Business of Tech: Daily 10-Minute IT Services Insights

Unauthorized Access: A Deep Dive into the Treasury Department Breach. Microsoft's VPN Shutdown


Listen Later

significant security breach has been identified within the U.S. Treasury Department, where unauthorized individuals gained administrator-level access to critical financial systems, including the Payment Automation Manager (PAM) and the Secure Payment System (SPS). This breach raises serious concerns about the integrity of the U.S. financial system, as it allows for unauthorized modifications to federal payment workflows and security configurations. The threat actors, linked to a private sector entity, have reportedly acquired elevated privileges without the necessary government vetting or legal authorization, potentially compromising sensitive financial operations and personal data of millions of Americans.

The implications of this breach extend beyond the Treasury, as individuals associated with the threat actors have also gained unauthorized access to the National Oceanic and Atmospheric Administration (NOAA). This unauthorized entry raises alarms about the potential compromise of classified environmental data and the integrity of agency operations. Lawmakers are expressing significant concern over the breach, particularly regarding its impact on federal funding mechanisms and the privacy of citizens. Affected customers have filed a lawsuit against the Treasury Department, alleging failures in enforcing access controls that could jeopardize personal and financial information.

The discussion highlights the importance of cybersecurity governance, compliance, and access control, emphasizing that security is not solely about defending against external threats. The podcast stresses that insider threats and unauthorized privileged access are equally critical issues that businesses must address. It calls for a shift in how organizations perceive security, advocating for a zero-trust approach and robust identity and access management practices. The need for continuous monitoring and strict auditing of privileged accounts is underscored, as unauthorized access can occur regardless of the actors' intent.

In addition to the main story, the episode covers several other cybersecurity-related topics, including the exposure of over one million chat records by DeepSeek, which has raised concerns about data security among AI providers. Microsoft announced the discontinuation of its Defender VPN service due to low usage, while Let's Encrypt plans to end its expiration notification email service. Cloudflare has introduced a feature to enhance online image authenticity, and the Trump administration has eliminated a key framework for AI integration into federal cloud services. These developments reflect broader trends in cybersecurity, privacy, and the evolving landscape of technology governance.

 

Four things to know today

 

00:00 Cybersecurity 101: If Even the Government Can’t Control Access, What About Your Business?  

06:39 DeepSeek Leaks a Million Chat Records—And the Pentagon Wants Nothing to Do with It

08:58 Microsoft Pulls the Plug on Defender VPN—Was Anyone Using It?

10:57 FedRAMP Shake-Up: No Special Treatment for AI as Trump Administration Ends Key Framework

 

 

Supported by:  https://www.huntress.com/mspradio/

Event: https://nerdiocon.com/

 

All our Sponsors:   https://businessof.tech/sponsors/

 

Do you want the show on your podcast app or the written versions of the stories? Subscribe to the Business of Tech: https://www.businessof.tech/subscribe/

Looking for a link from the stories? The entire script of the show, with links to articles, are posted in each story on https://www.businessof.tech/

 

Support the show on Patreon: https://patreon.com/mspradio/

 

Want to be a guest on Business of Tech: Daily 10-Minute IT Services Insights? Send Dave Sobel a message on PodMatch, here: https://www.podmatch.com/hostdetailpreview/businessoftech

 

Want our stuff? Cool Merch? Wear “Why Do We Care?” - Visit https://mspradio.myspreadshop.com

 

Follow us on:

LinkedIn: https://www.linkedin.com/company/28908079/

YouTube: https://youtube.com/mspradio/

Facebook: https://www.facebook.com/mspradionews/

Instagram: https://www.instagram.com/mspradio/

TikTok: https://www.tiktok.com/@businessoftech

Bluesky: https://bsky.app/profile/businessof.tech

...more
View all episodesView all episodes
Download on the App Store

Business of Tech: Daily 10-Minute IT Services InsightsBy MSP Radio

  • 4.9
  • 4.9
  • 4.9
  • 4.9
  • 4.9

4.9

129 ratings


More shows like Business of Tech: Daily 10-Minute IT Services Insights

View all
WSJ Tech News Briefing by The Wall Street Journal

WSJ Tech News Briefing

1,636 Listeners

WSJ Your Money Briefing by The Wall Street Journal

WSJ Your Money Briefing

1,744 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

628 Listeners

Bloomberg Businessweek by Bloomberg

Bloomberg Businessweek

425 Listeners

a16z Podcast by Andreessen Horowitz

a16z Podcast

1,014 Listeners

Bold Names by The Wall Street Journal

Bold Names

1,449 Listeners

Techmeme Ride Home by Brian McCullough

Techmeme Ride Home

942 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

167 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

187 Listeners

The Killing IT Podcast by Karl W. Palachuk

The Killing IT Podcast

12 Listeners

MSP Unplugged by Paco Lebron

MSP Unplugged

10 Listeners

The MSP Zone by Charles Weaver

The MSP Zone

14 Listeners

MSP Business School by MSP Business School

MSP Business School

6 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

129 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

33 Listeners