PLAY PODCASTS
The 443 - Security Simplified

The 443 - Security Simplified

388 episodes — Page 6 of 8

S2021 Ep 138Hacked by Cosmic Rays

This week on the podcast we cover Gootkitand Gootloader, two oddly-named pieces of an evasive trojan that researchers have been watching evolve into a fileless threat. We also discuss the security benefits and drawbacks of Apple's closed-door approach to security. Finally, we end with some research on what happens when a cosmic ray causes your computer to load up the wrong destination for a network connection.

Mar 9, 202139 min

S2021 Ep 137Microsoft Says “Regulate Us”

This week on the podcast we cover an upcoming Chrome browser update with important behind-the-scenes changes, a 9.8/10 severity vulnerability in VMWare vCenter, and a plea from Microsoft for more breach disclosure regulation in the wake of the SolarWinds breaches.

Mar 3, 202136 min

S2021 Ep 136RIPE for the Taking

This week on the podcast, we chat about an authentication attack against one of the world’s internet address registrars, another Russian threat actor targeting a popular IT software company, and research on a credential theft trojan and its delivery methods.

Feb 24, 202131 min

S2021 Ep 135So Confused

This week on The 443, we cover a cyber-attack against the water supply of a small Florida town and research into a new class of vulnerabilities in software libraries called Dependency Confusion.

Feb 18, 202130 min

S2021 Ep 134CacheFlow

This week on the podcast, we cover the latest research from Avast on evasion techniques in use by malicious Chrome extensions. After that, we discuss the latest report from Google's Threat Analysis Group on nation-state threat actors targeting white hat security researchers.

Feb 11, 202131 min

S2021 Ep 133It’s Always DNS

This week on the podcast, we bring on Trevor Collins from the WatchGuard Threat Lab to chat about a the recently disclosed MalwareBytes breach and a series of vulnerabilities in a popular DNS forwarder, dubbed DNSPOOQ.

Jan 26, 202145 min

S2021 Ep 132AppleScryptominers

This week on the podcast, we cover a cloud security alert courtesy of Cybersecurity & Infrastructure Security Agency (CISA) and encrypted DNS guidance from the NSA. We also discuss a macOS malware evasion technique that has eluded analysis for over 5 years, until now.

Jan 19, 202135 min

S2021 Ep 131The Hack of the Decade

This week on the podcast we dive into what will likely be remembered as the hack of the decade. With victims including dozens of Fortune 500 companies and US Federal agencies, the SolarWinds supply chain breach has had a massive impact on the industry and as the potential to change client/vendor trust relationships going forward.

Jan 11, 202140 min

S2020 Ep 130Biohacking with Amal Graafstra Rewind

Happy Holidays! This week on the podcast, we're going back to one of our favorite episodes from 2019 where we sat down with Biohacking pioneer Amal Graafstra to discuss implants, RFID technology and the future of human/technology interactions.

Dec 28, 202045 min

S2020 Ep 1292021 Security Predictions

This week on the podcast, we jump in to WatchGuard Threat Lab's 2021 security predictions. From automated spear phishing to booby-trapped electric vehicle chargers, we'll discuss each of the 8 predictions we made and why we made them. You can read about the predictions in full at watchguard.com/predictions.

Dec 7, 202033 min

S2020 Ep 1282020 Predictions Recap

Every November, WatchGuard Threat Lab tries to make predictions about potential security events in the coming year. While some predictions might come off as a bit extreme, they're all grounded in actual trends that we see and expect to continue. With 2020 almost under wraps, its time for us to look back to the predictions we made one year ago and grade ourselves on how well we did.

Nov 30, 202033 min

S2020 Ep 127Securing SMBs with John Grady

This week on the podcast, we sit down with ESG Analyst John Grady again, this time to chat about the topic of SMB Security. We'll cover how the cyber threat landscape has changed throughout 2020 and what SMBs got right, and wrong when it came to adapting.

Nov 23, 202031 min

S2020 Ep 126Getting SASE with John Grady

This week on the podcast we sit down with John Grady, analyst at Enterprise Strategy Group, to break down the latest industry industry terms Secure Access Service Edge (SASE) and Zero Trust Network Access (ZTNA). We'll dive in to exactly what they encompass and then get John's thoughts on where they stand in small and medium enterprises.

Nov 16, 202033 min

S2020 Ep 125Packaged Attacks

This week on the podcast we discuss a previously unsolved mystery from the dark web that was just solved with a little help from the IRS. We'll then discuss the growing issue of malicious opensource packages and libraries after researchers last week discovered a malicious package masquerading as a popular communications service.

Nov 9, 202020 min

S2020 Ep 124Healthcare Hacking

This week on the podcast, we'll discuss an alert from US-CERT and the FBI that details an "imminent threat" to hospitals and other healthcare facilities, as well as some recently disclosed critical vulnerabilities in a popular healthcare records software. After that, we'll give you your (hopefully) last dose of election security news with some election related hacking from the past week.

Nov 2, 202050 min

S2020 Ep 123Top Election Security Threats

With the US elections only a week away, we're talking election security on this week's episode. We'll cover what we do and don't think attackers will target in the coming week and what we can do as a country to improve our security posture.

Oct 29, 202038 min

S2020 Ep 122Trickbot Takedown

This week on the podcast, we discuss the latest round of indictments against foreign intelligence agents for cyber espionage. After that, we cover a Microsoft-lead coalition that has so far made a significant impact in taking down the infrastructure behind one of the largest active botnets. Finally, we highlight key takeaways from the latest Google Threat Analysis Group update on foreign hacking efforts.

Oct 22, 202025 min

S2020 Ep 121Android Ransomware Evolution

This week on The 443, we cover research from Microsoft's security team on a new Android ransomware variant that gets around Google's latest protections. We also cover a UEFI malware loader discovered by Kaspersky and the US Department of Justice's actions against a popular video game console mod chip manufacturer.

Oct 12, 202042 min

S2020 Ep 120ZeroLogon

This week on the podcast we circle back to cover a critical vulnerability in Windows Server, that could allow an attacker to obtain the keys to the kingdom with minimal effort. After that, we discuss a pair of alerts from the US Department of Treasury Office of Foreign Assets Control and Financial Crimes Enforcement Network on the topic of ransomware payments.

Oct 5, 202033 min

S2020 Ep 119Q2 2020 Internet Security Report

This week on the podcast, we cover the latest internet security report from WatchGuard Threat Lab. We'll go over the key takeaways from the Q2 2020 report including malware and network attacks that targeted WatchGuard customer networks. Before that though, we'll discuss an alert from the US Cybersecurity and Infrastructure Security Agency (CISA) that detailed a successful cyber attack against an unnamed federal agency.

Sep 28, 202033 min

S2020 Ep 118Combating Disinformation with Nina Jankowicz

This week on The 443 – Security Simplified, we sit down for a chat on disinformation with Nina Jankowicz, author of How to Lose the Information War. From the US to Estonia, we’ll discuss how nation states are weaponizing social discussion against their adversaries to sow discord and advance their own influence and agenda, in some cases without even having to pick a side.

Sep 21, 202051 min

S2020 Ep 117Election Security Update

This week on the podcast, we cover the city of Portland's ban on facial recognition technology for both public and private organizations, malware targeting VOIP soft switches, and an update from Microsoft on foreign hacking attempts into entities involved in this year's US elections.

Sep 14, 202034 min

S2020 Ep 116Snowden Vindication?

This week on the podcast we cover an update on the MYSTIC surveillance platform, one of several covert and potentially illegal spying programs that former NSA contractor Edward Snowden leaked the existence of in 2014. Additionally, we'll discus an update on the payment card skimming malware MageCart and a Python Remote Access Trojan. Episode Note: Yes, we posted this episode a bit late but we'll be back to our normal Monday episodes next week!

Sep 10, 202039 min

S2020 Ep 115Uber Cover Up

This week on the podcast we cover the latest updates on Uber’s cover up of their 2016 data breach that impacted 57 million customers and employees. After that, we discuss a DDoS attack against the New Zealand Stock Exchange and an interesting malware delivery technique that researchers at ProofPoint recently disclosed.

Aug 31, 202034 min

S2020 Ep 114AI Bloggers

This week on the podcast, we cover Generative Pre-trained Transformer 3 or GPT-3, an AI model that a UC Berkeley student recently used to generate blog posts that fooled humans enough to propel one of them to the top of Hacker News. Additionally, we'll discuss a P2P botnet that has been targeting SSH servers on the internet.

Aug 24, 202044 min

S2020 Ep 113The Dark Web Rewind

This week on the podcast, we’re bringing back a favorite episode from the very beginnings of The 443 – Security Simplified where we dove in to the Dark Web and discussed how It works, where it came from, and who uses it now. This episode originally aired in 2018.

Aug 17, 202032 min

S2020 Ep 112BlackHat 2020 Recap

With BlackHat’s online-only 2020 edition conference in the bag we take a look back at a few of our favorite briefings and discuss the takeaways as they apply to our industry. From a penetration test gone wrong to what security professionals can learn from an EMT, we cover the best talks from this year’s event.

Aug 10, 202053 min

S2020 Ep 111BlackHat and DEF CON Online

With the Black Hat and DEF CON security conferences starting this week, albeit in an online-only mode, we decided to take a look through this year’s agenda and pick some of the talks we are most looking forward to. We’ve picked out talks ranging from new research to updates on recent vulnerabilities to discuss on this week’s episode. Be sure to check out defcon.org this weekend since the conference is entirely free this year.

Aug 3, 202040 min

S2020 Ep 110Meowing Databases

This week on The 443 – Security Simplified we discuss yet another alert from the UK National Cyber Security Center, this time on cyber-attacks targeting sporting organizations. We also take a quick dive into Meowing, a wave of destructive hacking that’s been targeting exposed databases online. Finally, with only a few weeks to go before the online-only editions of Black Hat and DEF CON, we chat about our annual Capture the Flag contest and how to participate this year. fls bxeu ee [[auyfj-8o1z1p9hq7]]

Jul 27, 202036 min

S2020 Ep 109Twoops

This week on The 443 – Security Simplified we cover a massive security breach at Twitter that resulted in an attacker taking over dozens of high-profile accounts ranging from former presidents to Apple. We also discuss the latest Microsoft patch Tuesday which included a fix for a critical security vulnerability in Windows DNS Server.

Jul 20, 202036 min

S2020 Ep 108Can We Trust Facial Recognition?

Welcome back to another episode of The 443 – Security Simplified. This week in the news, we cover an open source vulnerability scanner from Google and phishing campaign that combines Microsoft 365 and Zoom. After that, we dive in to the world of facial recognition and discuss recent research from WatchGuard Threat Lab and other concerns about the technology.

Jul 13, 202041 min

S2020 Ep 107Don’t Trust the App

This week on The 443 – Security Simplified, we discuss the latest out-of-band security patch from Microsoft solving two potentially serious vulnerabilities, a cryptocurrency phishing campaign that made its way on to the Google Play app store, and a neat way that payment card skimming malware hide’s its malicious code.

Jul 6, 202033 min

S2020 Ep 106Q1 2020 Internet Security Report

It’s that time of year again! This week on The 443 we cover the latest internet security report from the WatchGuard Threat Lab. In this episode, we’ll cover the stats and key findings from threat intelligence gathered from over 44,000 security appliances deployed across the world.

Jun 29, 202054 min

S2020 Ep 105A New DDoS Record

This week on The 443 – Security Simplified, we discuss a new DDoS throughput record as reported by Amazon in their AWS Shield Therat Landscape Report for Q1 2020 as well as a history of reflective amplification DDoS attacks. Before that though, we cover an interesting macOS Gatekeeper bypass that involves a bit of social engineering and the latest Intel CPU technology that just might make ROP chains a thing of the past. macOS Gatekeeper bypass - https://www.intego.com/mac-security-blog/new-mac-malware-reveals-google-searches-can-be-unsafe/ Intel Tiger Lake CET - https://newsroom.intel.com/editorials/intel-cet-answers-call-protect-common-malware-threats/ AWS DDoS Record - https://aws-shield-tlr.s3.amazonaws.com/2020-Q1_AWS_Shield_TLR.pdf

Jun 22, 202055 min

S2020 Ep 104Section 230

This week on The 443 – Security Simplified we’re taking a break from the news to talk about a cornerstone of the modern internet, Title 47, Section 230 of the US code, also known as the safe harbor provisions. These laws, which are critical for a free and open internet, have been increasingly under attack in recent months by politicians in the United States from both major political parties. That is why we’re focusing an entire episode exactly what these laws protect and how they came to be.

Jun 15, 202023 min

S2020 Ep 103Nuclear Ransomware

This week on The 443 – Security Simplified, we cover a story from Cloudflare on cyber-attacks targeting activists, APTs targeting political campaigns, and ransomware targeting nuclear missile contractors.

Jun 11, 202036 min

S2020 Ep 102Sandworm Situation

This week on The 443 – Security Simplified we cover an NSA alert on the Russian government-backed hacking group known as Sandworm. After that, we discuss the latest findings from Google’s Threat Analysis Group and what OpenSSH’s deprecation of SHA-1 means to servers everywhere.

Jun 1, 202040 min

S2020 Ep 101Unemployment Fraud

This week on The 443 – Security Simplified, we cover the latest Google Chrome update, another airline data breach, and a wave of unemployment affecting residents of Washington State and possibly elsewhere.

May 26, 202039 min

S2020 Ep 100Centennial

This week is a very special week for The 443 – Security Simplified, our 100th episode! To celebrate, we’ve combed through our last 99 shows and picked out several stories and topics that we’ve discussed which have updates. In this episode, we’ll bring you up to speed with these topics and then highlight the latest developments.

May 20, 202028 min

S2020 Ep 99Toasters and Proxies

This week on The 443 – Security Simplified we cover the latest in cyber security news including a sneaky payment card skimming malware delivery method, a multinational alert on APTs targeting healthcare, and the latest research on remote access vulnerabilities.

May 11, 202029 min

S2020 Ep 98Random Name Generator

This week on The 443 – Security Simplified, we cover the latest in questionably-named nation state hacking, a crackdown on Chrome extensions, and an actively in-development android Trojan.

May 4, 202028 min

S2020 Ep 97You’ve Got Mail [App Vulns]

Welcome back to another episode of The 443 – Security Simplified. This week, we cover the latest security news including over 160,000 compromised Nintendo accounts, nation state hacking, and a battle over a critical Apple iOS vulnerability.

Apr 27, 202030 min

S2020 Ep 96xHelper xUpdate

This week on The 443 – Security Simplified, we cove the latest news stories including yet another security incident involving the video conferencing software Zoom, the effects of the COVID-19 epidemic on cyber-attack trends, and the latest update on the “unkillable” android malware xHelper.

Apr 20, 202025 min

S2020 Ep 95Talking Remote Working with Cat Murdock

This week, we have a special episode of The 443 – Security Simplified where we sit down with a penetration testing and general security expert Cat Murdock of GuidePoint Security to discuss how the COVID-19 pandemic and the rapid shift to working from home has changed the security landscape. You can follow Cat on Twitter @catmurd0ck and check out her latest work at GuidePoint Security here.

Apr 13, 20201h 8m

S2020 Ep 94Zoom Zoom

Welcome back to another episode of The 443 – Security Simplified. Chances are by now you’ve been invited to join a Zoom meeting by someone in your work or personal life. Chances are, you’ve also probably noticed the deluge of attention Zoom has been receiving in terms of vulnerability research in the past few weeks. That’s why in this episode, we’re talking all about Zoom including our takes on its latest vulnerabilities and how to have a secure meeting safe from Zoom Bombing.

Apr 6, 202030 min

S2020 Ep 94Q4 2019 Internet Security Report Recap

It’s the end of the quarter which means it’s time for another special edition of The 443 – Security Simplified where we discuss the latest Internet Security Report from WatchGuard Threat Lab. In this episode, we’ll cover the top security trends from Q4 2019 and defensive tips for keeping your organization safe from the latest threats.

Mar 31, 202055 min

S2020 Ep 92Securing Remote Workers

Welcome back to another episode of The 443 – Security Simplified. With the COVID-19 pandemic forcing anyone and everyone who can work from home to work from home, many organizations are having to rapidly create remote worker policies and infrastructure for the first time. This week, we cover the latest news before diving in to a discussion on securing a mobile workforce.

Mar 23, 202037 min

S2020 Ep 91Phishing for Viruses

Welcome back to another episode of The 443 – Security Simplified. This week, we cover an emergency patch from Microsoft, a massive botnet takedown, and the latest in COVID-19-related phishes.

Mar 16, 202026 min

S2020 Ep 91RSA 2020 – Day 3 Recap

Welcome to our third and final special RSA 2020 edition of The 443 – Security Simplified. On this episode, we cover the talks we saw on the third day of RSA, ranging from web browser fingerprinting to detecting shadow IT in your organization.

Feb 28, 202027 min

S2020 Ep 90RSA 2020 – Day 2 Recap

Welcome back to another special edition episode of The 443 – Security Simplified. On this episode, we recap day 2 of RSA Conference in San Francisco. We’ll talk about several IoT topics, security vs privacy tradeoffs, and some research into gift card APIs by a 15 year old.

Feb 27, 202030 min