- Simply Cyber Newsletter
- Posts
- Simply Cyber Newsletter #193
Simply Cyber Newsletter #193
Crush Your Week Like a Cyber Pro with Simply Cyber!
Start your work week off at full speed with expert analysis and actionable intel from top cybersecurity news stories. Share with your End Users, Peers, and Executives to support weekly security awareness with the Simply Cyber Newsletter.
FOR END USERS
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware. Researchers uncovered an ongoing campaign that hijacks hotel Wi-Fi networks to redirect travelers to fake browser or operating system updates. If a traveler installs the offered software or follows the instructions, attackers can install malware or steal authenticated Microsoft sessions. Researchers have observed the activity since May, but the overall number of successful compromises is unknown.
What you need to know: Most people expect hotel Wi-Fi to ask them to sign in. They don't expect it to tell them their browser, operating system, or security software needs an update. That's exactly what this campaign exploits.
Teach travelers one simple rule: the network providing internet access should never become your software update service. If a hotel Wi-Fi page offers a browser update, security tool, certificate, or asks you to run a command, stop. Complete software updates through the application's built-in updater or your device's normal update process instead. If your organization provides an always-on VPN, connect as soon as possible after joining the network.
The goal isn't to make people afraid of hotel Wi-Fi. It's to help them recognize one unusual moment where attackers are counting on habit. One good decision there can stop the attack before it starts.
FOR PEERS
New Pass-ta-key attacks let malware hijack Google-synced passkeys. Researchers identified three techniques that allow malware on an already compromised Windows device to abuse Google Password Manager's synced passkeys. The attacks target device trust and credential synchronization, not passkey cryptography itself, reinforcing that passwordless authentication still depends on endpoint security.
What you need to know: This research doesn't suggest organizations should reconsider passkeys. It suggests they should reconsider the assumptions around them. While the attacks require malware to already be running on the endpoint, they demonstrate that passwordless authentication is only as strong as the trust placed in the device, its recovery process, and the surrounding identity workflow.
Start a conversation with your identity and endpoint teams. Ask whether your passkey strategy assumes the endpoint is inherently trustworthy, and whether user verification, device re-registration, and recovery workflows have been validated. If you're using Google Password Manager for synced passkeys, review Google's response to the research and assess whether additional controls or compensating safeguards are warranted.
FOR EXECUTIVES
Data Centers Exposed US Carriers to China Hack, House Panel Says. A House committee concluded that indirect connections between U.S. telecommunications providers and infrastructure linked to Chinese state-owned carriers may have contributed to the exposure exploited during the Salt Typhoon campaign. The report argues that regulatory gaps and overlooked architectural dependencies left critical communications infrastructure vulnerable.
What you need to know: The most valuable finding isn't that a nation-state breached major telecom providers. It's that risk persisted outside the boundaries organizations believed they had secured.
The report suggests indirect infrastructure relationships, including third-party data centers and related services, created exposure even after regulators restricted Chinese telecommunications providers from operating in the U.S. Compliance addressed the obvious connections. It did not necessarily eliminate every pathway.
This is a useful reminder that resilience depends on understanding how critical services are connected, not just whether they meet regulatory requirements. Before this becomes an executive briefing, confirm whether similar indirect dependencies exist within your organization's critical providers. The lesson isn't about one telecom attack. It's about challenging assumptions that yesterday's mitigation removed today's risk.
1,000+ Claude Prompts Top Professionals Actually Use at Work
Claude can be your analyst, editor, and strategist.
But most professionals are using it to fix grammar.
These 1,000+ Claude prompts take it from grammar tool to your most powerful AI work assistant.
Sign up for Superhuman AI and get:
1,000+ ready-to-use Claude prompts to get real work done in minutes — researched, tested, and used by professionals at Google, Microsoft, and NASA
Superhuman AI newsletter (4 min daily) so you keep learning new AI tools and skills to stay ahead in your career — the prompts are just the beginning

DAILY CYBER THREAT BRIEF ON SIMPLY CYBER
JOIN US EVERY WEEKDAY MORNING
Gerald Auger, Ph.D. livestreams the Daily Cyber Threat Brief on Simply Cyber every weekday at 8:00 AM EDT: https://cyberthreatbrief.simplycyber.io
Join the party with cybersecurity enthusiasts and professionals alike who enjoy learning about the latest in cybersecurity news and staying connected.
SC VIDEO DROP: TECH RUNNING THE WORLD
You tapped your card this morning and something made it just work. That something was probably a mainframe, the technology most people don’t think about. Roughly 70% of the world's transactions still run on these machines every single day. So when IBM invited me to their Poughkeepsie campus, where they build IBM Z mainframes and then try everything they can to break them, I had to see it for myself. Almost everything I assumed turned out to be wrong.
What you'll learn in this video:
🔹 What a mainframe actually is (hardware, firmware, and OS, not just a big server)
🔹 Why 70% of global transactions and the entire cashless economy depend on them
🔹 How IBM engineers eight nines of reliability: three-tenths of a second of downtime per year
🔹 How they replace a processor while the system is still running (concurrent drawer repair)
🔹 The environmental torture testing: thermal chambers, 3,000 meter altitude, and earthquakes
🔹 The FIPS level 4 security module that physically destroys its own keys when tampered with
🔹 How mainframes protect data while it's actually in use, not just at rest or in transit
🔹 What crypto agility means and how IBM is preparing for a post-quantum world
🔹 How AI is built directly into the chip with Telum and confidential computing
If you have ever depended on a machine you have never seen, this one is for you.
Set your notifications for 9:30 AM EDT: https://www.youtube.com/@SimplyCyber/videos
SC MEDIA GROUP WEEKLY EVENTS SCHEDULE
Learning and networking happening every day of the work week on Simply Cyber:
Check out Simply Cyber on YouTube: youtube.com/@simplycyber
Connect with the SC Discord community: simplycyber.io/discord
SC ACADEMY THE PLACE FOR CYBER CAREERS
At Simply Cyber Academy, we specialize in making GRC and Cybersecurity Careers a reality. Empower your career by learning real in-demand skills from cyber experts and the theory behind those skills with Simply Cyber Academy.
The popular GRC Analyst Master Class is a must for kickstarting your GRC Cybersecurity career. In addition, we have new courses covering various areas of focus in cyber available to help you advance in your career.
Check out the NEW FREE courses available in the academy!
Simply Cyber Academy Blog Highlight:
Check out the highlighted blog of the week on Simply Cyber Academy:
LET’S CONNECT
Stay current on trending topics, tips, events and resources in cybersecurity, connect with Simply Cyber on socials for new content.
As always, please send me feedback. Which tip above is your favorite? What do you want more or less of? Other suggestions? Please let me know. Just send a DM on X with #actionableintel in the subject so I can find it.
Join us on the Daily Cyber Threat Brief happening every weekday morning at 8 AM Eastern on YouTube and LinkedIn.
Find more about what’s happening this week in the Simply Cyber community, below. Join us on the Daily Cyber Threat Brief happening every weekday morning at 8 AM Eastern on YouTube and LinkedIn.
Thank you and see you again next week, #TeamSC!
Gerry






