Kristi Noem Pledged to Boost the Nation’s Cybersecurity. She Gutted It Instead.

Homeland Security Secretary Kristi Noem's substantial cuts to the Cybersecurity and Infrastructure Security Agency have raised concerns about U.S. cyber defenses, particularly as threats from adversaries like China and Russia increase. While Noem claims to prioritize cybersecurity, her actions—such as staffing reductions and funding cuts for election security—reflect the opposite. Critics argue that this undermines CISA's effectiveness and diminishes the nation's ability to protect critical infrastructure. CISA is currently under-resourced and lacks a Senate-confirmed leader amidst escalating cyber threats.

https://www.politico.com/news/2025/10/23/kristi-noem-cybersecurity-strategy-concerns-cisa-00619108

Microsoft 365 Copilot – Arbitrary Data Exfiltration via Mermaid Diagrams

TL;DR: Microsoft 365 Copilot allowed data exfiltration via mermaid diagrams through an indirect prompt injection, fetching sensitive information (e.g., emails) and encoding it in a clickable “login button.” Clicking the button sent the data to an attacker's server. The vulnerability was confirmed and subsequently patched by Microsoft.

https://www.adamlogue.com/microsoft-365-copilot-arbitrary-data-exfiltration-via-mermaid-diagrams-fixed/

Why You Should Swap Passwords for Passphrases

Switch from complex passwords to passphrases. Focus on length over complexity for stronger security. Memorable passphrases reduce resets and improve defense against attacks. Implement clear guidelines for users: 3-4 unrelated words with a separator. Update password policies to support this approach, ensuring longer minimums and blocking compromised credentials. Monitor adoption and user feedback. While not a complete solution, passphrases enhance security when combined with other methods like MFA.

https://thehackernews.com/2025/10/why-you-should-swap-passwords-for.html

Is Your Car a BYOD Risk? Researchers Demonstrate How

Researchers demonstrated that cars can act as a security risk under BYOD policies, as attackers can compromise an employee’s smartphone by spoofing a vehicle’s Bluetooth signal. Once the phone is infected, the attacker can access corporate networks when the phone connects at work, enabling data theft and lateral movement. The attack used cheap, easily accessible hardware and exploited overlooked connectivity between devices. Security experts stress the importance of holistic mobile device management, network segmentation, and addressing gaps between different security systems, as most breaches stem from simple oversights rather than sophisticated attacks.

https://www.darkreading.com/vulnerabilities-threats/car-byod-risk

DNS0.EU Private DNS Service Shuts Down Over Sustainability Issues

DNS0.EU, a non-profit public DNS service, shut down due to unsustainable time and resource constraints. It recommended users transition to alternatives like DNS4EU or NextDNS for privacy-focused DNS resolution. The service offered features like no-logs, end-to-end encryption, and safety filters but ceased operations on October 20, 2025.

https://www.bleepingcomputer.com/news/security/dns0eu-private-dns-service-shuts-down-over-sustainability-issues/

Agentic AI’s OODA Loop Problem

Agentic AI faces significant security challenges due to untrusted inputs within its OODA (Observe, Orient, Decide, Act) loops, originally designed for trusted environments. Adversarial attacks, like prompt injection, exploit the AI's reliance on potentially corrupted data, resulting in enduring vulnerabilities. These weaknesses emerge from the architecture of AI systems, making integrity enforcement crucial but complex. Without safeguards, agentic AI may inadvertently act on malicious prompts, leading to harmful outcomes. Consequently, improving AI's semantic integrity remains a vital yet unresolved issue in ensuring secure, trustworthy AI deployment.

https://www.schneier.com/blog/archives/2025/10/agentic-ais-ooda-loop-problem.html

Extortion and Ransomware Drive Over Half of Cyberattacks

Over half of cyberattacks are driven by financial motives, mainly extortion and ransomware, according to Microsoft's latest Digital Defense Report. Most incidents targeted data theft rather than espionage. Cybercriminals, empowered by AI and automation, continue to target critical services like healthcare and local governments, often hindering emergency response. Nation-state actors also pose a threat, expanding their operations for espionage and financial gain. Microsoft emphasizes the importance of strong cybersecurity measures, including phishing-resistant multifactor authentication, and calls for collaboration between organizations and governments to combat increasingly sophisticated cyber threats.

https://blogs.microsoft.com/on-the-issues/2025/10/16/mddr-2025/

Europol Dismantles SIM Farm Network Powering 49 Million Fake Accounts Worldwide

Europol disrupted a SIM farm network enabling the creation of 49 million fake accounts used for various cybercrimes, including phishing and fraud. The operation led to seven arrests and the seizure of equipment and funds across multiple countries, revealing significant financial fraud impacts. The network provided services for anonymous communication and facilitated numerous criminal activities worldwide.

https://thehackernews.com/2025/10/europol-dismantles-sim-farm-network.html

You Only Need $750 of Equipment to Pilfer Data From Satellites, Researchers Say

Researchers found that many satellite communications, including sensitive data from cell phone carriers and militaries, are transmitted unencrypted. A study from UCSD and the University of Maryland revealed that half of the analyzed signals were vulnerable, allowing interception of communications like calls and texts. The researchers used a simple $750 setup to collect this data, warning that companies underestimated potential threats to satellite security. Fixed vulnerabilities have since been confirmed for some affected organizations.

https://gizmodo.com/satellites-are-exposing-unprotected-cellphone-and-military-data-study-finds-2000672091

AI Makes Phishing 4.5x More Effective, Microsoft Says

Microsoft's report reveals AI enhances phishing emails, boosting click rates from 12% to 54% and potentially increasing profitability by 50 times. Cybercriminals exploit AI for targeted attacks, utilizing tools like voice cloning and deepfakes. Nation-state actors are also adopting AI for cyber operations. Additionally, new tactics like “ClickFix” have emerged, allowing attackers to manipulate users into executing malware. Overall, AI significantly alters phishing strategies, making attacks more efficient and harder to detect.

https://www.theregister.com/2025/10/16/ai_makes_phishing_45x_more_effective/

Over 100 VS Code Extensions Exposed Developers to Hidden Supply Chain Risks

Over 100 VS Code extensions leaked access tokens, allowing potential distribution of malicious updates, risking over 150,000 installations. Wiz security identified 550 hard-coded secrets across more than 500 extensions, including major service providers' secrets. Users are advised to limit extensions and enforce scrutiny to mitigate risks. Additionally, a threat actor, TigerJack, published malicious extensions disguised as legitimate ones to exploit unsuspecting developers, reinforcing the vulnerabilities in extension security across platforms. Microsoft is enhancing security measures but warns of risks outside its marketplace.

https://thehackernews.com/2025/10/over-100-vs-code-extensions-exposed.html

How AI-powered Ransomware Could Destroy Your Business

AI-powered ransomware presents a significant threat to businesses, demonstrated by the collapse of KNP Logistics after a ransomware attack exploiting weak passwords. AI techniques like generative adversarial networks (GANs) enhance password cracking, making traditional defenses ineffective. Organizations must adopt robust security measures, including password managers, employee training, and multi-factor authentication, to mitigate these risks. The evolution of AI in cybercrime necessitates a reevaluation of security protocols to combat increasingly sophisticated attacks.

https://www.theregister.com/2025/10/16/machine_learning_meets_malware/

F5 Security Incident

F5 reported a security incident involving a nation-state threat actor accessing and exfiltrating files from their BIG-IP product development environment in August 2025. They confirmed some BIG-IP source code was taken, but no critical vulnerabilities were disclosed or exploited. F5 is updating their software, engaging cybersecurity experts, and implementing security measures. They advise customers to update systems, enhance monitoring, and utilize available resources to strengthen security. Ongoing efforts aim to improve the overall security posture and regain customer trust.

https://my.f5.com/manage/s/article/K000154696

New Pixnapping Attack Steals 2FA Codes From Google Authenticator Within 30 Seconds

New Pixnapping attack on Android devices can steal 2FA codes from Google Authenticator in under 30 seconds. It exploits hardware vulnerabilities in GPUs and Android APIs without needing special permissions. The attack bypasses traditional app security, can capture sensitive data from various apps, and has both Google and Samsung addressing the issue. Users are urged to update devices and monitor app behavior to mitigate risks.

https://cybersecuritynews.com/pixnapping-attack/

Scroll to Top