Cybersecurity Daily: News & Threats

Klue's Double Extortion, Dialog Leak & $10M US Breach Costs

4 min · 28. kesä 2026
jakson Klue's Double Extortion, Dialog Leak & $10M US Breach Costs kansikuva

Kuvaus

(00:00:00) Klue's Double Extortion, Dialog Leak & $10M US Breach Costs (00:00:46) Icarus Gets Hit Back (00:01:37) Dialog Misconfiguration, Not Crime (00:02:17) US Breach Costs Hit $10.22 Million (00:03:01) The $1.9 Million AI Security Divide (00:03:27) Third-Party Risk Now Systemic A supply chain attack on market intelligence platform Klue has exposed roughly 195 enterprise customers after attackers stole OAuth tokens tied to Salesforce, Gong, Deel, and other integrations — bypassing MFA entirely. In a rare twist, the original threat actor, Icarus, was itself compromised by a second criminal group, leaving victims navigating simultaneous extortion demands from two separate actors over the same stolen dataset. Meanwhile, a data exposure at the Dialog Group — a private network linked to Peter Thiel — turned out to stem from a website misconfiguration rather than criminal intrusion. The practical outcome was the same: member records, including details linked to a White House intelligence official and a special operations officer, were publicly accessible to anyone who looked. New IBM Cost of a Data Breach data sharpens the financial picture. The average US breach now costs $10.22 million — an all-time high and more than double the global average of $4.44 million. The US recorded 3,322 breaches in 2024, driven by a complex regulatory environment spanning fifty-state notification laws, HIPAA, and SEC disclosure requirements. Two metrics stand out for security leaders. Organizations using AI and automation in security operations saved $1.9 million per breach compared to those without — a gap wide enough to reframe AI adoption as cost control rather than efficiency. Third-party breaches now account for 30% of all incidents, double the prior-year rate, with the Klue case illustrating exactly how a single compromised credential can extend a blast radius across hundreds of downstream customers. A YesWee production. Built using AI technology. This episode includes AI-generated content.

Kommentit

0

Ole ensimmäinen kommentoija

Rekisteröidy nyt ja liity Cybersecurity Daily: News & Threats-yhteisöön!

Aloita maksutta

14 vrk ilmainen kokeilu

Kokeilun jälkeen 7,99 € / kuukausi. · Peru milloin tahansa.

  • Podimon podcastit
  • 20 kuunteluaikaa / kuukausi
  • Lataa offline-käyttöön

Kaikki jaksot

50 jaksot

jakson Klue's Double Extortion, Dialog Leak & $10M US Breach Costs kansikuva

Klue's Double Extortion, Dialog Leak & $10M US Breach Costs

(00:00:00) Klue's Double Extortion, Dialog Leak & $10M US Breach Costs (00:00:46) Icarus Gets Hit Back (00:01:37) Dialog Misconfiguration, Not Crime (00:02:17) US Breach Costs Hit $10.22 Million (00:03:01) The $1.9 Million AI Security Divide (00:03:27) Third-Party Risk Now Systemic A supply chain attack on market intelligence platform Klue has exposed roughly 195 enterprise customers after attackers stole OAuth tokens tied to Salesforce, Gong, Deel, and other integrations — bypassing MFA entirely. In a rare twist, the original threat actor, Icarus, was itself compromised by a second criminal group, leaving victims navigating simultaneous extortion demands from two separate actors over the same stolen dataset. Meanwhile, a data exposure at the Dialog Group — a private network linked to Peter Thiel — turned out to stem from a website misconfiguration rather than criminal intrusion. The practical outcome was the same: member records, including details linked to a White House intelligence official and a special operations officer, were publicly accessible to anyone who looked. New IBM Cost of a Data Breach data sharpens the financial picture. The average US breach now costs $10.22 million — an all-time high and more than double the global average of $4.44 million. The US recorded 3,322 breaches in 2024, driven by a complex regulatory environment spanning fifty-state notification laws, HIPAA, and SEC disclosure requirements. Two metrics stand out for security leaders. Organizations using AI and automation in security operations saved $1.9 million per breach compared to those without — a gap wide enough to reframe AI adoption as cost control rather than efficiency. Third-party breaches now account for 30% of all incidents, double the prior-year rate, with the Klue case illustrating exactly how a single compromised credential can extend a blast radius across hundreds of downstream customers. A YesWee production. Built using AI technology. This episode includes AI-generated content.

28. kesä 20264 min
jakson AI Dev Tool Backdoors, Europe's Ransomware Surge & Dark Web AI Explosion kansikuva

AI Dev Tool Backdoors, Europe's Ransomware Surge & Dark Web AI Explosion

(00:00:00) AI Dev Tool Backdoors, Europe's Ransomware Surge & Dark Web AI Explosion (00:00:38) MCP Implicit Trust Problem (00:01:22) European Ransomware Supply Chain Surge (00:02:12) Dark Web AI Tool Explosion (00:03:07) SIP Telephony Industrialized Exploitation (00:03:34) Watchpoints and Closing A critical vulnerability in AI developer tooling is rewriting the threat model for software teams worldwide. CVE-2026-12957 in Amazon Q Developer allows a malicious config file to execute arbitrary code using the developer's live AWS credentials — silently, with no prompt. But the story is bigger than one vendor: Claude Code, Cursor, and Windsurf carry structurally identical flaws, all rooted in the Model Context Protocol's implicit trust of project-level config files. Patches are available for Amazon Q Developer; the open question is how many other MCP-compatible tools share the same dangerous assumption. In Europe, ransomware disclosures jumped 55% in the first four months of 2026 versus the same period in 2025. The dominant vector is supply chain compromise: a single third-party breach chain hit 64 organisations and exposed over one million personal records. Qilin is now active across 26 of 31 European countries, putting NIS2 and DORA compliance programs under real operational pressure. On the threat democratisation front, dark web posts referencing AI hacking tools surged from 38 in December 2025 to roughly 1,500 by February 2026 — a 40-fold increase. WormGPT is now freemium. Voice cloning from three seconds of audio succeeds in over 90% of social engineering attempts. The floor for capable attacks has dropped sharply. Finally, a honeypot monitoring SIP telephony systems recorded 1.86 million credential attempts in just 18 days alongside 90,000 toll-fraud call attempts — evidence that enterprise phone infrastructure is being monetised at industrial scale. Today's through-line: implicit trust, in config files, supplier relationships, and telephony auth, is being exploited methodically and at volume. This episode includes AI-generated content.

Eilen5 min
jakson ShinyHunters Hits NAIC, PQC Federal Mandate & US Breach Costs Peak kansikuva

ShinyHunters Hits NAIC, PQC Federal Mandate & US Breach Costs Peak

(00:00:00) ShinyHunters Hits NAIC, PQC Federal Mandate & US Breach Costs Peak (00:01:19) ShinyHunters Breaches NAIC (00:02:12) Post-Quantum Cryptography Federal Mandate (00:03:07) Mexico's Six-Year Cybersecurity Plan (00:03:34) US Breach Costs Hit Record High Today's briefing opens with two actively exploited device families — Lantronix EDS5000 and Ubiquiti UniFi OS — now under a 72-hour federal patch deadline set by CISA for June 26th. The Lantronix flaw (CVE-2025-67038, CVSS 9.8) allows root-level OS command execution, while three chained Ubiquiti flaws are already delivering reverse shells in the wild via a Bishop Fox proof-of-concept. The insurance sector's primary US regulator, the National Association of Insurance Commissioners, confirmed a breach by ShinyHunters, who claim to have stolen 3.1 terabytes of data through an Oracle PeopleSoft zero-day. The NAIC disputes the full scope, but the FBI is now involved — and the sensitivity of state-level regulatory data makes this a high-value target regardless of exact volume. The White House signed an executive order on June 25th establishing the first binding federal mandate for post-quantum cryptography migration. Agencies must adopt NIST-approved PQC algorithms for key establishment by end of 2030 and digital signatures by end of 2031 — a tight timeline driven by harvest-now, decrypt-later threats from state-level adversaries. Mexico's Congress approved a National Cybersecurity Plan running 2025 through 2030, including a national cyber range and a Latin America incident response hub, though institutional durability remains an open question. Finally, a new industry report shows global average data breach costs fell 9% to $4.44 million — but US costs hit an all-time high of $10.22 million per breach, driven by healthcare exposure, financial regulation, and 50-state notification complexity. Organizations with AI-driven security tooling averaged $1.9 million less per breach. This episode includes AI-generated content.

26. kesä 20265 min
jakson Critical Infrastructure RCEs, npm RAT & Post-Quantum Mandate kansikuva

Critical Infrastructure RCEs, npm RAT & Post-Quantum Mandate

(00:00:00) Critical Infrastructure RCEs, npm RAT & Post-Quantum Mandate (00:00:46) Ubiquiti UniFi RCE Chain (00:01:44) npm PostCSS RAT Campaign (00:02:20) OpenAI GPT-5.5-Cyber Launch (00:02:54) Federal Post-Quantum Deadline (00:03:27) Texas Breach Watch Three critical infrastructure vulnerabilities hit Lantronix, Ubiquiti, and Cisco simultaneously — all confirmed actively exploited within 48 hours of disclosure. The Ubiquiti UniFi chain is particularly alarming: three maximum-severity flaws tracked as CVE-2026-34908, 34909, and 34910 can be chained in a single HTTP request to achieve full root access, with commodity malware already deploying the chain in the wild. Cisco's SSRF flaw in Unified Communications Manager and Lantronix's CVSS 9.8 command injection round out a trifecta that highlights how fast exploitation windows are collapsing. The npm ecosystem surfaces another supply chain threat: three PostCSS-impersonating packages used AES-256 encryption to hide a Windows RAT until runtime, bypassing static analysis and code review. Over a thousand downloads before discovery — small in number, significant in method maturity. OpenAI released GPT-5.5-Cyber to trusted defenders, already surfacing eight Linux kernel memory leaks and a 23-year-old OpenBSD flaw. The capability cuts both ways: defenders and attackers now both have access to faster vulnerability discovery tools. A new Executive Order makes post-quantum cryptography binding for federal high-value assets by December 31, 2030, with FIPS 203, 204, and 205 standards already in place. The mandate is the change — and the compliance cost runs into billions. Two Texas breaches round out the episode: Texas Parks and Wildlife lost data on three million licence holders via a vendor compromise, and Carnival Cruise disclosed a breach affecting over 800,000 Texas residents, with disclosure arriving 44 days after the incident. Cybersecurity Daily is a YesWee production, built using AI technology. This episode includes AI-generated content.

25. kesä 20265 min
jakson Space Surge, Icarus OAuth & Chrome Zero-Day CVE-2026-11645 kansikuva

Space Surge, Icarus OAuth & Chrome Zero-Day CVE-2026-11645

(00:00:00) Space Surge, Icarus OAuth & Chrome Zero-Day CVE-2026-11645 (00:00:51) Klue Breach Hits Security Vendors (00:01:51) Bajaj Auto Ransomware Disclosed (00:02:37) FortiBleed Automated Domain Takeover (00:03:13) Five Eyes AI Warning and GPT-5.5-Cyber (00:04:13) Chrome Zero-Day CVE-2026-11645 Today's cybersecurity briefing opens with the sharpest signal in weeks: a 400% surge in cyberattacks against space infrastructure, timed to the escalation of U.S. and Israeli military operations against Iran. The attacks blend nation-state sophistication with hacktivist volume, targeting defense contractors, aerospace operators, and satellite systems in what appears to be large-scale reconnaissance — or pre-positioning for future disruption. The Icarus OAuth breach is the day's defining supply chain story. A newly attributed extortion group stole OAuth tokens via a compromised Klue-Salesforce integration, exposing CRM data at Huntress, Recorded Future, Tanium, Jamf, HackerOne, Snyk, and others. The victims are security vendors — companies whose core business is protecting others. The vector was a trusted third-party connector, not a direct attack. That's exactly what makes it so effective. India's Bajaj Auto confirmed a ransomware attack on June 23rd affecting parent systems and subsidiary BATL. Containment is ongoing; exfiltration is unconfirmed. For a manufacturer at this scale, the operational risk extends well beyond data loss into production disruption and supply chain exposure. The FortiBleed campaign demonstrates what AI-assisted exploitation looks like at scale: GPU-powered credential cracking, OpenFortiVPN pivoting, and an automated AI penetration agent achieving full domain compromise across thousands of networks. The Five Eyes alliance issued a coordinated warning the same day, flagging that frontier AI models are compressing the window from vulnerability discovery to active exploitation from years to months. Finally, a Chrome V8 zero-day — CVE-2026-11645 — is being actively exploited in the wild. Patch status is unconfirmed as of this recording. Enterprise browser policy teams should treat this as a priority item today. This episode includes AI-generated content.

24. kesä 20266 min