- Simply Cyber Newsletter
- Posts
- Simply Cyber Newsletter #192
Simply Cyber Newsletter #192
Crush Your Week Like a Cyber Pro with Simply Cyber!
Start your work week off at full speed with expert analysis and actionable intel from top cybersecurity news stories. Share with your End Users, Peers, and Executives to support weekly security awareness with the Simply Cyber Newsletter.
FOR END USERS
Microsoft Teams vishing attacks lead to Chaos ransomware attacks. Attackers posed as IT support through external Microsoft Teams accounts, persuaded employees to start remote support sessions, and installed backdoors. Sophos linked at least three intrusions to Chaos ransomware, including one that reached file encryption in under 17 hours.
What you need to know: Educate your end users about the moment someone claiming to be IT asks them to launch Quick Assist, install remote support software, or share control of their screen. The attacker may know company language, use an ordinary-sounding name, and contact them through Microsoft Teams instead of email, making the request feel legitimate. Remind employees that none of those details prove the caller works for your organization.
Give them one simple habit: before granting remote access, stop the conversation and verify the request through your organization's normal help desk process using a known support channel, not one provided by the caller. The goal is not to make people distrust IT. It's to make verification part of the process whenever someone asks for control of a device. A simple response such as, "Before I give remote access, I need to verify this through our normal support process," is often enough to interrupt the attack before any software is installed.
FOR PEERS
Over 24,000 exposed server BMCs leak password hash via decades-old flaw. Researchers found more than 24,000 internet-facing server management interfaces exposing password hashes through a long-known IPMI weakness. Many also accepted weak or default credentials, highlighting how forgotten management infrastructure can quietly become one of an organization's highest-risk attack surfaces.
What you need to know: Use this report to start a conversation with infrastructure, platform engineering, and server teams about inventory ownership, network isolation, credential rotation, and whether legacy IPMI authentication still exists anywhere in production.
Baseboard Management Controllers, or BMCs (dedicated hardware used to remotely manage servers), often exist outside the visibility of vulnerability management, asset inventories, and even server ownership records. That makes this story less about a 20-year-old IPMI weakness and more about operational blind spots.
Ask who owns your organization's management plane and whether anyone can confidently inventory every internet-accessible BMC, iLO, iDRAC, or Redfish interface. If the answer requires several meetings to discover, you've already identified the larger issue. The organizations most at risk may not be those with the oldest firmware, but the ones where management infrastructure quietly became nobody's responsibility over time.
FOR EXECUTIVES
Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack. Hackers targeted operational technology at more than 30 Minnesota water utilities. One plant went offline for about three hours, while other communities used manual operations or contingency plans. Officials reported no change to drinking water use.
What you need to know: Brief executives on what this incident proved: operational resilience depends on whether essential services can continue when computerized systems fail or become untrusted. More than 30 water utilities were targeted, yet affected communities used manual operations, contingency plans, and
The busines lesson here is not limited to water systems. Any organization with operational technology, automated facilities, manufacturing controls, or other systems tied to physical operations faces the same decision point. Cybersecurity investment must account for the ability to isolate affected technology, operate safely without it, and restore it without creating a second disruption. This knowledge should inform future decisions about resilience funding, incident exercises, staffing, and modernization.
Continuity plans are only credible when the organization can run the operation after the digital layer becomes unavailable.
1,000+ Claude Prompts Top Professionals Actually Use at Work
Claude can be your analyst, editor, and strategist.
But most professionals are using it to fix grammar.
These 1,000+ Claude prompts take it from grammar tool to your most powerful AI work assistant.
Sign up for Superhuman AI and get:
1,000+ ready-to-use Claude prompts to get real work done in minutes — researched, tested, and used by professionals at Google, Microsoft, and NASA
Superhuman AI newsletter (4 min daily) so you keep learning new AI tools and skills to stay ahead in your career — the prompts are just the beginning

THIS WEEK: LIVE FROM HACKER SUMMER CAMP
JOIN US WEEKDAYS DAILY CYBER THREAT BRIEF
Gerald Auger, Ph.D. livestreams the Daily Cyber Threat Brief on Simply Cyber every weekday at 8:00 AM EDT: https://cyberthreatbrief.simplycyber.io
Join the party with cybersecurity enthusiasts and professionals alike who enjoy learning about the latest in cybersecurity news and staying connected.
SC VIDEO DROP: THE FASTEST WAY INTO CYBER
Two people get the same $100,000 to protect the same house. One secures the doors, windows, and alarm. The other spends all of it on the chimney. That difference is what GRC is, and knowing how to spend limited budget for the most risk reduction is the most valuable skill in cybersecurity.
Here is the part nobody tells you. The fastest, most forgiving way into the industry is the GRC audit role. In audit you are not deciding which controls to build. You are checking whether the required controls are actually in place, yes or no. And the economics of federal audit work quietly favor hiring juniors, so your inexperience is the reason a firm wants you, not the obstacle you think it is.
I spent 20 years in cyber, mostly in GRC, doing this exact work inside one of the largest federal contractors in the US. This is the honest breakdown, plus the free NIST documents you can start studying tonight.
What you'll learn:
What GRC (Governance, Risk, and Compliance) actually is, using a simple house-and-budget analogy
Why GRC is the foundation of every cybersecurity program
Why almost nobody breaking into cyber has heard of GRC (and why that is your opening)
Why the GRC audit role is the fastest and most forgiving way into the industry
How audit work actually works: checking controls yes or no, and learning in junior-senior pairs
Why federal audit economics make firms want to hire junior auditors
What the cybersecurity workforce gap and GRC market growth mean for your odds
Why GRC is less technical but not non-technical, and the foundation you still need
Which free NIST 800-series documents to study first (800-37, 800-30, 800-18, 800-53, 800-53A)
Check out the video now on YouTube: https://youtu.be/rFFefZgnjT8
SIMPLY CYBER x HACK SMARTER MEETUP
Simply Cyber x Hack Smarter Hacker Summer Camp Meetup
Simply Cyber and Hack Smarter are teaming up again to bring the community together in real life at DEF CON.
Join us Friday, August 7th at 4:00 PM at Beer Zombie Brewing Company, the same spot that hosted us last year. This is your chance to put faces to the names you see in chat every day, swap war stories, trade ideas, and hang out with the people who make this community what it is.
Expect great conversation, plenty of laughs, and a genuinely welcoming crowd. Beer Zombie has an excellent tap list, non-alcoholic options are available so everyone can join in, and food trucks will be on site to keep you fueled.
Registration required - Tickets are $5, and 100% of proceeds go to directly charity. Grab yours below and we'll see you in Vegas.
Hosted by Simply Cyber and Hack Smarter - register below:
SC MEDIA GROUP WEEKLY EVENTS SCHEDULE
Learning and networking happening every day of the work week on Simply Cyber:
Check out Simply Cyber on YouTube: youtube.com/@simplycyber
Connect with the SC Discord community: simplycyber.io/discord
SC ACADEMY THE PLACE FOR CYBER CAREERS
At Simply Cyber Academy, we specialize in making GRC and Cybersecurity Careers a reality. Empower your career by learning real in-demand skills from cyber experts and the theory behind those skills with Simply Cyber Academy.
The popular GRC Analyst Master Class is a must for kickstarting your GRC Cybersecurity career. In addition, we have new courses covering various areas of focus in cyber available to help you advance in your career.
Check out the NEW FREE courses available in the academy!
Simply Cyber Academy Blog Highlight:
Check out the highlighted blog of the week on Simply Cyber Academy:
SC MERCH STORE GRAND OPENING
The New Simply Cyber Merch Store grand opening is happening now!
Enjoy 20% off all aparel, hats, and bags - now through August 7th:
Get your gear and represent #TeamSC!
LET’S CONNECT
Stay current on trending topics, tips, events and resources in cybersecurity, connect with Simply Cyber on socials for new content.
As always, please send me feedback. Which tip above is your favorite? What do you want more or less of? Other suggestions? Please let me know. Just send a DM on X with #actionableintel in the subject so I can find it.
Join us on the Daily Cyber Threat Brief happening every weekday morning at 8 AM Eastern on YouTube and LinkedIn.
Find more about what’s happening this week in the Simply Cyber community, below. Join us on the Daily Cyber Threat Brief happening every weekday morning at 8 AM Eastern on YouTube and LinkedIn.
Thank you and see you again next week, #TeamSC!
Gerry








