May 2025 News & Tips | Cybersecurity News Review

May 2025 News & Tips | Cybersecurity News Review
View this email in your browser
The mission of this publication is to cut through the clutter of cybersecurity news stories and provide you with the most important, relevant and actionable cybersecurity information.

If this newsletter adds value, fantastic! That is the goal. Please forward it on to friends/colleagues. If not, no hard feelings. Please look to the bottom for an easy to click "unsubscribe" button.
Subscribe
In this issue:
Month's News in Review
Upcoming Speaking Events
TCE Strategy in the News
Must Read Articles This Month
Cybersecurity Tip of the Month
Enjoy this month's newsletter? You can use this link to post on social media or send to friends! Thanks for sharing!
This Month's News in Review

Welcome back to the monthly TCE Strategy newsletter! From A.I. lies to USB ports infecting your phone to 20 arrest warrants for a huge ransomware gang, May has not disappointed to keep the cybersecurity world on its toes. Let’s see how this month’s cybersecurity news can help us make better decisions about what is Secure Enough for us, the companies we work for, and our families.


Airports and USB chargers

The irony is not lost on me that as I type this from a lounge in the Las Vegas International airport, there are literally 50 USB charging ports within 100 feet of me. It has long been known that USB ports can be specially programmed to try to steal data from your phone or to infect it with a virus, to the point where some cybersecurity companies offer “data diodes” as giveaways at conferences that go in between your phone and a charger. The “data diode” allows your battery to charge, but no data to be transferred. I’d always considered this to be an unusual threat, so while I do not use USB chargers in airports, I haven’t recommended to my clients that they steer clear of them. Turns out I was wrong. The TSA has sent out a formal warning against using USB chargers in airports, as well as avoiding airport Wi-Fi systems. This is an interesting alert, as there are literally billions of dollars of infrastructure for those technologies in airports around the globe, but apparently the budget to ensure the security of those devices is an opportunity for improvement. The TSA did not elaborate on what triggered this alert, nor the number of incidents that they are aware of, but that is common in the world of cybersecurity alerts, regrettably.

Takeaway: If the TSA is sending out warnings about USB ports and airport public Wi-Fi systems, they likely know something that we don’t about the frequency of these attacks. Use a “data diode” or a portable battery to charge your smart phones and tablets. Use your phone as a Wi-Fi hotspot instead of connecting via a public Wi-Fi system. Stay vigilant.


AI lies and concerns, part 1:

AI “hallucinations” are a well-known (although not well understood) phenomena. I’ve had it happen several times myself: I ask ChatGPT a question. It gives me an answer. I tell it to cite 3 sources that support its answer. It ignores my request and doubles down on the answer it originally gave. I demand that I need 3 sources supporting that answer or I will consider this answer to be invalid. ChatGPT then reverses course and takes back everything it said and includes sources that contradict its original answer. This is a hallucination, and they happen with enough frequency that EVERYTHING you hear from an AI engine should be taken with a grain of salt, exactly the way that this news reporter didn’t. This was a pretty innocent mistake, in that this was concerning a summer reading list that was published in the Sunday's Chicago Sun-Times and The Philadelphia Inquirer. Some of the books on the list simply didn’t exist – they were a figment of an AI bot’s imagination. Regrettably, some AI mistakes are much more serious. I’ve had AI tell me that a certain cybersecurity attack vector is a very real issue and needs to be remediated, when in reality, there is no such attack vector. It just invented links in an attack chain that never existed.

Takeaway: AI does a lot of things well and is very useful, but it’s like a 4-year-old child: it doesn’t really understand the world that it lives in yet. Do not take AI answers as facts. Think of them as mild suggestions. That being said, I have had AI give me some terrific food recipes, so I trust it more in the kitchen than I do in my office. :-)


AI lies and hallucinations, part 2:

To continue on the 4-year-old analogy, AI engines are ingesting new data all the time to try to give better answers going forward, and this training often goes on without any awareness for the users, nor the millions of websites being scanned by AI. In fact, the website issue has become so significant that Cloudflare has introduced a new feature of their Website Application Firewall (WAF) that is specifically designed to fight this type of unauthorized scanning. They are also proposing that AI bots be required to authenticate themselves to websites before being allowed to scan them. The problem here is twofold: first, websites can publish anything the author wants to. There is no fact checking or “source of truth” on most Internet sites. Therefore, AI bots are certain to fall victim to the “garbage in, garbage out” computer issue that has existed for decades. Second, the data that we type into AI engines is being analyzed by the AI engine to turn its answers for future responses, often without our knowledge or consent. The privacy and cybersecurity implications here are huge (thank you Robert Whelan for sending me this article). CISA has released guidance on how to secure data used to train AI systems, so best practices in this area are available.

Takeaway: Don’t type anything into an AI engine that you wouldn’t openly tell your friends, family, or even complete strangers. Think of AI as an untrusted stranger, and be careful what you tell it.


Cybersecurity as a war machine disruptor

It was common in WWII to attack the supply lines of your enemy as opposed to your enemy directly, as without food, ammunition, weapons, etc., their ability to fight is greatly diminished. This playbook has not changed, although the methods used to implement it are vastly different in the Internet age. US Intelligence has announced that Russia is targeting private companies that are involved in supplying Ukraine’s war effort with cyberattacks. This isn’t a new tactic, as the “Sunburst” Solarwinds Orion breach from a few years ago so famously demonstrated, but the scope of this appears to be far more widespread.

Takeaway: Cybersecurity is about measuring and mitigating risk. For any company that is even peripherally involved in the Ukraine war effort, consider yourself on the cybersecurity front lines of a war zone. According to the USA, UK, and Australian governments, you are.


Finally, some good news!

Supply chain attacks can cut both ways: In an impressively coordinated takedown, a Europol cybercrime policing effort called “Operation Endgame” took down 300 servers and 650 website domains that were being used as part of ransomware attacks, along with issuing arrest warrants for 20 individuals. Almost $4 million in cryptocurrency was also recovered. While those numbers represent a drop in the bucket to cybercrime activities overall, every bit helps. Congratulations to the Europol team that made this a reality.


Until next month, stay safe!

Upcoming Speaking Events

Here is a list of the cities that I will be in over the next several months. Please reach out if you have an event in mind!


June 3-6, Victoria, BC, Canada

July 3, Brainerd, MN

July 9-21, Dublin, Ireland

July 22-24, Orlando, FL

July 25-30, Phoenix, AZ

August 24-27, Indianapolis, IN

October 7-9, Trenton, NJ

October 21-23, Lansing, MI

October 29-30, Worcester, MA

December 1-5, Key West, FL

December 22-26, Ft. Myers, FL

TCE Strategy in the News

Thank you to Gordon Severson, KARE 11 and NBC for the opportunity to partner on a story about a $2.4 million dollar cryptocurrency heist in Anoka County, Minnesota.


Thank you to Maartje van Krieken for the opportunity to be on her podcast, The Business Emergency Room, to talk about cybersecurity for small businesses.

Interesting Articles

"This is a perilous moment. Rapid technological advances over the past two decades have made data shedding ubiquitous—whether it comes from the devices everyone carries or the platforms we use to communicate with the world. As a society, we produce unfathomable quantities of information, and that information is easier to collect than ever before."
The company was charged with a crime because they refused to log the people using their VPN. They were acquitted. Huge win for privacy advocates everywhere, genuine concern for those in favor of mandatory customer policing.
Cybersecurity Tip of the Month


      Lock Screen Smarts: Simple Steps for Better Security


Back in the office more often? Taking your laptop to the local coffee shop or enjoying the spring air while working outside? No matter where you are, securing your devices when you step away is essential. One of the easiest and most effective habits you can build is locking your screen—every time you walk away. Both Windows and Mac offer quick shortcuts to do this, and it only takes a second to protect sensitive information.

Windows: Use Windows + L to instantly lock your screen, or press Ctrl + Alt + Del and select “Lock”. For added protection, enable facial recognition (if available), set a strong password or 6-digit PIN, and configure your system to auto-lock after a short period of inactivity. Some devices even support automatic locking when you step away—check your settings.

Mac: Make sure your Mac is set to require a password immediately after sleep or screensaver starts. Lock your screen quickly with Ctrl + Cmd + Q (be careful not to press Cmd + Q as this will shut down the application you are using which could be a problem if you have unsaved work), or go to the Apple menu > Lock Screen. Strengthen your device’s security by using Touch ID or Face ID, a secure password or PIN, and enabling auto-lock.

iPhone/iPad: Press the side or top button to lock your screen. Enable Face ID or Touch ID, use a strong passcode, and check that auto-lock is set to trigger after a short period of inactivity.
 

Locking your screen is a small step with big security benefits. Make it a habit wherever you work!

LinkedIn
Twitter
Facebook
Website
Forward Forward
We want your feedback!

< On a scale of 10, how helpful was this newsletter?>

lowest 1   2   3   4   5   6   7   8   9   10   highest

Copyright © 2025 TCE Strategy, All rights reserved.
You are receiving this email because you are on Bryce Austin's contact list

Our mailing address is:
TCE Strategy
18268 Java Trl
Lakeville, MN 55044

Add us to your address book


Want to change how you receive these emails?
You can update your preferences or unsubscribe from this list

You can reach Bryce at bryce@bryceaustin.com

Email Marketing Powered by Mailchimp
Subscribe to Newsletter

Browse newsletter archives: