CyberWire Daily: CISA Budget Cuts, Google Settlement, and AI Copyright
N2K NetworksMay 12, 202528 min446 views
23 connections·40 entities in this video→iClicker Breach and Social Engineering
- 💡 A major student engagement platform, iClicker, was compromised via a ClickFix social engineering attack between April 12th and 16th.
- 🎯 Attackers used a fake CAPTCHA to trick visitors into running a malicious PowerShell script, potentially leading to information theft.
- ✅ iClicker confirmed the breach on May 6th, stating the vulnerability was fixed and unaffected apps/data, though user impact remains unknown.
Major Data Breaches and Settlements
- 💰 Google agreed to a $1.375 billion settlement with Texas over allegations of secretly tracking user locations and private browsing data without consent.
- 🛍️ UK stores, particularly Co-op, are experiencing empty shelves due to an ongoing cyberattack disrupting logistics systems, with customer and member data compromised.
- 🏥 Ascension Health reported over 437,000 patients affected by a third-party vendor data breach, likely from a ransomware attack on a file transfer platform.
Exploited Vulnerabilities and New Threats
- ⚠️ A critical zero-day vulnerability in SAP NetWeaver is being actively exploited by Chinese state-sponsored hackers, allowing unauthenticated remote code execution.
- 🔍 Researchers uncovered two major threats: SEO poisoning targeting IT admins with malware and a critical root access flaw in Azure's NFS mount utility.
- 🛡️ A new tool, DefendNot, disables Microsoft Defender by tricking Windows into believing a legitimate antivirus is installed, posing a risk if abused by malware developers.
Congressional Reactions to CISA Budget Cuts
- 📉 The White House proposed a $491 million cut to CISA's budget, which lawmakers like Senator Chris Murphy called an "illegal gutting of cybersecurity."
- 🗣️ Lawmakers expressed concern, questioning the rationale for cuts when adversaries like Russia and China are active threats, with some calling for more details on the proposed reductions.
- 🏛️ The discussion also touched on past rhetoric about CISA being a "Ministry of Truth" and how the agency has shifted its focus away from misinformation.
Generative AI and Copyright Law
- ⚖️ The US Copyright Office released a report arguing that copying during AI training is presumptively infringing and that fair use depends on the AI's ultimate use.
- 📈 The report introduced a novel market dilution theory, warning that AI-generated content could devalue markets even without direct copying.
- 💡 The reasoning in this report could significantly shape over 40 ongoing copyright cases involving generative AI.
Knowledge graph40 entities · 23 connections
How they connect
An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.
Hover · drag to explore
40 entities
Chapters10 moments
Key Moments
Transcript103 segments
Full Transcript
Topics16 themes
What’s Discussed
ClickFix AttackSocial EngineeringData BreachGoogle Privacy SettlementCyberattackSAP NetWeaver VulnerabilityZero-Day VulnerabilityIT Admin ThreatsCloud SecurityBotnetsMicrosoft DefenderCISA Budget CutsCongressional ReactionGenerative AICopyright LawFair Use
Smart Objects40 · 23 links
Companies· 9
Products· 8
Medias· 2
People· 8
Locations· 2
Events· 4
Concepts· 7