Cybersecurity Decrypted #29: April 10 – 17

Your weekly 5 minute news recap.

Last updated on Jun 6, 2025 1 Minute To Read
Joel Witts Written by Joel Witts
Laura Iannini Technical Review by Laura Iannini

📰 Top Stories

    • The US Government has extended funding for non-profit research firm MITRE to continue operating its Common Vulnerabilities and Exposures (CVEs) program. The extension is confirmed to be for 11 months. 🔗

    • The China-backed Salt Typhoon attack on US carrier networks may have been caused by a legal “back door” implemented to support law enforcement agencies surveilling communications. 🔗

    • Bots now account for more traffic on the web than humans, according to new research from Thales. Bot traffic accounted for 51% of total web activity last year – an increase driven by AI and LLMs. 🔗

    • What’s the biggest target for ransomware? Remote access tools, according to a new report. Remote access tools were the initial entry point of 8 in every 10 ransomware attacks in 2024. VPNs are the second most likely target. 🔗

    • The aviation industry is at high risk of cyberattack due to vulnerable software and aging technologies, according to a new report released by the Foundation for Defense of Democracies. 🔗

Get the stories that matter, straight to your inbox. Sign up to Cyber Weekly.

This field is for validation purposes and should be left unchanged.

FREE NEWSLETTER

Cyber Weekly

Get curated cybersecurity news, threats and insights delivered free every Thursday.

📡 Threat Watch

  • Browser extensions could be a serious enterprise security risk, according to a new report from LayerX. Over 50% of browser extensions can access critical data like passwords, cookies, and browsing information. 🔗
  • Tycoon2FA, a leading phishing-as-a-service platform is now more dangerous. The platform has added new features to avoid fingerprinting by domain reputation systems. There has been a huge increase in SVG-based phishing linked to the Tycoon2FA platform. 🔗
  • Cybercriminals could target ‘AI-hallucinated’ names in code dependencies that resemble popular libraries to spread malware, according to a new report. There are no confirmed reports yet – but if you use AI code, make sure to watch for this risk. 🔗
  • AI has become a tool of the trade for scammers. This tax season, hackers used AI-produced audio to launch voice-phishing campaigns impersonating tax preparers and the IRS to try and steal funds and trick people into sending financial documents. 🔗
  • An AI-powered bot platform named ‘AkiraBot’ has spammed over 80,000 websites since September 2024, according to SentinelOne threat researchers. The bot uses OpenAI to spam contact forms and chat widgets to promote SEO services. 🔗

🚨 Industry News

  • SSL/TLS certificates will have shorter lifespans over the next few years, with a final lifespan of 47 days starting in 2029. The move is designed to minimize risks from outdated certificate data and reduce exposure for compromised credentials. 🔗
  • Google has made a big move to simplify its suite of security tools – merging all its major products into a single platform: Google Unified Security. 🔗
  • Microsoft is launching a new Defender for Endpoint feature that will block inbound and outbound traffic from undiscovered endpoints. This will work by containing the IP addresses of devices that haven’t been onboarded. 🔗
  • Github has announced that its new ‘security campaigns’ feature is now available to all GitHub Advanced Security and GitHub Code Security customers. The new feature makes it easier for developers to fix vulnerabilities in applications. 🔗
  • Virtue AI has announced a $30 million USD seed and series A funding round for a new platform designed to help organizations deploy generative AI securely and compliantly. 🔗
  • Reminder: Microsoft Exchange 2016 and 2019 reach end of support in just 6-months. 🔗

🏛 Cybersecurity Policy

  • President Trump has ordered an investigation into former CISA Director Chris Krebs. Krebs is a lifelong Republican and was appointed director of CISA when Trump founded the agency in 2018. He was later fired by Trump for stating there had been no technological issues in the 2020 election. 🔗
  • Krebs has now resigned from his role at SentinelOne, stating: “For those who know me, you know I don’t shy away from tough fights. But I also know this is one I need to take on fully – outside of SentinelOne.” 🔗
  • China has accused the US National Security Agency of carrying out cyber-attacks targeting the Asian Winter Games in February. 🔗
  • The Pentagon has announced it will terminate several IT service contracts valued at $5.1 billion USD, including contracts at Accenture, Booz Allen Hamilton, and Deloitte. This covers consulting and non-essential services, says Defense Secretary Pete Hegseth. 🔗
  • The House Oversight Committee will investigate security and privacy risks caused by the bankruptcy of genetic testing company 23andMe. 🔗

🌎 Global News

  • EU Diplomats have been targeted with phishing emails delivering malware via fake invites to wine tasting events. The attack is linked to a Russian threat actor group – you can’t say they don’t know their audience. 🔗
  • IKEA’s operating company in Eastern Europe had losses of nearly $23 million USD after a ransomware attack which hit before Black Friday last year. 🔗
  • Notorious online forum 4Chan has been offline after a major hack. Emails of admins, moderators, and janitors have been allegedly leaked, as well as screenshots of admin panels and maintenance tools. 🔗

Get the stories that matter, straight to your inbox. Sign up to Cyber Weekly.

This field is for validation purposes and should be left unchanged.

FREE NEWSLETTER

Cyber Weekly

Get curated cybersecurity news, threats and insights delivered free every Thursday.

Written By Written By
Joel Witts
Joel Witts Content Director

Joel is the Director of Content and a co-founder at Expert Insights; a rapidly growing media company focussed on covering cybersecurity solutions.

He’s an experienced journalist and editor with 8 years’ experience covering the cybersecurity space. He’s reviewed hundreds of cybersecurity solutions, interviewed hundreds of industry experts and produced dozens of industry reports read by thousands of CISOs and security professionals in topics like IAM, MFA, zero trust, email security, DevSecOps and more.

He also hosts the Expert Insights Podcast and co-writes the weekly newsletter, Decrypted. Joel is driven to share his team’s expertise with cybersecurity leaders to help them create more secure business foundations.

Technical Review Technical Review
Laura Iannini
Laura Iannini Cybersecurity Analyst

Laura Iannini is a Cybersecurity Analyst at Expert Insights. With deep cybersecurity knowledge and strong research skills, she leads Expert Insights’ product testing team, conducting thorough tests of product features and in-depth industry analysis to ensure that Expert Insights’ product reviews are definitive and insightful.

Laura also carries out wider analysis of vendor landscapes and industry trends to inform Expert Insights’ enterprise cybersecurity buyers’ guides, covering topics such as security awareness training, cloud backup and recovery, email security, and network monitoring. Prior to working at Expert Insights, Laura worked as a Senior Information Security Engineer at Constant Edge, where she tested cybersecurity solutions, carried out product demos, and provided high-quality ongoing technical support.

Laura holds a Bachelor’s degree in Cybersecurity from the University of West Florida.