This week, we get un-curmudgeoned by Mandy, spending a bunch of time talking about regulations, compliance, and even the US federal government's commitment to cybersecurity internally and with the community at large. We even dive into some Microsoft patches, hacking defunct eScooters, and a lively discussion on ADS-B spoofing!
The Embedded Systems Threat Matrix has been unveiled as a new cybersecurity framework by MITRE to improve the defenses of critical embedded systems, according to SecurityWeek.
Intel and AMD have confirmed that some of their processors are impacted by a trio of new low-severity PCI Express flaws, tracked as CVE-2025-9612, CVE-2025-9613, and CVE-2025-9614, according to SecurityWeek.
Threat actors have continued leveraging USB drives to spread the CoinMiner cryptocurrency mining malware as part of an ongoing attack campaign aimed at South Korean workstations, Cyber Security News reports.
Intel's Software Guard Extensions and Trust Domain Extensions, as well as AMD's Secure Encrypted Virtualization with Secure Nested Paging, which are DDR5 CPUs' trusted execution environments, could expose secrets through the new TEE.Fail side-channel attack, reports The Hacker News.
In the security news: When in doubt, blame DNS, you're almost always correct, How to Make Windows 11 great, or at least suck less, CSRF is the least of your problems, Shady exploits, Linux security table stakes (not steaks), The pill camera, Give AI access to your UART, Security products that actually try to be secure?, Firmware vulnerabilities, lo...
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.