July 2025 News & Tips | Cybersecurity News Review

July 2025 News & Tips | Cybersecurity News Review
View this email in your browser
The mission of this publication is to cut through the clutter of cybersecurity news stories and provide you with the most important, relevant and actionable cybersecurity information.

If this newsletter adds value, fantastic! That is the goal. Please forward it on to friends/colleagues. If not, no hard feelings. Please look to the bottom for an easy to click "unsubscribe" button.
Subscribe
In this issue:
Month's News in Review
Upcoming Speaking Events
Must Read Articles This Month
Cybersecurity Tip of the Month
Enjoy this month's newsletter? You can use this link to post on social media or send to friends! Thanks for sharing!
This Month's News in Review

Welcome back to the monthly TCE Strategy newsletter! From kiss-cam carnage to AI feeding into mental health issues to McDonald’s exposing a database of applicants with a password of 123456, July has been a heck of a month in the world of cybersecurity. Let’s see how this month’s cybersecurity news can help us make better decisions about what is Secure Enough for us, the companies we work for, and our families.


The ”McHire” site has been McBreached because someone used a ridiculously bad McPassword.

McDonald’s is embracing the move to AI whole-hog, and to be honest, AI does do some things very well, so using it for those things makes sense. In a dubious use of AI, McDonald’s chose to build an AI chatbot called “Olivia” to screen applicants. “Olivia” does things like ask for a resume and give personality tests.

“Olivia” keeps logs of all of its chats, which makes sense. “Olivia” also asks for a lot of personal information, which also makes sense given that job applicants are using it. It turns out that the developers of the “Olivia" chatbot chose a back-end account with a username of administrator and a password of 123456. According to cybersecurity researchers Sam Curry and Ian Carroll, that administrator account “allowed them to access a Paradox.ai account and query the company's databases that held every McHire user's chats with Olivia. The data appears to include as many as 64 million records, including applicants' names, email addresses, and phone numbers.” Um… Wow. Just, wow. I’ve worked incidents where someone set up a test account with a ridiculously bad password, but not an administrator account. This is the cybersecurity equivalent of making your garage door code to be “1234”, except your garage door opener is Internet-facing and you are keeping 64 million sensitive records in your garage. I haven’t seen a password this bad since Mel Brooks’s password in Spaceballs.

Takeaway: Ridiculously bad cybersecurity McBehavior like this isn’t going to change unless it is in corporations’ financial best interest to care about the McCybersecurity of their McDatabases. Sure, there will be class action lawsuits about this, but the lawyers will walk away with millions and the actual victims will get less than the cost of a Happy Meal. (NOTE1: If there were EU-applicants in the database, GDPR laws may have some teeth here. NOTE2: I got a virtual check for $6 from the Equifax breach of 2017, which I suppose would have paid for a Happy Meal). So what do we do? We elect political leaders that will pass laws to make cybersecurity penalties high enough that USA-based companies will care. There is simply no other way I’m aware of to change this type of behavior.


Kiss Cams and privacy

Kiss cams have been around for decades. They are fun at sporting events, and apparently pop music concerts have taken to them as well. They are also seemingly random. If you’re in the audience, you may or may not end up on the Jumbotron screen depending on the mood of the cameraman. Fate was not smiling on Andy Byron and Kristin Cabot at a Coldplay concert last week, when they ended up on the kiss cam, but they are both married to other people. And Andy Byron is the CEO of a company called “Astronomer”. And Kristin Cabot is the head of HR for Astronomer. This is not a good look for Astronomer, and is unlikely to lead to marital bliss for Andy Byron or Kristin Cabot either. 

We live in a society of constant surveillance because of the convenience and low cost of the technology needed to do surveillance (cell phones and video cameras being the most obvious examples, but there are many others). In fact, leaving your cell phone at home has been used in courts as evidence of malicious intent, so any interest in not being surveilled is an indication of being “up to no good”. I’m not a fan of this. I grew up in a pre-Internet era, and the thought that I could get in my car at 16 years old and go where I wanted to without the assumption that I’m being tracked was the literal definition of freedom in my book. That era has long since gone, and I’m in no way convinced that society is better for it. The immediate fallout is that Andy Byron is no longer CEO of Astronomer and Coldplay now has a disclaimer at the beginning of their concerts. Long term, who knows?

Takeaway: Assume you are on camera. Keep private matters out of public view. Or, you can just choose not to have an affair.

 

Have you noticed how nice AI is when you ask it questions? Sometimes it’s too nice.

I’ve been using AI bots for some time, and have had distinctively mixed interactions with them. Sometimes they are stunningly impressive in what they can do. Sometimes it’s a game of 20 questions just to get it to understand what you’re asking, and then it gets the answer wrong. No matter what I’ve asked, though, its AI bots seem to be programmed to be polite, encouraging and complimentary. While I’m a huge fan of more politeness and encouragement in society, there are times when being polite is not helpful. Encouraging a toddler to keep eating a crayon is not helpful. Encouraging a new driver to drive through standing water at high speeds is not helpful. Encouraging people with thoughts of doing self-harm is downright destructive. The real question is, where should the line be drawn between AI being encouraging and it encouraging all the wrong things?

In a very interesting case described in the Wall Street Journal, ChatGPT ran into (likely completely unintended) controversy recently when it interacted with a gentleman named Jacob Irwin. Jacob asked ChatGPT to critique his theory on faster-than-light travel a few months back, and ChatGPT was very complimentary and encouraging, stating that he had found a way to bend time and had invented “god-tier tech”. As it turns out, he was going through a manic episode and ended up hospitalized.

There isn’t any thought here that ChatGPT can induce mental health issues, but in this case, it did seem to encourage them, perhaps by being programmed to be too nice? Sometimes being kind and encouraging to a fault can be extremely counterproductive.

Takeaway: AI is a tool, not a friend. It is not a counselor. It is not designed to provide feedback on scientific theories. It does what it is programmed to do, and the people who build AI engines don’t fully understand how they work. Find support and friendship among your friends. AI has no feelings, no emotion, and no morality beyond what the programmers gave it (and again, even they don’t fully understand how AI works).


Pig butchering scams are preying on retirees. 

The term “pig butchering” is used for online cybercriminal scams that try to steal the life savings of people (primarily retirees), similar to “fattening up a hog for slaughter”, hence the name. It has been around for some time, and many people have lost millions to people halfway around the world. The scam normally works something like this:

  1. Cybercriminal reaches out to you on a social media platform acting strictly as a friend.

  2. Cybercriminal tries to deepen friendship. May become romantic. Shares intimate details about his/her life.

  3. Cybercriminal mentions how well they are doing in their investments, in the hopes that you will ask more about how they invest.

  4. You ask to get in on some of their investments.

  5. Cybercriminal sets up a fake website and gives you a fake account on it where it looks to you like you can invest your money.

  6. Cybercriminal makes the website look like you are making a ton of money on your investments.

  7. You invest most or all of your available assets in the investments.

  8. Cybercriminal disappears with your money. The investments were a scam from the start.

This is a very real scenario for many people, especially retirees and widows/widowers, and it takes a sharp eye to see the warning signs of these scams. This month, a new article appeared that talks about how retirees are particularly vulnerable to scams such as these if they begin to face some sort of cognitive decline, such as undiagnosed early-stage Alzheimer’s disease. This makes sense when you think about it: If someone is lonely, looking for companionship, has always done a good job managing their finances, and is now at the very early stages of a cognitive issue, it would be the perfect time for a cybercriminal to strike. 

The article also talks about if banks should do more to fight these sorts of scams, and to be honest they probably should, but until there is a financial incentive or regulatory requirement for them to do so, they almost certainly won’t.

Takeaway: Your investments should get more and more conservative the older you get. Get-rich-quick schemes are almost always scams. Look after friends/loved ones that may need help managing their money. Consider having a trusted relative help you with your financial picture so that you always have a second set of eyes on any major financial decisions.


Until next month, stay safe!

Upcoming Speaking Events


Here is a list of the cities that I will be in over the next several months. Please reach out if you have an event in mind!

July 25-30, Phoenix, AZ

August 24-27, Indianapolis, IN

October 7-9, Trenton, NJ

October 21-23, Lansing, MI

October 29-30, Worcester, MA

December 1-5, Key West, FL

December 22-26, Ft. Myers, FL

March 6-18, 2026, Cairns, Australia

Interesting Articles

Be careful what you put on your home network. "In a Public Service Announcement (PSA), the law enforcement agency claimed that threat actors either install malware to the devices prior to purchase, or via 'required applications' containing backdoors that must be downloaded during setup. It said that affected devices, made mainly in China, include TV streaming devices, digital projectors, aftermarket vehicle infotainment systems, digital picture frames and other products."
Signal chats are now being used as a phishing attack vector. Be very careful who you respond to on any messaging platform, Signal or otherwise.
Microsoft's Copilot is still very much in the beta stage. Not a fan. "EchoLeak exploits what researchers term an 'LLM Scope Violation,' a new class of vulnerability where a large language model can be manipulated into accessing and leaking privileged data beyond its intended authorization scope."



 
This tone-deaf reconciliation package ignores serious threats facing the Nation — including cyber threats from Russia, China and its typhoon campaign, Iran, and cyber criminals — while turning a blind eye to the administration’s reckless dismantling of America’s cybersecurity agency.”
Cybersecurity Tip of the Month

Using a VPN to Protect Your Public Wi-Fi Use
 

Why Use a VPN?

Public Wi-Fi offers a convenient way to get online without using your mobile data. But these networks are often unprotected, making it easier for cybercriminals to intercept sensitive data like login credentials, payment information, and personal emails. In some cases, attackers can even deliver malware to connected devices.

A Virtual Private Network (VPN) is one of the most effective tools for staying safe on public networks. A VPN encrypts your internet traffic, making it unreadable to anyone trying to snoop on your connection. If you regularly connect to public Wi-Fi, using a reputable VPN can help keep your data private and secure.


How to Choose a Reliable VPN

Not all VPNs are created equal—especially free ones. Some may log your data or have weak security protections. Look for VPN providers that have strong privacy policies, good reputations, and strong encryption standards. For tips and recommendations, check out this guide: https://www.comparitech.com/blog/vpn-privacy/vpn-public-wifi/


Extra Steps for Online Safety

While a VPN goes a long way, these additional actions can help boost your security when using public networks:

  • Use multi-factor authentication for important accounts

  • Only enter personal info on websites with HTTPS

  • Turn off Wi-Fi when not in use to avoid auto-connecting to risky networks

  • Set your device to “forget” public networks

  • Disable file and printer sharing in public settings

LinkedIn
Twitter
Facebook
Website
Forward Forward
We want your feedback!

< On a scale of 10, how helpful was this newsletter?>

lowest 1   2   3   4   5   6   7   8   9   10   highest

Copyright © 2025 TCE Strategy, All rights reserved.
You are receiving this email because you are on Bryce Austin's contact list

Our mailing address is:
TCE Strategy
18268 Java Trl
Lakeville, MN 55044

Add us to your address book


Want to change how you receive these emails?
You can update your preferences or unsubscribe from this list

You can reach Bryce at bryce@bryceaustin.com

Email Marketing Powered by Mailchimp
Subscribe to Newsletter

Browse newsletter archives: