
Loading summary
David Spark
From the CISO series, it's Cybersecurity Headlines.
Sarah Lane
These are the cybersecurity headlines for Wednesday, July 30, 2025. I'm Sarah Lane. Critical authentication flaw identified in base 44 vibe coding platform Wiz Research found a critical authentication flaw in Base44's vibe coding platform, recently acquired by Wix, letting attackers bypass SSO and access private apps using only a public app id. The issue came from exposed API endpoints that didn't need authentication affecting apps with sensitive enterprise data. Wix patched the flaw within 24 hours and says there's no sign of exploitation, but Wiz notes broader risks in low code AI development platforms where basic security controls can fail across shared infrastructure. French telecom giant Orange discloses cyberattack French telecom giant Orange disclosed a cyber attack on one of its information systems, detected and isolated on July 25th by Orange Cyber Defense. The incident caused temporary service disruptions for some French customers, though no data theft has been confirmed. No attacker has been identified either, but the breach has similarities to recent global telecom intrusions. The linked to China's Salt Typhoon cyber espionage group FBI seizes 2.4 million in Bitcoin from new Chaos ransomware operation the FBI seized over $2.4 million in Bitcoin from a member of the New Chaos ransomware operation, now traced to attacks on Texas based companies. The funds were tied to an affiliate known as HORS, that's H O R S and confiscated on April 15th. The Department of Justice filed a civil forfeiture complaint on July 24 to claim permanent ownership. As we covered in Tuesday's show, this Chaos group is believed to be a rebrand of Black Suit Ransomware, itself an offshoot of the defunct Conti Gang. The seizure follows law enforcement pressure and recent takedowns of ransomware infrastructure linked to Black Suit. Poland says more than 30 suspects face trial over pro Russian sabotage Poland arrested 32 individuals from multiple nationalities, including Polish, Russian, Ukrainian, Belarusian and Colombian for allegedly conducting sabotage and arson attacks on behalf of Russian intelligence since the start of the war in Ukraine. One Colombian suspect has already been convicted in the Czech Republic for a series of arson attacks tied to a broader Russian hybrid warfare campaign using Telegram to recruit operatives. Poland's Prime Minister Donald Tusk warned that any efforts to destabilize the country would be met with ruthless action, huge thanks to our sponsor DropZone AI. What if your SAW could investigate every single alert without burning out your team? That is exactly what Dropzone AI does. They're the leader in autonomous security investigations and companies like Zapier and Fortune 500s are already on board. Their AI works alongside your analysts handling the routines so humans can be strategic. See them at Black Hat in Startup City booth 6427 or experience it yourself. DropZone AI has a self guided demo ready for you. FBI CISA warn about Scattered Spiders evolving Tactics the FBI and CISA issued an updated advisory warning that Scattered Spider remains a serious threat using sophisticated social engineering and intrusion tactics including phishing, MFA fatigue, sim swapping and ransomware like Dragon Force to reach systems including encrypting VMware ESXi servers. Despite recent arrests tied to the gang, US, UK, Canadian and Australian authorities emphasized that scattered Spiders evolving techniques continue to pose a big risk to national security and critical infrastructure nimble Gunra Ransomware Evolves with Linux Variants the Gunra Ransomware Group released a sophisticated Linux variant capable of encrypting files using up to 100 concurrent threads, a pretty big evolution from its original Windows targeting malware. Trend Micro researchers say that the variant supports partial encryption and configurable settings, giving attackers greater control and greater speed. After gaining notoriety for high profile breaches, the group is now apparently targeting diverse industries across multiple countries. Autocolor backdoor malware exploits SAP vulnerability In other Linux news, a Linux targeting malware called autocolor is exploiting a critical SAP netweaver vulnerability to infiltrate systems, with the first known attack hitting a US chemical company back in April. The malware acts as a remote access trojan and uses advanced persistent techniques to evade detection, establish control via tls and stay dormant when disconnected from its command server. Supply chain attacks spotted in GitHub Actions, gravity forms and NPM Researchers at Armis Labs uncovered major software supply chain attacks in GitHub Actions, the uaparser JS npm package and and the Gravity Forms WordPlus plugin, all involving backdoors or poisoned code that jeopardized thousands of systems. These incidents remind us how trusted developer tools can be compromised and how AI driven coding practices are being exploited. Experts warn that attackers can now backdoor vast numbers of software projects in days, making early detection and code integrity checks more critical than ever. If you're in Montreal, then you need to join us this Friday, August 1st for a CISO Series meetup. David Spark will be hosting the event at the Crew Cafe starting at 8:30am Network with some fellow CISO Series fans, play some games and grab a coffee or a bite. For more details, head on over to our events page@cisoseries.com and if you have thoughts on the news from today or about the show in general. Be sure to reach out to us@feedbacksoseries.com we'd love to hear from you. I'm Sarah Lane reporting for the CISO series. Thank you so much for listening.
David Spark
Cybersecurity headlines are available every weekday. Head to cisoseries.com for the full stories behind the headlines.
Cyber Security Headlines - Episode Summary Hosted by CISO Series | Release Date: July 30, 2025
In the latest episode of Cyber Security Headlines by CISO Series, host Sarah Lane delves deep into significant developments in the information security landscape. This episode covers a range of topics from critical vulnerabilities in popular platforms to sophisticated ransomware operations and evolving cyber threats targeting national security. Below is a detailed summary of the key discussions, insights, and conclusions presented in the episode.
At the outset, Sarah Lane highlights a significant vulnerability identified by Wiz Research in the Base44 vibe coding platform, recently acquired by Wix. This flaw allows attackers to bypass Single Sign-On (SSO) mechanisms and access private applications using only a public app ID.
“Wiz Research found a critical authentication flaw in Base44's vibe coding platform, letting attackers bypass SSO and access private apps using only a public app id.” [00:07]
Key Points:
Sarah reports on a cyberattack affecting one of France’s leading telecom providers, Orange. The incident was identified and contained by Orange Cyber Defense on July 25th, leading to temporary service disruptions for some users.
“French telecom giant Orange disclosed a cyber attack on one of its information systems, detected and isolated on July 25th by Orange Cyber Defense.” [00:07]
Key Points:
One of the episode’s highlights is the FBI’s successful seizure of over $2.4 million in Bitcoin from the New Chaos ransomware group, targeting Texas-based companies.
“The FBI seized over $2.4 million in Bitcoin from a member of the New Chaos ransomware operation, now traced to attacks on Texas based companies.” [00:07]
Key Points:
Sarah covers Poland’s significant crackdown on individuals allegedly conducting sabotage and arson on behalf of Russian intelligence since the onset of the Ukraine conflict.
“Poland's Prime Minister Donald Tusk warned that any efforts to destabilize the country would be met with ruthless action.” [00:07]
Key Points:
In an updated advisory, the FBI and CISA warn about the persistent and evolving threats posed by the Scattered Spider group, which continues to employ sophisticated social engineering and intrusion tactics.
“The FBI and CISA issued an updated advisory warning that Scattered Spider remains a serious threat using sophisticated social engineering and intrusion tactics.” [00:07]
Key Points:
Gunra Ransomware Group has introduced a sophisticated Linux variant, marking a notable evolution from its original focus on Windows-based systems.
“The Gunra Ransomware Group released a sophisticated Linux variant capable of encrypting files using up to 100 concurrent threads.” [00:07]
Key Points:
Autocolor, a Linux-targeting malware, is exploiting a critical vulnerability in SAP NetWeaver to infiltrate systems.
“A Linux targeting malware called autocolor is exploiting a critical SAP netweaver vulnerability to infiltrate systems.” [00:07]
Key Points:
Supply chain vulnerabilities remain a critical concern as researchers at Armis Labs identify major attacks within trusted development tools and platforms.
“Researchers at Armis Labs uncovered major software supply chain attacks in GitHub Actions, the uaparser JS npm package and the Gravity Forms WordPress plugin.” [00:07]
Key Points:
For professionals in Montreal, a CISO Series meetup is scheduled for Friday, August 1st, hosted by David Spark at the Crew Cafe starting at 8:30 AM. Attendees will have the opportunity to network, participate in games, and enjoy refreshments. More details can be found on the CISO Series Events Page.
This episode of Cyber Security Headlines provides a comprehensive overview of the current cybersecurity landscape, highlighting significant vulnerabilities, sophisticated ransomware operations, and the persistent evolution of cyber threats targeting both corporate and national infrastructures. Hosts like Sarah Lane ensure that listeners are well-informed about the latest developments, empowering them to bolster their security measures effectively.
For a more in-depth exploration of these stories, listeners are encouraged to visit CISOseries.com.
This summary is intended for informational purposes and reflects the discussions presented in the July 30, 2025 episode of Cyber Security Headlines by CISO Series.