# 🔴 CYBERSECURITY NEWS HUNTING with @endingwithali

Source: https://www.youtube.com/watch?v=Wv4114aVJl8
Recap page: https://rapidrecap.app/video/Wv4114aVJl8
Generated: 2025-07-23T02:08:30.731+00:00

---
## Quick Overview

During a live cybersecurity news hunting session, host Allie and viewers created a July 2025 cybersecurity bingo board featuring predictions like a major US infrastructure cyber attack and a quantum computing breakthrough, while also discussing recent vulnerabilities including Microsoft's direct send email spoofing flaw, the new Citrix Bleed 2, and unpatchable vulnerabilities in Brother printers.

**Key Points:**
- Host Allie and viewers collaboratively created a July 2025 cybersecurity bingo board, predicting events such as a 'major US infrastructure cyber attack,' 'quantum computing breakthrough,' and 'Defcon drama.'
- A novel phishing campaign exploited Microsoft's 'direct send' feature, allowing unauthenticated email spoofing from internal devices like printers, targeting over 70 predominantly US-based organizations since May 2025.
- New vulnerabilities, dubbed 'Citrix Bleed 2' (CVE 2025 5349 and CVE 2025 5777), affect Citrix NetScaler ADC and Gateway products, enabling attackers to steal tokens and bypass MFA via out-of-bounds memory reads.
- Brother multifunction printers contain eight vulnerabilities, including CVE 2024 5197, which allows remote unauthenticated attackers to leak serial numbers and generate default passwords, with some flaws requiring manufacturing process changes for full remediation.
- A Google Chrome API allows browsers to permanently set the global microphone volume without user notification, with no easy way to disable it beyond hidden flags.
- The bingo board also includes more speculative predictions like 'US accidentally hires a North Korean IT worker' and 'PewDiePie drops new open-source propaganda.'

**Context:** During a live streaming session titled "Cybersecurity News Hunting," host Allie engages with her audience to create a monthly "bingo board" of cybersecurity predictions, a recurring segment. She then transitions to reviewing recent cybersecurity news, focusing on specific vulnerabilities and exploits that have emerged.

## Detailed Analysis

The video captures a live cybersecurity news hunting session where host Allie engages with her audience to collaboratively build a July 2025 cybersecurity bingo board, a recurring segment where specific predictions are made for the upcoming month. Past bingo boards included items like "branded vulnerabilities" and "AI company gets funding." For July, predictions range from a "major US infrastructure cyber attack" and a "quantum computing breakthrough" to more speculative items like "Defcon drama" and "US accidentally hires a North Korean IT worker." Following the bingo board creation, Allie reviews recent cybersecurity news. She highlights a significant Microsoft "direct send" vulnerability that allows unauthenticated email spoofing, which threat actors have exploited in a novel phishing campaign targeting over 70 predominantly US-based organizations since May 2025. The discussion also covers "Citrix Bleed 2," a new set of vulnerabilities (CVE 2025 5349 and CVE 2025 5777) affecting Citrix NetScaler ADC and Gateway products, which enable attackers to steal tokens and bypass MFA through out-of-bounds memory reads, drawing parallels to the original Citrix Bleed. Additionally, Allie examines eight vulnerabilities found in Brother multifunction printers, including CVE 2024 5197, which allows remote unauthenticated attackers to leak serial numbers and generate default passwords, noting that some of these flaws require manufacturing process changes for full remediation rather than just firmware updates. Other brief mentions include a Google Chrome API that allows permanent global microphone volume control without user notification and the general nature of common cybersecurity news.

### July 2025 Cybersecurity Bingo Board

- The host and live chat collaboratively brainstormed predictions for the monthly bingo board, a game where specific cybersecurity events are crossed off if they occur
- Past bingo boards included items like 'branded vulnerabilities' and 'AI company gets funding'
- Key predictions for July include 'major US infrastructure cyber attack,' 'quantum computing breakthrough,' 'streaming service data breach,' 'new DDoS record set by Cloudflare,' 'Defcon drama,' 'US accidentally hires a North Korean IT worker,' 'major iOS 26 vulnerability found,' and 'PewDiePie drops new open-source propaganda'

### Microsoft Direct Send Vulnerability

- A novel phishing campaign, active since May 2025, exploited Microsoft 365's 'direct send' feature to spoof internal users and deliver phishing emails without authentication
- This vulnerability allowed attackers to send emails appearing to originate from inside an organization by using publicly available smart host addresses and internal recipient formats
- The campaign targeted over 70 predominantly US-based organizations, leveraging the lack of authentication required for direct send

### Citrix Bleed 2 Vulnerabilities

- New vulnerabilities, CVE 2025 5349 and CVE 2025 5777, affect Citrix NetScaler ADC and Gateway products, dubbed 'Citrix Bleed 2' due to their similarity to the original Citrix Bleed
- These flaws work by using out-of-bounds memory reads to steal tokens and extract authentication data, enabling MFA bypass and user session hijacking
- Citrix publicly disclosed these on June 17, 2025, though researchers at Valia Quest reported active exploitation despite Citrix's initial assessment

### Brother Printer Vulnerabilities

- Eight vulnerabilities were discovered in Brother multifunction printers, including CVE 2024 5197, which allows remote unauthenticated attackers to leak serial numbers and generate default passwords
- Some of these flaws, like the default password generation, cannot be fully remediated via firmware updates and require changes in the manufacturing process for affected models
- The host questioned the practical impact of these vulnerabilities, noting the ability to use printers as network jumping points or for PII scanning would be more concerning

### Other Cybersecurity News Mentions

- The discussion briefly touched on a Google Chrome API that allows the browser to permanently set the global microphone volume without user notification or easy disablement
- The host also dismissed an NSA CISA report on memory-safe languages as 'boring' and 'old news'
- Other potential news topics like 'Scattered Spider going after airlines' and 'Bluetooth flaws' were briefly considered but not deeply explored

