CyberWire Daily: NSO Group Fined, ICS/SCADA Threats, and AI Security at RSAC
N2K NetworksMay 7, 202528 min413 views
26 connections·40 entities in this video→NSO Group and Spyware Allegations
- ⚖️ A US federal jury ordered Israeli spyware maker NSO Group to pay over $167 million to Meta for hacking WhatsApp and violating US anti-hacking laws.
- 🎯 The ruling, which rejected NSO's claim of immunity, highlights the significant threat spyware poses to privacy and democracy, as Pegasus has been used against journalists and activists.
- 💰 Meta plans to donate the damages to digital rights groups, while NSO Group is considering an appeal.
Industrial Control System Threats
- ⚠️ CISA, FBI, and other agencies issued a joint advisory warning of unsophisticated cyber actors targeting US oil and gas ICS and SCADA systems.
- 🎣 Attackers are exploiting poor cyber hygiene with basic tools like default credentials and brute force attacks, potentially leading to system shutdowns or physical damage.
- 🛡️ Asset owners are urged to remove OT systems from the public internet, enforce strong MFA, secure remote access, and segment networks.
Privacy Risks in TM Signal App
- 📱 Researcher Micah Lee documented serious privacy risks in the TM Signal app, used by high-level Trump officials, which bypasses end-to-end encryption.
- 🔓 The app sends plain text messages to TeleMessage's archive server, making them vulnerable to access by the firm's staff and potentially foreign intelligence.
- 🚨 Senator Ron Wyden has urged the DOJ to investigate due to national security concerns, noting the app's visual similarity to Signal makes it hard to detect.
NSA Downsizing and NIST Departures
- 📉 The NSA plans to cut up to 2,000 civilian positions as part of a broader federal government downsizing effort.
- 🧠 Key cybersecurity leaders are departing NIST amid federal downsizing, raising concerns about the agency's capacity in AI and post-quantum cryptography.
- 🌐 This US instability is driving global demand for alternatives to US cloud dominance, with Europe pursuing digital sovereignty.
Medical Device Cyberattack and Smishing Kit
- 🏥 Medical device giant Masimo disclosed a cyberattack that disrupted its ability to process and ship customer orders, though financial guidance is not expected to be affected.
- 🇨🇳 A new China-based smishing kit called Panda Shop is enabling cyber criminals to steal financial data by impersonating trusted brands and using advanced tactics to bypass detection.
Deepfake Attempts and RSAC 2025 Insights
- 🎭 Accenture's CFO thwarted a deepfake attempt where someone impersonating an attorney used a fake CEO voice to request an urgent funds transfer.
- 🤖 At RSAC 2025, discussions focused on Agentic AI, its security risks, and the need for automation platforms to bridge the gap between board-level interest and team execution.
- 🤝 Key themes included the rise of AI agents, securing these agents, and the importance of detection automation and threat intelligence in SOC operations.
Knowledge graph40 entities · 26 connections
How they connect
An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.
Hover · drag to explore
40 entities
Chapters12 moments
Key Moments
Transcript102 segments
Full Transcript
Topics25 themes
What’s Discussed
NSO GroupSpywareMetaWhatsAppCISAICS/SCADAOil and Gas SectorTM Signal AppTeleMessageNSANISTCloud ComputingDigital SovereigntyMasimoCyberattackPanda ShopSmishingDeepfakeAccentureRSAC 2025Agentic AIAI SecurityAutomationThreat IntelligenceDetection and Response
Smart Objects40 · 26 links
Companies· 15
Media· 1
Concepts· 9
Products· 6
People· 5
Locations· 3
Event· 1