
Loading summary
A
From the CISO series, it's Cybersecurity Headlines.
B
These are the cybersecurity headlines for Friday, August 15, 2025. I'm Steve Prentiss. A new wave of NFC relay fraud, call hijacking and root exploits faces the banking sector. Researchers at ThreatFabric have released a report describing a new Android Trojan called Phantom Car as one word that abuses near field communication to conduct relay attacks for facilitating fraudulent transactions targeting banking customers, end quote. Currently, these attacks are occurring in Brazil based on an NFC relay malware. As a service of Chinese origin, the tool relays NFC data from a victim's banking card to the fraudster's device, end quote. It is distributed on fake Google Play web pages and features deceptive positive reviews to persuade victims into installing the app. Canada's House of Commons suffers cyber Attack According to the Canadian news broadcaster CBC News, the attack occurred last Friday. The House of Commons, which is somewhat similar in mission and function to the US Congress, alerted staff on Monday about an information breach stating that a malicious actor was able to exploit a recent Micro Microsoft vulnerability to gain unauthorized access to a database containing information used to manage computers and mobile devices, end quote. This is in addition to employees names, job titles, office locations and email addresses, no threat actor or more specific cause has been identified as of yet. Zoom fixes critical Windows client flaw that could enable a privilege escalation the flaw has a CVE number and a CVSS score of 9.6 and exists within Zoom clients for Windows. An advisory from the company confirms that an untrusted search path in certain Zoom clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access, end quote. The advisory also lists the various products affected. A link is available in the show Notes to this episode. Microsoft fixes Windows 1124H2 updates that failed under WSUS Microsoft has now resolved an issue that may have Otherwise prevented the August 2025 Windows 1124H2 cumulative update from being delivered via Windows Server Update Services. This WSUS is a 20 year old product that helps IT administrators defer, approve and schedule updates for Microsoft products on enterprise networks from a single local update server rather than having each endpoint update from Redmond's own servers. Microsoft fixed the issue after learning of widespread reports from Windows admins regarding error messages received while installing the update. Huge thanks to our sponsor Vanta. Do you know the status of your compliance controls right now? Like right now, we know that real time visibility is critical for security, but when it comes to our GRC programs. We rely on point in time checks, but more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks like SoC2 and ISO 27001. They also centralize key workflows like policies, access reviews and reporting, and help you get security questionnaires done five times faster with AI. Now that's a new way to GRC. Get started at vanta.com headlines that is V A N T A dot com headlines Italian hotel guests Threatened by Cyber Heist the Italian government has issued a warning that, quote, identity documents belonging to tens of thousands of people who had stayed at hotels in the country allegedly have been stolen and are being illegally sold online. Italy's Computer Emergency Response Team states that a cybercriminal gang going by the handle mydocs has offered more than 90,000 documents for sale. These documents are allegedly obtained from 10 different Italian hotels and are high resolution scans of identity, confirming materials used during check ins such as passports and other forms of official ID. End Quote New York sues Zell creator over $1 billion in thefts New York Attorney General Letitia James announced the lawsuit against Early Warning Services on Wednesday, alleging that the creator of the Zelle electronic payment platform did little to stop scammers from using it to steal more than $1 billion from users between 2017 and 2023. The suit claims that the company knew from the beginning that scammers were abusing the platform, but did not adopt basic safeguards to protect users. End quote Hackers expand Cobalt Strike reach To Linux and macOS Japan's CERT coordination center revealed yesterday its observation of incidents that involved the use of a command and control framework called cross C2, that is C R O S S C2, which is designed to extend the functionality of Cobalt Strike to other platforms like Linux and Apple macOS for cross platform system control. End quote this activity was detected between September and December of 2024 and targets numerous countries booking.com faces another sneaky phishing Trick Back in June we covered a story about booking.com dealing with the Click Fix Captcha scam. And now the travel organization is dealing with a new challenge, a variation on an old school homograph scam in which a letter in a URL is replaced by a similar looking character. This time it is a Japanese hiragana character that looks like a forward slash and a little tilde together. In this particular case, the phishing email containing the bogus link purports to be a follow up to a complaint of service. This is occurring at the same time that financial software company Intuit is dealing with a similar homograph scam with a capital letter I of its name being replaced by a lowercase L. Are you checking out our Week in Review Show? Every Friday, every week, Rich Stravolino brings on a security leader to discuss the biggest news stories of the week. If you have ever wanted a CISO level view of the news, you have to check it out and you can be part of the show by adding your comments to our online chat on YouTube live. It starts at 3:30pm Eastern on the CISO series YouTube channel. And this week Steve Zielewski, co host of Defence in Depth, will be our guest, providing his expert commentary on the news that happened this week. So join us live, join in our chat, ask questions and share your thoughts on the news and developments in our industry. We would love to see you there. And again, if you have some thoughts on the news from today or about this show in general, please be sure to reach out to us@feedbackisoseries.com we would love to hear from you. I'm Steve Prentiss reporting. Four the CISO series.
A
Cybersecurity headlines are available every weekday. Head to CISoseries.com for the full stories. Behind the headlines.
Cyber Security Headlines: Detailed Summary of August 15, 2025 Episode
Hosted by CISO Series, "Cyber Security Headlines" delivers daily updates on the latest developments in information security. In the August 15, 2025 episode, host Steve Prentiss delves into a range of critical cybersecurity issues, offering insights and expert analysis on emerging threats and significant breaches.
Timestamp: [00:06] - [02:30]
Steve Prentiss opens the episode by discussing a novel threat targeting the banking industry: NFC (Near Field Communication) relay fraud. Researchers at ThreatFabric have identified a new Android Trojan named PhantomCar, which leverages NFC technology to execute relay attacks facilitating fraudulent transactions.
Notable Quote:
"A new wave of NFC relay fraud... targets banking customers by relaying NFC data from victims' cards to fraudsters" — Steve Prentiss [00:15]
Timestamp: [02:31] - [03:45]
Prentiss reports a significant breach affecting Canada's House of Commons, drawing parallels to the US Congress in terms of mission and function. The attack, disclosed by CBC News, exploited a recent Microsoft vulnerability to gain unauthorized access to sensitive databases.
Notable Quote:
"A malicious actor was able to exploit a recent Microsoft vulnerability to gain unauthorized access" — Steve Prentiss [02:50]
Timestamp: [03:46] - [04:30]
The episode highlights a critical security flaw in Zoom’s Windows client, which could allow for privilege escalation. The vulnerability, assigned a CVE number and a CVSS score of 9.6, is due to an untrusted search path issue.
Notable Quote:
"An unauthenticated user may conduct an escalation of privilege via network access" — Steve Prentiss [04:05]
Timestamp: [04:31] - [05:15]
Prentiss updates listeners on Microsoft’s resolution of an issue affecting the delivery of the August 2025 Windows 1124H2 cumulative update via Windows Server Update Services (WSUS).
Notable Quote:
"Microsoft fixed the issue after learning of widespread reports from Windows admins regarding error messages received while installing the update" — Steve Prentiss [04:50]
Timestamp: [05:16] - [06:10]
The episode covers a alarming cyber heist targeting Italian hotel guests, as warned by the Italian government. The breach involves the theft and illegal online sale of personal identity documents belonging to tens of thousands of hotel guests.
Notable Quote:
"Identity documents belonging to tens of thousands of people... are being illegally sold online" — Steve Prentiss [05:30]
Timestamp: [06:11] - [06:50]
Prentiss reports that the New York Attorney General, Letitia James, has filed a lawsuit against Early Warning Services, the creator of the Zelle electronic payment platform. The lawsuit alleges that Zelle facilitated over $1 billion in thefts from users between 2017 and 2023.
Notable Quote:
"The company knew from the beginning that scammers were abusing the platform, but did not adopt basic safeguards to protect users" — Steve Prentiss [06:25]
Timestamp: [06:51] - [07:10]
The podcast highlights how hackers are extending the reach of Cobalt Strike, a popular command and control framework, to other operating systems beyond Windows.
Notable Quote:
"Hackers expand Cobalt Strike reach to Linux and macOS" — Steve Prentiss [07:00]
Timestamp: [07:11] - [07:45]
Prentiss discusses recent phishing attacks targeting booking.com and Intuit, utilizing sophisticated homograph scams that manipulate URLs to deceive users.
Booking.com Scam:
Intuit Scam:
Notable Quote:
"This time it is a Japanese hiragana character that looks like a forward slash and a little tilde together" — Steve Prentiss [07:20]
Steve Prentiss wraps up the episode by directing listeners to additional resources and promoting community engagement through the CISO Series’ online platforms. He emphasizes the importance of staying informed and vigilant in the ever-evolving landscape of cybersecurity threats.
Final Quote:
"Cybersecurity headlines are available every weekday. Head to CISOsseries.com for the full stories. Behind the headlines." — Steve Prentiss [07:52]
This comprehensive overview encapsulates the critical issues discussed in the August 15, 2025 episode of "Cyber Security Headlines." From emerging NFC fraud tactics to significant breaches and sophisticated phishing schemes, the episode underscores the dynamic challenges facing the cybersecurity landscape today.