanks to today's episode sponsor, Conveyor

It’s Friday and Conveyor hopes you don’t have a meaty security questionnaire waiting for you on the other side of this podcast. If you do, you should check them out. As the market leader in instant, generative AI answers to entire security questionnaires, Conveyor helps you complete questionnaires fast, no matter the format they’re in, so you don’t feel like you’re getting crushed by the wave of unfinished work. Learn why we’re the software your infosec friends love at www.conveyor.com

For the stories behind the headlines, head to CISOseries.com

View Details

UK mandatory ransomware reporting gets watered-down

Google introduces AI agent to look for software bugs

Critical infrastructure ransomware costs spike

Thanks to today's episode sponsor, Conveyor

Does the anticipation of the next monster security questionnaire wrecking your day ever make you feel like a balloon floating above a cactus field? If so, you should check out Conveyor. Conveyor is the market-leader in instant, generative AI answers to entire security questionnaires no matter the format they are in. Yes, that’s right. Upload any file like Excel, Word docs and even PDFs for instant processing and tackle any portal-based questionnaire with a browser extension that auto-scrolls and fills in answers for you. Try a free proof of concept today at www.conveyor.com.

Yesteryears (DECISION) by Sascha Ende Free download: https://filmmusic.io/song/244-yesteryears-decision License (CC BY 4.0): https://filmmusic.io/standard-license

View Details

Rite Aid says 'limited’ cybersecurity incident affected over 2 million people

AT&T ransom laundered through mixers and gambling services

Hacktivists leak Disney data to protect artist rights

Thanks to today's episode sponsor, Conveyor

Why do teams choose Conveyor over the competition to automate answering security questionnaires? A few reasons. One. Market-leading AI accuracy Two. They don’t have to maintain a crazy knowledge base anymore because ConveyorAI can read from any source like external support sites, documents, past questionnaires and more. Three. It can process ANY customer file format - even PDFs! It will even auto-scroll and auto-complete portal-based questionnaires. Don’t believe it? Try it yourself for free at www.conveyor.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Alphabet in talks to acquire Wiz

AT&T allegedly paid hacker to delete data

Details on Squarespace domain hacks

Thanks to today's episode sponsor, Conveyor

Does the mountain of security questionnaires in your inbox make you feel like you're in a rowboat trying to make it through a tsunami? If so, you should check out Conveyor. As the market leader in instant, generative AI answers to entire security questionnaires, Conveyor helps you complete them fast, no matter the format they’re in, and never feel like you’re getting crushed by the wave of unfinished work. Learn more about the AI security review automation platform your infosec friends love at www.conveyor.com. Mention this podcast for 5 free questionnaire credits when you purchase a Pro plan.

View Details

Rite Aid announces data breach following June cyberattack

The personal security implications of the AT&T breach

US offers support to prevent Paris Olympics cyber and disinformation attacks

Thanks to today's episode sponsor, Conveyor

Ever feel like completing security questionnaires has become your full-time side hustle you’re not even getting paid extra for? If so, you should check out Conveyor. Conveyor is the market leader in instant, generative AI answers to entire security questionnaires no matter the format they are in. Yes, that’s right. Upload any file like Excel, Word docs and even PDFs for instant processing and tackle any portal-based questionnaire with a browser extension that auto-scrolls and fills in answers for you. Try a free proof of concept today at www.conveyor.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Andrew Cannata, CISO, Primo Water

Thanks to our show sponsor, Entro Security

What are you doing to secure your company’s non-human identities? Vaults and scanners are helpful, but they don’t give the context for where your secrets are, how they’re being used, or when it’s time to remove or rotate them. The entro platform provides automated lifecycle management and seamless integration, ensuring comprehensive security & compliance through a unified and easy to use interface.

All links and the video of this episode can be found on CISO Series.com

View Details

PHP vulnerability exploited, spreading malware and DDoS attacks

Advance Auto Parts reveals damage from Snowflake breach

FTC report reveals dark patterns used to trick consumers

Thanks to today's episode sponsor, Entro

Reclaim control over your Non-human identities! Entro enables security teams to manage and secure the lifecycle of non-human identities and secrets from inception to rotation. Think of it like an airtag for your secrets - know where they are, how they’re being used, and their risk level in one seamless platform. Visit https://entro.security/ to learn more.

For the stories behind the headlines, head to CISOseries.com.

View Details

Australia targets government tech under foreign control

Singapore banks replace OTP with digital tokens

New group targets Veeam vulnerability

Thanks to today's episode sponsor, Entro

What are you doing to secure your company’s non-human identities? Vaults and scanners are helpful, but they don’t give the context for where your secrets are, how they’re being used, or when it’s time to remove or rotate them. The entro platform provides automated lifecycle management and seamless integration, ensuring comprehensive security & compliance through a unified and easy to use interface. Visit https://entro.security/ to learn more.

View Details

US disrupts Russian AI-powered disinformation bot farm

Senate takes aim at ‘overly burdensome’ cybersecurity regs

Fujitsu confirms customer data exposed in cyberattack

Thanks to today's episode sponsor, Entro

Reclaim control over your Non-human identities! With Entro, security teams can now manage and secure the lifecycle of Non-human identities and secrets. Like an air tag for your non-human identities, The entro platform provides automated lifecycle management and seamless integration, ensuring comprehensive security & compliance through a unified and easy to use interface. Visit https://entro.security/ to learn more.

For the stories behind the headlines, visit CISOseries.com.

View Details

Record-breaking 10 billion stolen passwords exposed

Supreme court ruling makes cybersecurity regulations even trickier

Apple removes popular apps at Russia’s request

Thanks to today's episode sponsor, Entro

Did you know that an attack on non-human identities and secrets is one of the top 2 cyber attack vectors out there ? With Entro, security teams can now manage and secure the lifecycle of Non-human identities and secrets. The entro platform provides automated lifecycle management and seamless integration, ensuring comprehensive security & compliance through a unified and easy to use interface. Visit https://entro.security/ to learn more.

View Details

Alabama Department of Education suffers data breach

New York Times claims hackers stole OpenAI secrets in a 2023 security breach

RansomHub claims to have published Florida health department data

Thanks to today's episode sponsor, Entro

Reclaim control over your Non-human identities! Entro enables security teams to manage and secure the lifecycle of non-human identities and secrets from inception to rotation. Think of it like an airtag for your secrets - know where they are, how they’re being used, and their risk level in one seamless platform. Visit https://entro.security/ to learn more.

For the stories behind the headlines, head to CISOseries.com.

View Details

Senate leader demands answers from CISA re March Ivanti hack

China’s Velvet Ant hackers exploiting new Cisco zero-day

Europol law enforcement takes down Cobalt Strike servers

Huge thanks to our sponsor, Demoed

Buyers do 70% of their product research before talking to a company. That blew our minds. Why not give buyers as much information about your product as possible to help them decide? Eliminating friction has always been key to a solid sales strategy. With Demoed, buyers can research faster and more effectively. Sign up at demoed.com

For the stories behind the headlines, head to CISOseries.com.

View Details

Evolve Bank data breach is evolving

Patelco Credit Union cyberattack disrupts services for nearly 500,000 members

LockBit claims cyberattack on Croatia’s largest hospital

Huge thanks to our sponsor, Demoed

Did you know that Demoed is the first platform that allows you to watch a live product demo and ask questions without receiving a barrage of follow-ups? We change buyer-vendor engagement: fewer follow-ups for buyers, more leads for vendors. Sign up now at demoed.com

For the stories behind the headlines, visit CISOseries.com.

View Details

14 million Linux systems threatened by ‘RegreSSHion’ vulnerability

Critical patch issued for Juniper routers

Millions not thousands impacted by Prudential breach

Huge thanks to our sponsor, Demoed

“I have extra time in my day” is something no security professional has ever said. Vendors on Demoed host 15-minute pitches highlighting their value and differentiation. Demoed allows buyers to browse and get educated without sales pressure—window shopping for enterprise sales. Sign up now at demoed.com

View Details

Update on the TeamViewer network breach

HubSpot looks into customer account hacks

U.S. businesses struggle to obtain cyber insurance

Huge thanks to our sponsor, Demoed

Demoed is a unique platform that connects buyers and sellers. Buyers want to see more products, and vendors want more leads. Demoed solves this for both by making buyers anonymous. Buyers can watch demos without follow-ups, hiding their identity until they are ready. Sign up now at demoed.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Jim Bowie, CISO, Tampa General Hospital

Thanks to our show sponsor, Prelude Security

When executives ask the question, are we vulnerable to this threat? How long does it take you to get a confident answer? Prelude automatically transforms threat intelligence into validated detections, so you can know with certainty in just a manner of minutes. Visit preludesecurity.com/threats to upload your own threat intelligence and see for yourself.

All links and the video of this episode can be found on CISO Series.com

View Details

Gas chromatograph vulnerabilities reveal medical IoT challenges

We never authorized polyfill.io to use our name, says Cloudflare

Evolve Bank confirms data breach, undermining LockBit’s Federal Reserve claim

Huge thanks to our sponsor, Prelude Security

When executives ask the question, are we vulnerable to this threat? How long does it take you to get a confident answer? Prelude automatically transforms threat intelligence into validated detections, so you can know with certainty in just a manner of minutes. Visit preludesecurity.com to upload your own threat intelligence and see for yourself.

For the stories behind the headlines, head to CISOseries.com.

View Details

Android lying Snowblind in the sun

Identity verification service exposed data for over a year

Polyfill.io JavaScript attack impacts thousands of sites

Huge thanks to our sponsor, Prelude Security

30 minutes to peace of mind. That’s what you’ll get with Prelude’s automated threat management platform where you can upload any piece of threat intelligence and quickly generate threat-hunting queries, detection rules, and more. Visit preludesecurity.com and get all of this in 30 minutes or get a pizza on Prelude.

View Details

Julian Assange to plead guilty and return to Australia

Fresh MOVEit bug under attack just hours after disclosure

Criminal selling Neiman Marcus customer info for $150K

Huge thanks to our sponsor, Prelude Security

Don’t be left wondering if you’re protected the next time a new threat hits the news. Week in review listeners can upload their threat intelligence to Prelude and receive a free bundle of relevant detection rules, hunt queries, and security tests. Any piece of threat intelligence. All in 30 minutes. Upload yours at prelude security dot com forward slash threats.

View Details

Indonesia battles Lockbit 3.0 ransomware

DOJ charges cybercrime group for $71 million in damages

SEC reports pile in following CDK Global attack

Huge thanks to our sponsor, Prelude Security

What would your security teams do with more time back in their day? Prelude provides an end-to-end threat management automation platform that quickly generates hunt queries, detection rules, and security tests from your threat intelligence to help you stay ahead of threats. Upload your own threat intelligence at preludesecurity.com and get all of that in just 30 minutes or less.

View Details

CDK Global outage caused by BlackSuit ransomware attack

Bug allows Microsoft corporate email account spoofing

UK’s largest nuclear site pleads guilty over cybersecurity failures

Huge thanks to our sponsor, Prelude Security

When executives ask the question, are we vulnerable to this threat? How long does it take you to get a confident answer? Prelude automatically transforms threat intelligence into validated detections, so you can know with certainty in just a manner of minutes. Visit preludesecurity.com to upload your own threat intelligence and see for yourself.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines - Week in Review is hosted by Rich Stroffolino with guest Bil Harmer, operating partner and CISO, Craft Ventures, also at wilharm3.com.

Thanks to our show sponsor, Vanta

Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security Our listeners get $1,000 off at vanta.com/headlines.

All links and the video of this episode can be found on CISO Series.com

View Details

CDK Global gets hacked twice

LockBit Activity on the rise

Kraken extorted by security researcher

Thanks to today's episode sponsor, Vanta

*Whether you’re starting or scaling your security program,  Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at  Vanta.com/headlines.*

View Details

Nvidia becomes world’s most valuable company

Markopolo scam delivers infostealer through fake meeting software

Medibank hack blamed on MFA failure

Thanks to today's episode sponsor, Vanta

When it comes to ensuring your company has top-notch security practices, things can get complicated, fast. Vanta automates compliance for SOC 2, ISO 27001, and more, saving you time and money. With Vanta, you can unify your security program management and proactively manage security reviews with AI-powered security questionnaires.Our listeners get $1,000 off at vanta.com/headlines.

For the stories behind the headlines, head to CISOseries.com.

View Details

AMD investigates breach after data for sale on hacking forum Qilin demands $50 million ransom from UK hospital Hackers derail Amtrak Guest Rewards accounts

Thanks to today's episode sponsor, Vanta

Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines.

For the stories behind the headlines, visit CISOseries.com.

View Details

Snowflake breach escalates with ransom demands and death threats

MITRE has a memo for the president

Velvet Ant maintains three-year cyber espionage campaign

Thanks to today's episode sponsor, Vanta

When it comes to ensuring your company has top-notch security practices, things can get complicated, fast. Vanta automates compliance for SOC 2, ISO 27001, and more, saving you time and money. With Vanta, you can unify your security program management and proactively manage security reviews with AI-powered security questionnaires.Our listeners get $1,000 off at vanta.com/headlines.

View Details

CISA leads first tabletop exercise for AI cybersecurity

Keytronic confirms data breach after ransomware gang leaks stolen files

New Linux malware controlled through Discord emojis

Thanks to today's episode sponsor, Vanta

Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Janet Heins, CISO, ChenMed and janetheins.com

Thanks to our show sponsor, Vanta

Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines.

All links and the video of this episode can be found on CISO Series.com

View Details

Record high for North American cyber insurance claims

NATO members to increase vigilance over Russian sabotage attempts

Remcos RAT discovered inside UUEncoding emails

Thanks to today's episode sponsor, Vanta

Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines.

For the stories behind the headlines, head to CISOseries.com.

View Details

Life360 faces extortion attempt after Tile data breach

White House report highlights increase in federal attacks

Russian hacker with ties to LockBit and Conti gangs arrested

Thanks to today's episode sponsor, Vanta

When it comes to ensuring your company has top-notch security practices, things can get complicated, fast. Vanta automates compliance for SOC 2, ISO 27001, and more, saving you time and money. With Vanta, you can unify your security program management and proactively manage security reviews with AI-powered security questionnaires.Our listeners get $1,000 off at vanta.com/headlines.

View Details

Pure Storage hacked via Snowflake workspace BreachForums down again and official Telegram channels deleted BlackBerry Cylance data up for sale

Thanks to today's episode sponsor, Vanta

Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines.

For the stories behind the headlines, visit CISOseries.com.

View Details

Cyber assistance coming to rural hospitals

UK and Canada launch investigation into 23andMe breach

Mandiant and Snowflake sending out breach notices

Thanks to today's episode sponsor, Vanta

When it comes to ensuring your company has top-notch security practices, things can get complicated, fast. Vanta automates compliance for SOC 2, ISO 27001, and more, saving you time and money. With Vanta, you can unify your security program management and proactively manage security reviews with AI-powered security questionnaires.Our listeners get $1,000 off at vanta.com/headlines.

View Details

Microsoft resets Recall plans

LastPass says outage caused by bad Chrome extension update

New York Times source code stolen using exposed GitHub token

Thanks to today's episode sponsor, Vanta

Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines - Week in Review is hosted by Rich Stroffolino with guest Andrew Wilder, CISO, Community Veterinary Partners, also cybersecurityintheboardroom.com.

Thanks to our show sponsor, Conveyor

Why did the AI cross the road? To complete your security questionnaires for you. Conveyor, the company using market-leading AI to automate the entire security review, wants you to check them out and book a call so they can stop writing these cheesy podcast ads. If you’re ready for AI to instantly complete security questionnaires for you, visit www.conveyor.com to try a free proof of concept. Mention this podcast for 5 free questionnaire credits when you purchase a Pro plan.

All links and the video of this episode can be found on CISO Series.com

View Details

FCC moves forward with BGP security measures

LockBit ransomware gang victims get lifeline from FBI

Gitloker attacks target GitHub repositories

Thanks to today's episode sponsor, Conveyor

Why did the AI cross the road? To complete your security questionnaires for you. Conveyor, the company using market-leading AI to automate the entire security review, wants you to check them out and book a call so they can stop writing these cheesy podcast ads. If you’re ready for AI to instantly complete security questionnaires for you, visit www.conveyor.com to try a free proof of concept. Mention this podcast for 5 free questionnaire credits when you purchase a Pro plan.

View Details

US researches using psychology against threat actors

AI leveling up unsophisticated threat actors

London Hospital attacks linked to Qilin

Thanks to today's episode sponsor, Conveyor

Conveyor is the market leading AI-powered platform that automates the entire customer security review process — from easily sharing your security posture and SOC 2 to letting AI answer security questionnaires instantly with 90% accuracy. Use Conveyor to fly through any customer security review in minutes. There’s a reason our customers have dubbed Conveyor their ‘favorite security tool of the year’. Test it out in a free proof of concept at www.conveyor.com and mention this podcast for 5 free questionnaire credits when you purchase a Pro plan.

View Details

Ransomware attack forces London hospitals to cancel operations

Christie’s stolen data sold to highest bidder

RansomHub claims responsibility for Frontier breach

Thanks to today's episode sponsor, Conveyor

Conveyor is the AI security review automation platform helping infosec teams automate everything from securely sharing a SOC 2 to one-click auto complete of your security questionnaires with AI. Teams like Lucid Software are finding in a free proof of concept that our AI is more accurate than the rest. Learn more at www.conveyor.com. Mention this podcast for 5 free questionnaire credits when you purchase a Pro plan.

View Details

Authorities unmask criminals behind malware loaders

3 billion records stolen from background check firm

Creds for 361 million accounts added to HIBP

Thanks to today's episode sponsor, Conveyor

What are infosec teams measuring these days? More often than not, their impact on the business through revenue. A director of GRC told us the most direct value for their CEO was showing the efficiencies and the dollars that security has been able to bring in from enabling sales through the security review. See how best in class infosec teams measure their performance in Conveyor’s ultimate guide to the security review KPIs that matter. Go to www.conveyor.com and click the banner at the top.

For the stories behind the headlines, visit CISOseries.com.

View Details

Ticketmaster hack affects 560 million customers, third-party denied liability

Australia’s Ticketek sees customer details exposed in cyber security breach

HHS changes tack, allows Change Healthcare to file breach notifications for others

Thanks to today's episode sponsor, Conveyor

Conveyor, the market-leading AI software for answering security questionnaires and securely sharing your security documents just released their ultimate guide to benchmarking your team’s performance on customer security reviews. Get all of the detailed metrics and learn how best in class infosec teams measure and tie their impact to revenue. Download the report at www.conveyor.com by clicking on the banner at the top.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Dimitri Van Zantvliet, CISO, Dutch Railways

Thanks to our show sponsor, Vanta

Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.

All links and the video of this episode can be found on CISO Series.com

View Details

Senator calls for UnitedHealth leadership to be held responsible

Europol seizes 2,000 domains in dropper takedown

Malware bricked over 600,000 routers

Thanks to today's episode sponsor, Vanta

Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.

View Details

New North Korean hacking group emerges

Dutch bank ABN Amro discloses data breach

Internet Archive, including Wayback Machine, impacted by DDoS

Thanks to today's episode sponsor, Vanta

Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.

For the stories behind the headlines, head to CISOseries.com.

View Details

BreachForums returns just weeks after FBI-led takedown

First American data breach impacts 44,000 people

Chinese nationals sanctioned for botnet that stole ‘billions’ in COVID-19 relief funds

Thanks to today's episode sponsor, Vanta

Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.

For the stories behind the headlines, visit CISOseries.com.

View Details

New ransomware uses Windows BitLocker to encrypt victim data

Sav-Rx discloses data breach impacting 2.8 million Americans

New ATM malware poses significant global threat

Thanks to today's episode sponsor, Vanta

Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.

For the stories behind the headlines, head to CISOseries.com.

View Details

Arc browser’s Windows launch sabotaged by malvertising

Cencora breach exposed patient info from 11 drug companies

Albany County investigating cybersecurity breach ahead of holiday weekend

Thanks to today's episode sponsor, Vanta

Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines - Week in Review is hosted by Rich Stroffolino with guest Mike Lockhart, CISO, EagleView. Make sure also to check out Mike's charity, the Grady Foundation for mental, physical and economic health. You can learn more and donate here.

Thanks to our show sponsor, Tines

Break away from traditional SOAR with Tines. Trusted by security teams at McKesson, Canva, and Mars, Tines is scalable and accessible for the whole team. Use Tines to automate security team toil, enrich alerts with data from across your tech stack, and foster a culture of cybersecurity. Start building for free at tines.com/ciso

All links and the video of this episode can be found on CISO Series.com

View Details

Chinese hackers hide on military and government networks for 6 years

Microsoft outage affects Bing, Copilot, DuckDuckGo and ChatGPT internet search

Mattis speaks out against separate military cyber service

Thanks to today's episode sponsor, Tines

Break away from traditional SOAR with Tines. Trusted by security teams at McKesson, Canva, and Mars, Tines is scalable and accessible for the whole team. Use Tines to automate security team toil, enrich alerts with data from across your tech stack, and foster a culture of cybersecurity. Start building for free at tines.com/ciso

For the stories behind the headlines, head to CISOseries.com.

View Details

NY Stock Exchange owner fined $10 million by SEC

US agency pledges $50 Million to automate hospital security

LockBit no longer reigns supreme

Thanks to today's episode sponsor, Tines

Digital threats evolve rapidly, making it difficult for security teams to keep pace. Tines security automation is different from traditional SOAR -- it allows teams to move faster and make better decisions in real-time. Built by security practitioners, for security practitioners, Tines powers mission-critical security workflows at McKesson, Canva, and Mars. Start building for free at tines.com/ciso

View Details

Brits to propose mandatory ransomware reporting

Industry heavyweights launch Tech Against Scams

Microsoft targets secure defaults in Windows 11

Thanks to today's episode sponsor, Tines

Automate the toil with SOAR that actually works for your team. With Tines, your whole team can build complex workflows, without having to write or manage code. Security teams at McKesson, Canva, and Mars use Tines to build, run, and monitor their most important workflows, from endpoint detection and response, to vulnerability management. Start building for free at tines.com/ciso

View Details

Military cyber service proposal picks up steam

Threat actors abusing legitimate services in campaign

Chatbots susceptible to jailbreaks

Thanks to today's episode sponsor, Tines

Security teams work best when all members are empowered to do their best work. With Tines, analysts and engineers have everything they need to automate the processes they’re closest to. The result? Hundreds or even thousands of hours that can be used on more impactful work. Built by security practitioners, for security practitioners. Get started today at tines.com/ciso

View Details

Grandoreiro banking Trojan reappears, hits banks worldwide

Kimsuky deploys new backdoor in latest attack on South Korea

Healthcare breaches in Australia and Texas

Huge thanks to this week’s episode sponsor, Tines

From endpoint detection and response to vulnerability management, Tines empowers security teams to automate even their most complex workflows. It’s fast, flexible, and secure by design. Your team can get up and running in minutes, not weeks. No code. No custom development. The world's smartest security teams trust Tines to support their mission-critical processes. Learn why at tines.com/ciso

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Ryan Bachman, evp and global CISO, GM Financial

Thanks to our show sponsor, vanta.com/ciso

Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.

All links and the video of this episode can be found on CISO Series.com

View Details

Nissan North America breach impacts over 53,000 employees

VMware fixes workstation flaws, thanks Pwn2Own hackers

Security flaws discovered in GE Ultrasound machines

Thanks to today's episode sponsor, Vanta

Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.

For the stories behind the headlines, head to CISOseries.com.

View Details

FBI seizes BreachForums

Android getting live threat detection

Senators recommend billions for AI investments

Editor's note: post updated to fix audio issue

Thanks to today's episode sponsor, Vanta

Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.

View Details

Singing River patient data was swiped in ransomware attack

PoC exploit released for D-Link router zero-day

Google to use GenAI to help identify phone scams

Thanks to today's episode sponsor, Vanta

Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.

For the stories behind the headlines, head to CISOseries.com.

View Details

FCC implements new classification to combat robocall groups

MITRE releases threat-modeling framework for embedded devices

World renowned auction house attacked ahead of mega-auction

Thanks to today's episode sponsor, Vanta

Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.

View Details

Boeing confirms $200 million ransomware extortion attempt

Dell announces data breach affecting 49 million customers

Ascension healthcare suffers cyberattack, goes offline

Thanks to today's episode sponsor, Vanta

Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Sasha Pereira, CISO, WASH

Thanks to our show sponsor, Vanta.com/ciso

Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.

All links and the video of this episode can be found on CISO Series.com

View Details

F5 Networks warns of new Big-IP vulnerabilities

UK armed forces’ personal data hacked in MoD breach

BetterHelp sends refund notices regarding data sharing lawsuit

Huge thanks to our sponsor, Vanta

Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.

For the stories behind the headlines, head to CISOseries.com.

View Details

Lockbit takes credit for Wichita attack

US looks at AI model export bans

The Spectre of Pathfinder haunts Intel CPUs

Huge thanks to our sponsor, Vanta

Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.

View Details

US indicts LockBit ransomware ringleader

DocGo discloses cyberattack that compromised patient health data

Payroll data breach exposed data of UK military personnel

Huge thanks to our sponsor, Vanta

Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.

For the stories behind the headlines, visit CISOseries.com.

View Details

LockBit’s website is back

Germany takes action amid alleged Russian attack

Chinese-linked ArcaneDoor targets global network infrastructure

Huge thanks to our sponsor, Vanta

Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.

View Details

NSC’s Neuberger suggests operational approach for on mitigating cyberattacks

French cybersecurity teams prepare for “unprecedented” Olympic threat

Feds warn about North Korean exploitation of improperly configured DMARC

Huge thanks to our sponsor, Vanta

Are lengthy security reviews pulling attention away from your security program? With the largest network of Trust Centers, Vanta can help you streamline security reviews to win customer trust, save time, and close deals fast. Proactively demonstrate security by showcasing key resources like your SOC 2 or ISO 27001 and provide real-time evidence for passing controls. And when a security questionnaire is required, Vanta takes the first pass for you. Visit vanta.com/ciso to take a tour.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Phil Beyer, former CISO, Etsy

Thanks to today’s episode sponsor, Dropzone.ai

Dropzone.ai’s AI Autonomous Analyst is transforming cybersecurity as we know it. By replicating the techniques of elite analysts and autonomously investigating every alert, our patented system force multiplies your SOC team by 10X without adding headcount. Experience the future of threat detection and response at dropzone.ai. Request a trial today!

All links and the video of this episode can be found on CISO Series.com

View Details

Goldoon botnet exploits D-Link routers

CISA adds Gitlab flaw to its KEV catalog

Dropbox discloses breach of digital signature service

Thanks to our episode sponsor, Dropzone AI

Dropzone.ai's AI Autonomous Analyst is transforming cybersecurity as we know it. By replicating the techniques of elite analysts and autonomously investigating every alert, our patented system force multiplies your SOC team by 10X without adding headcount. Experience the future of threat detection and response at dropzone.ai. Request a trial today!

For the stories behind the headlines, head to CISOseries.com.

View Details

Chinese disinformation proving ineffectual

NCSC release Advanced Mobile Solutions risk model

China implements new State Secrets Law

Thanks to our episode sponsor, Dropzone AI

Cybersecurity leaders, are you being asked to leverage the power of Gen AI in your SOC? Dropzone.ai's AI Autonomous Analyst empowers your team to thoroughly investigate every alert. No playbooks, no code, just intelligent, adaptable alert investigation. Test drive on dropzone.ai to immediately see the results for yourself.

View Details

UnitedHealth Group CEO faces congress & cause of hack revealed

Major U.S. wireless carriers face $200M FCC fine

Marriott backtracks claims of encryption protection

Thanks to our episode sponsor, Dropzone AI

Dropzone.ai is proud to announce our selection as a Top 10 Finalist for the prestigious RSA Innovation Sandbox. Our AI Autonomous Analyst is revolutionizing the way SOC teams operate, replicating the techniques of elite analysts and autonomously investigating every alert. Meet us at RSAC and book a time at dropzone.ai.

View Details

USPS phishing sites are popular

UK bans bad IoT credentials

USB malware attacks targeting industrial sites

Thanks to our episode sponsor, Dropzone AI

Attention cybersecurity professionals! Are you investigating 100% of the alerts from your IT and security systems? Dropzone.ai's AI Analyst autonomously investigates every alert without playbooks or code, enabling you to turn over every rock. Visit dropzone.ai to learn more and request a trial. Offload your tier-1 analysis to an AI analyst that never sleeps so you can.

View Details

Kaiser Permanente website tracking tools may have compromised customer data

DHS announces AI safety board

Okta warns of “unprecedented” credential stuffing attacks on customers

Thanks to our episode sponsor, Dropzone AI

Introducing Dropzone.ai, the industry's first AI Autonomous SOC Analyst. Their patented LLM replicates the techniques of elite analysts, autonomously investigating every alert without playbooks or code. Force multiply your SOC team by 10X without adding headcount. Visit dropzone.ai to request a trial and experience the power of AI-driven cybersecurity.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Christina Shannon, CIO, KIK Consumer Products

Thanks to our show sponsor, Veracode

Get ready to experience the future of application security at RSAC 2024 with Veracode. Join us as we unveil cutting-edge innovations and insights to tackle today’s most pressing security challenges. From live demos showcasing our newest products to engaging discussions with industry experts. See you at RSAC!

All links and the video of this episode can be found on CISO Series.com

View Details

Google postpones third-party cookie deprecation

Brocade SAN appliances and switches exposed to hacking

ICICI Bank exposes credit cards to wrong users

Thanks to this week's episode sponsor, Veracode

Don't miss out on this opportunity to elevate your cybersecurity strategy. Build and scale secure software from code to cloud with speed and trust. Visit our booth #2045 at RSAC 2024 to discover how Veracode is shaping the future of Application Security in the AI era.

For the stories behind the headlines, head to CISOseries.com.

View Details

Chinese keyboard app flaws exposed

Threat actors plant fake assassination story

ByteDance on the clock to divest TikTok

Thanks to this week's episode sponsor, Veracode

Research reveals AI-generated code mirrors human-written code's security flaws. Even seasoned programmers struggle to spot errors, with incorrect AI-generated answers abound. Veracode knows the stakes. While AI accelerates coding, relying on hunches won't suffice. Trust multi-faceted, data-driven insights to mitigate risk from the start. Don't compromise on security. Choose Veracode, your security partner in the AI-driven era of development.

View Details

Iranian nationals charged with hacking U.S. companies and agencies

Siemens working to fix device affected by Palo Alto firewall bug

Russian hackers claim cyberattack on Indiana water plant

Thanks to this week's episode sponsor, Veracode

Are you truly listening to both your security and development teams? Make informed decisions with Veracode. Our developer-friendly security tools integrate with your existing tech stack to secure code from the start. Bridge the gap between security and development for more efficient operations and stronger defenses. Visit veracode.com for a collaborative approach to security.

For the stories behind the headlines, visit CISOseries.com.

View Details

TikTok ban passes the US House

Sandworm targets critical Ukrainian orgs

North Koreans animating streaming shows

Thanks to this week's episode sponsor, Veracode

AI coding companions assist in generating high-quality code snippets, while Veracode swoops in to conduct thorough security assessments, identifying and fixing vulnerabilities quickly. With this dynamic duo, developers can innovate with confidence, knowing their code is both efficient and secure. Secure more code with Co-Pilot or any AI coding companion and Veracode. We’ll be your wingman anytime.

View Details

RedLine stealer GitHub connection

MITRE’s breached was through Ivanti zero-day vulnerabilities

Researchers find dozens of fake E-ZPass toll websites following FBI warning

Thanks to this week's episode sponsor, Veracode

Imagine your intelligent coding companion, backed by the robust security expertise of Veracode. Together, we form the ultimate duo, empowering developers to write better code while ensuring it's secure from the get-go. Learn more at RSAC 2024 with Veracode.

For the stories behind the headlines, head to CISOseries.com

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Dan Walsh, CISO, Paxos

Thanks to our show sponsor, Conveyor

Happy Friday! Are you tired of hearing about Conveyor’s AI security review automation software? We’ll stop talking about it if you book a call. Ready to give the market leading AI for security questionnaires a spin? Try a free proof of concept at www.conveyor.com. Don’t forget to mention this podcast for 5 free questionnaire credits when you purchase a Pro plan.

All links and the video of this episode can be found on CISO Series.com

View Details

Police bust reveals sophisticated phishing-as-a-service platform

Overlooked Windows Fibers offer handy route for malicious payload deployment

Michigan healthcare organization suffers data breach

Thanks to today's episode sponsor, Conveyor

Happy Friday! Are you tired of hearing about Conveyor’s AI security review automation software? We’ll stop talking about it if you book a call. Ready to give the market leading AI for security questionnaires a spin? Try a free proof of concept at www.conveyor.com. Don’t forget to mention this podcast for 5 free questionnaire credits when you purchase a Pro plan.

For the stories behind the headlines, head to CISOseries.com.

View Details

Sandworm-linked group tied to attack on water utilities

GPT-4 reads security advisories

Cell carrier workers solicited for SIM swaps

Thanks to today's episode sponsor, Conveyor

Conveyor is the market leading AI-powered platform that automates the entire customer security review process — from sharing your security posture and SOC 2 in a single portal to using that same information to automate answering security questionnaires with 90% accuracy. Use Conveyor to fly through any customer security review in minutes. It might sound like every other software claim out there, but there’s a reason our customers have dubbed Conveyor their ‘favorite security tool of the year’. Test it out in a free proof of concept at www.conveyor.com

View Details

Cisco announces breach of multifactor authentication message provider

Bad bots drive 10% annual surge in account takeover attacks

LockBit 3.0 variant generates custom, self-propagating malware

Thanks to today's episode sponsor, Conveyor

Conveyor is the AI security review automation platform helping infosec teams automate everything from securely sharing a SOC 2 to one-click autofilling security questionnaires with AI so you can spend almost zero time on the manual tasks that make you want to cry into your laptop. Teams like Lucid Software are finding in a free proof of concept that our AI is better than the rest. Learn more at www.conveyor.com. Mention this podcast for 5 free questionnaire credits when you purchase a Pro plan.

For the stories behind the headlines, head to CISOseries.com.

View Details

Meta to close Threads in Turkey

Palo Alto fixes backdoor zero-day

Details on Microsoft’s security overhaul

Thanks to today's episode sponsor, Conveyor

What are infosec teams measuring these days? More often than not, their impact on sales. As infosec teams become hands on in the sales cycle, proving your value becomes key. A director of GRC said last week that the most direct value for their CEO was showing the efficiencies and the dollars that security has been able to bring in from enabling sales. See these trends and more in Conveyor’s ‘2024 State of the Security Review” report at www.conveyor.com. Click the banner at the top.

View Details

House passes reauthorization of U.S. surveillance program

Roku says 576,000 accounts compromised in latest security breach

Microsoft breach exposed federal agencies

Thanks to today's episode sponsor, Conveyor

It’s Conveyor again, the market-leading AI software for answering security questionnaires and securely sharing your security posture and documents. Conveyor’s ‘State of the Security Review” report for 2024 was just released and it’s all about what the “new era” of infosec holds. Learn how positioning security and compliance early in the sales cycles increases win rates by 42% and what infosec teams need to prepare for as they move closer to the sales function. You can find the report at www.conveyor.com by clicking on the banner at the top.

For the stories behind the headlines, visit CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Mike Levin, deputy CISO, 3M

Thanks to our show sponsor, Vanta

When it comes to ensuring your company has top-notch security practices, things can get complicated fast. With Vanta, you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA. Even more, Vanta’s market-leading Trust Management Platform enables you to unify security program management with a built-in risk register and reporting, and streamline security reviews with AI-powered security questionnaires. Over 7,000 fast-growing companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security in real time. Watch Vanta’s on-demand demo at vanta.com/ciso.

All links and the video of this episode can be found on CISO Series.com

View Details

Palo Alto Networks fixes several DoS vulnerabilities in PAN-OS operating system

Sisense breach exposes customers to potential supply chain attack

Threat actors gaming GitHub Search

Thanks to today's episode sponsor, Vanta

The average security pro spends nearly a full workday every week just on compliance. With Vanta, you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA. Even more, Vanta’s market-leading Trust Management Platform enables you to unify security program management with a built-in risk register and reporting, and streamline security reviews with AI-powered security questionnaires. Over 7,000 fast-growing companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security in real time. Watch Vanta’s on-demand demo at vanta.com/ciso.

For the stories behind the headlines, head to CISOseries.com.

View Details

CISA expands automated malware analysis

US Cyber Command launched “hunt forward” missions

Spectre v2: Linux Boogaloo

CHECK OUT Capture the CISO season 2 here.

Thanks to today's episode sponsor, Vanta

The average security pro spends nearly a full workday every week just on compliance. With Vanta, you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA. Even more, Vanta’s market-leading Trust Management Platform enables you to unify security program management with a built-in risk register and reporting, and streamline security reviews with AI-powered security questionnaires. Over 7,000 fast-growing companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security in real time. Watch Vanta’s on-demand demo at vanta.com/ciso.

View Details

Ukraine's head of cybersecurity suspended and assigned to combat zone

Over 90,000 LG Smart TVs exposed to remote attack

Microsoft exposed internal passwords in security lapse

Thanks to today's episode sponsor, Vanta

The average security pro spends nearly a full workday every week just on compliance. With Vanta, you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA. Even more, Vanta’s market-leading Trust Management Platform enables you to unify security program management with a built-in risk register and reporting, and streamline security reviews with AI-powered security questionnaires. Over 7,000 fast-growing companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security in real time. Watch Vanta’s on-demand demo at vanta.com/ciso.

For the stories behind the headlines, visit CISOseries.com.

View Details

Cyberattack causes major disruptions for UK vet firm

Data privacy bill pushes forward with bipartisan support

Department of Justice hack exposes hundreds of thousands

Thanks to today's episode sponsor, Vanta

The average security pro spends nearly a full workday every week just on compliance. With Vanta, you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA. Even more, Vanta’s market-leading Trust Management Platform enables you to unify security program management with a built-in risk register and reporting, and streamline security reviews with AI-powered security questionnaires. Over 7,000 fast-growing companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security in real time. Watch Vanta’s on-demand demo at vanta.com/ciso.

View Details

Government warns hospitals of hackers targeting IT help desks

U.S. government contractor Acuity responds to alleged Five Eyes breach

New York City becomes latest in municipal government hack attempts

Thanks to today's episode sponsor, Vanta

The average security pro spends nearly a full workday every week just on compliance. With Vanta, you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA. Even more, Vanta’s market-leading Trust Management Platform enables you to unify security program management with a built-in risk register and reporting, and streamline security reviews with AI-powered security questionnaires. Over 7,000 fast-growing companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security in real time. Watch Vanta’s on-demand demo at vanta.com/ciso.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by David Spark with guest Steve Gentry, Advisor, Clari

Thanks to our show sponsor, Vanta

The average security pro spends nearly a full workday every week just on compliance.

With Vanta, you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA.

Even more, Vanta’s market-leading Trust Management Platform enables you to unify security program management with a built-in risk register and reporting, and streamline security reviews with AI-powered security questionnaires.

Over 7,000 fast-growing companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security in real time.

Watch Vanta’s on-demand demo at vanta.com/ciso.

All links and the video of this episode can be found on CISO Series.com

View Details

Classified Five Eyes data theft announced

Cancer center data breach affects 800,000

Android Pixel phone zero-day flaws being exploited by forensic companies

Thanks to today's episode sponsor, Vanta

The average security pro spends nearly a full workday every week just on compliance.

With Vanta, you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA.

Even more, Vanta’s market-leading Trust Management Platform enables you to unify security program management with a built-in risk register and reporting, and streamline security reviews with AI-powered security questionnaires.

Over 7,000 fast-growing companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security in real time.

Watch Vanta’s on-demand demo at vanta.com/ciso to learn more.

For the stories behind the headlines, head to CISOseries.com.

View Details

Report criticizes Microsoft’s Chinese hack response

NIST needs help with vulnerability backlog

Chrome tests feature to prevent session hijacking

Thanks to today's episode sponsor, Vanta

The average security pro spends nearly a full workday every week just on compliance.

With Vanta, you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA.

Even more, Vanta’s market-leading Trust Management Platform enables you to unify security program management with a built-in risk register and reporting, and streamline security reviews with AI-powered security questionnaires.

Over 7,000 fast-growing companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security in real time.

Watch Vanta’s on-demand demo at vanta.com/ciso to learn more.

View Details

CISA releases draft rule for cyber incident reporting

Google now blocks spoofed emails for better phishing protection

Breach at online shopping platform PandaBuy affects 1.3 million customers

Thanks to today's episode sponsor, Vanta

The average security pro spends nearly a full workday every week just on compliance.

With Vanta, you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA.

Even more, Vanta’s market-leading Trust Management Platform enables you to unify security program management with a built-in risk register and reporting, and streamline security reviews with AI-powered security questionnaires.

Over 7,000 fast-growing companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security in real time.

Watch Vanta’s on-demand demo at vanta.com/ciso to learn more.

For the stories behind the headlines, head to CISOseries.com.

View Details

Google to delete Incognito tracking data

Hallucinated software packages as a security vulnerability

FCC investigating phone infrastructure security

Thanks to today's episode sponsor, Vanta

The average security pro spends nearly a full workday every week just on compliance.

With Vanta, you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA.

Even more, Vanta’s market-leading Trust Management Platform enables you to unify security program management with a built-in risk register and reporting, and streamline security reviews with AI-powered security questionnaires.

Over 7,000 fast-growing companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security in real time.

Watch Vanta’s on-demand demo at vanta.com/ciso to learn more.

View Details

Data of 73 million AT&T customers leaked on dark web

Accidental Linux backdoor discovery likely prevented thousands of infections

DHS expected to stop buying access to your phone info

Thanks to today's episode sponsor, Vanta

The average security pro spends nearly a full workday every week just on compliance.

With Vanta, you can automate compliance for in-demand frameworks like SOC 2, ISO 27001, and HIPAA.

Even more, Vanta’s market-leading Trust Management Platform enables you to unify security program management with a built-in risk register and reporting, and streamline security reviews with AI-powered security questionnaires.

Over 7,000 fast-growing companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security in real time.

Watch Vanta’s on-demand demo at vanta.com/ciso to learn more.

For the stories behind the headlines, visit CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Yaron Levi, CISO, Dolby, and sageinsights.io

Thanks to our show sponsor, Varonis

Ready to reduce your risk without taking any? Try Varonis’ free data risk assessment. It takes minutes to set up and in 24 hours you’ll have a clear, risk-based view of the data that matters most and a clear path to automated remediation. Get started for free today at varonis.com/cisoseries.

All links and the video of this episode can be found on CISO Series.com

View Details

17 billion personal records exposed in data breaches in 2023

U.S. Treasury warns financial sector about AI cybersecurity threats

Retail chain Hot Topic hit by new credential stuffing attacks

Thanks to today's episode sponsor, Varonis

Ready to reduce your risk without taking any? Try Varonis’ free data risk assessment. It takes minutes to set up and in 24 hours you’ll have a clear, risk-based view of the data that matters most and a clear path to automated remediation. Get started for free today at varonis.com/cisoseries.

For the stories behind the headlines, head to CISOseries.com.

View Details

Spyware fuels rise in zero-day exploits

CISA warns about Microsoft SharePoint vulnerability

Facebook snooped on encrypted Snapchat traffic

Thanks to today's episode sponsor, Varonis

Ready to reduce your risk without taking any? Try Varonis’ free data risk assessment. It takes minutes to set up and in 24 hours you’ll have a clear, risk-based view of the data that matters most and a clear path to automated remediation. Get started for free today at varonis.com/cisoseries.

View Details

APT31 targeting family members to surveil targets

Ransomware gang attacks UK newspaper supporting the homeless

MFA bombing attacks target Apple users

Thanks to today's episode sponsor, Varonis

Ready to reduce your risk without taking any? Try Varonis’ free data risk assessment. It takes minutes to set up and in 24 hours you’ll have a clear, risk-based view of the data that matters most and a clear path to automated remediation. Get started for free today at varonis.com/cisoseries. For the stories behind the headlines, visit CISOseries.com.

View Details

EU targets tech giants with DMA

China starts US tech ban in government

Think tank calls for US military cyber service

Thanks to today's episode sponsor, Varonis

Ready to reduce your risk without taking any? Try Varonis’ free data risk assessment. It takes minutes to set up and in 24 hours you’ll have a clear, risk-based view of the data that matters most and a clear path to automated remediation. Get started for free today at varonis.com/cisoseries.

View Details

Kimsuky turns to compiled HTML Help files for cyberattacks

KDE issues warning after theme wipes Linux user’s files

Critical flaw in Atlassian Bamboo data center and server must be fixed immediately

Thanks to today's episode sponsor, Varonis

Ready to reduce your risk without taking any? Try Varonis’ free data risk assessment. It takes minutes to set up and in 24 hours you’ll have a clear, risk-based view of the data that matters most and a clear path to automated remediation. Get started for free today at varonis.com/cisoseries.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review, is hosted by Rich Stroffolino with guest Gerald Auger Ph.D., Chief Content Creator, Simply Cyber

Thanks to our show sponsor, Vanta

Managing the requirements for modern security programs is increasingly challenging. Vanta’s trust management platform helps you quickly assess risk, streamline security reviews, and automate compliance for SOC 2, ISO 27001, HIPAA, and more. Plus, you can save time by completing security questionnaires with Vanta AI. Join over 7,000 global companies that use Vanta to automate evidence collection, unify risk management, and secure customer trust. To learn more, go to vanta.com/ciso

All links and the video of this episode can be found on CISO Series.com

View Details

Microsoft confirms Windows Server issue behind domain controller crashes

Over 800 npm packages found with discrepancies

Nemesis darknet marketplace raided in Germany-led operation

Thanks to today's episode sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

For the stories behind the headlines, head to CISOseries.com.

View Details

US plans Water Sector Cybersecurity Task Force

Loop DoS attack exploits the infinite regress of UDP

GitHub tool uses AI to fix vulnerabilities

Thanks to today's episode sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

View Details

Mid-stream hack postpones ESports league

Bank loses $40 million after “systems glitch”

LockBit reemerges with vengeance

Thanks to today's episode sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

View Details

UnitedHealth fronts over $2 billion in recovery efforts

Spyware agreement gains more international support

FTC probes Reddit's AI data licensing ahead of IPO

Thanks to today's episode sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

View Details

Global McDonald’s outage blamed on third-party vendor, not cyberattack

Google adds real-Time URL protection for Chrome

Network outages hit Birmingham Alabama

Thanks to today's episode sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Alexandra Landegger, Executive Director and CISO Collins Aerospace

Thanks to our show sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

All links and the video of this episode can be found on CISO Series.com

View Details

Change Healthcare - AHA asks for aid, HHS questions HIPAA compliance

Fortinet warns of severe SQLi vulnerability in FortiClientEMS software

Yacht company MarineMax announces cyberattack

Thanks to today's episode sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

For the stories behind the headlines, head to CISOseries.com.

View Details

Researchers find vulnerabilities in Gemini

New York Times denies it “hacked” OpenAI for lawsuit

Leaked GitHub secrets up 28%

Thanks to today's episode sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

View Details

LockBit takes credit for hacking South African pension fund

CISA’s OT attack response team understaffed

US and Russia accuse each other of potential election cyberattacks

Thanks to today's episode sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

For the stories behind the headlines, visit CISOseries.com.

View Details

Roku forces reset after 15,000 accounts compromised

French government agencies targeted in “unprecedented” attacks

Fintech firm taken offline by ransomware attack

Thanks to today's episode sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

For the stories behind the headlines, head to CISOseries.com.

View Details

Microsoft says Russian hackers breached its systems, accessed source code

CISA adds JetBrains TeamCity bug to its KEV catalog

Over 225,000 compromised ChatGPT credentials for sale

Thanks to today's episode sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest David Cross, SVP/CISO, Oracle. Also check out David’s travel blog, DavidCrossTravels.com

Thanks to our show sponsor, Conveyor

Conveyor is the AI security review automation platform helping infosec teams automate everything from securely sharing a SOC 2 to one-click autofilling security questionnaires in OneTrust so you can spend almost zero time on the manual tasks that make you want to throw your computer out the window. Teams are finding in a free proof of concept that our AI is better than the rest. Learn more at www.conveyor.com. Mention this podcast for 5 free questionnaire credits when you purchase an Enterprise plan.

All links and the video of this episode can be found on CISO Series.com

View Details

Flipper Zero WiFi attack can unlock and steal Tesla cars

Former Google engineer indicted for stealing AI secrets for Chinese companies

PetSmart warns customers of credential stuffing attack

Thanks to today's episode sponsor, Conveyor

Conveyor is the AI security review automation platform helping infosec teams automate everything from securely sharing a SOC 2 to one-click autofilling security questionnaires in OneTrust so you can spend almost zero time on the manual tasks that make you want to throw your computer out the window. Teams are finding in a free proof of concept that our AI is better than the rest. Learn more at www.conveyor.com. Mention this podcast for 5 free questionnaire credits when you purchase an Enterprise plan.

For the stories behind the headlines, head to CISOseries.com.

View Details

Online fraud hits record losses

States urge Meta to crack down on scammers

Apple issues update for zero-day flaw

Thanks to today's episode sponsor, Conveyor

Happy Thursday. Are you tired of us talking about how Conveyor’s AI security review automation software? We’ll stop talking about it if you come talk to them. Ready to give the market leading AI for security questionnaires a spin? Try a free proof of concept at www.conveyor.com. Don’t forget to mention this podcast for 5 free questionnaire credits when you purchase an Enterprise plan.

For the stories behind the headlines, head to CISOseries.com.

View Details

US cybersecurity strategy update on the way

US Treasury issues first spyware sanctions

UK denies responsibility for ALPHV takedown

Thanks to today's episode sponsor, Conveyor

Conveyor is the only GPT-powered customer trust portal that automates the entire customer security review process — from sharing your security posture and documents in a single portal to automating security questionnaire responses with 90% accuracy so you can fly through any customer security review in minutes. It might sound like every other compliance software claim out there, but there’s a reason our customers have dubbed Conveyor their ‘favorite security tool of the year’. Test our market-leading AI in a free proof of concept at www.conveyor.com

View Details

North Korea targets semiconductor industry

ALPHV infrastructure goes dark

China to offer computing vouchers to AI startups

Thanks to today's episode sponsor, Conveyor

AI is getting pretty smart so you shouldn’t settle for mediocre security questionnaire automation software that only generates the right answer 20 to 50 percent of the time or have to wait a day for the vendor’s team to check the answers. Conveyor's security questionnaire automation tool not only boasts industry leading AI accuracy reducing time spent on security reviews by 80%, but now also autofills in OneTrust portal questionnaires with a single click. Trying a proof of concept with your own data is always free. Learn more at www.conveyor.com. Mention this podcast for 5 free questionnaire credits when you purchase an Enterprise plan.

View Details

NSO Group to ordered to give Pegasus code to WhatsApp

Change Healthcare confirms BlackCat, Schumer asks for aid

Law firm announces data breach affecting 325,000 people

Thanks to today's episode sponsor, Conveyor

We’ve got a returning sponsor this week – Conveyor. They’re the AI security review automation platform helping infosec teams automate everything from securely sharing a SOC 2 to one-click autofilling security questionnaires in OneTrust so you can spend almost zero time on the manual tasks that make you want to throw your computer out the window. Teams are finding in a free proof of concept that their AI is better than the rest. Learn more at www.conveyor.com. Mention this podcast for 5 free questionnaire credits when you purchase an Enterprise plan.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Russ Ayres, SVP of Cyber & Deputy CISO, Equifax

Thanks to our show sponsor, Egress

People are the biggest risk to your organization’s security, and they are most vulnerable when using email.

With more advanced threats getting through secure email gateway detection every day, Egress provides AI-powered email security that eliminates both inbound phishing attacks and outbound data breaches. What's more, Egress' adaptive security architecture personalizes security for each user based on their real-time risk score.

Visit egress.com to learn more about Egress’ Intelligent Cloud Email Security suite and start detecting email threats your secure email gateway is missing today.

All links and the video of this episode can be found on CISO Series.com

View Details

Pharma giant Cencora announces data breach

GenAI drives surge in BEC attacks

Popular video doorbell easy hijacked

Thanks to today's episode sponsor, Egress

People are the biggest risk to your organizations' security and they are most vulnerable when using email. With more advanced threats getting through secure email gateway detection every day, Egress provides AI-powered email security that eliminates both inbound phishing attacks and outbound data breaches. What's more, Egress' adaptive security architecture personalizes security for each user based on their real-time risk score. Visit egress.com to learn more about Egress' Intelligent Cloud Email Security suite and start detecting email threats your secure email gateway is missing today.

For the stories behind the headlines, head to CISOseries.com.

View Details

Biden signs order limiting the sale of personal data

Australia claims its seeing unprecedented “foreign interference”

Lazarus Group targeting Windows and PyPi

Thanks to today's episode sponsor, Egress

People are the biggest risk to your organizations' security and they are most vulnerable when using email. With more advanced threats getting through secure email gateway detection every day, Egress provides AI-powered email security that eliminates both inbound phishing attacks and outbound data breaches. What's more, Egress' adaptive security architecture personalizes security for each user based on their real-time risk score. Visit egress.com to learn more about Egress' Intelligent Cloud Email Security suite and start detecting email threats your secure email gateway is missing today.

View Details

NIST releases cybersecurity framework 2.0

Optum attack linked to BlackCat ransomware

ScreenConnect exploitations continue

Thanks to today's episode sponsor, Egress

People are the biggest risk to your organizations' security and they are most vulnerable when using email. With more advanced threats getting through secure email gateway detection every day, Egress provides AI-powered email security that eliminates both inbound phishing attacks and outbound data breaches. What's more, Egress' adaptive security architecture personalizes security for each user based on their real-time risk score. Visit egress.com to learn more about Egress' Intelligent Cloud Email Security suite and start detecting email threats your secure email gateway is missing today.

View Details

SolarWinds attackers changing tactics

Brand domains used in spam operation

Steel giant hit with cyberattack

Thanks to today's episode sponsor, Egress

People are the biggest risk to your organizations' security and they are most vulnerable when using email. With more advanced threats getting through secure email gateway detection every day, Egress provides AI-powered email security that eliminates both inbound phishing attacks and outbound data breaches. What's more, Egress' adaptive security architecture personalizes security for each user based on their real-time risk score. Visit egress.com to learn more about Egress' Intelligent Cloud Email Security suite and start detecting email threats your secure email gateway is missing today.

View Details

British police taunt LockBit administrator

PayPal files patent for new stolen cookies detector

Vending machine crash reveals face recognition tech

Thanks to today's episode sponsor, Egress

People are the biggest risk to your organizations' security and they are most vulnerable when using email. With more advanced threats getting through secure email gateway detection every day, Egress provides AI-powered email security that eliminates both inbound phishing attacks and outbound data breaches. What's more, Egress' adaptive security architecture personalizes security for each user based on their real-time risk score. Visit egress.com to learn more about Egress' Intelligent Cloud Email Security suite and start detecting email threats your secure email gateway is missing today.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Thom Langford, CISO, Velonetic

Thanks to our show sponsor, Conveyor

Conveyor AI is so good, it can now autofill OneTrust portal questionnaires in one click. Yes, we’ve been talking about it all week. Conveyor's security questionnaire automation tool not only boasts industry leading AI accuracy, but now fills in One Trust portals with a single click. Trying a proof of concept with your own data is always free. Learn more at www.conveyor.com. Mention this podcast for 5 free questionnaire credits when you purchase an Enterprise plan.

All links and the video of this episode can be found on CISO Series.com

View Details

LockBit was building next gen encryptor before takedown

Thousands of wireless customers suffer outage

Prescription delays due to Change Healthcare cyberattack

Thanks to today's episode sponsor, Conveyor

Conveyor, the security questionnaire automation software one of their customers dubbed “my favorite security tool of the year”, is now even better. They’ve upgraded our browser extension for portal-based questionnaires and it can now autofill OneTrust portal questionnaires in one click. You can test the AI in a free proof of concept at www.conveyor.com. Mention this podcast for 5 free questionnaire credits when you purchase an Enterprise plan.

Get the stories behind the headlines at CISOSeries.com

View Details

Thanks to today's episode sponsor, Conveyor

Happy Thursday. Are you tired of us talking about how Conveyor’s AI can now autofill OneTrust security questionnaires in one-click? Well, we’ll stop talking about it if you come talk to them. Ready to give the market leading AI for security questionnaires a spin? Try a free proof of concept by booking a demo at www.conveyor.com. And mention this podcast for 5 free questionnaire credits when you purchase an Enterprise plan.

Get the stories behind the headlines at CISOSeries.com

View Details

LockBit takedown update

Signal now lets users keep phone numbers private

NSA Cybersecurity Director Rob Joyce to retire

Thanks to today's episode sponsor, Conveyor

No more portal scaries. Conveyor just launched AI autofill of OneTrust portal questionnaires. That means no more clicking question-by-question to copy-paste each answer when a customer sends you a OneTrust security questionnaire. Conveyor’s AI will read and autofill the whole page for you. Trying a proof of concept with your own data is always free. Learn more at www.conveyor.com. Mention this podcast for 5 free questionnaire credits when you purchase an Enterprise plan.

Get the stories behind the headlines at CISOSeries.com

View Details

LockBit disrupted by global police operation

Cactus leaks Schneider Electric data on dark web

ALPHV gang takes credit for LoanDepot, Prudential attacks

Thanks to today's episode sponsor, Conveyor

Conveyor, the security questionnaire automation software one of our customers dubbed “my favorite security tool of the year”, is now even better. They’ve upgraded their browser extension for portal-based questionnaires and it can now autofill OneTrust portal questionnaires in one click. You can test the AI in a free proof of concept at www.conveyor.com. Mention this podcast for 5 free questionnaire credits when you purchase an Enterprise plan.

Get the stories behind the headlines at CISOSeries.com

View Details

Google Chrome feature blocks attacks against home networks

Mastermind behind Zeus and IcedID malware pleads guilty

Air Canada must honor refund invented by its chatbot, says court

Thanks to today's episode sponsor, Conveyor

Conveyor AI is so good, it can now autofill OneTrust portal questionnaires in one click. Yes, you heard us right. Conveyor's security questionnaire automation tool not only boasts industry leading AI accuracy, but now fills in One Trust portals with a single click. Trying a proof of concept with your own data is always free. Learn more at www.conveyor.com. Mention this podcast for 5 free questionnaire credits when you purchase an Enterprise plan.

Get the stories behind the headlines at CISOSeries.com

View Details

Link to blog post

This week’s Cyber Security Headlines - Week in Review is hosted by Rich Stroffolino with guest Trina Ford, CISO, iHeartMedia

Thanks to our show sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

All links and the video of this episode can be found on CISO Series.com

View Details

Microsoft warns of new Exchange Server zero-day

Neuberger: Pace of ransomware takedown operations isn’t enough

Gold Pickaxe malware steals your face

Huge thanks to our sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

For the stories behind the headlines, head to CISOseries.com.

View Details

Trans-Northern Pipelines confirms cyberattack

Threat actors using LLMs to improve cyberattacks

Email provider published internal emails in plain text

Huge thanks to our sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

View Details

Prudential Financial data breached in cyberattack

Facebook Marketplace user records leaked on hacking forum

Bank of America customers at risk after third party breach

Huge thanks to our sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

For the stories behind the headlines, visit CISOseries.com.

View Details

CISA releases repository security framework

Ransomware takes down Romanian healthcare management system

Ivanti flaw used to deploy backdoor

Huge thanks to our sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

View Details

Raspberry Robin – a new one-day exploit targeting Windows

Hyundai Europe suffers Black Basta ransomware attack

Cisco to cut thousands of jobs as it focuses on high growth areas

Huge thanks to our sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Doug Mayer, vp, CISO, WCG

Thanks to our show sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

All links and the video of this episode can be found on CISO Series.com

View Details

CISA, FBI issue sobering warning about Volt Typhoon

Cisco fixes critical Expressway flaws

3 million records from thousands of credit unions exposed

Thanks to today's episode sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging.

Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization.

Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk.

To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

For the stories behind the headlines, visit CISOseries.com.

View Details

CISA collaboration initiative on thin ice

Iran focusing cyber efforts

Ransomware payments cross $1 billion in 2023

Thanks to today's episode sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging.

Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization.

Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk.

To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

For the stories behind the headlines, visit CISOseries.com.

View Details

Tech giants and world govs unite to tackle spyware threats

Spyware vendors to blame for most Google zero-days

Insider data breach hits almost half of Verizon’s employee base

Thanks to today's episode sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging.

Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization.

Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk.

To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

For the stories behind the headlines, visit CISOseries.com.

View Details

Spoutible API vulnerability leaks user data

Illicit service cranks out fake IDs

Sudo coming to Windows

Thanks to today's episode sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging.

Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization.

Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk.

To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

For the stories behind the headlines, visit CISOseries.com.

View Details

Cloudflare announces nation-state level breach

AnyDesk says hackers breached production servers, reset passwords

Chicago children’s hospital announces cyberattack

Thanks to today's episode sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging.

Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization.

Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk.

To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

For the stories behind the headlines, visit CISOseries.com.

View Details

Link to blog post

Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Mary Rose Martinez, vp, CISO Marathon Petroleum

Thanks to our show sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

All links and the video of this episode can be found on CISO Series.com

View Details

FBI director warns of Chinese hacker threat to U.S. critical infrastructure

CISA warns of exploited Apple flaw

Pentagon Intelligence supplier allegedly hacked

Thanks to today's episode sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging.

Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization.

Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk.

To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

For the stories behind the headlines, visit CISOseries.com.

View Details

FBI grounds Volt Typhoon

More companies refuse to pay ransoms

Binance internal info exposed on GitHub

Thanks to today's episode sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging.

Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization.

Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk.

To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

For the stories behind the headlines, visit CISOseries.com.

View Details

Mercedes-Benz exposes sensitive data, source code

Juniper Networks issues out-of-band fix for high severity flaws

New ZLoader malware, now with 64-bit Windows compatibility

Thanks to today's episode sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging.

Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization.

Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk.

To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

For the stories behind the headlines, visit CISOseries.com.

View Details

Microsoft takes another hit

Energy giant hit by ransomware

The NSA is secretly buying your data

Thanks to today's episode sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging.

Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization.

Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk.

To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

For the stories behind the headlines, visit CISOseries.com.

View Details

Urgent patch alert for Jenkins

Cisco flaw exposes Unified Comms systems

Pro-Ukraine hackers wipe 2 petabytes of data from Russian intelligence center

Thanks to today's episode sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging.

Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization.

Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk.

To learn more, go to vanta.com/ciso and watch their 3-minute product demo.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Mike Kelley, vp, CISO, The E.W. Scripps Company and partner, OTAWireless.com.

Thanks to our show sponsor, Conveyor

Conveyor, the security questionnaire automation software known for generating the most accurate AI answers to questionnaires is launching a much-requested feature. Conveyor’s AI can now use uploaded security documents like a SOC 2 and security policy whitepapers to auto-generate precise answers to entire questionnaires in seconds. See why customers like Lucid and Carta are raving about the software and try the AI yourself in a free proof of concept at www.conveyor.com.

All links and the video of this episode can be found on CISO Series.com

View Details

Hewlett Packard Enterprise (HPE) attacked through Microsoft 365 email system

Study reveals 18,000 exposed API secrets, including $20 million in vulnerable Stripe tokens

Ukrainian energy, postal, and transportation services hit by cyberattacks

Thanks to today's episode sponsor, Conveyor

Conveyor, the security questionnaire automation software known for generating the most accurate AI answers to questionnaires is launching a much-requested feature. Conveyor’s AI can now use uploaded security documents like a SOC 2 and security policy whitepapers to auto-generate precise answers to entire questionnaires in seconds. See why customers like Lucid and Carta are raving about the software and try the AI yourself in a free proof of concept at www.conveyor.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Cyberattack knocks EquiLend offline

Brits warn of the AI impact on ransomware

Data leak claims to hold over 26 billion records

Thanks to today's episode sponsor, Conveyor

Conveyor, the security questionnaire automation software one of our customers dubbed “my favorite security tool of the year”, is now even better. How? Conveyor’s AI can now use uploaded security documents like a SOC 2 or security policy document to auto-generate precise answers to entire security questionnaires in seconds. You can test the AI in a free proof of concept at www.conveyor.com.

View Details

CISA boss targeted in “harrowing” swatting attack

Subway puts a LockBit investigation on the menu

Australia sanctions REvil hacker behind Medibank data breach

Thanks to today's episode sponsor, Conveyor

Ever wish AI could auto-generate answers to security questionnaires for you just based on your SOC 2 or other documents? Spoiler alert - it can and you can now try it for free with Conveyor’s AI security questionnaire automation software. Set up takes a few seconds. Get a free Conveyor account and simply upload your security documents. Then, upload a new questionnaire to see AI generate answers in seconds based on your documents. Try a free proof of concept today at www.conveyor.com.

For the stories behind the headlines, visit CISOseries.com.

View Details

Thailand court attempts to suppress data leak

CISA issues emergency directive on Ivanti zero-days

Cybersecurity startup funding down 50%

Huge thanks to our episode sponsor, Conveyor

What’s worse than a last minute security questionnaire in your inbox?

Having to maintain a thousand question and answer pairs to use to respond to a questionnaire.

Now, Conveyor’s AI security questionnaire automation software can use security documents like a SOC 2 and a pared down question and answer bank to auto-generate precise answers to entire questionnaires in seconds.

Try a free proof of concept today at www.conveyor.com.

View Details

Russian hackers breach Microsoft executive emails to learn about themselves

JPMorgan Chase says hacking attempts are increasing

TeamViewer still being abused to breach networks in new ransomware attacks

Thanks to today's episode sponsor, Conveyor

AI can now literally answer any question in seconds, yet infosec teams are still in a living nightmare manually filling out questionnaires. Conveyor AI’s can now use your uploaded security documents to auto-generate precise answers to entire questionnaires. The software one of our customers dubbed “my favorite security tool of the year” in 2023 has gotten even better and it takes just minutes to get started. Try a free proof of concept at www.conveyor.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Jerich Beason, CISO, WM

Thanks to our show sponsor, Savvy Security

Shadow identities on SaaS apps are growing unchecked, rapidly expanding an attack surface where businesses have little-to-no visibility or control. Savvy helps security teams safely embrace SaaS benefits by automating the discovery and removal of the most toxic combinations of SaaS identity risk. Savvy’s automation playbooks and just-in-time security guardrails guide users at scale towards proper identity hygiene. That’s Savvy—Identity-First SaaS Security. Learn more at savvy.security/headlines.

All links and the video of this episode can be found on CISO Series.com

View Details

Atlassian outage briefly affected multiple cloud services

iShutdown helps discover spyware on iPhones

Russian state hackers COLDRIVER deploy malware in European espionage campaign

Huge thanks to our sponsor, Savvy Security

Shadow identities on SaaS apps are growing unchecked, rapidly expanding an attack surface where businesses have little-to-no visibility or control. Savvy helps security teams safely embrace SaaS benefits by automating the discovery and removal of the most toxic combinations of SaaS identity risk. Savvy’s automation playbooks and just-in-time security guardrails guide users at scale towards proper identity hygiene. That’s Savvy—Identity-First SaaS Security.

Learn more at savvy.security/headlines.

For the stories behind the headlines, head to CISOseries.com.

View Details

Chinese drones considered national security threat

PixieFail could spell trouble for cloud providers

Have I Been Pwned adds “statistically significant” data leak

Huge thanks to our sponsor, Savvy Security

Shadow identities on SaaS apps are growing unchecked, rapidly expanding an attack surface where businesses have little-to-no visibility or control. Savvy helps security teams safely embrace SaaS benefits by automating the discovery and removal of the most toxic combinations of SaaS identity risk. Savvy’s automation playbooks and just-in-time security guardrails guide users at scale towards proper identity hygiene. That’s Savvy—Identity-First SaaS Security.

Learn more at savvy.security/headlines.

View Details

Google patches first Chrome zero-day vulnerability of the year

Urgent warning from Citrix to patch two zero-day vulnerabilities

New malware strain persists despite patch

Huge thanks to our sponsor, Savvy Security

Shadow identities on SaaS apps are growing unchecked, rapidly expanding an attack surface where businesses have little-to-no visibility or control. Savvy helps security teams safely embrace SaaS benefits by automating the discovery and removal of the most toxic combinations of SaaS identity risk. Savvy’s automation playbooks and just-in-time security guardrails guide users at scale towards proper identity hygiene. That’s Savvy—Identity-First SaaS Security.

Learn more at savvy.security/headlines.

View Details

Turkey blocks some VPNs

OpenAI publishes election guidance

Spanish municipality faces stiff ransomware demand

Huge thanks to our sponsor, Savvy Security

Shadow identities on SaaS apps are growing unchecked, rapidly expanding an attack surface where businesses have little-to-no visibility or control. Savvy helps security teams safely embrace SaaS benefits by automating the discovery and removal of the most toxic combinations of SaaS identity risk. Savvy’s automation playbooks and just-in-time security guardrails guide users at scale towards proper identity hygiene. That’s Savvy—Identity-First SaaS Security.

Learn more at savvy.security/headlines.

View Details

Ransomware gang targets clean water nonprofit

Denmark energy sector attacks likely not Sandworm after all

SEC says X account breach did not lead to further breaches

Thanks to our episode sponsor, Savvy Security

Shadow identities on SaaS apps are growing unchecked, rapidly expanding an attack surface where businesses have little-to-no visibility or control. Savvy helps security teams safely embrace SaaS benefits by automating the discovery and removal of the most toxic combinations of SaaS identity risk. Savvy’s automation playbooks and just-in-time security guardrails guide users at scale towards proper identity hygiene. That’s Savvy—Identity-First SaaS Security. Learn more at savvy.security/headlines.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Allan Cockriel, Group CISO, Shell

Thanks to our show sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To see Vanta’s platform firsthand and access resources plus a special offer, go to vanta.com/ciso and watch their 3-minute product demo.

All links and the video of this episode can be found on CISO Series.com

View Details

Ivanti VPN hit by zero-days

Akira targeting backups

Sensitive school data accidentally exposed online

Remember to subscribe to the Cyber Security Headlines newsletter here.

Thanks to today's episode sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To see Vanta’s platform firsthand and access resources plus a special offer, go to vanta.com/ciso and watch their 3-minute product demo.

View Details

Texas healthcare provider suffer data breach

Entire population of Brazil possibly exposed in data leak

Decryptor for Tortilla ransomware released

Thanks to today's episode sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To see Vanta’s platform firsthand and access resources plus a special offer, go to vanta.com/ciso and watch their 3-minute product demo.

For the stories behind the headlines, head to CISOseries.com.

View Details

Bitcoin price spikes after SEC Twitter account hijack

Twitter account hijack wave affects Mandiant

China claims it cracked Apple AirDrop

Thanks to today's episode sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To see Vanta’s platform firsthand and access resources plus a special offer, go to vanta.com/ciso and watch their 3-minute product demo.

For the stories behind the headlines, head to CISOseries.com.

View Details

Google accounts hacked: No passwords required

loanDepot joins growing list of US mortgage lenders attacked

Netgear and Hyundai’s X accounts latest to be compromised in crypto scam

Thanks to today's episode sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To see Vanta’s platform firsthand and access resources plus a special offer, go to vanta.com/ciso and watch their 3-minute product demo.

View Details

Merck and its insurers settle $1.4 billion NotPetya case

BreachForums admin Popompurin breaches terms of pretrial freedom

Iranian crypto exchange Bit24.cash accidentally exposes customer data

Thanks to today's episode sponsor, Vanta

From dozens of spreadsheets and screenshots to fragmented tools and manual security reviews, managing the requirements for modern compliance and security programs is increasingly challenging. Vanta is the leading Trust Management Platform that helps you centralize your efforts to establish trust and enable growth across your organization. Over 6,000 companies partner with Vanta to automate compliance, strengthen security posture, streamline security reviews, and reduce third-party risk. To see Vanta’s platform firsthand and access resources plus a special offer, go to vanta.com/ciso and watch their 3-minute product demo.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Johna Till Johnson, CEO, Nemertes, and podcaster at Heavy Strategy.

Thanks to our show sponsor, NetSPI

Take the hassle out of dealing with alert fatigue, validation, and prioritization. Instead, use NetSPI’s ASM platform to hone in on what’s actually important. Attack surface vulnerabilities constantly evolve, causing a lack of visibility and overwhelm for your security teams. Start the new year off right by partnering with NetSPI to enhance your security program. Visit netspi.com/ASM

All links and the video of this episode can be found on CISO Series.com

View Details

Mandiant Twitter account restored after crypto scam hack

Law firm that handles data breaches hit by data breach

Spanish mobile carrier suffers outage after account takeover

Thanks to today's episode sponsor, NetSPI

Take the hassle out of dealing with alert fatigue, validation, and prioritization. Instead, use NetSPI's ASM platform to hone in on what's actually important. Attack surface vulnerabilities constantly evolve, causing a lack of visibility and overwhelm for your security teams. Start the new year off right by partnering with NetSPI to enhance your security program. Visit netspi.com/ASM to learn more.

For the stories behind the headlines, head to CISOseries.com.

View Details

A call for formal ban on ransomware payments

FTC asks for ideas to fight voice cloning

Cyberattack impacts French township

Thanks to today's episode sponsor, NetSPI

Take the hassle out of dealing with alert fatigue, validation, and prioritization. Instead, use NetSPI's ASM platform to hone in on what's actually important. Attack surface vulnerabilities constantly evolve, causing a lack of visibility and overwhelm for your security teams. Start the new year off right by partnering with NetSPI to enhance your security program. Visit netspi.com/ASM to learn more.

View Details

Google settles $5 billion ‘incognito mode’ lawsuit

Over $80 million in crypto stolen from Orbit Chain

Watchdog calls for updated medical device cyber agreement

Thanks to today's episode sponsor, NetSPI

Take the hassle out of dealing with alert fatigue, validation, and prioritization. Instead, use NetSPI's ASM platform to hone in on what's actually important. Attack surface vulnerabilities constantly evolve, causing a lack of visibility and overwhelm for your security teams. Start the new year off right by partnering with NetSPI to enhance your security program. Visit netspi.com/ASM to learn more. Take the hassle out of dealing with alert fatigue, validation, and prioritization. Instead, use NetSPI's ASM platform to hone in on what's actually important. Attack surface vulnerabilities constantly evolve, causing a lack of visibility and overwhelm for your security teams. Start the new year off right by partnering with NetSPI to enhance your security program. Visit netspi.com/ASM to learn more.

For the stories behind the headlines, visit CISOseries.com.

View Details

Swedish national grocer stung by Cactus

Flaw in Black Basta decryptor allows recovery of victims’ files - temporarily

Cyberattack hist Boston area hospital

Thanks to today's episode sponsor, NetSPI

Take the hassle out of dealing with alert fatigue, validation, and prioritization. Instead, use NetSPI's ASM platform to hone in on what's actually important. Attack surface vulnerabilities constantly evolve, causing a lack of visibility and overwhelm for your security teams. Start the new year off right by partnering with NetSPI to enhance your security program. Visit netspi.com/ASM to learn more.

For the stories behind the headlines, head to CISOseries.com.

View Details

LockBit hits German hospital system over the holidays

Ohio Lottery cyberattack claimed by DragonForce

First American says funds are secure

Thanks to today's episode sponsor, Barricade Cyber Solutions

Don't let ransomware ruin the holidays again this year! Prepare and spread holiday cheer with recoverfromransomware.com! The trusted DFIR experts at Barricade Cyber Solutions have saved 3,000 and counting businesses from ransomware attacks, including small and medium businesses just like yours! Barricade Cyber is YOUR solution for rapid data and systems recovery. Book a meeting directly with the CEO to discover how to recover from ransomware. Visit recoverfromransomware.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Threat actors install backdoor on Barracuda appliances

iPhone triangulation exploit used undocumented features

New York Times starts the publisher LLM lawsuits

Thanks to today's episode sponsor, Barricade Cyber Solutions

Don't let ransomware ruin the holidays again this year! Prepare and spread holiday cheer with recoverfromransomware.com! The trusted DFIR experts at Barricade Cyber Solutions have saved 3,000 and counting businesses from ransomware attacks, including small and medium businesses just like yours! Barricade Cyber is YOUR solution for rapid data and systems recovery. Book a meeting directly with the CEO to discover how to recover from ransomware. Visit recoverfromransomware.com.

View Details

CBS and Paramount owner hacked a year ago

Rockstar Games allegedly suffers source code leak

LoanCare says 1.3 million people affected by cyberattack

Thanks to today's episode sponsor, Barricade Cyber Solutions

When you're hit with ransomware, remember recoverfromransomware.com. Barricade Cyber Solutions' experienced DFIR team is ready to help your business recover from ransomware now. You'll work directly with the CEO to resolve your case quickly and efficiently. Whether you're experiencing a ransomware attack or want to get ahead of one by discussing a prevention plan, contact Barricade Cyber Solutions at recoverfromransomware.com.

For the stories behind the headlines, visit CISOseries.com.

View Details

First American suffers cyberattack, website down

Iran-linked group targets defense contractors worldwide

November saw record numbers of ransomware leak site victims

Thanks to today's episode sponsor, Barricade Cyber Solutions

Encountering a ransomware attack? Keep cool and reach out to Barricade Cyber Solutions, the trusted DFIR experts. Barricade is known for helping small and medium businesses just like yours restore their business data and successfully recover from ransomware. Escape the ransomware nightmare and bring your business back online now. Contact Barricade Cyber Solutions today at recoverfromransomware.com. That's recoverfromransomware.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Indian tech company HCL investigating ransomware attack

Agent Tesla and an old Microsoft Office vulnerability create new problems

New JavaScript malware targets banks

Thanks to today's episode sponsor, Barricade Cyber Solutions

Is ransomware affecting your business operations? Contact Barricade Cyber Solutions at recoverfromransomware.com. Barricade Cyber Solutions are elite DFIR experts who come to the rescue for businesses like yours daily. The trusted team at Barricade Cyber traces the source of infiltration and fortifies your defenses. Depend on Barricade Cyber Solutions for your data and system security prevention and recovery. Go to recoverfromransomware.com and set up a time to connect with the team today. Again, that's recoverfromransomware.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

BlackCat came back

Child abuse images found in AI datasets

ESO solutions breach impacts million

Thanks to today's episode sponsor, Barricade Cyber Solutions

Has your organization fallen victim to ransomware? Remain calm and head over to recoverfromransomware.com. Barricade Cyber Solutions is the "go-to" for ransomware recovery services that small to medium business executives can trust. Over the past 5 years, Barricade Cyber Solutions has saved 3,000+ businesses in your shoes. Trust the elite DFIR team at Barricade Cyber Solutions with your data and system security recovery. Book a free consultation with the CEO at recoverfromransomware.com now.

View Details

FBI disrupts BlackCat ransomware network

International operation arrests thousands of cybercriminals

Sony’s video game plans leaked by ransomware group

Thanks to today's episode sponsor, Barricade Cyber Solutions

Don't let ransomware ruin your holiday. Remember to visit recoverfromransomware.com! Barricade Cyber Solutions are THE trusted DFIR experts, and they've saved 3,000 and counting businesses from ransomware attacks, small and medium businesses just like yours! Barricade Cyber is YOUR solution for rapid data and security systems recovery. Book a meeting directly with the CEO to discuss securing your future today. Head over to recoverfromransomware.com to learn more.

For the stories behind the headlines, visit CISOseries.com.

View Details

Play ransomware is no game

The return of QakBot

Hacking with Mr. Cooper

Huge thanks to our sponsor, Barricade Cyber Solutions

Facing a ransomware attack? Don't panic, remain calm and remember to contact Barricade Cyber Solutions, the DFIR team trusted to quickly recover business data with exclusive ransomware recovery services for small and medium businesses alike. Recover from ransomware and get your business back online with Barricade Cyber Solutions. Visit recoverfromransomware.com to schedule a call with the team today.

View Details

Box storage platform suffers outage

MongoDB suffers breach

States lag in tackling political deepfakes

Thanks to today's episode sponsor, Barricade Cyber Solutions

Experiencing ransomware? Barricade Cyber Solutions will help you recover from the nightmare. Trust the industry DFIR experts who have rescued over 3,000 businesses cases over the past 5 years. Remember to visit recoverfromransomware.com and connect with Barricade Cyber Solutions rapid ransomware recovery team. This elite team works quickly to recover and restore your business data and services. All you need to remember is recoverfromransomware.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Rusty Waldron, Chief Business Security Officer, ADP

Thanks to our show sponsor, Barricade Cyber Solutions

Are ransomware attackers causing your business MAJOR disruptions? Connect with Barricade Cyber Solutions, the trusted DFIR experts specializing in helping small to medium businesses, like yours, recover from ransomware. Barricade Cyber Solutions has a proven track record of successfully handling over 3,000 business cases and counting with advanced recovery services to quickly restore business data and services. Recover from ransomware with Barricade Cyber Solutions at recoverfromransomware.com.

All links and the video of this episode can be found on CISO Series.com

View Details

French police arrest alleged Hive banker

Train bricking accusations lead to lawsuit against ethical hackers

New Hacker Group ‘GambleForce’ Targets APAC through SQL injection

Thanks to today's episode sponsor, Barricade Cyber Solutions

Has your organization faced a ransomware attack? Keep calm, breathe, and head over to recoverfromransomware.com. Barricade Cyber Solutions is the industry choice for ransomware recovery services that small and medium business leaders can rely on. With a track record of rescuing over 3,000+ businesses like yours in the last 5 years alone, you can trust Barricade Cyber Solutions' elite DFIR team for the recovery of your business' data and systems. Schedule a complimentary consult today at recoverfromransomware.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

UK ransomware report isn’t pretty

MS warns of OAuth abuse

Apple discloses pushback to push notification disclosure

Thanks to today's episode sponsor, Barricade Cyber Solutions

Don't let ransomware ruin the holidays again this year! Prepare and spread holiday cheer with recoverfromransomware.com! The trusted DFIR experts at Barricade Cyber Solutions have saved 3,000 and counting businesses from ransomware attacks, including small and medium businesses just like yours! Barricade Cyber is YOUR solution for rapid data and systems recovery. Book a meeting directly with the CEO to discover how to recover from ransomware. Visit recoverfromransomware.com.

View Details

Cyberattack shuts down Ukrainian telco

Former Uber CISO advocates for CISO protections

GAO report on government AI usage

Thanks to today's episode sponsor, Barricade Cyber Solutions

When you're hit with ransomware, remember recoverfromransomware.com. Barricade Cyber Solutions' experienced DFIR team is ready to help your business recover from ransomware now. You'll work directly with the CEO to resolve your case quickly and efficiently. Whether you're experiencing a ransomware attack or want to get ahead of one by discussing a prevention plan, contact Barricade Cyber Solutions at recoverfromransomware.com.

View Details

US tries to avoid internet fragmentation

EU reaches agreement on AI Act

North Korea finds continued success with Log4Shell

Thanks to today's episode sponsor, Barricade Cyber Solutions

Encountering a ransomware attack? Keep cool and reach out to Barricade Cyber Solutions, the trusted DFIR experts. Barricade is known for helping small and medium businesses just like yours restore their business data and successfully recover from ransomware. Escape the ransomware nightmare and bring your business back online now. Contact Barricade Cyber Solutions today at recoverfromransomware.com. That's recoverfromransomware.com.

View Details

5G network security vulnerabilities discovered, impacting chipset vendors and smartphones

SLAM Spectre-based vulnerability affects CPUs

CISA adds Qlik bugs to exploited vulnerabilities catalog

Thanks to today's episode sponsor, Barricade Cyber Solutions

Caught in a ransomware crisis? Barricade Cyber Solutions is your lifeline for recovery. Trust the industry's experienced DFIR experts, with a track record of saving over 3,000 businesses in the last 5 years. Remember to visit recoverfromransomware.com to connect with Barricade Cyber Solutions' trusted ransomware recovery team. This elite squad moves quickly to restore your business data and services. Visit recoverfromransomware.com today.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Andy Ellis, operating partner YL Ventures

Thanks to our show sponsor, Barricade Cyber Solutions

Are ransomware attackers causing disruptions? Remember to stay composed and immediately contact Barricade Cyber Solutions, the trusted ransomware recovery experts specializing in small to medium businesses. Barricade Cyber Solutions has a proven track record of successfully handling over 3,000 business cases and counting- with advanced recovery services for rapid business restoration. Recover from ransomware with Barricade Cyber Solutions. Visit recoverfromransomware.com to learn more.

All links and the video of this episode can be found on CISO Series.com

View Details

Insurance firm sees cyberattacks as more likely than fire or theft

North Korean hackers steal anti-aircraft system data

Vulnerability discovered in fleet management software

Huge thanks to our sponsor, Barricade Cyber Solutions

Is ransomware affecting your business? Contact Barricade Cyber Solutions at recoverfromransomware.com. Barricade Cyber Solutions are elite DFIR experts who come to the rescue for businesses like yours daily. The trusted team at Barricade Cyber traces the source of infiltration and fortifies your defenses. Depend on Barricade Cyber Solutions for your data and system security. Remember recoverfromransomware.com, that’s recoverfromransomware.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Krebs on ICANN Lookups

Wyden warns of spying push notifications

Google unveils Gemini

Huge thanks to our sponsor, Barricade Cyber Solutions

Has your organization fallen victim to ransomware? Remain calm and head over to recoverfromransomware.com. Barricade Cyber Solutions is the "go-to" for ransomware recovery services that small to medium business executives can trust. Over the past 5 years, Barricade Cyber Solutions has saved 3,000+ businesses in your shoes. Trust the elite DFIR team at Barricade Cyber Solutions with your data and system security recovery. Book a free consultation at recoverfromransomware.com now.

View Details

Spyware trial implicating former Mexican president kicks off

Federal agency breached through Adobe ColdFusion vulnerability

Malicious loan app downloaded 12 million times from Google Play

Huge thanks to our sponsor, Barricade Cyber Solutions

Don't let ransomware ruin your holiday. Remember to visit recoverfromransomware.com! Barricade Cyber Solutions are THE trusted DFIR experts, and they've saved 3,000 and counting businesses from ransomware attacks, small and medium businesses just like yours! Barricade Cyber is YOUR solution for rapid data and security systems recovery. Book a meeting directly with the CEO to discuss securing your future today. Visit recoverfromransomware.com. That's recoverfromransomware.com.

For the stories behind the headlines, visit CISOseries.com.

View Details

UK nuclear site attacked by state-linked attackers

US confirms Iranian actors behind water breaches

The infinite regress of ChatGPT data exfiltration

Huge thanks to our sponsor, Barricade Cyber Solutions

Facing a ransomware attack? Don't panic, remain calm and remember to contact Barricade Cyber Solutions, the DFIR team trusted to quickly recover business data with exclusive ransomware recovery services for small and medium businesses alike. Recover from ransomware and get your business back online with Barricade Cyber Solutions. Visit recoverfromransomware.com to schedule a call with the team today. That's recoverfromransomware.com.

View Details

Credit unions facing outages due to ransomware attack on cloud provider

Roblox, Twitch allegedly targeted by ransomware cartel

Apple fixes two new iOS zero-days in emergency updates

Huge thanks to our sponsor, Barricade Cyber Solutions

Experiencing ransomware? Barricade Cyber Solutions will help you recover from the nightmare. Trust the industry DFIR experts who have rescued over 3,000 business cases over the past 5 years. Remember to visit recoverfromransomware.com and connect with Barricade Cyber Solutions rapid ransomware recovery team. This elite team works quickly to recover and restore your business data and services. Visit recoverfromransomware.com today.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Christina Shannon, CIO, KIK Consumer Products

Thanks to our show sponsor, SpyCloud

SpyCloud disrupts cybercrime by telling you what criminals know about your business and your customers, so you can take action on exposed authentication data to prevent ransomware, session hijacking, account takeover, and online fraud.

With knowledge of the specific data criminals have in hand – like credentials, cookies, and PII compromised by breaches and malware infections – security teams have better visibility into the expanding attack surface that puts their organization at risk of cyberattacks and can respond quickly with SpyCloud’s automated solutions.

Find out what cybercriminals know about your business by visiting spycloud.com/ciso to get your free exposure report. That’s spycloud.com/ciso.

All links and the video of this episode can be found on CISO Series.com

View Details

Manufacturing industry tops cyber extortion trend

Google’s RETVec the latest warrior on bad emails

Zyxel warns of vulnerabilities in NAS devices

Huge thanks to our sponsor, SpyCloud

New research from SpyCloud reveals a critical discovery: nearly a third of ransomware victim companies this year were infected with infostealer malware like Raccoon, Vidar or Redline before they were attacked. These infostealers exfiltrate authentication data from infected systems to aid follow-on attacks – everything from passwords to 2FA codes, and even cookies that enable session hijacking without the need for credentials at all. SpyCloud specializes in recapturing and remediating data siphoned from infostealers to protect businesses and their users from cybercrime. Get SpyCloud’s new research and check your malware exposure at spycloud.com/ciso.

For the stories behind the headlines, head to CISOseries.com.

View Details

All Okta customers exposed in breach

JAXA hit by cyberattack

OpenAI’s chatbots leak secrets

Huge thanks to our sponsor, SpyCloud

For some people ignorance is bliss – but that’s not an option for those of us in cybersecurity. SpyCloud has a free tool that lets you check your company’s darknet exposure, and you might find some things that are pretty alarming. Go to spycloud.com/ciso to see your company's exposure from data breaches and even infostealer malware infections that can open the door to ransomware. SpyCloud’s focus is helping businesses act on what criminals are using right now to target them – addressing stolen passwords, cookies, and even API keys automatically to stop criminals in their tracks. To learn more and get your darknet exposure report, go to spycloud.com/ciso.

View Details

Ransomware gang busted in Ukraine by international operation

North Texas water utility hit with cyberattack

Former Uber CISO speaks out after 6-year silence

Huge thanks to our sponsor, SpyCloud

SpyCloud has discovered that infostealer malware infections are an early warning signal for ransomware. In fact, nearly a third of ransomware victim companies this year were infected with infostealer malware like Raccoon, Vidar or Redline before they were attacked. Are you thinking about infostealers as a precursor to ransomware? SpyCloud believes that knowing what criminals have stolen from your managed, unmanaged and undermanaged infected machines is step one to stopping ransomware attacks. Get SpyCloud’s new research on this topic and check your company’s exposure from malware infections at spycloud.com/ciso.

For the stories behind the headlines, visit CISOseries.com.

View Details

International AI agreement

PA water utility hit by cyberattack

Ukraine claims cyber attack against Russian aviation

Huge thanks to our sponsor, SpyCloud

Our sponsor today, SpyCloud, wants us to pay attention to a ransomware precursor that’s not being talked about enough: infostealer malware. If you think you’re covered by endpoint protection and anti-virus solutions, think again. The SpyCloud team discovered that the presence of infostealers including Racoon, Vidar, and Redline on machines accessing work applications may indicate a likely future ransomware attack. They believe the first step in thwarting ransomware lies in knowing the data criminals have stolen from malware-infected systems and remediating it quickly. Get SpyCloud’s new research and check your malware exposure at spycloud.com/ciso.

View Details

London & Zurich, and Fidelity National Financial attacks

Royal Family’s hospital and Vanderbilt University Med Center suffer cybersecurity incidents

Gulf Air exposed to data breach

Huge thanks to our sponsor, SpyCloud

For some people ignorance is bliss – but that’s not an option for those of us in cybersecurity. SpyCloud has a free tool that lets you check your company’s darknet exposure, and you might find some things that are pretty alarming. Go to spycloud.com/ciso to see your company's exposure from data breaches and even infostealer malware infections that can open the door to ransomware. SpyCloud’s focus is helping businesses act on what criminals are using right now to target them – addressing stolen passwords, cookies, and even API keys automatically to stop criminals in their tracks. To learn more and get your darknet exposure report, go to spycloud.com/ciso.

View Details

Cyber exec admits hacking hospital as a sales tactic

‘Citrix Bleed’ vulnerability targeted by nation-state hackers

Binance CEO steps down in $4 billion settlement

Thanks to today's episode sponsor, Egress

People are the biggest risk to your organizations' security and they are most vulnerable when using email. Egress is the only cloud email security platform to use an adaptive security architecture to automate threat detection and response for advanced phishing attacks and outbound data breaches, tailoring the experience for each user based on their real-time risk score. Visit egress.com to learn more about Egress’ Intelligent Cloud Email Security suite and start detecting email threats your existing solution is missing today.

For the stories behind the headlines, visit CISOseries.com.

View Details

Healthcare platform impacted by MOVEit

Threat actors find a use for trigonometry

What’s happening with OpenAI

Thanks to today's episode sponsor, Egress

People are the biggest risk to your organizations' security and they are most vulnerable when using email. Egress is the only cloud email security platform to use an adaptive security architecture to automate threat detection and response for advanced phishing attacks and outbound data breaches, tailoring the experience for each user based on their real-time risk score. Visit egress.com to learn more about Egress’ Intelligent Cloud Email Security suite and start detecting email threats your existing solution is missing today.

View Details

Clorox CISO departs months after cyberattack

ALPHV/BlackCat Ransomware gang files SEC complaint

Drenan Dudley acting national cyber director while Coker confirmation process continues

Thanks to today's episode sponsor, Egress

People are the biggest risk to your organizations' security and they are most vulnerable when using email. Egress is the only cloud email security platform to use an adaptive security architecture to automate threat detection and response for advanced phishing attacks and outbound data breaches, tailoring the experience for each user based on their real-time risk score. Visit egress.com to learn more about Egress’ Intelligent Cloud Email Security suite and start detecting email threats your existing solution is missing today.

For the stories behind the headlines, head to CISOseries.com

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Jay Wilson, CISO, Insurity

Thanks to our show sponsor, Sysdig

For businesses innovating in the cloud, every second counts. Sysdig strengthens cyber resilience by reducing the attack surface, detecting threats in real time, and accelerating incident response. Our platform correlates signals across cloud workloads, identities, and services to enable businesses to prioritize risks and act decisively. Sysdig. Secure every second. Learn more at Sysdig.com

All links and the video of this episode can be found on CISO Series.com

View Details

Fortinet warns of critical command injection bug in FortiSIEM

Another data breach for Samsung

Rhysida warning from FBI and CISA

Thanks to today's episode sponsor, Sysdig

For businesses innovating in the cloud, every second counts. Sysdig strengthens cyber resilience by reducing the attack surface, detecting threats in real time, and accelerating incident response. Our platform correlates signals across cloud workloads, identities, and services to enable businesses to prioritize risks and act decisively. Sysdig. Secure every second.

For the stories behind the headlines, head to CISOseries.com.

View Details

Microsoft goes all in on Copilot

YouTube’s AI disclosure requirement

CISA’s AI Roadmap

Thanks to today's episode sponsor, Sysdig

For businesses innovating in the cloud, every second counts. Sysdig strengthens cyber resilience by reducing the attack surface, detecting threats in real time, and accelerating incident response. Our platform correlates signals across cloud workloads, identities, and services to enable businesses to prioritize risks and act decisively. Sysdig. Secure every second.

View Details

IPStorm botnet dismantled after hacker’s guilty plea

Federal court rules social media giants must face child safety lawsuits

Authorities warn of Royal ransom gang’s activities and rebranding

Thanks to today's episode sponsor, Sysdig

For businesses innovating in the cloud, every second counts. Sysdig strengthens cyber resilience by reducing the attack surface, detecting threats in real time, and accelerating incident response. Our platform correlates signals across cloud workloads, identities, and services to enable businesses to prioritize risks and act decisively. Sysdig. Secure every second. For businesses innovating in the cloud, every second counts. Sysdig strengthens cyber resilience by reducing the attack surface, detecting threats in real time, and accelerating incident response. Our platform correlates signals across cloud workloads, identities, and services to enable businesses to prioritize risks and act decisively. Sysdig. Secure every second.

For the stories behind the headlines, visit CISOseries.com.

View Details

Australian ports hit with cyberattack

AI companies join on to Christchurch Call to Action

Generative AI threatens to dismantle terrorist content detection

Thanks to today's episode sponsor, Sysdig

For businesses innovating in the cloud, every second counts. Sysdig strengthens cyber resilience by reducing the attack surface, detecting threats in real time, and accelerating incident response. Our platform correlates signals across cloud workloads, identities, and services to enable businesses to prioritize risks and act decisively. Sysdig. Secure every second.

View Details

Industrial and Commercial Bank of China suffers ransomware attack

UK health data donated for medical research shared with insurance companies

Boeing data published by LockBit

Thanks to today's episode sponsor, Sysdig

For businesses innovating in the cloud, every second counts. Sysdig strengthens cyber resilience by reducing the attack surface, detecting threats in real time, and accelerating incident response. Our platform correlates signals across cloud workloads, identities, and services to enable businesses to prioritize risks and act decisively. Sysdig. Secure every second.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Sean Kelly with guest Howard Holton, CTO, GigaOm

Thanks to today’s episode sponsor, OffSec

OffSec (formerly Offensive Security), the cyber training company behind the well-known OSCP certification and Kali Linux distro, is hosting a virtual summit for CISOs and Cybersecurity leaders called Evolve on November 15th. During the event, you’ll learn how to attract and assess top talent, how to craft positioning for budget conversations, why CISOs make great board members, and more. Hear from forward-thinking infosec leaders from companies like CISCO, Amazon, and Salesforce. Save your seat and equip yourself with actionable takeaways to help shape the future of your organization’s security. Register now at offsec.com/evolve

All links and the video of this episode can be found on CISO Series.com

View Details

US most breached country last quarter

OpenAI blames DDoS attacks for ongoing ChatGPT outages

Clop exploits SysAid vulnerability

Thanks to today's episode sponsor, OffSec

And now a word from our sponsor. OffSec (formerly Offensive Security), the cyber training company behind the well-known OSCP certification and Kali Linux distro, is hosting a virtual summit for CISOs and Cybersecurity leaders called Evolve on November 15th. During the event, you'll learn how to attract and assess top talent, how to craft positioning for budget conversations, why CISOs make great board members, and more. Hear from forward-thinking infosec leaders from companies like CISCO, Amazon, and Salesforce. Save your seat and equip yourself with actionable takeaways to help shape the future of your organization's security. Register now at offsec.com/evolve

For the stories behind the headlines, head to CISOseries.com.

View Details

US launches “Shields Ready” campaign

Microsoft and Meta announced AI imagery rules

App Defense Alliance moves under the Linux Foundation

Thanks to today's episode sponsor, OffSec

And now a word from our sponsor. OffSec (formerly Offensive Security), the cyber training company behind the well-known OSCP certification and Kali Linux distro, is running a virtual summit for CISOs and Cybersecurity leaders called Evolve on November 15th. Attend Evolve and get insider insights from a former bank hacker. Discover strategies on stretching your security budget and get tips to attract the crème de la crème of talent. It's more than just an event – it's a masterclass helping you elevate your cybersecurity leadership game. Hear from forward-thinking cybersecurity leaders from companies like CISCO, Amazon, Salesforce and more. Register today and get the insights you need to help shape the future of your company’s security. Sign up now at offsec.com/evolve

View Details

Singapore’s Marina Bay Sands customer data stolen in cyberattack

Atlassian bug escalated to 10.0 severity

Fake Ledger Live app steals over $700,000 in crypto

Thanks to today's episode sponsor, OffSec

And now a word from our sponsor. OffSec (formerly Offensive Security), the cyber training company behind the well-known OSCP certification and Kali Linux distro, is hosting a virtual summit for CISOs and Cybersecurity leaders called Evolve on November 15th. During the event, you'll learn how to attract and assess top talent, how to craft positioning for budget conversations, why CISOs make great board members, and more. Hear from forward-thinking infosec leaders from companies like CISCO, Amazon, and Salesforce. Save your seat and equip yourself with actionable takeaways to help shape the future of your organization's security. Register now at offsec.com/evolve

For the stories behind the headlines, visit CISOseries.com.

View Details

Android Dropper-as-a-Service Bypasses Google’s Defenses

Increase in zero-day exploits worries CISA

Google Calendar as a C2 infrastructure

Thanks to today's episode sponsor, OffSec

And now a word from our sponsor. OffSec (formerly Offensive Security), the cyber training company behind the well-known OSCP certification and Kali Linux distro, is running a virtual summit for CISOs and Cybersecurity leaders called Evolve on November 15th. Attend Evolve and get insider insights from a former bank hacker. Discover strategies on stretching your security budget and get tips to attract the crème de la crème of talent. It's more than just an event – it's a masterclass helping you elevate your cybersecurity leadership game. Hear from forward-thinking cybersecurity leaders from companies like CISCO, Amazon, Salesforce and more. Register today and get the insights you need to help shape the future of your company’s security. Sign up now at offsec.com/evolve

For the stories behind the headlines, head to CISOseries.com.

View Details

Okta explains hack source and response timeline

Looney Tunables now being exploited

Lazarus Group uses KandyKorn against blockchain engineers

Thanks to today's episode sponsor, OffSec

And now a word from our sponsor. OffSec (formerly Offensive Security), the cyber training company behind the well-known OSCP certification and Kali Linux distro, is hosting a virtual summit for CISOs and Cybersecurity leaders called Evolve on November 15th. During the event, you'll learn how to attract and assess top talent, how to craft positioning for budget conversations, why CISOs make great board members, and more. Hear from forward-thinking infosec leaders from companies like CISCO, Amazon, and Salesforce. Save your seat and equip yourself with actionable takeaways to help shape the future of your organization's security. Register now at offsec.com/evolve

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Shawn Bowen, CISO, World Kinect Corporation

Thanks to our show sponsor, Hunters

There’s nothing worse than relying on a legacy SIEM that your security team has out-grown, especially when it impacts your ability to detect real incidents. Hunters’ SOC Platform offers built-in, always up-to-date detection rules and automatic correlation that allow SOC analysts to focus on higher-value tasks that impact your organization. It’s time to move to a platform that reduces risk, complexity & cost for the SOC. Visit hunters.security to learn how you can replace your SIEM today.

All links and the video of this episode can be found on CISO Series.com

View Details

Power outage darkens Cloudflare dashboard and APIs

Apache ActiveMQ flaw sees HelloKitty attempt

Boeing says cyber incident affects parts and distribution

Thanks to today's episode sponsor, Hunters

There’s nothing worse than relying on a legacy SIEM that your security team has out-grown, especially when it impacts your ability to detect real incidents. Hunters’ SOC Platform offers built-in, always up-to-date detection rules and automatic correlation that allow SOC analysts to focus on higher-value tasks that impact your organization. It’s time to move to a platform that reduces risk, complexity & cost for the SOC. Visit hunters.security to learn how you can replace your SIEM today.

For the stories behind the headlines, head to CISOseries.com.

View Details

Countries at UK summit pledge to tackle AI risks

‘Kill switch’ deliberately shuts down notorious botnet

EU regulator bans Meta's targeted advertising practices

Thanks to today's episode sponsor, Hunters

There’s nothing worse than relying on a legacy SIEM that your security team has out-grown, especially when it impacts your ability to detect real incidents. Hunters’ SOC Platform offers built-in, always up-to-date detection rules and automatic correlation that allow SOC analysts to focus on higher-value tasks that impact your organization. It’s time to move to a platform that reduces risk, complexity & cost for the SOC. Visit hunters.security to learn how you can replace your SIEM today. There’s nothing worse than relying on a legacy SIEM that your security team has out-grown, especially when it impacts your ability to detect real incidents. Hunters’ SOC Platform offers built-in, always up-to-date detection rules and automatic correlation that allow SOC analysts to focus on higher-value tasks that impact your organization. It’s time to move to a platform that reduces risk, complexity & cost for the SOC. Visit hunters.security to learn how you can replace your SIEM today.

For the stories behind the headlines, visit CISOseries.com.

View Details

Canada bans WeChat on government devices

40 countries sign no ransom pledge

Apple warns Indian opposition leaders about iPhone attacks

Thanks to today's episode sponsor, Hunters

If your SIEM is causing an endless cycle of noisy alerts, manually writing generic detection rules, and limited data ingestion & retention, your SOC might need an upgrade. Hunters is a SaaS platform, purpose built for your Security Operations team. Solaris Group, a leading German FinTech, implemented Hunters to replace their SIEM eliminating the burden of redundant detection engineering and manual event correlation. Solaris Group’s SOC analysts can now focus their time and energy on higher-value tasks. Visit hunters.security to learn how to replace your SIEM today.

View Details

Executive order outlines generative AI rules in the US

Russia launchings its own VirusTotal

Roaming data could leak geolocations

Thanks to today's episode sponsor, Hunters

Piecing together a SIEM not only takes forever, but it wastes your security team’s valuable resources. Hunters is a SIEM alternative purpose built to help your Security Operations mature to the next level in a fraction of the time. Spontnana, a next-generation Travel-as-a-Service platform, uses Hunters’ built-in correlation and enrichment capabilities to make better security decisions and experienced value from day one. Are you ready to evaluate Hunters as a SIEM alternative? Visit Hunters.security to learn more.

View Details

DC Board of Elections breach may include entire voter roll

LockBit claims Boeing breach

StripedFly malware infects 1 million Windows and Linux hosts

Thanks to today's episode sponsor, Hunters

Hunters is a SIEM alternative, built for your security team. Hunters empowers companies to replace their SIEM with unlimited ingestion and normalization of security data at a predictable cost. Using Hunters, a CISO at a leading online retailer “tripled the amount of data ingested by her security team while cutting costs from a legacy SIEM provider by 75%.” To learn more about the benefits of replacing your legacy SIEM with Hunters visit hunters.security today.

For the stories behind the headlines, head to CISOseries.com

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Arvin Bansal, former CISO, Nissan Americas

Thanks to our show sponsor, Vanta

Growing a business? That likely means more tools, third-party vendors, and data sharing — AKA, way more risk.

Vanta's market-leading trust management platform brings GRC and security efforts together. Integrate information from multiple systems and reduce risks to your business and your brand — all without the need for additional staffing.

And by automating up to 90% of the work for SOC 2, ISO 27001, and more, you’ll be able to focus on strategy and security, not maintaining compliance.

Join 5,000 fast-growing companies that leverage Vanta to manage risk and prove security in real-time. Our listeners get $1,000 off Vanta. Go to vanta.com/ciso to claim this discount.

All links and the video of this episode can be found on CISO Series.com

View Details

ILeakage attack steals emails, passwords from Apple devices and browsers

CISA protests potential 25% budget cut as “catastrophic”

Surge in hyper-volumetric HTTP DDoS attacks

Thanks to today's episode sponsor, Vanta

View Details

SMIC making advanced chips with ASML tech

Roundcube webmail exploited with zero-day

Philadelphia’s week somehow gets worse

Thanks to today's episode sponsor, Vanta

View Details

Cisco IOS XE Update: Number of infected devices via zero-day remains high

California sidelines GM’s driverless cars, citing safety risk

Canada accuse China of ‘Spamouflage’ disinformation campaign

Thanks to today's episode sponsor, Vanta

View Details

Chrome testing IP Protection

Microsoft tests Security Copilot

Cisco releases IOS XE patches

Thanks to today's episode sponsor, Vanta

View Details

Okta HAR support system attacked

Cisco identifies additional IOS XE vulnerability

Key Ragnar Locker player arrested in Paris

Thanks to today's episode sponsor, Vanta

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Andrew Wilder, CISO, Community Veterinary Partners

Thanks to our show sponsor, Vanta

“Growing a business? That likely means more tools, third-party vendors, and data sharing — AKA, way more risk. Vanta’s market-leading trust management platform brings GRC and security efforts together. Integrate information from multiple systems and reduce risks to your business and your brand — all without the need for additional staffing. And by automating up to 90% of the work for SOC 2, ISO 27001, and more, you’ll be able to focus on strategy and security, not maintaining compliance. Join 5,000 fast-growing companies that leverage Vanta to manage risk and prove security in real-time. Our listeners get $1,000 off Vanta. Go to vanta.com/ciso to claim this discount.

All links and the video of this episode can be found on CISO Series.com

View Details

International sting operation brings down RagnarLocker

More 23andMe records leaked

Casio discloses data breach

Huge thanks to our sponsor, Vanta

Growing a business? That likely means more tools, third-party vendors, and data sharing — AKA, way more risk. Vanta's market-leading trust management platform brings GRC and security efforts together. Integrate information from multiple systems and reduce risks to your business and your brand — all without the need for additional staffing. And by automating up to 90% of the work for SOC 2, ISO 27001, and more, you’ll be able to focus on strategy and security, not maintaining compliance. Join 5,000 fast-growing companies that leverage Vanta to manage risk and prove security in real-time. Our listeners get $1,000 off Vanta. Go to vanta.com/ciso to claim this discount.

For the stories behind the headlines, head to CISOseries.com.

View Details

State-backed attackers exploit WinRAR zero-day

Five Eyes warns of Chinese IP theft

ServiceNow data exposure issue identified

Huge thanks to our sponsor, Vanta

Growing a business? That likely means more tools, third-party vendors, and data sharing — AKA, way more risk. Vanta's market-leading trust management platform brings GRC and security efforts together. Integrate information from multiple systems and reduce risks to your business and your brand — all without the need for additional staffing. And by automating up to 90% of the work for SOC 2, ISO 27001, and more, you’ll be able to focus on strategy and security, not maintaining compliance. Join 5,000 fast-growing companies that leverage Vanta to manage risk and prove security in real-time. Our listeners get $1,000 off Vanta. Go to vanta.com/ciso to claim this discount.

View Details

Zero-day attacks affect over 10,000 Cisco devices

US government warns of widespread exploitation of Confluence vulnerability

D-Link confirms data breach caused by phishing attack

Huge thanks to our sponsor, Vanta

Growing a business? That likely means more tools, third-party vendors, and data sharing — AKA, way more risk. Vanta's market-leading trust management platform brings GRC and security efforts together. Integrate information from multiple systems and reduce risks to your business and your brand — all without the need for additional staffing. And by automating up to 90% of the work for SOC 2, ISO 27001, and more, you’ll be able to focus on strategy and security, not maintaining compliance. Join 5,000 fast-growing companies that leverage Vanta to manage risk and prove security in real-time. Our listeners get $1,000 off Vanta. Go to vanta.com/ciso to claim this discount.

For the stories behind the headlines, visit CISOseries.com.

View Details

Israeli government warns to secure home security cameras

Signal debunks zero-day report

Equifax fined for 2017 data breach

Huge thanks to our sponsor, Vanta

Growing a business? That likely means more tools, third-party vendors, and data sharing — AKA, way more risk. Vanta's market-leading trust management platform brings GRC and security efforts together. Integrate information from multiple systems and reduce risks to your business and your brand — all without the need for additional staffing. And by automating up to 90% of the work for SOC 2, ISO 27001, and more, you’ll be able to focus on strategy and security, not maintaining compliance. Join 5,000 fast-growing companies that leverage Vanta to manage risk and prove security in real-time. Our listeners get $1,000 off Vanta. Go to vanta.com/ciso to claim this discount.

View Details

LockBit claims attack on CDW

FBI and CISA publish joint advisory regarding AvosLocker ransomware

EPA rescinds cyber regulations for water sector

Huge thanks to our sponsor, Vanta

Growing a business? That likely means more tools, third-party vendors, and data sharing — AKA, way more risk. Vanta's market-leading trust management platform brings GRC and security efforts together. Integrate information from multiple systems and reduce risks to your business and your brand — all without the need for additional staffing. And by automating up to 90% of the work for SOC 2, ISO 27001, and more, you’ll be able to focus on strategy and security, not maintaining compliance. Join 5,000 fast-growing companies that leverage Vanta to manage risk and prove security in real-time. Our listeners get $1,000 off Vanta. Go to vanta.com/ciso to claim this discount.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review, is hosted by Rich Stroffolino with guest Martin Choluj, VP Security ClickHouse

Thanks to our show sponsor, Hyperproof

Are you struggling to showcase the value of your work? It’s a classic challenge in the risk and compliance space: leadership just doesn’t understand what exactly you do and why it matters. With Hyperproof, the leading risk and compliance management platform, you get access to real-time reports that can help your leadership team understand the impact of the valuable work you do every day. Get a demo at hyperproof.io.

All links and the video of this episode can be found on CISO Series.com

View Details

Microsoft thwarts large-scale ransomware attack

Former Uber CISO files appeal

ToddyCat group targets telcos

Thanks to today's episode sponsor, Hyperproof

Is your company scaling? Do you need to quickly add more compliance frameworks but don’t know where to start? Hyperproof has you covered. Hyperproof is a risk and compliance management platform that can help you manage compliance at scale. With Hyperproof, you can quickly add new frameworks, crosswalk controls between frameworks, view your risk posture, and manage your risks, all in one place. Visit hyperproof.io to get started today.

View Details

404 pages hijacked

Atlassian Confluence attacked by state-backed actors

Adobe’s “icon of transparency”

Thanks to today's episode sponsor, Hyperproof

It’s more critical than ever to focus on strategically addressing risk, but how can you do it when working with limited resources? That’s where Hyperproof comes in: Hyperproof is a risk and compliance operations platform that helps you automate evidence collection, task management, and collaboration within your organization so you can focus on what matters most: keeping your company secure by prioritizing strategy, not manual processes. Get a demo at Hyperproof.io.

View Details

Internet-wide zero-day bug fuels largest-ever DDoS attack

23andMe resets user passwords after genetic data posted online

Microsoft Exchange gets ‘better’ patch to mitigate critical bug

Thanks to today's episode sponsor, Hyperproof

We get it. You’re a risk manager or compliance professional, and you’re overworked. You’re trying to do the right thing by keeping your company safe and secure, but your technology is holding you back. Why not upgrade to Hyperproof? Hyperproof is a platform that not only eliminates the manual tasks you dread, but helps you scale security. Get a demo today at hyperproof.io.

For the stories behind the headlines, visit CISOseries.com.

View Details

Hacktivist attacks abound in the Middle East

Network protocol open-source tool Curl faces worst security flaw in a long time

HelloKitty ransomware source code leaked on hacking forum

Thanks to today's episode sponsor, Hyperproof

Imagine. You have an audit coming up, but instead of the usual rush, you actually feel prepared. You’ve collected your evidence. You can see which risks have been mitigated. And best of all, you don’t have to send out any last-minute emails to other teams begging them for that one screenshot. Sounds like a dream, right? With Hyperproof’s risk and compliance platform, this could be your reality. Get a demo at hyperproof.io.

For the stories behind the headlines, head to CISOseries.com.

View Details

MGM Resorts quotes ransomware tab at $110 million

Blackbaud in $49.5 million settlement for May 2020 ransomware attack

23andMe investigates breach claims

Thanks to today's episode sponsor, Hyperproof

Tired of managing risk and compliance in spreadsheets? Sick of tracking down stakeholders to find evidence? Worried about whether that evidence is up to date for your next audit? Hyperproof has you covered. With Hyperproof, you can efficiently manage multiple compliance frameworks and risks in a single place so you can focus on what matters most: keeping your company secure and growing. Visit hyperproof.io to get a demo.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review, is hosted by Rich Stroffolino with guest Bob Schuetter, CISO, Ashland

Thanks to our show sponsor, Conveyor

Got a scary security questionnaire to complete and you’d rather have AI do it? Your infosec friends are making the switch from outdated RFP and compliance tools to Conveyor: the most accurate security questionnaire automation software on the market. The proof is in the AI. Customers are seeing 80-90% accurate auto-generated answers by and decreasing the time spent on questionnaire answering by 91%. Try a free one-week proof of concept at www.conveyor.com.

All links and the video of this episode can be found on CISO Series.com

View Details

Apple rolls out patch for active iOS Zero-Day

Cisco patches urgent Emergency Responder flaw

Researchers warn of 100,000 exposed ICS systems

Thanks to our episode sponsor, Conveyor

We can all agree that AI can take one job from us: answering security questionnaires. Enter Conveyor: the AI security review platform helping infosec teams attack security questionnaires from all angles. Reduce incoming questionnaires by sharing a trust portal with customers and for those questionnaires you do get, use our AI questionnaire completion tool to auto-generate precise answers to entire questionnaires in seconds. Lucid tried a free one week proof of concept and reduced time spent on questionnaires by 91%. Learn more at www.conveyor.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Red Cross issues hacktivist rules

Looney Tunables hits major Linux distros

CISA may have violated the First Amendment

Thanks to our episode sponsor, Conveyor

Will security questionnaires ever go away? Maybe. But as long as they’re still here, you might as well get AI to complete them for you. Enter Conveyor. The AI security questionnaire automation software that auto-generates 80-90% accurate answers to entire questionnaires in seconds so all you have to do is review. There’s even a browser extension for the world’s worst portals. Not sure if it’ll work for you? Try a free one-week proof of concept at www.conveyor.com.

View Details

Arm and Qualcomm warn about exploited GPU drivers

EU Parliament strengthens spyware protections for journalists

NSA creates AI Security Center

Thanks to our episode sponsor, Conveyor

Does the mountain of security questionnaires in your inbox make you feel like a 2 dollar umbrella in a hurricane? Then you might want to check out Conveyor: the AI security review platform helping infosec teams attack security questionnaires from all angles. Reduce incoming questionnaires by sharing a trust portal with customers and for those questionnaires you do get, use our AI questionnaire completion tool to auto-generate precise answers to entire questionnaires in seconds. Lucid tried a free one week proof of concept and reduced time spent on questionnaires by 91%. Learn more at www.conveyor.com.

View Details

Critical Progress FTP bug now being exploited in attacks

Norway urges Europe-wide ban on Meta's targeted data collection

KillNet claims DDoS attack against Royal Family website

Thanks to our episode sponsor, Conveyor

Got a scary security questionnaire to complete and you’d rather have AI do it? Your infosec friends are making the switch from outdated RFP and compliance tools to Conveyor: the most accurate security questionnaire automation software on the market. The proof is in the AI. Customers are seeing 80-90% accurate auto-generated answers by and decreasing the time spent on questionnaire answering by 91%. Try a free one-week proof of concept at www.conveyor.com.

For the stories behind the headlines, visit CISOseries.com.

View Details

Cloudflare DDoS protections bypassed using Cloudflare

McLaren Health Care becomes latest ALPHV/BlackCat victim

Lazarus Group poses as Meta recruiters to spearfish Spanish engineers

Thanks to our episode sponsor, Conveyor

Does the thought of answering another security questionnaire make you want to beat the stuffing out of 32 pinatas?

Then you might want to check out Conveyor: the AI security review platform helping infosec and sales teams attack security questionnaires from all angles.

Reduce incoming questionnaires by sharing a trust portal with customers and for those questionnaires you do get, use our AI questionnaire completion tool to auto-generate precise answers to entire questionnaires in seconds.

Lucid tried a free one week proof of concept and reduced time spent on questionnaires by 91%. Learn more at www.conveyor.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review, is hosted by Rich Stroffolino with guest Andrew Storms, VP of security, Replicated

Thanks to our show sponsor, AppOmni

Are you confident in your organization’s SaaS security? AppOmni surveyed 600+ security practitioners globally and 71% answered yes. But 79% experienced SaaS cybersecurity incidents. What’s behind this disconnect?

CISOs believe they have a mature level of SaaS cybersecurity using CASB, MFA, and IdP. But these solutions lack unified risk visibility. Without SSPM, they’re blind to the true extent of their SaaS attack surface risk. Don’t gamble with your data. Get the visibility and insights you need to protect your SaaS environment with AppOmni.

All links and the video of this episode can be found on CISO Series.com

View Details

Chinese hackers stole emails from US State Dept in Microsoft breach

Johnson Controls faces $51 million ransomware demand

Google fixes year’s fifth Chrome zero-day

Thanks to today's episode sponsor, AppOmni

If you think CASBs effectively secure your SaaS data… think again. CASBs lack visibility into your SaaS estate. Nor can they address and detect risks that arise from SaaS apps’ unlimited endpoints. What you need is a robust SSPM designed to secure the dynamic and extensible nature of SaaS apps and their data. That’s where AppOmni comes in. We continuously monitor your SaaS estate to detect cyber risks and secure your company’s most critical data and workflows. Get started at AppOmni.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

GPUs vulnerable to pixel-stealing attacks

Info-stealing commits hit GitHub

Alleged Sony hackers hit NTT Docomo

Thanks to today's episode sponsor, AppOmni

Are you confident in your organization’s SaaS security? AppOmni surveyed 600+ security practitioners globally and 71% answered yes. But 79% experienced SaaS cybersecurity incidents. What’s behind this disconnect? CISOs believe they have a mature level of SaaS cybersecurity using CASB, MFA, and IdP. But these solutions lack unified risk visibility. Without SSPM, they’re blind to the true extent of their SaaS attack surface risk. Don’t gamble with your data. Get the visibility and insights you need to protect your SaaS environment with AppOmni.

View Details

Multiple threat actors lay claim to Sony hack

Philippines health org struggling to recover from ransomware attack

Canadian Flair Airlines leaked user data for months

Thanks to today's episode sponsor, AppOmni

If you think CASBs effectively secure your SaaS data… think again. CASBs lack visibility into your SaaS estate. Nor can they address and detect risks that arise from SaaS apps’ unlimited endpoints. What you need is a robust SSPM designed to secure the dynamic and extensible nature of SaaS apps and their data. That’s where AppOmni comes in. We continuously monitor your SaaS estate to detect cyber risks and secure your company’s most critical data and workflows. Get started at AppOmni.com.

For the stories behind the headlines, visit CISOseries.com.

View Details

Mixin Network loses $200 million

Kia and Hyundai exploit linked to massive car thefts

Stress testing voting equipment

Thanks to today's episode sponsor, AppOmni

Are you confident in your organization’s SaaS security? AppOmni surveyed 600+ security practitioners globally and 71% answered yes. But 79% experienced SaaS cybersecurity incidents. What’s behind this disconnect? CISOs believe they have a mature level of SaaS cybersecurity using CASB, MFA, and IdP. But these solutions lack unified risk visibility. Without SSPM, they’re blind to the true extent of their SaaS attack surface risk. Don’t gamble with your data. Get the visibility and insights you need to protect your SaaS environment with AppOmni.

View Details

Car audio manufacturer Clarion hacked – ALPHV claims responsibility

High-ranking Egyptian politician targeted by Predator spyware

City of Dallas issues report on May cyberattack

Thanks to today's episode sponsor, AppOmni

If you think CASBs effectively secure your SaaS data… think again. CASBs lack visibility into your SaaS estate. Nor can they address and detect risks that arise from SaaS apps’ unlimited endpoints. What you need is a robust SSPM designed to secure the dynamic and extensible nature of SaaS apps and their data. That’s where AppOmni comes in. We continuously monitor your SaaS estate to detect cyber risks and secure your company’s most critical data and workflows. Get started at AppOmni.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review, is hosted by Rich Stroffolino with guest Shawn Bowen, CISO, World Kinect Corporation

Thanks to our show sponsor, Hyperproof

Is your company scaling? Do you need to quickly add more compliance frameworks but don’t know where to start? Hyperproof has you covered. Hyperproof is a risk and compliance management platform that can help you manage compliance at scale. With Hyperproof, you can quickly add new frameworks, crosswalk controls between frameworks, view your risk posture, and manage your risks, all in one place. Visit hyperproof.io to get started today.

All links and the video of this episode can be found on CISO Series.com

View Details

UK launches comprehensive new online safety laws

Cisco buys Splunk

TransUnion denies breach

Huge thanks to our sponsor, Hyperproof

Is your company scaling? Do you need to quickly add more compliance frameworks but don’t know where to start? Hyperproof has you covered. Hyperproof is a risk and compliance management platform that can help you manage compliance at scale. With Hyperproof, you can quickly add new frameworks, crosswalk controls between frameworks, view your risk posture, and manage your risks, all in one place. Visit hyperproof.io to get started today.

For the stories behind the headlines, head to CISOseries.com.

View Details

Cyber attack disrupted Canadian airports

Huawei ships chips for surveillance cameras

Signal adds quantum-resistant encryption

Huge thanks to our sponsor, Hyperproof

It’s more critical than ever to focus on strategically addressing risk, but how can you do it when working with limited resources? That’s where Hyperproof comes in: Hyperproof is a risk and compliance operations platform that helps you automate evidence collection, task management, and collaboration within your organization so you can focus on what matters most: keeping your company secure by prioritizing strategy, not manual processes. Get a demo at Hyperproof.io.

View Details

DHS council seeks to simplify cyber incident reporting rules

UK passes the Online Safety Bill

Finland and Europol take down PIILOPUOTI marketplace

Huge thanks to our sponsor, Hyperproof

We get it. You’re a risk manager or compliance professional, and you’re overworked. You’re trying to do the right thing by keeping your company safe and secure, but your technology is holding you back. Why not upgrade to Hyperproof? Hyperproof is a platform that not only eliminates the manual tasks you dread, but helps you scale security. Get a demo today at hyperproof.io.

For the stories behind the headlines, visit CISOseries.com.

View Details

Microsoft leaks terabytes of internal data

UK CMA outlines principles for AI regulation

Germany warns of attacks on LNG terminals

Huge thanks to our sponsor, Hyperproof

Imagine. You have an audit coming up, but instead of the usual rush, you actually feel prepared. You’ve collected your evidence. You can see which risks have been mitigated. And best of all, you don’t have to send out any last-minute emails to other teams begging them for that one screenshot. Sounds like a dream, right? With Hyperproof’s risk and compliance platform, this could be your reality. Get a demo at hyperproof.io.

View Details

Lazarus Group suspected in CoinEx robbery

Thailand financial company CardX discloses leak

Ransomware hits trucking software provider

Huge thanks to our sponsor, Hyperproof

Tired of managing risk and compliance in spreadsheets? Sick of tracking down stakeholders to find evidence? Worried about whether that evidence is up to date for your next audit? Hyperproof has you covered. With Hyperproof, you can efficiently manage multiple compliance frameworks and risks in a single place so you can focus on what matters most: keeping your company secure and growing. Visit hyperproof.io to get a demo.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review, is hosted by Rich Stroffolino with guest Davi Ottenheimer, VP, Trust and Ethics, Inrupt

Thanks to our show sponsor, Conveyor

The team at Lucid software reduced the time spent answering customer security questionnaires by a whopping 91% with Conveyor’s security questionnaire automation software – powered by OpenAI. Compared to the tools on the market, Conveyor’s AI auto-generates the most accurate answers to entire questionnaires so you can spend almost zero time on them. That’s it. That’s the ad. We’ll let you get back to the show, but if you want to take away the pain of questionnaires, try a free proof of concept at www.conveyor.com.

All links and the video of this episode can be found on CISO Series.com

View Details

Caesars reportedly paid millions to stop Scattered Spider

Cybersecurity incident impacts Canada’s Weather Network

Blocked LockBit affiliate deploys 3AM instead

Huge thanks to our sponsor, Conveyor

The team at Lucid software reduced the time spent answering customer security questionnaires by a whopping 91% with Conveyor’s security questionnaire automation software - powered by OpenAI. Compared to the tools on the market, Conveyor’s AI auto-generates the most accurate answers to entire questionnaires so you can spend almost zero time on them. That’s it. That’s the ad. We’ll let you get back to the headlines, but if you want to take away the pain of questionnaires, try a free proof of concept at www.conveyor.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

NSC asks governments not to pay ransoms

CISA’s open source software security roadmap

Save the Children hit with ransomware

Huge thanks to our sponsor, Conveyor

Got a scary security questionnaire to complete and you’d rather have AI do it? Your infosec friends are making the switch from outdated RFP and compliance tools to Conveyor - the most accurate security questionnaire automation software on the market. The proof is in the AI. Customers are seeing 80-90% accurate answers and decreasing the time spent on questionnaire answering by 91%. We’re excited about the success customers like Lucid and Carta have seen using Conveyor. Try a free proof of concept at www.conveyor.com.

View Details

MGM Resorts slot machines and ATMs disrupted by "cybersecurity incident"

Hackers access sensitive data of thousands of Airbus vendors

Cryptoqueen’s sidekick sentenced for $4 billion scam

Huge thanks to our sponsor, Conveyor

Here’s how to measure if your security questionnaire answering software is effective.

We benchmarked the RFP and compliance tools on the market and most are only generating accurate responses to questionnaires 20-50% of the time.

Ready for 80-90% auto-generated accurate answers so you can fly through your review?

Then you should try Conveyor’s AI-security questionnaire automation tool.

Don’t believe us? Try a free proof of concept at www.conveyor.com

For the stories behind the headlines, visit CISOseries.com.

View Details

UK government sees record critical IT infrastructure attacks

Charming Kitten unleashes Sponsor backdoor

Ransomware costs Sri Lankan government months of data

Huge thanks to our sponsor, Conveyor

The team at Lucid software reduced the time spent answering customer security questionnaires by a whopping 91% with Conveyor’s security questionnaire automation software - powered by OpenAI.

Compared to the tools on the market, Conveyor’s AI auto-generates the most accurate answers to entire questionnaires so you can spend almost zero time on them.

That’s it. That’s the ad.

We’ll let you get back to the headlines, but if you want to take away the pain of questionnaires, try a free proof of concept at www.conveyor.com.

View Details

Evil Telegram fake apps send spyware

Akamai announces mitigation of largest DDoS on a US financial company

Rhysida attacks three more hospitals

Huge thanks to our sponsor, Conveyor

What’s scarier than the Sunday scaries? Opening your inbox to a 200 question, 15 tab macro-enabled workbook containing a customer security questionnaire to complete. Let Conveyor's AI security questionnaire automation tool, powered by OpenAI, help your answering process go a lot faster. Spend 91% less time on questionnaires when you get precise answers auto-generated for you. Try a free proof of concept to see how fast you can get through questionnaires with Conveyor at www.conveyor.com

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review, is hosted by Rich Stroffolino  with guest Dan Walsh, CISO, VillageMD

Thanks to our show sponsor, Comcast DataBee

DataBee™, from Comcast Technology Solutions, is a cloud-native security, risk and compliance data fabric platform that transforms your security data chaos into connected outcomes. Built by security professionals for security professionals, DataBee makes your data a gold mine, rich with information that enables you to examine the past, react to the present, and protect the future of your business. Learn more at https://comca.st/DataBee.

All links and the video of this episode can be found on CISO Series.com

View Details

How Chinese hackers stole a Microsoft signing key

The ICC to prosecute cyberwar crimes

North Korean cyberattacks against Russian targets

Thanks to today's episode sponsor, Comcast

DataBee™, from Comcast Technology Solutions, is a cloud-native security, risk and compliance data fabric platform that transforms your security data chaos into connected outcomes. Built by security professionals for security professionals, DataBee makes your data a gold mine, rich with information that enables you to examine the past, react to the present, and protect the future of your business. Learn more at https://comca.st/DataBee.

View Details

CISA close to finalizing incident reporting rules

Krebs on cracked LastPass keys

Connected cars not great for privacy and security

Thanks to today's episode sponsor, Comcast

Are you still using whiteboards and pivoting between tools to find out who owns what data sources and the relationships between data points? It’s time to improve your OODA loop and enhance your security and compliance efforts with  DataBee, from Comcast Technology Solutions. Learn how DataBee weaves together and enriches data from across the enterprise to provide deeper insights into your security, risk and compliance posture. Visit https://comca.st/DataBee.

View Details

CISA hires ‘Mudge’ to work on security-by-design principles

All 50 states call on Congress to address AI-generated CSAM

Stake.com loses $41 million to hot wallet hackers

Thanks to today's episode sponsor, Comcast

What if you could integrate enterprise-wide business intelligence with your security data for better contextual insights into potential threats and compliance issues? You can. With DataBee™, from Comcast Technology Solutions. Learn how DataBee enables users to leverage integrated insights to mitigate risks and stay compliant. Visit https://comca.st/DataBee.

For the stories behind the headlines, visit CISOseries.com.

View Details

New PDF MalDoc allows evasion of antivirus

MinIO Storage system being used to compromise servers

Okta warns of IT help desk attacks

Thanks to today's episode sponsor, Comcast

Data rules everything around us – but why are the people who need data the most unable to access it? What if you could boost the productivity of your security teams and their ability to collaborate by providing them access to the same shared and enriched data?

You can. With DataBee™, from Comcast Technology Solutions. Learn how DataBee can help your organization make better informed decisions, quickly and cost-effectively. Visit https://comca.st/DataBee

For the stories behind the headlines, head to CISOseries.com.

View Details

X to collect member employment data

Technical details of Sandworm malware ‘Infamous Chisel’ released

Golf club maker Callaway suffers breach

Thanks to today's episode sponsor, Comcast

“Data is the currency of the 21st century”, yet for so many cybersecurity professionals, it’s still too difficult to access, correlate and use this ‘currency’ for better, faster security and compliance decision-making. That’s why Comcast Technology Solutions created DataBee™, a cloud-native security data fabric platform that can help you turn your security data into valuable business ‘currency’. Learn more at https://comca.st/DataBee.

For the stories behind the headlines, head to CISOseries.com.

View Details

Gamaredon hackers hit Ukraine military

Movie giant Paramount Global suffers data breach

Takeover swarm exploits OpenFire

Huge thanks to today's episode sponsor, AppOmni

Over provisioned users could lead to your most sensitive data being exposed or leaked. Just a single attack on one of those users may compromise your entire SaaS estate. With AppOmni’s SaaS Identity Fabric, secure and manage end-users, entitlements, and threat-based activity. Gain visibility and control over provisioned users, the SaaS data they have access to, and receive guided remediation. Get connected with SaaS security experts at AppOmni.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Chinese threat actors breached Japan’s cybersecurity agency

Human trafficking into cyber scams

China set to approve first generative AI services

Huge thanks to today's episode sponsor, AppOmni

SaaS cyberattacks are prevalent and often go unnoticed until data loss or breaches occur. Sign-ins from an unusual IP address. Stolen session tokens. These security risks can lurk in the shadows and put your entire SaaS estate at risk.

Don’t wait for a breach to secure your SaaS data. AppOmni helps security teams to detect suspicious activity, decide what activities to be alerted on, and receive guided remediation. Learn how at AppOmni.com.

View Details

FBI dismantles Qakbot operation that took millions in ransom

University of Michigan severs ties to internet after cyberattack

Microsoft joins growing list of organizations criticizing UN cybercrime treaty

Huge thanks to today's episode sponsor, AppOmni

Over provisioned users could lead to your most sensitive data being exposed or leaked. Just a single attack on one of those users may compromise your entire SaaS estate.

With AppOmni’s SaaS Identity Fabric, secure and manage end-users, entitlements, and threat-based activity. Gain visibility and control over provisioned users, the SaaS data they have access to, and receive guided remediation. Get connected with SaaS security experts at AppOmni.com.

For the stories behind the headlines, visit CISOseries.com.

View Details

UK network outage grounds flights

The malware loader Big 3

Another spyware firm breached

Huge thanks to today's episode sponsor, AppOmni

SaaS cyberattacks are prevalent and often go unnoticed until data loss or breaches occur. Sign-ins from an unusual IP address. Stolen session tokens. These security risks can lurk in the shadows and put your entire SaaS estate at risk.

Don’t wait for a breach to secure your SaaS data. AppOmni helps security teams to detect suspicious activity, decide what activities to be alerted on, and receive guided remediation. Learn how at AppOmni.com.

View Details

Cisco fixes flaws in NX-OS AND FXOS software

Windows preview updates bring blue screen of death

FBI warns Barracuda bug still has bite

Huge thanks to today's episode sponsor, AppOmni

Over provisioned users could lead to your most sensitive data being exposed or leaked. Just a single attack on one of those users may compromise your entire SaaS estate.

With AppOmni’s SaaS Identity Fabric, secure and manage end-users, entitlements, and threat-based activity. Gain visibility and control over provisioned users, the SaaS data they have access to, and receive guided remediation. Get connected with SaaS security experts at AppOmni.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review, is hosted by Rich Stroffolino with guest Gerald Auger Ph.D., Chief Content Creator, Simply Cyber

Thanks to our show sponsor, HyperProof

Is your company scaling? Do you need to quickly add more compliance frameworks but don’t know where to start? Hyperproof has you covered. Hyperproof is a risk and compliance management platform that can help you manage compliance at scale. With Hyperproof, you can quickly add new frameworks, crosswalk controls between frameworks, view your risk posture, and manage your risks, all in one place. Visit hyperproof.io to get started today.

All links and the video of this episode can be found on CISO Series.com

View Details

Lazarus Group exploits ManageEngine to drop new RATS on internet and healthcare

Vulnerabilities in Rockwell ThinManager threaten industrial control systems

Mississippi hospital system suffers cyberattack

Huge thanks to our sponsor, HyperProof

Is your company scaling? Do you need to quickly add more compliance frameworks but don’t know where to start? Hyperproof has you covered. Hyperproof is a risk and compliance management platform that can help you manage compliance at scale. With Hyperproof, you can quickly add new frameworks, crosswalk controls between frameworks, view your risk posture, and manage your risks, all in one place. Visit to get started today.

For the stories behind the headlines, head to CISOseries.com.

View Details

Tornado Cash developers face indictment

UN begins final cybercrime treaty talks

FBI warns of North Korean crypto cash out

Huge thanks to our sponsor, HyperProof

It’s more critical than ever to focus on strategically addressing risk, but how can you do it when working with limited resources? That’s where Hyperproof comes in: Hyperproof is a risk and compliance operations platform that helps you automate evidence collection, task management, and collaboration within your organization so you can focus on what matters most: keeping your company secure by prioritizing strategy, not manual processes. Get a demo at Hyperproof.io.

View Details

CISOs proclaim cybersecurity confidence, but majority admit to SaaS incidents

Cyber Health Report: Hacker entry point shifts from email to network

Duo outage causes Azure Auth authentication errors

Huge thanks to our sponsor, HyperProof

We get it. You’re a risk manager or compliance professional, and you’re overworked. You’re trying to do the right thing by keeping your company safe and secure, but your technology is holding you back. Why not upgrade to Hyperproof? Hyperproof is a platform that not only eliminates the manual tasks you dread, but helps you scale security. Get a demo today at hyperproof.io.

For the stories behind the headlines, head to CISOseries.com.

View Details

ChatGPT used in crypto botnet

Brits tipping off ransomware targets

Tesla data breach caused by insiders

Huge thanks to our sponsor, HyperProof

Imagine. You have an audit coming up, but instead of the usual rush, you actually feel prepared. You’ve collected your evidence. You can see which risks have been mitigated. And best of all, you don’t have to send out any last-minute emails to other teams begging them for that one screenshot. Sounds like a dream, right? With Hyperproof’s risk and compliance platform, this could be your reality. Get a demo at hyperproof.io.

View Details

North Korean hackers suspected of targeting S. Korea-US drills

Android malware apps use APK compression to evade detection

Security agencies warn space industry of increased attacks

Huge thanks to our sponsor, HyperProof

Tired of managing risk and compliance in spreadsheets? Sick of tracking down stakeholders to find evidence? Worried about whether that evidence is up to date for your next audit? Hyperproof has you covered. With Hyperproof, you can efficiently manage multiple compliance frameworks and risks in a single place so you can focus on what matters most: keeping your company secure and growing. Visit hyperproof.io to get a demo.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review, is hosted by Rich Stroffolino with guest, Jon Oltsik, distinguished analyst and fellow, Enterprise Strategy Group

Thanks to our show sponsor, Veza

75% of breaches happen because of bad permissions. The problem is that you don’t know exactly WHO has access to WHAT data in your environment. For example, roles labeled as “read-only” can often edit and delete sensitive data. Veza automatically finds and fixes every bad permission—in every app—across your environment.

All links and the video of this episode can be found on CISO Series.com

View Details

Influence operators fine-tuning AI to deceive targets

67% of government agencies claim confidence in adopting zero trust

CISA warns of urgent Citrix vulnerability

Huge thanks to today's episode sponsor, Veza

75% of breaches happen because of bad permissions. The problem is that you don’t know exactly WHO has access to WHAT data in your environment. For example, roles labeled as “read-only” can often edit and delete sensitive data. Veza automatically finds and fixes every bad permission—in every app—across your environment.

For the stories behind the headlines, head to CISOseries.com.

View Details

LockBit struggles to publish leaked data

Google’s quantum resilient security key

Organizations optimistic and unprepared for AI

Huge thanks to today's episode sponsor, Veza

75% of breaches happen because of bad permissions. The problem is that you don’t know exactly WHO has access to WHAT data in your environment. For example, roles labeled as “read-only” can often edit and delete sensitive data. Veza automatically finds and fixes every bad permission—in every app—across your environment.

View Details

Huge thanks to today's episode sponsor, Veza

75% of breaches happen because of bad permissions. The problem is that you don’t know exactly WHO has access to WHAT data in your environment. For example, roles labeled as “read-only” can often edit and delete sensitive data. Veza automatically finds and fixes every bad permission—in every app—across your environment.

For the stories behind the headlines, visit CISOseries.com.

View Details

Moovit bug allowed for free rides

A look at Black Hat’s network operations center

Business and gaming disputes lead to DDoS attacks

Huge thanks to today's episode sponsor, Veza

75% of breaches happen because of bad permissions. The problem is that you don’t know exactly WHO has access to WHAT data in your environment. For example, roles labeled as “read-only” can often edit and delete sensitive data. Veza automatically finds and fixes every bad permission—in every app—across your environment.

View Details

Ford says cars with WiFi vulnerability still safe to drive

Cyber Safety Review Board to analyze cloud security in wake of Microsoft hack

Knight ransomware distributed in fake TripAdvisor complaint emails

Huge thanks to today's episode sponsor, Veza

75% of breaches happen because of bad permissions. The problem is that you don’t know exactly WHO has access to WHAT data in your environment. For example, roles labeled as “read-only” can often edit and delete sensitive data. Veza automatically finds and fixes every bad permission—in every app—across your environment.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to blog post

This week’s Cyber Security Headlines – Week in Review, August 7-11, is hosted by Rich Stroffolino with guest, Michael Woods, CISO, GE

Thanks to our show sponsor, Conveyor

We can all agree there’s one thing the AI bots can take from us: completing customer security questionnaires. That’s why we built Conveyor’s GPT-questionnaire response tool.

It auto-generates precise, accurate answers to entire questionnaires with accuracy far superior to existing tools on the market. It’s so accurate, your customers can now use it in our new ‘upload questions to trust portal’ feature. It’s exactly as it sounds. Customers can upload questions and the AI will generate instant answers based on your trust portal content.

Try a free proof of concept with your own data and see why top SaaS companies are making the switch from outdated RFP software and other portal solutions. Learn more at Conveyor.

All links and the video of this episode can be found on CISO Series.com

View Details

CISA Warns organizations of exploited vulnerability affecting .NET, Visual Studio

Dell Compellent hardcoded key exposes VMware vCenter admin creds

DEF CON: Thousands of security researchers vie to outsmart AI in Las Vegas

Thanks to today's episode sponsor, Conveyor

We can all agree there’s one thing the AI bots can take from us: completing customer security questionnaires. That’s why we built Conveyor’s GPT-questionnaire response tool.
It auto-generates precise, accurate answers to entire questionnaires with accuracy far superior to existing tools on the market. It’s so accurate, your customers can now use it in our new ‘upload questions to trust portal’ feature. It’s exactly as it sounds. Customers can upload questions and the AI will generate instant answers based on your trust portal content.

Try a free proof of concept with your own data and see why top SaaS companies are making the switch from outdated RFP software and other portal solutions.

Learn more at www.conveyor.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

AI Cyber Challenge announced at Black Hat

Tencent typing app had real time “eavesdropper”

Google adds cellular security to Android

Thanks to today's episode sponsor, Conveyor

Your scariest questionnaires that are HUNDREDS of questions long are no match for Conveyor’s GPT-security questionnaire tool - the most accurate questionnaire automation tool on the market. It’s so accurate that you can even let customers upload their own questions in your portal to get instant answers generated from your content. For questionnaires you still need complete, infosec and sales teams are spending 89% less time on answering questionnaires because they’re getting accurate answers to entire questionnaires that they don’t have to re-write.

Try a free proof of concept with your own data. Learn more at www.conveyor.com

View Details

Google’s Messages app now uses RCS to encrypt chats

Electoral Commission apologizes for security breach involving UK voters’ data

Banks hit with over $500 million in fines for using out-of-band chat apps

Thanks to today's episode sponsor, Conveyor

Did you catch the biggest release of the year? No, not Barbenheimer.

It’s Conveyor’s GPT-powered security questionnaire response tool: the most accurate questionnaire automation tool on the market. It’s so good, you can let your customers upload their own questions in your trust portal to get instant answers based on your content. And of course, it’s not just for your customers. You can use the GPT-questionnaire response tool internally as well to get auto-generated precise answers to entire questionnaires in minutes so all you have to do is review.

Maybe it's time to replace your outdated RFP software… Try a free proof of concept with your own data. Learn more at www.conveyor.com

For the stories behind the headlines, head to CISOseries.com

View Details

White House rolls out school cyber initiatives

North Koreans breach Russian missile developer

Large language models getting worse at math

Thanks to today's episode sponsor, Conveyor

GPT for security questionnaires? Conveyor has already built that for you. Conveyor’s GPT-questionnaire response tool is so accurate, you can use it in two ways.

One: Let your customers upload their own questions in your trust portal to get AI-generated answers based on the content in your portal.

And Two: It’s not just for your customers. You can use the GPT-questionnaire response tool internally as well to get auto-generated precise answers to entire questionnaires in minutes so all you have to do is review.

Try a free proof of concept with your own data to see it in action. Learn more at www.conveyor.com

View Details

Microsoft resolves vulnerability following criticism from Tenable CEO

FBI investigating ransomware attack crippling hospitals across 4 states

New acoustic attack steals data from keystrokes with 95% accuracy

Thanks to today's episode sponsor, Conveyor

Did you catch the biggest release of the year? No, not Barbenheimer.

It’s Conveyor’s GPT-powered security questionnaire response tool: the most accurate questionnaire automation tool on the market. It’s so good, you can let your customers upload their own questions in your trust portal to get instant answers based on your content. And of course, it’s not just for your customers. You can use the GPT-questionnaire response tool internally as well to get auto-generated precise answers to entire questionnaires in minutes so all you have to do is review.

Maybe it's time to replace your outdated RFP software… Try a free proof of concept with your own data. Learn more at www.conveyor.com

For the stories behind the headlines, head to CISOseries.com

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, July 31-August 4, is hosted by Rich Stroffolino with guest, Jeff Hudesman, CISO, Pinwheel

Thanks to our show sponsor, Opal

Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal’s mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identity security for scale. Visit opal.dev.

View Details

Fortinet VPN bug tops CISA’s list of most exploited vulnerabilities in 2022

Chrome malware Rilide targets enterprise users via PowerPoint guides

Researchers discover bypass for recently fixed Ivanti EPMM vulnerability

Thanks to today's episode sponsor, Opal

Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identity security for scale. Visit Opal.dev.

For the stories behind the headlines, head to CISOseries.com.

View Details

Australian Senate recommends banning WeChat

US company accused of aiding APT

Hacking group to detail P2P protocol at DEF CON 

Thanks to today's episode sponsor, Opal

Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identity security for scale. Visit Opal.dev.

View Details

Musk sues disinformation researchers for driving away advertisers

Researchers claim cloud host facilitated state-backed cyberattacks

UK spy agencies want to relax ‘burdensome’ laws on AI data use

Thanks to today's episode sponsor, Opal

Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identity security for scale. Visit Opal.dev.

For the stories behind the headlines, visit CISOseries.com.

View Details

White House releases National Cyber and Workforce Education Strategy 

Latest DeFi exploit sees millions in losses

No link found between cyber insurance and paying ransoms

Thanks to today's episode sponsor, Opal

Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identity security for scale. Visit Opal.dev.

View Details

Israel’s largest oil refinery website offline amid cyber attack claims

TSA renews cybersecurity guidelines for pipelines

CISA AND Australia warn of IDOR vulnerabilities after major breaches

Thanks to today's episode sponsor, Opal

Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identity security for scale. Visit Opal.dev.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, July 24-28, is hosted by Rich Stroffolino with guest, TC Niedzialkowski‌, CISO, Nextdoor

Thanks to today’s episode sponsor, AppOmni

Over provisioned users could lead to your most sensitive data being exposed or leaked. Just a single attack on one of those users may compromise your entire SaaS estate. With AppOmni’s SaaS Identity Fabric, secure and manage end-users, entitlements, and threat-based activity. Gain visibility and control over provisioned users, the SaaS data they have access to, and receive guided remediation. Get connected with SaaS security experts at AppOmni.com.

All links and the video of this episode can be found on CISO Series.com

View Details

Millions affected by data breach at US government contractor Maximus

Two severe Linux vulnerabilities impact 40% of Ubuntu users

Heart monitoring technology provider confirms cyberattack

Thanks to today's episode sponsor, AppOmni

Over provisioned users could lead to your most sensitive data being exposed or leaked. Just a single attack on one of those users may compromise your entire SaaS estate.

With AppOmni’s SaaS Identity Fabric, secure and manage end-users, entitlements, and threat-based activity. Gain visibility and control over provisioned users, the SaaS data they have access to, and receive guided remediation. Get connected with SaaS security experts at AppOmni.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Russian court convicts cyber security executive of treason

SEC to require incident disclosure

Government cyber attacks rely on valid credentials

Thanks to today's episode sponsor, AppOmni

SaaS cyberattacks are prevalent and often go unnoticed until data loss or breaches occur. Sign-ins from an unusual IP address. Stolen session tokens. These security risks can lurk in the shadows and put your entire SaaS estate at risk.

Don’t wait for a breach to secure your SaaS data. AppOmni helps security teams to detect suspicious activity, decide what activities to be alerted on, and receive guided remediation. Learn how at AppOmni.com.

View Details

Vulnerability found in TETRA encryption

Ryzen CPUs vulnerable to Zenbleed exploit

Norwegian government breached with Ivanti zero-day

Thanks to today's episode sponsor, AppOmni

Over provisioned users could lead to your most sensitive data being exposed or leaked. Just a single attack on one of those users may compromise your entire SaaS estate.

With AppOmni’s SaaS Identity Fabric, secure and manage end-users, entitlements, and threat-based activity. Gain visibility and control over provisioned users, the SaaS data they have access to, and receive guided remediation. Get connected with SaaS security experts at AppOmni.com.

View Details

Clop moves leaked data to clearweb sites

EU governments push back on centralized cyber reporting

Cost of data breaches up 15%

Thanks to today's episode sponsor, AppOmni

SaaS cyberattacks are prevalent and often go unnoticed until data loss or breaches occur. Sign-ins from an unusual IP address. Stolen session tokens. These security risks can lurk in the shadows and put your entire SaaS estate at risk.

Don’t wait for a breach to secure your SaaS data. AppOmni helps security teams to detect suspicious activity, decide what activities to be alerted on, and receive guided remediation. Learn how at AppOmni.com.

View Details

Microsoft key stolen by Chinese hackers provided access far beyond Outlook

JumpCloud breach traced back to North Korean state hackers

DHL investigating MOVEit breach as number of victims surpasses 20 million

Thanks to today's episode sponsor, AppOmni

Over provisioned users could lead to your most sensitive data being exposed or leaked. Just a single attack on one of those users may compromise your entire SaaS estate.

With AppOmni’s SaaS Identity Fabric, secure and manage end-users, entitlements, and threat-based activity. Gain visibility and control over provisioned users, the SaaS data they have access to, and receive guided remediation. Get connected with SaaS security experts at AppOmni.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, July 17-21, is hosted by Rich Stroffolino with our guest, Dimitri van Zantvliet, CISO, Dutch Railways

Thanks to our show sponsor, OpenVPN

According to Oriel Hernan Villalba Pinzetta, a System Administrator with CEDEC’s cybersecurity and IT department, “The pandemic meant we could not come to the office, and we needed to facilitate access to our local resources,” says Villalba. “Cloud Connexa was really easy and fast to set up, two things we really needed in that moment.” Read more here.

All links and the video of this episode can be found on CISO Series.com

View Details

New P2PInfect worm targeting Redis servers on Linux and Windows systems

Adobe releases new patches for exploited ColdFusion vulnerabilities

Estée Lauder breached by two ransomware groups

And now a word from our sponsor, OpenVPN

According to Oriel Hernan Villalba Pinzetta, a System Administrator with CEDEC’s cybersecurity and IT department, “The pandemic meant we could not come to the office, and we needed to facilitate access to our local resources,” says Villalba. “Cloud Connexa was really easy and fast to set up, two things we really needed in that moment.” Read more at the link in our show notes.

For the stories behind the headlines, head to CISOseries.com.

View Details

Complex DDoS attacks on the rise

MI6 warns of Chinese data traps

Microsoft expands cloud log access

And now a word from our sponsor, OpenVPN

Karim Hakim, CTO at Hakim Misr Paco, says that CloudConnexa has given him some long-sought peace of mind. “OpenVPN has helped my company to access remote nodes securely without worrying about security protocols,” he says. “My company has been looking for a similar solution for years, and we finally got what we were looking for.” Read more at the link in our show notes.

View Details

US government launches IoT security labeling program

Renewable technologies could pose risk to US electric grid

US blacklists two spyware firms run by Israeli former general

And now a word from our sponsor, OpenVPN

Stephen Haecker, Chief Technology Officer at Carteras Colectivas, relies on Cloud Connexa customer support for his remote team. “I have used them about once per month to help with our growing networks,” he says, “and the service quality is great with quick turnarounds.” Haecker appreciates the consistency of the support team, and their personalized approach. Read more at the link in our show notes.

For the stories behind the headlines, visit CISOseries.com.

View Details

JumpCloud breached by APT

Wisconsin allegedly hit by LockBit

Typos leaking military emails

And now a word from our sponsor, OpenVPN

Zach Belhadri, the Infrastructure Manager at Knight Capital, shares why using Cloud Connexa for his team’s security has been a game changer. With the Cybershield feature, he’s able to prevent malware, phishing, and other threats by restricting access to only authorized and trusted internet destinations. He calls Cloud Connexa “an awesome product with huge potential.” Read more at the link in our show notes.

View Details

Russia-linked Gamaredon starts stealing data 30 to 50 minutes after initial compromise

New AI tool – WormGPT allows for sophisticated cyber attacks

Microsoft still unsure how hackers stole Azure AD signing key

And now a word from our sponsor, OpenVPN

We asked Anthony Hook, the CTO at Dataweavers, if he would recommend Cloud Connexa to other companies. His response? A resounding yes! With Cloud Connexa, he says “we bypassed the clunky client-owned VPNs and networks, gaining a seamless, secure, and efficient connectivity solution.” Read more at the link in our show notes.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, July 10-14, is hosted by Sean Kelly with our guest, Yaron Levi, CISO, Dolby

Thanks to our show sponsor, Opal

Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal’s mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identity security for scale. Visit Opal.dev.

All links and the video of this episode can be found on CISO Series.com

View Details

USB drive malware attacks spiking again in first half of 2023

Users of Honeywell Experion DCS platforms urged to patch 9 vulnerabilities immediately

Ransomware gangs have extorted $449 million this year

Thanks to this week's episode sponsor, Opal

Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identity security for scale.

For the stories behind the headlines, head to CISOseries.com.

View Details

What we know about NATO cyber pledges 

Tax prep companies “recklessly” shared data

Report finds decrease in crypto crime

Thanks to this week's episode sponsor, Opal

Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identity security for scale.

View Details

Silk Road’s senior advisor sentenced to 20 years in prison

11 million HCA patients impacted by data breach

Google hit with lawsuit alleging it stole user data to train its AI tools

Thanks to this week's episode sponsor, Opal

Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identity security for scale.

For the stories behind the headlines, visit CISOseries.com.

View Details

JumpCloud resets customer API keys

Would you be interested in a slightly used dark web market? 

US and EU agree on new data transfer agreement

Thanks to this week's episode sponsor, Opal

Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identity security for scale.

View Details

New ‘Big Head’ ransomware displays fake Windows update alert

RedEnergy stealer-as-a-ransomware threat targeting energy and telecom sectors

Three new MOVEit bugs spur CISA warning as more victims report breaches

Thanks to this week's episode sponsor, Opal

Opal is the data-centric identity platform. Identity is one of the last great enterprise frontiers. It’s fragmented with legacy architecture. Opal's mission is to empower enterprises to understand and calibrate access end to end. The best security teams from companies like Databricks, Figma, Blend, and Drata use Opal to build identity security for scale.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, July 3-7, is hosted by Rich Stroffolino with our guest, Hadas Cassorla, CISO, M1

Thanks to today’s episode sponsor, SlashNext

SlashNext, a leader in SaaS-based Integrated Cloud Messaging Security across email, web, and mobile has the industry’s first artificial intelligence solution, HumanAI, that uses generative AI to defend against advanced business email compromise (BEC), supply chain attacks, executive impersonation, and financial fraud. Request a demo today.

All links and the video of this episode can be found on CISO Series.com

View Details

Shell confirms MOVEit-related breach after ransomware group leaks data

28,000 impacted by data breach at Pepsi Bottling Ventures

INTERPOL nabs hacking crew OPERA1ER’s leader behind $11 million cybercrime

Thanks to today's episode sponsor, SlashNext

SlashNext, a leader in SaaS-based Integrated Cloud Messaging Security across email, web, and mobile has the industry’s first artificial intelligence solution, HumanAI, that uses generative AI to defend against advanced business email compromise (BEC), supply chain attacks, executive impersonation, and financial fraud. Request a demo today.

For the stories behind the headlines, head to CISOseries.com.

View Details

Japan’s major port hit with ransomware

European court orders changes to Meta’s data practices

Injunction restricts White House contact with social media companies

Thanks to today's episode sponsor, SlashNext

SlashNext, a leader in SaaS-based Integrated Cloud Messaging Security across email, web, and mobile has the industry’s first artificial intelligence solution, HumanAI, that uses generative AI to defend against advanced business email compromise (BEC), supply chain attacks, executive impersonation, and financial fraud. Request a demo today.

View Details

BlackCat ransomware pushes Cobalt Strike via WinSCP search ads

CISA issues warning for cardiac device system vulnerability

330,000 FortiGate firewalls still unpatched to CVE-2023-27997 RCE flaw

Thanks to today's episode sponsor, SlashNext

SlashNext, a leader in SaaS-based Integrated Cloud Messaging Security across email, web, and mobile has the industry’s first artificial intelligence solution, HumanAI, that uses generative AI to defend against advanced business email compromise (BEC), supply chain attacks, executive impersonation, and financial fraud. Request a demo today.

For the stories behind the headlines, head to CISOseries.com.

View Details

Semiconductor giant says IT supplier was attacked, LockBit makes related claims

Several US states investigating ‘SiegedSec’ hacking campaign

Russian telecom confirms hack after group backing Wagner boasted about an attack

Thanks to today's episode sponsor, SlashNext

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, June 26-30, is hosted by Rich Stroffolino with our guest, Cassio Goldschmidt, CISO, ServiceTitan

Thanks to our show sponsor, AppOmni

Over provisioned users could expose your organization’s most sensitive data. Just a single attack on one of those users may compromise your entire SaaS estate. With AppOmni’s identity and threat detection capabilities, you can detect and respond to suspicious activities within your SaaS environment. Gain visibility into over provisioned users, the SaaS data they have access to, and receive guided remediation. Get started at AppOmni.com.

All links and the video of this episode can be found on CISO Series.com

View Details

SEC notice to SolarWinds CISO and CFO roils cybersecurity industry

Newly uncovered ThirdEye Windows-based malware steals sensitive data

Cyber Command to expand ‘canary in the coal mine’ unit working with private sector

Thanks to today's episode sponsor, AppOmni

Over provisioned users could expose your organization’s most sensitive data. Just a single attack on one of those users may compromise your entire SaaS estate.

With AppOmni’s identity and threat detection capabilities, you can detect and respond to suspicious activities within your SaaS environment. Gain visibility into over provisioned users, the SaaS data they have access to, and receive guided remediation. Get started at AppOmni.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Federal network devices fail CISA requirements

US considering more AI chip export bans 

The scope of MOVEit vulnerability

Thanks to today's episode sponsor, AppOmni

Are you continuously monitoring the common misconfigurations occurring in your SaaS ecosystem? From inactive connected SaaS apps retaining access to sensitive data, to threat actors manipulating conditional access rules, these misconfigurations can pose a significant threat to your SaaS security.

Take action with AppOmni. Secure your organization’s most sensitive data and continuously monitor your SaaS estate for data exposure and misconfigurations. Visit AppOmni.com to get a free risk assessment.

View Details

Thanks to today's episode sponsor, AppOmni

Over provisioned users could expose your organization’s most sensitive data. Just a single attack on one of those users may compromise your entire SaaS estate.

With AppOmni’s identity and threat detection capabilities, you can detect and respond to  suspicious activities within your SaaS environment. Gain visibility into over provisioned users, the SaaS data they have access to, and receive guided remediation. Get started at AppOmni.com.

For the stories behind the headlines, visit CISOseries.com.

View Details

Monopoly darknet operator charged

Activision Blizzard games hit with DDoS

5G deadline could impact flights

Thanks to today's episode sponsor, AppOmni

Are you continuously monitoring the common misconfigurations occurring in your SaaS ecosystem? From inactive connected SaaS apps retaining access to sensitive data, to threat actors manipulating conditional access rules, these misconfigurations can pose a significant threat to your SaaS security.

Take action with AppOmni. Secure your organization’s most sensitive data and continuously monitor your SaaS estate for data exposure and misconfigurations. Visit AppOmni.com to get a free risk assessment.

View Details

CISA adds 6 flaws to known exploited vulnerabilities catalog

US military personnel report receiving smartwatches in the mail

Microsoft 365 users new Outlook and Teams problems

Thanks to today's episode sponsor, AppOmni

Over provisioned users could expose your organization’s most sensitive data. Just a single attack on one of those users may compromise your entire SaaS estate.

With AppOmni’s identity and threat detection capabilities, you can detect and respond to suspicious activities within your SaaS environment. Gain visibility into over provisioned users, the SaaS data they have access to, and receive guided remediation. Get started at AppOmni.com.

For the stories behind the headlines, head to CISOseries.com

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, June 19-23, is hosted by Rich Stroffolino with our guest, Janet Heins, CISO, iHeartMedia

Thanks to our show sponsor, Wing Security

The first step to securing your organization’s SaaS usage is knowing which SaaS applications your employees are using. 3rd party included. Wing offers a completely free, SaaS Shadow IT Discovery tool. You can find it at wing.security and self onboard. No sales in the process, no credit card needed, no time-limit. Just go ahead and discover your SaaS usage.

All links and the video of this episode can be found on CISO Series.com

View Details

Cybersecurity breaches more than double among Canadian businesses

Experienced China-based hacking group has new backdoor tool

Cyberattacks on OT, ICS lay groundwork for kinetic warfare

Thanks to today's episode sponsor, Wing Security

The first step to securing your organization’s SaaS usage is knowing which SaaS applications your employees are using. 3rd party included. Wing offers a completely free, SaaS Shadow IT Discovery tool. You can find it at wing.security and self onboard. No sales in the process, no credit card needed, no time-limit. Just go ahead and discover your SaaS usage.

For the stories behind the headlines, head to CISOseries.com.

View Details

New DoJ cyber prosecution team will go after nation-state threat actors

Apple fixes zero-days used to deploy Triangulation spyware

Schumer unveils strategy to regulate AI

Thanks to today's episode sponsor, Wing Security

Shadow IT is an evolving pain and a security risk, especially in today’s decentralized work environments. Now’s the time to regain control of your SaaS usage by taking advantage of Wing’s Free SaaS Shadow IT discovery solution. Check out wing.security to self-onboard today, no strings attached.

For the stories behind the headlines, visit CISOseries.com.

View Details

Rorschach ransomware takes the speed crown

Data leak impacts Australian government

Cyber security market growth outpaces tech sector

Thanks to today's episode sponsor, Wing Security

Can you answer these three questions confidently?
1. How many SaaS applications are used in your organization?
2. Which permissions did users provide these applications?
and
3. What is the data that flows in and in between these applications?
Wing provides the answers. In fact, it discovers your SaaS usage completely for free, no time limit. Visit wing.security to self-onboard.

View Details

Reddit hit with ransom demand

UK’s cyber chief moves on to organized crime

Binance reaches deal with the SEC

Thanks to today's episode sponsor, Wing Security

The first step to securing your organization’s SaaS usage is knowing which SaaS applications your employees are using. 3rd party included. Wing offers a completely free, SaaS Shadow IT Discovery tool. You can find it at wing.security and self onboard. No sales in the process, no credit card needed, no time-limit. It takes minutes to discover your organization's SaaS usage.

View Details

Microsoft says early June service outages were cyberattacks

Third MOVEit vulnerability raises alarms as US Agriculture Department says it may be impacted

US govt offers $10 million bounty for info on Clop ransomware

Thanks to today's episode sponsor, Wing Security

The folks at Wing believe that SaaS Shadow IT discovery is the basic first step to securing your SaaS usage. They believe it so strongly that they launched a completely free SaaS Shadow IT Discovery solution. Check out wing.security to self-onboard today, no strings attached, no time limit. Wing.security.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, June 12-16, is hosted by Sean Kelly with our guest, Phil Beyer, former Head of Security, Etsy

Thanks to our show sponsor, Conveyor

Your scariest questionnaires that are hundreds of questions long are no match for Conveyor’s GPT-questionnaire tool – now with a browser extension for complex portals. Get GPT-generated precise answers to entire questionnaires so your review takes seconds. Now you can spend 89% less time completing questionnaires when you get accurate answers you don’t have to re-write. Try a free proof of concept with your own data to see it in action. See what security and sales teams are raving about at www.conveyor.com

All links and the video of this episode can be found on CISO Series.com

View Details

US federal agencies affected by MOVEit vulnerability

Pentagon leak suspect indicted by a federal grand jury

Suspected LockBit ransomware affiliate nabbed

Thanks to today's episode sponsor, Conveyor

Your scariest questionnaires that are hundreds of questions long are no match for Conveyor’s GPT-questionnaire tool - now with a browser extension for complex portals.

Get GPT-generated precise answers to entire questionnaires so your review takes seconds.

Now you can spend 89% less time completing questionnaires when you get accurate answers you don’t have to re-write.

Try a free proof of concept with your own data to see it in action. See what security and sales teams are raving about at www.conveyor.com

For the stories behind the headlines, visit CISOseries.com.

View Details

China-linked APT group spotted exploiting a VMware ESXi zero-day

Hundreds of thousands of ecommerce sites impacted by critical plugin vulnerability

7-Nation LockBit report shows US paid over $90m in ransoms since 2020

Thanks to today's episode sponsor, Conveyor

Let’s gladly pass the most thankless job in cybersecurity – completing customer security questionnaires – to the AI bots.

Conveyor’s GPT-questionnaire response tool auto-generates precise, accurate answers to entire questionnaires.

With accuracy far superior to other tools, you can spend almost zero time reviewing generated answers. There’s an in platform auto-fill feature or a browser extension for tricky portals.

Stop settling for mediocre tools that only provide lousy “near hits” from your library. Try a free proof of concept with your own data. Learn more at www.conveyor.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Amazon server outage broke fast food apps among other things

Update: Fortinet warns of possible zero-day exploited in limited attacks

US intelligence confirms it buys Americans’ personal data

Thanks to today's episode sponsor, Conveyor

What’s better than using Conveyor’s GPT-questionnaire response tool to generate precise answers to security questionnaires?

Letting customers upload their own questionnaires to your portal and getting back answers in seconds - all based on the content in your knowledge base.

Think of it like a security questionnaire ATM. A prospect clicks through an NDA, uploads questions and gets all the answers they need from the bot, all without ever having to speak to you.

We call that a win-win. Learn more at www.conveyor.com.

For the stories behind the headlines, visit CISOseries.com.

View Details

Critical RCE flaw discovered in Fortinet FortiGate firewalls

BatCloak engine makes malware fully undetectable

Swiss Government targeted by series of cyberattacks

Thanks to today's episode sponsor, Conveyor

Tried to use GPT to fill out questionnaires yet? We already built that for you.

Conveyor’s GPT-questionnaire response tool auto-generates precise, accurate answers to entire questionnaires.

With accuracy far superior to other tools, you can spend almost zero time reviewing generated answers. There’s also a browser extension for complex portals and other scary questionnaires. Best part is, it actually works.

Try a free proof of concept with your own data to see it in action. You won’t be disappointed. Learn more at www.conveyor.com

For the stories behind the headlines, head to CISOseries.com.

View Details

Faked crypto journalists steal real crypto

Strava heat maps leak addresses

API changes lead to Reddit protests

Thanks to today's episode sponsor, Conveyor

Let’s gladly pass the most thankless job in cybersecurity – completing customer security questionnaires –  to the AI bots.

Conveyor’s GPT-questionnaire response tool auto-generates precise, accurate answers to entire questionnaires.

With accuracy far superior to other tools, you can spend almost zero time reviewing generated answers. There’s an in platform auto-fill feature or a browser extension for tricky portals.

Stop settling for mediocre tools that only provide lousy “near hits” from your library. Try a free proof of concept with your own data. Learn more at www.conveyor.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, June 5-9, is hosted by Rich Stroffolino with our guest, Joshua Scott, Head of Security and IT, Postman

Thanks to our show sponsor, Trend Micro

Hybrid work, cloud adoption, and shadow IT have introduced new cybersecurity risks to organizations. Security leaders are left asking, “How can I manage our expanding attack surface?”
Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities in their “Risk to Resilience World Tour. Hear from experts on the latest threat landscape trends, solutions, and platform strategies to manage risk and defend your organization with speed and accuracy. Find the closest city to you and register today to take a leap towards a more resilient future. Head to trendmicro.com/cisoseries

All links and the video of this episode can be found on CISO Series.com

View Details

New PowerDrop malware targets U.S. aerospace defense industry

Zipper giant YKK confirms cyberattack targeted U.S. networks

Barracuda urges customers to replace vulnerable appliances immediately

Thanks to this week's episode sponsor, Trend Micro

Hybrid work, cloud adoption, and shadow IT have introduced new cybersecurity risks to organizations. Security leaders are left asking, “How can I manage our expanding attack surface?”

Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities in their “Risk to Resilience World Tour.

Hear from experts on the latest threat landscape trends, solutions, and platform strategies to manage risk and defend your organization with speed and accuracy. Find the closest city to you and register today to take a leap towards a more resilient future.

Head to trendmicro.com/cisoseries

For the stories behind the headlines, head to CISOseries.com.

View Details

Google improves brand email authentication

SEC drops cases due to data protection failures

Clop asks victims to contact it for a ransom

Thanks to this week's episode sponsor, Trend Micro

Hybrid work, cloud adoption, and shadow IT have introduced new cybersecurity risks to organizations. Security leaders are left asking, “How can I manage our expanding attack surface?”

Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities in their “Risk to Resilience World Tour.

Hear from experts on the latest threat landscape trends, solutions, and platform strategies to manage risk and defend your organization with speed and accuracy. Find the closest city to you and register today to take a leap towards a more resilient future.

Head to trendmicro.com/cisoseries

View Details

Thanks to this week's episode sponsor, Trend Micro

Hybrid work, cloud adoption, and shadow IT have introduced new cybersecurity risks to organizations. Security leaders are left asking, “How can I manage our expanding attack surface?”

Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities in their “Risk to Resilience World Tour.

Hear from experts on the latest threat landscape trends, solutions, and platform strategies to manage risk and defend your organization with speed and accuracy. Find the closest city to you and register today to take a leap towards a more resilient future.

Head to trendmicro.com/cisoseries

For the stories behind the headlines, visit CISOseries.com.

View Details

Satellite hacking at DEF CON

Atomic Wallet investigating losses

SEC sues Binance

Thanks to this week's episode sponsor, Trend Micro

Hybrid work, cloud adoption, and shadow IT have introduced new cybersecurity risks to organizations. Security leaders are left asking, “How can I manage our expanding attack surface?”

Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities in their “Risk to Resilience World Tour.

Hear from experts on the latest threat landscape trends, solutions, and platform strategies to manage risk and defend your organization with speed and accuracy. Find the closest city to you and register today to take a leap towards a more resilient future.

Head to trendmicro.com/cisoseries

View Details

Xplain hack impacts Swiss cantonal police and Fedpol

BlackSuit shows similarities to Royal

Microsoft is retiring Cortana on Windows

Thanks to this week's episode sponsor, Trend Micro

Hybrid work, cloud adoption, and shadow IT have introduced new cybersecurity risks to organizations. Security leaders are left asking, “How can I manage our expanding attack surface?”

Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities in their “Risk to Resilience World Tour.

Hear from experts on the latest threat landscape trends, solutions, and platform strategies to manage risk and defend your organization with speed and accuracy. Find the closest city to you and register today to take a leap towards a more resilient future.

Head to trendmicro.com/cisoseries

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines - Week in Review, May 29-June 2, is hosted by Sean Kelly with our guest, Howard Holton, CTO, GigaOm

Thanks to today’s episode sponsor, Barricade Cyber

Have you fallen victim to a ransomware attack? Don’t worry! Barricade Cyber Solutions has helped thousands of customers in situations just like yours. Their proprietary ransomware recovery services are designed to quickly get your business back on track. Their team of experts will identify the source of the attack and provide a comprehensive solution to prevent it from happening again. You can count on them for the security of your data and systems. Visit barricadecyber.com

All links and the video of this episode can be found on CISO Series.com

View Details

Amazon Ring, Alexa accused of privacy violations by FTC

Kaspersky reports on new mobile APT campaign targeting iOS devices             

White House to choose Army general Hartman to be Cyber Command No. 2

Thanks to today's episode sponsor, Barricade Cyber Solutions

Have you fallen victim to a ransomware attack? Don't worry! Barricade Cyber Solutions has helped thousands of customers in situations just like yours. Their proprietary ransomware recovery services are designed to quickly get your business back on track. Their team of experts will identify the source of the attack and provide a comprehensive solution to prevent it from happening again. You can count on them for the security of your data and systems. Visit barricadecyber.com

For the stories behind the headlines, head to CISOseries.com.

View Details

Toyota finds more cloud leaks

Gigabyte firmware update system insecure

Twitter expands Community Notes to images

Thanks to today's episode sponsor, Barricade Cyber Solutions

Have you fallen victim to a ransomware attack? Don't worry! Barricade Cyber Solutions has helped thousands of customers in situations just like yours. Their proprietary ransomware recovery services are designed to quickly get your business back on track. Their team of experts will identify the source of the attack and provide a comprehensive solution to prevent it from happening again. You can count on them for the security of your data and systems. Visit barricadecyber.com

View Details

Leading experts warn of a risk of extinction from AI

Hackers demand $3 million from Scandinavian Airlines

Theranos founder turns herself in for 11-year prison term

Thanks to today's episode sponsor, Barricade Cyber Solutions

Have you fallen victim to a ransomware attack? Don't worry! Barricade Cyber Solutions has helped thousands of customers in situations just like yours. Their proprietary ransomware recovery services are designed to quickly get your business back on track. Their team of experts will identify the source of the attack and provide a comprehensive solution to prevent it from happening again. You can count on them for the security of your data and systems. Visit barricadecyber.com

For the stories behind the headlines, visit CISOseries.com.

View Details

New GobRAT remote access trojan targeting Linux routers in Japan

Attackers use encrypted RPMSG messages in Microsoft 365 targeted phishing attacks            

Hackers hold city of Augusta hostage in a ransomware attack

Thanks to today's episode sponsor, Barricade Cyber Solutions

Have you fallen victim to a ransomware attack? Don't worry! Barricade Cyber Solutions has helped thousands of customers in situations just like yours. Their proprietary ransomware recovery services are designed to quickly get your business back on track. Their team of experts will identify the source of the attack and provide a comprehensive solution to prevent it from happening again. You can count on them for the security of your data and systems. Visit barricadecyber.com

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

Cyber Security Headlines – Week in Review, May 22-26, is hosted by Rich Stroffolino with our guest, Rich Greenberg, ISSA Distinguished Fellow and Honor Roll

Thanks to our show sponsor, Sonrai Security

Did you know that 81% of breaches are due to compromised identities? It’s a sobering statistic and one that enterprise organizations cannot afford to ignore. Sonrai Security has made a name for itself by securing enterprise clouds from the inside out, securing every identity, access, and permission in the cloud. Download Sonrai Security’s new CIEM Buyer’s Guide to learn more about fortifying your cloud from the inside out at sonraisecurity.com.

All links and the video of this episode can be found on CISO Series.com

View Details

GDPR is 5 years old, and over 1 million people have asked to be forgotten

GitLab security update patches critical vulnerability

Mysterious malware designed to cripple industrial systems linked to Russia

And now a word from our sponsor, Sonrai Security

Did you know that 81% of breaches are due to compromised identities? It's a sobering statistic and one that enterprise organizations cannot afford to ignore. Sonrai Security has made a name for itself by securing enterprise clouds from the inside out, securing every identity, access, and permission in the cloud. Download Sonrai Security’s new CIEM Buyer’s Guide to learn more about fortifying your cloud from the inside out at sonraisecurity.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Google launches GUAC

Barracuda gateways breached by zero-day

Cyberattacks focus on Kenya’s Chinese debt

And now a word from our sponsor, Sonrai Security

Did you know that 81% of breaches are due to compromised identities? It's a sobering statistic and one that enterprise organizations cannot afford to ignore. Sonrai Security has made a name for itself by securing enterprise clouds from the inside out, securing every identity, access, and permission in the cloud. Download Sonrai Security’s new CIEM Buyer’s Guide to learn more about fortifying your cloud from the inside out at sonraisecurity.com.

View Details

TikTok sues Montana after state bans app

US sanctions orgs behind North Korea’s ‘illicit’ IT worker army

Fake images on Twitter briefly spook the stock market

And now a word from our sponsor, Sonrai Security

Did you know that 81% of breaches are due to compromised identities? It's a sobering statistic and one that enterprise organizations cannot afford to ignore. Sonrai Security has made a name for itself by securing enterprise clouds from the inside out, securing every identity, access, and permission in the cloud. Download Sonrai Security’s new CIEM Buyer’s Guide to learn more about fortifying your cloud from the inside out at sonraisecurity.com.

For the stories behind the headlines, visit CISOseries.com.

View Details

Meta receives record fine over EU data transfers

China bans Micron over cybersecurity risks

Crypto mixer hijacked

And now a word from our sponsor, Sonrai Security

Did you know that 81% of breaches are due to compromised identities? It's a sobering statistic and one that enterprise organizations cannot afford to ignore. Sonrai Security has made a name for itself by securing enterprise clouds from the inside out, securing every identity, access, and permission in the cloud. Download Sonrai Security’s new CIEM Buyer’s Guide to learn more about fortifying your cloud from the inside out at sonraisecurity.com.

View Details

HP rushes to fix bricked printers after faulty firmware update

PyPI repository under attack: User sign-ups and package uploads temporarily halted

New security flaw exposed in Samsung devices

And now a word from our sponsor, Sonrai Security

Did you know that 81% of breaches are due to compromised identities? It's a sobering statistic and one that enterprise organizations cannot afford to ignore. Sonrai Security has made a name for itself by securing enterprise clouds from the inside out, securing every identity, access, and permission in the cloud. Download Sonrai Security’s new CIEM Buyer’s Guide to learn more about fortifying your cloud from the inside out at sonraisecurity.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, May 15-19, is hosted by Rich Stroffolino with our guest, Dave Hannigan, CISO, Nubank

Thanks to our show sponsor, Hunters

There is nothing worse than relying on a legacy SIEM that your security team has out-grown, especially when it impacts your ability to detect real incidents. Hunters’ SOC Platform offers built-in, always up-to-date detection rules and automatic correlation that allow SOC analysts to focus on higher-value tasks that impact your organization. It’s time to move to a platform that reduces risk, complexity and cost for the SOC. Visit hunters.security to learn how you can Move Beyond SIEM and let them know you heard about Hunters on the CISO Series.

All links and the video of this episode can be found on CISO Series.com

View Details

Supreme Court shields Twitter from liability and leaves Section 230 untouched

Montana governor bans TikTok

Millions of smartphones distributed worldwide with preinstalled ‘Guerrilla’ malware

Thanks to today's episode sponsor, Hunters

There is nothing worse than relying on a legacy SIEM that your security team has out-grown, especially when it impacts your ability to detect real incidents. Hunters’ SOC Platform offers built-in, always up-to-date detection rules and automatic correlation that allow SOC analysts to focus on higher-value tasks that impact your organization. It’s time to move to a platform that reduces risk, complexity & cost for the SOC. Visit hunters.security to learn how you can Move Beyond SIEM and let them know you heard about Hunters on the CISO Series.

For the stories behind the headlines, head to CISOseries.com.

View Details

Lancefly group hits Asia

Meta facing record EU privacy fine

New TLDs a vector for phishing

Thanks to today's episode sponsor, Hunters

There is nothing worse than relying on a legacy SIEM that your security team has out-grown, especially when it impacts your ability to detect real incidents. Hunters’ SOC Platform offers built-in, always up-to-date detection rules and automatic correlation that allow SOC analysts to focus on higher-value tasks that impact your organization. It’s time to move to a platform that reduces risk, complexity & cost for the SOC. Visit hunters.security to learn how you can Move Beyond SIEM and let them know you heard about Hunters on the CISO Series.

View Details

An inside look at RaaS

White House cyber strategy goes big on education

Chinese attackers hit TP-Link routers

Thanks to today's episode sponsor, Hunters

If your SIEM is causing an endless cycle of noisy alerts, manually writing generic detection rules, and limited data ingestion & retention, your SOC might need an upgrade. Hunters is a SaaS platform, purpose built for your Security Operations team. Solaris Group, a leading German FinTech, implemented Hunters SOC Platform to eliminate the burden of redundant detection engineering and manual event correlation – allowing SOC analysts to focus on higher-value tasks. Visit hunters.security to learn how your SOC can Move Beyond SIEM and let them know you heard about Hunters on the CISO Series.

View Details

Cyber attack hits Philadelphia Inquirer

Transportation Department cyber breach exposes federal employee data

3 million data breach notices being sent to SchoolDude users 

Thanks to today's episode sponsor, Hunters

Relying on a SIEM in 2023 is like living in a college dorm room, post-graduation - you’re operating in an environment you’ve out-grown. The Hunters SOC Platform is purpose built to help your Security Operations mature to the level you need to be at. ChargePoint, the world's largest network of electric vehicle charging stations, uses Hunters SOC Platform to leverage its out-of-the-box detection content to more efficiently respond to new threats and vulnerabilities. It’s time to Move Beyond SIEM. Visit Hunters.security to learn more and let them know you heard about Hunters on the CISO Series.

For the stories behind the headlines, visit CISOseries.com.

View Details

Discord suffers data breach

Car location data of 2 million Toyota customers exposed for ten years

Swiss tech giant ABB confirms ‘IT security incident’

Thanks to today's episode sponsor, Hunters

Hunters is a SOC platform, built for your security team. Hunters empowers companies to move beyond SIEM with unlimited ingestion and normalization of security data at a predictable cost. Using Hunters, a CISO at a leading online retailer “tripled the amount of data ingested by her security team while cutting costs from a legacy SIEM provider by 75%.” It’s time to Move Beyond SIEM. Visit hunters.security to learn more and let them know you heard about Hunters on the CISO Series.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

Cyber Security Headlines – Week in Review, May 8-12, is hosted by Rich Stroffolino with our guest, Paul Connelly, Former CISO, HCA Healthcare

Thanks to today’s episode sponsor, Trend Micro

Cybersecurity is not just about protection, it’s about foresight, agility, and resilience. Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks. Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind. Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.

All links and the video of this episode can be found on CISO Series.com

View Details

Twitter launches encrypted private messages

Microsoft releases fix for patched Outlook issue exploited by Russian hackers

North Korea-linked APT group breaches the Seoul National University Hospital

Thanks to today's episode sponsor, TrendMicro

Cybersecurity is not just about protection, it’s about foresight, agility, and resilience. Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks. Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind. Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.

For the stories behind the headlines, head to CISOseries.com.

View Details

The long term impact of leaked Intel Boot Guard keys

AtlasOS shrugs at Windows security features

Cisco warns of new phishing-as-a-service tool

Thanks to today's episode sponsor, TrendMicro

Cybersecurity is not just about protection, it’s about foresight, agility, and resilience. Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks. Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind. Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.

View Details

Operation Medusa takes down ‘Snake’ malware network

‘PlugwalkJoe’ pleads guilty to massive 2020 Twitter hack

Justice Department takes down 13 DDoS-for-Hire sites

Thanks to today's episode sponsor, TrendMicro

Cybersecurity is not just about protection, it’s about foresight, agility, and resilience. Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks. Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind. Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.

For the stories behind the headlines, visit CISOseries.com.

View Details

Dallas still reeling from ransomware

Hacked Facebook pages buying Facebook ads

Court rules on Merck cyber insurance claim

Thanks to today's episode sponsor, TrendMicro

Cybersecurity is not just about protection, it’s about foresight, agility, and resilience. Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks. Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind. Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.

View Details

Top US cyber official warns AI may be the ‘most powerful weapon of our time’

Ex-Uber CSO given three-year probation sentence, avoids prison after guilty verdict

Ransomware group behind Oakland attack targets city in Massachusetts

Thanks to today's episode sponsor, TrendMicro

Cybersecurity is not just about protection, it’s about foresight, agility, and resilience. Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks. Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind. Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, May 1-5, is hosted by Rich Stroffolino with our guest, Allison Miller, Cybersecurity and Technology Executive

Thanks to our show sponsor, Trend Micro

Cybersecurity is not just about protection, it’s about foresight, agility, and resilience. Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks. Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind. Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.

All links and the video of this episode can be found on CISO Series.com

View Details

City of Dallas hit by Royal ransomware attack impacting IT services

Researchers uncover new exploit for PaperCut vulnerability that can bypass detection

Mirai botnet loves exploiting unpatched TP-Link routers, CISA warns

Thanks to today's episode sponsor, TrendMicro

Cybersecurity is not just about protection, it’s about foresight, agility, and resilience. Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks. Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind. Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.

For the stories behind the headlines, head to CISOseries.com.

View Details

FTC comes down on Meta monetizing minors

CISA urges adoption of Covered List

Almost half of HTML attachments found malicious

Thanks to today's episode sponsor, TrendMicro

Cybersecurity is not just about protection, it’s about foresight, agility, and resilience. Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks. Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind. Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.

View Details

Authorities seize 9 crypto exchanges used for money laundering

T-Mobile discloses 2nd data breach of 2023

‘Godfather of AI’ quits Google and warns of misinformation dangers

Thanks to today's episode sponsor, TrendMicro

Cybersecurity is not just about protection, it’s about foresight, agility, and resilience. Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks. Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind. Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.

For the stories behind the headlines, visit CISOseries.com.

View Details

The academic threat of juice jacking

Data breach lawsuits on the rise

Telegram ban lifted in Brazil

Thanks to today's episode sponsor, TrendMicro

Cybersecurity is not just about protection, it’s about foresight, agility, and resilience. Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks. Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind. Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.

View Details

Hackers target vulnerable Veeam backup servers exposed online

DOJ detected the SolarWinds hack 6 months earlier than first disclosed

Cold storage giant Americold outage caused by network breach

Thanks to today's episode sponsor, TrendMicro

Cybersecurity is not just about protection, it’s about foresight, agility, and resilience. Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks. Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind. Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, April 24-28, is hosted by Sean Kelly with our guest, Steve Zalewski, former CISO, Levi Strauss and co-host, Defense in Depth.

Thanks to today’s episode sponsor, Tines

Ready to take security automation up a notch? With Tines, it’s easier than ever! The no-code automation platform is redefining and simplifying security operations – start building mission-critical workflows and apps that streamline processes AND ensure crucial data stays safe while extending the influence of your security team throughout your organization. Visit Tines.com to find out more!

All links and the video of this episode can be found on CISO Series.com

View Details

Charming Kitten APT uses a new BellaCiao malware

Microsoft blames clop affiliate for PaperCut attacks

Big tech crackdown looms as EU, UK ready new rules

And now a word from our sponsor, Tines

Ready to take security automation up a notch? With Tines, it’s easier than ever! The no-code automation platform is redefining and simplifying security operations - start building mission-critical workflows and apps that streamline processes AND ensure crucial data stays safe while extending the influence of your security team throughout your organization. Visit Tines.com to find out more!

For the stories behind the headlines, head to CISOseries.com.

View Details

Messaging app update distributes malware

China reclassifies cyberattacks

Malware-free cyberattacks on the rise

And now a word from our sponsor, Tines

Ask anyone at RSA; security teams can’t operate in a silo. No SOAR solutions enable users to dynamically collect information outside their systems and use it at multiple points in an automated workflow - but Tines does! With Tines, users can exchange real-time information outside its platform and use it to drive automated workflows. Visit Tines.com/build to learn more!

View Details

US policing use of AI for civil rights violations

Bill proposes new security testing centers for critical government tech

Microsoft Edge is leaking user browsing data to Bing

And now a word from our sponsor, Tines

To proactively protect against threats, you need a culture of cybersecurity - and solutions that facilitate this. With Tines’ no-code automation platform, you can: 1. Remediate threats faster. 2. Improve automation. 3. Control access to your data. 4. Create a culture of cybersecurity. Tines allows users to leverage real-time information across any stage of an automated workflow! Visit Tines.com to learn more.

For the stories behind the headlines, visit CISOseries.com.

View Details

A call to standardize threat group naming

Threat actors using new tool to disable EDR

North Dakota turns to AI for cyber

And now a word from our sponsor, Tines

Ready to take security automation up a notch? With Tines, it’s easier than ever! The no-code automation platform is redefining and simplifying security operations - start building mission-critical workflows and apps that streamline processes AND ensure crucial data stays safe while extending the influence of your security team throughout your organization. Visit Tines.com to find out more.

View Details

Energy sector orgs in US, Europe hit by same supply chain attack as 3CX

CISA adds 3 actively exploited flaws to KEV catalog, including critical PaperCut bug

Hyena code poised to devour GPT4

And now a word from our sponsor, Tines

Ask anyone at RSA; security teams can’t operate in a silo. No SOAR solutions enable users to dynamically collect information outside their systems and use it at multiple points in an automated workflow - but Tines does! With Tines, users can exchange real-time information outside its platform and use it to drive automated workflows. Visit Tines.com/build to learn more!

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, April 17-21, is hosted by Rich Stroffolino with our guest, Shawn Bowen, CISO, World Fuel Services

Thanks to our show sponsor, Pentera

This episode of Cyber Security Headlines is made possible in part by Pentera. Today over 60% of cyber attacks involve the use of exposed credentials. Now, for the first time, security teams can address this critical threat head-on. Pentera collects an organization’s leaked credentials and automatically tests their exploitability across the external and internal attack surface.  Pentera’s customers find that leveraging the Pentera automated security validation platform as part of their exposure management strategy increases their ability to identify security gaps, improves the efficiency of remediation processes, and maximizes their security readiness. To learn more, visit Pentera.io

All links and the video of this episode can be found on CISO Series.com

View Details

Microsoft 365 outage blocks access to web apps and services

Capita has 'evidence' customer data was stolen in digital burglary

3CX supply chain attack was the result of a previous supply chain attack

Thanks to today's episode sponsor, Pentera 

This episode of Cyber Security Headlines is made possible in part by Pentera. Today over 60% of cyber attacks involve the use of exposed credentials. Now, for the first time, security teams can address this critical threat head-on. Pentera collects an organization’s leaked credentials and automatically tests their exploitability across the external and internal attack surface. Pentera’s customers find that leveraging the Pentera automated security validation platform as part of their exposure management strategy increases their ability to identify security gaps, improves the efficiency of remediation processes, and maximizes their security readiness. To learn more, visit Pentera.io

For the stories behind the headlines, head to CISOseries.com.

View Details

NCSC warns of “new class” of Russian adversaries

GitHub adds Action to help open source security

Used routers hold on to secrets

Thanks to today's episode sponsor, Pentera 

This episode of Cyber Security Headlines is made possible in part by Pentera. Today over 60% of cyber attacks involve the use of exposed credentials. Now, for the first time, security teams can address this critical threat head-on. Pentera collects an organization’s leaked credentials and automatically tests their exploitability across the external and internal attack surface. Pentera’s customers find that leveraging the Pentera automated security validation platform as part of their exposure management strategy increases their ability to identify security gaps, improves the efficiency of remediation processes, and maximizes their security readiness. To learn more, visit Pentera.io

View Details

Elon Musk wants to develop TruthGPT

Southwest’s operations resume after a ‘technical issue’

US, UK warn of govt hackers targeting Cisco routers

Thanks to today's episode sponsor, Pentera 

This episode of Cyber Security Headlines is made possible in part by Pentera. Today over 60% of cyber attacks involve the use of exposed credentials. Now, for the first time, security teams can address this critical threat head-on. Pentera collects an organization’s leaked credentials and automatically tests their exploitability across the external and internal attack surface. Pentera’s customers find that leveraging the Pentera automated security validation platform as part of their exposure management strategy increases their ability to identify security gaps, improves the efficiency of remediation processes, and maximizes their security readiness. To learn more, visit Pentera.io

For the stories behind the headlines, head to CISOseries.com.

View Details

Ransomware comes for macOS

The security considerations of low code

Israeli offensive cyber company shutting down

Thanks to today's episode sponsor, Pentera 

This episode of Cyber Security Headlines is made possible in part by Pentera. Today over 60% of cyber attacks involve the use of exposed credentials. Now, for the first time, security teams can address this critical threat head-on. Pentera collects an organization’s leaked credentials and automatically tests their exploitability across the external and internal attack surface. Pentera’s customers find that leveraging the Pentera automated security validation platform as part of their exposure management strategy increases their ability to identify security gaps, improves the efficiency of remediation processes, and maximizes their security readiness. To learn more, visit Pentera.io

View Details

Microsoft warns of Remcos RAT campaign targeting tax accountants

NCR suffers POS outage after BlackCat ransomware attack

Google releases urgent Chrome update to fix actively exploited zero-day vulnerability

Thanks to today's episode sponsor, Pentera 

This episode of Cyber Security Headlines is made possible in part by Pentera. Today over 60% of cyber attacks involve the use of exposed credentials. Now, for the first time, security teams can address this critical threat head-on. Pentera collects an organization’s leaked credentials and automatically tests their exploitability across the external and internal attack surface. Pentera’s customers find that leveraging the Pentera automated security validation platform as part of their exposure management strategy increases their ability to identify security gaps, improves the efficiency of remediation processes, and maximizes their security readiness. To learn more, visit Pentera.io

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, April 10-14, is hosted by Rich Stroffolino with our guest, Dmitriy Sokolovskiy, CISO, Avid

Thanks to our show sponsor, AppOmni

Can you name all the third party apps connected to your major SaaS platforms, like Salesforce,  Microsoft 365, or Google Workspace? What about the data these apps can access? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk. With AppOmni, you get visibility to all third party apps and SaaS-to-SaaS connections — including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com today to request a free risk assessment.

All links and the video of this episode can be found on CISO Series.com

View Details

Weak passwords targeted on Google Cloud

Potential IT snitches warned about employment stitches

Discord cooperating with leaked document investigation

And now a word from our sponsor, AppOmni 

Can you name all the third party apps connected to your major SaaS platforms, like Salseforce,  Microsoft 365, or Google Workspace? What about the data these apps can access? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk. With AppOmni, you get visibility to all third party apps and SaaS-to-SaaS connections — including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com today to request a free risk assessment.

View Details

Windows zero-day exploited in Nokoyawa ransomware attacks

LinkedIn and Microsoft Entra introduce a new way to verify professional contacts

Russian places Ukraine internet infrastructure clearly in its sights, both high tech and low

And now a word from our sponsor, AppOmni 

Can you name all the third party apps connected to your major SaaS platforms, like Salseforce,  Microsoft 365, or Google Workspace? What about the data these apps can access? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk. With AppOmni, you get visibility to all third party apps and SaaS-to-SaaS connections — including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com today to request a free risk assessment.

For the stories behind the headlines, head to CISOseries.com.

View Details

Microsoft warns of Azure shared key authorization abuse

Attackers hide stealer behind AI chatbot Facebook ads

OpenAI to launch bug bounty program

And now a word from our sponsor, AppOmni 

Can you name all the third party apps connected to your major SaaS platforms, like Salseforce,  Microsoft 365, or Google Workspace? What about the data these apps can access? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk. With AppOmni, you get visibility to all third party apps and SaaS-to-SaaS connections — including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com today to request a free risk assessment.

For the stories behind the headlines, visit CISOseries.com.

View Details

Netherlands to adopt RPKI

Widespread backdoor installed on WordPress sites

Tracing leaked Pentagon documents

And now a word from our sponsor, AppOmni 

Can you name all the third party apps connected to your major SaaS platforms, like Salseforce,  Microsoft 365, or Google Workspace? What about the data these apps can access? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk. With AppOmni, you get visibility to all third party apps and SaaS-to-SaaS connections — including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com today to request a free risk assessment.

View Details

Apple releases updates to address zero-day flaws

Flipper Zero banned by Amazon for being a ‘card skimming device’

China to probe Micron over cybersecurity, in chip war’s latest battle

And now a word from our sponsor, AppOmni 

Can you name all the third party apps connected to your major SaaS platforms, like Salseforce,  Microsoft 365, or Google Workspace? What about the data these apps can access? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk. With AppOmni, you get visibility to all third party apps and SaaS-to-SaaS connections — including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com today to request a free risk assessment.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, April 3-7, is hosted by Rich Stroffolino with our guest, Rich Gautier, former CISO, Department of Justice, Criminal Division

Was your address caught up in the Genesis Market? Check it here:

https://www.politie.nl/en/information/checkyourhack.html#check

Thanks to our show sponsor, Normalyze

Normalyze is a cloud data security platform that continuously discovers sensitive data and their access paths across your cloud environments. Normalyze provides the ability to analyze, prioritize and respond to data threats to prevent damaging data breaches. Their cloud-native platform manages data security posture and compliance by automatically tracking risks to sensitive data, visually showing teams who can access what, and quickly block unauthorized access or vulnerable points of attack. Discover, visualize, and secure your cloud data in minutes with Normalyze Freemium. Go to normalyze.ai.

All links and the video of this episode can be found on CISO Series.com

View Details

Criminal records office yanks web portal offline amid 'cyber security incident'

Samsung reportedly leaked its own secrets through ChatGPT

Money Message ransomware gang claims MSI breach, demands $4 million

Thanks to today's episode sponsor, Normalyze

Normalyze is a cloud data security platform that continuously discovers sensitive data and their access paths across your cloud environments. Normalyze provides the ability to analyze, prioritize and respond to data threats to prevent damaging data breaches.Their cloud-native platform manages data security posture and compliance by automatically tracking risks to sensitive data, visually showing  teams who can  access what, and quickly block unauthorized access or vulnerable points of attack.Discover, visualize, and secure your cloud data in minutes with Normalyze Freemium. Go to normalyze.ai.

For the stories behind the headlines, head to CISOseries.com.

View Details

Prominent Spanish hacker arrested

The UK’s Offensive Cyber Capabilities Principles

eFile site serving malware

Thanks to today's episode sponsor, Normalyze

Normalyze is a cloud data security platform that continuously discovers sensitive data and their access paths across your cloud environments. Normalyze provides the ability to analyze, prioritize and respond to data threats to prevent damaging data breaches.Their cloud-native platform manages data security posture and compliance by automatically tracking risks to sensitive data, visually showing  teams who can  access what, and quickly block unauthorized access or vulnerable points of attack.Discover, visualize, and secure your cloud data in minutes with Normalyze Freemium. Go to normalyze.ai.

View Details

Genesis Market platform seized by police

Rorschach is now the fastest ransomware encryptor

Tax return software caught serving up malware

Thanks to today's episode sponsor, Normalyze

Normalyze is a cloud data security platform that continuously discovers sensitive data and their access paths across your cloud environments. Normalyze provides the ability to analyze, prioritize and respond to data threats to prevent damaging data breaches.Their cloud-native platform manages data security posture and compliance by automatically tracking risks to sensitive data, visually showing  teams who can  access what, and quickly block unauthorized access or vulnerable points of attack.Discover, visualize, and secure your cloud data in minutes with Normalyze Freemium. Go to normalyze.ai.

For the stories behind the headlines, visit CISOseries.com.

View Details

TMX reveals customer data leak

The security costs of remote work

Western Digital confirms network breach 

Thanks to today's episode sponsor, Normalyze

Normalyze is a cloud data security platform that continuously discovers sensitive data and their access paths across your cloud environments. Normalyze provides the ability to analyze, prioritize and respond to data threats to prevent damaging data breaches.Their cloud-native platform manages data security posture and compliance by automatically tracking risks to sensitive data, visually showing  teams who can  access what, and quickly block unauthorized access or vulnerable points of attack.Discover, visualize, and secure your cloud data in minutes with Normalyze Freemium. Go to normalyze.ai.

View Details

More evidence links 3CX supply-chain attack to North Korean hacking group

Hackers exploiting WordPress Elementor Pro Vulnerability, leaving millions of sites at risk

DISH slapped with multiple lawsuits after ransomware cyber attack

Thanks to today's episode sponsor, Normalyze

Normalyze is a cloud data security platform that continuously discovers sensitive data and their access paths across your cloud environments. Normalyze provides the ability to analyze, prioritize and respond to data threats to prevent damaging data breaches.Their cloud-native platform manages data security posture and compliance by automatically tracking risks to sensitive data, visually showing  teams who can  access what, and quickly block unauthorized access or vulnerable points of attack.Discover, visualize, and secure your cloud data in minutes with Normalyze Freemium. Go to normalyze.ai.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, March 27-31, is hosted by Rich Stroffolino with our guest, Brett Conlon, CISO, American Century Investments

Thanks to today’s episode sponsor, Trend Micro

Cybersecurity is not just about protection, it’s about foresight, agility, and resilience. Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks. Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind. Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.

All links and the video of this episode can be found on CISO Series.com

View Details

Supply-chain attack on business phone provider 3CX could impact thousands of companies

Vulkan files leak reveals Putin’s global and domestic cyberwarfare tactics

Bing search results hijacked via misconfigured Microsoft app

Thanks to today's episode sponsor, Trend Micro

Cybersecurity is not just about protection, it’s about foresight, agility, and resilience.

Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks.

Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind.

Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.

For the stories behind the headlines, head to CISOseries.com.

View Details

Flaw found in WiFi protocol

Environmental activists targeted by threat actors

Open letter calls for AI “pause”

Thanks to today's episode sponsor, Trend Micro

Cybersecurity is not just about protection, it’s about foresight, agility, and resilience.

Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks.

Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind.

Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.

View Details

Microsoft unveils OpenAI-based chat tools to combat cyberattacks

Google accused of willfully destroying evidence in antitrust battle

A million pen tests show companies' security postures are getting worse

Thanks to today's episode sponsor, Trend Micro

Cybersecurity is not just about protection, it’s about foresight, agility, and resilience.

Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks.

Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind.

Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.

For the stories behind the headlines, visit CISOseries.com.

View Details

Pinduoduo malware confirmed

Binance sued by CFTC 

Twitter source code takedown 

Thanks to today's episode sponsor, Trend Micro

Cybersecurity is not just about protection, it’s about foresight, agility, and resilience.

Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks.

Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind.

Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.

View Details

UK bans TikTok from government mobile phones

Microsoft pushes OOB security updates for Windows Snipping tool flaw

Vice Society claims attack on Puerto Rico Aqueduct and Sewer Authority

Thanks to today's episode sponsor, Trend Micro

Cybersecurity is not just about protection, it’s about foresight, agility, and resilience.

Navigating a new era of cyber risk demands evolved strategies, new frameworks, and integrated tools to equip security teams to anticipate and defend against even the most advanced attacks.

Trend Micro, the global leader in cybersecurity is bringing the cyber risk conversation to more than 120 cities around the world in their latest “Risk to Resilience World Tour” — The largest cybersecurity roadshow of its kind.

Find the closest city to you and register today to take a leap towards a more resilient future. Head to TrendMicro.com/cisoseries.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, March 20-24, is hosted by David Spark with our guest, Kurt Sauer, VP, Information security, Workday

Thanks to today’s episode sponsor, Conveyor

Does the thought of answering another security questionnaire make you want to beat the stuffing out of 32 pinatas? Then you might want to check out Conveyor: the end-to-end trust platform helping infosec teams reduce incoming questionnaires and fly through the ones they do have to complete. Give customers access to a self-serve trust portal to download docs and FAQs. For any remaining questionnaires that do come in, use our GPT-Questionnaire response tool or white-glove questionnaire completion service to knock them completely off your to-do list. Learn more at www.conveyor.com.

All links and the video of this episode can be found on CISO Series.com

View Details

Dole discloses data breach after February ransomware attack

New Android banking trojan targets financial apps

Pwn2Own Vancouver 2023 Day 1: Windows 11 and Tesla hacked

Thanks to this week's episode sponsor, Conveyor

Does the thought of answering another security questionnaire make you want to beat the stuffing out of 32 pinatas? Then you might want to check out Conveyor: the end-to-end trust platform helping infosec teams reduce incoming questionnaires and fly through the ones they do have to complete. Give customers access to a self-serve trust portal to download docs and FAQs. For any remaining questionnaires that do come in, use our GPT-Questionnaire response tool or white-glove questionnaire completion service to knock them completely off your to-do list. Learn more at www.conveyor.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Another image editor leaks data

More Clop victims come forward

Big tech lobbies to limit spying law

Thanks to this week's episode sponsor, Conveyor

Does the thought of answering another security questionnaire make you feel like clearing out the ice cream section at your local grocery store? Though we fully support the ice cream thing, you might want to check out Conveyor first: the end-to-end trust platform helping infosec teams reduce incoming questionnaires and fly through the ones they do have to complete. Give customers access to a self-serve trust portal to download security info and for any remaining questionnaires that do come in, use our GPT-Questionnaire response tool or white-glove questionnaire completion service to knock them completely off your to-do list. Learn more at www.conveyor.com.

View Details

BreachForums to shut down amidst law enforcement concerns

Hackers use zero-day to drain $1.6 million from Bitcoin ATMs

DC Health Link hacker motivated by Russian patriotism

Thanks to this week's episode sponsor, Conveyor

Does the mountain of security questionnaires in your inbox make you feel like a 2 dollar umbrella in a hurricane? Then you might want to check out Conveyor: the end-to-end trust platform helping infosec teams reduce incoming questionnaires and fly through the ones they do have to complete. Give customers access to a self-serve trust portal to download docs and FAQs. For any remaining questionnaires that do come in, use our  GPT-Questionnaire response tool or white-glove questionnaire completion service to knock them completely off your to-do list. Learn more at www.conveyor.com.

For the stories behind the headlines, visit CISOseries.com.

View Details

China led zero-days in 2022

HinataBot focuses on DDoS attacks

Vulnerability lets you uncrop screenshots

Thanks to this week's episode sponsor, Conveyor

Does the thought of answering another security questionnaire make you want to beat the stuffing out of 32 pinatas? Then you might want to check out Conveyor: the end-to-end trust platform helping infosec teams reduce incoming questionnaires and fly through the ones they do have to complete. Give customers access to a self-serve trust portal to download docs and FAQs. For any remaining questionnaires that do come in, use our GPT-Questionnaire Eliminator response tool or white-glove questionnaire completion service to knock them completely off your to-do list. Learn more at www.conveyor.com.

View Details

NBA is warning fans of a data breach after a third-party newsletter service hack

Emotet malware now distributed in Microsoft OneNote files to evade defenses

Dutch shipping giant Royal Dirkzwager confirms Play ransomware attack

Thanks to this week's episode sponsor, Conveyor

Love security questionnaires? Then you’re going to hate Conveyor: the end-to-end trust platform built to eliminate questionnaires. Infosec teams have reduced questionnaires by 80% by giving their customers access to our self-serve trust portal to download docs and answers. For any remaining questionnaires that do come in, use our GPT-Questionnaire Eliminator response tool or white-glove questionnaire completion service to knock them off your to-do list. Use all 3 parts of the platform to solve the questionnaire problem or start with one. Learn more at www.conveyor.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, March 13-17, is hosted by Rich Stroffolino  with our guest, JJ Agha, CISO, FanDuel

All links and the video of this episode can be found on CISO Series.com

View Details

US Government IIS server breached via Telerik software flaw

Critical Microsoft Outlook bug PoC shows how easy it is to exploit

LockBit threatens release of thousands of SpaceX blueprints

Brought to you by the CISO Series.

For the stories behind the headlines, head to CISOseries.com.

View Details

Two charged in DEA portal hack

Americans lose billions in scams

TikTok considering divestment

Brought to you by the CISO Series.

View Details

Microsoft warns of large-scale use of phishing kits to send millions of emails daily

Ransomware group claims hack of Amazon's Ring

CISA creates new ransomware vulnerability warning program

Brought to you by the CISO Series.

For the stories behind the headlines, head to CISOseries.com.

View Details

North Korea targets security researchers

UK launches National Protective Security Authority

Bank failures bleed into crypto

Brought to you by the CISO Series.

View Details

FBI and international authorities catch a NetWire RAT

CISA warns of actively exploited Plex bug after LastPass breach

Blackbaud to pay $3 million for misleading ransomware disclosure

For the stories behind the headlines, visit CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, March 6-10, is hosted by Rich Stroffolino  with our guest, Nick Espinosa, Host, The Deep Dive Radio Show (Daily Podcast & Daily Videos)

Thanks to our show sponsor, Packetlabs

Trust the ethical hackers at Packetlabs for expert penetration testing services. Our certified professionals specialize in strengthening your security posture. Download our free Penetration Testing Buyers Guide at ciso.packetlabs.net and get the top 20 questions to ask third party vendors before hiring them. Let us guide you through the process and help you find the perfect match for your organization’s security needs.

All links and the video of this episode can be found on CISO Series.com

View Details

Biden’s budget seeks increase in cybersecurity spending

AT&T alerts 9 million customers of data breach after vendor hack

GitHub makes 2FA mandatory next week for active developers

Thanks to today's episode sponsor, Packetlabs

Trust the ethical hackers at Packetlabs for expert penetration testing services. Our certified professionals specialize in strengthening your security posture. Download our free Penetration Testing Buyers Guide at ciso.packetlabs.net and get the top 20 questions to ask third party vendors before hiring them. Let us guide you through the process and help you find the perfect match for your organization's security needs.

For the stories behind the headlines, head to CISOseries.com.

View Details

TSA issues cybersecurity regulations

Lazarus Group deploys zero-day

Ransomware gang uses video ransom note

Thanks to today's episode sponsor, Packetlabs

Reduce cyber insurance premiums and minimize risk. Learn how a thorough penetration test can benefit your business. Download our Penetration Testing Buyers Guide at ciso.packetlabs.ca. Packetlabs is an ethical hacking firm that will simulate real-world, covert attacks to get answers to your “what if” scenarios. Protect your business from cyber attacks and get the most out of your penetration testing investment with Packetlabs, your friendly neighborhood ethical hackers.

View Details

Bipartisan bill allows for US ban of TikTok

EU concerned with Twitter’s content moderation plans

Emotet malware returns after three-month hiatus

Thanks to today's episode sponsor, Packetlabs

Looking for the right cybersecurity service provider can be a daunting task. How do you know if they're trustworthy and reliable? Packetlabs has made it easier for you with our free Penetration Testing buyers guide. We've compiled a list of the top 20 questions you should ask potential providers to ensure you make an informed decision. Download the guide today at ciso.packetlabs.net.

For the stories behind the headlines, visit CISOseries.com.

View Details

Police disrupt DoppelPaymer

EPA releases cybersecurity notice for water systems

Cloud exploitation on the rise

Thanks to today's episode sponsor, Packetlabs

Struggling to justify cybersecurity investments to decision-makers? Meet ROSI, the superhero of cybersecurity investments! Calculate your Return On Security Investment to quantify the value of prevention and save money by avoiding cybersecurity breaches. ROSI builds synergies between your business, security, and finance teams, bringing everyone together. Download our free buyer's guide to learn the ROSI formula, how to reduce cyber insurance premiums, and what to look for in a provider. Visit ciso.packetlabs.net and unleash the power of ROSI in your c-suite discussions today!

View Details

U.S. Government warns of Royal ransomware attacks against critical infrastructure

Credential Stuffing attack on Chick-fil-A

Play Ransomware gang has begun to leak data stolen from City of Oakland

Thanks to today's episode sponsor, Packetlabs

Concerned about your organization's data security? Privacy breaches, ransomware attacks, insider threats, and intellectual property theft are on the rise. A one-size-fits-all vulnerability assessment scan no longer suffices. Get our Penetration Testing Buyer's guide to help plan, scope, and execute your projects. Discover valuable information on frameworks, standards, methodologies, cost factors, reporting options, and what to look for in a provider. Choose the right ethical hacking firm to uncover vulnerabilities in your IT and network systems. Download your free copy at ciso.packetlabs.net and take control of your cybersecurity today.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines - Week in Review, February 27-March 3, is hosted by Rich Stroffolino  with our guest, Nick Vigier, CISO, Talend

Thanks to our show sponsor, Conveyor

Just because your security questionnaire is from the stone age, doesn’t mean you have to answer it with cave-era tools. At Conveyor, we implemented GPT-3 into our first-of-its-kind questionnaire eliminator so teams of all sizes can blast through questionnaires faster than you can say “prehistoric”. Go beyond re-writing mediocre matches, to getting your questionnaire auto-filled with the exact answers customers need. Join the top SaaS companies in the GPT-3 powered future by using Conveyor. Learn more at conveyor.com.

All links and the video of this episode can be found on CISO Series.com

View Details

White House gets tough with new National Cyber Strategy

CISA releases free ‘Decider’ tool to help with MITRE ATT&CK mapping

British retail chain WH Smith says data stolen in cyberattack

Thanks to this week's episode sponsor, Conveyor

Just because your security questionnaire is from the stone age, doesn’t mean you have to answer it with cave-era tools. At Conveyor, we implemented GPT-3 into our first-of-its-kind questionnaire eliminator so teams of all sizes can blast through questionnaires faster than you can say “prehistoric”. Go beyond re-writing mediocre matches, to getting your questionnaire auto-filled with the exact answers customers need. Join the top SaaS companies in the GPT-3 powered future by using Conveyor. Learn more at conveyor.com.

For the stories behind the headlines, head to CISOseries.com. 

View Details

Russia bans foreign private messaging apps

GitHub expands secret scanning

Bootkit bypasses Secure Boot

Thanks to this week's episode sponsor, Conveyor

“I HATE security questionnaires with the fury of a thousand suns.” said one of our customers. Makes sense, since tools used to answer them haven’t changed in years. At Conveyor, we’re on a mission to get teams out of the questionnaire stone age by implementing GPT-3 into our first-of-its-kind questionnaire eliminator. Go beyond re-writing mediocre matches, to getting your questionnaire auto-filled with the exact answers customers need. Join the top SaaS companies in the GPT-3 powered future by using Conveyor. Learn more at conveyor.com.

View Details

US Marshals hit by ransomware

DISH outages caused by confirmed ransomware attack

Some more bad news for LastPass 

Thanks to this week's episode sponsor, Conveyor

AI can now literally answer any question on the internet in seconds, yet infosec teams are still in a living nightmare manually filling out security questionnaires with existing tools. Get out of the questionnaire stone age with Conveyor’s new questionnaire eliminator tool powered by GPT-3. It provides perfectly crafted answers to questionnaires all within minutes and review now takes seconds. Join the top SaaS companies in the GPT-3 powered future by using Conveyor. Learn more at conveyor.com.

For the stories behind the headlines, visit CISOseries.com.

View Details

CISA says to stop passing the security buck

The cyber security fallout of Russia’s war in Ukraine

Canada bans TikTok on government devices

Thanks to this week's episode sponsor, Conveyor

Just because your security questionnaire is from the stone age, doesn’t mean you have to answer it with cave-era tools. At Conveyor, we implemented GPT-3 into our first-of-its-kind questionnaire eliminator so teams of all sizes can blast through questionnaires faster than you can say “prehistoric”. Go beyond re-writing mediocre matches, to getting your questionnaire auto-filled with the exact answers customers need. Join the top SaaS companies in the GPT-3 powered future by using Conveyor. Learn more at conveyor.com.

View Details

News Corp reveals that attackers remained on its network for two years

TELUS investigating leak of stolen source code, employee data

Dish Network goes offline after likely cyberattack, employees cut off

Thanks to this week's episode sponsor, Conveyor

AI can now literally answer any question on the internet in seconds, yet infosec teams are still living a nightmare manually filling out security questionnaires with existing tools. Get out of the questionnaire stone age with Conveyor’s new questionnaire eliminator tool powered by GPT-3. Go beyond re-writing mediocre matches, to getting your questionnaire auto-filled with the exact answers customers need in minutes. Join the top SaaS companies in the GPT-3 powered future by using Conveyor. Learn more at conveyor.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, February 20-24, is hosted by Rich Stroffolino  with our guest, Jared Mendenhall, Head of Information Security, Impossible Foods

Thanks to our show sponsor, Barricade Cyber

Have you fallen victim to a ransomware attack? Don’t worry! Barricade Cyber Solutions has helped thousands of customers in situations just like yours. Our proprietary ransomware recovery services are designed to quickly get your business back on track. Our team of experts will identify the source of the attack and provide a comprehensive solution to prevent it from happening again. You can count on us for the security of your data and systems. Visit barricadecyber.com

All links and the video of this episode can be found on CISO Series.com

View Details

Fruit giant Dole suffers ransomware attack impacting operations

Stress pushing CISOs out the door

Lazarus group likely using new backdoor to exfiltrate sensitive data

Thanks to this week's episode sponsor, Barricade Cyber Solutions

Have you fallen victim to a ransomware attack? Don't worry! Barricade Cyber Solutions has helped thousands of customers in situations just like yours. Our proprietary ransomware recovery services are designed to quickly get your business back on track. Our team of experts will identify the source of the attack and provide a comprehensive solution to prevent it from happening again. You can count on us to the security of your data and systems. Visit barricadecyber.com

For the stories behind the headlines, head to CISOseries.com.

View Details

Threat actors cry Havoc, let slip a new post-exploitation framework

VMware warns of critical Carbon Black flaw

Ransomware attack time shrinking rapidly

Thanks to this week's episode sponsor, Barricade Cyber Solutions

Have you fallen victim to a ransomware attack? Don't worry! Barricade Cyber Solutions has helped thousands of customers in situations just like yours. Our proprietary ransomware recovery services are designed to quickly get your business back on track. Our team of experts will identify the source of the attack and provide a comprehensive solution to prevent it from happening again. You can count on us to the security of your data and systems. Visit barricadecyber.com

View Details

Apple updates advisories as security firm discloses new class of vulnerabilities

Sensitive US military emails spill online

Russian state TV website goes down during Putin speech

Thanks to this week's episode sponsor, Barricade Cyber Solutions

Have you fallen victim to a ransomware attack? Don't worry! Barricade Cyber Solutions has helped thousands of customers in situations just like yours. Our proprietary ransomware recovery services are designed to quickly get your business back on track. Our team of experts will identify the source of the attack and provide a comprehensive solution to prevent it from happening again. You can count on us to the security of your data and systems. Visit barricadecyber.com

For the stories behind the headlines, head to CISOseries.com.

View Details

Samsung guards against zero-click attacks 

Rethinking ransomware cat and mouse

Norway seizes Lazarus Group crypto

Thanks to this week's episode sponsor, Barricade Cyber Solutions

Have you fallen victim to a ransomware attack? Don't worry! Barricade Cyber Solutions has helped thousands of customers in situations just like yours. Our proprietary ransomware recovery services are designed to quickly get your business back on track. Our team of experts will identify the source of the attack and provide a comprehensive solution to prevent it from happening again. You can count on us to the security of your data and systems. Visit barricadecyber.com

View Details

Hackers backdoor Microsoft IIS servers with new Frebniis malware

Twitter limits SMS-based 2-factor authentication to Blue subscribers only

Fortinet issues patches for 40 flaws

Thanks to this week's episode sponsor, Barricade Cyber Solutions

Have you fallen victim to a ransomware attack? Don't worry! Barricade Cyber Solutions has helped thousands of customers in situations just like yours. Our proprietary ransomware recovery services are designed to quickly get your business back on track. Our team of experts will identify the source of the attack and provide a comprehensive solution to prevent it from happening again. You can count on us to the security of your data and systems. Visit barricadecyber.com

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, February 13-17, is hosted by Sean Kelly with our guest, George Al-Koura, CISO, Ruby

Thanks to our show sponsor, CISO Series

“If it is important it will likely be in the Cyber Security Headlines update in the morning… And it allows me and my team to dig in a little more on aspects that might affect our technology stack,” said Shawn Bowen, CISO for World Fuel Services. Security leaders listen and make decisions based on what they hear on this very show. Do you have a solution that just needs to find the attention of the right audience of cyber professionals? To learn more about pricing and audience, email us at info@cisoseries.com.

All links and the video of this episode can be found on CISO Series.com 

View Details

February updates break some Windows Server 2022 VMs

BEC groups use Google Translate to target high value victims

Evolving cyberattacks and alert fatigue creating DFIR burnout

Thanks to today's episode sponsor, US, yes, CISO Series

“If it is important it will likely be in the Cyber Security Headlines update in the morning… And it allows me and my team to dig in a little more on aspects that might affect our technology stack,” said Shawn Bowen, CISO for World Fuel Services. Security leaders listen and make decisions based on what they hear on this very show. Do you have a solution that just needs to find the attention of the right audience of cyber professionals? To learn more about pricing and audience, email us at info@cisoseries.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Israeli influence group exposed

Another day, another record DDoS

Cut cables lead to Lufthansa outage

Thanks to today's episode sponsor, US, yes, CISO Series

“Every week, one of the stories from Cyber Security Headlines comes up in our team meetings,” said Brett Conlon, CISO for American Century Investments who admits he starts his day with this very show. And did you know that Cyber Security Headlines has longevity? It’s a daily news show but we see significant downloads for four months after episodes air. That means your ad campaign will continue to live long after the premier airing. To learn more about pricing and audience, email us at info@cisoseries.com.

View Details

Hackers breached Pepsi Bottling network

AI has successfully piloted an F-16 fighter jet

Hyundai and Kia to update anti-theft software on millions of vehicles

Thanks to today's episode sponsor, US, yes, CISO Series

"I value Cyber Security Headlines early every morning as it provides me advance notice of what I might need to explore first thing at the start of the day." That’s active listener David Cross, SVP, CISO of Oracle SaaS Cloud. And for sponsors of Cyber Security Headlines what you get are the ears and eyes of avid security leaders. Sponsorship includes the podcast, our blog, and our daily newsletter. In whatever format our listeners want, Cyber Security Headlines reaches cyber leaders who want to quickly consume daily cyber news. To learn more about pricing and audience, email us at info@cisoseries.com.

For the stories behind the headlines, visit CISOseries.com

View Details

Namecheap sent phishing emails to customers

New Bing search hit with injection attack

Regulators stop minting of BUSD stablecoin

Thanks to today's episode sponsor, US, yes, CISO Series

“Those cyber security headlines are fantastic. It’s the first thing I look at in the am.” That’s a quote from active listener Jared Mendenhall, head of information security at Impossible Foods. Cyber Security Headlines is our fastest growing show on the CISO Series network. It’s grown 20-fold since we launched. And it did so during the pandemic while other shows started to slide. That’s because at only 6-7 minutes every day, Cyber Security Headlines does not need a commute to consume. Listen before you start your day. To learn more about pricing and audience, email us at info@cisoseries.com.

View Details

Reddit admits it was hacked and data stolen, says “don’t panic”

Clop ransomware claims it breached 130 orgs using GoAnywhere zero-day

CISA has a possibly-maybe fix for VMware ESXi ransomware campaign

Thanks to today's episode sponsor, US, yes, CISO Series

If you’re looking to reach a committed audience of cybersecurity professionals every day, then consider advertising right here on Cyber Security Headlines, a show that consistently ranks in the top ten for tech news on Apple Podcasts in the U.S. That’s pretty impressive for a show that’s a niche within a niche. Cyber Security Headlines sponsorship includes continuous week-long brand awareness in newsletters, blog posts, and this very podcast. To learn more about pricing and audience, email us at info@cisoseries.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, February 6-10, is hosted by Rich Stroffolino  with our guest, Ed Covert, head of Cyber Risk Engineering, Bowhead Specialty

Thanks to our show sponsor, us! CISO Series!

“If it is important it will likely be in the Cyber Security Headlines update in the morning… And it allows me and my team to dig in a little more on aspects that might affect our technology stack,” said Shawn Bowen, CISO for World Fuel Services. Security leaders listen and make decisions based on what they hear on this very show. Do you have a solution that just needs to find the attention of the right audience of cyber professionals? If you’re interested in sponsorship, email us at info@cisoseries.com.

All links and the video of this episode can be found on CISO Series.com

View Details

Microsoft Outlook outage prevents users from sending, receiving emails

Britain and US make major move against ransomware gangs by sanctioning seven individuals

Experts publish a list of proxy IPs used by the pro-Russia group Killnet

Thanks to today's episode sponsor, us, yes, CISO Series

“If it is important it will likely be in the Cyber Security Headlines update in the morning… And it allows me and my team to dig in a little more on aspects that might affect our technology stack,” said Shawn Bowen, CISO for World Fuel Services. Security leaders listen and make decisions based on what they hear on this very show. Do you have a solution that just needs to find the attention of the right audience of cyber professionals? To learn more about pricing and audience, email us at info@cisoseries.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

NIST standardizes crypto for IoT

Chinese phones collect PII

Chinese firms also working on AI chatbots

Thanks to today's episode sponsor, US, yes, CISO Series

“Every week, one of the stories from Cyber Security Headlines comes up in our team meetings,” said Brett Conlon, CISO for American Century Investments who admits he starts his day with this very show. And did you know that Cyber Security Headlines has longevity? It’s a daily news show but we see significant downloads for four months after episodes air. That means your ad campaign will continue to live long after the premier airing. To learn more about pricing and audience, email us at info@cisoseries.com.

View Details

ARMO, Microsoft, Google race to integrate AI into their products

FAA needs until 2030 to fix its safety system

Biden’s State of the Union addresses children’s online safety and privacy… again

Thanks to today's episode sponsor, US, yes, CISO Series

"I value Cyber Security Headlines early every morning as it provides me advance notice of what I might need to explore first thing at the start of the day." That’s active listener David Cross, SVP, CISO of Oracle SaaS Cloud. And for sponsors of Cyber Security Headlines what you get are the ears and eyes of avid security leaders. Sponsorship includes the podcast, our blog, and our daily newsletter. In whatever format our listeners want, Cyber Security Headlines reaches cyber leaders who want to quickly consume daily cyber news. To learn more about pricing and audience, email us at info@cisoseries.com.

For the stories behind the headlines, visit CISOseries.com.

View Details

Cyber insurer predicts a rise in critical CVEs

British steel supplier hit by “cyber incident”

Microsoft pins recent attack on Charlie Hebdo

Thanks to today's episode sponsor, US, yes, CISO Series

“Those cyber security headlines are fantastic. It’s the first thing I look at in the am.” That’s a quote from active listener Jared Mendenhall, head of information security at Impossible Foods. Cyber Security Headlines is our fastest growing show on the CISO Series network. It’s grown 20-fold since we launched. And it did so during the pandemic while other shows started to slide. That’s because at only 6-7 minutes every day, Cyber Security Headlines does not need a commute to consume. Listen before you start your day. To learn more about pricing and audience, email us at info@cisoseries.com.

View Details

Hackers actively exploiting zero-day in Fortra's  GoAnywhere MFT

Tallahassee hospital diverting patients, canceling non-emergency surgeries after cyberattack

Fraudulent “CryptoRom” apps slip through Apple and Google App Store review process

Thanks to today's episode sponsor, US, yes, CISO Series

If you’re looking to reach a committed audience of cybersecurity professionals every day, then consider advertising right here on Cyber Security Headlines, a show that consistently ranks in the top ten for tech news on Apple Podcasts in the U.S. That’s pretty impressive for a show that’s a niche within a niche. Cyber Security Headlines sponsorship includes continuous week-long brand awareness in newsletters, blog posts, and this very podcast. To learn more about pricing and audience, email us at info@cisoseries.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines - Week in Review, January 30-February 3, is hosted by Rich Stroffolino  with our guest, David Nolan, VP, Enterprise Risk & Chief Information Security Officer – Aaron’s

Thanks to our show sponsor, Hunters

Hunters is a complete SOC platform, purpose built for your Security Operations team. Hunters’ brand new IOC Search is a game-changing search tool that determines if a known ‘Indicator of Compromise’ has been in your organization’s environment - without needing to write a single line of code. Type an IOC into the search bar, hit ‘enter’ and get results within seconds. Visit hunters.ai to learn more.

All links and the video of this episode can be found on CISO Series.com

View Details

City of London on high alert after ransomware attack

Watchdog warns FDIC fails to test banks’ cyberdefenses effectively

Foreign states already using ChatGPT maliciously, UK IT leaders believe

Thanks to this week's episode sponsor, Hunters

Hunters is a complete SOC platform, purpose built for your Security Operations team. Hunters’ brand new IOC Search is a game-changing search tool that determines if a known ‘Indicator of Compromise’ has been in your organization’s environment - without needing to write a single line of code. Type an IOC into the search bar, hit ‘enter’ and get results within seconds. Visit hunters.ai to learn more.

For the stories behind the headlines, head to CISOseries.com.

View Details

Watchdog calls for improved bank cyber testing

Containers hold high-risk vulnerabilities

2022 set a record for crypto hacks

Thanks to this week's episode sponsor, Hunters

Hunters is a complete SOC platform, purpose built for your Security Operations team. Hunters’ brand new IOC Search is a game-changing search tool that determines if a known ‘Indicator of Compromise’ has been in your organization’s environment - without needing to write a single line of code. Type an IOC into the search bar, hit ‘enter’ and get results within seconds. Visit hunters.ai to learn more.

View Details

Microsoft grants phishers 'Verified' Cloud Partner status

DocuSign brand impersonation attack targets thousands of users

Google Fi says hackers accessed customer information

Thanks to this week's episode sponsor, Hunters

Hunters is a SaaS platform, purpose built for your Security Operations team. Solaris Group, a leading German FinTech, implemented Hunters SOC Platform to eliminate the burden of threat detection and correlation – allowing SOC analysts to focus on higher-value tasks. It's time to move beyond SIEM. Visit hunters.ai to learn more.

For the stories behind the headlines, visit CISOseries.com

View Details

Criminal crypto goes through 5 exchanges

TikTok CEO heads to the House

KillNet launches German DDoS

Thanks to this week's episode sponsor, Hunters

The Hunters SOC Platform helps your security team identify, understand, triage, and respond to incidents at a much faster pace. ChargePoint, the world's largest network of electric vehicle charging stations, uses Hunters SOC Platform to leverage its out-of-the-box detection content to more efficiently respond to new threats and vulnerabilities. Visit Hunters.ai to learn more.

View Details

Charter Communications says vendor breach exposed some customer data

Russia’s Sandworm hackers blamed in fresh Ukraine malware attack

Experts plans to release VMware vRealize log RCE exploit this week

Thanks to this week's episode sponsor, Hunters

Hunters is a complete SOC platform, built for your security team. By providing unlimited ingestion and normalization of security data without ruining your bottom line, a CISO at a leading online retailer was able to “triple her data ingestion while cutting costs from her SIEM provider by 75%.” It's time to move beyond SIEM, with Hunters. Visit hunters.ai to learn more.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, January 23-27, is hosted by David Spark with our guest, Kathleen Mullin, CISO, Cancer Treatment Centers of America

Thanks to our show sponsor, SafeBase

If a prospective customer asked about your trust program or security policies, where would you send them? Chances are, you’d need to send an NDA, hunt down documentation, go back and forth via email, and answer a litany of questions. SafeBase is the better way. SafeBase’s Smart Trust Center allows you to send one link to customers or buyers, so they can easily access the security and compliance information they need. Meanwhile, you get more control over who has access to your documents, and for how long. Build customer trust the smart way with SafeBase – learn more at safebase.com

All links and the video of this episode can be found on CISO Series.com

View Details

FBI seizes Hive ransomware group infrastructure after lurking in servers for months

Layoffs come to IBM - Kyndryl, Watson and Russia to blame

Microsoft says services have recovered after widespread outage

Thanks to this week's episode sponsor, SafeBase

If a prospective customer asked about your trust program or security policies, where would you send them? Chances are, you’d need to send an NDA, hunt down documentation, go back and forth via email, and answer a litany of questions. SafeBase is the better way. SafeBase’s Smart Trust Center allows you to send one link to customers or buyers, so they can easily access the security and compliance information they need. Meanwhile, you get more control over who has access to your documents, and for how long. Build customer trust the smart way with SafeBase - learn more at safebase.com

For the stories behind the headlines, head to CISOseries.com.

View Details

A look at North Korean crypto stealing tactics

Russia saw record DDoS attacks

China leads in facial recognition tech exports

Thanks to this week's episode sponsor, SafeBase

These days, customer trust can be an organization’s strongest competitive advantage. But how can you develop and maintain customer trust over the long term? The answer is SafeBase. After implementing SafeBase’s Smart Trust Center, many companies see shorter deal cycles, higher-value contracts, and stronger long-term customer relationships. Some even achieve a 90% reduction in security questionnaires. Learn more at safebase.com

View Details

Pakistani authorities investigating whether cyberattack caused nationwide blackout

FBI identifies hackers behind Horizon Bridge crypto theft

GoTo says hackers stole encrypted backups and MFA settings

Thanks to this week's episode sponsor, SafeBase

Jump start your journey to long-lasting customer trust with SafeBase. Our Smart Trust Center helps your organization build customer trust through improved transparency, secure document sharing, process control and insights, and proactive communication. Security and GRC leaders at companies like Jamf, Instacart, and Snyk all rely on SafeBase as a central enabler of their trust program. Learn more and check out the case studies at SafeBase.com

For the stories behind the headlines, visit CISOseries.com

View Details

LA School attack exposed Social Security numbers

Government Accountability Office names and shames

PLAY ransomware hits UK car dealerships

Thanks to this week's episode sponsor, SafeBase

If a prospective customer asked about your trust program or security policies, where would you send them? Chances are, you’d need to send an NDA, hunt down documentation, go back and forth via email, and answer a litany of questions. SafeBase is the better way. SafeBase’s Smart Trust Center allows you to send one link to customers or buyers, so they can easily access the security and compliance information they need. Meanwhile, you get more control over who has access to your documents, and for how long. Build customer trust the smart way with SafeBase - learn more at safebase.com

View Details

PayPal accounts breached in large-scale credential stuffing attack

Ransomware gang steals data from KFC, Taco Bell, and Pizza Hut brand owner

ODIN Intelligence hack exposes a huge trove of police raid files

Thanks to this week's episode sponsor, SafeBase

These days, customer trust can be an organization’s strongest competitive advantage. But how can you develop and maintain customer trust over the long term? The answer is SafeBase. After implementing SafeBase’s Smart Trust Center, many companies see shorter deal cycles, higher-value contracts, and stronger long-term customer relationships. Some even achieve a 90% reduction in security questionnaires. Learn more at safebase.com

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines - Week in Review, January 16-20, is hosted by Rich Stroffolino with our guest, George Finney, CISO, Southern Methodist University

Thanks to our show sponsor, Cerby

Did you know that over 60% of the cloud applications used by your company don’t support identity standards like single sign-on? And that these applications are the leading cause of breaches? Cerby can help.

Cerby discovers new applications, eliminates manual security tasks like offboarding, and addresses misconfigurations like disabled 2FA while increasing employee productivity. Wait. A security tool that increases productivity? Yup. Learn more at cerby.com.

All links and the video of this episode can be found on CISO Series.com

View Details

Ransomware revenue falls by $300 million in 2022 as more victims refuse to pay

Vice Society claims ransomware attack against University of Duisburg-Essen

Android users beware of new Hook malware with RAT capabilities

Thanks to today's episode sponsor, Cerby

Did you know that over 60% of the cloud applications used by your company don’t support identity standards like single sign-on? And that these applications are the leading cause of breaches? Cerby can help. Cerby discovers new applications, eliminates manual security tasks like offboarding, and addresses misconfigurations like disabled 2FA while increasing employee productivity. Wait. A security tool that increases productivity? Yup. Learn more at cerby.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Vendors bypassing security patches

ChatGPT creates polymorphic malware

Bitwarden acquires Passwordless.dev

Thanks to today's episode sponsor, Cerby

Did you know that over 60% of the cloud applications used by your company don’t support identity standards like single sign-on? And that these applications are the leading cause of breaches? Cerby can help. Cerby discovers new applications, eliminates manual security tasks like offboarding, and addresses misconfigurations like disabled 2FA while increasing employee productivity. Wait. A security tool that increases productivity? Yup. Learn more at cerby.com.

View Details

Ransomware attack impacts 1,000 ships

Crypto influencer victimized by malware pushed by ads on Google

Microsoft patches flaws in Azure cloud services

Thanks to today's episode sponsor, Cerby

Did you know that over 60% of the cloud applications used by your company don’t support identity standards like single sign-on? And that these applications are the leading cause of breaches? Cerby can help. Cerby discovers new applications, eliminates manual security tasks like offboarding, and addresses misconfigurations like disabled 2FA while increasing employee productivity. Wait. A security tool that increases productivity? Yup. Learn more at cerby.com.

For the stories behind the headlines, visit CISOseries.com

View Details

Cyber attack disrupts esport event

Qbot overtakes Emotet

CircleCI breach caused by infostealer

Thanks to today's episode sponsor, Cerby

Did you know that over 60% of the cloud applications used by your company don’t support identity standards like single sign-on? And that these applications are the leading cause of breaches? Cerby can help. Cerby discovers new applications, eliminates manual security tasks like offboarding, and addresses misconfigurations like disabled 2FA while increasing employee productivity. Wait. A security tool that increases productivity? Yup. Learn more at cerby.com.

View Details

NortonLifeLock warns that hackers breached Password Manager accounts

Hacker steals credit card info from Canada’s largest alcohol retailer

Severe security flaw found in "jsonwebtoken" library

Thanks to today's episode sponsor, Cerby

Did you know that over 60% of the cloud applications used by your company don’t support identity standards like single sign-on? And that these applications are the leading cause of breaches? Cerby can help. Cerby discovers new applications, eliminates manual security tasks like offboarding, and addresses misconfigurations like disabled 2FA while increasing employee productivity. Wait. A security tool that increases productivity? Yup. Learn more at cerby.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, January 9-13, is hosted by Rich Stroffolino with our guest, Shaun Marion, CISO, McDonald’s

Thanks to our show sponsor, AppOmni

Can you name all the third party apps connected to your major SaaS platforms like Salesforce and Microsoft? What about the data these apps can access? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk. With AppOmni, you get visibility to all third party apps and SaaS-to-SaaS connections — including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com to request a free risk assessment.

All links and the video of this episode can be found on CISO Series.com

View Details

Experts detail Chromium browser security flaw putting confidential data at risk

Twitter says 200 million-user leak not obtained from its systems, others disagree

IcedID malware strikes again: Active Directory domain compromised in under 24 hours

Thanks to today's episode sponsor, AppOmni

Can you name all the third party apps connected to your major SaaS platforms like Salseforce and Microsoft? What about the data these apps can access? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk.

With AppOmni, you get visibility to all third party apps and SaaS-to-SaaS connections — including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com to request a free risk assessment.

For the stories behind the headlines, head to CISOseries.com.

View Details

FAA system failure delays flights

Royal Mail hit by “cyber incident”

Police app leaked operations data

Thanks to today's episode sponsor, AppOmni

Can you name all the third party apps connected to your major SaaS platforms like Salseforce and Microsoft? What about the data these apps can access? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk.

With AppOmni, you get visibility to all third party apps and SaaS-to-SaaS connections — including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com to request a free risk assessment.

View Details

Iowa school district cancels classes due to cyberattack

TikTok CEO questioned by EU about its data practices

Government watchdog cracks federal agency’s passwords

Thanks to today's episode sponsor, AppOmni

Can you name all the third party apps connected to your major SaaS platforms like Salseforce and Microsoft? What about the data these apps can access? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk.

With AppOmni, you get visibility to all third party apps and SaaS-to-SaaS connections — including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com to request a free risk assessment.

For the stories behind the headlines, visit CISOseries.com

View Details

API vulnerabilities found across car brands

Bypassing Experian Security

Trying to write malware with ChatGPT

Thanks to today's episode sponsor, AppOmni

Can you name all the third party apps connected to your major SaaS platforms like Salseforce and Microsoft? What about the data these apps can access? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk.

With AppOmni, you get visibility to all third party apps and SaaS-to-SaaS connections — including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com to request a free risk assessment.

View Details

Russian Turla hackers hijack decade-old malware infrastructure to deploy new backdoors

LastPass hit with lawsuit over August breach

Hackers abuse Windows error reporting tool to deploy malware

Thanks to today's episode sponsor, AppOmni

Can you name all the third party apps connected to your major SaaS platforms like Salseforce and Microsoft? What about the data these apps can access? After all, one compromised 3rd party app could put your entire SaaS ecosystem at risk.

With AppOmni, you get visibility to all third party apps and SaaS-to-SaaS connections — including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com to request a free risk assessment.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, January 2-6, is hosted by Sean Kelly with our guest, Bryan Willett, CISO, Lexmark

Thanks to our show sponsor, AppOmni

Did you know that over half of companies have sensitive SaaS data exposed on the public internet? And many breaches making headlines now involve SaaS apps? AppOmni can help. AppOmni identifies misconfigurations and guides remediation to keep your SaaS data secure. We help Security teams make sense of data access permissions, third party app visibility, and threat detection across their entire SaaS ecosystem. Get started at AppOmni.com.

All links and the video of this episode can be found on CISO Series.com

View Details

Slack's private GitHub code repositories stolen over holidays

CircleCI warns of security breach — rotate your secrets!

NATO tests AI’s ability to protect critical infrastructure against cyberattacks

Thanks to today's episode sponsor, AppOmni

Did you know that over half of companies have sensitive SaaS data exposed on the public internet? And many breaches making headlines now involve SaaS apps? AppOmni can help. AppOmni identifies misconfigurations and guides remediation to keep your SaaS data secure. We help Security teams make sense of data access permissions, third party app visibility, and threat detection across their entire SaaS ecosystem. Get started at AppOmni.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

‘Mudge’ joins cybersecurity firm Rapid7

Meta fined $400 million by European regulator

Coinbase strikes a $100 million deal with regulators

Thanks to today's episode sponsor, AppOmni

Did you know that over half of companies have sensitive SaaS data exposed on the public internet? And many breaches making headlines now involve SaaS apps? AppOmni can help. AppOmni identifies misconfigurations and guides remediation to keep your SaaS data secure. We help Security teams make sense of data access permissions, third party app visibility, and threat detection across their entire SaaS ecosystem. Get started at AppOmni.com.

For the stories behind the headlines, visit CISOseries.com

View Details

FTX founder has pleaded not guilty to fraud charges

LA housing authority operations disrupted by cyberattack

Ukrainian authorities bust major vishing call center

Thanks to today's episode sponsor, AppOmni

Did you know that over half of companies have sensitive SaaS data exposed on the public internet? And many breaches making headlines now involve SaaS apps? AppOmni can help. AppOmni identifies misconfigurations and guides remediation to keep your SaaS data secure. We help Security teams make sense of data access permissions, third party app visibility, and threat detection across their entire SaaS ecosystem. Get started at AppOmni.com.

For the stories behind the headlines, visit CISOseries.com

View Details

Google to pay $29.5 million to settle lawsuits over user location tracking

Ransomware gang cloned victim’s website to leak stolen data

LockBit gang apologizes, gives SickKids Hospital free decryptor

Thanks to today's episode sponsor, AppOmni

Did you know that over half of companies have sensitive SaaS data exposed on the public internet? And many breaches making headlines now involve SaaS apps? AppOmni can help. AppOmni identifies misconfigurations and guides remediation to keep your SaaS data secure. We help Security teams make sense of data access permissions, third party app visibility, and threat detection across their entire SaaS ecosystem. Get started at AppOmni.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

NETGEAR fixes a severe bug in its routers. Patch it ASAP!

PyTorch discloses malicious dependency chain compromise over holidays

LockBit ransomware claims attack on Port of Lisbon in Portugal

Thanks to today's episode sponsor, AppOmni

Did you know that over half of companies have sensitive SaaS data exposed on the public internet? And many breaches making headlines now involve SaaS apps? AppOmni can help. AppOmni identifies misconfigurations and guides remediation to keep your SaaS data secure. We help Security teams make sense of data access permissions, third party app visibility, and threat detection across their entire SaaS ecosystem. Get started at AppOmni.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Snooping bug found on Google Home speakers

3Commas API database leaked

Ireland investigating Twitter users data for sale

Thanks to this week's episode sponsor, Tines

Tines is the solution for security teams struggling with too much work, a talent shortage, and inevitable security incidents. Tines breaks the silos that exist between technologies and teams, so employees can focus on meaningful, not menial, tasks. Fewer manual errors and faster response times. Visit Tines.com to learn more.

View Details

Ransomware continues to hammer hospitals

Citrix servers found vulnerable despite patches

Log4Shell celebrates an anniversary

Thanks to this week's episode sponsor, Tines

If you're overwhelmed by your workload, Tines is the solution you've been looking for. Tines no-code automation checks boxes legacy SOAR tools can only dream of. Break the silos between tools and teams, focus on meaningful work, and eliminate manual errors while improving your response times. Visit Tines.com to stay ahead of the curve without breaking a sweat!

View Details

Facebook reaches settlement related to Cambridge Analytica scandal

BTC.com lost $3 million in cyberattack

Hackers use trojan to steal $8 million from BitKeep users

Thanks to this week's episode sponsor, Tines

Ever feel like you're stuck in a never-ending cycle of alerts? It's exhausting and frustrating. But here's the good news: Tines! Tines helps you focus on meaningful, not menial, tasks.  Fewer mistakes, faster response times. And best of all, Tines’ no-code automation platform can handle massive complexity and easily connect to your unique tech stack. Visit Tines.com now!

For the stories behind the headlines, visit CISOseries.com

View Details

LastPass admits to severe data breach, encrypted password vaults stolen

Chris Inglis to resign as national cyber director

Comcast Xfinity accounts hacked in widespread 2FA bypass attacks

Thanks to our episode sponsor, Tines

Wondering how the world’s leading security teams are figuring out how to do more with less? The answer is Tines! Tines is a hyper-flexible automation platform loved by customers like Okta, Canva, Kayak, and Coinbase. Tines enables security teams to focus on what matters most by taking care of the grunt work! Learn more at Tines.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

FBI warns of malware in search ads

Guardian hit with suspected ransomware

Attackers grab Okta source code

Thanks to this week's episode sponsor, Tines 

Tis the season for more alerts and fewer resources available to manage them. But you can still be jolly--with Tines! Tines eliminates the need for security teams to waste time on repetitive, manual tasks. Powered by a no-code approach, security teams create—and maintain—powerful automations that deliver immediate results. Visit Tines.com to learn more!

View Details

McGraw Hill exposed student grades and personal info

UK privacy regulator names and shames breached firms

Twitter aided the Pentagon in covert online propaganda campaign

Thanks to this week's episode sponsor, Tines 

If you're like most security teams, you currently face more phishing attacks and alert fatigue. The holiday season is the most wonderful time of the year for shoppers... but it's also a busy time for cybercriminals. Tines’ no-code automation platform can help you transform your SecOps and stay one step ahead. Visit Tines.com to sign up for free today!

For the stories behind the headlines, visit CISOseries.com

View Details

Botnet shrugs off Google

The future of ransomware

Epic Games receives record privacy fines

Thanks to this week's episode sponsor, Tines 

If you’re like most security teams, you’re juggling multiple mission-critical priorities. But what if there was a way to break the silos in your environment? A way to focus on meaningful tasks? A way to reduce errors and achieve faster response times? Check out Tines.com to start experiencing the true benefits of proactive security operations powered by no-code automation.

View Details

CISA says Russia's Fancy Bear infiltrated US satellite network

Google introduces end-to-end encryption for Gmail on the web

NSA cyber director warns of Russian digital assaults on global energy sector

Thanks to this week's episode sponsor, Tines 

Before Tines, co-founders Eoin and Thomas spent 15 years as senior security operators. Frustrated by the inability to solve for the challenges their teams were facing, they built their own solution. Tines allows security teams to robustly automate mundane, repetitive tasks – without code – so they can focus on their most important work. Visit Tines.com to learn more!

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, December 12-16, is hosted by Rich Stroffolino with our guest, Jeremy Embalabala, CISO, HUB International

Thanks to our show sponsor, Fortra

The cybersecurity landscape is full of single-solution providers, making it easy for unexpected cyberthreats to sneak through the cracks. That’s why Fortra is creating a stronger, simpler strategy for protection. One that increases your security maturity while decreasing the operational burden that comes with it. Fortra’s integrated, scalable solutions help customers face their toughest challenges with confidence. Learn more at Fortra.com

All links and the video of this episode can be found on CISO Series.com

View Details

Hackers target Japanese politicians with new MirrorStealer malware

Crooks use HTML smuggling to spread QBot malware via SVG files

FBI charges 6, seizes domains linked to DDoS-for-hire service platforms

Thanks to this week's episode sponsor, Fortra

The cybersecurity landscape is full of single-solution providers, making it easy for unexpected cyberthreats to sneak through the cracks. That's why Fortra is creating a stronger, simpler strategy for protection. One that increases your security maturity while decreasing the operational burden that comes with it. Fortra's integrated, scalable solutions help customers face their toughest challenges with confidence. Learn more at Fortra.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

EU gets closer to US-data sharing agreement

Microsoft signed malicious drivers

InfraGard data for sale on dark web

Thanks to this week's episode sponsor, Fortra

The cybersecurity landscape is full of single-solution providers, making it easy for unexpected cyberthreats to sneak through the cracks. That's why Fortra is creating a stronger, simpler strategy for protection. One that increases your security maturity while decreasing the operational burden that comes with it. Fortra's integrated, scalable solutions help customers face their toughest challenges with confidence. Learn more at Fortra.com.

View Details

Twitter addresses claims of recent data leak

Uber hit with another breach after attack on third-party vendor

Police in China arrest gang who laundered $1.7 billion via crypto

Thanks to this week's episode sponsor, Fortra

The cybersecurity landscape is full of single-solution providers, making it easy for unexpected cyberthreats to sneak through the cracks. That's why Fortra is creating a stronger, simpler strategy for protection. One that increases your security maturity while decreasing the operational burden that comes with it. Fortra's integrated, scalable solutions help customers face their toughest challenges with confidence. Learn more at Fortra.com.

For the stories behind the headlines, visit CISOseries.com

View Details

India’s foreign ministry leaks passport details

Cloudflare Zero Trust suite available to at-risk groups

Greece outlaws spyware

Thanks to this week's episode sponsor, Fortra

The cybersecurity landscape is full of single-solution providers, making it easy for unexpected cyberthreats to sneak through the cracks. That's why Fortra is creating a stronger, simpler strategy for protection. One that increases your security maturity while decreasing the operational burden that comes with it. Fortra's integrated, scalable solutions help customers face their toughest challenges with confidence. Learn more at Fortra.com.

View Details

Pwn2Own Toronto 2022 nets almost $1M for 63 zero days

Antivirus and EDR solutions tricked into acting as data wipers

Iran-linked MuddyWater APT launches new campaign

Thanks to this week's episode sponsor, Fortra

The cybersecurity landscape is full of single-solution providers, making it easy for unexpected cyberthreats to sneak through the cracks. That's why Fortra is creating a stronger, simpler strategy for protection. One that increases your security maturity while decreasing the operational burden that comes with it. Fortra's integrated, scalable solutions help customers face their toughest challenges with confidence. Learn more at Fortra.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, December 5-9, is hosted by Rich Stroffolino with our guest, Ken Athanasiou, CISO, VF Corporation

Thanks to our show sponsor, PlexTrac

The best pentesting teams trust PlexTrac. PlexTrac can improve efficiency and effectiveness at every phase of your proactive assessments. By centralizing the data from all your automation tools, cataloging important reusable content for easy access, and promoting communication and visibility at every phase of an assessment, PlexTrac cuts reporting time in half and adds value between reports. Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the premier pentest reporting and collaboration platform.

All links and the video of this episode can be found on CISO Series.com

View Details

North Korea-linked APT37 exploits Internet Explorer zero-day flaw

Firewalls of several major vendors bypassed with generic attack method

New 'Zombinder' platform binds Android malware with legitimate apps

Thanks to today's episode sponsor, PlexTrac

The best pentesting teams trust PlexTrac. PlexTrac can improve efficiency and effectiveness at every phase of your proactive assessments. By centralizing the data from all your automation tools, cataloging important reusable content for easy access, and promoting communication and visibility at every phase of an assessment, PlexTrac cuts reporting time in half and adds value between reports. 

Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the premier pentest reporting and collaboration platform.

For the stories behind the headlines, head to CISOseries.com.

View Details

Pentagon awards cloud deal to four major providers

Apple finally adds encryption to iCloud backups

CloudSEK claims it was hacked by another cybersecurity firm

Thanks to today's episode sponsor, PlexTrac

The Plextrac platform is your offensive security team’s secret weapon. Build better reports in half the time, centralize your data, maximize your reusable content, and become more efficient and effective. PlexTrac clients report a “5X ROI in 1 year,” a “30% increase in efficiency,” have “cut their reporting cycle by 65%,” and experienced a “18 to 22% time savings per engagement.” Check out PlexTrac.com/CISOSeries to learn how PlexTrac can help your team deliver results.

For the stories behind the headlines, visit CISOseries.com

View Details

Are we in the age of AI generated malware

Rackspace confirms ransomware attack

Meta Oversight Board rules on cross-check system

Thanks to today's episode sponsor, PlexTrac

The best pentesting teams trust PlexTrac. PlexTrac can improve efficiency and effectiveness at every phase of your proactive assessments. By centralizing the data from all your automation tools, cataloging important reusable content for easy access, and promoting communication and visibility at every phase of an assessment, PlexTrac cuts reporting time in half and adds value between reports. Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the premier pentest reporting and collaboration platform.

View Details

Vulnerabilities found in popular baseboard software

Chinese threat group stole COVID-19 relief funds

The question of AI generated code

Thanks to today's episode sponsor, PlexTrac

The Plextrac platform is your offensive security team’s secret weapon. Build better reports in half the time, centralize your data, maximize your reusable content, and become more efficient and effective. PlexTrac clients report a “5X ROI in 1 year,” a “30% increase in efficiency,” have “cut their reporting cycle by 65%,” and experienced a “18 to 22% time savings per engagement.” Check out PlexTrac.com/CISOSeries to learn how PlexTrac can help your team deliver results.

View Details

Open source software host Fosshost shutting down, CEO unreachable

DHS Cyber Safety Review Board to review Lapsus$ attacks

Rackspace rocked by ‘security incident’ that has taken out hosted Exchange services

Thanks to today's episode sponsor, PlexTrac

The best pentesting teams trust PlexTrac. PlexTrac can improve efficiency and effectiveness at every phase of your proactive assessments. By centralizing the data from all your automation tools, cataloging important reusable content for easy access, and promoting communication and visibility at every phase of an assessment, PlexTrac cuts reporting time in half and adds value between reports.

Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the premier pentest reporting and collaboration platform.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, November 28-December 2, is hosted by Rich Stroffolino with our guest, Terrance Cooley, CISO, Air Force JADC2 R&D Center.

Thanks to our show sponsor, Automox

Are you ready to ditch manual patching and all the complexity and hassle that comes with it? With Automox, you can automatically patch your Windows, macOs, and Linux devices with one easy-to-use, cloud-native platform. Modern patching should be easy. And now it is. With automated cross-OS patching, you’ll save time and sleep better at night knowing your IT environment is secure. Visit Automox.com to learn more and start a free trial today.

All links and the video of this episode can be found on CISO Series.com

View Details

Intruders gain access to user data in LastPass incident

Sirius XM flaw unlocks smart cars thanks to code flaw

Medibank hackers announce ‘case closed’ and dump huge data file on dark web

Thanks to this week's episode sponsor, Automox

And now a word from our sponsor, Automox. Are you ready to ditch manual patching and all the complexity and hassle that comes with it? With Automox, you can automatically patch your Windows, macOs, and Linux devices with one easy-to-use, cloud-native platform. Modern patching should be easy. And now it is. With automated cross-OS patching, you’ll save time and sleep better at night knowing your IT environment is secure. Visit Automox.com to learn more and start a free trial today.

For the stories behind the headlines, head to CISOseries.com.

View Details

Elon Musk’s Starlink and the White House targeted by Killnet hackers

Google links Windows exploit framework used to send spyware

Malicious Android app creates fake accounts on multiple platforms

Thanks to this week's episode sponsor, Automox

Threat exposure is a growing business risk. Today, vulnerabilities are piling up faster than traditional remediation processes and tools can fix them. But fixing vulnerabilities doesn’t have to be a fire drill. Now you can eliminate threats and manage exposed endpoints with Automox Automated Vulnerability Remediation, the only cloud-native solution that harmonizes your SecOps and ITOps workflow and lets you fix vulnerabilities dramatically faster – in minutes, not months. Visit Automox.com to learn more and start a free trial today.

For the stories behind the headlines, head to CisoSeries.com

View Details

Hackers use trending TikTok 'Invisible Challenge' to spread malware

Cyber Monday online sales hit record

Sandworm gang launches Monster ransomware attacks on Ukraine

Thanks to this week's episode sponsor, Automox

Are you tired of using multiple tools to patch your third-party applications? With Automox you’ll gain complete visibility of all your software and the ability to patch it, automatically, from a single platform. Fix missing third-party patches with the click of a button to dramatically reduce the time, effort, and complexity it takes to maintain a strong security posture. Visit Automox.com to learn more and start a free trial today.

For the stories behind the headlines, head to CISOseries.com.

View Details

Project Zero warns of “patch gap”

Twitter hit with spam campaign

Canadian food company refuses ransom demands

Thanks to this week's episode sponsor, Automox

Are you ready to say goodbye to manual patching? With Automox you can automatically patch your Windows, macOs, and Linux devices with one easy-to-use, cloud-native platform. Modern patching can and should be easy. Save time and sleep better at night knowing your IT environment is secure with automated cross-OS patching. Visit Automox.com to learn more and start a free trial today.

View Details

FCC announces ban on Chinese telecom and surveillance equipment

New Windows Server updates cause domain controller freezes, restarts

WhatsApp data leak: 500 million user records for sale

Thanks to this week's episode sponsor, Automox

Automox allows you to automate the configuration, patching, and compliance of your Windows, macOS, and Linux systems all from the cloud. Visit Automox.com to start a free trial and have all your endpoints safe and secure in just 15 minutes. Automox is also offering special pricing from now until December 31st so you can start 2023 off right and get automated patching without breaking your budget.

For the stories behind the headlines, head to CISOseries.com.

View Details

FCC announces ban on Chinese telecom and surveillance equipment

New Windows Server updates cause domain controller freezes, restarts

WhatsApp data leak: 500 million user records for sale

Thanks to this week's episode sponsor, Automox

Automox allows you to automate the configuration, patching, and compliance of your Windows, macOS, and Linux systems all from the cloud. Visit Automox.com to start a free trial and have all your endpoints safe and secure in just 15 minutes. Automox is also offering special pricing from now until December 31st so you can start 2023 off right and get automated patching without breaking your budget.

For the stories behind the headlines, head to CISOseries.com.

View Details

Twitter enlists hacker George Hotz for 12 week “internship”

Estonian duo arrested for masterminding $575 million Ponzi scheme

Hackers steal $300K from DraftKings customers

Thanks to today’s episode sponsor, Compyl

Preparing a Thanksgiving meal can be stressful, but managing your security and compliance program doesn't have to be. Compyl quickly integrates with the tools you use, and automates 85% of the day-to-day tasks, all while providing complete visibility and comprehensive reporting along the way. Learn about Compyl today at www.compyl.com.

For the stories behind the headlines, visit CISOseries.com

View Details

Emotet returns with a malspam vengeance

Google publishes YARA rules for Cobalt Strike

Ticketmaster blames “bot attacks” for ticketing fiasco

Thanks to today’s episode sponsor, Compyl

This thanksgiving, sit around the table and be thankful for Compyl. Compyl is an all-in-one platform that supercharges your security program and takes control of your compliance and audits. Automate workflows, audit collection, compliance management, and all the boring security stuff. Learn about Compyl today at www.compyl.com.

View Details

New ransomware encrypts files, then steals your Discord account

Donald Trump returns to Twitter after Elon Musk's poll

More than half of Black Friday spam emails are scams

Thanks to today’s episode sponsor, Compyl

We all know that CISOs are overworked and stressed. CISOs made Compyl to reduce the noise, accelerate security maturity and let you and your team quickly make decisions that directly affect what's important to your business. Learn about Compyl at www.compyl.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, November 14-18, is hosted by Rich Stroffolino with our guest, John Scrimsher, CISO, Kontoor Brands

Thanks to today’s episode sponsor, AppOmni

Can you name all the third party apps connected to your major SaaS platforms like SalesForce and Microsoft? What about the data these apps can access? After all, one compromised third party app could put your entire SaaS ecosystem at risk. With AppOmni, you get visibility to all third party apps, including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com to request a free risk assessment.

All links and the video of this episode can be found on CISO Series.com

View Details

Musk’s ultimatum to employees leaves Twitter at risk

Iranian APT breaches government agency using Log4Shell

Hundreds of Amazon RDS snapshots discovered leaking user data

And now a word from our sponsor, AppOmni

Can you name all the third party apps connected to your major SaaS platforms like Salseforce and Microsoft? What about the data these apps can access? After all, one compromised third party app could put your entire SaaS ecosystem at risk.

With AppOmni, you get visibility to all third party apps, including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com to request a free risk assessment.

View Details

Disneyland phishes with Punycode

The effectiveness of Ukraine’s IT army

NSA seeks to lower barriers to work with private sector

And now a word from our sponsor, AppOmni

Can you name all the third party apps connected to your major SaaS platforms like Salseforce and Microsoft? What about the data these apps can access? After all, one compromised third party app could put your entire SaaS ecosystem at risk.

With AppOmni, you get visibility to all third party apps, including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com to request a free risk assessment.

View Details

Amazon to cut 10,000 employees in tech and corporate roles Privacy experts cautious about FIFA World Cup Apps

98% of organizations have been severely impacted by cyber supply chain breach

And now a word from our sponsor, AppOmni

Can you name all the third party apps connected to your major SaaS platforms like Salseforce and Microsoft? What about the data these apps can access? After all, one compromised third party app could put your entire SaaS ecosystem at risk.

With AppOmni, you get visibility to all third party apps, including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com to request a free risk assessment.

For the stories behind the headlines, head to CISOseries.com.

View Details

Australia considers ban on ransomware payments

Thousands of sites used for brand impersonation

GitHub gets private reporting

And now a word from our sponsor, AppOmni

Can you name all the third party apps connected to your major SaaS platforms like Salseforce and Microsoft? What about the data these apps can access? After all, one compromised third party app could put your entire SaaS ecosystem at risk.

With AppOmni, you get visibility to all third party apps, including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com to request a free risk assessment.

View Details

Android phone owner accidentally finds a way to bypass lock screen

Thales hit by Lockbit 3.0 again

At least $1 billion of client funds missing at FTX

And now a word from our sponsor, AppOmni

Can you name all the third party apps connected to your major SaaS platforms like Salseforce and Microsoft? What about the data these apps can access? After all, one compromised third party app could put your entire SaaS ecosystem at risk.

With AppOmni, you get visibility to all third party apps, including which end users have enabled them, and the level of data access they’ve been granted. Visit AppOmni.com to request a free risk assessment.

For the stories behind the headlines, head to CISOseries.com.

View Details

Alleged LockBit operator to be extradited from Canada to U.S.

Musk’s ends remote work and promised to fight spam. CISO Kissner quits.

Insurance giant settles NotPetya lawsuit, signaling cyber insurance shakeup

And now a word from our sponsor, AppOmni

Did you know that over half of companies have sensitive SaaS data exposed on the public internet? And many breaches making headlines now involve SaaS apps? AppOmni can help.

AppOmni identifies misconfigurations and guides remediation to keep your SaaS data secure. We help Security teams make sense of data access permissions, third party app visibility, and threat detection across their entire SaaS ecosystem. Get started at AppOmni.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Crypto Winter comes for FTX

Vulnerability found in oil and gas utilities

Vulnerability found in oil and gas utilities

And now a word from our sponsor, AppOmni

Did you know that over half of companies have sensitive SaaS data exposed on the public internet? And many breaches making headlines now involve SaaS apps? AppOmni can help.

AppOmni identifies misconfigurations and guides remediation to keep your SaaS data secure. We help Security teams make sense of data access permissions, third party app visibility, and threat detection across their entire SaaS ecosystem. Get started at AppOmni.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

$2 billion Powerball drawing delayed by security issues

Hackers leak Australian health records on dark web

Hushpuppi gets 11 years in prison for cyber fraud

And now a word from our sponsor, AppOmni

Did you know that over half of companies have sensitive SaaS data exposed on the public internet? And many breaches making headlines now involve SaaS apps? AppOmni can help.

AppOmni identifies misconfigurations and guides remediation to keep your SaaS data secure. We help Security teams make sense of data access permissions, third party app visibility, and threat detection across their entire SaaS ecosystem. Get started at AppOmni.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

China stockpiling vulnerabilities

US seizes Silk Road bitcoins

DOJ takes down Z-Library

And now a word from our sponsor, AppOmni

Did you know that over half of companies have sensitive SaaS data exposed on the public internet? And many breaches making headlines now involve SaaS apps? AppOmni can help.

AppOmni identifies misconfigurations and guides remediation to keep your SaaS data secure. We help Security teams make sense of data access permissions, third party app visibility, and threat detection across their entire SaaS ecosystem. Get started at AppOmni.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

US Treasury thwarts DDoS attack from Russian Killnet group

British government scanning all Internet devices hosted in UK

Denmark trains halted by cyberattack

And now a word from our sponsor, AppOmni

Did you know that over half of companies have sensitive SaaS data exposed on the public internet? And many breaches making headlines now involve SaaS apps? AppOmni can help.

AppOmni identifies misconfigurations and guides remediation to keep your SaaS data secure. We help Security teams make sense of data access permissions, third party app visibility, and threat detection across their entire SaaS ecosystem. Get started at AppOmni.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, October 31-November 4, is hosted by Rich Stroffolino with our guest, Marcos Marrero, CISO, H.I.G. Capital

Thanks to today’s episode sponsor, Votiro

UFOs are everywhere.
They’re in your applications, cloud storage, endpoints, and emails.
That’s right – UFOs – Unidentified File Objects – are hiding in files across your organization.
UFOs can contain malware that exfiltrates data or deploys ransomware. And 70% of UFOs can’t be detected by traditional scanning solutions like Anti-Virus and Sandboxing.
That’s where Votiro comes in. Votiro prevents UFOs before they hitch a ride in on files – without detection, and without slowing down business.
Do you believe? Learn more at Votiro.com/UFOs

All links and the video of this episode can be found on CISO Series.com

View Details

Cyber incident at Boeing subsidiary causes flight planning disruptions

Stripe to lay off 14% of workforce

Over 250 US news websites deliver malware via supply chain attack

Thanks to today’s episode sponsor, Votiro

UFOs are everywhere. They’re in your applications, cloud storage, endpoints, and emails. That’s right – UFOs – Unidentified File Objects – are hiding in files across your organization. UFOs can contain malware that exfiltrates data or deploys ransomware. And 70% of UFOs can’t be detected by traditional scanning solutions like Anti-Virus and Sandboxing. That’s where Votiro comes in. Votiro prevents UFOs before they hitch a ride in on files – without detection, and without slowing down business.

Do you believe? Learn more at Votiro.com/ufos

For the stories behind the headlines, head to CISOseries.com.

View Details

W4SP malware stings PyPI

LastPass warns of security hubris

Dropbox breached

Thanks to today’s episode sponsor, Votiro

UFOs are everywhere.They’re in your applications, cloud storage, endpoints, and emails.That’s right – UFOs – Unidentified File Objects – are hiding in files across your organization. UFOs can contain malware that exfiltrates data or deploys ransomware. And 70% of UFOs can’t be detected by traditional scanning solutions like Anti-Virus and Sandboxing. That’s where Votiro comes in. Votiro prevents UFOs before they hitch a ride in on files – without detection, and without slowing down business.

Do you believe? Learn more at Votiro.com/

View Details

LockBit dominates ransomware

CISA on voting integrity

A call for more ransomware reporting

Thanks to today’s episode sponsor, Votiro

UFOs are everywhere.They’re in your applications, cloud storage, endpoints, and emails.That’s right – UFOs – Unidentified File Objects – are hiding in files across your organization. UFOs can contain malware that exfiltrates data or deploys ransomware. And 70% of UFOs can’t be detected by traditional scanning solutions like Anti-Virus and Sandboxing. That’s where Votiro comes in. Votiro prevents UFOs before they hitch a ride in on files – without detection, and without slowing down business.

Do you believe? Learn more at Votiro.com/

View Details

Threat group rides antivirus software to install malware

White House organizes ransomware summit

Ed tech company exposed user data

Thanks to today’s episode sponsor, Votiro

UFOs are everywhere.They’re in your applications, cloud storage, endpoints, and emails.That’s right – UFOs – Unidentified File Objects – are hiding in files across your organization. UFOs can contain malware that exfiltrates data or deploys ransomware. And 70% of UFOs can’t be detected by traditional scanning solutions like Anti-Virus and Sandboxing. That’s where Votiro comes in. Votiro prevents UFOs before they hitch a ride in on files – without detection, and without slowing down business.

Do you believe? Learn more at Votiro.com/

View Details

Thomson Reuters leaks 3TB of sensitive data

Massive cyberattack hits Slovak and Polish Parliaments

Twitter trolls bombard platform after Elon Musk takeover

Thanks to today’s episode sponsor, Votiro

UFOs are everywhere. They’re in your applications, cloud storage, endpoints, and emails.

That’s right – UFOs – Unidentified File Objects – are hiding in files across your organization. UFOs can contain malware that exfiltrates data or deploys ransomware. And 70% of UFOs can’t be detected by traditional scanning solutions like Anti-Virus and Sandboxing. That’s where Votiro comes in. Votiro prevents UFOs before they hitch a ride in on files – without detection, and without slowing down business.

Do you believe? Learn more at Votiro.com/ufos.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, October 24-28, is hosted by Rich Stroffolino with our guest, Will Gregorian, former Senior Director, Technology Operations and Security, Rhino

Thanks to this week’s episode sponsor, Votiro

UFOs are everywhere.
They’re in your applications, cloud storage, endpoints, and emails.
That’s right – UFOs – Unidentified File Objects – are hiding in files across your organization.
UFOs can contain malware that exfiltrates data or deploys ransomware. And 70% of UFOs can’t be detected by traditional scanning solutions like Anti-Virus and Sandboxing. That’s where Votiro comes in. Votiro prevents UFOs before they hitch a ride in on files – without detection, and without slowing down business. Do you believe? Learn more at Votiro.com/UFOs.

All links and the video of this episode can be found on CISO Series.com

View Details

Russia warns West: We can target your commercial satellites

New York Post says its site was hacked after posting offensive tweets

White House announces 100-day cyber sprint for chemical sector

Thanks to this week’s episode sponsor, Votiro

UFOs are everywhere.They’re in your applications, cloud storage, endpoints, and emails.

That’s right – UFOs – Unidentified File Objects – are hiding in files across your organization. UFOs can contain malware that exfiltrates data or deploys ransomware. And 70% of UFOs can’t be detected by traditional scanning solutions like Anti-Virus and Sandboxing. That’s where Votiro comes in. Votiro prevents UFOs before they hitch a ride in on files – without detection, and without slowing down business.
Do you believe? Learn more at Votiro.com/UFOs For the stories behind the headlines, head to CISOseries.com.

View Details

Sigstore opens free software signing service

Australian health insurer hacked

Researcher details 20-year old SQLite bug

Thanks to this week’s episode sponsor, Votiro

UFOs are everywhere.They’re in your applications, cloud storage, endpoints, and emails.

That’s right – UFOs – Unidentified File Objects – are hiding in files across your organization. UFOs can contain malware that exfiltrates data or deploys ransomware. And 70% of UFOs can’t be detected by traditional scanning solutions like Anti-Virus and Sandboxing. That’s where Votiro comes in. Votiro prevents UFOs before they hitch a ride in on files – without detection, and without slowing down business.
Do you believe? Learn more at Votiro.com/UFOs

View Details

See Tickets discloses 2.5 year-long credit card breach

US charges Chinese agents in Huawei obstruction case

Hive begins leaking Tata Power’s data

Thanks to this week’s episode sponsor, Votiro

UFOs are everywhere.They’re in your applications, cloud storage, endpoints, and emails.

That’s right – UFOs – Unidentified File Objects – are hiding in files across your organization. UFOs can contain malware that exfiltrates data or deploys ransomware. And 70% of UFOs can’t be detected by traditional scanning solutions like Anti-Virus and Sandboxing. That’s where Votiro comes in. Votiro prevents UFOs before they hitch a ride in on files – without detection, and without slowing down business.
Do you believe? Learn more at Votiro.com/UFOs

For the stories behind the headlines, visit CISOseries.com

View Details

CISA warns of Daixin Team

Exploit POCs used to host malware

Iranian nuclear agency hacked

Thanks to this week’s episode sponsor, Votiro

UFOs are everywhere.They’re in your applications, cloud storage, endpoints, and emails.

That’s right – UFOs – Unidentified File Objects – are hiding in files across your organization. UFOs can contain malware that exfiltrates data or deploys ransomware. And 70% of UFOs can’t be detected by traditional scanning solutions like Anti-Virus and Sandboxing. That’s where Votiro comes in. Votiro prevents UFOs before they hitch a ride in on files – without detection, and without slowing down business.
Do you believe? Learn more at Votiro.com/UFOs

View Details

Exploited Windows zero-day lets JavaScript files bypass Mark of the Web security warnings

FBI warns of ‘hack-and-leak’ operations from group based in Iran

Wholesale giant METRO confirmed to have suffered a cyberattack

Thanks to this week’s episode sponsor, Votiro

UFOs are everywhere. They’re in your applications, cloud storage, endpoints, and emails. That’s right – UFOs – Unidentified File Objects – are hiding in files across your organization. UFOs can contain malware that exfiltrates data or deploys ransomware. And 70% of UFOs can’t be detected by traditional scanning solutions like Anti-Virus and Sandboxing. That’s where Votiro comes in. Votiro prevents UFOs before they hitch a ride in on files – without detection, and without slowing down business. Do you believe? Learn more at Votiro.com/UFOs

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, October 17-21, is hosted by Rich Stroffolino with our guest, Lee Parrish, CISO, Newell Brands

Thanks to this week’s episode sponsor, SafeBase

Security questionnaires are a pain, and sharing sensitive documents takes too much back and forth. As a result, security can be wrongly viewed as a roadblock rather than a sales enabler. That’s where SafeBase comes in. Our Smart Trust Center makes it easy to showcase your security program, share sensitive documents, and streamline security reviews. It’s the missing piece of your security and sales workflow, and the only security tool that gives you time back. Find out more at safebase.com

All links and the video of this episode can be found on CISO Series.com

View Details

Internet connectivity worldwide impacted by severed EU subsea cables

Microsoft BlueBleed customer data leak claimed to be 'one of the largest' in years

Health system data breach due to Meta Pixel hits 3 million patients

Thanks to this week's episode sponsor, SafeBase

Security questionnaires are a pain, and sharing sensitive documents takes too much back and forth. As a result, security can be wrongly viewed as a roadblock rather than a sales enabler. That's where SafeBase comes in. Our Smart Trust Center makes it easy to showcase your security program, share sensitive documents, and streamline security reviews. It's the missing piece of your security and sales workflow, and the only security tool that gives you time back. Find out more at safebase.com

For the stories behind the headlines, head to CISOseries.com.

View Details

Ransom Cartel linked to REvil

Do we need cybersecurity training for Gen Z?

Open Compute Project announces Caliptra

Thanks to this week's episode sponsor, SafeBase

Security questionnaires. If those two words sent a shiver down your spine, you need to check out SafeBase. SafeBase’s Smart Trust Center is a centralized source of truth for your organization’s security and compliance information. After implementing SafeBase, many companies see a 90% reduction in custom questionnaires. Imagine how much time you’d save. Visit safebase.com to find out more.

View Details

Verizon notifies customers their accounts were breached

German cyber chief removed over alleged Russian ties

Fortinet vulnerability being actively exploited

Thanks to this week's episode sponsor, SafeBase

Security questionnaires are a pain, and sharing sensitive documents takes too much back and forth. As a result, security can be wrongly viewed as a roadblock rather than a sales enabler. That's where SafeBase comes in. Our Smart Trust Center makes it easy to showcase your security program, share sensitive documents, and streamline security reviews. It's the missing piece of your security and sales workflow, and the only security tool that gives you time back. Find out more at safebase.com

For the stories behind the headlines, head to CISOseries.com

View Details

Ransomware halts German newspaper circulation

Meta disputes Indian content moderation report

KakaoTalk called a “national communication network” in Korea

Thanks to this week's episode sponsor, SafeBase

Security questionnaires are a pain, and sharing sensitive documents takes too much back and forth. As a result, security can be wrongly viewed as a roadblock rather than a sales enabler. That's where SafeBase comes in. Our Smart Trust Center makes it easy to showcase your security program, share sensitive documents, and streamline security reviews. It's the missing piece of your security and sales workflow, and the only security tool that gives you time back. Find out more at safebase.com

View Details

Microsoft says Ukraine, Poland targeted with novel ransomware attack

Wi-Fi spy drones snoop on financial firm

Indian power generation giant Tata Power hit by a cyber attack

Thanks to this week's episode sponsor, SafeBase

Security questionnaires. If those two words sent a shiver down your spine, you need to check out SafeBase. SafeBase’s Smart Trust Center is a centralized source of truth for your organization’s security and compliance information. After implementing SafeBase, many companies see a 90% reduction in custom questionnaires. Imagine how much time you’d save. Visit safebase.com to find out more.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, October 10-14, is hosted by Rich Stroffolino with our guest, Matt Honea, Head Of Security, SmartNews

Thanks to today’s episode sponsor, NoName Security

Prevent API attacks in real-time with automated AI and ML-based detection from Noname Security. Monitor API traffic for data leakage, data tampering, data policy violations, suspicious behavior, and API security attacks. Integrate with your existing IT workflow management system like Jira, ServiceNow, or Slack for seamless remediation. Learn more at nonamesecurity.com/runtime-protection

All links and the video of this episode can be found on CISO Series.com

View Details

Polonium APT targets Israel with a new custom backdoor dubbed PapaCreep

RSA Conference reveals CISO-Board relationships

UK government urges action to enhance supply chain security

Thanks to today’s episode sponsor, Noname Security

Prevent API attacks in real-time with automated AI and ML-based detection from Noname Security. Monitor API traffic for data leakage, data tampering, data policy violations, suspicious behavior, and API security attacks. Integrate with your existing IT workflow management system like Jira, ServiceNow, or Slack for seamless remediation. Learn more at nonamesecurity.com/runtime-protection

For the stories behind the headlines, head to CISOseries.com.

View Details

Npm timing attack could impact supply chain

Legit software used to spread malicious WhatsApp mod

Mango Markets hit by $100 million hack

Thanks to today’s episode sponsor, Noname Security

Are you sure your APIs are secure? Noname Security discovers all the APIs running on your network and analyzes them to spot design flaws, misconfigurations, and vulnerabilities. You can even catalog sensitive data and quickly see how many APIs are able to access credit card data, phone numbers, SSNs, and other sensitive PII data. Learn more at nonamesecurity.com/posture-management

View Details

UK warns of Chinese global security threat

Toyota data leak impacts 300,000 customers

CISOs at risk of being overworked

Thanks to today’s episode sponsor, Noname Security

Stop API vulnerabilities before production with Noname Security. Automatically run over 100 dynamic tests that simulate malicious traffic, including the OWASP API Top Ten. Integrate with your existing CI/CD pipelines and tools, such as Jenkins and Postman, as well as all your ticketing and workflow tools such as ServiceNow, Slack, and Jira. Learn more at nonamesecurity.com/active-testing

For the stories behind the headlines, head to CISOseries.com

View Details

Finger heat can leak your password

US airport sites targeted by KillNet

Intel confirms UEFI leak

Thanks to today’s episode sponsor, Noname Security

Prevent API attacks in real-time with automated AI and ML-based detection from Noname Security. Monitor API traffic for data leakage, data tampering, data policy violations, suspicious behavior, and API security attacks. Integrate with your existing IT workflow management system like Jira, ServiceNow, or Slack for seamless remediation. Learn more at nonamesecurity.com/runtime-protection

View Details

Fortinet warns admins to patch critical auth bypass bug immediately

Windows 11 22H2 errors break provisioning

Security chiefs fear ‘CISO scapegoating’ following Uber-Sullivan verdict

Thanks to today’s episode sponsor, Noname Security

Are you sure your APIs are secure? Noname Security discovers all the APIs running on your network and analyzes them to spot design flaws, misconfigurations, and vulnerabilities. You can even catalog sensitive data and quickly see how many APIs are able to access credit card data, phone numbers, SSNs, and other sensitive PII data. Learn more at nonamesecurity.com/posture-management

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, October 3-7, is hosted by Sean Kelly, with our guest, Patrick Benoit, VP, Global Cyber, GRC/BISO, CBRE

Thanks to this week’s episode sponsor, Hunters

Hunters is a SaaS platform, purpose built for Security Operation teams. Providing unlimited data ingestion and normalization at a predictable cost, Hunters helps SOC teams mitigate real threats faster and more reliably than SIEM. Visit Hunters.ai to learn more.

All links and the video of this episode can be found on CISO Series.com

View Details

Former Uber security chief found guilty of data breach coverup

Optus confirms 2.1 million ID numbers exposed in data breach

Retailer Easylife fined £1.5m for data protection breaches

Thanks to today’s episode sponsor, Hunters

Hunters is a SaaS platform, purpose built for Security Operation teams. Providing unlimited dataingestion and normalization at a predictable cost, Hunters helps SOC teams mitigate real threats faster and more reliably than SIEM. Visit Hunters.ai to learn more.

For the stories behind the headlines, head to CISOseries.com.

View Details

CommonSpirit Health hit with “IT security issue”

MySQL servers backdoored

Fraud hitting P2P payment apps

Thanks to today’s episode sponsor, Hunters

Hunters is a SaaS platform, purpose built for Security Operation teams. Providing unlimited dataingestion and normalization at a predictable cost, Hunters helps SOC teams mitigate real threats faster and more reliably than SIEM. Visit Hunters.ai to learn more.

View Details

Musk offers to proceed with Twitter deal

TikTok security deal becomes a political pawn

Netwalker ransomware affiliate sentenced to 20 years in prison

Thanks to today’s episode sponsor, Hunters

Hunters is a SaaS platform, purpose built for your Security Operation team. Cimpress, theparent company of VistaPrint, implemented Hunters SOC Platform to replace its SIEM. Thanks to Hunters, Cimpress no longer needs to babysit alerts and detection logic – they’ve improved their SOC’s efficiency, and optimized costs. Visit Hunters.ai to learn more.

For the stories behind the headlines, visit CISOseries.com

View Details

LA school data published on leak site

Exchange zero-day mitigations bypassed

Supreme Court will look legal protections for apps and sites

Thanks to today’s episode sponsor, Hunters

Hunters helps your security team overcome data volume and complexity – while significantlyreducing false positives. Upwork uses Hunters SOC Platform to “remain threat focused”. Because of Hunters, Upwork has been able to stop going through the daily repetitive task of looking at alerts, and doing repetitive, manual investigations. Learn more at: Hunters.ai

View Details

Microsoft confirms two Exchange Server zero days are being used in cyberattacks

Lazarus hackers abuse Dell driver bug using new FudModule rootkit

Ex-NSA employee charged with violating Espionage Act, selling U.S. cyber secrets

Thanks to today’s episode sponsor, Hunters

Hunters is a SaaS platform, purpose built for Security Operation teams. Providing unlimited dataingestion and normalization at a predictable cost, Hunters helps SOC teams mitigate real threats faster and more reliably than SIEM. Visit Hunters.ai to learn more.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, September 26-30, is hosted by Rich Stroffolino with our guest, Sara Lazarus, VP and head of trust and security, Stavvy

Thanks to today’s episode sponsor, Votiro

Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.

All links and the video of this episode can be found on CISO Series.com

View Details

Finnish intelligence warns Russia ‘highly likely’ to turn to cyber in winter

Researchers uncover covert attack campaign targeting military contractors

IRS warns of "industrial scale" smishing surge

Thanks to today’s episode sponsor, Votiro

Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Finnish intelligence warns Russia ‘highly likely’ to turn to cyber in winter

Researchers uncover covert attack campaign targeting military contractors

IRS warns of "industrial scale" smishing surge

Thanks to today’s episode sponsor, Votiro

Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Leaked ransomware builder used in attacks

Cloudflare hopes Turnstile can replace CAPTCHAs

Fast Company goes dark after cyber attack

Thanks to today’s episode sponsor, Votiro

Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.

View Details

Leaked ransomware builder used in attacks

Cloudflare hopes Turnstile can replace CAPTCHAs

Fast Company goes dark after cyber attack

Thanks to today’s episode sponsor, Votiro

Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.

View Details

Lazarus Group targets macOS users

Geopolitics behind recent DDoS surge

Meta takes on influence networks

Thanks to today’s episode sponsor, Votiro

Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.

View Details

Lazarus Group targets macOS users

Geopolitics behind recent DDoS surge

Meta takes on influence networks

Thanks to today’s episode sponsor, Votiro

Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.

View Details

Jamf buys ZecOps

Porn phishing scam turns into a DDoS

Cloudflare announced secure eSIM offering

Thanks to today’s episode sponsor, Votiro

Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.

View Details

Jamf buys ZecOps

Porn phishing scam turns into a DDoS

Cloudflare announced secure eSIM offering

Thanks to today’s episode sponsor, Votiro

Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.

View Details

London Police arrest 17-year-old hacker suspected of Uber and GTA 6 breaches

Microsoft SQL servers hacked in TargetCompany ransomware attacks

Attackers impersonate CircleCI platform to compromise GitHub accounts

Thanks to today’s episode sponsor, Votiro

Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

London Police arrest 17-year-old hacker suspected of Uber and GTA 6 breaches

Microsoft SQL servers hacked in TargetCompany ransomware attacks

Attackers impersonate CircleCI platform to compromise GitHub accounts

Thanks to today’s episode sponsor, Votiro

Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, September 19-23, is hosted by Rich Stroffolino with our guest, Joseph Lewis, Director, Cyber Assessment Strategy, US Department of Energy

Thanks to this week’s sponsor, 6clicks

6clicks is your AI-powered GRC platform, featuring a fully integrated content library. 6clicks provides organizations with a powerful GRC platform to build highly scalable risk and compliance functions and advisors with the tools to streamline and scale their services, saving everyone enormous time and money. Reimagine risk. Improve cybersecurity. Demonstrate compliance. For more information visit 6clicks.com/cisoseries.

All links and the video of this episode can be found on CISO Series.com

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, September 19-23, is hosted by Rich Stroffolino with our guest, Joseph Lewis, Director, Cyber Assessment Strategy, US Department of Energy

Thanks to this week’s sponsor, 6clicks

6clicks is your AI-powered GRC platform, featuring a fully integrated content library. 6clicks provides organizations with a powerful GRC platform to build highly scalable risk and compliance functions and advisors with the tools to streamline and scale their services, saving everyone enormous time and money. Reimagine risk. Improve cybersecurity. Demonstrate compliance. For more information visit 6clicks.com/cisoseries.

All links and the video of this episode can be found on CISO Series.com

View Details

MFA Fatigue: Hackers’ new favorite tactic in high-profile breaches

Senate reports details inefficiencies, confusion at key U.S. counterintelligence center

Australian telco Optus suffers massive data breach

Thanks to today’s episode sponsor, 6clicks

With 6clicks, organizations can manage enterprise risk easier than ever before. 6clicks helps you identify your risks, group them into risk registers, and run risk assessments. It highlights causes and potential impacts, outlines risk treatment plans, and helps you manage the full treatment lifecycle – all while informing your holistic GRC posture with built-in data linkages. For more information visit 6clicks.com/cisoseries.

For the stories behind the headlines, head to CISOseries.com.

View Details

MFA Fatigue: Hackers’ new favorite tactic in high-profile breaches

Senate reports details inefficiencies, confusion at key U.S. counterintelligence center

Australian telco Optus suffers massive data breach

Thanks to today’s episode sponsor, 6clicks

With 6clicks, organizations can manage enterprise risk easier than ever before. 6clicks helps you identify your risks, group them into risk registers, and run risk assessments. It highlights causes and potential impacts, outlines risk treatment plans, and helps you manage the full treatment lifecycle – all while informing your holistic GRC posture with built-in data linkages. For more information visit 6clicks.com/cisoseries.

For the stories behind the headlines, head to CISOseries.com.

View Details

15-year old Python bug causing problem

LinkedIn Smart Links used for phishing

US military buys Augury network monitoring tool

Thanks to today’s episode sponsor, 6clicks

Your GRC solution is only as valuable as the reports it can generate. Provide an exceptional analytics experience for all your GRC stakeholders with the 6clicks reporting suite. Unlock powerful insights and prove compliance using dashboards and charts, pixel perfect reporting, presentations, and data storytelling via LiveDocs.. For more information visit 6clicks.com/cisoseries.

View Details

15-year old Python bug causing problem

LinkedIn Smart Links used for phishing

US military buys Augury network monitoring tool

Thanks to today’s episode sponsor, 6clicks

Your GRC solution is only as valuable as the reports it can generate. Provide an exceptional analytics experience for all your GRC stakeholders with the 6clicks reporting suite. Unlock powerful insights and prove compliance using dashboards and charts, pixel perfect reporting, presentations, and data storytelling via LiveDocs.. For more information visit 6clicks.com/cisoseries.

View Details

American Airlines announce breach of customer and staff info

Crypto market maker hacked for $160 million

2K and Rockstar fall victim to cyber attacks

Thanks to today’s episode sponsor, 6clicks

The 6clicks GRC solution comes with a fully integrated content library full of hundreds of standards, assessment templates, libraries, playbooks, and more. With the content library included in every 6clicks license, organizations can get started on their GRC implementation faster than ever before. For more information visit 6clicks.com/cisoseries.

For the stories behind the headlines, head to CISOseries.com

View Details

American Airlines announce breach of customer and staff info

Crypto market maker hacked for $160 million

2K and Rockstar fall victim to cyber attacks

Thanks to today’s episode sponsor, 6clicks

The 6clicks GRC solution comes with a fully integrated content library full of hundreds of standards, assessment templates, libraries, playbooks, and more. With the content library included in every 6clicks license, organizations can get started on their GRC implementation faster than ever before. For more information visit 6clicks.com/cisoseries.

For the stories behind the headlines, head to CISOseries.com

View Details

The shifting ways of Chromeloader

Ransomware attacks fall in first half

Pentagon orders review of social media influence campaigns

Thanks to today’s episode sponsor, 6clicks

Experience the magic of Hailey, the 6clicks artificial intelligence engine for risk and compliance. With Hailey, organizations can automatically show cross-compliance between regulations or identify gaps to external compliance requirements in their policies. Eliminate manual and costly risk and compliance processes by joining the hundreds of businesses that trust 6clicks. For more information visit 6clicks.com/cisoseries.

View Details

The shifting ways of Chromeloader

Ransomware attacks fall in first half

Pentagon orders review of social media influence campaigns

Thanks to today’s episode sponsor, 6clicks

Experience the magic of Hailey, the 6clicks artificial intelligence engine for risk and compliance. With Hailey, organizations can automatically show cross-compliance between regulations or identify gaps to external compliance requirements in their policies. Eliminate manual and costly risk and compliance processes by joining the hundreds of businesses that trust 6clicks. For more information visit 6clicks.com/cisoseries.

View Details

Uber says there is no evidence that users’ private information was compromised

LastPass says hackers accessed its systems for just 4 days

Netgear Routers impacted by FunJSQ module flaw

Thanks to today’s episode sponsor, 6clicks

6clicks has pioneered a unique Hub & Spoke architecture to underpin its AI-powered GRC solution and cater to markets requiring scalable, multi-tenanted GRC. This model enables organizations to deploy multiple, autonomous GRC entities connected to a single hub for roll-up reporting, management, and visibility. For more information visit 6clicks.com/cisoseries.

For the stories behind the headlines, head to CISOseries.com.

View Details

Uber says there is no evidence that users’ private information was compromised

LastPass says hackers accessed its systems for just 4 days

Netgear Routers impacted by FunJSQ module flaw

Thanks to today’s episode sponsor, 6clicks

6clicks has pioneered a unique Hub & Spoke architecture to underpin its AI-powered GRC solution and cater to markets requiring scalable, multi-tenanted GRC. This model enables organizations to deploy multiple, autonomous GRC entities connected to a single hub for roll-up reporting, management, and visibility. For more information visit 6clicks.com/cisoseries.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, Quincy Castro, CISO, Redis

Thanks to today’s episode sponsor, Edgescan

Scalable automated and continuous Attack Surface Management (ASM) and vulnerability detection integrated with a world-class cyber security team provide 100% false-positive-free alerts and expert remediation guidance. Edgescan.com

All links and the video of this episode can be found on CISO Series.com

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, Quincy Castro, CISO, Redis

Thanks to today’s episode sponsor, Edgescan

Scalable automated and continuous Attack Surface Management (ASM) and vulnerability detection integrated with a world-class cyber security team provide 100% false-positive-free alerts and expert remediation guidance. Edgescan.com

All links and the video of this episode can be found on CISO Series.com

View Details

Gamers targeted by self-spreading stealer on YouTube

Biden order further scrutinizes foreign tech supply chains

Phishing attacks being launched in the name of Queen Elizabeth II

Thanks to today’s episode sponsor, Edgescan

Edgescan simplifies Vulnerability Management by delivering a single full-stack solution (SaaS) integrated with world-class security professionals. Instead of managing a plethora of point scanning tools for each layer of the attack surface and squandering precious staff resources manually removing false positives, Edgescan offers automated and accurate contextualized alerts across the entire attack surface into a single source of truth.

For the stories behind the headlines, head to CISOseries.com

View Details

Gamers targeted by self-spreading stealer on YouTube

Biden order further scrutinizes foreign tech supply chains

Phishing attacks being launched in the name of Queen Elizabeth II

Thanks to today’s episode sponsor, Edgescan

Edgescan simplifies Vulnerability Management by delivering a single full-stack solution (SaaS) integrated with world-class security professionals. Instead of managing a plethora of point scanning tools for each layer of the attack surface and squandering precious staff resources manually removing false positives, Edgescan offers automated and accurate contextualized alerts across the entire attack surface into a single source of truth.

For the stories behind the headlines, head to CISOseries.com

View Details

Teams stores tokens in cleartext

Cyberscammers caught up in human trafficking

US Treasury issues guidance on Tornado Cash

Thanks to today’s episode sponsor, Edgescan

Scalable automated and continuous Attack Surface Management (ASM) and vulnerability detection integrated with a world-class cyber security team provide 100% false-positive-free alerts and expert remediation guidance.

View Details

Teams stores tokens in cleartext

Cyberscammers caught up in human trafficking

US Treasury issues guidance on Tornado Cash

Thanks to today’s episode sponsor, Edgescan

Scalable automated and continuous Attack Surface Management (ASM) and vulnerability detection integrated with a world-class cyber security team provide 100% false-positive-free alerts and expert remediation guidance.

View Details

Apple Releases iOS and macOS updates to patch actively exploited zero-day flaw

Extreme California heat knocks key Twitter data center offline

New phishing scheme uses 'herd mentality' approach to dupe victims

Thanks to today’s episode sponsor, Edgescan

Edgescan combines full-stack coverage with integrated reporting and business-level prioritization to deliver a single source of truth for your entire vulnerability management program with zero false positives.

For the stories behind the headlines, head to CISOseries.com.

View Details

Apple Releases iOS and macOS updates to patch actively exploited zero-day flaw

Extreme California heat knocks key Twitter data center offline

New phishing scheme uses 'herd mentality' approach to dupe victims

Thanks to today’s episode sponsor, Edgescan

Edgescan combines full-stack coverage with integrated reporting and business-level prioritization to deliver a single source of truth for your entire vulnerability management program with zero false positives.

For the stories behind the headlines, head to CISOseries.com.

View Details

Google closes on Mandiant

Paying the iron price for Retbleed mitigation

Meta hands over the keys to PyTorch

Thanks to today’s episode sponsor, Edgescan

Edgescan offers a single platform solution that covers the full stack, from Web Applications to APIs to the Network and data layer. Continuous Attack Surface Management coupled with automated & strategic Pen-testing as a Service (PTaaS) yields fully scalable coverage.

View Details

Google closes on Mandiant

Paying the iron price for Retbleed mitigation

Meta hands over the keys to PyTorch

Thanks to today’s episode sponsor, Edgescan

Edgescan offers a single platform solution that covers the full stack, from Web Applications to APIs to the Network and data layer. Continuous Attack Surface Management coupled with automated & strategic Pen-testing as a Service (PTaaS) yields fully scalable coverage.

View Details

Ransomware gangs switching to new intermittent encryption tactic

Firmware bugs in many HP computer models left unfixed for over a year

U.S. SEC to set up new office for crypto filings

Thanks to today’s episode sponsor, Edgescan

Edgescan simplifies Vulnerability Management by delivering a single full-stack solution (SaaS) integrated with world-class security professionals. Instead of managing a plethora of point scanning tools for each layer of the attack surface and squandering precious staff resources manually removing false positives, Edgescan offers automated and accurate contextualized alerts across the entire attack surface into a single source of truth.

For the stories behind the headlines, head to CISOseries.com.

View Details

Ransomware gangs switching to new intermittent encryption tactic

Firmware bugs in many HP computer models left unfixed for over a year

U.S. SEC to set up new office for crypto filings

Thanks to today’s episode sponsor, Edgescan

Edgescan simplifies Vulnerability Management by delivering a single full-stack solution (SaaS) integrated with world-class security professionals. Instead of managing a plethora of point scanning tools for each layer of the attack surface and squandering precious staff resources manually removing false positives, Edgescan offers automated and accurate contextualized alerts across the entire attack surface into a single source of truth.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, Jason Elrod, CISO, Multicare Health System

Thanks to today’s episode sponsor, Snyk

*Developers want to code fast and security wants to ship securely — and they want to do it all from the cloud. That’s why they both choose Snyk. Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.
Code, dependencies, containers, cloud environments… all of it.

And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects and cloud environments, so they can prioritize and focus their efforts in the right places.

Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity*

All links and the video of this episode can be found on CISO Series.com

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, Jason Elrod, CISO, Multicare Health System

Thanks to today’s episode sponsor, Snyk

*Developers want to code fast and security wants to ship securely — and they want to do it all from the cloud. That’s why they both choose Snyk. Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.
Code, dependencies, containers, cloud environments… all of it.

And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects and cloud environments, so they can prioritize and focus their efforts in the right places.

Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity*

All links and the video of this episode can be found on CISO Series.com

View Details

China accuses US of cyberattacks and cyberespionage

London's biggest bus operator hit by cyber "incident"

Researchers reveal new Iranian threat group APT42

Thanks to today’s episode sponsor, Snyk

Developers want to code fast and security wants to ship securely — and they want to do it all from the cloud. That’s why they both choose Snyk. Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.

Code, dependencies, containers, cloud environments... all of it.

And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects and cloud environments, so they can prioritize and focus their efforts in the right places.

Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity

For the stories behind the headlines, head to CISOseries.com.

View Details

China accuses US of cyberattacks and cyberespionage

London's biggest bus operator hit by cyber "incident"

Researchers reveal new Iranian threat group APT42

Thanks to today’s episode sponsor, Snyk

Developers want to code fast and security wants to ship securely — and they want to do it all from the cloud. That’s why they both choose Snyk. Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.

Code, dependencies, containers, cloud environments... all of it.

And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects and cloud environments, so they can prioritize and focus their efforts in the right places.

Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity

For the stories behind the headlines, head to CISOseries.com.

View Details

CISA asks for feedback on reporting rules

New Linux-focused malware targets IoT

Albania cuts diplomatic ties over cyberattack

Thanks to today’s episode sponsor, Snyk

Developers want to code fast and security wants to ship securely — and they want to do it all from the cloud. That’s why they both choose Snyk. Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.

Code, dependencies, containers, cloud environments... all of it.

And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects and cloud environments, so they can prioritize and focus their efforts in the right places.

Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity

View Details

CISA asks for feedback on reporting rules

New Linux-focused malware targets IoT

Albania cuts diplomatic ties over cyberattack

Thanks to today’s episode sponsor, Snyk

Developers want to code fast and security wants to ship securely — and they want to do it all from the cloud. That’s why they both choose Snyk. Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.

Code, dependencies, containers, cloud environments... all of it.

And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects and cloud environments, so they can prioritize and focus their efforts in the right places.

Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity

View Details

Uber's ex-cyber exec heads to trial

Twitter fires back at Mudge for “parroting” Elon Musk

FBI warns of ransomware attacks on school districts

Thanks to today’s episode sponsor, Snyk

Developers want to code fast and security wants to ship securely — and they want to do it all from the cloud. That’s why they both choose Snyk. Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.

Code, dependencies, containers, cloud environments... all of it.

And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects and cloud environments, so they can prioritize and focus their efforts in the right places.

Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity

For the stories behind the headlines, head to CISOseries.com

View Details

Uber's ex-cyber exec heads to trial

Twitter fires back at Mudge for “parroting” Elon Musk

FBI warns of ransomware attacks on school districts

Thanks to today’s episode sponsor, Snyk

Developers want to code fast and security wants to ship securely — and they want to do it all from the cloud. That’s why they both choose Snyk. Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.

Code, dependencies, containers, cloud environments... all of it.

And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects and cloud environments, so they can prioritize and focus their efforts in the right places.

Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity

For the stories behind the headlines, head to CISOseries.com

View Details

Transnational sextortion ring dismantled

TikTok denies breachtok

Cloudflare cuts off Kiwi Farms

Thanks to today’s episode sponsor, Snyk

Developers want to code fast and security wants to ship securely — and they want to do it all from the cloud. That’s why they both choose Snyk. Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.

Code, dependencies, containers, cloud environments... all of it.

And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects and cloud environments, so they can prioritize and focus their efforts in the right places.

Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity

View Details

Transnational sextortion ring dismantled

TikTok denies breachtok

Cloudflare cuts off Kiwi Farms

Thanks to today’s episode sponsor, Snyk

Developers want to code fast and security wants to ship securely — and they want to do it all from the cloud. That’s why they both choose Snyk. Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.

Code, dependencies, containers, cloud environments... all of it.

And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects and cloud environments, so they can prioritize and focus their efforts in the right places.

Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity

View Details

Federal agencies share supply chain security tips

Apple settles lawsuit with developer over App Store rejections and scams

Hackers were inside Neopets systems for 18 months

Thanks to today’s episode sponsor, Code42

It’s not just about the data leaving your company - what about the data coming in? Along with departing employees, new talent is also actively joining your organization. This poses cybersecurity challenges since they could be knowingly or unknowingly bringing data from their former company into your network.
Code42 Incydr is an Insider Risk Management SaaS that provides a comprehensive understanding of your data exposure and shows which activities require security intervention. Learn more at Code42.com/showme.

For the stories behind the headlines, head to CISOseries.com

View Details

Federal agencies share supply chain security tips

Apple settles lawsuit with developer over App Store rejections and scams

Hackers were inside Neopets systems for 18 months

Thanks to today’s episode sponsor, Code42

It’s not just about the data leaving your company - what about the data coming in? Along with departing employees, new talent is also actively joining your organization. This poses cybersecurity challenges since they could be knowingly or unknowingly bringing data from their former company into your network.
Code42 Incydr is an Insider Risk Management SaaS that provides a comprehensive understanding of your data exposure and shows which activities require security intervention. Learn more at Code42.com/showme.

For the stories behind the headlines, head to CISOseries.com

View Details

Google launches open-source bug bounty

Ragnar Locker claims attack on airline

Cloudflare won’t terminate services for controversial customers

Thanks to today’s episode sponsor, Code42

Surprise! Surprise! Five years from now, Jamie, who’s resigning today, will ring the NASDAQ bell officially launching her company on the public market. And what you’ll soon realize is that Jamie stole your most valuable data to start her new company. Learn how Code42 Incydr can stop data theft and protect your organizations’ most valuable assets. Visit Code42.com/showme to learn more.

View Details

Google Translate app is actually Windows crypto-mining malware

White House to give aviation executives classified cyberthreat briefing

Book distributor Baker & Taylor hit by ransomware

Thanks to our episode sponsor, Code42

Cybersecurity teams are facing unprecedented challenges when it comes to protecting sensitive corporate data from exposure, leak and theft.

In fact, the Code42 Annual Data Exposure Report revealed there’s a 1 in 3 chance that your company will lose IP when an employee quits. To learn more about stopping data leaks with Insider Risk Management visit Code42.com/showme.

For the stories behind the headlines, head to CISOseries.com.

View Details

Microsoft warns Iranians using Log4Shell

Montenegro hit with Russian cyberattacks

AlphaBay Turns 1

Thanks to this week's episode sponsor, Code42

Have you been thinking about launching an Insider Risk Management program? You don’t need to be Big Brother to effectively address Insider Risk.
Code42 believes that the Three Es should define any IRM program: expertise, education, and enforcement. Shift your security culture from “watchdog” to “guide dog” and everyone wins. Learn more at Code42.com/showme.

View Details

Microsoft warns Iranians using Log4Shell

Montenegro hit with Russian cyberattacks

AlphaBay Turns 1

Thanks to this week's episode sponsor, Code42

Have you been thinking about launching an Insider Risk Management program? You don’t need to be Big Brother to effectively address Insider Risk.
Code42 believes that the Three Es should define any IRM program: expertise, education, and enforcement. Shift your security culture from “watchdog” to “guide dog” and everyone wins. Learn more at Code42.com/showme.

View Details

Hackers breach LastPass developer system to steal source code

New Agenda ransomware appears in the threat landscape

Facebook-Cambridge Analytica data breach lawsuit ends in 11th hour settlement

Thanks to this week’s episode sponsor, Code42

It’s not just about the data leaving your company - what about the data coming in? Along with departing employees, new talent is also actively joining your organization. This poses cybersecurity challenges since they could be knowingly or unknowingly bringing data from their former company into your network.

Code42 Incydr is an Insider Risk Management SaaS that provides a comprehensive understanding of your data exposure and shows which activities require security intervention. Learn more at Code42.com/showme.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, John McClure, CISO, Sinclair Broadcast Group

Thanks to today’s episode sponsor, Code42

It’s not just about the data leaving your company – what about the data coming in? Along with departing employees, new talent is also actively joining your organization. This poses cybersecurity challenges since they could be knowingly or unknowingly bringing data from their former company into your network.
Code42 Incydr is an Insider Risk Management SaaS that provides a comprehensive understanding of your data exposure and shows which activities require security intervention. Learn more at Code42.com/showme.

All links and the video of this episode can be found on CISO Series.com

View Details

North Korean malware present at Black Hat

Ransomware attacks jump as new malware strains proliferate

Pentagon may require flaw-free software

Thanks to today’s episode sponsor, Code42

It’s not just about the data leaving your company - what about the data coming in? Along with departing employees, new talent is also actively joining your organization. This poses cybersecurity challenges since they could be knowingly or unknowingly bringing data from their former company into your network.
Code42 Incydr is an Insider Risk Management SaaS that provides a comprehensive understanding of your data exposure and shows which activities require security intervention. Learn more at Code42.com/showme

For the stories behind the headlines, head to CISOseries.com.

View Details

North Korean malware present at Black Hat

Ransomware attacks jump as new malware strains proliferate

Pentagon may require flaw-free software

Thanks to today’s episode sponsor, Code42

It’s not just about the data leaving your company - what about the data coming in? Along with departing employees, new talent is also actively joining your organization. This poses cybersecurity challenges since they could be knowingly or unknowingly bringing data from their former company into your network.
Code42 Incydr is an Insider Risk Management SaaS that provides a comprehensive understanding of your data exposure and shows which activities require security intervention. Learn more at Code42.com/showme

For the stories behind the headlines, head to CISOseries.com.

View Details

Microsoft reveals Nobelium’s MagicWeb

Details emerge on large-scale pro-Western influence campaigns

Stolen NFTs prove big business

Thanks to today’s episode sponsor, Code42

Surprise! Surprise! Five years from now, Jamie, who’s resigning today, will ring the NASDAQ bell officially launching her company on the public market. And what you’ll soon realize is that Jamie stole your most valuable data to start her new company. Learn how Code42 Incydr can stop data theft and protect your organizations’ most valuable assets. Visit Code42.com/showme to learn more.

View Details

Microsoft reveals Nobelium’s MagicWeb

Details emerge on large-scale pro-Western influence campaigns

Stolen NFTs prove big business

Thanks to today’s episode sponsor, Code42

Surprise! Surprise! Five years from now, Jamie, who’s resigning today, will ring the NASDAQ bell officially launching her company on the public market. And what you’ll soon realize is that Jamie stole your most valuable data to start her new company. Learn how Code42 Incydr can stop data theft and protect your organizations’ most valuable assets. Visit Code42.com/showme to learn more.

View Details

Ex-security chief accuses Twitter of cybersecurity negligence

Ukraine and Poland join forces to counter Russian cyberattacks

Hackers use Binance exec deepfake in crypto exchange scam

Thanks to today’s episode sponsor, Code42

Cybersecurity teams are facing unprecedented challenges when it comes to protecting sensitive corporate data from exposure, leak and theft.
In fact, the Code42 Annual Data Exposure Report revealed there’s a 1 in 3 chance that your company will lose IP when an employee quits. To learn more about stopping data leaks with Insider Risk Management visit Code42.com/showme.

For the stories behind the headlines, head over to CISOseries.com

View Details

State-backed attacks excluded from cyber insurance

LockBit hit with DDoS

Cozy Bear using Microsoft accounts to bypass MFA

Thanks to today’s episode sponsor, Code42

Have you been thinking about launching an Insider Risk Management program? You don’t need to be Big Brother to effectively address Insider Risk.

Code42 believes that the Three Es should define any IRM program: expertise, education, and enforcement. Shift your security culture from “watchdog” to “guide dog” and everyone wins. Learn more at Code42.com/showme.

View Details

iPhone users urged to update to patch 2 zero-days

Encrypted ZIP files can have two correct passwords

White hat hackers broadcast through decommissioned satellite

Thanks to today’s episode sponsor, Code42

It’s not just about the data leaving your company - what about the data coming in? Along with departing employees, new talent is also actively joining your organization. This poses cybersecurity challenges since they could be knowingly or unknowingly bringing data from their former company into your network.
Code42 Incydr is an Insider Risk Management SaaS that provides a comprehensive understanding of your data exposure and shows which activities require security intervention. Learn more at Code42.com/showme

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, Stephen Harrison, VP Cyber Defense, MGM Resorts

Thanks to today’s episode sponsor, 6clicks

With 6clicks, organizations can manage enterprise risk easier than ever before. 6clicks helps you identify your risks, group them into risk registers, and run risk assessments. It highlights causes and potential impacts, outlines risk treatment plans, and helps you manage the full treatment lifecycle. For more information visit 6clicks.com/cisoseries.

All links and the video of this episode can be found on CISO Series.com

View Details

Google blocks largest HTTPS DDoS attack 'reported to date'

Cyber Command loses Moore

A new version of BlackByte offers extortion options

Thanks to today’s episode sponsor, 6clicks

With 6clicks, organizations can manage enterprise risk easier than ever before. 6clicks helps you identify your risks, group them into risk registers, and run risk assessments. It highlights causes and potential impacts, outlines risk treatment plans, and helps you manage the full treatment lifecycle. For more information visit 6clicks.com/cisoseries.

For the stories behind the headlines, head to CISOseries.com.

View Details

PyPi packages turn installed apps to backdoors

Project Sugarush targets Israeli shipping

RedAlpha ramps up phishing efforts

Thanks to today’s episode sponsor, 6clicks

Manage the full assessment lifecycle and get your business audit-ready more easily than ever using 6clicks. Identify overlap from completed audits and assessments with other standards and frameworks using Hailey-AI to streamline compliance with multiple audit requirements. With built-in content, organizations can get started on their audit and assessments faster than ever before. For more information visit 6clicks.com/cisoseries.

View Details

Oracle begins auditing TikTok's algorithms

Digital Ocean dumps Mailchimp after attack leaked customer data

Signal users exposed in targeted Twilio attack

Thanks to today’s episode sponsor, 6clicks

6clicks is where vulnerability management and GRC unite. With 6licks, organizations can ingest their vulnerabilities from all scanners, link assets to vulnerabilities, raise risks and issues to remediate, and close vulnerabilities as they are remediated – all while informing their risk and compliance posture in a single platform for cohesive reporting. For more information visit 6clicks.com/cisoseries.

For the stories behind the headlines, head to CISOseries.com.

View Details

Chat app used as a backdoor

PyPi package drops crytominer

Access to corporate networks sees a value dip

Thanks to today’s episode sponsor, 6clicks

Protect your supply chain from third-party risk with the power of 6clicks. Organizations can better manage their vendor risk by automating the vendor assessment lifecycle and detecting vendor assessment findings. Users can identify and raise risks linked to vendors post-assessment and group them into risk registers. Then, manage, remediate and report on risks directly from 6clicks. For more information visit 6clicks.com/cisoseries.

View Details

Ukraine's cyber chief makes surprise visit to Black Hat

Killnet claims to have hacked Lockheed Martin

Starlink successfully hacked using $25 modchip

Thanks to today’s episode sponsor, 6clicks

Identify, track, respond, and remediate issues and incidents from your various GRC workflows with 6clicks. With an issue submission form, 6clicks makes it easy and efficient for employees to submit incidents directly to an incident management team for triaging and response. Use the built-in incident response playbooks, or your own, to standardize incident response across the organization. For more information visit 6clicks.com/cisoseries.

For the stories behind the headlines, head to CISOseries.com

View Details

Ukraine's cyber chief makes surprise visit to Black Hat

Killnet claims to have hacked Lockheed Martin

Starlink successfully hacked using $25 modchip

Thanks to today’s episode sponsor, 6clicks

Identify, track, respond, and remediate issues and incidents from your various GRC workflows with 6clicks. With an issue submission form, 6clicks makes it easy and efficient for employees to submit incidents directly to an incident management team for triaging and response. Use the built-in incident response playbooks, or your own, to standardize incident response across the organization. For more information visit 6clicks.com/cisoseries.

For the stories behind the headlines, head to CISOseries.com

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, Jack Kufahl, CISO, Michigan Medicine

Thanks to today’s episode sponsor, Edgescan

Edgescan simplifies Vulnerability Management by delivering a single full-stack solution (SaaS) integrated with world-class security professionals. Instead of managing a plethora of point scanning tools for each layer of the attack surface and squandering precious staff resources manually removing false positives, Edgescan offers automated and accurate contextualized alerts across the entire attack surface into a single source of truth.

All links and the video of this episode can be found on CISO Series.com

View Details

Cisco admits corporate network compromised by gang with links to Lapsus$

CISA should split from DHS says Chris Krebs

Ransomware data theft epidemic fueling BEC attacks

Thanks to today’s episode sponsor, Edgescan

Edgescan simplifies Vulnerability Management by delivering a single full-stack solution (SaaS) integrated with world-class security professionals. Instead of managing a plethora of point scanning tools for each layer of the attack surface and squandering precious staff resources manually removing false positives, Edgescan offers automated and accurate contextualized alerts across the entire attack surface into a single source of truth.

For the stories behind the headlines, head to CISOseries.com.

View Details

Introducing the Open Cybersecurity Schema Framework

New flaw found in Intel SGX

CISA adds to its Known Exploited Vulnerabilities database

Thanks to today’s episode sponsor, Edgescan

Scalable automated and continuous Attack Surface Management (ASM) and vulnerability detection integrated with a world-class cyber security team provide 100% false-positive-free alerts and expert remediation guidance.

View Details

Chinese fraudsters target kids playing online games

Former Twitter employee convicted in Saudi spy case

Facebook divulges data leading to abortion prosecution

Thanks to today’s episode sponsor, Edgescan

Edgescan combines full-stack coverage with integrated reporting and business-level prioritization to deliver a single source of truth for your entire vulnerability management program with zero false positives.

For the stories behind the headlines, head to CISOseries.com

View Details

Treasury sanctions Tornado Cash

Twilio confirms hack

Chinese hacking group targets backdoors

Thanks to today’s episode sponsor, Edgescan

Edgescan offers a single platform solution that covers the full stack, from Web Applications to APIs to the Network and data layer. Continuous Attack Surface Management coupled with automated & strategic Pen-testing as a Service (PTaaS) yields fully scalable coverage.

View Details

Critical flaws found in US Emergency Alert System

Security experts urge Fick's speedy confirmation as first U.S. cyber ambassador

High-severity bug in Kaspersky VPN client opens door to PC takeover

Thanks to today’s episode sponsor, Edgescan

Edgescan simplifies Vulnerability Management by delivering a single full-stack solution (SaaS) integrated with world-class security professionals. Instead of managing a plethora of point scanning tools for each layer of the attack surface and squandering precious staff resources manually removing false positives, Edgescan offers automated and accurate contextualized alerts across the entire attack surface into a single source of truth.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, Yael Nagler, CISO, Walker & Dunlop

Thanks to this week’s sponsor, HYAS

“Did you know a cybersecurity breach doesn’t have to mean that your business is shut down or your data is stolen? Malware, ransomware, data exfiltration: They all report to a command and control infrastructure to receive instructions.

HYAS’s unrivaled understanding of adversary infrastructure empowers you to cut off threats from their command and control, along with any related infrastructure. Like that old roach motel, hackers can get in, but they can’t communicate out, rendering their attack worthless. When HYAS has your back, you can proactively prevent attacks from being executed — letting your business keep moving full forward. Visit HYAS.com“

All links and the video of this episode can be found on CISO Series.com

View Details

Cyberattacks hit Taiwan to coincide with Speaker Pelosi’s visit4

Cisco addresses critical flaws in Small Business VPN routers

DOJ now relies on paper for its most sensitive court documents, official says

Thanks to today’s episode sponsor, HYAS

We know IT and security teams are already overloaded — facing constant pressure to improve security without additional resources. That’s why it’s so important to find solutions that bolster your security, not your workload.

HYAS Protect deploys in under 30 minutes, easily integrates into existing infrastructure, constantly updates with the latest threat intelligence, renders attacks inert (regardless of how they infiltrated your environment), and doesn’t require day-to-day hand-holding — letting you focus on keeping your business moving full forward.

Visit HYAS.com

For the stories behind the headlines, head to CISOseries.com.

View Details

Ukraine takes down massive bot farm

Thousands of Solana wallets drained

Semikron hit by cyberattack

Thanks to today’s episode sponsor, HYAS

Cybercriminals try their hardest to cover their tracks, but no matter what, they always leave a trail. HYAS Insight gives you access to all of the data you need to trace an attack back to its source. This helps you map out the complete attack campaign infrastructure, letting you proactively defend against future attacks and even potentially provide key data to law enforcement.

Take your cybersecurity investigations further than you ever thought possible with HYAS Insight.

Visit HYAS.com

View Details

US crypto firm hit by $190 million theft

T-Mobile store owner busted running phone unlocking scheme

EU missile maker denies breach but confirms extortion attempt

Thanks to today’s episode sponsor, HYAS

Cybercriminals try their hardest to cover their tracks, but no matter what, they always leave a trail. HYAS Insight gives you access to all of the data you need to trace an attack back to its source. This helps you map out the complete attack campaign infrastructure, letting you proactively defend against future attacks and even potentially provide key data to law enforcement.

Take your cybersecurity investigations further than you ever thought possible with HYAS Insight.

Visit HYAS.com

View Details

Akamai disrupts record DDoS in Europe

Australian man faces spyware charges

Meta accused of failing to tackle hate speech in Kenya

Thanks to today’s episode sponsor, HYAS

*Cybercriminals try their hardest to cover their tracks, but no matter what, they always leave a trail. HYAS Insight gives you access to all of the data you need to trace an attack back to its source. This helps you map out the complete attack campaign infrastructure, letting you proactively defend against future attacks and even potentially provide key data to law enforcement.

Take your cybersecurity investigations further than you ever thought possible with HYAS Insight.

Visit HYAS.com*

View Details

Huge network of 11,000 fake investment sites targets Europe

DawDropper Android apps serve up banking malware

North Korea-linked SharpTongue spies on email accounts with a malicious browser extension

Thanks to today's episode sponsor, Hyas.

Better production environment security starts with visibility. After all, how can you protect your most valuable asset if you don’t know A: what’s expected and B: when something’s happening that isn’t expected?

This is why HYAS Confront monitors traffic to alert you to anomalies, letting you address risks, threats, and changes, while blocking infiltrations before they become successful attacks.

Don’t just react, take your security back with HYAS. Visit HYAS.com

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, Deneen DeFiore, VP, CISO, United Airlines

Thanks to our show sponsor, Snyk

*Developers want to code fast and security wants to ship securely. And that’s why they both choose Snyk.
Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.

Code, dependencies, containers, cloud infrastructure… all of it.

And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects, so they can prioritize and focus their efforts in the right places.

Developer tested. Security approved. Start your free Snyk account atsnyk.co/cybersecurity.*

All links and the video of this episode can be found on CISO Series.com

View Details

Hackers opting for new attack methods after Microsoft blocked macros by default

Microsoft 365 outage knocks down admin center in North America

22 million US health records breached thus far in 2022

Thanks to today’s episode sponsor, Snyk

Developers want to code fast and security wants to ship securely. And that’s why they both choose Snyk.
Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.

Code, dependencies, containers, cloud infrastructure... all of it.

And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects, so they can prioritize and focus their efforts in the right places.

Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity.

For the stories behind the headlines, head to CISOseries.com.

View Details

Hackers opting for new attack methods after Microsoft blocked macros by default

Microsoft 365 outage knocks down admin center in North America

22 million US health records breached thus far in 2022

Thanks to today’s episode sponsor, Snyk

Developers want to code fast and security wants to ship securely. And that’s why they both choose Snyk.
Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.

Code, dependencies, containers, cloud infrastructure... all of it.

And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects, so they can prioritize and focus their efforts in the right places.

Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity.

For the stories behind the headlines, head to CISOseries.com.

View Details

Microsoft warns of Subzero malware

JusTalk logs leak

The cost of an average data breach

Thanks to today’s episode sponsor, Snyk

Developers want to code fast and security wants to ship securely. And that’s why they both choose Snyk.
Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.

Code, dependencies, containers, cloud infrastructure... all of it.

And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects, so they can prioritize and focus their efforts in the right places.

Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity.

View Details

Hacker swipes $6 million from blockchain music platform

Coding error to blame for Rogers outage

US doubles reward for tips on North Korean-backed hackers

Thanks to today’s episode sponsor, Snyk

Developers want to code fast and security wants to ship securely. And that’s why they both choose Snyk.
Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.

Code, dependencies, containers, cloud infrastructure... all of it.

And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects, so they can prioritize and focus their efforts in the right places.

Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity.

For the stories behind the headlines, head to CISOseries.com

View Details

Hacker swipes $6 million from blockchain music platform

Coding error to blame for Rogers outage

US doubles reward for tips on North Korean-backed hackers

Thanks to today’s episode sponsor, Snyk

Developers want to code fast and security wants to ship securely. And that’s why they both choose Snyk.
Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.

Code, dependencies, containers, cloud infrastructure... all of it.

And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects, so they can prioritize and focus their efforts in the right places.

Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity.

For the stories behind the headlines, head to CISOseries.com

View Details

LockBit hits Italy

Quantum cybersecurity bill heads to the Senate

Windows adds brute force defense

Thanks to today’s episode sponsor, Snyk

Developers want to code fast and security wants to ship securely. And that’s why they both choose Snyk.
Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.

Code, dependencies, containers, cloud infrastructure... all of it.

And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects, so they can prioritize and focus their efforts in the right places.

Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity.

View Details

FBI uncovers Chinese and Huawei misdeeds

5.4 million Twitter accounts available for sale

Microsoft warns that new Windows updates may break printing

Thanks to today’s episode sponsor, Snyk

Developers want to code fast and security wants to ship securely. And that’s why they both choose Snyk.
Backed by industry-leading security intelligence, Snyk provides real-time scanning with automated fixes and remediation advice right from the tools and workflows developers use.

Code, dependencies, containers, cloud infrastructure... all of it.

And while developers are building securely, Snyk gives security teams a bird’s eye view of all of their projects, so they can prioritize and focus their efforts in the right places.

Developer tested. Security approved. Start your free Snyk account at snyk.co/cybersecurity.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, Renee Guttmann, Former CISO, Campbell Soup, Coca Cola, Time Warner

Thanks to this week’s sponsor, 6clicks

6clicks is your AI-powered GRC platform, featuring a fully-integrated content library. 6clicks provides organizations with a powerful GRC platform to build highly scalable risk and compliance functions and advisors with the tools to streamline and scale their services, saving everyone enormous time and money. Reimagine risk. Improve cybersecurity. Demonstrate compliance. For more information visit 6clicks.com/cisoseries.

All links and the video of this episode can be found on CISO Series.com

View Details

Microsoft Teams outage also takes down Microsoft 365 services

Heatwave forced Google and Oracle to shut down in London

Hackers for hire: adversaries employ “cyber mercenaries”

Thanks to today’s episode sponsor, 6clicks

Experience the magic of Hailey, the 6clicks artificial intelligence engine for risk and compliance. With Hailey, organizations can automatically show cross-compliance between regulations or identify gaps to external compliance requirements in their policies. Eliminate manual and costly risk and compliance processes by joining the hundreds of businesses that trust 6clicks. For more information visit 6clicks.com/cisoseries.

For the stories behind the headlines, head to CISOseries.com.

View Details

Microsoft cuts security jobs amidst weakening economy

Is your cute little Neopet leaking your personal data?

Russia disguises malware as Ukrainian app for hacking Russia

Thanks to today’s episode sponsor, 6clicks

The 6clicks GRC solution comes with a fully integrated content library full of hundreds of standards, assessment templates, libraries, playbooks, and more. With the content library included in every 6clicks license, organizations can get started on their GRC implementation faster than ever before. For more information visit 6clicks.com/content.

For the stories behind the headlines, head over to CISOseries.com

View Details

Car GPS tracker exposes location data

Russian malware groups spoof pro-Ukraine apps

MacOS backdoor speaks to the cloud

Thanks to today’s episode sponsor, 6clicks

Your GRC solution is only as valuable as the reports it can generate. Provide an exceptional analytics experience for all your GRC stakeholders with the 6clicks reporting suite. Unlock powerful insights and prove compliance using dashboards and charts, pixel perfect reporting, presentations, and data storytelling via LiveDocs. For more information visit 6clicks.com/analytics/overview.

View Details

Albania hit with cyberattack

Vendors not patching for speculative execution

DARPA looks into open-source

Thanks to today’s episode sponsor, 6clicks

6clicks has pioneered a unique Hub & Spoke architecture to underpin its AI-powered GRC solution and cater to markets requiring scalable, multi-tenanted GRC. This model enables organizations to deploy multiple, autonomous GRC entities connected to a single hub for roll-up reporting, management, and visibility. For more information visit 6clicks.com/lp-enterprise-hub-spoke.

View Details

Dozens of cities and towns are paying tech workers to abandon Silicon Valley

CISA orders agencies to patch new Windows zero-day used in attacks

Password recovery tool infects industrial systems with Sality malware

Thanks to today’s episode sponsor, 6clicks

The 6clicks AI-powered GRC platform with an integrated content library is the most intelligent way to get ISO 27001 certified. It allows you to automate audits, manage risks, track assets, and report in real-time. Join hundreds of businesses that trust 6clicks and start your ISO 27001 journey today. For more information visit 6clicks.com/lp-iso-27001.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, Carla Sweeney, VP Information Security Red Ventures

Thanks to our episode sponsor, Edgescan

Edgescan simplifies Vulnerability Management by delivering a single full-stack solution (SaaS) integrated with world-class security professionals. Instead of managing a plethora of point scanning tools for each layer of the attack surface and squandering precious staff resources manually removing false positives, Edgescan offers automated and accurate contextualized alerts across the entire attack surface into a single source of truth.

All links and the video of this episode can be found on CISO Series.com

View Details

Ex-C.I.A. engineer convicted in biggest theft ever of Agency secrets

Chinese hackers targeted U.S. political reporters just ahead of January 6 attack, researchers say

Twitter outage briefly hits thousands

Thanks to today’s episode sponsor, Edgescan

Edgescan simplifies Vulnerability Management by delivering a single full-stack solution (SaaS) integrated with world-class security professionals. Instead of managing a plethora of point scanning tools for each layer of the attack surface and squandering precious staff resources manually removing false positives, Edgescan offers automated and accurate contextualized alerts across the entire attack surface into a single source of truth.

For the stories behind the headlines, head to CISOseries.com.

View Details

Microsoft warns of massive phishing operation

Android malware downloaded over 3 million times

More speculative-execution attacks found for x86

Thanks to today’s episode sponsor, Edgescan

Scalable automated and continuous Attack Surface Management (ASM) and vulnerability detection integrated with a world-class cyber security team provide 100% false-positive-free alerts and expert remediation guidance.

View Details

FTC is cracking down on false claims of anonymizing data

TikTok halts privacy policy change in Europe

Government contractor pays $9 million over whistleblower allegations

Thanks to today’s episode sponsor, Edgescan

Edgescan combines full-stack coverage with integrated reporting and business-level prioritization to deliver a single source of truth for your entire vulnerability management program with zero false positives.

For the stories behind the headlines, head to CISOseries.com

View Details

Ransomware hits French telco

NSO Group acquisition called off

Krebs on Experian security

Thanks to today’s episode sponsor, Edgescan

Edgescan offers a single platform solution that covers the full stack, from Web Applications to APIs to the Network and data layer. Continuous Attack Surface Management coupled with automated & strategic Pen-testing as a Service (PTaaS) yields fully scalable coverage.

View Details

China tries to censor what could be biggest data hack in history

Pentagon: We'll pay you if you can find a way to hack us

Tech’s red-hot hiring spree shows signs of cooling

Thanks to today’s episode sponsor, Edgescan

Edgescan simplifies Vulnerability Management by delivering a single full-stack solution (SaaS) integrated with world-class security professionals. Instead of managing a plethora of point scanning tools for each layer of the attack surface and squandering precious staff resources manually removing false positives, Edgescan offers automated and accurate contextualized alerts across the entire attack surface into a single source of truth.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

Cyber Security Headlines – Week in Review – July 4-8, 2022   This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, David Cross, SVP/CISO Oracle SaaS Cloud

Thanks to today’s episode sponsor, Votiro

Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.

All links and the video of this episode can be found on CISO Series.com

View Details

Cisco and Fortinet release security patches for multiple products

Canada’s RCMP have been using powerful malware to snoop on people’s communications

Online programming IDEs can be used to launch remote cyberattacks

Thanks to today’s episode sponsor, Votiro

Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Attackers moving off Cobalt Strike

Cyberattacks against law enforcement on the rise

Apple announces lockdown mode

Thanks to today’s episode sponsor, Votiro

Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.

View Details

Hacker may have stolen personal data of 1 billion Chinese citizens

Ukrainian police take down phishing gang behind payments scam

NIST unveils ‘quantum-proof’ cryptography algorithms

Thanks to today’s episode sponsor, Votiro

Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.

For the stories behind the headlines, head to CISOseries.com

View Details

Jenkins discloses dozens of zero-day bugs in multiple plugins

Rogue HackerOne employee steals bug reports to sell on the side

Patchable and preventable security issues lead causes of Q1 attacks

Thanks to today’s episode sponsor, Votiro

Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.

For the stories behind the headlines, head to CISOseries.com. 

View Details

A new sophisticated malware is attacking SOHO routers

New study shows over half of employees use prohibited apps

Google battles bots, puts Workspace admins on alert

Thanks to today’s episode sponsor, Optiv

The modern enterprise needs a solution as unique as its business.

*Optiv’s Advanced Detection and Response (ADR) works with your organization to comb through the D&R clutter and find the ideal security solutions for your business. ADR delivers tailored detection and response backed by technology, real-time intel and deep expertise applied at touch. Bottom line: ADR finds and neutralizes threats fast, so you can focus on what matters.

If you’d like to learn more about Optiv ADR, please visit Optiv.com/adr.*

For the stories behind the headlines, head to CISOseries.com.

View Details

NATO to create rapid response cyber force

FBI warns of deep fakes for remote work

Ship controls identified as another major attack surface

Thanks to today’s episode sponsor, Optiv

The modern enterprise needs a solution as unique as its business.

*Optiv’s Advanced Detection and Response (ADR) works with your organization to comb through the D&R clutter and find the ideal security solutions for your business. ADR delivers tailored detection and response backed by technology, real-time intel and deep expertise applied at touch. Bottom line: ADR finds and neutralizes threats fast, so you can focus on what matters.

If you’d like to learn more about Optiv ADR, please visit Optiv.com/adr.*

View Details

Stolen PII and deepfakes used to apply for tech jobs

Russia fines foreign firms for data violations

Premier League crypto sponsorships expose fans to big losses

Thanks to today’s episode sponsor, Optiv

The modern enterprise needs a solution as unique as its business.

*Optiv’s Advanced Detection and Response (ADR) works with your organization to comb through the D&R clutter and find the ideal security solutions for your business. ADR delivers tailored detection and response backed by technology, real-time intel and deep expertise applied at touch. Bottom line: ADR finds and neutralizes threats fast, so you can focus on what matters.

If you’d like to learn more about Optiv ADR, please visit Optiv.com/adr.*

For the stories behind the headlines, head to CISOseries.com

View Details

Ransomware gang launches bug bounty

KillNet claims DDoS on Lithuania

ICS security bill passes House

Thanks to today’s episode sponsor, Optiv

The modern enterprise needs a solution as unique as its business.

*Optiv’s Advanced Detection and Response (ADR) works with your organization to comb through the D&R clutter and find the ideal security solutions for your business. ADR delivers tailored detection and response backed by technology, real-time intel and deep expertise applied at touch. Bottom line: ADR finds and neutralizes threats fast, so you can focus on what matters.

If you’d like to learn more about Optiv ADR, please visit Optiv.com/adr.*

View Details

New phishing method bypasses MFA using Microsoft WebView2 apps

Russian threat actors may be behind the explosion at Texas liquefied natural gas plant

Google reveals sophisticated Italian spyware campaign targeting victims in Italy, Kazakhstan

Thanks to today’s episode sponsor, Optiv

The modern enterprise needs a solution as unique as its business.

*Optiv’s Advanced Detection and Response (ADR) works with your organization to comb through the D&R clutter and find the ideal security solutions for your business. ADR delivers tailored detection and response backed by technology, real-time intel and deep expertise applied at touch. Bottom line: ADR finds and neutralizes threats fast, so you can focus on what matters.

If you’d like to learn more about Optiv ADR, please visit Optiv.com/adr*

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, Marnie Wilking, CISO, Wayfair

Thanks to today’s episode sponsor, Optiv

Modernizing your identity control plane from AD to the cloud is complex. Ralph Martino, who is leading the identity and access management (IAM) group for Optiv, discusses what challenges CISOs are facing in today’s ever-changing climate:
• Increasing security
• Decreasing risk
• Lowering cost
Learn more at www.optiv.com/IAM-Microsoft.

All links and the video of this episode can be found on CISO Series.com

View Details

Cloud email threats soar 101% in a year

NHS warns of scam COVID-19 text messages

Fancy Bear uses nuke threat lure to exploit 1-click bug

Thanks to today's episode sponsor, Optiv

Modernizing your identity control plane from AD to the cloud is complex. Ralph Martino, who is leading the identity and access management (IAM) group for Optiv, discusses what challenges CISOs are facing in today’s ever-changing climate:
• Increasing security
• Decreasing risk
• Lowering cost
Learn more at www.optiv.com/IAM-Microsoft.

For the stories behind the headlines, head to CISOseries.com.

View Details

Daycare apps found insecure

Encryption flaws found in Mega

Microsoft retires cloud facial recognition

Thanks to today's episode sponsor, Optiv

Modernizing your identity control plane from AD to the cloud is complex. Ralph Martino, who is leading the identity and access management (IAM) group for Optiv, discusses what challenges CISOs are facing in today’s ever-changing climate:
• Increasing security
• Decreasing risk
• Lowering cost
Learn more at www.optiv.com/IAM-Microsoft.

View Details

Cloudflare outage impacts crypto exchanges

Biden signs a pair of cybersecurity bills

7-zip now supports Windows ‘Mark-of-the-Web’ security feature

Thanks to today's episode sponsor, Optiv

Modernizing your identity control plane from AD to the cloud is complex. Ralph Martino, who is leading the identity and access management (IAM) group for Optiv, discusses what challenges CISOs are facing in today’s ever-changing climate:
• Increasing security
• Decreasing risk
• Lowering cost
Learn more at www.optiv.com/IAM-Microsoft.

For the stories behind the headlines, head to CISOseries.com

View Details

Windows downloads blocked in Russia

The importance of receipts

Chrome extensions can be used for fingerprinting

Thanks to today's episode sponsor, Optiv

Modernizing your identity control plane from AD to the cloud is complex. Ralph Martino, who is leading the identity and access management (IAM) group for Optiv, discusses what challenges CISOs are facing in today’s ever-changing climate:
• Increasing security
• Decreasing risk
• Lowering cost
Learn more at www.optiv.com/IAM-Microsoft.

View Details

US DoJ announces shut down of Russian RSOCKS Botnet

Experts warn of a new eCh0raix ransomware campaign targeting QNAP NAS

Mixed results for Russia's aggressive Ukraine information war, experts say

Thanks to today's episode sponsor, Optiv

Modernizing your identity control plane from AD to the cloud is complex. Ralph Martino, who is leading the identity and access management (IAM) group for Optiv, discusses what challenges CISOs are facing in today’s ever-changing climate:
• Increasing security
• Decreasing risk
• Lowering cost
Learn more at www.optiv.com/IAM-Microsoft.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, Ariel Weintraub, CISO, MassMutual

Thanks to today’s episode sponsor, Datadog

Check out Datadog‘s on-demand fireside chat with CTO Cormac Brady. Over the course of his 20+ year career at Thomson Reuters, Cormac consistently built bridges between technical teams—and in the process helped teams achieve superior results and earned himself senior leadership positions. Watch now at datadoghq.com/ciso/

All links and the video of this episode can be found on CISO Series.com

View Details

House Armed Services chair calls national security software, systems 'too vulnerable'

Microsoft Office 365 AutoSave can assist cloud ransomware attacks

OMIGOD! There’s more to OMIGOD

Thanks to today’s episode sponsor, Datadog

Watch Datadog's on-demand webinar for a 30-minute discussion on driving DevSecOps best practices in the enterprise with CTO Cormac Brady.
Over the course of his 20+ year career at Thomson Reuters, Cormac consistently built bridges between technical teams—and in the process helped teams achieve superior results and earned himself senior leadership positions.
Cormac shares stories and leadership lessons that are applicable to any enterprise technical leader looking to help their firm build and operate services in an increasingly competitive and treacherous digital economy. Watch now at datadoghq.com/ciso/

For the stories behind the headlines, head to CISOseries.com.

View Details

Cloudflare repels another record DDoS

Africa’s largest supermarket chain hit with ransomware

Resurgence in travel not ignored by threat actors

Thanks to today’s episode sponsor, Datadog

Check out Datadog's on-demand fireside chat with CTO Cormac Brady. Over the course of his 20+ year career at Thomson Reuters, Cormac consistently built bridges between technical teams—and in the process helped teams achieve superior results and earned himself senior leadership positions. Watch now at datadoghq.com/ciso/

View Details

US defense contractor discusses takeover of NSO spyware

DoJ will no longer prosecute ethical hackers

Attack on Kaiser Permanente exposes data of thousands of customers

Thanks to today’s episode sponsor, Datadog

Watch Datadog's on-demand webinar for a 30-minute discussion on driving DevSecOps best practices in the enterprise with CTO Cormac Brady.
Over the course of his 20+ year career at Thomson Reuters, Cormac consistently built bridges between technical teams—and in the process helped teams achieve superior results and earned himself senior leadership positions.
Cormac shares stories and leadership lessons that are applicable to any enterprise technical leader looking to help their firm build and operate services in an increasingly competitive and treacherous digital economy. Watch now at datadoghq.com/ciso/

For the stories behind the headlines, head to CISOseries.com

View Details

Leaky continuous integration logs

Exchange servers used to deploy Black Cat

Bluetooth can be used to track phones

Thanks to today’s episode sponsor, Datadog

Check out Datadog's on-demand fireside chat with CTO Cormac Brady. Over the course of his 20+ year career at Thomson Reuters, Cormac consistently built bridges between technical teams—and in the process helped teams achieve superior results and earned himself senior leadership positions. Watch now at datadoghq.com/ciso/

View Details

Amazon’s chat app has a child sex abuse problem

Ransomware decryptors now for sale on gaming platform

China’s biggest online influencers go dark

Thanks to today’s episode sponsor, Datadog

Watch Datadog's on-demand webinar for a 30-minute discussion on driving DevSecOps best practices in the enterprise with CTO Cormac Brady.
Over the course of his 20+ year career at Thomson Reuters, Cormac consistently built bridges between technical teams—and in the process helped teams achieve superior results and earned himself senior leadership positions.
Cormac shares stories and leadership lessons that are applicable to any enterprise technical leader looking to help their firm build and operate services in an increasingly competitive and treacherous digital economy. Watch now at datadoghq.com/ciso/

For the stories behind the headlines, head to CISOseries.com

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, June 6-10, is hosted by Rich Stroffolino with our guest, Upendra Mardikar, CSO, Snap Finance

Thanks to our sponsor, PlexTrac *PlexTrac is the platform that empowers your offensive security team to spend more time hacking and less time reporting. Build better reports in half the time, centralize your data, maximize your reusable content, and become more efficient and effective. PlexTrac clients report a “5X ROI in 1 year,” a “30% increase in efficiency,” have “cut their reporting cycle by 65%,” and experienced a “18 to 22% time savings per engagement.”

Check out PlexTrac.com/CISOSeries to learn how PlexTrac can help your team deliver results.*

All links and the video of this episode can be found on CISO Series.com

View Details

MFA could be long haul for some federal agencies says CISA official

New Emotet variant stealing users' credit card information from Google Chrome

Symantec: More malware operators moving in to exploit Follina

Thanks to today’s episode sponsor, PlexTrac

*PlexTrac is the platform that empowers your offensive security team to spend more time hacking and less time reporting. Build better reports in half the time, centralize your data, maximize your reusable content, and become more efficient and effective. PlexTrac clients report a “5X ROI in 1 year,” a “30% increase in efficiency,” have “cut their reporting cycle by 65%,” and experienced a “18 to 22% time savings per engagement.” 

Check out PlexTrac.com/CISOSeries to learn how PlexTrac can help your team deliver results.*

For the stories behind the headlines, head to CISOseries.com.

View Details

Lack of reporting hurting the ransomware fight

CISA warns of China-linked network snooping

Personal information marketplace taken down

Thanks to today’s episode sponsor, PlexTrac

*PlexTrac is the platform that empowers your offensive security team to spend more time hacking and less time reporting. Build better reports in half the time, centralize your data, maximize your reusable content, and become more efficient and effective. PlexTrac clients report a “5X ROI in 1 year,” a “30% increase in efficiency,” have “cut their reporting cycle by 65%,” and experienced a “18 to 22% time savings per engagement.” 

Check out PlexTrac.com/CISOSeries to learn how PlexTrac can help your team deliver results.*

View Details

Passwords are finally dead

Hackers steal credit cards from online gun shops

Shields data breach affects 2 million patients

Thanks to today’s episode sponsor, PlexTrac

The best penetration tests begin and end with PlexTrac. PlexTrac can improve efficiency and effectiveness at every phase of your proactive assessments. By centralizing the data from all your automation tools, cataloging important reusable content for easy access, and promoting communication and visibility at every phase of an assessment, PlexTrac cuts reporting time in half and adds value between reports.
Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the premier pentest reporting and management platform.

For the stories behind the headlines, head to CISOseries.com

View Details

The once and future AlphaBay

Karakurt adopts bill collector tactics

China concludes its cybersecurity review of Didi

Thanks to today’s episode sponsor, PlexTrac

*PlexTrac is the platform that empowers your offensive security team to spend more time hacking and less time reporting. Build better reports in half the time, centralize your data, maximize your reusable content, and become more efficient and effective. PlexTrac clients report a “5X ROI in 1 year,” a “30% increase in efficiency,” have “cut their reporting cycle by 65%,” and experienced a “18 to 22% time savings per engagement.” 

Check out PlexTrac.com/CISOSeries to learn how PlexTrac can help your team deliver results.*

View Details

Evasive phishing mixes reverse tunnels and URL shortening services

Exploit released for Atlassian Confluence RCE bug, patch now

Lawmakers are racing to pass tech antitrust reforms before midterms

Thanks to today’s episode sponsor, PlexTrac

The best penetration tests begin and end with PlexTrac. PlexTrac can improve efficiency and effectiveness at every phase of your proactive assessments. By centralizing the data from all your automation tools, cataloging important reusable content for easy access, and promoting communication and visibility at every phase of an assessment, PlexTrac cuts reporting time in half and adds value between reports.
Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the premier pentest reporting and management platform.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, May 30-June 3, is hosted by Rich Stroffolino with our guest, Steve Zalewski, Co-host, Defense in Depth

Thanks to today’s episode sponsor, Feroot

All links and the video of this episode can be found on CISO Series.com

View Details

Leaked Conti chats confirm gang’s ability to conduct firmware-based attacks

Critical UNISOC chip vulnerability affects millions of Android smartphones

ExpressVPN removes servers in India after refusing to comply with government order

Thanks to today’s episode sponsor, Feroot

*Feroot secures client-side web applications so that businesses can deliver a flawless and safe digital user experience to their customers. Inspector and Pageguard, Feroot’s automated data protection solutions, increase code visibility, facilitate threat analysis, and detect and protect from dangerous client-side attacks, such as Magecart, cross-site scripting, e-skimming, and other threats focused on front-end JavaScript and web applications.

Learn more at www.feroot.com.*

For the stories behind the headlines, head to CISOseries.com.

View Details

Europol shuts down FluBot

Hive ransomware kicks Costa Rica when its down

CISA issues advisory on voting machine vulnerabilities

Thanks to today’s episode sponsor, Feroot

*Feroot secures client-side web applications so that businesses can deliver a flawless and safe digital user experience to their customers. Inspector and Pageguard, Feroot’s automated data protection solutions, increase code visibility, facilitate threat analysis, and detect and protect from dangerous client-side attacks, such as Magecart, cross-site scripting, e-skimming, and other threats focused on front-end JavaScript and web applications.

Learn more at www.feroot.com.*

View Details

Follina vulnerability under active exploitation

Tension inside Google over conduct of fired researcher

IBM to pay $1.6 billion for poaching customer account

Thanks to today’s episode sponsor, Feroot

*Feroot secures client-side web applications so that businesses can deliver a flawless and safe digital user experience to their customers. Inspector and Pageguard, Feroot’s automated data protection solutions, increase code visibility, facilitate threat analysis, and detect and protect from dangerous client-side attacks, such as Magecart, cross-site scripting, e-skimming, and other threats focused on front-end JavaScript and web applications.

Learn more at www.feroot.com.*

For the stories behind the headlines, head to CISOseries.com

View Details

China censoring open-source code

Follina zero-day hits Office

EnemyBot botnet acts fast

Thanks to today’s episode sponsor, Feroot

*Feroot secures client-side web applications so that businesses can deliver a flawless and safe digital user experience to their customers. Inspector and Pageguard, Feroot’s automated data protection solutions, increase code visibility, facilitate threat analysis, and detect and protect from dangerous client-side attacks, such as Magecart, cross-site scripting, e-skimming, and other threats focused on front-end JavaScript and web applications.

Learn more at www.feroot.com.*

View Details

Pro-Russian hacker group KillNet plans to attack Italy today

Microsoft warns that hackers are using more advanced techniques to steal credit card data

China makes offer to ten nations help to run their cyber-defenses

Thanks to today’s episode sponsor, Feroot

*Feroot secures client-side web applications so that businesses can deliver a flawless and safe digital user experience to their customers. Inspector and Pageguard, Feroot’s automated data protection solutions, increase code visibility, facilitate threat analysis, and detect and protect from dangerous client-side attacks, such as Magecart, cross-site scripting, e-skimming, and other threats focused on front-end JavaScript and web applications.

Learn more at www.feroot.com.*

For the stories behind the headlines, head to CISOseries.com.

View Details

Up to 83% of known compromised passwords would satisfy regulatory requirements

Broadcom confirms deal to acquire VMware

Experts warn of rise in ChromeLoader malware

Thanks to today’s episode sponsor, Optiv

Up for a Zero Trust Crash Course? Join our expert, Jerry Chapman, Engineering Fellow at Optiv and author of "Zero Trust Security: An Enterprise Guide," as he delivers the following takeaways:
- An introduction to Zero Trust
- An overview of Optiv’s Zero Trust principles
- How to visualize your Zero Trust journey and place it in the proper context
Catch Jerry's Zero Trust crash course or learn more by going to www.optiv.com/zerotrust.

For the stories behind the headlines, head to CISOseries.com.

View Details

Popular open source libraries leaked keys for “research”

DuckDuckGo gives Microsoft a pass on trackers

Microsoft weathers the vulnerability storm

Thanks to today’s episode sponsor, Optiv

Need a guide on your Zero Trust journey? Jerry Chapman, Engineering Fellow at Optiv and author of "Zero Trust Security: An Enterprise Guide" shares the following takeaways:
- The key elements of Zero Trust
- How to visualize your Zero Trust journey and place it in the proper context
- Integrated technologies to drive adaptive processes and a mature security model
Learn more at www.optiv.com/zerotrust.

View Details

Interpol warns nation-state malware could become a commodity on dark web soon

General Motors Hit by cyber-attack exposing car owners' personal info

Canada to ban China's Huawei and ZTE from its 5G networks

Thanks to today’s episode sponsor, Optiv

Up for a Zero Trust Crash Course? Join our expert, Jerry Chapman, Engineering Fellow at Optiv and author of "Zero Trust Security: An Enterprise Guide," as he delivers the following takeaways:
- An introduction to Zero Trust
- An overview of Optiv’s Zero Trust principles
- How to visualize your Zero Trust journey and place it in the proper context
Catch Jerry's Zero Trust crash course or learn more by going to www.optiv.com/zerotrust.

For the stories behind the headlines, head to CISOseries.com.

View Details

Cyberattack divorces Zola users from registries

A look at the RansomHouse data-extortion operation

Now we have to worry about pre-hijacking attacks

Thanks to today’s episode sponsor, Optiv

Need a guide on your Zero Trust journey? Jerry Chapman, Engineering Fellow at Optiv and author of "Zero Trust Security: An Enterprise Guide" shares the following takeaways:
- The key elements of Zero Trust
- How to visualize your Zero Trust journey and place it in the proper context
- Integrated technologies to drive adaptive processes and a mature security model
Learn more at
www.optiv.com/zerotrust.

For the stories behind the headlines, go to CISOseries.com

View Details

Ransomware victim trolls hackers with obscene pics

CISOs list top cyber threats to enterprises in 2022

YouTube removes more than 9,000 Ukraine war-related channels

Thanks to today’s episode sponsor, Optiv

Need a guide on your Zero Trust journey? Jerry Chapman, Engineering Fellow at Optiv and author of "Zero Trust Security: An Enterprise Guide" shares the following takeaways:
- The key elements of Zero Trust
- How to visualize your Zero Trust journey and place it in the proper context
- Integrated technologies to drive adaptive processes and a mature security model
Learn more at
www.optiv.com/zerotrust.

For the stories behind the headlines, go to CISOseries.com

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, May 16-20, is hosted by Rich Stroffolino with our guest, Jerich Beason, CISO, Commercial Bank, CapitalOne

Thanks to today's episode sponsor, Torq

All links and the video of this episode can be found on CISO Series.com

View Details

Greenland health services limited from cyberattacks

Phishing attacks surge in Q1

Google details 2021 zero-days

And now let’s thank today’s sponsor, Torq

Myth 5: You Should Automate All Security Processes
False. You should automate routine, repetitive tasks that are not subject to much conditional variance. But workflows that can’t be reliably managed by automation tools, such as assessing the financial consequences of a breach or determining whether a security incident should trigger an application rollback, should remain the domain of humans. To learn more about the realities of automation, head to torq.io.

View Details

VMware bugs abused to deliver Mirai malware

Microsoft to debut of zero trust GDAP tool

Bank of Zambia refuses to pay ransom to cyberattack group Hive

And now let’s thank today’s sponsor, Torq

Myth 4: Automation Will Replace Skilled Security Professionals
Not true. Any business that attempts to automate security will quickly find that most high-stakes security issues are far too complex to be detected and remediated by automation tools alone. Human security professionals need to take the lead delivering nuanced insight about the business impact of a large-scale breach. To learn more about the realities of automation, head to torq.io.

For the stories behind the headlines, head to CISOseries.com.

View Details

Buffalo massacre suspect signaled plans on Discord for months

Google faces litigation for unauthorised use of medical records

Venezuelan doctor accused of developing and distributing ransomware

And now let’s thank today’s sponsor, Torq

Myth 3: Only Enterprises Need Security Automation
Debunked. While enterprises with thousands of endpoints and sprawling teams certainly need automation, businesses of all sizes face challenges related to other forms of scale when it comes to security. For instance, there are about 1 billion known types of malware in existence, and they imperil businesses of all sizes equally. To learn more about the realities of automation, head to torq.io.

For the stories behind the headlines, head to CISOseries.com

View Details

Costa Rican ransomware rhetoric somehow gets uglier

DOJ files its first criminal cryptocurrency sanctions case

Trying to fix open source supply chain security

And now let’s thank today’s sponsor, Torq

Myth 2: Security Automation Is Just a New Term for Automated Security Testing
Wrong. While scanning and testing may be one example of a security automation use case, it’s hardly the only one. Automation can be used to do things like help manage complex security workflows and optimize collaboration between different stakeholders. These are tasks that were not traditionally automated. To learn more about the realities of automation, head to torq.io.

View Details

Ukraine CERT-UA warns of new attacks launched by Russia-linked Armageddon APT

Microsoft fixes new PetitPotam Windows NTLM relay attack vector

Hackers are exploiting critical bug in Zyxel firewalls and VPNs

And now let’s thank today’s sponsor, Torq

Myth 1: Automation Is Only a Reactive Part of SecOps
Incorrect. Proactive management of security incidents is just as important, like automatically scanning IaC configurations to detect vulnerabilities, automating collaboration between devs, IT ops and SecOps to prevent risks before they’re threats. To learn more about the realities of automation, head to torq.io.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, May 9-13, is hosted by Rich Stroffolino with our guest, Rich Lindberg, CISO, JAMS

Thanks to our sponsor, Datadog

Break down silos between DevOps and Security teams to enable collaboration and strengthen the security of your environment. In this on-demand webinar, hear from one of Datadog’s engineers on how teams can speed up investigations by assessing security and observability data using Datadog’s unified platform to reduce security threats by detecting vulnerabilities.
Watch the on-demand webinar now to learn how to get full-stack security for your production environment at datadoghq.com/ciso/

All links and the video of this episode can be found on CISO Series.com

View Details

Google will use mobile devices to thwart phishing attacks

CISA urges organizations to patch actively exploited F5 BIG-IP vulnerability

Kick China off social media, says tech governance expert

Thanks to our episode sponsor, Datadog

Break down silos between DevOps and Security teams to enable collaboration and strengthen the security of your environment. In this on-demand webinar, hear from one of Datadog’s engineers on how teams can speed up investigations by assessing security and observability data using Datadog’s unified platform to reduce security threats by detecting vulnerabilities.
Watch the on-demand webinar now to learn how to get full-stack security for your production environment at datadoghq.com/ciso/

For the stories behind the headlines, head to CISOseries.com.

View Details

Old botnets are new again

Meta withdraws Oversight Board guidance request

EU proposes new CSAM rules

Thanks to our episode sponsor, Datadog

In this on-demand webinar, you’ll learn how to best utilize the suite of Datadog Cloud Security products to identify the root cause of an attack and how a unified platform provides real-time threat-detection and continuous configuration audits across applications, hosts, containers and cloud infrastructure.
Built on top of the observability platform, Datadog brings unprecedented integration between security and devops aligned to shared organizational goals.
Watch the on-demand webinar now to learn how to get full-stack security for your production environment at datadoghq.com/ciso/

View Details

Russian TV hacked on Victory Day

US pledges to help Ukraine keep internet and lights running

Pentagon’s concerns China may prompt vetting startups

Thanks to our episode sponsor, Datadog

In this on-demand webinar, you’ll learn how to best utilize the suite of Datadog Cloud Security products to identify the root cause of an attack and how a unified platform provides real-time threat-detection and continuous configuration audits across applications, hosts, containers and cloud infrastructure.
Built on top of the observability platform, Datadog brings unprecedented integration between security and devops aligned to shared organizational goals.
Watch the on-demand webinar now to learn how to get full-stack security for your production environment at datadoghq.com/ciso/

View Details

Ransomware state of emergency in Costa Rica

Microsoft launches service to fill the cyber skills gap

College closes permanently due to ransomware

Thanks to our episode sponsor, Datadog

Break down silos between DevOps and Security teams to enable collaboration and strengthen the security of your environment. In this on-demand webinar, hear from one of Datadog’s engineers on how teams can speed up investigations by assessing security and observability data using Datadog’s unified platform to reduce security threats by detecting vulnerabilities.
Watch the on-demand webinar now to learn how to get full-stack security for your production environment at datadoghq.com/ciso/

View Details

Google Play now blocks paid app downloads, updates in Russia

NIST releases updated guidance for defending against supply-chain attacks

US State Department offering $10 million reward for information about Conti members

Thanks to our episode sponsor, Datadog

In this on-demand webinar, you’ll learn how to best utilize the suite of Datadog Cloud Security products to identify the root cause of an attack and how a unified platform provides real-time threat-detection and continuous configuration audits across applications, hosts, containers and cloud infrastructure.
Built on top of the observability platform, Datadog brings unprecedented integration between security and devops aligned to shared organizational goals.
Watch the on-demand webinar now to learn how to get full-stack security for your production environment at datadoghq.com/ciso/

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, May 2-6, is hosted by Rich Stroffolino with our guest, Shawn Bowen, CISO, World Fuel Services

Thanks to our episode sponsor, Censys

Why Censys? Our Attack Surface Management tool is designed from the ground up to seamlessly integrate with existing security workflows. It’s the only ASM tool that discovers modern cloud specific assets like storage buckets and our scanning platform finds more than 85% more services than our nearest competitor. Start with Censys at censys.io.

All links and the video of this episode can be found on CISO Series.com

View Details

Decade-old bugs discovered in Avast, AVG antivirus software

Thailand and Hong Kong Banks used most in BEC

Every ISP in the US must block these 3 pirate streaming services

Thanks to today's episode sponsor, Censys

Why Censys? Our Attack Surface Management tool is designed from the ground up to seamlessly integrate with existing security workflows. It’s the only ASM tool that discovers modern cloud specific assets like storage buckets and our scanning platform finds more than 85% more services than our nearest competitor. Start with Censys at censys.io.

For the stories behind the headlines, head to CISOseries.com.

View Details

CuckooBees campaign stings targets for years

Health and Human Services hammered over security

Docker images used to DDoS Russian sites

Thanks to today's episode sponsor, Censys

Censys’ Attack Surface Management tool discovers and inventories all Internet-facing assets including traditional assets like hosts, IPs, and cloud services like storage buckets across all accounts and networks. ASM gives you a continuous picture of your attack surface. Start with Censys at censys.io.

View Details

Google claims to have blocked billions of malicious app downloads

NortonLifeLock willfully infringed malware patents

Former eBay exec pleads guilty to cyber stalking

Thanks to today's episode sponsor, Censys

Tom the CTO can’t go into the boardroom unprepared. It’s his job to know all the risks to his company – especially the one that could land him on the front page of the newspaper. His best bet for survival is staying ahead of the most critical threats. Tom, you can be that source of truth; start with Censys at censys.io right now.

For the stories behind the headlines, head to CISOseries.com

View Details

Solana network goes dark after bot swarm

The spyware in Spain falls mostly on the politicians

Security isn’t top of mind for mental health apps

Thanks to today's episode sponsor, Censys

All Pat the Security Practitioner wants is to do a good job and be the frontline in keeping his company safe. He’s got great tools, but nothing that can show him if there are company assets that have somehow made their way onto the internet. If only Pat knew about Censys’ Attack Surface Management tool. Now you do – start with Censys at censys.io.

View Details

Top 15 exploited security vulnerabilities in 2021

India gives orgs 6 hours to report cyber incidents

The White House wants more powers to crack down on rogue drones

Thanks to today's episode sponsor, Censys

What Chris the CISO wants is to protect against revenue loss and damage to his company’s brand from data breaches and compliance failures. But he’s got a blind spot around his internet exposure. What assets are out there on the internet that his team doesn’t know about? Well, Chris, it’s simple – start with Censys at censys.io.

For the stories behind the headlines, visit CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines - Week in Review, Apr 25-29, is hosted by Rich Stroffolino with our guest, Hadas Cassorla, CISO, M1 Financial 

Thanks to our episode sponsor, Feroot

All links and the video of this episode can be found on CISO Series.com

View Details

Global security spending set to hit $198bn by 2025

New malware loader Bumblebee adopted by known ransomware access brokers

Cloudflare thwarts record DDoS attack

Thanks to today’s episode sponsor, Feroot

Feroot secures client-side web applications so that businesses can deliver a flawless and safe digital user experience to their customers.

Inspector and Pageguard, Feroot’s automated data protection solutions, increase code visibility, facilitate threat analysis, and detect and protect from dangerous client-side attacks, such as Magecart, cross-site scripting, e-skimming, and other threats focused on front-end JavaScript and web applications.

Learn more at www.feroot.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Russia experiences hacks at scale

State Department puts a price on NetPetya’s head

Two-thirds of organizations hit with ransomware

Thanks to today’s episode sponsor, Feroot

Feroot secures client-side web applications so that businesses can deliver a flawless and safe digital user experience to their customers.

Inspector and Pageguard, Feroot’s automated data protection solutions, increase code visibility, facilitate threat analysis, and detect and protect from dangerous client-side attacks, such as Magecart, cross-site scripting, e-skimming, and other threats focused on front-end JavaScript and web applications.

Learn more at www.feroot.com.

View Details

Elon Musk’s Twitter takeover could be bad for security and privacy

Stormous Ransomware targets Coca Cola

US offers $10 million reward for help locating Russian hackers

Thanks to today’s episode sponsor, Feroot

Feroot secures client-side web applications so that businesses can deliver a flawless and safe digital user experience to their customers.

Inspector and Pageguard, Feroot’s automated data protection solutions, increase code visibility, facilitate threat analysis, and detect and protect from dangerous client-side attacks, such as Magecart, cross-site scripting, e-skimming, and other threats focused on front-end JavaScript and web applications.

Learn more at www.feroot.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Mandiant finds record zero-days in 2021

Bored Ape Yacht Club hacked

Oracle patches critical Java vulnerability

Thanks to today’s episode sponsor, Feroot

 *Feroot secures client-side web applications so that businesses can deliver a flawless and safe digital user experience to their customers.*

Inspector and Pageguard, Feroot’s automated data protection solutions, increase code visibility, facilitate threat analysis, and detect and protect from dangerous client-side attacks, such as Magecart, cross-site scripting, e-skimming, and other threats focused on front-end JavaScript and web applications.

Learn more at www.feroot.com.

View Details

Hackers find 122 vulnerabilities, 27 deemed critical, during first round of DHS bug bounty program

Anonymous has leaked 5.8 TB of Russian data since declaring cyber war

AWS's Log4j patches blew holes in its own security

Thanks to today’s episode sponsor, Feroot

Feroot secures client-side web applications so that businesses can deliver a flawless and safe digital user experience to their customers.

Inspector and Pageguard, Feroot’s automated data protection solutions, increase code visibility, facilitate threat analysis, and detect and protect from dangerous client-side attacks, such as Magecart, cross-site scripting, e-skimming, and other threats focused on front-end JavaScript and web applications.

Learn more at www.feroot.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Critical chipset bugs open millions of Android devices to remote spying

New Five Eyes alert warns of Russian threats targeting critical infrastructure

Machine-learning models vulnerable to undetectable backdoors

And here’s a word from our sponsor, Votiro

Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Okta reports on Lapsus$ breach

Popular VPNs use risky certificates

Project Zero disclosed a new vulnerability record

And here’s a word from our sponsor, Votiro

Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.

View Details

LinkedIn is now the most popular phish bait

Lenovo patches firmware vulnerabilities impacting millions of users

Ukraine war stokes internet connectivity concerns in Taiwan

And here’s a word from our sponsor, Votiro

Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.

For the stories behind the headlines, head to CISOseries.com

View Details

Catalan leaders targeted by NSO spyware

Researchers share a deep dive into PYSA ransomware operations

Most security teams feeling the talent shortage

And here’s a word from our sponsor, Votiro

Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.

View Details

Microsoft: Office 2013 will reach end of support in April 2023

Stolen OAuth tokens used to download data from dozens of organizations, GitHub warns

Mute button in conferencing apps may not actually mute your mic

And here’s a word from our sponsor, Votiro

Can you trust that your content and data is free of malware and ransomware? With Votiro you can. Votiro removes evasive and unknown malware from content in milliseconds, without impacting file fidelity or usability. It even works on password-protected and zipped files. Plus, it’s an API, so it integrates with everything – including Microsoft 365. Learn more at Votiro.com.

For the stories behind the headlines, head to CISOseries.com.

View Details

Data breach disclosures surge 14% in Q1 2022

Windows 11 tool to add Google Play secretly installed malware

DHS investigators say they foiled cyberattack on undersea internet cable in Hawaii

Thanks to our episode sponsor, Code42

Have you been thinking about launching an Insider Risk Management program? You don’t need to be Big Brother to effectively address Insider Risk. 

Code42 believes that the Three Ts should define any IRM program: transparency, training, and technology. Shift your security culture from “watchdog” to “guide dog” and everyone wins. Learn more at Code42.com/showme.

For the stories behind the headlines, head to CISOseries.com.

View Details

Industrial cybersecurity companies form coalition

Microsoft disrupts ZLoader

T-Mobile hired someone to get their data back

Thanks to our episode sponsor, Code42

It’s not just about the data leaving your company - what about the data coming in? Along with departing employees, new talent is also actively joining your organization. This poses cybersecurity challenges since they could be knowingly or unknowingly bringing data from their former company into your network.

Code42 Incydr is an Insider Risk Management SaaS that provides a comprehensive understanding of your data exposure and shows which activities require security intervention. Learn more at Code42.com/showme.

View Details

RaidForums hacker marketplace shut down in cross-border law enforcement operation

Sandworm hackers fail to take down Ukrainian energy provider

CISA warns of Russian state hackers exploiting WatchGuard bug

Thanks to our episode sponsor, Code42

Surprise! Surprise! Five years from now, Jamie, who’s resigning today, will ring the NASDAQ bell officially launching her company on the public market. And what you’ll soon realize is that Jamie stole your most valuable data to start her new company. Learn how Code42 Incydr can stop data theft and protect your organizations’ most valuable assets. Visit Code42.com/showme to learn more.

For the stories behind the headlines, head to CISOseries.com.

View Details

NSO Group spyware reportedly used against European Commission

The malware is coming from inside the phone

OpenSSH gets ready for quantum computing

Thanks to our episode sponsor, Code42

Cybersecurity teams are facing unprecedented challenges when it comes to protecting sensitive corporate data from exposure, leak and theft.

In fact, the Code42 Annual Data Exposure Report revealed there’s a 1 in 3 chance that your company will lose IP when an employee quits. To learn more about stopping data leaks with Insider Risk Management visit Code42.com/showme.

View Details

New Meta information stealer distributed in malspam campaign

NB65 group targets Russia with a modified version of Conti’s ransomware

Elon Musk unveils vision for Twitter after joining board

Thanks to our episode sponsor, Code42

Have you been thinking about launching an Insider Risk Management program? You don’t need to be Big Brother to effectively address Insider Risk.

Code42 believes that the Three Ts should define any IRM program: transparency, training, and technology. Shift your security culture from “watchdog” to “guide dog” and everyone wins. Learn more at Code42.com/showme.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, Apr 4-8, is hosted by Rich Stroffolino with our guest, Brett Conlon, CISO, American Century Investments

Thanks to our sponsor, Code42

*It’s not just about the data leaving your company – what about the data coming in? Along with departing employees, new talent is also actively joining your organization. This poses cybersecurity challenges since they could be knowingly or unknowingly bringing data from their former company into your network.

Code42 Incydr is an Insider Risk Management SaaS that provides a comprehensive understanding of your data exposure and shows which activities require security intervention. Learn more at Code42.com/showme.*

View Details

Newly discovered flaw could allow hacking of Samsung Android devices

Adobe Creative Cloud Experience makes malware easier to hide

Parrot redirect service infects 16,500 sites to push malware

Thanks to our episode sponsor, Code42

*It’s not just about the data leaving your company - what about the data coming in? Along with departing employees, new talent is also actively joining your organization. This poses cybersecurity challenges since they could be knowingly or unknowingly bringing data from their former company into your network.

Code42 Incydr is an Insider Risk Management SaaS that provides a comprehensive understanding of your data exposure and shows which activities require security intervention. Learn more at Code42.com/showme.*

For the stories behind the headlines, head to CISOseries.com.

View Details

US disrupted Russian botnet

Twitter shadowbans Russian government accounts

DOJ charges Russian national with operating Hydra

Thanks to our episode sponsor, Code42

Surprise! Surprise! Five years from now, Jamie, who’s resigning today, will ring the NASDAQ bell officially launching her company on the public market. And what you’ll soon realize is that Jamie stole your most valuable data to start her new company. Learn how Code42 Incydr can stop data theft and protect your organizations’ most valuable assets. Visit Code42.com/showme to learn more.

View Details

Germany takes down world's largest darknet market

Anonymous leaks personal details of Russian soldiers

CISA adds Spring4Shell to list of exploited vulnerabilities

Thanks to our episode sponsor, Code42

Cybersecurity teams are facing unprecedented challenges when it comes to protecting sensitive corporate data from exposure, leak and theft.

In fact, the Code42 Annual Data Exposure Report revealed there’s a 1 in 3 chance that your company will lose IP when an employee quits. To learn more about stopping data leaks with Insider Risk Management visit Code42.com/showme.

For the stories behind the headlines, visit CISOseries.com

View Details

Russian secret police exposed in data leak

MailChimp hit with breach

The Bureau of Cyberspace and Digital Policy goes live

Thanks to our episode sponsor, Code42

Have you been thinking about launching an Insider Risk Management program? You don’t need to be Big Brother to effectively address Insider Risk. 

Code42 believes that the Three Ts should define any IRM program: transparency, training, and technology. Shift your security culture from “watchdog” to “guide dog” and everyone wins. Learn more at Code42.com/showme.

View Details

New Borat remote access malware is no laughing matter

Apple rushes out patches for 0-days in MacOS, iOS

National Security Agency employee indicted for 'leaking top secret info'

Thanks to our episode sponsor, Code42

*It’s not just about the data leaving your company - what about the data coming in? Along with departing employees, new talent is also actively joining your organization. This poses cybersecurity challenges since they could be knowingly or unknowingly bringing data from their former company into your network.

Code42 Incydr is an Insider Risk Management SaaS that provides a comprehensive understanding of your data exposure and shows which activities require security intervention. Learn more at Code42.com/showme.*

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, Mar 28-Apr 1, is hosted by Rich Stroffolino with our guest, Fredrick Lee, CISO, Gusto

Thanks to our episode sponsor, Varonis

All links and the video of this episode can be found on CISO Series.com

View Details

Palo Alto Networks error exposed customer support cases, attachments

New AcidRain data wiper malware targets modems and routers

Remote code execution flaws in Spring and Spring Cloud frameworks put Java apps at risk

Thanks to our episode sponsors, Varonis

Varonis will help you get meaningful data security results faster than you thought possible. Protect sensitive data, detect sophisticated threats, and streamline privacy and compliance. Visit www.varonis.com/cisoseries for a demo of Varonis’ leading data security platform.

For the stories behind the headlines, head to CISOseries.com.

View Details

Hackers abusing the power of subpoena

Lapsus$ claims hack of Globant

Brian Krebs sued by Ubiquiti for defamation

Thanks to our episode sponsors, Varonis

The first time we got hit with ransomware it took us weeks to recover. The second time we got hit, it took us two hours. Why? Because we had Varonis. Varonis reduces the ransomware blast radius and monitors our most important data, automatically. Hear more at www.varonis.com/cisoseries.

View Details

Ukraine destroys panic-spreading bot farms

Yandex is sending iOS user data to Russia

Ronin Network victimized in record-breaking crypto heist

Thanks to our episode sponsors, Varonis

Varonis will help you get meaningful data security results faster than you thought possible. Protect sensitive data, detect sophisticated threats, and streamline privacy and compliance. Visit www.varonis.com/cisoseries for a demo of Varonis’ leading data security platform.

For the stories behind the headlines, visit CISOseries.com.

View Details

Ukraine ISP taken down by cyber attack

Windows can now block drivers

Deepfakes take a turn for the banal

Thanks to our episode sponsors, Varonis

What is your ransomware blast radius? The average user can access 17 million files. Varonis reduces your blast radius in days, not years. Combined with advanced detection that monitors every file touch, ransomware doesn’t stand a chance. Learn more at www.varonis.com/cisoseries.

View Details

Critical Sophos Firewall vulnerability allows remote code execution

Okta: "We made a mistake" delaying the Lapsus$ hack disclosure

CISA adds 66 new flaws to the Known Exploited Vulnerabilities Catalog

Thanks to our episode sponsors, Varonis

On average, an employee can access 17 million files on day one. Varonis will show you where critical data is vulnerable, detect anomalies, and automatically right-size privileges to get you to “Zero Trust.” Their data security platform can test your ransomware readiness and show you where you stack up. Learn more at www.varonis.com/cisoseries.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, Mar 21-25, is hosted by Rich Stroffolino with our guest, John Prokap, CISO, Success Academy Charter Schools

Thanks to our episode sponsor, Varonis

Customer: "The first time we got hit with ransomware it took us weeks to recover. The second time we got hit, it took us two hours. Why? Because we had Varonis. Varonis reduces the ransomware blast radius and monitors our most important data, automatically." Hear more at www.varonis.com/cisoseries.

All links and the video of this episode can be found on CISO Series.com

View Details

UK police arrest 7 people in connection with Lapsus$

North Korean hackers exploit Chrome zero-day weeks before patch

Anonymous claims to have hacked the Central Bank of Russia

Thanks to our episode sponsor, Varonis

The first time we got hit with ransomware it took us weeks to recover. The second time we got hit, it took us two hours. Why? Because we had Varonis. Varonis reduces the ransomware blast radius and monitors our most important data, automatically. Hear more at www.varonis.com/cisoseries.

For the stories behind the headlines, head to CISOseries.com.

View Details

Microsoft expands program to fill cyber skills gap

Cyber Crime Losses Up 64% in 2021

Microsoft confirms Lapsus$ breach

Thanks to our episode sponsor, Varonis

What is your ransomware blast radius? The average employee can access 17 million files they don’t need, and only a handful live on their laptop. Protect your data from the inside out and detect early signs of ransomware – automatically with Varonis. Visit www.varonis.com/cisoseries.

View Details

Ransomware attack on Okta leads to data breach

Lapsus$ leaks 37GB of Microsoft source code

Anonymous hacks Nestlè for operating in Russia

Thanks to our episode sponsor, Varonis

Varonis will help you get meaningful data security results faster than you thought possible. Protect sensitive data, detect sophisticated threats, and streamline privacy and compliance. Visit www.varonis.com/cisoseries for a demo of Varonis’ leading data security platform.

For the stories behind the headlines, visit CISOseries.com

View Details

Ransomware puts the breaks on Bridgestone

Phishing with browser-in-a-browser attacks

Conti Leaks leaks Conti code

Thanks to our episode sponsor, Varonis

What is your ransomware blast radius? The average user can access 17 million files. Varonis reduces your blast radius in days, not years. Combined with advanced detection that monitors every file touch, ransomware doesn’t stand a chance. Learn more at www.varonis.com/cisoseries.

View Details

CISA, FBI tell satellite communications network owners to watch out for hacks after Ukraine attack

Hackers claim to breach TransUnion South Africa with 'Password' password

Developer sabotages own npm module prompting open-source supply chain security questions

Thanks to our episode sponsor, Varonis

On average, an employee can access 17 million files on day one. Varonis will show you where critical data is vulnerable, detect anomalies, and automatically right-size privileges to get you to “Zero Trust.” Their data security platform can test your ransomware readiness and show you where you stack up. Learn more at www.varonis.com/cisoseries.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, Mar 14-18, is hosted by David Spark with our guest, Eric Hussey, CISO, Aptiv

Thanks to our episode sponsor, Varonis

The first time we got hit with ransomware it took us weeks to recover. The second time we got hit, it took us two hours. Why? Because we had Varonis. Varonis reduces the ransomware blast radius and monitors our most important data, automatically. Hear more at www.varonis.com/cisoseries.

All links and the video of this episode can be found on CISO Series.com

View Details

Thanks to our episode sponsor, Varonis

The first time we got hit with ransomware it took us weeks to recover. The second time we got hit, it took us two hours. Why? Because we had Varonis. Varonis reduces the ransomware blast radius and monitors our most important data, automatically. Hear more at www.varonis.com/cisoseries.

View Details

Phony Instagram ‘support staff’ emails hit insurance company

Facebook hit with $18.6 million GDPR fine over 12 data breaches in 2018

Microsoft Defender tags Office updates as ransomware activity

Thanks to our episode sponsor, Varonis

What is your ransomware blast radius? The average employee can access 17 million files they don’t need, and only a handful live on their laptop. Protect your data from the inside out and detect early signs of ransomware – automatically with Varonis. Visit www.varonis.com/cisoseries.

For the stories behind the headlines, head to CISOseries.com.

View Details

More destructive wiper malware strikes Ukraine

German security agency recommends replacing Kaspersky antivirus

HackerOne apologizes to Ukrainian hackers for blocking payouts

Thanks to our episode sponsor, Varonis

Varonis will help you get meaningful data security results faster than you thought possible. Protect sensitive data, detect sophisticated threats, and streamline privacy and compliance. Visit www.varonis.com/cisoseries for a demo of Varonis’ leading data security platform.

For the stories behind the headlines, visit CISOseries.com

View Details

Ukraine’s IT army hit with malware

Mobile endpoints see a lot of malicious apps

AMD vulnerable to Spectre v2

Thanks to our episode sponsor, Varonis

What is your ransomware blast radius? The average user can access 17 million files. Varonis reduces your blast radius in days, not years. Combined with advanced detection that monitors every file touch, ransomware doesn’t stand a chance. Learn more at www.varonis.com/cisoseries.

View Details

Ubisoft changes employee passwords after “cyber security incident”

Cyber Command chief tells Congress chip shortage has national security implications

LockBit claims hack on Bridgestone tires

Thanks to our episode sponsor, Varonis

On average, an employee can access 17 million files on day one. Varonis will show you where critical data is vulnerable, detect anomalies, and automatically right-size privileges to get you to “Zero Trust.” Their data security platform can test your ransomware readiness and show you where you stack up. Learn more at www.varonis.com/cisoseries.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, Mar 7 – 11, is hosted by Rich Stroffolino with our guest, Anshu Gupta, Investor, Silicon Valley CISO Investments

Thanks to our sponsor, Torq

Security Automation Myth 5: You Should Automate All Security Processes
False. You should automate routine, repetitive tasks that are not subject to much conditional variance. But workflows that can’t be reliably managed by automation tools, such as assessing the financial consequences of a breach or determining whether a security incident should trigger an application rollback, should remain the domain of humans. To learn more about the realities of automation, head to torq.io.

All links and the video of this episode can be found on CISO Series.com

View Details

Russia creates its own TLS certificate authority to bypass sanctions

Online sleuths are using face recognition to ID Russian soldiers

Basic text-color trick can fool phishing filters

There are many misconceptions about security automation, so today's episode sponsor Torq is debunking a security automation myth each day this week.

Myth 5: You Should Automate All Security Processes
False. You should automate routine, repetitive tasks that are not subject to much conditional variance. But workflows that can’t be reliably managed by automation tools, such as assessing the financial consequences of a breach or determining whether a security incident should trigger an application rollback, should remain the domain of humans. To learn more about the realities of automation, head to torq.io.

For the stories behind the headlines, head to CISOseries.com.

View Details

Chipmakers warn of new speculative execution bugs

US worked to shore up Ukraine’s cyber defense in 2021

Twitter Tor service launches

There are many misconceptions about security automation, so today's episode sponsor Torq is debunking a security automation myth each day this week.

Myth 4: Automation Will Replace Skilled Security Professionals
Not true. Any business that attempts to automate security will quickly find that most high-stakes security issues are far too complex to be detected and remediated by automation tools alone. Human security professionals need to take the lead delivering nuanced insight about the business impact of a large-scale breach. To learn more about the realities of automation, head to torq.io.

View Details

Google to purchase cybersecurity firm Mandiant for $5.4 billion

Security vendors help infrastructure orgs protect against Russian cyberattacks

Russian VPN demand soars amidst social media crackdown

There are many misconceptions about security automation, so today's episode sponsor Torq is debunking a security automation myth each day this week.

Myth 3: Only Enterprises Need Security Automation
Debunked. While enterprises with thousands of endpoints and sprawling teams certainly need automation, businesses of all sizes face challenges related to other forms of scale when it comes to security. For instance, there are about 1 billion known types of malware in existence, and they imperil businesses of all sizes equally. To learn more about the realities of automation, head to torq.io.

For the stories behind the headlines, head over to CISOseries.com

View Details

Leaked Nvidia data used in malware

Russia says it's okay to download a car

Sharkbot takes a bite out of the Play Store

There are many misconceptions about security automation, so today's episode sponsor Torq is debunking a security automation myth each day this week.

Myth 2: Security Automation Is Just a New Term for Automated Security Testing
Wrong. While scanning and testing may be one example of a security automation use case, it’s hardly the only one. Automation can be used to do things like help manage complex security workflows and optimize collaboration between different stakeholders. These are tasks that were not traditionally automated. To learn more about the realities of automation, head to torq.io.

View Details

Charities and NGOs that provide support to Ukraine hit by malware

'Most advanced' China-linked backdoor ever raises alarms for cyber-espionage investigators

Hackers allegedly leak Samsung data, source code

There are many misconceptions about security automation, so today's episode sponsor Torq is debunking a security automation myth each day this week.

Myth 1: Automation Is Only a Reactive Part of SecOps
Incorrect. Proactive management of security incidents is just as important, like automatically scanning IaC configurations to detect vulnerabilities, automating collaboration between devs, IT ops and SecOps to prevent risks before they’re threats. To learn more about the realities of automation, head to torq.io.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, Feb 28-Mar 4, is hosted by Rich Stroffolino with our guest, Ody Lupescu, CISO, Ethos Life

Thanks to our episode sponsor, Torq

There are many misconceptions about security automation, so Torq is debunking a security automation myth each day this week.

Myth 5: You Should Automate All Security Processes
False. You should automate routine, repetitive tasks that are not subject to much conditional variance. But workflows that can’t be reliably managed by automation tools, such as assessing the financial consequences of a breach or determining whether a security incident should trigger an application rollback, should remain the domain of humans. To learn more about the realities of automation, head to torq.io.

All links and the video of this episode can be found on CISO Series.com

View Details

Cyberattack attempts on Ukraine surge tenfold

Ukraine's “IT army” targets Belarus railway network, Russian GPS

Eight-character passwords can be cracked in less than 60 minutes

There are many misconceptions about security automation, so Torq is debunking a security automation myth each day this week.

Myth 5: You Should Automate All Security Processes
False. You should automate routine, repetitive tasks that are not subject to much conditional variance. But workflows that can’t be reliably managed by automation tools, such as assessing the financial consequences of a breach or determining whether a security incident should trigger an application rollback, should remain the domain of humans. To learn more about the realities of automation, head to torq.io.

For the stories behind the headlines, head to CISOseries.com.

View Details

Conti and Trickbot code leaks

API attacks surge in 2021

Log4Shell still being used in the wild

There are many misconceptions about security automation, so Torq is debunking a security automation myth each day this week.

Myth 4: Automation Will Replace Skilled Security Professionals
Not true. Any business that attempts to automate security will quickly find that most high-stakes security issues are far too complex to be detected and remediated by automation tools alone. Human security professionals need to take the lead delivering nuanced insight about the business impact of a large-scale breach. To learn more about the realities of automation, head to torq.io.

View Details

Russia-Ukraine War update

Nvidia confirms company data was stolen in hack

Half of employees use unauthorized file services at work

There are many misconceptions about security automation, so Torq is debunking a security automation myth each day this week.

Myth 3: Only Enterprises Need Security Automation
Debunked. While enterprises with thousands of endpoints and sprawling teams certainly need automation, businesses of all sizes face challenges related to other forms of scale when it comes to security. For instance, there are about 1 billion known types of malware in existence, and they imperil businesses of all sizes equally. To learn more about the realities of automation, head to torq.io.

For the stories behind the headlines, go to cisoseries.com

View Details

Toyota suspends Japanese production due to cyberattack

Microsoft providing threat intelligence to Ukraine

Twitter to label tweets from state-owned media

There are many misconceptions about security automation, so Torq is debunking a security automation myth each day this week.

Myth 2: Security Automation Is Just a New Term for Automated Security Testing
Wrong. While scanning and testing may be one example of a security automation use case, it’s hardly the only one. Automation can be used to do things like help manage complex security workflows and optimize collaboration between different stakeholders. These are tasks that were not traditionally automated. To learn more about the realities of automation, head to torq.io.

View Details

Ukraine recruits volunteer IT army to hack list of Russian entities

Russia demands Google restore access to its media YouTube channels in Ukraine

Chipmaker giant Nvidia hit by ransomware attack

There are many misconceptions about security automation, so Torq is debunking a security automation myth each day this week.

Myth 1: Automation Is Only a Reactive Part of SecOps
Incorrect. Proactive management of security incidents is just as important, like automatically scanning IaC configurations to detect vulnerabilities, automating collaboration between devs, IT ops and SecOps to prevent risks before they’re threats. To learn more about the realities of automation, head to torq.io.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, Feb 21-25, is hosted by Rich Stroffolino with our guest, Mark Eggleston, CISO, CSC

Thanks to our episode sponsor, Tines

Tines is hosting a virtual game show in conjunction with Lacework on March 8. It’s free to attend, with security trivia, fun prizes, and donations going to good causes like Women in Cybersecurity. Places are limited, so head over to tines.com/gameshow to register.

All links and the video of this episode can be found on CISO Series.com

View Details

Cyberattacks accompany Russian military assault on Ukraine

Putin's government warns Russian critical infrastructure of potential cyberattacks

Manufacturing was the top industry targeted by ransomware last year

Thanks to our episode sponsor, Tines

Tines is hosting a virtual game show in conjunction with Lacework on March 8. It's free to attend, with security trivia, fun prizes, and donations going to good causes like Women in Cybersecurity. Places are limited, so head over to tines.com/gameshow to register.

For the stories behind the headlines, head to CISOseries.com.

View Details

Samsung shipped devices with flawed encryption

New York state gets cybersecurity center

Microsoft Defender adds support for GCP

Thanks to our episode sponsor, Tines

Tines is hosting a virtual game show in conjunction with Lacework on March 8. It's free to attend, with security trivia, fun prizes, and donations going to good causes like Women in Cybersecurity. Places are limited, so head over to tines.com/gameshow to register.

View Details

IRS is allowing taxpayers to opt out of facial recognition

UK Defence Secretary warns Russia of cyber-retaliation

Slack confirms outage for some users

Thanks to our episode sponsor, Tines

Tines is hosting a virtual game show in conjunction with Lacework on March 8. It's free to attend, with security trivia, fun prizes, and donations going to good causes like Women in Cybersecurity. Places are limited, so head over to tines.com/gameshow to register.

For the stories behind the headlines, head to cisoseries.com

View Details

Researches find decryption for Hive ransomware

In the Google Play Store, no one can hear you scream

Linux leads in patching speeds

Thanks to our episode sponsor, Tines

Tines is hosting a virtual game show in conjunction with Lacework on March 8. It's free to attend, with security trivia, fun prizes, and donations going to good causes like Women in Cybersecurity. Places are limited, so head over to tines.com/gameshow to register.

View Details

White House attributes Ukraine DDoS incidents to Russia's GRU

Master key for Hive ransomware retrieved using a flaw in its encryption algorithm

New phishing campaign targets Monzo online-banking customers

Thanks to our episode sponsor, Tines

Tines is hosting a virtual game show in conjunction with Lacework on March 8. It's free to attend, with security trivia, fun prizes, and donations going to good causes like Women in Cybersecurity. Places are limited, so head over to tines.com/gameshow to register.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, Feb 14-18, is hosted by Rich Stroffolino with our guest, Mike Hanley, CSO, GitHub

Thanks to our episode sponsor, PlexTrac

*PlexTrac is the Purple Teaming Platform. Use the Runbooks Module to facilitate your tabletop exercises, red team engagements, breach and attack simulations, and pentest automation to improve communication and collaboration. PlexTrac upgrades your program’s capabilities by making the most of every team member and tool. 

Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the perfect platform for CISOs!*

All links and the video of this episode can be found on CISO Series.com

View Details

DOJ beefs up efforts to combat criminal use of cryptocurrencies

Canada's major banks go offline in mysterious hours-long outage

Hackers slip into Microsoft Teams chats to distribute malware

Thanks to our episode sponsor, PlexTrac

*PlexTrac is the Purple Teaming Platform. Use the Runbooks Module to facilitate your tabletop exercises, red team engagements, breach and attack simulations, and pentest automation to improve communication and collaboration. PlexTrac upgrades your program’s capabilities by making the most of every team member and tool. 

Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the perfect platform for CISOs!*

For the stories behind the headlines, head to CISOseries.com.

View Details

State-sponsored hackers hits defense contractors

Unskilled hacker targeted aviation industry for years

Privacy Sandbox heading to Android

Thanks to our episode sponsor, PlexTrac

*Solve your talent shortage with PlexTrac. Use PlexTrac to automate security tasks and workflows to keep your red, blue, and purple teams focused on the real security work. Gain precious time back in your team’s day and improve their morale by making them more effective with PlexTrac.

Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the perfect platform for CISOs!*

View Details

Cyberattacks take down Ukrainian military and bank websites

Super Bowl ad shines a light on QR code risks

CISA directs agencies to patch actively exploited Chrome and Magento bugs

Thanks to our episode sponsor, PlexTrac

*PlexTrac is the solution to deal with your data. Aggregate findings from all assessments to produce the analytics needed to make informed decisions. Produce data visualizations and add them to reports with one click to communicate effectively to leadership. PlexTrac is the premier product for security data management. 

Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the perfect platform for CISOs!*

For the stories behind the headlines, visit cisoseries.com

View Details

FTC warns VoIP providers about robocalls

SEC outlines new cybersecurity rules for investment firms

Rampant plagiarism hits NFT marketplace

Thanks to our episode sponsor, PlexTrac

*Gain a real-time view of security posture with PlexTrac by consolidating scanner findings, assessments, and bug bounty tools. Visualize your posture in the Analytics Module to quickly assess and prioritize, creating a more effective workflow. Map risks to the MITRE ATT&CK framework to create a living risk register.

Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the perfect platform for CISOs!*

View Details

San Francisco 49ers hit by Blackbyte ransomware attack

Linux malware attacks are on the rise, and businesses aren't ready for it

Fake Windows 11 upgrade installers deliver RedLine malware

Thanks to our episode sponsor, PlexTrac

*PlexTrac is a powerful, yet simple, cybersecurity platform that centralizes all security assessments, pentest reports, audit findings, and vulnerabilities. PlexTrac transforms the risk management lifecycle, allowing security professionals to generate better reports faster, aggregate and visualize analytics, and collaborate on remediation in real-time.

Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the perfect platform for CISOs!*

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, Feb 7-11, is hosted by Rich Stroffolino with our guest, Dave Stirling, CISO, Zions Bancorporation

Thanks to our episode sponsor, Datadog

*Datadog Security Monitoring is part of the Datadog Cloud Security Platform, which protects an organization’s production environment and provides threat detection, posture management, workload security, and application security in a single pane of glass.

In this Datadog Security Monitoring product brief, you’ll learn how to:
Solve cloud complexity challenges with threat detection tools, detect and analyze security threats anywhere in your stack, and deploy turnkey detection rules mapped to the MITRE ATT&CK framework. Download the brief today to learn more at datadoghq.com/ciso/*

All links and the video of this episode can be found on CISO Series.com

View Details

Donation site for Ottawa truckers’ “Freedom Convoy” protest exposed donors’ data

FritzFrog botnet returns to attack healthcare, education, government sectors

If you use Zoom on a Mac, you might want to check your microphone settings

Thanks to our episode sponsor, Datadog

*Datadog Security Monitoring is part of the Datadog Cloud Security Platform, which protects an organization’s production environment and provides threat detection, posture management, workload security, and application security in a single pane of glass.

In this Datadog Security Monitoring product brief, you’ll learn how to:
Solve cloud complexity challenges with threat detection tools, detect and analyze security threats anywhere in your stack, and deploy turnkey detection rules mapped to the MITRE ATT&CK framework. Download the brief today to learn more at datadoghq.com/ciso/*

For the stories behind the headlines, head to CISOseries.com.

View Details

Ukraine takes down social media bot farm

Federal use of cell siphoning tech on the rise

Microsoft expands security business

Thanks to our episode sponsor, Datadog

*Datadog’s Cloud Security Platform delivers real-time threat detection and continuous configuration audits across your entire production environment, so you can bring speed and scale to your security organization. The Cloud Security Platform is built on top of Datadog’s observability platform, which breaks down silos between Security and DevOps teams and aligns them to shared organizational goals.

To learn more about how Datadog Security Monitoring can solve cloud complexity challenges with a unified platform, download the product brief at datadoghq.com/ciso/*

View Details

DOJ arrests New York couple, seizing $3.6 billion in bitcoin

Google sees 50% drop in compromises after 2SV enrollment

Puma employee data stolen as a result of Kronos attack

Thanks to our episode sponsor, Datadog

*Datadog Security Monitoring is part of the Datadog Cloud Security Platform, which protects an organization’s production environment and provides threat detection, posture management, workload security, and application security in a single pane of glass.

In this Datadog Security Monitoring product brief, you’ll learn how to:
Solve cloud complexity challenges with threat detection tools, detect and analyze security threats anywhere in your stack, and deploy turnkey detection rules mapped to the MITRE ATT&CK framework. Download the brief today to learn more at datadoghq.com/ciso/*

For the stories behind the headlines, head to cisoseries.com

View Details

Stolen crypto used to fund North Korean missile program

Microsoft disables protocol used by malware

Meta may pull out of the EU

Thanks to our episode sponsor, Datadog

*Datadog’s Cloud Security Platform delivers real-time threat detection and continuous configuration audits across your entire production environment, so you can bring speed and scale to your security organization. The Cloud Security Platform is built on top of Datadog’s observability platform, which breaks down silos between Security and DevOps teams and aligns them to shared organizational goals.

To learn more about how Datadog Security Monitoring can solve cloud complexity challenges with a unified platform, download the product brief at datadoghq.com/ciso/*

View Details

US House passes bill to boost chip manufacturing and R&D

One in seven ransomware extortion attempts leak key operational tech records

New Argo CD bug could let hackers steal secret info from Kubernetes apps

Thanks to our episode sponsor, Datadog

*Datadog Security Monitoring is part of the Datadog Cloud Security Platform, which protects an organization’s production environment and provides threat detection, posture management, workload security, and application security in a single pane of glass.

In this Datadog Security Monitoring product brief, you’ll learn how to:
Solve cloud complexity challenges with threat detection tools, detect and analyze security threats anywhere in your stack, and deploy turnkey detection rules mapped to the MITRE ATT&CK framework. Download the brief today to learn more at datadoghq.com/ciso/*

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, Jan 24-Feb 4, is hosted by Rich Stroffolino with our guest, Brian Lozada, CISO, HBOMax

Thanks to our episode sponsor, Pentera

Align validation to the MITRE ATT&CK framework and the OWASP Top 10. By aligning to industry standards, security teams ensure that their testing covers the latest adversary techniques. Most attacks succeed by leveraging the most common TTPs, so challenging the attack surface against these frameworks provides comprehensive coverage of adversary techniques in the wild. In addition, it allows security executives to clearly report to management on security control efficacy and enterprise readiness against potential threats. Find out more at pentera.io

All links and the video of this episode can be found on CISO Series.com

View Details

iPhone flaw exploited by second Israeli spy firm

Target shares its own web skimming detection tool with the world

MFA adoption pushes phishing actors to reverse-proxy solutions

Thanks to our episode sponsor, Pentera

Align validation to the MITRE ATT&CK framework and the OWASP Top 10. By aligning to industry standards, security teams ensure that their testing covers the latest adversary techniques. Most attacks succeed by leveraging the most common TTPs, so challenging the attack surface against these frameworks provides comprehensive coverage of adversary techniques in the wild. In addition, it allows security executives to clearly report to management on security control efficacy and enterprise readiness against potential threats. Find out more at pentera.io

For the stories behind the headlines, head to CISOseries.com.

View Details

Iran-linked APT activity on the rise

Hacker claims responsibility for North Korean internet disruptions

TikTok: the once and future national security threat

Thanks to our episode sponsor, Pentera

To continuously know the exploitable attack surface, automate your validation. Security validation must be as dynamic as the attack surface it’s securing. Periodical and manual tests aren’t enough to challenge the changes an organization undergoes. Security teams need to have an on-demand view of their assets and exposures, and the only way to get there is by automating your testing. Find out more at pentera.io

View Details

Cyber attack disrupts German oil firm operations

Tesla recalls Full Self Driving feature that lets cars roll through stop signs

FBI recommends using burner phones at the Olympics

Thanks to our episode sponsor, Pentera

To understand the exploitable attack surface, security teams need to cover the full scope of potential attacks. Adversaries take the path of least resistance to the critical assets. This means using a variety of techniques to progress an attack, leveraging any vulnerability and its relevant correlations along the way. For this reason, the validation methods used must match - they need to go beyond the static vulnerability scan or control attack simulation to include a full penetration test scope. Find out more at pentera.io

For the stories behind the headlines, head to CISOseries.com

View Details

Your GPU knows your secrets

UPnP behind Eternal Silence router campaign

DeFi platform hacked for $80 million

Thanks to our episode sponsor, Pentera

To understand the exploitable attack surface, take the adversarial perspective. The way to know which vulnerabilities are exploitable is to…well, exploit them. This way, security teams get a concise attack vector pointing to the organization’s weakest link. From here remediation requests handed to IT are focused, manageable, and based on true business impact. Find out more at pentera.io

View Details

Novel device registration trick enhances multi-stage phishing attacks

US bans major Chinese telecom over national security risks

Over 20,000 data center management systems exposed to hackers

Thanks to our episode sponsor, Pentera

Pentera introduces Automated Security Validation! The newly-minted unicorn out of Israel takes a whole new approach to penetration testing - allowing every organization to continuously test the integrity of all cybersecurity layers - including against ransomware - leveraging proprietary ethical exploits to emulate real-world attacks at scale. All day, everyday. This week Pentera will discuss how to identify your exploitable attack surface, so stay tuned for their ‘Tip of the Day’. Or visit pentera.io to find out more.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, Jan 24-28, is hosted by Rich Stroffolino with our guest, Gary Hayslip, CISO, Softbank Investment Advisers

Thanks to our episode sponsor, deepwatch

All links and the video of this episode can be found on CISO Series.com

View Details

US says national water supply 'absolutely' vulnerable to hackers

Microsoft mitigated a record 3.47 Tbps DDoS attack on Azure users

BotenaGo Mirai botnet code leaked to GitHub

Thanks to our episode sponsor, deepwatch

Increasing ransomware attacks and their evolving sophistication have been putting more pressure on security teams than ever before. Luckily, managed detection and response (or MDR) has emerged as a critical component for improving security operations, reducing ransomware risk, and minimizing the overall impact an attack can have. Visit deepwatch.com to see how we help to prevent breaches for our customers, by working together.

For the stories behind the headlines, head to CISOseries.com.

View Details

White House releases new cybersecurity strategy

Trickbot gets trickier

VPNLab shuttered in global takedown

Thanks to our episode sponsor, deepwatch

Increasing ransomware attacks and their evolving sophistication have been putting more pressure on security teams than ever before. Luckily, managed detection and response (or MDR) has emerged as a critical component for improving security operations, reducing ransomware risk, and minimizing the overall impact an attack can have. Visit deepwatch.com to see how we help to prevent breaches for our customers, by working together.

View Details

Canada's foreign ministry hacked

Hactivists target Belarus rail system to stop Russian military buildup

Segway victimized by Magecart attack

Thanks to our episode sponsor, deepwatch

Increasing ransomware attacks and their evolving sophistication have been putting more pressure on security teams than ever before. Luckily, managed detection and response (or MDR) has emerged as a critical component for improving security operations, reducing ransomware risk, and minimizing the overall impact an attack can have. Visit deepwatch.com to see how we help to prevent breaches for our customers, by working together.

For the stories behind the headlines, head to CISOseries.com

View Details

SBA launches cybersecurity program

Ransomware gangs step up insider recruitment

American Olympians warned to take cybersecurity precautions

Thanks to our episode sponsor, deepwatch

Increasing ransomware attacks and their evolving sophistication have been putting more pressure on security teams than ever before. Luckily, managed detection and response (or MDR) has emerged as a critical component for improving security operations, reducing ransomware risk, and minimizing the overall impact an attack can have. Visit deepwatch.com to see how we help to prevent breaches for our customers, by working together.

View Details

Ukraine attack update: experts find strategic similarities with NotPetya

Molerats use Google Drive and Dropbox as attack infrastructure

Senators introduce bill to protect satellites from getting hacked

Thanks to our episode sponsor, deepwatch

Increasing ransomware attacks and their evolving sophistication have been putting more pressure on security teams than ever before. Luckily, managed detection and response (or MDR) has emerged as a critical component for improving security operations, reducing ransomware risk, and minimizing the overall impact an attack can have. Visit deepwatch.com to see how we help to prevent breaches for our customers, by working together.

For the stories behind the headlines, head to CISOseries.com.

View Details

Link to Blog Post

This week’s Cyber Security Headlines – Week in Review, Jan 17-21, is hosted by Rich Stroffolino with our guest, Julie Tsai, Cybersecurity Leader

Thanks to our episode sponsor, Datadog

Join Datadog in their upcoming webinar to learn how to dissect the anatomy of an attack vector in the cloud with the use of their unified Cloud Security Platform. Visit datadoghq.com/ciso to register for the webinar in the time zone most convenient for you and attendees will also get a chance to win a Datadog t-shirt.

All links and the video of this episode can be found on CISO Series.com

View Details

NATO and Ukraine sign deal to boost cybersecurity

Microsoft Sees Log4j attacks exploiting SolarWinds Serv-U bug

Large-scale cyberattack hits the Red Cross

Thanks to our episode sponsor, Datadog

Join Datadog in their upcoming webinar to learn how to dissect the anatomy of an attack vector in the cloud with the use of their unified Cloud Security Platform. Visit datadoghq.com/ciso to register for the webinar in the time zone most convenient for you and attendees will also get a chance to win a Datadog t-shirt.

For the stories behind the headlines, head to CISOseries.com.

View Details

CISA warns of data-wiping attacks

EU working on its own DNS service

Biden expands the NSA’s cybersecurity purview

Thanks to our episode sponsor, Datadog

In Datadog's upcoming webinar, you’ll learn how to best utilize the suite of Datadog Cloud Security products to identify the root cause of an attack and how a unified platform provides real-time threat-detection and continuous configuration audits across applications, hosts, containers and cloud infrastructure. Visit datadoghq.com/ciso to register for the webinar in the time zone most convenient for you and attendees will also get a chance to win a Datadog t-shirt.

View Details

Beijing 2022 Winter Olympics app loaded with privacy risks

Europol shuts down cybercriminals' VPN service of choice

Newspaper accuses Israeli police of spying on its own citizens

Thanks to our episode sponsor, Datadog

Join Datadog in their upcoming webinar to learn how to dissect the anatomy of an attack vector in the cloud with the use of their unified Cloud Security Platform. Visit datadoghq.com/ciso to register for the webinar in the time zone most convenient for you and attendees will also get a chance to win a Datadog t-shirt.

For the stories behind the headlines, head to CISOseries.com

View Details

Ukraine points fingers in recent cyber attacks

Another dark web marketplace calls it quits

Renewable energy targeted for cyber espionage

Thanks to our episode sponsor, Datadog

In Datadog's upcoming webinar, you’ll learn how to best utilize the suite of Datadog Cloud Security products to identify the root cause of an attack and how a unified platform provides real-time threat-detection and continuous configuration audits across applications, hosts, containers and cloud infrastructure. Visit datadoghq.com/ciso to register for the webinar in the time zone most convenient for you and attendees will also get a chance to win a Datadog t-shirt.

View Details

Microsoft discloses malware attack on Ukraine government networks

New unpatched Apple Safari browser bug allows cross-site user tracking

Now you can get your vulnerability alerts by phone

Thanks to our episode sponsor, Datadog

Join Datadog in their upcoming webinar to learn how to dissect the anatomy of an attack vector in the cloud with the use of their unified Cloud Security Platform. Visit datadoghq.com/ciso to register for the webinar in the time zone most convenient for you and attendees will also get a chance to win a Datadog t-shirt.

For the stories behind the headlines, head to CISOseries.com.