
Loading summary
A
From the CISO series. It's Cybersecurity Headlines.
B
These are the cybersecurity headlines for Monday, November 24, 2025. I'm Steve Prentiss. CrowdStrike catches insider feeding information to hackers.
C
CrowdStrike has now confirmed that an insider.
B
Shared screenshots taken on internal systems, this after the images were leaked on Telegram.
C
CrowdStrike emphasized that its systems were not.
B
Breached as a result of this incident and that customers data was not compromised.
C
They did not, however, specify the threat.
B
Group responsible for the image taking incident. Spanish airline Iberia suffers breach and data.
C
Leak the company says this occurred as.
B
A result of unauthorized access to a supplier's systems. The compromised data is alleged to consist.
C
Of names and surnames of customers, along with the email address and Iberia Club.
B
Loyalty card identification numbers.
C
The airline says customers Iberia account login credentials and passwords were not compromised, nor.
B
Was any banking or payment card information accessed.
C
The company is warning customers to be.
B
Vigilant for suspicious communications. AI is too risky to insure, say insurers.
C
According to the Financial Times news outlet, major insurers such as AIG, Great American and W.R. barclay are asking U.S. regulators.
B
For permission to exclude AI related liabilities from corporate policies.
C
These liabilities are described by one underwriter.
B
As too much of a black box. The fear, they say, is of thousands of simultaneous claims when a widely used AI model makes a mistake. The article quotes one executive from the insurance company Aon saying insurers can handle a $400 million loss to one company. What they can't handle is an agentic AI mishap that triggers 10,000 losses at once. The Financial Times article cites examples of the types of events that are spooking insurers. These include Google's AI Overview falsely accusing a solar company of legal Troubles, triggering a $110 million lawsuit back in March, Air Canada being forced to honour a discount invented by its chatbot and the infamous $25 million deepfake heist that happened to the London based design engineering firm Arup last year in Hong Kong. Salesforce warns of data breach after third party activity this warning was released last.
C
Wednesday evening after the company discovered unusual activity related to a third party application called Gainsight, a platform designed to help.
B
Customers track sales data and customer information.
C
Salesforce emphasized that there was no indication.
B
That the issue resulted from any vulnerability in the Salesforce platform.
C
Instead, the company says the activity appears.
B
To be related to the app's external connection to Salesforce.
C
Although the actors behind this have not yet been confirmed, it appears that this.
B
May be yet another attack by affiliates of the Scattered Spider Shiny Hunters group.
C
Huge thanks to our sponsor KnowBe4. Cybersecurity isn't just a tech problem, it's a human one. That's why KnowBe4's human risk management platform allows you to measure, quantify and actually.
B
Reduce human risk across your organization.
C
With AI powered risk scoring and automated coaching and reporting, HRM helps you surface your highest risk users and reduce the.
B
Risk of data breaches and cyber attacks. Proactively ready to move from awareness to action?
C
Request a demo of hrm today@knowbefore.com that.
B
Is knowbe and the number4.com SonicWall identifies SSL VPN Flaw Allowing Firewall Crashes this is a high severity buffer overflow flaw in Sonic OS SSL VPN that lets attackers crash Gen7 and Gen8 firewalls with a CVE number and a CVSS score of 7.5.
C
The issue comes from a stack based.
B
Buffer overflow that can trigger a denial of service condition on vulnerable devices. SonicWall is urging all customers to apply patches immediately. The flaw only impacts the Sonic OS SSL VPN interface or service if enabled.
C
On the firewall and SonicWall is not.
B
Aware of attacks in the wild. Exploiting this vulnerability Cox Enterprises Discloses Oracle E Business Suite Data Breach the telecommunications.
C
Giant is notifying impacted individuals of a.
B
Data breach that exposed their personal data. The hackers breached the company network in August after exploiting a zero day flaw in Oracle E Business Suite. The company, however, did not detect the intrusion until late September following an internal investigation. No attackers have been named, but the Clop Ransomware gang has taken credit for exploiting A CVE numbered zero day vulnerability long before Oracle released a patch on October 5th. Cox Enterprises has not specified what types of data were exposed. Law enforcement agencies in Oklahoma and Massachusetts respond to cyber incidents. The Cleveland County Sheriff's Office, just south of Oklahoma City, announced on Thursday that.
C
It was facing a ransomware attack affecting.
B
Parts of its internal computer system.
C
Officials confirmed that there was no interruption.
B
To public safety services or 911 service. Meanwhile, the Massachusetts city of Attleborough also reported a cyber attack impacting the local government and the police department, affecting phone lines to the city of Attleborough and Attleborough Police Department, as well as municipal email service. Citywide online bill payments are also temporarily unavailable. Wind Farm worker Turns Turbines into a Crypto mine from the when you're a.
C
Hammer, everything looks like a nail department. A technical manager at the Dutch wind farm operator Nordex has been sentenced to 120 hours of community service after it was discovered that he had secretly installed.
B
Cryptocurrency mining rigs at two wind farm.
C
Sites just as the company was recovering.
B
From a Conti ransomware attack.
C
The unnamed employee, who was in his 40s, used the turbines to power the.
B
Cryptocurrency mining operation at two of the company's sites. As Graham Cluley writes, this is not an isolated case, and he cites a.
C
2018 instance in which several scientists at.
B
A top secret Russian nuclear warhead facility.
C
In Sarov were arrested for attempting to use one of the country's most powerful.
B
Supercomputers to mine Bitcoin.
C
And in China, a school headmaster was arrested for stealing his school's electricity to.
B
Power a 24 hour day cryptocurrency mining rig do you want to know more.
C
About the most pressing stories of the last few days in time for your weekly stand up?
B
If so, or even if you don't.
C
Join us today at 4:00pm Eastern for the Department of Know Where. Our guests, Keith Townsend, Chief Technology Advisor.
B
At the Futurum Group, and Howard Holden.
C
CEO at gigaom, will sort out the.
B
Priority stories and do a deep dive on the ones that matter most.
C
And of course we will actively involve you in the conversation.
B
Just go to YouTube, search for CISO.
C
Series and look for Rich Stroffolino's smiling.
B
Face under upcoming live streams. And if you have some thoughts on the news from today or about this.
C
Show in general, please be sure to.
B
Reach out to us@feedbackisoseries.com we would love to hear from you. I'm Steve Prentiss reporting for the CISO series.
A
Cybersecurity headlines are available every weekday. Head to cisoseries.com for the full stories behind the headlines.
D
Sam.
Podcast: CISO Series – Cyber Security Headlines
Host: Steve Prentiss
Date: November 24, 2025
Episode Theme:
This episode delivers quick, incisive updates on major cybersecurity incidents, highlighting insider threats, supply chain breaches, AI-driven insurance dilemmas, critical vulnerabilities, and unusual cybercrime cases making headlines worldwide.
"CrowdStrike emphasized that its systems were not breached as a result of this incident and that customers data was not compromised." (Steve Prentiss, 00:33)
"The airline says customers Iberia account login credentials and passwords were not compromised, nor was any banking or payment card information accessed." (Steve Prentiss, 01:04–01:09)
Summary:
Major insurers, including AIG, Great American, and W.R. Barclay, are lobbying to exclude AI-related liabilities from corporate policies due to the unpredictability of AI-triggered mass claims.
Key Insights:
Quote:
"What they can't handle is an agentic AI mishap that triggers 10,000 losses at once." (Steve Prentiss quoting Aon executive, 01:49)
"Salesforce emphasized that there was no indication that the issue resulted from any vulnerability in the Salesforce platform." (Steve Prentiss, 02:52)
"SonicWall is urging all customers to apply patches immediately." (Steve Prentiss, 04:18)
"No attackers have been named, but the Clop Ransomware gang has taken credit for exploiting a CVE numbered zero day vulnerability long before Oracle released a patch..." (Steve Prentiss, 05:03)
"Officials confirmed that there was no interruption to public safety services or 911 service." (Steve Prentiss, 05:40)
"A technical manager at the Dutch wind farm operator Nordex has been sentenced to 120 hours of community service after it was discovered that he had secretly installed cryptocurrency mining rigs at two wind farm sites..." (Steve Prentiss, 06:09)
On AI Insurance Risk:
"These liabilities are described by one underwriter as too much of a black box. The fear, they say, is of thousands of simultaneous claims when a widely used AI model makes a mistake." (Steve Prentiss, 01:37)
On Third-Party Supply Chain Attacks:
"The compromised data is alleged to consist of names and surnames of customers, along with the email address and Iberia Club loyalty card identification numbers." (Steve Prentiss, 00:57)
On Insider and Policy Enforcement:
"This is not an isolated case, and he cites a 2018 instance in which several scientists at a top secret Russian nuclear warhead facility in Sarov were arrested for attempting to use one of the country's most powerful supercomputers to mine Bitcoin." (Steve Prentiss, 06:42)
For more details and story links, visit cisoseries.com.