Transcript
Dave Buettner (0:02)
You're listening to the Cyberwire Network powered by N2K.
Maria Vermazes (0:14)
We've all been there. You realize your business needs to hire someone yesterday. How can you find amazing candidates fast? Well, it's easy. Just use Indeed when it comes to hiring, Indeed is all you need. Stop struggling to get your job post noticed Indeed Sponsored Jobs helps you stand out and hire fast. Your post jumps to the top of search results so the right candidates see it first and it works. Sponsored Jobs on indeed get 45% more applications than non sponsored ones. One of the things I love about Indeed is how fast it makes hiring. And yes, we do actually use Indeed for hiring here at N2K CyberWire. Many of my colleagues here came to us through Indeed plus with Sponsored Jobs. There are no subscriptions, no long term contracts. You only pay for results. How fast is Indeed? Oh, in the minute or so that I've been Talking to you, 23 hires were made on Indeed according to Indeed Data Worldwide. There's no need to wait any longer. Speed up your hiring right now with Indeed and listeners to this show will get a $75 sponsored job credit. To get your jobs more visibility at indeed.com cyberwire just go to indee indeed.com cyberwire right now and support our show by saying you heard about Indeed on this podcast. Indeed.com cyberwire terms and conditions apply. Hiring Indeed is all you need. The FCC looks to counter Chinese cyber threats there's turmoil at CISA volt typhoon infiltrates a power utility for over 300 days. Europe takes the lead at Ukraine's annual cyber conference. Facebook discloses a critical vulnerability in Freetype. A new Android spyware infiltrates the Google Play Store. Our guest is Alvaro Alonso Ruiz, co founder and CCO of leanspace. Discussing software in space with T Minus Space Daily host Maria Vermazes and a UK hospital finds thousands of unwelcome guests guests on their network. It's Thursday, March 13, 2025. I'm Dave Buettner and this is your Cyberwire Intel Brief. Foreign thanks for joining us here once again. It is always great to have you with us. The FCC is establishing a National Security Council to counter Chinese cyber threats and maintain US leadership in key technologies like AI 5G and quantum computing. FCC Chair Brendan Carr says the Council will focus on mitigating cyberattacks, espionage and reducing supply chain reliance on adversaries. It will be led by Adam Chan, a former House China committee lawyer. The FCC's role has expanded amid U S China tech tensions overseeing telecom security, drone certification and subsea cables. A key early focus is Salt Typhoon, the large scale Chinese cyber attack on US telecom networks. The move aligns with broader US efforts like the CIA's China Mission center to curb Beijing's tech ambitions. China's embassy dismissed the concerns, urging a cooperative approach to U S China relations. In a piece for Wired, Eric Geller makes the case that the Cybersecurity and Infrastructure Security Agency is in crisis due to mass layoffs and political pressure under President Donald Trump's administration. Employees report low morale, leadership failures and weakened cybersecurity efforts, making it harder to protect US Infrastructure from cyber threats. Many critical staffers have been dismissed and partnerships with international and private sector allies are unraveling. CISA's election security efforts have been suspended and key AI and open source security programs are being dismantled. Employees fear political retaliation and the agency's acting director, Bridget Bean, is accused of prioritizing Trump's agenda over national security. Restrictions on communication, frozen projects and uncertainty about future layoffs have left employees demoralized and overwhelmed with adversaries like Russia, China and Iran ramping up cyber threats Former officials warn that CISA's decline could have dire consequences for US security and economic stability. Many fear worse is yet to come. Meanwhile, CISA is cutting $10 million in annual funding for Ms. ISAC and EI ISAC Cybersecurity Intelligence groups that help state and local governments defend against cyber threats. The move is part of broader budget and staffing cuts under the Trump administration. Experts warn that defunding EI ISAC leaves election offices vulnerable to foreign cyberattacks, shifting costs to local taxpayers. Cuts are also undermining international anti cybercrime efforts, including stopping Southeast Asian scam operations. Critics argue these moves weaken US Cyber defenses, leaving critical infrastructure and elections exposed to increasing threats from nation state hackers. The states aren't taking the ISAC cuts lying down. Arizona Secretary of State Adrian Fontes is proposing Vote isac, an independent cybersecurity initiative for state and local election offices. The plan aims to replace EI ISAC, which previously provided 247 threat monitoring and federal intelligence sharing. Without it, counties face a $45 million cybersecurity gap. Fantas has already reached out to states and stakeholders and plans to launch Vote ISAC as a nonprofit with support from public officials, philanthropy and private industry. Chinese threat actor Volt Typhoon infiltrated Littleton electric, light and water departments in Massachusetts, maintaining access for over 300 days before detection in November of 2023. The attack, discovered during Dragos OT security deployment, targeted operational technology data including energy grid operations and spatial layouts. Volt Typhoon, linked to Chinese espionage, is known for persistent access and data exfiltration. Dragos warns the group could escalate to stage two ICS attacks, potentially disrupting critical US infrastructure in the future. Elsewhere, Chinese cyber espionage group UNC3886 is deploying custom backdoors on end of life Juniper Network's MX routers, which no longer receive security updates. The backdoors, based on tiny shell malware, allow data exchange and command execution. Mandiant discovered the attacks in mid-2024, linking them to UNC3886, known for exploiting zero day vulnerabilities in Fortinet and VMware ESXi. The hackers bypassed Juno OS security by injecting malicious code into trusted processes, circumventing VeraExec protections. This ongoing espionage campaign threatens critical networking infrastructure globally. At Ukraine's Kyiv International Cyber Resilience Forum, Ukraine's major annual cyber conference, European allies took the lead amid diminished U.S. presence last year. The U.S. department of State and top American cyber officials played key roles, but no Trump administration officials attended this year, highlighting geopolitical tensions between Kyiv and Washington. While Google, Cloudflare and CrowdStrike partnered with the event, only Mandiant's Sandra Joyce gave a keynote. Discussions focused on European led cybersecurity strategies, with Ukrainian officials advocating for a collective European cybersecurity framework based on Ukraine's frontline experience. Ukraine formalized ties with the European Cybersecurity Competence center, signaling closer European cooperation. Past US Cyber aid, including software and funding via usaid, was acknowledged but largely absent from discussions. Ukrainian officials remain hopeful for future US Cyber collaborations, though the State Department has reportedly halted funding for cyber diplomacy programs under President Trump. Facebook has disclosed a critical vulnerability in FreeType, an open source font rendering library widely used in Linux, Android game engines and GUI frameworks. The flaw, present in all versions up to 2.13, allows arbitrary code execution and is actively exploited. The issue stems from an out of bounds Write when parsing TrueType, GX and Variable Font files. While FreeType patched the bug in February of 2023, older versions remain at risk. Developers are urged to update immediately. North Korean threat group APT37, also known as Scarcruft, deployed Cospy, an Android spyware that infiltrated Google Play and APK Pure via five malicious apps disguised as file managers and security tools. Active since March 2022, Cospy steals SMS call logs, GPS data files, audio and keystrokes. The malware evades detection by using Firebase firestore and encrypted C2 communications. Google has removed the infected apps, but users must manually uninstall them or reset devices. Google Play Protect helps block known versions of cospy. Coming up after the break, Maria Ramazes sits down with Alvaro Alonso Ruiz to discuss software in space. And a UK hospital finds thousands of unwelcome guests on their network. Stay with us. Cyber threats are more sophisticated than ever. Passwords. They're outdated and can be cracked in a minute. Cybercriminals are intercepting SMS codes and bypassing authentication apps. While businesses invest in network security, they often overlook the front door, the login. Yubico believes the future is passwordless. Yubikeys offer unparalleled protection against phishing. For individuals, SMBs and enterprises. They deliver a fast, frictionless experience that users love. Yubico is offering N2K followers a limited buy one get one offer. Visit yubico.com N2K to unlock this deal. That's Yubico. Say no to modern cyber threats Upgrade your security today. Do you know the status of your compliance controls right now? Like right now? We know that real time visibility is critical for security, but when it comes to our GRC programs, we rely on point in time checks. More than 8,000 companies like Atlassian and Quora have continuous visibility into their controls with Vanta. Here's the gist. Vanta brings automation to evidence collection across 30 frameworks like SoC2 and ISO 27001. They also centralize key workflows like policies, access reviews and reporting, and helps you get security questionnaires done five times faster with AI. Now that's a new way to GRC. Get $1,000 off Vanta when you go to vanta.com cyber that's vanta.com cyber for $1,000 off. Alvaro Alonso Ruiz is co founder and CCO of leanspace. He recently got together with my N2K colleague Maria Vermasis, host of the T Minus Space Daily. Their discussion centered on software in space.
