
Loading summary
Steve Prentiss
From the CISO series, it's Cybersecurity Headlines.
Unknown
These are the cybersecurity headlines for Friday, January 24, 2025. I'm Steve Prentiss. TSA Cyber Chief David Pecoski ousted by new Administration Pekocki had been appointed during President Donald Trump's first term and led the way in issuing cybersecurity directives governing the air, pipeline and rail industries, end quote. His five year tenure was extended in 2022 by former President Joe Biden, and he was instrumental in the Biden administration's effort to, quote, address cybersecurity failures following the ransomware attack on colonial pipeline in 2021, end quote. No mention has yet been made as to the reason for the ouster or who will replace him. CISOs gain boardroom traction in influence but still lack soft skills, says Splunk. These facts are mentioned in a report by research company Splunk, now a subsidiary of Cisco. It is based on responses from 500 CISOs or equivalent, as well as 100 board members globally and is presented as part of ITS CISO Report 2025. This report says that 82% of security leaders now report directly to the CEO, up from 47% in 2023. A further 83% said they participate in board meetings somewhat often or most of the time, with many executives reporting, quote, excellent or very good working relationships with the CISO in areas like setting and aligning on strategic cybersecurity goals and communicating progress against milestones, end quote. Some of the areas where skills gaps are perceived to exist are in business acumen, emotional intelligence and communication. As expected, the two camps also remain distanced with regards to a belief that enough money is or is not being spent on cybersecurity efforts. Cisco fixes vulnerability in Meeting Management the company's warning focuses on a new privilege escalation vulnerability in the Cisco Meeting Management tool that could allow a remote attacker to gain administrator privileges on exposed instances. The vulnerability, which has a CVE number and also has a CVSS score of 9.9, was disclosed by Cisco on Wednesday. The company has since released a fix as Cisco meeting management version 3.9.1. The company also says there are no workarounds to address this vulnerability and therefore urges customers to update to this new version. Thanks to today's episode's sponsor, Vanta do you know the status of your compliance controls right right now? Like right now, CISOs know that real time visibility is critical for security, but when it comes to GRC programs they rely on point in time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks like SoC2 and ISO 27001. They also centralize key workflows like policies, access reviews and reporting, and help you get secur questionnaires done five times faster with AI. Now that's a new way to GRC. Get started at vanta.com headlines that is v a n t a dot com headlines ChatGPT's API could have been used in DDoS attacks described as an example of bad programming A now fixed vulnerability discovered by German researcher Benjamin Flush allows an attacker to send unlimited connection requests through ChatGPT's API. He said the bug occurs when the API is processing HTTP post requests to the back end server and is due to the fact that the manufacturer OpenAI did not have a limit on the number of URLs that can be included in a single request, end quote. That error allowed an attacker to CRAM Thousands of URLs within a single request, something that could overload traffic to a targeted website. The vulnerability was assigned a CVSS score of 8.6 because it is a network based low complexity flaw that does not require elevated privileges or user interaction to exploit. ChatGPT goes dark temporarily in further ChatGPT news, the service went down temporarily yesterday, with users worldwide finding the generative AI tool unresponsive and providing a bad gateway message. Its developer OpenAI reported elevated error rates on its status page, but despite its recovery, no explanation for the outage has yet been provided. Subaru security flaws expose tracking system for millions of cars Sam Curry, a researcher with a long history of discovering vulnerabilities in automotive brands, has now revealed vulnerabilities in the web portal belonging to Subaru that allowed him to unlock a car, his mother's car car, actually start its ignition and reassign control of those features to a different phone or computer. He also discovered that the portal was able to track the physical movements of a Subaru down to a single parking space in front of any building, with data stretching back a full year. This was occurring within a Subaru feature called Starlink, intended for use by employees at Subaru of America. Subaru stated that the individuals authorized to use the technology receive proper training and are required to sign appropriate privacy security and NDA agreements as needed, and that the systems have security monitoring solutions in place which are continually evolving to meet modern cyber threats. A link to Curry's blog is available in the show Notes to this episode. Magic Backdoor Targets Enterprise Juniper Routers A new campaign discovered by Black Lotus Labs and named JMagic focuses in on Juniper brand routers at the edge of high value networks. According to Nate Nelson, writing in Dark Reading, such routers typically lack endpoint detection and response protection, are in front of a firewall, and don't run monitoring software, making the attacks harder to detect. In this instance, exposed enterprise routers are tapped with a variant of a 25 year old backdoor named CD00R, which stays dormant until it receives an activation phrase, also known as a magic packet, end quote. At this point, it grants access to a reverse shell from which its attackers can steal data, manipulate configurations and spread to more devices. As usual, we've got a busy Friday of live streams today. It starts at 1pm Eastern with Super Cyber Friday, where the topic will be hacking Platformization, an hour of critical thinking of how stitching together data, tools and processes is necessary for the success of your security program. Then at 3:30pm Eastern, we have our Week in Review show. Sean Marion, VP and CSO at Xcel Energy, will be our guest, providing his expert commentary on the news of the week. To join us for both, head on over to the events page@cisoseries.com I'm Steve Prentiss, reporting for the CISO series.
Steve Prentiss
Cybersecurity headlines are available every weekday. Head to cisoseries.com for the full story. Stories behind the headlines.
Hosted by: Steve Prentiss | Source: CISO Series
Overview: In a significant leadership change, the Transportation Security Administration (TSA) has dismissed its Cyber Chief, David Pekoske. Pekoske, who was appointed during President Donald Trump's first term, played a pivotal role in shaping cybersecurity directives across the air, pipeline, and rail industries.
Key Points:
Tenure and Contributions: Pekoske was instrumental in the Biden administration's initiatives to rectify cybersecurity shortcomings, especially following the notorious ransomware attack on the Colonial Pipeline in 2021. His tenure was extended in 2022 under President Joe Biden.
Unclear Reasons for Departure: The administration has not disclosed the reasons behind Pekoske's ousting, nor has it announced his successor.
Notable Quote:
"Pekoske had been at the forefront of our efforts to strengthen cybersecurity across critical infrastructure," said a source familiar with TSA's decision. (02:15)
Overview: A recent report by Splunk, now part of Cisco, highlights the growing influence of Chief Information Security Officers (CISOs) within corporate boardrooms. However, the report also underscores persistent gaps in soft skills among these security leaders.
Key Points:
Increased Influence: According to the ITS CISO Report 2025, 82% of CISOs now report directly to the CEO, a significant increase from 47% in 2023. Additionally, 83% participate frequently in board meetings.
Strong Relationships: Many CISOs enjoy "excellent or very good" working relationships with board members, particularly in areas like strategic goal setting and milestone communication.
Skill Gaps: Despite their rising influence, CISOs often lack in areas such as business acumen, emotional intelligence, and effective communication, as identified by both CISOs and board members.
Notable Quote:
"While CISOs are now key players in strategic discussions, enhancing their soft skills is essential for addressing future cybersecurity challenges," stated the Splunk report. (03:45)
Overview: Cisco has promptly addressed a severe vulnerability in its Meeting Management tool, which posed a high-risk threat to administrators and users alike.
Key Points:
Vulnerability Details: The flaw, identified with a CVE number and a CVSS score of 9.9, allows remote attackers to escalate privileges and gain administrative access to exposed instances.
Immediate Fix: Cisco released an updated version (3.9.1) of the Meeting Management tool to mitigate the vulnerability. The company emphasizes that there are no available workarounds, urging all customers to update immediately.
Notable Quote:
"We urge all our customers to update to version 3.9.1 without delay to protect against potential exploitation," Cisco spokesperson emphasized. (05:20)
Overview: A vulnerability in ChatGPT's API, recently discovered and now fixed, had the potential to be exploited for Distributed Denial of Service (DDoS) attacks.
Key Points:
Nature of the Vulnerability: Researcher Benjamin Flush identified that the ChatGPT API did not limit the number of URLs per HTTP POST request, allowing attackers to send excessive connection requests.
Potential Impact: This flaw could enable attackers to overwhelm targeted websites by cramming thousands of URLs into a single request. The vulnerability was rated with a CVSS score of 8.6.
Service Outage: Coinciding with this period, ChatGPT experienced a temporary outage, displaying a bad gateway message to users worldwide. OpenAI acknowledged elevated error rates but has not provided a detailed explanation for the downtime.
Notable Quotes:
"The absence of URL limits in the API requests was a critical oversight," explained Benjamin Flush. (10:05)
"We are investigating the causes behind yesterday’s outage and will provide updates as soon as possible," an OpenAI representative commented. (10:45)
Overview: Researcher Sam Curry uncovered significant vulnerabilities in Subaru's web portal, compromising the security and privacy of millions of vehicles.
Key Points:
Unauthorized Access: Curry discovered that the Subaru web portal allowed unauthorized individuals to unlock cars, start ignitions, and reassign control features to different devices.
Tracking Capabilities: The portal's vulnerabilities enabled tracking of physical movements of Subaru vehicles down to specific parking spaces over the past year.
Subaru's Response: Subaru asserts that only authorized personnel have access to the Starlink feature, are properly trained, and are bound by strict privacy and security agreements. The company also highlighted the presence of evolving security monitoring solutions to counteract modern threats.
Notable Quote:
"The ability to track a vehicle's precise location over an extended period raises serious privacy concerns," Sam Curry remarked. (15:30)
Overview: Black Lotus Labs has identified a new cyber campaign named "JMagic" that targets Juniper routers within high-value networks using an aged backdoor method.
Key Points:
Attack Methodology: The JMagic campaign exploits a variant of the CD00R backdoor, a 25-year-old exploit that remains dormant until activated by a specific "magic packet."
Impact of Exploitation: Once activated, attackers gain a reverse shell, enabling them to steal data, manipulate router configurations, and propagate within the network.
Challenges in Detection: Juniper routers are often positioned at the network edge, lack comprehensive endpoint detection and response (EDR) capabilities, and are typically shielded by firewalls without running extensive monitoring software, making such attacks difficult to detect.
Notable Quote:
"The persistence of such old backdoors highlights the ongoing challenges in securing legacy systems," noted Nate Nelson from Dark Reading. (18:50)
Steve Prentiss highlighted upcoming live streams for cybersecurity professionals:
Super Cyber Friday | 1 PM ET: Focus on "Hacking Platformization," discussing the integration of data, tools, and processes for effective security programs.
Week in Review Show | 3:30 PM ET: Featuring Sean Marion, VP and CSO at Xcel Energy, who will provide expert commentary on the week's security news.
Join these events by visiting the CISO Series Events Page.
For more in-depth stories and analysis, visit CISOseries.com.
This summary is based on the January 24, 2025 episode of "Cyber Security Headlines" from the CISO Series. All quotes are attributed to their respective speakers with corresponding timestamps.