PLAY PODCASTS
Bite Sized Cyber Crime

Bite Sized Cyber Crime

120 episodes — Page 2 of 3

Ep 177Former Dev Gets 4 Years for Sabotaging Workplace

Everyone may get elaborate revenge fantasies but few follow through due to the bad outweighing the satisfaction. One man, sensing he was to be terminated soon, however, decided if he were to go he would try to take the whole company down with him. Last week he was sentenced to 4 years in prison. Sources: https://pastebin.com/Pi0YSFUt

Aug 25, 20256 min

Ep 176Hydroelectric Dam in Norwary Hacked

Water and energy are both critical resources to society. In a display of fear, pro-Russia hacktivists compromised a dam in Norway remotely, demonstrating that cyberattacks can have very physical implications. Sources: https://pastebin.com/mwwrPwtR

Aug 18, 20256 min

Ep 175UK To Ban Public Sector from Paying Ransomware

The UK recently proposed the banning of public sector organizations from paying ransomware ransoms, in an effort to discourage cybercriminals from targeting them. How may this end up working out though? Sources: https://pastebin.com/37jGGd9X

Aug 11, 20257 min

Ep 174CISA Opens Thorium Tool to Public

CISA has developed many interesting and powerful tools over the year for cybersecurity, but recently they made one of malware analysis and automation open source and available for the public to use. Thorium. Let's talk about what this tool can do. Sources: https://pastebin.com/zhmAvguE

Aug 4, 20256 min

Ep 173Inside a North Korean Laptop Farm Scheme

An Arizona woman was arrested for running a North Korean IT worker laptop farm out of her home, and this gave us a little look into the strange world of how these threat actors are able to infiltrate US organizations. Sources: https://pastebin.com/qvrWirYa

Jul 28, 20255 min

Ep 172New FIDO MFA Downgrade Attack Exploited

FIDO is the passwordless authentication set of protocols of the future, however that doesn't mean it's perfect and as cyber defenders attack, so do attackers. This novel exploit isn't a flaw within FIDO exploit but does threaten improperly implemented versions of it. Sources: https://pastebin.com/fmUZEBAM

Jul 21, 20256 min

Ep 171PerfektBlue Vulnerabilities Impacts Vehicle Bluetooth

With cars becoming just another type of computer, and having rather complicated implementations, vulnerabilities in one system are major. A recent series of vulnerabilities discovered in OpenSynergy's BlueSDK could prove dangerous. Sources: https://pastebin.com/5JHAyuAV

Jul 14, 20256 min

Ep 170Ransomware Negociator Received Payments from Ransomware Groups

Ransomware negotiators may be called in to save some financial burden on organizations suffering from one of the worst cyberattacks they can. However, they seem like the natural people for ransomware groups to corrupt, and allegedly one such group did corrupt one such person. Sources: https://pastebin.com/fANnhtTj

Jul 7, 20257 min

Ep 169Brother Printers Affected by Unpatchable Critical Vulnerability

Printers are the bane of many's existence, but they may have just gotten worse for security professionals. Rapid7 discovered 8 new vulnerabilities mostly impacting Brother branded printers, one of which cannot be patched by the vendor and leaks the admin password of the device. Sources: https://pastebin.com/vNDbrwsU

Jun 30, 20256 min

Ep 168Were 16 Billion Passwords Just Leaked?

News has hit the mainstream media that all your passwords have been leaked yet again, in a massive password leak including Google, Meta, and Apple. But how much of that sensationalized story is true? Sources: https://pastebin.com/Xi1MPpFg

Jun 23, 20257 min

Ep 167I Got Scammed

And it could happen to you too. On this week's episode of Bite Size Cyber Crime I detail an actual scam I fell for and emphasize that anyone can be a victim of a scam anywhere on the internet.

Jun 16, 20257 min

Ep 166Malwareception: SakuraRAT is a Backdoor to Trick Script Kiddies

Malware is everywhere, even inside of other malware. One tool advertising itself as an advanced remote access trojan ended up being much more, a backdoor infecting novice hackers. This was not just a one off, however, and lead to the discovery of a massive backdoored malware campaign infecting other hackers and gaming cheaters. Sources: https://pastebin.com/C4DG6LTw

Jun 9, 20256 min

Ep 165MSP Customers Face Ransomware after Remote Assist Tool Compromised

Using an MSP can be handy for getting your IT set up or managing technical support without hiring a lot of full time staff, but there are risks that can come with outsourcing your IT to a third party. One MSP was compromised, leading to many customers having ransomware headaches. Sources: https://pastebin.com/hLKSqRaS

Jun 2, 20256 min

Ep 164Malware Spread via fake TikTok Piracy Tutorials

Piracy and accidentally getting malware go hand in hand for many, and though the days of Limewire viruses on your Linkin Park albums are mostly over, modern problems require modern solutions so attackers have moved to modern platforms to spread malware to those not interested in paying for software. Sources: https://pastebin.com/i7yriZXy

May 26, 20256 min

Ep 163Coinbase Insiders Bribed to Hand Over Data to Scammers

Coinbase is one of the largest crypto exchanges, but when corrupt employees are compromised into handing over data to scammers, a series of social engineering attacks took place. The scammers demanded a ransom, but Coinbase fired back. Sources: https://pastebin.com/dTZR6hKw

May 19, 20256 min

Ep 162Pearson Breached Via Exposed GitLab Token

Pearson is an education giant, providing learning tools and standardized assessments across many fields, schools, and organizations. Recently they were breached by what was likely a series of relatively minor mistakes. Sources: https://pastebin.com/YemUE0Xi

May 12, 20255 min

Ep 161Security Firm CEO Installs Malware on Hospital Computer

This is one of the craziest stories I've ever covered in my 3 years of this podcast, and hearing both sides somehow makes the situation even less clear. Cybersecurity firm CEO Jeff Bowie accessed hospital computers and wrote malicious scripts on them intended to steal data. But why? Sources: https://pastebin.com/qqLMem11

May 5, 20259 min

Ep 160SuperCardX Steals Payment Data via NFC

NFC has allowed for payments to be easier than ever, but it was only a matter of time before this method was exploited by threat actors. A bold, new real time malware that leverages NFC has been making rounds. Sources: https://pastebin.com/QgquMLj8

Apr 28, 20256 min

Ep 159What's Going on With CVE?

The CVE program is essential for tracking vulnerabilities all across the technology industry, but what happens when funding is cut? Let's talk about what's been going on with the CVE program. Sources: https://pastebin.com/QPVXe6kD

Apr 21, 20256 min

Ep 158USB Drive Drops Infostealer Malware on Military Devices

You're always told to never plug in a random flash drive because it may have malware on it, but is that really a thing? The answer is yes, and it can potentially compromise a military mission. Sources: https://pastebin.com/LURNpcH5

Apr 14, 20256 min

Ep 157Tax Season and Scams

Tax season is a stressful time for many in the US, and this creates the perfect opportunity for a number of scams against virtually anyone living in the US. Be aware of fake documents, fake filing services, and unusual emails. Sources: https://pastebin.com/zJQGMndk

Apr 7, 20256 min

Ep 156Oracle Denies Data Breach, Evidence Suggests Otherwise

A hacker claimed to have stolen 6 million lines of data from Oracle, which Oracle swiftly denied. However when security firms received data samples and showed them to customers, the data was confirmed to be real. Sources: https://pastebin.com/6WnaeYZs

Mar 31, 20258 min

Ep 155Google Aquires Wiz for $32 Billion

Google, though a tech giant, has lagged behind Amazon and Microsoft when it comes to cloud computing, but this bold new acquisition could bridge that gap... or introduce legal troubles. Sources: https://pastebin.com/004Wu6hv

Mar 24, 20255 min

Ep 154X DDoSed Multiple Times

Elon Musk has become a controversial political figure, leaving little surprise that one of his projects, the X platform, became a target for a hacktivist group, leaving the major social media platform down from a DDoS attack. Sources: https://pastebin.com/Pa6b0nrm

Mar 17, 20257 min

Ep 153Ransomware Group Bypasses EDR using Webcam

Ransomware groups sometimes run into issues, like being blocked by security tools, and often have to pivot. Some techniques are less conventional than others, but are just as destructive. Here's how a webcam led to ransomware being deployed org wide. Sources: https://pastebin.com/FHxVYgBg

Mar 10, 20256 min

Ep 152Access Management Systems Exposed on Internet

Building access management is an important part of physical security that has only become more intelligent. However, with all the data on these systems that exist on employees it is important that they are properly secured. Recently, 49,000 systems were found unsecured on the open internet with data viewable, and sometimes modifiable. Sources: https://pastebin.com/8feGBvEu

Mar 3, 20257 min

Ep 151HNFS Pays $11 Million Settlement for False Security Certifications

Government contractors are expected to follow certain compliance policies, so what happens when a company lies about compliance? Hefty fines tend to follow. Sources: https://pastebin.com/vJPEikD9

Feb 24, 20259 min

Ep 150Serial SWATter Sentenced to 4 Years in Prison

SWATting is a dangerous crime that involves making extreme police reports against people to illicit a response from the SWAT team. This has resulted in innocent people being killed or injured. One teen turned making these reports into a business and was recently sentenced to 4 years in prison for it. Learn about his crimes and methodology today. Sources: https://pastebin.com/ET9xMi85

Feb 17, 20258 min

Ep 149Crypto Stealer Searches Gallery for Wallet Passphrases

Recently a new crypto stealing malware was found in apps on both the Google Play, and the famously restrictive Apple App Store, but it seems not to be its own app, but rather something inserted into existing apps at a later time to steal passphrases for crypto wallets from images on devices. Sources: https://pastebin.com/fHgDP4fg

Feb 10, 20259 min

Ep 148What's the Deal with Deepseek?

Recently a brand new generative AI model came out of nowhere and blew up overnight. There are a lot of controversies and concerns surrounding this model, providing more efficient AI but also bringing a lot of data sensitivity risks and topics of government censorship to the forefront. Sources: https://pastebin.com/WRGERYCE

Feb 3, 202510 min

Ep 147EV Chargers Hacked in Pwn2Own Automotive

Pwn2Own by TrendMicro's Zero Day Initiative is a hacking contest where people try to hack "up to date" products to discover zero day vulnerabilities in them and win cash prizes for doing so. The automotive version of this contest not only involved cars themselves, but chargers for electric vehicles. Sources: https://pastebin.com/4siwYEYK

Jan 27, 20256 min

Ep 146Crowdstrike Phishing Email Installs Crypto Miner

Job offer scams are sadly rather common, but most of the time it's a waste of time or an identity theft scam rather than a scam that installs unauthorized crypto miners on your devices. A new scam email impersonating Crowdstrike that is targeting developers does just that. Sources: https://pastebin.com/Lpg673yh

Jan 13, 20259 min

Ep 145US Treasury Hacked in String of Chinese Nation State Cyberattacks

The US Department of Treasury was targeted in a suspected state-sponsored hack. No ransomware was deployed, though the threat actors compromised machines remotely, linked to a BeyondTrust data breach and accessed many unclassified documents. Sources: https://pastebin.com/rUi3Wdxg

Jan 6, 20257 min

Ep 144Deepfakes Used to Commit Financial Fraud

Deepfakes and AI image and video generation have become nearly indistinguishable from real people to the naked eye. This creates a problem when it comes to identity verification that involves previously very difficult to fake Face ID systems. Recently a deep web identity fraud database was being build was scraped data and images with the intention to target financial accounts. Sources: https://pastebin.com/X7acHzs9

Dec 30, 202411 min

Ep 143Ascension Notifies 5.6 Million of Breach

The healthcare industry remains one of the top targeted by hackers, and even the biggest healthcare organizations are not safe. Sources: https://pastebin.com/UgauFXsL

Dec 23, 20245 min

Ep 142The Melissa Virus

In 1999 one of the most infamous viruses was released on the world, slowing down email systems and causing chaos in the corporate world and among personal computer users. Sources: https://pastebin.com/FgE9ETKk

Dec 16, 20248 min

Ep 141FBI Advisory: Use Encrypted Channels for Texting

Telecom providers across many countries have been compromised by an APT, which means your text messages may be vulnerable if you text people with different phones, due to insecurities in text message protocols. Fortunately there's some solutions. Sources: https://pastebin.com/pMnEP6Lj

Dec 9, 20247 min

Ep 140Godot Game Engine Exploited to Distribute Malware

Game engines are used to help developers create games we love, but where code can be written, malware can be written, and one group has figured out a way to exploit the Godot game engine to discreetly package malware that often goes undetected. Sources: https://pastebin.com/5b3LcJpW

Dec 2, 20245 min

Ep 139Ford Data Sold for 2 Dollars on Hacking Forums

A hacking group boasted about breaching car manufacturer Ford's network and stealing data on 44,000 customers, selling it for 2 dollars on hacking forums for everyone to enjoy. The only problem? That data isn't exactly what they claimed. Sources: https://pastebin.com/d7r88Q7m

Nov 25, 20247 min

Ep 138Sitting Duck Attack Allows Hackers to Hijack Websites

Simple misconfiguration can often lead to disaster, and sometimes that disaster is a threat actor sneakily taking over your trusted website and using it to host malware, send phishing emails, or control botnets. Here's a surprisingly easily exploited DNS oversight that has allowed threat actors to take over 70,000 websites. Sources: https://pastebin.com/DqXL1BRb

Nov 18, 20249 min

Ep 137Ransomware Group Requests Payment in Baguettes

Ransomware groups typically request payments in the form of crypto, but newcomers Hellcat wanted to get this bread in a more literal sense. So why bread? There may be a more realistic reason than you'd think... Sources: https://pastebin.com/kAkdLJD5

Nov 11, 20247 min

Ep 136Phish N Ship Scams Infect Sites with Fake Products

There's all sorts of online shopping scams, but one of the newest ones discovered exploits legitimate eshops by creating fake product listings on other people's websites and redirecting shoppers to an attacker-controlled page that will steal credit card data. Sources: https://pastebin.com/VS9XFHRF

Nov 4, 20246 min

Ep 135What Can the Flipper Zero Actually Do?

The Flipper Zero is a notorious hacking tool used to wreak havoc on traffic lights, banks, locks, and cars. Or is it? What can the Flipper actually do, and is it really as dangerous as it seems on Tik Tok? Sources: https://pastebin.com/cnJyQkXC

Oct 28, 202410 min

Ep 134The New Guy May be a North Korean Threat Actor

A couple months ago security education company KnowBe4 accidentally hired a North Korean threat actor who tried to install malware on their machine. Turns out this may not be as uncommon as you'd think. Recently a network of North Korean threat actors applying for jobs, and US citizens helping them, has been uncovered. Sources: https://pastebin.com/1npHD8cA

Oct 21, 20246 min

Ep 133The Internet Archive is Under Attack

The Internet Archive is a website vital in the preservation of digital information, and recently it was attacked on two separate occasions. Here's what went down. Sources: https://pastebin.com/nbhNFAv5

Oct 14, 20248 min

Ep 132Pig Butchering Scams

Ever receive a weird wrong number text or match with someone on a dating site who starts talking about crypto? It may be part of a long term scam meant to drain you of as much money as you're willing to part with to make a big investment. Once it seems too good to be true and you go to withdraw your earnings, suddenly you realize you've lost it all.

Oct 7, 20247 min

Ep 131Kia Exploit Almost Allowd Remote Control Over Millions of Cars

Cars are just big computers now, and that means they are vulnerable to exploits that could allow a concerning amount of control over them. Security researchers discovered a vulnerability in the Kia dealer portal that could allow a hacker remote control over millions of cars made after 2013. Sources: https://pastebin.com/tsJGg8jq

Sep 30, 20245 min

Ep 130Was the Tor Network Just Cracked?

The Tor network allows for anonymous connections to unindexed search engines, including to online criminal services. Recently though, German authorities claimed to have de-anonymized a user using Tor and made an arrest. Has Tor finally been cracked, or is this a scare tactic to instill fear in threat actors? Sources: https://pastebin.com/Hfrrbdag

Sep 23, 20247 min

Ep 129YubiKey Vulnerability Allows for Device Cloning

YubiKeys are physical authentication devices that have a lot of flexibility and are compatible with just about every service, but as it turns out if you know a lot about math and electronics you can uncover the private keys and clone the device! Sources: https://pastebin.com/WacbUmA1

Sep 16, 20245 min

Ep 128Columbus Ohio Sues Researcher for Exposing Severity of Data Breach

The city of Columbus, Ohio had a data breach occur in July. According to the mayor, the information leaked was nothing important to hackers. A security researcher proved that this was not the case, that the data was incredibly sensitive. In response, the city sued him. Sources: https://pastebin.com/C632hthD

Sep 2, 20247 min