Pwned is a weekly information and cyber security podcast addressing real-world security challenges. Occasionally funny, always informational, and driven by those who live and breathe security. Each episode we dive into the latest and greatest in technology, security frameworks, best practices, and how-tos. We’ll chat with industry leaders to learn how they got to where they are, what they see coming, and how they learned from their mistakes.
In this mailbag episode of Pwned, Justin and Jack respond to a listener question that has all the earmarks of a well-known security problem: a new leader starting in an organization with what feels like a random mix of products and problems. By talking through the different elements of the situation, the team offers proven and straightforward suggestions for making the transition more action-oriented, more measurable, and much less stressful.
Check out this week's video:
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
For general information, you can reach us at info@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you on the next one.
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
This week, Justin and Jack are talking AI with one of the security industry’s most well-known experts and influencers, Diana Kelley of Protect AI. The topics, like the growth of AI, are all over the place, from the impacts of AI on security teams to secure AI development, and even a quick mention of the rights of sentient AI. Come hear what’s new in ML SecOps and high-integrity AI, and some well-informed predictions for the future.
If you want to get in touch with Diana, you can find her LinkedIn here.
Check out this week's video:
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
For general information, you can reach us at info@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you on the next one.
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In this breach of the week episode, Justin and Jack look into the recent attacks targeting the GitHub developer community. Developers are increasingly being targeted by North Korean state-sponsored threat actors to use and execute poison code. Tune in to get the scoop.
The DarkReading article can be found here: North Korean Cyberspies Target GitHub Developers (darkreading.com)
CISA’s request for comment can be found here: Request for Comment on Secure Software Self-Attestation Common Form | CISA
Watch this week's video:
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
For general information, you can reach us at info@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you on the next one.
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Multifaceted French security and defense firm, Thales, has acquired longtime application and availability cybersecurity pioneer, Imperva, in a major acquisition from U.S. cybersecurity private equity leader, Thoma Bravo. In this RightSwipes episode of Pwned, Justin and Jack review the histories of both Imperva and Thales, adding valuable context to the market analysis. There’s plenty to talk about and factor into this week’s thumbs-up/thumbs-down conclusion.
Check out the following links for resources mentioned in this episode:
Announcement
Thales
Imperva
Thoma Bravo
Watch this week's episode:
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
For general information, you can reach us at info@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you on the next one.
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In Massachusetts, a group of communities are banding together to improve IT acquisition effectiveness. In this episode of Pwned, Justin and Jack explore the benefits of this alliance, ideas on the cybersecurity impact, and the relationship between this effort and other regional and whole-of-state strategies. It’s a feel-good episode of Pwned, and the team is bringing positive vibes.
Learn more about the North Shore IT Collaborative here: North Shore IT Collaborative | Danvers, MA (danversma.gov)
Watch this week's video:
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
For general information, you can reach us at info@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you on the next one.
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In this episode Justin and Jack are taking a question from the mailbag on choosing regional or private security operations centers (SOCs). The conversation quickly turns to finding the best SOC for your needs, the most beneficial preparation before engaging with vendors, and the right of any organization to demand answers in language they can understand and apply.
Watch this week's video:
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
For general information, you can reach us at info@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you on the next one.
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
From ChatGPT to predictive analytics, AI techniques are changing all industries and knocking on the door of cybersecurity. Justin and Jack are answering with an episode examining potential advancements and limitations that we’ll likely encounter over the next few years. If you’re interested in an experienced, optimistic, but grounded view on what AI can do for your security operation, this is an episode for you.
Check out this week's video:
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
For general information, you can reach us at info@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you on the next one.
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
The White House has released another statement on their National Cybersecurity Strategy. This time Justin and Jack are supportive of the tone and some of the content. In this episode, hear about the new approach to improving cybersecurity with an emphasis on vendor responsibility, liability, opportunities, and outcomes.
Do you think the President’s directive is helpful, or do you think it lacks the specifics for these policies to succeed?
Resources mentioned in this episode:
Policy: FACT SHEET: Biden-Harris Administration Announces National Cybersecurity Strategy | The White House.
Dark Reading: The White House National Cybersecurity Strategy Has a Fatal Flaw (darkreading.com) by Eyal Mamo.
Request for Comment on Software Security Attestation: Request for Comment on Secure Software Self-Attestation Common Form | CISA by CISA.
For more insight on federal cybersecurity policy, listen to our 2022 White House Week series:
Presidential Prerogative – “Bulletproof Cybersecurity in One Week or Less”
Another Presidential Push - This Time It’s National
Washington Week 3 is Spelled SEC
Check out this week's video:
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
For general information, you can reach us at info@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you on the next one.
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In this RightSwipes episode, the unexpected union of Proofpoint and Illusive creates an irresistible combination for Justin and Jack. They're talking through the applicability of deception technology, market appetite, and Proofpoint's move to deepen their bench with Illusive. The question remains whether Proofpoint was looking to strengthen identity-based defenses of if there's a broader strategy in motion.
As referenced in this episode, you can check out Ericka Chickowski's article on DarkReading here.
Watch this week's video here:
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
For general information, you can reach us at info@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you on the next one.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In this episode, Justin and Jack are talking about threat intelligence, from its ideal content mix to the audience, and ways to improve its usefulness and availability. Threat intel is about more than feeds. It's about hunting, sharing, and enriching our understanding of threats whenever we can.
Check out our SLED Cybersecurity Priorities Report here to examine top cybersecurity priorities in SLED, what's fueling them, and how you can implement them in your organization.
Check out this week's video:
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
For general information, you can reach us at info@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you on the next one.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In part two of “An Old Friend, Some Old Equipment, and New Challenges All Around”, we welcome back Zack Borst. Since his departure from NuHarbor Security, Zack has since embarked on a mission to enhance emergency management, including cyber preparedness, and now he's talking with Justin and Jack about the state of cybersecurity systems and subsequent challenges. Join the trio for the second part of this eye-opening discussion about technology, threats, aging equipment, critical services, and the troubling mix of kinetic and cybersecurity emergencies.
Watch this week's video here:
Check out EM Weekly at EM Weekly — The Readiness Lab or on your favorite podcast streaming service.
You can find Zack on Linked in here: https://www.linkedin.com/in/zborst/, or by email at zack.borst@dobermanemg.com.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
For general information, you can reach us at info@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you on the next one.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Our latest episode welcomes back Zack Borst, former co-host and co-contributor to PWNED in its earlier seasons. Zack has since embarked on a mission to enhance emergency management, including cyber preparedness, and he’s talking with Justin and Jack about the state of cybersecurity systems and subsequent challenges. It’s an eye-opening discussion that blends technology, threats, aging, equipment, critical services, and the troubling mix of kinetic and cybersecurity emergencies. Gain insight into an emerging arena and a heightened urgency for cybersecurity improvements.
Watch this week’s video here:
You can find Zack on Linked in here: https://www.linkedin.com/in/zborst/, or by email at zack.borst@dobermanemg.com.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
For general information, you can reach us at info@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We’ll catch you on the next one.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In an episode that is close to Jack’s heart and history, he and Justin explore a renewed interest in the security of applications. They discuss the new Application Security Center of Excellence (ASCOE) being built at the Commonwealth of Massachusetts, shifting far left of boom by prioritizing contract language, and the importance of championing the need for application security before implementing any program.
Listen in for practical ways to make progress in an area that will only get better by working on the applications you’ll see tomorrow.
Key moments:
1:51 – Introduction to application security.
8:26 – Application security surrounding AI/ChatGPT. Is open source insecure?
9:38 – Application security = restaurant?
10:39 – In a world where no one wants you to get in front of application security, how do you get in front of it?
18:15 – Strong application security requires healthy communication.
21:38 – Why is application security so important?
25:26 – Application security is not a one-and-done deal; it goes on forever. It’s a continuing cycle of Whac-A-Mole.
Watch this week’s episode here:
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
For general information, you can reach us at info@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We’ll catch you on the next one.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In this episode, Justin and Jack delve into the growing trend toward increased investment in detection and response. With the rise in successful attacks and public breaches, detection and response are getting plenty of love, sometimes at the expense of preventative measures. Tune in as our duo explore the current state of affairs, share their observations on various response tactics, and provide valuable insight for listeners who are considering investing in cybersecurity capabilities to reduce the likelihood or impact of inevitable threats.
Check out this week’s video:
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
For general information, you can reach us at info@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We’ll catch you on the next one.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In this mailbag edition of PWNED, Justin and Jack are presented with a question from a listener who’s feeling pressured to justify continuing cybersecurity tooling spend. They’ve seen this happen repeatedly and offer recommendations for responding with well-articulated tradeoffs and benefits and preparing for budget cuts during the proposal and acquisition process.
Ultimately, security leaders do their best when they can maximize value from their existing tooling, or garner support from non-security stakeholders that can translate the negative impacts of reduced security capabilities into business terms. Listen in for practical advice as security teams start to bear more scrutiny and field more requests for spending justification in tight economic times.
Check out this week’s video:
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
For general information, you can reach us at info@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We’ll catch you on the next one.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In this episode, Justin and Jack discuss a recent CISO dialogue around the difficulties in replacing staff that move on, and strategies for easing the impact of losing talented folks to competitors or lottery wins. From educating other team members, to succession planning and developing close relationships with vendors there are ways to prevent the unexpected loss of teammates from resulting in a corresponding loss of sleep.
Check out this week’s video:
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
For general information, you can reach us at info@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We’ll catch you on the next one.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In this episode, Justin and Jack respond to a note from the mailbag. A listener inquires about successful approaches to recruiting support for security initiatives, and the team shares stories about educating stakeholders, developing champions, and encouraging security program collaborators, especially when planning a multiyear, multipronged strategy.
Check out this week’s video:
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
For general information, you can reach us at info@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We’ll catch you on the next one.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Following a listener request, Justin Fimlaid and Jack Danahy are talking about successful paths forward when a CISO finds themselves in a role that’s a little larger than they expected, or an organization has a well-meaning CISO that needs a little more time to get it right. This happens all the time, and it doesn’t have to end with burning out or throwing out an otherwise capable executive. If you find yourself in that oversized chair, sit back and give a listen.
Helpful links:
The Hunt for the Super CISO Part 1
The Hunt for the Super CISO Part 2
CISO Job Description Download
Check out this week’s video:
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Following well-publicized comments from Zurich Insurance CEO Mario Greco on the potential demise of cyber insurance, Justin and Jack are digging deep. They describe the challenge to insurers, the potential for unlimited liability, and propose a new and more intentional model that benefits insurers, clients, and the CISOs involved. It’s a new take on a thorny problem, with lessons for all players.
Links:
Are Cyber Attacks Uninsurable?
World Economic Forum 2020 Grim Insurance Predictions
On a lighter note: Whisky Home – Old Forester | First Bottled Bourbon™
Check out this week’s video:
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In this last episode of PWNED Season 3, Justin and Jack are paying off the year’s debts from infractions against the Pit of Despair, while analyzing a BlackHat announcement by a leader in the market. There are debts to be paid, and there’s a striking new example of the old security tendency to obscure, over-the-top messaging. The season is going out with a bang, and it looks like Season 4 will start with a blank slate but a full list of issues to watch for.
As mentioned in this episode, check out the Security Bullshit Generator!
Check out this week’s video:
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
After much work and a little fanfare, the 2022 SLED Cybersecurity Priorities Report has been publicly released. Justin and Jack are giving a quick overview of the findings, along with their usual, and unavoidable, take on some of the results. For those of you who have participated in the research or have been following the lead-up to this day, you’ll be glad to hear that the result does not disappoint.
Here’s the announcement: SLED Leaders Find Roadmap for 2023 Success in Groundbreaking Report From NuHarbor Security | Business Wire
And here’s the CPR: https://info.nuharborsecurity.com/2022-sled-cpr
In this episode of PWNED, Justin springs an unexpected topic, based on his deep affection for social media. Seeing a post from a security leader who feels he has been unfairly held accountable by his company, he’s bringing it to the podcast. We’ve got victimhood, CISO expectation setting, transparency, and disappointment, all in one episode as Jack and Justin take this common feeling apart.
As referenced in this episode, you can find the book, “Can’t Hurt Me”, by David Goggins here: Can’t Hurt Me, David Goggins
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We’ll catch you on the next one.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In this episode, Justin and Jack are talking about the trends, common concerns, and research done to support the soon-to-be-released 2022 SLED Cybersecurity Priorities report. Input from hundreds of sources has been combined with insights from major vendors and the NuHarbor team to deliver some surprising conclusions about the state of the SLED cybersecurity landscape and the leaders that are transforming protection of public services and public trust.
As referenced in this episode, check out this article by Wendy Nather (2011) on the The Security Poverty Line.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you on the next one.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Following the news that Twitter, now owned by Elon Musk, is charging users for a "blue check" next to their name -- an icon that once signaled a verified and authentic user, Justin and Jack discuss the cybersecurity implications behind this new phenomenon, and clear away the confusion and chaos that comes with it.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you on the next one.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In this RightSwipes episode of Pwned, Justin and Jack start with an analysis of the recent CrowdStrike acquisition of Reposify, and while they may not agree on the love match, it starts an interesting new debate on "Best-in-Breed" versus "Combined Value" players in cybersecurity. It's an important point of inflexion for companies, and maybe for the cybersecurity market, so listen in.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you on the next one.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In this final episode with Justin and Jack speaking to a group of state security leaders, the PWNED team is talking about a series of topics from new, more successful awareness campaigns to the challenges of avoiding being a target in the first place. This entire session is driven by audience questions, and you may hear one that you’d have asked were you there.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you on the next one.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In their second episode in front of a group of public sector tech execs, Justin and Jack are talking about the challenge and risks of application security, including the cascading exposure from supply chain vulnerabilities like log4j. They also spend some time talking about the attack trend towards automation and the ubiquitous threats that indiscriminately target organizations regardless of size or specialty. It’s another episode driven by listener questions and current events, with a focus on the impact to mid-sized organizations and those who serve through the SLED community.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you on the next one.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In this first installment of a three-part series, Justin and Jack are speaking with public sector leaders about the unique challenges and successes of securing platforms and systems within the State, Local, and higher Ed (SLED) community. They’ve got plenty of experience and plenty to say as they answer questions about current threats, new approaches, and the patterns of success that NuHarbor has seen over the past few years.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you on the next one.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Following another school system breach and some pretty dire reporting, Justin and Jack are reviewing current events and talking about the current environment of risk and impact to K-12. There is plenty to discuss, but the result is a much more balanced view and some thoughts on applying a reasonableness filter to the stories we're hearing.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you on the next one.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In a new two-for-one Breach of the Week, Justin and Jack discuss a couple of controversial events from the news this week. First, the recent disclosures by Twitter’s Pieter (Mudge) Zatko and a follow-on article by long-time security icon Edward Amoroso, have our hosts sharing two different points of view on what the story means. Second, we get back to a harmonious Pwned cast as Justin and Jack discuss the recent LastPass source code breach, which was handled quickly and effectively by the LastPass team. It’s a two-fer, combining the role of the CISO and the hyperbole of breach reporting, all in one BOTW episode.
Helpful Links:
Edward Amoroso's article
CNN Business article reporting on Mudge
LastPass blog post
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you on the next one.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Justin and Jack join John Egan of Mad River Distillers for a chat about his thoughts on cybersecurity acquisitions, and his own experience as a lawyer in the technology field. Special thank you to John and the rest of Mad River Distillers employees for welcoming the team and giving their time.
Justin and Jack took the time to write out reviews of some of the beverages from Mad River. Those can be found below:
Burnt Rock Bourbon
The Burnt ROck Bourbon had a long finish, combining a sweet undertone of vanilla and oak with a distinctive power at the front of the palate.
Revolution Rye
The Revolution Rye is a spicy entrant, capable of standing up to an ice cube, or even a little mixing, without losing it's personality. That's why we featured it in our Old Fashioned Madman cocktail.
PX Rum
All of the bourbons and even the featured special, a caramel-y rum called the Mad Rive PX Rum, have a custom feel to them. There is a sense that somebody specifically put that booze in that bottle with thought for who would be drinking it.
If you want to reach out to John Egan, you can email him at jegan@goodwinlaw.com, or find him on LinkedIn.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you on the next one.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
We've got more mail! Thank you to Mike for sending in this intriguing questions about how to decide what cybersecurity college program to attend to get the most for your future. Justin and Jack have an answer for you, and it's a little more complicated than you would think; take a look at a program's past and present successes to determine what you want your future to be.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you on the next one.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
With the release of the new Enterprise Strategy Group (ESG) report, by Jon Oltsik, in late July, Justin and Jack sit down and discuss their thoughts on the research and the importance of consolidating industry-wide terminology and technology. Will they deem the report to be spot-on, or are there just too many unrealistic expectations? Tune in to find out!
If you would like to read through the ESG report, please click here.
For information on the AWS conference, please click here.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you on the next one.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Jack is back at it this time at the National Association of Counties (NACo) conference in Aurora, Colorado. Justin attempts to remotely highjack the microphone to discuss Maslow's Hierarchy of Needs for Cybersecurity with the audience. Justin checks in before and after the presentation to discuss talking points, maturity of an organization, and how the presentation went.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you on the next one.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In this special Pwned episode, Justin and Jack discuss Almanna Cyber - their new cybersecurity accelerator fund. Almanna, derived from the Old Norse word for "everyone", is just that: a cyber accelerator for everyone. The J's are inviting new cyber startups and individuals with a great ideas to apply for membership in their first cohorts. Sharing over 50 years of experience in the industry, and having built multiple successful cybersecurity businesses, Justin and Jack will help cohort members to grow their own ideas and companies into a strong, successful, cyber business.
Pwned content will still be released weekly, but keep an eye out for their new podcast as well: Cyber Engine, which can be found on your favorite podcast streaming apps, or through the Almanna Cyber Website. To listen to the first episode, please click here.
For questions regarding Almanna Cyber, please visit www.almannacyber.com, or email Justin at justin@almannacyber.com or Jack at jack@almannacyber.com.
If you have any questions or suggestions regarding Pwned, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you on the next one.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
US birth rates are the lowest in 40 years, and we may be seeing a spread of that trend into our RightSwipes matchups. With no meaningful Swipes in sight, Jack and Justin are taking a look at the SwipeScene and drawing some conclusions (and predictions) about the Swipeless period we find ourselves in. Is it a return to the bright lights of fundamental analysis showing some of the real faces behind the carefully crafted cosmetics, or is everyone taking a "wait & see" attitude towards the end of the night? Hard to tell, but Justin and Jack are making some prognostications for the quarterly and yearly likely SwipeStats.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In this GOGO (Give One, Get One) episode of Pwned, Justin and Jack discuss two recent breaches. The first, a breach of 23 million compromised accounts from CafePress that was disguised to users as a password policy update; and the other a recipe for a hot tub breach with a side of "hot, stinky soup".
To access the articles we reference in this episode, check out these links below:
Judgment against CafePress CafePress Fined $500,000 After Massive Data Breach CafePress Slammed After Major Breach Affecting 23 Million Hacking Into the Worldwide Jacuzzi SmartTub Network Jacuzzi Could be Hacked, Turned Into "Hot, Stinky Soup", Researcher Warns
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
An overachieving heart surgeon in Venezuela has turned his hand to ransomware, and it looks like his heart was really in it. Sadly for him, but great for those us losing "patients" with this cottage economy, he was busted by the FBI, and it's Code Blue for his highly-rated, 5-star reviewed, $10K+/month, custom ransomware platform and SDK. Justin and Jack break it down and talk through the details and the factors that are making this type of malpractice possible.
For more information on this topic, check out these links:
Medical Economics Article by Todd Shyrock SecurityWeek Article
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
As their portfolio companies (and everyone else) are facing a sea change in market and financing conditions, Sequoia Capital has shared their recommendations for surviving the storm. In this episode of Pwned, Justin and Jack provide a Pwned-style interpretation and application of the insights while taking a regretful victory lap over their earlier predictions that this market reset was also coming for cybersecurity.
For more information on references we make in this episode, check out the links below:
Sequoia Deck Hungry Hungry Hippos Synthetic Unicorns Cybersecurity Company Uncertainty
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Applications are the root of so many things we use on a day-to-day basis. In this episode, Justin and Jack discuss a way more pragmatic approach to application security than securing all data at once.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Justin and Jack are joined by NuHarbor ace recruiter, Olive Robb, for an open discussion of cybersecurity recruiting, the job market, and an employer's view of resumes that show lots of movement. It's a candid conversation, as usual, with some recommendations about making the most out of your own positions and time in the cybersecurity market.
Olive is happy to connect directly over email or LinkedIn regarding opportunities here at NuHarbor. Looking for future opportunities or don't see something exactly up your alley? We also have a general careers email if you wish to send along your resume.
Olive's LinkedIn: Olive Robb | LinkedIn
Olive's email address: orobb@nuharborsecurity.com
NuHarbor's general careers email: careers@nuharborsecurity.com
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In the second half of our CISO recruiting series, Justin and Jack are talking about the pressure, about incident handling, and about the importance of intellectual curiosity in this hire. There are tips for candidates, hiring teams, and even executive management in general, on what to expect, and how to look for it.
To view our CISO job description write up, click this link.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
The first of a two-part series, this episode highlights what qualities make a good Chief Information Security Officer (CISO), along with how to find the perfect candidate and what the right questions are to ensure they meet those capabilities. Make sure you tune in for part 2!
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In this Breach of the Week episode, Justin and Jack share the story of how 600 million USDC was stolen from Axie Infinity, as well as some other crypto catastrophes with the purpose of deciding whether cryptocurrency has the stability and safety to move from its current second-class status to a legitimate, recognized, form of practical currency.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Following the National Collegiate Cyber Defense Competition (NCCDC), Justin and Jack talk with their director, Dwayne Williams, about the competition, his own history, and some insights on the next generation of security leaders. We even get his well-honed view of the likely future of the cybersecurity space and threats within it. A special thank you Dwayne for taking the time to bring his voice to Pwned, and for his continuing efforts to raise the caliber and quantity of college students moving into cybersecurity.
Congratulations to the University of Central Florida on their triumph, and to all the finalists for securing a place in the national competition.
If you wish to get in contact with Dwayne, you can email him at dwayne.williams@utsa.edu.
For information on the NCCDC, please visit this website.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Justin and Jack are digging into the pressures and practical realities of cybersecurity investing, both from investor and company perspectives. From a need to spend to the evanescence of some valuations, the two J's are taking party hats off of ponies and providing some advice for companies that are currently feeling the pinch of an emerging and more realistic investor appetite.
To read the article we referenced in this episode, click here. The picture we reference can be found below.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In this episode of RightSwipes, Justin and Jack take a look at Security Week's article of 40 cybersecurity company acquisitions that took place just in the month of March of 2022.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Following up on our January prognostications, Justin and Jack highlight the emergence of the foreshadowed "mXDR" vendors and the causes of the ongoing devolution of security language. All isn't lost, though, as the team recognizes the potential for a beneficial new set of demands from Board-level security voices.
To listen to the XDR episode, "Pwned GigaByte - The Pit of Despair", click here!
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In a Washington Week series where the team has reviewed both private and public sector cybersecurity memoranda from the President, they're now looking at an announcement that really matters; cybersecurity guidelines from the Securities and Exchange Commission. Will this be the catalyst of change? Will these requirements make cybersecurity better? Probably not.
If you want to read more about the subject, check out these links below:
SEC Rule Announcement SEC Rule Summary Full SEC Rule Sarbanes-Oxley Regret Judge Learned Hand and the Formula for Neglect Forbes Article Harvey Dent Reference
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In the second Pwned Washington Week episode, Justin and Jack are interpreting the President's National Security Memorandum #8 and they're finding more trees than forest. Add to that a call for a different style of advisor to the President, a metaphorical insertion of Harvey Dent, and it's a full basket of Pwned insights.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In the first episode of Pwned's Washington Week series, Justin and Jack lay out the details of the Biden Administration's announcement on protecting national security. Is it too little, too late, too optimistic, or just more political noise?
If you're interested in reading the articles we mentioned in this episode, check the links below!
Statement by President Biden on our Nation's Security FACT SHEET: Act Now to Protect Against Potential Cyberattacks
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Justin and Jack surf on the recent Forrester Wave for Global Cybersecurity and end up hanging ten on some of the criteria, but wiping out on its usefulness.
Some links we referenced in this episode can be found here:
Bullsh*t Generator
Alinea Restaurant
Forrester Lead Analyst, Jeff Pollard
PWC Link to Forrester Report
McDonald's in Paris
Top 10 Accounting Firms in the US
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
With no security hookups in sight, Pwned is digging into the investment fever in the cybersecurity meat market, from the reasons behind the massive valuation to the impact of these investments on security vendors and customers. It may not be RightSwipes, but it is definitely part of that process.
In this episode, we referenced CrunchBase's article "Cybersecurity Funding Remains High Even as Venture Cools Off". You can find the article by clicking here.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In this mailbag episode, Justin and Jack are looking at security vendor Zscaler, answering an inbound from Alvin, a listener in Canada. His question and the topic is whether or not Zscaler is a good choice and a good investment, and the answer is clear.
If you missed the episode of Pwned with SentinelOne and Attivo that we referenced in this episode, you can listen to it here.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
And we're live!! On March 18th, Justin and Jack took to the stage at the Northeast Collegiate Cyber Defense Competition (NECCDC), hosted at Champlain College, where they presented an episode of PWNED in front of a live audience. The future of cybersecurity; one where we reduce the complexity and confusion of cybersecurity, starts with this new generation of security minds who will be entering the workforce over the next few years. Together we need to make cybersecurity easier.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Justin and Jack turn up the heat by throwing a painfully over-used and under-accurate term, "Trusted Advisor", into the depths of the Pit of Despair.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In this week's RightSwipes, Justin and Jack talk about SentinelOne's acquisition. Have they been subject to Attivo's deceptive ways?
Some pieces of media we mentioned in this episode are:
SentinelOne's Q4 Earnings Call Transcript
Mandiant's Announcement of Partnership with SentinelOne
2019 PWNED Episode - The Best Security Technology You Probably Aren't Using
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Finally face-to-face, Justin and Jack discuss 3 ways to power through cybersecurity product technology, uncertainty, and doubt, to get to know a company before joining as an employee, purchasing as a consumer, or investing as an investor.
Huge thanks to Robby Dow (LinkedIn | Instagram | Article), our own Katy Feifs' brother, for his stellar recommendation of Old Forrester 1920 Prohibition Style bourbon.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Another pull from the mailbag combined with some wisdom from BSides' Jack Daniel prompt Justin and Jack to talk about the importance and authenticity of cyber grassroots groups.
"These types of organizations are exactly who we need in the community" - Justin Fimlaid
We would like to give a huge shoutout to the following individuals and groups:
Jack Daniel - LinkedIn Page Steve Morgan & Cybersecurity Ventures - Cybersecurity Ventures LinkedIn ; Cybercrime Magazine Website ; Diana Kelley - LinkedIn Page Tenable - Website Shoulders of Infosec - Tenable Article Written By Jack Daniel Breaches and Beers - To reach out to the group, shoot an email to bb@squidanddagger.com
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Recently, former ransomware group Lapsus$ threatens to expose the private information of NVIDIA if they don't stop disabling crypto-mining. Justin and Jack break it down.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
The links we mentioned in this podcast can be found below:
Brett Callow Tweets
Ars Technica Article
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In a security community match that tops a Kardashian hookup, Google and Mandiant have found each other and this time, Justin and Jack aren't in sync on the love match. Come hear why.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
To view our Google and Siemplify episode mentioned, click here.
To view an archive of all of our podcast episodes, click here.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
A new Breach of the Week episode highlights NSO, Pegasus, and iPhone breaches.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Resources Mentioned:
New York Times Article
Washington Post Article
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
A rant on "Eyes on Glass" turns into a new entry into the Pit of Despair.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
It looks like KKR and Optiv may be moving on. Was this a missed Swipe, or have they just grown apart? Justin and Jack have got the details.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Jesse wants to go from Down Under to tops in cybersecurity, and is looking to Justin and Jack for some advice.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Cybersecurity has evolved over the years. The increased accessibility of features and functionality requires less understanding of the cybersecurity practice and discipline to be successful. Is the "art of cybersecurity" lost, or does a shift in consumption bring more people to the fight?
At the 3:08 minute mark, we reference episode 8: "We've Got Mail - The Science of Security Spend". Make sure you give it a listen!
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
You ask, we answer. Thank you to investor Ryan for your insightful question into market share, security vendors, and what it means for the security marketplace.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
This week's Pwned episode comes with a zero-sum Breach of the Week! Jack and Justin talk one publicly disclosed breach, and one publicly disclosed breach that could have been, but wasn't.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
This week’s Pwned episode comes with a zero-sum Breach of the Week! Jack and Justin talk one publicly disclosed breach, and one publicly disclosed breach that could have been, but wasn’t.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We’ll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://www.nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Google recently acquired Siemplify to integrate it into Google Cloud Chronicle. Jack and Justin give the run down of the pair and decide if the match has chemistry and will thrive in their relationship, or if Google should have just gone home alone.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We’ll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://www.nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Google recently acquired Siemplify to integrate it into Google Cloud Chronicle. Jack and Justin give the run down of the pair and decide if the match has chemistry and will thrive in their relationship, or if Google should have just gone home alone.
If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com.
If you like our content, please like, share, and subscribe! We'll catch you next time.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
We're back - like Groundhog Day! Wait, it is Groundhog Day! The debate of supporting open source software and software supply chain security keeps repeating. Learn what one programmer does to get peoples attention and put an explanation point on the power that open source software developers have.
Earmuff your whistle pigs and open the bottle of WhistlePig while you listen to the story of the Punxsutawney Programmer. Holiday notes can be sent to pwned@nuharborsecurity.com
(Justin writing - do me a solid! Please like, share, subscribe)
VIL (Very Important Links):
JavaScript developer screws over own popular npm packages • The Register
Dev corrupts NPM libs 'colors' and 'faker' breaking thousands of apps (bleepingcomputer.com)
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
We’re back – like Groundhog Day! Wait, it is Groundhog Day! The debate of supporting open source software and software supply chain security keeps repeating. Learn what one programmer does to get peoples attention and put an explanation point on the power that open source software developers have.
Earmuff your whistle pigs and open the bottle of WhistlePig while you listen to the story of the Punxsutawney Programmer. Holiday notes can be sent to pwned@nuharborsecurity.com
(Justin writing – do me a solid! Please like, share, subscribe)
VIL (Very Important Links):
JavaScript developer screws over own popular npm packages • The Register
Dev corrupts NPM libs ‘colors’ and ‘faker’ breaking thousands of apps (bleepingcomputer.com)
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://www.nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Zero Trust is a highly attractive term that conjures beneficial impacts, but is inconsistently defined (hint: it means “Don’t Trust Anything”). Its history of overuse means Justin and Jack have to spend some time making it clear.
Beware the Pit of Despair!
If you have any suggestions on what might fall into the pit next, send us an email at pwned@nuharborsecurity.com.
Content referenced in this episode can be found in the links below:Microsoft’s approach to advocating for a Zero Trust business plan.
John Kindervag’s Zero Trust Network Architecture video.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://www.nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Zero Trust is a highly attractive term that conjures beneficial impacts, but is inconsistently defined (hint: it means "Don't Trust Anything"). Its history of overuse means Justin and Jack have to spend some time making it clear.
Beware the Pit of Despair!
If you have any suggestions on what might fall into the pit next, send us an email at pwned@nuharborsecurity.com.
Content referenced in this episode can be found in the links below: Microsoft's approach to advocating for a Zero Trust business plan. John Kindervag's Zero Trust Network Architecture video.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Episode 3 of the Pwned podcast is here and a new victim, Trellix, joins its old friend XDR in the Pit of Despair. Join Justin and Jack through their deep dive into the pit. If you have any suggestions on who might fall into the pit next, send us an email at pwned@nuharborsecurity.com.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website:https://www.nuharborsecurity.com Facebook:https://www.facebook.com/nuharbor/ Twitter:https://twitter.com/NuHarbor@nuharbor LinkedIn:https://www.linkedin.com/company/nuharbor/ Instagram:https://www.instagram.com/nuharborsecurity/
Episode 3 of the Pwned podcast is here and a new victim, Trellix, joins its old friend XDR in the Pit of Despair. Join Justin and Jack through their deep dive into the pit. If you have any suggestions on who might fall into the pit next, send us an email at pwned@nuharborsecurity.com.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Welcome back to season 3 of Pwned! In this Breach of The Week episode, Justin and Jack cover the base and the wind up of the log4j vulnerability exposed in December, and the impact it has on the world’s supply chain. Tune in to learn more about the vulnerability, and how NuHarbor Security can help you secure your network.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website:https://www.nuharborsecurity.com Facebook:https://www.facebook.com/nuharbor/ Twitter:https://twitter.com/NuHarbor@nuharbor LinkedIn:https://www.linkedin.com/company/nuharbor/ Instagram:https://www.instagram.com/nuharborsecurity/
Welcome back to season 3 of Pwned! In this Breach of The Week episode, Justin and Jack cover the base and the wind up of the log4j vulnerability exposed in December, and the impact it has on the world's supply chain. Tune in to learn more about the vulnerability, and how NuHarbor Security can help you secure your network.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Aaaaaaand…. We’re back! Justin and Jack kick off season 3 of Pwned by introducing the Pit of Despair, where marketing terms end up when they have a strong start and a promising future, but derail from the path of meaning and end up in the ditches. What will the first victim of the Pit of Despair be?
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Aaaaaaand…. We’re back! Justin and Jack kick off season 3 of Pwned by introducing the Pit of Despair, where marketing terms end up when they have a strong start and a promising future, but derail from the path of meaning and end up in the ditches. What will the first victim of the Pit of Despair be?
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. **Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
Pwned Season 3! WE’RE BACK! Time to rub the haze out your eyes and earmuff the kids. Gloves are off this time. I’ve had too long with my personal thoughts and the cybersecurity industry still can’t figure this thing out. Season 3 kicks off in January! Catch you later!
**Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
Pwned Season 3! WE'RE BACK! Time to rub the haze out your eyes and earmuff the kids. Gloves are off this time. I've had too long with my personal thoughts and the cybersecurity industry still can't figure this thing out. Season 3 kicks off in January! Catch you later!
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Pfizer falls victim to cloud misconfiguration. Clouds can be complex. 🙁
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
Cool places to read about this BOTW (especially if you don’t trust our info):
https://www.healthcareitnews.com/news/emea/pfizer-covid-19-vaccine-data-leaked-hackers
https://www.infosecurity-magazine.com/news/pfizer-exposes-data-hundreds-drug/
https://securityboulevard.com/2020/10/pfizer-suffers-huge-data-breach-on-unsecured-cloud-storage/
Pfizer falls victim to cloud misconfiguration. Clouds can be complex. :(
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Cool places to read about this BOTW (especially if you don't trust our info):
https://www.healthcareitnews.com/news/emea/pfizer-covid-19-vaccine-data-leaked-hackers
https://www.infosecurity-magazine.com/news/pfizer-exposes-data-hundreds-drug/
https://securityboulevard.com/2020/10/pfizer-suffers-huge-data-breach-on-unsecured-cloud-storage/
This week we're surveying identity as a mechanism of compromise in a first-of-its-kind "Partner Spotlight" series. In Part 2, we chat with Brandon Traffanstedt, Global Director, Solutions Engineering at CyberArk. He digs into the complications of super powerful access, and reminds us exactly why we don't write our passwords on sticky notes.
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
This week we’re surveying identity as a mechanism of compromise in a first-of-its-kind “Partner Spotlight” series. In Part 2, we chat with Brandon Traffanstedt, Global Director, Solutions Engineering at CyberArk. He digs into the complications of super powerful access, and reminds us exactly why we don’t write our passwords on sticky notes.
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
This week we're surveying identity as a mechanism of compromise in a first-of-its-kind "Partner Spotlight" series. In Part 1, Justin talks shop with CyberArk's Scott Whitehouse, VP Channels and Alliances for the Americas. Get the scoop on how NuHarbor partner and global leader in privileged access management continues to innovate in the name of helping folks become consistently more secure.
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
This week we’re surveying identity as a mechanism of compromise in a first-of-its-kind “Partner Spotlight” series. In Part 1, Justin talks shop with CyberArk’s Scott Whitehouse, VP Channels and Alliances for the Americas. Get the scoop on how NuHarbor partner and global leader in privileged access management continues to innovate in the name of helping folks become consistently more secure.
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
Every company operating in the United States is required to maintain a Form I-9 file on every employee to ensure that they are legally allowed to work and not subject to more restrictive immigration rules. But Form I-9 files can contain a ton of sensitive information making a good target for identity thieves.
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
Reputable places to read more about this BOTW:
https://www.law.com/therecorder/2020/10/27/fragomen-reports-data-breach-impacting-some-google-employees
https://www.reuters.com/article/dataprivacy-fragomen-googlebreach/fragomen-says-breach-exposed-google-employees-information-but-client-data-systems-safe-idUSL1N2HJ020
https://techcrunch.com/2020/10/26/fragomen-data-breach-google-employees/
Every company operating in the United States is required to maintain a Form I-9 file on every employee to ensure that they are legally allowed to work and not subject to more restrictive immigration rules. But Form I-9 files can contain a ton of sensitive information making a good target for identity thieves.
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Reputable places to read more about this BOTW:
https://www.law.com/therecorder/2020/10/27/fragomen-reports-data-breach-impacting-some-google-employees
https://www.reuters.com/article/dataprivacy-fragomen-googlebreach/fragomen-says-breach-exposed-google-employees-information-but-client-data-systems-safe-idUSL1N2HJ020
https://techcrunch.com/2020/10/26/fragomen-data-breach-google-employees/
Geez, I guess nothing is off limits. Vastaamo was first breached in 2018, but this...just...keeps...going. Vastaamo has been requested by attackers to pay half a million USD in Bitcoin. But to make it worse employees and patients are also targets of extortion.
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Other places to grab information on this BOTW:
https://blog.malwarebytes.com/cybercrime/2020/10/vastaamo-psychotherapy-data-breach-sees-the-most-vulnerable-victims-extorted/
https://www.scmagazine.com/home/security-news/data-breach/vastaamo-breach-is-blackmailing-individual-customers-the-next-extortion-trend/
https://threatpost.com/vastaamo-hackers-blackmailing-therapy-patients/160536/
Geez, I guess nothing is off limits. Vastaamo was first breached in 2018, but this…just…keeps…going. Vastaamo has been requested by attackers to pay half a million USD in Bitcoin. But to make it worse employees and patients are also targets of extortion.
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
Other places to grab information on this BOTW:
https://blog.malwarebytes.com/cybercrime/2020/10/vastaamo-psychotherapy-data-breach-sees-the-most-vulnerable-victims-extorted/
https://www.scmagazine.com/home/security-news/data-breach/vastaamo-breach-is-blackmailing-individual-customers-the-next-extortion-trend/
https://threatpost.com/vastaamo-hackers-blackmailing-therapy-patients/160536/
Long story short, somebody hacked Harvest Finance and by manipulating asset values, stole tens of millions of dollars. Soon there was a bounty on the black hat, and the relationship is still complicated – Harvest is offering the hacker $1M for their $23M back.
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
Long story short, somebody hacked Harvest Finance and by manipulating asset values, stole tens of millions of dollars. Soon there was a bounty on the black hat, and the relationship is still complicated - Harvest is offering the hacker $1M for their $23M back.
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
So Nitro PDF got hit. The popular PDF software had an undisclosed number of accounts and files released into the wild. Contracts, agreements, love letters, etc. were up for sale on the dark web within hours. Hear what Justin hates to say about it.
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
So Nitro PDF got hit. The popular PDF software had an undisclosed number of accounts and files released into the wild. Contracts, agreements, love letters, etc. were up for sale on the dark web within hours. Hear what Justin hates to say about it.
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
In this week’s episode, we look into a big hack at one of the last bookstore giants. Barnes and Noble got whacked in both their brick and mortar and their cyber stores preventing purchases and virtual book reading. Justin discusses why he picked the Nook over the Kindle and Zack laments that the last big bookstore is getting picked on.
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
In this week's episode, we look into a big hack at one of the last bookstore giants. Barnes and Noble got whacked in both their brick and mortar and their cyber stores preventing purchases and virtual book reading. Justin discusses why he picked the Nook over the Kindle and Zack laments that the last big bookstore is getting picked on.
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
We are joined by Jeff to talk social engineering both in the real world and the digital world. Jeff talks about how the movie Sneakers sparked his interest, how he got paid to sneak into people's buildings, and why we see so many people getting duped today.
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
We are joined by Jeff to talk social engineering both in the real world and the digital world. Jeff talks about how the movie Sneakers sparked his interest, how he got paid to sneak into people’s buildings, and why we see so many people getting duped today.
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
I know, another election security episode with Zack? Yes! Well this week we’re looking at strategies to stop you from getting duped because we’re about to cross the finish line and this year more than ever, cybersecurity is playing a big role in our election and each of us has a role to play. We have some more details on a recent email campaign out of Iran and will talk about why actual data breaches aren’t necessary when you can just make it seem like you’ve stolen data. The good news is that Justin is back again Thursday with a new Breach of the Week and we have some really great episodes with our partners coming up that are going to be awesome!
CISA has put together an excellent resource page for election security that I highly recommend: CISA.gov/protect2020
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
I know, another election security episode with Zack? Yes! Well this week we're looking at strategies to stop you from getting duped because we're about to cross the finish line and this year more than ever, cybersecurity is playing a big role in our election and each of us has a role to play. We have some more details on a recent email campaign out of Iran and will talk about why actual data breaches aren't necessary when you can just make it seem like you've stolen data. The good news is that Justin is back again Thursday with a new Breach of the Week and we have some really great episodes with our partners coming up that are going to be awesome!
CISA has put together an excellent resource page for election security that I highly recommend: CISA.gov/protect2020
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
It’s another solo episode and we’re digging deep into the recent indictment of six Russian GRU agents belonging to Sandstorm. What did they do? What happens now? Is this going to stop future attacks? Listen in and find out!
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
It's another solo episode and we're digging deep into the recent indictment of six Russian GRU agents belonging to Sandstorm. What did they do? What happens now? Is this going to stop future attacks? Listen in and find out!
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
It’s a solo episode as Zack follows up on some of the previous discussions and updates you on some of the latest issues around election security. Russia still wants to ruin our democracy, botnets are great at spreading garbage news, and the feds are feeling pretty good so far about the overall threat to election infrastructure.
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
It's a solo episode as Zack follows up on some of the previous discussions and updates you on some of the latest issues around election security. Russia still wants to ruin our democracy, botnets are great at spreading garbage news, and the feds are feeling pretty good so far about the overall threat to election infrastructure.
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
On this week’s breach, we’re talking about an unnamed federal agency that was compromised by a fairly easy backdoor into the agency’s network. While we can only speculate about which agency was hit or what the intent was of the bad actors, we can all agree that the feds getting whacked is not a good thing.
For more info: https://www.infosecurity-magazine.com/news/us-federal-agency-compromised-by/
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
On this week's breach, we're talking about an unnamed federal agency that was compromised by a fairly easy backdoor into the agency's network. While we can only speculate about which agency was hit or what the intent was of the bad actors, we can all agree that the feds getting whacked is not a good thing.
For more info: https://www.infosecurity-magazine.com/news/us-federal-agency-compromised-by/
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In what may be the most upsetting episode of Pwned yet, Justin and Zack discuss the implications of a coffee maker going rogue and the possibilities of our IoT appliances turning on us. Are the machines rising against us? Was the coffee maker made by Cyberdyne Systems? Pour yourself a fresh cup of java and listen in as we figure out which appliances have it in for us.
Read the story here: https://decoded.avast.io/martinhron/the-fresh-smell-of-ransomed-coffee/
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
In what may be the most upsetting episode of Pwned yet, Justin and Zack discuss the implications of a coffee maker going rogue and the possibilities of our IoT appliances turning on us. Are the machines rising against us? Was the coffee maker made by Cyberdyne Systems? Pour yourself a fresh cup of java and listen in as we figure out which appliances have it in for us.
Read the story here: https://decoded.avast.io/martinhron/the-fresh-smell-of-ransomed-coffee/
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
This week we're talking about breach at a food delivery service that appears to be the result of a disgruntled insider. Justin and Zack talk about how easy it was to get the data and how the perpetrator sent out notification of the breach themselves.
You can read the article here: https://www.infosecurity-magazine.com/news/delivery-service-chowbus-breach/
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
This week we’re talking about breach at a food delivery service that appears to be the result of a disgruntled insider. Justin and Zack talk about how easy it was to get the data and how the perpetrator sent out notification of the breach themselves.
You can read the article here: https://www.infosecurity-magazine.com/news/delivery-service-chowbus-breach/
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
Justin is back for another episode and we’re again talking about a medical system that’s been hit by ransomware. In what may be the largest attack on a US healthcare network, Universal Health Services had their entire US system impacted by a ransomware attack forcing staff to shut down computers and resort to pen and paper documentation. Justin and Zack talk about the implications of these attacks and then go off the rails discussing the vulnerabilities of US infrastructure and the possibility of an EMP destroying everything.
You can read the article here: https://www.nbcnews.com/tech/security/cyberattack-hits-major-u-s-hospital-system-n1241254
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
Justin is back for another episode and we're again talking about a medical system that's been hit by ransomware. In what may be the largest attack on a US healthcare network, Universal Health Services had their entire US system impacted by a ransomware attack forcing staff to shut down computers and resort to pen and paper documentation. Justin and Zack talk about the implications of these attacks and then go off the rails discussing the vulnerabilities of US infrastructure and the possibility of an EMP destroying everything.
You can read the article here: https://www.nbcnews.com/tech/security/cyberattack-hits-major-u-s-hospital-system-n1241254
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
We're talking QR codes this week and no, it is not 2010. QR codes are back and they're doing more than ever. QR codes have returned to help us do contactless payments, authentication, and all the other fun stuff they could do before, however, like everything digital, the bad guys are trying to ruin everything for us.
You can read the article here:https://www.forbes.com/sites/louiscolumbus/2020/09/20/the-cybersecurity-threat-no-one-talks-about-is-a-simple-code/
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
We’re talking QR codes this week and no, it is not 2010. QR codes are back and they’re doing more than ever. QR codes have returned to help us do contactless payments, authentication, and all the other fun stuff they could do before, however, like everything digital, the bad guys are trying to ruin everything for us.
You can read the article here:https://www.forbes.com/sites/louiscolumbus/2020/09/20/the-cybersecurity-threat-no-one-talks-about-is-a-simple-code/
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
What’s the future hold for information technology in a post-COVID world? Justin is back on the podcast to talk about a recent list Microsoft put together speculating what cyber security will look when we start to get back to a new normal. Spoiler, it’s a lot of stuff cybersecurity teams have been pushing for that are finally starting to become commonplace and will likely stick around when things settle.
Here’s the article about Microsoft’s predictions: https://www.techrepublic.com/article/microsoft-says-the-pandemic-has-changed-the-future-of-cybersecurity-in-these-five-ways/
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
What's the future hold for information technology in a post-COVID world? Justin is back on the podcast to talk about a recent list Microsoft put together speculating what cyber security will look when we start to get back to a new normal. Spoiler, it's a lot of stuff cybersecurity teams have been pushing for that are finally starting to become commonplace and will likely stick around when things settle.
Here's the article about Microsoft's predictions: https://www.techrepublic.com/article/microsoft-says-the-pandemic-has-changed-the-future-of-cybersecurity-in-these-five-ways/
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Justin has returned to the podcast and this week we're covering what could be the first death to be directly linked to a ransomware attack. We talk about why hospitals are targets, how this could become far more complicated if it's found to be a nation state, and how the legal system will address this and whether this will result in a homicide charge.
You can read the article here: https://www.theverge.com/2020/9/17/21443851/death-ransomware-attack-hospital-germany-cybersecurity
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Justin has returned to the podcast and this week we’re covering what could be the first death to be directly linked to a ransomware attack. We talk about why hospitals are targets, how this could become far more complicated if it’s found to be a nation state, and how the legal system will address this and whether this will result in a homicide charge.
You can read the article here: https://www.theverge.com/2020/9/17/21443851/death-ransomware-attack-hospital-germany-cybersecurity
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
Kathie is one of the early members of NuHarbor and has been directly responsible for finding and curating the team that has grown into the company NuHarbor is today. Kathie joined the podcast today to talk about how NuHarbor has built a successful work culture, how it's surviving the pandemic, and what's next. Kathie has served as the NuHarbor gatekeeper and evangelist and is often one of the first people you speak to when you submit your application and if you'd like to talk to her yourself, you can apply to NuHarbor here: https://nuharborsecurity.com/careers.
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Kathie is one of the early members of NuHarbor and has been directly responsible for finding and curating the team that has grown into the company NuHarbor is today. Kathie joined the podcast today to talk about how NuHarbor has built a successful work culture, how it’s surviving the pandemic, and what’s next. Kathie has served as the NuHarbor gatekeeper and evangelist and is often one of the first people you speak to when you submit your application and if you’d like to talk to her yourself, you can apply to NuHarbor here: https://www.nuharborsecurity.com/careers.
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
We’re continuing our exploration of the intersection of cyber and real world disasters and this week we have a report from Cynet about unrelenting attacks that have occurred since the beginning of the COVID-19 crisis and how criminals are using this real world disaster to exploit people in the digital world. You can read the original story here https://thehackernews.com/2020/09/covid-cybersecurity-report.html and you can read our two most recent posts on Threat Intelligence and Threat Hunting, both of which will help you close the gap on the new and novel threats you may face.
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
We're continuing our exploration of the intersection of cyber and real world disasters and this week we have a report from Cynet about unrelenting attacks that have occurred since the beginning of the COVID-19 crisis and how criminals are using this real world disaster to exploit people in the digital world. You can read the original story here https://thehackernews.com/2020/09/covid-cybersecurity-report.html and you can read our two most recent posts on Threat Intelligence and Threat Hunting, both of which will help you close the gap on the new and novel threats you may face.
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
It's National Preparedness Month! Zack is going to tap into his previous life as an emergency manager to discuss the increasing intersection of disasters and cybersecurity. From identity theft and fraud to the increasing reliance on cybersecurity to how cybersecurity professionals can increase their knowledge and skills to respond, we're exploring a lot on today's episode. We will likely take some deeper looks at these issues in the coming weeks because a large swath of the US is currently being impacted by significant natural disasters.
National Incident Management and Incident Command System Courses: https://training.fema.gov/nims/ TEEX online courses: https://teex.org/program/online/
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
It’s National Preparedness Month! Zack is going to tap into his previous life as an emergency manager to discuss the increasing intersection of disasters and cybersecurity. From identity theft and fraud to the increasing reliance on cybersecurity to how cybersecurity professionals can increase their knowledge and skills to respond, we’re exploring a lot on today’s episode. We will likely take some deeper looks at these issues in the coming weeks because a large swath of the US is currently being impacted by significant natural disasters.
National Incident Management and Incident Command System Courses: https://training.fema.gov/nims/
TEEX online courses: https://teex.org/program/online/
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
We’re back with the second half of our discussion on election security with Davis. This week we’re talking about strategies and concepts that must be considered as part of a comprehensive security plan from physical security to ensuring people don’t share bad information. If you like this episode, check out last week’s episode discussing all of the threats and vulnerabilities that elections face.
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
We're back with the second half of our discussion on election security with Davis. This week we're talking about strategies and concepts that must be considered as part of a comprehensive security plan from physical security to ensuring people don't share bad information. If you like this episode, check out last week's episode discussing all of the threats and vulnerabilities that elections face.
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
We are back with our second episode exploring how NuHarbor Security began and what sets us apart from our peers. This week we're joined by Scott, NuHarbor's VP and guru of marketing and sales. Scott is another one of the OG crowd and has been with NuHarbor since the very early days. We'll talk to Scott about how he has embraced content creation, like this podcast, over using traditional methods of marketing and why he and Justin are willing to give away things that other companies may feel people should be charged for.
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
We are back with our second episode exploring how NuHarbor Security began and what sets us apart from our peers. This week we’re joined by Scott, NuHarbor’s VP and guru of marketing and sales. Scott is another one of the OG crowd and has been with NuHarbor since the very early days. We’ll talk to Scott about how he has embraced content creation, like this podcast, over using traditional methods of marketing and why he and Justin are willing to give away things that other companies may feel people should be charged for.
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
We are just a couple of months away from the 2020 election and like many voters, we are discussing election security. This week we are joined again by Davis and we’re talking about the threats to our election and how most people focus on the wrong thing when it comes to securing elections. From voting machines to hanging chads to social engineering, how much of a threat do we face and what can we do about it? This was a big episode, so big we actually split it into two, so this week we talk about the threats, and next week we will cover philosophical and strategic approaches to election security.
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
We are just a couple of months away from the 2020 election and like many voters, we are discussing election security. This week we are joined again by Davis and we're talking about the threats to our election and how most people focus on the wrong thing when it comes to securing elections. From voting machines to hanging chads to social engineering, how much of a threat do we face and what can we do about it? This was a big episode, so big we actually split it into two, so this week we talk about the threats, and next week we will cover philosophical and strategic approaches to election security.
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
The original group, or OG's as they're referred to around the office, have seen NuHarbor grow from a scrappy little company trying to break the mold to a quickly expanding cybersecurity firm punching above their numbers. What is it that motivated the original members to take the leap and join Justin in his pursuit of building an infosec company in his own image? What is it that is driving the company growth despite the challenging economy? We're starting this discussion with Kyle, the company Swiss Army knife, and leader of REDSEC offensive security operations. Kyle has been with NuHarbor since the early days and shares his thoughts on starts-ups, entrepreneurs, and why he's still here.
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
The original group, or OG’s as they’re referred to around the office, have seen NuHarbor grow from a scrappy little company trying to break the mold to a quickly expanding cybersecurity firm punching above their numbers. What is it that motivated the original members to take the leap and join Justin in his pursuit of building an infosec company in his own image? What is it that is driving the company growth despite the challenging economy? We’re starting this discussion with Kyle, the company Swiss Army knife, and leader of REDSEC offensive security operations. Kyle has been with NuHarbor since the early days and shares his thoughts on starts-ups, entrepreneurs, and why he’s still here.
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
This week Zack is solo and is discussing a new report out from IBM Security on the costs of data breaches. To put it bluntly, it’s not cheap. However, the report shows that all is not lost and that organizations that have strong cybersecurity plans, software, and personnel, will save millions of dollars post-breach compared to those who have nothing. The lesson here is to hire us because every dollar you spend before an incident will return a lot more should something occur.
We highly recommend you review the report which you can find here: https://www.ibm.com/security/digital-assets/cost-data-breach-report/Cost%20of%20a%20Data%20Breach%20Report%202020.pdf
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
This week Zack is solo and is discussing a new report out from IBM Security on the costs of data breaches. To put it bluntly, it's not cheap. However, the report shows that all is not lost and that organizations that have strong cybersecurity plans, software, and personnel, will save millions of dollars post-breach compared to those who have nothing. The lesson here is to hire us because every dollar you spend before an incident will return a lot more should something occur.
We highly recommend you review the report which you can find here: https://www.ibm.com/security/digital-assets/cost-data-breach-report/Cost%20of%20a%20Data%20Breach%20Report%202020.pdf
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
We are back with Part II of our taking care of the team series. In this episode, Zack and Justin will address some of the challenges in keeping staff and what leaders can do to support their staff as well as how to build up team members so that someday they can take over. Justin also discusses how taking care of your team is taking care of your customers. Listen in and let us know what you think! Contact us at pwned@nuharborsecurity.com if you have topics you'd like discussed or if you're interested in being a guest.
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
We are back with Part II of our taking care of the team series. In this episode, Zack and Justin will address some of the challenges in keeping staff and what leaders can do to support their staff as well as how to build up team members so that someday they can take over. Justin also discusses how taking care of your team is taking care of your customers. Listen in and let us know what you think! Contact us at pwned@nuharborsecurity.com if you have topics you’d like discussed or if you’re interested in being a guest.
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
On this week’s breach, we’re talking about a breach that took years to come to fruition. How many of us have sold, recycled, or tossed a used computer with the hard drive still in it? It happens countless times a day and we likely don’t even think about the amount of data that remains, even after you “wipe” it. That’s right, your secret list of coworkers with the worst taste in music could be out in the wild as we speak! Listen in to learn what you should do to secure these old drives as well as what not to do when you get rid of a computer.
For info on this weeks breach, check out: https://www.recyclingtoday.com/article/lessons-electronics-recyclers-itad-companies-learn-morgan-stanley-data-breach/
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
On this week's breach, we're talking about a breach that took years to come to fruition. How many of us have sold, recycled, or tossed a used computer with the hard drive still in it? It happens countless times a day and we likely don't even think about the amount of data that remains, even after you "wipe" it. That's right, your secret list of coworkers with the worst taste in music could be out in the wild as we speak! Listen in to learn what you should do to secure these old drives as well as what not to do when you get rid of a computer.
For info on this weeks breach, check out: https://www.recyclingtoday.com/article/lessons-electronics-recyclers-itad-companies-learn-morgan-stanley-data-breach/
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
We're talking team care this week with Zack and Justin. They'll cover the challenges of leading a team in crisis (like a pandemic), how to keep up enough on the lives of your team members without being creepy, and why leaders fail to lead. This was a very long recording session so we're breaking it up into two separate episodes. If you take care of your team, they'll take care of you.
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
We’re talking team care this week with Zack and Justin. They’ll cover the challenges of leading a team in crisis (like a pandemic), how to keep up enough on the lives of your team members without being creepy, and why leaders fail to lead. This was a very long recording session so we’re breaking it up into two separate episodes. If you take care of your team, they’ll take care of you.
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
Justin is back on the podcast and for this week’s breach, we’re talking about the big Twitter breach that opened up some of the biggest users on the system to a bitcoin scam. We were shocked at how incredibly easy it was to get into the system, access important accounts, and then waste the opportunity for a second rate bitcoin scam. We’ll talk about how this type of vulnerability is far more common than you think and why businesses continue to fail at the most basic security practices.
To learn more about the recent arrest of the perpetrator: https://www.wfla.com/news/hillsborough-county/tampa-teen-accused-of-being-mastermind-behind-twitter-hack-that-targeted-high-profile-accounts/
**Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
Justin is back on the podcast and for this week's breach, we're talking about the big Twitter breach that opened up some of the biggest users on the system to a bitcoin scam. We were shocked at how incredibly easy it was to get into the system, access important accounts, and then waste the opportunity for a second rate bitcoin scam. We'll talk about how this type of vulnerability is far more common than you think and why businesses continue to fail at the most basic security practices.
To learn more about the recent arrest of the perpetrator: https://www.wfla.com/news/hillsborough-county/tampa-teen-accused-of-being-mastermind-behind-twitter-hack-that-targeted-high-profile-accounts/
Check out NuHarbor Security for complete cybersecurity protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
We brought Travis back to give us an update on what he's seeing for trends and issues. We talk about the biggest things on the horizon including securing remote workers, the shift away from offices, securing education from k-12 through higher ed, and even election security and the threat to democracy. We're in a dynamic world and Travis talks about how companies are managing everything and moving forward.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
We brought Travis back to give us an update on what he’s seeing for trends and issues. We talk about the biggest things on the horizon including securing remote workers, the shift away from offices, securing education from k-12 through higher ed, and even election security and the threat to democracy. We’re in a dynamic world and Travis talks about how companies are managing everything and moving forward.
**Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
We're joined by Kristof to dig into another compliance frontier, the Cybersecurity Maturity Model Certification (CMMC). Kristof will give us a primer on who CMMC affects, what they need to do get compliant, how you get certified, and when this certification goes live. If you fall into the Defense Industrial Base (DIB) or work with the Dept of Defense or contractors who are connected to the DoD, you better ready for CMMC. Kristof also discusses how this will replace NIST with the DoD and the potential alignment of CMMC with other federal agencies.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
We’re joined by Kristof to dig into another compliance frontier, the Cybersecurity Maturity Model Certification (CMMC). Kristof will give us a primer on who CMMC affects, what they need to do get compliant, how you get certified, and when this certification goes live. If you fall into the Defense Industrial Base (DIB) or work with the Dept of Defense or contractors who are connected to the DoD, you better ready for CMMC. Kristof also discusses how this will replace NIST with the DoD and the potential alignment of CMMC with other federal agencies.
**Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.
Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/**
We’re joined by two NuHarbor staffers this week to explore the dark web. We posted a poll on Twitter yesterday and the people have spoken, they wanted dark web content and we are delivering. We’ll discuss what the dark web is, how it is used, and whether or not it is a good idea to visit it on your home computer. We’ll also learn what happens to your stolen credentials post hack and what they may be used for. So if you’re a dark web noob, tune in and get educated.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website:https://www.nuharborsecurity.com
Facebook:https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
We're joined by two NuHarbor staffers this week to explore the dark web. We posted a poll on Twitter yesterday and the people have spoken, they wanted dark web content and we are delivering. We'll discuss what the dark web is, how it is used, and whether or not it is a good idea to visit it on your home computer. We'll also learn what happens to your stolen credentials post hack and what they may be used for. So if you're a dark web noob, tune in and get educated.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
We are back with another throwback episode, this time on Application Security Authentication Requirements. You probably would not be surprised to realize that there are still organizations out there that are not using best practices when it comes to authentication requirements and their lack of understanding often results in security headaches for their organization and potential data leaks for users. Justin shares 10 requirements from OWASP and how they can help you in your quest for compliance with various security standards.
You can read Justin's in depth post here: https://nuharborsecurity.com/10-application-security-authentication-requirements/
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
We are back with another throwback episode, this time on Application Security Authentication Requirements. You probably would not be surprised to realize that there are still organizations out there that are not using best practices when it comes to authentication requirements and their lack of understanding often results in security headaches for their organization and potential data leaks for users. Justin shares 10 requirements from OWASP and how they can help you in your quest for compliance with various security standards.
You can read Justin’s in depth post here: https://www.nuharborsecurity.com/10-application-security-authentication-requirements/
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
Today we’re talking Blue Leaks, the massive data leak impacting law enforcement agencies at all levels, not to be confused with the classic Martin Lawrence movie Blue Streak, a comedy from 1999. We talk about the impacts of the breach, how and why it happened, and the continued risk to government agencies as they expand their online presence.
More info on the breach from Wired: https://www.wired.com/story/blueleaks-anonymous-law-enforcement-hack/
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
Today we're talking Blue Leaks, the massive data leak impacting law enforcement agencies at all levels, not to be confused with the classic Martin Lawrence movie Blue Streak, a comedy from 1999. We talk about the impacts of the breach, how and why it happened, and the continued risk to government agencies as they expand their online presence.
More info on the breach from Wired: https://www.wired.com/story/blueleaks-anonymous-law-enforcement-hack/
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
On this week’s episode we’re talking to Kristof about ISO 27001. We cover the who, what, when, why, and how of ISO and discuss how the process works from initial discussion through certification. Kristof points out some of the pitfalls and shares his thoughts on why ISO is often a better choice than some of the other standards that exist (NIST, we are looking at you.) If you’re a organization interested in ISO, be sure to listen!
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
On this week’s episode we're talking to Kristof about ISO 27001. We cover the who, what, when, why, and how of ISO and discuss how the process works from initial discussion through certification. Kristof points out some of the pitfalls and shares his thoughts on why ISO is often a better choice than some of the other standards that exist (NIST, we are looking at you.) If you're a organization interested in ISO, be sure to listen!
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
This week Justin and Zack realize with terror, that their favorite form of transportation has betrayed them. The NuHarbor train system of choice, Amtrak, found itself on the receiving end of a data breach and unfortunately the train has left the station. The breach appears to have originated within the app used to access your Amtrak guest points system, sharing all the weird things you purchased using your points and your PII like social security number, names, and addresses. At the same time, travel by train is the best and both Justin and Zack said they’re Amtrakers for life.
To read more about the breach, check out https://cyware.com/news/critical-vulnerabilities-spotted-in-the-amtrak-mobile-application-1474d637
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
This week Justin and Zack realize with terror, that their favorite form of transportation has betrayed them. The NuHarbor train system of choice, Amtrak, found itself on the receiving end of a data breach and unfortunately the train has left the station. The breach appears to have originated within the app used to access your Amtrak guest points system, sharing all the weird things you purchased using your points and your PII like social security number, names, and addresses. At the same time, travel by train is the best and both Justin and Zack said they're Amtrakers for life.
To read more about the breach, check out https://cyware.com/news/critical-vulnerabilities-spotted-in-the-amtrak-mobile-application-1474d637
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
You shouldn't be shocked by this, but North Korea is trying to break into your data. Seriously, check your logs. If you do not see the telltale signs, it's only a matter of when, not if, a nation state takes a shot at you. This was originally set to be a Breach of the Week, but we got chatty and we decided to launch this as a regular full episode. Justin and Zack discuss how cyber-attacks are leveling the playing field between nations. Specifically, they discuss how North Korea has built a 7,000 person cyber security division that's only purpose to damage, destroy, and steal data. Are you ready to take on an adversarial nation?
To learn more about North Korea's Cyber Army, check out: https://www.businessinsider.com/north-korea-kim-jong-un-cyber-army-cyberattacks-nuclear-weapons-2020-6
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
You shouldn’t be shocked by this, but North Korea is trying to break into your data. Seriously, check your logs. If you do not see the telltale signs, it’s only a matter of when, not if, a nation state takes a shot at you. This was originally set to be a Breach of the Week, but we got chatty and we decided to launch this as a regular full episode. Justin and Zack discuss how cyber-attacks are leveling the playing field between nations. Specifically, they discuss how North Korea has built a 7,000 person cyber security division that’s only purpose to damage, destroy, and steal data. Are you ready to take on an adversarial nation?
To learn more about North Korea’s Cyber Army, check out: https://www.businessinsider.com/north-korea-kim-jong-un-cyber-army-cyberattacks-nuclear-weapons-2020-6
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
For this week’s Breach of the Week, we're talking about a software on a chip maker that got hit by our old friend, Maze Ransomware. Justin talks about the persistence of viruses after you've been hit and how companies can try to prevent this from happening. We also are beginning to discuss 5G. What is 5G? Well, if you believe the hype, it is literally everything. Stay tuned for more 5G coverage in the future as we begin to explore the benefits and challenges of this new tech.
To learn more about this breach: https://www.bleepingcomputer.com/news/security/chipmaker-maxlinear-reports-data-breach-after-maze-ransomware-attack/
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
For this week’s Breach of the Week, we’re talking about a software on a chip maker that got hit by our old friend, Maze Ransomware. Justin talks about the persistence of viruses after you’ve been hit and how companies can try to prevent this from happening. We also are beginning to discuss 5G. What is 5G? Well, if you believe the hype, it is literally everything. Stay tuned for more 5G coverage in the future as we begin to explore the benefits and challenges of this new tech.
To learn more about this breach: https://www.bleepingcomputer.com/news/security/chipmaker-maxlinear-reports-data-breach-after-maze-ransomware-attack/
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
What is up everyone! For this week's episode we're digging into the archives and we picked one of the most popular episodes from Season 1 of Pwned, Exim Server Vulnerabilities. What's fascinating about Exim is that it first launched 25 years ago and still supports a lot of email systems around the globe. The software’s longevity and proliferation mean that hackers have had a long time to learn the vulnerabilities of the platform and unpatched servers seems to be the target that get picked off the most. Give the episode a listen and let us know what you think!
To learn more about Exim Server Vulnerabilities:
https://nuharborsecurity.com/exim-server-vulnerabilities/
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
What is up everyone! For this week’s episode we’re digging into the archives and we picked one of the most popular episodes from Season 1 of Pwned, Exim Server Vulnerabilities. What’s fascinating about Exim is that it first launched 25 years ago and still supports a lot of email systems around the globe. The software’s longevity and proliferation mean that hackers have had a long time to learn the vulnerabilities of the platform and unpatched servers seems to be the target that get picked off the most. Give the episode a listen and let us know what you think!
To learn more about Exim Server Vulnerabilities:
https://www.nuharborsecurity.com/exim-server-vulnerabilities/
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
We have a very special episode this week! NuHarbor Security is literally the best place to work. Seriously, NuHarbor was selected as a “Best Places to Work in Vermont” for the second time! Justin and Zack discuss why they think NuHarbor was selected and why NuHarbor staff members make the difference. Justin also talks about how having a strong corporate philosophy that emphasizes staff wellness above all else can help any company succeed and how he prioritizes building a company of people who work well together. You can read more about the award and Justin’s remarks as we received the award here: https://www.nuharborsecurity.com/best-place-to-work-2020
You can join NuHarbor and find out why we’re a best place to work by visiting our career page at https://www.nuharborsecurity.com/careers
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
We have a very special episode this week! NuHarbor Security is literally the best place to work. Seriously, NuHarbor was selected as a "Best Places to Work in Vermont" for the second time! Justin and Zack discuss why they think NuHarbor was selected and why NuHarbor staff members make the difference. Justin also talks about how having a strong corporate philosophy that emphasizes staff wellness above all else can help any company succeed and how he prioritizes building a company of people who work well together. You can read more about the award and Justin's remarks as we received the award here: https://nuharborsecurity.com/best-place-to-work-2020
You can join NuHarbor and find out why we're a best place to work by visiting our career page at https://nuharborsecurity.com/careers
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
On this week’s Breach of the Week, we’re talking CIA and a pretty epic dump of highly sensitive and classified materials including some of the most dangerous hacking tools they’ve created. Was it a nation state looking to seek revenge? Was it a hacking group that perpetrated the deepest depths of the government’s networks? Listen and find out (hint: It wasn’t either of those things). Justin gives his thoughts on how this went down, the lack of good policies and procedures, and we talk about the risk of the insider threat.
Link to the story: https://www.washingtonpost.com/national-security/elite-cia-unit-that-developed-hacking-tools-failed-to-secure-its-own-systems-allowing-massive-leak-an-internal-report-found/2020/06/15/502e3456-ae9d-11ea-8f56-63f38c990077_story.html
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
On this week’s Breach of the Week, we're talking CIA and a pretty epic dump of highly sensitive and classified materials including some of the most dangerous hacking tools they've created. Was it a nation state looking to seek revenge? Was it a hacking group that perpetrated the deepest depths of the government's networks? Listen and find out (hint: It wasn't either of those things). Justin gives his thoughts on how this went down, the lack of good policies and procedures, and we talk about the risk of the insider threat.
Link to the story: https://www.washingtonpost.com/national-security/elite-cia-unit-that-developed-hacking-tools-failed-to-secure-its-own-systems-allowing-massive-leak-an-internal-report-found/2020/06/15/502e3456-ae9d-11ea-8f56-63f38c990077_story.html
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
On this week’s episode Justin’s discussing cyber threat intelligence and why it takes a combination of good systems, smart people, and solid processes to stay ahead of the bad guys. Justin also shared some sources you can use to find intel and some thoughts on how to effectively use that intel including building your platform to manage all the data. You’re going to be drinking from a fire hose once you start ingesting intel, so Justin also provides his thoughts on how to make sense of everything and how hiring someone, perhaps NuHarbor Security, can help to take that raw intel and use it to create a robust security posture that isn’t constantly feeding you false positives.
If you like this episode, you should check our episode with Davis, one of our Cyber Threat Analysts https://www.nuharborsecurity.com/pwned-gigabytes-davis-finds-threats-before-they-find-you/
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
On this week's episode Justin's discussing cyber threat intelligence and why it takes a combination of good systems, smart people, and solid processes to stay ahead of the bad guys. Justin also shared some sources you can use to find intel and some thoughts on how to effectively use that intel including building your platform to manage all the data. You're going to be drinking from a fire hose once you start ingesting intel, so Justin also provides his thoughts on how to make sense of everything and how hiring someone, perhaps NuHarbor Security, can help to take that raw intel and use it to create a robust security posture that isn’t constantly feeding you false positives.
If you like this episode, you should check our episode with Davis, one of our Cyber Threat Analysts https://nuharborsecurity.com/pwned-gigabytes-davis-finds-threats-before-they-find-you/
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
On this week’s episode we are digging into a specific Maze Ransomware attack that hit one of the biggest security firms on the planet. What does it mean when a security company gets hit, how they’ll probably be just fine with their billions of dollars, and whether or not we should cut them some slack. While we don’t know how much they ultimately paid the hackers, we know that they estimate the impact to their company to be in the tens of millions of dollars, which for a company of this size is probably not something they wanted to deal with but have the resources to handle.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
On this week’s episode we are digging into a specific Maze Ransomware attack that hit one of the biggest security firms on the planet. What does it mean when a security company gets hit, how they'll probably be just fine with their billions of dollars, and whether or not we should cut them some slack. While we don't know how much they ultimately paid the hackers, we know that they estimate the impact to their company to be in the tens of millions of dollars, which for a company of this size is probably not something they wanted to deal with but have the resources to handle.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Maze Ransomware has been in the headlines quite a bit recently and the way things look, we’re probably going to see it more in the future. Justin and Zack take a deep dive into what Maze is, how it works, and why businesses impacted should probably not mess around with getting it sorted out. They’ll also cover the unfortunate reality that once your hit, it’s very likely you’ll be targeted again and what you can do to prevent getting impacted in the first place. As is often the case, human error is the most common vector for attack but there are some tools and technology you can use to make it a bit harder for the people trying to break into your systems.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
Maze Ransomware has been in the headlines quite a bit recently and the way things look, we're probably going to see it more in the future. Justin and Zack take a deep dive into what Maze is, how it works, and why businesses impacted should probably not mess around with getting it sorted out. They'll also cover the unfortunate reality that once your hit, it's very likely you'll be targeted again and what you can do to prevent getting impacted in the first place. As is often the case, human error is the most common vector for attack but there are some tools and technology you can use to make it a bit harder for the people trying to break into your systems.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Despite the mediocre R.E.M. pun, this is a good episode. We're covering ShinyHunters and how they got busy in May dumping millions of accounts into the dark web. Zack learns that hacked data doesn't necessarily arrive ready to start using and Justin laments at the fact that hackers only need to be right once and business need to be right 100% of the time. We also talk about the return of Anonymous and who their targeting during their resurgence. Once again, we suggest you let REDSEC, our offensive security team, hack you before someone else does.
hbspt.cta.load(9212203, 'fb57af26-98aa-434b-93de-f33cfde6f331', {"region":"na1"});
Check out the full Wired story here: https://www.wired.com/story/shinyhunters-hacking-group-data-breach-spree/
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Despite the mediocre R.E.M. pun, this is a good episode. We’re covering ShinyHunters and how they got busy in May dumping millions of accounts into the dark web. Zack learns that hacked data doesn’t necessarily arrive ready to start using and Justin laments at the fact that hackers only need to be right once and business need to be right 100% of the time. We also talk about the return of Anonymous and who their targeting during their resurgence. Once again, we suggest you let REDSEC, our offensive security team, hack you before someone else does.
Check out the full Wired story here: https://www.wired.com/story/shinyhunters-hacking-group-data-breach-spree/
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
On this week’s episode we’re talking to Davis about threat analysis and how he sifts through the noise to help keep organizations safer from security threats. We are covering everything from the alphabet soup of infosec acronyms to why having some human eyes on intel can strengthen information security to what the future holds in threat analysis. Davis sits in the purple side of the house between the REDSEC offensive security team and the groups defending against attacks. Justin also gets another opportunity to take a shot at AI and again we are reminded that even with the best technology, you gotta make sure the people that work for you are not downloading sketchy files.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
On this week’s episode we're talking to Davis about threat analysis and how he sifts through the noise to help keep organizations safer from security threats. We are covering everything from the alphabet soup of infosec acronyms to why having some human eyes on intel can strengthen information security to what the future holds in threat analysis. Davis sits in the purple side of the house between the REDSEC offensive security team and the groups defending against attacks. Justin also gets another opportunity to take a shot at AI and again we are reminded that even with the best technology, you gotta make sure the people that work for you are not downloading sketchy files.
hbspt.cta.load(9212203, 'fb57af26-98aa-434b-93de-f33cfde6f331', {"region":"na1"});
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In this week’s Breach of the Week episode we talk about a big breach at Nintendo that revealed NNID, Nintendo’s ID system, which is linked to other private and payment info. Justin and Zack then discuss everything from the cost of video games to video game streaming. Also, we discuss video game currencies and how big streaming video games is. Like, share, subscribe!
Link to story: https://www.cshub.com/attacks/articles/incident-of-the-week-nintendo-investigating-160000-account-breaches
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
In this week's Breach of the Week episode we talk about a big breach at Nintendo that revealed NNID, Nintendo's ID system, which is linked to other private and payment info. Justin and Zack then discuss everything from the cost of video games to video game streaming. Also, we discuss video game currencies and how big streaming video games is. Like, share, subscribe!
Link to story: https://www.cshub.com/attacks/articles/incident-of-the-week-nintendo-investigating-160000-account-breaches
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
This week we are welcoming Kyle to the podcast to tell us all about REDSEC. We’ll learn who they are and how they help clients find vulnerabilities before the bad guys do. Kyle will talk about why we have updated and centralized the offensive testing side of the house at NuHarbor and what sets it apart from other offensive security organizations. From snooping Wi-Fi to phishing for credentials to hacking webapps, nothing is safe from the skilled operators. We also talk about R.A.V.E.N., the remote testing tool used by the team, and the benefits and flexibility it adds to the security assessment process. Long story short, they can keep you out of the news and off of our Breach of the Week episodes. For more content related to offensive security, check out our previous Gigabyte and Breach of the Week episodes with Eric and Randy.
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
This week we are welcoming Kyle to the podcast to tell us all about REDSEC. We'll learn who they are and how they help clients find vulnerabilities before the bad guys do. Kyle will talk about why we have updated and centralized the offensive testing side of the house at NuHarbor and what sets it apart from other offensive security organizations. From snooping Wi-Fi to phishing for credentials to hacking webapps, nothing is safe from the skilled operators. We also talk about R.A.V.E.N., the remote testing tool used by the team, and the benefits and flexibility it adds to the security assessment process. Long story short, they can keep you out of the news and off of our Breach of the Week episodes. For more content related to offensive security, check out our previous Gigabyte and Breach of the Week episodes with Eric and Randy.
hbspt.cta.load(9212203, 'fb57af26-98aa-434b-93de-f33cfde6f331', {"region":"na1"});
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In this weeks Breach of the Week, Justin and Zack discuss not one, but two, separate breaches at Marriott hotels, one releasing nearly enough data for every person in the United States! Will this stop Justin and Zack from ever staying at a Marriott again or will they cash in those reward points for a future room upgrade? Tune in to find out!
You can find more breaches at the privacy rights clearing house: https://privacyrights.org/data-breaches
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
In this weeks Breach of the Week, Justin and Zack discuss not one, but two, separate breaches at Marriott hotels, one releasing nearly enough data for every person in the United States! Will this stop Justin and Zack from ever staying at a Marriott again or will they cash in those reward points for a future room upgrade? Tune in to find out!
You can find more breaches at the privacy rights clearing house: https://privacyrights.org/data-breaches
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
It’s graduation season and despite the very strange and challenging times we live in, a lot of awesome and talented students are about to be unleashed into the world and if you’re a cyber security company that’s trying to attract them, Justin has some thoughts. Maybe you already have a full roster but for some reason you just cannot seem to figure out why your best folks keep leaving, well, Justin has some thoughts on that as well. Attracting and keeping your talent is difficult and expensive. Yes, you gotta spend money to make money and that also goes with your people as well. Finally, Justin has a few thoughts on how you can build your skill set by building your own lab and putting in the work on your own time to make you a better candidate. A little something for everyone. Like, share, rate, and review! Let us know what you think!
We’re also including an in depth blog post to allow you to dig deeper into this episode and find ways to recruit and retain cyber talent: https://www.nuharborsecurity.com/attracting-keeping-cybersecurity-talent
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
It's graduation season and despite the very strange and challenging times we live in, a lot of awesome and talented students are about to be unleashed into the world and if you're a cyber security company that's trying to attract them, Justin has some thoughts. Maybe you already have a full roster but for some reason you just cannot seem to figure out why your best folks keep leaving, well, Justin has some thoughts on that as well. Attracting and keeping your talent is difficult and expensive. Yes, you gotta spend money to make money and that also goes with your people as well. Finally, Justin has a few thoughts on how you can build your skill set by building your own lab and putting in the work on your own time to make you a better candidate. A little something for everyone. Like, share, rate, and review! Let us know what you think!
We're also including an in depth blog post to allow you to dig deeper into this episode and find ways to recruit and retain cyber talent: https://nuharborsecurity.com/attracting-keeping-cybersecurity-talent
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
On this week’s episode, we’re testing how far a breach can go and what happens when a customer is 100% positive they’re system is bullet proof. Can Eric drop ship a very expensive item to prove a point? Can Randy print himself a badge so that he doesn’t have to wait for one? Did Justin really want a tractor for the office? Our dynamic duo of Eric and Randy are back and it’s Eric’s turn to share some of his penetration testing highlights. Here’s another chance to get a peek behind the curtain and see how our offensive testing team does their work.
You can find more breaches at the privacy rights clearing house: https://privacyrights.org/data-breaches
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
On this week's episode, we're testing how far a breach can go and what happens when a customer is 100% positive they're system is bullet proof. Can Eric drop ship a very expensive item to prove a point? Can Randy print himself a badge so that he doesn't have to wait for one? Did Justin really want a tractor for the office? Our dynamic duo of Eric and Randy are back and it's Eric's turn to share some of his penetration testing highlights. Here's another chance to get a peek behind the curtain and see how our offensive testing team does their work.
You can find more breaches at the privacy rights clearing house: https://privacyrights.org/data-breaches
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Why are government agencies constantly a target for ransomware? Not a day goes without a story about a city or government agency that is found itself on the losing end of a ransomware attack. Adversaries can create relentless attacks on networks looking for any vulnerabilities to exploit and get unlimited tries while an agency only needs one person to make a mistake and compromise an entire system. Justin will share his thoughts on why governments are such attractive targets and why preventing these attacks is so difficult. He will also go over why ransomware is a symptom of a larger problem of under investment, limited funds, and constant poaching of cyber talent into the private sector.
If you are looking for even more info about the risk ransomware and why this is such a pervasive challenge, check out our blog for a in depth analysis of this problem: https://www.nuharborsecurity.com/government-ransomware-target
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
Why are government agencies constantly a target for ransomware? Not a day goes without a story about a city or government agency that is found itself on the losing end of a ransomware attack. Adversaries can create relentless attacks on networks looking for any vulnerabilities to exploit and get unlimited tries while an agency only needs one person to make a mistake and compromise an entire system. Justin will share his thoughts on why governments are such attractive targets and why preventing these attacks is so difficult. He will also go over why ransomware is a symptom of a larger problem of under investment, limited funds, and constant poaching of cyber talent into the private sector.
If you are looking for even more info about the risk ransomware and why this is such a pervasive challenge, check out our blog for a in depth analysis of this problem: https://nuharborsecurity.com/government-ransomware-target
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
This week we’re again joined by Eric and Randy to hear some war stories. Randy takes us through the time that he immediately accessed a bunch of very critical files while he was hanging out waiting for an engagement to begin. He also discusses how Justin tried to talk him into making a very large statement to let the customer know that they’d been had and how Randy had to talk Justin out of it. Randy also sheds some light on how something as simple as opening up the system to allow for some maintenance can be the thing that takes down your company. Learn from the pros so you don’t find yourself on our next Breach of the Week!
You can find more breaches at the privacy rights clearing house: https://privacyrights.org/data-breaches
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
This week we're again joined by Eric and Randy to hear some war stories. Randy takes us through the time that he immediately accessed a bunch of very critical files while he was hanging out waiting for an engagement to begin. He also discusses how Justin tried to talk him into making a very large statement to let the customer know that they'd been had and how Randy had to talk Justin out of it. Randy also sheds some light on how something as simple as opening up the system to allow for some maintenance can be the thing that takes down your company. Learn from the pros so you don't find yourself on our next Breach of the Week!
You can find more breaches at the privacy rights clearing house: https://privacyrights.org/data-breaches
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
Whether you recently graduated or are looking to break into cyber security, you need to check out our hiring and recruiting episode with two of our Talent Acquisition Specialists, Emi and Allie. Should you write a 20-page resume? How important are cover letters? What are companies like NuHarbor looking for? Should you include a recipe for your world-famous spaghetti recipe? We are going to learn what happens behind the scenes after you upload your resume and hit submit and with any luck, help you get hired for your next cyber security job. A lot of tech companies are hiring and most of us probably have an idea of what we think sets us apart but Emi and Allie are going to set us straight on what catches a recruiters eye and how to stand out without being obnoxious. If you think you are a cyber security rock star and want to work for a company that values your skills as much as your work/life balance, check out the latest job postings and reach out to Emi and Alli on our career page: https://www.nuharborsecurity.com/careers
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
Whether you recently graduated or are looking to break into cyber security, you need to check out our hiring and recruiting episode with two of our Talent Acquisition Specialists, Emi and Allie. Should you write a 20-page resume? How important are cover letters? What are companies like NuHarbor looking for? Should you include a recipe for your world-famous spaghetti recipe? We are going to learn what happens behind the scenes after you upload your resume and hit submit and with any luck, help you get hired for your next cyber security job. A lot of tech companies are hiring and most of us probably have an idea of what we think sets us apart but Emi and Allie are going to set us straight on what catches a recruiters eye and how to stand out without being obnoxious. If you think you are a cyber security rock star and want to work for a company that values your skills as much as your work/life balance, check out the latest job postings and reach out to Emi and Alli on our career page: https://nuharborsecurity.com/careers
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
We live in a world where everything is connected to the internet, even fish tanks, and as we learn in today's episode, that internet connected fish tanks can cause you some real headaches. Justin found a story about a fish tank in a casino that was used to access a lot of sensitive data and Zack reveals why he is no longer welcome at PetSmart. We also explore the potentially lucrative market of protecting internet connected fish tanks. We are just beginning to see how difficult securing your data is when everything we own has an IP address and is ready for exploitation. For all this and more, check out this weeks, Breach of the Week!
You can find more breaches at the privacy rights clearing house: https://privacyrights.org/data-breaches
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: https://twitter.com/NuHarbor@nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
We live in a world where everything is connected to the internet, even fish tanks, and as we learn in today’s episode, that internet connected fish tanks can cause you some real headaches. Justin found a story about a fish tank in a casino that was used to access a lot of sensitive data and Zack reveals why he is no longer welcome at PetSmart. We also explore the potentially lucrative market of protecting internet connected fish tanks. We are just beginning to see how difficult securing your data is when everything we own has an IP address and is ready for exploitation. For all this and more, check out this weeks, Breach of the Week!
You can find more breaches at the privacy rights clearing house: https://privacyrights.org/data-breaches
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: https://twitter.com/NuHarbor@nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
On this week's episode of Pwned, Justin and Zack are joined by Eric and Randy, two operators from our penetration testing team. This is another long episode and we are spending that time to learn everything about how our team uses white hat techniques to poke, prod, and punch into various systems. They will be discussing the tactics, techniques, and procedures used by adversaries how they simulate attacks, from creating code that will give them credentials to walking in a building and plugging in a device. You will also learn the difference is between penetration testing and vulnerability scans and how Eric and Randy do their best to find vulnerability scan reports to prove the value of a true penetration test. Sidenote, yes, I said Petaflop and I meant Petabyte and I'll forever live with this mistake - Zack
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: @nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
On this week’s episode of Pwned, Justin and Zack are joined by Eric and Randy, two operators from our penetration testing team. This is another long episode and we are spending that time to learn everything about how our team uses white hat techniques to poke, prod, and punch into various systems. They will be discussing the tactics, techniques, and procedures used by adversaries how they simulate attacks, from creating code that will give them credentials to walking in a building and plugging in a device. You will also learn the difference is between penetration testing and vulnerability scans and how Eric and Randy do their best to find vulnerability scan reports to prove the value of a true penetration test. Sidenote, yes, I said Petaflop and I meant Petabyte and I’ll forever live with this mistake – Zack
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: @nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
On this week’s episode of Pwned Breach of the Week, we are checking out dating data that found itself on the market, unfortunately it was not interested in starting a new relationship. The data breach resulted in numerous online dating services finding their client information on the dark web for sale to the highest bidder. In an age of increasing online dating, this type of breach can be expensive, revealing, and in some cases, quite embarrassing. Justin provides some helpful tips in how services can test systems prior to a breach to protect them and Zack professes his love for coffee and bagels. As always, we’d love to hear your feedback and hear your breach stories.
You can find more breaches at the privacy rights clearing house: https://privacyrights.org/data-breaches
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: @nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
On this week’s episode of Pwned Breach of the Week, we are checking out dating data that found itself on the market, unfortunately it was not interested in starting a new relationship. The data breach resulted in numerous online dating services finding their client information on the dark web for sale to the highest bidder. In an age of increasing online dating, this type of breach can be expensive, revealing, and in some cases, quite embarrassing. Justin provides some helpful tips in how services can test systems prior to a breach to protect them and Zack professes his love for coffee and bagels. As always, we'd love to hear your feedback and hear your breach stories.
You can find more breaches at the privacy rights clearing house: https://privacyrights.org/data-breaches
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: @nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
You would be hard pressed to find a cyber security company that isn't marketing its artificial intelligence capabilities. If you believe the hype, you probably think that AI can block zero day attacks, find the bad guys, and bring them to justice. The reality of what AI can and can't do, is quite different from what you may be seeing in advertisements. While it's not a silver bullet, AI does have a role in cyber security. Can it catch things that the good ol' fashioned human being would otherwise miss? Can it actually stop attacks before they happen? On this weeks episodes Justin is laying out what artificial intelligence is, what it can do, and why you should be cautious when you are looking to employ AI systems to protect your organization.
We're also including an in depth blog post to allow you to dig deeper into episode and learn more about artificial intelligence: https://nuharborsecurity.com/vulnerability-ai
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: @nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
You would be hard pressed to find a cyber security company that isn’t marketing its artificial intelligence capabilities. If you believe the hype, you probably think that AI can block zero day attacks, find the bad guys, and bring them to justice. The reality of what AI can and can’t do, is quite different from what you may be seeing in advertisements. While it’s not a silver bullet, AI does have a role in cyber security. Can it catch things that the good ol’ fashioned human being would otherwise miss? Can it actually stop attacks before they happen? On this weeks episodes Justin is laying out what artificial intelligence is, what it can do, and why you should be cautious when you are looking to employ AI systems to protect your organization.
We’re also including an in depth blog post to allow you to dig deeper into episode and learn more about artificial intelligence: https://www.nuharborsecurity.com/vulnerability-ai
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: @nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
On this week’s Breach of the Week, we learn the importance of measure twice, cut once. Why are we sharing this timeless carpentry advice? Well, for one, it is great advice to ensure you don't waste construction materials but for our purposes, the breach this week is about an email sent out with the best of intentions and instead releasing significant PII data. As if you need another reason to check your email, we also talk about an email involving Nicholas Cage and yet another email that revealed who was pulling their weight at a big corporation. We highlight these mistakes because it is so easy that anyone could mistakenly do this, proving yet again human error is a significant vulnerability. So, check that email twice before sending, measure that board twice before cutting, and stay off our Breach of the Week!
You can find more breaches at the privacy rights clearing house: https://privacyrights.org/data-breaches
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: https://nuharborsecurity.com Facebook: https://www.facebook.com/nuharbor/ Twitter: @nuharbor LinkedIn: https://www.linkedin.com/company/nuharbor/ Instagram: https://www.instagram.com/nuharborsecurity/
On this week’s Breach of the Week, we learn the importance of measure twice, cut once. Why are we sharing this timeless carpentry advice? Well, for one, it is great advice to ensure you don’t waste construction materials but for our purposes, the breach this week is about an email sent out with the best of intentions and instead releasing significant PII data. As if you need another reason to check your email, we also talk about an email involving Nicholas Cage and yet another email that revealed who was pulling their weight at a big corporation. We highlight these mistakes because it is so easy that anyone could mistakenly do this, proving yet again human error is a significant vulnerability. So, check that email twice before sending, measure that board twice before cutting, and stay off our Breach of the Week!
You can find more breaches at the privacy rights clearing house: https://privacyrights.org/data-breaches
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: https://www.nuharborsecurity.com
Facebook: https://www.facebook.com/nuharbor/
Twitter: @nuharbor
LinkedIn: https://www.linkedin.com/company/nuharbor/
Instagram: https://www.instagram.com/nuharborsecurity/
Welcome to our first GigaByte episode! In this long episode, we are taking a big dive into information and cyber security industry trends with two of our Trusted Security Advisors, Chad, and Travis. They share what they have seen over the last few months, what changed with COVID-19 and what the future holds for the information security industry. As the industry has adapted, so has NuHarbor (in fact, this entire podcast was recorded remotely) and Chad and Travis explain how they have had to use their expertise to help information security professionals protect their organizations in a landscape that changes by the day. Chad and Travis also provide their thoughts on what changes are going to stick around, including significant increases in people working remotely and the challenges of using company devices, on personal networks, to log into company networks. How can companies prepare for this security challenge? Does the future of work involve more opportunities to stay in your pajamas? And will we ever have to go into a grocery store again? Tune in and find out!
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: www.nuharborsecurity.com
Facebook: www.facebook.com/nuharbor/
Twitter: @nuharbor
LinkedIn: www.linkedin.com/company/nuharbor/
Instagram: www.instagram.com/nuharborsecurity/
Welcome to our first GigaByte episode! In this long episode, we are taking a big dive into information and cyber security industry trends with two of our Trusted Security Advisors, Chad, and Travis. They share what they have seen over the last few months, what changed with COVID-19 and what the future holds for the information security industry. As the industry has adapted, so has NuHarbor (in fact, this entire podcast was recorded remotely) and Chad and Travis explain how they have had to use their expertise to help information security professionals protect their organizations in a landscape that changes by the day. Chad and Travis also provide their thoughts on what changes are going to stick around, including significant increases in people working remotely and the challenges of using company devices, on personal networks, to log into company networks. How can companies prepare for this security challenge? Does the future of work involve more opportunities to stay in your pajamas? And will we ever have to go into a grocery store again? Tune in and find out!
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: www.nuharborsecurity.com Facebook: www.facebook.com/nuharbor/ Twitter: @nuharbor LinkedIn: www.linkedin.com/company/nuharbor/ Instagram: www.instagram.com/nuharborsecurity/
This week we’re mixing it up with our Breach of the Week: The Case of the Missing CD-ROM. Yes, CD-ROM. Zack and Justin discuss the theft of a CDROM with PII and ponder why anyone would want to steal a CD-ROM and if they would even have a drive to get the data off in the first place. A real whodunit. Was it the Smithsonian, a confused child, or a Pintrest fail? Tune in to find out. Also, we’ve already hit 1000 listens for the new season! Thank you to everyone that listens to and enjoys our podcast! Unfortunately, we’re not satisfied with a mere 1000 listens and are challenging you to subscribe, like, share, rate, and review and get your fellow infosec and cyber security friends to listen. Next week we’ve got our first long episode where we talk to two of our Trusted Security Advisors about trends in the cyber security industry and how COVID-19 has flipped everything on its head.
You can find more breaches at the privacy rights clearing house: https://privacyrights.org/data-breaches
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: www.nuharborsecurity.com
Facebook: www.facebook.com/nuharbor/
Twitter: @nuharbor
LinkedIn: www.linkedin.com/company/nuharbor/
Instagram: www.instagram.com/nuharborsecurity/
This week we're mixing it up with our Breach of the Week: The Case of the Missing CD-ROM. Yes, CD-ROM. Zack and Justin discuss the theft of a CDROM with PII and ponder why anyone would want to steal a CD-ROM and if they would even have a drive to get the data off in the first place. A real whodunit. Was it the Smithsonian, a confused child, or a Pintrest fail? Tune in to find out. Also, we've already hit 1000 listens for the new season! Thank you to everyone that listens to and enjoys our podcast! Unfortunately, we're not satisfied with a mere 1000 listens and are challenging you to subscribe, like, share, rate, and review and get your fellow infosec and cyber security friends to listen. Next week we've got our first long episode where we talk to two of our Trusted Security Advisors about trends in the cyber security industry and how COVID-19 has flipped everything on its head.
You can find more breaches at the privacy rights clearing house: https://privacyrights.org/data-breaches
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: www.nuharborsecurity.com Facebook: www.facebook.com/nuharbor/ Twitter: @nuharbor LinkedIn: www.linkedin.com/company/nuharbor/ Instagram: www.instagram.com/nuharborsecurity/
This week we're exploring Tactics, Techniques and Procedures (TTP) related to COVID-19 threats. As with many disasters, cyber criminals are hoping to exploit people who are trying to find helpful information online and may be more likely to open sketchy links or email attachments. Therefore, the best ways to protect your organization is to understand what these threats look like, how they work, and who may be behind them, all of which requires that you understand the TTPs being used. So, check out this episode to learn about TTPs for COVID-19 threats. If you are enjoying these episodes, have ideas around topics, or would like to be on a future episode, contact us at pwned @ nuharborsecurity.com
Episode Transcript: PWNED Transcripts - S2E4 - TTPs for COVID-19 Threats
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: www.nuharborsecurity.com Facebook: www.facebook.com/nuharbor/ Twitter: @nuharbor LinkedIn: www.linkedin.com/company/nuharbor/ Instagram: www.instagram.com/nuharborsecurity/
Covid-19 related TTPs:
Malware / Attack Phishing
Geography / Industry Japan
Lure Coronavirus
Info Microsoft Word with malicaious VBA macro. Installs Emotet via Powershell.
Malware / Attack Phishing
Geography / Industry United States
Lure "COVID-19 — Now Airborne, Increased Community Transmission", appears to be from the CDC.gov (headers manipulated)
Info Originally identified by Cofense, When victims click on the embedded link, they are redirected to a Microsoft Outlook login page, and upon entering their legitimate credentials, are further redirected to a legitimate website of the CDC.
Malware / Attack Phishing
Geography / Industry Italy
Lure "Coronavirus: informazioni importanti su precauzioni", appears to be from “Dr. Penelope Marchetti,” an employee of the WHO in Italy.
Info Emails contain Microsoft Office Documents with VBA macros that installs Trickbot Malware that steals personal information or installs additional malware.
Malware / Attack Phishing
Geography / Industry South Korea
Lure Varying subject lines that claim to information about South Korea's response to COVID-19.
Info Emails contain Microsoft Word documentation that installs the North Korea's BabyShark Malware.
Malware / Attack Phishing
Geography / Industry United States
Lure Email claiming to provide victims with information on global FedEx operations while the COVID-19 outbreak continues.
Info Emails contained an attachment titled “Customer Advisory.PDF. exe” that, when opened, infected the victim with the Lokibot malware
Malware / Attack Phishing
Geography / Industry United States
Lure Email claiming to provide victims with information on global FedEx operations while the COVID-19 outbreak continues.
Info Emails contained an attachment titled “Customer Advisory.PDF. exe” that, when opened, infected the victim with the Lokibot malware
Malware / Attack Phishing
Geography / Industry United States
Lure COVID-19 type content
Info Originally identified by Proofpoint, These attacks involved emails that contained Microsoft Office document attachments designed to lure victims and exploit a Microsoft Office vulnerability, tracked as CVE-2017-11882, which allows attackers to run arbitrary code in the context of the current user ultimately installing AZORult malware.
Malware / Attack Phishing
Geography / Industry United States
Lure COVID-19 emails from CDC.gov
Info URL contained within a phishing email led to a fake Microsoft Outlook login page, designed to convince victims to input their credentials. In another instance, victims were asked to donate Bitcoin to the CDC to aid in the pursuit of a vaccine.
This week we’re exploring Tactics, Techniques and Procedures (TTP) related to COVID-19 threats. As with many disasters, cyber criminals are hoping to exploit people who are trying to find helpful information online and may be more likely to open sketchy links or email attachments. Therefore, the best ways to protect your organization is to understand what these threats look like, how they work, and who may be behind them, all of which requires that you understand the TTPs being used. So, check out this episode to learn about TTPs for COVID-19 threats. If you are enjoying these episodes, have ideas around topics, or would like to be on a future episode, contact us at pwned @ nuharborsecurity.com
Episode Transcript: PWNED Transcripts – S2E4 – TTPs for COVID-19 Threats
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: www.nuharborsecurity.com
Facebook: www.facebook.com/nuharbor/
Twitter: @nuharbor
LinkedIn: www.linkedin.com/company/nuharbor/
Instagram: www.instagram.com/nuharborsecurity/
Covid-19 related TTPs:
| Malware / Attack | Phishing | | Geography / Industry | Japan | | Lure | Coronavirus | | Info | Microsoft Word with malicaious VBA macro. Installs Emotet via Powershell. |
| Malware / Attack | Phishing | | Geography / Industry | United States | | Lure | “COVID-19 — Now Airborne, Increased Community Transmission”, appears to be from the CDC.gov (headers manipulated) | | Info | Originally identified by Cofense, When victims click on the embedded link, they are redirected to a Microsoft Outlook login page, and upon entering their legitimate credentials, are further redirected to a legitimate website of the CDC. |
| Malware / Attack | Phishing | | Geography / Industry | Italy | | Lure | “Coronavirus: informazioni importanti su precauzioni”, appears to be from “Dr. Penelope Marchetti,” an employee of the WHO in Italy. | | Info | Emails contain Microsoft Office Documents with VBA macros that installs Trickbot Malware that steals personal information or installs additional malware. |
| Malware / Attack | Phishing | | Geography / Industry | South Korea | | Lure | Varying subject lines that claim to information about South Korea’s response to COVID-19. | | Info | Emails contain Microsoft Word documentation that installs the North Korea’s BabyShark Malware. |
| Malware / Attack | Phishing | | Geography / Industry | United States | | Lure | Email claiming to provide victims with information on global FedEx operations while the COVID-19 outbreak continues. | | Info | Emails contained an attachment titled “Customer Advisory.PDF. exe” that, when opened, infected the victim with the Lokibot malware |
| Malware / Attack | Phishing | | Geography / Industry | United States | | Lure | Email claiming to provide victims with information on global FedEx operations while the COVID-19 outbreak continues. | | Info | Emails contained an attachment titled “Customer Advisory.PDF. exe” that, when opened, infected the victim with the Lokibot malware |
| Malware / Attack | Phishing | | Geography / Industry | United States | | Lure | COVID-19 type content | | Info | Originally identified by Proofpoint, These attacks involved emails that contained Microsoft Office document attachments designed to lure victims and exploit a Microsoft Office vulnerability, tracked as CVE-2017-11882, which allows attackers to run arbitrary code in the context of the current user ultimately installing AZORult malware. |
| Malware / Attack | Phishing | | Geography / Industry | United States | | Lure | COVID-19 emails from CDC.gov | | Info | URL contained within a phishing email led to a fake Microsoft Outlook login page, designed to convince victims to input their credentials. In another instance, victims were asked to donate Bitcoin to the CDC to aid in the pursuit of a vaccine. |
On today’s episode we’re talking COOP, or Continuity of Operations Planning. It’s estimated that as many as 50 percent of businesses impacted by a disaster will fail and that number is even higher for small businesses. You’re likely operating some form of a COOP plan due to COVID-19 and you may not have even realized it and hopefully you had a plan before everything hit the fan. Unfortunately, we’re seeing business close up shop because they were not prepared.
COOP at it’s most basic level is planning for how you’ll maintain your businesses critical functions before, during, and after a major disruption. What exactly does it cover? Some basic things to plan for include how you’ll communicate and access data, how staff will work, what systems must remain operational, how long you can function in a contingency mode, organizing your teams, delegating authority, and how you’ll get back to normal operations.
What can you do to prepare? FEMA has developed two online courses specific to COOP planning during a pandemic.
IS 520: Introduction to Continuity of Operations Planning for Pandemic Influenzas and IS 522: Exercising Continuity Plans for Pandemic Course.
These courses provide a great intro to the COOP process and can help build a solid foundation of training and experience.
There are a number of different standards to help assess and guide your COOP planning efforts and many organizations that can assist you from federal agencies to private sector consultants. Continuity of Operations Planning is a critical process that will help to ensure that your organization can survive any disaster. If you need assistance with your cyber COOP planning, contact us at NuHarbor Security today.
As always, thank you to our sponsor, Nuharbor security your end to end provider of security services and solutions If your looking for smart security solutions for your business and a security partner that actually gives a BEEP, visit us at www.nuharborsecurity.com
On today's episode we're talking COOP, or Continuity of Operations Planning. It's estimated that as many as 50 percent of businesses impacted by a disaster will fail and that number is even higher for small businesses. You're likely operating some form of a COOP plan due to COVID-19 and you may not have even realized it and hopefully you had a plan before everything hit the fan. Unfortunately, we're seeing business close up shop because they were not prepared.
COOP at it's most basic level is planning for how you'll maintain your businesses critical functions before, during, and after a major disruption. What exactly does it cover? Some basic things to plan for include how you'll communicate and access data, how staff will work, what systems must remain operational, how long you can function in a contingency mode, organizing your teams, delegating authority, and how you'll get back to normal operations.
What can you do to prepare? FEMA has developed two online courses specific to COOP planning during a pandemic.
IS 520: Introduction to Continuity of Operations Planning for Pandemic Influenzas and IS 522: Exercising Continuity Plans for Pandemic Course.
These courses provide a great intro to the COOP process and can help build a solid foundation of training and experience.
There are a number of different standards to help assess and guide your COOP planning efforts and many organizations that can assist you from federal agencies to private sector consultants. Continuity of Operations Planning is a critical process that will help to ensure that your organization can survive any disaster. If you need assistance with your cyber COOP planning, contact us at NuHarbor Security today.
As always, thank you to our sponsor, Nuharbor security your end to end provider of security services and solutions If your looking for smart security solutions for your business and a security partner that actually gives a BEEP, visit us at www.nuharborsecurity.com
This week we explore security orchestration, automation and response (SOAR) and how managed security service providers (MSSP) can leverage SOAR to better secure your organization. We’ll discuss the challenges of traditional security monitoring and the benefits of working with an MSSP that integrates SOAR in its practice to be better prepared to respond to real events and understand how traditional methods of monitoring cyber security events can create complacency and miss real world incidents. We’ll also talk about the different providers of security services and why it’s important that you pick a provider that specializes in protecting organizations from cyber attacks.
In this episode, we’ll cover:
Episode Transcript: Pwned Transcripts – S2 E3 -SOAR FOR MSSP Transcript
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: www.nuharborsecurity.com
Facebook: www.facebook.com/nuharbor/
Twitter: @nuharbor
LinkedIn: www.linkedin.com/company/nuharbor/
Instagram: www.instagram.com/nuharborsecurity/
This week we explore security orchestration, automation and response (SOAR) and how managed security service providers (MSSP) can leverage SOAR to better secure your organization. We'll discuss the challenges of traditional security monitoring and the benefits of working with an MSSP that integrates SOAR in its practice to be better prepared to respond to real events and understand how traditional methods of monitoring cyber security events can create complacency and miss real world incidents. We'll also talk about the different providers of security services and why it's important that you pick a provider that specializes in protecting organizations from cyber attacks.
In this episode, we'll cover:
Understanding SOAR technology and how it can boost your security presence The challenges of alert fatigue and complacency Understanding the limitation of SOAR and how MSSP providers can optimize its use Ensuring that your organization understand the difference in security resources available and how some may conflict Picking the tools that will best protect you
Episode Transcript: Pwned Transcripts - S2 E3 -SOAR FOR MSSP Transcript
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: www.nuharborsecurity.com Facebook: www.facebook.com/nuharbor/ Twitter: @nuharbor LinkedIn: www.linkedin.com/company/nuharbor/ Instagram: www.instagram.com/nuharborsecurity/
Without question, we've entered a new era of web-based meetings. This has become how most companies are conducting business with the current pandemic. And I suspect this is going to remain even active after we're all back at our offices. One thing that's come up with the proliferation of web meetings is the failure to secure those meetings. It's gotten bad enough that the FBI field office in Boston actually sent out an advisory today talking about the risks of meetings being infiltrated. So, what are those risks? First, as many of us have experienced over the last two weeks, people jumping into meetings that don't belong in there, and in worst case, scenarios yelling obscene and noxious things that's obnoxious for everyone listening in, and it also makes you, the host, look like you don't know what you're doing. Another important risk to consider is that if you have people inside those meetings that don't belong there, they're listening in on your business and other activities. You wouldn't allow strangers to hang out in your conference room in real life, don't let it happen online. So, what can you do? First, try to avoid open URL meetings. Don't send them out to mass emails, don't post them on social media. If you're gonna have a meeting, make sure you invite who's supposed to be there and provide them specific tokens or other information to login you can password protect your meetings which add an additional layer of protection. If you are having an open meeting for the love of God, mute everyone. No one wants to hear people eating food or commenting on the discussion, unless of course it is entertaining. Finally, pay attention to who's logged in. Most meeting systems have a waiting room before you enter and that's an opportunity to take a look around and see who doesn't belong. You can also take actual attendance and boot people who don't answer you. That's today's Pwned Byte Sized episode. Remember, keep your meetings safe and secure.
Website: www.nuharborsecurity.com Facebook: www.facebook.com/nuharbor/ Twitter: @nuharbor LinkedIn: www.linkedin.com/company/nuharbor/ Instagram: www.instagram.com/nuharborsecurity/
Without question, we’ve entered a new era of web-based meetings. This has become how most companies are conducting business with the current pandemic. And I suspect this is going to remain even active after we’re all back at our offices. One thing that’s come up with the proliferation of web meetings is the failure to secure those meetings. It’s gotten bad enough that the FBI field office in Boston actually sent out an advisory today talking about the risks of meetings being infiltrated. So, what are those risks? First, as many of us have experienced over the last two weeks, people jumping into meetings that don’t belong in there, and in worst case, scenarios yelling obscene and noxious things that’s obnoxious for everyone listening in, and it also makes you, the host, look like you don’t know what you’re doing. Another important risk to consider is that if you have people inside those meetings that don’t belong there, they’re listening in on your business and other activities. You wouldn’t allow strangers to hang out in your conference room in real life, don’t let it happen online. So, what can you do? First, try to avoid open URL meetings. Don’t send them out to mass emails, don’t post them on social media. If you’re gonna have a meeting, make sure you invite who’s supposed to be there and provide them specific tokens or other information to login you can password protect your meetings which add an additional layer of protection. If you are having an open meeting for the love of God, mute everyone. No one wants to hear people eating food or commenting on the discussion, unless of course it is entertaining. Finally, pay attention to who’s logged in. Most meeting systems have a waiting room before you enter and that’s an opportunity to take a look around and see who doesn’t belong. You can also take actual attendance and boot people who don’t answer you. That’s today’s Pwned Byte Sized episode. Remember, keep your meetings safe and secure.
Website: www.nuharborsecurity.com
Facebook: www.facebook.com/nuharbor/
Twitter: @nuharbor
LinkedIn: www.linkedin.com/company/nuharbor/
Instagram: www.instagram.com/nuharborsecurity/
Many organizations are finding themselves scrambling to secure their remote workforce due to COVID-19. On this episode, we’re talking remote workforce security best practices and what you can do to keep your team running out of the office. Best case scenario, you planned and exercised for just this situation and your team was ready to make the switch to off site, your staff were trained on how to securely work away from the office, and your system was built to keep your network and data safe both on and off premises. Unfortunately, the reality for many organizations was that they hadn’t considered remote workforce security, or at least to the scale of this crisis,and had to figure it out live. Wherever in that spectrum of readiness you find yourself, we’ve got tips, techniques, and strategies to help you keep you and your team secure and operational.
In this episode, we’ll cover:
Episode Transcript
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust.Website: www.nuharborsecurity.com
Facebook: www.facebook.com/nuharbor/
Twitter: @nuharbor
LinkedIn: www.linkedin.com/company/nuharbor/
Instagram: www.instagram.com/nuharborsecurity/
Many organizations are finding themselves scrambling to secure their remote workforce due to COVID-19. On this episode, we're talking remote workforce security best practices and what you can do to keep your team running out of the office. Best case scenario, you planned and exercised for just this situation and your team was ready to make the switch to off site, your staff were trained on how to securely work away from the office, and your system was built to keep your network and data safe both on and off premises. Unfortunately, the reality for many organizations was that they hadn't considered remote workforce security, or at least to the scale of this crisis,and had to figure it out live. Wherever in that spectrum of readiness you find yourself, we've got tips, techniques, and strategies to help you keep you and your team secure and operational.
In this episode, we'll cover:
Email security and phishing threats Training and educating your employees to be safe and secure while working remotely Preparing your enterprise security for remote work Knowing what to look for and how to respond to threats Encrypt, encrypt, encrypt Utilizing cloud apps Policies and procedures to help guide workers and keep your data safe
Episode Transcript
Check out NuHarbor Security for complete cyber security protection for your business and a security partner you can trust. Website: www.nuharborsecurity.com Facebook: www.facebook.com/nuharbor/ Twitter: @nuharbor LinkedIn: www.linkedin.com/company/nuharbor/ Instagram: www.instagram.com/nuharborsecurity/
NuHarbor Security announces the relaunch of PWNED – The Information Security Podcast with Justin Fimlaid. Stay tuned for episodes about staying secure while working from home, artificial intelligence, and emerging threats in 5G.
NuHarbor Security announces the relaunch of PWNED - The Information Security Podcast with Justin Fimlaid. Stay tuned for episodes about staying secure while working from home, artificial intelligence, and emerging threats in 5G.
Sponsor:https://www.nuharborsecurity.com
Contact Me:https://justinfimlaid.com/contact-me/
Twitter: @justinfimlaid
LinkedIn: https://www.linkedin.com/in/jfimlaid/
All the notes: https://www.nuharborsecurity.com/exim-server-vulnerabilities/
Interesting Tid-bits:
Firewall Addresses:
Sponsor:https://www.nuharborsecurity.com
Contact Me:https://justinfimlaid.com/contact-me/
Twitter: @justinfimlaid
LinkedIn: https://www.linkedin.com/in/jfimlaid/
Sponsor:https://www.nuharborsecurity.com
Contact Me:https://justinfimlaid.com/contact-me/
Twitter: @justinfimlaid
LinkedIn: https://www.linkedin.com/in/jfimlaid/
Sponsor:https://www.nuharborsecurity.com
Contact Me:https://justinfimlaid.com/contact-me/
Twitter: @justinfimlaid
LinkedIn: https://www.linkedin.com/in/jfimlaid/
IOCs: APT10/Operation Cloud Hopper – Indicators of Compromise v3.csv
Important Links:
More Info: https://www.nuharborsecurity.com/4-things-to-know-about-the-ohio-data-protection-act/
State of Ohio Data Protection Act Law Text: https://www.legislature.ohio.gov/legislation/legislation-documents?id=GA132-SB-220
IAPP Analysis (by Katelyn Burgess): https://iapp.org/news/a/analysis-ohios-data-protection-act/
What is the Ohio Data Protection Law (by Jenna Kersten): https://kirkpatrickprice.com/blog/what-is-the-ohio-data-protection-act/
Sponsor:https://www.nuharborsecurity.com
Contact Me:https://justinfimlaid.com/contact-me/
Twitter: @justinfimlaid
LinkedIn: https://www.linkedin.com/in/jfimlaid/
Important Links:
SHA-1 Collision Explanation Page: https://shattered.io/
Malicious Hashing: Eve’s Variant of SHA-1 https://link.springer.com/content/pdf/10.1007%2F978-3-319-13051-4_1.pdf
Finding SHA-1 Characteristics: General Results and Applications: https://link.springer.com/chapter/10.1007%2F11935230_1
Sponsor:https://www.nuharborsecurity.com
Contact Me:https://justinfimlaid.com/contact-me/
Twitter: @justinfimlaid
LinkedIn: https://www.linkedin.com/in/jfimlaid/
Show Notes: https://www.nuharborsecurity.com/building-a-vulnerability-management-program-with-the-end-in-mind/
Sponsor: https://www.nuharborsecurity.com
Contact Me: https://justinfimlaid.com/contact-me/
Twitter: @justinfimlaid
LinkedIn: https://www.linkedin.com/in/jfimlaid/
Show Notes: https://justinfimlaid.com/quickstart-building-a-security-program-with-the-nist-cybersecurity-framework/h
Sponsor: https://www.nuharborsecurity.com
Contact Me: https://justinfimlaid.com/contact-me/
Twitter: @justinfimlaid
LinkedIn: https://www.linkedin.com/in/jfimlaid/
Show Notes: https://www.nuharborsecurity.com/red-teaming-vs-penetration-testing/
Sponsor: https://www.nuharborsecurity.com
Contact Me: https://justinfimlaid.com/contact-me/
Twitter: @justinfimlaid
LinkedIn: https://www.linkedin.com/in/jfimlaid/
Sponsor: https://www.nuharborsecurity.com
Contact Me: https://justinfimlaid.com/contact-me/
Twitter: @justinfimlaid
LinkedIn: https://www.linkedin.com/in/jfimlaid/
My opinion of
security has changed. We are not keeping up.
Companies keep getting breached.
First things first,
the idea and concepts of security have been around for a while. In the most general terms, truth is we have
senior industry and junior skill set.
Our collective
industry is not helping us be better.
Security product companies are coming to the market with new half
solutions and big marketing budgets.
Advisory companies are coming to the table with new buzzwords and hollow
concepts. And “thought
leaders” and “trusted advisors” are still trying to figure this
out, and probably not giving the best advice yet. All these things take our collective eye off
the ball, cause us to loose focus, and distract us from doing well at security
fundamentals.
For those listening
to this unfamiliar with our space, here’s some examples what we’re dealing
with:
Those are some
examples, but it’s not all bad. We need
stay focused though. In order for our security industry to get better we need
get back to basics of good security hygiene.
I admit this is easier said than done, its going to take time to get
there. Until we do this we can’t start
to think about automation because if you do crappy security and automate it,
security automation will allow you just do crappy security faster. You don’t need blockchain, if you don’t
believe it do some research in European Election Security…they use good
old-fashion asymmetric encryption. If
you’re getting started, or need a realignment go back the fundamentals, good
policy, good security architecture, good security hygiene of accounts,
etc. When you’ve done this, then
hopefully you have a good handle on requirements for security technology and
you have the expertise on how the technology should work in your environment.
Show Notes: https://www.nuharborsecurity.com/open-banking-directive-and-securing-web-application-vulnerabilities/
Sponsor: https://www.nuharborsecurity.com
Contact Me: https://justinfimlaid.com/contact-me/
Twitter: @justinfimlaid
LinkedIn: https://www.linkedin.com/in/jfimlaid/
Application Security Checklist for Web Applications and API's. Also @ NuHarbor Security.
I have not seen an Open Banking Web Application Checklist, so hopefully this is a good starting point for some.
1.Ensure HTTPS:
This one is pretty simple but HTTPS protects authentication credentials in transit for example passwords, API keys, or JSON Web Tokens. It also allows clients to authenticate the service and guarantees integrity of the transmitted data.
There seems to be a convergence toward using JSON web tokens as the format for security tokens. JSON web tokens are JSON data structure containing a set of claims that can be used for access control decisions. If you are looking for more on JSON formats, here's a good starting point.
Non-public rest services must perform access control at each API endpoint. Web services in monolithic applications implement this by means of user authentication, authorization of logic in session management. To this right at scale, user authentication should be through a centralized Identity Provider which issues their own tokens.
Anyone developing for a while knows this is a requirement. If you don't sanitize inputs your application days are numbered. Contact me if you want the full-list on this one.
Apply a whitelist of permitted HTTP Methods (e.g. GET, POST, PUT) and make sure the caller is authorized to use the incoming HTTP method on the resource collection, action, and record. Leverage 405's when rejecting all requests not matching the whitelist.
API
Keys can reduce the impact of denial of service attacks. However, when their
issue to third-party clients, they are easy to compromise. There are a couple things you can do to
mitigate security risks including require API keys for every request to the
protected endpoint. You can also returning a 429 message “too many
requests” if the volume of requests are to high. Do not rely solely on API
keys to protect high-value resources.
A
rest request a response body should match the intended content type in the
header. Otherwise this can cause misinterpretation at the consumer/producer
side lead to code injection/execution.
Some additional things to think about:
Validate Request Content TypesSend Safe Response Content Types
There is a couple things you can do to securely manage your end points. Avoid exposing your management and points by way of the Internet. If your management and points must be accessible to the Internet, make sure that all users authenticate using strong authentication mechanisms such as multi factor authentication. Security by obscurity is not always a good strategy, but exposing management endpoints by way of different HTTP ports or host on different/restricted subnets can also reduce some risk. Lastly restrict access to these endpoints by firewall ACL's.
Keep error message is generic in nature. Try to avoid revealing details of any and all failures when necessary. This will help prevent giving the potential attackers the information they need to game the system or perform a secondary attack with the new information.
This one is sometimes overlooked, but to make sure the content of the given resources is interpreted correctly by the browser, the server should always send the “content-type” header with the correct content type, and preferably the “content-type” header should include a charset. The server should sent the “X-Content-Type-Options: nosniff” security he…
Show Notes: https://www.nuharborsecurity.com/how-does-estonias-e-voting-work/
Sponsor: https://www.nuharborsecurity.com
Contact Me: https://justinfimlaid.com/contact-me/
Twitter: @justinfimlaid
LinkedIn: https://www.linkedin.com/in/jfimlaid/
Show Notes: https://www.nuharborsecurity.com/building-on-people-process-and-technology/
Sponsor: https://www.nuharborsecurity.com
Contact Me: https://justinfimlaid.com/contact-me/
Twitter: @justinfimlaid
LinkedIn: https://www.linkedin.com/in/jfimlaid/
Show Notes: https://www.nuharborsecurity.com/pci-data-security-standard-4-0/
Sponsor: https://www.nuharborsecurity.com
Contact Me: https://justinfimlaid.com/contact-me/
Twitter: @justinfimlaid
LinkedIn: https://www.linkedin.com/in/jfimlaid/
Show Notes: https://www.nuharborsecurity.com/10-application-security-authentication-requirements/
Sponsor: https://www.nuharborsecurity.com
Contact Me: https://justinfimlaid.com/contact-me/
Twitter: @justinfimlaid
LinkedIn: https://www.linkedin.com/in/jfimlaid/
Show Notes: https://justinfimlaid.com/soc2-report-quickstart/
Sponsor: https://www.nuharborsecurity.com
Contact Me: https://justinfimlaid.com/contact-me/
Twitter: @justinfimlaid
LinkedIn: https://www.linkedin.com/in/jfimlaid/
Looking for information on SOC2, read more here: https://www.nuharborsecurity.com/do-i-need-a-soc2-report/
Show Notes: https://justinfimlaid.com/not-invented-here-syndrome-for-security
Sponsor: https://www.nuharborsecurity.com
Contact Me: https://justinfimlaid.com/contact-me/
Twitter: @justinfimlaid
LinkedIn: https://www.linkedin.com/in/jfimlaid/
Have
you ever had an idea to advance your company or another companies security
posture? And it's a really good
idea. Like really good. You do you your homework and dot the
“I's” and cross the “T's” and your propose a superior
solution that sets your organization up for, what you think, is long term
success? When you propose your idea,
someone passionately proposes an alternative weaker solution. Or worse, people take shots at your idea
trying to make it look like swiss cheese for the apparent purpose of making an
alternate idea better?
If
yes, you might have seen and experienced the “Not Invented Here
Syndrome”.
One of the more concise definitions of Not Invented Here Syndrome (NIHS) I've heard come from Techopedia:
“Not invented here syndrome is a mindset or corporate culture that favors internally-developed products over externally-developed products, even when the external solution is superior.
NIHS is
frequently used in the context of software development, where a programmer will
overlook all the attributes of an existing solution simply
because it wasn't produced in-house.”
Another variant
to NIHS is the micro variation comes when the security department or CISO is
accountable for security but doesn't have responsibility for security. So if you are security professional
recommending products/solutions that are always “shot down” by those
with budget authority there could be a few reasons and Not Invented Here might
be the cause. NIHS can take a couple
forms (this list adapted from Techopedia):
The other teams don't value the work of others. They have pride in a negative way.They don't understand or unwilling to try to understand the benefits and lack confidence.Fear that their previous ideas aren't valued.Territorial battles, e.g. internal “turf wars”.Fear of having to learn something new.Wanting to control the process. Would rather “reinvent the wheel” to maintain control.Jealousy that they didn't think of the idea first.Belief that they can do a better job.The other teams don't value the work of others and believe they can do better. They have pride in a positive way.
There's
always the counter argument that the Security team always makes sub-tier
recommendations and IT rather keeps the proverbial security train on the
tracks.
Anyway,
NIHS is a real thing and can really be barrier to completing an annual
plan. For organizations that don't
foster innovation NIHS can really be present in the way the company operates
day to day. There's some great articles
on Not Invented Here and how some of the worlds longest standing companies
foster innovation and work with external ideas to make their business grow.
Some interesting links you might check out…
https://hbswk.hbs.edu/item/the-benefits-of-not-invented-here
https://www.forbes.com/sites/haroldsirkin/2017/03/09/not-invented-here-not-at-the-most-innovative-companies/#1d85172c1e35
Show Notes: https://www.nuharborsecurity.com/red-teaming-vs-penetration-testing/
Sponsor: https://www.nuharborsecurity.com
Contact Me: https://justinfimlaid.com/contact-me/
Twitter: @justinfimlaid
LinkedIn: https://www.linkedin.com/in/jfimlaid/
Show Notes: https://justinfimlaid.com/without-wax:-the-quest-for-perfection/
Sponsor: https://www.nuharborsecurity.com
Contact Me: https://justinfimlaid.com/contact-me/
Twitter: @justinfimlaid
LinkedIn: https://www.linkedin.com/in/jfimlaid/
I had an English
Teacher in High School that was big on
Etymology. If you aren't familiar with
Etymology, its history of how certain words came to be. What I like about
Etymology is the stories behind certain words.
This teacher was one the few teachers I actually liked in High School,
and I hated English classes so I guess that says a lot. One word, and one his lessons has always
stuck with me. That word in
Sincere. Sincere is from the Latin words
Sin Cera. In Latin Sin is “without” and
Cera is “wax”.
The story of Sin
Cera dates back to ancient Roman times.
The artistry from that time period was seen in statues and ornate marble
pillars. What was significant about that
time period is that artists were appreciated for their perfection. An apprentice could work for most of their
life in a specific craft, trade, or artistry…they’d only do that one
thing. An apprentice might spend years
learning how to pick the right type of marble, or they'd spend years learning
how to carve a specific type of statue, or spend years learning how to polish a
statue. The best artists were PERFECT.
Whats interesting
about the best artists from Roman Times and the ones that sculpted Marble is
that they embodied perfection in their craft.
They would carve perfect sculptures or perfect marble pillars.
For All the other
artists trying to make a name for themselves, who cut corners in their trade
and lacked experience used wax to cover their mistakes. They would use wax to fill holes, cracks and
mistakes. The nice thing about wax is it
could be smoothed and polished to look like marble. It could be plastered over and it could be
painted over. For most buyers they could
not determine which was artificial Sin Cera or with out wax. And in some cases they’d never know until the
artist was long gone.
Today when we say we
are Sincere, it generally means we’re honest.
But origins of Sincere also means you are without wax and perfect in
your craft.
The reason I bring
this up, it seems to be relevant as of late.
I see more folks and companies trying to capitalize on the Security
market. I understand the push, it’s
capitalism in full-swing. However, I see
folks working in the security space who are really confused and are granted
trust because of a title, position, or certification. If you are in Security as a buyer or
supplier, whether inside your own company or a third party…and you claim to do
security, you need to actually do it.
Let me clarify what I mean by that.
What I mean by that
is you have an obligation to continuously learn because the threat landscape is
constantly shifting.
I realize every
subject matter expert started with 0 experience. But what makes someone sincere in their craft
isn’t the fact they have a job in the field, it’s the fact they’re a student of
the craft and continually strive to be perfect.
This means always learning and helping others bridge the security
knowledge gap. This means you can’t just dabble in security, it’s not a bullet
item on a website or on a resume. We can
do this, but we all have to put in the work and make everyone better.
We have an
obligation to get this right, if not for us then for the future generation so
they have a solid foundation to make things better.
Show Notes: https://justinfimlaid.com/quickstart-building-a-security-program-with-the-nist-cybersecurity-framework/h
Sponsor: https://www.nuharborsecurity.com
Contact Me: https://justinfimlaid.com/contact-me/
Twitter: @justinfimlaid
LinkedIn: https://www.linkedin.com/in/jfimlaid/
Hey Everyone – I'm
starting to feel a little bad that the Government has been shutdown for so
long. I've hit the NIST site at least
10-15 over the last couple weeks looking for a reference only to be met by a
we're closed frowny face. Anyway – as
soon as I recorded this the government opened up…figures. By the time this goes live NIST will be open
again.
If you're looking to
build or enhance your security program.
The NIST Cybersecurity Framework might be a good place to start.
I see a lot of
companies looking to build their security or compliance programs around
PCI-DSS, HIPAA, or FFIEC guidance to name a few. It's good guidance but these regulations fail
to recognize an organized security capability.
Meaning – there's no categorization that exists that says if you do
these group of security tasks you'll be better protected, or if you focus on
these groups of tasks you'll be better positioned to recover from a cyber
event.
The NIST
Cybersecurity framework is organized exactly that way. In absence of any regulation or compliance
requirement this framework might provide a nice step into budget conversations
or even establishing a common way to talk about cybersecurity within your
organization or institution.
To read more about
the NIST Cybersecurity Framework, check out my post
at NuHarbor Security.
Show Notes: https://justinfimlaid.com/the-best-security-technology-you-probably-arent-using
Sponsor: https://www.nuharborsecurity.com
Contact Me: https://justinfimlaid.com/contact-me/
Twitter: @justinfimlaid
LinkedIn: https://www.linkedin.com/in/jfimlaid/
With all the
breaches in the news as of late there’s been a lot of chatter about the
shifting threat landscape. I saw a post on social earlier in the week that got
me thinking; if the threat landscape is shifting – why is it that and how does
the collective industry slow things down so we can catch our breach and be
proactive with security. The one piece
of security tech I rarely see folks using is deception technology, but maybe
the value of the tech is overlooked.
The idea
of evolution and Darwinism is pretty established at this point. Whether you be
believe in creation or evolution it doesn’t matter too much but what I want to
dial into is the concept of natural selection, if you aren’t familiar with term
it’s the process whereby organisms better adapted to their environment tend to
survive and produce more offspring.
Charles Darwin’s idea of natural selection is generally created as an
evolutionist theory BUT the point I want
to highlight is I think we can all agree is the common thread here whether
you’re a evolutionist of creationist is…mutation. As we, collectively, evolve as species and
as all species we mutate we migrate and create a sense of genetic drift from
the original DNA strains. But at the
most fundamental level genetic drift occurs from testing. We test food, if it poisons us we die. We
test our living environments, if it makes us sick we have a lower chance of
procreation. If we’re dispositioned to reckless habits it could limit our
ability to pass on our genetics and or lessons to the next generation if we’re
dead.
Foundationally
speaking this is a very long term testing effort as a species but, what happens
if we couldn’t test. What happens if the
test results were random. I mean truly random. What is something was gaming us all like
something out of the Hunger Games? Two
people with the same genetic make up, eat the same berries – one gets poisoned
and dies and the other doesn’t. What
happens those same two people with the same genetic make up live in an
environment that makes one sick but not the other. If this was the case, it would be incredibly
hard to “test” and evolve. Now, what
happens if that same idea applied to castle defenses?
The idea
of attacking castles is well documented over time and there’s a long history or
action and reaction. An attacker storms the front gate and gets in, the
defenders react and build a moat if they have a next time. The defenders build the walls higher, the
attackers build a siege tower to easily get soldiers over the walls. The defenders build defense in depth and
attackers create the Trojan horse. But
what would happen if attack results were truly random, sometimes you go through
the front gate…sometimes you didn’t.
Sometimes the moat was a problem, sometimes it wasn’t. Sometimes you “thought” you got the Trojan
horse in, but you actually didn’t. What
would have happened if the attackers thought they were exploiting castle
defense but were just wasting time and were delayed until the point they were
killed. If this scenario was true – then
it’s safe to assume that the evolution of attacker techniques would be
slowed…because let’s be honest, they don’t know what does or doesn’t work. If this scenario were true – it’s also safe
to assume the intellectual cultivation of castle siege and defense tactics and
overall “investment” in new attack or defense would be slowed because attackers
truly don’t have a relative sample size to test their hypothesis since the
results are random and not based on scientific fact.
If you agree with
those ideas, the environment in medieval times didn’t exist to create random
results but the technology exists today.
Show Notes: https://justinfimlaid.com/benefits-of-a-security-certification-&-equifax-security-breach/h
Sponsor: https://www.nuharborsecurity.com
Contact Me: https://justinfimlaid.com/contact-me/
Twitter: @justinfimlaid
LinkedIn: https://www.linkedin.com/in/jfimlaid/
A lot of companies
or agency executives are looking for a security certification or some kind of
assurance they can sleep well at night.
Truth of the matter is no security firm would assert that their clients
are bullet proof from a cyber security breach.
The threat landscape is shifting intraday and anything a security firm
would attest to today might be outdated by the time the team walks out of the
building. In our industry today – there
is no certification that offers this level of warranty. HITRUST, PCI-DSS, ISO27001, SOC Reports all
ensure that a process is in place not necessarily the rigor of the security
control in place and value of said control in the long run. The Knox Security
Certification, is the lone technical security certification but that also has
bounds to the warranty and very much requires that the company continue to
maintain the hygiene of their security posture as nothing in security is set it
and forget it.
Any potentially viable security certifications is in jeopardy because of this coupled with the fact there is so many people that misunderstand this concept. Case in point is the Equifax security breach. If you don’t know Equifax, congratulations on making it out from under your rock and listening to this first. Equifax is a large credit reporting bureau that holds credit and personal information for millions of people. The breach, impacted over 140 million people…which to put that in perspective is also HALF the citizens in the US.
Here’s the thing,
Equifax has an ISO27001 certification. The certification was delivered by Ernst
and Young and their EY CertifyPoint division. Some folks, including those at
Equifax, seemed to think this certification shielded them from breach. If you ever listened to any of my podcasts or
read anything I’ve written related to ISO27001, you know that ISO27001 simply
certifies you’ve followed a framework and methodology to choose security
controls—not whether those controls are right and complete security controls
for your environment. To add one more,
scope is a big component of ISO27001 and just because someone has an ISO 27001
certification doesn’t mean it for the environment they say it is. For example, some companies have an ISO27001
certification on their broom closet and say it’s for the whole company.
The issue with this
Equifax situation is that E&Y, according to MarketWatch, issued an attest
opinion that all security controls were complete and in place, which later
could not be supported. Aside from this
not being possible because it fails to acknowledge existance of the crystal
ball that predicts any and all zero day attacks, it’s also a conflict of
interest and violation of any accreditation rules.
To me this indicates
a huge lack of understanding OR purposeful negligence.
Further, commentary
from former SEC Chiefs…I’m withholding names since I don’t know if quotes are
taken out of context BUT one head scratching quote, I’m paraphrasing,
“there’s question concerning how much
reliance should be placed on the ISO certification when assessing internal
controls over financial reporting.”
Uhh…you think? I can
help out there…none. There should be no
reliance. The context of the control is
COMPLETELY different than what you would expect for a SOX 302 or 404 control.
This brings me to
the belief that there continues to be a huge and massive misunderstanding of
security controls at the highest level of organizations and within
organizations that are supposed to be a trusted security advisor.
More often than not
I see accounting firms fulfilling this assessment and assertion role within
business.
BUT who did Equifax
Show Notes: https://justinfimlaid.com/5-security-predictions-for-2019/
Sponsor: https://www.nuharborsecurity.com
Contact Me: https://justinfimlaid.com/contact-me/
Twitter: @justinfimlaid
LinkedIn: https://www.linkedin.com/in/jfimlaid/
Most companies put
together a “top predictions” for FY19. Most are garbage. There's a couple I think are decent but they
are few.
Here's my top 5
predictions for FY19.
People will realize that SOAR (Security Orchestration and Automation Response) is not the security savior. In fact, I'd be so bold to say it hinders the security industry by forcing security professionals to become distracted from doing the core and foundational security work. Security takes work…plain and simple. You have to eat some shit and grind it out. That's the job. There's no easy button for this. While people are spending the year trying to figure out what to automate, they'll only get to December with little to show and year wasted. I often see SOAR being sold as the end all be all to the security talent short-comings…”no staff, no problems…just buy this solution and we'll solve it for you.” BS. In my experience, most companies don't have good security practices, and what happens when you automate broken processes…you break the process more times and faster. Additionally, the fundamental thing that SOAR is missing is that security is often distributed within an organization, meaning…it's not one team rather a bunch of teams/departments doing their part of security. The issue in corporate is that those departments DO NOT allow another group to dictate automatic configuration of technology they are responsible for. Lastly, folks are still trying to figure out security…never mind automate it. Security teams still need to fundamentally understand the tedious parts of security before they can automate anything…and unfortunately, most people don't know what they don't knowNetwork visibility becomes an important thing. Yeah – this one has been around for a while but I think this is the year it picks up momentum. With distributed networks and IOT blowing up, I think folks will finally start to realize that you can't secure what you can't see and will finally own up to needing a solution that provides central visibility to all devices with an internet connection. To date, I think this has been a bit of a luxury to have this level of visibilty but I think must folks have tried to cobble together make-shift or home grown solutions to get this level of visibility, so this year I think we'll see folks start to own it.Blockchain will become commoditized. C'mon let's face it…there is ton of folks trying to tout how smart they are with innovative blockchain solutions. Honestly…there's so many people trying to do this, and if someone can find useful use-cases then I foresee this becoming as commoditized as asymmetric and symmetric encryption for data protection late this year. Other words, if someone can do something worthwhile, it become table stakes and no one will care anymore. Scan-jockeys will be identified. Contrary to what I hear every week – a vulnerability scan is not a Penetration Test. In the industry we call these folks who run a vulnerability scan and pass it off as a penetration test as Scan Jockey. These are folks that don't really know how to pen test, so they choose a vulnerability scanner, run a scan and hope no one knows the difference. Now, don't get me wrong, a vulnerability scan has a VERY valid use in security; in fact I think every organization should be doing vulnerability scans. My issue is people faking to be a penetration tester. I do see folks in industry becoming more educated in the difference between the two types of test, and I think later this calendar year more scan-jockeys will have a harder time in security as penetration testers, and people who actually spend time practicing their craft will get cr…