Go offline with the Player FM app!
Get to patching: Patch Tuesday updates.
Manage episode 482793396 series 112238
A busy Patch Tuesday. Investigators discover undocumented communications devices inside Chinese-made power inverters. A newly discovered Branch Privilege Injection flaw affects Intel CPUs. A UK retailer may claim up to £100mn from its cyber insurers after a major cyberattack. A Kosovo national has been extradited to the U.S. for allegedly running an illegal online marketplace. CISA will continue alerts on its website following industry backlash. On our Industry Voices segment, Neil Hare-Brown, CEO at STORM Guidance, discusses Cyber Incident Response (CIR) retainer service provision. Shoring up the future of the CVE program.
Remember to leave us a 5-star rating and review in your favorite podcast app.
Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.
CyberWire Guest
On today’s Industry Voices segment, we are joined by Neil Hare-Brown, CEO at STORM Guidance, discussing Cyber Incident Response (CIR) retainer service provision. You can learn more here.
Selected Reading
Microsoft Patch Tuesday security updates for May 2025 fixed 5 actively exploited zero-days (Security Affairs)
SAP patches second zero-day flaw exploited in recent attacks (Bleeping Computer)
Ivanti fixes EPMM zero-days chained in code execution attacks (Bleeping Computer)
Fortinet fixes critical zero-day exploited in FortiVoice attacks (Bleeping Computer)
Vulnerabilities Patched by Juniper, VMware and Zoom (SecurityWeek)
ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Schneider, Phoenix Contact (SecurityWeek)
Adobe Patches Big Batch of Critical-Severity Software Flaws (SecurityWeek)
Ghost in the machine? Rogue communication devices found in Chinese inverters (Reuters)
New Intel CPU flaws leak sensitive data from privileged memory (Bleeping Computer)
M&S cyber insurance payout to be worth up to £100mn (Financial Times)
US extradites Kosovo national charged in operating illegal online marketplace (The Record)
CISA Planned to Kill .Gov Alerts. Then It Reversed Course. (Data BreachToday)
CVE Foundation eyes year-end launch following 11th-hour rescue of MITRE program (CyberScoop)
Share your feedback.
We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show.
Want to hear your company in the show?
You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at [email protected] to request more info.
The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Learn more about your ad choices. Visit megaphone.fm/adchoices
3328 episodes
Manage episode 482793396 series 112238
A busy Patch Tuesday. Investigators discover undocumented communications devices inside Chinese-made power inverters. A newly discovered Branch Privilege Injection flaw affects Intel CPUs. A UK retailer may claim up to £100mn from its cyber insurers after a major cyberattack. A Kosovo national has been extradited to the U.S. for allegedly running an illegal online marketplace. CISA will continue alerts on its website following industry backlash. On our Industry Voices segment, Neil Hare-Brown, CEO at STORM Guidance, discusses Cyber Incident Response (CIR) retainer service provision. Shoring up the future of the CVE program.
Remember to leave us a 5-star rating and review in your favorite podcast app.
Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.
CyberWire Guest
On today’s Industry Voices segment, we are joined by Neil Hare-Brown, CEO at STORM Guidance, discussing Cyber Incident Response (CIR) retainer service provision. You can learn more here.
Selected Reading
Microsoft Patch Tuesday security updates for May 2025 fixed 5 actively exploited zero-days (Security Affairs)
SAP patches second zero-day flaw exploited in recent attacks (Bleeping Computer)
Ivanti fixes EPMM zero-days chained in code execution attacks (Bleeping Computer)
Fortinet fixes critical zero-day exploited in FortiVoice attacks (Bleeping Computer)
Vulnerabilities Patched by Juniper, VMware and Zoom (SecurityWeek)
ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Schneider, Phoenix Contact (SecurityWeek)
Adobe Patches Big Batch of Critical-Severity Software Flaws (SecurityWeek)
Ghost in the machine? Rogue communication devices found in Chinese inverters (Reuters)
New Intel CPU flaws leak sensitive data from privileged memory (Bleeping Computer)
M&S cyber insurance payout to be worth up to £100mn (Financial Times)
US extradites Kosovo national charged in operating illegal online marketplace (The Record)
CISA Planned to Kill .Gov Alerts. Then It Reversed Course. (Data BreachToday)
CVE Foundation eyes year-end launch following 11th-hour rescue of MITRE program (CyberScoop)
Share your feedback.
We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show.
Want to hear your company in the show?
You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at [email protected] to request more info.
The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Learn more about your ad choices. Visit megaphone.fm/adchoices
3328 episodes
All episodes
×Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.