meta_pixel
Tapesearch Logo
Log in
CyberWire Daily

No hocus pocus—MagicINFO flaw is the real threat.

CyberWire Daily

N2K Networks, Inc.

Daily News, Tech News, News, Technology

4.61K Ratings

🗓️ 6 May 2025

⏱️ 33 minutes

🧾️ Download transcript

Summary

A critical flaw in a Samsung’s CMS is being actively exploited. President Trump’s proposed 2026 budget aims to slash funding for CISA. “ClickFix” malware targets both Windows and Linux systems through advanced social engineering. CISA warns of a critical Langflow vulnerability actively exploited in the wild. A new supply-chain attack targets Linux servers using malicious Go modules found on GitHub. The Venom Spider threat group targets HR professionals with fake resume submissions. The Luna Moth group escalates phishing attacks on U.S. legal and financial institutions. The U.S. Treasury aims to cut off a Cambodia-based money laundering operation. Our guest is  Monzy Merza, Co-Founder and CEO of Crogl, discussing the CISO's conundrum in the face of AI. Malware, mouse ears, and mayhem: Disney hacker pleads guilty. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On our Industry Voices segment, we are joined by Monzy Merza, Co-Founder and CEO of Crogl, who is discussing the CISO's conundrum—the growing challenge of securing organizations in a world where AI rapidly expands both the number of users and potential adversaries.Selected Reading Samsung MagicINFO Vulnerability Exploited Days After PoC Publication (SecurityWeek) Trump would cut CISA budget by $491M amid ‘censorship’ claim  (The Register) New ClickFix Attack Mimics Ministry of Defense Website to Attack Windows & Linux Machines (Cyber Security News) Critical Vulnerability in AI Builder Langflow Under Attack (SecurityWeek) Linux wiper malware hidden in malicious Go modules on GitHub (Bleeping Computer) Malware scammers target HR professionals with Venom Spider malware (SC Media) Luna Moth extortion hackers pose as IT help desks to breach US firms (Bleeping Computer) US Readies Huione Group Ban Over Cybercrime Links (GovInfo Security) Hacker 'NullBulge' pleads guilty to stealing Disney's Slack data (Bleeping Computer) Share your feedback. We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show.  Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at [email protected] to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript

Click on a timestamp to play from that location

0:00.0

You're listening to the Cyberwire Network, powered by N2K.

0:09.7

And now a word from our sponsor, SpyCloud. Identity is the new battleground, and attackers are

0:17.8

exploiting stolen identities to infiltrate your organization.

0:21.6

Traditional defenses can't keep up.

0:23.9

SpyCloud's holistic identity threat protection helps security teams uncover and automatically

0:29.3

remediate hidden exposures across your users, from breaches, malware and fishing to neutralize

0:35.6

identity-based threats like account takeover, fraud, and ransomware.

0:40.0

Don't let invisible threats compromise your business.

0:43.0

Get your free corporate darknet exposure report at spycloud.com slash cyberwire and see what

0:49.9

attackers already know. That's spycloud.com slash cyberwire.

0:55.4

A critical flaw in Samsung's CMS is being actively exploited.

1:14.0

President Trump's proposed 2026 budget aims to slash funding for SISA.

1:18.6

Click-fix malware targets both Windows and Linux systems through advanced social engineering.

1:23.7

Sisa warns of a critical Langflow vulnerability actively exploited. A new supply chain attack

1:29.3

targets Linux servers using malicious go modules found on GitHub. The Venom Spider Threat

1:34.8

group targets HR professionals with fake resume submissions. The Lunamoth Group escalates

1:39.9

fishing attacks on U.S. legal and financial institutions. The Treasury aims to cut off a Cambodia-based money laundering campaign.

1:48.2

Our guest is Monzi Merza, co-founder and CEO of Krogel, discussing the Sissos conundrum in the

1:54.1

face of AI.

1:55.6

And malware, mouse ears, and mayhem.

1:58.8

A Disney hacker pleads guilty.

2:08.4

Music Mouse ears and mayhem. A Disney hacker pleads guilty. It's Tuesday, May 6th, 2025.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from N2K Networks, Inc., and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of N2K Networks, Inc. and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.