
Loading summary
Sean Kelly
From the CISO series, it's Cybersecurity headlines. These are the cybersecurity headlines for Wednesday, May 7, 2025. I'm Sean Kelly. Congress challenges Noem over proposed CISA cuts On Tuesday, Homeland Security Secretary Kristi Noem faced tough questioning from members of Congress about the Trump administration's proposal to cut CESA's funding by $491 million as part of their skinny budget. Homeland Security subcommittee chair Mark Amadei said, at a time when government leaders are saying China is getting the better of the US in cyberspace, appropriators need more information on the budget proposal, top panel Democrat Lorne Underwood said to Noem last week. You said we should just wait for the president's grand cyber plan, but you have not waited to erode the department's cyber defense capabilities by removing resources and personnel from CISA and other components, end quote. Noem maintained that instead of censorship, SISA is now focused on securing critical infrastructure. She added that the president's cyber plan would be coming out shortly and that's the president's prerogative, end quote. Texas school district breach impacts over 47,000 people Elvin Independent School District confirmed they suffered a breach back in June of last year that compromised sensitive information belonging to 47,606 individuals. The district began notifying affected people over the weekend that the incident exposed names, Social Security numbers, state issued IDs, credit card and financial account details, as well as medical and health insurance info. The Fogg ransomware gang published the district's name on its leak site last summer, but it remains unclear whether the district paid a ransom. Since then, Fogg has claimed responsibility for 20 confirmed ransomware attacks, 12 of them on educational institutions and an additional 157 unconfirmed incidents. However, the group appears to have sudden gone dark. Last month, NSO group to pay WhatsApp $167 million in damages on Tuesday, after a five year legal battle, a jury ruled that the NSO group must pay the meta owned platform $167 million in punitive damages and around $444,000 in compensatory damages. WhatsApp accused NSO Group of exploiting an audio calling vulnerability in the chat app to target around 1400 people, including dissidents, human and journalists. WhatsApp was seeking more than $400,000 in compensatory damages based on the time its employees spent on investigation and remediation of the attacks. A WhatsApp spokesperson hailed the historic ruling as the first victory against illegal spyware that threatens the safety and privacy of everyone. NSO Group said it plans to carefully review the details of the verdict and left the door open for an appeal. NSA to cut up to 2,000 civilian roles the National Security Agency has been directed to cut 8% of civilian employees as part of the Trump administration's push to reduce the size of the federal government. The NSA's staffing cuts will likely impact roles ranging from administrative staff to defense and offensive cybersecurity operators. The NSA's total number of non military personnel is classified, but anonymous sources told the record that between 1,500 and 2,000 positions are expected to be cut. The source has added that currently the agency has until end of this year to make the cuts, and now we'd like to thank today's episode sponsor Threat Locker Threat Locker is a global leader in zero trust endpoint security, offering cyber security controls to protect businesses from zero day attacks and ransomware. Threat Locker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit threatlocker.com CISO that's T-H-R-E-A-T L O C K E R.com CISO easily exploitable langflow flaw requires immediate patching CISA has added a critical authentication flaw found in the open source Langflow platform to its known exploited vulnerabilities catalog. Langflow is a python based web application that allows users to build AI driven agents and workflows. The issue allows remote code injection and affects Langflow versions. Prior to 1.3.0 horizon 3AI who discovered the flaw said it's easily exploitable and the available patch fails to fully address the issue. The researchers encouraged users to update to the latest Langflow version to fully mitigate the risk of exploitation. Hackers exploit IoT devices to deploy Mirai Botnet Threat actors have been observed actively exploiting security flaws in two different Internet of Things devices to corral them into the Mirai botnet for conducting distributed denial of Service attacks. The first device is an end of life GeoVision surveillance device, which can be exploited via two critical severity operating system command injection flaws. These issues could be used by threat actors to execute arbitrary system commands. That disclosure comes as researchers warned of an act of exploitation path traversal flaw in Samsung Magic info 9 digital signage server. That issue could enable an attacker to write arbitrary files as system authority. While Samsung addressed that issue back in August of last year, it has since been weaponized by attackers following the release of a proof of concept exploit on April 30th. New investment scams use Facebook ads and filter victims Cybersecurity researchers have identified two threat actors codenamed Reckless Rabbit and Ruthless Rabbit, orchestrating investment scams through spoofed celebrity endorsements on Facebook. The platforms use web forms to collect user data, including user names, phone numbers, email addresses, and also offer the ability to auto generate passwords. The next phase of the attack uses validation tools to filter out traffic from certain countries and ensures that the contact info provided is legitimate. Validated victims are routed through a traffic distribution system or tds, for cloaking to a scam platform where they are either coaxed into making high return investments or where they are instructed to wait for a representative to call them. Reckless Rabbit has been creating domains since at least April of 2024, primarily targeting users in Russia, Romania and Poland. Meanwhile, Ruthless Rabbit has been actively targeting European users since at leave November of 2022. Magento backdoor hid for 6 years before activation it took 6 years for a backdoor hidden in widely used Magento online store extensions to finally reveal itself on April 20th. The malware finally began affecting hundreds of digital storefronts. Security Firm Sansec uncovered 21 modules published between 2019 and 2022, which share malicious logic hidden in PHP files. Once activated, the backdoor runs a remote payload, enabling attackers to deploy Magecart style skimming scripts in customer browsers. Sansec estimates that between 500 and 1,000 stores are running the backdoored software, including a $40 billion multinational. The researchers said it is rare that a backdoor remains undetected for six years, but it is even stranger that actual abuse has only started now, end quote. And that does it for today's cybersecurity headlines. But make sure you check out our new episode of Security. You should know it just dropped today. And we learned from Threat Locker what they're doing to help improve the drudgery that is patch management. You can look for the show wherever you get your podcasts or head over to cisoseries.com thank you for listening to the podcast that brings you more of the top cyber news stories and more cowbell. I'm Sean Kelly. Cybersecurity headlines are available every weekday. Head to cisoseries.com for the full stories behind the headline.
Cyber Security Headlines: Detailed Summary of May 7, 2025 Episode
Hosted by Sean Kelly from the CISO Series
In the opening segment, Sean Kelly discusses the intense scrutiny Congress has placed on Homeland Security Secretary Kristi Noem regarding the Trump administration's proposal to reduce the Cybersecurity and Infrastructure Security Agency (CISA) funding by $491 million. This reduction is part of the broader "skinny budget" initiative aimed at shrinking the federal government.
Key Points:
Congressional Concerns: The Homeland Security subcommittee, led by Chair Mark Amadei, expressed alarm over the proposed cuts, especially amid growing concerns about China surpassing the U.S. in cyberspace.
"At a time when government leaders are saying China is getting the better of the US in cyberspace, appropriators need more information on the budget proposal."
— Mark Amadei ([02:15])
Democratic Opposition: Democrat Lorne Underwood criticized Noem for weakening cyber defense capabilities ahead of the release of the president’s grand cyber plan.
"You have not waited to erode the department's cyber defense capabilities by removing resources and personnel from CISA and other components."
— Lorne Underwood ([03:05])
Noem's Defense: Secretary Noem defended the administration’s stance, emphasizing a shift from censorship to securing critical infrastructure and promising the forthcoming cyber strategy.
"The president's cyber plan would be coming out shortly and that's the president's prerogative."
— Kristi Noem ([04:10])
Insights:
Sean Kelly reports on a significant cybersecurity incident involving the Elvin Independent School District in Texas, which revealed a breach compromising personal information of over 47,000 individuals.
Key Points:
Breach Details: The district confirmed the breach occurred in June of the previous year, exposing sensitive data including Social Security numbers, state IDs, credit card information, and medical records.
"The incident exposed names, Social Security numbers, state issued IDs, credit card and financial account details, as well as medical and health insurance info."
— Sean Kelly ([05:30])
Ransomware Involvement: The Fogg ransomware gang was identified as responsible, having published the district’s name on their leak site. However, it remains uncertain whether a ransom was paid.
"Fogg has claimed responsibility for 20 confirmed ransomware attacks, 12 of them on educational institutions and an additional 157 unconfirmed incidents."
— Sean Kelly ([06:45])
Current Status: Since the breach, Fogg appears to have ceased activity, raising questions about their operational status.
Insights:
A landmark legal decision was covered, where the NSO Group was mandated to pay substantial damages to WhatsApp following allegations of exploiting vulnerabilities to deploy spyware.
Key Points:
Court Ruling: After a five-year legal battle, a jury concluded that NSO Group must pay WhatsApp $167 million in punitive damages and approximately $444,000 in compensatory damages.
"A jury ruled that the NSO group must pay the meta owned platform $167 million in punitive damages and around $444,000 in compensatory damages."
— Sean Kelly ([08:20])
WhatsApp's Accusations: The company alleged that NSO exploited an audio calling vulnerability to target around 1,400 individuals, including dissidents, human rights activists, and journalists.
Company Statements: A WhatsApp spokesperson hailed the decision as a historic victory against illegal spyware.
"This is the first victory against illegal spyware that threatens the safety and privacy of everyone."
— WhatsApp Spokesperson ([09:10])
NSO Group's Response: NSO expressed intentions to review the verdict and consider an appeal.
Insights:
The National Security Agency (NSA) is slated to reduce its civilian workforce by up to 8%, translating to approximately 1,500 to 2,000 positions, as part of broader federal government downsizing efforts.
Key Points:
Scope of Cuts: The reduction will affect a range of roles from administrative positions to critical defense and offensive cybersecurity operators.
"The NSA's staffing cuts will likely impact roles ranging from administrative staff to defense and offensive cybersecurity operators."
— Unnamed Source ([10:50])
Timeline: The agency has until the end of the year to implement these cuts.
Confidentiality: The exact number of non-military personnel at the NSA remains classified, with estimates provided by anonymous sources.
Insights:
CISA has identified a severe authentication vulnerability in the open-source Langflow platform, necessitating immediate action from users.
Key Points:
Vulnerability Details: The flaw allows for remote code injection, affecting Langflow versions prior to 1.3.0.
"The issue allows remote code injection and affects Langflow versions prior to 1.3.0."
— Sean Kelly ([12:30])
Current Status: While a patch has been released, it does not fully mitigate the vulnerability. Researchers advise updating to the latest version to ensure complete protection.
"The available patch fails to fully address the issue. The researchers encouraged users to update to the latest Langflow version to fully mitigate the risk of exploitation."
— Horizon 3AI ([13:15])
Insights:
Threat actors are actively targeting vulnerabilities in IoT devices to incorporate them into the Mirai botnet, facilitating large-scale Distributed Denial of Service (DDoS) attacks.
Key Points:
Targeted Devices:
An end-of-life GeoVision surveillance device is being exploited through two critical command injection flaws.
"These issues could be used by threat actors to execute arbitrary system commands."
— Sean Kelly ([14:45])
Samsung's Magic Info 9 digital signage server has a path traversal flaw that was weaponized after a proof-of-concept was released on April 30th.
"An attacker to write arbitrary files as system authority."
— Sean Kelly ([15:30])
Historical Context: Although Samsung addressed the Magic Info issue in August of the previous year, the release of an exploit has led to renewed attacks.
Insights:
Cybersecurity researchers have uncovered sophisticated investment scams conducted through Facebook, orchestrated by two threat actors known as Reckless Rabbit and Ruthless Rabbit.
Key Points:
Operational Tactics:
"Reckless Rabbit has been creating domains since at least April of 2024, primarily targeting users in Russia, Romania and Poland."
— Sean Kelly ([16:40])
"Ruthless Rabbit has been actively targeting European users since at least November of 2022."
— Sean Kelly ([17:05])
Stages of Attack:
Insights:
A hidden backdoor within Magento online store extensions has been activated after six years of undetected presence, affecting hundreds of digital storefronts.
Key Points:
Discovery: Security firm Sansec identified malicious logic in 21 Magento modules published between 2019 and 2022, which went unnoticed until April 20th.
"Sansec uncovered 21 modules... which share malicious logic hidden in PHP files."
— Sean Kelly ([18:25])
Functionality: Once activated, the backdoor allows attackers to deploy Magecart-style skimming scripts, targeting customer browsers to steal payment information.
Impact: An estimated 500 to 1,000 stores, including a $40 billion multinational company, were running the compromised software.
"The researchers said it is rare that a backdoor remains undetected for six years, but it is even stranger that actual abuse has only started now."
— Sean Kelly ([19:10])
Insights:
In this episode of Cyber Security Headlines, Sean Kelly provided a comprehensive overview of pressing cybersecurity issues ranging from governmental budgetary decisions impacting national defense capabilities to significant breaches and sophisticated cyber-attacks affecting various sectors. Notable legal victories against spyware operators and revelations of long-hidden vulnerabilities emphasize the evolving landscape of cyber threats. Additionally, the discussion on workforce reductions at the NSA and emerging scam tactics on social media platforms highlight the multifaceted challenges in maintaining cybersecurity resilience.
For more in-depth stories and updates on these headlines, listeners are encouraged to visit CISOseries.com.
This summary encapsulates the key discussions and insights from the May 7, 2025 episode of "Cyber Security Headlines" by CISO Series, ensuring an informative overview for those who have not tuned in.