Cybersecurity Daily: News & Threats
(00:00:00) Klue's Double Extortion, Dialog Leak & $10M US Breach Costs (00:00:46) Icarus Gets Hit Back (00:01:37) Dialog Misconfiguration, Not Crime (00:02:17) US Breach Costs Hit $10.22 Million (00:03:01) The $1.9 Million AI Security Divide (00:03:27) Third-Party Risk Now Systemic A supply chain attack on market intelligence platform Klue has exposed roughly 195 enterprise customers after attackers stole OAuth tokens tied to Salesforce, Gong, Deel, and other integrations — bypassing MFA entirely. In a rare twist, the original threat actor, Icarus, was itself compromised by a second criminal group, leaving victims navigating simultaneous extortion demands from two separate actors over the same stolen dataset. Meanwhile, a data exposure at the Dialog Group — a private network linked to Peter Thiel — turned out to stem from a website misconfiguration rather than criminal intrusion. The practical outcome was the same: member records, including details linked to a White House intelligence official and a special operations officer, were publicly accessible to anyone who looked. New IBM Cost of a Data Breach data sharpens the financial picture. The average US breach now costs $10.22 million — an all-time high and more than double the global average of $4.44 million. The US recorded 3,322 breaches in 2024, driven by a complex regulatory environment spanning fifty-state notification laws, HIPAA, and SEC disclosure requirements. Two metrics stand out for security leaders. Organizations using AI and automation in security operations saved $1.9 million per breach compared to those without — a gap wide enough to reframe AI adoption as cost control rather than efficiency. Third-party breaches now account for 30% of all incidents, double the prior-year rate, with the Klue case illustrating exactly how a single compromised credential can extend a blast radius across hundreds of downstream customers. A YesWee production. Built using AI technology. This episode includes AI-generated content.
50 jaksot
Kommentit
0Ole ensimmäinen kommentoija
Rekisteröidy nyt ja liity Cybersecurity Daily: News & Threats-yhteisöön!