Steganography, RICO, CMMC, End of 10, AI is coming for you, Aaran Leyland and More… – SWN #477

This episode of Security Weekly covers the latest cybersecurity news, including recent vulnerabilities, legal updates, and the impact of AI on education and industry. The host discusses emerging threats, policy changes, and technological debates shaping the cybersecurity landscape.

Keypoints :

  • US authorities issued a warning about actively exploited Chrome vulnerabilities that require urgent patching.
  • Google calendar can be exploited for malware delivery using Unicode steganography to hide malicious code in invites.
  • The RICO Act, historically used against organized crime, is now applied to recent crypto thefts involving millions of dollars and asset forfeitures.
  • New cybersecurity rules for US Department of Defense contractors demand increased internal security measures within three years, creating compliance challenges.
  • Concerns about tech waste grow as upgrades to Windows 11 lead to discarding functional hardware; alternative OS options like Linux could be considered.
  • Chinese-manufactured solar inverters with undocumented embedded wireless modules pose risks of remote shutdown and energy grid vulnerabilities.
  • Chinese hacking groups target drone supply chains, injecting malware into updates, complicating international security and supply chain integrity.