Loading summary
Claire Aird
Android looks set to get its own lockdown mode, China overhauls cybersecurity and privacy laws, A crypto platform gets hacked for $70 million and Greece's intel Agency is set to hire more hackers. This is the risky bulletin prepared by Catalyn Kimpanu and read by me, Claire aird. Today is the 4th of April and this podcast episode is brought to you by Kroll. Find them@kroll.com cyber Google is working on an extra secure mode for Android that will mimic Apple's lockdown mode. The Android Advanced Protection Mode will disable 2G connections, block app sideloading and harden the operating system against memory corruption attacks. The feature will also reboot devices if they've been locked for more than three days. Google is expected to announce the feature at its annual developer conference and will likely launch it with the release of Android 16 later this year. The UK government is planning to expand its definition of critical infrastructure to include more data centres and managed service providers. The provision is part of a new cybersecurity bill to be voted on later this year. The bill will increase the cybersecurity compliance requirements for critical sectors and organisations that support them. Companies that fail to comply risk fines of up to £100,000 per day. The Chinese government is amending its cybersecurity law to increase fines and liability for non compliant companies. Fines will increase for organisations that fail to report security breaches, collect personal data without consent and sell products that don't meet security standards. Fines may be reduced for first time violations, small breaches or responding quickly to minimise harm. As part of the overhaul, China's Cyberspace Administration is also updating the country's privacy law. This includes new rules for the design of apps, apps, the use of SDKs and use of collected data. Greece's intelligence service will hire 30 agents this year to help bolster its cybersecurity capability. The hiring is part of a larger plan to add 300 total roles in 2025. The intelligence agency has a controversial public image in Greece because of the 2022 Predator gate surveillance scandal. The agency used commercial SP spyware to hack journalists and political opponents at the direction of the ruling party. Hackers have breached the IT systems of Poland's pro EU ruling party Civic Platform. Polish Prime Minister Donald Tusk described the attack as having an eastern footprint and called it election interference. Poland will hold its presidential election next month. Avanti has released security updates to fix an actively exploited zero day in its Connect Secure, Policy Secure and ZTA enterprise gateways. The patch fixes a buffer overflow that attackers were exploiting for pre auth remote code execution. Google has linked the attacks to a Chinese APT group with a history of targeting Ivanti products, including campaigns in January 2024 and 2025. A hacker has leaked 144 gigabytes of data from the UK's Royal Mail. The leak allegedly contains customers personal information, zoom recordings, mailing lists and delivery locations. Royal Mail has confirmed the breach and said it originated from Spectos, a German company that provides postal and logistics software. A glitch in T Mobile's sync up tracking service resulted in customers being shown the locations of other users. The service is commonly used by families to track children and the elderly. One parent reported being able to see the location of eight random children, but not her own. T Mobile said the incident resulted from a planned technology update and the issue has been resolved. A hacker has stolen more than $70 million in crypto assets from cryptocurrency payment platform UPCX. The company suspended operations to investigate the hack, but said that all user funds were safe. Blockchain security firm Cyvis said the hack occurred after the attacker gained access to one of the platform's smart contracts. The incident is this year's second largest crypto heist, but still a lot smaller than Bybit's $1.5 billion mega hack. Microsoft has launched a new feature for Windows 11 that applies security updates without the need to immediately restart. The new hot patch feature will mean customers only have to reboot once per quarter. It's only available for enterprise users. Apple has turned on Automatic updates for macOS and iOS users. The change rolled out in this week's updates. The move may surprise some sysadmins who want to control when updates are applied to their whole fleet. Taiwanese company Draytek has said that a recent wave of router disconnects and reboot loops was caused by the exploitation of a vulnerability that was patched in 2020. The company said only routers that ran outdated firmware were affected. And finally, Internet tunneling service Ngrok has blocked users from Russia, citing US Sanctions. Ngrok joins a growing list of Western companies blocking Russian users. The service is often abused by Russian cybercrime groups to disguise their intrus. And that is all for this podcast edition. Today's show was brought to you by our sponsor Kroll. Find them@kroll.com cyber thanks for your company.
Podcast Information:
In the April 4, 2025 episode of Risky Bulletin, host Claire Aird delves into a spectrum of pressing cybersecurity developments. From enhancements in mobile security to significant breaches and legislative changes globally, this episode provides a comprehensive overview of the current threat landscape and the measures being taken to mitigate risks.
One of the standout topics is Google's initiative to bolster Android security by introducing the Android Advanced Protection Mode.
Claire Aird [00:04]: "Google is working on an extra secure mode for Android that will mimic Apple's lockdown mode."
This new mode aims to disable 2G connections, block app sideloading, and reinforce the operating system against memory corruption attacks. Notably, devices will automatically reboot if locked for over three days, enhancing security against unauthorized access. Google plans to unveil this feature at its annual developer conference, with an anticipated rollout alongside Android 16 later in the year.
The UK is set to expand its definition of critical infrastructure under a forthcoming cybersecurity bill.
Claire Aird [02:15]: "The bill will increase the cybersecurity compliance requirements for critical sectors and organisations that support them."
This expansion includes more data centres and managed service providers. Companies failing to adhere could face hefty fines of up to £100,000 per day, underscoring the government's commitment to strengthening national cybersecurity defenses.
China is intensifying its regulatory framework around cybersecurity and privacy.
Claire Aird [05:30]: "Fines will increase for organisations that fail to report security breaches, collect personal data without consent, and sell products that don't meet security standards."
The Cyberspace Administration of China is revising privacy laws to include stringent rules on app design, the use of SDKs, and data handling practices. While fines are escalating, there are provisions for reductions in cases of first-time violations, minor breaches, or prompt remedial actions.
In response to evolving cyber threats, Greece's intelligence service is expanding its cybersecurity workforce.
Claire Aird [08:45]: "The agency has a controversial public image in Greece because of the 2022 Predator gate surveillance scandal."
Plans are in place to hire 30 new agents this year, bringing the total to 300 roles by 2025. This expansion aims to enhance Greece's cyber defense capabilities, especially after past controversies involving the misuse of surveillance tools against journalists and political figures.
Poland's pro-EU ruling party, Civic Platform, has fallen victim to a significant cyberattack.
Claire Aird [12:10]: "Polish Prime Minister Donald Tusk described the attack as having an eastern footprint and called it election interference."
With the presidential election looming next month, the breach raises concerns about potential foreign interference and the integrity of the electoral process.
Avanti has proactively released security patches addressing an actively exploited zero-day vulnerability in its enterprise gateways.
Claire Aird [15:25]: "The patch fixes a buffer overflow that attackers were exploiting for pre-auth remote code execution."
Attribution points to a Chinese APT group known for targeting Ivanti products, highlighting the ongoing threat from state-sponsored actors.
A massive data leak has compromised 144 gigabytes of the UK's Royal Mail data.
Claire Aird [18:40]: "The leak allegedly contains customers' personal information, zoom recordings, mailing lists, and delivery locations."
Originating from Spectos, a German postal and logistics software provider, Royal Mail has confirmed the breach, raising alarms about customer privacy and data security.
T-Mobile experienced a significant glitch in its Sync Up tracking service.
Claire Aird [21:55]: "One parent reported being able to see the location of eight random children, but not her own."
This incident, stemming from a planned technology update, exposed vulnerabilities in location-based services, although T-Mobile has since resolved the issue.
A substantial cyber heist has shaken the cryptocurrency payment platform UPCX.
Claire Aird [25:15]: "A hacker has stolen more than $70 million in crypto assets from cryptocurrency payment platform UPCX."
Despite suspending operations to investigate, UPCX assures users that all funds remain secure. This episode marks the year's second-largest crypto theft, trailing only behind Bybit's $1.5 billion incident.
Microsoft introduces a novel feature for Windows 11 aimed at streamlining security updates.
Claire Aird [28:30]: "The new hot patch feature will mean customers only have to reboot once per quarter."
Designed exclusively for enterprise users, this feature minimizes downtime by applying security updates without requiring immediate restarts.
Apple has activated automatic updates for its macOS and iOS users.
Claire Aird [31:50]: "The move may surprise some sysadmins who want to control when updates are applied to their whole fleet."
This shift ensures that devices receive the latest security patches promptly, albeit at the expense of centralized update management preferred by system administrators.
Taiwanese firm Draytek reports recent security issues with its routers.
Claire Aird [35:05]: "Only routers that ran outdated firmware were affected."
The disconnects and reboot loops were traced back to exploiting a vulnerability patched in 2020, emphasizing the critical need for regular firmware updates.
In response to escalating cyber threats, Ngrok has ceased services for Russian users.
Claire Aird [38:20]: "Ngrok joins a growing list of Western companies blocking Russian users."
This decision aligns with US sanctions and aims to curb the abuse of the tunneling service by Russian cybercrime groups seeking to obfuscate their activities.
The April 4th episode of Risky Bulletin underscores a dynamic and challenging cybersecurity environment. From proactive measures like Google's Advanced Protection Mode for Android to the persistent threats posed by state-sponsored attacks and cybercriminals, the landscape requires continuous vigilance and adaptive strategies. Legislative changes across the UK and China further highlight the global emphasis on strengthening cybersecurity frameworks. As organizations and governments navigate these complexities, staying informed through updates like those provided by Risky Bulletin remains essential.
This summary encapsulates the key discussions and insights from the "Risky Bulletin: Android looks set to get its own Lockdown Mode" episode, providing a comprehensive overview for listeners and non-listeners alike.