
Loading summary
A
From the CISO series, it's Cybersecurity headlines.
B
These are the cybersecurity headlines for Wednesday, March 5, 2025. I'm Sarah Lane. In today's cybersecurity news, Apple is suing the UK government over its demands to weaken icloud encryption under the Investigatory Powers Act. The UK wants a backdoor for law enforcement and and Apple argues that that would compromise global security. Apple previously pulled its Advanced Data protection feature from the UK and the battle has drawn criticism from some US officials. The case could set a precedent for encryption policies worldwide, with major implications for user privacy and tech companies. Broadcom is telling VMware customers to patch three actively exploited zero day vulnerabilities affecting ESXi, Workstation and Fusion. These flaws allow attackers with admin access to escape virtual machines and compromise the underlying host, which can lead to data exfiltration, malware deployment and service disruption. CISA has added these vulnerabilities to its exploited list, requiring federal agencies to patch by March 25th. Mozilla's recent changes to Firefox's privacy policies have sparked backlash, with users upset over a new terms update that seemingly grants Mozilla broad rights over user data. The company removed its previous claim that it never sells data, fueling concerns that Firefox could be monetizing user information or using it for AI training. Mozilla says it's just legal wording, not a policy shift. Users can control their Firefox settings, switch to alternatives like Brave or Tor, or use privacy focused Firefox variants like Waterfox or Librewolf. Reuter sources say that some U.S. government workers with top security clearances were fired without standard exit briefings, which typically includes reminders about non disclosure agreements and instructions on handling foreign adversary approaches. The layoffs were overseen by the Department of Government Efficiency. Former security officials warned this poses a counterintelligence risk, especially for those with knowledge of nuclear security. A DOA spokesperson says steps are being taken to remind dismissed employees of their obligations, but experts call the lack of debriefings a a serious security concern. Thank you to this Week's episode sponsor ThreatLocker. ThreatLocker is a global leader in zero trust endpoint security, offering cybersecurity controls to protect businesses from zero day attacks and ransomware. ThreatLocker operates with the default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit threatlocker.com the Electronic Frontier foundation launched an open source tool called Ray Hunter, designed to detect cell site simulators or devices that mimic cell towers to track phones and potentially intercept data. Ray Hunter runs on a $20 orbic mobile hotspot and monitors control traffic to identify suspicious activity. Like force downgrades to vulnerable 2G networks, users get alerts for anomalies and can review logs. The EFF expects Ray Hunter to help build defenses against CSS and inform legal efforts to regulate their use. Amnesty International reports that Serbian police used a cellebrite mobile extraction tool and an exploit chain to hack a student activist phone. The attack used Android USB driver vulnerabilities and let authorities gain root access and possibly install spyware. Celebrate claims its products are for lawful investigations but has stopped supplying certain customers. Some experts debate the ethical responsibility of vendors providing these kinds of tools, with calls for stricter SafeGuards and accountability. FaceTech has launched UrenCoder, which is software that lets biometric ID issuers create ur codes digitally signed face data stored on a user's device for secure identity verification. The system promises privacy while letting authorities like DMVs, passport offices and employers issue biometric credentials. UR codes use cryptographic signatures to prevent tampering and can be scanned on a mobile device or a webcam. FaceTech offers a free license for governments and nonprofits, with commercial use available through partnerships. Developer Access is now open, with additional software components rolling out soon. Nokia Researchers have discovered 1111 bottom infecting more than 86,000 IoT devices like security cameras and NVRs for DDoS attacks, the botnet is loosely linked to Iran and targeted telecom providers and gaming servers, reaching attack volumes of hundreds of millions of packets per second, spreading through brute force attacks on weak admin credentials and scans for exposed telnet or SSH ports. Security researchers say that blocking associated IPs, updating firmware, disabling unnecessary remote access, and changing default credentials is the way to mitigate risk. Palo Alto Networks Unit 42 reports that a threat actor known as Java Ghost is exploiting misconfigured AWS environments to steal access keys and send phishing emails that bypass security filters. Java Ghost has been scanning for exposed credentials in public files, gaining unauthorized access and avoiding detection by sidestepping common AWS tracking methods since 2022. The group then apparently uses compromised AWS Simple Email Service accounts to send phishing messages, making them seem legitimate. Remember to subscribe to the CISO Series podcast on YouTube. We stream our Weekend Review show on our channel every Friday at 3:30pm Eastern Time. Plus, we publish original interviews, demos and segments from our other shows. If that sounds good to you, subscribe to our channel on YouTube.
A
Cybersecurity headlines are available every weekday. Head to CISoseries.com for the full stories behind the headlines.
B
I'm Sarah Lane reporting for the CISO series. Talk to you next time.
Podcast Summary: Cyber Security Headlines
Hosted by CISO Series
Episode: Apple vs UK Encryption Backdoor, VMware Bugs Allow Sandbox Escape, JavaGhost Targets AWS
Release Date: March 5, 2025
In a significant legal battle, Apple has initiated a lawsuit against the UK government in response to demands for weakening iCloud encryption under the Investigatory Powers Act. The British authorities are seeking the establishment of a backdoor to facilitate law enforcement investigations, a move Apple argues would undermine global security standards.
Sarah Lane highlights, “Apple is suing the UK government over its demands to weaken iCloud encryption under the Investigatory Powers Act” ([00:07]). Apple had previously withdrawn its Advanced Data Protection feature from the UK, intensifying the dispute. This case is poised to set a global precedent for encryption policies, potentially impacting user privacy and the operational frameworks of major tech companies worldwide. The controversy has also attracted criticism from some U.S. officials, emphasizing the international ramifications of this legal confrontation.
Broadcom has issued urgent warnings to VMware customers about three actively exploited zero-day vulnerabilities affecting VMware ESXi, Workstation, and Fusion. These critical flaws enable attackers with administrative access to escape virtual machines (VMs) and compromise the underlying host systems. The potential consequences include data exfiltration, malware deployment, and widespread service disruptions.
As Sarah Lane states, “These flaws allow attackers with admin access to escape virtual machines and compromise the underlying host” ([00:07]). The Cybersecurity and Infrastructure Security Agency (CISA) has classified these vulnerabilities as exploited, mandating that federal agencies apply patches by March 25th to mitigate the risks. This situation underscores the ongoing challenges in securing virtual environments against sophisticated threats.
Mozilla’s recent amendments to Firefox’s privacy policies have sparked significant user backlash. The updated terms suggest a shift in how user data is handled, with concerns that Mozilla may begin monetizing user information or utilizing it for AI training, contrary to their previous stance of never selling data.
Sarah Lane explains, “The company removed its previous claim that it never sells data, fueling concerns that Firefox could be monetizing user information or using it for AI training” ([00:07]). Mozilla has responded by asserting that the changes are purely in legal wording and do not reflect a policy shift. Users are encouraged to adjust their Firefox settings, explore alternative browsers like Brave or Tor, or switch to privacy-focused variants such as Waterfox or Librewolf to maintain their desired level of privacy.
Reuters has reported that several U.S. government employees with top security clearances were terminated without undergoing the standard exit briefings. These briefings typically include critical information about non-disclosure agreements and protocols for managing foreign adversary approaches.
Sarah Lane notes, “Former security officials warned this poses a counterintelligence risk, especially for those with knowledge of nuclear security” ([00:07]). The Department of Government Efficiency was responsible for overseeing these layoffs. A spokesperson from the department mentioned that steps are being taken to remind dismissed employees of their ongoing obligations. However, experts have raised alarms about the potential counterintelligence risks associated with the lack of proper debriefings, emphasizing the importance of comprehensive exit procedures in safeguarding national security.
The Electronic Frontier Foundation (EFF) has unveiled an open-source tool named Ray Hunter, designed to detect cell site simulators (CSS) or devices that imitate cell towers to track mobile phones and intercept data. Ray Hunter operates on an affordable $20 Orbic mobile hotspot and continuously monitors control traffic to identify any suspicious activities indicative of CSS.
According to Sarah Lane, “Ray Hunter runs on a $20 Orbic mobile hotspot and monitors control traffic to identify suspicious activity” ([00:07]). The tool provides users with alerts for anomalies similar to force downgrades to vulnerable 2G networks and allows them to review detailed logs. EFF anticipates that Ray Hunter will enhance defenses against CSS attacks and support ongoing legal efforts to regulate the use of such surveillance technologies.
Amnesty International has revealed that Serbian police employed Cellebrite’s mobile extraction tool alongside exploiting Android USB driver vulnerabilities to hack into the phone of a student activist. This sophisticated attack granted authorities root access, potentially allowing the installation of spyware on the device.
Sarah Lane reports, “Amnesty International reports that Serbian police used a Cellebrite mobile extraction tool and an exploit chain to hack a student activist phone” ([00:07]). While Celebrate, the company behind Cellebrite, maintains that their tools are intended for lawful investigations, they have ceased supplying their technology to certain customers amid growing ethical concerns. This incident has ignited debates among experts regarding the ethical responsibilities of vendors providing such surveillance tools and the necessity for stricter safeguards and accountability measures to prevent misuse.
FaceTech has launched UrenCoder, a software solution that enables biometric ID issuers to create digitally signed UR codes. These codes store face data securely on a user’s device, facilitating robust identity verification while preserving privacy.
Sarah Lane explains, “UR codes use cryptographic signatures to prevent tampering and can be scanned on a mobile device or a webcam” ([00:07]). UrenCoder is designed for use by authorities such as Department of Motor Vehicles (DMVs), passport offices, and employers to issue biometric credentials securely. FaceTech is offering free licenses to government entities and nonprofits, with commercial licenses available through partnerships. Additionally, developer access to UrenCoder is now open, with plans to release additional software components in the near future.
Nokia researchers have uncovered a botnet named "1111" that has compromised over 86,000 Internet of Things (IoT) devices, including security cameras and Network Video Recorders (NVRs). This botnet is believed to be loosely associated with Iran and primarily targets telecom providers and gaming servers, achieving attack volumes reaching hundreds of millions of packets per second.
As detailed by Sarah Lane, “Nokia Researchers have discovered 1111 botnet infecting more than 86,000 IoT devices... spreading through brute force attacks on weak admin credentials and scans for exposed telnet or SSH ports” ([00:07]). Mitigation strategies recommended by security researchers include blocking associated IP addresses, updating device firmware, disabling unnecessary remote access services, and changing default administrative credentials to secure devices against such large-scale botnet attacks.
Palo Alto Networks’ Unit 42 has identified a threat actor known as JavaGhost that is actively exploiting misconfigured Amazon Web Services (AWS) environments. JavaGhost targets exposed credentials in public files to gain unauthorized access, subsequently evading detection by traditional AWS tracking methods.
Sarah Lane remarks, “Java Ghost has been scanning for exposed credentials in public files, gaining unauthorized access and avoiding detection by sidestepping common AWS tracking methods since 2022” ([00:07]). Once inside, JavaGhost leverages compromised AWS Simple Email Service (SES) accounts to send phishing emails that appear legitimate, thereby bypassing security filters. This tactic increases the likelihood of credential theft and phishing success, posing significant risks to organizations utilizing AWS services. Unit 42 advises organizations to secure their AWS credentials, monitor for unusual activities, and implement robust security practices to defend against such sophisticated exploits.
For a deeper dive into each of these stories and more, visit CISOseries.com.