Transcript
A (0:02)
You're listening to the Cyberwire Network powered by N2K.
A (0:14)
We've all been there. You realize your business needs to hire someone yesterday. How can you find amazing candidates fast? Well, it's easy. Just use Indeed when it comes to hiring, Indeed is all you need. Stop struggling to get your job post noticed Indeed. Sponsored Jobs helps you stand out and hire fast. Your post jumps to the top of search results so the right candidates see it first. And it works. Sponsored Jobs on indeed get 45% more applications than non sponsored ones. One of the things I love about Indeed is how fast it makes hiring. And yes, we do actually use Indeed for hiring here at N2K CyberWire. Many of my colleagues here came to us through Indeed. Plus with Sponsored Jobs. There are no subscriptions, no long term contracts. You only pay for results. How fast is Indeed? Oh, in the minute or so that I've been Talking to you, 23 hires were made on Indeed according to Indeed Data Worldwide. There's no need to wait any longer. Speed up your hiring right now with Indeed and listeners to this show will get a $75 sponsored job credit. To get your jobs more visibility at indeed.com cyberwire just go to indee indeed.com cyberwire right now and support our show by saying you heard about Indeed on this podcast. Indeed.com cyberwire terms and conditions apply. Hiring Indeed is all you need.
A (2:00)
We got your Patch Tuesday Rundown Federal process Prosecutors charge a Houston man with smuggling Nvidia chips to China, a Ukrainian woman for targeting critical infrastructure, and an Atlanta activist for wiping his phone. The power sector sees cyber threats doubling the new Spider man fishing kit slings its way across the dark web. Our guest is Dick o', Brien, principal intelligence analyst with Symantec and Carbon Black Threat Hunter Team. Discussing unwanted gifts, a major campaign that lures targets with fake party invites and the Pentagon unveils a killer chatbot.
A (2:52)
It's Wednesday, December 10, 2025. I'm Dave Bittner and this is your Cyberwire Intel Brief.
B (3:07)
Foreign.
A (3:13)
Thanks for joining us here today. It's great to have you with us. Microsoft's December Patch Tuesday rolled out fixes for 57 vulnerabilities including 30 days. Only one is under active exploitation, a use after free flaw in the Windows cloud files mini filter driver that allows privilege escalation to system. Microsoft says it has seen in the wild activity but has not shared attack details. A second mini filter driver bug carries the same severity and is likely to be exploited. Publicly disclosed command injection issues in Copilot for JetBrains and PowerShell also received patches along with 13 office vulnerabilities that include two high severity remote code execution flaws triggered through the preview pane. Adobe issued nearly 140 fixes across ColdFusion and Experience Manager addressing critical remote code execution, widespread cross site scripting and vulnerable components. Major industrial vendors published advisories covering code execution, denial of service and unauthorized access across Siemens, Schneider Electric, Rockwell Automation and Phoenix Contact products. Google closed the Gemini Jack prompt injection weakness in Gemini Enterprise, which allowed hidden instructions in documents or emails to drive automated data exfiltration. Fortinet patched 18 vulnerabilities, including two authentication bypass flaws in Fortacloud, SSO login and several high severity issues across Fortaweb, Fortisandbox and Fortavoice.
