meta_pixel
Tapesearch Logo
Log in
CyberWire Daily

When exploits go wild and patches race the clock.

CyberWire Daily

N2K Networks, Inc.

News, Daily News, Tech News, Technology

4.81.1K Ratings

🗓️ 11 December 2024

⏱️ 26 minutes

🧾️ Download transcript

Summary

Microsoft confirms a critical Windows zero-day vulnerability. Global law enforcement agencies dismantle 27 DDoS platforms. Researchers compromise memory in AMD virtual machines. Ivanti reports multiple critical vulnerabilities in its Cloud Services Application. Group-IB researchers expose a sophisticated global phishing campaign. A zero-day vulnerability in Cleo’s managed file transfer software is under active exploitation. The U.S. sanctions a Chinese firm for a 2020 firewall exploit. Congress looks to require the FCC to regulate telecom cybersecurity. Our guest is Malachi Walker, Security Strategist at DomainTools, discussing their role in ODNI's newly established Sentinel Horizon Program. SpartanWarriorz dodge a Telegram crackdown.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Our guest is Malachi Walker, Security Strategist at DomainTools, about their role in ODNI's newly established Sentinel Horizon Program. Selected Reading New Windows 0Day Attack Confirmed—Homeland Security Says Update Now (Forbes) Microsoft Fixes 71 CVEs Including Actively Exploited Zero-Day (Infosecurity Magazine) Atlassian, Splunk Patch High-Severity Vulnerabilities (SecurityWeek) Chrome Security Update, Patch for 3 High-severity Vulnerabilities (Cyber Security News) ICS Patch Tuesday: Security Advisories Released by Siemens, Schneider, CISA, Others (SecurityWeek) Operation PowerOFF Takes Down DDoS Boosters (Infosecurity Magazine) AMD Chip VM Memory Protections Broken by BadRAM (Security Boulevard) Three more vulns spotted in Ivanti CSA, all critical, one 10/10 (The Register) Global Ongoing Phishing Campaign Targets Employees Across 12 Industries (Hackread) New Cleo zero-day RCE flaw exploited in data theft attacks (Bleeping Computer)  US Sanctions Chinese Firm at Center of Global Firewall Hack (Infosecurity Magazine) Wyden legislation would mandate FCC cybersecurity rules for telecoms (CyberScoop) Scam Kit Maker Rebuilding Business After Telegram Channel Shut Down (Security Boulevard)  Share your feedback. We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show.  Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript

Click on a timestamp to play from that location

0:00.0

You're listening to the Cyberwire Network, powered by N2K.

0:09.7

Quick question. Do your end users always, and I mean always, without exception,

0:18.8

work on company-owned devices and IT-approved apps.

0:22.4

I didn't think so.

0:24.2

So my next question is, how do you keep your company's data safe when it's sitting on all

0:29.1

those unmanaged apps and devices?

0:31.8

OnePassword has an answer to this question, extended access management.

0:36.7

One-Password, extended access management helps you secure

0:40.2

every sign-in for every app on every device, because it solves the problems traditional IAM and

0:46.8

MDM can't touch. And it's now available to companies with Octa and Microsoft Entra and in beta for

0:54.1

Google Workspace customers.

0:56.4

Check it out at OnePassword.com slash Cyberwire.

1:00.2

That's OnePassword.com slash Cyberwire. Microsoft confirms a critical Windows Zero Day vulnerability.

1:24.0

Global law enforcement agencies dismantled 27 DDoS platforms.

1:28.5

Researchers compromise memory and AMD virtual machines.

1:32.6

Evanti reports multiple critical vulnerabilities in its cloud services application.

1:37.4

Group IB researchers expose a sophisticated global fishing campaign.

1:41.8

A zero-day vulnerability in Clio's managed file transfer software is under active exploitation.

1:48.0

The U.S. sanctions a Chinese firm for a 2020 firewall exploit.

1:52.8

Congress looks to require the FCC to regulate telecom cybersecurity.

1:57.3

Our guest is Malachi Walker, security strategist at Domain Tools,

2:01.5

discussing their role in ODNI's newly established Sentinel Horizon program.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from N2K Networks, Inc., and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of N2K Networks, Inc. and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.