Skip to main content

CyberWire Daily: Take It Down Act, Ransomware Trends, and AI's Evolving Role

N2K NetworksMay 20, 202529 min409 views
26 connections·40 entities in this video

New Legislation and Cyber Threats

  • ⚖️ The Take It Down Act has been signed into law, criminalizing the distribution of non-consensual intimate images, including AI-generated deepfakes, with platforms having 48 hours to remove such content.
  • ⚠️ Critics of the Take It Down Act express concerns about potential abuse, selective enforcement, and chilling effects on free expression, especially given the FTC's enforcement power.
  • 🔒 A UK logistics firm, Peter Green Chilled, faced a ransomware attack, disrupting order processing and highlighting the vulnerability of the food sector supply chain.

Evolving Exploitation Tactics

  • 🔑 Trojanized versions of the KeePass password manager are being used to distribute malware and steal credentials, often distributed through malicious Bing ads.
  • 🎯 A sophisticated phishing campaign is impersonating Zoom meeting invites, leveraging urgency and trust to steal user credentials through spoofed login pages.
  • 🔍 SEO poisoning on Microsoft Bing is being used to deliver Bumblebee malware by targeting IT professionals with fake download sites for technical software.

Vulnerability Management and Metrics

  • 📈 Researchers from CISA and NIST have proposed a new metric, Likely Exploited Vulnerabilities (LEV), to better predict and prioritize actively exploited software flaws.
  • 🚨 CISA has added six actively exploited vulnerabilities, including flaws in Ivanti, Streamax, Zimbra, and ZK Technology, to its Known Exploited Vulnerabilities (KEV) Catalog, mandating remediation for federal agencies.

Generative AI and Third-Party Risk

  • 💡 Generative AI is increasingly being used by threat actors for social engineering, but organizations are more often facing issues from internal misuse and lack of governance, such as uploading corporate data to public AI platforms.
  • 🤝 Third-party risk has doubled year-over-year, with a significant increase to 30% of breaches, emphasizing the need for organizations to thoroughly evaluate their supply chain and their third parties' ecosystems.

Federal Cybersecurity Workforce

  • 🏛️ A bipartisan bill, the Federal Cyber Workforce Training Act, aims to strengthen the federal cybersecurity workforce by establishing a centralized training center for onboarding and recruitment.
  • 📉 The bill addresses challenges in federal cyber hiring, exacerbated by past workforce cuts and hiring freezes, seeking to create sustainable career paths and improve training standards.

Verizon DBIR Insights

  • 📊 Chris Novak from Verizon shared key findings from the 2025 Data Breach Investigations Report (DBIR), noting a 34% increase in vulnerability exploitation as an initial access step.
  • 💻 Ransomware events increased by 37%, significantly impacting small and medium-sized businesses, though overall, 64% of victim organizations did not pay the ransom this year.
  • 🌐 The DBIR highlights the growing global nature of data breaches, covering 139 victim countries and over 22,000 incidents.
Knowledge graph40 entities · 26 connections

How they connect

An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.

Hover · drag to explore
40 entities
Chapters12 moments

Key Moments

Transcript106 segments

Full Transcript

Topics15 themes

What’s Discussed

Take It Down ActRansomwareKeePassCISANISTBumblebee MalwarePhishingZoomKnown Exploited Vulnerabilities CatalogFederal Cybersecurity WorkforceVerizon DBIRGenerative AIThird-Party RiskDeepfakesSEO Poisoning
Smart Objects40 · 26 links
Medias· 4
Concepts· 10
People· 6
Companies· 14
Location· 1
Products· 2
Events· 3