Simply Cyber Newsletter #186

Crush Your Week Like a Cyber Pro with Simply Cyber!

In partnership with

Start your work week off at full speed with expert analysis and actionable intel from top cybersecurity news stories. Share with your End Users, Peers, and Executives to support weekly security awareness with the Simply Cyber Newsletter.

FOR END USERS

If you don't fall for these extortionists' calls, they'll show up with USB sticks. A cybercrime group known as UNC3753 is targeting U.S. organizations by impersonating IT support staff through phone calls, remote support sessions, and, in some cases, in-person visits. Researchers observed attacks progressing from initial contact to data theft and extortion within a single day, with some data theft beginning in less than an hour.

What you need to know: Educate your end users that threats don't always start with a bad link. Sometimes it's a phone call, a Teams message, or someone in the lobby claiming to be from IT.

Attackers have posed as help desk staff, security team members, or outside contractors to talk employees into granting remote access, sharing files, or letting work be done on their machines. Some showed up in person to image a computer or run a USB backup.

Many of these attacks open with a routine-looking email, an invoice or renewal notice, with no link or attachment. That email isn't the attack. Its job is to make the call that follows feel expected. The call is the attack.

Verify any unexpected request involving tech support, account changes, software installs, remote access, or removable media, even when it sounds urgent. Confirm it through a normal process or a contact you already know. And if something feels off, report it even if you didn't go along with it. These groups call the same people more than once, so reporting early often protects whoever they try next.

A legitimate request will still be legitimate after you've checked.

FOR PEERS

Exclusive: Anthropic's Mythos can exploit new flaws in hours. Anthropic researchers found that its Mythos Preview model could transform publicly disclosed software vulnerabilities into working exploits in hours. In testing, the model generated a proof-of-concept exploit for a Windows kernel flaw in 31 minutes and successfully created multiple exploits for recently disclosed Windows and Firefox vulnerabilities.

What you need to know: This one is worth raising with your team.

For years we've treated public disclosure as the start of a race between patching and exploitation. What makes this research notable isn't that AI can find vulnerabilities. It's how fast it can weaponize the ones we already know about.

In Anthropic's testing, Mythos read the patches, figured out the flaw, and built working exploits for newly disclosed bugs in a fraction of the usual time. Controlled environment, but it points at a trend we're all watching: the window between disclosure and exploitation keeps closing.

This doesn't make everything an emergency patch. It means working a patch list top to bottom matters less than knowing your own environment. Which assets actually matter, which are internet-facing, and which of those bugs are genuinely exploitable where you sit. That's where I'd put your attention. As exploit development gets faster and cheaper, the teams that come out ahead won't be the ones patching the most. They'll be the ones who know their exposure and prioritize by real risk.

If this shifts how you'd brief your team, say so to the people around you. This kind of thing spreads peer to peer, not top down.

FOR EXECUTIVES

CISA to require federal agencies to patch some cyber vulnerabilities within 3 days. CISA issued a new directive requiring federal agencies to patch the highest-risk vulnerabilities within three days. The policy prioritizes vulnerabilities that are actively exploited, internet-facing, automatable, and capable of giving attackers control of systems. CISA cited advances in artificial intelligence as a key factor driving the need for faster remediation.

What you need to know: CISA just told federal agencies to patch their highest-risk vulnerabilities within three days, and pointed to AI as the reason the clock got shorter. The detail worth your attention isn't the deadline. It's that in one agency CISA studied, only about 1% of vulnerabilities met the bar for that three-day window.

That 1% is the whole point. As AI speeds up how fast attackers turn a known flaw into a working exploit, the advantage shifts away from organizations that patch the most and toward those that know exactly which assets carry the most risk. The directive is really a prioritization model: actively exploited, internet-facing, automatable, and capable of handing over control. Everything else can move at a normal pace.

If you take one thing to your senior leadership, make it this: we don't need to patch everything faster, we need to know which 1% would actually threaten the business and be able to move on it in days. That shift, from volume to prioritization, is what AI-accelerated exploitation is forcing on every organization, ours included.

The question to put on the table is simple. Do we know what our 1% is right now, and can we act on it fast enough when the next one lands?

1,000+ Proven ChatGPT Prompts That Help You Work 10X Faster

ChatGPT is insanely powerful.

But most people waste 90% of its potential by using it like Google.

These 1,000+ proven ChatGPT prompts fix that and help you work 10X faster.

Sign up for Superhuman AI and get:

  • 1,000+ ready-to-use prompts to solve problems in minutes instead of hours—tested & used by 1M+ professionals

  • Superhuman AI newsletter (3 min daily) so you keep learning new AI tools & tutorials to stay ahead in your career—the prompts are just the beginning

JOIN US EVERY WEEKDAY DAILY CYBER THREAT BRIEF

Gerald Auger, Ph.D. livestreams the Daily Cyber Threat Brief on Simply Cyber every weekday at 8:00 AM EDT: https://cyberthreatbrief.simplycyber.io

Join the party with cybersecurity enthusiasts and professionals alike who enjoy learning about the latest in cybersecurity news and staying connected.

NEW VIDEO DROP: SOC ANALYST INTERVIEW - PART 5

What do you do when your threat intel feed flags a ransomware variant actively targeting your industry through a specific vulnerability - and you don't know if you're patched?

This question is showing up more in SOC analyst interviews as threat intel programs mature. The answer tells an interviewer everything: whether you understand how intel translates into action, how to work cross-functionally, and how to communicate risk before an incident happens.

Eric Capuano reviews answers from three candidates - junior, mid-level, and senior - and breaks down what a proactive security mindset actually sounds like in the room.

In this video:
- Why threat intel is harder to operationalize than most analysts think
- The first question you should always ask before acting on any intel
- How to work cross-functionally when you don't own asset inventory or patch management
- What separates a technically strong answer from a strategically strong one

BONUS: What are STIX and TAXII - and are they actually used in real SOCs?

Check out the video now on YouTube: https://youtu.be/J5BD6DJIv4s 

SIMPLY CYBER FIRESIDES LIVE


Join us this Thursday at 4:30 PM EDT for the upcoming Simply Cyber Firesides Live: https://youtube.com/@simplycyber 

SC MEDIA GROUP WEEKLY EVENTS SCHEDULE

Learning and networking happening every day of the work week on Simply Cyber:

SIMPLY CYBER MONTHLY EVENTS LINEUP

Want to know what’s happening at Simply Cyber at any given time?

Head over to the SC Monthly Events Calendar to register for new and upcoming events for the month - don’t forget to subscribe! lu.ma/simplycyber 

SC ACADEMY THE PLACE FOR CYBER CAREERS

At Simply Cyber Academy, we specialize in making GRC and Cybersecurity Careers a reality. Empower your career by learning real in-demand skills from cyber experts and the theory behind those skills with Simply Cyber Academy.

The popular GRC Analyst Master Class is a must for kickstarting your GRC Cybersecurity career. In addition, we have new courses covering various areas of focus in cyber available to help you advance in your career.

Check out the NEW FREE courses available in the academy!

SIMPLY CYBER ACADEMY BLOG HIGHLIGHT

Check out the highlighted blog on Simply Cyber Academy:  

LET’S CONNECT

Stay current on trending topics, tips, events and resources in cybersecurity, connect with Simply Cyber on socials for new content.

As always, please send me feedback. Which tip above is your favorite? What do you want more or less of? Other suggestions? Please let me know. Just send a DM on X with #actionableintel in the subject so I can find it.

Join us on the Daily Cyber Threat Brief happening every weekday morning at 8 AM Eastern on YouTube and LinkedIn.

Find more about what’s happening this week in the Simply Cyber community, below. Join us on the Daily Cyber Threat Brief happening every weekday morning at 8 AM Eastern on YouTube and LinkedIn.

Thank you and see you again next week, #TeamSC!

Gerry