
These Cyberattacks Keeps Getting Crazier...
Source: YouTube · SomeOrdinaryGamers · published Jul 23, 2025 · 17:04
The video reports on a breach of the US National Nuclear Security Administration (NNSA) via a Microsoft SharePoint vulnerability, clarifying that no classified nuclear data was compromised due to strict security protocols like air-gapping 0:00.
Key Takeaways:
• The attack was part of a larger campaign affecting approximately 400 institutions globally, exploiting a zero-day vulnerability (CVE-2025-3770) in on-premises SharePoint servers to execute remote code 4:00 8:03.
• Microsoft attributes the early exploitation to a "Chinese nexus" threat actor, highlighting the role of state-sponsored cyber warfare which often faces no repercussions 4:35.
• Despite the breach, nuclear weapons remain secure because they are air-gapped from the internet, rely on legacy systems, and utilize physical failsafes like Permissive Action Links 2:38.
• The exploit involves sending a malicious POST request with a spoofed referer header to bypass authentication and trigger deserialization of untrusted data 10:42.
• The incident raises alarms about the vulnerability of critical infrastructure, such as power grids and hospitals, to state-sponsored attacks that could cost human lives 14:50.
While the nuclear stockpile is safe, this event underscores the urgent need for improved cybersecurity in other critical sectors and potentially international regulations to govern cyber warfare.
Sources:
- 0:00 Intro to NNSA breach context
- 2:38 Explanation of air-gapping and legacy systems
- 4:00(https://www.youtube.com/w
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Yeah, the title is not clickbait here, ladies and gentlemen. Yes, the US nuclear weapons agency did in fact get breached. Now, you know, I love talking about computer cyber security. I love talking about crazy hacks, especially when things are out of our control because uh sometimes all you can do in this crazy world is sort of laugh. Okay? And uh that's really all you're able to do right now, ladies and gentlemen. So, for anybody that doesn't know what's been going on, this is the United States Department of Energy. And underneath the Department of Energy is again the National Nuclear Security Administration, the NNSA. Now, what is the job of the NNSA? Their core missions, meaning this is literally what they're made for, is to ensure the United States maintains a safe, secure, and reliabl…