TrustedSec Security Podcast: Recent Episodes

TrustedSec

A podcast dedicated to bringing the latest news on information security and the industry - from those that work in the industry.

View Details

In this episode, Geoff and Skyler dive deep into hardware hacking with Rob Simon! Rob is the Mobile and Hardware Security Practice Lead at TrustedSec and shares the deets on hardware security assessments. The importance of hardware fundamentals in security, especially when it comes to IoT devices, is one of the key takeaways this week.

Rob answers questions like: Who needs hardware assessments? What tools and techniques are used? And what potential vulnerabilities are associated with IoT devices?

Join us for great discussion, stay for the lolz, and clutch your Flipper Zeros tight!

About this podcast:

Security Noise, a TrustedSec Podcast hosted by Geoff Walton and Producer/Contributor Skyler Tuter, features our cybersecurity experts in conversation about the infosec topics that interest them the most. Hack the planet!

View Details

Yeehaw 🤠 This week, Skyler is reporting from the ground in Deadwood, South Dakota at Wild West Hackin'​ Fest and sits down for an interview with Senior Security Consultant Travis Kaun about the talk he gave there. Our guest Senior Security Consultant Kelsey Segrue, who attended the conference for the first time, chats with Geoff and Skyler about her most memorable moments from her native voyage to Deadwood.

About this podcast:

Security Noise, a TrustedSec Podcast hosted by Geoff Walton and Producer/Contributor Skyler Tuter, features our cybersecurity experts in conversation about the security topics that interest them the most.

View Details

Let's talk about Threat Hunting! On this episode of Security Noise, Geoff and Skyler are joined by Principal Security Consultants Shane Hartman and Justin Vaicaro to discuss the essential components of a successful Threat Hunting program. But where do you start and how do you access the best resources? Listen as they share insights on building an effective program, operationalizing practices, and the importance of a proactive mindset.

About this podcast:

Security Noise, a TrustedSec Podcast hosted by Geoff Walton and Producer/Contributor Skyler Tuter, features our cybersecurity experts in conversation about the security topics that interest them the most.

View Details

In this episode of Security Noise, we focus on Cloud Security Testing. Our guest , Security Consultant Edwin David, discusses current objectives for securing the cloud, tools for cloud testing, and the challenges of multi-cloud and hybrid environments.

Key takeaways include:

-The importance of MFA and conditional access

-The need for strong password protection

-The lack of a unified toolset for cloud testing

-The complexities and security implications of multi-cloud and hybrid environments.

About this podcast: Security Noise, a TrustedSec Podcast hosted by Geoff Walton and Producer/Contributor Skyler Tuter, features our cybersecurity experts in conversation about the security topics that interest them the most. Listen and subscribe wherever you get your podcasts!

View Details

This week on Security Noise, we talk about "Hacker Summer Camp" also known as DEF CON and BlackHat in Las Vegas. We chat with Senior Security Consultants Luke Bremer and Aaron James, who both attended for the first time, about initial impressions and takeaways from the cons and Vegas itself.

About this podcast: Security Noise, a TrustedSec Podcast hosted by Geoff Walton and Producer/Contributor Skyler Tuter, features our cybersecurity experts in conversation about the security topics that interest them the most. Listen and subscribe wherever you get your podcasts!

View Details

On this episode of Security Noise, we discuss the recent CrowdStrike incident with our guests: Director of Advisory Innovation Rockie Brockway and Managing Director of Remediation Services Paul Sems. The incident occurred on July 19, 2024, when a CrowdStrike security platform update caused a large number of Windows platforms to fail to boot, resulting in the largest IT outage in history. We also touch on patch management and the balance between speed and risk. What is the potential for future attacks targeting kernel-level drivers? What can you expect from similar attacks in the future? Listen now as we cover all this and more on Security Noise!

About this podcast:

Security Noise, a TrustedSec Podcast hosted by Geoff Walton and Producer/Contributor Skyler Tuter, features our cybersecurity experts in conversation about the security topics that interest them the most. Listen and subscribe wherever you get your podcasts!

View Details

In this episode, Geoff and Skyler are joined by special guests Keith Koehne and Matt Miller from Paradigm Cyber Ventures to discuss their mission to integrate cybersecurity into high school industrial tech education. Through this program, teachers at high schools around the U.S. are trained to deliver an in-depth cybersecurity curriculum to their students which introduces them to the field, giving them practical training and readying them for industry exams. The program prepares and empowers students to join the cybersecurity workforce, attend college, or both.

About this podcast:

Security Noise, a TrustedSec Podcast hosted by Geoff Walton and Producer/Contributor Skyler Tuter, features our cybersecurity experts in conversation about the security topics that interest them the most. Listen and subscribe wherever you get your podcasts!

View Details

On this episode of Security Noise, we talk to some veteran network guys to discuss CVE-2024–3661 and other thoughts about VPN security. Geoff and Skyler are joined by Security Consultant Philip DuBois and Principal Security Consultant Justin Bollinger to get their perspective on current issues.

About this podcast:

Security Noise, a TrustedSec Podcast hosted by Geoff Walton and Producer/Contributor Skyler Tuter, features our cybersecurity experts in conversation about the security topics that interest them the most. Listen and subscribe wherever you get your podcasts!

View Details

On this episode, Skyler talks to Principal Security Consultant Drew Kirkpatrick who recently gave a talk at CackalackyCon where he demonstrated new features of his tool, JS-Tap. The tool allows red teams to monitor and attack web applications by rewriting code in the user's browser. Drew introduced a new feature called Mimic, which automates the process of generating custom JavaScript payloads for performing actions as the user in the application. The payloads can be integrated with a Command and Control (C2) system to execute tasks in the user's browser. Drew provided a demo of the tool using a vulnerable WordPress site. JS-Tap is a powerful tool for monitoring and attacking web applications. It allows users to log in and track client activity, including cookies, local storage, and session storage. JS-Tap can intercept form submissions and network communications, making it useful for both monitoring and attacking. It can generate custom payloads and exfiltrate data from the target application. The tool is versatile and can be used for red teaming, penetration testing, and post-exploitation. JS-TAP is available on GitHub and is open source.

Watch the podcast and demo on YouTube here - https://youtu.be/cU915mxLfTo

About this podcast Security Noise, a TrustedSec Podcast, features our cybersecurity experts in conversation about the security topics that interest them the most. Hosted by Geoff Walton and Producer/Contributor Skyler Tuter. Listen and subscribe wherever you get your podcasts!

View Details

In this episode, we discuss state-of-the-art red team testing with Targeted Operations Practice Lead Jason Lang and Director of Security Intelligence Carlos Perez. The conversation is focused on how to extract more value via enhanced cooperation between the red team and the IT Security organization. We conclude with Jason sharing some highlights from his talk "Modern Hackery: A Look At Current Breaches Through An Attacker's Eyes" which will be presented at NolaCon in New Orleans on May 17, 2024.

Show References: https://services.google.com/fh/files/misc/m-trends-2024.pdf

View Details

Join us as we continue our series on developing careers in InfoSec. In this episode, we talk about a unique opportunity for students at Bedford High School in Ohio, a school that is near and dear to TrustedSec Founder and CEO David Kennedy. We chat with Dave about the cybersecurity education program that was launched recently with help from long-time Bedford teacher Darren Pocek and others. Listen to learn how this program was created and how it helps prepare students for careers in cybersecurity.

View Details

Security Noise starts a multi episode look at how to start or grow a career in infoSec. We begin by talking with Senior Security Consultant Kelsey Segrue and Security Consultant Olivia Cate who took what might be considered the traditional route. They share their stories and offer some insights into how to maximize the advantage of similar opportunities.

About this podcast Security Noise, a TrustedSec Podcast, features our cybersecurity experts in conversation about the security topics that interest them the most. Hosted by Geoff Walton and Producer/Contributor Skyler Tuter. Listen and subscribe wherever you get your podcasts!

View Details

On this episode of Security Noise, we are revisiting the topic of open-source intelligence (OSINT) in the wake of the theories spurred by the Royal Family's social media photo that was quickly flagged as being altered. Along with guests, Senior Security Consultants Joe Sullivan and David Boyd, we delve into various theories surrounding the Princess of Wales' controversial Mother's Day photo and the media's subsequential reaction.

Methods for spotting fake images, such as reverse image searches and metadata analysis, are discussed, highlighting the importance of scrutinizing visual content in today's digital age. Additionally, tools like AIornot.com and insights into Twitter/X's handling of metadata add depth to the discussion.

Overall, the episode sheds light on the complexities of image authenticity in the era of digital manipulation and emphasizes the need for critical thinking when consuming visual media.

Security Noise is hosted by Geoff Walton and Producer/Contributor Skyler Tuter.

Links: https://fotoforensics.com https://www.aiornot.com/ https://www.getghiro.org/ https://www.suncalc.org

View Details

It's Leak Week for this episode of Security Noise! Geoff and Skyler chat with Security Consultant Whitney Phillips and Senior Security Consultant Kurt Muhl about a number of recent privacy pitfalls including destructive ransomware groups such as LockBit, leaked government emails, and other data and privacy mishaps.

References:

  1. https://krebsonsecurity.com/2024/02/u-s-internet-leaked-years-of-internal-customer-emails/
  2. https://krebsonsecurity.com/2024/02/feds-seize-lockbit-ransomware-websites-offer-decryption-tools-troll-affiliates/

Security Noise, a TrustedSec podcast, is hosted by Geoff Walton and Producer/Contributor Skyler Tuter in conversation with cybersecurity experts discussing the security topics that interest them the most.

View Details

Skyler and Geoff chat with Senior Security Consultant Joe Sullivan about using open-source intelligence (OSINT) for gathering ideas and information. We discuss some of the ethical questions about what you can do with what you learn.

View Details

Geoff and Skyler talk to Incident Response Practice Lead Tyler Hudak about when you need an IR plan, what kind of relationships you should have with your IR vendor, and what things to know before perusing an IR retainer. The conversation looks at the needs for businesses of various sizes, proposes some self-assessment questions, and concludes with some war stories!

View Details

Geoff and Skyler make bold predictions for 2024 about AI, changes to Air Tags, and Open Source!

LINKS:

https://techcrunch.com/2024/01/04/orrick-law-firm-data-breach/

https://arstechnica.com/security/2023/12/researchers-come-up-with-better-idea-to-prevent-airtag-stalking/

https://www.theregister.com/2023/12/27/bruce_perens_post_open/

View Details

In this very special year-end episode, we're cranking up the heat as we explore some of our favorite InfoSec tools of 2023.

Guest Lineup:

Drew Kirkpatrick - JS-Tap Unleashed

Drew Kirkpatrick is the maestro behind "JS-Tap." He dropped this pentesting bombshell at Wild West Hackin' Fest this year with his talk, "JS-Tap: Weaponizing JavaScript for Red Teams." Skyler snagged an exclusive interview with Drew at the conference and we'll get to hear that discussion on this episode.

Luke Bremer - Hackvertor

Luke Bremer graces our podcast to dive into his blog, "What is Hackvertor (and why should I care?)." Get ready to dive into the use cases of this Burp Suite plugin and how you can utilize it on your next pentest!

Ben Mauch (Ben Ten) - Unveiling Impede

We end our discussion with Ben Mauch, aka @Ben0xA, as he unveils TrustedSec's latest software offering: Impede. Brace yourself for a deep dive into the features and innovations packed into this cybersecurity marvel.

Gather 'round and settle in for our year-end episode of SECURITY NOISE!

View Details

In this episode, we wrap up our 4-part series, "The Road Ahead," with TrustedSec CTO Justin Elze and Targeted Operations Lead Jason Lang as they provide insight into how the targeted operations landscape has evolved for everyone, from client to consultant. We discuss what groups are doing red teaming and what the practice looks like today. Our guests also discuss the impacts of SSO, third-party IDP solutions, and assumed breach strategies.

Get ready to be offensive on this episode of Security Noise!

This episode concludes a short series called "The Road Ahead." Each episode highlights an area of Information Security and features guests who are experts in those areas.

Security Noise is hosted by Geoff Walton and Producer/Contributor Skyler Tuter.

View Details

In this episode, we discuss the evolution of the Internal Penetration Test with two experienced practitioners, David Boyd and Justin Bollinger. We cover how test preparation and planning have changed over the years, how hybrid environments with on-premises and cloud-hosted applications have impacted pen testing, and the effects of Zero Trust and contemporary security models. Of course we'll also talk shop, where we look at the current tools of the trade and what the client-consultant relationship looks like today.

This episode is Part 3 of 4 in a short series called "The Road Ahead." Each episode highlights an area of Information Security and features guests who are experts in those areas.

Come along as we explore the history and future of InfoSec!

Security Noise is hosted by Geoff Walton and Producer/Contributor Skyler Tuter.

View Details

Geoff and Skyler discuss how the defense and vulnerability side of application development and deployment has evolved over the years. They are joined on the panel by two other members of the TrustedSec team, Paul Sems and Mitch Parish, who were there to help and lead organizations through those transitions in their current and prior roles.

This episode is Part 2 of 4 in a short series called "The Road Ahead." Each episode will highlight an area of Information Security and feature guests who are experts in those areas.

Come along as we explore the history and future of InfoSec!

Security Noise is hosted by Geoff Walton and Producer/Contributor Skyler Tuter.

View Details

On this episode of Security Noise, Geoff and Skyler speak with members of the TrustedSec Software Security team to discuss the past, present, and future of AppSec. Security Consultants Joe Sullivan and Philip DuBois and Director of Software Security Scott White weigh in on the evolution of security tools, how engagements have changed, and where AppSec is heading.

This episode is Part 1 of 4 in a short series called "The Road Ahead." Each episode will highlight an area of Information Security and feature guests who are experts in those areas.

Come along as we explore the history and future of InfoSec!

Security Noise is hosted by Geoff Walton and Producer/Contributor Skyler Tuter.

View Details

In this episode, nyxgeek joins us to change your mind about enumeration and federation, Producer Skyler Tuter tells us what happened at DEF CON in Vegas, and we hear from Security Consultant Whitney Phillips about her presentation and augmented reality. Security Noise is hosted by Geoff Walton and Producer/Contributor Skyler Tuter.

View Details

On this episode of Security Noise, we remember the man who changed InfoSec forever—Kevin Mitnick, who recently passed away after a battle with cancer. TrustedSec CEO Dave Kennedy joins in to share some of our favorite stories and memories of Kevin. Security Noise is hosted by Geoff Walton and Producer/Contributor Skyler Tuter.

View Details

This week on Security Noise, we discuss DOs and DON'Ts of Grey-hat work with the practice lead for research at TrustedSEc, Carlos Perez! Security Noise is hosted by Geoff Walton and Producer/Contributor Skyler Tuter.

View Details

Are you afraid of the dark web? In this week's episode, several folks from TrustedSec's consulting team tell infosec campfire stories. Scott White, Kurt Mhul, Philip Dubois, Skyler Tuter, and Geoff Walton share tales of disaster, near disaster, spooky or straight-up funny stories, and discuss how those experiences changed their perspectives on infosec.

View Details

Artificial intelligence is progressing at a quick (and some say alarming) rate. Security Noise returns with a look at Large Language Models (LLMs) as well as AI audio and image generation, exploring emerging possibilities commercial, curious, and malicious. Listen in on the conversation with TrustedSec team members Carlos Perez and Rob Simon as they discuss current topics with host Geoff Walton and Producer/Contributor Skyler Tuter.

View Details

How much of your life is tied up on your phone? This week, Security Noise looks at the client side of mobile security. In this episode, we explore some current topics surrounding mobiles and how you should treat them. Joining us are several folks from the Mobile Security team at TrustedSec: Drew Kirkpatrick, Rob Simon, and Whitney Phillips. Security Noise is hosted by Geoff Walton with Producer/Contributor Skyler Tuter.

View Details

Security Noise kicks off its inaugural episode with host Geoff Walton and Producer/Contributor Skyler Tuter! This week, we discuss cloud transitioning topics with our expert guest panel: Paul Sems, Edwin David, and Phil Rowland. Our guests have a range of perspectives and backgrounds in design, defense, and offensive security. In this episode, we explore the changing roles of IT personnel, where identities live, hybrid environments, DOs and DONTs, and share some stories. 

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Justin Elze, Justin Bollinger, and David Boyd.

Get ahead of the new PCI requirements

PCI 4.0 is coming! Find out how the new requirements will affect your organization’s goals and prepare now, with a PCI DSS assessment from TrustedSec.

Penetration testing the cloud isn’t the same as your network

Go to TrustedSec.com to get our guide on how to get the most out of your cloud penetration test.

Join the TrustedSec Discord Community

TrustedSec is on Discord! Join our server to interact with the security community and the TrustedSec team. Go to discord.gg/trustedsec to join.

Stories

Title: Two U.S. Men Charged in 2022 Hacking of DEA Portal

URL: https://krebsonsecurity.com/2023/03/two-us-men-charged-in-2022-hacking-of-dea-portal/

Author: Brian Krebs

Title: Cancer patient sues hospital after ransomware gang leaks her nude medical photos

URL: https://www.theregister.com/2023/03/15/cancer_lvhn_sues_hospital/?td=rt-3a

Author: Jessica Lyons Hardcastle

The Interview:

Link: https://www.trustedsec.com/blog/critical-outlook-vulnerability-in-depth-technical-analysis-and-recommendations-cve-2023-23397/

Justin Elze, CTO and Director of Research at TrustedSec, talks to us about CVE-2023-23397, covering how TrustedSec investigated and responded as well as where it will land in the penetration tester's toolbox.

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Edwin David, Kelsey Segrue, and Alex Hamerstone.

Get ahead of the new PCI requirements

PCI 4.0 is coming! Find out how the new requirements will affect your organization’s goals and prepare now, with a PCI DSS assessment from TrustedSec.

Penetration testing the cloud isn’t the same as your network

Go to TrustedSec.com to get our guide on how to get the most out of your cloud penetration test.

Join the TrustedSec Discord Community

TrustedSec is on Discord! Join our server to interact with the security community and the TrustedSec team. Go to discord.gg/trustedsec to join.

Stories

Title: You can now run a GPT-3-level AI model on your laptop, phone, and Raspberry Pi

URL: https://arstechnica.com/information-technology/2023/03/you-can-now-run-a-gpt-3-level-ai-model-on-your-laptop-phone-and-raspberry-pi/

Author: Benj Edwards

Title: OWASP Low-Code/No-Code Top 10

URL: https://owasp.org/www-project-top-10-low-code-no-code-security-risks/

Author: OWASP Project

Title: Biden admin’s cloud security problem: ‘It could take down the internet like a stack of dominos’

URL: https://www.politico.com/news/2023/03/10/white-house-cloud-overhaul-00086595

Authors: John Sakellariadis

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Edwin David, David Boyd and Skyler Tuter.

Get ahead of the new PCI requirements

PCI 4.0 is coming! Find out how the new requirements will affect your organization’s goals and prepare now, with a PCI DSS assessment from TrustedSec.

Penetration testing the cloud isn’t the same as your network

Go to TrustedSec.com to get our guide on how to get the most out of your cloud penetration test.

Join the TrustedSec Discord Community

TrustedSec is on Discord! Join our server to interact with the security community and the TrustedSec team. Go to discord.gg/trustedsec to join.

Stories

Title: Hackers Scored Data Center Logins for Some of the World's Biggest Companies

URL: https://www.bloomberg.com/news/features/2023-02-21/hackers-scored-corporate-giants-logins-for-asian-data-centers?leadSource=uverify%20wall

Author: Jordan Robertson

Title: Best Practices for Securing Your Home Network

URL: https://media.defense.gov/2023/Feb/22/2003165170/-1/-1/0/CSI_BEST_PRACTICES_FOR_SECURING_YOUR_HOME_NETWORK.PDF

Author: NSA

Title: US military email server left exposed for 2 weeks, allowing internal emails to leak

URL: https://www.foxnews.com/politics/us-military-email-server-left-exposed-two-weeks-allowing-internal-emails-leak

Authors: Jennifer Griffin, Adam Sabes

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Alex Hamerstone, Whitney Phillips, Skyler Tuter.

Get ahead of the new PCI requirements

PCI 4.0 is coming! Find out how the new requirements will affect your organization’s goals and prepare now, with a PCI DSS assessment from TrustedSec.

Penetration testing the cloud isn’t the same as your network

Go to TrustedSec.com to get our guide on how to get the most out of your cloud penetration test.

Join the TrustedSec Discord Community

TrustedSec is on Discord! Join our server to interact with the security community and the TrustedSec team. Go to discord.gg/trustedsec to join.

Stories

Title: Realtek Vulnerability Under Attack: Over 134 Million Attempts to Hack IoT Devices

URL: https://thehackernews.com/2023/01/realtek-vulnerability-under-attack-134.html?m=1

Author: Ravie Lakshmanan

Title: Extract Actionable Intelligence from Text-based Threat Intel using Sentinel Notebook

URL: https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/what-s-new-extract-actionable-intelligence-from-text-based/ba-p/3729508

Author: Vani Asawa

Title: Dashlane publishes its source code to GitHub in transparency push

URL: https://techcrunch.com/2023/02/02/dashlane-publishes-its-source-code-to-github-in-transparency-push/

Author: Paul Sawers

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Alex Hamerstone, Whitney Phillips, Steven Erwin, and Mitch Parish.

Announcements

Join the TrustedSec Discord Community

TrustedSec is on Discord! Join our server to interact with the security community and the TrustedSec team. Go to discord.gg/trustedsec to join.

Stories

Title: A call to action: Think seriously about “safety”; then do something sensible about it

URL: https://www.open-std.org/jtc1/sc22/wg21/docs/papers/2023/p2739r0.pdf

Author: Bjarne Stroustrup

Title: U.S. airline accidentally exposes ‘No Fly List’ on unsecured server

URL: https://www.dailydot.com/debug/no-fly-list-us-tsa-unprotected-server-commuteair/

Authors: Mikael Thalen, David Covucci

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Justin Bollinger, Scott White, and Scott Nusbaum

Announcements

Join the TrustedSec Discord Community

TrustedSec is on Discord! Join our server to interact with the security community and the TrustedSec team. Go to discord.gg/trustedsec to join.

Stories

Title: Lastpass: Hackers stole customer vault data in cloud storage breach

URL: https://www.bleepingcomputer.com/news/security/lastpass-hackers-stole-customer-vault-data-in-cloud-storage-breach/

Author: Sergiu Gatlan

Title: Android is adding support for updatable root certificates amidst TrustCor scare

URL: https://blog.esper.io/android-14-updatable-certificates/

Author: Mishaal Rahman

Interview

Guest: Scott White

Subject: Planning your Application Tests

View Details

Welcome to the TrustedSec Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Justin Bollinger, Alex Hamerstone, and Skyler Tuter.

Announcements

Join the TrustedSec Discord Community

TrustedSec is on Discord! Join our server to interact with the security community and the TrustedSec team. Go to discord.gg/trustedsec to join.

Stories

Title: FBI, CISA say Cuba ransomware gang extorted $60M from victims this year

URL: https://techcrunch.com/2022/12/02/fbi-cisa-cuba-ransomware

Author: Carley Page

Title: A new analysis urges CISO’s to take strategic steps ahead of the advent of quantum computing.

URL: https://www.nextgov.com/emerging-tech/2021/11/report-china-may-steal-encrypted-government-data-now-decrypt-quantum-computers-later/187020/

Author: Brandi Vincent

Title: Lastpass says hackers accessed customer data in new breach

URL: https://www.bleepingcomputer.com/news/security/lastpass-says-hackers-accessed-customer-data-in-new-breach/?mibextid=Zxz2cZ

Author: Sergiu Gatlan

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Kurt Muhl, Justin Bollinger, and David Boyd

Title: A simple Android lock screen bypass bug landed a researcher $70,000

URL: https://techcrunch.com/2022/11/14/android-lock-screen-bypass-google-pixel/

Author: Zack Whittaker

Title: NSA Releases Guidance on How to Protect Against Software Memory Safety Issues

URL: https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/3215760/nsa-releases-guidance-on-how-to-protect-against-software-memory-safety-issues/

Author: NSA

Title: Flight Radar Report Shows FTX Co-Founder's Private Jet Flew to Argentina, SBF Says He's Still in the Bahamas

URL: https://news.bitcoin.com/flight-radar-report-shows-ftx-co-founders-private-jet-flew-to-argentina-sbf-says-hes-still-in-the-bahamas/?fbclid=IwAR3iBvfrTl471Im9-OFdhuaoaBiJuG8PF8TFwcGtBO_8tf4SL_cWMAsO43g

Author: Jamie Redman

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Alex Hamerstone, Joe Sullivan, and Whitney Phillips.

Announcements

Join the TrustedSec Discord Community

TrustedSec is on Discord! Join our server to interact with the security community and the TrustedSec team. Go to discord.gg/trustedsec to join.

Stories

Title: Security certification body (ISC)² defends ‘undemocratic’ bylaw changes

URL: https://portswigger.net/daily-swig/security-certification-body-isc-defends-undemocratic-bylaw-changes

Author: Emma Woollacott

Title: Chrome will finally force you to upgrade from Windows 7 in 2023

URL: https://www.androidpolice.com/chrome-windows-7-support/

Author: Stephen Schenck

Tool Time

Link: https://portswigger.net/burp/dastardly

Dastardly TL:DL

docker run --user $(id -u) --rm -v $(pwd):/dastardly -e \ DASTARDLY_TARGET_URL=https://ginandjuice.shop -e \ DASTARDLY_OUTPUT_FILE=/dastardly/dastardly-report.xml \ public.ecr.aws/portswigger/dastardly:latest

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Justin Bollinger, Luke Bremer, and Whitney Phillips.

Stories

Title: No fix in sight for mile-wide loophole plaguing a key Windows defense for years

URL: https://arstechnica.com/information-technology/2022/10/no-fix-in-sight-for-mile-wide-loophole-plaguing-a-key-windows-defense-for-years/

Author: Dan Goodin

Title: Intel's Alder Lake BIOS Source Code Reportedly Leaked Online

URL: https://www.tomshardware.com/news/intels-alder-lake-bios-source-code-reportedly-leaked-online

Author: Paul Alcorn

Live-ish From GrrCon

Our panel discusses their experience at GrrCon 2022 so far. Luke mentions some research into recovering old botnets ("Botnets Don't Die") by Aamir Lakhani. 

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Scott White, Justin Bollinger, and Patrick Mayo.

Stories

URL: https://www.bleepingcomputer.com/news/security/lastpass-says-hackers-had-internal-access-for-four-days/?mibextid=d3iphx

Author: Sergiu Gatlan

Title: Microsoft Edge and Google Chrome enhanced spellcheck feature exposes passwords

URL: https://www.neowin.net/news/microsoft-edge-and-google-chrome-enhanced-spellcheck-feature-exposes-passwords/

Author: Steve Bennett

Title: AttachMe: critical OCI vulnerability allows unauthorized access to customer cloud storage volumes

URL: https://www.wiz.io/blog/attachme-oracle-cloud-vulnerability-allows-unauthorized-cross-tenant-volume-access

Author: Elad Gabay

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Skyler Tuter, Alex Hamerstone, and David Boyd.

Stories

Title: Google Chrome Emergency Update Fixes New Zero-Day Used in Attacks

URL: https://www.bleepingcomputer.com/news/security/google-chrome-emergency-update-fixes-new-zero-day-used-in-attacks/

Author: Sergiu Gatlan

Title: IRS says it exposed some confidential taxpayer data on website

URL: https://www.marketwatch.com/story/irs-says-it-exposed-some-confidential-taxpayer-data-on-website-11662148381

Author: Richard Rubin

View Details

SHOW NOTES

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Steve Erwin, Alex Hamerstone, and Melvin Langvik.

Stories

Title: PayPal Phishing Scam Uses Invoices Sent Via Paypal

URL: https://krebsonsecurity.com/2022/08/paypal-phishing-scam-uses-invoices-sent-via-paypal/

Author: Brian Krebs

Title: Hyundai Uses Example Keys for Encryption System

URL: https://www.theregister.com/2022/08/17/software_developer_cracks_hyundai_encryption/

Author: Thomas Claburn

The Interview

Melvin Langvik talks TeamFiltration

URL: https://github.com/Flangvik/TeamFiltration

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Steve Erwin, Justin Bollinger, and Skyler Tuter.

Stories

Title: New Gmail Attack Bypasses Passwords And 2FA To Read All Email

URL: https://www.forbes.com/sites/daveywinder/2022/08/02/gmail-warning-as-new-attack-bypasses-passwords--2fa-to-read-all-email/?sh=711642763a12

Author: Davey Winder

Title: Post-quantum encryption contender is taken out by single-core PC and 1 hour

URL: https://arstechnica.com/information-technology/2022/08/sike-once-a-post-quantum-encryption-contender-is-koed-in-nist-smackdown/

Author: Dan Goodin

The Interview

A talk with Steve Marchewitz on his visit to the Gartner Conference.

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Justin Bollinger, Alex Hamerstone, and Edwin David.

Stories

Title: Your Phone's Lock Screen Is Getting a Big Revamp

URL: https://www.cnet.com/tech/mobile/your-phone-lock-screen-is-getting-a-big-revamp/

Author: Lisa Eadicicco

Title: Facebook has started to encrypt links to counter privacy-improving URL Stripping

URL: https://www.ghacks.net/2022/07/17/facebook-has-started-to-encrypt-links-to-counter-privacy-improving-url-stripping/

Author: Martin Brinkmann

Tool Time

A burp plugin by Geoff Walton to locate relationships between UUID/GUID request parameters and appearances of the same identifiers in HTTP responses to other resources.

https://github.com/GeoffWalton/UUID-Watcher/blob/main/UUID.rb

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Justin Bollinger, Skyler Tuter, and Costa Petros.

Stories

Title: Mega says it can’t decrypt your files. New POC exploit shows otherwise

URL: https://arstechnica.com/information-technology/2022/06/mega-says-it-cant-decrypt-your-files-new-poc-exploit-shows-otherwise/

Author: Dan Goodin

Title: NSA shares tips on securing Windows devices with PowerShell

URL: https://www.bleepingcomputer.com/news/security/nsa-shares-tips-on-securing-windows-devices-with-powershell/

Author: Ionut Ilascu

Link: https://media.defense.gov/2022/Jun/22/2003021689/-1/-1/1/CSI_KEEPING_POWERSHELL_SECURITY_MEASURES_TO_USE_AND_EMBRACE_20220622.PDF

Title: Security flaws in internet-connected hot tubs exposed owners’ personal data

URL: https://techcrunch.com/2022/06/22/jacuzzi-flaws-admin-exposed-users/

Author: Carly Page

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Justin Bollinger, Travis Kaun, and David Boyd.

Stories

Title: Most Security Product Byers Aren’t Getting Promised Results

URL: https://www.esecurityplanet.com/trends/most-security-product-buyers-arent-getting-promised-results/

Author: Paul Shread

Title: NSA: Ransomware Gangs Are Getting Rich Enough to Buy Zero-Day Exploits

URL: https://www.pcmag.com/news/nsa-ransomware-gangs-are-getting-rich-enough-to-buy-zero-day-exploits

Author: Michael Kan

Interview

Guest: Travis Kaun

Subject: PWNton Pack!

Links: https://www.trustedsec.com/blog/pwnton-pack-an-unlicensed-802-11-particle-accelerator/

View Details

SHOW NOTES

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Justin Bolinger, Alex Hamerstone, and David Boyd.

Announcements

Join the TrustedSec Discord Community

TrustedSec is on Discord! Join our server to interact with the security community and the TrustedSec team. Go to discord.gg/trustedsec to join.

Enrollment is open

Enrollment is open for the next online training course, PowerShell for Offense and Defense, taking place on September 30th. Class participants learn how to attack and defend against Powershell attacks within simulated corporate environments and find out the tactics, techniques, and procedures (TTPs) commonly used by penetration testers.

Stories

Title: The Math Prodigy Whose Hack Upended DeFi Won’t Give Back His Millions

URL: https://www.bloomberg.com/news/features/2022-05-19/crypto-platform-hack-rocks-blockchain-community

Author: Christopher Beam

Title: Hackers can hack your online accounts before you even register them

URL: https://www.bleepingcomputer.com/news/security/hackers-can-hack-your-online-accounts-before-you-even-register-them/

Author: Bill Toulas

Title: Fake Windows exploits target infosec community with Cobalt Strike

URL: https://www.bleepingcomputer.com/news/security/fake-windows-exploits-target-infosec-community-with-cobalt-strike/

Author: Lawrence Abrams

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Skyler Tuter, Edwin David, and Alex Hamerstone. Announcements

Join the TrustedSec Discord Community

TrustedSec is on Discord! Join our server to interact with the security community and the TrustedSec team. Go to discord.gg/trustedsec to join.

Stories

Title: Your Phone May Soon Replace Many of Your Passwords

URL: https://krebsonsecurity.com/2022/05/your-phone-may-soon-replace-many-of-your-passwords/

Author: Brian Krebs

Title: Heroku Status – 2413 Updated

URL: https://status.heroku.com/incidents/2413?updated

Author: Heroku Security

Interview

Special Event Commentary – With David Kennedy, Chris Boesch, Martin Bos, Justin Elze, and Eric Girard!

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Justin Bollinger, David Boyd, and Alex Hamerstone.

Stories

Title: Cybercriminals do their homework for latest banking scam

URL: https://www.theregister.com/2022/04/15/the_latest_scam_pay_yourself/

Author: Brandon Vigliarolo

Title: Breach of Internal Tools at Mailchimp Used To Deliver Phishing Attacks Targeted at Crypto Wallets

URL: https://www.cpomagazine.com/cyber-security/breach-of-internal-tools-at-mailchimp-used-to-deliver-phishing-attacks-targeted-at-crypto-wallets/

Author: Scott Ikeda

Title: GitHub: Attacker breached dozens of orgs using stolen OAuth tokens

URL: https://www.bleepingcomputer.com/news/security/github-attacker-breached-dozens-of-orgs-using-stolen-oauth-tokens/

Author: Sergui Gatlan

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rick Yocum, Rob Simon, and David Boyd.

Announcements

Join the TrustedSec Discord Community

TrustedSec is on Discord! Join our server to interact with the security community and the TrustedSec team. Go to discord.gg/trustedsec to join.

Stories

Title: Hackers Gaining Power of Subpoena Via Fake “Emergency Data Requests”

URL: https://krebsonsecurity.com/2022/03/hackers-gaining-power-of-subpoena-via-fake-emergency-data-requests/

Author: Brian Krebs

Title: Nestlé: Anonymous Didn't Hack Us, We Leaked Our Own Data

URL: https://gizmodo.com/nestle-denies-anonymous-hack-claims-says-it-leaked-dat-1848691484

Author: Lucas Ropek

Interview

Guest: Rob Simon

Subject: Hardware Hacking

Links: https://www.trustedsec.com/blog/hacking-the-my-arcade-contra-pocket-player-part-i/

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Alex Hamerstone, Justin Bollinger, and Drew Kirkpatrick. Announcements

Join the TrustedSec Discord Community

TrustedSec is on Discord! Join our server to interact with the security community and the TrustedSec team. Go to discord.gg/trustedsec to join.

Stories

Title: Hacked US companies to face new reporting requirements

URL: https://apnews.com/article/russia-ukraine-technology-business-congress-gary-peters-c46e063220568b2beb56220ac60f6041

Author: Alan Suderman and Eric Tucker

Title: Russia creates its own TLS certificate authority to bypass sanctions

URL: https://www.bleepingcomputer.com/news/security/russia-creates-its-own-tls-certificate-authority-to-bypass-sanctions/

Author: Bill Toulas

Interview

Guest: Drew Kirkpatrick

Subject: Service Workers

Links:

https://www.trustedsec.com/blog/persistence-through-service-workers-part-1-introduction-and-target-application-setup/

https://www.trustedsec.com/blog/persistence-through-service-workers-part-2-c2-setup-and-use/

https://www.trustedsec.com/blog/persistence-through-service-workers-part-3-easy-javascript-payload-deployment/

View Details

SHOW NOTES This episode features the following members: Adam Compton, David Boyd, and Justin Bollinger.

Stories

Title: Vulnerable U.S. electric grid facing threats from Russia and domestic terrorists

URL: https://www.cbsnews.com/news/america-electric-grid-60-minutes-2022-02-27/

Author: Bill Whitaker

Title: BitConnect’s Indicted Founder Kumbhani Vanished, SEC Says

URL: https://www.bloomberg.com/news/articles/2022-03-01/bitconnect-s-indicted-founder-kumbhani-has-disappeared-sec-says

Author: David Voreacos

Tool Time

Title: bkcrack

Link: https://github.com/kimci86/bkcrack

About

The TrustedSec Security Podcast is a production of TrustedSec. To learn more about how TrustedSec can help your organization’s security program, visit TrustedSec.com.

The show is hosted and moderated by Geoff Walton

Our podcast music was composed by Steve Neme

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Edwin, David, David Boyd, and Justin Elze. Stories

Title: Website fined by German court for leaking visitor's IP address via Google Fonts

URL: https://www.theregister.com/2022/01/31/website_fine_google_fonts_gdpr

Author: Thomas Claburn

Title: Helping users stay safe: Blocking internet macros by default in Office

URL: https://techcommunity.microsoft.com/t5/microsoft-365-blog/helping-users-stay-safe-blocking-internet-macros-by-default-in/ba-p/3071805

Author: Kellie Eickmeyer

Title: North Korea Hacked Him. So He Took Down Its Internet

URL: https://www.wired.com/story/north-korea-hacker-internet-outage/

Author: Andy Greenberg

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Justin Bollinger, Alex Hamerstone, and Melvin Langvik.

Stories

Title: Linux malware is on the rise. Here are three top threats right now

URL: https://www.zdnet.com/article/linux-malware-is-on-the-rise-here-are-three-top-threats-right-now/

Author: Liam Tung

Title: Intel CEO Urges Lawmakers to ‘Not Waste This Crisis’ in Chip Push

URL: https://www.bloomberg.com/news/articles/2022-01-19/intel-urges-lawmakers-to-not-waste-this-crisis-with-chip-push

Author: Ian King

Tool Time

Link: https://www.trustedsec.com/blog/seeyoucm-thief-exploiting-common-misconfigurations-in-cisco-phone-systems/

Link: https://github.com/trustedsec/SeeYouCM-Thief

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rob Simon, David Boyd and Justin Bollinger.

Stories

Title: Dev corrupts NPM libs 'colors' and 'faker' breaking thousands of apps

URL: https://www.bleepingcomputer.com/news/security/dev-corrupts-npm-libs-colors-and-faker-breaking-thousands-of-apps/

Author: Ax Sharma

Title: FTC warns legal action against companies who fail to mitigate Log4Shell

URL: https://therecord.media/ftc-warns-legal-action-against-companies-who-fail-to-mitigate-log4shell/

Author: Catalin Cimpanu

Title: Threat actors can simulate iPhone reboots and keep iOS malware on a device

URL: https://therecord.media/threat-actors-can-simulate-iphone-reboots-and-keep-ios-malware-on-a-device/

Author: Catalin Cimpanu

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Alex Hamerstone, David Boyd, and Dave Kennedy!

**Announcements**

Join the TrustedSec Discord Community

TrustedSec is on Discord! Join our server to interact with the security community and the TrustedSec team. Go to discord.gg/trustedsec to join.

Stories

Title: FBI document shows what data can be obtained from encrypted messaging apps

URL: https://therecord.media/fbi-document-shows-what-data-can-be-obtained-from-encrypted-messaging-apps/

Author: Catalin Cimpanu

Title: New Windows zero-day with public exploit lets you become an admin

URL: https://www.bleepingcomputer.com/news/microsoft/new-windows-zero-day-with-public-exploit-lets-you-become-an-admin/

Author: Lawrence Abrams

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Justin Bollinger, Melvin Langvik, and Edwin David.

Announcements

Join the TrustedSec Discord Community

TrustedSec is on Discord! Join our server to interact with the security community and the TrustedSec team. Go to discord.gg/trustedsec to join.

Stories

Title: Microsoft to Kill OneDrive for Windows 7, 8, 8.1 in Early 2022

URL: https://www.thurrott.com/cloud/microsoft-consumer-services/onedrive/259004/microsoft-to-kill-onedrive-for-windows-7-8-8-1-in-early-2022

Author: Paul Thurrott

Title: Tim Cook: Users Who Want to Sideload Apps Can Use Android, While the iPhone Experience Maximizes 'Security and Privacy'

URL: https://www.macrumors.com/2021/11/09/tim-cook-users-sideloading-use-an-android/

Author: Sami Fathi

Title: Complexity is killing software developers

URL: https://www.infoworld.com/article/3639050/complexity-is-killing-software-developers.html

Author: Scott Carey

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Justin Bollinger, Stefano Ratto, and David Boyd.

Announcements

Join the TrustedSec Discord Community

TrustedSec is on Discord! Join our server to interact with the security community and the TrustedSec team. Go to discord.gg/trustedsec to join.

Stories of Interest

Title: FBI Raids Chinese Point-of-Sale Giant PAX Technology

URL: https://krebsonsecurity.com/2021/10/fbi-raids-chinese-point-of-sale-giant-pax-technology/

Author: Brian Krebs

Title: Here's the FBI's Internal Guide for Getting Data from AT&T, T-Mobile, Verizon

URL: https://www.vice.com/en/article/m7vqkv/how-fbi-gets-phone-data-att-tmobile-verizon

Author: Joseph Cox

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Justin Bollinnger, Carlos Perez, and David Boyd.

Announcements

Join the TrustedSec Discord Community

TrustedSec is on Discord! Join our server to interact with the security community and the TrustedSec team. Go to discord.gg/trustedsec to join.

PentesterLab Giveaway

To enter visit https://www.trustedsec.com/podcastgiveaway please submit on or before October 22, 2021 to be eligible.

Stories

Title: What Happened to Facebook, Instagram, & WhatsApp?

URL: https://krebsonsecurity.com/2021/10/what-happened-to-facebook-instagram-whatsapp/

Author: Brian Krebs

Title: Company That Routes Billions of Text Messages Quietly Says It Was Hacked

URL: https://www.vice.com/en/article/z3xpm8/company-that-routes-billions-of-text-messages-quietly-says-it-was-hacked

Author: Lorenzo Franceschi-Bicchierai

Title: Apple Pay with VISA lets hackers force payments on locked iPhones

URL: https://www.bleepingcomputer.com/news/security/apple-pay-with-visa-lets-hackers-force-payments-on-locked-iphones/

Author: Ionut Ilascu

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Scott White, Alex Hamerstone, and David Boyd.

Announcements

Join the TrustedSec Discord Community

TrustedSec is on Discord! Join our server to interact with the security community and the TrustedSec team. Go to discord.gg/trustedsec to join.

PentesterLab Giveaway

To enter visit https://www.trustedsec.com/podcastgiveaway please submit on or before October 22, 2021 to be eligible.

Stories

Title: US Fine former NSA employees who provided hacker-for-hire services to UAE

URL: https://therecord.media/us-fines-former-nsa-employees-who-provided-hacker-for-hire-services-to-uae/

Author: Catalin Cimpanu

Title: Researchers compile list of vulnerabilities abused by ransomware gangs

URL: https://www.bleepingcomputer.com/news/security/researchers-compile-list-of-vulnerabilities-abused-by-ransomware-gangs/

Author: Sergiu Gatlan

Title: Customer Care Giant TTEC Hit By Ransomware

URL: https://krebsonsecurity.com/2021/09/customer-care-giant-ttec-hit-by-ransomware/

Author: Brian Krebs

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rob Simon, Carlos Perez, and Justin Bollinger .

Stories

Title: You can post LinkedIn jobs as almost ANY employer

URL: https://www.bleepingcomputer.com/news/security/you-can-post-linkedin-jobs-as-almost-any-employer-so-can-attackers/

Author: Ax Sharma

Title: ChaosDB: How we hacked thousands of Azure customers’ databases

URL: https://www.wiz.io/blog/chaosdb-how-we-hacked-thousands-of-azure-customers-databases

Authors: Nir Ohfeld and Sagi Tzadik

Tool Time

Subject: iHide

Link: https://www.trustedsec.com/blog/introducing-ihide-a-new-jailbreak-detection-bypass-tool/

View Details

Welcome to the Trusted Security Podcast – In this hacker to hacker talk Justin gets Geoff up to speed on some newer ADS relay attacks. The episode features the following members: Geoff Walton and Justin Bollinger.

Links

https://github.com/sensepost/assless-chaps

https://us-cert.cisa.gov/ncas/current-activity/2021/07/27/microsoft-releases-guidance-mitigating-petitpotam-ntlm-relay

https://us-cert.cisa.gov/ncas/current-activity/2021/07/27/microsoft-releases-guidance-mitigating-petitpotam-ntlm-relay

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Justin Bollinger, Alex Hamerstone and David Boyd.

Stories

Title: New Law Will Help Chinese Government Stockpile Zero-Days

URL: https://www.securityweek.com/new-law-will-help-chinese-government-stockpile-zero-days

Author: Kevin Townsend

Title: Huge data leak shatters the lie that the innocent need not fear surveillance

URL: https://www.theguardian.com/news/2021/jul/18/huge-data-leak-shatters-lie-innocent-need-not-fear-surveillance

Author: Paul Lewis

Title: Kaseya Hack Floods Hundreds of Companies with Ransomware

URL: https://techcrunch.com/2021/07/05/kaseya-hack-flood-ransomware

Author: Zach Whittaker

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rick Yocum, Alex Hamerstone, and David Boyd.

Announcements

Black Hat Training

Join the TrustedSec Black Hat virtual training course: Actionable Defense - Understanding Adversary Tactics, taking place virtually July 31st - August 3rd. Go to blackhat.com/us-21 for more information.

Join the TrustedSec Discord Community

TrustedSec is on Discord! Join our server to interact with the security community and the TrustedSec team. Go to discord.gg/trustedsec to join.

Stories

Title: PoC exploit accidentally leaks for dangerous Windows PrintNightmare bug

URL: https://therecord.media/poc-released-for-dangerous-windows-printnightmare-bug/

Author: Catalin Cimpanu

Title: LinkedIn breach reportedly exposes data of 92% of users, including inferred salaries

URL: https://9to5mac.com/2021/06/29/linkedin-breach/

Author: Ben Lovejoy

Title: MyBook Users Urged to Unplug Devices from Internet

URL: https://krebsonsecurity.com/2021/06/mybook-users-urged-to-unplug-devices-from-internet/

Author: Brian Krebs

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Justin Bollinger, Alex Hamerstone, and Rockie Brockway.

Announcements

Black Hat Training

Join the TrustedSec Black Hat virtual training course: Actionable Defense - Understanding Adversary Tactics, taking place virtually July 31st - August 3rd. Go to blackhat.com/us-21 for more information.

Join the TrustedSec Discord Community

TrustedSec is on Discord! Join our server to interact with the security community and the TrustedSec team. Go to discord.gg/trustedsec to join.

Stories

Title: Largest US propane distributor discloses '8-second' data breach

URL: https://www.bleepingcomputer.com/news/security/largest-us-propane-distributor-discloses-8-second-data-breach/

Author: Ax Sharma

Title: McDonald’s Hit by Data Breach

URL: https://www.wsj.com/articles/mcdonalds-hit-by-data-breach-in-south-korea-taiwan-11623412800

Author: Heather Haddon

Title: Privilege escalation with polkit: How to get root on Linux with a seven-year-old bug

URL: https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/

Author: Kevin Backhouse

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Scott Nusbaum, and Paul Sems.

Announcements

Black Hat Training

Join the TrustedSec Black Hat virtual training course: Actionable Defense - Understanding Adversary Tactics, taking place virtually July 31st - August 3rd. Go to blackhat.com/us-21 for more information.

Carlos Mimikatz Training

Enroll in our next online training course: Mimikatz: Everything You Need to Know. Taking place on June 10- June 11 and led by TrustedSec Research Practice Lead, Carlos Perez. Visit TrustedSec.com to learn more and enroll.

Stories

Title: The Colonial pipeline ransomware hackers had a secret weapon: self-promoting cybersecurity firms

URL: https://www.technologyreview.com/2021/05/24/1025195/colonial-pipeline-ransomware-bitdefender/amp/

Authors: Renee Dudley and Daniel Golden

Title: PowerShell Is Source of More Than a Third of Critical Security Threats

URL: https://www.esecurityplanet.com/threats/powershell-source-of-third-of-critical-security-threats/

Author: Paul Shread

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Kelsey Segrue, Alex Hamerstone and David Boyd .

Stories

Title: Absolute stupidity': Cybersecurity experts condemn White House for breaking with FBI and suggesting private companies could pay ransomware demands

URL: https://www.dailymail.co.uk/news/article-9566489/Cybersecurity-experts-condemn-White-House-suggesting-companies-canpay-ransomware-demands.html

Author: Rob Crilly

Title: Thousands of Tor exit nodes attacked cryptocurrency users over the past year

URL: https://therecord.media/thousands-of-tor-exit-nodes-attacked-cryptocurrency-users-over-the-past-year/

Author: Catalin Cimpanu

Title: Malicious Office 365 Apps Are the Ultimate Insiders

URL: https://krebsonsecurity.com/2021/05/malicious-office-365-apps-are-the-ultimate-insiders/

Author: Brian Krebs

View Details

SHOW NOTES

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Kelsey Segrue, Justin Bollinger, and David Boyd.

Stories

Title: Deere John: Researcher Warns Ag Giant’s Site Provides a Map to Customers, Equipment

URL: https://securityledger.com/2021/04/deere-john-researcher-warns-ag-giants-site-provides-a-map-to-customers-equipment/

Author: Paul Roberts

Title: D.C. Police Department Victim Of Apparent Ransomware Attack

URL: https://www.npr.org/2021/04/27/991116344/d-c-police-department-victim-of-apparent-ransomware-attack

Author: Jaclyn Diaz

Title: Signal CEO Hacks Cellebrite iPhone Hacking Device Used By Cops

URL: https://www.vice.com/en/article/k78q5y/signal-ceo-hacks-cellebrite-iphone-hacking-device-used-by-cops

Author: Lorenzo Franceschi-Bicchierai

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rob Simon and David Boyd .

Stories

Title: NAME:WRECK vulnerabilities impact millions of smart and industrial devices

URL: https://therecord.media/namewreck-vulnerabilities-impact-millions-of-smart-and-industrial-devices/

Author: Catalin Cimpanu

Original Research Link: https://www.forescout.com/company/resources/namewreck-breaking-and-fixing-dns-implementations/

Title: PHP's Git server hacked to add backdoors to PHP source code

URL: https://www.bleepingcomputer.com/news/security/phps-git-server-hacked-to-add-backdoors-to-php-source-code/

Author: Ax Sgarna

Title: Facebook Says It’s Your Fault That Hackers Got Half a Billion User Phone Numbers

URL: https://www.vice.com/en/article/88awzp/facebook-says-its-your-fault-that-hackers-got-half-a-billion-user-phone-numbers

Author: David Gilbert

View Details

SHOW NOTES

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rob Simon, Justin Bollinger and David Boyd .

Stories

Title: A Security App’s Fake Reviews Give Us a Window Into ‘App Store Optimization’

URL: https://www.vice.com/en/article/n7vxgd/a-security-apps-fake-reviews-give-us-a-window-into-app-store-optimization

Author: Lorenzo Franceschi-Bicchierai

Title: Can We Stop Pretending SMS is Secure Now

URL: https://krebsonsecurity.com/2021/03/can-we-stop-pretending-sms-is-secure-now/

Author: Brian Krebs

Tool Time

Title: Response Tinker

Link: https://www.trustedsec.com/?p=23828&preview=1&_ppp=ffd12e7902

View Details

SHOW NOTES

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rick Yocum, Logan Sampson, and David Boyd .

Stories

Title: Finding Evil Go Packages

URL: https://michenriksen.com/blog/finding-evil-go-packages/

Author: Michael Henriksen

Title: Hackers Breach Thousands of Security Cameras, Exposing Tesla, Jails, Hospitals

URL: https://www.bloomberg.com/news/articles/2021-03-09/hackers-expose-tesla-jails-in-breach-of-150-000-security-cams

Author: William Turton

Title: A Basic Timeline of the Exchange Mass-Hack

URL: https://krebsonsecurity.com/2021/03/a-basic-timeline-of-the-exchange-mass-hack
Author: Brian Krebs

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Scott White, Adam Compton, and David Boyd.

Title: New Windows 10 update permanently removes Adobe Flash

URL: https://www.zdnet.com/article/new-windows-10-update-permanently-removes-adobe-flash

Author: Liam Tung

Title: M1 Malware Has Arrived

URL: https://gizmodo.com/m1-malware-has-arrived-1846286255

Author: Victoria Song

Title: The Long Hack: How China Exploited a U.S. Tech Supplier

URL: https://www.bloomberg.com/features/2021-supermicro/

Author: Jordan Robertson and Michael Riley

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rob Simon, Justin Bollinger.

Stories of Interest

Title: Tales of F A V I C O N S and Caches: Persistent Tracking in Modern Browsers

URL: https://www.cs.uic.edu/~polakis/papers/solomos-ndss21.pdf

ALT URL: https://www.vice.com/en/article/n7v5y7/browser-favicons-can-be-used-as-undeletable-supercookies-to-track-you-online

Authors: Konstantinos Solomos, John Kristoff, Chris Kanich, Jason Polakis

Title: Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies

URL: https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610

Author: Alex Birsan

Title: Florida city attacked by a hacker trying to poison its drinking water

URL: https://www.engadget.com/oldsmar-florida-water-treatment-hack-225713558.html

Author: I. Bonifacic

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, David Boyd, Alex Hamerstone, and Justin Bollinger.

Title: New campaign targeting security researchers
URL: https://blog.google/threat-analysis-group/new-campaign-targeting-security-researchers/
Author: Adam Weidemann

Title: After disabling Adobe Flash trains in Dalian, China could hardly open
URL: https://verietyinfo.com/taiwaneng/after-disabling-adobe-flash-trains-in-dalian-china-could-hardly-open-technews-%E7%A7%91%E6%8A%80-%E6%96%B0-%E6%8A%A5/
ALT URL: https://arstechnica.com/tech-policy/2021/01/deactivation-of-flash-cripples-chinese-railroad-for-a-day/

Title: SolarWinds: What Hit Us Could Hit Others
URL: https://krebsonsecurity.com/2021/01/solarwinds-what-hit-us-could-hit-others/

Author: Brian Krebs

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Carlos Perez, Adam Compton, Kelsey Segrue.

[Stories of Interest]

Title: All Aboard the Pequod!

URL: https://krebsonsecurity.com/2021/01/all-aboard-the-pequod/

Author: Brian Krebs

Title: Kazuar: Multiplatform Espionage Backdoor with API Access

URL: https://unit42.paloaltonetworks.com/unit42-kazuar-multiplatform-espionage-backdoor-api-access/

Author: Brandon Levene, Robert Falcone and Tyler Halfpop

Title: Security researchers claims downloading 70TB of sensitive Parler data

URL: https://www.hackread.com/security-researchers-leak-70tb-parler-data/

Author: Waqas

[Tool Time]

https://github.com/trustedsec/SysmonCommunityGuide

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rick Yocum, Alex, and David Boyd.

Title: GE puts default password in radiology devices, leaving healthcare networks exposed

URL: https://arstechnica.com/information-technology/2020/12/default-password-in-radiology-devices-leaves-healthcare-networks-open-to-attack/

Author: Dan Goodin

Title: FireEye, a Top Cybersecurity Firm, Says It Was Hacked by a Nation-State

URL: https://www.nytimes.com/2020/12/08/technology/fireeye-hacked-russians.html

Author: David E. Sanger and Nicole Perlroth

Title: What you need to know about Amazon Sidewalk

URL: https://appleinsider.com/articles/20/11/24/what-you-need-to-know-about-amazon-sidewalk

Author: Mike Peterson

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Alex Hamerstone, Justin Bollinger, and Rob Simon.

[Stories]

Title: Apple search bot leaked internal IPs via proxy configuration

URL: https://www.bleepingcomputer.com/news/security/apple-search-bot-leaked-internal-ips-via-proxy-configuration/

Author: Ax Sharma

Title: Woman accused of impersonating prosecutor, dropping criminal charges against herself

URL: https://www.unionleader.com/news/courts/woman-accused-of-impersonating-prosecutor-dropping-criminal-charges-against-herself/article_1fdb1551-147d-53dd-ad45-6680bfc556fa.html?fbclid=IwAR2ovZ_mr_uVcIXJIcW3j_bEji7eLjE1yw_s90IPUKzsSxZ94-cDE-7YDys

Author: Mark Hayward

Title: Why Paying to Delete Stolen Data is Bonkers

URL: https://krebsonsecurity.com/2020/11/why-paying-to-delete-stolen-data-is-bonkers/

Author: Brian Krebs

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rick Yocum, and David Boyd.

Stories

Title: Link Previews: How a Simple Feature Can Have Privacy and Security Risks

URL: https://www.mysk.blog/2020/10/25/link-previews/

Author: Talal Haj Bakry and Tommy Mysk

Title: Hackers behind life-threatening attack on chemical-maker are sanctioned

URL: https://arstechnica.com/information-technology/2020/10/us-sanctions-russian-hackers-who-hit-chemical-maker-with-dangerous-malware/

Author: Dan Goodin

Title: Three npm packages found opening shells on Linux, Windows systems

URL: https://www.zdnet.com/article/three-npm-packages-found-opening-shells-on-linux-windows-systems/
Author: Catalin Cimpanu

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Costa Petros, and David Boyd.

Stories

Title: POLICE departments across the country Monday night reported their 911 systems nonoperational

URL: https://www.the-sun.com/news/1548945/911-lines-go-down-across-us/

Author: Catherina Gioino

Title: Looks Like the Windows XP Source Code Just Leaked on 4chan

URL: https://www.gizmodo.com.au/2020/09/looks-like-the-windows-xp-source-code-just-leaked-on-4chan/

Author: Cam Wilson

Title: Microsoft: Some ransomware attacks take less than 45 minutes

URL: https://www.zdnet.com/article/microsoft-some-ransomware-attacks-take-less-than-45-minutes/
Author: Catalin Cimpanu

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Aaron James, Alex Hamerstone, and David Boyd.

Stories

Title: Windows 10 themes can be abused to steal Windows passwords

URL: https://www.bleepingcomputer.com/news/microsoft/windows-10-themes-can-be-abused-to-steal-windows-passwords/

Author: Lawrence Abrams

Title: The Big Tesla Hack: A hacker gained control over the entire fleet, but fortunately he’s a good guy

URL: https://electrek.co/2020/08/27/tesla-hack-control-over-entire-fleet/

Author: Fred Lambert

Tool Time

SPAnalyzer -

https://www.trustedsec.com/blog/fuzzing-the-front-end/

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rick Yocum, Logan Sampson, and Justin Bollinger.

Stories

Title: Former Uber Executive Charged With Paying 'Hush Money' To Conceal Massive Breach

URL: https://www.npr.org/2020/08/20/904113981/former-uber-executive-charged-with-paying-hush-money-to-conceal-massive-breach

Author: Shannon Bond

Title: Report: AI Company Leaks Over 2.5M Medical Records

URL: https://www.pcmag.com/news/report-ai-company-leaks-over-25m-medical-records

Author: Matthew Humphries

Title: Picking Locks with Audio Technology

URL: https://cacm.acm.org/news/246744-picking-locks-with-audio-technology/fulltext

Author: Paul Marks

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rick Yocum, David Boyd, and Aaron James.

Stories:

Title: Hacker leaks passwords for 900+ enterprise VPN servers

URL: https://www.zdnet.com/article/hacker-leaks-passwords-for-900-enterprise-vpn-servers/

Author Catalin Cimpanu

Title: Three Charged in July 15 Twitter Compromise

URL: https://krebsonsecurity.com/2020/07/three-charged-in-july-15-twitter-compromise/

Author: Brian Krebs

Title: Web Cache Entanglement: Novel Pathways to Poisoning

URL: https://portswigger.net/research/web-cache-entanglement

Author: James Kettle

View Details

SHOW NOTES

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Scott White, Rob Simon, and Alex Hamerstone.

Title: The more cybersecurity tools an enterprise deploys, the less effective their defense is URL: https://www.zdnet.com/article/the-more-cybersecurity-tools-an-enterprise-deploys-the-

less-effective-their-defense-is/

Author: Charlie Osborne

Title: Home Router Security Report 2020

URL:https://www.fkie.fraunhofer.de/content/dam/fkie/de/documents/HomeRouter/HomeRouter

Security_2020_Bericht.pdf

Author: Peter Weidenbach Johannes vom Dorp

Title: SIGRed – Resolving Your Way into Domain Admin: Exploiting a 17 Year-old Bug in

Windows DNS Servers

URL: https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin:-exploiting-

a-17-year-old-bug-in-windows-dns-servers/

Author: Sagi Tzadik

And…Talking Twitter

View Details

SHOW NOTES

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rick Yocum, David Boyd, and Scott Nusbaum

Stories

Title: A hacker gang is wiping Lenovo NAS devices and asking for ransoms

URL: https://www.zdnet.com/article/a-hacker-gang-is-wiping-lenovo-nas-devices-and-asking-for-ransoms/

Author: Catalin Cimpanu

Title: FCC formally declare Huawei, ZTE ‘national security threats’

URL: https://techcrunch.com/2020/06/30/fcc-huawei-zte-national-security/

Author: Zack Whittaker, Devin Coldewey

Tool Time

Link: https://www.trustedsec.com/blog/access-locked-files-with-tscopy/

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rob Simon, Drew Kirkpatrick, and David Boyd.

Title: Career Choice Tip: Cybercrime is Mostly Boring
URL: https://krebsonsecurity.com/2020/05/career-choice-tip-cybercrime-is-mostly-boring/
Author: Brian Krebs

Title: Ripple 20
URL: https://www.jsof-tech.com/ripple20/\
Authors: Moshe Kol, Ariel Schon, Shlomi Oberman, Andrey Zagrebin, Yuli Shapiro

Title: Dating Apps Exposed 845 GB of Explicit Photos, Chats, and More
URL: https://www.wired.com/story/dating-apps-leak-explicit-photos-screenshots/
Authors: Lily Hay Newman

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Justin Bollinger, Paul Sems, and David Boyd

[Stories]

Title: PrintDemon: Print Spooler Privilege Escalation, Persistence & Stealth (CVE-2020-1048 & more)

URL: https://windows-internals.com/printdemon-cve-2020-1048/

Author: Yarden Shafir & Alex Ionescu

Title: Supercomputers hacked across Europe to mine cryptocurrency

URL: https://www.zdnet.com/article/supercomputers-hacked-across-europe-to-mine-cryptocurrency/

Author: Catalin Cimpanu

[Tool Time]

Pop open your Windows 10 Terminal and run:

pktmon help

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Alex Hamerstone, Logan Sampson, and David Boyd

Stories of Interest

Title: Cisco spotlights new IT roles you've never heard of

URL: https://www.networkworld.com/article/3541363/cisco-spotlights-new-it-roles-youve-never-heard-of.html

Author: Michael Cooney

Title: The three early, maddening viruses that shook the world—and Microsoft

URL: https://www.fastcompany.com/90500378/iloveyou-virus-microsoft-steven-sinofsky-book Author: Steveen Sinofsky

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Alex Hamerstone, Rick Yocum, and David Boyd

Stories of Interest

Title: Ransomware scumbags leak Boeing, Lockheed Martin, SpaceX documents after contractor refuses to pay

URL: https://www.theregister.co.uk/2020/04/10/lockheed_martin_spacex_ransomware_leak/

Author: Shaun Nichols and Gareth Corfield

Title: DHS CISA: Companies are getting hacked even after patching Pulse Secure VPNs

URL: https://www.zdnet.com/article/dhs-cisa-companies-are-getting-hacked-even-after-patching-pulse-secure-vpns/

Author: Catalin Cimpanu

Title: Researchers Say They Caught an iPhone Zero-Day Hack in the Wild

URL: https://www.vice.com/en_us/article/pken5n/iphone-email-zero-day-hack-in-the-wild/

Author: Lorenzo Franceschi-Bicchierai

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Alex Hamerstone, Rick Yocum, and Rockie Brockway

Feature: Discussion with TrustedSec Advisory Services on migrating to remote work

Stories

Title: Beware—This Open Database On Google Cloud ‘Exposes 200 Million Americans’: Are You At Risk?

URL: https://www.forbes.com/sites/zakdoffman/2020/03/20/stunning-new-google-cloud-breach-hits-200-million-us-citizens-check-here-if-youre-now-at-risk/#cd6889985879

Author: Zak Doffman

Title: Marriott says new data breach affects 5.2 million guests

URL: https://abcnews.go.com/Technology/wireStory/marriott-data-breach-affects-52-million-guests-69895558

Author: Dee-Ann Durbin

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Alex Hamerstone, Paul Sems, and David Boyd

Stories

Title: Trump signs law banning use of federal funds to purchase Huawei equipment

URL: https://thehill.com/policy/cybersecurity/487266-trump-signs-into-law-bill-banning-use-of-federal-funds-to-purchase

Author: Maggie Miller

Title: You can now take up to 12 ounces of hand sanitizer through airport security

URL: https://www.theverge.com/2020/3/13/21179120/tsa-hand-sanitizer-liquid-size-airport-screening-coronavirus-covid-19

Author: Andrew Hawkins

Title: Live Coronavirus Map Used to Spread Malware

URL: https://krebsonsecurity.com/2020/03/live-coronavirus-map-used-to-spread-malware/

Author: Brian Krebs

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rob Simon, Scott White, and David Boyd

Title: Cybersecurity warning: Almost half of connected medical devices are vulnerable to hackers exploiting BlueKeep

URL: https://www.zdnet.com/article/cybersecurity-warning-almost-half-of-connected-medical-devices-are-vulnerable-to-hackers-exploiting-bluekeep/

Author: Danny Palmer

**Title**: Perilous Peripherals: The Hidden Dangers Inside Windows & Linux Computers

URL: https://eclypsium.com/2020/2/18/unsigned-peripheral-firmware/

Author: By Eclypsium

**Title**: Pay Up, Or We’ll Make Google Ban Your Ads

URL: https://krebsonsecurity.com/2020/02/pay-up-or-well-make-google-ban-your-ads/

Author: Brian Krebs

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, David Boyd, Alex Hamerstone and Rob Simon.

Title: Critical Exposure in Citrix ADC (NetScaler) – Unauthenticated Remote Code Execution

URL: https://www.trustedsec.com/blog/critical-exposure-in-citrix-adc-netscaler-unauthenticated-remote-code-execution/

Author: David Kennedy

Title: Microsoft patches Windows 10 after the NSA quietly told it about a major vulnerability

URL: https://www.cnbc.com/2020/01/14/microsoft-to-patch-windows-10-after-nsa-finds-vulnerability.html

Author: Kate Fazzini

URL2: https://news.ycombinator.com/item?id=22048619

Author2: tptacek

URL3: https://curveballtest.com/index.html

Author3: SANS Internet Storm Center

Title: Seven Years Later, Scores of EAS Systems Still sit UN-Pached, Vulnerable

URL: https://securityledger.com/2020/01/seven-years-later-scores-of-eas-systems-sit-un-patched-vulnerable/

Author: Paul Roberts

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, David Kennedy, and David Boyd.

Title: Ransomware Gangs Now Outing Victim Businesses That Don’t Pay Up

URL: https://krebsonsecurity.com/2019/12/ransomware-gangs-now-outing-victim-businesses-that-dont-pay-up/

Author: Brian Krebs

Title: Chrome now warns you when your password has been stolen

URL: https://www.theverge.com/2019/12/10/21004434/google-chrome-79-password-protections-security-stolen-password-data-features

Author: Tom Warren

Title: Breaking the Rules: A Tough Outlook for Home Page Attacks

URL: https://www.fireeye.com/blog/threat-research/2019/12/breaking-the-rules-tough-outlook-for-home-page-attacks.html

Authors: Matthew McWhirt, Nick Carr, Douglas Bienstock

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, David Boyd, Rob Simon, and Steve Maxwell!

Stories

Title: A bug in Microsoft’s login system put users at risk of account hijacks

URL: https://techcrunch.com/2019/12/02/microsoft-login-flaw-account-hijack/

Author: Zack Whittaker

Title: It’s Way Too Easy to Get a .gov Domain Name

URL: https://krebsonsecurity.com/2019/11/its-way-too-easy-to-get-a-gov-domain-name/

Author: Brian Krebs

Title: Two malicious Python libraries caught stealing SSH and GPG keys

URL: https://www.zdnet.com/article/two-malicious-python-libraries-removed-from-pypi/

Author: Catalin Cimpanu

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Alex Hamerstone, Rob Simon, and David Boyd!

Stories

Title: NordVPN users’ passwords exposed in mass credential-stuffing attacks

URL: https://arstechnica.com/information-technology/2019/11/nordvpn-users-passwords-exposed-in-mass-credential-stuffing-attacks/

Author: Dan Goodin

Title: ISPs lied to Congress to spread confusion about encrypted DNS, Mozilla says

URL: https://arstechnica.com/tech-policy/2019/11/isps-lied-to-congress-to-spread-confusion-about-encrypted-dns-mozilla-says/

Author: Jon Brodkin

Title: Robinhood Traders Discovered a Glitch That Gave Them ‘Infinite Leverage’

URL: https://www.bloomberg.com/news/articles/2019-11-05/robinhood-has-a-glitch-that-gives-traders-infinite-leverage

Author: Brandon Kochkodin

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, David Boyd, Justin Bollinger, and Alex Hamerstone!

Stories

Title: Hacker Releases 'Unpatchable' Jailbreak For All iOS Devices, iPhone 4s to iPhone X

URL: https://thehackernews.com/2019/09/bootrom-jailbreak-ios-exploit.html?m=1

Author: Mohit Kumar

Title: Researchers uncover 125 vulnerabilities across 13 routers and NAS devices

URL: https://www.helpnetsecurity.com/2019/09/17/vulnerabilities-iot-devices/

Title: Mozilla Won't Turn on DoH as Default in the UK Like It's Planning to Do in the US

URL: https://www.gizmodo.co.uk/2019/09/mozilla-doh-not-default-in-uk/

Author: Shabana Arif

Letters

We have good success using the historical DNS data available at https://securitytrails.com to locate the origin servers. This facilitates bypassing filtering to attack web applications.

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, David Kennedy, and Martin Bos

This show features a little different format we look back on nine years of DerbyCon with two of the principle organizers!

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Hans Lakhan, and David Boyd

In this episode we share what happened in Vegas! Wait is that allowed?

Links from the show:

Proxmark3

API Induced SSRF

Gone to the Dogs - Constructing Kerberos Attacks with Delegation Primitives

HTTP Desync Attacks: Request Smuggling Reborn

Owning the Cloud Through Server-Side Request Forgery

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rob Simon, David Boyd, and Alex Hamerstone.

Title: Kazakhstan's HTTPS Interception

URL: https://censoredplanet.org/kazakhstan

Author: Ram Sundara Raman1, Leonid Evdokimov, Eric Wustrow2, Alex Halderman1, Roya Ensafi

Title: DMARC's abysmal adoption explains why email spoofing is still a thing

URL: https://www.zdnet.com/article/dmarcs-abysmal-adoption-explains-why-email-spoofing-is-still-a-thing/

Author: Catalin Cimpanu

Title: My browser, the spy: How extensions slurped up browsing histories from 4M users

URL: https://arstechnica.com/information-technology/2019/07/dataspii-inside-the-debacle-that-dished-private-data-from-apple-tesla-blue-origin-and-4m-people/

Author: Dan Goodin

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Hans Lakhan, Alex Hamerstone and David Boyd

Title: Firms That Promised High-Tech Ransomware Solutions Almost Always Just Pay the Hackers

URL: https://features.propublica.org/ransomware/ransomware-attack-data-recovery-firms-paying-hackers/

Author: Renee Dudley and Jeff Kao

Title: https://www.kaspersky.com/blog/chip-n-pin-cloning/21502/

URL: https://www.kaspersky.com/blog/chip-n-pin-cloning/21502/

Author: Alex Perekalin

Title: Track This is a new kind of incognito, says Mozilla

URL: https://www.hackread.com/mozillas-track-this-choose-fake-identity-to-deceive-advertisers/

Author: Waqas

Letters Home:

Try busting that CAPTCHA

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing

the latest news on information security and the industry. This episode

features the following members: Geoff Walton, Justin Bollinger, and Steve Maxwell!

Stories

Title: Quest Diagnostics Says Up to 12 Million Patients May Have Had Financial, Medical, Personal Information Breached

URL: https://www.nbcnewyork.com/news/local/Quest-Diagnostics-12-Million-People-Data-Breach-510754611.html

Author: NBC New York

Title: Google disables Baltimore's Gmail accounts used during ransomware recovery

URL: https://www.baltimoresun.com/maryland/baltimore-city/bs-md-ci-gmail-accounts-20190523-story.html

Author: Ian Duncan

Title: Microsoft warns of major WannaCry-like Windows security exploit, releases XP patches

URL: https://www.theverge.com/2019/5/14/18623565/microsoft-windows-xp-remote-desktop-services-worm-security-patches

Author: Tom Warren

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Scott White, Justin Bollinger, and David Boyd!

Stories  

Title: Exposing lockbox rental scam

URL:https://www.cbs46.com/investigations/better_call_harry/better-call-harry-exposing-lockbox-rental-scam/article_d9a7242a-6ae4-11e9-bad4-b3ba30648147.html

Author: Harry Samler (CBS46 Atlanta)

Title: In a first, Israel responds to Hamas hackers with an air strike

URL: https://www.zdnet.com/article/in-a-first-israel-responds-to-hamas-hackers-with-an-air-strike/#ftag=RSSbaffb68

Author: Catalin Cimpanu

Title: Uber apologizes after racist tweet

URL: https://mashable.com/article/uber-racist-tweet

Author: Jake Morse

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing

the latest news on information security and the industry. This episode

features the following members: Geoff Walton, Rob Simon, Justin Bollinger, and David Boyd!

Stories

Title: The Feds Are Dropping Child Porn Cases Instead of Revealing Info on Their Surveillance Systems

URL: https://reason.com/2019/04/24/the-feds-are-dropping-child-porn-cases-instead-of-revealing-info-on-their-surveillance-systems/

Author: Elizabeth Nolan Brown

Title: Microsoft admits expiring-password rules are useless

URL: https://www.cnet.com/news/microsoft-admits-expiring-password-rules-are-useless/

Author: Ian Sherr

Title: Huawei row: UK to let Chinese firm help build 5G network

URL: https://www.bbc.com/news/uk-48032286

Author: BBC

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing

the latest news on information security and the industry. This episode

features the following members: Geoff Walton, Oddvar Moe, Justin Bollinger, and Alex Hamerstone!

Stories

Title: Casino Screwup Royale: A tale of “ethical hacking” gone awry

URL: https://arstechnica.com/information-technology/2019/03/50-shades-of-greyhat-a-study-in-how-not-to-handle-security-disclosures/

Author: Sean Gallagher

Title: Researchers Find Google Play Store Apps Were Actually Government Malware

URL: https://motherboard.vice.com/en_us/article/43z93g/hackers-hid-android-malware-in-google-play-store-exodus-esurv

Author: Lorenzo Franceschi-Bicchierai and Riccardo Coluccini

Title: Beyond Sketchy’: Facebook Demanding Some New Users’ Email Passwords

URL: https://www.thedailybeast.com/beyond-sketchy-facebook-demanding-some-new-users-email-passwords

Author: Kevin Poulsen

Letters home

A discussion with Alex Hamerstone about how the need to plan communications before you deploy a honeypot or other deception technology.

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rockie Brockway, Steve Maxwell, Hans Lakhan, and David Boyd

Title: Iranian-backed hackers stole data from major U.S. government contractor

URL: https://www.nbcnews.com/politics/national-security/iranian-backed-hackers-stole-data-major-u-s-government-contractor-n980986

Author: Dan De Luce and Courtney Kube

Title: Beto O'Rourke Was Reportedly a Member of a 'Hacktivist' Group. What's That?

URL: http://time.com/5552860/beto-orourke-hacktivist-cdc/

Author: By Patrick Lucas

Title: NSA releases Ghidra, a free software reverse engineering toolkit

URL: https://www.zdnet.com/article/nsa-release-ghidra-a-free-software-reverse-engineering-toolkit/

Author: Catalin Cimpanu

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rob Simon, Justin Bollinger, and Jessica Ryan

Title: Thunderbolt vulnerabilities leave computers wide-open

URL: https://www.itnews.com.au/news/thunderbolt-vulnerabilities-leave-computers-wide-open-519855

Author: Juha Saarinen

Title: Microsoft Edge lets Facebook run Flash code behind users' backs

URL: https://www.zdnet.com/article/microsoft-edge-lets-facebook-run-flash-code-behind-users-backs/

Author: Catalin Cimpanu

Title: Supermicro hardware weaknesses let researchers backdoor an IBM cloud server

URL: https://arstechnica.com/information-technology/2019/02/supermicro-hardware-weaknesses-let-researchers-backdoor-an-ibm-cloud-server/

Author: Dan Goodin

Tool Time

Tool: Monitor.App

URL: https://www.fireeye.com/services/freeware/monitor.html

Author: FIREEYE

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rob Simon, Alex Hamerstone, David Boyd and Jessica Ryan

Title: Russia to disconnect from the internet as part of a planned test

URL https://www.zdnet.com/article/russia-to-disconnect-from-the-internet-as-part-of-a-planned-test/

Author: Catalin Cimpanu

Title: Doomsday Docker security hole uncovered

URL: https://www.zdnet.com/article/doomsday-docker-security-hole-uncovered/

Author: Steven J. Vaughan-Nichols

Title: How Bezo's dick pics might've been exposed

URL: https://blog.erratasec.com/2019/02/how-bezos-dick-pics-mightve-been-exposed.html?m=1

Author: Errata Security

Additional Links:

https://www.keepassx.org/

https://haveibeenpwned.com/

https://www.spokeo.com/

https://pipl.com/

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rob Simon, Scott White, and Jessica Ryan

Title: How Web Apps Can Turn Browser Extensions Into Backdoors

URL: https://threatpost.com/web-apps-browser-extensions-backdoors/141061/

Author: Tom Spring

Title: How Web Apps Can Turn Browser Extensions Into Backdoors

URL: https://threatpost.com/web-apps-browser-extensions-backdoors/141061/

Author: Tom Spring

Link to original research: http://www-sop.inria.fr/members/Doliere.Some/papers/empoweb.pdf

Title: Most out of date applications exposed: Shockwave, VLC and Skype top the list

URL: https://www.helpnetsecurity.com/2019/01/23/most-out-of-date-applications/ /

Author: Unspecified

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rob Simon, Scott White, David Kennedy, and Alex Hamerstone

Title: NSA to release a free reverse engineering tool

URL https://www.zdnet.com/article/nsa-to-release-a-free-reverse-engineering-tool/

Author: Catalin Cimpanu

Title: USB Type-C Authentication Program launched to protect your devices

URL https://newatlas.com/usb-c-authentication-program/57844/

Author: Paul Ridden

Title: The 6 reasons why Huawei gives the US and its allies security nightmares

URL: https:// www.technologyreview.com/s/612556/the-6-reasons-why-huawei-gives-the-us-and-its-allies-security-nightmares/

Author: Martin Giles and Elizabeth Woyke

Tool Time:

Tool by: GitHub user ecthros

URL: https://github.com/ecthros/uncaptcha2

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rob Simon, David Boyd, Justin Bollinger, and Alex Hamerstone

Title: facebook reaveals bug exposed 6.8 million users’ photos
URL https://www.cnn.com/2018/12/14/tech/facebook-private-photos-exposed-bug/index.html Author: Donie O’Sullivan

Title: As Facebook Raised a Privacy Wall, It Carved an Opening for Tech Giants
URL https://www.nytimes.com/2018/12/18/technology/facebook-privacy.htmlAuthor: Donie O’Sullivan
Author: Gabriel Dance

Title: Hackers swipe card numbers from local government payment portals
URL: https://www.zdnet.com/article/hackers-swipe-card-numbers-from-local-government-payment-portals/
Author: Catalin Cimpanu

Title: Chinese spies reportedly behind massive Marriott hack
URL: https://www.cnet.com/news/chinese-spies-reportedly-behind-massive-marriott-hack/
Author: Steven Musil

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rob Simon, David Boyd, and Rocky Brockway

Title: Amazon exposed customer names and emails in a 'technical error'

URL https://www.cnbc.com/2018/11/21/amazon-exposed-customer-names-and-emails-in-a-technical-error.html

Author: Jack Gillum

Title: Tiny Twitter thumbnail tweaked to transport different file types

URL: https://www.theregister.co.uk/2018/10/31/twitter_thumbnail_code/

Author: Thomas Claburn

Title: Who’s In Your Online Shopping Cart?

URL: https://krebsonsecurity.com/2018/11/whos-in-your-online-shopping-cart/

Author: Brian Krebs

[Tool Time]

URL:  https://attack.mitre.org/

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rob Simon, Justin Bollinger, and Alex Hammerstone

Title: Yahoo to pay $50M, Other Coasts for Massive Security Breach

URL: https://abcnews.go.com/Technology/wireStory/yahoo-pay-50m-costs-massive-security-breach-58693643

Author: Michael Liedtke

Title: New iPhone Bug Gives Anyone Access to Your Private Photos

URL: https://thehackernews.com/2018/10/iphone-lock-passcode-bypass.html

Author: Mohit Kumar

Title: A mysterious grey-hat is patching people's outdated MikroTik routers

URL: https://www.zdnet.com/article/a-mysterious-grey-hat-is-patching-peoples-outdated-mikrotik-routers/

Author: Catalin Cimpanu

Tool Time

URL: https://blog.netspi.com/exploiting-adidns/

Kingpin: How One Hacker Took Over the Billion-Dollar Cybercrime Underground

https://www.amazon.com/Kingpin-Hacker-Billion-Dollar-Cybercrime-Underground/dp/0307588696

View Details

TS Podcast 3.3 SHOW NOTES
Live from DerbyCon 8!

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rob Simon, Justin Bollinger, and Alex Hammerstone

Title: Facebook Security Breach Exposes Accounts of 50 Million Users
URL: https://www.nytimes.com/2018/09/28/technology/facebook-hack-data-breach.html

Author: Mike Isaac and Sheera Frankel
Title: KRBTGT Account Password Reset Scripts now available for customers
URL:https://cloudblogs.microsoft.com/microsoftsecure/2015/02/11/krbtgt-account-password-reset-scripts-now-available-for-customers/

Author: Tim Rains

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Hans Lakhan, Justin Bollinger, and introducing Logan Sampson

Title: British Airways breach caused by the same group that hit Ticketmaster
URL: https://www.zdnet.com/article/british-airways-breach-caused-by-the-same-group-that-hit-ticketmaster/
Author: Catalin Cimpanu

Title: Microsoft to offer paid Windows 7 Extended Security Updates
URL: https://www.zdnet.com/article/microsoft-to-offer-paid-windows-7-extended-security-updates/
Author: Mary Jo Foley

Title: An Approach to Bypassing Mail Filters
URL https://silentbreaksecurity.com/bypassing-mail-filters/
Author: Will Pearce

Title: Five-Eyes Intelligence Services Choose Surveillance Over Security
Url: https://www.schneier.com/blog/archives/2018/09/five-eyes_intel.html
Author: Bruce Schneier

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rob Simon, Justin Bollinger, and introducing Logan Sampson

Title: Experts Urge Rapid Patching of Struts Bug
URL: https://krebsonsecurity.com/2018/08/experts-urge-rapid-patching-of-struts-bug/
Author: Brian Krebs

Title: Epic Games First Fortnite Installer allowed hackers to download and install silently
URL: https://www.androidcentral.com/epic-games-first-fortnite-installer-allowed-hackers-download-install-silently
Author: Andrew Martonik

Title: The Ticking PHP Time Bomb
URL https://www.linkedin.com/pulse/ticking-php-time-bomb-martin-wheatley/
Author: Martin Wheatley

Title: Crowdsourcing the hunt for software bugs is a booming business—and a risky one
Url: https://www.technologyreview.com/s/611892/crowdsourcing-the-hunt-for-software-bugs-is-a-booming-businessand-a-risky-one/
Author: Martin Giles

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rob Simon, Justin Bollinger, Ben Mauch, and David Boyd.

TS Podcast 3.0 SHOW NOTES

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rob Simon, Justin Bollinger, Ben Mauch, and David Boyd

Title: Vegas - Where Thugs Come Into Your Room And Search Your Stuff
URL: https://www.secjuice.com/defcon-hotel-security-fiasco/amp/?__twitter_impression=true
Author: Infosec Scribe

Title: An 11-Year-Old Hacked Into a U.S. Voting System Replica in 10 Minutes This Weekend
URL: http://time.com/5366171/11-year-old-hacked-into-us-voting-system-10-minutes/
Author: Alix Langone

Title: Putting Stickers On Your Laptop Is Probably a Bad Security Idea
URL https://motherboard.vice.com/en_us/article/pawvnk/stickers-on-laptop-operational-security-bad-idea
Author: Joseph Cox

Title: Practical Web Cache Poisoning
Url: https://portswigger.net/blog/practical-web-cache-poisoning
Author: James Kettle

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rob Simon, Justin Bollinger, and Scot Berner

Show Links:

https://twitter.com/Bitfi6

https://krebsonsecurity.com/2018/07/sextortion-scam-uses-recipients-hacked-passwords/

https://www.cybereason.com/blog/wmi-lateral-movement-win32

https://www.cybereason.com/blog/wmi-lateral-movement-win32

https://www.csis.org/analysis/low-hanging-fruit-evidence-based-solutions-digital-evidence-challenge

Tool Time Notes:

https://github.com/NetSPI/PowerShell/blob/master/Invoke-ExternalDomainBruteforce.ps1

https://bitbucket.org/grimhacker/office365userenum/src

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rob Simon, Justin Bollinger, and Scott White.

Show links:

https://www.recordedfuture.com/reaper-drone-documents-leaked/

https://www.bleepingcomputer.com/news/security/malware-found-in-arch-linux-aur-package-repository/

https://blog.netspi.com/exploiting-adidns/

https://arstechnica.com/information-technology/2018/07/stolen-certificates-from-d-link-used-to-sign-password-stealing-malware/

https://posts.specterops.io/the-tale-of-settingcontent-ms-files-f1ea253e4d39

Tool Time Notes:

https://github.com/trustedsec/unicorn

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rob Simon, Justin Bollinger, Scott White.

Show links:

https://blog.talosintelligence.com/2018/05/VPNFilter.html

https://www.nytimes.com/2018/06/04/technology/microsoft-github-cloud-computing.html

https://www.reddit.com/r/jailbreak/comments/8owp2j/tutorial_ios_1131_kernel_exploit_explanation

https://www.techworld.com.au/article/641555/oracle-plans-dump-risky-java-serialization

http://www.theregister.co.uk/2018/06/05/zip_slip_bug_archives

Tool Time Notes:

https://github.com/sensepost/objection

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rob Simon, Justin Bollinger, Rocky Brockway.

Show links:

https://krebsonsecurity.com/2018/04/dont-give-away-historic-details-about-yourself

https://gizmodo.com/malware-attack-on-vendor-to-blame-for-delta-and-sears-d-1825015769

https://www.bleepingcomputer.com/news/software/firefox-follows-chrome-and-blocks-the-loading-of-most-ftp-resources

https://randywestergren.com/compromising-opendrives-cloud-storage-accounts-or-how-not-to-design-session-management/

https://motherboard.vice.com/en_us/article/7xdeby/t-mobile-stores-part-of-customers-passwords-in-plaintext-says-it-has-amazingly-good-security

Tool Time Notes:

http://www.sqlfiddle.com/

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Rob Simon, Scot Berner, and Adrian Crenshaw.

Show links:

Calendar 2 tried turning Macs into cryptocurrency mining rigs, swiftly rolled back Mac App Store update following reviews

https://letsencrypt.org/2017/07/06/wildcard-certificates-coming-jan-2018.html

https://krebsonsecurity.com/2018/03/look-alike-domains-and-visual-confusion

https://www.cnet.com/news/amd-has-a-spectre-meltdown-like-security-flaw-of-its-own

Tool Time Notes:

https://github.com/securitywithoutborders/hardentools/releases

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Geoff Walton, Ben Tenjamin, Geoff Walton, Scott White, Costa Petros, and Rob Simon

Show links:

http://www.zdnet.com/article/popular-virtual-keyboard-leaks-31-million-user-data/

https://www.bleepingcomputer.com/news/security/man-hacks-jail-computer-network-to-get-friend-released-early/

https://nypost.com/2017/12/03/schumer-says-grinch-bots-are-stealing-christmas/

https://posts.specterops.io/designing-effective-covert-red-team-attack-infrastructure-767d4289af43

https://arstechnica.com/gadgets/2017/12/chrome-will-block-third-party-software-from-meddling-with-its-processes/

Tool Time Notes:

https://github.com/bbb31/slurp

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Ben Tenjamin, Geoff Walton, Scott White, Ryan Leese, Scot Berner, and Rob Simon

Show links:

http://www.securityweek.com/final-version-2017-owasp-top-10-released

https://objective-see.com/blog/blog_0x24.html

http://money.cnn.com/2017/11/22/technology/uber-hack-consequences-cover-up

https://krebsonsecurity.com/2017/12/former-nsa-employee-pleads-guilty-to-taking-classified-data

https://blogs.akamai.com/2017/10/what-you-need-to-know-about-the-roca-vulnerability.html

Tool Time Notes:

https://github.com/al14s/rawr

https://github.com/ChrisTruncer/EyeWitness

https://github.com/michenriksen/aquatone

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Dave Kennedy, Ben Tenjamin, Geoff Walton, Chris Prewitt, Justin Bollinger

Show links:

http://www.nbcnews.com/news/us-news/can-cia-nsa-be-trusted-cyber-hacking-tools-n778731

https://www.theverge.com/2017/7/2/15910826/nato-response-petya-attack-state-actor-russia-ukraine

https://www.reuters.com/article/us-usa-cyber-energy-idUSKBN19L2Z9

https://www.bleepingcomputer.com/news/security/systemd-bug-lets-attackers-hack-linux-boxes-via-malicious-dns-packets/

http://hosted.ap.org/dynamic/stories/E/EU_RUSSIA_KASPERSKY?SITE=KVUE&SECTION=HOME&TEMPLATE=DEFAULT

https://www.binarydefense.com/petya-ransomware-without-fluff/

Tool Time Notes:

https://github.com/byt3bl33d3r/DeathStar

https://labs.mwrinfosecurity.com/blog/add-in-opportunities-for-office-persistence/

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Dave Kennedy, Scott White, Geoff Walton, Costa Petros, and Alex Hamerstone.

Show links:

https://www.wired.com/2017/05/vicious-microsoft-bug-left-billion-pcs-exposed/

http://www.reuters.com/article/us-usa-trump-cyber-idUSKBN1872L9

http://www.binarydefense.com/powershell-injection-diskless-persistence-bypass-techniques/

https://www.nytimes.com/2017/05/09/world/europe/hackers-came-but-the-french-were-prepared.html?_r=0

http://observer.com/2017/05/national-geographic-breakthrough-hacking-trust/

Tool Time Notes:

https://portswigger.net/burp/

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Dave Kennedy, Scott White, Justin Bollinger, Costa Petros, Ben Ten, Chris Prewitt, Jayson E. Street

Show links:

https://www.bloomberg.com/news/articles/2017-05-04/seriously-beware-the-shadow-brokers

https://www.cnet.com/how-to/why-the-google-docs-scam-was-a-different-kind-of-phishing/

http://www.theregister.co.uk/2017/01/13/giuliani_joomla_outdated_site/

http://www.darkreading.com/attacks-breaches/verizon-dbir-shows-attack-patterns-vary-widely-by-industry/d/d-id/1328757

Tool Time Notes:

https://github.com/trustedsec/unicorn

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Dave Kennedy, Justin Elze, Geoff Walton, Scott White, Paul Burkeland, Ben Ten, Alex Hamerstone, and Sarah Norris.

Show links:

https://krebsonsecurity.com/2017/01/who-is-anna-senpai-the-mirai-worm-author/

http://www.welivesecurity.com/2017/01/20/ransomware-attack-hits-st-louis-public-library/

http://www.theregister.co.uk/2017/01/13/giuliani_joomla_outdated_site/

https://www.bleepingcomputer.com/news/security/chrome-users-targeted-with-malware-via-new-font-wasnt-found-technique/

Tool Time Notes:

https://github.com/danielbohannon/Invoke-Obfuscation

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Dave Kennedy, Justin Elze, Geoff Walton, Adrian Crenshaw, Jim McMurry and Ethan Coulter from Milton Security:

Special thanks to Dual Core Music for the intro music and to Milton Security Jim and Ethan for joining the podcast this episode!

Show links:

http://www.wsj.com/articles/cyber-hack-exposes-law-firms-weak-spots-1482965375

http://www.politico.com/story/2016/12/election-hacking-vulnerabilities-233024

http://www.infoworld.com/article/3153217/hacking/5-signs-were-finally-getting-our-act-together-on-security.html

http://www.newsweek.com/hackers-hijack-planes-flight-system-flaw-534071

http://www.wsj.com/articles/trump-namesthomasbossert-chief-adviser-on-homeland-security-1482852680

https://www.trustedsec.com/december-2016/wire-messenger-new-competitor-signal/

Tool Time Notes:

https://www.cobaltstrike.com/

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Dave Kennedy, Justin Elze, Geoff Walton, Rob Simon, Ben Ten

Special thanks to Dual Core Music for the intro music!!

Show links:

http://www.infoworld.com/article/3148145/security/flash-player-remains-target-of-choice-for-exploit-kits.html

http://www.computerweekly.com/news/450404333/PowerShell-security-threats-greater-than-ever-researchers-warn

http://www.npr.org/2016/12/09/504971174/president-obama-orders-review-of-russian-hacking-during-2016-campaign

http://money.cnn.com/2016/12/05/technology/expedia-hack-insider-trading-sec/

https://www.bleepingcomputer.com/news/security/new-exo-android-trojan-sold-on-hacking-forums-dark-web/

http://www.theverge.com/2016/12/8/13892400/samsung-galaxy-note-7-permanently-disabled-no-charging-us-update

Tool Time Notes

Bypassing Two-Factor Authentication on OWA & Office365 Portals

https://github.com/sensepost/ruler
https://github.com/dafthack/MailSniper

View Details

Welcome to the Trusted Security Podcast – a podcast dedicated to bringing the latest news on information security and the industry. This episode features the following members: Dave Kennedy, Geoff Walton, Rob Simon, Paul Burkeland.

Special thanks to Dual Core Music for the intro music!!

Show links:

http://www.arabianbusiness.com/computer-hackers-target-saudi-arabia-in-series-of-virus-attacks-654965.html

http://www.zdnet.com/article/gooligan-android-malware-grabs-a-million-google-accounts-in-huge-google-play-fraud/

http://www.mintpressnews.com/obama-administration-grants-fbi-massive-expansion-hacking-powers/222681/

http://www.csoonline.com/article/3145728/it-jobs/2017-security-predictions.html