Transcript
A (0:02)
You're listening to the Cyberwire network, powered by N2K. AI agents are now reading sensitive data, executing actions and making decisions across our environments. But are we managing their access safely? Join Dave Bittner and Barak Shalef from Oasis Security on on Wednesday, December 3rd at 1pm Eastern for a live discussion on agentic access management and how to secure non human identities without slowing. Innovation can't make it live. Register now to get on demand access after the event, visit events.thecyberwire.com that's events with an s.thecyberwire.com to save your spot.
B (1:01)
What's your 2am Security worry? Is it do I have the right controls in place?
C (1:06)
Maybe?
B (1:07)
Are my vendors secure? Or the one that really keeps you up at night? How do I get out from under these old tools and manual processes? That's where Vanta comes in. Vanta automates the manual work so you can stop sweating over spreadsheets, chasing audit evidence and filling out endless questionnaires. Their trust management platform continuously monitors your systems, centralizes your data and simplifies your security at scale. And it fits right into your workflows, using AI to streamline evidence collection, flag risks and keep your program audit ready all the time. With Vanta, you get everything you need to move faster, scale confidently and finally get back to sleep. Get started@vanta.com cyber that's V A N T A dot com cyber.
A (2:10)
CISA warns of Spyware Targeting Messaging apps Code Red this is not a test. Infostealer campaign spreads via malicious blender files Chai Halludes second coming real estate finance firm Cetus AMC Investigates Breach Dartmouth College Discloses Oracle EBS Breach Dave Bittner is joined by Tim Starks, senior reporter from cyberscoop, to discuss the Trump administration's upcoming cyber strategy and tis the season for deals and digital deception. Today is Tuesday, november 25, 2025. I'm maria varmazes, host of n2k's t minus space daily, in for dave buettner today and this is your cyberwire intel briefing. Thank you for joining me everyone. Let's get started. The U.S. cybersecurity and Infrastructure Security Agency, better known as CISA, issued an advisory yesterday warning of multiple cyber threat actors actively leveraging commercial spyw to target users of mobile messaging applications. The spyware is delivered via phishing, zero click exploits and app impersonation. SISSA notes that quote while current targeting remains opportunistic, evidence suggests these cyber actors focus on high value individuals such as current and former high ranking government, military and political officials. As well as civil society organizations and individuals across the United States, the Middle east and Europe. A sophisticated cyber attack on the Code Red emergency notification system managed by OnSolve has forced its nationwide decommissioning and migration to a new platform due to service disabling infrastructure compromise. The breach exposed thousands of users, names, phone numbers, email addresses and passwords previously used to register for alerts. Although no payment card or financial data was stored, localities across Missouri and Colorado, among others, remain unable to send targeted voice, text or email alerts for water main breaks, severe weather and other emergencies, leaving public safety communications vulnerable. Municipal officials are urging all affected users to change reused passwords immediately while emergency management agencies scramble to deploy alternative alerting channels and prepare communities for a protracted system recovery timeline. The supply chain malware campaign dubbed Shai Second Coming has resurfaced in the NPM ecosystem using malicious packages with a two stage loader that can propagate across 100 packages per execution and wipe a compromised developer's home directory if authentication fails. The threat now leverages randomly named GitHub repos to reduce detection abuses, credential access to packages in CI pipelines, and has prompted security firms to rapidly add affected versions to their malicious package databases. Checkmark's developers and organizations are urged to temporarily block access to public NPM registries, review NPM token permissions and configure endpoint protections to flag the loader, file names and malicious behavior. Real estate finance technology vendor Citus AMC has confirmed that it discovered a breach on November 12th the that resulted in the theft of client information, according to a report from the Register. The company said in a statement, corporate data associated with certain of our clients relationships with CETIS amc, such as accounting records and legal agreements has been impacted. Certain data relating to some of our clients customers may also have been impacted. The scope, nature and extent of such impact remain under investigation by the company AS and its third party advisors. The New York Times cites sources as saying that the company has notified JPMorgan Chase, Citi and Morgan Stanley that their client data may have been affected. The FBI is investigating the breach. Dartmouth College has disclosed that it was among the victims of a wave of zero day attacks targeting Oracle E Business Suite or EBS instances, according to a report from Bleeping Computer. The university hasn't disclosed the total number of impacted individuals, but said in a breach notification with the Maine Attorney General's office that just under 1,500 Maine residents were affected. The breach occurred in August 2025 and involved names and Social Security numbers. The Klopp ransomware gang has posted the alleged stolen data to its leak site. The other confirmed victims of Klopp's Oracle EBS campaign include Logitech, Harvard University, the Washington Post, Envoy Air, and Mazda. John Holtquist, chief analyst at Google's Threat Intelligence Group, told Bleeping Computer that dozens of additional organizations were likely breached. Coming up after the break, we have Dave Bittner sitting down with Tim Starks, senior reporter from cyberscoop, to discuss the Trump administration's upcoming cyber strategy and who's the season for deals and digital deceptions.
