All Episodes

September 29, 2025 21 mins

This is today’s cyber news for 2025-09-29. Ransomware, zero-days, and persistent backdoors dominated the headlines, showing just how wide the attack surface has become. Medusa claims to have stolen more than 800 gigabytes of Comcast data and is demanding $1.2 million in extortion. Akira continues to find ways around SonicWall VPN multi-factor authentication, raising fresh concerns about identity controls. The UK’s Co-op has revealed that its April attack cost the retailer hundreds of millions in lost revenue, while Ohio’s Union County confirmed nearly 45,000 residents had Social Security and financial data exposed. Attackers also seeded malicious ads for fake Teams installers that drop the Oyster backdoor.

Other stories cover Salesforce’s “ForcedLeak” flaw, the GoAnywhere zero-day exploited before disclosure, Cisco firewall attacks that dropped entirely new malware families, and Google’s warning of the stealthy “Brickstorm” backdoor aimed at U.S. legal and tech firms. The lineup continues with phishing campaigns delivering PureRAT, AT&T’s $177 million settlement over breaches, and auto supply chain disruptions from cyber incidents. We close with macOS malware, fake TradingView ads, and Microsoft acknowledging Outlook and Edge security issues.

Mark as Played
Transcript

Episode Transcript

Available transcripts are automatically generated. Complete accuracy is not guaranteed.
(00:00):
This is today’s cyber news for september 29th. You can also listen on the go at daily cyber dot news. Lets get started!

We’ve also seen a run of supply-chain compromises rippling through the auto sector. Three major vehicle manufacturers reported disruptions in the past month that trace back to issues at suppliers, not necessarily the carmakers themselves. That’s the pattern we keep seeing in tightly coupled production networks (00:09):
attackers reach a tier-one or tier-two vendor, then pivot through shared systems or trusted integrations, and the household brand ends up wearing the public impact. Details vary case by case—sometimes it’s ransomware, sometimes it’s credential abuse—but the outcome is familiar

(01:18):
That’s the BareMetalCyber Daily Brief for September 29th, 2025. For more, visit BareM etal Cyber dot com, and listen daily at daily cyber dot news. Thanks for listening. We’re back tomorrow.
Advertise With Us

Popular Podcasts

Stuff You Should Know
Dateline NBC

Dateline NBC

Current and classic episodes, featuring compelling true-crime mysteries, powerful documentaries and in-depth investigations. Follow now to get the latest episodes of Dateline NBC completely free, or subscribe to Dateline Premium for ad-free listening and exclusive bonus content: DatelinePremium.com

The Breakfast Club

The Breakfast Club

The World's Most Dangerous Morning Show, The Breakfast Club, With DJ Envy, Jess Hilarious, And Charlamagne Tha God!

Music, radio and podcasts, all free. Listen online or download the iHeart App.

Connect

© 2025 iHeartMedia, Inc.