meta_pixel
Tapesearch Logo
CyberWire Daily

When fake fixes hide real attacks.

CyberWire Daily

N2K Networks, Inc.

Daily News, Tech News, News, Technology

4.61K Ratings

🗓️ 21 April 2025

⏱️ 26 minutes

🧾️ Download transcript

Summary

Adversary nations are using ClickFix in cyber espionage campaigns. Japan’s Financial Services Agency issues an urgent warning after hundreds of millions in unauthorized trades. The critical Erlang/OTP’s SSH vulnerability now has public exploits. A flawed rollout of a new Microsoft Entra app triggers widespread account lockouts.  The alleged operator of SmokeLoader malware faces federal hacking charges. A new scam blends social engineering, malware, and NFC tech to drain bank accounts. GSA employees may have been oversharing sensitive documents. Yoni Shohet, Co-Founder and CEO of Valence Security, who cautions financial organizations of coming Chinese open source AI. Crosswalks in the crosshairs of satirical hacking. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest We are joined by Yoni Shohet, Co-Founder and CEO of Valence Security, discussing how the onslaught of more open source AI tools coming out of China will be difficult to manage for companies especially those in the financial sector. Selected Reading North Korea, Iran, Russia-Backed Hackers Deploy ClickFix in New Attacks (Hackread) Countries Shore Up Their Digital Defenses as Global Tensions Raise the Threat of Cyberwarfare (SecurityWeek) Japan warns of hundreds of millions of dollars in unauthorized trades from hacked accounts (The Record) Critical Erlang/OTP SSH RCE bug now has public exploits, patch now (Bleeping Computer) Widespread Microsoft Entra lockouts tied to new security feature rollout (Bleeping Computer) Alleged SmokeLoader malware operator facing federal charges in Vermont (The Record) New payment-card scam involves a phone call, some malware and a personal tap (The Record) Sensitive files, including White House floor plans, shared with thousands (The Washington Post) Hacking US crosswalks to talk like Zuck is as easy as 1234 (The Register)  Share your feedback. We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show.  Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at [email protected] to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript

Click on a timestamp to play from that location

0:00.0

You're listening to the Cyberwire Network, powered by N2K.

0:09.7

And now a word from our sponsor, SpyCloud. Identity is the new battleground, and attackers are

0:17.8

exploiting stolen identities to infiltrate your organization.

0:21.6

Traditional defenses can't keep up.

0:23.9

SpyCloud's holistic identity threat protection helps security teams uncover and automatically

0:29.3

remediate hidden exposures across your users, from breaches, malware and fishing to neutralize

0:35.6

identity-based threats like account takeover, fraud, and ransomware.

0:40.0

Don't let invisible threats compromise your business.

0:43.0

Get your free corporate darknet exposure report at spycloud.com slash cyberwire and see what

0:49.9

attackers already know. That's spycloud.com slash cyberwire.

1:09.4

Adversary nations are using click-fix in cyber espionage campaigns.

1:14.2

Japan's financial services agency issues an urgent warning after hundreds of millions in

1:19.0

unauthorized trades.

1:20.7

The critical Erlang OTPSH vulnerability now has public exploits.

1:25.5

A flawed rollout of a new Microsoft Entra app triggers widespread

1:29.7

account lockouts. The alleged operator of smokeloader malware faces federal hacking charges.

1:35.7

A new scam blends social engineering, malware, and NFC tech to drain bank accounts. GSA employees may

1:43.0

have been oversharing

1:44.2

sensitive documents.

1:46.0

Our guest is Yanni Schohet,

1:47.6

co-founder and CEO of Valence Security,

1:50.4

who cautions financial organizations

...

Transcript will be available on the free plan in 20 days. Upgrade to see the full transcript now.

Disclaimer: The podcast and artwork embedded on this page are from N2K Networks, Inc., and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of N2K Networks, Inc. and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.