meta_pixel
Tapesearch Logo
Log in
CyberWire Daily

Almost letting hackers rule the web.

CyberWire Daily

N2K Networks, Inc.

Daily News, Tech News, News, Technology

4.61K Ratings

🗓️ 22 August 2024

⏱️ 28 minutes

🧾️ Download transcript

Summary

A Wordpress plugin vulnerability puts 5 million sites at risk. Google releases an emergency Chrome update addressing an actively exploited vulnerability. Cisco patches multiple vulnerabilities. Researchers say Slack AI is vulnerable to prompt injection. Widely used RFID smart cards could be easily backdoored. The FAA proposes new cybersecurity rules for airplanes, engines, and propellers. A member of the Russian Karakurt ransomware group faces charges in the U.S. The Five Eyes release a guide on Best Practices for Event Logging and Threat Detection. The Kremlin claims widespread online outages are due to DDoS, but experts think otherwise. In our Threat Vector segment, guest host Michael Sikorski speaks with Jason Healey, Senior Research Scholar at Columbia University's School of International and Public Affairs. A deadbeat dad dodges debt through death. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. Threat Vector Segment In this Threat Vector segment, guest host Michael Sikorski, CTO of Unit 42, engages in a thought-provoking conversation about the historical challenges and advances in cyber conflict with Jason Healey, Senior Research Scholar at Columbia University's School of International and Public Affairs. To listen to their full conversation, check out the episode here. You can catch new episodes of Threat Vector every Thursday on the N2K CyberWire network. Selected Reading Critical Privilege Escalation in LiteSpeed Cache Plugin (Patchstack) Google fixes ninth Chrome zero-day exploited in attacks this year (The Register) Cisco Patches High-Severity Vulnerability Reported by NSA (SecurityWeek) Slack AI can leak private data via prompt injection (The Register) Major Backdoor in Millions of RFID Cards Allows Instant Cloning (SecurityWeek) FAA proposes new cybersecurity rules for airplanes (The Record) U.S. charges Karakurt extortion gang’s “cold case” negotiator (Bleeping Computer) ASD’s ACSC, CISA, FBI, and NSA, with the support of International Partners Release Best Practices for Event Logging and Threat Detection (CISA) Kremlin blames widespread website disruptions on DDoS attack; digital experts disagree (The Record) Deadbeat dad faked his own death by hacking government sites (The Register) Share your feedback. We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at [email protected] to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript

Click on a timestamp to play from that location

0:00.0

You're listening to the CyberWire Network, powered by N2K.

0:07.0

When it comes to ensuring your company has top-notch security practices, things can get complicated fast.

0:21.0

Vanta automates compliance for SOC2, ISO 2701, HIPAA and more, saving you time and money.

0:29.7

With Vanta you can streamline security reviews by automating questionnaires and

0:34.2

demonstrating your security posture with a customer-facing trust center.

0:38.4

Over 7,000 global companies like Atlassian, Flow Health, and Quora use Vanta to manage risk and prove security

0:46.5

in real time.

0:48.4

Our listeners can claim a special offer of $1,000 off Vanta at vanta.com slash cyber.

0:55.8

That's VANTA.com slash cyber for $1,000 off Banta. A Word Press plugin vulnerability puts 5 million sites at risk.

1:19.0

Google releases an emergency Chrome update addressing an actively exploited vulnerability.

1:23.6

Cisco Patches multiple vulnerabilities.

1:26.3

Researchers say Slack AI is vulnerable to prompt injection.

1:30.2

Widely used RFID Smartcards could be easily back-doored.

1:34.0

The FAA proposes new cybersecurity rules for airplanes, engines, and propellers.

1:39.3

A member of the Russian Karakert Ransomere Group faces charges in the U.S.

1:44.2

The Five Eyes release a guide on best practices for event logging and threat detection.

1:49.2

The Kremlin claims widespread online outages are due to D-D-D-D-D-S, but experts think otherwise.

1:55.4

In our Threat Vector segment, guest host Michael Sikorski speaks with Jason Healy, senior research

2:01.0

scholar at Columbia University University School of International

2:03.7

and Public Affairs. And a deadbeat dad dodges debt through death! It's Thursday, August 22nd, 2024. I'm Dave Bitner and this is your CyberWire Intel briefing. Thanks for joining us here today. It is great to have you with us. A vulnerability in the

2:42.3

light speed cash WordPress plugin. you with us. A vulnerability in the LightSpeed Cash Word Press plugin allows unauthenticated

2:46.6

users to escalate their privileges to an administrator level, putting over 5 million sites at

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from N2K Networks, Inc., and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of N2K Networks, Inc. and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.