RSS Amplifier

Pithy Security | InfoSec Made Simple · Oct 3, 2025

America's Cyber Defenders Just Got Benched

0
Sign in to vote or save

MrComputerScience · Pithy Security | InfoSec Made Simple

Three massive cyber events dominated the security landscape this week, exposing critical weaknesses in both government defense and global commerce.

The U.S. government benched two-thirds of its national cyber defense team, hackers are actively exploiting Cisco firewalls, and a major crime group just started extorting heavyweight executives en masse over sensitive corporate data.

Here’s what happened and why this triple threat matters to you.

The government shutdown that began this week has effectively sidelined America’s digital defense team, furloughing 65 percent of the personnel at the Cybersecurity and Infrastructure Security Agency (CISA). Around 900 of CISA’s 2,500 employees remain at work, a skeleton crew dedicated to mitigating massive, active threats, such as the recent Cisco firewall vulnerabilities. The rest are sitting at home, unpaid, precisely at a time when major state-sponsored hackers and criminal ransomware groups are not taking days off.

Key Insights:

The timing of this is especially dangerous because, amid the shutdown fight, the Cybersecurity Information Sharing Act of 2015 (a crucial law allowing private companies to share real-time threat information with the government) just expired. This means the vital, two-way street of threat intelligence between major tech companies and federal defenders has effectively come to a close. Think of it like cutting the phone lines between your local police and neighborhood watch during a crime wave. The visibility and coordination across the national cyber landscape have been severely degraded.

Why This Matters For You:

Your company’s security likely depends on the alerts and guidance from CISA, whether you are aware of it or not. When hospitals are hit with ransomware, your bank detects a breach, or critical infrastructure faces a significant attack, CISA coordinates the national response. Currently, that coordination is running on fumes, while major cyber threats, such as those targeting executives at Cisco and Google, continue to escalate. This shutdown dramatically increases the risk ceiling for every organization in the country.

Read More on The Register.

Executives at large organizations are currently being targeted by a sophisticated, high-volume extortion campaign, according to warnings from Google’s Mandiant security team and Google Threat Intelligence Group (GTIG). The threat, which claims affiliation with the notorious Cl0p criminal outfit and has links to the FIN11 cybercrime group, alleges massive breaches and theft of sensitive data from Oracle E-Business Suite (EBS) applications. The criminals began this campaign on or before September 29, sending highly personalized emails from hundreds of compromised third-party accounts to the C-suite of various companies, with ransom demands reaching as high as $50 million. The attack is significant because it relies on social engineering to terrorize senior corporate leaders into paying ransom money.

Key Insights:

The core of this attack is not necessarily a proven technical compromise, but a sophisticated social engineering campaign. Google and Mandiant have not identified evidence of a vulnerability or breach in Oracle’s E-Business Suite, and have not yet substantiated the claims made by this group. However, Oracle confirmed awareness of the extortion emails and noted the potential use of previously identified vulnerabilities that are addressed in the July 2025 critical patch update, suggesting some victims may have been compromised due to unpatched systems. In any case, the attackers’ goal is to panic executives into paying the ransom, betting that the C-suite will pay to preempt the reputational damage and regulatory scrutiny that even an unconfirmed public leak could trigger.

Why This Matters For You:

Your organization likely uses Oracle or a similar enterprise software, which means your executives may be next in line to receive one of these threatening emails. Whether the underlying data theft is genuine or a sophisticated bluff, the extortion campaign itself is very real and actively underway, with some threat actors backing up their claims with alleged proof of compromise. This case highlights how modern cybercrime relies not only on technical exploits but also on exploiting the reputational fears and financial risks associated with senior corporate leaders.

Read More on The Hacker News.

The U.S. government just issued a rare emergency cybersecurity directive because hackers found a way to completely bypass Cisco firewalls, the security devices protecting thousands of networks worldwide. Nearly 50,000 Cisco ASA and FTD devices exposed on the public web are vulnerable to two actively exploited zero-day flaws. This attack is already in use and is so severe that hackers can install the persistent “RayInitiator” GRUB bootkit, which is flashed to the device’s firmware. This means the infection survives reboots and system upgrades, allowing the actor to maintain access even when an IT team thinks they have fixed the system.

Key Insights:

This threat comes from a sophisticated Advanced Persistent Threat (APT) actor (linked to the ArcaneDoor campaign), likely state-sponsored, specifically targeting government networks worldwide for large-scale data exfiltration. Because these Cisco devices sit at the edge of networks, they act as digital gatekeepers for schools, hospitals, businesses, and government offices. Federal agencies were given just days to hunt for evidence of compromise, disconnect affected devices, and apply emergency patches to contain the damage.

Why This Matters For You:

If your workplace uses these Cisco devices, your IT teams are scrambling right now. The threat is active, critical, and has effectively turned the security system into the exact weakness it was supposed to prevent. This is a massive failure at the most fundamental level of network defense, serving as a potent reminder that perimeter security is only as strong as its weakest low-level code.

Read More on Cybersecurity Dive.

In November 1988, a Cornell graduate student named Robert Tappan Morris released a self-replicating program as an “experiment” to gauge the size of the nascent Internet. It didn’t go as planned. Due to a bug in his code, the program spread faster than expected, repeatedly re-infecting the same machines and clogging network resources. Within hours, the worm had stifled an estimated 10% of the Internet, shutting down email and system access across major universities, government laboratories, and research centers.

This incident was a profound accident. To give you an idea of the mayhem, the Internet back then had only about 60,000 computers, and the people who were online were all incredibly specialized. This meant the entire community was suddenly forced to collectively debug and patch the issue, often communicating via fax or phone calls since their emails were dead.

The fallout was massive. It birthed the first felony conviction under the Computer Fraud and Abuse Act (Morris was fined and sentenced to probation). More importantly, it was the moment the world realized that the network could be brought to its knees, not by a sophisticated adversary, but by a single, accidental line of code. This event directly led to the formation of the first Computer Emergency Response Team (CERT), a foundation of modern cybersecurity defense.

Please read my two newsletters:

# 1 - Pithy Cyborg - AI news in a no-fluff format. Timely insights into how AI is changing the world around us. Plus, a fun and battle-tested AI prompt in each issue.

# 2 - Pithy Security - Useful cybersecurity news without fear-mongering. Simple security that lets you spot scams and stay safe without needing to become an expert.

PS: Do you have questions? Reply to this email!

Thanks for reading. More cutting-edge cybersecurity insights coming soon.

You’re receiving this because you subscribed at PithySecurity.Substack.com. You can unsubscribe at any time using the link below. This newsletter reflects my personal opinions, not professional or legal advice. I may earn commissions from recommended tools. Thanks for your support!

Read the original on pithysecurity.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.