
Loading summary
Unknown Host
From the CISO series It's Cybersecurity Headlines.
Rich Stroffelino
These are the cybersecurity headlines for Thursday, May 15, 2025. I'm Rich Stroffelino Steel Producer Disrupted by.
Unknown Contributor
Cyber Attack Nucor Corporation, the largest steel producer in the US disclosed in an 8K filing with the US securities and Exchange Commission that it suffered a cyber attack involving unauthorized third party access to certain information technology systems. No other information on date, threat actor or the type of attack was disclosed. The attack halted production at several locations, although the company began slowly restarting operations. No threat group has taken credit for the attack so far.
Rich Stroffelino
European Vulnerability Database is Online the European.
Unknown Contributor
Union Agency for Cybersecurity, or ANISA, announced.
Rich Stroffelino
In June 2024 that it would start work on the database as part of.
Unknown Contributor
The EU's Network and Information Security 2 directive. A closed beta for the EUVD rolled out last month. Now a full version is available online. Like the US Government's National Vulnerability Database, the EUVD will identify disclosed vulnerabilities. These vulnerabilities will carry Standard CVE assigned IDs as well as EUVD identifiers. It features dashboards for critical and actively exploited vulnerabilities. The EUVD claims near real time updates.
Rich Stroffelino
Sourced from open source databases, vendors, vendor.
Unknown Contributor
Guidelines and national advisories. CISA pauses advisory overhaul the U.S. cybersecurity and Infrastructure Security Agency announced on May 13 that it planned to stop publishing standard updates on its cybersecurity alerts and advisory site and would instead shift to publishing advisories and other updates through either email or social media. This would end the ability for professionals to subscribe to alerts through rss. The agency framed the overhaul as a way to prioritize urgent alerts. However, following a flurry of feedback on May 14, the agency said, we have paused immediate changes while we reassess the best approach to sharing with our stakeholders. Australian Human Rights Commission leaks data the AHRC is an independent statutory body created by the Australian government that receives complaints about human rights abuses. The organization announced that six hundred and seventy documents were exposed online from April 3 through May 5, 2025 and indexed by search engines.
Rich Stroffelino
These documents contain complaint web form content.
Unknown Contributor
With private personal information as well as submissions to the National Anti Racism Framework paper. The AHRC said the incident did not represent a malicious external attack. It temporarily disabled all web forms to prevent subsequent issues due to a misconfiguration and requested the indexed search engines remove the.
Rich Stroffelino
And now thanks to our episode sponsor Vanta.
Unknown Contributor
Do you know the status of your compliance controls right now?
Rich Stroffelino
Like right now we know that real time visibility is critical for security, but when it comes to our GRC programs.
Unknown Contributor
We rely on point in time checks.
Rich Stroffelino
But more than 9,000 companies have continuous.
Unknown Contributor
Visibility into their controls with Vanta. Vanta brings automation to evidence collection across.
Rich Stroffelino
Over 35 frameworks like SoC2 and ISO2701.
Unknown Contributor
They also centralize key workflows like policies.
Rich Stroffelino
Access reviews and reporting, and helps you get security questionnaires done five times faster with AI.
Unknown Contributor
Now that's a new way to GRC.
Rich Stroffelino
Get started at vanta.com headlines that's V A N T A dot com headlines.
Unknown Contributor
Advanced protection comes to Android In 2017, Google debuted an advanced protection feature for.
Rich Stroffelino
Google accounts, giving further layers of security.
Unknown Contributor
For particularly at risk users like journalists, public figures and dissidents. Now the company is extending this feature to phones running Android 16. Similar to Apple's lockdown mode on iOS, this blocks connections to legacy 2G data networks and disables JavaScript optimizations in the default browser. It also offers intrusion logging, which are stored end to end encrypted in the cloud to provide indelible logs that will survive even if a phone or a Google account is compromised. Google will also offer an API for third party app integration with advanced protection.
Rich Stroffelino
New Picks for US Cyber Command coming Soon Multiple military, civilian and congressional sources.
Unknown Contributor
Told the Record that the Trump administration will name a candidate for the vacant role of National Security Agency Deputy Director before Memorial Day. US Cyber Command and NSA Head General Timothy Hoff and Deputy NSA Chief Wendy Noble were dismissed last month. This comes as the administration investigates whether to end the so called dual hat leadership structure of the NSA and US Cyber Command.
Rich Stroffelino
Restructuring the leadership requires sign off from.
Unknown Contributor
Both the Secretary of Defense and the Joint Chiefs Chairman that the move won't hinder Cyber Command.
Rich Stroffelino
Exposing North Korean IT workers at scale.
Unknown Contributor
Wired shared a report from Dtech Systems that includes a list of over 1,000 email addresses identified as linked to North Korean IT worker activity.
Rich Stroffelino
Their report profiles two members of a.
Unknown Contributor
Group of North Korean developers now based.
Rich Stroffelino
Out of Russia, using the Personas Naoki.
Unknown Contributor
Murano and Jensen Collins. This group of developers generally worked for cryptocurrency companies including Coinbase, creating fake job applications and searching for accomplices.
Rich Stroffelino
These fake IT workers are generally required.
Unknown Contributor
To hit specific income quotas with evidence of military personnel directly monitoring communications so they don't become defectors. Evanti patches actively exploited EPMM 0 days. The company issued patches for vulnerabilities allowing for authentication bypasses and remote code execution, impacting two open source libraries. It uses in its endpoint Manager mobile solution. In its patch disclosure, the company saw a very limited number of customers impacted by these vulnerabilities. Filtering access to the API using ACLS can help significantly reduce the risk of.
Rich Stroffelino
Compromise until a patch can be deployed.
Unknown Contributor
Avanti will also work with maintainers of the impacted libraries to see if any additional CVEs should be assigned Microsoft Extends.
Rich Stroffelino
Office Security Support earlier this year, Microsoft.
Unknown Contributor
Announced it would stop supporting Office apps on Windows 10 when the OS reaches the end of support on October 14, 2025. Now, Microsoft says it will extend support for Office Security updates for an additional.
Rich Stroffelino
Three years to help maintain security while.
Unknown Contributor
You Transition to Windows 11. Microsoft still recommends businesses update to Windows.
Rich Stroffelino
11 well before that deadline to avoid.
Unknown Contributor
Performance and reliability issues over time.
Rich Stroffelino
Over the past decade, the CISO role.
Unknown Contributor
Has evolved into a seemingly impossible job.
Rich Stroffelino
But someone still has to do it.
Unknown Contributor
How must CISOs accept the Sisyphean role?
Rich Stroffelino
That's what we're trying to figure out on this week's episode of Defense in Depth. We just dropped our new episode, the CISO's job is impossible, over@cisoseries.com this morning. Look for it wherever you get your podcasts. Reporting for the CISO series, I'm Rich Stroffelino, reminding you to have a super sparkly day.
Unknown Host
Cybersecurity headlines are available every weekday. Head to cisoseries.com for the full stories behind the headlines.
Cyber Security Headlines - Episode Summary
Podcast Information:
In this episode of Cyber Security Headlines, host Rich Stroffelino delivers an in-depth analysis of the latest developments in the information security landscape. Covering significant events such as the cyber attack on a major steel producer, the launch of the European Vulnerability Database (EUVD), and the recent advisory overhaul by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), this episode provides valuable insights for cybersecurity professionals and enthusiasts alike.
At [00:15], Rich introduces the first major headline: a cyber attack targeting Nucor Corporation, the largest steel producer in the United States. The attacker gained unauthorized access to certain of the company’s information technology systems, as disclosed in an 8-K filing with the U.S. Securities and Exchange Commission.
Key Points:
Notable Quote:
"No threat group has taken credit for the attack so far." — Unknown Contributor [00:46]
Moving to cybersecurity infrastructure, at [00:46], Rich discusses the European Union’s latest initiative—the European Vulnerability Database (EUVD).
Key Points:
Notable Quote:
"The EUVD claims near real-time updates." — Unknown Contributor [00:57]
At [01:28], Rich covers significant changes proposed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) regarding its advisory dissemination methods.
Key Points:
Notable Quote:
"We have paused immediate changes while we reassess the best approach to sharing with our stakeholders." — CISA Representative [01:28]
Transitioning to international news at [02:34], Rich reports on a data breach involving the Australian Human Rights Commission (AHRC).
Key Points:
Notable Quote:
"This incident did not represent a malicious external attack." — AHRC Representative [02:36]
At [02:58], the episode includes a sponsored segment by Vanta, a platform dedicated to automating compliance and governance, risk, and compliance (GRC) programs.
Key Points:
Call to Action:
"Get started at vanta.com/headlines." — Vanta Representative [03:43]
At [03:52], Rich delves into Google's enhancements to its security features for Android devices.
Key Points:
Comparison: These features are akin to Apple's lockdown mode on iOS, offering similar layers of security for enhanced protection.
Notable Quote:
"This blocks connections to legacy 2G data networks and disables JavaScript optimizations in the default browser." — Unknown Contributor [03:58]
At [04:37], the focus shifts to internal developments within the U.S. military cybersecurity apparatus.
Key Points:
Notable Quote:
"Restructuring the leadership requires sign off from both the Secretary of Defense and the Joint Chiefs Chairman that the move won't hinder Cyber Command." — Unknown Contributor [04:43]
At [05:07], Rich discusses a significant report by Wired that sheds light on North Korean IT operations.
Key Points:
Notable Quote:
"These fake IT workers are generally required to hit specific income quotas with evidence of military personnel directly monitoring communications so they don't become defectors." — Unknown Contributor [05:31]
At [05:47], the episode covers recent security updates from Evanti, a cybersecurity firm.
Key Points:
Notable Quote:
"Filtering access to the API using ACLs can help significantly reduce the risk of compromise until a patch can be deployed." — Unknown Contributor [05:50]
At [06:27], Rich informs listeners about Microsoft's latest updates regarding Office application support.
Key Points:
Notable Quote:
"Microsoft still recommends businesses update to Windows 11 well before that deadline to avoid performance and reliability issues over time." — Unknown Contributor [06:56]
Concluding the episode at [07:11], Rich reflects on the challenges facing Chief Information Security Officers (CISOs) in the modern cybersecurity landscape.
Key Points:
Notable Quote:
"The CISO role has evolved into a seemingly impossible job, but someone still has to do it." — Rich Stroffelino [07:11]
Rich wraps up the episode by reminding listeners of the continuous availability of Cybersecurity Headlines every weekday and directs them to cisoseries.com for comprehensive stories behind the headlines.
Final Note: This summary encapsulates the key discussions and insights shared in the May 15, 2025 episode of Cyber Security Headlines by the CISO Series. For more detailed information and ongoing updates, listeners are encouraged to visit CISOseries.com.