
Loading summary
A
From the CISO series, it's Cybersecurity Headlines.
B
These are the cybersecurity headlines for Monday, March 3, 2025. I'm Steve Prentiss. Hegseth orders Cyber Command to stand down on Russia planning According to an exclusive report from the Record, Defense Secretary Pete Hegseth has ordered US Cyber Command to halt all planning against Russia offensive cyber actions. The directive was given to Cyber Command Chief general Timothy hall, who related to Marine Corps Major general Ryan Heritage. The order does not extend to the National Security Agency or its signals intelligence efforts. The full scope remains unclear, but it aligns with White House efforts to normalize relations with Moscow following the invasion of Ukraine. SolarWinds CISO says security executives are nervous about personal legal liability for breaches Speaking at Cyber Law, Con Brown, who was the highest ranking security official during the 2020 SolarWinds hack, which was linked to Russian intelligence, noted that CISOs are increasingly uncertain about their legal risks, fearing liability while trying to implement strong security measures. Other security executives, he said, are quote re evaluating how they publicly discuss their cybersecurity programs, end quote. He also noted that holding individuals liable for breaches can distract or hinder CISOs in effectively managing the aftermath of cyber attacks. End quote. Microsoft Hangs up on Skype after 14 years a decade and a half after being brought in as a replacement for Windows Live messenger, users of the video, call and messaging service will now be asked to switch to teams free. Their contacts, call logs and messages will be automatically migrated once they log into their accounts. Users who do not want to switch to teams can export their data, including chat history and images shared in messages. But this must all happen by May 5th. Mark Cuban offers to fund government tech unit that was cut this unexpected offer of support was posted on the social network Bluesky and urged the displaced engineers and designers to turn the upheaval to their advantage. Referring to the 18F Technology Unit of the government's General Services Administration, Cuban if you worked for 18F and got fired group together to start a consulting company, it's just a matter of time before Doge needs you to fix the mess they inevitably created. They will have to hire your company as a contractor to fix it, but on your terms. I'm happy to invest and or help. The 18F unit had reportedly built, amongst other things, login.gov, a secure and private way for the public to access services at government agencies including Social Security and the Department of Veterans affairs, thanks to this week's episode's sponsor, ThreatLocker. ThreatLocker is a global leader in zero trust endpoint security offering cybersecurity controls to protect businesses from zero day attacks and ransom. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and to start your free trial, visit threatlocker.com that is threat locker.com Ransomware gangs exploit Paragon Partition Manager bug in BYO VD attacks Microsoft has discovered five flaws in the Paragon Partition Manager driver. One of these has been used by ransomware gangs in zero day attacks to gain system privileges in Windows. These were exploited in bring your own vulnerable driver attacks, where threat actors drop the kernel driver on a targeted system to elevate privileges or cause a denial of service scenario on the victim's machine. US recovers $31 million stolen in 2021 Uranium Finance hack this cryptocurrency was originally stolen in 2021 on Uranium Finance, a DEFI protocol on Binance's BNB chain. Hackers exploited vulnerabilities in its smart contracts, leading to its collapse and significant investor losses. Blockchain intelligence firm TRM Labs collaborated with the Southern District of New York and Homeland Security Investig track the stolen assets by analyzing laundering patterns and tracing transactions through tornado cash and cross chain swaps. Law enforcement successfully seized the funds in February of this year, marking one of the most significant cryptocurrency recoveries in recent years. Microsoft Identifies Generative AI hacking for Hire Scheme Hackers following up on a story we have been covering over the last few weeks, Microsoft has now identified individuals from Iran, China, Vietnam and the UK as key players in an international scheme to hijack and sell Microsoft accounts capable of bypassing generative AI safety guidelines. In December, Microsoft petitioned a Virginia court to seize infrastructure from 10 unnamed individuals accused of running a hacking as a service operation using stolen API keys. These compromised accounts provided unauthorized access to Azure OpenAI to generating harmful content, including falsified celebrity imagery. Microsoft's Digital Crimes Unit is leading the legal effort to shut down the operation, though specifics on the safety violations were not disclosed. Philippine Army Suffers a Cyber Attack the Philippine army confirmed a cyber attack after a local hacking group claimed to have breached its systems and accessed confidential documents. Army spokesperson colonel Louis Dema Alla described it as an illegal access attempt that was swiftly contained with no detected data theft or damage. However, digital security group Deep WebConnect reported that hacker group Exodus Security claimed responsibility, alleging it had compromised 10,000 records of active and retired service members. The leaked data reportedly includes personal, military and financial details, although its authenticity and exact volume remain unverified. It's only Monday, but that doesn't mean you shouldn't be thinking about Friday already. That's because we've got a great Super Cyber Friday event happening this week at 1pm Eastern, 10am Pacific. This week we're talking about the commodification of cybercrime, digging into how your security program needs to change now that the barrier to entry on malware is down to almost nothing. Head on over to the events page on cisoseries.com to register to join us this Friday. I'm Steve Prentiss, reporting for the CISO series.
A
Cybersecurity headlines are available every weekday. Head to CISoseries.com for the full stories behind the headlines.
Cyber Security Headlines - Episode Summary
Title: Hegseth Orders Standdown, Microsoft Terminates Skype, Cuban Offers Lifeline
Host: CISO Series
Release Date: March 3, 2025
In a significant shift in U.S. cybersecurity strategy, Defense Secretary Pete Hegseth has directed the U.S. Cyber Command to halt all planning against Russia's offensive cyber operations. This directive was communicated to Cyber Command Chief General Timothy Hall, who subsequently relayed the order to Marine Corps Major General Ryan Heritage.
Key Points:
Notable Quote:
"The order does not extend to the National Security Agency or its signals intelligence efforts. The full scope remains unclear..." – General Timothy Hall [00:07]
Con Brown, the highest-ranking security official during the 2020 SolarWinds hack, addressed increasing anxiety among Chief Information Security Officers (CISOs) regarding personal legal liabilities associated with cybersecurity breaches. Speaking at the Cyber Law conference, Brown emphasized that the threat of personal liability is causing CISOs to "re-evaluate how they publicly discuss their cybersecurity programs."
Key Points:
Notable Quote:
"CISOs are increasingly uncertain about their legal risks, fearing liability while trying to implement strong security measures." – Con Brown [02:15]
After a decade and a half of service, Microsoft has officially terminated Skype, urging users to transition to Microsoft Teams by May 5th. This marks the end of Skype as a standalone video call and messaging platform, which was initially introduced as a replacement for Windows Live Messenger.
Key Points:
Notable Quote:
"Users who do not want to switch to Teams can export their data, including chat history and images shared in messages." – Steve Prentiss [03:45]
Entrepreneur Mark Cuban has stepped forward to assist engineers and designers affected by the disbanding of the 18F Technology Unit within the General Services Administration. Through a post on the social network Bluesky, Cuban has offered funding and support for these professionals to establish consulting firms.
Key Points:
Notable Quote:
"It's just a matter of time before Doge needs you to fix the mess they inevitably created. They will have to hire your company as a contractor to fix it, but on your terms. I'm happy to invest and/or help." – Mark Cuban [04:30]
Microsoft has identified five critical flaws in the Paragon Partition Manager driver, one of which has been exploited by ransomware gangs in zero-day attacks. These vulnerabilities have been leveraged in "Bring Your Own Vulnerable Driver" (BYO VD) attacks, allowing threat actors to install kernel drivers that elevate system privileges or cause denial-of-service conditions.
Key Points:
Notable Quote:
"Threat actors drop the kernel driver on a targeted system to elevate privileges or cause a denial of service scenario on the victim's machine." – Steve Prentiss [05:15]
In a major victory against cryptocurrency theft, the U.S. has successfully recovered $31 million stolen in the 2021 Uranium Finance hack. The decentralized finance (DeFi) protocol on Binance's BNB chain was compromised through vulnerabilities in its smart contracts, leading to significant investor losses.
Key Points:
Notable Quote:
"Law enforcement successfully seized the funds in February of this year, marking one of the most significant cryptocurrency recoveries in recent years." – Steve Prentiss [05:50]
Microsoft has uncovered an international hacking-for-hire operation involving individuals from Iran, China, Vietnam, and the UK. This scheme focuses on hijacking Microsoft accounts to bypass generative AI safety protocols, enabling the generation of harmful content such as falsified celebrity imagery.
Key Points:
Notable Quote:
"These compromised accounts provided unauthorized access to Azure OpenAI to generate harmful content, including falsified celebrity imagery." – Steve Prentiss [06:30]
The Philippine Army has confirmed a cyber attack perpetrated by the hacker group Exodus Security, which claims to have breached its systems and accessed confidential documents. While the Army spokesperson, Colonel Louis Dema Alla, stated that the intrusion was contained without detected data theft or damage, Exodus Security alleges that 10,000 records of active and retired service members were compromised.
Key Points:
Notable Quote:
"It was swiftly contained with no detected data theft or damage." – Colonel Louis Dema Alla [06:50]
The CISO Series is hosting a "Super Cyber Friday" event, scheduled to take place at 1 PM Eastern / 10 AM Pacific. The event will focus on the commodification of cybercrime and how security programs must evolve as the barrier to entry for malware creation continues to diminish.
Key Points:
Notable Quote:
"We're talking about the commodification of cybercrime, digging into how your security program needs to change now that the barrier to entry on malware is down to almost nothing." – Steve Prentiss [07:00]
Final Note: For in-depth coverage of these headlines and more, listeners are encouraged to visit CISOseries.com.