In the latest episode of the Security Sprint, Dave and Andy covered the following topics:
Opening:
- White House instructs agencies to avoid firing cybersecurity staff, email says
- CISA Probationary Reinstatements
- DOGE Staffer Broke Treasury Rules Transmitting Personal Data
- China, Russia, Iran, and North Korea Intelligence Sharing
Main Topics:
Severe Weather:
- 40 dead as storms head east; fire risk remains in parts of U.S.
- ‘I’ve seen nothing like this since I was a kid’: At least 39 people have died across 7 states after powerful storm system
- Severe weather disaster: 40 dead after destructive tornadoes, wildfires and dust storms, sweep across US;
- Europe’s Winter Storms Will Get Worse as Emissions Rise, Study Says
- Ready.gov
Scams & Fraud:
- New FTC Data Show a Big Jump in Reported Losses to Fraud to $12.5 Billion in 2024
- Top scams of 2024
- FBI Warns of Fraudulent Federal Warrants in Wyoming
- Take9
Quick Hits:
- Texas man faces prison for activating ‘kill switch’ on former employer’s network
- Lawsuit Alleges $12 Billion "Unicorn" Deel Cultivated Spy, Orchestrated Long-Running Trade-Secret Theft & Corporate Espionage Against Competitor
- Flexport accuses former employees of stealing its source code to create a rival startup
- Rethinking Insider Risk in an AI-Driven Workplace
- CISA and Partners Release Cybersecurity Advisory on Medusa Ransomware
- CISA: Medusa ransomware hit over 300 critical infrastructure orgs
- Iraqi PM says Islamic State leader for Iraq and Syria killed
- Lawmakers seek DHS records in probe of US response to Chinese cyber campaigns
- Europe's telecoms sector under increased threat from cyber spies, warns Denmark
- Risky Bulletin: GitHub supply chain attack prints everyone's secrets in build logsGitHub Actions Supply Chain Compromise: tj-actions/changed-files Action
- CAIR’s Civil Rights Report Shows Islamophobia Complaints at All-Time High, Viewpoint Discrimination Key Factor
- Trump administration weighs travel ban on dozens of countries, memo says
- Canadian Centre for Cyber Security - Mass Exploitation of Critical PHP-CGI Vulnerability (CVE-2024-4577).
- Ransomware gang creates tool to automate VPN brute-force attacks