PLAY PODCASTS
Talkin' Bout [Infosec] News

Talkin' Bout [Infosec] News

352 episodes — Page 3 of 8

Ep 12024-08-05 - What's the f_____

00:00 - PreShow Banter™ — What’s the f___03:34 - BHIS - Talkin’ Bout [infosec] News 2024-08-0506:57 - Story # 1: Proofpoint Email Routing Flaw Exploited to Send Millions of Spoofed Phishing Emails23:57 - Story # 2: Bumble and Hinge allowed stalkers to pinpoint users’ locations down to 2 meters, researchers say36:47 - Story # 3: Eavesdropping on HDMI cables can reveal computer screen’s content37:43 - Story # 3b Hak5 Screen Crab39:18 - Story # 4: Microsoft says massive Azure outage was caused by DDoS attack43:31 - Story # 5: CrowdStrike says it’s not to blame for Delta’s days-long outage55:34 - Story # 6: CrowdStrike sued by investors over massive global IT outage (00:00) - PreShow Banter™ — What's the f___ (03:34) - BHIS - Talkin' Bout [infosec] News 2024-08-05 (06:57) - Story # 1: Proofpoint Email Routing Flaw Exploited to Send Millions of Spoofed Phishing Emails (23:57) - Story # 2: Bumble and Hinge allowed stalkers to pinpoint users’ locations down to 2 meters, researchers say (36:47) - Story # 3: Eavesdropping on HDMI cables can reveal computer screen’s content (37:43) - Story # 3b Hak5 Screen Crab (39:18) - Story # 4: Microsoft says massive Azure outage was caused by DDoS attack (43:31) - Story # 5: CrowdStrike says it’s not to blame for Delta’s days-long outage (55:34) - Story # 6: CrowdStrike sued by investors over massive global IT outage

Aug 6, 20241h 3m

Ep 12024-07-29 - Microsoft Sad Face

00:00 - PreShow Banter™ — Microsoft Sad Face02:13 - BHIS - Talkin’ Bout [infosec] News 2024-07-2903:08 - Story # 1: Fake CrowdStrike repair manual pushes new infostealer malware15:26 - Story # 1b: 83-year-old man found safe a week after going missing when CrowdStrike outage canceled flight20:39 - Story # 2: Multifactor Authentication Is Not Enough to Protect Cloud Data38:59 - Graphrunner47:19 - Story # 3: Data pilfered from Pentagon IT supplier Leidos57:57 - Story # 4: How a North Korean Fake IT Worker Tried to Infiltrate Us (00:00) - PreShow Banter™ — Microsoft Sad Face (02:13) - BHIS - Talkin' Bout [infosec] News 2024-07-29 (03:08) - Story # 1: Fake CrowdStrike repair manual pushes new infostealer malware (15:26) - Story # 1b: 83-year-old man found safe a week after going missing when CrowdStrike outage canceled flight (20:39) - Story # 2: Multifactor Authentication Is Not Enough to Protect Cloud Data (38:59) - Graphrunner (47:19) - Story # 3: Data pilfered from Pentagon IT supplier Leidos (57:57) - Story # 4: How a North Korean Fake IT Worker Tried to Infiltrate Us

Jul 31, 20241h 0m

Ep 12024-07-24 - CrowdStroke Memes

00:00 - PreShow Banter™ — CrowdStroke Memes05:59 - BHIS - Talkin’ Bout [infosec] News 2024-07-2207:01 - Story # 1: A Windows version from 1992 is saving Southwest’s butt right now07:36 - Crowdstrike Global Outage - BHIS - Talkin’ Bout [infosec] #News09:48 - Story # 1b: CrowdStrike’s faulty update crashed 8.5 million Windows devices, says Microsoft12:13 - Story # 1c: Let’s blame the dev who pressed “Deploy”17:23 - Figure 122:14 - Story # 2: DHS Has a DoS Robot to Disable Internet of Things ‘Booby Traps’ Inside Homes25:58 - Story # 3: Notorious Hacker Kingpin ‘Tank’ Is Finally Going to Prison28:08 - Story # 4: UK Police Arrest Suspect in MGM Ransomware Attack30:49 - Story # 5: Russians plead guilty to involvement in LockBit ransomware attacks33:24 - Story # 6: DHS watchdog rebukes CISA and law enforcement training center for failing to protect data38:32 - Story # 7: Yacht giant MarineMax data breach impacts over 123,000 people40:38 - Story # 8: Sizable Chunk of SEC Charges Against SolarWinds Tossed Out of Court47:14 - Story # 9: The US Supreme Court Kneecapped US Cyber Strategy52:12 - Story # 10: War Thunder does it again, this time with classified documents relating to 3 Russian tanks (00:00) - PreShow Banter™ — CrowdStroke Memes (05:59) - BHIS - Talkin' Bout [infosec] News 2024-07-22 (07:01) - Story # 1: A Windows version from 1992 is saving Southwest’s butt right now (07:36) - Crowdstrike Global Outage - BHIS - Talkin' Bout [infosec] #News (09:48) - Story # 1b: CrowdStrike’s faulty update crashed 8.5 million Windows devices, says Microsoft (12:13) - Story # 1c: Let's blame the dev who pressed "Deploy" (17:23) - Figure 1 (22:14) - Story # 2: DHS Has a DoS Robot to Disable Internet of Things ‘Booby Traps’ Inside Homes (25:58) - Story # 3: Notorious Hacker Kingpin ‘Tank’ Is Finally Going to Prison (28:08) - Story # 4: UK Police Arrest Suspect in MGM Ransomware Attack (30:49) - Story # 5: Russians plead guilty to involvement in LockBit ransomware attacks (33:24) - Story # 6: DHS watchdog rebukes CISA and law enforcement training center for failing to protect data (38:32) - Story # 7: Yacht giant MarineMax data breach impacts over 123,000 people (40:38) - Story # 8: Sizable Chunk of SEC Charges Against SolarWinds Tossed Out of Court (47:14) - Story # 9: The US Supreme Court Kneecapped US Cyber Strategy (52:12) - Story # 10: War Thunder does it again, this time with classified documents relating to 3 Russian tanks

Jul 24, 202458 min

Ep 12024-07-22 - Crowdstrike Global Outage

The outage of the decade!

Jul 22, 20241h 4m

Ep 12024-07-18 - Absolute Madmen

00:00 - PreShow Banter™ — Absolute Madmen02:28 - BHIS - Talkin’ Bout [infosec] News 2024-07-1503:18 - Wi-Fi Forge07:31 - Story # 1: CISA Red Team’s Operations Against a Federal Civilian Executive Branch Organization Highlights the Necessity of Defense-in-Depth22:39 - Story # 2: AT&T says criminals stole phone records of ‘nearly all’ customers in new data breach33:35 - Story # 3: FTC study finds ‘dark patterns’ used by a majority of subscription apps and websites38:48 - Story # 4: Club Penguin fans breached Disney Confluence server, stole 2.5GB of data41:52 - Story # 5: Heritage Foundation Exec Threatens ‘Gay Furry Hackers’ in Unhinged Texts47:51 - Story # 6: German Navy to replace aging 8-inch floppy drives with an emulated solution for its anti-submarine frigates50:14 - Story # 7: 1.4 GB NSA Data Leaked Online – Email Address, Phone Number & Gov Classified Data Exposed53:56 - Story # 8: Hackers Claim to Have Leaked 1.1 TB of Disney Slack Messages (00:00) - PreShow Banter™ — Absolute Madmen (02:28) - BHIS - Talkin' Bout [infosec] News 2024-07-15 (03:18) - Wi-Fi Forge (07:31) - Story # 1: CISA Red Team’s Operations Against a Federal Civilian Executive Branch Organization Highlights the Necessity of Defense-in-Depth (22:39) - Story # 2: AT&T says criminals stole phone records of ‘nearly all’ customers in new data breach (33:35) - Story # 3: FTC study finds ‘dark patterns’ used by a majority of subscription apps and websites (38:48) - Story # 4: Club Penguin fans breached Disney Confluence server, stole 2.5GB of data (41:52) - Story # 5: Heritage Foundation Exec Threatens ‘Gay Furry Hackers’ in Unhinged Texts (47:51) - Story # 6: German Navy to replace aging 8-inch floppy drives with an emulated solution for its anti-submarine frigates (50:14) - Story # 7: 1.4 GB NSA Data Leaked Online – Email Address, Phone Number & Gov Classified Data Exposed (53:56) - Story # 8: Hackers Claim to Have Leaked 1.1 TB of Disney Slack Messages

Jul 18, 20241h 3m

Ep 12024-07-08 – A Bunch of Lunatics

00:00 - PreShow Banter™ — A Bunch of Lunatics05:09 - BHIS - Talkin’ Bout [infosec] News 2024-07-0808:41 - Story # 1: Europol takes down 593 Cobalt Strike servers used by cybercriminals09:54 - Story # 1b: National Crime Agency leads international operation to degrade illegal versions of Cobalt Strike15:17 - Story # 2: ‘RockYou2024’: Nearly 10 billion passwords leaked online22:12 - Story # 3: Ticketmaster Breach: ShinyHunters Leak 440K Taylor Swift Eras Tour Ticket Data24:20 - Story # 3b: Hackers reverse-engineer Ticketmaster’s barcode system to unlock resales on other platforms27:41 - Story # 4: US Supreme Court ruling will likely cause cyber regulation chaos39:39 - Story # 5: California Advances Unique Safety Regulations for AI Companies Despite Tech Firm opposition41:13 - Story # 5b: Senator Scott Wiener43:45 - Story # 6: OpenAI Did Not Disclose 2023 Breach to Feds, Public: Report53:10 - Story # 7: Microsoft’s Midnight Blizzard source code breach also impacted federal agencies55:27 - Story # 8: Japan’s Government Finally Stops Using Floppy Disks57:48 - Story # 9: This smart toilet paper monitor tells you when you need a new roll58:50 - Story # 10: Twilio says hackers identified cell phone numbers of two-factor app Authy users (00:00) - PreShow Banter™ — A Bunch of Lunatics (05:09) - BHIS - Talkin' Bout [infosec] News 2024-07-08 (08:41) - Story # 1: Europol takes down 593 Cobalt Strike servers used by cybercriminals (09:54) - Story # 1b: National Crime Agency leads international operation to degrade illegal versions of Cobalt Strike (15:17) - Story # 2: ‘RockYou2024’: Nearly 10 billion passwords leaked online (22:12) - Story # 3: Ticketmaster Breach: ShinyHunters Leak 440K Taylor Swift Eras Tour Ticket Data (24:20) - Story # 3b: Hackers reverse-engineer Ticketmaster’s barcode system to unlock resales on other platforms (27:41) - Story # 4: US Supreme Court ruling will likely cause cyber regulation chaos (39:39) - Story # 5: California Advances Unique Safety Regulations for AI Companies Despite Tech Firm opposition (41:13) - Story # 5b: Senator Scott Wiener (43:45) - Story # 6: OpenAI Did Not Disclose 2023 Breach to Feds, Public: Report (53:10) - Story # 7: Microsoft’s Midnight Blizzard source code breach also impacted federal agencies (55:27) - Story # 8: Japan's Government Finally Stops Using Floppy Disks (57:48) - Story # 9: This smart toilet paper monitor tells you when you need a new roll (58:50) - Story # 10: Twilio says hackers identified cell phone numbers of two-factor app Authy users

Jul 10, 20241h 8m

Ep 12024-07-01 - Ice Cream Season

00:00 - PreShow Banter™ — Ice Cream Season07:22 - BHIS - Talkin’ Bout [infosec] News 2024-07-0107:48 - Story # 1: TeamViewer’s corporate network was breached in alleged APT hack09:11 - Story # 1b: TeeamViewer Security Update – June 28, 2024, 12:10 PM CEST16:33 - Story # 2: Supreme Court orders new look at Texas, Florida social media laws21:32 - Story # 3: New OpenSSH Vulnerability Could Lead to RCE as Root on Linux Systems24:52 - Story # 4: CISA: Most critical open source projects not using memory safe code40:03 - Story # 5: Exploit for critical Fortra FileCatalyst Workflow SQLi flaw released42:35 - Story # 6: South Korean telecom company attacks customers with malware — over 600,000 torrent users report missing files, strange folders, and disabled PCs49:24 - Story # 7: Drone As First Responder Programs Are Swarming Across the United States55:22 - GRC Rapid Fire (00:00) - PreShow Banter™ — Ice Cream Season (07:22) - BHIS - Talkin' Bout [infosec] News 2024-07-01 (07:48) - Story # 1: TeamViewer's corporate network was breached in alleged APT hack (09:11) - Story # 1b: TeeamViewer Security Update – June 28, 2024, 12:10 PM CEST (16:33) - Story # 2: Supreme Court orders new look at Texas, Florida social media laws (21:32) - Story # 3: New OpenSSH Vulnerability Could Lead to RCE as Root on Linux Systems (24:52) - Story # 4: CISA: Most critical open source projects not using memory safe code (40:03) - Story # 5: Exploit for critical Fortra FileCatalyst Workflow SQLi flaw released (42:35) - Story # 6: South Korean telecom company attacks customers with malware — over 600,000 torrent users report missing files, strange folders, and disabled PCs (49:24) - Story # 7: Drone As First Responder Programs Are Swarming Across the United States (55:22) - GRC Rapid Fire

Jul 3, 20241h 0m

Ep 12024-06-24 - Life is a Highway

00:00 - PreShow Banter™ — Life is a Highway04:28 - BHIS - Talkin’ Bout [infosec] News 2024-06-2405:30 - Story # 1: Colorado Privacy Act Amended To Include Biometric Data Provisions14:18 - Story # 2: Scathing report on Medibank cyberattack highlights unenforced MFA24:30 - Story # 3: CDK suffered another data breach as it was attempting to recover35:08 - Story # 4: LockBit claims the hack of the US Federal Reserve40:00 - Story # 5: Amazon-Powered AI Cameras Used to Detect Emotions of Unwitting UK Train Passengers45:36 - Story # 6: That PowerShell ‘fix’ for your root cert ‘problem’ is a malware loader in disguise 51:13 - Story # 7: US sanctions Kaspersky Lab executives, board members over ‘cooperation’ with Russia 53:23 - Story # 7b: Treasury Sanctions Kaspersky Lab Leadership in Response to Continued Cybersecurity Risks (00:00) - PreShow Banter™ — Life is a Highway (04:28) - BHIS - Talkin' Bout [infosec] News 2024-06-24 (05:30) - Story # 1: Colorado Privacy Act Amended To Include Biometric Data Provisions (14:18) - Story # 2: Scathing report on Medibank cyberattack highlights unenforced MFA (24:30) - Story # 3: CDK suffered another data breach as it was attempting to recover (35:08) - Story # 4: LockBit claims the hack of the US Federal Reserve (40:00) - Story # 5: Amazon-Powered AI Cameras Used to Detect Emotions of Unwitting UK Train Passengers (45:36) - Story # 6: That PowerShell 'fix' for your root cert 'problem' is a malware loader in disguise (51:13) - Story # 7: US sanctions Kaspersky Lab executives, board members over ‘cooperation’ with Russia (53:23) - Story # 7b: Treasury Sanctions Kaspersky Lab Leadership in Response to Continued Cybersecurity Risks

Jun 26, 20241h 2m

Ep 12024-06-17 - Recall Gets Recalled

00:00 - PreShow Banter™ — Hungry Hungry Hipaa03:39 - BHIS - Talkin’ Bout [infosec] News 2024-06-17 05:40 - Story # 1: Windows security hole allows attackers to install malware via Wi-Fi — new patch plugs gaping vulnerability16:27 - Story # 2: Microsoft’s all-knowing Recall AI feature is being delayed25:34 - Story # 3: Here’s how Apple’s AI model tries to keep your data private32:27 - Story # 4: New Linux malware is controlled through emojis sent from Discord35:28 - Story # 5: Pure Storage confirms data breach after Snowflake account hack38:44 - Story # 6: Microsoft Chose Profit Over Security and Left U.S. Government Vulnerable to Russian Hack, Whistleblower Says (00:00) - PreShow Banter™ — Hungry Hungry Hipaa (03:39) - BHIS - Talkin' Bout [infosec] News 2024-06-17 (05:40) - Story # 1: Windows security hole allows attackers to install malware via Wi-Fi — new patch plugs gaping vulnerability (16:27) - Story # 2: Microsoft’s all-knowing Recall AI feature is being delayed (25:34) - Story # 3: Here’s how Apple’s AI model tries to keep your data private (32:27) - Story # 4: New Linux malware is controlled through emojis sent from Discord (35:28) - Story # 5: Pure Storage confirms data breach after Snowflake account hack (38:44) - Story # 6: Microsoft Chose Profit Over Security and Left U.S. Government Vulnerable to Russian Hack, Whistleblower Says

Jun 19, 20241h 1m

Ep 12024-6-13 - Recall Disaster, Ransomware and Drone Police

00:00 - PreShow Banter™ — Louie is Live04:53 - BHIS - Talkin’ Bout [infosec] News 2024-06-1007:09 - Story # 1: UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion18:39 - Story # 2: Stealing everything you’ve ever typed or viewed on your own Windows PC is now possible with two lines of code — inside the Copilot+ Recall disaster.39:02 - Story # 3: TikTok fixes zero-day bug used to hijack high-profile accounts41:34 - Story # 4: The Age of the Drone Police Is Here52:07 - Story # 5: London hospitals declare emergency following ransomware attack54:45 - Story # 6: Former Senior Executive and Former Sales Manager Convicted of Selling Data on Millions of U.S. Consumers to Perpetrators of Mail Fraud Schemes56:40 - Story # 7: FBI Kicks Hackers In The Teeth With Free 7,000 Ransomware Key Giveaway57:32 - Story # 8: FCC OKs pilot to bolster school, library cybersecurity (00:00) - PreShow Banter™ — Louie is Live (04:53) - BHIS - Talkin' Bout [infosec] News 2024-06-10 (07:09) - Story # 1: UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion (18:39) - Story # 2: Stealing everything you’ve ever typed or viewed on your own Windows PC is now possible with two lines of code — inside the Copilot+ Recall disaster. (39:02) - Story # 3: TikTok fixes zero-day bug used to hijack high-profile accounts (41:34) - Story # 4: The Age of the Drone Police Is Here (52:07) - Story # 5: London hospitals declare emergency following ransomware attack (54:45) - Story # 6: Former Senior Executive and Former Sales Manager Convicted of Selling Data on Millions of U.S. Consumers to Perpetrators of Mail Fraud Schemes (56:40) - Story # 7: FBI Kicks Hackers In The Teeth With Free 7,000 Ransomware Key Giveaway (57:32) - Story # 8: FCC OKs pilot to bolster school, library cybersecurity

Jun 13, 20241h 3m

Ep 12024-06-2024 - RVs, Hackers and Poison.

00:00:00 - PreShow Banter™ — In an RV down by the dumpster 00:07:39 - BHIS - Talkin’ Bout [infosec] News 2024-06-03 00:09:21 - Story # 1: Ticketmaster confirms massive breach after stolen data for sale online 00:10:46 - Story # 1b: Snowflake, Cloud Storage Giant, Suffers Massive Breach: Hacker Confirms to Hudson Rock Access Through Infostealer Infection 00:13:03 - Story # 1c: Detecting and Preventing Unauthorized User Access: Instructions 00:13:42 - Story # 1d: Snowflake Denies Responsibility for Ticketmaster, Santander Breaches 00:21:21 - Story # 2: Chinese hackers hide on military and govt networks for 6 years 00:29:17 - Story # 3: Federal agency warns critical Linux vulnerability being actively exploited 00:34:19 - Story # 4: US dismantles 911 S5 botnet used for cyberattacks, arrests admin 00:39:19 - Story # 4b: How the FBI’s fake cell phone company put criminals into real jail cells 00:43:48 - Story # 5: Exploit released for maximum severity Fortinet RCE bug, patch now 00:46:09 - Story # 6: Enforcement Alert: Drinking Water Systems to Address Cybersecurity Vulnerabilities 00:54:44 - Story # 6b: Hackers attempt to poison Florida city’s water supply near Super Bowl 01:03:32 - Story # 7: GPT-4o’s Chinese token-training data is polluted by spam and porn websites (00:00) - PreShow Banter™ — In an RV down by the dumpster (07:39) - BHIS - Talkin' Bout [infosec] News 2024-06-03 (09:21) - Story # 1: Ticketmaster confirms massive breach after stolen data for sale online (10:46) - Story # 1b: Snowflake, Cloud Storage Giant, Suffers Massive Breach: Hacker Confirms to Hudson Rock Access Through Infostealer Infection (13:03) - Story # 1c: Detecting and Preventing Unauthorized User Access: Instructions (13:42) - Story # 1d: Snowflake Denies Responsibility for Ticketmaster, Santander Breaches (21:21) - Story # 2: Chinese hackers hide on military and govt networks for 6 years (29:17) - Story # 3: Federal agency warns critical Linux vulnerability being actively exploited (34:19) - Story # 4: US dismantles 911 S5 botnet used for cyberattacks, arrests admin (39:19) - Story # 4b: How the FBI's fake cell phone company put criminals into real jail cells (43:48) - Story # 5: Exploit released for maximum severity Fortinet RCE bug, patch now (46:09) - Story # 6: Enforcement Alert: Drinking Water Systems to Address Cybersecurity Vulnerabilities (54:44) - Story # 6b: Hackers attempt to poison Florida city's water supply near Super Bowl (01:03:32) - Story # 7: GPT-4o’s Chinese token-training data is polluted by spam and porn websites

Jun 6, 20241h 8m

Ep 12024-05-23 - Sneaky AI Policies, Two Year Linux Backdoor and Good Ol' Fraud!

00:00 - PreShow Banter™ — Antichafing Training.04:31 - BHIS - Talkin’ Bout [infosec] News 2024-05-2007:12 - Story # 1: Linux maintainers were infected for 2 years by SSH-dwelling backdoor with huge reach29:49 - Story # 2: Palo Alto Networks is buying security assets from IBM to expand customer base36:50 - Story # 3: Charges and Seizures Brought in Fraud Scheme Aimed at Denying Revenue for Workers Associated with North Korea43:55 - Story # 4: FCC might require telecoms to report on securing internet’s BGP technology52:45 - Story # 5: Slack under attack over sneaky AI training policy (00:00) - PreShow Banter™ — Antichafing Training. (04:31) - BHIS - Talkin' Bout [infosec] News 2024-05-20 (07:12) - Story # 1: Linux maintainers were infected for 2 years by SSH-dwelling backdoor with huge reach (29:49) - Story # 2: Palo Alto Networks is buying security assets from IBM to expand customer base (36:50) - Story # 3: Charges and Seizures Brought in Fraud Scheme Aimed at Denying Revenue for Workers Associated with North Korea (43:55) - Story # 4: FCC might require telecoms to report on securing internet's BGP technology (52:45) - Story # 5: Slack under attack over sneaky AI training policy

May 23, 20241h 6m

Ep 12024-05-16 - Hackers Target Children, FBI Surveillance and RSA Cookies?

00:00 - PreShow Banter™ — World Class RSA Cookies04:49 - BHIS - Talkin’ Bout [infosec] News 2024-05-1406:33 - Story # 1: Zscaler takes “test environment” offline after rumors of a breach18:48 - Story # 2: Okta’s security chief on the company’s own cyberattack and how the ‘battleground’ has shifted43:36 - Story # 3: Leaked FBI email stresses need for warrantless surveillance of Americans48:46 - Story # 4: Despite big tech lobbying, Maryland passes two internet privacy bills52:26 - Story # 4b: The Anxious Generation53:46 - Story # 5:Hackers are now targeting the children of corporate executives in elaborate ransomware attacks (00:00) - PreShow Banter™ — World Class RSA Cookies (04:49) - BHIS - Talkin' Bout [infosec] News 2024-05-14 (06:33) - Story # 1: Zscaler takes "test environment" offline after rumors of a breach (18:48) - Story # 2: Okta’s security chief on the company’s own cyberattack and how the ‘battleground’ has shifted (43:36) - Story # 3: Leaked FBI email stresses need for warrantless surveillance of Americans (48:46) - Story # 4: Despite big tech lobbying, Maryland passes two internet privacy bills (52:26) - Story # 4b: The Anxious Generation (53:46) - Story # 5:Hackers are now targeting the children of corporate executives in elaborate ransomware attacks

May 16, 202457 min

Ep 12024-05-07 - LastPass Goes Independent, Hacker Sentenced, Vulnerabilities Among us.

00:00 - PreShow Banter™ — RSA Power Moves08:14 - BHIS - Talkin’ Bout [infosec] News 2024-05-0609:49 - Story # 1: Shortridge Makes Sense of the 2024 Verizon DBIR15:04 - Story # 2: A recent security incident involving Dropbox Sign20:30 - Story # 3: Sandbox Escape Vulnerabilities in Judge0 Expose Systems to Complete Takeover28:40 - Story # 4: Millions of Docker repos found pushing malware, phishing sites32:53 - Story # 5: 1,400 GitLab Servers Impacted by Exploited Vulnerability42:07 - Story # 6: LastPass goes independent over a year after serious breaches50:16 - Cyber Security Basics for Muggles & Minions with Ashley and Chris50:40 - Story # 7: Ukrainian REvil Hacker Sentenced to 13 Years and Ordered to Pay $16 Million54:12 - Story # 8: Lockbit’s seized site comes alive to tease new police announcements56:27 - Story # 9: Systemd v256 Introduces run0: A Safer Alternative to sudo (00:00) - PreShow Banter™ — RSA Power Moves (08:14) - BHIS - Talkin' Bout [infosec] News 2024-05-06 (09:49) - Story # 1: Shortridge Makes Sense of the 2024 Verizon DBIR (15:04) - Story # 2: A recent security incident involving Dropbox Sign (20:30) - Story # 3: Sandbox Escape Vulnerabilities in Judge0 Expose Systems to Complete Takeover (28:40) - Story # 4: Millions of Docker repos found pushing malware, phishing sites (32:53) - Story # 5: 1,400 GitLab Servers Impacted by Exploited Vulnerability (42:07) - Story # 6: LastPass goes independent over a year after serious breaches (50:16) - Cyber Security Basics for Muggles & Minions with Ashley and Chris (50:40) - Story # 7: Ukrainian REvil Hacker Sentenced to 13 Years and Ordered to Pay $16 Million (54:12) - Story # 8: Lockbit's seized site comes alive to tease new police announcements (56:27) - Story # 9: Systemd v256 Introduces run0: A Safer Alternative to sudo

May 8, 20241h 2m

Ep 12024-04-29 - Hack All The Things!

00:00 - BHIS - Talkin’ Bout [infosec] News 2024-04-29 02:33 - Story # 1: Cyber Hygiene Helps Organizations Mitigate Ransomware-Related Vulnerabilities 10:38 - Story # 2: ‘Admin’ and ‘12345’ banned from being used as passwords in UK crackdown on cyber attacks 16:34 - Story # 3: Maximum severity Flowmon bug has a public exploit, patch now 21:06 - Story # 3b: CVE-2024-2389: Command Injection Vulnerability In Progress Flowmon 22:45 - Story # 4:GitHub comments abused to push malware via Microsoft repo URLs 30:52 - Story # 5: Security bugs in popular phone-tracking app iSharing exposed users’ precise locations 36:47 - Story # 6: Biden signs bill criticized as “major expansion of warrantless surveillance” 49:38 - Story # 7: ChatGPT’s hallucinations draw EU privacy complaint 57:46 - Story # 8: Sweden’s liquor shelves to run empty this week due to ransomware attack (00:00) - BHIS - Talkin' Bout [infosec] News 2024-04-29 (02:33) - Story # 1: Cyber Hygiene Helps Organizations Mitigate Ransomware-Related Vulnerabilities (10:38) - Story # 2: 'Admin' and '12345' banned from being used as passwords in UK crackdown on cyber attacks (16:34) - Story # 3: Maximum severity Flowmon bug has a public exploit, patch now (21:06) - Story # 3b: CVE-2024-2389: Command Injection Vulnerability In Progress Flowmon (22:45) - Story # 4:GitHub comments abused to push malware via Microsoft repo URLs (30:52) - Story # 5: Security bugs in popular phone-tracking app iSharing exposed users’ precise locations (36:47) - Story # 6: Biden signs bill criticized as “major expansion of warrantless surveillance” (49:38) - Story # 7: ChatGPT’s hallucinations draw EU privacy complaint (57:46) - Story # 8: Sweden's liquor shelves to run empty this week due to ransomware attack

May 1, 202459 min

Ep 12024-04-24 - Exploits, Breaches and, Lawsuits!

00:00 - PreShow Banter™ — A Parent Process 03:01 - BHIS - Talkin’ Bout [infosec] News 2024-04-22 04:13 - Story # 1: Exploit code for Palo Alto Networks zero-day now public 07:44 - Story # 1b: (Timeline) Zero-Day Exploitation of Unauthenticated Remote Code Execution Vulnerability in GlobalProtect (CVE-2024-3400) 23:22 - Story # 2: MGM says FTC can’t possibly probe its ransomware downfall – watchdog chief Lina Khan was a guest at the time 31:37 - Story # 3: MITRE was breached through Ivanti zero-day vulnerabilities 32:27 - Story # 4: Cisco Integrated Management Controller CLI Command Injection Vulnerability 41:20 - Story # 5: Cisco Duo’s Multifactor Authentication Service Breached 46:01 - Story # 6: DevSecOps security practices are doggone disastrous 54:57 - Story # 7: FYI: This site claims to have harvested 4B+ Discord chats, today all yours for a price (00:00) - PreShow Banter™ — A Parent Process (03:01) - BHIS - Talkin' Bout [infosec] News 2024-04-22 (04:13) - Story # 1: Exploit code for Palo Alto Networks zero-day now public (07:44) - Story # 1b: (Timeline) Zero-Day Exploitation of Unauthenticated Remote Code Execution Vulnerability in GlobalProtect (CVE-2024-3400) (23:22) - Story # 2: MGM says FTC can't possibly probe its ransomware downfall – watchdog chief Lina Khan was a guest at the time (31:37) - Story # 3: MITRE was breached through Ivanti zero-day vulnerabilities (32:27) - Story # 4: Cisco Integrated Management Controller CLI Command Injection Vulnerability (41:20) - Story # 5: Cisco Duo's Multifactor Authentication Service Breached (46:01) - Story # 6: DevSecOps security practices are doggone disastrous (54:57) - Story # 7: FYI: This site claims to have harvested 4B+ Discord chats, today all yours for a price

Apr 24, 20241h 0m

Ep 12024-04-17 - SoCal Man Arrested, EPA Leaks, Net Neutrality returns?

00:00 - PreShow Banter™ — Retro Actions 04:48 - BHIS - Talkin’ Bout [infosec] News 2024-04-15 07:05 - Story # 1: FCC to vote on net neutrality rules on April 25 18:52 - Story # 2: “All Your Secrets Are Belong To Us” — A Delinea Secret Server AuthN/AuthZ Bypass 23:40 - Story # 2b: Delinea has cloud security incident in Thycotic Secret Server gaff 28:23 - Story # 3: CISA Releases Malware Next-Gen Analysis System for Public Use 40:36 - Story # 4: Hacker Leaks 8.5M U.S. Environmental Protection Agency (EPA) Contact Data 45:55 - Story # 5: SoCal Man Arrested on Federal Charges Alleging He Schemed to Advertise and Sell ‘Hive’ Computer Intrusion Malware (00:00) - PreShow Banter™ — Retro Actions (04:48) - BHIS - Talkin' Bout [infosec] News 2024-04-15 (07:05) - Story # 1: FCC to vote on net neutrality rules on April 25 (18:52) - Story # 2: “All Your Secrets Are Belong To Us” — A Delinea Secret Server AuthN/AuthZ Bypass (23:40) - Story # 2b: Delinea has cloud security incident in Thycotic Secret Server gaff (28:23) - Story # 3: CISA Releases Malware Next-Gen Analysis System for Public Use (40:36) - Story # 4: Hacker Leaks 8.5M U.S. Environmental Protection Agency (EPA) Contact Data (45:55) - Story # 5: SoCal Man Arrested on Federal Charges Alleging He Schemed to Advertise and Sell ‘Hive’ Computer Intrusion Malware

Apr 17, 202459 min

Ep 12024-04-10 - Vigilante Hackers, Data Sharing, Cybersecurity Taken Over by Computers?

00:00 - PreShow Banter™ — BHIS Bees Corp® 04:08 - The FUTURE IS…… Kickstarter 05:29 - BHIS - Talkin’ Bout [infosec] News 2024-04-08 06:03 - Story # 1: New draft bipartisan US federal privacy bill unveiled 11:03 - Story # 2: How To Opt Out Of GM Sharing Your Driving Data With Insurance Companies 13:04 - Story # 2b: Request a Consumer Disclosure Report 14:25 - Story # 3: Hackers Hijacked Notepad++ Plugin To Execute Malicious Code 29:19 - Story # 4: A Vigilante Hacker Took Down North Korea’s Internet. Now He’s Taking Off His Mask 46:15 - Story # 5: It’s Time to Hand Cybersecurity Over to the Computers (00:00) - PreShow Banter™ — BHIS Bees Corp® (04:08) - The FUTURE IS...... Kickstarter (05:29) - BHIS - Talkin' Bout [infosec] News 2024-04-08 (06:03) - Story # 1: New draft bipartisan US federal privacy bill unveiled (11:03) - Story # 2: How To Opt Out Of GM Sharing Your Driving Data With Insurance Companies (13:04) - Story # 2b: Request a Consumer Disclosure Report (14:25) - Story # 3: Hackers Hijacked Notepad++ Plugin To Execute Malicious Code (29:19) - Story # 4: A Vigilante Hacker Took Down North Korea’s Internet. Now He’s Taking Off His Mask (46:15) - Story # 5: It’s Time to Hand Cybersecurity Over to the Computers

Apr 10, 20241h 3m

Ep 12024-04-03 - Zippers, Jokes & Data Breaches

00:00 - PreShow Banter™ — Zippers, Jokes, & Lawyers (Not to be confused with the song "Lawyers, Guns and Money")02:59 - BHIS - Talkin’ Bout [infosec] News 2024-04-0103:57 - Story # 1: New Darcula phishing service targets iPhone users via iMessage11:57 - Story # 2: Recent ‘MFA Bombing’ Attacks Targeting Apple Users17:22 - Story # 3: Thousands of phones and routers swept into proxy service, unbeknownst to users22:11 - Story # 4: Digital signs around Brookline are collecting data from your phone as you walk by26:57 - Story # 5: Backdoor found in widely used Linux utility targets encrypted SSH connections28:22 - Story # 5b: XZ Outbreak diagram37:32 - Story # 6: Vans warns customers of data breach40:00 - Story # 7: Worldwide Agenda Ransomware Wave Targets VMware ESXi Servers50:32 - Story # 8: Criminals Are Weaponizing Child Abuse Imagery to Ban Discord Servers56:41 - Story # 9: International car theft tool seized in Australia, sparking police warning58:14 - Story # 9b: Investigation into electronic device at Utah high school raises larger concerns for police (00:00) - PreShow Banter™ — Zippers, Jokes & Lawyers (02:59) - BHIS - Talkin' Bout [infosec] News 2024-04-01 (03:57) - Story # 1: New Darcula phishing service targets iPhone users via iMessage (11:57) - Story # 2: Recent ‘MFA Bombing’ Attacks Targeting Apple Users (17:22) - Story # 3: Thousands of phones and routers swept into proxy service, unbeknownst to users (22:11) - Story # 4: Digital signs around Brookline are collecting data from your phone as you walk by (26:57) - Story # 5: Backdoor found in widely used Linux utility targets encrypted SSH connections (28:22) - Story # 5b: XZ Outbreak diagram (37:32) - Story # 6: Vans warns customers of data breach (40:00) - Story # 7: Worldwide Agenda Ransomware Wave Targets VMware ESXi Servers (50:32) - Story # 8: Criminals Are Weaponizing Child Abuse Imagery to Ban Discord Servers (56:41) - Story # 9: International car theft tool seized in Australia, sparking police warning (58:14) - Story # 9b: Investigation into electronic device at Utah high school raises larger concerns for police

Apr 3, 20241h 6m

Ep 12024-5-03-27 - Social Media Ban, Sold Data and Splunk w/ Graham Helton

00:00 - PreShow Banter™ — “Allegedly”03:18 - BHIS - Talkin’ Bout [infosec] News 2024-03-2508:00 - Story # 1: Cisco Completes Acquisition of Splunk10:47 - Story # 2: General Motors Quits Sharing Driving Behavior With Data Brokers15:27 - Story # 3: Ron DeSantis signs bill requiring parental consent for kids under 16 to hold social media accounts24:34 - Story # 4: House passes bill to prevent the sale of personal data to foreign adversaries28:19 - Story # 5: Unsaflok - vulnerability impacts over 3 million hotel doors33:57 - Story # 6: Canada revisits decision to ban Flipper Zero36:57 - Story # 7: Truck-to-truck worm could infect – and disrupt – entire US commercial fleet42:59 - Story # 8: Cybercriminals Beta Test New Attack to Bypass AI Security46:31 - Story # 9: Russians will no longer be able to access Microsoft cloud services, business intelligence tools50:36 - Story # 10: New ‘Loop DoS’ Attack Impacts Hundreds of Thousands of Systems55:05 - Story # 11: New surveillance video of man catching a flight without ticket (00:00) - PreShow Banter™ — "Allegedly" (03:18) - BHIS - Talkin' Bout [infosec] News 2024-03-25 (08:00) - Story # 1: Cisco Completes Acquisition of Splunk (10:47) - Story # 2: General Motors Quits Sharing Driving Behavior With Data Brokers (15:27) - Story # 3: Ron DeSantis signs bill requiring parental consent for kids under 16 to hold social media accounts (24:34) - Story # 4: House passes bill to prevent the sale of personal data to foreign adversaries (28:19) - Story # 5: Unsaflok - vulnerability impacts over 3 million hotel doors (33:57) - Story # 6: Canada revisits decision to ban Flipper Zero (36:57) - Story # 7: Truck-to-truck worm could infect – and disrupt – entire US commercial fleet (42:59) - Story # 8: Cybercriminals Beta Test New Attack to Bypass AI Security (46:31) - Story # 9: Russians will no longer be able to access Microsoft cloud services, business intelligence tools (50:36) - Story # 10: New 'Loop DoS' Attack Impacts Hundreds of Thousands of Systems (55:05) - Story # 11: New surveillance video of man catching a flight without ticket

Mar 27, 202459 min

Ep 12024-03-20 - New Arms Again w/ Jay Beale of InGuardians

Brought to you by Antisyphon Training — https://www.antisyphontraining.com00:00:00 - PreShow Banter™ — New Arms Again00:03:24 - BHIS - Talkin’ Bout [infosec] News 2024-03-1800:04:54 - Story # 1: NIST Releases Version 2.0 of Landmark Cybersecurity Framework00:10:50 - Story # 2: The FCC has finally decreed that 25Mbps and 3Mbps are not ‘broadband’ speed00:14:33 - Story # 3: Welcome to the 2024 Threat Detection Report00:33:40 - Story # 4: NSA Releases Top Ten Cloud Security Mitigation Strategies00:47:33 - Story # 5: US government agencies demand fixable ice cream machines00:53:14 - Story # 6: Homeland Security is testing AI to help with immigration, trafficking investigations, and disaster relief01:03:19 - Story # 7: Feds seize $1.4 million of tech support scam proceeds with the help of crypto firm (00:00) - PreShow Banter™ — New Arms Again (03:24) - BHIS - Talkin' Bout [infosec] News 2024-03-18 (04:54) - Story # 1: NIST Releases Version 2.0 of Landmark Cybersecurity Framework (10:50) - Story # 2: The FCC has finally decreed that 25Mbps and 3Mbps are not ‘broadband’ speed (14:33) - Story # 3: Welcome to the 2024 Threat Detection Report (33:40) - Story # 4: NSA Releases Top Ten Cloud Security Mitigation Strategies (47:33) - Story # 5: US government agencies demand fixable ice cream machines (53:14) - Story # 6: Homeland Security is testing AI to help with immigration, trafficking investigations, and disaster relief (01:03:19) - Story # 7: Feds seize $1.4 million of tech support scam proceeds with the help of crypto firm

Mar 20, 20241h 5m

Ep 12024-03-13 - International Hacking Co. Featuring: Josh Mason

00:00 - PreShow Banter™ — Death to Clippy05:18 - BHIS - Talkin’ Bout [infosec] News 2024-03-11 – Featuring Josh Mason06:58 - Story # 1: Behind the doors of a Chinese hacking company, a sordid culture fueled by influence, alcohol, and sex13:43 - Story # 2: Top US cybersecurity agency hacked and forced to take some systems offline23:39 - Story # 3: Microsoft admits Russian state hack still not contained. ‘This has tremendous national security implications’30:27 - Story # 4: FBI’s 2023 Internet Crime Report38:18 - Story # 5: QNAP warns of critical auth bypass flaw in its NAS devices50:42 - Story # 6: Automakers Are Sharing Consumers’ Driving Behavior With Insurance Companies (00:00) - PreShow Banter™ — Death to Clippy (05:18) - BHIS - Talkin' Bout [infosec] News 2024-03-11 – Featuring Josh Mason (06:58) - Story # 1: Behind the doors of a Chinese hacking company, a sordid culture fueled by influence, alcohol and sex (13:43) - Story # 2: Top US cybersecurity agency hacked and forced to take some systems offline (23:39) - Story # 3: Microsoft admits Russian state hack still not contained. ‘This has tremendous national security implications’ (30:27) - Story # 4: FBI's 2023 Internet Crime Report (38:18) - Story # 5: QNAP warns of critical auth bypass flaw in its NAS devices (50:42) - Story # 6: Automakers Are Sharing Consumers’ Driving Behavior With Insurance Companies

Mar 13, 20241h 0m

Ep 12024-03-06 - No Logs No Breach, I'm Good

A weekly Podcast with BHIS and Friends. stories. We discuss notable Infosec, and infosec-adjacent news stories. Brought to you by: Black Hills Information Securityhttps://www.blackhillsinfosec.com/Antisyphon Traininghttps://www.antisyphontraining.com/Story # 1: Executive Order on Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concernhttps://www.whitehouse.gov/briefing-r...Story # 2: A leaky database spilled 2FA codes for the world’s tech giantshttps://techcrunch.com/2024/02/29/lea...Story # 3: eBay, VMware, McAfee Sites Hijacked in Sprawling Phishing Operationhttps://www.darkreading.com/applicati...23:36 - LokiHakanin's related Post / sean-reilly-techopssec_8000-domains-of-tru... Story # 4: Ivanti Connect Secure hackers hide in plain sight, evading protectionshttps://www.cybersecuritydive.com/new...Story # 5: Over 100,000 Infected Repos Found on GitHubhttps://apiiro.com/blog/malicious-cod...Story # 6: Hackers backed by Russia and China are infecting SOHO routers like yours, FBI warnshttps://arstechnica.com/security/2024... (00:00) - PreShow Banter™ — Adopting Cats (00:43) - BHIS - Talkin' Bout [infosec] News 2024-03-04 (01:40) - Story # 1: Executive Order on Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern (08:56) - Story # 2: A leaky database spilled 2FA codes for the world’s tech giants (20:14) - Story # 3: eBay, VMware, McAfee Sites Hijacked in Sprawling Phishing Operation (22:37) - LokiHakanin's related Post (31:37) - Story # 4: Ivanti Connect Secure hackers hide in plain sight, evading protections (39:44) - Story # 5: Over 100,000 Infected Repos Found on GitHub (48:44) - Story # 6: Hackers backed by Russia and China are infecting SOHO routers like yours, FBI warns

Mar 6, 202458 min

Ep 12024-03-01 - All of our base belong to China w/ Mike Poor

Story #1: Mr. Cooper leak exposes over two million customersStory #2: ConnectWise ScreenConnect attacks deliver malwareStory #3: LockBit Infrastructure Seized by US, UK PoliceStory #4: US health tech giant Change Healthcare hit by cyberattackStory #5: The reported leak of Chinese hacking documents supports experts’ warnings about how compromised the US could be (00:00) - PreShow Banter™ — It's a Wii Match (05:22) - BHIS - Talkin' Bout [infosec] News 2024-02-26 (07:10) - Story # 1: Mr. Cooper leak exposes over two million customers (17:42) - Story # 2: ConnectWise ScreenConnect attacks deliver malware (27:49) - Story # 3: LockBit Infrastructure Seized by US, UK Police (34:17) - Story # 4: US health tech giant Change Healthcare hit by cyberattack (39:43) - Story # 5: The reported leak of Chinese hacking documents supports experts' warnings about how compromised the US could be (53:24) - Story # 6: Vending machine error reveals secret face image database of college students

Mar 1, 202457 min

Ep 1Talkin’ About Infosec News – 2/20/24

The post Talkin’ About Infosec News – 2/20/24 appeared first on Black Hills Information Security.

Feb 20, 202455 min

Ep 1Talkin’ About Infosec News – 2/14/2024

The post Talkin’ About Infosec News – 2/14/2024 appeared first on Black Hills Information Security. (00:00) - PreShow Banter™ — Fashion in Oregon (01:51) - BHIS - Talkin' Bout [infosec] News 2024-02-12 (08:54) - Story # 1: Ivanti devices hit by wave of exploits for latest security hole (31:53) - Story # 2: Hackers Exploit Job Boards, Stealing Millions of Resumes and Personal Data (43:15) - Story # 3: Critical Boot Loader Vulnerability in Shim Impacts Nearly All Linux Distros (54:13) - Story # 4: Feds Want to Ban the World’s Cutest Hacking Device. Experts Say It's a ‘Scapegoat’

Feb 14, 20241h 5m

Ep 1Talkin’ About Infosec News – 2/6/24

The post Talkin’ About Infosec News – 2/6/24 appeared first on Black Hills Information Security. (00:00) - PreShow Banter™ — 5 Min Webcasts (04:29) - BHIS - Talkin' Bout [infosec] News 2024-02-05 (09:06) - Story # 1: Thanksgiving 2023 security incident (22:09) - Story # 2: AnyDesk Incident Response 5-2-2024 (34:14) - Story # 3: Finance worker pays out $25 million after video call with deepfake ‘chief financial officer’ (50:13) - Story # 4: All federal civilian agencies ordered to disconnect at-risk Ivanti products by Friday

Feb 6, 20241h 2m

Ep 1Talkin’ About Infosec News – 1/31/2024

The post Talkin’ About Infosec News – 1/31/2024 appeared first on Black Hills Information Security. (00:00) - PreShow Banter™ — No Hacking on Fridays (04:33) - BHIS - Talkin' Bout [infosec] News 2024-01-29 (09:48) - Story # 1: SEC confirms X account was hacked in SIM swapping attack (17:45) - Story # 2: MavenGate Attack Could Let Hackers Hijack Java and Android via Abandoned Libraries (23:03) - Story # 3: Fortra warns of new critical GoAnywhere MFT auth bypass, patch now (26:35) - Story # 4: Tesla hacked, 24 zero-days demoed at Pwn2Own Automotive 2024 (35:38) - Story # 5: Election cybersecurity director was a victim of a ‘swatting’ attack in her home (39:44) - Story # 6: Ring will no longer allow police to request users' doorbell camera footage (44:25) - Story # 7: Group permission misconfiguration exposes Google Kubernetes Engine clusters (47:03) - REPRISE STORY: Mega-Breach Database Exposes 26 Billion Records (47:50) - Story # 8: The NSA buys Americans’ internet data, newly released documents show (56:03) - Story # 9: Privacy predictions for 2024

Jan 31, 20241h 8m

Ep 1Talkin’ About Infosec News – 1/24/2024

The post Talkin’ About Infosec News – 1/24/2024 appeared first on Black Hills Information Security. (00:00) - PreShow Banter™ — There's More Than Swim Meets (01:21) - BHIS - Talkin' Bout [infosec] News 2024-01-22 (05:21) - Story # 1 : Florida bill banning youth from social media moves forward (14:19) - Story # 2 : Microsoft network breached through password-spraying by Russia-state hackers (21:38) - Story # 3 : This new data poisoning tool lets artists fight back against generative AI (28:50) - Story # 4: Top 3 Priorities for CISOs in 2024 (41:37) - Story # 5 : Inside the Massive Naz.API Credential Stuffing List (48:09) - Story # 6 : Jamf discovers new malware disguised as popular macOS apps

Jan 24, 20241h 1m

Ep 1Talkin’ About Infosec News – 1/16/2024

The post Talkin’ About Infosec News – 1/16/2024 appeared first on Black Hills Information Security. (00:00) - PreShow Banter™ — Book-It Steak Dinners (05:25) - BHIS - Talkin' Bout [infosec] News 2024-01-15 (08:01) - Most Offensive Con - (08:16) - Story # 1: Linux devices are under attack by a never-before-seen worm (21:09) - Story # 2: Hacker spins up 1 million virtual servers to illegally mine crypto (25:47) - Story # 3: Actively exploited 0-days in Ivanti VPN are letting hackers backdoor networks (29:33) - Podcast Self-Awareness (32:14) - Story # 4: Hospital IT help desks targeted by sophisticated social engineering schemes

Jan 16, 202457 min

Ep 1Talkin’ About Infosec News – 1/10/24

The post Talkin’ About Infosec News – 1/10/24 appeared first on Black Hills Information Security. (00:00) - PreShow Banter™ — Welcome to 2025 (03:36) - BHIS - Talkin' Bout [infosec] News 2024-01-08 (05:30) - Story # 1: Law firm that handles data breaches was hit by data breach (10:36) - Story # 2: Fred Hutch patients get blackmail emails after cyberattack (17:55) - Story # 3: Bitwarden Heist - How to Break Into Password Vaults Without Using Passwords (19:56) - Story # 3b: Privacy Harms – Daniel Solove (21:20) - Story # 4: 23andMe tells victims it’s their fault that their data was breached (33:12) - Story # 5: Hacked Mandiant X Account Abused for Cryptocurrency Theft (37:38) - Story # 6: Merck $1.4 Billion Cyberhack Settlement Ends ‘Warlike’ Act Claim (45:27) - Story # 7: Volkswagen is adding ChatGPT to its infotainment system (51:02) - Story # 8: US nuke reactor lab hit by 'gay furry hackers' demanding cat-human mutants

Jan 10, 202455 min

Ep 1Talkin’ About Infosec News – 12/21/2023

The post Talkin’ About Infosec News – 12/21/2023 appeared first on Black Hills Information Security. (00:00) - PreShow Banter™ — Talking Bout Fabric (07:16) - BHIS - Talkin' Bout [infosec] News 2023-12-18 (10:06) - Story # 1: Cartels Are Using a Police Database to Track and Target Their Enemies (23:15) - Story # 2: CVS, Rite Aid, Walgreens hand out medical records to cops without warrants (37:18) - Story # 3: Cloud engineer gets 2 years for wiping ex-employer’s code repos (45:11) - Story # 4: Ukraine’s intelligence claims cyberattack on Russia’s state tax service (49:06) - Story # 5: A suspected cyberattack paralyzes the majority of gas stations across Iran (51:18) - Story # 6: Discord adds Security Key support for all users to enhance security (54:32) - Story # 7: Kraft Heinz reviewing claims of cyberattack but internal systems ‘operating normally’ (56:49) - Breach Season Speed Run (58:19) - Story # 8: Ten Years Later, New Clues in the Target Breach (01:00:38) - Story # 9: Oops, wrong number! The real story behind NORAD's Santa tracker (01:02:59) - Story # 9b: NORAD Santa Tracker

Dec 21, 20231h 6m

Ep 1Talkin’ About Infosec News – 12/15/2023

https://youtu.be/MaThvw_VWJ8 Brought to you by Antisyphon Training https://www.antisyphontraining.com (00:00) - PreShow Banter™ — Fine McDonalds Drinkware (04:36) - BHIS - Talkin' Bout [infosec] News 2023-12-11 (07:04) - Story # 1: America’s Water Infrastructure Act of 2018 (AWIA) (08:55) - Story # 1b: Dragos Launches Program to Provide Water, Electric Utilities With Free Cybersecurity Tools (09:42) - Story # 1c: Dragos Community Defense Program (11:38) - Story # 2: BlackCat ransomware crims threaten to directly extort victim's customers (20:17) - Story # 3: Fancy Bear goes phishing in US, European high-value networks (21:06) - Story # 3b: Guidance for investigating attacks using CVE-2023-23397 (24:16) - Story # 4: New AeroBlade hackers target aerospace sector in the U.S. (26:27) - Story # 5: Reuters Takes Down Blockbuster Hacker-for-Hire Investigation After Indian Court Order (27:51) - Story # 5b: How an Indian startup hacked the world (32:28) - Story # 6: Just about every Windows and Linux device vulnerable to new LogoFAIL firmware attack (39:28) - Story # 7: 23andMe confirms hackers stole ancestry data on 6.9 million users (51:02) - Story # 7b: 23andMe updates user agreement to prevent data breach lawsuits (55:12) - Story # 8: Facebook Messenger Rolls Out End-to-End Encryption by Default (57:31) - Story # 9: Police Arrest Hundreds of Human Traffickers Linked to Cyber Fraud (01:06:57) - Signal For Help

Dec 15, 20231h 7m

Ep 1Talkin’ About Infosec News – 12/06/2023

The post Talkin’ About Infosec News – 12/06/2023 appeared first on Black Hills Information Security. (00:00) - PreShow Banter™ — Chaos Agency (08:16) - BHIS - Talkin' Bout [infosec] News 2023-12-04 (11:03) - Story # 1: 2 municipal water facilities report falling to hackers in separate breaches (30:49) - Story # 2: PoC for Splunk Enterprise RCE flaw released (CVE-2023-46214) (37:16) - Story # 3: ownCloud vulnerability with maximum 10 severity score comes under “mass” exploitation (39:44) - Story # 4: Zyxel warns of multiple critical vulnerabilities in NAS devices (43:09) - Story # 5: Russian developer of Trickbot malware pleads guilty, faces 35-year sentence (46:55) - Story # 6: Hackers spent 2+ years looting secrets of chipmaker NXP before being detected (52:24) - Story # 7: Okta hackers stole data on all customer support users in major breach (53:30) - Story # 7b: November 29, 2023 - October Customer Support Security Incident - Update and Recommended Actions (01:01:55) - Story # 8: Dollar Tree hit by third-party data breach impacting 2 million people (01:04:07) - Hal's 20,000 - Over 20,000 vulnerable Microsoft Exchange servers exposed to attacks

Dec 6, 20231h 10m

Ep 1Talkin’ About Infosec News – 11/30/2023

The post Talkin’ About Infosec News – 11/30/2023 appeared first on Black Hills Information Security. (00:00) - PreShow Banter™ — Glitch, Please (01:54) - BHIS - Talkin' Bout [infosec] News 2023-11-27 (04:55) - Story # 1: General Electric investigates claims of cyber attack, data theft (10:01) - Story # 2: CISA orders federal agencies to patch Looney Tunables Linux bug (16:26) - Story # 3: Phishing attacks spike attributed to generative AI adoption (18:49) - Story # 3b: SlashNext report uncovers 1,265% increase in phishing emails in a year (19:09) - Story # 3c: Complete Generative AI Security for Email, Mobile, and Browser (24:39) - Story # 4: Fidelity National Financial shuts down network in wake of cybersecurity incident (25:56) - Story # 4b: BlackCat claims it is behind Fidelity National Financial ransomware shakedown (38:08) - Story # 5: Chief Operating Officer of Network Security Company Charged with Cyberattack on Medical Center (01:01:52) - Snake Oil? Summit 2023

Nov 29, 20231h 2m

Ep 1Talkin’ About Infosec News – 11/22/2023

The post Talkin’ About Infosec News – 11/22/2023 appeared first on Black Hills Information Security. (00:00) - PreShow Banter™ — A clean-shaven galaxy, a long time away. (07:50) - BHIS - Talkin' Bout [infosec] News 2023-11-20 (09:53) - Story # 1: Ransomware gang files complaint with SEC complaining victim didn’t promptly announce breach (12:36) - Story # 1b: AlphV files an SEC complaint against MeridianLink for not disclosing a breach to the SEC (2) (17:04) - Story # 1c : Services in North Carolina town unavailable after ransomware attack (18:13) - Story # 1d: WHISTLEBLOWER AWARD PROCEEDING (20:32) - Story # 2: Taylor Swift Fans Spring Into Action After Singer’s Hotel Location Leaks (26:01) - Story # 3: Recognizing fake news now a required subject in California schools (35:34) - Story # 4: Hackers breach healthcare orgs via ScreenConnect remote access (37:07) - Story # 4b: Bitter Pill: Third-Party Pharmaceutical Vendor Linked to Pharmacy and Health Clinic Cyberattack (42:59) - Story # 5: Russian hackers use Ngrok feature and WinRAR exploit to attack embassies (47:19) - Story # 6: US Announces IPStorm Botnet Takedown and Its Creator’s Guilty Plea (50:32) - Story # 7: Ignite News: Augment your EDR with deception tactics to catch adversaries early (59:54) - Snake Oil? Summit 2023

Nov 22, 20231h 3m

Ep 1Talkin’ About Infosec News – 11/13/2023

The post Talkin’ About Infosec News – 11/13/2023 appeared first on Black Hills Information Security. (00:00) - PreShow Banter™ — Tinder Skills Endorsements (01:38) - BHIS - Talkin' Bout [infosec] News 2023-11-13 (02:42) - Story # 1: Boeing data published by Lockbit hacking gang (03:57) - Story # 2: Google, Meta, Discord, and more team up to fight child abuse online (28:06) - Story # 3: Data broker’s “staggering” sale of sensitive info exposed in unsealed FTC filing (39:37) - Story # 4: Maine government says data breach affects 1.3 million people (44:40) - Story # 1 REPRISE: Boeing data published by Lockbit hacking gang (50:52) - Story # 5: Inside Denmark’s hell week as critical infrastructure orgs faced cyberattacks

Nov 16, 202355 min

Ep 1Talkin’ About Infosec News – 11/10/2023

The post Talkin’ About Infosec News – 11/10/2023 appeared first on Black Hills Information Security. (00:00) - PreShow Banter™ — The Jerky Experience (03:40) - BHIS - Talkin' Bout [infosec] News 2023-11-06 (04:34) - Story # 1: Okta hit by third-party data breach exposing employee information (07:03) - Story # 1b: Okta Hack Blamed on Employee Using Personal Google Account on Company Laptop (13:13) - Story # 2: Boeing confirms cyberattack, global services disrupted (14:34) - Story # 3: Four dozen countries declare they won’t pay ransomware ransoms (15:26) - Story # 4: https://www.healthcareinfosecurity.com/feds-levy-first-ever-hipaa-fine-for-ransomware-data-breach-a-23448 (27:08) - Story # 5: “This vulnerability is now under mass exploitation.” Citrix Bleed bug bites hard (30:52) - Story # 6: 3,000 Apache ActiveMQ servers vulnerable to RCE attacks exposed online (32:03) - Story # 7: Exploit released for critical Cisco IOS XE flaw, many hosts still hacked (33:28) - Story # 7b: Cisco IOS XE CVE-2023-20198: Deep Dive and POC (42:38) - Story # 8: SEC charges SolarWinds CISO with fraud for misleading investors before major cyberattack

Nov 10, 202359 min

Ep 1Talkin’ About Infosec News – 11/09/2023

The post Talkin’ About Infosec News – 11/09/2023 appeared first on Black Hills Information Security. (00:00) - PreShow Banter™ — Costume Party (02:04) - BHIS - Talkin' Bout [infosec] News 2023-10-30 (03:24) - Story # 1: Okta cybersecurity breach wipes out more than $2 billion in market cap (18:43) - Story # 2: Boeing assessing Lockbit hacking gang threat of sensitive data leak (26:09) - Story # 3: The AI-Generated Child Abuse Nightmare Is Here (41:37) - Story # 4: MGM Resorts hackers 'one of the most dangerous financial criminal groups’

Nov 9, 202359 min

Ep 1Talkin’ About Infosec News – 11/4/2023

The post Talkin’ About Infosec News – 11/4/2023 appeared first on Black Hills Information Security. (00:00) - PreShow Banter™ — Pre-Con-Crud (01:49) - BHIS - Talkin' Bout [infosec] News 2023-10-23 (04:33) - WWHF 2023 recap (12:20) - Story # 1: Mysterious APT compromises Asian government's secure USBs (16:13) - Story # 2: CIA exposed to potential intelligence interception due to X's URL bug (20:02) - Story # 3: EPA withdraws cyber audit requirement for water systems (22:54) - Story # 3b: Florida Water Treatment Plant Hit With Cyber Attack (27:00) - Story # 4: Thousands of remote IT workers sent wages to North Korea to help fund weapons program, FBI says (33:10) - Story # 5: Okta says its support system was breached using stolen credentials (37:13) - Story # 6: Casio discloses data breach impacting customers in 149 countries (41:44) - Story # 7: Ragnar Locker ransomware’s dark web extortion sites seized by police (44:02) - Story # 7b: Ragnar Locker ransomware developer arrested in France (46:54) - Story # 8: Flipper Zero can be used to crash iPhones running iOS 17, but there's a way to foil the attack (50:42) - Story # 9: U.S. Government Releases Popular Phishing Technique Used by Hackers (53:39) - Story # 10: Selfie-scraper, Clearview AI, wins appeal against UK privacy sanction

Nov 4, 202358 min

Ep 1Talkin’ About Infosec News – 10/10/23

The post Talkin’ About Infosec News – 10/10/23 appeared first on Black Hills Information Security. (00:00) - PreShow Banter™ — Canadian Bacon Day (04:35) - BHIS - Talkin' Bout [infosec] News 2023-10-09 (06:19) - Story # 1: NSA and CISA reveal top 10 cybersecurity misconfigurations (13:35) - Story # 1b: NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations (21:21) - Story # 2: QR codes in emails? Watch out - it could be part of a 'Quishing' scam (25:07) - Story # 2b: https://github.com/jocephus/QuellR (28:16) - Story # 2c: https://twitter.com/vmyths/status/1212201412068818944 (30:47) - Story # 3: New Marvin attack revives 25-year-old decryption flaw in RSA (35:59) - Story # 4: Bounty offered for secret NSA seeds behind NIST elliptic curves algo (38:01) - Story # 5: Rules of engagement issued to hacktivists after chaos (01:02:55) - PROGRAMMING NOTE – WWHF2023

Oct 10, 20231h 3m

Ep 1Talkin’ About Infosec News – 10/9/2023

The post Talkin’ About Infosec News – 10/9/2023 appeared first on Black Hills Information Security. (00:00) - PreShow Banter™ — The Scented Podcast (04:42) - BHIS - Talkin' Bout [infosec] News 2023-10-02 (07:24) - Story # 1: Google assigns new maximum rated CVE to libwebp bug exploited in attacks (24:13) - Story # 2: Progress warns of maximum severity WS_FTP Server vulnerability (31:16) - Story # 3: Sony PlayStation Hack: What We Know So Far About the LAPSUS$ Cyberattack (36:10) - Story # 4: City of Fort Lauderdale loses $1.2 million in phishing scam, police in Florida say (41:42) - Story # 5: FCC announces plans to reinstate net neutrality (52:32) - Story # 6: [New research] Do longer passwords protect you from compromise?

Oct 9, 20231h 7m

Ep 1Special Segment – Cyber Security Career Advice – 9/28/2023

The post Special Segment – Cyber Security Career Advice – 9/28/2023 appeared first on Black Hills Information Security. (00:00) - PreShow Banter™ Segment Special – Cyber Security Career Advice (00:26) - Q :Entry Level Cybersecurity equals Mid-Level I.T. ? (08:05) - Q: How do I get started, I'm new in the Cyber Security Industry? (09:37) - Q: What Degree(s) do you recommend for Cyber Security / Infosec? (16:07) - Q: How did Chris Traynor join Black Hills Information Security? (18:58) - LINK– Pancake Con Chris Traynor Talk - https://youtube.com/watch?v=tMgDSb5_mKs (20:13) - LINK - BHIS Discord - https://discord.gg/bhis (23:35) - LINK - Chicago meetups : https://burbsec.com (25:53) - LINK: YouTube– Acess Granted Webcast – https://youtube.com/live/oaTEK9Feo5s

Sep 28, 202326 min

Ep 1Talkin’ About Infosec News – 9/25/2023

The post Talkin’ About Infosec News – 9/25/2023 appeared first on Black Hills Information Security. (00:00) - PreShow Banter™ — Poop Shoots and Chocolate Bunnies (02:33) - BHIS - Talkin' Bout [infosec] News 2023-09-25 (07:15) - Story # 1: Cisco to Acquire Splunk (08:15) - CISCO RSA Plane https://assets-cdn.workingnotworking.com/a1w71r9as47v5iap49d6u2md0dfr (09:21) - Jack Rhysider on Splunk https://twitter.com/JackRhysider/status/1704986407415038213 (18:09) - Story # 2: Youth hacking ring at the center of cybercrime spree (26:45) - Story # 3: T-Mobile users say other people’s account information is appearing in their app (30:11) - Story # 4: Okta: Caesars, MGM hacked in social engineering campaign (35:40) - Story # 5: Data breach reveals distressing info: People who order pineapple on pizza (39:28) - Story # 6: National Student Clearinghouse data breach impacts 890 schools (46:16) - Story # 7: Kroll Suffers Data Breach: Employee Falls Victim to SIM Swapping Attack

Sep 27, 20231h 4m

Ep 1Talkin’ About Infosec News – 9/18/2023

The post Talkin’ About Infosec News – 9/18/2023 appeared first on Black Hills Information Security. (00:00) - PreShow Banter™ — Billionare Traps & Dump Lists (05:11) - BHIS - Talkin' Bout [infosec] News 2023-09-18 (07:28) - Story # 1: Statement on MGM Resorts International (12:06) - Story # 1b: Okta & MGM sitting in a tree (14:53) - Story # 1c: Okta Agent Involved in MGM Resorts Breach, Attackers Claim (20:26) - Story # 1d: Social Engineering: How It Works, Examples & Prevention (26:49) - Story # 1e: Lina Khan Got Stuck in the Fallout of the MGM Hack at Las Vegas (44:09) - Story # 2: F-35 goes missing near North Charleston; pilot hospitalized after ejecting (48:38) - Story # 3: Pirated Software Likely Cause of Airbus Breach (53:48) - (K)night (I)ndustries (T)esla (T)hree opens parking garage gate

Sep 22, 20231h 2m

Ep 1Talkin’ About Infosec News – 9/11/2023

The post Talkin’ About Infosec News – 9/11/2023 appeared first on Black Hills Information Security. (00:00) - PreShow Banter™ — Felling Trees 504 (02:03) - Talkin' Bout [infosec] News 2023-09-11 (05:51) - 22nd Anniversary of the 9-11 Tragedy (10:35) - Story # 1: AT&T Customers Doxed Themselves En Masse In Reply-All Nightmare (15:47) - Story # 1b: Senate email system crashes amid avalanche of reply-alls to security test (18:09) - Story # 2: Millions Infected by Spyware Hidden in Fake Telegram Apps on Google Play (23:47) - Story # 2b: BLASTPASS NSO Group iPhone Zero-Click, Zero-Day Exploit Captured in the Wild (29:16) - Story # 3: Apple finally admits the CSAM scanning flaw we all pointed out (33:32) - Story # 4: Outlook Hack: Microsoft Reveals How a Crash Dump Led to a Major Security Breach (38:57) - Story # 4b: Microsoft finally explains cause of Azure breach: An engineer’s account was hacked (51:16) - Story # 5: FBI, Partners Dismantle Qakbot Infrastructure in Multinational Cyber Takedown — FBI (52:24) - Story # 5b: Data From The Qakbot Malware is Now Searchable in Have I Been Pwned, Courtesy of the FBI (57:49) - https://github.com/alephdata/aleph

Sep 13, 20231h 3m

Ep 1Talkin’ About Infosec News – 8/28/2023

Brought to you by Antisyphon Training — https://www.antisyphontraining.com (00:00) - PreShow Banter™ — Deep Disruptions (04:01) - BHIS - Talkin' Bout [infosec] News 2023-08-28 (05:43) - Story # 1: Exclusive: Cybersecurity firm SentinelOne explores sale -sources (13:28) - Story # 2: WinRAR 0-day that uses poisoned JPG and TXT files under exploit since April (20:17) - Story # 3: NIST Publishes Draft Post-Quantum Cryptography Standards (23:29) - Story # 4: Mysterious Cyberattack Shuts Down Yet More Telescopes For Weeks (29:31) - Story # 5: Danish cloud host says customers ‘lost all data’ after ransomware attack (35:04) - Story # 6: Lapsus$: Court finds teenagers carried out hacking spree (35:45) - Story # 6b: GTA 6 Hacker Found To Be Teen With Amazon Fire Stick In Small Town Hotel Room (44:36) - Story # 7: New Juniper Junos OS Flaws Expose Devices to Remote Attacks - Patch Now

Aug 30, 202357 min

Ep 1Talkin’ About Infosec News – 8/21/2023

Brought to you by Antisyphon Training — https://www.antisyphontraining.com (00:00) - PreShow Banter™ — Overarching Hot Takes (01:27) - BHIS - Talkin' Bout [infosec] News 2023-08-21 (04:30) - Story # 1: Hackers red-teaming A.I. are ‘breaking stuff left and right,’ but don’t expect quick fixes from DefCon: ‘There are no good guardrails’ (06:18) - Story # 1b: What happens when thousands of hackers try to break AI chatbots (08:46) - Story # 2: US lawmaker says FBI notified him of email breach linked to Microsoft cloud hack (11:18) - Story # 3: Elon Musk's army of inactive followers paints a bleak picture of X as a whole (12:42) - Story # 3b: Elon Musk’s Shadow Rule (18:45) - Story # 4: Haggling With Hackers: Surprising Lessons From 50 Negotiations With Ransomware Gangs (23:42) - Story # 5: WinRAR flaw lets hackers run programs when you open RAR archives (27:55) - Story # 6: CISA, experts warn of Citrix vulnerabilities being exploited by hackers (29:44) - Story # 7: Ongoing Duo outage causes Azure Auth authentication errors (30:38) - Story # 8: Phishing campaign steals accounts for Zimbra email servers worlwide (35:48) - Story # 9: WD refused to answer our questions about its self-wiping SanDisk SSDs (38:35) - Story # 9b: Backblaze Drive Stats for Q2 2023 (42:07) - Story # 10: NYC Bans TikTok on City Devices (55:38) - Story # 11: IMAX Still Runs on PalmPilot Operating System (57:25) - Story # 12: Major LinkedIn Account Takeover Campaign Underway

Aug 28, 202359 min

Ep 1Talkin’ About Infosec News – 8/14/2023

Aug 21, 20231h 1m

Ep 1Talkin’ About Infosec News – 8/7/2023

Aug 15, 202359 min