
Loading summary
Host
From the CISO series, it's Cybersecurity Headlines.
Steve Prentiss
These are the cybersecurity headlines for Monday, April 28, 2025. I'm Steve Prentiss.
Cybersecurity Expert
SAP Zero Day Vulnerability under Widespread Active.
Steve Prentiss
Exploitation Security researchers are observing a widespread.
Cybersecurity Expert
Exploitation of a zero day vulnerability affecting SAP netweaver systems. This unrestricted file upload vulnerability has a CVE number and a score of 10.
Steve Prentiss
On the CVSS scale.
Cybersecurity Expert
It allows attackers to upload files directly.
Steve Prentiss
To the system without authorization following discovery.
Cybersecurity Expert
By reliaquest on Tuesday. SAP issued an emergency patch on Thursday.
Steve Prentiss
But the enterprise company's security advisory is.
Cybersecurity Expert
Only available to SAP customers with login credentials. Watchtower is seeing active exploitation by threat actors hackers abuse OAuth 2.0 workflows to.
Steve Prentiss
Hijack Microsoft 365 accounts this attack is.
Cybersecurity Expert
Separate from the domain keys identified mail.
Steve Prentiss
OAuth attack DKIM that we covered on Tuesday.
Cybersecurity Expert
Since early March, Russian threat actors have been abusing legitimate OAuth 2.0 authentication workflows to hijack Microsoft 365 accounts of employees.
Steve Prentiss
Tied to Ukraine and human rights causes in this campaign.
Cybersecurity Expert
The attackers impersonate European officials or Ukrainian.
Steve Prentiss
Diplomats via WhatsApp and signal luring targets with fake invitations to private video meetings.
Cybersecurity Expert
Victims are tricked into providing Microsoft authorization.
Steve Prentiss
Codes or clicking phishing links.
Cybersecurity Expert
One communication originated from a compromised Ukrainian government account. Cybersecurity firm CEO charged with installing malware.
Steve Prentiss
On hospital systems Jeffrey Bowie is CEO.
Cybersecurity Expert
Of the cybersecurity firm Veritico V E R I T A C O. He is now facing two counts of violating Oklahoma's Computer Crimes act for allegedly infecting employee computers at the Oklahoma City St. Anthony Hospital.
Steve Prentiss
End quote On August 6th of last year, he was arrested in April based.
Cybersecurity Expert
On security footage showing a man attempting.
Steve Prentiss
To access multiple officers.
Cybersecurity Expert
The malware was designed to capture screenshots every 20 minutes and transmit them to an external IP address.
Steve Prentiss
Officials have stated that no patient data was accessed.
Cybersecurity Expert
That Windows folder initpub might be a problem after all. Two Mondays ago, we reported on an issue following Patch Tuesday in which a new empty folder had been created on the hard drives of Windows subscribers. Microsoft issued a statement telling users that the folder was part of a fix for a Windows process activation elevation of.
Steve Prentiss
Privilege vulnerability and that it should not be removed.
Cybersecurity Expert
However, cybersecurity expert Kevin Beaumont says this folder, initpub can be abused to prevent further Windows updates from being installed if it is created in a certain way. He added that he had discovered that this fix introduces a denial of service vulnerability in the Windows servicing stack that allows allows non admin users to stop.
Steve Prentiss
All future Windows security updates, end quote.
Cybersecurity Expert
This, he says, can be achieved by anyone by simply creating a junction between c enetpub and a Windows file by.
Steve Prentiss
Using a simple one line command.
Cybersecurity Expert
Beaumont says he reported the bug to Microsoft, who has assigned it a medium severity classification and has closed the case.
Steve Prentiss
Stating that they will consider fixing it in the future.
Cybersecurity Expert
Huge thanks to our sponsor, ThreatLocker ThreatLocker is a global leader in zero trust endpoint security, offering cybersecurity controls to protect businesses from zero day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and to start your free trial, visit threatlocker.com CISO that is.
Steve Prentiss
Thrash E A T L O C.
Cybersecurity Expert
K E R.com CISO education clouds get hit with Azure Checker that deploys crypto.
Steve Prentiss
Mining containers Microsoft has identified a threat.
Cybersecurity Expert
Actor named Storm1977 that has been conducting password spraying attacks against cloud tenants in.
Steve Prentiss
The education sector over the past year.
Cybersecurity Expert
The Microsoft Threat Intelligence team stated in an analysis. The attack involves the use of AzureChecker EXE, a command line interface tool that is being used by a wide range of threat actors. The tool connects to an external server to pull in files containing username and.
Steve Prentiss
Password combinations to carry out the password spray attack.
Cybersecurity Expert
In one instance, the threat actor was able to create more than 200 containers.
Steve Prentiss
Within a victim's resource group in order to conduct illicit cryptocurrency mining.
Cybersecurity Expert
Long beach cyber attack from 2023 affected almost 500,000 people. The government of Long Beach, California says the November 2023 attack involved sensitive data, including Social Security numbers, financial account information, credit and debit card numbers, biometric information.
Steve Prentiss
Medical data, driver's license numbers, passports, tax data and more. No ransomware gang has yet claimed responsibility for this attack.
Cybersecurity Expert
Africa's largest telecom suffers cyber incident exposing.
Steve Prentiss
Customer data Johannesburg based MTN Group confirmed the attack on Thursday.
Cybersecurity Expert
The company operates in more than 20 countries and has more than 200 million subscribers, making it one of the largest mobile operators in the world. Details as to what information may have.
Steve Prentiss
Been accessed, the number of people affected.
Cybersecurity Expert
Or the perpetrators behind the attack are.
Steve Prentiss
As of yet unavailable.
Cybersecurity Expert
YALE New Haven Health data breach impacted.
Steve Prentiss
5.5 million patients the nonprofit healthcare network.
Cybersecurity Expert
Headquartered in New Haven, Connecticut, suffered the breach earlier in March, resulting in the theft of patient pii, including Social Security.
Steve Prentiss
Numbers, but no financial or medical data.
Cybersecurity Expert
The organization has not yet disclosed technical details about this attack, nor has any.
Steve Prentiss
Ransomware group taken responsibility.
Cybersecurity Expert
Make sure you check out our latest episode of Security. You should know we just released a new episode with Dropzone AI looking into what they are doing to address alert.
Steve Prentiss
Fatigue without missing the things that you need to know.
Cybersecurity Expert
Look for the show over@cisoseries.com or wherever.
Steve Prentiss
You get your podcasts. I'm Steve Prentiss reporting for the CISO series.
Host
Cybersecurity headlines are available every weekday. Head to CISoseries.com for the full stories behind the headlines.
Podcast Summary: Cyber Security Headlines Hosted by CISO Series | Release Date: April 28, 2025
Introduction
In the latest episode of Cyber Security Headlines by CISO Series, host Steve Prentiss delves into a series of pressing cybersecurity issues affecting enterprises and individuals worldwide. From zero-day vulnerabilities to high-profile arrests, this episode covers a broad spectrum of topics that underscore the evolving landscape of information security.
Key Points:
Notable Quotes:
Discussion: Security researchers from ReliaQuest observed widespread exploitation of this critical vulnerability. Despite SAP's prompt release of an emergency patch on April 27, the advisory remains accessible solely to authenticated customers, potentially delaying remediation efforts for others. The vulnerability's high CVSS score underscores the urgent need for organizations to apply the patch promptly to mitigate potential breaches.
Key Points:
Notable Quotes:
Discussion: The exploitation involves sophisticated social engineering tactics, where victims receive fake invitations to private video meetings. Once engaged, they are deceived into divulging Microsoft authorization codes or clicking on malicious phishing links, thereby granting attackers access to their accounts. One notable incident involved a communication from a compromised Ukrainian government account, highlighting the targeted nature of these attacks.
Key Points:
Notable Quotes:
Discussion: The arrest of Jeffrey Bowie marks a significant event in the cybersecurity community, illustrating that even those within the industry are not immune to engaging in malicious activities. Officials assure that no patient data was accessed during the breach, but the incident raises concerns about insider threats and the integrity of cybersecurity firms.
Key Points:
Notable Quotes:
Discussion:
Kevin Beaumont’s discovery reveals that the initpub folder can be manipulated to create a denial of service condition within the Windows servicing stack. By establishing a junction between c:\enetpub and another Windows file using a simple command, non-admin users can prevent the installation of future security updates, thereby exposing systems to ongoing vulnerabilities.
Key Points:
Notable Quotes:
Discussion: AzureChecker, initially a legitimate tool, has been repurposed by Storm1977 to conduct wide-scale password spraying attacks targeting educational institutions. The creation of numerous containers for cryptocurrency mining highlights the financial motivation behind these attacks. Educational institutions are particularly vulnerable due to often limited cybersecurity resources, making them prime targets for such exploitations.
Key Points:
Notable Quotes:
Discussion: The extensive nature of the Long Beach cyber attack underscores the challenges municipalities face in protecting citizen data. The breadth of compromised information raises concerns about potential identity theft and financial fraud. The lack of attribution to a ransomware group suggests either a sophisticated attack by non-traditional actors or the possibility of a new threat actor emerging.
Key Points:
Notable Quotes:
Discussion: As one of the largest mobile operators globally, MTN Group's data breach has significant implications for customer trust and data security. The absence of detailed information delays the ability to assess the breach's impact and implement necessary safeguards. This incident highlights the vulnerability of large telecom operators to cyber threats and the importance of robust security measures.
Key Points:
Notable Quotes:
Discussion: The breach at Yale-New Haven Health serves as a stark reminder of the persistent threats targeting healthcare institutions. Although financial and medical data were not compromised, the exposure of PII poses risks of identity theft and privacy violations. The lack of transparency regarding the attack's technical aspects hampers efforts to understand and prevent similar incidents in the future.
Conclusion
This episode of Cyber Security Headlines presents a comprehensive overview of the latest threats and incidents shaping the cybersecurity landscape. From critical vulnerabilities and sophisticated exploitation techniques to significant data breaches and insider threats, the discussed topics highlight the multifaceted challenges organizations face in safeguarding their digital assets. As cyber threats continue to evolve, the importance of proactive security measures and timely information dissemination becomes increasingly paramount.
Notable Resources:
Credits: Summary prepared based on the transcript provided from the Cyber Security Headlines episode by CISO Series.