Cybersecurity Daily: News & Threats
(00:00:00) ShinyHunters Hits NAIC, PQC Federal Mandate & US Breach Costs Peak (00:01:19) ShinyHunters Breaches NAIC (00:02:12) Post-Quantum Cryptography Federal Mandate (00:03:07) Mexico's Six-Year Cybersecurity Plan (00:03:34) US Breach Costs Hit Record High Today's briefing opens with two actively exploited device families — Lantronix EDS5000 and Ubiquiti UniFi OS — now under a 72-hour federal patch deadline set by CISA for June 26th. The Lantronix flaw (CVE-2025-67038, CVSS 9.8) allows root-level OS command execution, while three chained Ubiquiti flaws are already delivering reverse shells in the wild via a Bishop Fox proof-of-concept. The insurance sector's primary US regulator, the National Association of Insurance Commissioners, confirmed a breach by ShinyHunters, who claim to have stolen 3.1 terabytes of data through an Oracle PeopleSoft zero-day. The NAIC disputes the full scope, but the FBI is now involved — and the sensitivity of state-level regulatory data makes this a high-value target regardless of exact volume. The White House signed an executive order on June 25th establishing the first binding federal mandate for post-quantum cryptography migration. Agencies must adopt NIST-approved PQC algorithms for key establishment by end of 2030 and digital signatures by end of 2031 — a tight timeline driven by harvest-now, decrypt-later threats from state-level adversaries. Mexico's Congress approved a National Cybersecurity Plan running 2025 through 2030, including a national cyber range and a Latin America incident response hub, though institutional durability remains an open question. Finally, a new industry report shows global average data breach costs fell 9% to $4.44 million — but US costs hit an all-time high of $10.22 million per breach, driven by healthcare exposure, financial regulation, and 50-state notification complexity. Organizations with AI-driven security tooling averaged $1.9 million less per breach. This episode includes AI-generated content.
51 episodes
Comments
0Be the first to comment
Sign up now and become a member of the Cybersecurity Daily: News & Threats community!