2,000 episodes

The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

CyberWire Daily N2K Networks

    • News
    • 4.8 • 942 Ratings

The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

    Riding the hype for new Arc browser. [Rsearch Saturday]

    Riding the hype for new Arc browser. [Rsearch Saturday]

    Jérôme Segura, Senior Director of Threat Intelligence at Malwarebytes, is discussing their work on "Threat actors ride the hype for newly released Arc browser." The Arc browser, newly released for Windows, has quickly garnered positive reviews but has also attracted cybercriminals who are using deceptive Google search ads to distribute malware disguised as the browser.
    These malicious campaigns exploit the hype around Arc, using techniques like embedding malware in image files and utilizing the MEGA cloud platform for command and control, highlighting the need for caution with sponsored search results and the effectiveness of Endpoint Detection and Response (EDR) systems.
    The research can be found here:
    Threat actors ride the hype for newly released Arc browser

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    • 27 min
    A snapshot of security woes.

    A snapshot of security woes.

    Microsoft's recall raises red flags. SolarWinds fixes flaws unearthed by NATO. Ukraine's CERT sounds alarm. Russian hacktivists cause trouble in EU elections. DEVCORE uncovers critical code execution flaw. LastPass leaves users locked out. Apple commits to five years of iPhone security. An AI mail fail. Inside the FCC's plan to strengthen BGP protocol. Dave sits down with our guest Camille Stewart Gloster, Former Deputy National Cyber Director at the White House, as she shares a retrospective of her public service career. And let’s all Cheers to cybersecurity.
    Our 2024 N2K CyberWire Audience Survey is underway, make your voice heard and get in the running for a $100 Amazon gift card. Remember to leave us a 5-star rating and review in your favorite podcast app.
    Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

    CyberWire Guest
    Guest Camille Stewart Gloster, Former Deputy National Cyber Director at the White House, shares a retrospective of her public service career. Camille’s full conversation with Dave can be found on our weekly cybersecurity law, policy and privacy podcast, Caveat. You can listen to it here. 

    Selected Reading
    Microsoft’s Recall Feature Is Even More Hackable Than You Thought (WIRED)
    Microsoft Research scientist gives non-answer when asked about Windows Recall privacy concerns (TechSpot) 
    TotalRecall: A New Tool that Extracts Data From Windows 11 Recall Feature (Cyber Security News)
    Exclusive: Senators express "serious concern" with Pentagon's Microsoft plan (Axios)
    SolarWinds Patches High-Severity Vulnerability Reported by NATO Pentester (SecurityWeek) 
    UAC-0020 used SPECTR Malware to target Ukraine defense forces (Security Affairs) 
    Russian hacktivists vow mass attacks against EU elections (The Register)
    Ransomware Actor Exploited CoinMiner Attacker's Proxy Server (Cyber Security News)
    Critical PHP Remote Code Execution Flaw let Attackers Inject Malicious Scripts (Cyber Security News)
    Users furious after LastPass down for hours (Cybernews)
    Apple Says iPhones Will Get Security Updates for at Least 5 Years (SecurityWeek) 
    EmailGPT Exposed to Prompt Injection Attacks (Infosecurity Magazine)
    FCC Proposes BGP Security Reporting for Broadband Providers (SecurityWeek)
    Unpacking the SEC 10-K cyber disclosures (PwC) 
    Apple set to launch Passwords app, taking on LastPass and 1Password (TechSpot)
    Wineloader Mimic As Ambassador Of India To Start The Infection Chain (Cyber Security News) 

    Share your feedback.
    We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 

    Want to hear your company in the show?
    You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.
    The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
    Learn more about your ad choices. Visit megaphone.fm/adchoices

    • 32 min
    CISA's calls for a JCDC makeover.

    CISA's calls for a JCDC makeover.

    CSAC recommends key changes to the  Joint Cyber Defense Collaborative. Cloud vendor Snowflake says single-factor authentication is to blame in their recent breach. Publishers sue Google over pirated ebooks. The FBI shares LockBit decryption keys. V3B is a phishing as a service campaign targeting banking customers. Commando Cat targets Docker servers to deploy crypto miners. Our guest is Danny Allen, Snyk's CTO, discussing how in the rush to implement GenAI, some companies are bypassing best practices and security policies. Club Penguin fans stumble upon a cache of secrets in the house of mouse.
    Our 2024 N2K CyberWire Audience Survey is underway, make your voice heard and get in the running for a $100 Amazon gift card. Remember to leave us a 5-star rating and review in your favorite podcast app.
    Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

    CyberWire Guest
    Guest is Danny Allan, Snyk's CTO, discussing how in the rush to implement GenAI, companies bypass best practices and security policies. This highlights a clear gap between those in leadership looking to adopt AI tools and the teams who are utilizing them. Learn more in Snyk Organizational AI Readiness Report. 

    Selected Reading
    CISA advisors urge changes to JCDC's goals, operations, membership criteria (The Record)
    CISA says 'patch now' to 7-year-old Oracle WebLogic bug (The Register)
    Snowflake says users with single-factor authentication targeted in attack (SC Media)
    Advance Auto Parts stolen data for sale after Snowflake attack (Bleeping Computer)
    Major Publishers Sue Google Over Ads for Pirated Ebooks (Publishing Perspectives)
    FBI unveils 7,000 decryption keys to aid LockBit victims (Silicon Republic)
     Hackers Attacking Banking Customers Using Phishing-As-A-Service V3B Toolkit (GB Hackers)
    Commando Cat: A Novel Cryptojacking Attack Abusing Docker Remote API Servers (Trend Micro)
    Club Penguin fans breached Disney Confluence server, stole 2.5GB of data (Bleeping Computer) 

    Share your feedback.
    We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 

    Want to hear your company in the show?
    You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.
    The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
    Learn more about your ad choices. Visit megaphone.fm/adchoices

    • 29 min
    Opening up on hidden secrets.

    Opening up on hidden secrets.

    OpenAI insiders describe a culture of recklessness and secrecy. Concerns over Uganda’s biometric ID system. Sophos uncovers a Chinese cyberespionage operation called Crimson Palace. Poland aims to sure up cyber defenses against Russia. Zyxel warns of critical vulnerabilities in legacy NAS products. Arctic Wolf tracks an amateurish ransomware variant named Fog. A TikTok zero-day targets high profile accounts. Cisco patches a Webex vulnerability that exposed German government meetings. On our Learning Layer segment, host Sam Meisenberg and Joe Carrigan continue their discussion of Joe's ISC2 CISSP certification journey, diving into Domain 7, Security Operations. A Canadian data breach leads to a class action payday. 
    Our 2024 N2K CyberWire Audience Survey is underway, make your voice heard and get in the running for a $100 Amazon gift card. Remember to leave us a 5-star rating and review in your favorite podcast app.
    Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

    Learning Layer
    On our Learning Layer segment, host Sam Meisenberg and Joe Carrigan continue their discussion of Joe's ISC2 CISSP certification journey using N2K’s comprehensive CISSP training course, CISSP practice test, and CISSP practice labs. Sam and Joe dive into Domain 7, Security Operations, and tackle the following question:
    Which of the following is the MOST important goal of Disaster Recovery Planning?

    Business continuity

    Critical infrastructure restoration

    Human Safety

    Regulatory compliance


    Selected Reading
    OpenAI Whistle-Blowers Describe Reckless and Secretive Culture (The New York Times)
    Uganda: Yoweri Museveni's Critics Targeted Via Biometric ID System (Bloomberg)
    Chinese South China Sea Cyberespionage Campaign Unearthed (GovInfo Security)
    Palau confirms 'major' cyberattack, points to China (Digital Journal)
    Poland to invest $760 million in cyberdefense as Russian pressure mounts (The Record)
    'NsaRescueAngel' Backdoor Account Again Discovered in Zyxel Products (SecurityWeek)
    Arctic Wolf sniffs out new ransomware variant (CSO Online)
    CNN, Paris Hilton, and Sony TikTok accounts hacked via DMs (Security Affairs)
    Cisco Patches Webex Bugs Following Exposure of German Government Meetings (SecurityWeek)
    ICBC must pay $15K to all who had data breached before JIBC attacks (Vancouver Sun) 

    Share your feedback.
    We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 

    Want to hear your company in the show?
    You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.
    The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
    Learn more about your ad choices. Visit megaphone.fm/adchoices

    • 31 min
    Ransomware hit causes pathology paralysis.

    Ransomware hit causes pathology paralysis.

    Ransomware disrupts London hospitals. Researchers discover serious vulnerabilities in Progress' Telerik Report Server and Atlassian Confluence Data Center and Server. Over three million people are affected by a breach at a debt collection agency. A report finds Rural hospitals vulnerable to ransomware. An Australian mining firm finds some of its data on the Dark Web. Google patches 37 Android vulnerabilities. Russian threat actors target the Summer Olympics in Paris. On our Industry Voices segment, we are joined by Sandy Bird, CTO at Sonrai. Sandy discusses the risks of unused identity infrastructure. The Amazon rainforest goes online.
    Our 2024 N2K CyberWire Audience Survey is underway, make your voice heard and get in the running for a $100 Amazon gift card. Remember to leave us a 5-star rating and review in your favorite podcast app.
    Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

    CyberWire Guest
    On our Industry Voices segment, we are joined by Sandy Bird, CTO at Sonrai. Sandy discusses the risks of unused identity infrastructure. You can learn more about Sonrai’s work in this area by reviewing their Quantifying Cloud Access Risk: Overprivileged Identities and Zombie Identities report.

    Selected Reading
    Critical incident declared as ransomware attack disrupts multiple London hospitals (The Record)
    CVE-2024-4358, CVE-2024-1800: Exploit Code Available for Critical Exploit Chain in Progress Telerik Report Server (Tenable)
    Atlassian’s Confluence hit with critical remote code execution bugs (CSO Online)
    Debt collection agency FBCS leaks information of 3 million US citizens (Malwarebytes)
    Rural hospitals are particularly vulnerable to ransomware, report finds (CyberScoop)
    Australian rare earths miner hit by cybersecurity breach (Mining Weekly)
    37 Vulnerabilities Patched in Android (SecurityWeek)
    Russia used fake AI Tom Cruise in Olympic disinformation campaign (Computer Weekly)
    The Internet's Final Frontier: Remote Amazon Tribes (New York Times)

    Listen to our newest podcast, “Only Malware in the Building.”
    N2K and Proofpoint have teamed up to launch “Only Malware in the Building,” the newest podcast on the N2K CyberWire network. Each month our hosts Selena Larson, Proofpoint’s staff threat researcher, and N2K’s Rick Howard and Dave Bittner, explore the mysteries around today’s most intriguing cyber threats. Listen to the first episode and subscribe now.

    Share your feedback.
    We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 

    Want to hear your company in the show?
    You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.
    The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
    Learn more about your ad choices. Visit megaphone.fm/adchoices

    • 33 min
    Things aren’t looking so Shiny(Hunters) at cloud provider Snowflake.

    Things aren’t looking so Shiny(Hunters) at cloud provider Snowflake.

    Signs point to a major cybersecurity event at cloud provider Snowflake. Hugging Face discloses "unauthorized access" to its Spaces platform. Australian legislation seeks jail time for deepfake porn. CISA adds two vulnerabilities to the KEV catalog. Spanish police investigate a potential breach of drivers license info. NSA shares mobile device best practices. Everbridge crisis management software company reports a data breach. N2K’s CSO, Chief Analyst, and Senior Fellow, Rick Howard joins us to preview CSO Perspectives Season 14 which launches today! Google tries to explain those weird AI search results. 
    Our 2024 N2K CyberWire Audience Survey is underway, make your voice heard and get in the running for a $100 Amazon gift card. Remember to leave us a 5-star rating and review in your favorite podcast app.
    Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.

    CyberWire Guest
    N2K’s CSO, Chief Analyst, and Senior Fellow, Rick Howard joins Dave to preview CSO Perspectives Season 14 which launches today! The first episode explores SolarWinds and the SEC. This episode of CSO Perspectives has a companion essay. You can find it here. Not an N2K Pro subscriber? You can catch the first half of the episode here. 

    Selected Reading
    The Ticketmaster Data Breach May Be Just the Beginning (WIRED)
    Hugging Face says it detected 'unauthorized access' to its AI model hosting platform (TechCrunch)
    Jail time for those caught distributing deepfake porn under new Australian laws (The Guardian)
    CISA warns of actively exploited Linux privilege elevation flaw (Bleeping Computer)
    Spanish police investigate whether hackers stole millions of drivers' data (Reuters)
    The NSA advises you to turn your phone off and back on once a week - here's why (ZDNET)
    Everbridge warns of corporate systems breach exposing business data (Bleeping Computer)
    Google’s AI Overview is flawed by design, and a new company blog post hints at why (Ars Technica) 

    Share your feedback.
    We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. 

    Want to hear your company in the show?
    You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at cyberwire@n2k.com to request more info.
    The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
    Learn more about your ad choices. Visit megaphone.fm/adchoices

    • 28 min

Customer Reviews

4.8 out of 5
942 Ratings

942 Ratings

Steve Kingah ,

Exquisite

Cyberwire is simply the best in this space. Rich and to the point.

Damien Lewke ,

I love this show, it’s my non negotiable

I’ve been listening to the Cyberwire for over seven years. As a happy Cyberwire Pro (yes I forked over the $$ for the premium version) customer I must say this show is the only non negotiable daily podcast I listen to. I GENUINELY cannot recommend this show to anyone who’s new to or highly experienced in cyber. I used this to bring myself up to speed when I was new in industry and a decade in, I still find value in it every day!! Five stars

[REDACTED] USER ,

You just subscribed to all of their podcasts with ads about their content…

UPDATE: You just subscribed to all of their podcasts… 5-10 mins of actual content with 15-20 mins of ads including inserting their other podcasts in the Cyberwire Daily podcast. I don't recommend this podcast to anyone who values their time. There is plenty of other shows that give you the content you want. Too much hassle. Weird how things are managed at this place. Including changing names. I suspect they pay their marketing team more than content team.

PREVIOUS UPDATE: I now can listen again! Great podcast! It now plays using VPNs with anti malware/anti tracking VPNs. I would really like to listen again without disabling antimalware/antitracking VPNs. Please change your publishing settings to allow. PREVIOUS UPDATE: Podcast doesn’t play when connected to VPN that uses anti malware technology. Weird why that is an issue with this podcast a few others… Will you please fix this? Most non-cyberwire podcasts play without any issues. I suspect it’s a setting within how you publish your content. Podcast does play with VPN with anti malware tech turned off. Previous PREVIOUS UPDATE: I’m enjoying the podcast again and getting news about cybersecurity. Previously Previous PREVIOUS REVIEW: STOP reporting on non cybersecurity news. Cyberwire not Newswire! If I wanted to listen to news unrelated to cybersecurity, I’d listen to mainstream media… Stick to what people tune into for. Maybe cut show length if you’re having to make up nonsense to fill the show. Otherwise, A good daily 30 min podcast about cybers Good podcast content. Some interviews are great.

Top Podcasts In News

The Daily
The New York Times
The Tucker Carlson Show
Tucker Carlson Network
Up First
NPR
Pod Save America
Crooked Media
The Ben Shapiro Show
The Daily Wire
The Megyn Kelly Show
SiriusXM

You Might Also Like

Cyber Security Headlines
CISO Series
Hacking Humans
N2K Networks
Cybersecurity Today
ITWC
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
Smashing Security
Graham Cluley & Carole Theriault
Malicious Life
Malicious Life