Skip to main content

CyberWire Daily: CISA Budget Cuts, Google Settlement, and AI Copyright

N2K NetworksMay 12, 202528 min446 views
23 connections·40 entities in this video

iClicker Breach and Social Engineering

  • 💡 A major student engagement platform, iClicker, was compromised via a ClickFix social engineering attack between April 12th and 16th.
  • 🎯 Attackers used a fake CAPTCHA to trick visitors into running a malicious PowerShell script, potentially leading to information theft.
  • ✅ iClicker confirmed the breach on May 6th, stating the vulnerability was fixed and unaffected apps/data, though user impact remains unknown.

Major Data Breaches and Settlements

  • 💰 Google agreed to a $1.375 billion settlement with Texas over allegations of secretly tracking user locations and private browsing data without consent.
  • 🛍️ UK stores, particularly Co-op, are experiencing empty shelves due to an ongoing cyberattack disrupting logistics systems, with customer and member data compromised.
  • 🏥 Ascension Health reported over 437,000 patients affected by a third-party vendor data breach, likely from a ransomware attack on a file transfer platform.

Exploited Vulnerabilities and New Threats

  • ⚠️ A critical zero-day vulnerability in SAP NetWeaver is being actively exploited by Chinese state-sponsored hackers, allowing unauthenticated remote code execution.
  • 🔍 Researchers uncovered two major threats: SEO poisoning targeting IT admins with malware and a critical root access flaw in Azure's NFS mount utility.
  • 🛡️ A new tool, DefendNot, disables Microsoft Defender by tricking Windows into believing a legitimate antivirus is installed, posing a risk if abused by malware developers.

Congressional Reactions to CISA Budget Cuts

  • 📉 The White House proposed a $491 million cut to CISA's budget, which lawmakers like Senator Chris Murphy called an "illegal gutting of cybersecurity."
  • 🗣️ Lawmakers expressed concern, questioning the rationale for cuts when adversaries like Russia and China are active threats, with some calling for more details on the proposed reductions.
  • 🏛️ The discussion also touched on past rhetoric about CISA being a "Ministry of Truth" and how the agency has shifted its focus away from misinformation.

Generative AI and Copyright Law

  • ⚖️ The US Copyright Office released a report arguing that copying during AI training is presumptively infringing and that fair use depends on the AI's ultimate use.
  • 📈 The report introduced a novel market dilution theory, warning that AI-generated content could devalue markets even without direct copying.
  • 💡 The reasoning in this report could significantly shape over 40 ongoing copyright cases involving generative AI.
Knowledge graph40 entities · 23 connections

How they connect

An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.

Hover · drag to explore
40 entities
Chapters10 moments

Key Moments

Transcript103 segments

Full Transcript

Topics16 themes

What’s Discussed

ClickFix AttackSocial EngineeringData BreachGoogle Privacy SettlementCyberattackSAP NetWeaver VulnerabilityZero-Day VulnerabilityIT Admin ThreatsCloud SecurityBotnetsMicrosoft DefenderCISA Budget CutsCongressional ReactionGenerative AICopyright LawFair Use
Smart Objects40 · 23 links
Companies· 9
Products· 8
Medias· 2
People· 8
Locations· 2
Events· 4
Concepts· 7