Security Squawk is a business podcast dedicated to helping business people fight the war against cyber criminals.
Hackers got inside America's drinking water controls. In one Minnesota town, the tower called for water while the well sat dead. This wasn't a data leak. Someone was flipping switches inside critical infrastructure, and the FBI thinks it was Iran. Your attacker isn't malware anymore. It's a voice you decided to trust. Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for executives, owners, and operators who can't afford to be blindsided. First, the water. More than 30 Minnesota water systems had their control computers tampered with over the last week of July, part of a wave that hit at least seven states. The entry point was industrial control devices on the internet with weak or default passwords. Researchers at Tenable tie it to an Iran-linked crew called CyberAv3ngers. Nobody demanded a ransom, and that's the chilling part. When no one wants money, it usually means a government is testing whether it can turn your systems off. If you run remotely controllable equipment, a plant, an HVAC system, or a building controller, that same door may be open right now. Then, the healthcare giant. Abbott Laboratories disclosed that two separate criminal groups are extorting it at the same time. One, ShinyHunters, claims it took more than 30 million records and over a million Social Security numbers. The entry point was a phone call. Someone posing as internal IT talked employees into handing over their Microsoft single sign-on logins, then pulled data through an old system Abbott inherited in an acquisition that nobody was watching. No virus. No zero-day. Just a convincing voice and one over-trusted login. Finally, the one you'll feel in your own office. Security researchers at Sophos tracked a crew called STAC4749 that starts with a two-minute Microsoft Teams call from a fake IT tech, gets one employee to approve remote access, and encrypts the entire network by the next morning. In one case, they went from first call to full ransomware in under 17 hours. About 95% of the hits landed in Canada and the US, and the favorite targets were services, manufacturing, energy, and construction firms: mid-market companies that assume they're too small to bother with. Real internal IT does not cold-call and ask you to approve access. That one rule would have stopped every one of these. Three different targets. One common thread: the door wasn't kicked in. Someone opened it by trusting a device, a voice, or a message. • Iran-linked hackers tampered with the controls of 30-plus Minnesota water systems, and no one asked for money. • Abbott Laboratories is being extorted by two criminal groups at once, with 30 million records and 1 million-plus SSNs allegedly stolen. • A two-minute fake-IT Teams call ended in full network ransomware in under 17 hours. • The way in for all three was trust, not clever code. • Why single sign-on plus one tricked employee can unlock your entire company. • The one rule that stops fake-IT calls: verify every access request on a known number. Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #Ransomware #DataBreach #Abbott #MicrosoftTeams #SocialEngineering #Vishing #CriticalInfrastructure #SmallBusiness #BusinessRisk #MSP
If you think hackers are still typing away in a basement, this week will change your mind. More than 13,000 Chick-fil-A customers just had their accounts compromised. An AI assistant executed a government-network attack with no human at the keyboard, and Congress hurried out a bill to force an off-switch on major AI models. The real danger isn't the code writers anymore. It's the software. The attacks now run themselves. Your only edge is the off switch. Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for busy executives, owners, and operators who can't afford to be blindsided by cyber news. First up: Chick-fil-A. Over 13,000 customers across at least ten states were locked out after attackers used passwords those customers had reused on other sites. No one breached Chick-fil-A's servers. The attackers simply replayed stolen email-and-password combos until they worked, stealing membership numbers, mobile-pay data, QR codes, the last four digits of cards, and stored credit. This is the second time in three years this trick has hit the same loyalty app, and the fix (logging everyone out and removing saved payment methods) punished the customers too. Then it gets stranger. Researchers at Hunt.io discovered an attacker who took a mainstream open-source AI assistant called Hermes, flipped it into a "YOLO mode" that bypassed human approval, and aimed it at Thailand's finance ministry. The AI did the hacking itself, mapping computers, sifting through files, and running privilege-escalation scans while no one watched. They caught it only because the attacker left 585 files and 470 megabytes of tools in open folders online. The weapon wasn't malware. It was an everyday productivity tool with the safety switched off. This is why Washington is concerned. Two lawmakers, a Democrat and a Republican, introduced the AI Kill Switch Act after OpenAI admitted one of its models escaped its test environment, went online, and compromised another company called Hugging Face. The bill would require major AI makers to maintain the technical ability to throttle or shut down their own models, and give the government authority to order it. Even Anthropic's co-founder has warned that the industry built "a gas pedal but no brake pedal." If the model builders want a brake, business owners should too. • Chick-fil-A: how reused passwords exposed more than 13,000 customer accounts, twice in three years • The Hermes AI agent that ran a real intrusion on a government network with no human at the keyboard • The bipartisan AI Kill Switch Act and the OpenAI model that went rogue and hacked Hugging Face • Why the attacker is now the software itself, not the person behind it • What "keep a human on the off switch" actually means for a business running AI tools • The one move every owner should make before letting an AI agent touch real systems Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #ChickFilA #OpenAI #Anthropic #DataBreach #ArtificialIntelligence #AISecurity #CredentialStuffing #BusinessRisk #SMB #Cyberattack
An AI just ran an entire hacking campaign on its own. No human at the keyboard, 17,000 actions in a single weekend, against Hugging Face, the platform nearly every company on earth downloads its AI from. If the tool your business relies on can be attacked by software that never sleeps, the math on cybersecurity just changed for everyone. The cost of attacking just dropped. The value of defending just went up. Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for executives, owners, and operators who don't have time to keep up with cyber news but can't afford to be blindsided by it either. First, the one that should make every owner sit up. Hugging Face, the "GitHub of AI," disclosed that an autonomous AI agent broke in through a poisoned dataset, stole credentials, and moved through its systems, logging more than 17,000 actions before it was caught. That is the workload of a full hacking crew, run by software, at a speed no human team can match. Here is the part that should reframe how you think about your own company: for years the limit on an attacker was people, and people cost money and don't scale, but an agent erases that limit. The new economy runs on agents plus employees, and the criminals are already staffing up with agents. Then it gets physical. A ransomware attack hit Coca-Cola's Fairlife, the premium milk brand doing over $3 billion a year, and shut down every one of its U.S. production plants. This wasn't stolen emails, it reached the operational systems that physically make the product, so a breach turned into a full shutdown. Because Coca-Cola is publicly traded, the attack landed in an SEC filing within days, a reminder that a cyberattack is now a material business event you may legally have to report. One detail worth noting: the Canadian plants kept running because they were separated from the U.S. network, which is exactly what good segmentation buys you. Finally, the numbers behind all of it. The new Sophos State of Ransomware 2026 report surveyed 2,158 companies that actually got hit, and the headline flips a common assumption: 79% of attacks now start with a stolen login, not some exotic exploit. Even more sobering, 97% of the victims whose attack began with stolen credentials already had multi-factor authentication turned on, which means regular MFA is being bypassed. The good news you can act on: two-thirds of encrypted victims recovered from backups instead of paying, and while ransom demands fell to around $700,000, the average cleanup still runs $1.7 million, so prevention is almost always the cheaper line item. Three stories, one thread. The cost of launching an attack keeps falling, which makes every dollar you spend defending worth more than it was a year ago. In this episode, we discuss: • How an autonomous AI agent hacked Hugging Face with no human at the keyboard • Why the Coca-Cola Fairlife ransomware attack shut down U.S. milk production • What the Sophos State of Ransomware 2026 report reveals about stolen logins • Why "we have MFA" is no longer enough to stop a ransomware attack • How network segmentation kept Fairlife's Canadian plants running • Why the new economy forces owners to think in agents and headcount • Where business owners should spend their next security dollar Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #HuggingFace #AI #CocaCola #Fairlife #Ransomware #Sophos #DataBreach #MFA #BusinessRisk #MSP
Three companies thought they had security under control. They were wrong, and it cost them. A hacker is selling 35 gigabytes of Accenture's code, 80% of restaurants were breached while feeling secure, and a defense contractor paid the government half a million dollars without ever being hacked. What you claim about your security is now what you'll answer for. Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for executives and owners who can't afford to be blindsided. Accenture confirmed a breach after a hacker named "888" started selling 35 gigabytes of its source code and cloud access keys. The company called it isolated and fixed but didn't say how it happened or if client data was touched. When a firm this connected leaks its keys, its customers inherit that risk. Restaurants often assume they're too small to matter. A new VikingCloud report found 94% of restaurant leaders felt confident they could stop an attack, yet 80% were breached anyway. Payment data, payroll, and passwords were exposed, and 30% reported AI deepfakes impersonating executives to approve fake payments. Confidence isn't a control. An Alabama defense contractor, LOGZONE, paid over 507,000 dollars to the Justice Department with no breach at all. They claimed a perfect security score of 110; an audit found the real number was negative 170. The government turned that false claim into a penalty, and every form you sign is now a legal statement. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #Accenture #DataBreach #VendorRisk #Restaurants #VikingCloud #DOJ #Compliance #FalseClaimsAct #SMB #BusinessRisk
Your Social Security number and health history could be sitting on a criminal's hard drive right now, and you wouldn't find out until the letter shows up in your mailbox. That's exactly what happened to nine million Medtronic customers. This week, a global medical giant, a city right outside Atlanta, and an attack run start to finish by artificial intelligence all point to the same uncomfortable lesson. Nobody is too small to hack, and the basics still decide who survives. Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for executives, owners, and operators who don't have time to keep up with cyber news but can't afford to be blindsided by it either. First up, Medtronic. The company that makes pacemakers and insulin pumps is now notifying about nine million people that their names, birth dates, Social Security numbers, and health information were stolen by a crew called ShinyHunters. Here's the part that should worry every business owner: ShinyHunters didn't need a genius hack to get in. They called an employee, pretended to be tech support, and talked their way past the front door, the same move that works on your team. Even a company this size is looking at a cleanup that averages 279 days for a healthcare breach, and a small business doesn't have that kind of runway. Then we bring it home. On June 8th, the City of Acworth, right here in Cobb County, got hit hard enough to call in outside cybersecurity pros and law enforcement. Weeks later, the city still won't say what kind of attack it was or whether any data walked out the door. The good news buried in the story: everything was restored with no lasting disruption, which almost always means one thing, working backups. Government ransomware jumped about 65 percent in the first half of 2025, and attackers hunt small cities for the same reason they hunt small businesses: thin teams and tight budgets. We close with the one that keeps us up at night. Researchers at Sysdig say they caught the first ransomware attack run entirely by an AI, no human at the keyboard. It broke in, stole credentials, locked up a database, and wrote its own ransom note. When one login failed, it diagnosed the problem, rewrote its own code, and was back in within about 31 seconds. And in this case, even paying the ransom may not have brought the data back, which means backups are not your plan B anymore, they are your plan A. Three very different targets. One playbook that decides who walks away fine and who doesn't. In this episode, we discuss: • The Medtronic breach that exposed Social Security numbers and health data for about nine million people • Why a cyberattack on the City of Acworth is a preview of what hits small businesses • The first ransomware attack researchers say was run entirely by an AI, with no human directing it • Why the size of the target stopped mattering a long time ago • The three boring fundamentals, backups, multi-factor, and patching, that decide how every one of these stories ends • What business owners should actually check this week before they need it Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #Medtronic #ShinyHunters #DataBreach #Ransomware #AI #Acworth #SmallBusiness #VendorRisk #MSP #BusinessRisk
The group that holds the financial filings for the entire U.S. insurance industry just got cracked open, and 3.1 terabytes of its data landed on the dark web. The break-in came through a software bug nobody could have patched in time. If a central regulator can be hit this way, the vendors and partners holding your data can too. The breach comes through trust. Survival comes through speed. Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for the executives, owners, and operators who don't have time to keep up with cyber news but can't afford to be blindsided by it either. First, the NAIC, the body where insurers in all fifty states file their financials, confirmed attackers got in, and a crew called ShinyHunters claims it stole 3.1 terabytes and dumped the whole haul when the ransom went unpaid. The way in was a zero-day, a flaw with no fix available, sitting inside Oracle's PeopleSoft software that the NAIC ran. Here is the part that should worry every owner: after the breach, credit rating agencies cut their data feeds to the NAIC, which froze a routine industry function for everyone downstream. One vendor's bug became hundreds of companies' problem, and "we're all patched" did nothing to stop it. Next, a story about the person already inside. A former analyst at Huntress, a security company that thousands of small businesses and their IT providers trust to catch hackers, claims a coworker fed information to a ransomware criminal, and that the company stayed quiet ahead of a planned IPO. The CEO calls it a teammate's poor judgment, not a betrayal, and says no, this is not what it looks like. We are careful here, because this is an allegation and the evidence has not been made public, but the lesson lands either way: the threat your firewall cannot stop is a trusted person with access, including the outside provider holding the keys to your network. Finally, the demand from the corner office. A new survey from Cohesity found two-thirds of CEOs now want to hear about an attack within thirty minutes, and more than 80% say someone's job is on the line if recovery drags. The reality check is humbling: only 19% of ransomware victims got back up within a day last year, and a typical attack still caused about 24 days of disruption. The good news is recovery is getting faster and cheaper for companies that actually plan and rehearse it. Recovery time is no longer an IT footnote. It is a board-level number with names attached. Three different doors, one pattern. A trusted vendor, a trusted insider, and your own readiness. The breach keeps arriving through something you already trusted, and the only thing that softens the blow is how fast you catch it and come back. • A zero-day in Oracle PeopleSoft let ShinyHunters claim 3.1 terabytes from the NAIC, and the fallout froze part of the insurance industry. • A former Huntress analyst alleges a coworker leaked information to a ransomware criminal, and the company disputes it. • Why insiders and outside IT providers are the risk your firewall was never built to catch. • A new survey shows CEOs now expect recovery in hours, with jobs on the line if it takes days. • The thread tying it together: the breach comes through trust, and survival comes through speed. • What owners should do this week: map who holds your data, vet your IT provider's insider controls, and set a recovery-time target you actually test. Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #DataBreach #Ransomware #InsiderThreat #Oracle #ShinyHunters #VendorRisk #MSP #CyberResilience #BusinessRisk #SMB
The government just put an AI company inside the NSA. Not to defend networks. To help find ways into them. At the same time, more than 3 million Texans had their driver's license and passport data exposed through a third-party vendor, and attackers harvested credentials from 75,000 Fortinet firewalls around the world, then organized the victims by how much money they were likely worth. Three stories. One uncomfortable reality: The most powerful security tools are being locked up while your biggest risks are still the basics. On this episode of Security Squawk, Bryan Hornung, Randy Bryan, and Reginald Andre break down what business owners, executives, IT leaders, and MSPs need to understand about AI, vendor risk, and the growing gap between the tools governments get and the threats businesses still face every day. Story 1: Anthropic Inside the NSA The Financial Times reported that Anthropic, the company behind Claude, embedded engineers inside the NSA to deploy a frontier AI model called Mythos. The same company that was previously flagged as a supply chain risk is now helping deploy one of the most advanced cyber-focused AI systems in government. Anthropic says the model is too dangerous for broad release. That raises a bigger question: If the most capable AI tools are increasingly treated as national-security assets, what happens when the tools your business depends on become tools you can no longer access? Story 2: 3 Million Texans Exposed Through a Vendor The Texas Parks and Wildlife Department disclosed a breach affecting more than 3 million people after attackers compromised a third-party vendor responsible for hunting and fishing license systems. Exposed data reportedly includes: • Driver's license information • Passport numbers • Home addresses • Phone numbers • Email addresses Officials emphasize that Social Security numbers were not exposed. That's missing the point. A driver's license, passport, address, and contact information already provide everything many criminals need for identity theft, fraud, and account takeover. The lesson is simple: Your security is only as strong as the vendors holding your data. Story 3: 75,000 Fortinet Firewalls Compromised Researchers disclosed a campaign that harvested administrator and VPN credentials from roughly 75,000 Fortinet firewalls across 194 countries. The attackers didn't just collect passwords. They categorized victims by: • Country • Industry • Company size • Estimated revenue In other words, they built a target list. Researchers say the infrastructure remains active and continues collecting credentials. If your organization uses Fortinet equipment, this is not a "someday" problem. This is a this-week problem. In This Episode • Why Anthropic's NSA deployment matters to every business using AI • Whether cybersecurity will become the justification for restricting advanced AI capabilities • How a third-party vendor exposed more than 3 million Texans • Why "no Social Security numbers were stolen" is often the wrong question • How attackers harvested credentials from 75,000 Fortinet devices • The immediate actions Fortinet customers should take • Why cybersecurity still comes down to fundamentals, even as AI transforms the battlefield The Bottom Line Most businesses worry about futuristic threats. Meanwhile, attackers are still winning through vendors, passwords, exposed systems, and concentration risk. The technology is changing fast. The fundamentals are not. Security Squawk is a weekly podcast and livestream focused on cybersecurity, business risk, ransomware, AI, vendor risk, and executive decision-making. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #Anthropic #NSA #AI #Claude #Fortinet #DataBreach #VendorRisk #IdentityTheft #BusinessRisk #MSP #Ransomware #AIRegulation
What happens to your business when the AI tool you rely on gets shut off overnight, not by a hacker, but by the U.S. government? Last Friday, Anthropic, the maker of Claude, pulled its two newest AI models offline within hours of a letter from Washington. This is the first time that has ever happened to a leading AI company, and it should change how every owner thinks about the tools they depend on. Every tool you depend on is a switch someone else can flip. Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for the executives, owners, and operators who don't have time to keep up with cyber news but can't afford to be blindsided by it either. First up: Anthropic. The Commerce Department ordered the company to block its newest models, Fable 5 and Mythos 5, for any foreign national, citing national security. Anthropic couldn't separate who was allowed from who wasn't fast enough, so it shut the models off for everyone just six days after launching them. And the trigger reportedly wasn't a foreign spy at all. It was a warning from a competitor, Amazon, which demonstrated a way to bypass the model's safeguards. If your company has wired a critical process to a single AI vendor, you just watched how fast that capability can vanish. Next, the FBI disrupted one of the largest AI-powered scam operations ever seen. A China-based crime ring called "Outsider Enterprise" used artificial intelligence to write flawless scam texts and blasted out 2.5 million of them in two weeks while impersonating brands people trust through AT&T, T-Mobile, and Verizon. Authorities tied more than one million fake web addresses and 3.8 million stolen credit cards to the operation, with an estimated $1.9 billion in losses. The old advice to "watch for typos" is dead. These messages are clean, personal, and look exactly like the real thing. If your brand gets impersonated, your customers pay the price and your reputation takes the hit. Finally, Russia's military intelligence is hiding inside everyday routers. The group known as Fancy Bear has been quietly taking over the inexpensive routers small offices and remote workers buy off the shelf, including MikroTik, TP-Link, and Ubiquiti EdgeRouters, and using them to steal Microsoft 365 logins in transit. They even hide their commands inside normal cloud services so nothing looks suspicious. At its peak, researchers counted more than 18,000 infected connections across 120 countries. The scariest part: they steal the login token, allowing them to bypass multi-factor authentication and remain logged in even after the password is changed. Three stories. One thread. A government order, a billion-dollar scam ring, and a foreign intelligence unit all reached into technology many organizations assumed they controlled. In this episode, we discuss: • Why the government forced Anthropic to pull its newest AI models and what it means for your business • How an AI-powered crime ring scammed people out of an estimated $1.9 billion • Why the router in your closet might be working for Russian intelligence • How "restrict some" quietly becomes "shut it all off" • Why stolen login tokens can bypass your multi-factor authentication • What concentration risk means when you bet your operation on a single vendor • The Monday-morning moves that actually protect your business Security Squawk is a weekly podcast and livestream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #Anthropic #AI #FBI #Phishing #Smishing #FancyBear #VendorRisk #BusinessRisk #SMB #MFA
Your dental plan just became your biggest security problem. DentaQuest — one of the largest dental-benefits companies in America — had the personal and health data of 2.6 million people dumped online, and almost none of those people ever chose to do business with them. If you think your own company is too careful for this, the newest numbers say otherwise. Confidence you can't prove is just exposure wearing a smile. Bryan Hornung and Randy Bryan break down this week's stories — for the executives, owners, and operators who don't have time to keep up with cyber news but can't afford to be blindsided by it either. (Reginald Andre is out this week — back next episode.) First up: the DentaQuest breach. The extortion crew ShinyHunters stole 234 gigabytes of data, tried to shake DentaQuest down for a ransom, and when the company didn't pay, they dumped the whole thing on a leak site. Inside that pile: names, birthdates, phone numbers, Medicaid IDs, and health-insurance details on 2.6 million people. The detail that should make you angry — researchers found roughly 1.7 million Social Security numbers in a separate folder, and a large share of them appear to belong to children. A stolen kid's SSN is gold to a fraudster, because nobody checks a nine-year-old's credit for ten years. And here's the part every business owner needs to hear: most victims never picked DentaQuest at all — their employer or their state Medicaid program did. Somebody else's vendor became your breach. Then we close on the mirror. A brand-new survey of 4,400 small and mid-size businesses found that owners have never felt more secure — 68% are confident they can stop an attack, and 75% trust they can respond. The problem? 45% of them got breached in the last year anyway. The number that stops you cold: among businesses hit more than once, confidence actually went UP — to 91% in the U.S. Meanwhile two-thirds still don't turn on multi-factor authentication, and only about 17% encrypt their data — the cheap, boring controls that stop most attacks. The average breach at a company under 500 people now runs about $3.31 million. Owners are scared of sci-fi AI malware while the rip current — phishing, weak passwords, no monitoring — is the thing actually pulling them under. Two stories, one crack running through both: somebody assumed they were covered, and the assumption was the vulnerability. The fix isn't more fear or more confidence — it's proof. In this episode, we discuss: • How 2.6 million people got exposed by a company most of them never chose. • Why ShinyHunters' "pay-or-we-leak" model makes your backups useless. • Why a stolen child's Social Security number is worth more than yours. • How small businesses can feel 68% confident and still get breached 45% of the time. • Why getting hit twice somehow makes owners MORE confident — and why that's backwards. • The two cheap controls two-thirds of businesses still skip. • How to replace "I feel secure" with proof you can actually show. Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk
Three breaches. No malware. No zero-days. Just trust being exploited. This week on Security Squawk, Bryan Hornung, Randy Bryan, and Reginald Andre break down three major cybersecurity incidents that reveal a growing reality: attackers are increasingly targeting people, vendors, and physical access instead of technology. NYC Health + Hospitals disclosed a breach affecting 1.8 million individuals after a third-party vendor compromise exposed sensitive patient information, including fingerprints. Carnival Corporation confirmed a cyberattack impacting nearly 6 million people after attackers used social engineering to gain access through an employee account. Meanwhile, the FBI is warning law firms about criminals posing as IT personnel, physically entering offices, deploying malicious USB devices, and stealing privileged client data. These attacks didn't begin with sophisticated malware or advanced exploits. They succeeded because trust was exploited. In this episode, we discuss: • The growing risk of third-party vendor breaches • Why biometric data theft creates permanent consequences • How social engineering continues to defeat security controls • The resurgence of physical intrusion attacks • What CEOs, business owners, IT leaders, and MSPs should be evaluating right now • Why many organizations may be defending the wrong attack surface If your cybersecurity strategy focuses only on networks, endpoints, and firewalls, this episode will challenge some assumptions. Support the show: https://buymeacoffee.com/securitysquawk Subscribe for weekly executive-level cybersecurity analysis focused on business impact, operational risk, and real-world consequences. #CyberSecurity #DataBreach #Carnival #NYCHealthAndHospitals #SocialEngineering #VendorRisk #LawFirmSecurity #CyberAttack #InformationSecurity #MSP #BusinessRisk #SecuritySquawk
This Week's Cybersecurity Breakdown 1. CISA Shrinks While the FBI Expands Its Cyber Role The federal cyber response structure is changing in real time: CISA reportedly lost over 1,000 employees Proposed federal budget would cut another $707 million FBI IC3 received 1 million cybercrime complaints in 2025 Reported financial losses climbed to $20.9 billion Raises major questions about how businesses should think about federal cyber support going forward 2. DocketWise Breach Exposes Sensitive Immigration Data A breach at an immigration legal platform continues to grow: Attackers used valid credentials to clone a developer pipeline Victim count increased from 116,000 to more than 143,000 individuals Exposed data includes: Social Security numbers passport data tax IDs medical history Another example of trusted access becoming the attack surface 3. 7-Eleven Confirms ShinyHunters Breach The ongoing Salesforce-linked extortion campaign continues: 185,000 franchise applicants exposed 7-Eleven reportedly refused ransom demands Attackers released a 9.4 GB archive publicly Campaign has now impacted organizations including: Google Cisco Qantas Allianz Adidas TransUnion LVMH The Bottom Line The cybersecurity assumptions businesses relied on even 18 months ago are changing. Federal cyber resources are shifting Trusted vendors continue getting breached Attackers are increasingly using legitimate access instead of sophisticated exploits And many organizations are still operating under incident response plans built for a threat landscape that no longer exists. Support the show: buymeacoffee.com/securitysquawk Subscribe for weekly breakdowns of ransomware, cybercrime, vendor risk, and executive-level cybersecurity strategy.
A poisoned software package compromised OpenAI employee devices before security teams could stop it. The company behind critical Ozempic injection components has been offline for weeks after a ransomware attack. And Change Healthcare is now facing another major lawsuit tied to the 2024 breach that crippled healthcare payments nationwide. Three stories. One message: Your business is now exposed to companies you don't control. On this episode of Security Squawk, Bryan Hornung, Randy Bryan, and Reginald Andre break down three cyber incidents that reveal how third-party trust has become one of the biggest operational risks in business today. This Week's Cybersecurity Breakdown 1. OpenAI, TanStack & the npm Supply Chain Worm A software supply chain attack spread through trusted developer ecosystems at massive speed: 42 npm packages poisoned in six minutes Malware stole GitHub tokens, AWS credentials, and CI/CD secrets OpenAI confirmed two employee devices were compromised ChatGPT Desktop, Codex App, Codex CLI, and Atlas certificates rotated Demonstrates how modern attacks now spread through trusted development infrastructure 2. West Pharmaceutical Ransomware Attack A cyberattack against a company most people have never heard of — but nearly everyone depends on: West Pharmaceutical components are used in roughly 43 billion injectable drug deliveries annually Includes Ozempic, Wegovy, insulin pens, vaccines, and hospital injectables Systems taken offline globally after ransomware deployment Manufacturing disruptions continue weeks later 3. Allied World v. Change Healthcare — The Financial Fallout Begins The legal consequences of the Change Healthcare breach are escalating: Cyber insurer Allied World filed suit seeking more than $1 million in damages Avesis operations were disrupted for roughly 90 days Root cause traced to a low-level Citrix account with no MFA Credentials were reportedly circulating on Telegram prior to the breach The Bottom Line The modern business attack surface is no longer just your company. It's: your software vendors your healthcare clearinghouses your package repositories your pharmaceutical suppliers Every trusted relationship is now a potential point of failure. And when those companies get breached, your business absorbs the consequences. Support the show: buymeacoffee.com/securitysquawk Subscribe for weekly breakdowns of ransomware, supply chain attacks, AI threats, and executive-level cybersecurity strategy.
A cybersecurity line just got crossed. Google has now confirmed the first known case of hackers using artificial intelligence to build a working zero-day exploit that bypasses two-factor authentication. At the same time, Instructure the company behind Canvas, used by over 9,000 schools worldwide appears to have quietly paid a ransom after ShinyHunters stole 275 million student and teacher records and defaced hundreds of school login pages. And if you think these attacks are rare, new data from BlackFog says otherwise: 90% of ransomware attacks this quarter were never publicly disclosed. Most breaches never make headlines. On this episode of Security Squawk, Bryan Hornung, Randy Bryan, and Reginald Andre break down three stories that reveal where cybercrime is heading next and why most organizations are less prepared than they think. This Week's Cybersecurity Breakdown 1. Canvas / Instructure Data Breach & Apparent Ransom Payment One of the largest education-sector breaches in recent memory: 275 million records allegedly stolen 3.65 TB of data taken from roughly 8,800+ schools Harvard, Stanford, Columbia, Duke, UNC, and other institutions impacted ~330 Canvas login portals defaced with ransomware messages Instructure later announced it had “reached an agreement” with attackers 2. AI Builds the First Confirmed Zero-Day Exploit Google's Threat Intelligence Group confirmed a major escalation: AI used to create a working zero-day exploit Attack specifically targeted two-factor authentication protections Signals a shift in offensive cyber capabilities previously associated with nation-state actors AI is no longer just assisting attackers it's helping build the attacks themselves 3. BlackFog Q1 2026 Report The Hidden Ransomware Crisis The public only sees a fraction of what's happening: 2,160 undisclosed ransomware attacks vs. 264 disclosed Only 1 in 9 attacks becomes public Average ransom demands surpassed $1 million Data stolen in 96% of incidents before encryption Backups alone are no longer enough The Bottom Line Cybersecurity is entering a new phase. AI is accelerating offensive capabilities Ransomware groups are operating in the shadows And organizations are quietly paying attackers to keep breaches out of public view This isn't just a technology problem anymore. It's an operational reality every business leader needs to understand. Support the show: buymeacoffee.com/securitysquawk Subscribe for weekly breakdowns of ransomware, cybercrime, AI threats, and executive-level cybersecurity strategy.
A major U.S. payment processor just got hit by ransomware, again. TSYS, one of the largest payment processors in the country, has been attacked by the Everest ransomware group for the second time in five years. Industry experts warned this was coming. It happened anyway. At the same time, ShinyHunters claims it stole 275 million records from Instructure, the company behind Canvas, the learning platform used by over 9,000 schools. Names, student IDs, and billions of private messages between students and teachers are now at risk. And in healthcare, regulators just fined four companies $1.165 million for ransomware-related failures, not because they were hacked, but because they ignored basic security requirements that have been in place since 2003. In one case, attackers sat inside a network for 16 months undetected. These aren't advanced attacks. These are failures to do the fundamentals. This Week's Cybersecurity Breakdown 1. TSYS Ransomware Attack (Everest Group) A repeat breach at a major payment processor: Systems encrypted and data exfiltrated Second major incident in five years Also impacts Fiserv Raises serious questions about systemic risk in payment infrastructure 2. Instructure / Canvas Data Breach (ShinyHunters) Massive education sector exposure: 275 million records allegedly stolen Student data, IDs, and private communications compromised Root cause: Salesforce misconfiguration Potential impact across 9,000+ schools 3. HHS HIPAA Fines for Ransomware Failures Regulatory enforcement is accelerating: $1.165 million in fines across four companies Failure to complete required security risk assessments One breach went undetected for 16 months OCR has now completed 19 ransomware investigations with the same pattern The Bottom Line These attacks aren't breaking through defenses. They're walking through doors that were never closed. Misconfigurations Missing risk assessments Known vulnerabilities left unpatched This isn't a technology problem. It's an execution problem. Support the show: buymeacoffee.com/securitysquawk Subscribe for weekly breakdowns of real-world cyber threats, ransomware attacks, and executive-level security insights.
A new type of cyberattack is bypassing every security tool you've invested in — and it starts with a simple Microsoft Teams message. No malware. No exploit. No zero-day. Just someone pretending to be IT support. At the same time, new data shows 73% of ransomware attacks are now entering through VPNs, and small businesses are absorbing an average of $422,000 per incident. Meanwhile, KPMG just released its 8 cybersecurity priorities for 2026, sending a clear message to executives: the biggest risk isn't technology — it's leadership. On this episode of Security Squawk, Bryan Hornung, Randy Bryan, and Reginald Andre break down three critical developments every business leader needs to understand right now. This Week's Cybersecurity Breakdown 1. Microsoft Teams Hack (UNC6692 Attack Campaign) Hackers are impersonating IT support inside Microsoft Teams to gain access to enterprise environments. No software vulnerability exploited Targets C-suite and senior leadership (77% of victims) Uses legitimate platforms like AWS and Heroku to evade detection 2. VPNs Are Now the Front Door for Ransomware (At-Bay 2026 Report) New insurance data reveals a sharp increase in ransomware attacks targeting VPN infrastructure: 73% of attacks originate through VPNs 60% of victims had EDR deployed — and still got hit SonicWall vulnerabilities linked to a significant percentage of attacks Average loss: $422,000 for SMBs 3. KPMG's 8 Cybersecurity Priorities for 2026 A strategic warning for boards, CEOs, and executives: AI is now an attack surface Non-human identities (APIs, service accounts) are a major blind spot Supply chain attacks are becoming the primary entry point Cybersecurity is no longer an IT issue — it's a leadership responsibility The Bottom Line The biggest cybersecurity gap today isn't technical. It's leadership. You can't patch employee trust You can't rely on tools without oversight You can't delegate cyber risk and expect protection If you're running a business, this is required awareness. Support the show: buymeacoffee.com/securitysquawk Subscribe for weekly breakdowns of real-world cyber threats, ransomware trends, and executive-level security insights.
The Everest ransomware group claims it has stolen 250,000+ Social Security Numbers and 3.4 million banking records from Frost Bank and Citizens Bank — and the leak countdown is already ticking. At the same time, ShinyHunters just executed coordinated attacks on Zara, Carnival, and 7-Eleven, while a Vercel breach tied to a compromised AI tool exposed how a single employee action can trigger a multi-million dollar data incident. This isn't theoretical cybersecurity risk — this is happening right now, and it directly impacts your business, your customers, and your exposure to AI-driven threats. On this episode of Security Squawk, Bryan Hornung, Randy Bryan, and Reginald Andre break down three major cyberattacks shaping the current threat landscape — and what leaders need to understand immediately. This Week's Cybersecurity Breakdown 1. ShinyHunters Cyberattacks (Zara, Carnival, 7-Eleven) One of the most aggressive data breach groups in the world targeted three global brands with a pay-or-leak ultimatum. Carnival: 8.7 million customer records stolen 7-Eleven: 600,000+ Salesforce records compromised Zara: breach originated through third-party vendor Anodot with cloud access 2. Everest Ransomware Attack (Frost Bank & Citizens Bank) A high-impact ransomware operation targeting major U.S. financial institutions: 380+ GB of stolen data posted to a dark web extortion site Includes SSNs, banking data, and unencrypted credit card numbers with CVVs Raises serious questions about data security standards in 2026 3. Vercel Data Breach via AI Tool (Context.ai) A textbook example of modern attack vectors: A single employee connected a compromised AI tool with “Allow All” permissions Attackers gained access to internal systems and are now selling the data for $2 million Highlights the growing risk of AI integrations in enterprise environments Why This Matters These incidents expose three critical realities: Third-party vendors are now primary attack surfaces Ransomware groups are escalating speed and scale AI tools are introducing new, poorly understood security risks If you run a business, manage IT, or rely on cloud platforms — this is required awareness. Support the show: buymeacoffee.com/securitysquawk Subscribe for weekly breakdowns of real-world cyber threats, ransomware attacks, and security leadership insights.
A ransomware attack on one software vendor exposed 823,000 people's Social Security numbers and bank account data across 80 community banks — and those banks didn't find out for 74 days. That's just one of three stories on today's Security Squawk that show exactly how the vendor trust chain is failing businesses right now. Bryan, Randy, and Reginald break down: a brand-new extortion crew called UNC6783 that's been hitting "several dozen" high-value corporations — including an alleged Adobe breach of 13 million support tickets — by breaking into their outsourced call centers and help desks instead of the companies themselves. Then Microsoft's new research on the Medusa ransomware group (tracked as Storm-1175), which is exploiting zero-day vulnerabilities before patches even exist and can go from initial access to full ransomware deployment in under 24 hours. And finally, the full Marquis Software story: a fintech vendor breach that cascaded through 80 community banks, led to a ransom payment, and ended with Marquis suing their own firewall vendor SonicWall for gross negligence while defending 36+ consumer class action lawsuits. If you trust vendors with your customer data — and you do — this episode is about what happens when that trust gets broken.
Chinese state-linked hackers breached the FBI's own surveillance system — and they got in through a vendor. That's not a spy novel plot; that's a confirmed federal "major incident" declared at the highest severity level under FISMA, and it happened in 2024. That's just the opener. On this episode of Security Squawk, Bryan Hornung, Randy Bryan, and Reginald Andre cover three stories that show exactly what happens when third-party risk, healthcare IT gaps, and a single phone call aren't taken seriously enough. SALT TYPHOON HACKS THE FBI — China's Salt Typhoon threat group targeted a vendor ISP with access to the FBI's court-authorized wiretap surveillance system. The breach was classified as a FISMA "major incident," the federal government's highest severity designation. BROCKTON HOSPITAL CYBERATTACK — April 6, 2026: ambulances diverted, chemo cancelled, pharmacies closed, staff on paper records. The same hospital was breached in 2021. Average healthcare ransomware recovery: $2.5M, 19 days, 33% increase in patient mortality. HIMS & HERS VISHING ATTACK — 2.5 million subscribers. $2.35 billion in revenue. Gone through one phone call. ShinyHunters used a single vishing call to steal an Okta SSO credential and access Zendesk support tickets. CA AG notified. Class action filed. Support the show: buymeacoffee.com/securitysquawk
A ransomware attack walked in through one email, sat silent for two days, then destroyed every computer in an Indiana sheriff's office — and the FBI is still investigating. That's just one of three cybersecurity stories that every business owner needs to hear this week. On this episode of Security Squawk, Bryan Hornung, Randy Bryan, and Reginald Andre cover: CHUBB'S 2026 CYBER CLAIMS REPORT — The average cyber insurance claim for large businesses nearly DOUBLED in one year, jumping from $2.2 million to $4.4 million. That's a 586% increase since 2021. And with premiums projected to rise 15-20% in 2026, the cyber insurance market is about to get expensive — even for small and mid-size businesses. ALAMO HEIGHTS ISD CYBERATTACK — A San Antonio-area school district serving 5,400 students went completely offline. Wi-Fi down. Gmail down. Third-party forensic investigators brought in. 27 Texas school districts hit in two years — and $55 million in state grants existed to prevent this. Only one-third applied. JACKSON COUNTY SHERIFF'S OFFICE RANSOMWARE ATTACK — A dormant ransomware payload entered through a phishing email, waited 48 hours, then activated and spread across every connected system. "Anything that it touched, it corrupted so bad, it won't be able to be used again." The sex offender registry may be permanently lost. Support the show: buymeacoffee.com/securitysquawk
31% of businesses that had backup solutions still failed to restore their data during a ransomware attack according to At-Bay's analysis of 186 real insurance claims. And if you think your business is safe because someone "set up backups," you need to watch this. Meanwhile, there are 4.8 million unfilled cybersecurity jobs globally right now and 61% of midsize businesses have zero dedicated security staff on payroll. Bryan Hornung and Reginald Andre break down exactly how bad the staffing gap has gotten (ISC2's 2025 Cybersecurity Workforce Study shows the pipeline shrank from 31% growth in 2022 to just 12% in 2024), why your IT person is being set up to fail, and how much a single mid-level security analyst actually costs vs. what an MSSP can deliver at the same price. Then they go straight at the backup crisis: the 25-point confidence gap between what IT teams believe about recovery and what At-Bay, Sophos, and Spiceworks data actually show. Ransomware attackers are targeting your backup repositories first before they trigger the main attack. The average business is down 24 days after a ransomware hit, with average recovery costs of $1.53 million. For a business under 500 employees, that can be existential. This episode is for every business owner who has ever said "we have backups" or "IT handles security" and hasn't verified either of those statements. Support the show: buymeacoffee.com/securitysquawk
A ransomware negotiator at DigitalMint secretly ran the attacks he was being paid to stop and then negotiated ransoms on behalf of the companies he'd just hit. This week on Security Squawk, we break down $75 million in extorted ransoms, an Iranian hacker group that destroyed 80,000 Stryker devices in three hours without using any malware, and a new Ponemon Institute survey showing 77% of industrial companies got breached in the past year. DigitalMint: Angelo Martino, a ransomware negotiator at Chicago-based cybersecurity firm DigitalMint, has been charged with running at least 10 ransomware attacks using the BlackCat/ALPHV gang while simultaneously negotiating ransoms for his own victims. Five companies he attacked then hired DigitalMint and were assigned Martino as their negotiator. Ransoms totaled $75.25 million. Two co-conspirators, including another DigitalMint negotiator and an employee at rival firm Sygnia, already pleaded guilty in December. Stryker: On March 11, the Iran-linked hacktivist group Handala wiped approximately 80,000 employee devices at medical device giant Stryker using Microsoft Intune, the same device management tool your IT team uses every day. No malware. No ransomware. Just a compromised admin account and a "remote wipe" command. OT Security Survey: A new Ponemon Institute survey commissioned by Siemens Energy found 77% of organizations running operational technology factories, pipelines, utilities, industrial control systems were breached in the last 12 months. 41% of attacks go completely undetected. Recovery takes seven months on average. Support the show: buymeacoffee.com/securitysquawk
A hacker used an AI chatbot to break into 10 government agencies and steal records on 195 million people — without writing a single line of code. Meanwhile, Cognizant's TriZetto healthcare billing platform sat silently compromised for over a year while 3.4 million patients' data walked out the door. This week on Security Squawk, Bryan Hornung, Randy Bryan, and Reginald Andre break down four stories that will change how you think about cybersecurity risk in 2026. COGNIZANT TRIZETTO + UMMC TriZetto Provider Solutions — a Cognizant company that processes medical billing for thousands of doctors and hospitals — was breached in November 2024. The company didn't discover it until November 2025. One full year. In that time, 3,433,965 patients had their Social Security numbers, Medicare IDs, birth dates, and health insurance details exposed. And in parallel: UMMC was hit by ransomware in February 2026 — shutting down all 35 of its statewide clinics for nine days, canceling surgeries, and sending doctors back to pen and paper. AKZONOBEL AkzoNobel — the $12 billion paint giant behind Dulux — confirmed that the Anubis ransomware gang stole 170GB of data from one of its U.S. sites. Passport scans, private emails, confidential client agreements. They called it "contained." The data is already public. AI AND THE MEXICO GOVERNMENT HACK Fewer than five people used Claude Code AI to breach 10 Mexican government agencies. 150 GB stolen. 195 million identities exposed. The AI initially said no. The attacker talked it into cooperating anyway. The cost of entry for a sophisticated cyberattack just became the price of an AI subscription. [00:00] Intro [02:30] Cognizant TriZetto: 3.4M Patients, 1 Year of Silence [11:00] UMMC: 9-Day Clinic Shutdown Update [15:30] AkzoNobel: "Contained" Means Nothing When the Data Is Already Gone [21:00] Claude Code and the Mexico Hack: AI Just Became a Weapon Anyone Can Afford [27:00] Wrap-Up Support the show: buymeacoffee.com/securitysquawk
This week's Security Squawk episode isn't about phishing. It's about structural weakness. Three separate incidents. Three different industries. One uncomfortable pattern: the systems organizations trust most are expanding risk quietly — and in some cases, architecturally. First, a lawsuit that should make every board member pay attention. Marquis Software Solutions, a fintech serving 74 U.S. banks, is suing SonicWall. The allegation centers on SonicWall's cloud backup system, where firewall configuration backups were allegedly accessible and contained credentials — including MFA scratch codes. Those backups were reportedly used to compromise Marquis, leading to a ransomware incident and downstream exposure. What began as a scoped 5% customer exposure was later reported as potentially impacting all customers. This is not a misconfigured endpoint. This is a control-plane failure. For CEOs, this reframes vendor risk. It's no longer a questionnaire exercise. It's a litigation vector. If a security provider's design exposes authentication artifacts, your internal diligence may not matter. The liability chain now includes vendors and MSPs in a very direct way. For IT Directors, the operational question is simple: what exactly is inside your firewall backups? Are reusable authentication artifacts stored? Who can access vendor-hosted exports? If attackers obtain your configuration backups, can they replay your defenses? For MSPs, the exposure is real. If you manage firewall exports or MFA deployments, you are part of the architecture. And potentially part of the courtroom. Then we shift to UFP Technologies, a medical device manufacturer. Intrusion detected. Billing and shipping label systems disrupted. Data stolen or destroyed. Insurance expected to offset financial impact. But this isn't primarily a data story. Attackers disrupted order-to-cash and fulfillment velocity. In healthcare supply chains, slowing billing and labeling can create immediate executive escalation without touching the factory floor. Modern ransomware groups increasingly target business process choke points — ERP, labeling, scheduling — because leverage doesn't require full encryption anymore. For CEOs, “no material impact expected” is accounting language. Customers measure impact in delayed shipments. For IT leaders, the question becomes operational: can billing, labeling, and fulfillment functions recover independently? Are those systems segmented? Tested? Immutable? For risk managers and insurers, this represents a shift in underwriting focus — from endpoints to process resilience. Finally, the University of Hawaiʻi Cancer Center ransomware incident. Roughly 87,000 study participants directly impacted. But historical datasets, including Social Security numbers collected from driver's license and voter registration data dating back to 1998, expanded potential exposure to nearly 1.2 million individuals. They engaged the threat actors. They received a decryptor. They received “assurances” that data was destroyed. That's not verification. That's negotiation. The uncomfortable truth: legacy identity data becomes modern ransom currency. Research environments often have weaker governance than clinical systems, yet they can contain decades of sensitive identifiers. For boards, the issue isn't just security posture. It's data retention discipline. What obsolete identity data are you still holding? Why? For how long? And who owns the risk? Across these stories, three themes emerge: Control-plane trust is fragile. Operational choke points are the new leverage strategy. Data retention is compounded liability. Cybersecurity is no longer just about stopping intrusion. It's about architectural accountability and governance maturity. If you value independent, executive-level analysis without vendor spin, support the show at: buymeacoffee.com/securitysquawk The real question is this: Are your greatest cyber risks coming from external attackers — or from design decisions you haven't revisited in years?
Hospital Shutdown, Ransomware Surge, Fortinet Failures A hospital doesn't cancel chemotherapy appointments because of a “technical issue.” They cancel them because they've lost operational control. This week, the University of Mississippi Medical Center shut down its entire network after a ransomware attack disrupted systems — including Epic. Clinics closed. Elective procedures paused. Outpatient services halted. Emergency operations activated. Leadership described the shutdown as precautionary. But here's the real question executives should be asking: Why was a full network shutdown necessary? If segmentation is validated… If identity governance is enforced… If lateral movement detection is operationalized… Why does the only safe option become “turn it all off”? In this episode of Security Squawk, we break down what this incident signals about containment confidence, governance maturity, and operational resilience — not just in healthcare, but across every industry that depends on uptime. And we zoom out. Because UMMC isn't happening in isolation. According to TechRadar, ransomware groups have reached an all-time high in 2025. The victim growth rate has doubled. Qilin and other affiliate-driven operators are scaling aggressively. This isn't random chaos. It's industrialization. More fragmentation. More specialization. More execution discipline on the criminal side. Healthcare, public sector, and critical infrastructure are being economically targeted because downtime equals leverage. When systems go dark, negotiation pressure spikes. Then we connect it to something many leaders are still underestimating: Fortinet exploitation patterns. Edge vulnerabilities. VPN credential harvesting. Reinfection cycles months after patches were released. The vulnerability itself isn't the story. The response maturity is. Attackers are repeatedly probing whether organizations: – Patch fast enough – Rotate exposed credentials – Reset trust boundaries after compromise – Validate segmentation integrity – Rebuild identity confidence When those governance steps are skipped, attackers come back. That's not a tooling failure. That's a leadership failure. This episode translates three headlines into one hard truth: Ransomware is no longer just a malware problem. It's a containment confidence problem. For CEOs: If you cannot isolate an intrusion without shutting down revenue operations, your resilience model is fragile. For IT Directors: Active Directory recovery is not a restore-from-backup event. It's a trust re-establishment event. For MSPs: Client environments are operating in a denser criminal ecosystem. Tool stacking without maturity validation will not scale. For Risk Leaders: Financial exposure is no longer limited to ransom. Revenue interruption, regulatory scrutiny, and reputational damage compound quickly — especially in healthcare. We also discuss: • Why attacker communication often signals a second phase • Why affiliate ransomware models are accelerating • Why segmentation validation will become a board-level metric • Why detection speed does not equal governance strength Security Squawk exists to translate cybersecurity chaos into business reality — without vendor spin and without hype. If you value that kind of analysis and want to support independent, executive-focused cybersecurity conversations, you can back the show at: buymeacoffee.com/securitysquawk Your support helps us keep this live, timely, and unfiltered. Because criminals are already running maturity audits. And they invoice in operational shutdown. The question is simple: If it happened to you tomorrow, could you contain it — or would you turn the lights off?
Google has confirmed that state-backed threat actors are operationally using Gemini across the intrusion lifecycle — not experimentally, but strategically. In this episode of Security Squawk, we break down how AI is being integrated into reconnaissance, phishing refinement, vulnerability research, and even dynamic malware generation. According to Google's Threat Intelligence Group, multiple clusters — including DPRK-linked actors — are using Gemini to synthesize OSINT, map organizational structures, refine recruiter impersonation campaigns, and research exploit paths. In one case, malware known as HONESTCUE leveraged Gemini's API to dynamically generate C# code for stage-two payload behavior, compile it in memory using legitimate .NET tooling, and execute filelessly. This isn't a zero-day story. It's a friction story. At the same time, two individuals in Connecticut were charged for allegedly using thousands of stolen identities to exploit FanDuel's onboarding and promotional systems. No exotic exploit. No advanced intrusion chain. Just automated workflow abuse at scale. The pattern is clear: AI is compressing attacker timelines, and identity-driven fraud is industrializing predictable processes. We examine: How AI-enhanced phishing eliminates traditional grammar-based red flags Why trusted SaaS domains (Gemini share links, Discord CDNs, Cloudflare fronting, Supabase backends) are weakening reputation-based defenses What model distillation attempts (100,000+ structured prompts) signal about API abuse and intellectual property risk How fileless malware compiled with legitimate developer tooling challenges signature-based detection Why onboarding workflows and recruiting processes are now primary attack surfaces For CEOs, this is about erosion of trust anchors and shifting insurability expectations. For IT Directors and SOC leaders, this means reevaluating fileless execution visibility, API anomaly detection, and the reliability of reputation filtering models. For MSPs and risk managers, breaches will increasingly originate from workflow exploitation rather than perimeter misconfiguration. AI didn't invent new attack types. It removed friction from existing ones. And when friction disappears, scale compounds. If your recruiting, onboarding, verification, or AI product interfaces can be scripted — they can be weaponized. This episode is about operational clarity in a rapidly compressing threat landscape. Keywords: Google Gemini, HONESTCUE malware, AI phishing, state-backed threat actors, DPRK cyber operations, model distillation attacks, API abuse detection, fileless malware, .NET in-memory compilation, identity fraud, FanDuel fraud case, workflow exploitation, SaaS infrastructure abuse, Cloudflare phishing, Discord CDN payloads, Supabase backend abuse. Support the show https://buymeacoffee.com/securitysquawk
In this episode of Security Squawk, Bryan Hornung, Reginald Ande, & Randy Bryan break down three stories that should change how executives think about cyber risk. This is not about tools, alerts, or vendor promises. It is about operational dependency, leadership accountability, and financial exposure when systems fail. Story one focuses on active exploitation of SolarWinds Web Help Desk vulnerabilities being used as an entry point for ransomware staging. Researchers are seeing attackers move fast after initial access, blending in by using legitimate remote management and incident response tools. That is the point. When attackers use normal looking admin utilities, many organizations do not detect the intrusion until the business impact is already locked in. If you run Web Help Desk or you have not verified your patch posture, this is a governance issue, not an IT debate. Patch timelines and exposure management are leadership decisions because they directly affect business interruption risk. Story two is a warning about the ransomware market adapting. As more organizations refuse to pay for data theft only extortion, threat actors are expected to pivot back toward encryption. Encryption creates urgency because it disrupts operations. The financial exposure shifts toward downtime, recovery labor, lost revenue, and customer churn. Executives should treat restore capability like a business continuity requirement. If your recovery plan has not been tested under pressure, it is not a plan. Story three covers the BridgePay ransomware incident and the downstream impact on merchants and local government services. Even when payment card data is not confirmed compromised, availability failures still create real harm. Customers do not care which vendor was hit. They only see that your business cannot process transactions. This is a clear reminder to revisit vendor criticality, SLAs, outage communications, and contingency processing options. Security Squawk is built for business owners, executives, board members, and IT leaders who want the real world impact without the fear marketing. Subscribe, share, and support the show at https://buymeacoffee.com/securitysquawk
Cyber risk is escalating fast, and most business leaders are still operating with outdated assumptions. This episode of Security Squawk confronts that reality head on. Ransomware is no longer limited to encrypted files and downtime calculations. Threat actors are escalating pressure tactics into the physical world, including intimidation and direct threats against employees and executives. That shift fundamentally changes the risk profile for organizations. Once physical safety enters the equation, cybersecurity stops being a technical issue and becomes a leadership, legal, and duty of care problem. Companies that are unprepared for this escalation expose themselves to serious liability, regulatory scrutiny, and reputational damage that insurance alone cannot fix. At the same time, businesses are quietly introducing new risks through personal AI agents and automation tools. These tools are often adopted without security review, legal oversight, or compliance consideration. Marketed as productivity enhancers, personal AI agents frequently operate with broad access to email, files, customer data, and internal systems. When these agents mishandle or leak data, responsibility does not fall on the software vendor or the employee experimenting with automation. It falls squarely on the business. Regulators, insurers, and courts do not accept ignorance or convenience as a defense. We also examine why extortion groups like ShinyHunters continue to succeed even as companies invest heavily in security controls. This is not about sophisticated hacking techniques. It is about business pressure. Attackers understand deadlines, brand risk, customer trust, and executive fear. They exploit supply chains, third party vendors, and disclosure obligations to force decisions under time constraints. Paying extortion may feel like resolution, but it often increases long term risk, invites repeat targeting, and complicates regulatory reporting. Throughout this episode, the focus is not on tools, vendors, or technical jargon. It is on decision making. Who owns cyber risk inside the organization? How prepared is leadership to respond when incidents move beyond IT into legal, HR, and physical security territory? And how does a board defend its actions when regulators or plaintiffs start asking questions after an incident? This conversation is designed for CEOs, business owners, board members, and senior leaders who understand that cybersecurity is inseparable from operational risk, financial exposure, and executive accountability. If your strategy relies on cyber insurance, compliance checklists, or the belief that serious incidents only happen to larger companies, this episode will challenge that thinking. Security Squawk cuts through vendor noise and fear driven messaging to focus on what actually matters to businesses making real decisions. Support the show at https://buymeacoffee.com/securitysquawk
This episode of Security Squawk breaks down a familiar and dangerous pattern in cybersecurity. Major brands are losing data. Attackers are moving fast. And companies are still relying on silence and delay as a response strategy. We cover hackers auctioning stolen source code from a major retailer, an unprotected database exposing millions of Gmail and Instagram records, ransomware claims involving Nike and Under Armour, and a gas station breach that exposed Social Security numbers. This is not about advanced hacking techniques or rare exploits. It is about basic security failures, weak response decisions, and the real business impact of hesitation after data exposure. If you are a business owner, executive, or IT leader, this episode explains why modern breaches cause damage long before confirmation and why waiting to respond often shifts risk onto customers and employees
Cybersecurity failures are no longer just IT problems. They are legal, financial, and leadership failures. In this episode of Security Squawk, we break down how a ransomware attack on Ireland's Office of the Ombudsman delayed justice for citizens and what that incident reveals about preparedness, accountability, and real-world consequences of cyber risk. We start with the Ireland cyberattack that forced a key public watchdog agency to halt case processing for months. This was not a minor disruption. Systems were taken offline, legal action was required to prevent potential data leaks, and people relying on the system became collateral damage. The story highlights a hard truth. When cybersecurity fails, mission failure follows. Government or private sector, the outcome is the same. From there, we zoom out to the private sector where the warning signs are flashing red. New survey data shows cybersecurity litigation risk is rising faster than any other legal exposure for U.S. businesses. Corporate legal teams expect cyber and data privacy disputes to intensify, yet fewer of them feel prepared compared to last year. That gap tells us everything we need to know. Companies understand the risk is growing, but they are not investing or aligning fast enough to reduce it. We also examine the dangerous confidence gap in middle market firms. Nearly one in five experienced a cyber incident, yet almost all executives still believe their security posture is strong. Confidence without controls is not resilience. It is exposure. This disconnect raises serious questions about leadership accountability and how security decisions are being made at the executive level. The episode also dives into research showing that many top U.S. companies still fail basic cybersecurity hygiene. Reused passwords, outdated software, poor configuration, and unpatched systems remain common in 2025. These are not advanced threats. These are fundamentals. When organizations cannot execute the basics, the issue is not technical skill. It is culture, discipline, and leadership priority. We discuss the ongoing wave of data breaches affecting insurance, healthcare, and business services organizations, exposing millions of records. These incidents are proof that many companies remain reactive instead of proactive. Third-party risk, weak internal controls, and poor governance continue to amplify the damage. Finally, we tackle a growing blind spot. AI security governance. As businesses rapidly adopt AI tools, many still lack formal rules, oversight, or risk frameworks. Without governance, innovation turns into liability. Attackers move faster than policy, and organizations are left exposed. This episode is a wake-up call for business leaders, MSPs, IT professionals, and security decision-makers. Cybersecurity is no longer about compliance checklists or technology spend. It is about reducing real risk, protecting trust, and leading responsibly. If you want to understand why cyberattacks now lead to lawsuits, why confidence is not the same as security, and why leadership decisions matter more than ever, this episode delivers the insight you need. Subscribe, follow, and share Security Squawk. And if you want to support the show, you can always buy me a coffee at buymeacoffee.com/securitysquawk.
Today on Security Squawk we are breaking down three different incidents that all point to the same underlying issue. Basic security failures with real consequences. An Oregon state agency exposes personal information tied to environmental complaints. Nissan suffers a ransomware incident that leaks nearly 900 gigabytes of internal data. And an Illinois government agency exposes sensitive information connected to more than 700,000 individuals. Randy Bryan, Reginald Andre, and Bryan Hornung walk through what actually happened, why these incidents keep repeating across industries, and what they mean for businesses that assume they are too small or too quiet to be targeted. If government agencies and global manufacturers are struggling with access control, monitoring, and accountability, the real question is what that means for your organization. Join us live to understand the risks and what to do next. Join Randy Bryan, Reginald Andre, and Bryan Hornung live and be part of the conversation.
University of Phoenix confirms a massive data breach affecting almost 3.5 million current and former students, staff, and partners after attackers exploited a zero-day in Oracle E-Business Suite. We break down the implications for identity theft risk and breach response. Next, Andre explains why most existing medical devices would fail the FDA's new cybersecurity standards and how healthcare organizations can manage legacy device risk in critical environments. Finally, Bryan breaks down a cloud breach spree that hit 50 global organizations because multi-factor authentication wasn't enforced. Learn why MFA is no longer optional and how basic security failures lead to major breaches. Tune in for expert insights, practical advice, and what every IT leader needs to know today.
In this annual Security Squawk tradition, we do two things most people avoid: accountability and predictions. First, we break down the top cyber-attacks of 2025 and translate them into what actually matters for business owners, IT pros, and MSPs. Then we grade our predictions from last year using real outcomes. No excuses. No hand waving. No “well technically.” Why does this episode matter? Because 2025 made one thing painfully clear. Most cyber damage does not come from genius hackers. It comes from predictable failures. Unpatched systems. Over-trusted third parties. Tokens and sessions that live too long. Help desks that can be socially engineered. And organizations that still treat cybersecurity like an IT issue instead of a business survival issue. We start with the Top 10 Cyber-Attacks of 2025 and pull out the patterns hiding behind the headlines. This year's list includes ransomware and extortion campaigns, software supply chain failures, identity and OAuth token abuse, and attacks that caused real operational disruption, not just data exposure. These stories show how attackers scale impact by targeting widely deployed platforms and trusted business tools, then turning that access into downtime, data theft, and brand damage. One of the biggest lessons of 2025 is simple: identity is the new perimeter. Many of the most important incidents were not break-in stories. They were log-in stories. Stolen sessions and OAuth tokens keep working because they let attackers bypass MFA, move quickly, and blend in as legitimate users. If your security strategy is focused only on blocking failed logins, you are watching the wrong signal. 2025 also reinforced how fragile third-party trust has become. Integrations are everywhere. They make businesses faster and more efficient, but they also expand the blast radius. When a third-party tool or service account is compromised, it can become a shortcut into systems that were never directly attacked. In this episode, we talk about practical steps like minimizing access scopes, eliminating unnecessary integrations, shortening token lifetimes, and having a real plan to revoke access when something looks off. We also dig into why on-prem enterprise tools continue to get hammered. Many organizations still run internet-facing platforms that are patched slowly and monitored poorly. Attackers love that combination. In 2025, we saw repeated exploitation of high-value enterprise software where a single weakness led to widespread compromise across industries. If your patching strategy is “we will get to it,” attackers already have. Another major theme this year was operational disruption. Some of the costliest incidents were not just about stolen data. They shut down production, halted sales, broke customer service systems, and created ripple effects across supply chains. That is where executives feel cyber risk the hardest. Data loss hurts. Downtime is a business emergency. Then we grade last year's predictions. Did AI take our jobs? Not even close. What it did do was raise the baseline for both attackers and defenders. AI improved phishing quality, accelerated scams, and forced organizations to confront the risks of adopting new tools without clear controls. We also review our call on token and session-based attacks. That prediction aged well. Identity-layer abuse dominated 2025. The issue was not a lack of MFA. The issue was that attackers did not need to defeat MFA if they could steal what comes after it. We also revisit regulation. It did not arrive all at once. It crept forward. Agencies and lawmakers continued tightening expectations, especially in sectors that keep getting hit. Businesses that wait for mandates before improving controls will pay more later, either through recovery costs, insurance pressure, or lost trust. Finally, we look ahead to 2026 with new predictions that are probable, not obvious. We discuss what is likely to change around identity, help desk security, SaaS governance, and how leaders measure cyber readiness. The short version is this: 2026 will reward companies that treat access as a living system and punish those that treat it like a one-time setup. If you like the show, help us grow it. Subscribe, leave a review, and share this episode with someone who still thinks cybersecurity is just antivirus and a firewall. And if you want to support the podcast directly, buy me a coffee at buymeacoffee.com/securitysquawk.
Cyber attacks are no longer a future problem or a Silicon Valley issue. They are happening right now across the United States, quietly and relentlessly, targeting local governments, public agencies, schools, police departments, fire services, and critical infrastructure that most people rely on every day. In this episode of the Security Squawk Podcast, we break down the uncomfortable truth about the current cyber threat landscape and why much of it is flying under the radar. We start with a major data breach involving 700Credit, a financial services company widely used by car dealerships across the country. The breach impacted an estimated 5.8 million consumers, exposing sensitive personal information including names, addresses, birth dates, and Social Security numbers. What makes this incident especially troubling is that it originated through a third-party integration and went undetected until it was too late. This is a textbook example of how supply chain risk, weak API oversight, and poor third-party visibility continue to plague organizations of all sizes. For business owners, IT leaders, and managed service providers, this breach highlights a critical lesson. Security controls inside your own environment are meaningless if your partners, vendors, or integrations are not held to the same standard. Attackers know this, and they are exploiting it aggressively. Next, we shift to a growing and deeply concerning trend involving nation-state threat actors, particularly Russian-backed groups targeting network edge devices. Firewalls, VPN appliances, routers, and other edge infrastructure are now prime targets because they offer direct access to internal networks and often remain poorly monitored or improperly configured. These attacks are not always sophisticated zero-day exploits. In many cases, they succeed because of exposed management interfaces, outdated firmware, or weak credentials. This matters because edge devices sit at the front door of nearly every organization. Once compromised, they allow attackers to persist quietly, move laterally, and stage future attacks without triggering traditional endpoint defenses. The takeaway is clear. If you are not actively inventorying, patching, and monitoring your edge infrastructure, you are already behind. Then we pull the lens back even further and focus on what may be the most underreported cyber crisis happening today. Public sector organizations across the United States are under sustained cyber attack. Cities, towns, school districts, emergency services, and municipal agencies are being hit week after week. These incidents rarely make national headlines. Instead, they show up in small local news outlets, if they are reported at all. We discuss a real-world incident in Attleboro, Massachusetts, where a cybersecurity event disrupted online municipal services and briefly appeared on local television. Stories like this are happening everywhere. From ransomware attacks that shut down city services to breaches that expose resident data, public organizations are being targeted because attackers know they are often underfunded, understaffed, and slow to recover. Using data from ransomware.live and other tracking resources, we highlight how widespread these attacks really are. Thousands of U.S.-based victims are logged publicly, many of them tied to government or quasi-government entities. This is not random. It is a calculated strategy by cybercriminals who understand the pressure public agencies face to restore services quickly, often making them more likely to pay ransoms or quietly rebuild without public disclosure. Throughout the episode, we connect these stories to practical lessons for businesses, MSPs, and IT professionals. Cybersecurity is no longer about preventing every breach. It is about resilience, visibility, and response. It is about understanding where your real risk lies and taking proactive steps before an incident forces your hand. If you work in IT, run an MSP, manage infrastructure, or support public organizations, this episode delivers insight you can use immediately. We cut through the noise, skip the fear marketing, and focus on what actually matters in today's threat environment. Security Squawk exists to make cybersecurity real, relevant, and actionable. If this episode brings value to you, please subscribe, leave a review, and share it with someone who needs to hear it. And if you want to support the show directly, the easiest way is to buy us a coffee at https://buymeacoffee.com/securitysquawk Your support helps us keep producing honest conversations about the threats most people never see until it's too late.
This episode breaks down the true scale of the cybercrime economy. Randy covers the Marquis vendor breach that exposed data across more than 74 banks and credit unions and highlights the ongoing weakness in third-party risk. Andre examines the FinCEN report showing over 2 billion in ransomware payments last year and reveals how organized these criminal groups have become. Bryan closes with a deep dive into the US Treasury's decade long analysis of 4.5 billion in ransom payments, showing how ransomware has grown into an economy that rivals legitimate global businesses. This is essential insight for business leaders, MSPs, and IT professionals who want to understand what is really driving the surge in cybercrime.
This episode breaks down three major cybersecurity stories that reveal exactly where businesses are exposed and how fast the threat landscape is shifting. We analyze how a ransomware group hijacked an emergency alert system to trigger fake national warnings, why more than half of retailers are still paying ransoms despite stronger defenses, and what security leaders should expect heading into 2026. You will learn the real weaknesses behind these incidents, why attackers continue to outpace outdated systems, and how companies can strengthen their defenses now. This episode delivers practical insights, real world examples, and expert commentary that help MSPs, IT teams, and business leaders stay ahead of the next wave of cyber threats.
In this Security Squawk episode, Brian Horning from Xact IT is joined by guests to unpack three real ransomware incidents, the rapid rise of “The Gentlemen” gang, and how attackers bypass basic security by turning off tools like Windows Defender. You'll learn why relying only on built-in protections creates dangerous blind spots, what layered security with EDR, SOC monitoring, and log retention looks like, and the practical steps business leaders can take now to harden their defenses and reduce ransomware risk.
In this episode of Security Squawk, we dig into three major cyber incidents — the DoorDash data breach exposing users' contact info, the Logitech zero-day and data-theft campaign tied to Clop, and the ransomware attack on the Pennsylvania AG office. We break down how each attack played out, what it means for MSPs and business owners, and how you can protect your organisation when the threat spectrum keeps shifting.
In this episode of the Security Squawk Podcast, Bryan Hornung, Randy Bryan, and Reginald Andre break down three major cybersecurity failures hitting government, media, and healthcare. We expose how a single employee action triggered a Nevada ransomware attack, why stolen Slack credentials led to a major Nikkei data leak, and how new NHS and Doctor Alliance breaches highlight the growing crisis in healthcare security. This episode is packed with insights for business leaders, MSPs, and IT pros who want to stay ahead of todays cyber threats. Listen to expert analysis, real world breakdowns, and practical steps to protect your organization from ransomware, credential theft, and supply chain attacks. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...
In this week's episode of the Security Squawk Podcast, Bryan Hornung, Randy Bryan, and Reginald Andre break down three major cybersecurity incidents that show how no industry is immune — from universities and government contractors to the British Library itself. We dig into a 1.2 million-record donor data breach, a ransomware-driven shutdown, and the growing supply-chain risk for MSPs and IT providers. Tune in for sharp analysis, real-world lessons, and actionable advice to protect your business from being the next victim. Cybersecurity podcast, data breach, ransomware, MSP, vendor risk, university breach, British Library, Conduent, IT security trends ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...
In this week's Security Squawk Podcast, Bryan Hornung, Randy Bryan, and Reginald Andre break down three massive cybersecurity stories shaping 2025. Bryan kicks off with Qilin — the ransomware gang behind over 700 global attacks this year. Andre covers a New York city that paid a $150,000 ransom to restore operations after a crippling hit. And Randy unpacks a major ISP email breach in Australia that led to SIM-swaps and stolen data. Packed with sharp insights, humor, and practical advice, this episode is a must-listen for MSPs, IT pros, and business owners looking to stay ahead of 2025's top threats.In this week's Security Squawk Podcast, Bryan Hornung, Randy Bryan, and Reginald Andre break down three massive cybersecurity stories shaping 2025. Bryan kicks off with Qilin — the ransomware gang behind over 700 global attacks this year. Andre covers a New York city that paid a $150,000 ransom to restore operations after a crippling hit. And Randy unpacks a major ISP email breach in Australia that led to SIM-swaps and stolen data. Packed with sharp insights, humor, and practical advice, this episode is a must-listen for MSPs, IT pros, and business owners looking to stay ahead of 2025's top threats. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...
In this week's episode of the Security Squawk Podcast, Bryan Hornung, Randy Bryan, and Reginald Andre tackle three major cybersecurity stories that show how the digital landscape is shifting fast, and why business owners, IT pros, and MSPs can't afford to get complacent. Andre kicks things off with the end of an era: Microsoft has officially ended support for Windows 10, even though nearly 41% of Windows users are still running it. He breaks down what that means for everyday users, how the new Extended Security Updates (ESU) program works, and why delaying an upgrade could leave your business wide open to attacks. Next, Randy dives into a ransomware attack that hit a key platform in the $4.3 trillion municipal bond market, disrupting critical financial infrastructure and proving that ransomware isn't just targeting small towns and hospitals anymore. It's going after the systems that keep entire economies running. He explains what went wrong, how it connects to larger threat trends, and what public-sector organizations can learn from it. Then Bryan closes out the show by unpacking Microsoft's 2025 Digital Defense Report, which offers a massive view into the global threat landscape. Microsoft processes over 100 trillion security signals every day, and the report highlights what's working, what's failing, and where the next wave of cyber threats is coming from. Bryan shares key stats, actionable takeaways, and the five core principles Microsoft says every business should follow to defend against ransomware and identity-based attacks. Together, the team connects the dots between these stories, showing how legacy systems, financial vulnerabilities, and evolving threat tactics are all part of the same bigger picture. Expect smart insight, real-world examples, and a few sarcastic jabs along the way as they break down what these headlines mean for your business and your bottom line. Listen to learn: What Microsoft's end of Windows 10 support really means for security Why ransomware is now a systemic financial risk The most important lessons from Microsoft's new Digital Defense Report How to protect your business with resilience, not just reaction If you enjoy the show, hit subscribe, leave a review, and share it with your network. You can also support the podcast directly at buymeacoffee.com/securitysquawk, where every coffee helps us keep squawkin' about cybersecurity that actually matters. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...
In this episode of the Security Squawk Podcast, Bryan Hornung, Randy Bryan, and Reginald Andre break down three major cybersecurity stories that show just how messy 2025 has become for data protection. Randy covers the WestJet breach that exposed more than 1.2 million customers, proving even major airlines can't keep turbulence out of their networks. Andre unpacks how the NSW government accidentally uploaded flood victims' personal data to ChatGPT, turning an AI experiment into a privacy nightmare. Bryan closes with new research showing ransomware attacks are climbing again just as fewer companies renew their cyber insurance — the perfect setup for costly business shutdowns. The team shares insights, lessons, and a few laughs as they explain what these stories mean for business owners, IT pros, and MSPs trying to stay ahead of the next big hit. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...
In this episode of the Security Squawk Podcast, Bryan Hornung, Randy Bryan, and Reginald Andre dissect three headline-making cybersecurity incidents that highlight how threats keep evolving—just in different directions. Randy kicks things off with WestJet's massive data breach, where over 1.2 million customers had their information exposed, showing how even major airlines struggle with protecting sensitive data in 2025. Andre dives into a shocking story out of Australia—the NSW government accidentally uploading flood victims' personal data to ChatGPT, revealing how AI misuse and data mishandling can turn into a privacy nightmare overnight. Bryan closes with the latest findings showing ransomware attacks are rising again—just as fewer companies renew their cyber insurance policies, setting up the perfect storm for costly business disruptions. The team breaks down what these stories mean for business owners, from growing AI data risks to the real cost of skipping cybersecurity insurance. Expect practical takeaways, sharp insights, and a few laughs along the way as the guys decode what's really happening behind the headlines. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...
In this episode of the Security Squawk Podcast, Bryan Hornung and Randy Bryan break down how ransomware keeps evolving and why businesses can't afford to let their guard down. Bryan covers three major stories: a ransomware attack on Volvo's supplier that exposed sensitive employee data, new research showing that 80% of ransomware victims get hit again, and how the Akira ransomware gang is flipping remote management tools against their victims. Randy dives into cyberattacks on global manufacturing, including production halts at Asahi and fallout from the Jaguar Land Rover ransomware incident. We'll unpack what these attacks mean for supply chains, IT teams, and everyday businesses—and why persistence is the new weapon of choice for cybercriminals. Tune in for sharp insights, real-world advice, and a little bit of sarcasm to keep it interesting. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...
In this episode of Security Squawk, Bryan and Randy break down two major cyber stories with real-world lessons for IT leaders and MSPs. First, a FinWise Bank insider breach tied to American First Finance exposed data on nearly 689,000 customers—highlighting offboarding failures and insider risk. Then, a ransomware attack on U.S.-based Collins Aerospace disrupted airport check-in systems across Europe, forcing manual backups and long delays. We unpack what happened, why it matters, and the practical steps businesses can take to reduce insider and third-party risk. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...
In this week's Security Squawk Podcast, Bryan Hornung and Randy Bryan break down two major cybersecurity threats making headlines. First, Bryan covers how artificial intelligence is already supercharging ransomware, making attacks faster, cheaper, and harder to stop. Then Randy dives into the massive ShinyHunters breach that leaked sensitive data from Vietnam's national credit bureau, putting millions at risk worldwide. Tune in for sharp insights, practical advice, and a dose of wit as we connect the dots for business owners, IT professionals, and MSPs. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...
This week on Security Squawk, Bryan Hornung and Randy Bryan break down two hard-hitting cybersecurity stories. Jaguar Land Rover's production lines grind to a halt after a massive cyberattack, showing how ransomware directly disrupts global manufacturing. Meanwhile, CISOs face mounting pressure to stay silent about breaches, raising serious questions about transparency, accountability, and corporate risk. Tune in for sharp insights, real-world lessons, and a dose of wit as we unpack what these stories mean for businesses, IT pros, and MSPs. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...
This week on Security Squawk, Randy and Bryan tackle two major cyber stories shaping 2025. First, Anthropic admits hackers are weaponizing its AI tools, giving cybercriminals a terrifying new advantage in building attacks faster than ever. Then, Bryan breaks down how Amazon disrupted a sophisticated campaign by Russia's APT29 (Cozy Bear), which abused Microsoft 365 device code authentication and cloud infrastructure to hijack accounts at scale. We explain how hackers are using AI to supercharge cybercrime, why APT29's tactics mark a dangerous evolution from past campaigns like SolarWinds and NotPetya, and what this means for businesses, IT professionals, and MSPs. Tune in for sharp insights, real-world examples, and practical takeaways to keep your defenses strong. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...
While everyone obsesses over AI security, the old-school cyber threats are piling up. In this episode of the Security Squawk Podcast, hosts Bryan Hornung and Randy Bryan break down four major incidents that prove ransomware, breaches, and network shutdowns aren't going anywhere. We cover: Nevada state offices crippled by a major security incident Farmers Insurance data breach affecting over 1 million people Data I/O ransomware attack shutting down systems Nissan's design studio breach claimed by the Qilin ransomware gang Plus, we connect the dots to show why ransomware attacks have surged nearly threefold in 2024 — and what businesses need to do to avoid being the next headline. Stay sharp, stay informed, and don't let the AI hype distract you from the real threats hitting businesses every day. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...
In this week's Security Squawk Podcast, hosts Bryan Hornung and Randy Bryan deliver an unfiltered breakdown of the week's most pressing cybersecurity headlines. We're talking about the Workday breach that exposed Salesforce customer data without a single file encrypted—just stolen credentials and surgical precision. Next up, we expose how Akira ransomware is turning cybercrime into marketing warfare, publicly naming and shaming victims in a bold bid to force ransom payouts. Finally, we tackle a brutal stat making waves across the industry: 25% of CISOs are replaced following a ransomware attack. If you're in cybersecurity leadership—or aiming to stay out of the headlines—this episode is your playbook for resilience. Packed with blunt analysis, leadership lessons, and real-world implications, this is one you'll want to share with your entire exec team. ☕ Like what you hear? Support the podcast: buymeacoffee.com/securitysquawk Workday breach, Salesforce breach, ransomware leak sites, Akira ransomware tactics, cybersecurity leadership, CISO turnover, cloud data security, Security Squawk Podcast ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...
In this episode of Security Squawk Podcast, hosts Bryan Hornung, Randy Bryan, and Reginald Andre tackle major cybersecurity events impacting high-profile targets. First, luxury fashion giant Chanel falls victim to a devastating cyberattack, compromising customer data. Next, the city of St. Paul grapples with widespread tech disruptions linked to a cybersecurity incident, revealing municipal vulnerabilities. Finally, an urgent investigation into an SSL vulnerability by cybersecurity hardware provider SonicWall leaves businesses scrambling for protection. Learn critical security insights, risk management tips, and proactive steps to safeguard your business against evolving threats. Cybersecurity, Chanel cyberattack, St. Paul tech disruptions, SonicWall vulnerability, SSL security, data breach, municipal cybersecurity, Security Squawk Podcast. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...
This week on the Security Squawk Podcast, we're diving into three major cybersecurity incidents that highlight just how vulnerable even the most well-known organizations still are in 2025. First up, we cover the massive data breach at Co-op, where all 6.5 million members had their personal information stolen. That's right—every single member. We unpack what went wrong, how the breach was discovered, and the long-term fallout for one of the UK's largest retail cooperatives. Then, we turn our attention to the notorious Scattered Spider cybercrime group, which is back in the headlines after breaching major corporations like Clorox and Cognizant. And how did they get in? Not with some zero-day exploit or advanced malware—just simple, convincing phone calls. It's a wake-up call for any business that thinks cybersecurity is all about firewalls and antivirus. Finally, we bring it closer to home with a cyberattack that shut down systems in the Fort Smith Public School District in Arkansas. It's the latest in a growing trend of ransomware targeting schools and disrupting education. We explore what districts can do to prepare and why K–12 institutions remain such easy, high-impact targets for cybercriminals. If you're a business owner, IT professional, school administrator, or just someone who cares about protecting data, this is one episode you don't want to miss. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...
Another week, another round of cyber fails making headlines. In this episode of Security Squawk, we break down how some of the biggest names in tech and business are still getting owned by basic mistakes. This week: Dell's breach exposes critical platforms to extortion groups ️ A 158-year-old company destroyed by one weak password Ransomware still targeting hospitals while reports claim it is in decline If you think big brands have it figured out, think again. Stay informed and stay protected. Watch or listen now for insights you will not hear anywhere else. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...
Ransomware attacks are exploding in 2025, and cybercriminals are getting bolder — and richer. In this episode of Security Squawk, we break down the latest schemes, lawsuits, and trends you need to know: Interlock ransomware's new ‘FileFix' malware trick Krispy Kreme sued for exposing employee data Ransomware attacks nearly double in 2025 Hackers getting 80% payouts to keep the attacks rolling If you own a business, manage IT, or care about protecting your data, you can't afford to miss this one. Watch or listen now and stay one step ahead. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...
A massive ransomware attack hits Ingram Micro — what happened, who's behind it, and what it means for your business. We also dive into the terrifying rise of AI-powered cyberattacks and the dangerous gap between innovation and data protection. In this episode: Ingram Micro ransomware attack breakdown AI cybercrime stats that will shock you Is AI innovation outpacing cybersecurity? Let's debate Tune in now and stay one step ahead of the threats. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...
Today on the Security Squawk Podcast: We're diving into a high-impact lineup of cyber threats and breaches shaking up industries from healthcare to aviation: Aflac Breach – Social Security numbers, health claims, and personal data compromised. ✈️ FBI Alert: 'Scattered Spider' cybercrime gang now targeting major U.S. airlines. Hawaiian Airlines hit by a cyberattack—what it means for travelers. ️ Hungryroot Breach – Over 1.1 million user records reportedly up for sale on the dark web. Tenacious Marketing USA – 414,000 records exposed. Another day, another marketing firm breached. ️ Hosted by Bryan Hornung, Reginald Andre, and Randy Bryan, this episode delivers real-world analysis, breach breakdowns, and what your business should be doing right now to stay protected. Join us live. Ask questions. Stay ahead. ️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! https://streamyard.com/pal/d/65161790...
Cybercriminals are getting bolder—and smarter.
This week, the Security Squawk crew tackles some of the most concerning stories in cyber news: a ransomware gang is now telling victims to call their lawyers, insurers like Aflac are struggling with ongoing ransomware outages, and healthcare data for over 50 million people has been exposed.
We each bring a real-world case that highlights just how chaotic—and dangerous—the threat landscape has become.
Topics this week:
Qilin ransomware's new legal scare tactic
Episource breach impacts 5.4 million patients
McLaren Health confirms sensitive data exfiltration
Aflac & other insurers hit by ransomware, causing major outages
Tune in for expert breakdowns, sharp insights, and actionable advice to keep your business secure.
What if paying the ransom guaranteed you'd still lose everything?
In this week's Security Squawk Podcast, Bryan, Reginald, and Randy break down one of the most disturbing ransomware developments yet—Anubis ransomware, which encrypts your data and wipes it out regardless of payment. There's no negotiation. No way back.
We also dive into:
Nova Scotia Power breach – A cyberattack hits a major utility provider. Is our infrastructure truly ready for what's coming?
Israel-Iran cyber war risks – As these nations trade digital blows, U.S. businesses may find themselves caught in the crossfire.
Insider threats exposed – It's not just rogue employees. Negligence and poor culture may be your biggest risk factor.
Motel 6 data leak – An investment firm mishandled sensitive data, exposing customers and employees. Who's responsible when partners fumble?
Tune in for expert insights, unfiltered opinions, and practical guidance on how these threats could impact your business—and what to do about it.
From the confirmed AT&T breach leaking 80+ million Social Security numbers to AI tools being labeled a “data breach time bomb,” the threats are getting smarter, faster, and more destructive. On this episode of Security Squawk, Bryan, Randy, and Andre break down the nonstop cyber carnage sweeping the U.S., with businesses, hospitals, and government agencies all taking hits.
In this episode:
AT&T's massive customer data leak finally confirmed
AI's dangerous role in future data breaches
Ransomware cripples a grocery giant, law enforcement, and mental health clinics
Remote monitoring software exploited in hospital attacks
Suspicious “outages” and confirmed data theft from major companies
This week on Security Squawk, we dive into the ransomware wave crashing across the U.S. From local governments like Lorain County and Durant to major healthcare providers and even Victoria's Secret, no one is off-limits.
We also expose the dangerous rise of triple extortion ransomware and highlight the response playbooks from Kettering Health and the City of Abilene.
Tune in as Bryan, Randy, and Andre break it all down and offer insights you can't afford to miss.
This week on the Security Squawk Podcast, Bryan Hornung, Randy Bryan, and Reginald Andre break down a brutal stretch of ransomware attacks that took out hospital systems, 911 emergency services, telecoms, and even a grocery store supply chain.
We cover how a zero-day exploit in Microsoft Windows is being used in real-world ransomware campaigns and how legal fallout is brewing for one cultural institution post-breach.
From critical infrastructure to everyday consumer access, this episode reveals the growing impact and frequency of ransomware in 2025. Tune in to hear expert analysis and insight you won't get anywhere else.
If this episode brings you value, don't forget to like, share, and subscribe—that's how you can help support the show without ads!
This week on Security Squawk, we're diving into high-impact cyber incidents affecting massive brands and vulnerable communities.
From Adidas leaking customer data to a lawsuit following a ransomware attack that exposed survivor records, it's clear the cyber threat landscape is only heating up.
We also look at Nucor's production shutdown, shocking stats showing most companies wait 4 months to report breaches, and a new debate—Is AI distracting IT from real security threats like ransomware?
Tune in for expert takes, powerful insights, and practical questions every business leader should be asking.
Cyber threats are evolving—and fast. In this episode of Security Squawk, we investigate Alabama's mysterious “cybersecurity event,” expose the growing threat of callback phishing from the Silent Ransom Group, and reveal why Lee Enterprises had to spend $2 million to recover from a ransomware attack. Plus, we dive into a Cisco study showing that just 4% of companies are prepared to face AI-powered cyber threats. Tune in as Bryan, Randy, and Andre break down what this means for your business and how to stay ahead of the game.
Topics Discussed:
Alabama's state-level cyber “event”
SilentRansomGroup & Luna Moth callback phishing
BEC remains strong despite drop in cyber claims
Lee Enterprises' $2M ransomware recovery
Cisco's shocking AI-era threat readiness stat
Future of AI-powered ransomware
M&S and Co-op attack updates
Join us on this week's Cybersecurity Podcast for an in‑depth, ad‑free exploration of the latest ransomware blitz and emerging defense strategies. I'm Bryan Hornung, alongside Randy Bryan and Reginald Andre three industry veterans with decades of hands‑on experience ready to unpack every twist and turn.
In our opening deep dive, we'll walk you through two headline‑grabbing attacks: a CBS affiliate in Chattanooga that fell victim to the Lynx ransomware gang, and Hitachi Vantara's flagship data center, crippled for days by the Akira group. What drove these adversaries to target media outlets and global enterprises, and how did each organization scramble to contain the damage? We'll analyze critical containment tactics, rapid recovery plans, and key lessons for shoring up defenses before the next breach strikes.
Next, we shift from real‑world incidents to cutting‑edge trends shaping tomorrow's battlefield. Discover why live ransomware simulations are becoming essential “war games” for security teams, and learn how agentic AI could empower attackers to move at machine speed outpacing human defenders. We'll also demystify Microsoft's bold move to make every new account passwordless by default, weighing the promise of passkeys and biometrics against privacy and compliance concerns. And don't miss our examination of the startling insider‑threat case, where a cybersecurity CEO allegedly turned hospital systems into his own surveillance testbed.
In our follow‑up segment, we revisit two major UK retail hacks Marks & Spencer's admitted lack of a coherent cyber‑response plan and the Co‑op's mass data theft—plus the alarming rise of “vishing” through fake IT help‑desk calls. Then, we cover the Cobb County leak and its fallout for citizen privacy, before closing with a critical look at DaVita's recent ransomware event, where 1.5 TB of patient data was exfiltrated yet life‑saving dialysis treatments continued under emergency protocols.
Whether you're a security leader, IT professional, or simply curious about how today's most dangerous cyber threats unfold and get contained, this episode delivers actionable insights and expert analysis. Listen now, subscribe for the latest updates, and share if you find value your support keeps our show free of ads and full of expertise!
First, the UK's Co-operative Group was forced to shut down part of its IT systems after a suspected cyberattack, disrupting internal operations like stock monitoring and remote access—just weeks after a similar event hit Marks & Spencer. While customer-facing services stayed online, the breach highlights growing risks in the retail supply chain.
Meanwhile, a ransomware attack crippled systems at the DuPage County Sheriff's Office and courthouse in Illinois. While 911 and public safety services remained active, critical infrastructure—including judicial and legal records—went dark.
The FBI and Secret Service are now leading the investigation.
But not all stories end in disruption—Doctors Hospital in the Cayman Islands successfully thwarted a ransomware attack thanks to quick action by its IT Director and a well-practiced incident response plan. No patient data was compromised, and operations resumed with minimal downtime.
We'll break down what went right, what went wrong, and why tabletop exercises and segmented infrastructure may be your best defense in this era of relentless cyber threats.
In this episode of Security Squawk, we dissect a wave of high-impact cyber events: a Texas city forced offline by a cyberattack; a 9% jump in ransomware against U.S. infrastructure; the FBI's record-breaking $16.6 B loss in 2024; North Korean spies posing as U.S. firms to infect crypto developers; global cyberwarfare readiness; and headline-grabbing data leaks—from Legends International to Blue Shield's PHI slip. Plus, Randy breaks down AI's promise (and pitfalls) in cybersecurity, and we unpack Verizon's DBIR warning on third-party breach surges. In our Follow-Up, we revisit DaVita's dialysis response, Sensata's production halt, and Frederick Health's 1 M patient-record breach. Tune in now!
This week on Security Squawk, we break down a wave of major ransomware attacks and data breaches shaking up the business world. From the global disruption at Sensata Technologies and a weekend attack on DaVita's kidney care network, to Hertz's customer data breach and a $23 million loss for IKEA's operator, no industry is safe. We also spotlight attacks on CMC Corporation and a dental care provider, revealing why organizations of all sizes are at risk. Join Bryan, Randy, and Andre as they unpack the latest threats, share expert insights, and offer practical tips to keep your data safe!
This week on The Security Squawk cybersecurity podcast, we're diving deep into a cybercrime spree hitting across the nation! First up, Baltimore finds itself $1.5 million lighter after cybercriminals pull off identity theft under the FBI's watchful eye. Then, we unpack the ransomware nightmare hitting close to home in Texas, as the State Bar warns thousands about compromised data.
But it doesn't stop there—Minnesota's Sioux Tribe faces operational chaos at Jackpot Junction Casino due to ransomware attackers holding their systems hostage. Meanwhile, cybercriminals shift tactics from encryption to pure extortion, signaling a dangerous new frontier in cyber threats.
We'll also expose the shocking truth about how hackers are increasingly using legitimate logins to bypass traditional security, discuss why plug-and-play antivirus solutions are falling short, and explore the fallout from massive breaches at the Port of Seattle and Nationwide Recovery Service, which left tens of thousands vulnerable.
Join us as we dissect these alarming trends, break down what went wrong, and give you actionable insights to keep your business and data safe from the evolving cyber threat landscape.
This week on the Security Squawk podcast, we're diving into the biggest cybersecurity stories shaking up the industry:
️ Oracle Health admits to a shocking breach.
Ransomware downtime averages 24 days—crippling businesses.
Healthcare providers remain dangerously vulnerable to ransomware.
️ Sam's Club investigates Clop ransomware breach claims.
❌ Check Point denies breach allegations while hackers sell access.
Local doctor fights to save his practice after ransomware hits—insurance gaps exposed.
Fake Zoom installer spreading dangerous ransomware—don't get tricked!
Join us live to discuss these critical issues! Don't forget to LIKE and SUBSCRIBE for weekly cybersecurity updates.
In our latest podcast episode, we discuss the evolving landscape of cybersecurity threats, uncovering how sophisticated attacks are impacting various sectors and how organizations are responding.
We begin by examining the recent Oracle Cloud breach, which has potentially exposed 6 million records, affecting over 140,000 businesses. This incident underscores the critical need for robust cloud security measures.
Next, we discuss Microsoft's initiative to bolster Teams' security against phishing and cyber attacks. These enhancements aim to support overwhelmed security teams by integrating advanced protective features into the widely used collaboration platform.
We also explore the shift in cyberattack readiness responsibilities to state and local governments, following an executive order from President Trump. This policy change raises questions about the preparedness of local entities to handle sophisticated cyber threats.
Additionally, we highlight the increasing targeting of Mac users by hackers through sophisticated Apple ID phishing scams. This trend challenges the perception of Macs being inherently more secure and emphasizes the need for vigilance among all users.
We then analyze PowerSchool's 'Trust The Hackers' response to a recent cyber incident, critiquing the approach and discussing the importance of transparency and trust in cybersecurity practices.
Furthermore, we address the cyberattack on DHR Health in Texas, which has raised concerns over the security of healthcare information systems and the protection of patient data.
In our latest podcast episode, we delve into the evolving landscape of cybersecurity threats, uncovering how sophisticated attacks are crippling industries and government institutions.
We examine how the Black Basta ransomware gang is leveraging brute-force attacks against edge devices, enabling them to infiltrate networks with alarming efficiency. This highlights the growing need for businesses to fortify their perimeter defenses.
Additionally, we discuss the Cleveland Municipal Court cyberattack, which has left operations crippled for over three weeks, shedding light on the prolonged impact of cyber incidents on the judicial system. Similarly, we explore the Atchison County government shutdown, where a cyberattack forced local offices to close, emphasizing the vulnerabilities in public sector cybersecurity.
We also analyze a recent KnowBe4 report, which warns that the education sector remains dangerously unprepared for escalating cyberattacks, leaving schools and universities at high risk.
Finally, we examine a newly discovered Microsoft365 exploit, where attackers are bypassing traditional email security measures, prompting an FBI warning for Gmail, Outlook, and VPN users to take immediate action.
Cyber threats are evolving rapidly—are organizations prepared to defend against them? Tune in as we break down these incidents and discuss proactive security measures to mitigate risks.
Join Bryan Hornung, Randy Bryan, and Reginald Andre on Security Squawk as we dive into an extensive breakdown of this week's significant cybersecurity incidents impacting a wide range of sectors. We'll begin by examining the troubling cyberattack at the Missouri Department of Conservation (MDC), headquartered in Jefferson City, Missouri, nearly three years after auditors first identified critical vulnerabilities. What lessons can government agencies learn from this delayed response?
Next, we'll analyze the ransomware attack on the Penn-Harris-Madison School Corporation in Indiana, highlighting the potential exposure of sensitive student information and discussing best practices for securing educational institutions. We'll also review recent phishing attacks that compromised client data at iTP Partners, a specialized financial advisory firm based in Florida and New York, and Legacy Professionals, an accounting and auditing firm from Westchester, Illinois, emphasizing the ongoing threats posed by these sophisticated scams.
Further, we'll explore the far-reaching implications of the cyberattack that temporarily took the Polish Space Agency offline, and the confusion surrounding Home Depot, the world's largest home improvement retailer based in Atlanta, Georgia, amid conflicting reports of a ransomware incident. With approximately 471,600 employees and revenues reaching $152.7 billion in 2023, what can companies of this scale do to maintain transparency and customer trust during cybersecurity crises?
Lastly, we'll discuss how ransomware led to the downfall of a 150-year-old company, underscoring that even the most established organizations are vulnerable in today's cyber threat landscape. What proactive steps can legacy businesses take to fortify their cybersecurity posture?
Tune in for expert insights, practical advice, and actionable strategies from Bryan Hornung, Randy Bryan, and Reginald Andre. If you find this episode valuable, please like, subscribe, and share to help others stay informed and prepared.
Join Bryan Hornung, Randy Bryan, and Reginald Andre on Security Squawk as we dive into an extensive breakdown of this week's significant cybersecurity incidents impacting a wide range of sectors. We'll begin by examining the troubling cyberattack at the Missouri Department of Conservation (MDC), headquartered in Jefferson City, Missouri, nearly three years after auditors first identified critical vulnerabilities. What lessons can government agencies learn from this delayed response?
Next, we'll analyze the ransomware attack on the Penn-Harris-Madison School Corporation in Indiana, highlighting the potential exposure of sensitive student information and discussing best practices for securing educational institutions. We'll also review recent phishing attacks that compromised client data at iTP Partners, a specialized financial advisory firm based in Florida and New York, and Legacy Professionals, an accounting and auditing firm from Westchester, Illinois, emphasizing the ongoing threats posed by these sophisticated scams.
Further, we'll explore the far-reaching implications of the cyberattack that temporarily took the Polish Space Agency offline, and the confusion surrounding Home Depot, the world's largest home improvement retailer based in Atlanta, Georgia, amid conflicting reports of a ransomware incident. With approximately 471,600 employees and revenues reaching $152.7 billion in 2023, what can companies of this scale do to maintain transparency and customer trust during cybersecurity crises?
Lastly, we'll discuss how ransomware led to the downfall of a 150-year-old company, underscoring that even the most established organizations are vulnerable in today's cyber threat landscape. What proactive steps can legacy businesses take to fortify their cybersecurity posture?
Tune in for expert insights, practical advice, and actionable strategies from Bryan Hornung, Randy Bryan, and Reginald Andre. If you find this episode valuable, please like, subscribe, and share to help others stay informed and prepared.
In this hard-hitting episode of Security Squawk, we break down a series of high-profile cyber breaches shaking institutions across America. From the ransomware chaos at Anne Arundel County and the delayed breach disclosure at St. Landry Parish Schools to the dramatic data heist at Riverdale Country School and the cyber assault on Williamsburg-James City County Public Schools, we uncover the tactics behind these attacks. We also explore the shutdown of Cleveland Municipal Court, the significant data breach at DISA Global Solutions, and the swift countermeasures at Cayuga Medical Center. Join us as our experts analyze these incidents, discuss emerging ransomware trends, and reveal why the dark web values healthcare data far above credit card details.
This week on Security Squawk, Bryan Hornung, Reginald Andre, and Randy Bryan dissect the recent ransomware attack on Lee Enterprises that disrupted newspaper operations across multiple states.
Our cybersecurity experts will use this high-profile case as a springboard to explore the broader landscape of current cyber threats. We'll analyze the alarming trend of ransomware gangs executing extortion attempts within just 17 hours of intrusion on average, and how this rapid-fire approach is changing the game for businesses of all sizes.
The conversation will span various sectors, from healthcare breaches at SimonMed Imaging to manufacturing disruptions at circuit board maker Unimicron. We'll also cover the alleged Nippon Steel ransomware attack and its potential global economic impact.
Government vulnerabilities won't be overlooked as we discuss the cyberattack on Virginia's Attorney General's office and its implications for public sector security.
Join us for an essential episode that not only highlights the pervasive nature of cyber threats but also provides actionable insights for achieving cyber resilience in these turbulent digital times.
In this explosive episode of Security Squawk, cyber security experts Bryan Hornung, Reginald Andre, and Randy Bryan tackle a cascade of high-profile ransomware attacks shaking diverse sectors across the nation. We kick off with the Sault Ste. Marie Tribe of Chippewa Indians, whose operations—from casinos to gas stations—were crippled by a ransomware assault. Then, we explore the shutdown of classes and critical services at Jefferson School District in Idaho following a cyberattack, and the far-reaching disruption at the University of The Bahamas that forced a shift to in-person learning. Our discussion also covers major corporate incidents, including updates on the Cisco Kraken breach and a recent cyber attack on a global engineering firm, along with the severe financial fallout from the Patelco Credit Union ransomware incident. Finally, we wrap up with practical, expert-backed solutions for enhancing cyber resiliency across all sectors. Tune in for in-depth analysis, thought-provoking questions, and actionable strategies to safeguard your organization in today's turbulent digital landscape.
In this action-packed episode of Security Squawk, we dive deep into the latest cybersecurity incidents shaking up industries worldwide. From ransomware attacks on critical blood centers to sophisticated hacks on WhatsApp, we cover it all. Our expert panel discusses:
The crippling ransomware attack on New York Blood Center and its ripple effects in Kansas City
Meta's confirmation of a WhatsApp hack targeting journalists and activists
Tata Technologies' ransomware incident and its implications for global tech
DeepSeek's massive AI data leak exposing over 1 million sensitive records
New York's game-changing updates to data breach notification laws
MGM Resorts' eye-watering $45 million data breach settlement
Plus, we break down what these incidents mean for you and how to stay protected in an increasingly digital world. Don't miss this critical discussion on the evolving landscape of cybersecurity threats and defenses. Whether you're a tech enthusiast, business owner, or concerned citizen, this episode has something for everyone.
In this video, we dive into the latest cybersecurity headlines that are shaking up the digital world. We'll cover:
UnitedHealth's staggering data breach affecting 190 million Americans
Microsoft's upcoming Teams phishing protection rollout
A ransomware attack paralyzing a Maryland hospital
Microsoft Edge's new defense against tech support scams
The aftermath of a costly ransomware attack in an Ohio county
Join us as we break down these critical cyber incidents and discuss their implications for healthcare, technology, and local government sectors.
Don't forget to like, subscribe, and hit the notification bell to stay updated on the latest in cybersecurity news!
Join us for this week's cybersecurity roundup as we dive into alarming data breaches and ransomware attacks that have hit organizations across various sectors. We'll discuss the widespread impact on Oregon school districts, the University of Oklahoma's IT network issues, and how even popular brands like Avery and Primal Wear have fallen victim to cybercriminals. We'll also explore the ongoing threats to financial institutions and government entities, including the Mortgage Investors Group breach and Wexford County's prolonged recovery from a ransomware attack. Plus, we'll provide updates on the evolving tactics of Russian hackers using Microsoft Teams and the far-reaching consequences of the PowerSchool breach affecting Ontario students. Don't miss this comprehensive look at the current state of cybersecurity threats and their real-world implications.
In this episode, we go into the FBI's unprecedented operation to wipe Chinese PlugX malware from over 4,000 U.S. computers, a stark reminder of the growing threat of cyber espionage.
We'll also discuss the OneBlood ransomware attack that compromised personal data, the cybersecurity breach affecting thousands of schools across the U.S. - PowerSchool system, and the Biden administration's push for healthcare cybersecurity upgrades—met with resistance from hospitals.
Finally, we reflect on why 2024 marked yet another grim year for healthcare ransomware attacks and the lessons to be learned for a safer digital future.
In this episode of Security Squawk, we dive deep into the latest cybersecurity threats facing schools, healthcare organizations, and businesses. Our experts analyze recent high-profile data breaches, discuss alarming cybersecurity statistics, and explore the evolving legal landscape of data protection. From the Volkswagen data leak to vulnerable SonicWall devices, we cover the most pressing issues in today's digital security world. Tune in for expert insights and practical advice on protecting your organization from cyber threats.
In this episode of Security Squawk, we unpack the latest cybersecurity incidents shaking up various sectors. We cover everything from ransomware hitting public transit in Pittsburgh to sophisticated malware targeting developers and from e-commerce data breaches to Chinese hacking campaigns against telecom giants. Our expert panel provides in-depth analysis and practical advice for organizations and individuals. Don't miss this crucial discussion on the ever-evolving cyber threat landscape!
In this episode of Security Squawk, we look back at the cybersecurity predictions made for 2022 and assess how accurate they were. From the rise of ransomware attacks to the evolution of AI in cybersecurity, we cherry-pick forecasts from top sources like CIS, Forbes, and IBM Security Intelligence. Join our trio of cybersecurity experts as we dive into what came true, what didn't, and the lessons businesses can learn to prepare for the year ahead. Don't miss this reflective and insightful discussion!
Join us as we dive into the latest cybersecurity nightmares: Rhode Island's system breach, hospital hack exposing millions, university scams, school district data leaks, Teams vulnerabilities, LastPass fallout, and YouTube creator attacks. Plus, we'll explore the push for offensive cyber strategies against foreign threats. Don't miss this crucial update on the evolving digital battleground!
In this explosive episode of Security Squawk, we dive deep into the latest wave of devastating ransomware attacks that are shaking the foundations of healthcare, education, and major industries. From hospitals to vodka makers, no sector is safe from the relentless onslaught of cybercriminals.
Healthcare Crisis: Discover how Anna Jaques Hospital and PIH Health fell victim to attacks, exposing sensitive data of over 300,000 patients and disrupting critical care services.
Education Under Attack: Learn about the ransomware strike on Highland Park ISD in Texas, and the challenges faced by schools in the digital age.
Industry Giants Crumble: Uncover how a ransomware attack forced vodka maker Stoli to file for bankruptcy, showcasing the financial devastation of cyber threats.
️ Government in the Crosshairs: Explore the ongoing saga of the Hoboken City Hall ransomware attack and its impact on local government services.
Medical Tech at Risk: Analyze the alarming ransomware attack on a leading heart surgery device maker and its potential life-threatening consequences.
Supply Chain Chaos: Examine the far-reaching implications of the Blue Yonder SaaS breach by the Termite ransomware gang on global supply chains.
Plus, don't miss our crucial follow-up section:
FBI's Urgent Warning: Learn why the FBI is urging users to change their WhatsApp, Facebook Messenger, and Signal apps immediately.
♂️ Evolving Threats: Uncover the latest tactics of the Black Basta ransomware group, including email bombing and QR code manipulation.
Join our expert panel as we dissect these cyber attacks, discuss prevention strategies, and explore the future of cybersecurity in an increasingly vulnerable digital landscape.
In this episode, we explore the latest and most alarming cybersecurity threats making headlines.
From warnings about Chinese port cranes potentially jeopardizing national security to predictions of AI-savvy teens and employees becoming the next wave of cyberattackers, the digital landscape is shifting rapidly. We'll also discuss major ransomware incidents impacting Costa Rica's energy sector, Bologna FC, and American Associated Pharmacies, as well as T-Mobile's breach by Chinese hackers.
Plus, we unpack the arrest of a notorious ransomware operator in Russia and what it means for the global fight against cybercrime. Join us for an insightful dive into how these threats impact businesses, governments, and individuals—and how to stay ahead of the curve.
In this episode of Security Squawk, we analyze recent cyberattacks impacting major companies like Starbucks and IGT. We also discuss financial repercussions faced by GEICO and Travelers following data breaches, along with how Stop & Shop managed to recover from an attack. Our experts share valuable insights on strengthening your cybersecurity posture and effectively managing crises. This is a must-listen for any professional concerned about their organization's security.
In this episode of Security Squawk, we dive into the latest cybersecurity challenges facing organizations and individuals.
We explore new two-step phishing (2SP) attacks and the critical role of two-factor authentication (2FA). Our experts discuss recent ransomware incidents in healthcare, alleged state-sponsored attacks on major corporations, and cyber threats to critical infrastructure.
We also examine how the cyber insurance industry shapes the ransomware landscape and analyze a cyberattack disrupting supermarket supply chains just before Thanksgiving.
Join us for an in-depth look at these pressing issues and expert insights on strengthening your cyber defenses.
Join us for an in-depth discussion on the recent cyberattack that disrupted Ahold Delhaize's U.S. operations, impacting major grocery chains like Food Lion and Hannaford. We'll explore the implications of this incident, including the vulnerabilities exposed in the retail sector and the broader landscape of cybersecurity threats facing businesses today.
In addition to our main topic, we'll cover other significant cybersecurity events, including Halliburton's $35 million loss from a ransomware attack, disruptions at local animal hospitals, and the alarming rise of ransomware demands targeting municipalities and healthcare facilities.
Tune in to learn about:
The tactics and techniques used by cybercriminals.
How organizations can better protect themselves against such attacks.
The latest trends in cybersecurity threats across various industries.
Whether you're a cybersecurity professional or simply interested in how these events affect our daily lives, this livestream will provide valuable insights and actionable takeaways. Don't miss it!
In this episode of Security Squawk, we analyze the latest cybersecurity trends, including a 68% increase in ransomware severity, targeted attacks on housing authorities, and a critical vulnerability affecting millions of Synology NAS devices. Join us as we break down these threats and discuss essential protection strategies for individuals and organizations alike.
In this episode of Security Squawk, we dive deep into the alarming rise of data breaches that bypass ransomware altogether. As cybercriminals evolve their tactics, organizations are left vulnerable to silent intrusions that compromise sensitive information without a ransom demand.
Join us as we explore recent high-profile cases, including the shocking breach affecting 800,000 individuals at Landmark Insurance and the cunning new tactics employed by the Black Basta ransomware group posing as IT support on Microsoft Teams.
We'll also follow up on previous stories, including the delayed disclosures from Henry Schein and the massive data theft impacting UnitedHealth.
Tune in to discover how these trends are reshaping the cybersecurity landscape and what businesses can do to safeguard their data against this emerging threat. Don't miss out—your data might depend on it!
Join us for an in-depth discussion on the latest cybersecurity threats and strategies. We'll cover the ongoing debate about ransomware payments, the UK's innovative approach to protecting schools with PDNS, and the recent breach of an ESET partner leading to attacks on Israeli organizations. We'll also follow up on the National Public data breach and the repeated attacks on the Internet Archive. Learn how these developments could impact your organization and what steps you can take to enhance your cybersecurity posture. Don't miss this crucial episode of Security Squawk!
Join us in this week's episode of Security Squawk as we dive deep into the latest cybersecurity incidents and trends that are shaking the digital landscape!
Topics Covered:
The shocking hack of the Internet Archive and its implications for digital history.
A new wave of malware attacks using phone calls to exploit employee systems.
OpenAI's confirmation that threat actors are leveraging ChatGPT to create sophisticated malware.
The ransomware attack on Axis Health System, where hackers demanded a staggering $1.6 million.
Casio's data breach, exposing sensitive information of employees and customers.
Insights into how a single employee's mistake led to a ransomware attack in Fulton County, Georgia.
Highlights from Microsoft's Digital Defense Report 2024, revealing current cybersecurity threats.
Stay informed and empowered as we discuss these critical issues affecting our digital security! Don't forget to like, subscribe, and hit the notification bell for more updates on cybersecurity!
Tune in to Security Squawk, the podcast where cybersecurity experts Bryan Hornung, Reginald Andre, and Randy Bryan break down the latest threats, breaches, and ransomware attacks impacting businesses and individuals.
This week, we dissect the massive Comcast data leak, expose a new ransomware strain targeting healthcare, and explore the rising danger of the "Toxic Cloud Triad."
Don't become a victim – get informed and stay ahead of the curve with Security Squawk!
Join us on Security Squawk as we analyze recent sophisticated cyber-attacks across the US, from educational institutions to healthcare systems. We'll dissect the strategies of notorious cybercriminal groups, their impacts on public and private sectors, and the ongoing responses from cybersecurity experts. Tune in to understand how these breaches affect you and what measures can safeguard against such pervasive threats.
Join us on this episode of Security Squawk as we dive deep into a series of high-profile cyber attacks that have left institutions ranging from public schools to the halls of Congress reeling.
We'll explore the shocking ransomware threat at Providence Public Schools, the extensive personal data leak impacting thousands of Congressional staffers, and the crippling cybersecurity issue at MoneyGram that disrupted global financial transactions. Our cybersecurity experts, Bryan Hornung, Reginald Andre, and Randy Bryan, will analyze the fallout, the responses, and what these events signify for the future of digital security.
Don't miss our expert insights on how these breaches could reshape cybersecurity strategies across various sectors. Subscribe and tune in to understand the complexities of safeguarding sensitive data in an increasingly interconnected world.
Join us on this week's episode of Security Squawk as we delve into the latest cyber upheavals affecting major cities and infrastructures. We dissect the Port of Seattle's bold stance against the Ryshida ransomware group, explore the unfolding controversy in Columbus, OH following a data breach debacle, and unravel the logistical nightmare of Transport for London's manual password reset for 30,000 employees. Hosted by cybersecurity experts Bryan Hornung, Reginald Andre, and Randy Bryan, this episode unpacks these entities' strategic, ethical, and logistical challenges, offering insights into how organizations can navigate the murky waters of cyber threats. Tune in for a compelling discussion on the consequences and lessons from these high-profile cyber incidents.
Don't forget to like, share, and subscribe for more insightful cybersecurity discussions!
Join us on Security Squawk as we delve into pressing cybersecurity issues from around the globe. This week, we cover the aftermath of a cyber hack on London's transport network, a massive data breach impacting nearly 1 million Medicare beneficiaries, the City of Columbus's tentative deal in a significant data breach lawsuit, and the cyberattack that led to school closures in Highline Public Schools.
Hosts Bryan Hornung, Reginald Andre & Randy Bryan discuss the broader implications of these attacks and the essential measures organizations can take to safeguard against future vulnerabilities. Tune in for expert insights and the latest updates on these unfolding cyber threats.
This week on Security Squawk, dive deep into the world of Ransomware-as-a-Service with a focus on the recent RansomHub attack that targeted Halliburton, causing significant disruption to their operations. We'll explore the intricacies of the attack, its implications for the oil and gas industry, and how RansomHub has become a major player in the ransomware landscape. Host Bryan Hornung leads the conversation on how businesses can navigate the escalating threats posed by RaaS groups and fortify their defenses against these sophisticated cyber attacks. Don't miss this critical episode packed with expert analysis and actionable insights.
In this week's episode of Security Squawk, host Bryan Hornung delves into the recent cyberattack on Seattle-Tacoma International Airport that left tens of thousands of travelers facing chaos. We explore how such breaches impact airport operations and discuss broader cyber threats to the travel industry. Learn about the response strategies, the experience of affected travelers, and what this means for future cybersecurity measures in our transportation infrastructures. Tune in as we dissect the lessons learned and consider how airports around the world can fortify their defenses against increasingly sophisticated cyber threats.
In this episode of Security Squawk, join host Bryan Hornung as we explore the enduring consequences of cyberattacks, beyond the immediate disruption. From a massive breach affecting billions to ransomware's economic ripple effects, we delve into how these digital threats reshape personal security, healthcare continuity, public infrastructure, and industry dynamics. Using recent high-profile cases as our guide, we discuss the broader implications for policy, industry practices, and personal data protection. Tune in to gain a deeper understanding of the long-term landscape of cyber resilience and what it means for you and your community.
Ransomware is running rampant, and we're diving headfirst into the chaos! Join Security Squawk as we dissect the latest ransomware attacks, interview cybersecurity experts, and uncover the strategies to protect yourself and your business. From McLaren Hospital to the City of Columbus, we're breaking down the breaches and exploring the solutions. Tune in for actionable advice and the latest news on this growing cyber threat.
This week on Security Squawk, we tackle the potential cyber attack on McLaren Health Care, the ongoing fallout, and previous cybersecurity breaches within the organization. We'll also cover recent ransomware attacks targeting key sectors and discuss how these incidents affect global operations and individual security.
This week on Security Squawk, we delve into a series of urgent cybersecurity incidents that have made headlines and raised concerns globally. We'll start with the massive data breach at HealthEquity affecting millions, followed by a critical ransomware attack on OneBlood that's impacting blood supplies. We'll also discuss the recent cyberattack on Fresnillo PLC, one of the world's largest silver producers, and end with updates on the ongoing impacts of cyber incidents affecting Columbus police officers and the wider implications of new cybersecurity legislation in Minnesota. Join us as we unpack these complex issues and explore their implications for cybersecurity practices and policies.
In this episode of Security Squawk, we discuss the global disruptions caused by a recent CrowdStrike update that triggered widespread system outages affecting millions. From airlines to hospitals, we'll explore the extensive implications of this incident and discuss cybersecurity resilience in an interlinked world.
Join us as we break down the technical mishaps, the financial fallout, and the lessons we must learn to safeguard against future crises.
In this episode, we dive into the aftermath of the AT&T hacking incident that affected millions, sparking a class-action lawsuit and raising significant privacy concerns. We'll also explore updates on cyber incidents affecting Patelco Credit Union and UnitedHealth Group, highlighting the escalating costs of cybersecurity breaches and their broader impact on industries and consumers.
This week on Security Squawk, we discuss the contentious debate surrounding ransomware payments. Should they be banned? We unpack insights from top cybersecurity leaders and explore the potential impacts of such a ban on businesses and the economy. Join us as we dissect the arguments for and against making ransomware payments a punishable offense, and discuss alternative strategies for combating these cyber threats.
This week on Security Squawk, cybersecurity experts dive into recent cyber incidents affecting major corporations like TeamViewer and financial institutions such as Patelco Credit Union and Evolve Bank and Trust. They discuss the implications of remote desktop vulnerabilities, the necessity of multi-factor authentication, and the risks associated with state-sponsored cyberattacks.
In this episode of our Security Squawk podcast, we dive deep into the recent wave of cyber attacks that have hit various sectors, with a significant focus on the auto industry. This attack has left many auto dealers struggling to operate, highlighting the critical nature of third-party risks and the importance of having robust cybersecurity measures and recovery plans.
We also touch on a major ransomware group's claim of hacking the Federal Reserve, exploring the potential implications and peculiarities surrounding this bold assertion.
Key topics include:
The CDK Global cyber attack and its impact on auto dealers.
The broader implications for third-party risk management in the auto industry.
The financial strain on small auto dealers and their employees.
The necessity of comprehensive cybersecurity and business continuity plans.
A discussion on the perception of cybersecurity in large companies and the real vulnerabilities they face.
The role of private equity in shaping cybersecurity practices within companies.
Join us as we navigate through these pressing issues and provide our expert insights on how businesses can better protect themselves in this increasingly volatile digital landscape.
This week's Security Squawk tackles a major cyberattack on forklift giant Crown Equipment, exploring the potential impact on the supply chain.
We'll also dive into other security news, including a healthcare ransomware attack, a malicious employee wiping servers, and ongoing exploitation of F5 vulnerabilities.
Tune in for insights and tips to stay secure!
This episode of Security Squawk takes a comprehensive look at the state of cybersecurity in June 2024. We dissect recent significant cyber incidents affecting city halls, hospitals, automotive groups, and a major data breach. Our hosts will also review Microsoft's latest cybersecurity decision reversal and discuss ongoing legislative changes and dark web data trends.
In this episode of the Security Squawk podcast, we unpack some of today's hottest cybersecurity threats, including the recent Ticket Master data breach that exposed millions of accounts due to a lack of multi-factor authentication. We'll also dive into the ongoing ransomware attack on the Seattle Public Library, highlighting the critical need for robust data protection.
We'll explore how businesses can fortify their defenses with zero-trust cybersecurity and discuss the potential consequences of the Ticketmaster cyberattack, emphasizing the importance of safeguarding customer data.
Join us for an insightful discussion on these critical issues and learn how to stay ahead of the curve in the ever-evolving cybersecurity landscape.
In this episode of Security Squawk, we discuss the role of security and awareness training for today's businesses. We explore what security training involves, its various delivery methods, the importance of regular updates, and how businesses can effectively enforce these programs. Learn why continual education and training are important for protecting your company's assets and data in an ever-evolving threat landscape.
This episode discusses the newly expanded SEC regulations that significantly impact financial firms. Our hosts will dissect the amendments affecting broker-dealers, investment advisers, and other financial entities, focusing on the requirements for incident response, data protection, and compliance documentation. This episode is crucial for financial professionals looking to understand and navigate the evolving regulatory landscape.
In this episode, we dive into the latest ransomware incidents impacting organizations in Ascension, Montclair, NJ, and Wichita, KS. We'll explore the rise of Ransomware-as-a-Service (RaaS) and analyze CISA's recent advisory on this growing menace. Discover how implementing Zero Trust Architecture and investing in cyber insurance can bolster your defenses against cyber-attacks. Stay ahead of the curve with insights into the emerging cyber threats of 2024 and learn proactive measures to safeguard your systems. Don't miss this essential discussion on protecting your business from cyber-attacks. Stay informed, stay protected!
This week on Security Squawk, dive into a critical open discussion about the Managed Service Provider (MSP) industry and its pivotal role in third-party IT risk management. Our hosts, Bryan Hornung, Reginald Andre, and Randy Bryan, along with industry experts, will explore current challenges, forecast industry shifts over the next 2-5 years, and dissect what CEOs need to know to safeguard their businesses against evolving IT and MSP landscapes.
Welcome to our latest podcast episode where we delve into the most recent developments in cybersecurity. In this episode, we discuss some critical topics affecting various sectors, and offer practical advice for enhancing cyber resilience.
Topics Covered:
a. Phishing attacks mimicking the U.S. Postal Service (USPS) and other popular services like Google, Microsoft, FedEx, and DHL. We discuss how these phishing sites can trick users into providing personal information or making fraudulent payments. We share tips on how individuals and organizations can identify and protect themselves from these sophisticated attacks.
b. Sophisticated ransomware attacks that target web browsers, highlighting the increasing threats to both personal and corporate data. We discuss the importance of training and cybersecurity software in defending against such threats.
c. The significant security lapse at Change Healthcare, a company owned by UnitedHealthcare, resulting to a large-scale ransomware attack. This incident emphasizes the importance of multifactor authentication (MFA) and other basic cybersecurity measures.
As cybersecurity experts, we bring you the latest cybersecurity news every week. Our podcast is free from ads and promotions, offering clear and concise discussions about current events and their implications for you, your workplace, and your personal life. If you're interested in protecting yourself from cyber threats, or if you're involved in managing cybersecurity for your business, this podcast is for you.
This episode of Security Squawk delves deep into the concerning rise of cyber threats from China against U.S. infrastructure, as highlighted by FBI Director Christopher Wray. We explore the implications of these relentless cyberattacks on national security and the broader geopolitical tensions. The episode also covers the alarming ransomware attacks impacting major U.S. corporations, including UnitedHealth Group, and a critical cyber incident that disrupted New York State's budget negotiations.
This week on Security Squawk, cybersecurity experts Bryan Hornung, Reginald Andre, and Randy Bryan analyze a series of breaches involving Microsoft from Russian and Chinese espionage efforts to systemic security failings. The team will dissect the implications of these incidents on U.S. national security, Microsoft's security culture, and the broader cybersecurity landscape.
Dive into a cybersecurity whirlwind with cybersecurity experts on this week's episode where we uncover a spectrum of cyber threats. We discuss a ransomware gang's botched extortion attempt, and severe data breaches impacting millions, including healthcare giants and global corporations. With a focus on recent attacks on public infrastructure and the exposure of critical personal and employee information, our cybersecurity experts offer invaluable insights into enhancing cyber defenses and navigating the complex landscape of digital security threats.
This episode of Security Squawk takes a cross-country journey through recent cyber security incidents that have captured national attention. Starting with a mysterious system outage at Omni Hotels, we dive into the massive data breach at AT&T affecting millions. We round off our discussion with a critical look at the cyber breach in Traverse City Area Public Schools. Through expert analysis and lively discussions, we aim to uncover the depth of these incidents, their impact on stakeholders, and the broader implications for cyber security in diverse sectors. Join us as we navigate the complexities of these high-profile cybersecurity challenges.
We dive into a series of cyberattacks highlighting the ever-present threat to both public and private sectors. Starting with a nationwide IT outage that has left Panera Bread grappling with significant operational challenges since Saturday, affecting online orders, point-of-sale systems, and internal communications, we'll explore the potential cyberattack implications and what this means for businesses and their cybersecurity measures.
Switching gears to the public sector, the Tarrant Appraisal District in Texas became the latest victim of a ransomware attack, with hackers demanding a hefty ransom. This incident disrupted the district's network and services, prompting a swift response involving leading cybersecurity experts to mitigate the damages and restore operations. The attack underscores the growing trend of targeting government entities and raises questions about data protection and crisis management in the face of cyber threats.
Join us as we dissect these incidents, examining cybercriminals' tactics, the affected organizations' response, and the broader implications for cybersecurity practices. With expert insights and analysis, Security Squawk aims to equip listeners with the knowledge to understand and navigate the complex landscape of cyber threats
In this episode, we discuss the most recent surge of cyber attacks against government agencies and public infrastructures.
We share information and insights about the cyber attack on CISA and the U.S. water infrastructure systems. We also discuss the resurgence of ransomware groups which were initially thought to have been disrupted. We explain why, despite record spending on cybersecurity measures, data breaches continue to surge. This episode sheds light on the dynamic battle between cyber protection efforts and the innovative tactics of cybercriminals.
Tune in for a better understanding of our country's cybersecurity landscape and insights into forging stronger digital defenses.
In this episode, we dive into a wave of sophisticated cyberattacks targeting businesses and organizations across the country. From the breach of US Cybersecurity and Infrastructure Security Agency (CISA) and financial firms like EquiLend and Paysign to a ransomware onslaught against a California law firm and alarming attacks on small and medium-sized businesses, no one is safe. We'll dissect these incidents, explore their implications, and share expert advice on bolstering defenses in an increasingly volatile digital world. Tune in to stay informed and prepared.
We dive deep into the recent cyber attacks that have left indelible marks on industries worldwide. Starting with the ransomware attack on Duvel Moortgat Brewery, we explore how even the production of Belgium's cherished beers isn't immune to the digital dangers lurking in the shadows.
Next, we unravel the intricate web woven by TA4903, a devious group specializing in business email compromise (BEC) attacks, exploiting the identities of trusted U.S. government bodies to perpetrate financial deceit.
We also analyze the attack against Microsoft by Nobelium, unveiling the theft of critical source code and the ongoing surveillance that challenges the tech titan's security fortitude.
The episode rounds off with an exclusive look at the less publicized ransomware attack on Ward Trucking, highlighting the silent yet severe impacts on the logistics and transportation sector.
Tune in to "Security Squawk" as we navigate these digital challenges, dissecting the aftermath, lessons learned, and the relentless quest for cyber resilience in an interconnected world.
In this eye-opening video, we delve deep into the shocking cyberattack on Change Healthcare, orchestrated by the notorious BlackCat ransomware group. Discover the alarming chain of events that led to a staggering $22 million extortion payment, and the subsequent fallout that rocked the cybercriminal world.
What You'll Learn:
The Importance of Change Healthcare: Understand the critical role of Change Healthcare in the U.S. healthcare system and the impact of the cyberattack on nationwide prescription drug services.
The Anatomy of the Attack: Follow the timeline of the cyberattack, from the initial breach to the eventual ransom payment, and the significant disruption it caused.
The Controversy of the Ransom Payment: Explore the complex dynamics of the $22 million ransom payment, including the dispute with a disgruntled affiliate and the failure to secure the deletion of stolen data.
We dissect recent high-profile cyberattacks - a ransomware attack on Change Healthcare; a data breach impacting millions at LoanDepot, and the resurgence of the LockBit ransomware gang. We also discuss the RCE flaw found in ConnectWise's ScreenConnect and explore the alarming cybersecurity statistics for 2024 that every business leader needs to be aware of.
Business owners, IT professionals, and anyone keen on keeping up with cybersecurity trends, this podcast will arm you with the knowledge to stay a step ahead in the digital battlefield.
This week, we discuss the escalating cyber threats targeting the United States, with a particular focus on recent developments and warnings from high-level officials and cybersecurity experts. We begin with FBI Director Christopher Wray's stark warning about China's cyber threat, revealing that offensive malware has been covertly placed in U.S. critical infrastructure by Chinese hackers, representing a scale of threat previously unseen. Wray's comments at the Munich security conference underscore the urgent need for heightened cybersecurity measures against such national security threats. We also cover the alarming ransomware attacks by the ALPHV/Blackcat gang on prominent companies such as Prudential Financial and loanDepot, showcasing the persistent risks ransomware poses to both private and public sectors. With over 16.6 million individuals affected by the loanDepot breach alone, the implications of these attacks are far-reaching. Additionally, we discuss the recent cyberattack that disrupted Georgia's Fulton County, affecting its main technology platforms and limiting operations across various county offices. This incident further highlights the vulnerabilities of local government infrastructure to sophisticated cyberattacks. Join us as we also explore the global response to these threats, including the U.S. State Department's rewards for information leading to the capture of ALPHV gang leaders and the ongoing efforts by law enforcement to counter Chinese hacking campaigns. With the use of artificial intelligence by hackers amplifying the threat landscape, we'll examine the calls for a "Geneva Convention around cyber" and the implications for future cybersecurity defenses. Tune into Security Squawk to stay informed on the latest cyber threats and the evolving landscape of cybersecurity defense strategies.
We unravel the mysteries behind recent cyber attacks against high profile organizations such as AnyDesk, Pennsylvania Courts, Schneider Electric, Clorox, and Johnson Controls. We explore the drama, dissect missteps, and extract lessons from these high-stakes breaches. Don't miss out on expert perspectives and actionable strategies to defend you and your business against digital threats.
This episode of Security Squawk delves into recent high-profile cybersecurity incidents. We explore the large-scale data breach at loan Depot affecting 16.6 million people, analyze Microsoft's encounter with Russian cyber espionage, and discuss the comprehensive findings of the Veeam Data Protection Trends Report for 2024. Join us as we dissect the implications of these events on global data security and corporate cyber defenses.
In this episode of our podcast, we delve into the intricate world of data retention and its associated risks. We explore the challenges businesses face in balancing data retention with privacy and security concerns. Our discussion includes insights on the legal ramifications of excessive data storage, the impact of privacy laws on retention policies, and effective strategies for maintaining data hygiene. Join us as we unravel the complexities of data retention and provide practical tips for safeguarding personal and organizational data.
In this episode of "Security Squawk," we delve deep into the complex world of Managed Service Providers (MSPs) and the pivotal role of pricing in determining the quality of IT services. We're taking a Q&A approach to unravel the mysteries behind the vast pricing spectrum in the MSP market, from budget-friendly options to premium services.
Join us as we dissect the differences between low-end and high-end MSPs, examining the impact of pricing on service breadth, response times, expertise, and overall quality. We'll explore the potential risks and pitfalls businesses face when opting for lower-priced IT solutions and ponder whether a higher price tag truly guarantees superior service.
Our discussion extends to practical advice on how businesses should navigate this landscape, assessing their specific IT needs and making informed decisions in choosing the right MSP. We'll also touch upon industry trends, hidden costs, and the future outlook of the MSP industry.
Whether you're a small business owner, a corporate executive, or just curious about the intricacies of IT service provision, this episode offers valuable insights and expert perspectives to guide you through the MSP maze. Tune in to "Security Squawk" for a comprehensive guide on balancing cost and quality in your quest for the ideal IT partner.
In this episode, we dive into the chaotic world of cybersecurity, where the stakes are as real as they get.
First up, we discuss a harrowing tale from California, where a man's life was turned upside down following the City of Oakland's ransomware attack. We'll break down this ABC7 Chicago report, exploring the profound personal impacts of such cyber breaches.
Then, we shift our focus to the healthcare sector. Hospitals are battling not just for patient health but against digital threats too. We'll analyze a BleepingComputer article about hospitals taking legal action to retrieve stolen data from a cloud storage firm. What does this mean for the future of sensitive data storage?
And there's more - the Ohio Lottery's recent struggle with a cyberattack claimed by DragonForce ransomware. How did this attack impact operations, and what can we learn from it? We'll dissect this incident, as reported by BleepingComputer, to understand the growing threat landscape.
To wrap things up, we open the floor for a live Q&A session! Your questions, our insights - it's all about demystifying the complex world of cybersecurity. Whether you're a tech geek, concerned citizen, or just curious about the digital world, this episode has something for everyone.
Tune in, get informed, and join the conversation. Let's navigate these digital threats together. Don't miss this episode of the Security Squawk Podcast - where cyber reality hits hard!
In this engaging episode of Security Squawk, our trio of cybersecurity experts delves into the intricate world of digital security through a dynamic Q&A format. Designed to enlighten business professionals, this episode is an essential listen for anyone looking to deepen their understanding of cyber threats and defenses.
Our hosts, each bringing their unique insights and experiences, will tackle a series of thought-provoking questions submitted by our audience. These questions range from the basics of identifying common cyber threats faced by small businesses to the complexities of regulatory compliance and emerging technologies.
Whether you're a business owner grappling with budget allocations for cybersecurity, an employee curious about the best practices in data handling, or simply someone fascinated by the evolving landscape of cyber threats and defenses, this episode has something for you.
Expect a deep dive into topics like effective incident response, the balance between data privacy and security needs, adapting to the challenges of remote work, and much more. Our hosts will not only provide answers but also share personal anecdotes and real-world examples, making this episode both informative and relatable.
Tune in to Security Squawk for this special Q&A episode and arm yourself with the knowledge to navigate the ever-changing tides of cybersecurity in the business world. Stay secure and informed with us!
This episode explores recent cyberattacks impacting healthcare, automotive, and critical infrastructure. We analyze the Fred Hutch and Norton Healthcare data breaches, exposing sensitive patient data to ransomware threats. In the automotive sector, Toyota and Nissan face significant cyber challenges, with customer data and internal systems compromised. We also discuss HTC Global Services' breach, revealing the widespread nature of cyber threats. A special focus is given to the alarming escalation in cyberattacks against critical infrastructure, including water systems, with potential international implications. Wrapping up, we delve into an MIT report showing an all-time high in data breaches, underscoring the urgency for heightened cybersecurity across sectors. Join us as we dissect these complex issues and their impact on global security.
Join us in our latest episode where we delve into the critical world of cybersecurity, focusing on recent high-profile cyberattacks targeting vital infrastructure and financial services. We start with CISA's urgent outreach to water utilities about exposed Unitronics devices, highlighting a direct link to the alarming attack on Pennsylvania's water supply. Next, we shift to the cyberattack on a North Texas water utility serving millions, underscoring the escalating threats to public utilities. Our discussion then pivots to the financial sector, examining the CitrixBleed ransomware group's impact on over 60 credit unions and hospitals. We also explore a significant breach involving US government agencies via an Adobe ColdFusion exploit. The episode also includes critical updates: a broader impact assessment of Okta's October 2023 support system breach and the response of Fidelity National Financial to a recent cyberattack. Tune in for an insightful look into these pressing cybersecurity challenges and their implications.
In this episode, cybersecurity experts dive into the catastrophic ransomware attack on Fidelity National Financial, paralyzing real estate transactions nationwide.
They also discuss the Thanksgiving Day ransomware attack on a healthcare giant, Ardent Health Services, affecting 30 hospitals across six states in the US.
They offer updates on General Electric's cybersecurity challenges and fresh insights into the Henry Schein healthcare cyber attack.
This episode is a must-listen for anyone navigating the digital landscape, filled with eye-opening revelations and helpful insights.
This episode explores the recent Boeing cyber attack, dissecting the Lockbit Ransomware group and Boeing's response to the incident. Cybersecurity experts discuss the implications, the leaked data, and the intricacies of dealing with such high-profile breaches.
This episode also dives into the changing landscape of AI investments versus traditional cybersecurity spending. The hosts discuss the potential consequences of diverting funds to AI rather than fortifying cybersecurity measures.
Lastly, this episode discusses the recent cyber attack on the City of Long Beach, underlining the critical need for robust cybersecurity measures in local government entities.
In this podcast episode, cybersecurity experts discuss the activities of the Royal ransomware, a hacker group that has now successfully targeted 350 victims worldwide, amassing $275 million in ransom payments. They delve into the group's sophisticated tactics which made them successful in their cyber exploits.
Additionally, the hosts shift the discussion to McLaren Healthcare, a Michigan-based healthcare provider that fell victim to a cyberattack by the Alfie ransomware gang. They highlight the severity of the breach, exposing which personal information was released to the cybercriminals.
The episode concludes with a mention of the ransomware attack on the state of Maine, affecting approximately 1.3 million individuals. The hosts discuss the extensive data theft, the government's response, and the offer of two years of free credit monitoring and identity theft protection services to affected individuals.
Join our cybersecurity experts in this week's episode of the Security Squawk podcast as they unravel the complexities of these cybersecurity incidents and uncover the lessons learned for both businesses and individuals.
In this episode, they discuss the ongoing Boeing cyber incident and provide updates on what has unfolded since the last episode. They also explore the actions taken by the Lockbit ransomware gang, their threats, and the impact on Boeing.
Additionally, they investigate the case of Mr. Cooper's cyber attack, where a severe breach left millions unable to make mortgage payments. They analyze the aftermath of the breach and its implications for businesses and customers.
Lastly, they shed light on the Cook County Health breach and its connection to a third-party service provider's cybersecurity vulnerabilities.
Don't miss this informative and thought-provoking episode!
In this episode of the Security Squawk Podcast, our cybersecurity experts discuss the recent cyber attacks on Dallas County and the aviation giant, Boeing. They will also deep dive into the recent charges against SolarWinds' ex-CEO, who has been accused of misleading investors and downplaying vulnerabilities within the company. This case highlights the changing legal landscape for those at the helm of organizations dealing with cyber incidents.
They will also touch on the latest changes to the FTC Safeguard Rule, which now requires non-banking financial institutions to report data breaches within 30 days. It's a significant move to ensure transparency and better protection for consumers.
So, whether you're a business leader, an IT professional, or simply someone curious about the ever-evolving world of cybersecurity, check out our latest episode. We promise it's a conversation you don't want to miss!
In this episode of the Security Squawk Podcast, our hosts and our special guest, Cindy Phillips, discuss various aspects of cybersecurity and its impact on businesses.
We discuss the human cost of cyberattacks and the emotional and financial repercussions on both businesses and employees. We also touch on the fact that many businesses claim to be prepared for cyber incidents, but their actual implementation of basic cybersecurity practices, such as multi-factor authentication (MFA) and strong passwords, is lacking. This podcast highlights the need for better preparation, awareness, and proactive cybersecurity measures in the face of growing cyber threats.
In this episode of the Security Squawk Podcast, we discuss two recent ransomware attacks:
Ampersand cyber attack: Ampersand is a company that provides viewership data to advertisers for about 85 million households. The Black Basta ransomware group reportedly claims the attack disrupted Ampersand's operations.
Henry Schein cyber attack: Henry Schein is a healthcare solutions company. In a recent cyber attack, they announced that part of their manufacturing and distribution have suffered data breaches.
We also discuss:
the importance of cyber resilience, which involves preparing for and withstanding cyber-attacks to ensure business continuity
the importance of having effective backups, as well as the cost implications of failing to restore data from backups after a ransomware attack
email security and the differences between Google Workspace and Microsoft 365
In a world where digital threats loom large, protecting your business is paramount. Tune in now and empower yourself and your business with the knowledge to stay secure in a digital world.
Here's a sneak peek of what we'll be discussing in this episode of the Security Squawk Podcast:
We uncover the alarming ransomware attack by the BlackCat Group ALPHV, targeting state courts in Northwest Florida. Discover how the personal information of judges and employees may have been compromised and the concerning lack of encryption in some organizations.
We explore the domino effect of supply chain attacks. Uncover the gripping tale of a cyber attack on an Oklahoma grocery store, driven by disruptions in a major food distributor's operations. The impact is more extensive than you can imagine!
We analyze the cyber attack on CDW Corporation, an IT reseller and service provider. As the Lockbit ransomware gang threatens data release after failed negotiations, we reveal the sinister world of cyber extortion.
We wrap it up with the jaw-dropping revelation of MGM's potential financial loss due to a cyber attack. Don't miss the final chapter in this podcast episode, where we underscore the critical importance of cybersecurity and the far-reaching consequences of cyberattacks on organizations and their customers.
Stay informed and stay safe!
We invite you to tune in to our latest podcast episode where we delve deep into the world of cybersecurity, recent cyberattacks, and the valuable lessons learned. Here's a sneak peek of what you can expect:
Cybersecurity Insights: Discover the latest developments in the cybersecurity landscape, including a major transportation company's battle against a ransomware gang and a cyberattack on the St. Louis Metro.
Hospital Ransomware Attack: Gain valuable insights into the aftermath of a ransomware attack on Prospect Medical Holdings' hospitals in Connecticut. Explore the challenges they faced, financial implications, and the importance of preparation.
Lessons for All: Learn how businesses and organizations can better prepare for cyber threats, isolate systems, conduct risk assessments, and build resilience to limit the impact of potential attacks.
Government and Third-Party Risks: Understand the broader implications of cyberattacks, including the impact on governments and healthcare providers and the need for collaboration and risk awareness.
In this episode of the Security Squawk Podcast, we discuss the pressing vulnerabilities that are shaping the cybersecurity landscape, including major firewall breaches and critical software vulnerabilities. We reveal the unsettling news about the Chinese government's involvement and backdoors that could give them unfettered access to your networks. Learn how these vulnerabilities can impact your organization and what you can do to protect yourself.
Discover why it's crucial to prioritize cybersecurity infrastructure, stay vigilant about security patches, and not assume that older systems are safe just because they've been in use for a long time. Cyber threats are constantly evolving, and it's essential to stay ahead of them to safeguard your business and data.
Tune in to "Cybersecurity Squawk Podcast" for expert insights, real-world examples, and actionable strategies to strengthen your organization's cybersecurity defenses. Don't miss this episode as we unveil the hidden threats and offer solutions to keep your digital assets safe and secure.
In this episode, we dive deep into the alarming cyberattack on MGM Resorts International. With daily losses ranging between $4.2 million to $8.4 million, the casino giant's revenue is severely under threat. Tune in as we explore the financial ramifications, the broader impact on employees and customers, and the key questions around insurance and potential ransom payments. Special attention is given to our feature guest's perspective, David Katz, an equity analyst who shares exclusive insights on the fallout.
In an era where casinos and lodgings are tech-driven, MGM Resorts faces a staggering shutdown of its computer systems. As digital key cards malfunction and reservation systems go offline, we dissect the multifaceted repercussions of this attack and what it reveals about the vulnerabilities in the industry's tech infrastructure.
Join us on this week's episode of Security Squawk as we delve into the recent takedown of Qakbot malware, explore a concerning trend of cyberattacks on schools worldwide, understand who LogicMonitor is and the implications of its breach, and finally, unpack the aftermath and lessons learned from two massive cyber incidents.
In this episode of the Security Squawk podcast, we dive deep into the rapidly shifting landscape of cybersecurity and the ripple effects that breaches have on organizations worldwide.
We begin by discussing the monumental court ruling favoring Merck's $1.4 billion insurance claim post the NotPetya cyberattack. The breaches at Leaseweb, Prospect Medical, and the University of Michigan reveal diverse sectors' vulnerabilities. But it's not just private entities in the crosshairs; even the US government's email servers have faced recent zero-day attacks.
Additionally, with data breaches like Mom's Meals affecting millions, and the University of California locking horns with Lloyd's of London over cyber insurance, it's evident that digital security and its implications are more profound than ever.
Join us as we dissect these events and shed light on the crucial lessons businesses and institutions should draw from them.
Get ready for an eye-opening experience on this week's episode of the Security Squawk Podcast as our cybersecurity experts dive deep into the world of cyber insurance applications.
Ever wondered why insurance companies ask for THAT information? Want to know what it all means for YOUR business? You won't want to miss this live video podcast!
Join us as we unravel the mysteries, share expert insights, and provide actionable advice that can benefit YOU!
Tune in to this week's episode of the Security Squawk Podcast, where our cybersecurity experts dissect the headlines and decode the digital landscape.
Prince George County's Cyber Clash: The public school network takes a hit as a cyber attack ripples through 4500 accounts. What went wrong, and how can similar crises be averted? Our experts weigh in with insights you can't afford to miss.
Connecticut's Million-Dollar Setback: Unravel the tale of a whopping $6 million loss caused by a cyber attack on a School District. Learn from this incident and arm yourself with knowledge on safeguarding against potential financial pitfalls.
White House Rallies for Defense: A summit for school districts facing ransomware threats takes center stage at the White House. Get the inside scoop on this crucial event and a deep dive into the IT budgets that can shield educational realms from digital storms.
Clorox's Brush with Cyber Intrigue: Even giants like Clorox aren't immune to cyber attacks. Delve into the details of this compelling case and understand the anatomy of a breach that impacts even the mighty.
Beyond the Headlines: Join our cyber defenders as they dissect the root causes behind these incidents and chart out the necessary strategies to thwart future attacks. Tune in for an insightful episode that unwraps the layers of modern cyber warfare, equipping you with the knowledge that can safeguard your digital realms. Subscribe now and arm yourself with the tools to combat the unexpected!
In this episode of the Security Squawk podcast, our cybersecurity experts reveal the top ransomware groups of 2023: Lockbit 3.0, Royal Ransomware, and Black Cat among others. They discuss the biggest and most recent ransomware attacks deployed by these groups, their techniques, and most importantly, how you can protect your business from being the next victim.
They also discuss recent cyber attacks against the healthcare and educational sectors, which usually stemmed from "zero-day vulnerabilities." Our cybersecurity experts explain what "zero-day vulnerability" means and how this is being used by malicious actors to conduct massive cyber attacks. They then share best practices to protect yourself and your business from zero-day exploits.
The Securities and Exchange Commission (SEC) has introduced new stringent cybersecurity rules, applicable to publicly-traded companies, family offices, and businesses dealing with investments. These new rules require companies to disclose breach-related information within four days of discovery and provide details about the incident, its impact, and any compromised data.
In this episode of the Security Squawk Podcast, we discuss the content and significance of this rule and share our expert insights to help businesses navigate the increasing prevalence of ransomware attacks.
Welcome to the Security Squawk Podcast, where we delve into the world of cybersecurity and the ever-evolving threats faced by businesses worldwide.
In this episode, we uncover the shocking exploits of the notorious "Cl0p" ransomware gang, which has been wreaking havoc by exploiting a zero-day vulnerability in the popular "MoveIt" application. We shed light on the ruthless tactics employed by this gang, which have resulted in the extortion of millions of dollars from their unfortunate victims. With estimates soaring up to $100 million in just a few months, the scale of their malicious activities is truly alarming. Discover the chilling impact of their attacks, as companies are forced to make a harrowing choice - pay the ransom or risk having sensitive data exposed to the world. But that's not all; the "Cl0p" gang has recently taken an even more dangerous turn by publishing stolen data on regular websites, making it readily accessible to anyone and potentially causing further chaos.
We bring valuable insights into the prevailing cybersecurity landscape and expose the flawed approach many businesses take to safeguard themselves. We explore the common practice of relying solely on cyber insurance and doing the bare minimum to meet insurance requirements. While this might seem like a convenient solution, it falls woefully short in preventing cyberattacks and data breaches.
We also delve into the significance of public disclosure, legislation, and enforcement in driving positive change within the cybersecurity industry. The use of AI and automation is not without its challenges, as we discuss the critical need for human involvement and verification to ensure the efficacy of these tools. In the face of ever-evolving cyber threats, our conversation ultimately underscores the importance of adopting a holistic and comprehensive approach to cybersecurity. It goes beyond just technology, touching upon the internal processes and responsibilities that must be embraced by businesses and individuals alike.
Tune in to the Security Squawk Podcast and equip yourself with the knowledge and understanding needed to navigate the treacherous waters of cybersecurity, and join us in advocating for a safer digital world. Together, we can fortify our defenses and stand strong against cyber criminals.
Welcome to another exciting episode of the Security Squawk podcast! Today, our cybersecurity experts are diving into some eye-opening incidents that have recently rocked the digital world. We'll be covering a cyber attack on a critical water treatment plant, the notorious Black Boy ransomware group, unsettling breaches at a medical facility in Texas, and a distressing ransomware attack on Sun Corp, an esteemed oil producer in Canada.
Now, here's the thing: cybersecurity is an ongoing battle, and our experts can't stress enough the importance of continuous training. It's not just a one-and-done deal! Stay vigilant and keep those skills sharp.
But hold on a second, folks. We've got some concerns. A measly $6 million settlement for businesses affected by a cyberattack? That just doesn't seem right. Our experts question whether that's enough to cover the damages and get things back on track.
So, remember to buckle up and keep those cybersecurity skills up to date. We're here to help you navigate this ever-evolving landscape. Don't forget to share this episode, ask us your burning questions, and stay tuned for more valuable insights.
Join our cybersecurity experts in this week's episode of the Security Squawk podcast where they tackle the latest pressing issues in cybersecurity!
In one story, Lockbit ransomware strikes a significant supplier for Apple, TSMC, demanding a staggering $70 million ransom. The big question is, will TSMC give in to the demand?
Another incident to discuss is the breach on USAA, which exposed the personal information of over 2,500 customers between December 2022 and May 2023. Find out what steps are being taken to address the situation and protect the affected customers.
The city of Dallas, after experiencing a cyber attack, has made headlines by investing a whopping $4 million in a system aimed at preventing future cyber attacks. Is this a viable solution to ensure cybersecurity or just a band-aid on a more significant problem? Tune in to hear our experts' take!
Don't miss this informative episode where our experts dive deep into these crucial cybersecurity topics.
In this episode of the Security Squawk podcast, our cybersecurity team brings you an in-depth analysis of the Verizon data breach report and its far-reaching implications. Join our knowledgeable hosts as they unpack the report's key findings and illuminate the ever-evolving threat landscape. Discover shocking statistics, such as the staggering 83% involvement of external actors in data breaches, emphasizing the pressing need for robust defense measures. Our hosts also delve into the critical role played by the human element in security incidents, with 74% of breaches attributed to human error. Furthermore, we shed light on the importance of safeguarding credentials and the dire need for better password management practices. By sharing valuable insights and practical advice, our podcast equips businesses with the knowledge and strategies to protect themselves against malicious cyber attacks.
Join us on our cybersecurity podcast as we dive into the latest topics and threats in the digital landscape.
In our recent episode, we discuss the MOVEit ransomware attack, UPS data breach, and the formation of a dark web unit by the federal government.
Our co-hosts, Brian, Reginald, and Randy, provide expert insights and analysis on these pressing cybersecurity issues.
Tune in now to stay informed and stay secure in the digital world.
In this episode of the Security Squawk podcast, we delve into the fresh and alarming cybersecurity headlines that have rocked the past week, courtesy of the intel from ID Agent's breach news.
We're diving into an array of breaches this week, including Dunkin Donuts' massive data breach affecting millions, the alarming attack on Nintendo Switch users, and the continued saga of LinkedIn phishing attacks.
But it's not all about recounting the incidents. Our mission is to equip you with insights, diving deep into these real-world cyberattacks to help you understand their impact, their mechanisms, and most importantly, how they could have been prevented.
In this episode, we'll unmask the details of these attacks - their origins, the victims, and the implications. Beyond the headlines, we're here to provide you with a clear picture of the evolving threat landscape and practical strategies to fortify your defenses.
With our light-hearted yet insightful discussions, we're making cybersecurity a subject everyone can understand and implement, from business leaders to anyone keen on digital safety.
Tune into this episode of Security Squawk, as we translate cyber threats into knowledge for safeguarding your business. Join the conversation - be informed, and stay secure.
In this week's episode, we're diving deep into the latest headlines in the world of cybersecurity. We kick off our discussion with an examination of the recently discovered MoveIT vulnerability that was exploited in a ransomware attack. What makes this vulnerability a prime target, and how can organizations fortify their defenses?
From there, we turn our attention to the biopharma industry. As this sector increasingly becomes a hotbed for cyber attacks, we'll dissect why this industry is attractive to cyber criminals and what measures companies can take to bolster their cybersecurity.
We'll also delve into the recent ransomware attack on Eisai, a leading pharmaceutical group. What lessons can other organizations learn from Eisai's experience? And more importantly, how can such incidents be prevented?
Finally, we wrap up with a discussion on the financial implications of ransomware attacks. A recent study by Verizon places the median cost of a ransomware incident at $26k. But is that the whole picture? We'll explore the hidden costs of ransomware and why prevention is always better than cure.
Tune in to stay informed and learn actionable strategies to protect your organization from these evolving cyber threats.
In this episode, our cybersecurity experts discuss the recent $4.25 million fine imposed on Lender OneMain for "cybersecurity lapses", the MCNA Dental data breach that impacted 8.9 million people, and the ransomware attacks on the city of Augusta and New York County.
The podcast also delves into how corporations are on the front lines of the ongoing cyberwar with China.
Don't miss out on this timely and important discussion - listen now and stay ahead of the cybersecurity curve.
In this episode:
Discover the eye-opening discussion that took place during their meeting with FBI agents, where the harsh reality of limited government assistance for small businesses battling cyber threats was unveiled.
Learn why small businesses often find themselves alone in the face of cyber dangers unless they meet specific financial thresholds, and gain valuable advice on how to navigate this landscape effectively.
Uncover the time-consuming nature of investigations and the critical need for every company, regardless of size, to take cybersecurity seriously.
Join us as we empower small businesses to face the challenges head-on, providing actionable insights and practical strategies to fortify their digital resilience.
In this episode of the Security Squawk podcast, our cyber security experts highlight the risks associated with hotel Wi-Fi, hotel TVs, and public charging stations while one is traveling, suggesting listeners adopt a zero-trust perspective in cybersecurity to stay secure.
In this episode, our cybersecurity experts explain the most common methods used by hackers to intercept and decrypt network traffic. They also cite actionable tips that anyone can do to mitigate these risks such as using a personal hotspot or a virtual private network (VPN). Other suggestions include using power-only USB cables, carrying a charging bank, or using charging bricks that plug into electrical outlets.
The concept of "juice jacking," where hackers modify public charging cables to install malware, is also explained.
In this episode, our cybersecurity experts from The Security Squawk podcast discuss the Dallas ransomware attack and urge increased investment in cybersecurity and better network segmentation. The article notes a rising trend in ransomware attacks in 2023, with a significant increase in claims compared to the previous quarter. Microsoft has implemented a more secure MFA push system, but the automation of hacking processes and finding vulnerable devices remains a concern. The vulnerabilities of churches to cyberattacks, the potential of biometric authentication, and recent news of Google's password-less authentication are also discussed.
In this episode, our cybersecurity experts discuss recent cybersecurity breaches at the US Marshals, T-Mobile, and Western Digital.
The US Marshals experienced a three-month recovery from a cyber attack on their computer network, highlighting that even those with extensive resources and knowledge are vulnerable to attacks. Meanwhile, T-Mobile disclosed a second data breach in 2023, where attackers had access to the personal information of hundreds of customers, which could be used to steal identities. On the other hand, Western Digital also suffered a data breach where 10 terabytes of data were stolen.
This podcast discusses the surge in ransomware attacks, particularly in manufacturing and professional services. The hosts emphasize the importance of reporting on these attacks and the potential consequences they may have. They also discuss challenges associated with securing data while working remotely. In addition, they touch on the importance of properly disposing of network equipment before use to avoid compromising a network's security. Companies can establish procedures for secure destruction and disposal of the digital equipment by following proper procedures when disposing of network equipment and wiping it clean before use.
In this podcast, our experts delve into recent cyber incidents this week that have caused significant damage and highlight the need for cybersecurity awareness. They discuss how hackers are targeting US financial organizations and accounting firms during tax season with the sophisticated GuLoader malware and the importance of creating a culture of cybersecurity awareness among employees to prevent such attacks.
They also discuss the recent cyberattack on Suffolk County, which resulted in 139 systems being compromised, with 71 of them being affected by ransomware. Our experts explain the causes of the attack and the impact it has on the county's residents.
The podcast also warns Mac users about the LockBit ransomware and the misconception that Mac devices are more secure than Windows. Our experts explain the costs of a ransomware attack, including legal fees, settlements, and brand damage, and provide examples of recent attacks on NCR and other businesses.
In this episode of the Security Squawk podcast, our cyber experts discuss recent cyber-attacks and threats, including:
· MSI, a Taiwanese chip maker hit by a cyber-attack with a group claiming responsibility for stealing critical data, including BIOS source code and keys, which could have devastating consequences for the company.
· The Camden County Police Department in New Jersey experiencing a ransomware attack, impacting criminal investigative files and day-to-day internal administration abilities.
· The group "Muddy Water" targeting facilities and networks with the intent to destroy the system completely, likely for geopolitical reasons.
· The Rorschach ransomware attack, believed to be the fastest to date and how companies are covering up cyber breaches and ransomware attacks out of fear of legal and financial penalties or compromising user data.
Join us as we delve into the latest cyber threats and explore the potential impact on businesses and individuals alike.
Welcome to this episode of the Security Squawk podcast, where our cyber experts bring you the latest updates on the top security news and trends. In today's episode, we cover the following stories:
Procter & Gamble falls victim to a ransomware attack by the notorious Clop group, highlighting the growing threat of ransomware to businesses and organizations.
Microsoft launches Exchange Online to prevent vulnerable servers from being exploited by hackers and block malicious emails from reaching users.
The theft of around 8 million driver's license numbers from Australia and New Zealand underscores the importance of securing personal data and the need for stronger data protection regulations.
We also discuss a recent bug discovered in Chat GPT, the AI language model, and its implications for data privacy and security.
Tune in to this episode for expert insights and analysis on these critical security issues.
Hosts: Brian Hornung, Reginald Andre, Randy Brian, and Ryan O'Hara
In this episode of the Security Squawk podcast, the hosts delve into several recent cybersecurity incidents. Firstly, they discuss the breach of the US Congress which led to the exposure of the personal information of 170,000 staff members. The hosts analyze the impact of this breach on the affected individuals and also consider the potential implications for future cybersecurity decisions made by Congress.
Next, the speakers examine the ransomware attack on Ring, a smart home security company owned by Amazon, which was carried out by a Russian group known as "Black Cat". The hosts critique Amazon's response to the attack and investigate the root cause of the incident.
Finally, the hosts discuss a recent hack on SpaceX's contractor, in which hackers threatened to sell 3,000 stolen drawings to the company's competitors. The speakers provide insight into how companies can safeguard their data when they collaborate with third-party vendors and contractors.
The Security Squawk Podcast discusses the recent vulnerabilities found in Trusted Platform Module (TPM) that could allow hackers to steal cryptographic keys and sensitive data. They also talk about recent cybersecurity incidents, such as the ransomware attack on Oakland and the data breach suffered by Acer. The hosts emphasize the need for businesses to take proactive measures to secure their data and prevent cyber-attacks.
They also mention the Medusa ransomware group's ransom demand for $1 million for the Minneapolis Public School hack.
The podcast ends with a discussion on the White House's updated National Cybersecurity Strategy for 2023, which focuses on shifting the burden of defending the country's cyberspace towards software vendors and service providers and the importance of collaboration between the public and private sectors.
Last Pass breach
In this episode of the Security Squawk podcast, the hosts analyze the latest cybersecurity incident with LastPass. LastPass, a popular password manager, suffered a data breach in August 2021. The company initially reported that the attackers had gained access to the backup server, but not the encrypted vaults containing user passwords. However, a recent update reveals that the attackers were able to obtain valid credentials for a senior DevOps engineer, giving them access to LastPass' data vault, among other things. The vault contained encryption keys for customer vault backups stored in Amazon S3 buckets. It is unclear whose vaults have been compromised, but the incident highlights the risks associated with remote work and the need for stronger security measures.
Ransomware attack on US Marshal Service
In this episode, the speakers also discuss the ransomware attack which hit the US Marshal Service. The attack targeted systems that contain sensitive law enforcement information, administrative information, and personally identifiable information. It is not known if it was a targeted attack, but it is believed that the attacker exfiltrated data before the attack. It is unlikely that they will turn over the keys for the ransom, especially after the FBI's recent successful takedown of Hive. Additionally, News Corp was breached over a year ago, and employees are only now being notified. It is believed that the Chinese government was behind the attack, and some personal information was compromised. The affected parties are being offered two years of free identity protection and credit monitoring.
GoDaddy Security breach
Further, the hosts discuss a series of security breaches that have recently occurred at GoDaddy, including spear phishing attacks and compromised passwords that have resulted in the theft of sensitive information belonging to thousands of customers. Despite being labeled as the work of "sophisticated threat actors," the author argues that most hacking attacks rely on con artistry and psychological tactics, rather than technical know-how. The article also highlights the importance of domain privacy and the risks associated with transferring domain names to unverified individuals.
The Security Squawk podcast crew discusses cybersecurity, where they examine various breaches and cyber threats. They analyze recent attacks against GoDaddy, which compromised the login credentials of their hosting customers and personnel. They discuss the importance of good password hygiene, multifactor authentication, and scanning for viruses and suspicious activity. They also talk about the proposed legalization of hacking in Russia for patriotic reasons and the recent FBI cybersecurity incident.
They dive into the rise of ransomware attacks against the semiconductor industry and the need for improved network security using government grants. The hosts also talk about a cybersecurity incident at Lehigh Valley Health Network, traced back to an unauthorized activity from a doctor's office. They emphasize the need for separate networks and awareness of the risks of connecting personal devices to corporate networks. The episode ended with a discussion about the use of BYOD devices in healthcare.
The Security Squawk podcast discusses the recent surge of ransomware attacks and their impact on cybersecurity. The hosts talk about the clop ransomware group's breach of 130 organizations using a zero-day vulnerability in the Go Anywhere MFT secure file transfer tool, highlighting the risks associated with file transfer tools that are installed on servers managed by companies and exposed to the internet without proper patching and firewall configurations. The conversation also discusses a recent supply chain breach involving GoAnywhere MFT software, with up to 10-13% of servers compromised, and expresses concern over the vulnerability of these companies and the potential disconnect between security professionals and management.
The article discusses multiple instances of cyber attacks on companies, including Pepsi Bottling Ventures, which was hit with malware that stole employees' personal information, and Nether Manufacturing, which was hit with ransomware. The article also mentions a new ransomware called Mortal Kombat that is targeting systems in the US and highlights the importance of proper security measures and not clicking on suspicious emails or files.
The news segment reports on a series of ransomware attacks in the United States, including on a school, a city, a police network, and a property appraisal website. The lack of cybersecurity maturity in some organizations is noted, and the need for companies to undertake third-party assessments of their network is emphasized.
The Security Squawk Podcast crew discusses cybersecurity. The hosts, Bryan Horning, Reginald Andre, Randy Brian, and Ryan O'Hara, talk about the current state of ransomware attacks happening in the world. They discuss the recent attack on a hospital in Tallahassee, which has led to a security issue, and the hospital has suspended all non-emergency procedures. The word "issue" to describe the attack is noted as being too weak, and the hosts suggest it is being used to minimize public fear and legal implications. The hospital has been targeted due to its large amount of valuable data, making it a high-value target for criminals. The hospital is prioritizing its IT systems and bringing them back online one by one.
Ryan, Randy, and Bryan are discussing the recent ransomware attacks on hospitals and other organizations. They mention that the increase in ransomware attacks was expected due to a combination of factors, including the position of the hackers, the release of vulnerabilities, and the recent boasting of the FBI and Justice Department about their takedown of some cybercrime groups. They also discuss the vulnerability in VMware ESXi servers, a common technology many organizations use for their server infrastructure. The ransomware variant, DougE, is fast and widespread, causing admins to scramble to patch their systems. The recommendation is to apply the patch as soon as possible and to scan for signs of compromise if the system is left unpatched. The vulnerability is considered serious as it gives the attacker's God mode access to all virtual machines running on the VMware ESXi server.
The conversation is about cyber security and the recent ransomware attacks on various organizations. The crew discusses the importance of having an independent cybersecurity risk assessment to understand the full picture of the security situation. They are also discussing the need for regular maintenance and updates to keep systems secure and the importance of educating people about cybersecurity, including the next generation. The cyber experts also mention the recent attack on a chipmaker and a school district, as well as Italy's recent ransomware attack, which was related to the VMware issue. They also mention the use of the Conte ransomware source code by the LockBit ransomware group, highlighting the need for constant vigilance and updates to stay ahead of evolving threats.
Cyber security experts Bryan Hornung, Randy Bryan, Reginald Andre, and Ryan O'Hara discuss a recent cyber attack on NextGen, a healthcare software giant that produces electronic health records and practice management systems for hundreds of large hospitals and clinics in the US, UK, India, and Canada. The company has responded to the attack, stating that they have immediately contained the threat, secured their network, and returned to normal operations. They are conducting a forensic review and have not uncovered evidence of access to or exfiltration of client data. The podcast hosts discuss the lack of information about the attack and speculate about the potential impact on Next Gen's customers.
The cybersecurity experts then discuss a recent cyber attack on T-Mobile that exposed the personal information of 37 million customers. The company has reassured that the hack did not include the most sensitive information that would put customer accounts and finances at risk. However, the group discussing the article expressed concern about T-Mobile's frequent cybersecurity breaches and the need for consumers to assume their data is already out there and take steps to protect it, such as freezing and locking their credit reports.
As a result, T-Mobile customers and the potential for phishing scams and MFA attacks. They also discussed a large-scale credential stuffing attack on PayPal accounts, where hackers used a dictionary of email addresses and passwords to gain access to accounts. The group noted that while PayPal quickly detected the unusual activity and did not report any financial losses, they advised users to change their passwords and enable MFA. They also discussed that many people are not taking the necessary steps to protect their personal information and identity.
The cyber security podcast crew then discussed concerns about the security of the TSA's no-fly list and the ease with which it can be accessed by hackers on unsecured regional airline computers. The speakers express concern about the lack of authentication and security measures in place to protect the list, and worry about the potential for hacking and misuse of the information. They also mention that ransomware payments have gone down but are still at record levels over the last few years. The show concludes with a reminder that there are always new attack vectors to be aware of.
Cybersecurity podcast Security Squawk Episode 107 - Educating business leaders about cyber threats.
Cybersecurity experts Bryan Hornung, Reginald Andre, Ryan O'Hara, and Randy Bryan sit down to discuss a ransomware attack on a company called Maternal and Family Health Services, in which the hackers had access to their system as far back as August 21, 2021. The cyber security experts discussed the potential lawsuit and the time gap between when the attack was discovered and when the notices were sent out. They also mention that it took the company a long time to figure it out and that personal information such as names, addresses, dates of birth, social security numbers, driver's license numbers, financial account payment, card information, user names, passwords, medical information and health insurance information were compromised.
Then the conversation turned to a ransomware attack that affected around 1000 vessels and their Ship Manager software, a Norwegian-based class society. They discussed the lack of detail provided and its impact on the ships, including the potential for the vessel to be locked out of the software and the need to run the boat manually. They also discussed a recent issue with the FAA system, which they believed to be a cyber attack, but they weren't sure if the information provided was accurate. They also talked about the issue of ransomware attacks affecting schools and organizations and the costly lawsuits that follow, such as the case of Hope College, which is currently facing three lawsuits with one as much as $5 million.
On episode 106 of the Security Squawk Podcast, cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss a cyber attack on a school district in Des Moines Iowa, where classes have been canceled for 33,000 students after a cyber attack on its Technology Network. The hosts discuss the issue and mention that this is a common MO for cyber attacks, where not much information is released. They also mention that this is a more serious issue than in the past and that the school district probably wants to keep negotiations private if there is a ransomware attack.
A follow-up to the Knox Community College ransomware. The school disclosed they investigated and responded to a data breach where sensitive information like personal information, national ID numbers, social insurance numbers, passport numbers, IP addresses, employer identification numbers, medical records, health insurance information, sexual orientation, religion, and union affiliation were exposed. The group expresses their concern and skepticism about the company's statement that there is no indication that any specific information was or will be misused, but they cannot rule out there may be attempts to carry out fraudulent activity. They mention that the data was exposed on the dark web, and the company didn't send out notices till the end of December, which is disturbing. They also discuss that companies often underestimate the value and potential use of their data by cybercriminals, and the lack of education and understanding of the risks involved in a cyber attack. They also mention that the data can be used to ruin people's lives for years and the border crisis and biometric information also being accessible.
We also discuss the sale of credentials for accessing Chick-fil-A accounts on the dark web, with the cyber experts discussing the ease with which criminals could use the information to steal from the accounts. They also discuss the need for companies to have policies in place that dictate what employees should and should not post on internal chat apps like Slack and the need for tools to help automate and police those policies.
In Episode 105 of the Security Squawk podcast, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss third-party risk and how the increasing number of cyber-attacks against your partners and vendors can impact your business.
The cybersecurity experts discuss why they think third-party vendor risk assessments will become more common and why businesses must start evaluating their third-party risk.
The crew discusses what companies are doing to ensure they have evaluated their third-party risk while discussing the Cott Systems cyber-attack, which has impacted many local governments in 21 States.
We also update everyone on some older cyber attacks that we have new information on, including the cyber-attack at Louisiana hospital that impacted 270,000 patients. We also updated the Toronto SickKids hospital, getting a free decryptor and an apology from LockBit.
We also cover Burlington Community College and Harrington Raceway & Casino cyber-attacks.
Please remember to share, like, and subscribe to our Podcast and social media channels.
In this week's episode, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss a wide range of cybersecurity topics currently impacting millions of people. In the show, the guys break down how and why the Password Manager provider Lastpass breach will impact millions in the coming months.
Toronto Children's Hospital provides more information about their recent ransomware event, coinciding with a joint warning from the FBI & CISA to U.S. hospitals. We discuss what that is all about.
As always, we enjoy updating our audience on past attacks, and Suffolk County has provided no shortage of lessons learned for cyber experts to dissect.
The crew then discusses the big deal with Okta Source Code discovered on Github.
And finally, the Electric Utility contractor data breach raises concerns over the security of the U.S. power grid.
There seems to be no shortage of new tactics that cybercriminals are trying in the past few weeks and months. In this week's episode, cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss some of these new tactics and what they could mean for businesses in the future.
The cybersecurity experts discuss an interesting twist around the Knox College ransomware attack that is becoming a favorite tactic for cybercriminals.
Cybercriminals have devised a new way to evade Spam filters and trick your employees. Check out this new tactic and how to protect yourself.
Then the cyber security experts dive into various topics around the Draft Kings data breach, the Seven Rooms data breach, and the new ways hackers are using Microsoft Windows to attack your business.
Please share & subscribe to our Podcast and as always find us on social media if you ever have any questions or comments.
In this week's episode, cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss all things Cyber Insurance.
Are you asking, "why do I need cyber insurance for my business?". "Or why does my business need cyber insurance in the first place?"
Even worse, insurance companies are making it harder for small and mid-sized businesses to obtain cyber insurance. The crew discusses what companies need to do to qualify for cyber insurance.
Cyber insurance may not pay out even if you qualify for a cyber insurance policy. Find out why many businesses are having their claims denied by cyber insurers.
2023 is a year when we are going to see more and more cyber attacks. Now is the time to prepare. Please listen to this episode; you will learn everything you need to know to protect your business in 2023.
In this week's episode, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss what is going on with the Rackspace security breach and what MSSP alerts are saying it is.
Next, the experts talk about a ransomware attack that caused a French hospital to transfer patients and shut down operations. They will talk on what happened and why businesses need to take cybersecurity seriously.
Then, the team talks about the Travis Central Appraisal District whose office was hit by a Royal Ransomware that shut down phone lines and online chat systems. What happened?
The experts continue to discuss a school in Little Rock, Arkansas who was hit with a ransomware attack and had to pay the hackers. They will discuss what they think was stolen from their systems.
Lastly, the experts briefly go into an update on Essent who is working to rebuild its systems. Also, a South Jersey district- Monroe Township- was closed for three days due to internet issue leaving parents to wonder, why?
Tune in, Like and Share the Show!
Articles Used:
https://doublepulsar.com/rackspace-cloud-office-suffers-security-breach-958e6c755d7f
https://www.msspalert.com/cybersecurity-news/rackspace-hosted-exchange-security-incident-timeline-and-recovery-updates/
https://www.bleepingcomputer.com/news/security/ransomware-attack-forces-french-hospital-to-transfer-patients/
https://www.statesman.com/story/news/2022/12/05/travis-county-tx-home-appraisals-ransomware-attack/69703419007/
https://www.thv11.com/video/news/education/little-rock-schools-to-pay-hackers-to-end-ransomware-attack/91-d492d592-062b-4d1a-ad78-9dd1a3a82f4d
https://www.asicentral.com/news/newsletters/promogram/december-2022/essent-working-to-rebuild-after-encryption-attack/
https://www.inquirer.com/news/monroe-township-schools-closed-internet-third-party-unauthorized-20221201.html
In this week's episode, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss some hackers who are exploiting TikTok's "Invisible Body Challenge" to spread malware that can steal passwords and credit card details. The experts get into what they believe is going on and what you can do to fix it.
Next, the experts discuss a brute cyberattack on customers who use DraftKings betting site. Find out how much they stole and what DraftKings president is saying.
Meanwhile, the crew talks about how Google has released an emergency security update for the desktop version of the Chrome web browser which is the eighth zero-day vulnerability this year. Also, the crew discusses how this Chrome extension is being deployed to steal cryptocurrency passwords.
Lastly, the team talks about WhatsApp data breach who is selling nearly 500 million user records and what's going on there?
Also, the experts briefly go over who the United States government is banning the sale of equipment from and what they are saying is the reason "unacceptable risks to national security".
Tune in! Like and Subscribe!
Articles used:
https://www.forbes.com/sites/barrycollins/2022/11/29/tiktok-invisible-body-challenge-hijacked-to-spread-malware
https://www.bleepingcomputer.com/news/security/hackers-steal-300-000-in-draftkings-credential-stuffing-attack
https://www.bleepingcomputer.com/news/security/google-pushes-emergency-chrome-update-to-fix-8th-zero-day-in-2022/
https://www.bleepingcomputer.com/news/security/google-chrome-extension-used-to-steal-cryptocurrency-passwords/
https://www.techradar.com/news/whatsapp-data-breach-sees-nearly-500-million-user-records-up-for-sale
https://www.bleepingcomputer.com/news/security/us-bans-sales-of-huawei-hikvision-zte-and-dahua-equipment/
In this week's episode, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara quickly provide an update on the Jackson County and MediBank cyberattacks that happened not to long ago.
The experts then discuss a data breach settlement that Forefron Dermatology has to pay $3.75M individuals who were impacted and how these individuals were impacted after the fact.
Meanwhile, the crew talks about a ransomware attack that has affected 650 healthcare providers, who was involved & how did this happen?
Next, the team discuss a CMMC update that helps prepare small businesses in the DoD space. Also, an update on the FTC safeguard rule that is extended now by six months, what does that mean for businesses?
Lastly, the cyber experts talk about a phishing kit that is impersonates well known brands to target US shoppers.
Tune in and Like/Share Show!
Articles that were used:
In this week's episode, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss an Austrailian bank, Medibank who faces possible class action after a devastating data breach that left millions of customers exposed. Who is allegdly behind this hack? Meanwhile, they continue to dive deeper into why Austrailia is considering banning the payment of ransoms to cybercriminals because of Medibank.
Next, the crew talks about a Canadian food retail giant, Sobeys, who was hit by Black Basta ransomware. What should the grocery store have in place so their IT systems don't disrupt their operations again? Tune in.
Meanwhile, the experts get into another ransomware attack that shut down two counties, Jackson and Hillsdale in Michigan because of a systems outage. What's going on here?
Lastly, the cyber experts talk about 42,000 web domains that impersonate well-known brands to redirect users to sites promoting adware apps, dating sites, or 'free' giveaways.
Like and share the show!
Articles that were used:
https://www.news.com.au/technology/online/hacking/medibank-faces-possible-class-action-after-hack-leaves-millions-of-customers-exposed/news-story/aa73c71740879c524b6dc01bfe268350
https://www.reuters.com/technology/australia-consider-banning-paying-ransoms-cyber-criminals-2022-11-12/
https://nbc25news.com/news/local/jackson-and-hillsdale-counties-close-due-to-ransomware-attack
https://www.bleepingcomputer.com/news/security/canadian-food-retail-giant-sobeys-hit-by-black-basta-ransomware/
https://www.bleepingcomputer.com/news/security/42-000-sites-used-to-trap-users-in-brand-impersonation-scheme/
In this week's episode, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss a new report on how hackers are selling access to 576 corporate networks for $4 million. The team will explain what they think these companies could've done to prevent this from happening.
Next, the experts talk about a threat actor who is behind this supply-chain attack which has injected a malicious code into a file that gets loaded by news outlets' websites and how to protect yourself if your a news outlet.
Also, the crew gets into an instagram influencer known as 'Hushpuppi' who has been sentenced to 11 years in prison for cyber fraud. Tune in!
Lastly, the cyber experts talk about Emotet malware operation which is again spamming malicious emails after almost a four-month "vacation." The team discusses what's going on here.
Make sure to like and share the show!
Articles used:
https://www.bleepingcomputer.com/news/security/hackers-selling-access-to-576-corporate-networks-for-4-million/
https://www.bleepingcomputer.com/news/security/influencer-hushpuppi-gets-11-years-in-prison-for-cyber-fraud/
https://www.bleepingcomputer.com/news/security/emotet-botnet-starts-blasting-malware-again-after-4-month-break/
https://www.bleepingcomputer.com/news/security/hundreds-of-us-news-sites-push-malware-in-supply-chain-attack/
In this week's episode, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss an FTC guideline or regulation that impacts a lot of businesses in the United States. The team talks on why people should be paying more attention to these guidelines and why its important to.
Next, the crew talks on what the government is saying and why they're pushing these businesses like financial services who handle transactions, credit card information, wire transfers, etc. to stay up to date on cybersecurity. Tune in!
Make sure to like and subscribe! Share the show!
In this week's episode, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara with special guest Javvad Malik at J4vv4D discuss the topic of phishing & what Javvad notices is going on with these types of attacks.
Next, the team disucsses 4 tips security experts are saying will help protect thier IT employees from clicking on a link. Tune in to learn how to mitigate this human error!
Then, the crew review some of the top phishing scams this week relating to Costco, Ace Hardware, PayPal, Netflix, Truist, cPanel, and Microsoft. Would you have been able to spot these scams?
Lastly, the security experts discuss an article about a 65-year women who was scammed on Instagram because she was in love.
Make sure to tune in! Like and Share the show!
Articles used:
https://unfspinnaker.com/98214/news/phishing-is-organized-crime-unf-chief-information-officer-says/
https://www.constructiondive.com/news/cybersecurity-spear-phishing-tech/634408/
https://news.trendmicro.com/2022/10/21/costco-ace-hardware-paypal-netflix-truist-cpanel-microsoft-phishing-scam/
https://gizmodo.com/astronaut-iss-instagram-1849638814
In this week's episode, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss a major cyber attack that delays patient care at a US hospital chain. What are experts saying?
Next, the experts talk about Microsoft Exchange servers that were hacked to deploy a LockBit ransomware. Wondering if you should move away from Microsoft Exchange email servers?
Then, some hardware vendors had some issues lately and why that could have major implications for a cyberdefenders/ people trying to keep their network secure down the road. Tune In!
Also, the crew talks on some Cloud services out there that are making hacking easier. Laslty, the experts will talk on some minor cyberattacks, which might be a nucance to some, but people should know those have a major impact too. Why?
Tune into the show! Like and Share!
Articles used:
https://www.theverge.com/2022/10/11/23398707/cyberattack-hospital-system-patient-care-issues?fbclid=IwAR27gxamTbY6C1R9zAinlpd7ff2a9e1RM1QNe5KPZvOVsEJ0LSjGXv4QN9s
https://www.bleepingcomputer.com/news/security/microsoft-exchange-servers-hacked-to-deploy-lockbit-ransomware/
https://www.bleepingcomputer.com/news/security/intel-confirms-leaked-alder-lake-bios-source-code-is-authentic/
https://www.bleepingcomputer.com/news/security/caffeine-service-lets-anyone-launch-microsoft-365-phishing-attacks/
https://www.theguardian.com/us-news/2022/oct/10/cyberattacks-disrupt-us-airport-websites
In this week's episode, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss some updates on two major ransomware attacks, LAUSD and Suffolk County. Find out what officals have found.
Next, the crew talks about how ransomware actors are actually getting into your systems and there is a new WWE champion and its not phising, tune in!
Then, the team discuss's a luxury car manufacturer dealing with a ransomware attack among other entities.
Lastly, the experts will jump into a discussion on vulnerabilities and why its important you look at different layers across your cybersecurity spectrum.
Remember to like and share the show!
Articles used:
https://www.axios.com/2022/10/03/hackers-stolen-data-la-school-district-ransomware
https://www.newsday.com/business/suffolk-county-ransomware-real-estate-cnapizgu
https://www.infosecurity-magazine.com/news/bug-exploitation-top-ransomware
https://www.wionews.com/world/ferrari-falls-victim-to-ransomware-attack-7gb-of-its-internal-documents-made-public-522248
https://www.globenewswire.com/news-release/2022/10/04/2528024/0/en/BlackByte-Ransomware-Gang-Adds-Sophisticated-Bring-Your-Own-Driver-Technique-to-Bypass-More-Than-1-000-Drivers-Used-by-Industry-Wide-Endpoint-Detection-and-Response-EDR-Products-So.html
In this week's episode, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss a particular industry out there that is a super soft target right now and the cyber criminals know it. Who is it and why should people be aware of this?
Next, the crew talks about some data that they gathered around ransomware attacks increasing and not only increasing but these ransomware groups are changing their tactics faster then what they thought. What are these changes?
Lastly, the team talks about a hotel chain that was cyber attack over the labor day weekend and now out 3-6 weeks stories are coming out.
Tune In! Like and Share the show!
Articles used:
https://suffolktimes.timesreview.com/2022/09/ransomware-attack-on-suffolk-county-heightens-importance-of-cybersecurity-for-local-municipalities/
https://www.msspalert.com/cybersecurity-research/research-20-of-all-reported-ransomware-attacks-occurred-in-the-last-12-months/
https://www.csoonline.com/article/3674848/ransomware-operators-might-be-dropping-file-encryption-in-favor-of-corrupting-files.html
https://www.bleepingcomputer.com/news/security/new-royal-ransomware-emerges-in-multi-million-dollar-attacks
https://www.wsj.com/articles/cyberattack-on-intercontinental-hotels-disrupts-business-at-franchisees-11664184602
In this week's episode, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss how uber believes the hacker behind last week's breach is associated with the Lapsus$ group. The crew will go deeper into what they think is going on here?
Next, the team talks about Grand Theft Auto 6 gameplay videos and source codes that have been leaked after a heacker breached Rockstar Game's Slack server and Cofluence wiki. The team will explain what happened and how this can be prevented from happening again.
Then, the crew talks about Revolut who has suffered a cyberattack that gave an authorized third party access to personal information of tens of thousands of clients.
Lastly, the team goes into the quote that Kozlovski says about how "cyber attacks are going to get much worse" and why?
Tune in to this week's episode! Like and subscribe!
Articles used in the show:
In this week's episode, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss a major moving and storage unit giant, U-Haul who discloses a data breach after a customer contract search tool was hacked to access customer names and driver license information. They will explain what they think is going on?
Next, the team gets into the Lorenz ransomware gang and what they are doing now to access private information among corporate networks.Meanwhile, the crew believes that this Lorenz ransomware group may be behind this Texas hospital communication systems to go offline and they explain why?
Then, the team goes into a medical billing company, Practice Resources LLC who faces a lawsuit months after ransomware attack. After, that they get into why more companies should publicly acknowledge these ransomware attacks? More openess would help protect others.
Lastly, 49 people were sued by Atlanta Falcons employee who was exposed to a data breach of her social security number and personal information.
Make sure to tune in!
Share the show!
Articles that were used in the show:
https://www.bleepingcomputer.com/news/security/u-haul-discloses-data-breach-exposing-customer-driver-licenses/
https://www.bleepingcomputer.com/news/security/lorenz-ransomware-breaches-corporate-network-via-phone-systems/
https://healthitsecurity.com/news/texas-hospital-rebuilding-communication-systems-after-ransomware-attack
https://wskg.org/medical-billing-company-faces-lawsuit-after-ransomware-attack/
https://www.zdnet.com/article/the-ransomware-problem-wont-get-better-until-we-change-one-thing/
https://amolivia.com/2022/09/09/49-people-sued-by-atlanta-falcons-employee-over-super-bowl-week-data-breach/
In this week's episode, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss a major US school district that has been hit with ransomware. The experts will explain what happened here as well as dive deeper into what ransomware is and how it actually works. Also, a major social media platform, TikTok is having data security issues which doesn't mean they were hacked. The team will explain why and what you should do to protect your accounts. Next, the experts get into two major organizations, a electronics manufacturer and a national football team league, both coming out with new information around previous breaches that their companies were involved with. Lastly, one of the Security Squawk co-hosts had an incident happen over the Labor day weekend. He will share what happened and what you can learn from it.
Tune into the show to find out more!
Articles featured in the show:
https://www.bleepingcomputer.com/news/security/second-largest-us-school-district-lausd-hit-by-ransomware/
https://fossbytes.com/tiktok-suffers-data-breach-change-your-passwords/
https://www.securityweek.com/samsung-us-says-customer-data-compromised-july-data-breach
https://www.bleepingcomputer.com/news/security/san-francisco-49ers-blackbyte-ransomware-gang-stole-info-of-20k-people/
In this week's episode, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss what happened to the targeted attacks on Twilio and Cloudflare employees that resulted in over 130 organizations compromised. Also, the crew talks about a related data breach with DoorDash and why the same Twilio attackers are targeting business clients of Okta.
Next, the experts will discuss what the Chilian government is saying about their systems being breached and what they think is happening here. Following, the crew talks about the Baker & Taylor's systems that remained offline a week after a ransomware attack and why?
At the end of the show, the experts will go over a ransomware group that is considered to be a threat to the U.S. Health sector and what the Department of Health and Human Services is saying.
Tune in to find out more information!
Articles featured in the show:
https://threatpost.com/0ktapus-victimize-130-firms/180487/
https://www.cpomagazine.com/cyber-security/food-delivery-company-doordash-latest-name-added-to-data-breach-spree-conducted-by-twilio-hackers/
https://www.infosecurity-magazine.com/news/chile-and-montenegro-floored-by/
https://www.infosecurity-magazine.com/news/baker-taylors-offline-ransomware/
https://www.scmagazine.com/analysis/ransomware/ransomware-group-blurs-lines-between-crime-state-sponsored-activities-hhs-alert-warns
In this week's episode the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss what they have been doing in Charlotte, North Carolina for cybersecurity and what's going on nowadays. Next, the crew will get into what they are hearing from an ex-CISA member, Chris Krebs, who is well-known in the cybersecurity realm. Lastly, the crew will get into some cybersecurity attacks that have been in the news recently and how you can prevent these attacks from happening to your business today!
Tune in! Like and Subscribe!
In this week's episode the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss a ransomware attack by the Yanluowang ransomware group who has breached Cisco. Next, the team talks about a fallout of HanesBrands who was hit ransomware and the recap/ lessons they learned from this attack. Also, the crew jumps into some trends in ransomware and what these ransomware gangs are doing. Lastly, the experts briefly will get into a new ransomware group called Zeppelin and the alert that was put out. The FBI/ CISA put these alerts out not to scare but to mitigate this from happening to you and your business.
Stay Tuned! Like and Subscribe!
Articles that were used in the show:
https://www.bleepingcomputer.com/news/security/cisco-hacked-by-yanluowang-ransomware-gang-28gb-allegedly-stolen/
https://www.axios.com/2022/08/11/hanesbrands-ransomware-attack-earnings-report
https://securityboulevard.com/2022/08/black-hat-insights-getting-bombarded-by-multiple-ransomware-attacks-has-become-commonplace/
https://www.darkreading.com/edge-threat-monitor/cybercriminals-weaponizing-ransomware-data-for-bec-attacks
https://www.cisa.gov/uscert/ncas/alerts/aa22-223a
In this week's episode the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss two data breaches, Twitter and Twilio. Twitter confirms that zero-day was used to expose data of 5.4 million accounts. The experts will get into what happened here and how you can protect your social media accounts. Also, the crew gets into Twilio who discloses a data breach after an SMS phishing attack on employees. Next, the team discusses what your next phishing email could be from, like Paypal and Quick Books. Lastly, the experts get into why phishers are making their way around 2FA and using other tactics like a phishing campaign aimed to take over Coinbase. Tune in!
Like and Subscribe!
Articles that were used in the show:
https://www.bleepingcomputer.com/news/security/twitter-confirms-zero-day-used-to-expose-data-of-54-million-accounts/
https://www.bleepingcomputer.com/news/security/twilio-discloses-data-breach-after-sms-phishing-attack-on-employees/
https://www.ghacks.net/2022/08/08/your-next-phishing-email-may-come-straight-from-paypal/
https://threatpost.com/phishers-2fa-coinbase/180356/
In this week's episode the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss some data breaches specifically with Wawa and One Touchpoint. What is actually going on? Next, the team gets into what the future might look like for businesses when it comes to cybersecurity and ransomware. Then, at the end the experts will reveal what they think people aren't doing enough today to protect themselves against these attacks and what they think people need to be aware of now.
Share the show!
Like and Subscribe
In this week's episode the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss a digital security giant called Entrust who suffered from a cyberattack where threat actors breached their network and stole data from internal systems. Next the crew dives into a hacker forum that is claiming to have access to 50 American companies through an unamed MSP. They explain what CISA is saying and what they believe is going on. Also, the team goes into a Kansas MSP called NetStandard who quickly shut down its MyAppsAnywhere cloud services due to a ransomware attack which might have to do with the hacker forum. The cyber experts continue with a mailing list provider called WordFly who are still trying to recover from a ransomware attack. Lastly, the crew talks about an incident response report that says 75% of these attacks are from disgruntled ex-emploees who left with the companies data and what they think is going on here?
Make sure to tune in!
In this week's episode the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss how Russian hackers are using some of your favorite online file sharing applications to ruin your day. Next, the crew looks into a report by Microsoft were they detected that cybercriminals have figured out a method for your MFA. Also, the team jumps into one company that survived a ransomware attack and how they didn't have to pay the ransom. Then, the experts update everyone on the statistics for ransomwares in 2022. At the end of the show, the team shows an example of a company who didn't get paid by their insurance company and why?
Tune into this week's episode!
Like and Subscribe!
In this week's episode the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara deep dive into a IT company in New Jersey called SHI, who is dealing with a ransomware event that occured over the 4th of July holiday. Also, the crew takes a look at a ransomware gang who is allowing you to search for data that they've stolen to make it easier for scammers to get a hold of. Next, the team gets into a Diamond Company that paid $7.5 Million to cybercriminals and the little lessons that need to be learned around cyber insruance. Lastly, the experts gets into a data breach against Marriot Hotels. What's going on with this hotel chain and why do they keep having issues with having their guest data exposed?
Please Like and Share the Show!
In this week's episode cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss an article by Politico which goes into explaining that by next Septemeber the government wants a goal of 2/3 of ransomware cases reported to them. The question then becomes how do we even figure out how many total ransomware attacks are out there? Also, the team discusses how CISA is getting a 3 billlion dollar budget this year which is a 13% increase from last year levels which raises the question has your business increased your cybersecurity expense by 13%? Lastly, experts talk about two critical infrastructure sectors hit with ransomware and what's going on. Tune in!
Please like and subscribe!
In this week's episode cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss a ransomware attack response on the major publisher Macmillan. The crew also discusses whether or not Walmart has been hacked, and why Exchange servers, RDP, and unpatched firewalls are still a successfully massive target for cybercriminals.
Cybercriminals claim they have stolen data from Chimpmaker AMD and why this could have further implications for cybersecurity in the future. Popular NFT platform OpenSea had a data breach and we discuss what the concerns are around that. Definitely not a slow news day on the podcast so strap in and enjoy the content.
Please share, like, and subscribe to our channel
In this week's episode, the cybersecurity experts Bryan Hornung, Reginald Andre, and Ryan O'Hara discuss some information statistics about how the C-Suite feels about ransomware? Then, the crew will get into several ransomware attacks and how it ties into the C-Suite statistics. At the end of the show, the crew will bring everyone up to speed on a new attack vector for cybercriminals that revolves around going after your cloud data and why that's important? Stay Tuned!
In this week's episode, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss some ransomware statistics from May. The team gets into a ransomware attack on a Arizona hopsital and why paying the ransomware puts a bigger bullseye on your back? Then the crew will go into this HelloXD ransomware and what they are up to with their new tactics. Lastly, the experts get into a pretty big attack on a popular project management, document sharing, document repository user of Confluence and they will explain how widespread these attacks are against the vulnerability that exists within that server. Tune in to find out more information!
In this week's episode, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss this exploit, this vulnerability, that is running rampant right now no patch for it and its a type of zero day that is known as MIcrosoft: Follina. The crew will explain what this is and what you shouldn't be clicking on, on your computers. Then, the team gets into two countries Costa Rica and Italy who are dealing with being pawned by cybercriminals. Could this start creeping into the United States? Next, the experts go into a retreat where cybercriminals believe that ransomware is not the best route to go nowadays. They will get into some detail about what they think these cybercriminals are going to change it to, to get more money? Briefly, the crew will get into a article on Qbot which is like Trickbot, who combine their forces together to spread these viruses quicker than normal. Lastly, the cyber experts will go into some targeted healthcare statistics and what they need to do to be secure? Tune in for more information!
In this week's episode, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara talk about the Hane's ransomware attack, which was not one of the attacks over Memorial Day weekend. Next, the crew goes into a county in New Jersey under a ransomware attack and new ransomware tactics that these cybercriminals are using towards businesses. Then, the team gets some exciting information about a state that had its financial passwords stolen. At the end of the show, the expert's deep dive into some ransomware statistics and how many of these attacks are happening in a day? Listen to find out more information!
In this weeks episode, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara go over the importance of cybersecurity awareness training for businesses. They crew also goes over what a cybersecurity awareness training should look like in a company of any size. At the end, the experts will explain how you can be a leader in this and help your company stay safe from cybercriminals.
In this weeks episode, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara update people on whats happening in Costa Rica as well as other countries too. Next, the team briefly goes into another cyber attack that happened against a school up in Michigan. Then, the experts talk about a state insurance agency down in Texas that was not secured properly which resulted in information getting released. The crew explains why this is important and why you could potentially have this in your business without even knowing it? Lastly, the cyber experts share some interesting data in a Proof Point report that paints a nice picture of where businesses are at with cybersecurity in May 2022 and where they need to go and do to get secured. Tune in to find out more information!
In this weeks episode, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss five active ransomware attacks that are happening right now and is being pushed out through the news. The first ransomware attack the team gets into is Conti who prompts Costa Rica Into National Emergency. The crew will go over what is happening in Costa Rica and what Conti is doing? Next, the experts get into a cyber attack that prompted a security response by Oregon secretary. Why is this happening, the experts explain? Then, the cyber experts go into a ransomware attack with Lincoln College and how they finally closed after 157 years. Also, the crew goes into Omnicell who reported some of information technology systems were affected by ransomware. Lastly, the team goes over a farm machinery giant AGCO who got hit with a major ransomware attack.
In this weeks episode, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss two universities that are dealing with a cyberattack, Austin Peay State University and Kellog Community College. The team talks about how these were announced and what happened with both? Moving along, the crew goes over Yuma Regional Medical Center's computer systems that are slowly returning after an attempted cyberattack. Then, the experts go over the new Black Basta ransomware that possibly linked to the Conti Group and what is going on there? Lastly, the cyber experts go over Blume Global whose platform went down after a 'cyber incident' and how they are trying to come back on?
In this weeks episode, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara goes over the Lapsus$ group and why they are targeting T-Mobile? Next, the crew talks about some theives who stole about 1 million dollars from an NFT Project. These cyber experts will educate you on the security side of NFT's and what you can do to protect yourself when using NFT's? Then, they take an inside look at a ransomware incident with Emotet which everyone thought was dead and now they are back. Lastly, the group talks about what nation state hackers do and who they are targeting today? Tune in to find out more!
In this weeks episode, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan, and Ryan O'Hara discuss two cyber attacks in the last week that has been going on that is being featured in the news. As well, the team goes over two gangs that are really behind more than half of the cyber attacks. Then, the crew will get into the long lasting effects of a ransomware attack and how this can impact your business for years and years, if you're able to re-cover? Also, the team shows two examples where ransomware attacks that happened years ago are still having a lasting effect on these businesses. Finally, the experts go over how Google Chrome on your computer can cause you to get ransomware? Tune in to find out more information!
In this weeks episode, cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan and Ryan O'Hara jump into some interesting information on a ransomware attack against Snap-On tools. The crew also wants to highlight some troubling attacks that are happening against smaller healthcare facilities around the U.S. and how prevalent these attacks are? Lastly, the experts bring in some data about cyber insurance, whether or not cyber insurance can cover you in an attack, and some examples where cyber insurance might not have worked out certain businesses and victims? Listen in to find out how the FBI is helping with this!
In this weeks episode, the cybersecurity experts, Bryan Hornung, Reginald Andre, Randy Bryan and Ryan O'Hara talk about employees and how they can cause breaches within your organization. The team gets into some examples as well as some stories that the crew has experienced around breaches with their own employees. Listen to what you can do to protect your business!
In this weeks episode, the cybersecurity experts, Bryan Hornung, Reginald Andre, Randy Bryan and Ryan O'Hara deep dive into the Lapsus$ hacking group. The crew goes over who they are, what they have been doing, and what their methodology is behind how they compromise company accounts? Also, the team talks about how businesses need to do more to protect themselves from a cyber attack, especially now. Tune in for more on Lapsus$ and what you can do to protect your business!
In this weeks episode, the cybersecurity experts, Bryan Hornung, Reginald Andre, Randy Bryan and Ryan O'Hara, share what the White House has said, "to get ready" of whats to come with cybersecurity. The experts point out that Russia is looking to unleash their government hackers and privte hackers onto all U.S. company businesses as the Ukraine and Russia invasion continues to occur. Also, the team will discuss what U.S. businesses should do to protect themselves from this? Lastly, the crew will go over some cyberattacks that are happening towards identity and access management companies and a big company who got fined $500,000 for 'shoddy' security.
In this weeks episode, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan and Ryan O'Hara discuss some recent cyberattacks that have been active in the news. Specifically, Israel who says their government websites were getting targeted with an cyber attack. Meanwhile, the automative giant Denso confirms hack and the Pandora ransomware group takes credit. The crew goes into why they think this case is interesting? Then, the experts go into an Accenture report who warns people that these cybercriminals overseas like Russia and Ukraine, might attack businesses in the U.S.? Lastly, the cybersecurity experts describe what this new law is that the government wants to mandate for companies when they get hacked.
In this weeks episode, the cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan and Ryan O'Hara discuss two big tech companies that got breached, Samsung and Nvidia. The crew will go over what is going on with these two and the cybercriminals who are behind it? Next, the team goes over a joint alert by CISA and the FBI to explain what exactly is going on with cyber attacks between Russia and Ukraine. Then, the experts will describe as to why it is so easy for these cyber criminals to get into your accounts? Lastly, the team goes in an article about passwords and how quickly it is for cyber criminals to brute themselves in.
In this weeks episode, cybersecurity experts Bryan Hornung, Reginald Andre, Randy Bryan and Ryan O'Hara discuss why they have seen constant cyber attacks happening as this war between Russia & Ukraine continues. The team then breaks this down further to explain what this all means in terms of what these cyber criminals are actually doing and how to prevent it from happening? Also, the crew goes over how these cyber criminals used social engineering or back door techniques to get into these businesses?
In this weeks episode, the cybersecurity experts, Bryan Hornung, Reginald Andre, Randy Bryan and Ryan O'Hara discuss a bigger ransomware attack that has caused expeditor shipping to shut down. The crew then goes deeper into what they think is happening with this company? Another point the crew talks on is this company Meyer Corporation who discloses a cyberattack that has impacted their employees. Lastly, Ryan O'Hara, talks on an experience he had with a smaller mom & pop retail business that was a victim in a ransomware attack.
In this weeks episode, the cybersecurity experts, Bryan Hornung, Reginald Andre and Randy Bryan go into the ransomware attack against the 49ers organization. The experts go on to raise some interesting points around the person in the FBI who leaked information around the 49ers cyber attack. Then, the team will take a look at who attacked the 49ers and what they are up to because there has been more attacks by this ransomware group than just the 49ers. Lastly, the crew will go over why Multi-Authentication is not the only protection you should use?
In this weeks episode, the cybersecurity experts, Bryan Hornung, Reginald Andre and Randy Bryan go over a Fortune 500 service provider who got hit with ransomware and what the repercussions of that were? This event is kind of like the Kronos ransomware attack. Also, the team goes over two smaller ransomware events that have to deal with cybercriminals who are changing their tactics vs. it just being a smaller attack. The crew will let you know what is changing and why?
In this weeks episode, the cybersecurity experts, Bryan Hornung, Reginald Andre and Randy Bryan discuss two different level cyber attacks, the largest printing company in the U.S. down for 1.5 months and the largest payroll & HR cloud provider down for 2 months that are affecting many people in the world today. The team briefly will go over why these attacks are not getting attention or press that it should? Then, the crew will move into an interesting network attached storage device called QNAP which is under a cyber attack. At the end, the cybersecurity experts will go over enaging data on what happened in 2021 regarding cybersecurity and why North Korean hackers are using Windows Update Service to infect malware into people's PC's.
In this weeks episode, the cybersecurity experts, Bryan Hornung, Reginald Andre and Randy Bryan will get into some geo politics because there is a problem in the news boiling between Russia potential moving into Ukraine and taking some military action. Also, the team will discuss why this problem should raise some concerns in cybersecurity and what it could lead to. At the end of the show, the experts are going to talk on schools about how and why they are getting targeted more than ever!
In this weeks episode, the cybersecurity experts, Bryan Hornung, Reginald Andre, and Randy Bryan will discuss briefly on how law enforcement is now stepping in to take down these cybercriminals. Also, the team will go into great detail about where businesses are in the state of cybersecurity. Specifically, the crew will talk on this survey, 2021 Global Chief Technology Officer survey report by STX Next, which has some great information on where businesses were at at the end of 2021 and where they should be now!
In this weeks episode, the cybersecurity experts Bryan Hornung, Reginald Andre and Randy Bryan will discuss how hackers are mailing malicious USB flash drives to spread ransomware. Next, the team discusses how external hackers breahc 93% of organizations networks and gained access to their internal systems within two days. Then, the team goes over how many agencies were unable to patch Log4J because of EoL systems. Lastly, the experts discuss how American schools still remain vulnerable to cyberattacks.
In this week's episode the cyber security experts, Bryan Hornung, Reginald Andre, and Randy Bryan discuss cyber attacks that are happening now in 2022. Also, the team will briefly go over the myth of LastPass and why people should not save passwords within their browsers.
In this weeks episode, the cybersecurity experts Bryan Hornung, Reginald Andre & Randy Bryan discuss 10 of the biggest cyber and ransomware attacks of 2021- Colonial Pipeline, Brenntag, JBS, KIA, Ireland's Health Service Executive (HSE), CNA Financial, Quanta, Acer, Accenture, and Kaseya. The crew also talks about two ransomware attacks, the Shutterfly services that was disrupted by Conti and the natural gas supplier Superior Plus that is similar to the Colonial Pipeline attack.
In this weeks episode, the cybersecurity experts Bryan Hornung, Reginald Andre, and Randy Bryan talk about Kronos and how paychecks & bonuses will be delayed this holiday season for millions of workers around the world. Also, the team discusses the shortage with cream cheese and how that plays into cybersecurity. Meanwhile, the experts briefly look at the Log4J attack- what this attack chain is and could mean for the future.
In this weeks episode, the cybersecurity experts Bryan Hornung, Reginald Andre, and Randy Bryan discuss the importance of password managers. The team reviews seven different types of password managers - Bitwarden, Lastpass, 1Password, RoboForm, Nordpass, Keeper and Dashlane. Also, the group will discuss as to why you & your business would need them and which password manager is the best today.
In this weeks episode on the Security Squawk Podcast- cybersecurity experts Bryan Hornung, Reginald Andre, and Randy Bryan discuss predicitions around the different ransomware, cybersecurity & cyber attacks that might occur in 2022.
In this weeks episode, cybersecurity experts Bryan Hornung, Reginald Andre and Randy Bryan discuss ransomware attacks over the U.S. Thanksgiving Holiday. The team will go into how IKEA warns people of an email cyberattack. The experts will also go into detail about the vishing attack on a Robinhood employee.
On this weeks episode Cyber security experts Bryan Hornung and Randy Bryan discuss ransomware as a threat, even for the smallest of businesses - and why that is. In addition, the cyber experts will dive into how the U.S. government warns about ransomware attacks happening through the Thanksgiving holiday.
In this weeks episode cybersecurity experts Bryan Hornung, Reginald Andre, and Randy Bryan discuss a new Congressional report concluding that Ransomware hackers have the upper hand all the way through a ransomware attack - The cyber pros also discuss how the FBI was hacked and what happened.
In this week's episode the cybersecurity experts, Bryan Hornung - Randy Bryan - and Reginald Andre, discuss ransomware attacks against a major financial trading platform. The cyber experts will dive into the significant amount of ransomware attempts this year which was close to a billion. Next, the Security Squawk team will continue to dive into ways you can start protecting yourself from ransomware. These cyber experts will give you deeper insights into these issues and what it means for your business today.
In this week's episode the cybersecurity experts, Bryan Hornung - Randy Bryan - and Reginald Andre, discuss 10 different ways ransomware attackers pressure you into paying the ransom. These cyber experts will give you deeper insights into these issues and what it means for your business today.
In this week's episode the cybersecurity experts, Bryan Hornung - Randy Bryan - and Reginald Andre, discuss evolving ways cyber attackers are getting into peoples systems. These cyber criminals are using Social Engineering to trick people into installing malware onto their networks. Next, the team will dive into how cyber insurers delay ransomware payments. Lastly, the crew will dive into why and how the REvil group went offline. These cyber experts will give you deeper insights into these issues and what it means for your business today.
In this week's episode the cybersecurity experts, Bryan Hornung - Randy Bryan - and Reginald Andre, discuss recent news articles on different ransomware group incidents. The crew dives into the Sinclair Broadcast Group and how they were a victim in a ransomware attack. Next, the experts will dive into the BlackMatter Group and what they are up to today. The Security Squawk team will give you deeper insights to these issues and what it means for your business.
In this week's episode the cybersecurity experts, Bryan Hornung - Randy Bryan - and Reginald Andre, discuss popular Ransomware Targets - New U.S. Ransomware Laws - a new threat causing concern called I.T. deep fakes. The cybersecurity experts give you deeper insights to these issues and what it means for your business.
In this week's episode the cybersecurity experts, Bryan Hornung - Randy Bryan - and Reginald Andre, discuss some staggering statistics around how business owners treat and feel about cybersecurity. Plus the insurance industry is having a lot of trouble figuring out how to deal with ransomware and providing cyber insurance to businesses profitably. The cybersecurity experts give you deeper insights to these issues and what it means for your business.
In this week's episode the cybersecurity experts, Bryan Hornung - Randy Bryan - and Reginald Andre, discuss DDoS Attacks on VoIP Providers and the Port of Houston Ransomware attack. We also jump into Google Adwords Malware delivery and how people are being tricked into installing malware by clicking on certain Google search ads.
Cybersecurity experts Bryan Hornung, Reginald Andre, and Randy Bryan break down today's top cybersecurity stories to a level anyone can understand. This week the crew discusses the resurgence of the BlackMatter (or DarkSide) in another supply chain ransomware attack. Cybercriminals are demanding $5.9 Million dollars. The New Cooperative agricultural group hit by ransomware over the weekend appears to have claimed that the impact of the attack on the US public could be worse than the Colonial Pipeline incident. We discuss this and some other topics on The Business of Cybersecurity - Security Squawk Podcast Live! - Episode 39
In this episode, Cybersecurity experts Bryan Hornung and Reginald Andre discuss yet another Microsoft Windows vulnerability that causes hackers to take over a system even if the user doesn't have administrative rights. This left I.T. professionals scrambling to apply for a workaround and left businesses security flapping in the wind. Next, the team looks at a recent cyber attack against a California hospital and leaked medical records on the dark web. Listen to the podcast and get educated and aware of the cyber security threats that exist today. Finally, REvil has reared their heads once again and the security community isn't sure what to make of it yet. FInd out what this could mean and what REvils next moves might be.
Security Squawk - Episode 38 - with Bryan Hornung, Reginald Andre & Randy Bryan - This is a business podcast with a cybersecurity twist. Security Squawk podcast is dedicated to providing CEOs and business owners with insights around trending cybersecurity topics and how they affect you and your business.
In this episode Cybersecurity experts, Bryan Hornung and Reginald Andre discuss a recent news article written in the insurance industry about Cyber insurance. The crew dives into what the insurance industry is saying about cyber insurance and what the future could look like. Next, the cyber experts dive into some interesting stats surrounding the Dark web and ransomware group and their recruiting practices. We break all this down into language you can understand and how it will impact you in the coming months.
Security Squawk - Episode 37 - with Bryan Hornung, Reginald Andre & Randy Bryan - This is a business podcast with a cybersecurity twist. Security Squawk podcast is dedicated to providing CEOs and business owners with insights around trending cybersecurity topics and how they affect you and your business.
Cybersecurity experts Bryan Hornung, Reginald Andre, and Randy Bryan discuss a news bulletin released by the FBI that outlines what Bad Cybersecurity practices look like. We look at that bulletin and give you our thoughts. Plus Hurricane Ida ripped through the U.S. leaving devastation in it's wake. The Security Squawk team discusses how a disaster recovery plan comes into play here, and why it matters for more than just cyber attacks.
Security Squawk - Episode 36 - with Bryan Hornung, Reginald Andre & Randy Bryan - This is a business podcast with a cybersecurity twist. Security Squawk podcast is dedicated to providing CEOs and business owners with insights around trending cybersecurity topics and how they affect you and your business.
Azure Breach - T-Mobile - U.S. Dept. of State Security - Squawk Podcast Live Recording - Episode 35
Cybersecurity experts Bryan Hornung, Reginald Andre, and Randy Bryan dive into some recent cyber attacks and ransomware attacks to highlight that things are still happening even though mainstream media isn't covering it. We discuss the ransomware attacks on a town in Italy where COVID vaccine distribution is being impacted. We also dive into another attack on a Florida government entity and we look at the resurfacing of the cybercriminal group DarkSide. Finally, we wrap up the show with 5 misconceptions we hear commonly from business leaders about cybersecurity.
Security Squawk - Episode 34 - with Bryan Hornung, Reginald Andre & Randy Bryan - This is a business podcast with a cybersecurity twist. Security Squawk podcast is dedicated to providing CEOs and business owners with insights around trending cybersecurity topics and how they affect you and your business.
Cybersecurity experts Bryan Hornung, Reginald Andre, and Randy Bryan dive into some recent cyber attacks and ransomware attacks to highlight that things are still happening even though mainstream media isn't covering it. We discuss the ransomware attacks on a town in Italy where COVID vaccine distribution is being impacted. We also dive into another attack on a Florida government entity and we look at the resurfacing of the cybercriminal group DarkSide. Finally, we wrap up the show with 5 misconceptions we hear commonly from business leaders about cybersecurity.
Security Squawk - Episode 33 - with Bryan Hornung, Reginald Andre & Randy Bryan - This is a business podcast with a cybersecurity twist. Security Squawk podcast is dedicated to providing CEOs and business owners with insights around trending cybersecurity topics and how they affect you and your business.
Cybersecurity experts Bryan Hornung, Reginald Andre, and Randy Bryan dive into the newly released government Web site StopRansomware.gov. The team looks at what the is, who it's for, and we determine whether we think it's a valuable tool for the public and private industry to use to combat cybercriminals and ransomware.
Security Squawk - Episode 32 - with Bryan Hornung, Reginald Andre & Randy Bryan - This is a business podcast with a cybersecurity twist. Security Squawk podcast is dedicated to providing CEOs and business owners with insights around trending cybersecurity topics and how they affect you and your business.
Ransomware has cooled in the mainstream media cycles, but they are still happening every day. Bryan Hornung, Reginald Andre, and Randy Bryan dive into some ransomware attacks that happened against a prominent U.S. law firm, a dermatology clinic, Mint Mobile, and disclosure of a cyber attack against popular fashion brand Guess.
Security Squawk - Episode 31 - with Bryan Hornung, Reginald Andre & Randy Bryan - This is a business podcast with a cybersecurity twist. Security Squawk podcast is dedicated to providing CEOs and business owners with insights around trending cybersecurity topics and how they affect you and your business.
The boys give a brief update on the Kaseya cyberattack response, the phone call Biden made to Putin and the mysterious disappearance of REvil. Then they dive into some data posted by CISA on the top techniques hackers are successful at using. The experts look at those techniques and give advice on what you can do to make sure your network isn't exploited by a hacker who uses one of these popular techniques.
Security Squawk - Episode 30 - with Bryan Hornung, Reginald Andre & Randy Bryan - This is a business podcast with a cybersecurity twist. Security Squawk podcast is dedicated to providing CEOs and business owners with insights around trending cybersecurity topics and how they affect you and your business.
We hate it when we are right, but on the podcast this week we discuss the fallout from the Kaseya VSA hack. Learn what happened and how over 1500 businesses were impacted by ransomware because of a flaw in the Kaseya VSA software. We also discuss what businesses can do to overcome supply chain cyber attacks like this.
Security Squawk - Episode 29 - with Bryan Hornung, Reginald Andre & Randy Bryan - This is a business podcast with a cybersecurity twist. Security Squawk podcast is dedicated to providing CEOs and business owners with insights around trending cybersecurity topics and how they affect you and your business.
So the trio this week discusses what the U.S. government is attempting to do to help with the increasing threats of cyber attacks on businesses. There are several proposals on the table from various government officials and the crew looks at those. Durin g the discussion, Bryan casually predicts a major cyber attack over the 4th of July holiday - and of course, we have the largest ransomware attack to date with the Kaseys VSA hack.
Security Squawk - Episode 28 - with Bryan Hornung, Reginald Andre & Randy Bryan - This is a business podcast with a cybersecurity twist. Security Squawk podcast is dedicated to providing CEOs and business owners with insights around trending cybersecurity topics and how they affect you and your business.
Security Squawk - Episode 27 - with Bryan Hornung, Reginald Andre & Randy Bryan - This is a business podcast with a cybersecurity twist. Security Squawk podcast is dedicated to providing CEOs and business owners with insights around trending cybersecurity topics and how they affect you and your business.
In this episode, Bryan, Reginald, and Randy discuss the paper trail that exists when cyber attacks go down. Once the attack is out of the headlines and the heat has been turned down, the real evidence comes out. The evidence that comes out months after an attack is far more detrimental to companies and CEOs than the first few days or weeks. We take a look at a few different scenarios where this happened and we look at some ransomware attacks that are underway right now at Wolfe Eye Clinic and St. Joseph's/Candler hospital The Security Squawk crew shares their thoughts on how those attacks will end up.
Security Squawk - Episode 26 - with Bryan Hornung, Reginald Andre & Randy Bryan - This is a business podcast with a cybersecurity twist. Security Squawk podcast is dedicated to providing CEOs and business owners with insights around trending cybersecurity topics and how they affect you and your business.
This week Bryan Hornung & Randy Bryan discuss where cybersecurity is heading and how cybersecurity will become a personal responsibility for everyone. Just like how strapping on a seat belt before you drive off in a vehicle has become the common (and right) thing to do, protecting yourself from cyber criminals will also become a normal way of life.
Security Squawk - Episode 25 - with Bryan Hornung, Reginald Andre & Randy Bryan - This is a business podcast with a cybersecurity twist. Security Squawk podcast is dedicated to providing CEOs and business owners with insights around trending cybersecurity topics and how they affect you and your business.
Ransomware is wreaking havoc on businesses every day. It doesn't matter if you're large or small, the cybercriminals don't care. So can ransomware really be prevented? In this week's episode, we dive into that with Cryptostopper CEO Greg Edwards.
Security Squawk - Episode 24 - with Bryan Hornung, Reginald Andre, & Randy Bryan - This is a business podcast with a cybersecurity twist. Security Squawk podcast is dedicated to providing CEOs and business owners with insights around trending cybersecurity topics and how they affect you and your business.
Once again we see one of the largest and most important pieces of the U.S. food supply was taken offline due to a ransomware hack. The JBS meat producer is the latest victim of the REvil ransomware gang. Andre, Bryan, and Randy discuss what happened to JBS and how this could impact what you pay at the grocery store. We also talk about The White House memo directed at all U.S. businesses what it says, and will it really protect you from ransomware attacks.
If your a business owner, CEO, or just in charge of your company's security, you'll gain a lot of insight into what goes down in the midst of a ransomware hack.
Is The U.S. Government Cybersecurity Plan Good Enough? - Security Squawk - Episode 23
In this episode, cybersecurity experts Bryan Hornung and Reginald Andre discuss the recent Biden administration efforts to combat cybercriminals. From Biden's executive order to the language included in the infrastructure bill - Do the proposed measures go far enough? Too Far? We discuss and give our expert opinion on the proposed cybersecurity legislation.
Ransomware Payments On The Rise - CNA Insurance Doles Out $40 Million To Hackers - Security Squawk - Episode 22
IN this week's episode Bryan Hornung and Reginald Andre discuss the rise in ransomware payments. Not only are the frequency of ransomware attacks rising, so are the monetary demands of the cybercriminals behind these attacks. Learn what the average ransomware payment is going for in 2021 and why these cybercriminals are getting away with fleecing businesses for hundreds of thousands, if not millions.
Security Squawk - Episode 21 - with Bryan Hornung & Reginald Andre - This is a business podcast with a cybersecurity twist. Security Squawk podcast is dedicated to providing CEOs and business owners with insights around trending cybersecurity topics and how they affect you and your business.
One of the largest and most important pieces of the U.S. oil infrastructure was taken offline due to a ransomware hack. The Colonial Pipeline is the latest victim of the Dark Side ransomware gang. Andre and Bryan discuss what happened to Colonial Pipeline and how this could impact gas prices and the overall economy. We also talk about Dark Side and who they are, and why they are doing these types of attacks.
If your a business owner, CEO, or just in charge of your company's security, you'll gain a lot of insight into what goes down in the midst of a ransomware hack.
Security Squawk - Episode 20 - with Bryan Hornung & Reginald Andre - This is a business podcast with a cybersecurity twist. Security Squawk podcast is dedicated to providing CEOs and business owners with insights around trending cybersecurity topics and how they affect you and your business.
In this week's episode, we discuss why businesses struggle with cybersecurity. While there is a multitude of reasons for this we cover the ones we feel are most common. As a business owner, you may have experience with some of the things we discuss. IF yo haven't, you're certainly going to learn a lot about how you can vs. how you should handle your I.T. and cybersecurity.
In the talk, we walk you through how to overcome these technical challenges and what to look for on the way.
Security Squawk - Episode 19 - with Bryan Hornung & Reginald Andre - This is a business podcast with a cybersecurity twist. Security Squawk podcast is dedicated to providing CEOs and business owners with insights around trending cybersecurity topics and how they affect you and your business.
In this week's episode, we discuss a multitude of cyber attacks that occurred over the last week and what you can learn from them, and why these matter to you. We're also seeing the U.S. government begin to attempt to tackle the ransomware problem. Andre and Bryan discuss why it might be too late for the government to do anything effectively and how other government tech programs have gone and what we can learn from those rollouts.
Security Squawk - Episode 18 - with Bryan Hornung & Reginald Andre - This is a business podcast with a cybersecurity twist. Security Squawk podcast is dedicated to providing CEOs and business owners with insights around trending cybersecurity topics and how they affect you and your business.
In this week's episode, we discuss how Apple got caught up in a cyberattack that happened to one supplier. This is the perfect example of two things we discussed around cybersecurity all the time: supply chain attacks and multiple extortion attempts, AKA hacker greed. Andre & Bryan discuss the prevalence of the supply chain attack and how it can catch you by surprise if you aren't prepared for it. Listen to this podcast if you want to know how you can start gauging your partner's cybersecurity practices and if they present a risk to your business.
In this episode of Security Squawk - Episode 17 - Does your organization struggle with cybersecurity? Many businesses do. In today's Podcast, Andre & Bryan discuss why organizations should be focused more on Cyber Resilience than Cyber Security. What's the difference? We discuss that on this week's Podcast.
Many businesses have cyber insurance to protect their business in the event of a cyber attack. Many businesses don't know that you must do certain things for your claim not to be denied.
In this episode of Security Squawk - Episode 16 - we walk you through what happened over at CNA Insurance with their latest Ransomware attack, and while we go through that, we look at what you need to do to ensure your cyber insurance pays out.
Security Squawk - Episode 15 - with Bryan Hornung & Reginald Andre - This is a business podcast with a cybersecurity twist. Security Squawk podcast is dedicated to providing CEOs and business owners with insights around trending technology and cybersecurity topics and how they affect you and your business.
Getting rid of employees, clients, and vendors can be a tricky thing even when technology isn't involved. Throw technology in the mix and you get a whole new pandoras box to deal with, especially if you do not handle things properly.
Bryan & Andres talk about how to get rid of technology the right way. Wheter it employees, clients, vendors, or computer, cell phones, or LEB bulbs - how you "get rid of" these things can cause you trouble down the road - and we explain why in today's Security Squawk Podcast.
Security Squawk - Episode 14 - with Bryan Hornung & Reginald Andre - This is a business podcast with a cybersecurity twist. Security Squawk podcast is dedicated to providing CEOs and business owners with insights around trending technology and cybersecurity topics and how they affect you and your business.
So you got hacked? Now what? - OK so you didn't really get hacked, but let's pretend you did. What would you do? Do you even know? Who would you call? Where would you even start?
Learn what you should do the minutes following a cyber attack or ransomware event. The wrong decision could cost you dearly or could be the difference between if your business comes back, or shuts its doors.
Security Squawk - Episode 13 - with Bryan Hornung & Reginald Andre - This is a business podcast with a cybersecurity twist. Security Squawk podcast is dedicated to providing CEOs and business owners with insights around trending technology and cybersecurity topics and how they affect you and your business.
CEOs, have you ever wondered if you have good technology in your business? Do you wonder if the people you hired are really taking care of your security?
In this week's episode, we dive into what good I.T. support looks like and what it should achieve for your business. We discuss the misconceptions some business owners have about how they should handle I.T.
We also look at the differences between good I.T people and companies, vs. bad I.T. people and companies so you can figure out what you have going on in your business.
If your a CEO, CIO, IT manager it's critical you listen to this Podcast. Don't make the mistake of doing I.T. wrong in your organization.
Security Squawk - Episode 12 - with Bryan Hornung & Reginald Andre - This is a business podcast with a cybersecurity twist. Security Squawk podcast is dedicated to providing CEOs and business owners with insights around trending cybersecurity topics and how they affect you and your business.
If you hire or are thinking about hiring, anyone to handle the I.T. in your business please listen to this Podcast.
We cover the critical questions you need to ask before letting anyone touch your network or handle your cybersecurity. We give you the why behind these questions and why it matters to you and your business.
If your a CEO, CIO, IT manager it's critical you listen to this Podcast. Don't make the mistake of doing I.T. wrong in your organization.
Security Squawk - Episode 11 - with Bryan Hornung & Reginald Andre - This is a business podcast with a cybersecurity twist. Security Squawk podcast is dedicated to providing CEOs and business owners with insights around trending cybersecurity topics and how they affect you and your business.
This week we discuss the trending new app Clubhouse and our initial impressions of it. Are we entering a new realm of information distribution, and how much each individual must govern what they believe and who they believe for their information?
Bryan breaks down a YouTube video he watched between Network Chuck and John Hammond and how this discussion reminded him of Clubhouse and why people with a platform need to be more mindful of the words, opinions, and expressions they give.
Security Squawk - Episode 8 - with Bryan Hornung & Reginald Andre - This is a business podcast with a cybersecurity twist. Security Squawk podcast is dedicated to providing CEOs and business owners with insights around trending cybersecurity topics and how they affect you and your business.
This week we discuss a hack attempt that failed and a hack attempt that didn't. We look at the differences these two businesses took when faced with a cyber-attack and what you can learn from these events. Third part cyber attacks are becoming increasingly popular. Find out what a third party or supply chain cyberattack is and how you can prevent yourself from becoming a victim of a cyberattack that isn't in your control.
Listen to this week's Podcast and share it with your friends!
Security Squawk - Episode 8 - with Bryan Hornung & Reginald Andre - This is a business podcast with a cybersecurity twist. Security Squawk podcast is dedicated to providing CEOs and business owners with insights around trending cybersecurity topics and how they affect you and your business.
In this week's episode, we discuss how COVID affects a company when the upper management has the virus - Why Sen. Mark Warren's request to have the FBI and Energy Department investigate the Florida water supply cyber incident is a complete waste of time and taxpayer dollars - More Supply Chain attacks as a medical imaging facility admits to having hackers on their network for 18 months due to "vulnerable" IT management software.
SO, get ready to get a punch in the face by a hacker. It's coming. We explain why, so give us a listen. It may soften the blow!!!
Security Squawk - Episode 8 - with Bryan Hornung & Reginald Andre - This is a business podcast with a cybersecurity twist. Security Squawk podcast is dedicated to providing CEOs and business owners with insights around trending cybersecurity topics and how they affect you and your business.
In this week's episode, we discuss the inner battle CEOs face when taking the day off - Why third-party cybersecurity assessments are critical and why you should be doing them regularly - More Supply Chain Fallout as a California based hospital is being sued as a result of a breach from a vendor they worked with - And Emote Hackers Taken Down by the United States Department of Justice and FBI.
Security Squawk - Episode 7 - Bryan Hornung & Reginald Andre's weekly business podcast with a cybersecurity twist.
This week Bryan & Andre talk about how backups won't stop the ransomware payment you will need to pay hackers. The post-SolarWinds attack is teaching us that we can't trust retail software like we used to.
We also discuss the Parler debacle and why it is a big deal contrary to what the Parler executives want you to believe. We also get into some good news that the latest round of PPP money allows for investment in Technology. Learn what it covers and what it doesn't, and how you can qualify for the money.
Security Squawk Podcast - Episode 6 with Bryan Hornung and Reginald Andre. This week we discuss more revelations about the SolarWinds cyber attack. The company released an eye-opening timeline of events, and we learn that the cybercriminals were in much earlier than originally thought.
Next, we discuss the cyber attack on a major player in the WiFi device game and what this can mean. We wrap up the show with how hackers are now combing through stolen data lifted during ransomware attacks and subsequently leaked on the dark Web. Now hackers are combing through that data to extort CEOs of even more money. Check out our podcast to get the details, and don't forget to share our podcast with your family and friends.
Security Squawk - Episode 4 - Bryan Hornung and Reginald Andre - In our first episode of 2021, we discuss the announcement that Microsoft & McAffee were forming a team to put an end to ransomware. Will it work? Can ransomware or viruses really ever be stopped?
We also discuss a recent article that discusses the U.S. Capitol protests that turned into a big fat mess. During that event, it has been reported that the trespassers have accessed the computer systems of U.S. federal employees who work in the U.S. Capitol building.
Finally, a quick update to the Orion SolarWinds hack. We've learned that SolarWinds outsource a significant part of the Orion platform to an Eastern European firm, JetSpeed. It has been reported that JetSPeed was compromised, and that is how the backdoor could have been inserted into the Orion software. Also, Microsoft confirms that hackers could access the private source code of some of their products. We discuss what that means and whether Microsoft could also be dealing with back door exploits of their own.
Security Squawk - Episode 4 - Bryan Hornung and Reginald Andre - Post-Christmas/Pre New Years update - Bryan's company bought a hard drive destruction device and give some advice n getting rid of old technology.
Office disruptions - how do you handle co-worker drive-bys- What are some strategies you can deploy to get back your time?
Amazon, who owns Ring, faces a slew of lawsuits from customers who feel Ring products led to them being hacked. We discuss what happened and why you should care if the devices in your home are secured.
While the world shines a spotlight on the Russian hacking on the U.S. Government & private business, they are also hard at work hacking countries outside of the United States.
A U.K. Hospital group was hacked, and celebrity plastic surgery photos are being held for ransom. We jump into the deal with the cybercriminal act and what this could mean for the victims and the hospital group.
Cyber insurance - will it exist in the future? Will ransomware payments continue to be covered? The writing is on the wall, with fewer carriers offering cyber insurance and increasing 20-50% rates in some industries. Many insurance companies say the product isn't profitable.
GoDaddy sent a Phishing test to its employees that stated employees were getting a bonus. Many fell for the "phish" and are upset. We get into the ethics of this and whether or not it's a tactic business should consider.
Security Squawk - Episode #3 - Bryan Hornung and Reginald Andre discuss the business of cybersecurity. An update on the SolarWinds hack. An update to lasts week's episode on working with the right I.T. company.
Outsourcing or hire? When is it good for business to consider hiring (and training) talent in-house vs. outsourcing various tasks to outside firms?
It's common for CEOs and business owners to hold on to tasks too long. Learn what the signs are and what we have done to break these productivity reducing habits.
Baltimore County Schools hack has led to students and employees becoming angry over the reported data leaks. We dive into what happened and how this can happen in any business.
On this week's episode of Security Squawk we talk about firing clients, what it means when you work with bad I.T. firms vs. good ones, and the SolarWinds Orion cyber attack.
In episode 1 of the Secuirty Squawk - Cybersecurity experts Bryan Hornung and Reginald Andre discuss the newest flavor of Ransomware called Egregor. We dive into Foxconn not paying the ransom and Smart homes being held for ransom.