
Loading summary
CISO Series Host
From the CISO series, it's Cybersecurity Headlines.
Sean Kelly
These are the cybersecurity headlines for Monday, February 24, 2025. I'm Sean Kelly.
Cybersecurity Analyst
Hacker steals nearly $1.5 billion from Bybit.
Sean Kelly
Crypto Wallet Undoubtedly the top cyber news.
Cybersecurity Analyst
Story developing over the weekend stemmed from the Bybit Crypto exchanges announcement on Friday that an unknown attacker stole over $1.46 billion in crypto from one of its Ethereum cold wa. This makes the incident the largest cryptocurrency.
Sean Kelly
Hacked to date, almost doubling the previous record.
Cybersecurity Analyst
Bybit said the attackers altered a wallet.
Sean Kelly
Transaction quote through a sophisticated attack that.
Cybersecurity Analyst
Masked the signing interface displaying the correct address while altering the underlying smart contract logic. End quote According to crypto fraud investigator Zach xbt, the perpetrator has already split a small percentage of the stolen Ethereum across 48 addresses. Bybit CEO Ben Zao said all other cold wallets and funds are fully secure and safe, and that the exchange remains both solvent and operational.
Sean Kelly
He added that even if the stolen.
Cybersecurity Analyst
Assets are not recovered, all client assets will be backed one to one. Meanwhile, researchers at Arkham Intelligence said its analysis showed definitive proof that the Bybit hack was the work of the North Korean Lazarus group. Apple pulls iCloud end to end encryption.
Sean Kelly
In the UK in the latest development.
Cybersecurity Analyst
In a story we've been following on cybersecurity headlines, Apple has made iCloud end to end encryption unavailable in the United Kingdom.
Sean Kelly
The move stems from the UK Government's.
Cybersecurity Analyst
Request for encryption backdoor access under its Investigatory Powers Act. End to end encryption is an optional setting for most iCloud data, including iCloud backup photos and notes, ensuring only users can access their data even in the event of a cloud breach. Even after this update, Apple's communication services, including iMessage and FaceTime and health and iCloud keychain data, will remain end to end encrypted. The Washington Post said the British government's mandate has no known precedent in major.
Sean Kelly
Democracies, end quote Apple said they are.
Cybersecurity Analyst
Gravely disappointed that these data protections will not be available to UK customers given.
Sean Kelly
The continued rise of data breaches and privacy threats.
Cybersecurity Analyst
PayPal new address feature abused to send.
Sean Kelly
Phishing emails over the past month, some.
Cybersecurity Analyst
PayPal users have received emails stating quote, this is just a quick confirmation that you added an address to your PayPal account, end quote the email also claims to be a purchase confirmation for a MacBook M4 and provides a phone number to call if the user did not authorize the purchase. The emails are being sent directly from PayPal's mail server using the Serviceaypal.com account, allowing the emails to bypass DKIM email security checks and spam filters. Testing by bleeping computer suggests attackers are somehow abusing PayPal's gift addresses feature that allows users to add addresses to their PayPal profile, which seemingly triggers legitimate emails from PayPal's email server. Researchers say because PayPal doesn't limit the number of characters in the address form fields, threat actors are able to inject their scam message. PayPal has been made aware of the issue but has yet to comment. U.S. aI Safety Institute Faces Staffing Cuts According to multiple reports, the National Institute of Standards and Technology could soon terminate as many as 500 staffers. Axios reported last week that the USAI Safety Institute and Chips for America, both part of nist, would be gutted by the layoffs, and Bloomberg reported that that some staffers have already received verbal termination notices.
Sean Kelly
The AI Safety Institute was established last.
Cybersecurity Analyst
Year by the Biden administration and tasked with studying AI risks and developing related standards. President Trump repealed that order on his first day in office, and the institute's director departed. Earlier in February, Jason Green Low, executive director of the center for AI Policy, said, quote, these cuts, if confirmed, would severely impact the government's capacity to research and address critical AI safety concerns at a time when such expertise is more vital than ever. End quote.
Sean Kelly
And now I'd like to thank today's episode sponsor conveyor. It's 2025.
Cybersecurity Analyst
This is your sign to get a trust center if you don't already have one, speed up security reviews and reduce the headaches. When you can share one, link to your trust center and let customers download what they need on demand.
Sean Kelly
Trusted by the world's top B2B companies.
Cybersecurity Analyst
Conveyor's enterprise grade trust center is specifically designed to handle multiple products, complex orgs and with AI first, so you can even push your customers to sel serve their own AI answers to questionnaires.
Sean Kelly
Learn more at www.conveyor.com that's c o n v e y-o r.com.
Cybersecurity Analyst
House Republicans Query Public for Ideas on Data Privacy Law On Friday, Brett Guthrie and John Joyce, both part of a Republican working group on data privacy, issued a request for information seeking input from the American public on long awaited national data privacy and security standards. The request includes inqu about personal data collection and use, data use disclosures and what lessons can be learned from privacy frameworks in other countries. It also queries how a comprehensive data privacy law might coexist with other major privacy statutes like hipaa, the Fair Credit Reporting act, and Gramm Leach Bliley. The public have until April 7 to provide their input, which can be done by sending an email to Privacy Working Group, mail.house.gov spylend malware in Google Play Store Predatory loan App malware called Spylend is targeting Android users in India and.
Sean Kelly
Has been downloaded over 100,000 times.
Cybersecurity Analyst
The malware is deployed to user devices by apps that promise quick and easy loans.
Sean Kelly
The apps also claim to be registered.
Cybersecurity Analyst
Non banking financial companies, or NBFCs, which researchers say is untrue. Upon installation, the apps request excessive device permissions, allowing apps to steal user contacts, call logs, SMS messages, photos and device location. The harvested information is then used to harass, extort and blackmail users. Users who suspect their device is infected should remove the apps, immediately, reset permissions, change their bank account passwords and perform a device scan. Users should also consider enabling Google's Play Protect tool, which detects and blocks known predatory apps. EPIRO unveils free scanner to detect malicious code merges Security researchers at EPIRO have released two free open source tools designed to detect and block malicious code before they are added to software projects.
Sean Kelly
The two tools use comprehensive static analysis.
Cybersecurity Analyst
Rule sets for SEMGREP and OpenGREP and leverage a GitHub integrated scanner called Prevent that alerts on suspicious code in pull requests. The researchers say the tools have a minimal false positive detection rate, making them valuable in the real world. Users should use these new tools at their own risk.
Sean Kelly
Google Adds Quantum Resistant Digital Signatures to Cloud KMS Google has revealed plans to.
Cybersecurity Analyst
Implement new post quantum cryptography standards from NIST.
Sean Kelly
The tech giant plans to start by.
Cybersecurity Analyst
Adding the two NIST quantum resistant digital signature algorithms, FIPS 204 and FIPS 205 to its Cloud Key Management Service, or KMS. Google Cloud KMS lets customers manage cryptographic keys throughout the Google Cloud ecosystem. The new POC Digital signature capability is now now available in preview, and Google plans to add support for NIST's Asymmetric Cryptography Standard later this year. And that does it for today's cybersecurity headlines. But we've got a fantastic Super Cyber Friday event set up for this week. This Friday at 1pm Eastern 10am Pacific, we'll be talking about hacking the modern audit, thinking about how to improve quality while reducing cost. We've all got to conduct audits, but we're talking about ways to make it a lot less painful.
Sean Kelly
Head over to our events page@cisoseries.com to register.
Cybersecurity Analyst
Thank you for listening to the podcast that brings you more of the top cyber news stories and more cowbell.
Sean Kelly
I'm Sean Kelly.
CISO Series Host
Cybersecurity headlines are available every weekday. Head to cisoseries.com for the full stories behind the headlines.
Cyber Security Headlines: Episode Summary – $1.5B Bybit Hack, UK E2E Pulled, PayPal Phishing Emails
Released on February 24, 2025 by CISO Series
1. Massive $1.5 Billion Bybit Cryptocurrency Exchange Hack
The episode opens with a grave report on one of the largest cryptocurrency heists to date. Sean Kelly introduces the story as the top cyber news of the day, highlighting the unprecedented scale of the attack.
Incident Details: An anonymous hacker successfully stole approximately $1.46 billion in cryptocurrency from Bybit, a prominent crypto exchange. This incident surpasses the previous record for the largest cryptocurrency hack by nearly double.
Sean Kelly [00:19]: "Crypto Wallet Undoubtedly the top cyber news."
Cybersecurity Analyst [00:19]: "Bybit Crypto exchanges announcement on Friday that an unknown attacker stole over $1.46 billion in crypto from one of its Ethereum cold wallets."
Method of Attack: The attackers executed a sophisticated breach by altering a wallet's transaction quote. They manipulated the signing interface to display the correct address while secretly modifying the underlying smart contract logic.
Aftermath and Response: Crypto fraud investigator Zach xbt revealed that the stolen Ethereum has already been dispersed into 48 different addresses. Despite the significant loss, Bybit CEO Ben Zao assured clients of the platform's security and solvency.
Attribution: Researchers from Arkham Intelligence have linked the Bybit hack to the North Korean Lazarus group, indicating a state-sponsored motive behind the attack.
2. UK Government Demands Withdrawal of iCloud's End-to-End Encryption
In a significant policy shift, Apple has complied with the UK Government’s request to disable end-to-end encryption (E2E) for iCloud services within the United Kingdom.
Policy Change: Apple has removed the option for E2E encryption on iCloud data, including backups, photos, and notes. This decision is in response to the UK Government's Investigatory Powers Act, which seeks backdoor access to encrypted data.
Cybersecurity Analyst [01:26]: "Apple has made iCloud end to end encryption unavailable in the United Kingdom."
Sean Kelly [01:28]: "The move stems from the UK Government's request for encryption backdoor access under its Investigatory Powers Act."
Impact on Services: Despite the removal of E2E encryption for certain iCloud data, Apple's communication services like iMessage, FaceTime, and iCloud Keychain remain protected with end-to-end encryption.
Apple’s Statement: Apple expressed deep disappointment over the UK mandate, emphasizing the critical need for robust data protections amidst rising data breaches and privacy threats.
3. PayPal Phishing Exploits via New Address Feature
A concerning trend has emerged wherein cybercriminals are exploiting PayPal's new address feature to send deceptive phishing emails to users.
Phishing Tactics: Over the past month, PayPal users have reported receiving fraudulent emails claiming the addition of a new address to their accounts. Some of these emails falsely reference unauthorized purchases, such as a "MacBook M4," and provide contact numbers for reporting discrepancies.
Technical Exploitation: Attackers are leveraging the legitimate PayPal mail server through the Serviceaypal.com account to bypass standard email security measures like DKIM checks and spam filters. By injecting malicious content into the address fields, they exploit the lack of character limitations to embed scam messages.
Response and Recommendations: While PayPal has been notified of the issue, they have not yet issued a public statement. Users are advised to remain vigilant, verify the authenticity of emails, and utilize security features like Google's Play Protect to safeguard their accounts.
4. U.S. AI Safety Institute Faces Significant Staffing Reductions
The U.S. National Institute of Standards and Technology (NIST) is reportedly planning to cut up to 500 positions, which would severely impact the AI Safety Institute and related initiatives.
Background: The AI Safety Institute was established in 2024 under the Biden administration to research AI risks and develop safety standards. However, the institute faced challenges when President Trump repealed its founding order, leading to the departure of its director.
Potential Impact: Jason Green Low, executive director of the Center for AI Policy, warned that these layoffs could drastically reduce the government's ability to manage critical AI safety issues at a time when such expertise is increasingly essential.
5. Republican House Members Seek Public Input on Data Privacy Legislation
Republican legislators Brett Guthrie and John Joyce have initiated a consultative process to gather public opinions on establishing national data privacy and security standards.
Legislative Proposal: The working group is soliciting feedback on various aspects, including personal data collection, usage disclosures, and integration with existing privacy laws like HIPAA and the Fair Credit Reporting Act.
Public Engagement: Citizens are encouraged to submit their insights and suggestions by April 7 through the provided contact channels, aiming to shape comprehensive data privacy legislation that harmonizes with international frameworks.
6. Spylend Malware Found in Google Play Store’s Predatory Loan Apps
Android users in India are at risk due to the spread of the Spylend malware, which has infiltrated over 100,000 downloads of loan-related applications on the Google Play Store.
Malware Characteristics: The Spylend malware disguises itself within apps that offer quick loans, falsely claiming affiliation with non-banking financial companies (NBFCs). Upon installation, the malware seeks excessive permissions, enabling it to access sensitive user data such as contacts, call logs, SMS messages, photos, and device location.
User Risk and Mitigation: The harvested data is exploited to harass, extort, and blackmail victims. Users are advised to promptly remove suspicious apps, reset device permissions, change banking passwords, and utilize security tools like Google's Play Protect to detect and block such threats.
7. EPIRO Launches Free Open-Source Tools to Combat Malicious Code
In a proactive move, EPIRO has introduced two free, open-source tools aimed at identifying and preventing the integration of malicious code in software projects.
Tool Features: These tools employ comprehensive static analysis and leverage rule sets for SEMGREP and OpenGREP. Additionally, they integrate with GitHub's Prevent scanner to alert developers about suspicious code during pull requests.
Effectiveness: With a minimal false positive rate, the tools offer practical utility for developers seeking to maintain code integrity. However, users are cautioned to implement these tools with consideration of their specific project environments.
8. Google Enhances Cloud Key Management Service with Quantum-Resistant Signatures
Addressing future security challenges, Google is set to incorporate NIST's post-quantum cryptography standards into its Cloud Key Management Service (KMS).
Implementation Details: Google plans to integrate two NIST-approved quantum-resistant digital signature algorithms, FIPS 204 and FIPS 205, into Cloud KMS. This enhancement aims to future-proof cryptographic security against emerging quantum computing threats.
Availability and Future Plans: The new digital signature capabilities are currently in preview, with broader support for NIST's Asymmetric Cryptography Standard expected later in the year. This upgrade allows customers to manage increasingly secure cryptographic keys within the Google Cloud ecosystem.
Conclusion
This episode of Cyber Security Headlines delivered an in-depth analysis of significant cybersecurity events impacting the global digital landscape. From the alarming scale of the Bybit hack to legislative changes affecting encryption standards in the UK, the discussions underscored the evolving challenges in information security. Additionally, emerging threats like the Spylend malware and proactive measures such as EPIRO’s new tools highlight the ongoing battle between cyber threats and defensive strategies. Finally, Google's advancements in quantum-resistant cryptography reflect the industry's commitment to anticipating and mitigating future risks.
For listeners seeking deeper insights and ongoing updates, further details are available at CISOseries.com.