
Loading summary
A
From the CISO series, it's Cybersecurity Headlines.
B
These are the cybersecurity headlines for Thursday, January 23, 2025. I'm Sarah Lane. In today's cybersecurity news, the Department of Homeland Security in the US has terminated all advisory committees, including the Cybersecurity Review Board, or csrb. All advisors are encouraged to reapply, but we're told that, quote, committee activities will be focused solely on advancing our critical mission to protect the homeland and support DHS's strategic priorities, end quote. The CSRB is known for investigating major cybersecurity incidents such as the SALT typhoon hacks. Researchers at threat intelligence firm Sibyl have discovered thousands of leaked credentials for at least 14 major cybersecurity vendors on the dark Web since the start of this year 2025, including CrowdStrike, Palo Alto Networks and McAfee. In a report published January 22, Siebel says these credentials were likely extracted from info stealer logs and include access to internal accounts and customer platforms. While many accounts may have additional security layers like mfa, the findings highlight the importance of dark web monitoring to prevent potential cycle cyber attacks. President Trump pardoned Ross Ulbricht, the creator of the Silk Road Marketplace, fulfilling a campaign promise that resonated with some cryptocurrency communities. Ulbricht was sentenced to life in prison back in 2015 for running Silk Road, which facilitated $200 million in illegal transactions. Prosecutors linked him to drug related deaths and alleged murder for hire plots, but others argued his sentence was excessive for a nonviolent crime. The securities and Exchange Commission, or sec, under acting chair Mark Ueda, announced a new crypto task force to create clear regulations for digital assets, fulfilling President Trump's promise of a crypto friendly administration. Led by SEC Commissioner Hester Pierce, the task force will focus on developing rules for coin registration and fostering innovation while protecting investors. Bitcoin rose 2.4% on this news as the announcement signals a shift from the Biden era sec, which was seen as hostile to the crypto industry, at least for some people. Do you know the status of your compliance controls right now? Like right now, we know that real time visibility is critical for security, but when it comes to our GRC programs we rely on point in time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation and evidence collection across 35 frameworks like SoC2 and ISO 27001. They also centralize key workflows like policies, access reviews and reporting and it helps you get security questionnaires done five times faster with AI. Now that's a new way to GRC. Get started at vanta.com/headlines Hackers who breached education tech giant Power School claim to have stolen personal Data for over 62.4 million students and 9.5 million teachers across 6,500 school districts in the U S, Canada and beyond. Bleeping computer reports that an FAQ stated that sensitive information such as Social Security numbers, medical information and grades were all stolen for a subset of students impacted by the breach. This FAQ also stated that PowerSchool paid a ransom to prevent the stolen data from being leaked. Privately seeing a video of the threat actor claiming to delete the data, PowerSchool is offering two years of free identity protection and credit monitoring for all affected individuals, although exact numbers remain unclear as investigations continue. IoT driven DDoS attacks are on the rise, along with a surge in botnets using infected home routers and cameras and other devices. Notably, Cloudflare reported a record 5.6 terabit per second DDoS attack from 13,000 IoT devices, while other security firms like Qualys and Trend Micro have tracked multiple botnets leveraging Mirai variants. Experts warn that IoT devices are still vulnerable to compromise due to outdated security and urge users to update passwords, disable remote management and install patches promptly. The UK government's announcement of the gov.uk digital wallet has sparked some confusion in the digital identity ecosystem as it's designed to support both public and private sector use cases, creating some overlap with the Digital Identity and Attributes Trust framework or DiatF. Digital ID providers are now dealing with a twin track system. The wallet will store only government issued credentials, leaving DIITF certified providers facing some unexpected competition. Two critical flaws in the Real home theme and easy Real estate plugins for WordPress allow unauthenticated attackers to gain admin privileges, leaving 32,600 websites vulnerable. Despite discovery in September of 2024, no patches have been released by Inspiry themes and both flaws remain exploitable. Administrators should immediately disable the affected plugins, restrict user registration and apply mitigations to prevent potential exploitation. How does a CISO approach strategy as they become more comfortable in their role? Is a long term strategy even possible for a new ciso? That's what we're going to get to the bottom of on our latest episode of Defense in Depth. Look for if and when should a CISO have a long term security plan in your favorite podcast app? Or head over to CISoseries.com Cybersecurity headlines.
A
Are available every weekday. Head to CISoseries.com for the full stories behind the headlines.
B
I'm Sarah Lane reporting for the CISO series. Thank you so much for listening.
Cyber Security Headlines - Episode Summary
Released on January 23, 2025 | Host: CISO Series
Overview: The Department of Homeland Security (DHS) in the United States has made a significant organizational change by terminating all its advisory committees, including the Cybersecurity Review Board (CSRB).
Details:
Implications:
Overview: Researchers from the threat intelligence firm Sibyl have uncovered thousands of leaked credentials belonging to at least 14 major cybersecurity vendors on the dark web.
Details:
Implications:
Overview: Former President Donald Trump has pardoned Ross Ulbricht, the founder of the infamous Silk Road Marketplace, fulfilling a campaign promise that resonated particularly with cryptocurrency communities.
Details:
Implications:
Overview: The Securities and Exchange Commission (SEC), led by acting chair Mark Ueda, has announced the formation of a new crypto task force aimed at developing clear regulations for digital assets.
Details:
Notable Quote: "Developing clear regulations is essential for fostering innovation while ensuring investor protection," stated SEC Commissioner Hester Pierce (Sarah Lane, 04:50).
Implications:
Overview: Education technology giant PowerSchool has fallen victim to a significant data breach compromising personal information of millions of students and teachers.
Details:
Implications:
Overview: There is an alarming increase in Distributed Denial of Service (DDoS) attacks orchestrated through Internet of Things (IoT) devices, with a surge in botnets utilizing compromised home routers and cameras.
Details:
Expert Advice: "Users must update passwords, disable remote management, and install patches promptly to protect their IoT devices," emphasized Sarah Lane (Sarah Lane, 07:15).
Implications:
Overview: The UK government's introduction of the gov.uk digital wallet has created confusion within the digital identity ecosystem due to its overlapping functionalities with existing frameworks.
Details:
Implications:
Overview: Two critical vulnerabilities have been discovered in the Real Home Theme and Easy Real Estate plugins for WordPress, allowing attackers to gain administrative privileges without authentication.
Details:
Implications:
In the latest episode of Defense in Depth, the discussion shifts to strategic approaches for new Chief Information Security Officers (CISOs). Questions addressed include:
Upcoming Episode Teaser: "For an in-depth exploration of these topics, tune into our next episode of Defense in Depth. Find out if and when a CISO should develop a long-term security plan on your favorite podcast app or visit CISOseries.com."
Notable Quotes:
"Committee activities will be focused solely on advancing our critical mission to protect the homeland and support DHS's strategic priorities."
— Sarah Lane (00:06)
"We know that real-time visibility is critical for security, but when it comes to our GRC programs we rely on point-in-time checks."
— Sarah Lane (05:00)
"Get security questionnaires done five times faster with AI. Now that's a new way to GRC."
— Sarah Lane (05:15)
For more detailed stories and daily updates, visit CISOseries.com.