Artwork

Content provided by Daily Security Review. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Daily Security Review or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Lazarus Strikes Again: Inside Operation SyncHole and the 1-Day Exploitation Crisis

12:49
 
Share
 

Manage episode 479084996 series 3645080
Content provided by Daily Security Review. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Daily Security Review or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.

In this episode, we break down the most urgent cybersecurity developments from late April 2025—including the Lazarus Group’s high-profile “Operation SyncHole” targeting South Korean industries. Discover how attackers are exploiting newly disclosed vulnerabilities faster than ever, with nearly 1 in 3 CVEs weaponized within 24 hours of publication.

We dive deep into the Lazarus Group's tactics, including watering hole attacks, one-day and potential zero-day vulnerabilities in tools like Innorix Agent and Cross EX, and their deployment of advanced malware families like ThreatNeedle and AGAMEMNON.

But that’s not all—we also cover:

  • The evolution of phishing-as-a-service with generative AI (Darcula and Gamma AI),
  • The increasing exploitation of browsers as attack surfaces,
  • A Linux rootkit that avoids detection by bypassing system calls,
  • Nation-state cyber activity from Russia, China, Iran, and North Korea,
  • And the silent crisis looming over the CVE program’s future funding.

Plus, we explore the growing importance of non-human identities (NHIs) in security strategies, and the ongoing risks in software supply chains—from malicious npm packages to cryptocurrency library compromises.

If you're a cybersecurity professional or threat analyst, this is your essential 30-minute intel download.

  continue reading

45 episodes

Artwork
iconShare
 
Manage episode 479084996 series 3645080
Content provided by Daily Security Review. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Daily Security Review or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.

In this episode, we break down the most urgent cybersecurity developments from late April 2025—including the Lazarus Group’s high-profile “Operation SyncHole” targeting South Korean industries. Discover how attackers are exploiting newly disclosed vulnerabilities faster than ever, with nearly 1 in 3 CVEs weaponized within 24 hours of publication.

We dive deep into the Lazarus Group's tactics, including watering hole attacks, one-day and potential zero-day vulnerabilities in tools like Innorix Agent and Cross EX, and their deployment of advanced malware families like ThreatNeedle and AGAMEMNON.

But that’s not all—we also cover:

  • The evolution of phishing-as-a-service with generative AI (Darcula and Gamma AI),
  • The increasing exploitation of browsers as attack surfaces,
  • A Linux rootkit that avoids detection by bypassing system calls,
  • Nation-state cyber activity from Russia, China, Iran, and North Korea,
  • And the silent crisis looming over the CVE program’s future funding.

Plus, we explore the growing importance of non-human identities (NHIs) in security strategies, and the ongoing risks in software supply chains—from malicious npm packages to cryptocurrency library compromises.

If you're a cybersecurity professional or threat analyst, this is your essential 30-minute intel download.

  continue reading

45 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Quick Reference Guide

Listen to this show while you explore
Play