loader from loading.io

Week in Review: Microsoft Trust abuse, 23andMe bankruptcy risks, NIST’s growing backlog

Cyber Security Headlines

Release Date: 03/28/2025

Russian army map malware, edge tech attack report, Commvault flaw show art Russian army map malware, edge tech attack report, Commvault flaw

Cyber Security Headlines

Russian army targeted by Android malware hidden in mapping app Attackers hit security device defects hard in 2024 Critical Commvault Command Center flaw warning Huge thanks to our sponsor, Dropzone AI Alert investigation is eating up your security team's day—30 to 40 minutes per alert adds up fast. 's SOC Analyst transforms this reality by investigating every alert with expert-level thoroughness at machine speed. Our AI SOC Analyst gathers evidence, connects the dots across your security tools, and delivers clear reports with recommended actions—all in minutes. No playbooks to build, no...

info_outline
Blue Shield of California shared private data,FBI IC3 report, Ex-Army sergeant jailed show art Blue Shield of California shared private data,FBI IC3 report, Ex-Army sergeant jailed

Cyber Security Headlines

Blue Shield of California shared private health data of millions with Google The FBI issues its 2024 IC3 report Ex-Army sergeant jailed for selling military secrets Huge thanks to our sponsor, Dropzone AI Security analysts need practical experience to build investigation skills, but getting expert guidance for every alert is impossible. That's why created COACH—a free Chrome extension that serves as an AI security mentor for SOC analysts at any level. COACH reads alerts across all major security platforms, explains their context, provides alternative hypotheses, and guides analysts through...

info_outline
Microsoft Recall updates, Russian orgs deal with networking software updates, SSL.com certificate issuance vulnerability show art Microsoft Recall updates, Russian orgs deal with networking software updates, SSL.com certificate issuance vulnerability

Cyber Security Headlines

Microsoft Recall on Copilot+ PC: testing the security and privacy implications Russian organizations targeted by backdoor masquerading as secure networking software updates SSL.com Scrambles to Patch Certificate Issuance Vulnerability  Huge thanks to our sponsor, Dropzone AI Is your security team spending too much time chasing alerts instead of stopping threats? modernizes your security operations by handling the routine investigations that consume your team's day. Our AI SOC Analyst works with your existing security tools, learns your environment, and delivers clear, actionable reports...

info_outline
Google OAuth abused, Japan's trading scams, hijacking with Zoom show art Google OAuth abused, Japan's trading scams, hijacking with Zoom

Cyber Security Headlines

Google OAuth abused in DKIM replay attack Japan warns of sharp rise in unauthorized trading North Koreans hijacking Zoom’s Remote Control Huge thanks to our sponsor, Dropzone AI Security threats don't clock out at 5 PM, but your analysts need to sleep sometime. delivers around-the-clock alert investigations with the same attention to detail at midnight as at noon. Our AI SOC Analyst ensures no more morning backlogs and no more off-hours blind spots. Just reliable, continuous protection that ensures every alert gets the attention it deserves, regardless of when it arrives. See how SOC teams...

info_outline
Microsoft Entra lockouts, wine tasting malware, job scam solution show art Microsoft Entra lockouts, wine tasting malware, job scam solution

Cyber Security Headlines

Widespread Microsoft Entra lockouts cause by new security feature rollout Malware delivered through diplomatic wine-tasting invites British companies told to hold in-person interviews to thwart North Korea job scammers Huge thanks to our sponsor, Dropzone AI Growing your MSSP client roster while your alerts are multiplying? works alongside your team, investigating alerts just like your best human analysts would. Our AI SOC Analyst cuts investigation time from an hour to minutes while handling five times more alerts per analyst. Unlike complex SOAR solutions, Dropzone deploys quickly and...

info_outline
Week in Review: CISA workforce cuts, AI slopsquatting risk, CVE funding saga show art Week in Review: CISA workforce cuts, AI slopsquatting risk, CVE funding saga

Cyber Security Headlines

Link to This week’s Cyber Security Headlines – Week in Review is hosted by with guest , CISO, Thanks to our show sponsor, Vanta Do you know the status of your compliance controls right now? Like…right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with . Vanta brings automation to evidence collection across over 35 frameworks, like SOC 2 and ISO 27001. They also centralize key workflows like policies, access reviews,...

info_outline
Cyberthreat sharing law renewal, APTs love ClickFix, GoDaddy mutes Zoom show art Cyberthreat sharing law renewal, APTs love ClickFix, GoDaddy mutes Zoom

Cyber Security Headlines

Bipartisan push for renewal of cyberthreat information sharing law ClickFix becoming a favorite amongst state-sponsored hackers GoDaddy puts Zoom on mute for about 90 minutes Thanks to this week's episode sponsor, Vanta Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with . Vanta brings automation to evidence collection across over 35 frameworks, like SOC...

info_outline
MITRE bailout, Krebs exits SentinelOne, Apple fixes zero-days show art MITRE bailout, Krebs exits SentinelOne, Apple fixes zero-days

Cyber Security Headlines

MITRE gets last-minute bailout from CISA Krebs exits SentinelOne after security clearance pulled Apple fixes two zero-days exploited in targeted iPhone attacks Thanks to this week's episode sponsor, Vanta Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with . For the stories behind the headlines, visit CISOseries.com. Vanta brings automation to evidence...

info_outline
BREAKING: CVE Funding Doesn't Lapse show art BREAKING: CVE Funding Doesn't Lapse

Cyber Security Headlines

CISA issued a statement that it execution an option on its contract with MITRE to continue funding the CVE program.

info_outline
Government CVE funding set to end, 4chan down following an alleged hack, China accuses US of launching advanced cyberattacks show art Government CVE funding set to end, 4chan down following an alleged hack, China accuses US of launching advanced cyberattacks

Cyber Security Headlines

Government CVE funding set to end Tuesday 4chan, the internet's most infamous forum, is down following an alleged hack China accuses US of launching 'advanced' cyberattacks, names alleged NSA agents Thanks to this week's episode sponsor, Vanta Do you know the status of your compliance controls right now? Like...right now? We know that real-time visibility is critical for security, but when it comes to our GRC programs…we rely on point-in-time checks. But more than 9,000 companies have continuous visibility into their controls with . Vanta brings automation to evidence collection across over...

info_outline
 
More Episodes

Link to episode page

This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest Jonathan Waldrop, CISO, The Weather Company

Jonathan will be speaking at The CrowdStrike Crowd Tour, on Tuesday, April 15, 2025 in Atlanta – details here.

He will also be speaking at the C Vision International Think Tank on April 24, 2025, also in Atlanta – details here.

Thanks to our show sponsor, ThreatLocker

ThreatLocker® is a global leader in Zero Trust endpoint security, offering cybersecurity controls to protect businesses from zero-day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit ThreatLocker.com.

All links and the video of this episode can be found on CISO Series.com