New vulnerability packs a punch.

Published: Dec. 7, 2023, 9:20 p.m.

Unpacking LogoFAIL's threat to Windows and Linux. The US DHS's new healthcare cybersecurity strategy, and dual Russian influence campaigns. A look at supply chain risks, increased bot activity in retail, Meta's end-to-end encryption in Messenger and Android's Autospill vulnerability. On today\u2019s Industry Voices segment, we welcome Todd Thorsen, CISO from CrashPlan, with insights on data resiliency. And the discovery of an alleged software 'kill switch' in Polish trains.\nRemember to leave us a 5-star rating and review in your favorite podcast app.\nMiss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you\u2019ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.\n\nCyberWire Guest\nOn today\u2019s Industry Voices segment, we welcome Todd Thorsen, CISO from CrashPlan. Todd discusses data resiliency.\n\xa0In an era where ransomware and malicious attacks are relentless, even the most secure organizations are not immune. These attacks can cripple organizations financially, operationally, and damage their reputation and compliance standing. My guest today is Todd Thorsen, CISO from CrashPlan. In this sponsored Industry Voices segment, we delve into crucial strategies for bolstering data resiliency.\n\nFor links to all of today's stories check out our CyberWire daily news briefing:\nhttps://thecyberwire.com/newsletters/daily-briefing/12/232\n\nSelected Reading\nJust about every Windows and Linux device vulnerable to new LogoFAIL firmware attack (Ars Technica)\xa0\nCISA, NSA, FBI and International Cybersecurity Authorities Publish Guide on The Case for Memory Safe Roadmaps (CISA)\xa0\nThe Case for Memory Safe Roadmaps (Joint release)\nHEALTHCARE\xa0 SECTOR CYBERSECURITY (US Department of Health and Human Services)\nHHS releases cybersecurity strategy for health care sector (American Hospital Association)\nFake Taylor Swift Quotes Are Being Used to Spread Anti-Ukraine Propaganda (WIRED)\nObfuscation and AI Content in the Russian Influence Network \u201cDoppelg\xe4nger\u201d Signals Evolving Tactics (Recorded Future)\nBritain summons Russian ambassador over years-long FSB cyberespionage campaign (Reuters)\nNCSC exposes Russian cyber attacks on UK political processes (ComputerWeekly)\nRussian FSB cyber actor Star Blizzard continues worldwide spear-phishing campaigns (NCSC)\nDefending Democracy (NCSC)\nThe State of Supply Chain Defense: Annual Global Insights Report (BlueVoyant)\n2023 Holiday Bad Bot Report (Kasada)\nFacebook and Messenger to automatically encrypt messages (BBC)\nYour mobile password manager might be exposing your credentials (TechCrunch)\nDieselgate, but for trains \u2013 some heavyweight hardware hacking (BadCyber)\nShare your feedback.\nWe want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show.\xa0\nWant to hear your company in the show?\nYou too can reach the most influential leaders and operators in the industry. Here\u2019s our media kit. Contact us at cyberwire@n2k.com to request more info.\nThe CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. \xa9 2023 N2K Networks, Inc.\nLearn more about your ad choices. Visit megaphone.fm/adchoices