Simply Cyber Newsletter #148

Crush Your Week Like a Cyber Pro with Simply Cyber!

Start your work week off at full speed with expert analysis and actionable intel from top cybersecurity news stories. Share with your End Users, Peers, and Executives to support weekly security awareness with the Simply Cyber Newsletter!

FOR END USERS

Google nukes 224 Android malware apps behind massive ad fraud campaign. A massive Android ad fraud scheme called SlopAds abused 224 apps with 38 million installs to generate 2.3 billion fake ad requests daily. End users unknowingly fueled the fraud, and businesses lost money through wasted ad spend and distorted marketing analytics.

What you need to know: Educate your end users about cautious app downloads, and raise awareness with marketing teams about ad fraud’s financial impact. The SlopAds campaign abused 224 malicious apps, downloaded 38 million times, to create over 2 billion fake ad requests daily. For end users, this shows that even apps from Google Play can quietly abuse devices and fuel fraud. For marketing teams, it highlights how fraud directly wastes advertising dollars and corrupts campaign analytics with fake impressions and clicks.

The clear takeaway is twofold: employees should avoid unverified mobile apps, and marketing leaders should build ad fraud monitoring into their strategy. Treating ad fraud as both a user behavior risk and a governance issue ensures protection of budgets and data integrity.

FOR PEERS

Microsoft to force install the Microsoft 365 Copilot app in October. Microsoft will begin force-installing the Microsoft 365 Copilot app on Windows devices outside the EEA starting in October, completing by mid-November. The app will appear in the Start Menu and be enabled by default, though admins can opt out in the Apps Admin Center.

What you need to know: Share this story with your peers and have conversations about what your organization is doing to prepare for Microsoft’s forced rollout of the 365 Copilot app starting in October. The app will automatically install on Windows devices with Microsoft 365 desktop clients (outside the EEA), appear in the Start Menu, and be enabled by default. While Microsoft frames this as a way to simplify access, it could lead to user confusion, support tickets, or policy concerns. Admins can opt out in the Apps Admin Center, but proactive planning is key. Coordinate with your help desk and comms teams now to prevent confusion and disruption later.

One last thought around all of this: while Microsoft frames this as simplifying access, it also raises governance questions around how Copilot will interact with organizational data, what safeguards exist, and which users should be permitted access.

FOR EXECUTIVES

FBI warms of Salesforce attacks by UNC6040 and UNC6395 groups. The FBI warns that cybercriminal groups are targeting Salesforce platforms through employee scams and compromised third-party apps to steal customer data for extortion. Major firms have been hit, making this not just a security issue but a business risk tied to trust, compliance, and reputation.

What you need to know: The FBI recently issued an alert warning that two cybercriminal groups are increasingly targeting Salesforce platforms to steal sensitive customer data and use it for extortion. Their tactics include tricking employees through phone calls that mimic IT support and exploiting malicious app integrations that bypass normal security controls. Once access is obtained, attackers can exfiltrate large customer databases and pressure organizations into paying to prevent public exposure.

While the technical details matter to security teams, the broader issue for executives is the impact on customer trust, regulatory compliance, and business continuity. The organizations named in the alert are household brands, which underscores that the reputational and financial consequences can be severe. Executives may want to consider whether current governance structures treat Salesforce and its integrations as critical infrastructure. It may also be worth reviewing with leaders across IT, help desk, marketing, and finance whether policies for approving third-party apps, training employees against scams, and responding to potential data exposure are aligned. By raising these conversations, executives can help ensure the business is positioned to withstand both manipulation and the loss of confidence that follows.

SIMPLY CYBER MEDIA GROUP PODCASTS

This Wednesday at 9:30 AM EDT on Simply Cyber Media Group

Industrial control systems (ICS) and operational technology (OT) are the backbone of modern society—powering electricity, water, gas, communications, manufacturing, chemicals, and even medical technology. But what happens when these systems must be secured in the middle of a warzone?

On this episode of Simply ICS Cyber, hosts Don C. Weber and Tom VanNorman sit down with special guest Patrick C. Miller, President & CEO of ‪Ampyx Cyber‬, a company dedicated to protecting the industrial world.

This is a rare opportunity to hear experts break down industrial cybersecurity in the harshest conditions. Whether you’re in IT, OT, or just want to understand the stakes, you’ll walk away with practical lessons and a deeper appreciation of what’s at risk.

Join us on Wednesday: https://youtu.be/yjgoVXcfuHM

Visit https://www.youtube.com/@SimplyCyber/podcasts to catch up on all of the podcasts available on Simply Cyber Media Group!

SIMPLY CYBER FIRESIDES

This Thursday at 4:30 PM EDT on Simply Cyber

🔥 In this episode of Simply Cyber Firesides, host Gerald Auger, Ph.D. sits down with AJ, U.S. Army veteran, co-founder of ByteChek, and Director of GRC Engineering at Aquia, to talk about the evolving world of GRC (Governance, Risk, and Compliance) engineering in cybersecurity.

AJ brings a wealth of expertise to the discussion, holding six AWS certifications — including the AWS Solutions Architect – Professional and AWS Security – Specialty — along with the CISSP. With over a decade of experience spanning military service, consulting, and leadership roles, he has built a reputation as a thought leader in cloud security, compliance automation, and governance frameworks.

A regular speaker at SANS Cloud Security events, including the BIPOC in Cloud Forum and CloudSecNext Summit, AJ has also contributed to major publications like CISOMag, InfosecMag, HackerNoon, and ISC2. His work continues to shape the conversation around how organizations can align security and compliance through modern engineering approaches.

Tune in live to hear AJ share his journey, explore what GRC engineering really means in practice, and offer insights for professionals looking to grow their careers in this vital area of cybersecurity.

Join #TeamSC in chat and bring your questions! https://www.youtube.com/live/CsaYycDXQWE 

SC MEDIA GROUP WEEKLY EVENTS SCHEDULE

New Week, New Cyber Insights!

Here’s your chance to catch the best minds in cybersecurity, live all week long with Simply Cyber Media Group:

Mon, Sept 22

📰 Daily Cyber Threat Brief – 8:00 AM EDT

🎤 Jaw Jackin’ AMA – 9:00 AM EDT

Tue, Sept 23

📰 Daily Cyber Threat Brief – 8:00 AM EDT

🎤 Jaw Jackin’ AMA – 9:00 AM EDT

Wed, Sept 24

📰 Daily Cyber Threat Brief – 8:00 AM EDT

🎤 Jaw Jackin’ AMA – 9:00 AM EDT

⚙️ Simply ICS Cyber Podcast – 9:30 AM EDT

Thu, Sept 25

📰 Daily Cyber Threat Brief – 8:00 AM EDT

🎤 Jaw Jackin’ AMA – 9:00 AM EDT

🔥 Simply Cyber Firesides Live – 4:30 PM EDT

Fri, Sept 26

📰 Daily Cyber Threat Brief – 8:00 AM EDT

🎤 Jaw Jackin’ AMA Panel – 9:00 AM EDT

Sat, Sept 27

🎓 Slay Security+ with @SlaySecurityPlus (YouTube) – 4:00 PM EDT

💬 Discord Extras

M–F: Pre-Show Jaw Jackin’ – 7:30 AM EDT

Tue: Public Speaking Masters – 7:00 PM EDT

🚀 Don’t just watch—be part of the community! Join us here: 👉 simplycyber.io/learn

#CyberSecurity #ThreatIntel #SimplyCyber

SIMPLY CYBER CON 2025

When: Sunday, Nov. 2nd & Monday, Nov. 3rd

We’re excited to share Simply Cyber Con is back for the third year in a row!

Registration is now available! Head over to the website to learn more about conference registration and training day options.

Don’t miss the opportunity to attend onsite training in-person with the amazing instructors on Nov. 2nd!

Interested in sponsoring? Review the sponsor packet. It’s going to be the best Simply Cyber Con yet, don’t miss out on this chance to sponsor and share your business with #TeamSC!

Stay tuned for updates! #simplycybercon

SC ACADEMY THE PLACE FOR CYBER CAREERS

At Simply Cyber Academy, we specialize in making GRC and Cybersecurity Careers a reality. Empower your career by learning real in-demand skills from cyber experts and the theory behind those skills with Simply Cyber Academy.

The popular GRC Analyst Master Class is a must for kickstarting your GRC Cybersecurity career. In addition, we have new courses covering various areas of focus in cyber available to help you advance in your career.

Check out the NEW FREE courses available in the academy and our new blog!

🆕 Two Brand New Courses Just Launched

Ready to break into offensive security? Our new "Hacking Linux" course with Ryan Yager is live and already making waves. This isn't just theory—you'll build vulnerable machines, then systematically break them down using real attack vectors like FTP, SSH, NFS exploitation, SUID bits, sudo abuse, and privilege escalation techniques. Perfect for anyone looking to understand how attackers think and move through Linux environments.

[Launch Special: 20% off until September 28th with code EARLYBIRD20] 👉 Start Hacking Linux Today

For our GRC professionals, Steve McMichael brings you "Cyber Risk Management Fundamentals"—your foundation for speaking the language of business risk. Master the NIST Risk Management Framework, learn to identify and prioritize threats, and develop the skills to communicate risk effectively to stakeholders who control the budget.👉 Master Risk Management

LET’S CONNECT

Stay current on trending topics, tips, events and resources in cybersecurity, connect with Simply Cyber on socials for new content.

As always, please send me feedback. Which tip above is your favorite? What do you want more or less of? Other suggestions? Please let me know. Just send a DM on X with #actionableintel in the subject so I can find it.

Join us on the Daily Cyber Threat Brief happening every weekday morning at 8 AM Eastern on YouTube and LinkedIn.

Find more about what’s happening this week in the Simply Cyber community, below. Join us on the Daily Cyber Threat Brief happening every weekday morning at 8 AM Eastern on YouTube and LinkedIn.

Thank you and see you again next week, #TeamSC!

Gerry