June 2025 News & Tips | Cybersecurity News Review

June 2025 News & Tips | Cybersecurity News Review
View this email in your browser
The mission of this publication is to cut through the clutter of cybersecurity news stories and provide you with the most important, relevant and actionable cybersecurity information.

If this newsletter adds value, fantastic! That is the goal. Please forward it on to friends/colleagues. If not, no hard feelings. Please look to the bottom for an easy to click "unsubscribe" button.
Subscribe
In this issue:
Month's News in Review
Upcoming Speaking Events
TCE Strategy in the News
Must Read Articles This Month
Cybersecurity Tip of the Month
Enjoy this month's newsletter? You can use this link to post on social media or send to friends! Thanks for sharing!
This Month's News in Review

Welcome back to the monthly TCE Strategy newsletter! From the largest username/password breach in history to a husband caught cheating on his wife by his toothbrush, the world of cybersecurity showed no signs of slowing down in June. Let’s see how this month’s cybersecurity news can help us make better decisions about what is Secure Enough for us, the companies we work for, and our families.


Big password leaks have happened before, but not this big

Password leaks are nothing new. Yahoo in 2013 and 2014. LinkedIn in 2012 (and again in late 2024, although that one involved lots of sensitive data, it did not have passwords). Often breaches such as these contain millions of records. It’s unusual for them to contain billions of usernames and passwords. A group at Cybernews stated that they have uncovered 30 separate leaked credential datasets, totaling 16 billion separate records. That’s 2 records for every person on the planet. The number of those usernames/passwords that are still active (working) is anyone’s guess, but it underscores just how many breaches have taken place against some of the largest on-line companies in the world. 

This breach is so large that coming up with a definitive answer on what we should do as individuals is challenging. Some are pushing hard to move away from passwords to passkeys. Some are recommending that users change all passwords just in case they are involved in a breach. I just checked in my password keeper, and I have literally over several hundred separate accounts in there. Changing them all would likely be a long weekend’s worth of work, and few people are likely to do that.

Takeaway: So what do we do? First, be absolutely sure that you have Multi-Factor Authentication (MFA) on all accounts that matter to you. Email accounts first, banking/healthcare second, social media third, and everything else after that. Second, a password keeper is extremely important, as there is no other way to have separate passwords for every account that you have.

P.S. I really wonder how the website haveibeenpwned.com is going to handle this influx of data. I’m waiting for the alerts to hit inboxes soon.


DoorDash driver finds a way to con the system out of $2.5 million

In another great example of a system being used in a way it was not intended to (see the TCE Strategy April newsletter about the Maryland school teacher that was paid for 73,000 days of work instead of 3), a Northern California Doordash driver concocted a scheme where he manipulated the DoorDash technology system to his own benefit. To quote the article, “The driver, Sayee Chaitainya Reddy Devagiri, placed expensive orders from a fraudulent customer account in the DoorDash app. Then, using DoorDash employee credentials, he manually assigned the orders to driver accounts he and the others involved had created. Devagiri would then mark the undelivered orders as complete and prompt DoorDash’s system to pay the driver accounts. Then he’d switch those same orders back to ‘in process’ and do it all over again. Doing this ‘took less than five minutes, and was repeated hundreds of times for many of the orders,’ writes the US Attorney’s Office.” There are two things that surprise me about this: First, I’m surprised that it took this long for someone to figure out this hole in DoorDash’s system. Second, I’m surprised that the DoorDash driver, Sayee Chaitainya Reddy Devagiri, didn’t try to use much smaller amounts and fly under the radar. Over $2 million in fraud is extremely likely to get noticed. 

Takeaway: If you are designing a computer system, making it “work” isn’t good enough. The system needs to know how to look for very unlikely situations and either reject them outright, or at a minimum flag them for review.


Windows “Recall” feature is recalling a bit too much, so Signal is choosing to block it.

Microsoft has been trying to launch a new piece of functionality (considered a “feature” by some and a “glaring bug” by others) called Recall, where pictures of the user’s screen are taken every 3 seconds and saved to the hard drive on the computer in question. That means that every time there is a password on your screen, a sensitive document, a bank account balance, or a health care record, those images are being stored.  There has been a lot already circulating about this, and there have even been ethical hackers making proofs-of-concept where a command-line tool can extract the data in Recall on Windows 11 (aptly named TotalRecall, which I find hilarious).

Some app developers are not happy with Recall and its ability to circumvent the security/privacy that they have worked hard to put into their applications. However, Microsoft has not provided a way for applications to opt-out of Recall snapshots, and since USA security/privacy laws are weak, there isn’t a legal incentive for them to do so. That didn’t sit well with some app developers, especially ones that are writing security/privacy application. In particular, Signal went to great lengths to figure out how to circumvent Recall, and they found a creative way to do so: copyright laws. Microsoft provides an API (Application Programming Interface) for protecting copyrighted material, as copyright laws in the USA are quite strong (if rarely enforced). Application developers can turn on this API to prevent Windows from taking screenshots of copyrighted content displayed in a given application. Signal has chosen to use that API to give their users an extra layer of privacy.

Takeaway: Some companies are security/privacy centric and others aren’t. Choose wisely which companies you support.


When your toothbrush confesses your adultery

We buy a lot of “smart” things nowadays. Furnaces. Washer/dryers. Weight scales. Water softeners. Toothbrushes. Well, it turns out that “smart” devices know a lot about you, such as every time you use them. In a hilarious tale from the UK, a wife suspected that her husband was having an affair, so she hired a private investigator to see if her suspicions were correct. After much investigation, he finally caught a break in the case: The husband was using a smart toothbrush, and he was brushing his teeth late morning on Fridays when he was supposed to be at work. It turns out that he had not been working on Fridays for several weeks, and was instead having an affair at home when he knew he would have the house to himself. Clean teeth revealed a dirty conscience.

Takeaway: Understand the surveillance state that we all live in. Try to have as few interactions as possible that you wouldn’t be comfortable telling your parents, spouse or close friend about. It used to be your cheating heart would tell on you, but now it’s your oral hygiene.


Until next month, stay safe!

Upcoming Speaking Events


Here is a list of the cities that I will be in over the next several months. Please reach out if you have an event in mind!


July 3, Brainerd, MN

July 9-21, Dublin, Ireland

July 22-24, Orlando, FL

July 25-30, Phoenix, AZ

August 24-27, Indianapolis, IN

October 7-9, Trenton, NJ

October 21-23, Lansing, MI

October 29-30, Worcester, MA

December 1-5, Key West, FL

December 22-26, Ft. Myers, FL

TCE Strategy in the News

Thank you to Ian Russell, KARE 11 and NBC for the opportunity to partner on a story about new text scams claiming to be from the Department of Motor Vehicles.

Interesting Articles

I think there is positive intent here, but is it enforceable? Could it be used for censorship instead of citizens' safety? "Under the law, anyone who distributes intimate images of someone without their consent faces federal criminal penalties. The law mandates that social media companies promptly remove such content when alerted, and empowers the Federal Trade Commission to enforce it."
Be careful what you put on your home network. "In a Public Service Announcement (PSA), the law enforcement agency claimed that threat actors either install malware to the devices prior to purchase, or via 'required applications' containing backdoors that must be downloaded during setup. It said that affected devices, made mainly in China, include TV streaming devices, digital projectors, aftermarket vehicle infotainment systems, digital picture frames and other products."
Cybersecurity Tip of the Month
 

Staying Cyber-Safe on Social Media This Summer

Summer is a time for travel, outdoor events, and new adventures, but it’s also a time to stay mindful about what you’re sharing online. When you post updates, photos, and plans on social media, you might be giving away more information than you intend, putting yourself, your home, and your belongings at risk. Here are some ways to keep your summer safe and secure:

  1. Hold off on posting. Try not to share travel details or photos while you’re still away from home, even if you’re just at a local event. Posting in real-time can tip off the wrong people that your home is unoccupied. Waiting until you’re back adds an extra layer of safety.

  2. Skip geotagging. Many social media platforms prompt you to share your location when you post. It’s a good habit to decline. You can also disable location services on your devices to reduce the chances of unintentionally sharing where you are.

  3. Review your privacy settings. Double-check who can see your posts and profile details. Most platforms let you choose audiences like “Friends,” “Only Me,” or “Custom.” Consider approving tags or posts from others before they show up on your timeline.

  4. Keep your home’s location private. Even if you wouldn’t post your address, photos of your house or neighborhood can sometimes reveal house numbers, street names, or other unique identifiers. Be thoughtful about what’s in the background of your pictures.

  5. Take a social break. Unplug when you can and enjoy being in the moment. Stepping back from social media now and then not only gives you a mental break but also limits your exposure to cybercriminals who monitor online activity.

LinkedIn
Twitter
Facebook
Website
Forward Forward
We want your feedback!

< On a scale of 10, how helpful was this newsletter?>

lowest 1   2   3   4   5   6   7   8   9   10   highest

Copyright © 2025 TCE Strategy, All rights reserved.
You are receiving this email because you are on Bryce Austin's contact list

Our mailing address is:
TCE Strategy
18268 Java Trl
Lakeville, MN 55044

Add us to your address book


Want to change how you receive these emails?
You can update your preferences or unsubscribe from this list

You can reach Bryce at bryce@bryceaustin.com

Email Marketing Powered by Mailchimp
Subscribe to Newsletter

Browse newsletter archives: