
Loading summary
A
From the CISO series, it's Cybersecurity Headlines.
B
These are the cybersecurity headlines for Thursday, August 7, 2025. I'm Sarah Lane. Hackers hijacked Google's Gemini AI with a poisoned Calendar invite to take over a smart home Wired has a new report on security researchers who are demonstrating indirect prompt injection attacks by hiding prompts for Gemini in Google Calendar items at Black Hat this week, they reported how these prompts could cause Gemini to do things like raise your smart blinds or start a zoom call every time you say to Gemini. Thanks. The researchers informed Google of the methods in February and Google has since deployed mitigations. Nvidia rejects US demand for backdoors in AI chips Nvidia is rejecting some US Lawmakers calls to add backdoors or kill switches in its AI chips, saying that the measures would create security vulnerabilities. Chief Security officer David Reber Jr. Said in a blog post that hardware level controls without user consent quote, would violate the fundamental principles of cybersecurity. These comments follow proposed U.S. legislation that would mandate tracking and remote disabling features in AI chips. Google says hackers stole its customers data by breaching its Salesforce database Google says hackers linked to the Shiny Hunters group breached one of its Salesforce databases containing small business contact information. While only basic and largely public data was taken. The attackers used voice phishing to gain access and may be preparing a leak site. The breach is the latest in a string of Salesforce related incidents following attacks on Cisco, Qantas and Pandora. Pandora confirms third party data breach warns of phishing attempts Speaking of Pandora, the jewelry maker with no relation to the music platform, Pandora confirmed a third party data breach exposing customer names and email addresses, but said that no sensitive data like passwords or payment info was accessed. The company says it hasn't seen signs of the data being leaked, but but is warning customers to watch for phishing attempts. Huge thanks to our sponsor ThreatLocker. ThreatLocker is a global leader in zero trust Endpoint security, offering cybersecurity controls to protect businesses from zero day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit threatlocker.com/c cell that's threatlocker.com CISO Microsoft researchers bullish on AI security agent even though it let 74% of malware slip through Microsoft unveiled Project Ire, an AI powered reverse engineering tool that uses LLMs to analyze unknown software and determine if it's malicious. In testing, it accurately flagged 89% of the malware it detected, but only caught 26% of all malicious files. Microsoft says the system is still a prototype and plans to integrate it into Defender as a binary analyzer. Experts say the low detection rate and false positives show that AI can't fully replicate traditional methods but will be crucial as attackers increasingly use AI themselves. Phishers abuse Microsoft 365 to spoof internal users attackers are exploiting Microsoft 365's direct send to spoof internal emails and bypass security filters, tricking users with phishing messages that appear legitimate. The method avoids authentication checks and has hit over 70 US organizations, mostly in finance, healthcare and and manufacturing. Experts recommend disabling Direct Send, enforcing DMARC and using email header stamping to block these attacks. Fake VPN and Spam blocker apps tied to Vextrio used in Ad fraud subscription scams A cybercrime group tied to Vextrio has been distributing fake vpn, spam blocker and utility apps via Apple's App Store and Google Play, masking them as legitimate tools. These apps trick users into pricey subscriptions, bombard them with ads and harvest personal data behind the scenes. Vextrio runs a massive ad fraud operation using a network of fake companies, traffic distribution systems and cloaking tools to steer victims to scam sites. The group's operations span dozens of countries and involve over 100 shell companies. Akira ransomware abuses CPU tuning tool to disable Microsoft Defender Akira ransomware operators are using a legitimate intel driver in a bring your own vulnerable driver attack to disable Microsoft Defender. Once loaded, it installs a malicious driver that modifies Defender settings via the registry to disable protections. This tactic has been observed in multiple incidents since mid July. Akira has also been linked to SonicWall SSL VPN exploits and uses SEO poisoning and fake software installers to spread Bumblebee malware, establish persistence and deploy ransomware across networks. Security researchers recommend close monitoring and using only official download sources. If you have thoughts on the news from today or about the show in general, be sure to reach out to us@feedbackisoseries.com we would love to hear from you. I am Sarah Lane reporting for the CISO series and we'll talk to you next time.
A
Cybersecurity headlines are available every weekday. Head to csoseries.com for the full stories. Behind the headlines.
Cyber Security Headlines - Episode Summary Hosted by CISO Series | Released on August 7, 2025
The latest episode of Cyber Security Headlines by CISO Series delves into a series of pressing issues in the information security landscape. Hosted by Sarah Lane, the episode covers significant breaches, emerging threats, and industry responses shaping the cybersecurity terrain today. This summary encapsulates the key discussions, insights, and conclusions drawn from the episode, structured into clear sections for ease of understanding.
Overview: The episode opens with a concerning development where hackers successfully hijacked Google's Gemini AI. This breach was executed through a poisoned Calendar invite, enabling attackers to control smart home devices.
Key Details:
Notable Quote:
"These prompts could cause Gemini to do things like raise your smart blinds or start a Zoom call every time you say to Gemini." – [00:07] Sarah Lane
Overview: Nvidia has firmly declined recent calls from US lawmakers to incorporate backdoors or kill switches into its AI chips. The company argues that such measures could inadvertently create new security vulnerabilities.
Key Details:
Notable Quote:
"Hardware level controls without user consent would violate the fundamental principles of cybersecurity." – [00:07] Sarah Lane
Overview: Google has reported a breach of its Salesforce database, believed to be perpetrated by the Shiny Hunters group. The compromised data includes small business contact information, though no sensitive data such as passwords or payment details were accessed.
Key Details:
Notable Quote:
"The attackers used voice phishing to gain access and may be preparing a leak site." – [00:07] Sarah Lane
Overview: Pandora, the jewelry manufacturer (distinct from the music platform), has confirmed a third-party data breach. Although customer names and email addresses were exposed, no sensitive information such as passwords or payment details were compromised.
Key Details:
Notable Quote:
"We haven't seen signs of the data being leaked, but we are warning customers to watch for phishing attempts." – [00:07] Sarah Lane
Overview: Microsoft introduced Project Ire, an AI-powered reverse engineering tool designed to analyze unknown software and identify malicious intent. Despite showing promise, the tool's performance metrics reveal significant limitations.
Key Details:
Notable Quote:
"In testing, it accurately flagged 89% of the malware it detected, but only caught 26% of all malicious files." – [00:07] Sarah Lane
Overview: Attackers are taking advantage of Microsoft 365's direct send feature to spoof internal emails, effectively bypassing standard security filters and deceiving users with seemingly legitimate phishing messages.
Key Details:
Notable Quote:
"Attackers are exploiting Microsoft 365's direct send to spoof internal emails and bypass security filters, tricking users with phishing messages that appear legitimate." – [00:07] Sarah Lane
Overview: A cybercrime group associated with Vextrio is spreading counterfeit VPNs, spam blockers, and utility apps through the Apple App Store and Google Play. These malicious applications deceive users into costly subscriptions, inundate them with ads, and covertly harvest personal data.
Key Details:
Notable Quote:
"These apps trick users into pricey subscriptions, bombard them with ads and harvest personal data behind the scenes." – [00:07] Sarah Lane
Overview: The Akira ransomware group has adopted a sophisticated method to disable Microsoft Defender by abusing a legitimate Intel driver as part of a "bring your own vulnerable driver" attack strategy.
Key Details:
Notable Quote:
"Akira ransomware operators are using a legitimate Intel driver in a bring your own vulnerable driver attack to disable Microsoft Defender." – [00:07] Sarah Lane
The episode underscores the evolving sophistication of cyber threats and the corresponding need for robust security measures. From AI-driven breaches and ransomware tactics to phishing exploits and fraudulent applications, the cybersecurity landscape continues to challenge organizations worldwide. Industry leaders like Google, Nvidia, and Microsoft are actively responding to these threats, balancing security enhancements with user privacy and operational integrity.
Final Thoughts: As cyber threats become more intricate and pervasive, the importance of proactive security strategies and collaboration between researchers and organizations becomes paramount. Staying informed about the latest threats and adopting recommended safeguards can significantly mitigate potential risks.
For more in-depth stories and updates, listeners are encouraged to visit CISOseries.com.
This summary provides a comprehensive overview of the discussed topics in the August 7, 2025 episode of Cyber Security Headlines. For those seeking detailed analyses and expert insights, tuning into the full episode is highly recommended.