Transcript
Maria Vermazes (0:02)
You're listening to the Cyberwire network, powered by N2K.
Dave Bittner (0:11)
And now a word from our sponsor. Spy Cloud Identity is the new battleground and attackers are exploiting stolen identities to infiltrate your organization. Traditional defenses can't keep up. Spy Cloud's holistic Identity Threat protection helps security teams uncover and automatically remediate hidden exposures across your users from breaches, malware and phishing to neutralize identity based threats like account takeover, fraud and ransomware. Don't let invisible threats compromise your business. Get your free corporate Darknet exposure report@spycloud.com cyberwire and see what attackers already know. That's spycloud.com cyberwire.
Maria Vermazes (1:09)
RSAC 2025 comes to an end Canadian power company hit by a cyber attack Ascension Health discloses another breach UK luxury department store Harrods discloses attempted cyber attack Microsoft fixes a bug flagging Gmail as spam, an unofficial version of the signal app shared in photo EU finds T TikTok for violating GDPR with China data transfer US treasury to cut off Southeast Asian cybercrime Key player Passwordless by default coming your way and our guest is Kevin McGee from Microsoft, sharing a medley of interviews that he gathered on the show floor of RSAC 2025. Today is May 2, 2025. I'm Maria Vermazes, host of T Minus Space Daily podcast in for Dave Bittner today and this is your Cyberwire Intel Briefing. Happy Friday everybody. Thanks for joining us today. On the final day of RSA Conference 2025, the cybersecurity community discussed emerging challenges and innovations. The AI Governance panel featured leaders from OpenAI, Workday and Uber who explored strategies for building trust in AI systems, emphasizing the need for robust safety measures and compliance frameworks. Legal eagles and CISOs highlighted the critical need for collaboration between legal teams and cybersecurity leaders to navigate regulatory landscapes and bolster organizational resilience. Deputy National Security Advisor Anne Neuberger offered a comprehensive overview of US cybersecurity policy, discussing initiatives related to AI 5G 6G technologies and strategies to combat ransomware and illicit cryptocurrency activities and RSAC College Day connected aspiring cybersecurity professionals with industry experts, fostering mentorship and career development. Be sure to stay tuned for a final installment from intern Kevin from the RSAC 2025 floor. Halifax based electric utility Nova Scotia Power and its parent company Emera have shut down parts of their IT networks while responding to a cyberattack. According to a report from Security Week. The attack disrupted the utility's customer care phone line and online portal but did not affect physical operations. The company stated that there remains no disruption to any of our Canadian physical operations, including at Nova Scotia Powers generation, transmission and distribution facilities, the Maritime Link or the Brunswick pipeline, and the incident has not impacted the utility's ability to safely and reliably serve customers in Nova Scotia. There has been no impact to Amera's US or Caribbean utilities. CBC News reports that the utility is only responding to emergencies and outages, leaving some new customers unable to get their power turned on. US Health system Ascension is informing some patients that their medical data was breached after hackers compromised a third party vendor and in December 2024, according to a report from the Register. The breached data involved personal information including Social Security numbers as well as medical information. The medical data included information related to inpatient visits such as the place of service, physician name, admission and discharge dates, diagnosis and billing codes, medical record number and insurance company name. Ascension sustained a separate breach in May 2024 after it was hit by the Black Bosta ransomware gang. London luxury department store Harrods has restricted Internet access at its locations following an attempted cyber attack, according to the BBC. The company says its flagship store remains open and customers can still shop online. Two other major UK retailers, Marks and Spencer and Co Op, are currently recovering from disruptive cyber attacks. The UK's National Cybersecurity center, or NCSC, chief executive Dr. Richard Horn said in a statement that the disruption caused by the recent incidents impacting the retail sector are naturally a cause for concern to those businesses affected, their customers and the public. The NCSC continues to work closely with organizations that have reported incidents to us to fully understand the nature of these attacks and to provide expert advice to the wider sector based on the threat picture, horn added. These incidents should act as a wake up call to all organizations. I urge leaders to follow the advice on the NCSC website to ensure that they have appropriate measures in place to help prevent attacks and respond and recover effectively. Microsoft has resolved a machine learning issue and Exchange Online that incorrectly flagged legitimate Gmail emails as spam. The problem, tracked as EX 1064 599, began on April 25, causing affected messages to be diverted to users junk folders. Microsoft attributed the false positives to the ML model, misclassifying emails due to similarities with known spam patterns. By May 1, the company reverted to a previous ML model version, effectively mitigating the issue. A photograph taken during a Trump Cabinet meeting revealed that the now former National Security Advisor Mike Waltz was using an unofficial version of the signal messaging app known as TM Signal. Developed by Telemessage, this modified app adds message archiving capabilities potentially compromising signal standard end to end encryption. The image showed Walt communicating with Top officials including J.D. vance, Tulsi Gabbard and Marco Rubio, raising concerns about the security of sensitive government communications. The European Union has fined TikTok 530 million euros, or approximately US$600 million for violating the General Data Protection Regulation, or GDPR, by inadequately safeguarding European users data accessed by staff in China. Ireland's Data Protection Commission found that TikTok failed to ensure EU equivalent protections and lacked transparency about data transfers. The investigation also revealed that TikTok provided inaccurate information, initially denying storage of EU user data on Chinese servers, only to later admit some data had indeed been stored there. TikTok plans to appeal, asserting that the issues predate its Project Clover, which aims to localize data within Europe through new data centers. Ukrainian national artem Strizhak, age 35, has been extradited from Spain to the United States to face charges related to his alleged role in the Nephilim ransomware operation. According to a superseding indictment unsealed in the Eastern District of New York, Strzhak is accused of conspiring to commit fraud and extortion by deploying Nephilim ransomware against high revenue companies across the United States, Canada, Europe and Australia between 2018 and 2021. He reportedly entered into an agreement with Nephilim administrators receiving access to the ransomware in exchange for 20% of the ransom proceeds. The attacks targeted sectors including aviation, chemicals, construction and insurance, resulting in millions of dollars in losses. Strizhak is scheduled for arraignment and if convicted faces up to five years in prison. The US Treasury's Financial Crimes Enforcement Network has designated Cambodia based Huion Group as a primary money laundering concern under section 311 of the USA Patriot Act. This action aims to sever Huion's access to the US financial system, citing its role in laundering over $4 billion in illicit proceeds between August 2021 and January 2025. The funds are linked to North Korean cyber heists and Southeast Asian pig butchering scams, which are fraudulent investment schemes that exploit victims through social engineering tactics. Microsoft has announced that all new Microsoft accounts will be passwordless by default to enhance security against threats like phishing and credential stuffing. So instead of traditional passwords, new users will authenticate using methods such as passkeys, biometric verification like Windows, hello security keys or push notifications. Stay tuned after the break. Evan McGee is closing out RSAC 2025 with a high energy medley of interviews straight from the show floor, packed with sharp insights and bold ideas from some of cyber security's standout voice.
