Risky Business: Recent Episodes

Patrick Gray

Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

  • How Storm-0558 stole Microsoft’s signing key
  • Cisco 0day being used by ransomware crews
  • We were right about Elon stumbling into the Ukraine war
  • Someone’s amazing image library 0day just got crushed
  • Much, much more!

This week’s show is brought to you by Nucleus Security. Co-founder Scott Kuffer is this week’s sponsor guest.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Show notes

  • Results of Major Technical Investigations for Storm-0558 Key Acquisition | MSRC Blog | Microsoft Security Response Center
  • Microsoft reveals how hackers stole its email signing key… kind of | TechCrunch
  • Kevin Beaumont: "One extra thing to highlight -…" - Cyberplace
  • Preventing Authentication Bypass: A Tale of Two Researchers - YouTube
  • BEC phishing kit hits thousands of Microsoft 365 business accounts | Cybersecurity Dive
  • Microsoft Teams phishing attack pushes DarkGate malware
  • CISA warns of attacks using Microsoft Word, Adobe bugs
  • New Emergency Chrome Security Update After Critical iOS 16.6.1 Release
  • Mozilla patches Firefox, Thunderbird against zero-day exploited in attacks
  • Cisco security appliance 0-day is under attack by ransomware crooks | Ars Technica
  • Cisco BroadWorks vulnerability snags highest CVSS score | Cybersecurity Dive
  • High-profile CVEs turn up in vulnerability exploit sales | Cybersecurity Dive
  • MGM Resorts takes systems offline following cyberattack
  • Save the Children International hit with cyberattack, but says operations weren’t impacted
  • Sri Lankan government loses months of data following ransomware attack
  • (6) Risky Biz News: US and UK dox and sanction 11 more Trickbot/Conti members. Charges included too.
  • Opinion | The untold story of Elon Musk’s support for Ukraine - The Washington Post
  • Elon Musk on X:
  • SpaceX unveils Starshield, a military variation of Starlink satellites
  • China-Linked Hackers Breached a Power Grid—Again | WIRED
  • Just waiting for a mate - YouTube
  • North Korea-backed hackers target security researchers with 0-day | Ars Technica
  • Cars are collecting data on par with Big Tech, watchdog report finds
  • Crypto Town Hall on X: "Crypto Kingpin's Downfall: 11,196 Years Behind Bars!"https://t.co/1RCNJ8um4c" / X

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

  • The FBI takes down Qakbot, steals operators’ bitcoins ha ha
  • Danish hosting provider completely destroyed in ransomware attack
  • Sophisticated Russian cyber attack on Polish trains. Well. Not really.
  • Microsoft revokes cert then revokes its revocation
  • Much, much more!

This week’s show is brought to you by Proofpoint. Ryan Kalember, Proofpoint’s EVP of cybersecurity strategy Ryan Kalember is this week’s sponsor guest.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Show notes

  • US says it and partners have taken down notorious 'Qakbot' hacking network | Reuters
  • Danish cloud host says customers ‘lost all data’ after ransomware attack | TechCrunch
  • VDP Platform 2022 Annual Report Showcases Platform’s Success | CISA
  • Proposed bill would require vulnerability disclosure policies for all federal contractors
  • The Cheap Radio Hack That Disrupted Poland's Railway System | WIRED
  • Two suspects arrested following Poland railway hack
  • ‘Incredible concern and anger’ among Metropolitan Police after hackers breach data
  • New malware from North Korea’s Lazarus used against healthcare industry
  • North Korea’s Lazarus hackers behind recent crypto heists: FBI
  • US arrests Tornado Cash co-founder, sanctions another who remains at large
  • Kroll Employee SIM-Swapped for Crypto Investor Data – Krebs on Security
  • (2) Risky Biz News: WinRAR zero-day used to hack stock and crypto traders
  • Microsoft signing keys keep getting hijacked, to the delight of Chinese threat actors | Ars Technica
  • Renegade certificate removed from Windows. Then it returns. Microsoft stays silent. | Ars Technica
  • Barracuda ESG zero-day exploit still under way after patches fail | Cybersecurity Dive
  • Diving Deep into UNC4841 Operations Following Barracuda ESG Zero-Day Remediation (CVE-2023-2868) | Mandiant
  • Unpacking the MOVEit Breach: Statistics and Analysis
  • The DEA Accidentally Sent $50,000 Of Seized Cryptocurrency To A Scammer
  • Akira Ransomware Targeting VPNs without Multi-Factor Authentication - Cisco Blogs
  • Ransomware attack dwell times fall, pressuring companies to quickly respond | Cybersecurity Dive
  • British court convicts two teen Lapsus$ members of hacking tech firms
  • Tourists Give Themselves Away by Looking Up. So Do Most Network Intruders. – Krebs on Security
  • Apple security updates could be banned by British government

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

(NOTE: This podcast was initially pushed out into the Risky Business News podcast feed in error. Sorry about that!)

  • US Government warnings to private space sector on cyber risk
  • Ukrainian hackers dump the inbox of Russian Duma deputy chair
  • Absentee voting in Ecuador’s election disrupted by DDoS attack
  • South Korea warns of Chinese “spy chips”
  • Much, much more!

This week’s show is brought to you by Airlock Digital. Its co-founders Daniel Schell and David Cottingham join this week’s show to talk about Powershell Constrained Language mode.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Show notes

  • Risky Biz News: US warns space sector of hacks, spying, IP theft, and sabotage
  • Safeguarding the US Space Industry - DocumentCloud
  • Ukrainian hackers claim to leak emails of Russian parliament deputy chief
  • Feature Interview: How Sandworm prepared Ukraine for a cyber war - Risky Business
  • British intelligence is tipping off ransomware targets to disrupt attacks
  • Ecuador’s national election agency says cyberattacks caused absentee voting issues
  • Chinese-made 'spy chip' found in Korean state-run weather agency system : r/korea
  • [단독]중국산 기상장비에 ‘스파이칩’ 첫 발견 | 채널A 뉴스
  • Legitimate software tainted in attacks on Hong Kong organizations, report says
  • Chinese hackers accused of targeting Southeast Asian gambling sector
  • Risky Biz News: PowerShell's official package repo is a supply chain mess
  • Zoom’s AI terms overhaul sets stage for broader data use scrutiny | Cybersecurity Dive
  • Fifty minutes to hack ChatGPT: Inside the DEF CON competition to break AI | CyberScoop
  • Ivanti: Customers ‘impacted’ by new zero-day vulnerability
  • CISA, experts warn of Citrix vulnerabilities being exploited by hackers
  • Zero Networks Connect - Zero Networks | Contain The Next Breach
  • Australia’s .au domain administrator denies data breach after ransomware posting
  • Hackers are increasingly hiding within services such as Slack and Trello to deploy malware | CyberScoop
  • ‘Extreme’ user abuse leads AnonFiles operators to shut down hosting service
  • Millions stolen from crypto platforms Exactly Protocol and Harbor Protocol
  • Windows feature that resets system clocks based on random data is wreaking havoc | Ars Technica
  • Did a Journalist Violate Hacking Law to Leak Fox News Clips? The Government Thinks He Did.

View Details

In this joint Risky Business and Geopolitics Decanted feature interview, Patrick Gray and Dmitri Alperovitch talk to Illia Vitiuk, the Head of the Department of Cyber and Information Security of the Security Service of Ukraine (SBU) about the cyber dimension to Russia’s invasion.

From turning off Ukraine’s power grid with a cyber attack in 2015 to the Viasat hack in 2022, Russia’s intelligence services are world renowned for executing creative destructive cyber campaigns. Despite this, after a year and a half of Russia waging war on Ukraine its power grid is up, its telcos are functioning and its banks are still processing transactions.

How has Ukraine been able to withstand Russia’s onslaught in the cyber domain? Vitiuk joins us to reveal insights into how Russian intelligence services are operating in Ukraine, and how the SBU is countering them.

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

  • More victims identified in Chinese breach of Microsoft email accounts
  • Cyber Safety Review Board to investigate Microsoft
  • We got some stuff wrong last week
  • More details on Viasat hack revealed
  • Special guest Heather Adkins talks about the CSRB’s Lapsus$ report
  • Much, much more

This week’s show is brought to you by RunZero. Its co-founder HD Moore is this week’s sponsor guest.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Show notes

  • Chinese Microsoft hackers also hit GOP Rep. Don Bacon of Nebraska - The Washington Post
  • US cyber board to investigate Microsoft hack of government emails | TechCrunch
  • Richard: "@briankrebs @metlstorm @riskyb…" - Mastodon.Radio
  • Mastodon.Radio
  • An SSRF, privileged AWS keys and the Capital One breach | by Riyaz Walikar | Appsecco
  • Chamber of Commerce urges SEC to delay cyber rule implementation | Cybersecurity Dive
  • Satellite hack on eve of Ukraine war was a coordinated, multi-pronged assault | CyberScoop
  • Microsoft to freeze license extensions for Russian companies
  • Takedown of Lolek bulletproof hosting service includes arrests, NetWalker indictment
  • Ransomware Diaries V. 3: LockBit's Secrets
  • How the FBI goes after DDoS cyberattackers | TechCrunch
  • Meet the Brains Behind the Malware-Friendly AI Chat Service ‘WormGPT’ – Krebs on Security
  • Multiple zero days found affecting crypto platforms
  • Lawmakers press FCC for action on Chinese-made cellular modules
  • Panasonic Warns That IoT Malware Attack Cycles Are Accelerating | WIRED
  • Rapid7 to cut 18% of workforce, shutter certain offices | Cybersecurity Dive
  • SecureWorks layoffs affect 15% staff | TechCrunch
  • Researcher says they were behind iPhone popups at Def Con | TechCrunch
  • Review of the Attacks Associated with LAPSUS$ and Related Threat Groups
  • US should crack down on SIM swapping following Lapsus$ attacks: DHS review
  • Kevin Collier: "Def Con is over and nobody hac…" - Infosec Exchange

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

  • Tenable gives Microsoft a spray over Azure bug fix delay, quality
  • Lateral movement fun via Azure Active Directory Cross-Tenant Synchronization
  • Ransomware targets hospitals, special needs schools
  • Japan’s cybersecurity has some catching up to do
  • Much, much more

This week’s show is brought to you by Corelight. Brian Dye, Corelight’s CEO, is this week’s sponsor guest.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Show notes

  • Tenable CEO accuses Microsoft of negligence in addressing security flaw | CyberScoop
  • Microsoft resolves vulnerability following criticism from Tenable CEO
  • New Microsoft Azure AD CTS feature can be abused for lateral movement
  • Hackers force hospital system to take its national computer system offline
  • Israeli hospital redirects new patients following ransomware attack
  • Russia-linked cybercriminals target school for children with learning difficulties
  • Hackers accessed 16 years of Colorado public school student data in June ransomware attack
  • Marine industry giant Brunswick Corporation lost $85 million in cyberattack, CEO confirms
  • China hacked Japan’s classified defense cyber networks, officials say - The Washington Post
  • Comrades in Arms? | North Korea Compromises Sanctioned Russian Missile Engineering Company - SentinelOne
  • Ukraine says it thwarted attempt to breach military tablets
  • The Mystery of Chernobyl’s Post-Invasion Radiation Spikes | WIRED
  • Radiation Spikes at Chernobyl: A Mystery Few Seem Interested in Solving
  • U.K. election regulator says hackers had access for over a year but elections still secure
  • Exclusive: DHS Used Clearview AI Facial Recognition In Thousands Of Child Exploitation Cold Cases
  • Eight Months Pregnant and Arrested After False Facial Recognition Match - The New York Times
  • New ‘Downfall’ Flaw Exposes Valuable Data in Generations of Intel Chips | WIRED
  • New Inception attack leaks sensitive data from all AMD Zen CPUs
  • Spyware maker LetMeSpy shuts down after hacker deletes server data | TechCrunch
  • ‘Crypto couple’ pleads guilty to money laundering, as husband admits to carrying out Bitfinex hack
  • Google Online Security Blog: Android 14 introduces first-of-its-kind cellular connectivity security features
  • Risky Biz News: Russian bill will hide the PII data of military, police, and intelligence agents

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

  • Ron Wyden’s “please explain” letter to Microsoft
  • Chinese APT crews prepositioning to disrupt US military logistics
  • China claims US hacked its seismology sensors
  • Ivanti/MobileIron exploitation going vertical
  • Much, much more

This week’s show is brought to you by Stairwell. Mike Wiacek, Stairwell’s founder and CEO, is this week’s sponsor guest. He’s joined by Eric Foster, Stairwell’s VP of Business Development.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Show notes

  • Wyden letter to CISA, DOJ, FTC re 2023 Microsoft breach
  • Senator calls on DOJ to investigate alleged China hack of Microsoft cloud tools
  • U.S. Hunts Chinese Malware That Could Disrupt American Military Operations - The New York Times
  • Multiple Chinese APTs establish major beachheads inside sensitive infrastructure | Ars Technica
  • John Hultquist🌻 on Twitter: "We found this actor in land, air, and sea transportation targets which could be leveraged for a serious disruption to logistics." / X
  • China accuses U.S. of hacking earthquake monitoring equipment
  • Exclusive: Pentagon Investigates ‘Critical Compromise’ Of Air Force Communications Systems
  • CISA: Ivanti hacks targeting Norway began in April
  • US, Australia cyber agencies warn IDOR security flaws can be exploited ‘at scale’ | TechCrunch
  • Ivanti warns of second vulnerability used in attacks on Norway gov’t
  • Andrew Morris on Twitter: "Exploitation of Ivanti EPMM (MobileIron Core) CVE-2023-35078 is currently popping off https://t.co/tkRoWqvtv1 https://t.co/XOaWEZ3U3X" / X
  • Trail of Bits | Products
  • US contractor says info of up to 10 million leaked in MOVEit breach
  • British ambulances unable to access patient records system following cyberattack
  • Valid account credentials are behind most cyber intrusions, CISA finds | Cybersecurity Dive
  • An Unexpected Endorsement for WebAuthn | Okta Security
  • SEC votes to overhaul disclosure rules for material cyber events | Cybersecurity Dive
  • White House unveils ‘whole of society’ push to expand cybersecurity workforce
  • Section 702 surveillance powers are necessary, but FBI access needs limits, panel says
  • The NSA Is Lobbying Congress to Save a Phone Surveillance 'Loophole' | WIRED
  • Kazakhstan refuses to extradite detained Russian cyber expert to US
  • Russia Sends Cybersecurity CEO to Jail for 14 Years – Krebs on Security
  • Millions stolen from crypto platforms through exploited ‘Vyper’ vulnerability
  • A New Attack Impacts ChatGPT—and No One Knows How to Stop It | WIRED
  • Cloud company assisted 17 different government hacking groups, U.S. researchers say | Reuters
  • No evidence ransomware victims with cyber insurance pay up more often, UK report says
  • ‘Worm-like’ botnet malware targeting popular Redis storage tool
  • Hackers are infecting Call of Duty players with a self-spreading malware | TechCrunch
  • Bug in Minecraft mods allows hackers to exploit players' devices

View Details

In this interview Patrick Gray speaks to Australia’s Home Affairs and Cyber Security Minister Clare O’Neil and NCSC founding director Ciaran Martin about the government’s upcoming cybersecurity strategy, releasing the hounds and more.

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

  • The dust-up between Microsoft and Wiz
  • MobileIron/Ivanti 0day hoses Norwegian government agencies
  • That’ll do TETRA, that’ll do…
  • Microsoft finally agrees to offer decent logging without price gouging
  • Much, much more

This week’s show is brought to you by Resoucely. Travis McPeak, Resourcely’s co-founder and CEO, is this week’s sponsor guest.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

View Details

This Soap Box edition of the podcast is sponsored by Proofpoint.

Proofpoint offers email security and DLP products and services, and they’re probably best known for being the biggest email security company on the planet.

That means they process a LOT of emails in the hopes of throttling the number of malicious emails that organisations have to deal with, whether that’s malware, phishing or BEC.

So, with that in mind, what role could large language models play in email security?

Now that the initial ChatGPT hype has died off a little, we spoke with Proofpoint’s VP of cybersecurity strategy Ryan Kalember about large language models and how they’re going to help defenders and attackers alike.

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

  • Microsoft’s weasel-word response to the State Department email hack
  • JumpCloud got owned, maybe by DPRK
  • Citrix 0day is getting stuff rekt
  • Two more spyware firms sanctioned by USA
  • Scammers list fake phone numbers for major airlines on Google Maps
  • Much, much more

This week’s show is brought to you by security focussed enterprise browser maker Island. Dan Amiga, Island’s CTO and co-founder, is this week’s sponsor guest. He talks about why widespread enterprise browser deployment is inevitable.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Show notes

  • China-based hackers breach email accounts at State Department
  • Microsoft hardens key issuance systems after state-backed hackers breach Outlook accounts | Cybersecurity Dive
  • Microsoft takes pains to obscure role in 0-days that caused email breach | Ars Technica
  • Stealth Mode: Chinese Cyber Espionage Actors Continue to Evolve Tactics to Avoid Detection | Mandiant
  • Hackers target Pakistani government, bank and telecom provider with China-made malware
  • Risky Biz News: JumpCloud compromised by APT group
  • Exploited 0-days, an incomplete fix, and a botched disclosure: Infosec snafu reigns | Ars Technica
  • CISA warns of dangerous Rockwell industrial bug being exploited by gov’t group
  • Rockwell Automation, Honeywell warned of critical vulnerabilities in industrial products | Cybersecurity Dive
  • CISA gives US civilian agencies until August 1 to resolve four Microsoft vulnerabilities
  • Google fixes ‘Bad.Build’ vulnerability affecting Cloud Build service
  • White House unveils consumer labeling program to strengthen IoT security | Cybersecurity Dive
  • Senate bill crafted with DEA targets end-to-end encryption, requires online companies to report drug activity
  • Two more foreign spyware firms blacklisted by US
  • Phone numbers for airlines listed on Google directed to scammers
  • By criminals, for criminals: AI tool easily generates ‘remarkably persuasive’ fraud emails
  • Itamar Golan 🤓 on Twitter: "A malicious LLM-based tool known as WormGPT 🪱 is rapidly gaining traction in underground forums. This tool empowers attackers to automate sophisticated phishing and BEC (Business Email Compromise) attacks, leveraging personalized fake emails to significantly enhance success… https://t.co/fAcrYhT696" / Twitter
  • FCC chair proposes $200M investment to boost K-12 cybersecurity | Cybersecurity Dive
  • Fed ends Capital One breach-related enforcement action | Cybersecurity Dive
  • Norwegian Refugee Council hit by cyberattack
  • Belarus-linked hacks on Ukraine, Poland began at least a year ago, report says
  • Albania’s PM complains US is not providing country with cyberdefense funds
  • VirusTotal: Datenleck offenbart Kunden der Google-Sicherheitsplattform - DER SPIEGEL
  • Genesis Market sold to anonymous buyer despite FBI disruption

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

  • The SEC is targeting SolarWinds executives
  • UK to make banks liable for fraud
  • NSA issues advice on UEFI trojan
  • Microsoft blocks 100+ dodgy drivers
  • The US IC knew what Prihozhin was up to. But what FSB doing?
  • Much, much more

This week’s show is brought to you by Netwrix. Martin Cannard, Netwrix’s VP of Product Strategy, is this week’s sponsor guest. He talks about why zero standing privilege is a worthy goal.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Show notes

  • SEC notifies SolarWinds CISO and CFO of possible action in cyber investigation | Cybersecurity Dive
  • While Australian banks refuse most scam victims refunds, the UK is making them mandatory - ABC News
  • New law could allow GCHQ to monitor UK internet logs in real-time to tackle fraud
  • Federal incentives could help utilities overcome major cybersecurity hurdle: money | CyberScoop
  • Major Japanese port suspends operation following ransomware attack
  • Petro-Canada reports service restoration after suspected Suncor breach | Cybersecurity Dive
  • Chinese state-backed hackers accidentally infected a European hospital with malware
  • Hackers exploit gaping Windows loophole to give their malware kernel access | Ars Technica
  • 336,000 servers remain unpatched against critical Fortigate vulnerability | Ars Technica
  • CISA says latest VMware analytics bug being exploited
  • MOVEit vulnerability snags almost 200 victims, more expected | Cybersecurity Dive
  • Actively exploited vulnerability threatens hundreds of solar power stations | Ars Technica
  • U.S. intelligence learned in mid-June Prigozhin was plotting uprising - The Washington Post
  • Russian election-meddling ‘troll factory’ reportedly shut down after Wagner revolt
  • Russian telecom confirms hack after group backing Wagner boasted about an attack | CyberScoop
  • Hackers claim to take down Russian satellite communications provider
  • Russian railway site allegedly taken down by Ukrainian hackers
  • Several US states investigating ‘SiegedSec’ hacking campaign
  • Hacking crew targeting states over transition bans claims cyberattack hitting global satellite systems | CyberScoop
  • Hacktivists steal government files from Texas city Fort Worth | TechCrunch
  • Belarusian hacktivists сlaim to breach country’s leading state university
  • British prosecutors say teen Lapsus$ member was behind hacks on Uber, Rockstar
  • Silk Road’s Second-in-Command, Variety Jones, Gets 20 Years in Prison | WIRED
  • Russian cyber expert arrested in Kazakhstan, triggering a showdown between US and Moscow
  • More than 6,500 arrested since French and Dutch police’s EncroChat hack
  • BreachForums seized by FBI three months after arrest of alleged admin
  • BreachForums replacement emerges as robust forum for criminal hackers to trade their spoils | CyberScoop
  • Genesis Market gang tries to sell platform after FBI disruption
  • Hackers using TrueBot malware for phishing attacks in US, Canada, officials warn | Cybersecurity Dive
  • CSI_BlackLotus_Mitigation_Guide.PDF
  • Hacks targeting British exam boards raise fears of students cheating
  • More than $125 million taken from crypto platform Multichain
  • Twitter’s chaotic weekend of outages and rate limits leaves more questions than answers
  • Mastodon fixes critical “TootRoot” vulnerability allowing node hijacking | Ars Technica

View Details

In this edition of the Soap Box podcast we’re going to be talking about a great topic – living off the land.

The recent Volt Typhoon report out of Microsoft chronicled the adventures of a Chinese APT crew in US critical infrastructure. But one of the most fascinating aspects of the Volt Typhoon campaign was that the attackers almost exclusively used so-called living off the land techniques.

So the question becomes – what can you do about an attacker in your environment who has privilege and isn’t using malware?

Guests David Cottingham and Daniel Schell, the CEO and CTO of Airlock Digital, join the show to talk it through.

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

  • Albanian authorities raid MEK over Iran hacks
  • Microsoft admits “Anonymous Sudan” took down its services
  • US Government puts $10m bounty on CL0P
  • A deeper look at the Barracuda hack campaign
  • Much, much more

This week’s show is brought to you by Nucleus Security. We’ll be hearing from one of Material’s friends – Courtney Healey, senior manager of insider threat at Coinbase – in this week’s sponsor interview.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Show notes

  • Police raid Iranian opposition camp in Albania, seize computers | AP News
  • Risky Biz News: Microsoft embarrassingly admits it got DDoSed into the ground by Anonymous Sudan
  • Anonymous Sudan and Killnet strike again, target EIB
  • Pro-Russian hackers remain active amid Ukraine counteroffensive | CyberScoop
  • Hackers infect Russian-speaking gamers with fake WannaCry ransomware
  • US puts $10M bounty on Clop as federal agencies confirm data compromises | Cybersecurity Dive
  • (1) Catherine Herridge on Twitter: "Tonight, sources tell @cbsnews senior government officials are racing to limit impact - of what one cyber expert calls - potentially the largest theft + extortion event in recent history. USG official says no evidence to date US MIL or INTEL compromised. https://t.co/R4f6naFqFx" / Twitter
  • U.S. government says several agencies hacked as part of broader cyberattack
  • Clop names a dozen MOVEit victims, but holds back details | Cybersecurity Dive
  • Another MOVEit vulnerability found, as state and federal agencies reveal breaches | Cybersecurity Dive
  • Barracuda ESG Zero-Day Vulnerability (CVE-2023-2868) Exploited Globally by Aggressive and Skilled Actor, Suspected Links to China | Mandiant
  • New DOJ unit will focus on prosecuting nation-state cybercrime
  • EU states told to restrict Huawei and ZTE from 5G networks ‘without delay’
  • The US Navy, NATO, and NASA Are Using a Shady Chinese Company’s Encryption Chips | WIRED
  • Widow of slain Saudi journalist Jamal Khashoggi files suit against Pegasus spyware maker
  • Jamal Khashoggi’s wife to sue NSO Group over Pegasus spyware | Jamal Khashoggi | The Guardian
  • Bipartisan bill would protect Americans’ data from export abroad
  • District of Nebraska | Massachusetts Man Sentenced for Computer Intrusion | United States Department of Justice
  • I Was Sentenced to 18 Months in Prison for Hacking Back - My Story | HackerNoon
  • CID-FLYER-TEMPLATE
  • New FCC privacy task force takes aim at data breaches, SIM-swaps | CyberScoop
  • Bloodied Macbooks and Stacks of Cash: Inside the Increasingly Violent Discord Servers Where Kids Flaunt Their Crimes
  • Russian National Arrested and Charged with Conspiring to Commit LockBit Ransomware Attacks Against U.S. and Foreign Businesses | OPA | Department of Justice
  • BrianKrebs: "Haha love it when a data ranso…" - Infosec Exchange

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

  • Fortinet 0day Groundhog Day
  • CISA’s new binding directive on exposed management interfaces
  • Confirmed: US intelligence buying commercially available data
  • MOVEit drama rolls on
  • Much, much more

This week’s show is brought to you by Red Canary. Chris Rothe is this week’s sponsor guest and he joins us to talk about how MDR providers are helping customers deal with cloud monitoring.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Show notes

  • Fortinet Warns Customers of Possible Zero-Day Exploited in Limited Attacks - SecurityWeek
  • Barracuda Urges Replacing — Not Patching — Its Email Security Gateways – Krebs on Security
  • MOVEit announces second vulnerability; Minnesota schools agency breached with original bug
  • Confidential data downloaded from UK regulator Ofcom in cyberattack
  • Ransomware group Clop issues extortion notice to ‘hundreds’ of victims
  • Another huge US medical data breach confirmed after Fortra mass-hack | TechCrunch
  • CISA orders US civilian agencies to remove tools from public-facing internet
  • Microsoft says Azure disrupted after a week of repeated service outages | Cybersecurity Dive
  • Microsoft says Azure outage was caused by ‘anomalous’ traffic spike
  • Microsoft investigating threat actor claims following multiple outages in 365, OneDrive | Cybersecurity Dive
  • Risky Biz News: Ukrainian hackers wipe equipment of major Russian telco
  • U.S. Spy Agencies Buy Vast Quantities of Americans’ Personal Data, U.S. Says - WSJ
  • The US Is Openly Stockpiling Dirt on All Its Citizens | WIRED
  • Srsly Risky Biz: Thursday, July 29 - by Tom Uren
  • National security officials make case for keeping surveillance powers to skeptical Congress - The Washington Post
  • Senators say Biden administration isn’t close on overhauling surveillance law
  • Russian nationals accused of Mt. Gox bitcoin heist, shifting stolen funds to BTC-e
  • North Korean hacking group Lazarus linked to $35 million cryptocurrency heist
  • North Korean hackers stole $100 million in recent cryptocurrency heist -analysts | Reuters
  • An Illinois hospital links closure to ransomware attack
  • Security professional's tweet forces big change to Google email authentication | CyberScoop
  • Can you trust ChatGPT’s package recommendations?
  • LastPass CEO reflects on lessons learned, regrets and moving forward from a cyberattack | Cybersecurity Dive

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:

  • Russia’s FSB uncovers “NSA malware” on iPhones
  • Cl0p mass harvests data from MOVEit file transfer servers
  • ASD discloses a bunch of operations against ISIS, criminals
  • Why China’s prepositioning is probably… prepositioning
  • Much, much more

This week’s show is brought to you by Thinkst Canary. Marco Slaviero is this week’s sponsor guest and he joins us to talk about indirect LLM prompt injection and the latest Canary release.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Show notes

  • Russia says US hacked thousands of Apple phones in spy plot | Reuters
  • Risky Biz News: Russia's FSB says NSA hacked iPhones in cyber-espionage campaign
  • Russia wants 2 million phones with home-grown Aurora OS for use by officials
  • Доверенная мобильная среда. Мобильная операционная система «Аврора» — Ростелеком
  • Why China's Latest APT Campaign is Legitimately Worrying
  • War crimes committed through cyberspace must not escape international justice, says Estonian president
  • Hacks Against Ukraine's Emergency Response Services Rise During Bombings | WIRED
  • How Australian cyber spies used 'Rickrolling' to disrupt Islamic State militants in Iraq - ABC News
  • Australian intelligence's secret hand in bringing down the Bali bombers - ABC News
  • Microsoft Threat Intelligence on Twitter: "Microsoft is attributing attacks exploiting the CVE-2023-34362 MOVEit Transfer 0-day vulnerability to Lace Tempest, known for ransomware operations & running the Clop extortion site. The threat actor has used similar vulnerabilities in the past to steal data & extort victims. https://t.co/q73WtGru7j" / Twitter
  • What we know about the MOVEit vulnerability and compromises | Cybersecurity Dive
  • metlstorm: "Great, so now I have to roll i…" - Infosec Exchange
  • Dave Aitel: "@riskybusiness @chort honestly…" - Infosec Exchange
  • Critical Barracuda 0-day was used to backdoor networks for 8 months | Ars Technica
  • Millions of Gigabyte Motherboards Were Sold With a Firmware Backdoor | WIRED
  • Ask Fitis, the Bear: Real Crooks Sign Their Malware – Krebs on Security
  • Wayback Machine
  • Discord Admins Hacked by Malicious Bookmarks – Krebs on Security
  • Google’s Android and Chrome extensions are a very sad place. Here’s why | Ars Technica
  • How university cybersecurity clinics can help cities fight ransomware | CyberScoop
  • Atomic - Crypto Wallet on Twitter: "We have received reports of wallets being compromised. We are doing all we can to investigate and analyse the situation. As we have more information, we will share it accordingly. For any questions and concerns, contact support@atomicwallet.io" / Twitter
  • BrianKrebs: "Russian news outlet Kommersant…" - Infosec Exchange
  • Thinkst

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • UK, USA ban Chinese security cameras
  • What is the Boa webserver and why is it everywhere?
  • Vanuatu, Guadeloupe smashed by ransomware
  • REvil back with more dumps despite ASD attention
  • Much, much more

This week’s sponsor guest is Jake King from Elastic Security, who joins us to talk through the company’s most recent threat report. There’s a link to the report in our show notes.

Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.

Show notes

  • British government bans Chinese surveillance cameras from sensitive locations - The Record by Recorded Future
  • US government bans Huawei, ZTE and Hikvision tech over ‘unacceptable’ spying fears | TechCrunch
  • What if Russian commercial aviation cuts too many safety corners? — Meduza
  • Microsoft attributes alleged Chinese attack on Indian power grid to ‘Boa’ IoT vulnerability - The Record by Recorded Future
  • U.S. Govt. Apps Bundled Russian Code With Ties to Mobile Malware Developer – Krebs on Security
  • Guadeloupe kickstarts continuity plan after wide-ranging cyberattack - The Record by Recorded Future
  • Vanuatu hospital staff using pen and paper after cyber attack that crippled public sector - ABC News
  • Extortion site used in Medibank attack goes offline after Australian gov pledges ‘offensive’ actions - The Record by Recorded Future
  • ThreatMon Ransomware Monitoring on Twitter:
  • Risky Biz News: Australia passes new privacy bill with huge data breach fines
  • Sandworm hacking group linked to new ransomware deployed in Ukraine - The Record by Recorded Future
  • UK Parliament launches inquiry into national security strategy around ransomware - The Record by Recorded Future
  • Canadian food giant refuses to pay ransom after gang threatens data leak - The Record by Recorded Future
  • Almost 1,000 suspects arrested in Interpol operation which seized over $129 million - The Record by Recorded Future
  • Risky Biz News: Authorities seize iSpoof in major blow to fraudsters and cybercrime groups
  • Espionage group using USB devices to hack targets in Southeast Asia - The Record by Recorded Future
  • WikiLeaks' Website Is Slowly Falling Apart
  • European Parliament declares Russia a terrorism sponsor, then its site goes down | Ars Technica
  • Hackers are spreading malware via trending TikTok challenge: report - The Record by Recorded Future
  • Samantha Borrego iS iNfeCtEd noT pArAnOID on Twitter:
  • elastic-global-threat-report-vol-1-2022.pdf

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Half of all UK COBRA meetings are ransomware related
  • Ransomware biggest risk to US port security
  • White House to move on spyware industry
  • EU to launch its own Starlink equivalent
  • Much, much more

AttackIQ’s Jonathan Reiber will be joining us in this week’s sponsor interview to talk about how companies and their boards are really moving towards outcomes-based security programs.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • Ransomware incidents now make up majority of British government’s crisis management COBRA meetings - The Record by Recorded Future
  • DHS Secretary: Cyberattacks are the most significant threat to port infrastructure - The Record by Recorded Future
  • Michigan school districts reopen after three-day closure due to ransomware attack - The Record by Recorded Future
  • Microsoft: Royal ransomware group using Google Ads in campaign - The Record by Recorded Future
  • Researchers Quietly Cracked Zeppelin Ransomware Keys – Krebs on Security
  • Risky Biz News: Cyber Partisans hack and disrupt Kremlin censor
  • US, Estonian authorities arrest two over $575 million cryptocurrency fraud - The Record by Recorded Future
  • New FTX CEO details 'complete failure of corporate controls' at crypto platform
  • OpenSSL Usage in UEFI Firmware Exposes Weakness in SBOMs
  • EU reaches agreement on new satellite constellation - The Record by Recorded Future
  • Ukraine’s Engineers Dodged Russian Mines To Get Kherson Back Online–With A Little Help From Elon Musk’s Satellites
  • Senate Democrats call on FTC to investigate Twitter's data security
  • 11.17.22 - FTC - Twitter Letter
  • Twitter has a lot of your data. Here's what you can do about it.
  • Mastodon vulnerable to multiple system configuration problems | The Daily Swig
  • System misconfiguration is the number one vulnerability, at least for Mastodon
  • White House expected to issue executive order reining in spyware
  • H20220930-005_Himes-Speier cc's - DocumentCloud
  • A Leak Details Apple's Secret Dirt on Corellium, a Trusted Security Startup | WIRED
  • Risky Biz News: Iranian state hackers breached US government agency and deployed a cryptominer, out of all things
  • India removes ban on VLC media player after cybersecurity concerns addressed - The Record by Recorded Future
  • Amazon addresses vulnerability affecting AWS AppSync - The Record by Recorded Future
  • CVE-2022-41924 - RCE in Tailscale, DNS Rebinding, and You
  • Iranian Islamic Revolutionary Guard Corps-Affiliated Cyber Actors Exploiting Vulnerabilities for Data Extortion and Disk Encryption for Ransom Operations | CISA
  • Impacket and Exfiltration Tool Used to Steal Sensitive Information from Defense Industrial Base Organization | CISA

View Details

In this podcast we speak with Randall Degges who leads the Developer Relations & Community team at Snyk. He’s here to talk to us about how to get developers enthusiastic about security, how to get them to use the right tooling, and how this tooling will evolve in the future to actually help developers fix bugs in their code.

Show notes

  • The Big Fix | Snyk

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Australia lets ASD loose on ransomware crews, but will it work? (Tom Uren joins us to chat about this one)
  • Twitter’s wheels haven’t fallen off yet but they sure are wobbling
  • Hundreds of millions stolen from FTX mid implosion
  • Security researchers start looking at Mastodon and… yeah
  • Much, much more!

This week’s show is brought to you by Gigamon. George Sandford from Gigamon pops in for this week’s sponsor interview to talk about how to successfully stand up an NDR program.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • Risky Biz News: Australia to hack the hackers
  • Australia to consider banning ransomware payments - The Record by Recorded Future
  • Two enormous cyberattacks convince Australia to 'hack the hackers' - The Washington Post
  • Australian Federal Police say cybercriminals in Russia behind Medibank hack - The Record by Recorded Future
  • The Hunt for the FTX Thieves Has Begun | WIRED
  • US reissues sanctions on Tornado Cash, tying it to North Korea's nuclear weapons program - The Record by Recorded Future
  • Twitter’s SMS Two-Factor Authentication Is Melting Down | WIRED
  • Is it safe to use Twitter? Security fears rise after Elon Musk drives off staff
  • Twitter’s Security And Privacy Leaders Quit Amidst Musk’s Chaotic Takeover
  • FTC tracking developments at Twitter with 'deep concern' after CISO resigns - The Record by Recorded Future
  • Mastodon users vulnerable to password-stealing attacks | The Daily Swig
  • Risky Biz News: Major hack-and-leak info-op unfolding in Moldova
  • All Day DevOps: Third of Log4j downloads still pull vulnerable version despite threat of supply chain attacks | The Daily Swig
  • Billbug: State-sponsored Actor Targets Cert Authority, Government Agencies in Multiple Asian Countries | Symantec Enterprise Blogs
  • Lenovo driver goof poses security risk for users of 25 notebook models | Ars Technica
  • Cisco: InterPlanetary File System seeing ‘widespread’ abuse by hackers - The Record by Recorded Future
  • Project Zero: A Very Powerful Clipboard: Analysis of a Samsung in-the-wild exploit chain
  • Google Pixel screen-lock hack earns researcher $70k | The Daily Swig
  • DJ Zavala & DMNTED - Welcome to Ukraine - YouTube

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • DoJ seizes 50k bitcoin stolen from Silk Road, charges thief
  • Australian health insurer Medibank refuses to pay ransom, data leaked
  • Inside Qatar’s $386m world cup espionage operation
  • EU Parliament report into spyware lands
  • SolarWinds settles shareholder lawsuit, faces SEC enforcement action
  • Much, much more

This week’s sponsor guest is Andrew Morris from Greynoise Intelligence.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • DOJ says it seized billions in Bitcoin stolen by hacker from Silk Road darknet marketplace - The Record by Recorded Future
  • U.S. Attorney Announces Historic $3.36 Billion Cryptocurrency Seizure And Conviction In Connection With Silk Road Dark Web Fraud | USAO-SDNY | Department of Justice
  • Medibank says it will not pay ransom in hack that impacted 9.7 million customers - The Record by Recorded Future
  • Names, addresses, birthdays posted to dark web by hackers after Medibank ransom deadline passes - ABC News
  • ‘Project Merciless’: how Qatar spied on the world of football in Switzerland - SWI swissinfo.ch
  • How Qatar hacked the World Cup — The Bureau of Investigative Journalism (en-GB)
  • FBI probing ex-CIA officer's spying for World Cup host Qatar - The Washington Post
  • EU governments accused of using spyware ‘to cover up corruption and criminal activity’ - The Record by Recorded Future
  • Press conference on draft findings of EP spyware inquiry | News | European Parliament
  • SolarWinds says it’s facing SEC ‘enforcement action’ over 2020 hack | TechCrunch
  • Microsoft accuses China of abusing vulnerability disclosure requirements - The Record by Recorded Future
  • 工业和信息化部国家互联网信息办公室公安部关于印发网络产品安全漏洞管理规定的通知-中共中央网络安全和信息化委员会办公室
  • Insurance giant settles NotPetya lawsuit, signaling cyber insurance shakeup
  • Could a ‘digital Red Cross emblem’ protect hospitals from cyber warfare? - The Record by Recorded Future
  • TrustCor Systems verifies web addresses, but its address is a UPS Store - The Washington Post
  • Cyber incident at Boeing subsidiary causes flight planning disruptions - The Record by Recorded Future
  • FIN7 cybercrime cartel tied to Black Basta ransomware operation: report - The Record by Recorded Future
  • More than 100 election jurisdictions waiting on federal cyber help, sources say
  • $28 million stolen from cryptocurrency platform Deribit - The Record by Recorded Future
  • Nigerian scammer sentenced to 11 years in US prison - The Record by Recorded Future
  • Hackers get into Dropbox developer accounts on GitHub, access 130 code repositories and more - The Record by Recorded Future
  • Urlscan.io API unwittingly leaks sensitive URLs, data | The Daily Swig
  • The Most Vulnerable Place on the Internet | WIRED
  • So long and thanks for all the bits - NCSC.GOV.UK

View Details

On this week’s show Patrick Gray, Adam Boileau and Dmitri Alperovitch discuss the week’s security news, including:

  • Twitter bluechecks face phishing barrage
  • Australian government goes berserk on Medibank hack response
  • Former WSJ journalist sues law firm over email hack and info op that got him fired
  • OpenSSL bug lands with a whimper
  • Apple macOS Ventura update breaks security tools
  • Much, much more

This week’s show is brought to you by Thinkst Canary. Marco Slaviero, Thinkst’s head of engineering, joins us this week to talk through the company’s latest release, codenamed Quokka.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • Twitter’s verification chaos is now a cybersecurity problem | TechCrunch
  • Unconfirmed hack of Liz Truss’ phone prompts calls for “urgent investigation” | Ars Technica
  • Chinese hackers are scanning state political party headquarters, FBI says - The Washington Post
  • Former WSJ reporter says law firm used Indian hackers to sabotage his career | Reuters
  • The source - Columbia Journalism Review
  • Upcoming ‘critical’ OpenSSL update prompts feverish speculation | The Daily Swig
  • OpenSSL vulnerability downgraded to ‘high’ severity | The Daily Swig
  • Medibank says hackers had access to ‘all personal data’ belonging to all customers - The Record by Recorded Future
  • Australia to tighten privacy laws, increase fines after series of data breaches - The Record by Recorded Future
  • Votes in Slovakia's parliament suspended after alleged ‘cybersecurity incident’ - The Record by Recorded Future
  • NY Post confirms hack after website, Twitter feed flooded with threats toward Biden, AOC - The Record by Recorded Future
  • Apple MacOS Ventura Bug Breaks Third-Party Security Tools | WIRED
  • Microsoft ties Vice Society hackers to additional ransomware strains - The Record by Recorded Future
  • How Vice Society Got Away With a Global Ransomware Spree | WIRED
  • FTC seeks action against Drizly — and its CEO — for cybersecurity failures - The Record by Recorded Future
  • Critical authentication bug in Fortinet products actively exploited in the wild | The Daily Swig
  • Google Play apps with >20M downloads depleted batteries and network bandwidth | Ars Technica
  • Battle with Bots Prompts Mass Purge of Amazon, Apple Employee Accounts on LinkedIn – Krebs on Security
  • Microsoft leaked 2.4TB of data belonging to sensitive customer. Critics are furious | Ars Technica
  • Microsoft disputes report on Office 365 Message encryption issue after awarding bug bounty - The Record by Recorded Future
  • Microsoft Office Online Server open to SSRF-to-RCE exploit | The Daily Swig
  • Microsoft's Sociopathic Cybersecurity Pedantry
  • Brazilian police announce arrest of alleged Lapsus$ member - The Record by Recorded Future
  • Accused ‘Raccoon’ Malware Developer Fled Ukraine After Russian Invasion – Krebs on Security
  • European gang that sold car hacking tools to thieves arrested - The Record by Recorded Future
  • How a Microsoft blunder opened millions of PCs to potent malware attacks | Ars Technica

View Details

Snake Oilers isn’t our regular weekly podcast, it’s a wholly sponsored series we do at Risky.Biz where vendors come on to the show to pitch their products to you, the Risky Business listener. To be clear – everyone you hear in one of these editions, paid to be here.

We’ll hear from three vendors in this edition of Snake Oilers:

  • Truffle Security talks secrets discovery
  • KSOC builds Kubernetes security tools
  • Snyk has a new product to better secure Infrastructure as Code

Show notes

  • Unearth Your Secrets - Truffle Security
  • KSOC: Kubernetes Security Operations Center
  • Cloud Security across the SDLC with Policy as Code | Snyk

View Details

Snake Oilers isn’t our regular weekly podcast, it’s a wholly sponsored series we do at Risky.Biz where vendors come on to the show to pitch their products to you, the Risky Business listener. To be clear – everyone you hear in one of these editions, paid to be here.

We’ll hear from three vendors in this edition of Snake Oilers:

  • Tines, the no code security automation solution that people are going absolutely nuts over
  • Code42, the insider threat detection solution maker
  • Kroll talks about its MDR offering

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Why former Uber CISO Joe Sullivan’s guilty verdict shouldn’t worry you
  • United States puts chipmaking restrictions on China, APT activity is coming
  • Elon blinks and Starlink goes dark on Ukraine’s front line
  • Master cyber criminal arrested in Australia
  • Much, much more

This week’s show is brought to you by runZero, the asset inventory and network visibility solution. runZero’s founding CTO and industry legend HD Moore is this week’s sponsor guest.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • Risky Biz News: Good news for the Capital One hacker, bad news for the former Uber CSO
  • Joe Sullivan guilty in Uber hacking case - The Washington Post
  • Security chiefs fear ‘CISO scapegoating’ following Uber-Sullivan verdict - The Record by Recorded Future
  • U.S. imposes foreign direct product rule on China for AI and supercomputing - The Washington Post
  • Popular censorship circumvention tools face fresh blockade by China | TechCrunch
  • 'Fear' driving Chinese state to manipulate tech ecosystem... - GCHQ.GOV.UK
  • Risky Biz News: China blocks several protocols used to bypass the Great Firewall
  • Joint_CSA_Top_CVEs_Exploited_by_PRC_cyber_actors_TLPWHITE - DocumentCloud
  • Starlink goes dark
  • Coverage of Killnet DDoS attacks plays into attackers' hands, experts say - The Record by Recorded Future
  • Ukrainian cybersecurity officer killed by Russian missile strike - The Record by Recorded Future
  • Biden signs new US-EU privacy framework, setting up surveillance safeguards - The Record by Recorded Future
  • White House to unveil ambitious cybersecurity labeling effort modeled after Energy Star
  • Australian teen charged with using leaked Optus data to blackmail customers - The Record by Recorded Future
  • Report: Big U.S. Banks Are Stiffing Account Takeover Victims – Krebs on Security
  • Hackers steal at least $100 million from Binance-linked blockchain - The Record by Recorded Future
  • Someone is clogging up the Zcash blockchain with a spam attack
  • Alberto Rodriguez, and Erik Hunstad - Stop writing malware! The Blue team has done it for you - YouTube
  • CVE-2022-34689 - Security Update Guide - Microsoft - Windows CryptoAPI Spoofing Vulnerability
  • Get root on macOS 12.3.1: proof-of-concepts for Linus Henze’s CoreTrust and DriverKit bugs (CVE-2022-26766, CVE-2022-26763) | Worth Doing Badly
  • Risky Biz News: LofyGang runs amok in the npm ecosystem with minimal gains

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • More Exchange 0days cause more havoc
  • A look at some earlier Exchange hack incidents
  • How the CIA got its agents killed with its truly awful online opsec
  • Ex NSA staffer arrested for espionage
  • Much, much more

This week’s show is brought to you by Proofpoint. Ryan Kalember, Proofpoint’s EVP of cybersecurity strategy, joins the show this week to talk about some overlooked detection opportunities – some simple stuff you can look for in your environment that should raise gigantic flashing red flags.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • Microsoft confirms two Exchange Server zero days are being used in cyberattacks - The Record by Recorded Future
  • CISA: Multiple government hacking groups had ‘long-term’ access to defense company - The Record by Recorded Future
  • Mexican president confirms ‘Guacamaya’ hack targeting regional militaries - The Record by Recorded Future
  • Mexican journalists targeted by zero-click spyware infections - The Record by Recorded Future
  • Ex-NSA employee charged with violating Espionage Act, selling U.S. cyber secrets
  • Putin grants citizenship to Edward Snowden, who disclosed US eavesdropping - The Washington Post
  • U.S. fails in bid to extradite Brit for helping North Korea evade sanctions with cryptocurrency - The Record by Recorded Future
  • Bill Marczak on Twitter: "NEW REPORT today from @Reuters @JoelSchectman providing more detail about fatal flaws in the CIA's defunct communications network. Iran and China compromised the network in 2011, and killed dozens of CIA assets https://t.co/AwN8pQtWL2" / Twitter
  • Numerous orgs hacked after installing weaponized open source apps | Ars Technica
  • 'Poisoned' Tor Browser tracks Chinese users' online history, location
  • Mystery Hackers Are ‘Hyperjacking’ Targets for Insidious Spying | WIRED
  • A Matrix Update Patches Serious End-to-End Encryption Flaws | WIRED
  • LA officials confirm ransomware group leaked students’ personal data - The Record by Recorded Future
  • Nearly 700 ransomware incidents traced back to wholesale access markets: report - The Record by Recorded Future
  • Semiconductor industry faced 8 attacks from ransomware groups, extortion gangs in 2022 - The Record by Recorded Future
  • CISA directs federal agencies to track software and vulnerabilities - The Record by Recorded Future
  • Fake CISO Profiles on LinkedIn Target Fortune 500s – Krebs on Security
  • House Democrats debut new bill to limit US police use of facial recognition | TechCrunch
  • EP000: Operation Aurora | HACKING GOOGLE - YouTube

View Details

In this Soap Box podcast Patrick Gray interviews Airlock Digital CTO Daniel Schell and CEO David Cottingham about Microsoft’s new Smart Application Control feature, why controlling browser extensions via endpoint instrumentation is really hard and why PAM solutions don’t actually do allowlisting, even if they claim they do.

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Lapsus$’s Teapot arrested by UK police
  • Optus hacker issues grovelling apology after feeling AFP and ASD heat
  • Ukraine claims Russia is planning massive attacks on its infrastructure
  • RSOCKS bot herder begs for extradition to USA
  • Russians scammed when seeking military service exemptions
  • Much, much more

This week’s show is sponsored by Votiro. Ravi Srinivasan, Votiro’s CEO, joins the show this week to talk about how people are using content disarm and reconstruction.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • British teen arrested in hacking case
  • Australian cybersecurity minister lambasts Optus for ‘unprecedented' hack - The Record by Recorded Future
  • CISA: Iranian hackers spent 14 months in Albanian gov’t network before launching ransomware - The Record by Recorded Future
  • Iran shutters mobile networks, Instagram, WhatsApp amid protests - The Record by Recorded Future
  • US Treasury carves out Iran sanctions exceptions for internet providers - The Record by Recorded Future
  • Signal Is Asking People Around the World to Help Iranians Access the Encrypted App
  • Shadowy Russian Cell Phone Companies Are Cropping Up in Ukraine | WIRED
  • Risky Biz News: XakNet "hacktivists" linked to APT28 and Russia's GRU intelligence service
  • Russia plans “massive cyberattacks” on critical infrastructure, Ukraine warns | Ars Technica
  • Accused Russian RSOCKS Botmaster Arrested, Requests Extradition to U.S. – Krebs on Security
  • Сбербанк предупредил о мошенничестве с продажей якобы "белых" военников - РИА Новости, 26.09.2022
  • SIM Swapper Abducted, Beaten, Held for $200k Ransom – Krebs on Security
  • How 3 hours of inaction from Amazon cost cryptocurrency holders $235,000 | Ars Technica
  • The record-setting DDoSes keep coming, with no end in sight | Ars Technica
  • International conflicts driving increased strength of DDoS attacks: report - The Record by Recorded Future
  • Tarfile path traversal bug from 2007 still present in 350k open source repos | The Daily Swig

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • A look at how Uber got owned so hard
  • Why cleartext cookie storage in Microsoft Teams’ Electron-based app is actually a big deal
  • Russian official: Starlink is a legitimate military target
  • Wagner mercs get doxxed
  • Kiwi Farms having a bad time
  • Much, much more

In this week’s sponsor interview we’ll be chatting to Nucleus’s CEO Steve Carter about CISA’s KEV list. He has feelings about the KEV list – they’re mostly positive, but he also has a few reasonable gripes and he joins me to talk about them.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • Uber attributes hack to Lapsus$, working with FBI and DOJ on investigation - The Record by Recorded Future
  • Uber confirms it is investigating cybersecurity incident - The Record by Recorded Future
  • Microsoft Teams stores cleartext auth tokens, won’t be quickly patched | Ars Technica
  • SharpTongue Deploys Clever Mail-Stealing Browser Extension "SHARPEXT" | Volexity
  • Hacking group focused on Central America dumps 10 terabytes of military emails, files
  • Securing the Supply Chain of Nothing | Kelly Shortridge
  • Russia Makes Veiled Threat to Destroy SpaceX's Starlink
  • Pro-Ukraine Hacktivists Claim to Have Hacked Notorious Russian Mercenary Group
  • Fears grow of Russian spies turning to industrial espionage - The Record by Recorded Future
  • Congressional inquiry reveals secret Customs and Border Protection database of U.S. phone records
  • Alternative payment apps such as AliPay a boon for cybercriminals, experts tell Congress
  • CISA floats plan to partner with local universities for '311' cyberattack triage service - The Record by Recorded Future
  • Breach of software maker used to backdoor ecommerce servers | Ars Technica
  • Kiwi Farms has been breached; assume passwords and emails have been leaked | Ars Technica
  • (8) Kevin Beaumont on Twitter: "The saga continues - there was (also?) a script injected for a month on Kiwi Farms called Troonshine, gathering information and credentials from user’s systems, posting it to “https://t.co/XnrUu4t3sd”. They look very, very owned. https://t.co/kxdR8kxtC1" / Twitter
  • Pentagon reviews psychological operations amid Facebook, Twitter complaints - The Washington Post
  • Bosnia and Herzegovina investigating alleged ransomware attack on parliament - The Record by Recorded Future
  • Botched Crypto Mugging Lands Three U.K. Men in Jail – Krebs on Security
  • Cryptocurrency company Wintermute says hackers stole $160 million - The Record by Recorded Future
  • Anonymous hacker, who bragged about exploits on TikTok, says he was raided by Canadian police

View Details

In this edition of the Soap Box podcast Patrick Gray talks to Haroon Meer about Thinkst Canary’s new sensitive command token. It’s a great way to detect intruders on your Windows systems. Haroon also talks about how to use canaries strategically.

Show notes

  • Canaries as Network Motion Sensors
  • Sensitive Command Token - So much offense in my defense

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Albania suffers under another crippling Iranian attack
  • Iran’s APT42 using clever, multi-persona phishing
  • State Department cyber snitching program paying off
  • Former NSA director Gen. Keith Alexander sued over alleged IronNet pump and dump
  • Mudge fronts US Senate Judiciary Committee
  • Much, much more…

This week’s show is brought to you by Stairwell. Mike Wiacek, Stairwell’s founder and CEO is this week’s sponsor guest and he talks about why they’ve pushed their Inception platform beyond YARA hunting. You can see a demo of Inception on our YouTube product demo page.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • Risky Biz News: Albania-Iran cyber drama far from over
  • US sanctions Iran intelligence agency over Albania cyberattack - The Record by Recorded Future
  • Tom Uren on Cyber Embuggerance
  • Iranian military using spoofed personas to target nuclear security researchers - The Record by Recorded Future
  • Iranian hackers spy on journalists and government officials, researchers warn - The Record by Recorded Future
  • FBI, DOJ defend ‘offensive’ actions against Chinese, Russian operations - The Record by Recorded Future
  • State Department bounty program for cybercriminal tips has 'born fruit,' top FBI official says
  • More than $30 million seized from North Korean hackers involved in Axie crypto-theft - The Record by Recorded Future
  • $30 Million Seized: How the Cryptocurrency Community Is Making It Difficult for North Korean Hackers To Profit - Chainalysis
  • Twitter whistleblower testifies to Congress, calls for tech regulation reforms - The Record by Recorded Future
  • Twitter whistleblower testifies before Senate
  • Former NSA Head Keith Alexander Accused of Pump-and-Dump Scheme
  • Google: Conti repurposing tools for Ukraine attacks using Follina bug, Musk impersonation - The Record by Recorded Future
  • Pro-Ukraine hackers claim attack on Russian TV broadcasts - The Record by Recorded Future
  • Initial access broker or ransomware gang has 'exclusive' access to Mitel zero-day exploit: report - The Record by Recorded Future
  • Cyberattacks against U.S. hospitals mean higher mortality rates, study finds
  • Buenos Aires legislature announces ransomware attack - The Record by Recorded Future
  • Ransomware attack knocked a Kentucky city-operated ISP offline before holiday - The Record by Recorded Future
  • Ransomware attacks on retail increase, average retail payment grows to more than $200K - The Record by Recorded Future
  • Cisco: Log4j vulnerability used to attack energy companies in Canada, US and Japan - The Record by Recorded Future
  • Patreon security team layoffs cause backlash in creator community
  • This Clever Anti-Censorship Tool Lets Russians Read Blocked News | WIRED
  • Apple Kills Passwords in iOS 16 and macOS Ventura | WIRED
  • Catalin Cimpanu on Twitter: "They're still recruiting, btw" / Twitter
  • Cyberfella on Twitter: "@campuscodi Please convince Patrick to have a segment about NAFO named "Shitposting Dogs on the Bird App are making Vatniks Seethe and Cope" on the next riskybizz ep 🙏🙏🙏" / Twitter
  • ironnet chart - Google Search
  • Stairwell's Inception Platform - YouTube
  • Все Буде Україна (Everything Will Be Ukraine) - YouTube
  • Pink Floyd - Hey Hey Rise Up (feat. Andriy Khlyvnyuk of Boombox) - YouTube
  • PROBASS ∆ HARDI - GOOD EVENING (WHERE ARE YOU FROM?) - YouTube

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • China’s super spies figure out Rob Joyce ran TAO ops
  • FBI, French authorities fly to Montenegro to investigate ransomware attack
  • NEWSFLASH: Cloudflare are still a bunch of Nazi cuddlers
  • SIM swap drama spills into real world shootings, firebombings
  • Yandex Taxi hack clogs Moscow streets
  • The TikTok breach that wasn’t
  • Project Raven veterans get wings clipped
  • Why recent BGP hijacks are getting a bit concerning
  • Much, much more

This week’s show is brought to you by Corelight, the company that maintains Zeek. Corleight’s Federal CTO Jean Schaffer joins us in this week’s sponsor interview to talk about whether or not the White House’s executive order on Zero Trust is actually changing anything.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • Exclusive: Evidence shows US’ NSA behind attack on email system of leading Chinese aviation university - Global Times
  • Lukasz Olejnik on Twitter: "Chinese accusation of US/NSA cyberattacks on China's aviation university. Unusually, a strong protest issued by China's Foreign Ministry. Chinese media write about NSA extensively, and doxx/point at Rob Joyce, specifically. Highly amusing! https://t.co/PG1XzZoIcW https://t.co/wRMEAokhVj" / Twitter
  • Patrick Gray on Twitter: "Great thread" / Twitter
  • FBI and French officials arrive in Montenegro to investigate ransomware attack - The Record by Recorded Future
  • Chile says gov’t agency struggling with ransomware attack - The Record by Recorded Future
  • Italy warns of cyberattacks on energy industry after Eni, GSE incidents - The Record by Recorded Future
  • Ransomware Gang Accessed Water Supplier’s Control System
  • Experts warn of more Ragnar Locker attacks, days after group targets airline - The Record by Recorded Future
  • Kevin Beaumont on Twitter: "IHG Hotel Group incident is ransomware" / Twitter
  • Criminal hackers targeting K-12 schools, U.S. government warns
  • QNAP warns of zero-day vulnerability in latest DeadBolt ransomware campaign - The Record by Recorded Future
  • Cloudflare Suggests It Won’t Cut Off Anti-Trans Stalking Forum
  • Cloudflare reverses decision and drops trans trolling website Kiwi Farms | Internet | The Guardian
  • Violence-as-a-Service: Brickings, Firebombings & Shootings for Hire – Krebs on Security
  • State Department debars ex-NSA cyber mercenaries who aided vast UAE surveillance operation
  • Hackers Create Traffic Jam in Moscow by Ordering Dozens of Taxis at Once Through App
  • Light Flashing, Siren Wailing: A Rich Muscovite in a Rush - The New York Times
  • TikTok denies security breach after hackers leak user data, source code
  • Samsung denies Social Security numbers involved in latest breach - The Record by Recorded Future
  • Truth Behind the Celer Network cBridge cross-chain bridge incident: BGP hijacking | by SlowMist | Coinmonks | Aug, 2022 | Medium
  • nanog: Yet another BGP hijacking towards AS16509
  • A Windows 11 Automation Tool Can Easily Be Hijacked | WIRED
  • Actors behind PyPI supply chain attack have been active since late 2021 | Ars Technica
  • Cybercriminal Service 'EvilProxy' Seeks to Hijack Accounts
  • Careless Errors in Hundreds of Apps Could Expose Troves of Data | WIRED
  • WatchGuard firewall exploit threatens appliance takeover | The Daily Swig
  • Patched TikTok security flaw allowed one-click account takeovers - The Record by Recorded Future
  • Chrome extensions with 1.4M installs covertly track visits and inject code | Ars Technica
  • Peter Eckersley, co-creator of Let’s Encrypt, dies at just 43 – Naked Security
  • DownUnderCTF

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • The Twilio breach was actually a big deal
  • How a Belarusian Cyber Partisans hack burned a GRU illegal
  • Who wants 25m hashed passwords from Russia?
  • An NFT we can get behind
  • How attackers are using game anti-cheat drivers to defeat EDR
  • Much, much more

This week’s sponsor interview is with Mike Benjamin, the VP of security research at Fastly. He pops in to argue that your red team needs to actually consider how your apps will cope with bot-driven attacks.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • Why the Twilio Breach Cuts So Deep | WIRED
  • Phishers who hit Twilio and Cloudflare stole 10k credentials from 136 others | Ars Technica
  • The number of companies caught up in recent hacks keeps growing | Ars Technica
  • How 1-Time Passcodes Became a Corporate Liability – Krebs on Security
  • (1) Christo Grozev on Twitter: "We first noticed her thanks to a super useful database shared with us by @cpartisans: the border crossing records of Belarus. We knew the passport ranges of GRU and FSB spies, so we decided to search in that data-set by partial matches, leaving the last 3 digits out as wildcards." / Twitter
  • (1) Belarusian Cyber-Partisans on Twitter: "🧵1/3🔥For the 1st time in human history a #hacktivist collective obtained passport info of the ALL country's citizens. Now we're offering you an opportunity to become a part of this history 😎. Get a unique digital version of #lukashenka passport as #NFT https://t.co/gOlWdoUehi https://t.co/RxdWpBqA8f" / Twitter
  • A huge Chinese database of faces and vehicle license plates spilled online | TechCrunch
  • Leading Russian streaming platform suffers data leak allegedly impacting 44 million users - The Record by Recorded Future
  • Plex imposes password reset after hackers steal data for >15 million users | Ars Technica
  • Montenegro struggles to recover from cyberattack that officials blame on Russia - The Record by Recorded Future
  • Patrick Gray on Twitter: "https://t.co/DOFdMExsPe" / Twitter
  • European data privacy watchdogs grill Twitter over Mudge security claims - The Record by Recorded Future
  • Google announces open source vulnerability reward program after Log4j, Codecov issues - The Record by Recorded Future
  • Google Online Security Blog: Announcing Google’s Open Source Software Vulnerability Rewards Program
  • Hackers Are Using Anti-Cheat in 'Genshin Impact' to Ransom Victims
  • An interview with initial access broker Wazawaka: 'There is no such money anywhere as there is in ransomware' - The Record by Recorded Future
  • LockBit ransomware group implicated in crippling attack on French hospital - The Record by Recorded Future
  • Major U.S. library service confirms ransomware attack, struggling to restore affected systems - The Record by Recorded Future
  • China-linked hackers target organizations operating in South China Sea - The Record by Recorded Future
  • Chinese hackers zero in on Australian manufacturers, wind turbine operators
  • FTC sues data broker that tracks locations of 125M phones per month | Ars Technica
  • FCC launches investigation into mobile carriers’ geolocation data practices - The Record by Recorded Future
  • Most top mobile carriers retain geolocation data for two years on average, FCC findings show - CyberScoop
  • Buddle co-accused one of 50 alleged criminals preparing challenge to police sting
  • Researchers discover sprawling pro-U.S. social media influence campaign
  • Unheard Voice: Evaluating five years of pro-Western covert influence operations
  • Rights groups, company leaders decry silence over VLC player ban in India - The Record by Recorded Future

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • A deep look at Mudge’s sensational whistleblower complaint against Twitter
  • Brazilian Federal Police raid Lapsus$ crew
  • NSO CEO to stand down (again), 100 staff to be let go
  • Signal users impacted in Twilio incident
  • Tornado Cash OFACs around and finds out
  • Much, much more

This week’s show is brought to you by Greynoise. Its founder, Andrew Morris, joins the show with a stinging critique of the wider threat intelligence industry. Don’t miss that one.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • Patrick Gray on Twitter: "Jesus… can open, worms everywhere. You basically can’t find anyone more credible than @dotMudge in infosec so this is a massive deal https://t.co/TaDQzTEtzR" / Twitter
  • Twitter confirms January breach, urges pseudonymous accounts to not add email or phone number - The Record by Recorded Future
  • A Slack Bug Exposed Some Users’ Hashed Passwords for 5 Years | WIRED
  • TikTok Says, No, It Isn't Stealing Your Passwords
  • Brazilian police launch investigation targeting Lapsus$ group - The Record by Recorded Future
  • Israeli spyware company NSO Group CEO steps down | Reuters
  • How a Third-Party SMS Service Was Used to Take Over Signal Accounts
  • VIASAT hack impacted French critical services | Cybernews
  • DOJ now relies on paper for its most sensitive court documents, official says
  • Microsoft disrupts Russia-linked hacking group targeting defense and intelligence orgs - The Record by Recorded Future
  • Lloyd’s to forbid insurers from covering losses due to state-backed hacks - The Record by Recorded Future
  • U.S. Treasury Sanctions Notorious Virtual Currency Mixer Tornado Cash | U.S. Department of the Treasury
  • OFAC Around and Find Out - Lawfare
  • Suspected Tornado Cash developer arrested in Netherlands - The Record by Recorded Future
  • Report: Ransomware gangs, fraudsters laundered $540 million through RenBridge platform - The Record by Recorded Future
  • Risky Biz News: Is ransomware going after the Global South? Sure looks like it!
  • Ransomware Now Threatens the Global South | Royal United Services Institute
  • Browser-Powered Desync Attacks: A New Frontier in HTTP Request Smuggling | PortSwigger Research
  • The Return of LOIC, HOIC, HULK, and Slowloris to the Threat Landscape | Radware Blog
  • Hackers steal crypto from Bitcoin ATMs by exploiting zero-day bug
  • A New Jailbreak for John Deere Tractors Rides the Right-to-Repair Wave | WIRED
  • Malicious code exploiting recent VMware bug publicly available, company warns - The Record by Recorded Future
  • Breaking SIDH in polynomial time
  • Hackers Use Deepfakes of Binance Exec to Scam Crypto Projects
  • Cisco confirms May attack by Yanluowang ransomware group - The Record by Recorded Future
  • Cisco releases advisories for bug affecting more than 1 million security devices - The Record by Recorded Future
  • Cisco warns of critical vulnerabilities in routers - The Record by Recorded Future
  • North Korea-backed hackers have a clever way to read your Gmail | Ars Technica
  • When Efforts to Contain a Data Breach Backfire – Krebs on Security
  • Microsoft: Bug in Janet Jackson’s “Rhythm Nation” could crash a laptop - The Record by Recorded Future
  • Anonymous poop gifting site hacked, customers exposed

View Details

In this edition of the Soap Box podcast Okta’s APAC CISO and former Risky Biz editor Brett Winterford talks about how attackers are getting much better at swiping session cookies via realtime phishing and malware.

He also talks about some mitigation strategies to combat this threat and introduces the concept of continuous authentication.

Show notes

  • Defending against session hijacking

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Taiwan tensions fail to conjure the cyber apocalypse
  • Crypto bridge exploit results in $150m feeding frenzy
  • Chainalysis evidence to be challenged in court
  • Post-quantum NIST candidate algorithm gets smoked
  • DSIRF’s Russia links
  • Much, much more

This week’s sponsor interview is with Jerrod Chong from Yubico. He’s joining the show to talk about why consumer-focussed implementations of Webauthn like Apple’s Passkeys aren’t a great enterprise solution.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • Taiwanese websites hit with DDoS attacks as Pelosi begins visit
  • 'Frenzied mob' steals more than $156 million from crypto platform Nomad - The Record by Recorded Future
  • Bitcoin Fog Case Could Put Cryptocurrency Tracing on Trial | WIRED
  • Post-quantum encryption contender is taken out by single-core PC and 1 hour | Ars Technica
  • Federal court system suffered previously undisclosed breach, congressional committee says
  • Australian police charge man with developing spyware used by more than 14,500 people - The Record by Recorded Future
  • Risky Biz News: Microsoft puts the limelight on another spyware maker—DSIRF from Austria
  • Eavesdropping probe finds Israeli police exceeded authority | AP News
  • Hacker use of Microsoft macros plummeted after default block: report - The Record by Recorded Future
  • On security researcher's newsletter, exposing cybercriminals behind ransomware
  • Luxembourg energy companies struggling with alleged ransomware attack, data breach - The Record by Recorded Future
  • At least 34 healthcare orgs affected by alleged ransomware attack on OneTouchPoint - The Record by Recorded Future
  • American Dental Association says April cyberattack involved ransomware - The Record by Recorded Future
  • Ransomware group demands £500,000 from British schools, citing cyber insurance policy - The Record by Recorded Future
  • Hackers stole passwords for accessing 140,000 payment terminals | TechCrunch
  • Experts warn of hacker claiming access to 50 U.S. companies through breached MSP - The Record by Recorded Future
  • German prosecutors issue warrant for Russian government hacker over energy sector attacks - The Record by Recorded Future
  • The commercial satellite boom is leaving space vulnerable to hackers - The Record by Recorded Future
  • Report to Congress of the U.S.-China Economic and Security Review Commission - U.S.-China Economic and Security Review Commission - Google Books
  • Spanish police arrest two accused of hacking radioactivity alert system - The Record by Recorded Future

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Why Entrust being ransomwared is good news
  • UEFI bootkits turn hardware into landfill
  • Microsoft resumes macro blocking rollout
  • Pat and Adam talk about why plugging your IDP into legacy apps is a dreadful idea
  • Much, much more

This week’s sponsor guest is Paul “The Voice” Lanzi of Remediant. He’s popping along to talk about the emergence of a new product category – Identity Threat Detection and Response, or ITDR.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • Italy investigating ransomware attack on tax agency - The Record by Recorded Future
  • IT security giant Entrust says it's investigating alleged June data breach - The Record by Recorded Future
  • Microsoft resuming default block of Office VBA macros - The Record by Recorded Future
  • Discovery of new UEFI rootkit exposes an ugly truth: The attacks are invisible to us | Ars Technica
  • China: Declaration by the Minister for Foreign Affairs on behalf of the Belgian Government urging Chinese authorities to take action against malicious cyber activities undertaken by Chinese actors | Federal Public Service Foreign Affairs
  • Cyber Command shares bevy of new malware used against Ukraine - The Record by Recorded Future
  • Cyber criminals attack Ukrainian radio network, broadcast fake message about Zelensky's health
  • Congress goes after spyware purveyors. Will it make a difference?
  • Report: Mercenary spyware exploited Google Chrome zero-day to target journalists - The Record by Recorded Future
  • TSA unveils updated cybersecurity regulations of oil and gas pipelines - The Record by Recorded Future
  • Congress Might Actually Pass ADPPA, the American Data Privacy and Protection Act | WIRED
  • Federal privacy legislation progresses, but concerns about data brokers loom
  • China cybersecurity agency fines ride-hailing giant Didi $1.2 billion for data issues - The Record by Recorded Future
  • T-Mobile reaches historic $350 million settlement in 2021 data breach - The Record by Recorded Future
  • Former Coinbase Manager Arrested by Feds for Alleged Insider Trading
  • Cisco patches dangerous bug trio in Nexus Dashboard | The Daily Swig
  • Atlassian patches batch of critical vulnerabilities across multiple products | The Daily Swig
  • Hardcoded password in Confluence app has been leaked on Twitter | Ars Technica

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • A look at the DHS Cyber Safety Review Board’s Log4j report
  • Joshua Schulte no longer the “alleged” Vault7 leaker
  • Chinese APT crews targeted US political journalists before Jan 6
  • Ransomware gangs make leak sites searchable
  • Why recovering plaintext passwords from Okta is expected behaviour
  • US Government seizes North Korean ransomware payment
  • Much, much more

This week’s show is brought to you by Trail of Bits. Dan Guido is this week’s sponsor guest and he’ll tell us about work Trail of Bits did for DARPA on investigating blockchain security fundamentals.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • Patrick Gray on Twitter: "During our discussion yesterday on the show we didn’t know pre-existing MDM was preserved when iOS lockdown mode is enabled, which is great!" / Twitter
  • DHS Cyber Safety Review Board found no evidence China knew of Log4j before disclosure
  • Ex-CIA Hacker Convicted for ‘One of the Most Damaging Acts of Espionage in American History’
  • Chinese hackers targeted U.S. political reporters just ahead of Jan. 6 attack, researchers say
  • Experts concerned about ransomware groups creating searchable databases of victim data - The Record by Recorded Future
  • Who-is-Trickbot.pdf
  • A Deep Dive Into the Residential Proxy Service ‘911’ – Krebs on Security
  • Risky Biz News: Google removes app permissions from the Play Store
  • Ongoing phishing campaign can hack you even when you’re protected with MFA | Ars Technica
  • ‘Password extraction risk’ in identity provider Okta disputed | The Daily Swig
  • Authomize Discovers Password Stealing and Impersonation Risks in Okta | Authomize.com
  • Okta Response to Security Report | Okta
  • DOJ seized ransoms paid by health centers in Kansas, Colorado after 2021 attacks - The Record by Recorded Future
  • North Korean hackers target small businesses with H0lyGh0st ransomware, Microsoft warns - The Record by Recorded Future
  • Colorado police investigating ransomware attack on small town - The Record by Recorded Future
  • Albania shuts down government websites, services due to wide ranging cyberattack - The Record by Recorded Future
  • Bandai Namco confirms cyberattack after ransomware group threatens leak - The Record by Recorded Future
  • MiCODUS MV720 GPS tracker | CISA
  • Honda redesigning latest vehicles to address key fob vulnerabilities - The Record by Recorded Future
  • Russia Released a Ukrainian App for Hacking Russia That Was Actually Malware
  • Are blockchains decentralized? | Trail of Bits Blog
  • Announcing the new Trail of Bits podcast | Trail of Bits Blog
  • GitHub - trailofbits/it-depends: A tool to automatically build a dependency graph and Software Bill of Materials (SBOM) for packages and arbitrary source code repositories.

View Details

On this week’s show Patrick Gray and guest cohost Dmitri Alperovitch discuss the week’s security news, including:

  • Why an American defence contractor acquiring NSO Group would be a nonproliferation win
  • A look at Microsoft’s botched macro measures
  • iPhone’s Lockdown Mode
  • Ukraine goes big on Yubikeys
  • Aerojet Rocketdyne pays millions over poor security controls, CISO whistleblower gets bag of cash
  • Much, much more

This week’s show is sponsored by Proofpoint. Ryan Kalember, Proofpoint’s Executive Vice President of Cybersecurity Strategy, joins us in this week’s sponsor interview to talk about changes he’s observed in the criminal ecosystem.

NOTE: This podcast contains an error. We say that iOS Lockdown Mode prevents users from using an MDM profile on their devices. It doesn’t, it just stops new MDM profiles from being loaded while in Lockdown Mode, so corporate users will be able to turn it on just fine.

Links to everything that we discussed are below and you can follow Patrick or Dmitri on Twitter if that’s your thing.

Show notes

  • L3Harris drops bid for NSO spyware following U.S. concerns - The Washington Post
  • Apple introduces 'Lockdown Mode' iPhone feature to block elite spyware
  • Risky Biz News: Thousands of Yubikeys have been deployed in Ukraine, more to come
  • PyPI repo to distribute 4,000 security keys to maintainers of ‘critical projects’ in 2FA drive | The Daily Swig
  • Microsoft makes major course reversal, allows Office to run untrusted macros [Updated] | Ars Technica
  • Microsoft says decision to stop blocking Office VBA macros by default is ‘temporary’ - The Record by Recorded Future
  • Hacktivists claiming attack on Iranian steel facilities dump tranche of 'top secret documents'
  • Rocket maker agrees to pay $9 million to settle allegations of cybersecurity violations - The Record by Recorded Future
  • North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target the Healthcare and Public Health Sector | CISA
  • North Korea is targeting hospitals with ransomware, U.S. agencies warn
  • Medical debt collection firm says ransomware attack exposed info on 650+ healthcare orgs - The Record by Recorded Future
  • French telecom company La Poste Mobile struggling to recover from ransomware attack - The Record by Recorded Future
  • Cyberattack knocks out California community college email, website, landlines - The Record by Recorded Future
  • OPM breach victims expected to receive about $700 each after class action settlement - The Record by Recorded Future
  • Chinese Hackers Targeting Russian Government and Telcos
  • DeFi Hacker Returns $8m
  • Millions in Cryptocurrency Stolen in Phishing Attacks

View Details

Today’s soap box is brought to you by Nucleus Security.

Nucleus makes a platform that ingests vulnerability scan information from all your vuln scanning tech so that you can do things like assign different vulnerabilities to different teams to manage and remediate. Send these ones to infrastructure, send these ones to app teams, send everything up and down this stack to this department etc.

If you want to see Nucleus in action I have recorded a demo and it’s on our YouTube product demos page, I’ve linked through to it in the show notes for this podcast.

Our guest in this episode is Scott Kuffer, co-founder of Nucleus, and the topic is running a vulnerability management program in a very large enterprise.

Show notes

  • Nucleus Security Product Demo on Risky Biz YouTube Channel

View Details

On this week’s show Patrick Gray and guest cohost Mark Piper discuss the week’s security news, including:

  • A billion records leaked in China
  • China to develop desktop operating system
  • HackerOne fires insider for stealing hackers’ work and bounties
  • FSB officer charged with stealing hacker’s bitcoin
  • Why Microsoft is wrong on Russia and Ukraine
  • Much, much more

Red Canary’s Adam Mashinchi and Brian Donohue will be along in this week’s sponsor interview to talk about Atomic Red Team, the open source adversary emulation framework they help to maintain.

Links to everything that we discussed are below and you can follow Patrick on Twitter if that’s your thing.

Show notes

  • Hacker claims to have stolen 1 bln records of Chinese citizens from police | Reuters
  • China lured graduate jobseekers into digital espionage | Ars Technica
  • Tech war: China doubles down on domestic operating systems to cut reliance on Windows, MacOS from the US | South China Morning Post
  • Risky Biz News: HackerOne discloses malicious insider incident, and nobody's surprised
  • (2) Paranoid Ninja (Brute Ratel C4) on Twitter: "A thoroughly detailed blog on Brute Ratel C4 by Palo Alto. Proper Actions have been taken to against the found licenses which were sold in the Black Market. As for existing customers, #BRc4 v1.1 release will change every aspect of IOC found in the previous releases." / Twitter
  • Microsoft Exchange servers worldwide hit by stealthy new backdoor | Ars Technica
  • Подполковника УФСБ по Самарской области арестовали за кражу криптовалюты у хакера - ТАСС
  • Cybersecurity experts question Microsoft's Ukraine report
  • (4) Victor Zhora on Twitter: "One more evidence of coordination of kinetic and cyber operations by russian aggressors. Ukrainian largest private energy company DTEK was cyberattacked simulateously with shelling of thermal power plant of the same company in Kryvyi Rih. Both targets are 100% civilian." / Twitter
  • Вслід за ракетними ударами по ТЕС ворог завдає хакерських атак по енергосистемі — ДТЕК
  • CyberKnow on Twitter: "Another new pro-russian hacktivist group. They have been conducting #ddos ops against #Norway with other groups. #cybersecurity #infosec #RussianUkrainianWar #UkraineRussiaWar https://t.co/rX069XVaof" / Twitter
  • Hacktivist personas back latest GhostWriter disinfo op targeting Poland, Ukraine
  • Gantz orders probe after TV reports hint IDF behind Iran steel plant cyberattack | The Times of Israel
  • Info of over 300,000 Israelis leaked as Iranian hackers target travel booking sites | The Times of Israel
  • TSA to change cybersecurity rules for pipelines following industry criticism - The Record by Recorded Future
  • After a sharp rise, cyber insurance rates show signs of stabilizing - The Record by Recorded Future
  • California DOJ apologizes for ‘unacceptable’ breach involving Firearms Dashboard - The Record by Recorded Future
  • Cops Investigating ‘WhatsApp for Gangsters’ Arrest Key Suspect in Caribbean
  • Publishing giant Macmillan still unable to process orders after ransomware attack - The Record by Recorded Future
  • State unemployment, jobs services down around the country after cyberattack
  • NIST selects first group of quantum-resistant encryption tools - The Record by Recorded Future
  • UnRAR path traversal flaw can lead to RCE in Zimbra | The Daily Swig
  • Universiteit Maastricht krijgt losgeld voor hack terug met flinke winst
  • Nearly $9 million stolen from DeFi platform Crema Finance - The Record by Recorded Future
  • North Korea accused of orchestrating $100 million Harmony crypto hack - The Record by Recorded Future
  • Nucleus Security's vulnerability management platform - YouTube
  • Explore Atomic Red Team

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Activists who are totally not Israeli military hackers make Iranian steel mills firebally
  • Chinese APT crews use ransomware to muddy attribution
  • Attackers are now ransoming cloud access
  • Chinese APTs using building control systems for persistence and stealth
  • USA, UK and NZ govts issue PowerShell advice
  • Much, much more

This week’s show is brought to you by Material Security. JJ Agha, CISO at Compass, joins the show to talk about how he’s using it to make phishing triage and automation less traumatic.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • Iranian steel facilities suffer apparent cyberattacks
  • Automotive fabric supplier TB Kawashima announces cyberattack
  • US arm of Japanese automotive hose maker Nichirin pauses production after ransomware attack - The Record by Recorded Future
  • BRONZE STARLIGHT Ransomware Operations Use HUI Loader | Secureworks
  • Ransomware groups targeting Mitel VoIP zero-day - The Record by Recorded Future
  • Brett Callow on Twitter: "LockBit also seems to have set its demands to automatically decrease over time. The longer victims wait, the less they need to pay. 4/5" / Twitter
  • Cisco Talos Intelligence Group - Comprehensive Threat Intelligence: De-anonymizing ransomware domains on the dark web
  • Brazilian retail giant confirms cyberattack after extortion group takes over Twitter account - The Record by Recorded Future
  • Akamai Blog | Bots Are Scalping Israeli Government Services
  • Rise of LNK (Shortcut files) Malware | McAfee Blog
  • Attacks on industrial control systems using ShadowPad | Kaspersky ICS CERT
  • Google: Seven zero-days in 2021 developed commercially and sold to governments - The Record by Recorded Future
  • The hacking industry faces the end of an era | MIT Technology Review
  • Lawmakers want to restrict user data sales to nations like China, Russia
  • US, UK, New Zealand argue against disabling PowerShell - The Record by Recorded Future
  • CSI_KEEPING_POWERSHELL_SECURITY_MEASURES_TO_USE_AND_EMBRACE_20220622.PDF
  • A pro-China online influence campaign is targeting the rare-earths industry | MIT Technology Review
  • Internet Crime Complaint Center (IC3) | Deepfakes and Stolen PII Utilized to Apply for Remote Work Positions
  • Statutory defense for ethical hacking under UK Computer Misuse Act tabled | The Daily Swig
  • BSides Cleveland organizer steps down after controversial guest added as ‘surprise’ speaker | The Daily Swig
  • CISA experts propose ‘311’ cybersecurity emergency call line for small businesses - The Record by Recorded Future
  • CISA, US Coast Guard warn of Log4Shell attacks after 130GB data breach in May - The Record by Recorded Future
  • CSAC Recommendations (06-16-2022) (1) - DocumentCloud
  • Meet the Administrators of the RSOCKS Proxy Botnet – Krebs on Security
  • Splunk patches critical vulnerability while users push for legacy updates | The Daily Swig
  • Oracle patches ‘miracle exploit’ impacting Middleware Fusion, cloud services | The Daily Swig
  • Cyber Insurance: Action Needed to Assess Potential Federal Response to Catastrophic Attacks | U.S. GAO
  • FBI investigating $100 million theft from blockchain company Harmony - The Record by Recorded Future
  • Jerry Gamblin on Twitter: "Ahhh... the orignal NFTs." / Twitter
  • PeckShield Inc. on Twitter: "1/ @XCarnival_Lab was exploited in a flurry of txs (one hack tx: https://t.co/LUcxSU9UQn), leading to the gain of 3,087 ETH (~$3.8M) for the hacker (The protocol loss may be larger). https://t.co/mmGw5PQfbt" / Twitter
  • Patrick Gray on Twitter: "🎉" / Twitter

View Details

Today’s Soap Box guest is an industry legend – Metasploit creator HD Moore. He’s here to tell us more about what’s happening with his latest creation, Rumble Network Discovery.

If you’re not familiar with Rumble, well, you should be. It’s a network scanner that you just set loose and it will go and find all the devices on your network. It has a freaky ability to see around corners, finding devices it can’t even connect to directly because HD and his team have done some really crazy work on pulling device information out of obscure protocol queries and things like that. It takes a few minutes to set up a scan with Rumble, so it’s infinitely easier than trying to do passive network discovery on the network or pull data from other solutions.

But Rumble isn’t just a network scanner anymore. They’ve been doing basic cloud asset inventory since the early days, but as you’ll hear it’s an area they’ve really been putting a lot of work into lately. Another big thing they’ve worked on is ICS and OT fingerprinting techniques that won’t actually cause those devices to command things to explode, so that’s nice.

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Paige Thompson guilty of Capital One hack
  • Microsoft is hiding serious Azure security issues
  • New Australian government lobbying for Julian Assange
  • How to ransomware documents in the cloud
  • Microsoft stops Windows 10/11 downloads in Russia
  • Belarusian cyber partisans obtain spy agency’s audio recordings
  • Much, much more

This week’s edition of the show is brought to you by Gigamon. Josh Day, Gigamon’s Director of applied threat research team, will be along in this week’s sponsor interview to talk about detecting badness on your network in encrypted traffic.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • Former Seattle tech worker convicted of wire fraud and computer intrusions | USAO-WDWA | Department of Justice
  • MPs back quiet diplomacy in Assange case
  • Botched and silent patches from Microsoft put customers at risk, critics say | Ars Technica
  • Microsoft’s Vulnerability Practices Put Customers At Risk | LinkedIn
  • Security firm warns of ransomware attacks targeting Microsoft cloud 'versioning' feature - The Record by Recorded Future
  • Separate Fujitsu cloud storage vulnerabilities could enable attackers to destroy virtual backups | The Daily Swig
  • Large supermarket chain in southern Africa hit with ransomware - The Record by Recorded Future
  • Telegram: Contact @tass_agency
  • Microsoft pulls Windows 10 and 11 in Russia • The Register
  • DDoS Attacks Delay Putin Speech at Russian Economic Forum
  • Russia warns of a “military clash” if it’s hit by US cyberattacks - The Record by Recorded Future
  • Belarusian hacktivist group releases purported Belarusian wiretapped audio of Russian embassy
  • U.S. defense firm L3Harris in talks with NSO Group over spyware - The Washington Post
  • Srsly Risky Biz: Friday June 17 - by Tom Uren
  • Suspect in hacking Russian customs detained in Moscow
  • String of attacks on French telecom infrastructure preceded April attack on fiber optic cables
  • Chinese APT groups targeting India, Pakistan and more with Sophos firewall vulnerability - The Record by Recorded Future
  • Ukrainian cybersecurity officials disclose two new hacking campaigns
  • Police Linked to Hacking Campaign to Frame Indian Activists | WIRED
  • INTERPOL raids hundreds of scammy call centers in sweep
  • A Twitch Streamer Is Exposing Coronavirus Scams Live | WIRED
  • Ranking The World's Angriest Scammers - 10/10 Rage - YouTube
  • MIT researchers find new hardware vulnerability in the Apple M1 chip - The Record by Recorded Future
  • A new vulnerability in Intel and AMD CPUs lets hackers steal encryption keys | Ars Technica
  • Tornado Cash Is Crypto Hackers’ Favorite Way to Cash Out, But Experts Say It Can Be Traced
  • How CISA's list of 'must-patch' vulnerabilities has expanded both in size, and who's using it
  • The tale of a whale who took Solend’s money – Amy Castor

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • “Shields Up” advice is now provably meaningless
  • Russia to ditch offshore comms apps like WhatsApp
  • Evil Corp’s Lockbit sanctions evasion attempt backfires
  • Binance is a cesspit of shady financial dealings
  • Apple’s passkey release foreshadows FIDO mass adoption
  • Much, much more

This week’s sponsor interview is about Elastic’s teardown on some really interesting APT linux malware called BPFdoor. Jake King and Colson Wilhoit joined the show for that interview.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • US military hackers conducting offensive operations in support of Ukraine, says head of Cyber Command | Science & Tech News | Sky News
  • White House: cyber activity not against Russia policy | Reuters
  • 'Shields Up': the new normal in cyberspace
  • Governors are being contacted - Newspaper Kommersant No. 95 (7296) dated 06/01/2022
  • «Вы лично отвечаете за инциденты». Почему 1 мая началась новая эпоха в информационной безопасности - Газета.Ru
  • Киев использовал против России новый принцип кибератак - Ведомости
  • Traffic will be sorted into folders - Newspaper Kommersant No. 102 (7303) dated 06/10/2022
  • FBI cybercrime seizure takes down one-time Ukraine IT Army collaborator
  • To HADES and Back: UNC2165 Shifts to LOCKBIT to Evade Sanctions | Mandiant
  • Risky Biz News: LockBit-Mandiant drama, explained
  • How Binance became a hub for hackers, fraudsters and drug sellers
  • Cryptocurrencies were once seen as an unmitigated boon for criminals. Not anymore.
  • Fed cyber officials detail Chinese state hackers using common exploits against telcos
  • Risky Biz News: Russia orders Google to remove Tor Browser from Russian Play Store
  • Bizbudding, Inc. v. 365 Data Centers Services, LLC, 3:22-cv-00715 – CourtListener.com
  • Business Email Compromise Scams Are Poised to Eclipse Ransomware | WIRED
  • Cybercriminal scams City of Portland, Ore. for $1.4 million - The Record by Recorded Future
  • Apple's Passkey Replaces Passwords With iPhone and Mac Authentication | WIRED
  • MongoDB Debuts ‘Queryable Encryption’ to Fight Hacks and Leaks | WIRED
  • Zero-Day Exploitation of Atlassian Confluence | Volexity
  • Microsoft Security Intelligence on Twitter: "Multiple adversaries and nation-state actors, including DEV-0401 and DEV-0234, are taking advantage of the Atlassian Confluence RCE vulnerability CVE-2022-26134. We urge customers to upgrade to the latest version or apply recommended mitigations: https://t.co/C3CykQgrOJ" / Twitter
  • Microsoft Follina Vulnerability in Windows Can Be Exploited Through Office 365 | WIRED
  • (3) Martin Sheppard on Twitter: "@riskybusiness And yes, many orgs can disable Macros in documents with the mark of the web without a lot of impact. Policy can be used to not mark documents from certain internal sites with mark of the web, which is one way to allow certain legitimate macros with this setting in place." / Twitter
  • Blockchain, 'Decentralized' Exchange Taken Offline After Hacker Steals Millions
  • ‘Optimism’ Crypto Hack Victim Hopes Thief Will Give Back $15 Million
  • PeckShieldAlert on Twitter: "#PeckShieldAlert Wintermute Exploiter has transferred 17 million $OP to @optimismPBC https://t.co/5PpgeZXaId" / Twitter
  • NFT insider trading charges filed against former OpenSea employee Nate Chastain
  • Detecting BPFDoor backdoor payload | Elastic

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • The msdt/office lolbinapalooza
  • Microsoft to introduce sensible defaults to Azure
  • Twitter fined $150m for sms 2fa spam
  • It turns out npm got owned in that Heroku/Travis CI thing
  • AWS cred-stealing supply chain attack was research your honour, I swear!
  • Much, much more

We’ll be chatting with Airlock Digital co-founder and CTO Daniel Schell in this week’s sponsor interview. He’ll be walking us through some of his own research into how to own Microsoft boxes via document-embedded office add-ins.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • nao_sec on Twitter: "Interesting maldoc was submitted from Belarus. It uses Word's external link to load the HTML and then uses the "ms-msdt" scheme to execute PowerShell code. https://t.co/hTdAfHOUx3 https://t.co/rVSb02ZTwt" / Twitter
  • Follina — a Microsoft Office code execution vulnerability | by Kevin Beaumont | May, 2022 | DoublePulsar
  • Kevin Beaumont on Twitter: "Additional Follina issue, if you use wget in Powershell, it blindly executes any code via MSDT as it trusts all MS Protocol URIs. So to clarify, if you wget a webpage you don’t control and the webpage adds Follina exploit string, your server the runs the code." / Twitter
  • Microsoft Office Remote Code Execution - “Follina” MSDT Attack
  • Raising the Baseline Security for all Organizations in the World - Microsoft Tech Community
  • npm security update: Attack campaign using stolen OAuth tokens | The GitHub Blog
  • Twitter fined $150 million by FTC for alleged privacy violations - The Record by Recorded Future
  • REvil prosecutions reach a 'dead end,' Russian media reports
  • Multiple flights across India grounded after SpiceJet airline hit with ransomware - The Record by Recorded Future
  • Exclusive: Russian hackers are linked to new Brexit leak website, Google says | Reuters
  • Российские компании начали увольнять украинских ИT-специалистов — РБК
  • Hacker Leaks Mountain of Files From Inside Xinjiang Camps
  • Spain set to strengthen oversight of secret services after NSO spying scandal | The Times of Israel
  • No evidence of exploitation of Dominion voting machine flaws, CISA finds - The Washington Post
  • Researchers identify FIDO2 protocol vulnerabilities - Security - iTnews
  • 756.pdf
  • Security ‘researcher’ hits back against claims of malicious CTX file uploads | The Daily Swig
  • Israeli private detective used Indian hackers in job for Russian oligarchs, court filing says | Reuters
  • Hacker Steals Database of Hundreds of Verizon Employees
  • GarWarner on Twitter: "Last month the US Department of Justice petitioned the court to be allowed to seize Mr. Woodbery's Bitcoin. 151.885720427 BTC is 11,930,370 Naira or $4,364,299 USD currently. (Thread 1/? ) https://t.co/Xh39FTLQUV" / Twitter
  • Malcolm Herbert on Twitter: "@riskybusiness @Metlstorm ... for some reason I never pictured you guys as doing a recording session before sunup, but then I guess with @Metlstorm being in NZ that kinda makes sense now that I think about it ... I'll see myself out ..." / Twitter
  • Darknet market Versus shuts down after hacker leaks security flaw
  • Omnipotent BMCs from Quanta remain vulnerable to critical Pantsdown threat | Ars Technica
  • Red Canary Managed Detection and Response - YouTube
  • Airlock Digital Demo - YouTube

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Conti’s war against Costa Rica
  • DoJ revises CFAA guidance
  • Naughty kids get access to DEA portal
  • A look at a Russian disinfo tool
  • PyPI and PHP supply chain drama
  • Much, much more

This week’s show is brought to you by Thinkst Canary. Its founder Haroon Meer will join us in this week’s sponsor interview to talk about what might happen to infosec programs now the world economy is getting all funky.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • President Rodrigo Chaves says Costa Rica is at war with Conti hackers - BBC News
  • Costa Ricans scrambled to pay taxes by hand after cyberattack took down country’s collection system
  • Costa Rican president claims collaborators are aiding Conti's ransomware extortion efforts
  • K-12 school districts in New Mexico, Ohio crippled by cyberattacks - The Record by Recorded Future
  • Greenland says health services 'severely limited’ after cyberattack - The Record by Recorded Future
  • Notorious cybercrime gang Conti 'shuts down,' but its influence and talent are still out there - The Record by Recorded Future
  • 'Multi-tasking doctor' was mastermind behind 'Thanos' ransomware builder, DOJ says - The Record by Recorded Future
  • Researchers warn of REvil return after January arrests in Russia - The Record by Recorded Future
  • Researcher stops REvil ransomware in its tracks with DLL-hijacking exploit | The Daily Swig
  • Bank refuses to pay ransom to hackers, sends dick pics instead • Graham Cluley
  • GoodWill ransomware forces victims to donate to the poor and provides financial assistance to patients in need - CloudSEK
  • Catalin Cimpanu on Twitter: "Report on a new ransomware strain named GoodWill that forces victims to perform acts of kindness to recover their files https://t.co/T0rhj5wjyC https://t.co/T92KPUJe61" / Twitter
  • Water companies are increasingly uninsurable due to ransomware, industry execs say
  • Department of Justice Announces New Policy for Charging Cases under the Computer Fraud and Abuse Act | OPA | Department of Justice
  • download
  • DEA Investigating Breach of Law Enforcement Data Portal – Krebs on Security
  • Intelligence Update. A question of timing: examining the circumstances surrounding the Nauru Police Force hack and leak
  • FSB's Fronton DDoS tool was actually designed for 'massive' fake info campaigns, researchers say
  • Sonatype PiPI blog post
  • Dvuln Labs - ServiceNSW’s Digital Drivers Licence Security appears to be Super Bad
  • New Bluetooth hack can unlock your Tesla—and all kinds of other devices | Ars Technica
  • Researchers devise iPhone malware that runs even when device is turned off | Ars Technica
  • New Research Paper: Pre-hijacking Attacks on Web User Accounts – Microsoft Security Response Center
  • CISA issues directive for exploited VMware bug after IR team deployed to ‘large’ org - The Record by Recorded Future
  • Hackers are actively exploiting BIG-IP vulnerability with a 9.8 severity rating | Ars Technica
  • Google, Apple, Microsoft Commit to Eliminating Passwords - Security Boulevard
  • Thinkst Canary

View Details

The following is a sample of our latest podcast, Risky Business News, which is published into a new RSS feed. It’s a short podcast published three times a week that updates listeners on the security news of the last few days, as prepared and presented by Catalin Cimpanu. You can find the newsletter version of this podcast here.

View Details

In this Soap Box edition of the show Proofpoint’s EVP of Cybersecurity Strategy Ryan Kalember joins host Patrick Gray to talk about why some security spending is just misguided. So much of the infosec industry is geared towards protecting organisations against exotic threats when, really, the trifecta of ransomware, BEC and staff being careless with data are the thing that will sink them.

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Spanish PM’s phone infected by Pegasus
  • Microsoft drops Ukraine research report
  • We can’t make heads or tails out of the FBI’s transparency report
  • France hit with coordinated fibre sabotage campaign
  • Why Musk’s algorithm pledge is meaningless
  • Much, much more

This week’s sponsor interview is with ExtraHop Networks’ CEO Patrick Dennis. He’s joining us this week to talk about how you can turn “Shield’s Up!” advice into something actionable.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • Spyware attack targeted Spanish prime minister’s phone - The Record by Recorded Future
  • Over 200 Spanish mobile numbers ‘possible targets of Pegasus spyware’ | Spain | The Guardian
  • Russia’s hackers and military went after the same targets in Ukraine, Microsoft says
  • Russia Is Being Hacked at an Unprecedented Scale | WIRED
  • Russia reroutes internet in occupied Ukrainian territory through Russian telcos - The Record by Recorded Future
  • Russia cyber case prompted big portion of FBI's surveillance database searches in 2021 - The Record by Recorded Future
  • 2022_ASTR_for_CY2020_FINAL.pdf
  • Wyden: “Surveillance Transparency Report” Fails To Explain How Many Americans’ Communications Are Searched By the FBI | U.S. Senator Ron Wyden of Oregon
  • How the French fiber optic cable attacks accentuate critical infrastructure vulnerabilities
  • Who tried to hack Hawaii’s undersea cable? - The Record by Recorded Future
  • Nauru police emails leaked to protest against Australia's offshore detention
  • Fighting Fake EDRs With ‘Credit Ratings’ for Police – Krebs on Security
  • Twitter may have given user's private data to a ransomware hacker, who then ran a researcher offline
  • Musk's plans to make Twitter's algorithms public raises disinformation conundrum
  • Elon Musk’s Plan to Open Source the Twitter Algorithm Won’t Solve Anything | WIRED
  • Kronos cyber attack sparks lawsuits against employers | BenefitsPRO
  • German wind farm operator confirms cybersecurity incident - The Record by Recorded Future
  • German library service struggling to recover from ransomware attack - The Record by Recorded Future
  • Trinidad’s largest supermarket chain crippled by cyberattack - The Record by Recorded Future
  • Austin Peay State University becomes latest US school hit with ransomware - The Record by Recorded Future
  • NC Prohibits Gov Entities from Paying Hacker Cybersecurity Ransoms
  • Connecticut inches closer to becoming fifth state with data privacy law - The Record by Recorded Future
  • Security alert: Attack campaign involving stolen OAuth user tokens issued to two third-party integrators | The GitHub Blog
  • Google touts new tool that scans for malicious packages in popular open-source repositories - The Record by Recorded Future
  • Log4Shell, ProxyLogon and Atlassian bug top CISA's list of routinely exploited vulnerabilities in 2021 - The Record by Recorded Future
  • Widespread Exploitation of VMware Workspace ONE Access CVE-2022-22954 | Rapid7 Blog
  • Microsoft finds Linux desktop flaw that gives root to untrusted users | Ars Technica
  • More than $13 million stolen from DeFi platform Deus Finance - The Record by Recorded Future
  • Binance freezes stolen Axie Infinity crypto after North Korean hackers move funds - The Record by Recorded Future
  • Everscale blockchain wallet shutters web version after vulnerability found - The Record by Recorded Future
  • Hackers steal $90 million from DeFi platforms Rari Capital and Saddle Finance - The Record by Recorded Future
  • Crypto Hackers Stole More Than $370 Million In April Alone
  • Airlock Digital Demo - YouTube
  • Risky Business News | Patrick Gray | Substack

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Israel Ministry of Defence is denying a lot of spyware export licences
  • Private detective in New York pleads guilty over BellTroX shenanigans
  • Scammers enrol stolen credit cards into Apple Pay
  • The Blackcat ransomware crew is very active right now
  • VirusTotal shells lol
  • Much, much more

This week’s sponsor interview is with Okta’s Brett Winterford, who talks in detail about the company’s brush with the Lapsus$ hacking crew. It’s unusual for a sponsor interview to be a must listen, but here we are.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • Export controls strangling Israel's cyberattack industry - Globes
  • Israeli charged in global hacker-for-hire scheme pleads guilty | Reuters
  • Criminals Abuse Apple Pay in Spending Sprees
  • Wealthy cybercriminals are using zero-day hacks more than ever | MIT Technology Review
  • Leaked Chats Show LAPSUS$ Stole T-Mobile Source Code – Krebs on Security
  • FBI: 60 organizations worldwide hit with BlackCat/ALPHV ransomware - The Record by Recorded Future
  • FBI warns agricultural sector of heightened risk of ransomware attacks
  • Russia's war on Ukraine making life difficult for Russian cybercriminals
  • In a first, Treasury Department sanctions major cryptocurrency mining firm
  • Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure | CISA
  • (6) Rewards for Justice on Twitter: "REWARD! Up to $10M for information on 6 Russian GRU hackers. They targeted U.S. critical infrastructure with malicious cyber ops. Send us info on their activities via our Dark Web-based tips line at: https://t.co/WvkI416g4W https://t.co/oZCKNHU3fY https://t.co/u1NMAZ9HQl" / Twitter
  • Foreign Malicious Cyber Activity Against U.S. Critical Infrastructure – Rewards For Justice
  • From the front lines of ‘the first real cyberwar’ - The Record by Recorded Future
  • CySource virus total blog
  • (3) Bernardo Quintero on Twitter: "for transparency purposes, this was my internal reply on May 21, 2021 at 03:09PM https://t.co/WR3QTRlxDc" / Twitter
  • Critical bug could have let hackers commandeer millions of Android devices | Ars Technica
  • Hot patch for Log4Shell vulnerability in AWS allowed full host takeover | The Daily Swig
  • Major cryptography blunder in Java enables “psychic paper” forgeries | Ars Technica
  • Brokers' sales of U.S. military personnel data overseas stir national security fears
  • Bored Ape Yacht Club Instagram Hacked, NFTs Worth Millions Stolen
  • A Crypto Entrepreneur Is on the Lam After Dev Jailed for North Korea Trip
  • Okta Concludes its Investigation Into the January 2022 Compromise | Okta
  • Risky Business News | Substack

View Details

On this week’s show Patrick Gray, Adam Boileau and Dmitri Alperovitch discuss the week’s security news, including:

  • Ukraine foils Russian ICS hack
  • US Government burns someone’s ICS toolkit
  • China gets all up in India’s energy gridz
  • The Heroku/Hithub/Travis CI story is very confusing
  • US DOJ removes GRU malware from Watchguard boxes under Rule 41
  • North Korea behind $540m crypto hack
  • Much, much more

This week’s sponsor interview is with Scott Kuffer, co-founder of Nucleus Security, and Jared Semrau of Mandiant. They’ll be joining us to talk about how you can now plug Mandiant data into the Nucleus vulnerability scan aggregator.

Links to everything that we discussed are below and you can follow Patrick, Dmitri or Adam on Twitter if that’s your thing.

Show notes

  • Ukraine foiled Russian cyberattack that tried to shut down energy grid
  • (4) Catalin Cimpanu on Twitter: "Days later... anyone managed to confirm or debunk this?" / Twitter
  • (4) Matthew Garrahan on Twitter: "Ukraine has since adapted a government app so that people can more easily upload information about Russian military positions https://t.co/oWRctXBTxU" / Twitter
  • Pipedream Malware: Feds Uncover 'Swiss Army Knife' for Industrial System Hacking | WIRED
  • Suspected Chinese hackers are targeting India's power grid
  • Lawmakers ask Energy Department to take point on sector digital security - The Record by Recorded Future
  • Threat of Russian cyberattack prompts energy firms to collaborate with U.S. government - The Washington Post
  • US says it disrupted Russian botnet 'before it could be weaponized'
  • DOJ's Sandworm operation raises questions about how far feds can go to disarm botnets
  • Microsoft seizes internet domains linked to GRU cyberattacks against Ukraine
  • WatchGuard failed to explicitly disclose critical flaw exploited by Russian hackers | Ars Technica
  • Microsoft uses court order to disrupt ZLoader botnet - The Record by Recorded Future
  • DHS investigators say they foiled cyberattack on undersea internet cable in Hawaii
  • US agency attributes $540 million Ronin hack to North Korean APT group - The Record by Recorded Future
  • Chemical sector targeted by North Korea-linked hacking group, researchers say - The Record by Recorded Future
  • U.S. offers $5 million for info on North Korean cyber operators - The Record by Recorded Future
  • Security alert: Attack campaign involving stolen OAuth user tokens issued to two third-party integrators | The GitHub Blog
  • After a brief decline, organizations once again are bombarded with ransomware - The Record by Recorded Future
  • BlackCat ransomware group claims attack on Florida International University - The Record by Recorded Future
  • North Carolina A&T hit with ransomware after ALPHV attack - The Record by Recorded Future
  • Ransomware groups go after a new target: Russian organizations - The Record by Recorded Future
  • T-Mobile Secretly Bought Its Customer Data from Hackers to Stop Leak. It Failed.
  • Experts warn of concerns around Microsoft RPC bug - The Record by Recorded Future
  • Make phishing great again. VSTO office files are the new macro nightmare? | by Daniel Schell | Apr, 2022 | Medium
  • VMware patches critical flaws in Workspace ONE Access identity management software | The Daily Swig
  • Researcher finds cryptomining malware targeting AWS Lambda - The Record by Recorded Future
  • Apple paid out $36,000 bug bounty for HTTP request smuggling flaws on core web apps – research | The Daily Swig
  • Hackers steal more than $11 million from Elephant Money DeFi platform - The Record by Recorded Future
  • WonderHero game disabled after hackers steal $320,000 in cryptocurrency - The Record by Recorded Future
  • 'We Are Fucked': Crypto Stablecoin Collapses After $182M Hack
  • The Original APT: Advanced Persistent Teenagers – Krebs on Security

View Details

Snake Oilers isn’t our regular weekly podcast, it’s a wholly sponsored series we do at Risky.Biz where vendors come on to the show to pitch their products to you, the Risky Business listener. To be clear – everyone you hear in one of these editions, paid to be here.

We’ll hear from three vendors in this edition of Snake Oilers:

  • Kevin Kennedy from Vectra talks about the company’s cloud native detection – it crunches stuff like CloudTrail and AzureAD logs and correlates it with network event information
  • Paul McCarty from SecureStack on its software composition analysis and “SBOM plus” tool
  • Google Cloud’s Anton Chuvakin talks about cloud-based SIEMs like Chronicle

Show notes

  • AI Cybersecurity - Threat Detection & Response Platform | Vectra AI
  • SecureStack - SecureStack
  • Chronicle Security - Google’s Cloud-Native SIEM Platform

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Why Spring4Shell isn’t all hype
  • How Viasat actually got owned
  • Russian war crimes likely extend to coercing sysadmis
  • Why lighter fluid and a box of matches is more effective than cyber in Belarus
  • Much, much more

This week’s sponsor interview is with Bernard Brantley, Corelight’s Chief Information Security Officer.

Corelight makes a network sensor you can use to plug in to your SIEM, among other things. It’s based on Zeek, the open source network sensor that Corelight maintains. Corelight is absolutely the industry standard for this sort of thing.

And they’ve just become the standard for something else, too: Microsoft Defender for IoT can now accept Corelight feeds. Bernard fills us in on that.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • Explaining Spring4Shell: The Internet security disaster that wasn’t | Ars Technica
  • VMware sprung by Spring4shell vulnerability - Security - iTnews
  • Viasat confirms report of wiper malware used in Ukraine cyberattack - The Record by Recorded Future
  • VIASAT incident: from speculation to technical details.
  • AcidRain | A Modem Wiper Rains Down on Europe - SentinelOne
  • EXCLUSIVE Hackers who crippled Viasat modems in Ukraine are still active- company official | Reuters
  • Kevin Collier on Twitter: "In a Zoom presser earlier today, UKR Telecom CIO Kirill Goncharuk said the hack on his ISP started with compromised credentials from an employee in a territory Russia recently occupied. Declined to address the potential implication that the employee was physically coerced." / Twitter
  • Ukrainian CERT details Russia-linked phishing attacks targeting government officials - The Record by Recorded Future
  • The Belarus ‘railway rebels’, who dare stop Vladimir Putin’s invasion in its tracks
  • German wind turbine maker shut down after cyberattack - The Record by Recorded Future
  • Hacker accessed 319 crypto- and finance-related Mailchimp accounts, company said - The Record by Recorded Future
  • Trezor cryptocurrency wallets targeted with phishing attacks following Mailchimp compromise | The Daily Swig
  • Two alleged Lapsus$ teens appear in London court
  • IT giant Globant discloses hack after Lapsus$ leaks 70GB of stolen data | Ars Technica
  • Notorious hacking group FIN7 adds ransomware to its repertoire
  • NSA employee indicted for mishandling Top Secret information - The Record by Recorded Future
  • Debate erupts at news the White House may scale back DOD cyber-ops authorities
  • Legislators rail against potential rollback of flexible DOD cyber powers
  • ‘Dangerous’ EU web authentication plan threatens to undercut browser-led certification system, detractors claim | The Daily Swig
  • Trend Micro warns of active attacks against Apex Central console | The Daily Swig
  • Apple releases fixes for two zero-days affecting Macs, iPhones and iPads - The Record by Recorded Future
  • Zyxel patches critical vulnerability that can allow Firewall and VPN hijacks | Ars Technica
  • GitLab addresses critical account hijack bug | The Daily Swig
  • Ola Finance DeFi platform hacked, nearly $5 million stolen - The Record by Recorded Future
  • Bank that lacked basic security suffers predictable fate • The Register
  • Corelight Announces Integration for Microsoft Defender for IoT as a Data Source for the Platform

View Details

Snake Oilers isn’t our regular weekly podcast, it’s a wholly sponsored series we do at Risky.Biz where vendors come on to the show to pitch their products to you, the Risky Business listener. To be clear – everyone you hear in one of these editions, paid to be here.

We’ll hear from three vendors in this edition of Snake Oilers:

  • Upskill your testers and developers with PentesterLab for US$20 a month
  • Manage penetration tests and reporting with AttackForge
  • How Sysdig can help herd your container cats (vuln management and detection for container environments)

Show notes

  • PentesterLab: Learn Web Penetration Testing: The Right Way
  • AttackForge® - Penetration Testing Workflow Management, Productivity & Collaboration Tools
  • Sysdig 2022 Cloud-Native Security and Usage Report: Stay on Top of Risks as You Scale – Sysdig

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Some arrests of suspected Lapsus$ members in the UK
  • Why the Okta incident is probably a fizzer
  • Four FSB officers indicted over Triton/Trisis malware
  • Kim Zetter interviewed Intrusion Truth
  • Australian government to upsize ASD
  • Wave bye bye to Finfisher
  • Much, much more

This week’s sponsor interview is with Mike Wiacek from Stairwell.

Stairwell makes a product that catalogues the files in your environment and lets you slice and dice that data. That makes threat hunting pretty easy and Mike is joining the show this week to talk about why organisations of all stripes should be doing threat hunting.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • Lapsus$: Oxford teen accused of being multi-millionaire cyber-criminal - BBC News
  • Okta ‘identifying and contacting’ customers potentially affected by Lapsus$ breach - The Record by Recorded Future
  • Okta revises original statement, says 366 customers affected by Lapsus$ breach - The Record by Recorded Future
  • Okta apologizes for waiting two months to notify customers of Lapsus$ breach - The Record by Recorded Future
  • Lapsus$ found a spreadsheet of accounts as they breached Okta, documents show | TechCrunch
  • DOJ unseals indictments of four Russian gov’t officials for cyberattacks on energy companies - The Record by Recorded Future
  • Four Russian Government Employees Charged in Two Historical Hacking Campaigns Targeting Critical Infrastructure Worldwide | OPA | Department of Justice
  • Intrusion Truth - Five Years of Naming and Shaming China’s Spies
  • ASD to double in size after $10bn cyber security funding boost - Security - iTnews
  • How the Biden budget goes big on cyber - The Record by Recorded Future
  • FBI, CISA advise 13,000 orgs to have 'low threshold' for reporting cyberattacks - The Record by Recorded Future
  • Senate report examines REvil ransomware attacks on US firms - The Record by Recorded Future
  • Senate ransomware investigation says FBI leaving victims in the lurch
  • Surveillance software firm FinFisher declares insolvency - The Record by Recorded Future
  • NSO refused Ukraine’s request for Pegasus spyware so it wouldn’t anger Russia - The Washington Post
  • FCC puts Kaspersky on security threat list, says it poses “unacceptable risk” | Ars Technica
  • Traffic at major Ukrainian internet service provider Ukrtelecom disrupted - The Record by Recorded Future
  • An interview with the chief technical officer at Ukrtelecom - The Record by Recorded Future
  • Hackers Gaining Power of Subpoena Via Fake “Emergency Data Requests” – Krebs on Security
  • North Korean hackers unleashed Chrome 0-day exploit on hundreds of US targets | Ars Technica
  • Google releases emergency security update for Chrome users after second 0-day of 2022 discovered - The Record by Recorded Future
  • Npm maintainers remove malicious packages after typosquatting attempt - The Record by Recorded Future
  • ‘Spam Nation’ Villain Vrublevsky Charged With Fraud – Krebs on Security
  • $2 million stolen from DeFi protocol Revest Finance, platform unable to reimburse victims - The Record by Recorded Future
  • Flash loan attack on One Ring protocol nets crypto-thief $1.4 million | The Daily Swig
  • More than $625 million stolen in DeFi hack of Ronin Network - The Record by Recorded Future
  • Hackers Who Stole $50 Million in Crypto Say They Will Refund Some Victims

View Details

Airlock Digital co-founders Daniel Schell and Dave Cottingham join host Patrick Gray to talk about:

  • What an effective allowlisting program looks like
  • Why the third party allowlisting industry failed the first time
  • What you can achieve with Microsoft tooling versus specialist tools
  • How much effort is involved to do this right

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Okta’s somewhat awful comms around its LAPSUS$ incident
  • Inside Microsoft’s brush with the same group
  • How Elon Musk’s Starlink service is being used to drop bombs on Russian tanks
  • US, UK governments warn of impending Russian cyberdoom
  • Much, much more…

This week’s sponsor interview is with Paul Lanzi, co-founder of Remediant. Paul joins the show this week to talk about cyber insurance. It’s a topic that has come up a lot for us lately – ransomware has borderline sunk the current cyber insurance model as payments ballooned and payouts made a lot of insurers adjust premiums to the. But all is not lost – Paul says this blowup means the insurance industry is actually adapting and could wind up being a driver of better security practices.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • Hackers hit authentication firm Okta, customers 'may have been impacted' | Reuters
  • Updated Okta Statement on LAPSUS$ | Okta
  • Microsoft investigating Lapsus$ claims of Bing, Cortana data theft - The Record by Recorded Future
  • DEV-0537 criminal actor targeting organizations for data exfiltration and destruction - Microsoft Security Blog
  • U.K. echoes Biden warning on Russian cyberattacks - The Record by Recorded Future
  • Statement by President Biden on our Nation’s Cybersecurity | The White House
  • FBI advised that hackers scanned networks of 5 US energy firms ahead of Biden's Russia cyberattack warning - CNNPolitics
  • CISA, FBI warn of satellite network hacks following Viasat cyberattack - The Record by Recorded Future
  • Specialist Ukrainian drone unit picks off invading Russian forces as they sleep | News | The Times
  • China’s DJI And Its Billionaire Chief Put In An Awkward Spot As Both Sides In Ukraine War Use Its Drones
  • Alert: peacenotwar module sabotages npm developers in the node-ipc package to protest the invasion of Ukraine | Snyk
  • Catalin Cimpanu on Twitter: "Following the poisoning of the node-ipc npm package to sabotage systems in Belarus and Russia, Russia's NKTsKI cyber-security agency has told companies to use local repos for FOSS software, use older versions prior to the invasion, and audit new updates https://t.co/3PlKdXTfn1 https://t.co/EV25HBBZFN" / Twitter
  • U.S. bars ex-spies from becoming 'mercenaries,' following Reuters series | Reuters
  • Behold, a password phishing site that can trick even savvy users | Ars Technica
  • Death of the Password? FIDO Alliance Reveals Its New Plan | WIRED
  • Scammers have 2 clever new ways to install malicious apps on iOS devices | Ars Technica
  • New details emerge on prolific Conti-linked cybercrime group
  • Trickbot is using MikroTik routers to ply its trade. Now we know why | Ars Technica
  • Sandworm-linked botnet has another piece of hardware in its sights
  • Hacker Steals Customer Data From Circle, BlockFi, Other Big Crypto Firms - Decrypt
  • Lawmakers Probe Early Release of Top RU Cybercrook – Krebs on Security
  • A different way to do PAM -- Paul Lanzi, Remediant - YouTube

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Germany issues stark warning to Kaspersky users
  • Ukraine SATCOM hack keeps getting more interesting
  • Russia to spin up its own CA, but it’s not what it seems
  • Why the ransomware threat could get worse, then better
  • Much, much more

This week’s show is brought to you by Fastly. Kelly Shortridge, Fastly’s Senior Principal Product Technologist, joins the show this week to tell us what modern security actually looks like. Kelly is always fascinating so we were thrilled she was in the sponsor chair this week.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • German government issues warning about Kaspersky products - CyberScoop
  • Exclusive: U.S. spy agency probes sabotage of satellite internet during Russian invasion, sources say | Reuters
  • SATELLITE SYSTEMS, SATCOM AND SPACE SYSTEMS UPDATE
  • Russia to create its own security certificate authority, alarming experts
  • Political fallout in cybercrime circles upping the threat to Western targets
  • (2) Oleg Shakirov on Twitter: "Russia's deputy foreign minister says he hopes the Russian-U.S. dialogue on cyber security will be resumed in response to a question whether it has been frozen He adds that it can bring tangible results like the disruption of REvil https://t.co/m817WD80vr" / Twitter
  • FinCEN warns ransomware proceeds could be part of Russia sanctions evasion
  • Biden takes big step toward government-backed digital currency
  • Ukrainian hackers say HackerOne is blocking their bug bounty payouts | TechCrunch
  • (2) Techmeme on Twitter: "Sources: Apple and Google removed Kremlin critic Navalny's app in September after FSB agents came to homes of top execs and threatened to take them to prison (Washington Post) https://t.co/nqvtHmG1Ft https://t.co/gQCcnFhnyo" / Twitter
  • Government agencies in Ukraine targeted in cyber-attacks deploying MicroBackdoor malware | The Daily Swig
  • (2) ESET research on Twitter: "#BREAKING #ESETresearch warns about the discovery of a 3rd destructive wiper deployed in Ukraine 🇺🇦. We first observed this new malware we call #CaddyWiper today around 9h38 UTC. 1/7 https://t.co/gVzzlT6AzN" / Twitter
  • Ukraine facing major regional internet outages as Russian invasion continues
  • Transparency Org Releases Alleged Leak of Russian Censorship Agency
  • Denial-of-service attack knocked Israeli government sites offline
  • The Lapsus$ Hacking Group Is Off to a Chaotic Start | WIRED
  • Penny Arcade - Comic - Also Known As Blackmail
  • Man charged with Kaseya hack extradited to the US - The Record by Recorded Future
  • NetWalker ransomware affiliate extradited to the US - The Record by Recorded Future
  • Researcher uses Dirty Pipe exploit to fully root a Pixel 6 Pro and Samsung S22 | Ars Technica
  • New method that amplifies DDoSes by 4 billion-fold. What could go wrong? | Ars Technica
  • SEC weighs reporting requirements for publicly traded companies
  • Biden signs cyber incident reporting bill into law - The Record by Recorded Future
  • Join The Dept of Know_ Live!
  • BAYRAKTAR-Official Song (english) - YouTube
  • Product Demo: Proofpoint Nexus People Explorer - YouTube

View Details

On this week’s show Patrick Gray, Brian Krebs and Adam Boileau discuss the week’s security news, including:

  • The Contileaks latest
  • Belarus targeted refugee data. Was it behind the ICRC hack?
  • How APT41 hacked America’s livestock
  • SATCOM hack in Ukraine may bode ill for Musk
  • Much, much more

Material Security’s co-founder Ryan Noon is this week’s sponsor guest. He joins the show to talk about a few things, how the building blocks for a whole new generation of security tooling – like large-scale data crunching tech – is now just available off the shelf. He also talks us through an integration Material has done with a groovy new SOAR platform called Tines.

Links to everything we discussed – and a YouTube demo of Material’s technology – are below.

Show notes

  • Conti Ransomware Group Diaries, Part I: Evasion – Krebs on Security
  • Conti Ransomware Group Diaries, Part II: The Office – Krebs on Security
  • Conti Ransomware Group Diaries, Part III: Weaponry – Krebs on Security
  • Conti Ransomware Group Diaries, Part IV: Cryptocrime – Krebs on Security
  • Christo Grozev on Twitter: "This is not the worst part. In the phone call in which the FSB officer assigned to the 41st Army reports the death to his boss in Tula, he says they've lost all secure communications. Thus the phone call using a local sim card. Thus the intercept. https://t.co/cgHHo7VaRi" / Twitter
  • Cloudflare not fully backing out of Russia, company says, as tech firms are forced to weigh in - CyberScoop
  • NATO countries' refugee management may have been targeted by Belarus-linked hackers - CyberScoop
  • Twitter Launches Tor Onion Service Making Site Easier to Access in Russia
  • Hive ransomware gang targets Romanian oil firm in its latest cyberattack - The Record by Recorded Future
  • Chinese Spies Hacked a Livestock App to Breach US State Networks | WIRED
  • Christophe on Twitter: "Casually compromising API keys from Azure customers: - Step 1: Create an Azure automation account - Step 2: curl localhost on ports 40000+ You now have an API token in the Azure tenant of another customer, with the same permissions as the automation🙈 https://t.co/XRI99mCJ1T" / Twitter
  • Google WAF bypassed via oversized POST requests | The Daily Swig
  • DDoSers are using a potent new method to deliver attacks of unthinkable size | Ars Technica
  • SATCOM terminals under attack in Europe: a plausible analysis.
  • The internet in Ukraine is still mostly online. Could Starlink be a backup if it goes out? - The Record by Recorded Future
  • Linux has been bitten by its most high-severity vulnerability in years | Ars Technica
  • Google to acquire Mandiant in $5.4 billion deal - The Record by Recorded Future
  • Senate approves cyber incident reporting bill amid worries about Russian threats - The Record by Recorded Future
  • Cyber insurance policies may be put to the test by Russian attacks, credit ratings firm warns - The Record by Recorded Future
  • Material Security: Keeping email safe at rest (improved audio) - YouTube
  • Risky Biz Product Demos - YouTube

View Details

On this week’s show Patrick Gray, Dmitri Alperovitch and Adam Boileau discuss the week’s security news, including:

  • We expected a cyberwar but got an information war
  • People with SDR kits are doing SIGINT in Ukraine
  • Conti has imploded and it’s hilarious
  • Much, much more

This week’s show is brought to you by Proofpoint. Sherrod DeGrippo, Proofpoint’s Vice President of Threat Research and Detection is this week’s sponsor guest. She joins us to talk about how there isn’t really any magic advice she can dispense to protect customers from Russian attacks.

There are some show notes below, but they’re not exhaustive.

Show notes

  • The propaganda war has eclipsed cyberwar in Ukraine | MIT Technology Review
  • Ukrainian Researcher Leaks Conti Ransomware Gang Data
  • Signal on Twitter: "We've had an uptick in usage in Eastern Europe & rumors are circulating that Signal is hacked & compromised. This is false. Signal is not hacked. We believe these rumors are part of a coordinated misinformation campaign meant to encourage people to use less secure alternatives." / Twitter
  • Cyber insurance policies may be put to the test by Russian attacks, credit ratings firm warns - The Record by Recorded Future
  • Phishing campaign targets European officials assisting in refugee operations - The Record by Recorded Future
  • https://twitter.com/sbreakintl/status/1498619303717142529?s=21
  • Apple halts sales of products to Russia, restricts access to Russian news apps
  • Belarusian hackers launch another attack, adding to chaotic hacktivist activity around Ukraine - CyberScoop
  • Russian State Media Hacked to Show Casualty Numbers for Russian Soldiers in Ukraine War
  • Would Banning Russia From Getting Software Updates Make It Easier to Hack?
  • Ukraine’s Volunteer ‘IT Army’ Is Hacking in Uncharted Territory | WIRED
  • vx-underground on Twitter: "Conti ransomware group previously put out a message siding with the Russian government. Today a Conti member has begun leaking data with the message "Fuck the Russian government, Glory to Ukraine!" You can download the leaked Conti data here: https://t.co/BDzHQU5mgw https://t.co/AL7BXnihza" / Twitter
  • Active Measures, LLC on Twitter: "That keyboard sound you hear is lawyers at US CYBERCOMMAND updating some opinions." / Twitter
  • Conti ransomware gang chats leaked by pro-Ukraine member - The Record by Recorded Future
  • Russia appears to deploy digital defenses after DDoS attacks - The Record by Recorded Future
  • Russia’s Sandworm Hackers Have Built a Botnet of Firewalls | WIRED
  • Auth0 co-founder and CEO Eugenio Pace walks us through the Auth0 platform - YouTube
  • Dmitri Alperovitch on Twitter: "In the last few weeks, I have become increasingly convinced that Kremlin has unfortunately made a decision to invade Ukraine later this winter. While it is still possible for Putin to deescalate, I believe the likelihood is now quite low. Allow me to explain why 🧵" / Twitter

View Details

These Soap Box editions of the show are entirely sponsored – that means everyone you hear in one of these episodes paid to be here.

In this edition we’re talking to Yubico’s Chief Solutions Officer Jerrod Chong. We do one of these Soap Box podcasts with Jerrod every year. Yubico, of course, is the maker of the Yubikey hardware security device.

In this chat with Jerrod we cover a few things – like the zero trust executive order, hardware-backed web transactions and how the industry leading the charge on security keys right now is actually the cryptocurrency space.

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Ukraine sanctions may lead to Russia going “cyber feral”
  • Brian Krebs links Red Cross breach to Iranian actor
  • APT10 uses cred stuffing as misdirection
  • Report: Global logistics behemoth Expeditors ransomwared
  • NFT thefts still hilarious
  • Inside the epic KlaySwap hack
  • Much, much more

In this week’s sponsor interview Thinkst Canary’s Marco Slaviero talks about some work they’ve done on introducing a “Safety Net” against AWS token enumeration edge cases. That’s a very interesting interview.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • White House attributes Ukraine DDoS incidents to Russia's GRU - CyberScoop
  • U.S. issues blanket warning on potential of destructive Russian hacks
  • Russian hackers have probably penetrated critical Ukraine computer networks, U.S. says - The Washington Post
  • Ukraine dismantles social media bot farm spreading "panic" - The Record by Recorded Future
  • US says Russian hackers breached multiple DOD contractors - The Record by Recorded Future
  • Red Cross blames hack on Zoho vulnerability, suspects APT attack - The Record by Recorded Future
  • Red Cross Hack Linked to Iranian Influence Operation? – Krebs on Security
  • Deep dive into hack against Iranian state TV yields wiper malware, other custom tools
  • VMware Horizon servers are under active exploit by Iranian state hackers | Ars Technica
  • Chinese hackers linked to months-long attack on Taiwanese financial sector - The Record by Recorded Future
  • San Francisco 49ers confirm ransomware attack - The Record by Recorded Future
  • Global logistics giant Expeditors suffers cyberattack, shuts down operations systems - FreightWaves
  • Vodafone Portugal struggles to restore service following cyberattack | Ars Technica
  • The US Crackdown on Spyware Vendors Is Only Beginning
  • People Whose NFTs Were Stolen Are Getting Wildly Different Refunds from OpenSea
  • Scam artists swindle NFTs worth 'millions' in OpenSea phishing attack | ZDNet
  • KlaySwap crypto users lose funds after BGP hijack - The Record by Recorded Future
  • Jaw-dropping Coinbase security bug allowed users to steal unlimited cryptocurrency | The Daily Swig
  • For signs of cryptocurrency laundering, look closely at Moscow firms, report says
  • Srsly Risky Biz: Thursday February 17
  • More data on Canadian 'Freedom Convoy' donors leaked -website | Reuters
  • Stream Episode 179: Truck Yeah, Canada feat Dan Boeckner by QAnon Anonymous | Listen online for free on SoundCloud
  • FBI sees increase in use of virtual meeting platforms for BEC scams - The Record by Recorded Future
  • This Is the ‘Hacking’ Investigation Into Journalist Who Clicked ‘View Source’ on Government Website
  • Bhima Koregaon case: New report finds activist Rona Wilson was targeted by hackers linked to cyber espionage - The Washington Post
  • Thousands of npm accounts use email addresses with expired domains - The Record by Recorded Future
  • EARN IT Act gets no changes to encryption language in Senate committee
  • SEC's breach notification proposal one step closer to a final vote
  • In touch with Reality Winner - The Record by Recorded Future
  • A “Safety Net” for AWS Canarytokens

View Details

There is no weekly news show this week. Instead, we’re running this feature interview with Michael Montoya, the CISO of Equinix. This isn’t a sponsored interview or anything like that, this podcast was prepared with support from the Hewlett Foundation’s Cyber Initiative.

Equinix has 9,000 staff and operates 220 data centres globally. Its annual revenue is in the order of USD$6bn. In September 2020 it was attacked by criminals who deployed the Netwalker ransomware on its corporate network. The attackers demanded a USD$4.5m ransom payment for service restoration and to keep the data they stole from the company private.

This interview has taken a while to organise, but when I first found out Michael was open to the idea of talking through the incident I jumped at it. It’s extremely rare for CISOs to be made available to talk about events like this, but it’s something that should happen more often. We can learn a lot by dissecting these types of incidents publicly. Enjoy!

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • A spate of ransomware attacks on European energy and transport
  • Russian authorities extend cybercrime crackdown
  • Irritating influencers arrested for laundering 2016 Bitfinex hack proceeds
  • IRS abandons ID.me trial
  • Microsoft disables macros by default, disables MSIX protocol handler
  • Much, much more

This week’s show is brought to you by ExtraHop.

Extrahop’s Ted Driggs is this week’s sponsor guest – he was on the show about a year ago talking about how we should really start thinking about putting together software bills of behaviours as well as bills of material. Ted is back to tell us how that effort is progressing. As you’ll hear, a lot of the behavioural data on software already exists, but it’s being hoarded by different vendors.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • Ransomware spree hitting European oil, transport companies
  • String of cyberattacks on European oil and chemical sectors likely not coordinated, officials say - The Record by Recorded Future
  • Weeks after a ransomware attack, some workers still worry about paychecks
  • Russian government continues crackdown on cybercriminals
  • Cyberattack brings down Vodafone Portugal mobile, voice, and TV services - The Record by Recorded Future
  • An ALPHV (BlackCat) representative discusses the group’s plans for a ransomware ‘meta-universe’ - The Record by Recorded Future
  • DOJ seizes $3.6 billion from 2016 Bitfinex hack, arrests New York couple - The Record by Recorded Future
  • Woman Who Allegedly Laundered $1B in Bitcoin Was Cringe YouTube Rapper
  • NetWalker ransomware affiliate sentenced to seven years in prison - The Record by Recorded Future
  • IRS abandons plans to use third-party facial recognition
  • DHS assembles Cyber Safety Review Board to imitate fed agency that studies aviation accidents
  • Senate lawmakers try again on cyber incident reporting legislation - The Record by Recorded Future
  • Microsoft temporarily disables MSIX protocol handler following malware abuse - The Record by Recorded Future
  • Microsoft to block internet macros by default in five Office applications - The Record by Recorded Future
  • Microsoft says MFA adoption remains low, only 22% among enterprise customers - The Record by Recorded Future
  • Google Cloud adds new cryptomining threat detection capability - The Record by Recorded Future
  • News Corp. says Wall Street Journal, New York Post were targeted by hackers
  • European governments targeted by Chinese hackers with a Zimbra webmail zero-day - The Record by Recorded Future
  • Palestinian hacking group evolving with new malware, researchers say
  • State Department sounds alarm over Red Cross breach
  • State Department offers $10M for information on Iranian election interference
  • Iran's national TV stream hacked for the second time in a week - The Record by Recorded Future
  • Open Source Security Foundation launches new initiative to stem the tide of software supply chain attacks | The Daily Swig
  • The Apache Log4j team talks about the Log4Shell patching process - The Record by Recorded Future
  • npm enrolls Top 100 package maintainers into mandatory 2FA - The Record by Recorded Future
  • Target open-sources its web skimmer detector - The Record by Recorded Future
  • North Korea Hacked Him. So He Took Down Its Internet | WIRED
  • Cryptocurrency platform Wormhole hacked for an estimated $322 million - The Record by Recorded Future

View Details

These soap box podcasts are wholly sponsored – that means everyone you hear in one of these editions paid to be here. Today’s guest is Andrew Morris, the founder and CEO of Greynoise.

Greynoise is one of those companies that has a brief that sounds simple but is actually quite hard to execute on. They detect malicious mass scanning on the Internet so their customers can plug that data into their SOC to see if the IP they just got an alert on is something targeting them or something targeting the whole internet.

You don’t even need to be a customer to get some use out of Greynoise. If you want to know about an IP you’ve seen an alert for just head over to greynoise.io and drop it into the search box – magic awaits.

Greynoise makes its money by selling API access to its service, basically, and its customers mostly use it for SIEM enrichment. But as you’ll hear, Andrew says the company is looking at moving toward actually blocking this type of mass scanning from hitting customer environments, and is even looking at working with telcos to scrub the most egregious stuff from the internet entirely. His rationale is actually pretty simple – he wants to narrow the aperture through which mass scanning can fit through. He wants to make it harder.

But this interview isn’t just about what Greynoise doing, it’s also about the current state of mass scanning.

View Details

On this week’s show Patrick Gray, Tom Uren and Joe Slowik discuss the week’s security news, including:

  • Why China’s Olympics app is probably not spyware
  • New DDoS record set at 3.47Tbps
  • USG goes all in on Zero Trust
  • Dmitry Medvedev makes all the right noises on ransomware cooperation
  • Iranian APT crew dabbles in ransomware
  • German fuel distribution ransomwared
  • The latest on NSO
  • Much, much more

This week’s show is brought to you by Google Cloud. Anton Chuvakin, the head of security solution strategy at Google Cloud will be along in this week’s sponsor interview to talk about why SIEM vendors – including Google Cloud – are gobbling up SOAR platforms in acquisitions.

Links to everything that we discussed are below and you can follow Patrick, Tom or Joeon Twitter if that’s your thing.

Show notes

  • The surveillance concerns around China’s Winter Olympics app – explained | Surveillance | The Guardian
  • Cross-Country Exposure: Analysis of the MY2022 Olympics App - The Citizen Lab
  • Wiper in Ukraine Used Code Repurposed From WhiteBlackCrypt Ransomware
  • German government warns of APT27 activity targeting local companies - The Record by Recorded Future
  • Microsoft fends off record-breaking 3.47Tbps DDoS attack | Ars Technica
  • White House releases final zero-trust strategy for federal government - The Record by Recorded Future
  • White House expands digital regulations for U.S. water supply
  • Conti ransomware hits Apple, Tesla supplier - The Record by Recorded Future
  • Top Russian official cites REvil arrests as sign of cooperation, says Moscow is awaiting reciprocation
  • Совет Безопасности Российской Федерации
  • Major German fuel storage provider hit with cyberattack, working under limited operations
  • Iranian state-sponsored group APT35 linked to Memento ransomware - The Record by Recorded Future
  • Deadbolt ransomware hits more than 3,600 QNAP NAS devices - The Record by Recorded Future
  • QNAP warns NAS users of DeadBolt ransomware, urges customers to update | ZDNet
  • Unpacking the rise of BlackCat ransomware: High victim count, high payouts, customized features
  • Ransomware group says it took files from French Ministry of Justice
  • Cybercriminals laundered $8.6 billion worth of cryptocurrency in 2021 - The Record by Recorded Future
  • DeepDotWeb co-admin sentenced to 8 years in prison - The Record by Recorded Future
  • Booby-trapped sites delivered potent new backdoor trojan to macOS users | Ars Technica
  • Apple pays out $100k bounty for Safari webcam hack that imperiled victims’ online accounts | The Daily Swig
  • Qubit Finance platform hacked for $80 million worth of cryptocurrency - The Record by Recorded Future
  • Android malware will factory-reset a phone after stealing a user's funds - The Record by Recorded Future
  • 2FA app with 10,000 Google Play downloads loaded well-known banking trojan | Ars Technica
  • Threat actor target Ubiquiti network appliances using Log4Shell exploits - The Record by Recorded Future
  • Finland says it found NSO's Pegasus spyware on diplomats' phones - The Record by Recorded Future
  • NSO offered US mobile security firm ‘bags of cash’, whistleblower claims | Surveillance | The Guardian
  • The Battle for the World’s Most Powerful Cyberweapon - The New York Times

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Belarusian Cyber Partisans ransom train network
  • A look at developments in Ukraine
  • Merck wins NotPetya insurance lawsuit
  • US VC firm in talks to acquire NSO Group
  • Much, much more

This week’s show is brought to you by Trail of Bits, the security engineering firm. Dan Guido joins us this week week to talk about zkdocs, a bunch of documentation Trail of Bits put together to provide guidance on how to implement some of these newfangled concepts – like zero knowledge proofs – that are popular in blockchain and cryptoland.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • Hactivists say they hacked Belarus rail system to stop Russian military buildup | Ars Technica
  • A top Ukrainian security official on defending the nation against cyber attacks - The Record by Recorded Future
  • Former Ukrainian official sanctioned for assisting Russian cyberattacks - The Record by Recorded Future
  • FSB detains administrator of UniCC carding forum - The Record by Recorded Future
  • Opinion | Russia’s takedown of REvil hacking collective sends an ominous message - The Washington Post
  • Merck wins cyber-insurance lawsuit related to NotPetya attack - The Record by Recorded Future
  • Canada confirms cyber-attack on foreign affairs ministry - The Record by Recorded Future
  • (1) Global Affairs Canada suffers ‘cyber attack’ amid Russia-Ukraine tensions: sources - National | Globalnews.ca
  • U.S. venture capital firm in talks to buy Israel's infamous spyware maker NSO - Business - Haaretz.com
  • Red Cross begs hackers not to leak data of "highly vulnerable people" - The Record by Recorded Future
  • Assange permitted to file U.K. Supreme Court appeal in extradition case
  • New MoonBounce UEFI bootkit can't be removed by replacing the hard drive - The Record by Recorded Future
  • Sketchy ‘Account Recovery’ Services Are Trying to Scam Hacking Victims on Twitter
  • A UK government-backed campaign aims to thwart end-to-end encryption rollout - The Record by Recorded Future
  • UK government plans to release Nmap scripts for finding vulnerabilities - The Record by Recorded Future
  • OpenSubtitles discloses successful extortion attempt, data breach - The Record by Recorded Future
  • IRS Will Soon Require Selfies for Online Access – Krebs on Security
  • New Log4j attacks target SolarWinds, ZyXEL devices - The Record by Recorded Future
  • Supply chain attack used legitimate WordPress add-ons to backdoor sites | Ars Technica
  • https://www.qualys.com/2022/01/25/cve-2021-4034/pwnkit.txt
  • GitHub Actions flaw that allowed code to be approved without review is addressed with new feature rollout | The Daily Swig
  • ‘Zero-Click’ Zoom Vulnerabilities Could Have Exposed Calls | WIRED
  • Flaws in third-party software exposed dozens of Teslas to remote access | TechCrunch
  • Dark Souls servers taken down following discovery of critical vulnerability | Ars Technica
  • F5 fixes high-risk NGINX Controller vulnerability in January patch rollout | The Daily Swig
  • RCE bug chain patched in CentOS Web Panel | The Daily Swig
  • Chain of vulnerabilities led to RCE on Cisco Prime servers | The Daily Swig
  • People Can’t See Some NFTs on Twitter, Crypto Wallets After OpenSea Goes Down
  • Hacker abuses OpenSea to buy NFTs at older, cheaper prices - The Record by Recorded Future
  • Crypto.com finally confirms major hack, says it lost $34 million - The Record by Recorded Future
  • A Hacker Is Negotiating With Victims on the Blockchain After $1.4M Heist
  • ‘White Hat’ Hacker Returns $1 Million Stolen In Crypto Theft Disaster
  • Pirates Spammed an Infamous Soviet Short-wave Radio Station with Memes
  • Introduction | ZKDocs
  • Trail of Bits | Careers

View Details

On this week’s show Patrick Gray, Adam Boileau and Dmitri Alperovitch discuss the week’s security news, including:

  • Russia arrests REvil crew
  • Ukraine government hit in messy hacks
  • White House hosts open source pow-wow, but is it pointless?
  • US cyber reporting law will come back from the dead
  • Report: Israeli police targeted activists with NSO but without warrants
  • Much, much more

This week’s sponsor interview is with HD Moore, the founder of Rumble. We’re talking through what how he and his team helped customers respond to the log4j drama. They quickly added the capability to scan customer’s environments for log4shell-affected tech. When asset discovery meets rapid vuln response!

Links to everything that we discussed are below and you can follow Patrick, Dmitri or Adam on Twitter if that’s your thing.

Show notes

  • Russia arrests ransomware gang responsible for high-profile cyberattacks
  • Celebrations over REvil ransomware arrests in Russia may be premature | The Daily Swig
  • Ransomware gang behind attacks on 50 companies arrested in Ukraine - The Record by Recorded Future
  • Europol takes down VPNLab, a service used by ransomware gangs - The Record by Recorded Future
  • Albuquerque schools are having a cybersecurity snow day—and they aren't alone - The Record by Recorded Future
  • What We Know and Don’t Know about the Cyberattacks Against Ukraine - (updated)
  • Dozens of Computers in Ukraine Wiped with Destructive Malware in Coordinated Attack
  • Belarus: Cyber upstart, or Russian staging ground?
  • White House hosts open-source software security summit in light of expansive Log4j flaw
  • Apache Software Foundation warns its patching efforts are being undercut by use of end-of-life software | The Daily Swig
  • GitLab shifts left to patch high-impact vulnerabilities | The Daily Swig
  • Cyber incident reporting backers pledge to resume push - The Record by Recorded Future
  • Israeli police used spyware to hack its own citizens, a report says : NPR
  • El Salvador journalists hacked with NSO's Pegasus spyware - The Record by Recorded Future
  • Cyber Command ties hacking group to Iranian intelligence - The Record by Recorded Future
  • Earth Lusca threat actor targets governments and cryptocurrency companies alike - The Record by Recorded Future
  • North Korea stole a record $400 million in cryptocurrency last year, researchers say
  • Crypto.com Says Alleged $15 Million Hack Was Just an 'Incident'
  • Who is the Network Access Broker ‘Wazawaka?’ – Krebs on Security
  • New Chrome security measure aims to curtail an entire class of Web attack | Ars Technica
  • EA blames support staff for recent hacks of high-profile FIFA accounts - The Record by Recorded Future
  • Researchers discover ‘extremely easy’ 2FA bypass in Box cloud management software | The Daily Swig
  • Introducing vAPI – an open source lab environment to learn about API security | The Daily Swig

View Details

In this edition of the soap box we’re chatting with Steve Miller, a senior researcher at Stairwell. Steve has a long history doing this sort of stuff. He worked inside various bits of the US government doing cyber things, and also spent a decent chunk of his career at Mandiant.

His new employer, Stairwell, makes a platform that collects information about all files present in your environment and let’s you do some fancy stuff with that information. You’ll hear a little bit more about what they do in this interview, but we’re not really talking that much about Stairwell in this interview. It’s more about the evolution of threat intel.

As you’ll hear, Steve said the first iteration of the commercial threat intel space was very much born of govvies jumping out and bringing their thinking with them, but the space is evolving. The take away from this interview is that threat intelligence is more something that you do, not something you just blindly consume.

View Details

On this week’s show Patrick Gray, Katie Nickels and Joe Slowik discuss the week’s security news, including:

  • US Government warns of impending critical infrastructure hacks
  • Log4j bug in VMWare gets a workout
  • Ex Uber CSO Joe Sullivan facing wire fraud charges
  • Signal to push ahead on cryptocurrency payments
  • Italian literary nerd busted for running one man APT operation
  • Much, much more

This week’s show is brought to you by Okta. Marc Rogers is the executive director of cybersecurity there and he’s joining us this week to talk about the log4j bug and some adjacent issues. He’s working on a paper with IST about the bug and what it all means, and he’s joining us this week to talk about why the log4j drama was different.

Links to everything that we discussed are below and you can follow Katie, Joe or Patrick on Twitter if that’s your thing.

Show notes

  • US warns of Russian state-sponsored attacks on critical infrastructure - The Record by Recorded Future
  • UK NHS: Threat actor targets VMware Horizon servers using Log4Shell exploits - The Record by Recorded Future
  • Suspected Chinese hackers use Log4j flaw to deploy Night Sky ransomware, Microsoft warns
  • CISA director: Log4Shell has not resulted in 'significant' government intrusions yet - The Record by Recorded Future
  • Researchers discover Log4j-like flaw in H2 database console | The Daily Swig
  • Prosecutors file additional charges against former Uber security chief over 2016 data breach ‘cover up’ | The Daily Swig
  • Signal's Cryptocurrency Feature Has Gone Worldwide | WIRED
  • Alex Stamos on Twitter: "I'm glad that @CaseyNewton wrote about the legal risks of marrying E2EE with hard-to-trace money transmission and I was glad to talk to him. I think @signalapp is underestimating the legal attack surface they are opening up here. https://t.co/qx3qzwd6mk" / Twitter
  • Signal >> Blog >> New year, new CEO
  • Deposits to illicit crypto addresses nearly doubled in 2021, Chainalysis finds
  • Italian man arrested for stealing unpublished book manuscripts - The Record by Recorded Future
  • Activision Sues and Unmasks Alleged 'Call of Duty: Warzone' Cheat Sellers
  • FBI: FIN7 hackers target US companies with BadUSB devices to install ransomware - The Record by Recorded Future
  • Threat actors can simulate iPhone reboots and keep iOS malware on a device - The Record by Recorded Future
  • SOHO routers impacted by bug in USB-over-network component - The Record by Recorded Future
  • Google Docs commenting feature abused in phishing operations - The Record by Recorded Future
  • Coming to a laptop near you: A new type of security chip from Microsoft | Ars Technica
  • SFile (Escal) ransomware ported for Linux attacks - The Record by Recorded Future
  • FinalSite discloses ransomware attack that crippled websites for 8,000 schools - The Record by Recorded Future
  • Albuquerque impacted by ransomware attack on Bernalillo County government - The Record by Recorded Future
  • Hotel chain switches to Chrome OS to recover from ransomware attack - The Record by Recorded Future
  • Moxie Marlinspike >> Blog >> My first impressions of web3

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • The log4j bug wrap
  • The ransomware wrap
  • The human rights and surveillance industry wrap
  • Research and carnage wrap

This week’s show is brought to you by Airlock Digital. They make allowlisting software that has mostly been used in Windows environments, but as you’re about to hear they’ve now got a very, very nice solution for the bigger Linux distros, and their Mac agent is going to be launched in a few weeks.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • FTC warns companies to remediate Log4j security vulnerability | Federal Trade Commission
  • Srsly Risky Biz: Thursday December 16
  • The internet runs on free open-source software. Who pays to fix it? | MIT Technology Review
  • Propane distributor Superior Plus admits ransomware breach | The Daily Swig
  • Ransomware attack threatens paychecks just before Christmas
  • Cyberattack on one of Norway’s largest media companies shuts down presses - The Record by Recorded Future
  • Photography site Shutterfly is dealing with a ransomware attack - CyberScoop
  • Lapsus$ ransomware gang hits SIC, Portugal's largest TV channel - The Record by Recorded Future
  • US food importer Atalanta admits ransomware attack | The Daily Swig
  • The FBI believes the HelloKitty ransomware gang operates out of Ukraine - The Record by Recorded Future
  • Ransomware affiliate arrested in Romania - The Record by Recorded Future
  • Iranian hackers behind Cox Media Group ransomware attack - The Record by Recorded Future
  • Israeli newspaper Jerusalem Post is hacked, website defaced to include threats
  • Iranian Hackers Abuse Slack For Cyber Spying
  • Why Wall Street is worried about state and local government cybersecurity - The Record by Recorded Future
  • North Korean hackers target Russian diplomats using New Year greetings - The Record by Recorded Future
  • Egyptian Politician Hacked by 2 Government Hacking Groups, Researchers Say
  • Saudi women's rights activist says phone hack by U.S. contractors led to arrest -lawsuit | Reuters
  • UAE agency put Pegasus spyware on the phone of Hanan Elatr, Jamal Khashoggi’s wife - Washington Post
  • A new spyware-for-hire, Predator, caught hacking phones of politicians and journalists | TechCrunch
  • Facebook says 50,000 users were targeted by cyber mercenary firms in 2021 | MIT Technology Review
  • Encrypted Phone Company Backdoored by FBI Will Lead to 'Years' of Arrests
  • Russian hackers bypass 2FA by annoying victims with repeated push notifications - The Record by Recorded Future
  • More than 1,200 phishing toolkits capable of intercepting 2FA detected in the wild - The Record by Recorded Future
  • Facebook expands bug bounty program to cover scraping attacks - The Record by Recorded Future
  • Wireless coexistence – New attack technique exploits Bluetooth, WiFi performance features for ‘inter-chip privilege escalation’ | The Daily Swig
  • Microsoft notifies customers of Azure bug that exposed their source code - The Record by Recorded Future
  • US charges former GRU officer with hacking and stock market trading scheme - The Record by Recorded Future
  • Crypto exchanges keep getting hacked, and there's little anyone can do
  • CISA tells agencies to patch recent Windows 10 zero-day abused by Emotet botnet - The Record by Recorded Future
  • Security flaws found in a popular guest Wi-Fi system used in hundreds of hotels | TechCrunch
  • Backdoor gives hackers complete control over federal agency network | Ars Technica
  • Microsoft fixes harebrained Y2K22 Exchange bug that disrupted email worldwide | Ars Technica

View Details

This isn’t the normal weekly news episode of the show, if you’re looking for the regular weekly Risky Business podcast, scroll one back in your podcast feed. This is a Soap Box edition, a wholly sponsored podcast brought to you in this instance by Thinkst Canary.

For those who don’t know, Thinkst makes hardware and virtual honeypots you can put on your network or into your cloud environments – they’ll start chirping if an attacker interacts with them. They’re a low cost and extremely effective detection tool. But you might not know that Thinkst also operates canarytokens.org where you can go set up a bunch of honeytokens for free. Hundreds of thousands of people are using canarytokens.org, but Thinkst doesn’t charge anything for it, it’s free to use. They’ll even give you a docker container of the whole thing so you can run it yourself.

Our guest today is Thinkst’s founder and infosec legend Haroon Meer. He spent a chunk of his career at the South African security consultancy SensePost before founding Thinkst Applied Research and eventually launching Canary.Tools. In this interview we talk about what the industry is getting wrong, supply chain security, effective detections and more. But I started off by asking him why Thinkst hasn’t tried to monetise canarytokens.org given how many people use it.

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • NSO Group tools found on US embassy staff phones in Uganda
  • Mitto is up to shady bidnez
  • Ubiquiti “whistleblower” charged over hack
  • Hounds everywhere
  • Planned Parenthood breached
  • Much, much more

This week’s sponsor interview is with Andrew Morris of Greynoise.

Greynoise has a bunch of sensors out there on the Internets, so they can tell you when and IP that’s hitting you is also hitting everyone else. If you work in a SOC, you know this is very useful. Greynoise has just signed a $30m deal with the US Department of Defense. As Andrew will explain in just a moment, this means if you work in a DoD agency it’s now very easy for you to get a subscription. In this interview I also talk to Andrew about his adventures chasing down one of the people spamming Internet attached receipt printers with the antiwork manifesto from Reddit.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • NSO Pegasus spyware used to hack U.S. diplomats’ phones - The Washington Post
  • This Swiss Firm Exec Is Said To Have Operated A Secret Surveillance Operation - Bloomberg
  • Ubiquiti Developer Charged With Extortion, Causing 2020 “Breach” – Krebs on Security
  • Cyber Command boss acknowledges US military actions against ransomware groups
  • Canadian spy agency targeted foreign hackers to ‘impose a cost’ for cybercrime - National | Globalnews.ca
  • FBI seized $2.3M from affiliate of REvil, Gandcrab ransomware gangs
  • gov.uscourts.2.2.million-ransom-seizure - DocumentCloud
  • 400,000 Planned Parenthood users' data stolen in ransomware attack
  • Canadian police arrest Ottawa resident for ransomware attacks - The Record by Recorded Future
  • Ransomware tracker: the latest figures [December 2021] - The Record by Recorded Future
  • Court hands Microsoft control of websites linked to spying by Chinese hackers
  • NICKEL targeting government organizations across Latin America and Europe - Microsoft Security Blog
  • A mysterious threat actor is running hundreds of malicious Tor relays - The Record by Recorded Future
  • The Justice Department is ramping up its crackdown on money mules
  • FIN7 hacker trialed in Russia gets no prison time - The Record by Recorded Future
  • 1.5 million users joined Facebook Protect since September - The Record by Recorded Future
  • Facebook Will Force More At-Risk Accounts to Use Two-Factor | WIRED
  • Cyber incident reporting mandates suffer another congressional setback
  • (5) Derek B Johnson on Twitter: "This statement from House Homeland Chair Bennie Thompson and Cyber Subcommittee Chair Yvette Clarke says process around incident reporting legislation was wracked with "dysfunction" and appears to firmly shut the door on the bill being reinserted into the NDAA. https://t.co/iBpmxAFJgQ" / Twitter
  • BitMart loses $150 million in the second-largest crypto-heist of the year - The Record by Recorded Future
  • Hacked Cryptocurrency Platform Begs Hacker to Please Return $119 Million
  • Really stupid “smart contract” bug let hackers steal $31 million in digital coin | Ars Technica
  • Received Some Random Cryptocurrency? It Might Be a Phishing Scam.
  • Web skimmers hit 300+ sites hidden inside Google Tag Manager containers - The Record by Recorded Future
  • New Payment Data Stealing Malware Hides in Nginx Process on Linux Servers
  • Zoho warns of new zero-day vulnerability exploited in attacks - The Record by Recorded Future
  • APT groups from China, Russia, and India adopt novel attack technique - The Record by Recorded Future
  • Flaws in Tonga’s top-level domain left Google, Amazon, Tether web services vulnerable to takeover | The Daily Swig
  • Compromising Email Supply Chains | CanIPhish
  • GitHub - SummitRoute/csp_security_mistakes: Cloud service provider security mistakes
  • USB Over Ethernet | Multiple Vulnerabilities in AWS and Other Major Cloud Services - SentinelOne
  • A different way to do PAM -- Paul Lanzi, Remediant - YouTube
  • Material Security: Keeping email safe at rest - YouTube
  • The Sweeney Background Music (1975-1978) - YouTube

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Israel slashes number of countries it will export cyber tools to
  • Interpol takes down 1,000 Internet fraudsters
  • Ransomware crews lying low?
  • When the tabloids do cyber the results are sometimes awesome
  • Much, much more…

This week’s sponsor interview is with Ryan Kalember of Proofpoint. He’s the EVP of Cybersecurity Strategy there and he’s joining me this week to talk about how investment activity in cybersecurity is basically leaving everyone who isn’t a mega enterprise behind.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • Israel restricts cyberweapons export list by two-thirds, from 102 to 37 countries - The Record by Recorded Future
  • US sanctions 28 quantum computing entities in China, Russia, Pakistan, Japan - The Record by Recorded Future
  • Months-long Interpol crackdown nets more than 1,000 online fraud arrests
  • Ukrainian police expose international phone-hacking gang | The Daily Swig
  • Group-IB helps Italian officials take down scammers selling COVID-19 docs via Telegram - The Record by Recorded Future
  • Ransomware gang targeting schools, hospitals reinvents itself to avoid scrutiny
  • Russian hacker wanted by FBI for 'using ransomware to fleece millions of dollars' is unmasked | Daily Mail Online
  • When Russia Helped the U.S. Nab Cybercriminals
  • How the pandemic pulled Nigerian university students into cybercrime - The Record by Recorded Future
  • A Hacking Spree Against Iran Spills Out Into the Physical World | WIRED
  • China agency tells Tencent their apps have to be approved before they go live or update - The Record by Recorded Future
  • Srsly Risky Biz: Thursday, November 25 - by Tom Uren
  • Incident reporting, ransomware payment legislation faces trouble in Senate
  • North Korean hackers posed as Samsung recruiters to target security researchers - The Record by Recorded Future
  • FBI document shows what data can be obtained from encrypted messaging apps - The Record by Recorded Future
  • AT&T takes action against DDoS botnet that hijacked VoIP servers - The Record by Recorded Future
  • You Can Now Get $25 From Zoom Following a Class Action Settlement
  • (3) Konstantin on Twitter: "Apparently, someone from r/antiwork is bombarding the internet with RAW TCP/IP printing requests. I'm going to tag this just for kicks. https://t.co/P0NC2dO6hx" / Twitter
  • (3) Matthew Garrett on Twitter: "Someone is targeting network-attached receipt printers on the public internet and just printing copies of the r/antiwork manifesto and this is glorious" / Twitter
  • Private 5G Mobile Networks – AWS Private 5G – Amazon Web Services

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Apple sues NSO Group and it’s all a bit weird
  • Israel charges defence minister’s house cleaner with Iranian hacker collusion (really)
  • USA charges two Iranians over “Proud Boy” emails
  • Cyber insurers nope out of comprehensive coverage
  • Prodaft shells Conti, drops report like it’s a Normal Thing
  • Much, much more

This week’s show is sponsored by VMRay. We’ll be chatting with one of VMRay’s customers in this week’s sponsor interview. Jim Byrge works on the CSIRT team at Valvoline, and he’ll be along to talk about how they replaced their ageing, in-house developed SOAR platform with commercial tools. It was still harder than it should be in 2021, but they got there in the end.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • Apple sues spyware maker NSO Group - The Record by Recorded Future
  • Apple_v_NSO_Complaint_112321.pdf
  • Crime Boss or Tech CEO? An Encrypted Phone Company Sues the Government to Save Itself
  • Israel charges Defense Minister's house cleaner with leaking data to Iranian hackers - The Record by Recorded Future
  • US charges Iranian hackers for spoofed Proud Boys emails threatening US voters - The Record by Recorded Future
  • Insurers run from ransomware cover as losses mount | Reuters
  • Brisbane’s Langs Building Supplies and Melbourne’s Network Overdrive hit by cyber attack | news.com.au — Australia’s leading news site
  • IRS seized $3.5 billion in cryptocurrency this past year, agency says
  • Conti ransomware gang suffers security breach - The Record by Recorded Future
  • Tor Project sees decline in server numbers, will offer rewards for new bridge operators - The Record by Recorded Future
  • Conti gang has made at least $25.5 million since July 2021 - The Record by Recorded Future
  • A third of all dark web domains are now v3 onion sites - The Record by Recorded Future
  • Evil Corp: 'My hunt for the world's most wanted hackers' - BBC News
  • Arrest in ‘Ransom Your Employer’ Email Scheme – Krebs on Security
  • FBI identified BEC scammers using bank surveillance footage - The Record by Recorded Future
  • Banks must report major cyber incidents within 36 hours under finalized regulation
  • Devious ‘Tardigrade’ Malware Hits Biomanufacturing Facilities | WIRED
  • GoDaddy data breach impacts 1.2 million WordPress site owners - The Record by Recorded Future
  • Attackers don't bother brute-forcing long passwords, Microsoft engineer says - The Record by Recorded Future
  • NUCLEUS:13 – Host of vulnerabilities shatter Nucelus TCP/IP stack defenses | The Daily Swig
  • Malicious Python packages caught stealing Discord tokens, installing shells - The Record by Recorded Future
  • Vulnerabilities in NPM allowed threat actors to publish new version of any package | The Daily Swig
  • US, UK, and Australia warn of Iranian hacking activity after Microsoft report - The Record by Recorded Future
  • FBI: An APT abused a zero-day in FatPipe VPNs for six months - The Record by Recorded Future
  • CISA, FBI issue holiday warning about hackers, urge vigilance - The Record by Recorded Future

View Details

In this edition of the Risky Biz Soap Box podcast we chat with Sean Leach, the Chief Product Architect at Fastly, about the history and current status of the DDoS ecosystem. Despite never really making money for criminals, DDoS attacks are still a problem.

CDNs have soaked up a lot of the problem, so DDoS crews are getting creative. Do you know where you’re vulnerable?

Show notes

  • Bouncy castle boss James Balcombe ordered arson hits on rivals

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Watering hole attacks are getting much better
  • How Israel’s government used NSO to strengthen its diplomatic ties
  • Randori sat on some PAN 0day. This is fine.
  • Facebook outs state-backed ops
  • FBi has unfortunate incident with its mail boxes
  • Much, much more

This week’s sponsor interview is with HD Moore. He’s the founder of Rumble, the network asset discovery scanner, and he’s joining us to talk about some new tricks he’s added to the product, like integrations with cloud service APIs and external discovery products like Censys.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • British news website was hacked to control readers' computers, report says
  • Strategic web compromises in the Middle East with a pinch of Candiru | WeLiveSecurity
  • Analyzing a watering hole campaign using macOS exploits
  • Israel, spyware and corruption: NSO ties to Netanyahu, Bennett and other politicians - Israel News - Haaretz.com
  • Pakistani hackers operated a fake app store to target former Afghan officials - The Record by Recorded Future
  • Exclusive: A Cyber Mercenary Is Hacking The Google And Telegram Accounts Of Presidential Candidates, Journalists And Doctors
  • New Moses Staff group targets Israeli organizations in destructive attacks - The Record by Recorded Future
  • Kevin Beaumont on Twitter: "Pay attention to this one when it’s out. I haven’t seen it, but it’s possible to use BitLocker to remotely (re)encrypt every endpoint in AD in a way that only the attacker can decrypt… and it bypasses sec solutions. So I imagine it’s that." / Twitter
  • Hacker sends spam to 100,000 from FBI email address
  • Booking.com was reportedly hacked by a US intel agency but never told customers | Ars Technica
  • ‘Ghostwriter’ Looks Like a Purely Russian Op—Except It's Not | WIRED
  • Emotet botnet returns after law enforcement mass-uninstall operation - The Record by Recorded Future
  • Canadian health systems recovering from breach that forced thousands of appointment cancellations
  • Dustin Volz on Twitter: "@riskybusiness @DAlperovitch I think folks outside government can also underestimate how much agencies rehearse talking points and in testimony like this and try to be always on the same page—unless they don’t want to be. And that adds to the sense of “conflict” or “disagreement” for some of us." / Twitter
  • CERT-PL employees rally around politically-dismissed chief - The Record by Recorded Future
  • US detains crypto-exchange exec for helping Ryuk ransomware gang launder profits - The Record by Recorded Future
  • Researchers wait 12 months to report vulnerability with 9.8 out of 10 severity rating | Ars Technica
  • DDR4 memory protections are broken wide open by new Rowhammer technique | Ars Technica
  • New secret-spilling hole in Intel CPUs sends company patching (again) | Ars Technica
  • GoCD bug chain provides second springboard for supply chain attacks | The Daily Swig
  • ‘Add yourself as super admin’ – Researcher details easy-to-exploit bug that exposed GSuite accounts to full takeover | The Daily Swig
  • Adult cam site StripChat exposes the data of millions of users and cam models - The Record by Recorded Future
  • Hundreds of WordPress sites defaced in fake ransomware attacks - The Record by Recorded Future

View Details

In this edition of the Soap Box podcast we’re chatting with Jake King. Jake is a co-founder of Cmd Security, a Linux Security startup that was recently acquired by Elastic.

Cmd’s technology basically started out as a control and visibility tool for Linux systems that could restrict user actions. But over time, the product evolved to be more detection and response oriented.

In this interview we talk to Jake about why Cmd wound up where it is, product wise, and what customers can expect now his company has been swept up by Elastic as a part of its broader push into XDR, or Extended Detection and Response.

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • US sanctions NSO, Candiru, COSEINC and Positive Technologies
  • We wrap up the action in ransomware
  • Why exploit tournaments are boring in America and exciting in China
  • More malicious npm packages in the wild
  • Pentagon updates CMMC to 2.0
  • Much, much more

We’ll hear from Corelight’s CISO Bernard Brantley in this week’s sponsor interview. We’re talking about how attackers think in graphs and defenders think in lists.. Microsoft’s John Lambert wrote a post about that back in 2015, and Bernard joins the show this week to talk about why it’s just as relevant as ever. Stick around for that one.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • U.S. sanctions Israel’s NSO Group over Pegasus spyware - The Washington Post
  • Risky Business #310 -- Export exploits? Wassenaar says no - Risky Business
  • Positive Technologies says US sanctions had little or no effect on its business - The Record by Recorded Future
  • Hungarian official confirms government bought and used Pegasus spyware - The Record by Recorded Future
  • NSO's Pegasus spyware found on the devices of six Palestinian activists - The Record by Recorded Future
  • “A grim outlook”: How cyber surveillance is booming on a global scale | MIT Technology Review
  • Spyware providers are flocking to international arms fairs to sell to NATO foes
  • Ukraine discloses identity of Gamaredon members links it to Russia's FSB - The Record by Recorded Future
  • PRC says FCC decision to pull China Telecom license was ‘based on suspicion,’ not facts - The Record by Recorded Future
  • China says a foreign spy agency hacked its airlines, stole passenger records - The Record by Recorded Future
  • Hackers with Chinese links breach defense, energy targets, including one in US
  • Pwn2Own Austin 2021: Synacktiv crowned Masters of Pwn after Sonos One, WD NAS exploits | The Daily Swig
  • House approves massive infrastructure plan that includes $1.9 billion for cybersecurity - The Record by Recorded Future
  • Malware found in coa and rc, two npm packages with 23M weekly downloads - The Record by Recorded Future
  • Pentagon issues revised cyber standards for contractors - The Record by Recorded Future
  • Hacker steals $55 million from bZx DeFi platform - The Record by Recorded Future
  • Suspect in scheme to breach major Twitter accounts is now charged with hacking crypto executives
  • Scammer Convinced Instagram That Its Top Executive Was Dead
  • GitLab servers are being exploited in DDoS attacks in excess of 1 Tbps - The Record by Recorded Future
  • Dangerous XSS bug in Google Chrome’s ‘New Tab’ page bypassed security features | The Daily Swig
  • US offers $10 million reward for info on Darkside ransomware group - The Record by Recorded Future
  • Hackers Apologize to Arab Royal Families for Leaking Their Data
  • A ransomware gang shut down after Cybercom hijacked its site and it discovered it had been hacked - The Washington Post
  • BlackMatter ransomware says its shutting down due to pressure from local authorities - The Record by Recorded Future
  • CERT-France: Lockean ransomware group behind attacks on French companies - The Record by Recorded Future
  • The ‘Groove’ Ransomware Gang Was a Hoax – Krebs on Security
  • Ransomware crackdown spreads in U.S., Europe and Asia
  • US Treasury sanctions crypto-exchange Chatex for links to ransomware payments - The Record by Recorded Future
  • Shared/Defenders think in lists. Attackers think in graphs. As long as this is true, attackers win.md at master · JohnLaTwC/Shared · GitHub
  • Compare to open source Zeek

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Someone took down Iranian fuel stations
  • Papua New Guinea ransomware attack is pretty grim stuff
  • Russia’s SVR still going berserk in cloudtown
  • China Telecom America gets the boot
  • Much, much more

We’ll be hearing from Senetas CEO Andrew Wilson in this week’s sponsor interview. He’s joining us to talk about how the global semiconductor shortage is making him a very, very sad panda.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • Iran says sweeping cyberattack took down gas stations across country
  • Cyber ​​group 'Adalat Ali' published documents related to the November 1998 protests - BBC News Farsi
  • Papua New Guinea Hit by Ransomware Hackers With Millions in Aid Frozen - Bloomberg
  • (1) Cloudpng on Twitter: "This is the setup for all agencies must be on-site at Vulupindi Haus, Finance dept POM to process claims for IFMS after the system was hacked in October 2021. It's pretty full so bookings must be made to secure a PC. #ifms #systems #png https://t.co/VCiUYE9hFL" / Twitter
  • (1) Hon Sasindran Muthuvel MP on Twitter: "Statement on the financial system failure and the challenges it now creates for all provinces. This issue must be addressed holistically and the Finance Dept must work in conjunction with the provinces. Sasi https://t.co/OLMAHxgDel" / Twitter
  • 'Destructive' cyberattack hits National Bank of Pakistan - The Record by Recorded Future
  • Microsoft says Russia hacked at least 14 IT service providers this year - The Record by Recorded Future
  • Industry group warns of coordinated DDoS extortion campaign against VoIP providers - The Record by Recorded Future
  • Bandwidth.com expects to lose up to $12M following DDoS extortion attempt - The Record by Recorded Future
  • DDoS attacks hit multiple email providers - The Record by Recorded Future
  • FCC revokes license for China Telecom Americas amid national security concerns - The Record by Recorded Future
  • LinkedIn to Shutter Service in China - The Record by Recorded Future
  • A Roaming Threat to Telecommunications Companies | CrowdStrike
  • NSA warns of threat actors compromising entire 5G networks via cloud systems - The Record by Recorded Future
  • Commerce Department announces new rule aimed at stemming sale of hacking tools to Russia and China - The Washington Post
  • Windows 10, iOS 15, Ubuntu, Chrome fall at China's Tianfu hacking contest - The Record by Recorded Future
  • FBI Raids Chinese Point-of-Sale Giant PAX Technology – Krebs on Security
  • Malware found in npm package with millions of weekly downloads - The Record by Recorded Future
  • Polygon pays out record $2 million bug bounty reward for critical vulnerability | The Daily Swig
  • Hacker steals government ID database for Argentina's entire population - The Record by Recorded Future
  • Fraudsters Cloned Company Director’s Voice In $35 Million Bank Heist, Police Find
  • How Hackers Hijacked Thousands of High-Profile YouTube Accounts | WIRED
  • Instagram Hacker Forces Victim to Make Hostage-Style Video
  • Missouri governor calls for prosecution of journalist who flagged website flaw
  • Israeli hospital cancels non-urgent procedures following ransomware attack | The Daily Swig
  • Ransomware Has Disrupted Almost 1,000 Schools in the US This Year
  • Ransomware attack disrupts Toronto's public transportation system - The Record by Recorded Future
  • Workers sent home after ransomware attack on major automotive parts manufacturer - The Record by Recorded Future
  • Largest candy corn maker in US gets hacked ahead of Halloween
  • Sinclair Workers Say TV Channels Are in ‘Pandemonium’ After Ransomware Attack
  • Cybercriminals claim to have hacked the NRA
  • 'Cyber event' knocks dairy giant Schreiber Foods offline amid industry ransomware outbreak - CyberScoop
  • Cyberattack hits Meliá, one of the largest hotel chains in the world - The Record by Recorded Future
  • Olympus US hack tied to sanctioned Russian ransomware group | TechCrunch
  • Europol detains suspects behind LockerGoga, MegaCortex, and Dharma ransomware attacks - The Record by Recorded Future
  • Hitting the BlackMatter gang where it hurts: In the wallet - Emsisoft | Security Blog
  • Ransomware hackers nervous, allege harassment from U.S.
  • DarkSide ransomware gang moves some of its Bitcoin after REvil got hit by law enforcement - The Record by Recorded Future
  • Hackers use SQL injection bug in BillQuick billing app to deploy ransomware - The Record by Recorded Future
  • Ransomware gangs are abusing a zero-day in EntroLink VPN appliances - The Record by Recorded Future
  • Conti Ransom Gang Starts Selling Access to Victims – Krebs on Security
  • Cybercrime gang sets up fake company to hire security experts to aid in ransomware attacks - The Record by Recorded Future
  • FBI PIN on ransomware crew targeting trend
  • EXCLUSIVE Governments turn tables on ransomware gang REvil by pushing it offline | Reuters
  • REvil gang shuts down for the second time after its Tor servers were hacked - The Record by Recorded Future
  • Countries agree to fight ransomware together after White House meetings - The Record by Recorded Future
  • CISA, FBI, and NSA warn of BlackMatter attacks on agriculture and other critical infrastructure - The Record by Recorded Future
  • International community joins forces as ransomware attacks create major disruptions | PBS NewsHour
  • US Treasury said it tied $5.2 billion in BTC transactions to ransomware payments - The Record by Recorded Future
  • Stream when do we get on the beers cause i'm losing it by Candy Moore | Listen online for free on SoundCloud

View Details

This feature podcast was made possible by the Hewlett Foundation’s Cyber Initiative. The foundation has given us grant funding to produce this podcast series, which is designed to educate policymakers in cybersecurity so they can make better decisions.

In this edition you’ll hear an interview I recorded with Mark Dowd.

Mark is a world-renowned security researcher who, some years ago, co-founded a company called Azimuth Security. As you’ll hear, the original plan was to provide security research and consulting services to vendors. But, pretty quickly, Azimuth became a serious player in offensive security, selling exploits and other tools to government agencies in the Five Eyes countries.

We recorded this interview touching on the history of Azimuth, what the public gets wrong when talking about 0day and surveillance, and were this whole thing could go – especially considering writing memory corruption exploits is getting so much harder.

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • UK, Netherlands and Australia promise offensive response to big ticket ransomware
  • Wave of major cyber regulation and legislation in USA
  • Iran up in yer O365s, Russians in yer gmails
  • Submarine spy guy would have been fine, if he didn’t make one very big mistake
  • Much, much more

Jonathan Reiber is this week’s sponsor guest. He’s senior director of cybersecurity at AttackIQ and he’s joining us to talk through the US Government’s executive order on Zero Trust. Jonathan says it is actually born of a realisation the US Government needs to do something differently, that the old approaches aren’t working.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • UK cyber head says Russia responsible for 'devastating' ransomware attacks - BBC News
  • Netherlands can use intelligence or armed forces to respond to ransomware attacks - The Record by Recorded Future
  • Ransomware Action Plan
  • Ransomware hackers find vulnerable target in U.S. grain supply
  • Emergent ransomware gang FIN12 strikes hospitals, moves quickly against big targets
  • Macquarie Health Corporation hit by cyberattack as hackers claim 6700 people affected | news.com.au — Australia’s leading news site
  • Microsoft: Iran-linked hackers breached Office 365 customer accounts - The Record by Recorded Future
  • Google notifies 14,000 Gmail users of targeted APT28 attacks - The Record by Recorded Future
  • Google distributing 10,000 security keys to journalists, elected officials, human rights activists | The Daily Swig
  • Peanut butter and ProtonMail: US charges underscore evolution of espionage in digital age
  • Hackers of SolarWinds stole data on U.S. sanctions policy, intelligence probes | Reuters
  • Senate committee advances major cybersecurity legislation - The Record by Recorded Future
  • Justice Department launches a National Cryptocurrency Enforcement Team - The Record by Recorded Future
  • DOJ to go after government contractors who don't disclose breaches - The Record by Recorded Future
  • TSA to impose cybersecurity mandates on major rail and subway systems - The Washington Post
  • OMB orders federal agencies to let CISA access defenses of devices, servers
  • CIA Funding Arm Gave Encrypted App Wickr $1.6 Million
  • U.S. prosecution of alleged WikiLeaks ‘Vault 7’ source hits multiple roadblocks
  • Ukraine arrests operator of DDoS botnet with 100,000 bots - The Record by Recorded Future
  • Botnet abuses TP-Link routers for years in SMS messaging-as-a-service scheme - The Record by Recorded Future
  • Microsoft said it mitigated a 2.4 Tbps DDoS attack, the largest ever - The Record by Recorded Future
  • Report links Indian company to spyware that targeted Togolese activist - The Record by Recorded Future
  • Trolls defaced Twitch's website with pictures of Jeff Bezos, the latest security concern
  • Twitch says no user passwords or cards numbers were exposed in major hack - The Record by Recorded Future
  • Video game streaming service Twitch suffers major data breach
  • Woman Allegedly Hacked Flight School, Cleared Planes With Maintenance Issues to Fly
  • Microsoft to disable Excel 4.0 macros, one of the most abused Office features - The Record by Recorded Future
  • NSA warns of ALPACA TLS attack, use of wildcard TLS certificates - The Record by Recorded Future
  • Azure, GitHub, GitLab, BitBucket mass-revoke SSH keys following bug report - The Record by Recorded Future
  • Reverse engineering and decrypting CyberArk vault credential files | Jelle Vergeer
  • Security researchers find another UEFI bootkit used for cyber-espionage - The Record by Recorded Future
  • Apple patches iPhone zero-day in iOS 15.0.2 - The Record by Recorded Future
  • Bindiff and POC for the IOMFB vulnerability, iOS 15.0.2 | IOMFB_integer_overflow_poc
  • Apache HTTP Server update fails to squash path traversal, RCE bugs | The Daily Swig
  • Executive Order on Improving the Nation's Cybersecurity | The White House

View Details

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Group-IB CEO arrested in Russia for treason
  • Lawsuit alleges ransomware contributed to hospitalised baby’s death
  • Nakasone outs self as hound release advocate
  • Syniverse owned, but we don’t know how badly
  • Why Google keyword warrants are awesome
  • Much, much more…

Nucleus co-founder Scott Kuffer is this week’s sponsor guest and the topic is actually a bit hilarious. They’ve found a killer use case that customers are clamouring for: Being able to map vulnerabilities to org groups within your enterprise so you can see who’s slacking off when it comes to patching.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Show notes

  • Group-IB founder arrested in Moscow on state treason charges - The Record by Recorded Future
  • Baby died because of ransomware attack on hospital, suit says
  • Conti gang threatens to dump victim data if ransom negotiations leak to reporters - The Record by Recorded Future
  • US to work with 30 countries to tackle ransomware problem - The Record by Recorded Future
  • Two ransomware operators arrested in Ukraine - The Record by Recorded Future
  • Ransomware gangs are starting more drama on cybercrime forums, upending 'honor among thieves' conventions
  • Ransomware attack disrupts hundreds of bookstores across France, Belgium, and the Netherlands - The Record by Recorded Future
  • NSA chief predicts U.S. will face ransomware 'every single day' for years to come - The Record by Recorded Future
  • Company That Routes Billions of Text Messages Quietly Says It Was Hacked
  • Hackers bypass Coinbase 2FA to steal customer funds - The Record by Recorded Future
  • The Rise of One-Time Password Interception Bots – Krebs on Security
  • FCC to work on rules to prevent SIM swapping attacks - The Record by Recorded Future
  • Exclusive: Government Secretly Orders Google To Identify Anyone Who Searched A Sexual Assault Victim’s Name, Address And Telephone Number
  • How a Secret Google Geofence Warrant Helped Catch the Capitol Riot Mob | WIRED
  • EXCLUSIVE U.S. lawmakers push for new controls on ex-spies working overseas | Reuters
  • DHS and NIST release post-quantum cryptography guidance - The Record by Recorded Future
  • New emergency cyber regulations lay out ‘urgently needed’ rules for pipelines but draw mixed reviews - The Washington Post
  • Rep. Katko introduces bill that would prioritize security for key US critical infrastructure
  • Let’s Encrypt root cert update catches out many big-name tech firms | The Daily Swig
  • Academics discover hidden layer in China's Great Firewall - The Record by Recorded Future
  • Bandwidth.com is latest victim of DDoS attacks against VoIP providers
  • A Simple Bug Is Leaving AirTag Users Vulnerable to an Attack | WIRED
  • Apache fixes actively exploited web server zero-day - The Record by Recorded Future
  • Hackers posed as Amnesty International, promising anti-spyware tool that actually collects passwords
  • Around the world with the NSA's cyber chief - The Record by Recorded Future
  • Facebook blames 'faulty configuration change' for major outages
  • Report: New PCR test intelligence around Wuhan suggests COVID-19 was virulent earlier than thought - The Record by Recorded Future
  • Does This Exposed Chinese Database Pose a Security Threat?