
Loading summary
Steve Prentiss
From the CISO series, it's Cybersecurity Headlines these are the Cybersecurity headlines for Friday, May 23, 2025. I'm Steve Prentiss. Signal Ads Recall Blocker the messaging app has updated its Windows app to block actions by Microsoft's AI Powered Recall feature from screenshotting conversations. When enabled, Screen Security will set a digital Rights management flag on Signals app Windows, blocking their content from being captured by Recall or other Windows apps and features, signal developer Joshua Lund stated in a post this week. Microsoft has simply given us no other options End quote critical Windows Server 2025 DMSA vulnerability warning According to Akamai security researcher Yuval Gordon, a privilege escalation flaw in Windows Server 2025 makes it possible for attackers to compromise any user in Active Directory. In a report shared with the Hacker News, Gordon said the attack exploits the delegated managed service account feature that was introduced in Windows Server 2025. The attack works with the default configuration and is trivial to implement. End quote Akamai has named this attack technique Bad Successor Pathology Lab suffers data breach North Carolina based Marlborough Chesterfield Pathology is a full service anatomic pathology laboratory that recently suffered an apparent ransomware attack. The company stated in a breach notice published on its website that unauthorized activity on some internal IT systems was discovered on January 16 and that further investigation showed that files had been stolen. The data in these files generally includes pii along with medical treatment information and health insurance information, but this varies by individual. Over 235,000 individuals may have been impacted. The ransomware group SafePay SafePay has claimed responsibility for the theft. FTC slaps GoDaddy upside the head the US Federal Trade Commission has finalized an order requiring the web hosting company to secure its services to settle charges of data security failures that led to several data breaches since 2018. End Quote the FTC also alleged that the company misled users about its security practices. It found that GoDaddy was unaware of vulnerabilities in its hosting environment due to a lack of standard security measures. The Commission's order prohibits the company from misleading consumers, mandates it to establish a robust information security program, hire an independent third party assessor and add mfa. Huge thanks to our sponsor Conveyor still spending hours maintaining a massive spreadsheet of Q and A pairs or using RFP tools to answer security questionnaires. Conveyor's AI doesn't need hand holding and gets you accurate answers every time with limited knowledge base maintenance. It reads directly from your connected sources, documents, wikis, websites, Confluence, Google Drive and even your Conveyor trust Center. You don't maintain a knowledge base. You connect to one and their AI does the rest for you. See what real autofill magic looks like@conveyor.com that is www.c o n v e y o r Consumer Reports accuses Kroger of using loyalty program to Sell Customer Data the consumer watchdog publication stated this past Tuesday that the grocery chain allegedly used data collected from loyalty shoppers to build sometimes incorrect profiles of them and sell their information to other companies. End quote. According to the record, their report was based on statements from a single customer in Oregon who used the state's new privacy law to expose what Kroger had been doing with his information, which turned out to be that it was sent to data brokers, tobacco companies, insurance and marketing firms. Kroger refutes this report Chinese Hackers Breach US Local Governments using cityworks Zero Day Chinese speaking hackers have been exploiting a now patched Trimble cityworks Zero day to breach multiple local governing bodies across the United States. Trimble cityworks is a geographic information system based asset management and work order management software primarily used by local governments, utilities and public works organizations and is designed to help infrastructure agencies and municipalities manage public assets, handle permitting and licensing and process work orders. The hacking group behind this campaign, UAT6382, used a rust based malware loader to deploy Cobalt Strike beacons and V Shell malware designed to backdoor compromised systems, provide long term persistent access as well as web shells and custom malicious tools. Written in Chinese Cisco Patches High Severity Flaws On Wednesday, Cisco published 10 security advisories detailing over a dozen vulnerabilities across its products, including two high severity flaws in its Identity Services Engine and Unified Intelligence Center. The ISE bug impacts the RADIUS message processing feature and could be exploited remotely without authentication to cause ISE to reload and lead to a denial of service condition. The security defect was resolved alongside a medium severity vulnerability that could be exploited for horizontal privilege escalation. More details about all these flaws is available in the show Notes to this episode. Unpatched critical bugs in Versa Concerto revealed these vulnerabilities, disclosed by researchers at Project Discovery, could allow remote attackers to bypass authentication and execute arbitrary code on affected systems, as described in Bleeping Computer. Versa Concerto is the centralized management and orchestration platform for Versa Networks and Secure Access Service Edge solutions used by large enterprises, telecom operators and government agencies. Project Discovery reported the vulnerabilities to the vendor on February 13th with a 90 day disclosure period. Versa Networks acknowledged the findings and promised hotfixes by April 7, but then went silent, prompting Project Discovery to publish the full details to alert Versa Concerto users of the danger. Make sure to join us later today at 3:30pm Eastern for our Week in Review show. George Finney, CISO at the University of Texas System, will be our guest, providing his expert commentary on the news of the week, and we encourage participation and comments through our YouTube live channel. Just go to the events page@ciso series.com to join us. If you're in the San Diego area, make sure to join us for our San Diego Cyber Group meetup on Wednesday, April 28. David Spark will be there for some fun discussions, silly games and networking. Details on this can also be found@the cisoseries.com events page. And remember to check out our new episode of Security youy Should Know. This week we're talking with threatlocker and what they are doing to solve the problem of unauthorized site access. If you haven't checked out this Show yet, each 15 minute episode gives you the answers to questions security leaders want to know when learning about a new solution. Check it out wherever you get your podcasts or again, head on over to cisoseries.com I'm Steve Prentice reporting for the CISO series. Cybersecurity headlines are available every weekday. Head to cisoseries.com for the full stories behind the headlines.
Cyber Security Headlines - Episode Summary Hosted by CISO Series Release Date: May 23, 2025
Timestamp: [00:00]
Steve Prentiss opens the episode by discussing Signal's latest update aimed at reinforcing user privacy. The messaging platform has introduced Screen Security in its Windows application, which activates a digital rights management flag. This flag effectively blocks Microsoft's AI-Powered Recall feature from capturing screenshots of conversations.
Notable Quote:
"Microsoft has simply given us no other options,"
– Joshua Lund, Signal Developer [00:45]
This development underscores Signal's commitment to maintaining user confidentiality against evolving platform features that may infringe on privacy.
Timestamp: [02:15]
A significant security concern highlighted is the privilege escalation flaw identified in Windows Server 2025. Akamai's security researcher, Yuval Gordon, revealed that this vulnerability allows attackers to compromise any user within Active Directory environments.
Notable Quote:
"The attack exploits the delegated managed service account feature that was introduced in Windows Server 2025. The attack works with the default configuration and is trivial to implement,"
– Yuval Gordon, Akamai [04:10]
Akamai has named this exploit technique "Bad Successor," emphasizing the ease with which malicious actors can leverage this flaw to gain unauthorized access.
Timestamp: [05:30]
Marlborough Chesterfield Pathology, a North Carolina-based anatomic pathology laboratory, disclosed a ransomware attack that resulted in unauthorized access and data theft. The breach, discovered on January 16, compromised sensitive personal identifiable information (PII), medical treatment records, and health insurance details of over 235,000 individuals.
Notable Quote:
"Files had been stolen. The data includes PII and medical information, varying by individual,"
– Marlborough Chesterfield Pathology [07:05]
The ransomware group SafePay has claimed responsibility for this incident, highlighting the persistent threat posed by such malicious entities targeting healthcare facilities.
Timestamp: [09:20]
The U.S. Federal Trade Commission (FTC) has imposed a settlement order on GoDaddy, addressing multiple data security breaches that occurred between 2018 and the present. The FTC accused GoDaddy of failing to implement standard security measures, rendering the company unaware of vulnerabilities within its hosting environment.
Notable Quote:
"GoDaddy was unaware of vulnerabilities in its hosting environment due to a lack of standard security measures,"
– FTC Statement [10:05]
The settlement mandates GoDaddy to establish a comprehensive information security program, engage an independent third-party assessor, implement multi-factor authentication (MFA), and refrain from misleading consumers about their security practices.
Timestamp: [12:45]
Consumer watchdog publication, Consumer Reports, has accused the grocery giant Kroger of exploiting data from its loyalty program to create inaccurate customer profiles and sell this information to external companies. This allegation emerged from a case in Oregon, where a customer utilized the state's privacy laws to reveal Kroger's data-sharing practices.
Notable Quote:
"Data was sent to data brokers, tobacco companies, insurance, and marketing firms,"
– Report Details [14:10]
Kroger has publicly refuted these claims, asserting that their data handling practices comply with all relevant regulations and emphasizing their commitment to customer privacy.
Timestamp: [16:00]
A sophisticated cyberattack campaign has been launched by Chinese-speaking hackers targeting U.S. local governments. Utilizing a now-patched zero-day vulnerability in Trimble Cityworks—a GIS-based asset management and work order software—the group, identified as UAT6382, has successfully breached multiple municipal systems.
The attackers deployed Rust-based malware loaders to install Cobalt Strike beacons and V Shell malware, facilitating persistent access and the installation of web shells and custom malicious tools.
Notable Quote:
"Designed to help infrastructure agencies manage public assets, the exploitation of Trimble Cityworks undermines critical municipal operations,"
– Security Analyst [17:35]
This breach underscores the vulnerability of essential public infrastructure to targeted cyber threats and the importance of timely patch management.
Timestamp: [19:50]
Cisco has released ten security advisories addressing over a dozen vulnerabilities across its product suite. Among these are two high-severity flaws in the Identity Services Engine (ISE) and Unified Intelligence Center. The ISE vulnerability affects RADIUS message processing, allowing remote, unauthenticated attackers to trigger a denial-of-service (DoS) by causing the ISE to reload.
Additionally, a medium-severity vulnerability was identified that permits horizontal privilege escalation, potentially enabling attackers to access unauthorized areas within the network.
Notable Quote:
"The ISE bug could be exploited remotely without authentication to cause ISE to reload and lead to a denial of service condition,"
– Cisco Security Advisory [21:15]
Cisco recommends all users apply the latest patches immediately to mitigate these critical vulnerabilities. Detailed information is available in the show notes.
Timestamp: [23:00]
Researchers from Project Discovery have uncovered critical vulnerabilities in Versa Concerto, the centralized management platform for Versa Networks' Secure Access Service Edge (SASE) solutions. These vulnerabilities allow remote attackers to bypass authentication and execute arbitrary code on affected systems.
Notable Quote:
"Vulnerabilities in Versa Concerto could allow remote attackers to bypass authentication and execute arbitrary code,"
– Project Discovery Report [24:20]
Despite initially acknowledging the issues and promising hotfixes by April 7, Versa Networks failed to release the patches within the 90-day disclosure period. Consequently, Project Discovery has publicly disclosed the vulnerabilities to alert users of the imminent risks.
Timestamp: [26:50]
Steve Prentiss concludes the episode by promoting upcoming events and resources:
Week in Review Show: Featuring George Finney, CISO at the University of Texas System, offering expert commentary on weekly cybersecurity news. Scheduled for today at 3:30 PM Eastern on their YouTube live channel. [26:55]
San Diego Cyber Group Meetup: Set for Wednesday, April 28, with host David Spark, focusing on discussions, games, and networking opportunities. Details available on the CISO Series events page.
New Podcast Episode - "Security You Should Know": This week’s episode features a discussion with ThreatLocker about combating unauthorized site access. Available on all major podcast platforms and at cisoseries.com.
Conclusion
This episode of Cyber Security Headlines by CISO Series provides a comprehensive overview of significant cybersecurity incidents and vulnerabilities impacting major platforms and organizations. From Signal's proactive measures against screenshot capturing to critical vulnerabilities in widely used systems like Windows Server and Trimble Cityworks, the discussions highlight the ongoing challenges in safeguarding digital assets. Additionally, regulatory actions against companies like GoDaddy and allegations against Kroger emphasize the importance of robust data security and ethical data handling practices. Stay informed and proactive by tuning into future episodes and participating in the CISO Series community events.
For full details on the topics discussed, visit cisoseries.com.