
Bite Sized Cyber Crime
120 episodes — Page 3 of 3
Ep 127GPO Used to Steal Credentials from Chrome Browser
Using native Windows tools rather than custom malware is becoming a better technique of pulling off attacks while remaining under the radar. Qilin was caught doing just this to steal credentials right from the Chrome web browser. Sources: https://pastebin.com/Ccvhs7Pd
Ep 126Malware That Uses a Driver to Kill EDR Software
Antimalware solutions like EDR are meant to keep a careful watch on our systems to ensure they are protected from even sneaky threats. But what happens when malware can take out an EDR solution before it is spotted? Sources: https://pastebin.com/6uRVy4Yd
Ep 1253 Billion Impacted in Background Check Company Breach
Often times we can reduce our risk to cyber crime by being careful about the websites we sign up for, but what if someone has our data that we never consented to giving them and ends up being breached? Just that happened, with a company you've probably never heard of. Sources: https://pastebin.com/Yms285F5
Ep 124Dark Angels Recieved the Biggest Ever Ransomware Payout
Ransomware threat actors are one of the biggest modern threats, and things will only ramp up when threat actors see just how much an organization is willing to pay to have their data back. Recently it was uncovered that a covert ransomware group quietly received the largest payout ever recorded in ransomware history. Sources: https://pastebin.com/uLQ9sFh0
Ep 123KnowBe4 Accidentally Hired a North Korean Hacker
KnowBe4 has employed hacker Kevin Mitnick as a spokesperson in their security training materials. But what happens when you employ a hacker by accident and they immediately try loading malware on the company provided laptop? Sources: https://pastebin.com/XrMa4bsS
Ep 122How CrowdStrike Broke the Internet
The biggest IT outage across the world just happened. Planes were grounded, hospitals and 911 dispatch centers were down, people couldn't turn their computers on, all on a massive global scale never seen before. So what is CrowdStrike, and how did this happen? Sources: https://pastebin.com/vxfyMcd4
Ep 121Multiple Data Breaches Linked to Snowflake Cloud Provider
Ticketmaster, AT&T, Neiman Marcus, Advanced Auto Parts. These organizations may not seem like they have anything in common, but they all were customers of Snowflake that had a data breach within the past couple months. With conflicting reports from Snowflake, the victims, the threat actors, and different security firms, who is really at fault here? Sources: https://pastebin.com/E1H5rgkd
Ep 12033 Million Authy User Phone Numbers Breached
Authy is an app that allows for multifactor authentication, recently the phone numbers of 33 million Authy customers were leaked due to an unsecured API, which could lead to attacks on those users. Sources: https://pastebin.com/qLsuL1Qb
Ep 119LockBit Lies About Hacking US Federal Reserve
After Lockbit was taken down in a multinational effort, they appear to still be a major threat after hacking the US Federal Reserve. Or did they? And why lie about such a major attack? Sources: https://pastebin.com/y8aYFSZv
Ep 118US Govt Bans Kaspersky Antivirus
Geopolitical tensions are a major factor in cyber crime as our lives become more and more online, due to concerns about Kaspersky antivirus being based in Russia, the US government has banned sales of the product, any new business agreements with Kaspersky and US orgs, and has barred them from sending software updates to Kaspersky AV users. But why ban an antivirus product at all? Sources: https://pastebin.com/DHzqYVhB
Ep 117Creeper and Reaper: The First Virus and Antivirus
Have you ever wondered what the first malware ever was? It was more like an experiment rather than a malicious tool of destruction that malware has become today. Although Creeper didn't do much damage it's interesting to reflect on how far malware has come. Sources: https://pastebin.com/68f9yTu1
Ep 116Microsoft Address Recall AI Security Concern
Microsoft introduced an upcoming AI tool that is able to remember everything you did on your PC and fetch results if you need to go back in time and remember. However with this tool came a mountain of distrust and security concerns. These are the concerns and how Microsoft addressed them. Sources: https://pastebin.com/QGdtx4Np
Ep 115Ticketmaster Breach Impacts Half a Billion Users
If you go to concerts or live shows sometimes like I do you've likely used Ticketmaster, as it has a strangehold over the industry. The morning after I saw a concert I woke up, checked Twitter, and saw that Ticketmaster had a massive data breach. This is what happened. Sources https://pastebin.com/8dSztCJg
Ep 114This Podcast is Not Sponsored by BetterHelp
After COVID-19 hit, telehealth businesses started booming and BetterHelp became especially prominent via YouTube and podcast sponsorships. However BetterHelp has been criticized for their data sharing practices, and the gray area they are in when it comes to regulations. Sources: https://pastebin.com/8fxw3sQy
Ep 113$25 Million in Ethereum Stolen from Trading Bots
Ethereum is a popular cryptocurrency, and some have started using bots to frontrun. Two brothers learned how they could exploit a vulnerability in these bots and make themselves $25 million richer. Sources: https://pastebin.com/xuQZ1ard
Ep 112Dell Breach Exposed Data of 49 Million Customers
Dell is a massive provider of technology for organizations and home users alike, and although on first glance their data breach seems not to contain sensitive data it has likely opened the floodgates for scams and phishing opportunities. Sources: https://pastebin.com/6jSYQM4P
Ep 111Fake USPS Sites Get Almost the Same Traffic as the Real One
With online shopping being so popular, getting delivery updates is not so uncommon, but this has led to the rise of a prolific scam that is much bigger than you may think. Sources: https://pastebin.com/mW6kWtWx
Ep 104Cloudbleed and the Vitality of Cloud Security
The cloud is ever expanding and allowing people to easily scale up at rates previously impossible. However one thing that must be considered is that security becomes complicated. You have to really trust your cloud provider to hold up their end, and even trusted providers can have oversights. Sources: https://pastebin.com/2LJPjrVx