- Simply Cyber Newsletter
- Posts
- Simply Cyber Newsletter #187
Simply Cyber Newsletter #187
Crush Your Week Like a Cyber Pro with Simply Cyber!
Start your work week off at full speed with expert analysis and actionable intel from top cybersecurity news stories. Share with your End Users, Peers, and Executives to support weekly security awareness with the Simply Cyber Newsletter.
FOR END USERS
FTC warns of record $3.5 billion losses to imposter scams in 2025. The FTC logged $3.5 billion in impersonation losses for 2025, the most reported fraud category of the year. The number that should shape your messaging is not the total. It is the channel. Social media accounted for $2.1 billion of those losses, an eightfold jump since 2020. If your awareness content still treats email as the primary threat surface, it is describing 2020.
What you need to know: There’s an old saying that is worth looking further into when you have the chance: “If you believe that, I’ve got a bridge to sell you.”
Impersonation works because it borrows trust your people already have. The bank, the government agency, the delivery service, the help desk. None of it requires malware. It requires a believable sender and a reason to act fast. That is the behavior your program exists to interrupt.
Two things are worth pulling forward this quarter for your end users:
First, broaden the channel story. Most end users still picture a scam as a sketchy email. The FTC data says the money is moving through Facebook, WhatsApp, and Instagram, with Facebook alone outpacing text and email combined. If you only run email phishing simulations, your population is rehearsing a limited threat topic. Adding or creating content around smishing and social-platform scenarios keeps the lessons matched to the threat.
Second, and this is a huge one, teach one portable behavior instead of a list of red flags. Red flags age badly but verification does not. The habit you want internalized is simple; when someone you did not contact asks you to move money or share information, stop and confirm through a channel you chose, not the one they handed you. Whether it be a known phone number or the official site typed in yourself, out of band verfication is one of the best defenses you can have is most situations. For those who know their Tolkien, think of it this way: Sauron rarely shows up as himself. He comes as a friendly voice, a trusted face, a fair offer - out of band verification unmasks all of them.
FOR PEERS
FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices. Researchers uncovered a dataset containing what appear to be valid usernames and plaintext passwords for roughly 74,000 Fortinet VPN and firewall devices worldwide. The source of the exposure remains unknown, but security researchers have verified portions of the data and believe many affected devices remain online.
What you need to know: FortiBleed is a conversation to start, not a control to recite.
Researchers do not agree on how the credentials were obtained. One theory points to large-scale brute forcing. Another suggests the data came directly from exported device configurations. The passwords were often long and complex, which does not fit the profile of easy guessing. The source remains unknown.
That uncertainty is the point. You cannot patch a leak when nobody has confirmed the door.
Start with two questions for your network peers. Are we in the dataset? Hudson Rock has published a free lookup tool. And how many FortiGate management interfaces are exposed to the internet?
For the SOC, the question is authentication, not exploitation. Pull the VPN logs. A stolen credential looks like a normal login until someone looks closer. And remember: patching is visible but credential exposure is not. This leak is a reminder that both belong in the same risk conversation, even when they have different owners.
FOR EXECUTIVES
Chainguard's new Athena coalition uses AI to fix open-source flaws - before attackers exploit them. A coalition of major technology companies launched Athena, an initiative that uses AI and shared intelligence to identify and remediate vulnerabilities in critical open-source software before attackers can weaponize them. The effort reflects growing concern that the time between discovery and exploitation is shrinking faster than traditional security processes can respond.
What you need to know: When competitors start sharing defenses, it is usually a sign that the problem has grown bigger than any one organization can solve alone.
The founding members of Athena include JPMorgan Chase and other major organizations operating in highly regulated and security-conscious industries. They are collaborating because the economics of software security are changing. The time between discovering a vulnerability and seeing it exploited keeps shrinking, while the work required to find, validate, and remediate those flaws keeps growing.
Open-source software quietly supports critical business functions across nearly every industry. Most organizations neither build it nor maintain it, yet they depend on it every day. As exploitation timelines shrink, that dependency becomes a business risk long before it becomes a technology problem.
Confirm you can name the critical open-source dependencies yout business relies on, and who owns watching them, before it becomes a leadership question. If that owner exists, you have your answer ready. If they do not, that gap is the thing to raise, not the coalition.
LLM traffic converts 3× better than Google search
58% of buyers now start their research in ChatGPT or Gemini, not Google. Most startups aren't showing up there yet.
The ones that are get cited by the AI tools their buyers, investors, and future hires already use. And they convert at 3×.
Download the free AEO Playbook for Startups from HubSpot and get the exact steps to start showing up. Five minutes to read.

JOIN US EVERY WEEKDAY DAILY CYBER THREAT BRIEF
Special Guest Host this week is Daniel Lowrie! Meet #TeamSC in live chat and get your dose of cybernews and expert analysis live before the day gets moving.
Gerald Auger, Ph.D. livestreams the Daily Cyber Threat Brief on Simply Cyber every weekday at 8:00 AM EDT: https://cyberthreatbrief.simplycyber.io
Join the party with cybersecurity enthusiasts and professionals alike who enjoy learning about the latest in cybersecurity news and staying connected.
NEW VIDEO: 3 QUESTIONS IN EVERY CYBER INTERVIEW
Most cybersecurity candidates spend hours studying technical concepts and almost no time preparing for the questions they're guaranteed to get. That mistake costs people offers.
In this new video, Gerald Auger, Ph.D. breaks down the three questions that show up in nearly every cybersecurity interview, along with the bonus question that often reveals whether you're genuinely invested in the field.
Learn how to answer:
🔹 Tell me about yourself
🔹 Why do you want this job?
🔹 What questions do you have for us?
🔹 How do you stay current in cybersecurity?
These aren't trick questions. They're opportunities to show hiring managers how you think, communicate, and fit the role.
If you've got a SOC analyst, GRC, pentest, or other cyber interview on the horizon, this is one worth watching.
Tune in to Simply Cyber Media Group at 4:00 PM EDT on Monday, June 22nd to learn more:
SC MEDIA GROUP WEEKLY EVENTS SCHEDULE
Learning and networking happening every day of the work week on Simply Cyber:
Check out Simply Cyber on YouTube: youtube.com/@simplycyber
Connect with the SC Discord community: simplycyber.io/discord
SIMPLY CYBER MONTHLY EVENTS LINEUP
Want to know what’s happening at Simply Cyber at any given time?
Head over to the SC Monthly Events Calendar to register for new and upcoming events for the month - don’t forget to subscribe! lu.ma/simplycyber
SC ACADEMY THE PLACE FOR CYBER CAREERS
At Simply Cyber Academy, we specialize in making GRC and Cybersecurity Careers a reality. Empower your career by learning real in-demand skills from cyber experts and the theory behind those skills with Simply Cyber Academy.
The popular GRC Analyst Master Class is a must for kickstarting your GRC Cybersecurity career. In addition, we have new courses covering various areas of focus in cyber available to help you advance in your career.
Check out the NEW FREE courses available in the academy!
SIMPLY CYBER ACADEMY BLOG HIGHLIGHT
Check out the highlighted blog on Simply Cyber Academy:
LET’S CONNECT
Stay current on trending topics, tips, events and resources in cybersecurity, connect with Simply Cyber on socials for new content.
As always, please send me feedback. Which tip above is your favorite? What do you want more or less of? Other suggestions? Please let me know. Just send a DM on X with #actionableintel in the subject so I can find it.
Join us on the Daily Cyber Threat Brief happening every weekday morning at 8 AM Eastern on YouTube and LinkedIn.
Find more about what’s happening this week in the Simply Cyber community, below. Join us on the Daily Cyber Threat Brief happening every weekday morning at 8 AM Eastern on YouTube and LinkedIn.
Thank you and see you again next week, #TeamSC!
Gerry







