"Pantsdown" firmware vulnerability. ChromeLoader warning. Conti update. Ransomware at SpiceJet. CISA's Known Exploited Vulnerabilities Catalog expands. Kyiv honors Google. Reformed ID thief.

Published: May 26, 2022, 8:15 p.m.

"Pantsdown" in QCT Baseboard Management Controllers. A warning on ChromeLoader. Conti updates. Ransomware\u2019s effect on SpiceJet. CISA's Known Exploited Vulnerabilities Catalog expands, again. Kyiv honors Google. Josh Ray from Accenture reminds us it\u2019s military appreciation month. Our guest is Melissa Bischoping of Tanium with lessons learned from the American Dental Association ransomware attack. And a poacher turned gamekeeper?\n\nFor links to all of today's stories check out our CyberWire daily news briefing:\nhttps://thecyberwire.com/newsletters/daily-briefing/11/102\n\nSelected reading.\nCritical 'Pantsdown' BMC Vulnerability Affects QCT Servers Used in Data Centers (The Hacker News)\nChromeLoader: a pushy malvertiser (Red Canary)\xa0\nConti leaks data stolen during January attack on Oregon county (The Record by Recorded Future)\xa0\nIs the Conti Ransomware Gang Stronger Apart Then Together? (OODA Loop)\xa0\nSpiceJet: Passengers stranded as India airline hit by ransomware attack (BBC News)\xa0\nSpiceJet's woes continue as ransomware attack delays flights (The Loadstar) .\nSpiceJet's brush with ransomware is a timely reminder to protect yourself against this cyber menace (cnbctv18.com\nCISA Adds 34 Known Exploited Vulnerabilities to Catalog (CISA)\xa0\nMykhailo Fedorov presented the first "Peace prize" to Google (Digital Gov)\xa0\n\xa0Notorious Vietnamese hacker turns government cyber agent (France 24)\nLearn more about your ad choices. Visit megaphone.fm/adchoices