Cyber (In)Securities – Issue 141

News

  1. Former cyber official targeted by Trump quits company over move
    NBC News – Kevin Collier
  2. MITRE’s CVE program given last-minute reprieve
    itNews – Raphael Satter
  3. Whistle Blower: Russian Breach of US Data Through DOGE
    Narativ – Zev Shalev
  4. Midnight Blizzard deploys GrapeLoader malware
    BleepingComputer – Bill Toulas
  5. 4chan taken down following major hack
    BleepingComputer – Sergiu Gatlan
  6. China places NSA operatives on wanted list
    Cyberscoop – Tim Starks
  7. RansomHouse Ransomware: What You Need To Know
    Fortra – Graham Cluley
  8. Wine-Inspired Phishing Targets EU Diplomats
    Dark Reading – Elizabeth Montalbano
  9. Chinese group uses open-source tools
    Cyberscoop – Derek B. Johnson
  10. Apache Roller Flaw enables persistent access
    Security Affairs – Pierluigi Paganini
  11. Chinese Hackers Use SNOWLIGHT on Linux
    The Hacker News – Ravie Lakshmanan
  12. 2.6M impacted in Landmark/Young breaches
    SecurityWeek – Ionut Arghire
  13. UNC5174 Leveraging Open Source for Espionage
    Dark Reading – Alexander Culafi
  14. DOGE may have exposed sensitive labor data
    NPR – Jenna McLaughlin
  15. Conduent confirms client data stolen
    BleepingComputer – Lawrence Abrams
  16. Firm buys hacker forum accounts
    BleepingComputer – Bill Toulas
  17. Cyber Congressman demands CISA answers
    The Register – Jessica Lyons
  18. Gladinet vulnerabilities exploited
    SecurityWeek – Ryan Naraine
  19. Chinese APTs exploit EDR blind spots
    Dark Reading – Becky Bracken
  20. Cyber risks in aviation sector
    Cybersecurity Dive – David Jones
  21. Phishing uses real-time email validation
    The Hacker News – Ravie Lakshmanan
  1. SSL/TLS cert lifespan shrinking
    BleepingComputer – Bill Toulas
  2. Malicious NPM packages target PayPal
    Security Affairs – Pierluigi Paganini
  3. Roblox poses risks to children
    The Guardian – Libby Brooks & Jedidajah Otte
  4. Fortinet Zero-Day Enables Remote Code Execution
    Dark Reading – Kristina Beek
  5. Hertz data breach confirmed
    itNews
  6. NIST Updates Privacy Framework
    NIST
  7. China accuses US of cyberattacks
    itNews – Laurie Chen
  8. China using ships to target undersea cables
    The Guardian – Angela Dewan
  9. US private prison firm fuels surveillance
    Middle East Eye
  10. ResolverRAT phishing targets healthcare
    The Hacker News – Ravie Lakshmanan
  11. Unknown Storm: Stealthiest hackers uncovered
    Wired
  12. Hacktivism likely state-sponsored
    The Register – Jessica Lyons
  13. AI hallucinated code dependencies
    BleepingComputer – Bill Toulas
  14. Microsoft recalls Recall feature
    The Register – Iain Thomson
  15. Lab breach exposes 1.6M records
    Security Affairs – Pierluigi Paganini
  16. Paper Werewolf spreads via USB
    Dark Reading – Kristina Beek
  17. Meta loses DEI group support
    The Guardian – Adria R Walker
  18. Third-party fraud leads cyber claims
    Dark Reading – Robert Lemos
  19. Western Sydney Uni breach
    BleepingComputer – Bill Toulas
  20. Trump attacks SentinelOne
    InnovationAus – Raphael Satter
  21. China admits Volt Typhoon cyberattacks
    SecurityWeek – Eduard Kovacs

Analysis

CyAN Op-Eds & Articles

CyAN Spotlights & Insights

  1. Online Safety for Kids and Teens – Biweekly Brief
    CyAN Member and Vyanams Strategies Founder Vaishnavi J

CyAN Member News

• Congratulations to CyAN Member Fatema Fardan, who has spent the past six months as a mentor with the QODWA program, initiated by the CFA Society Bahrain! We at CyAN are massive supporters of mentorship programs within the industry, knowing that they not only build professional confidence and capability, but also create lasting networks of support and inspiration. Fatema’s contribution to the next generation of cybersecurity and finance professionals reflects the heart of what makes our community so special—sharing knowledge, lifting others, and leading by example. Well done, Fatema! 👏💙

• Huge congrats to CyAN Member Will Rivera for representing MyOwn Image at two standout events on public service and responsible tech. On March 27, he spoke at Hartwick College’s Gender & Public Service event, honouring Judith “Judy” Day’s legacy. Then on April 5, he joined All Tech Is Human and NYIT to spotlight MyOwn Image’s advocacy against tech-facilitated violence. From campus panels to national policy—Will is leading with purpose. 👏💙

• CyAN thrives because of the incredible talent, leadership, and dedication of our members, and we are proud to see them shaping the future of cybersecurity on a global stage! 🚀💙

• CyAN Board Member Bharat Raigangar has been particularly busy recently! April 9–11 found him in Lisbon speaking at the Third Party and Supply Chain Cyber Security Summit (SCCS), and this week, while in NYC, he caught up with fellow CyAN members Gilles Chevillon and Vaishnavi J!

🗓️ Upcoming CyAN (and CyAN Partner) Global Events:

GITEX AFRICA Logo

📍 Marrakesh, Morocco

GITEX AFRICA
April 14–16

Read more
GITEX ASIA Logo

📍 Singapore

GITEX ASIA
April 23–25

Read more
GISEC Logo

📍 Dubai, UAE

GISEC
May 6–8

Read more
Cyber OSPAs Logo

📍 London, UK

Cyber OSPAs
May 8

Read more
CSG Awards Logo

📍 Dubai, UAE

CSG Awards 2025
May 7

Read more
World AI Expo Logo

📍 Dubai, UAE

World AI Technology Expo
May 14–15

Read more

🎉 Celebration

CyAN 10th Anniversary
(Details TBA)

GITEX Europe Logo

📍 Berlin, Germany

GITEX Europe Messe
May 21–23

Read more
MaTeCC Logo

📍 Rabat, Morocco

MaTeCC
June 7–9

Read more

🌐 Online

CyAN Q2 Call (APAC + Gulf)
June 11 – 12:00 GST / 16:00 SGT / 18:00 AEST

🌐 Online

CyAN Q2 Call (EMEA + Americas)
June 11 – 20:00 GST / 18:00 CET / 17:00 UTC / 12:00 EDT