Black Hills Information Security: Recent Episodes

Black Hills Information Security

Penetration testing for Fortune 50 companies since 2008.

View Details

00:00:00 - PreShow Banter™ — The Grey Times

00:04:33 - BHIS - Talkin’ Bout [infosec] News 2024-11-04

00:05:54 - Story # 1: Midnight Blizzard conducts large-scale spear-phishing campaign using RDP files

00:16:45 - Story # 2: Follow Up - 5 Things To Know On Delta’s Lawsuit Against CrowdStrike

00:17:43 - Story # 2b: CrowdStrike Sues Delta: 5 Key Takeaways

00:22:04 - Story # 3: Russian charged by U.S. for creating RedLine infostealer malware

00:22:59 - Story # 3b: How a series of opsec failures led US authorities to the alleged developer of the Redline password-stealing malware

00:28:09 - Story # 4: Fired Disney staffer accused of hacking menu to add profanity, wingdings, removes allergen info

00:30:02 - Story # 4b: ‘We strive to put humanity above all’: Disney drops arbitration demand over wrongful death lawsuit after woman died from fatal food allergy

00:37:10 - Story # 5: OCR Announces First Financial Penalty Under HIPAA Risk Analysis Enforcement Initiative

00:44:54 - Story # 6: Security researchers found a serious zero-click bug in Synology’s Photos app

00:50:10 - Story # 7: Inside a Firewall Vendor’s 5-Year War With the Chinese Hackers Hijacking Its Devices

00:52:21 - Story # 8: Microsoft wants $30 if you want to delay Windows 11 switch

01:00:03 - Story # 9: Colorado Secretary of State posted spreadsheet with voting system passwords

View Details

00:00:00 - PreShow Banter™ — Sarsaparilla

00:05:50 - BHIS - Talkin’ Bout [infosec] News 2024-10-28

00:06:46 - Story # 1: AWS, Azure auth keys found in Android and iOS apps used by millions

00:15:02 - Story # 2: Burning Zero Days: FortiJump FortiManager vulnerability used by nation state in espionage via MSPs

00:29:03 - Story # 3: Delta officially launches lawyers at $500M CrowdStrike problem

00:40:60 - Story # 4: New Rules for US National Security Agencies Balance AI’s Promise With Need to Protect Against Risks

00:46:25 - Story # 4b: CISA proposes new security requirements to protect govt, personal data

00:51:03 - Story # 5: Largest Retail Breach in History: 350 Million “Hot Topic” Customers’ Personal & Payment Data Exposed — As a Result of Infostealer Infection

00:55:35 - Story # 6: Throne’s toilet camera takes pictures of your poop

01:04:57 - A Community Support Moment - https://www.crisistextline.org

View Details

00:00:00 - PreShow Banter™ — Log Con

00:11:41 - BHIS - Talkin’ Bout [infosec] News 2024-10-21

00:12:51 - Story # 1: Internet Archive exposed again – this time through Zendesk

00:14:57 - Story # 1b: Hackers steal information from 31 million Internet Archive users

00:20:42 - Story # 2: Sophos buys Secureworks for $859 mln to beef up cybersecurity portfolio

00:24:21 - Story # 3: USDoD hacker behind National Public Data breach arrested in Brazil

00:27:12 - Story # 4: Debunking Hype: China Hasn’t Broken Military Encryption With Quantum

00:32:14 - Story # 5: Microsoft said it lost weeks of security logs for its customers’ cloud products

00:35:03 - Story # 6: Should We Chat, Too? FAQ

00:40:05 - Story # 7: More than two dozen countries have used internet outages to sway elections

00:43:50 - Story # 8: Pokemon dev Game Freak confirms breach after stolen data leaks online

00:46:32 - Story # 9: Hackers made robot vacuums randomly yell racial slurs

00:49:19 - Story # 9b: We hacked a robot vacuum — and could watch live through its camera

00:50:19 - Story # 10: The government is getting fed up with ransomware payments fueling endless cycle of cyberattacks

00:54:55 - Story # 11: Google’s Chrome Browser Starts Disabling uBlock Origin

01:01:00 - WWHF Recorvery

View Details

00:00:00 - PreShow Banter™ — Cast of Special Characters

00:06:37 - BHIS - Talkin’ Bout [infosec] News 2024-09-30

00:08:06 - Story # 1: CUPS flaws enable Linux remote code execution, but there’s a catch

00:23:40 - Story # 2: US Capitol Hit by Massive Dark Web Cyber Attack - Newsweek

00:27:40 - Story # 2b: ‘I’m a black NAZI!’: NC GOP nominee for governor made dozens of disturbing comments on porn forum

00:35:57 - Story # 3: NIST proposes barring some of the most nonsensical password rules

00:47:01 - Story # 3b: Why Two-Factor Authentication Is So Important - Teen Vogue

00:54:04 - Story # 4: Hacker plants false memories in ChatGPT to steal user data in perpetuity

01:00:42 - Story # 5: Millions of Vehicles Could Be Hacked and Tracked Thanks to a Simple Website Bug

01:02:54 - Story # 6: Massive E-Learning Platform Udemy Gave Teachers a Gen AI ‘Opt-Out Window’. It’s Already Over.

View Details

00:00 - PreShow Banter™ — Plane Talk

05:50 - BHIS - Talkin’ Bout [infosec] News 2024-09-23

06:16 - A SANS Difference Maker Award Finalist

09:47 - Story # 1: Pagers attack brings to life long-feared supply chain threat

24:08 - Story # 2: Recaptcha Phish - John Hammond

25:49 - Story # 2b: Clever ‘GitHub Scanner’ campaign abusing repos to push malware

30:05 - Story # 3: Lazarus Group Targets Developers in Fresh VMConnect Campaign

35:22 - Story # 4: LinkedIn Addresses User Data Collection for AI Training

37:40 - Story # 5: Disney ditching Slack after massive July data breach

41:42 - Story # 6: FTC exposes massive surveillance of kids, teens by social media giants

51:35 - Story # 7: Kaspersky deletes itself, installs UltraAV antivirus without warning

View Details

00:00 - PreShow Banter™ — Pour Over News

06:01 - BHIS - Talkin’ Bout [infosec] News 2024-09-16

07:14 - Story # 1: Fortinet confirms data breach after hacker claims to steal 440GB of files

15:37 - Story # 2: Snowflake slams ‘more MFA’ button again – months after Ticketmaster, Santander breaches

21:30 - Story # 3: Omnipresent AI cameras will ensure good behavior, says Larry Ellison

28:11 - Story # 4: Mastercard bolsters threat intelligence capabilities with $2.65 billion deal for Recorded Future

34:27 - Story # 5: Cyber insurance set for explosive growth

40:20 - Story # 6: 23andMe will pay $30 million to settle 2023 data breach lawsuit

45:25 - Story # 7: Google faces EU investigation over AI data compliance

50:35 - Story # 8: Rogue WHOIS server gives researcher superpowers no one should ever have

View Details

00:00 - Introduction

01:22 - The Scenario

02:50 - First Steps

03:48 - Endpoint Analysis Roll

04:22 - Logon Scripts Were installed

05:09 - I.R. Team Introductions

07:17 - Second Step

10:32 - Network Threat Hunting Roll

11:36 - Third Step

15:12 - Anyway Here’s Firewall Roll

15:43 - Fourth Step

18:26 - SIEM Roll

19:41 - Fifth Step

20:47 - UEBA Roll

21:19 - Senario Recap

22:20 - Senario Plausibility?

25:51 - Wrap-up Takeaways

View Details

00:00 - PreShow Banter™ — Revenge of the Nerds / More Chicken Related Crimes

05:19 - N.Y. Official Charged With Taking Money, Travel and Poultry to Aid China

09:23 - BHIS - Talkin’ Bout [infosec] News 2024-09-09

09:50 - Story # 1: YubiKeys are vulnerable to cloning attacks thanks to newly discovered side channel

20:35 - Story # 2: Therapy Sessions Exposed by Mental Health Care Firm’s Unsecured Database

25:24 - Story # 3: California legislature passes sweeping AI safety bill

38:02 - Story # 4: Brain Cipher claims attack on Olympic venue, promises 300 GB data leak

41:59 - Story # 5: How Navy chiefs conspired to get themselves illegal warship Wi-Fi

42:45 - Story # 5b: After seeing Wi-Fi network named “STINKY,” Navy found hidden Starlink dish on US warship

49:18 - Story # 6: Researchers say a bug let them add fake pilots to rosters used for TSA checks

51:32 - Story # 7: Durex India spilled customers’ private order data

54:53 - Story # 8: City of Columbus Sues Researcher Who Disclosed Impact of Ransomware Attack

View Details

00:00 - PreShow Banter™ — Move to Signal

03:47 - BHIS - Talkin’ Bout [infosec] News 2024-08-26

04:37 - Story # 1: Pavel Durov’s Arrest Leaves Telegram Hanging in the Balance

11:03 - Story # 1b: Moxie on X.com

23:17 - Story # 2: Unveiling “sedexp”: A Stealthy Linux Malware Exploiting udev Rules

29:39 - Story # 3: Seattle airport ‘possible cyberattack’ snarls travel yet again

32:42 - Story # 4: Iran named as source of Trump campaign phish, leaks

38:53 - Story # 5: Man who hacked Hawaii state registry to forge his own death certificate sentenced to 81 months

44:11 - Story # 6: Hardware Backdoor Discovered in RFID Cards Used in Hotels and Offices Worldwide

47:26 - Story # 7: New ‘ALBeast’ Misconfiguration Exposes Weakness in AWS Application Load Balancer

48:52 - Story # 8: “We will hold them accountable”: General Motors sued for selling customer driving data to third parties

View Details

00:00:00 - PreShow Banter™ — Nine Years for Chicken Wings

00:08:19 - BHIS - Talkin’ Bout [infosec] News 2024-08-19

00:09:03 - Story # 1: NationalPublicData.com Hack Exposes a Nation’s Data

00:18:17 - Story # 1b: National Public Data Published Its Own Passwords

00:25:01 - Story # 2: RansomHub Group Deploys New EDR-Killing Tool in Latest Cyber Attacks

00:26:52 - Story # 3: T-Mobile fined $60 million for failing to stop data breaches

00:34:03 - Story # 4: Massive Cyber Attack On AWS Targets 230 Million Unique Cloud Environments

00:45:43 - Story # 5: The US wants to use facial recognition to identify migrant children as they age

00:54:16 - Story # 6: Six ransomware gangs behind over 50% of 2024 attacks

00:59:56 - Story # 7: US accuses man of being ‘elite’ ransomware pioneer they’ve hunted for years

01:01:57 - Rinsed: From Cartels to Crypto: How the Tech Industry Washes Money for the World’s Deadliest Crooks

View Details

00:00 - PreShow Banter™ — Scotty’s Pizza (Not Sponsored)

03:38 - BHIS - Talkin’ Bout [infosec] News 2024-08-12

03:59 - Hacker Summer Camp Report 2024

08:56 - Story # 1: ‘Sinkclose’ Flaw in Hundreds of Millions of AMD Chips Allows Deep, Virtually Unfixable Infections

14:26 - Story # 2: Black Hat USA 2024, DEF CON 32 attendees treated like children – or criminals – with invasive hotel room checks

29:49 - Story # 3: DEF CON Badge Maker Pulled Off Stage Amid Claims of Non-Payment and Failed Work

30:06 - New raspberry pi chip in badge

33:31 - Story # 4: Exploit released for Cisco SSM bug allowing admin password changes

34:12 - Story # 5: 0.0.0.0 Day: Exploiting Localhost APIs From the Browser

38:02 - Story # 6: Intelligence bill would elevate ransomware to a terrorist threat

44:36 - Story # 6b: Proposed bill would block large ransomware payments by financial institutions

46:26 - Story # 6c: Report shows decreased ransomware payments

54:26 - Story # 7: After global IT meltdown, CrowdStrike courts hackers with action figures and gratitude

55:12 - Story # 8: CrowdStrike pursuing deal to buy patch management specialist Action1

57:24 - Story # 9: Microsoft punches back at Delta Air Lines and its legal threats

View Details

00:00 - PreShow Banter™ — What’s the f___

03:34 - BHIS - Talkin’ Bout [infosec] News 2024-08-05

06:57 - Story # 1: Proofpoint Email Routing Flaw Exploited to Send Millions of Spoofed Phishing Emails

23:57 - Story # 2: Bumble and Hinge allowed stalkers to pinpoint users’ locations down to 2 meters, researchers say

36:47 - Story # 3: Eavesdropping on HDMI cables can reveal computer screen’s content

37:43 - Story # 3b Hak5 Screen Crab

39:18 - Story # 4: Microsoft says massive Azure outage was caused by DDoS attack

43:31 - Story # 5: CrowdStrike says it’s not to blame for Delta’s days-long outage

55:34 - Story # 6: CrowdStrike sued by investors over massive global IT outage

View Details

00:00 - PreShow Banter™ — Microsoft Sad Face

02:13 - BHIS - Talkin’ Bout [infosec] News 2024-07-29

03:08 - Story # 1: Fake CrowdStrike repair manual pushes new infostealer malware

15:26 - Story # 1b: 83-year-old man found safe a week after going missing when CrowdStrike outage canceled flight

20:39 - Story # 2: Multifactor Authentication Is Not Enough to Protect Cloud Data

38:59 - Graphrunner

47:19 - Story # 3: Data pilfered from Pentagon IT supplier Leidos

57:57 - Story # 4: How a North Korean Fake IT Worker Tried to Infiltrate Us

View Details

00:00 - PreShow Banter™ — CrowdStroke Memes

05:59 - BHIS - Talkin’ Bout [infosec] News 2024-07-22

07:01 - Story # 1: A Windows version from 1992 is saving Southwest’s butt right now

07:36 - Crowdstrike Global Outage - BHIS - Talkin’ Bout [infosec] #News

09:48 - Story # 1b: CrowdStrike’s faulty update crashed 8.5 million Windows devices, says Microsoft

12:13 - Story # 1c: Let’s blame the dev who pressed “Deploy”

17:23 - Figure 1

22:14 - Story # 2: DHS Has a DoS Robot to Disable Internet of Things ‘Booby Traps’ Inside Homes

25:58 - Story # 3: Notorious Hacker Kingpin ‘Tank’ Is Finally Going to Prison

28:08 - Story # 4: UK Police Arrest Suspect in MGM Ransomware Attack

30:49 - Story # 5: Russians plead guilty to involvement in LockBit ransomware attacks

33:24 - Story # 6: DHS watchdog rebukes CISA and law enforcement training center for failing to protect data

38:32 - Story # 7: Yacht giant MarineMax data breach impacts over 123,000 people

40:38 - Story # 8: Sizable Chunk of SEC Charges Against SolarWinds Tossed Out of Court

47:14 - Story # 9: The US Supreme Court Kneecapped US Cyber Strategy

52:12 - Story # 10: War Thunder does it again, this time with classified documents relating to 3 Russian tanks

View Details

The outage of the decade!

View Details

00:00 - PreShow Banter™ — Absolute Madmen

02:28 - BHIS - Talkin’ Bout [infosec] News 2024-07-15

03:18 - Wi-Fi Forge

07:31 - Story # 1: CISA Red Team’s Operations Against a Federal Civilian Executive Branch Organization Highlights the Necessity of Defense-in-Depth

22:39 - Story # 2: AT&T says criminals stole phone records of ‘nearly all’ customers in new data breach

33:35 - Story # 3: FTC study finds ‘dark patterns’ used by a majority of subscription apps and websites

38:48 - Story # 4: Club Penguin fans breached Disney Confluence server, stole 2.5GB of data

41:52 - Story # 5: Heritage Foundation Exec Threatens ‘Gay Furry Hackers’ in Unhinged Texts

47:51 - Story # 6: German Navy to replace aging 8-inch floppy drives with an emulated solution for its anti-submarine frigates

50:14 - Story # 7: 1.4 GB NSA Data Leaked Online – Email Address, Phone Number & Gov Classified Data Exposed

53:56 - Story # 8: Hackers Claim to Have Leaked 1.1 TB of Disney Slack Messages

View Details

00:00 - PreShow Banter™ — A Bunch of Lunatics

05:09 - BHIS - Talkin’ Bout [infosec] News 2024-07-08

08:41 - Story # 1: Europol takes down 593 Cobalt Strike servers used by cybercriminals

09:54 - Story # 1b: National Crime Agency leads international operation to degrade illegal versions of Cobalt Strike

15:17 - Story # 2: ‘RockYou2024’: Nearly 10 billion passwords leaked online

22:12 - Story # 3: Ticketmaster Breach: ShinyHunters Leak 440K Taylor Swift Eras Tour Ticket Data

24:20 - Story # 3b: Hackers reverse-engineer Ticketmaster’s barcode system to unlock resales on other platforms

27:41 - Story # 4: US Supreme Court ruling will likely cause cyber regulation chaos

39:39 - Story # 5: California Advances Unique Safety Regulations for AI Companies Despite Tech Firm opposition

41:13 - Story # 5b: Senator Scott Wiener

43:45 - Story # 6: OpenAI Did Not Disclose 2023 Breach to Feds, Public: Report

53:10 - Story # 7: Microsoft’s Midnight Blizzard source code breach also impacted federal agencies

55:27 - Story # 8: Japan’s Government Finally Stops Using Floppy Disks

57:48 - Story # 9: This smart toilet paper monitor tells you when you need a new roll

58:50 - Story # 10: Twilio says hackers identified cell phone numbers of two-factor app Authy users

View Details

00:00 - PreShow Banter™ — Ice Cream Season

07:22 - BHIS - Talkin’ Bout [infosec] News 2024-07-01

07:48 - Story # 1: TeamViewer’s corporate network was breached in alleged APT hack

09:11 - Story # 1b: TeeamViewer Security Update – June 28, 2024, 12:10 PM CEST

16:33 - Story # 2: Supreme Court orders new look at Texas, Florida social media laws

21:32 - Story # 3: New OpenSSH Vulnerability Could Lead to RCE as Root on Linux Systems

24:52 - Story # 4: CISA: Most critical open source projects not using memory safe code

40:03 - Story # 5: Exploit for critical Fortra FileCatalyst Workflow SQLi flaw released

42:35 - Story # 6: South Korean telecom company attacks customers with malware — over 600,000 torrent users report missing files, strange folders, and disabled PCs

49:24 - Story # 7: Drone As First Responder Programs Are Swarming Across the United States

55:22 - GRC Rapid Fire

View Details

00:00 - PreShow Banter™ — Life is a Highway

04:28 - BHIS - Talkin’ Bout [infosec] News 2024-06-24

05:30 - Story # 1: Colorado Privacy Act Amended To Include Biometric Data Provisions

14:18 - Story # 2: Scathing report on Medibank cyberattack highlights unenforced MFA

24:30 - Story # 3: CDK suffered another data breach as it was attempting to recover

35:08 - Story # 4: LockBit claims the hack of the US Federal Reserve

40:00 - Story # 5: Amazon-Powered AI Cameras Used to Detect Emotions of Unwitting UK Train Passengers

45:36 - Story # 6: That PowerShell ‘fix’ for your root cert ‘problem’ is a malware loader in disguise

51:13 - Story # 7: US sanctions Kaspersky Lab executives, board members over ‘cooperation’ with Russia

53:23 - Story # 7b: Treasury Sanctions Kaspersky Lab Leadership in Response to Continued Cybersecurity Risks

View Details

00:00 - PreShow Banter™ — Hungry Hungry Hipaa

03:39 - BHIS - Talkin’ Bout [infosec] News 2024-06-17

05:40 - Story # 1: Windows security hole allows attackers to install malware via Wi-Fi — new patch plugs gaping vulnerability

16:27 - Story # 2: Microsoft’s all-knowing Recall AI feature is being delayed

25:34 - Story # 3: Here’s how Apple’s AI model tries to keep your data private

32:27 - Story # 4: New Linux malware is controlled through emojis sent from Discord

35:28 - Story # 5: Pure Storage confirms data breach after Snowflake account hack

38:44 - Story # 6: Microsoft Chose Profit Over Security and Left U.S. Government Vulnerable to Russian Hack, Whistleblower Says

View Details

00:00 - PreShow Banter™ — Louie is Live

04:53 - BHIS - Talkin’ Bout [infosec] News 2024-06-10

07:09 - Story # 1: UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion

18:39 - Story # 2: Stealing everything you’ve ever typed or viewed on your own Windows PC is now possible with two lines of code — inside the Copilot+ Recall disaster.

39:02 - Story # 3: TikTok fixes zero-day bug used to hijack high-profile accounts

41:34 - Story # 4: The Age of the Drone Police Is Here

52:07 - Story # 5: London hospitals declare emergency following ransomware attack

54:45 - Story # 6: Former Senior Executive and Former Sales Manager Convicted of Selling Data on Millions of U.S. Consumers to Perpetrators of Mail Fraud Schemes

56:40 - Story # 7: FBI Kicks Hackers In The Teeth With Free 7,000 Ransomware Key Giveaway

57:32 - Story # 8: FCC OKs pilot to bolster school, library cybersecurity

View Details

00:00:00 - PreShow Banter™ — In an RV down by the dumpster

00:07:39 - BHIS - Talkin’ Bout [infosec] News 2024-06-03

00:09:21 - Story # 1: Ticketmaster confirms massive breach after stolen data for sale online

00:10:46 - Story # 1b: Snowflake, Cloud Storage Giant, Suffers Massive Breach: Hacker Confirms to Hudson Rock Access Through Infostealer Infection

00:13:03 - Story # 1c: Detecting and Preventing Unauthorized User Access: Instructions

00:13:42 - Story # 1d: Snowflake Denies Responsibility for Ticketmaster, Santander Breaches

00:21:21 - Story # 2: Chinese hackers hide on military and govt networks for 6 years

00:29:17 - Story # 3: Federal agency warns critical Linux vulnerability being actively exploited

00:34:19 - Story # 4: US dismantles 911 S5 botnet used for cyberattacks, arrests admin

00:39:19 - Story # 4b: How the FBI’s fake cell phone company put criminals into real jail cells

00:43:48 - Story # 5: Exploit released for maximum severity Fortinet RCE bug, patch now

00:46:09 - Story # 6: Enforcement Alert: Drinking Water Systems to Address Cybersecurity Vulnerabilities

00:54:44 - Story # 6b: Hackers attempt to poison Florida city’s water supply near Super Bowl

01:03:32 - Story # 7: GPT-4o’s Chinese token-training data is polluted by spam and porn websites

View Details

00:00 - PreShow Banter™ — Antichafing Training.

04:31 - BHIS - Talkin’ Bout [infosec] News 2024-05-20

07:12 - Story # 1: Linux maintainers were infected for 2 years by SSH-dwelling backdoor with huge reach

29:49 - Story # 2: Palo Alto Networks is buying security assets from IBM to expand customer base

36:50 - Story # 3: Charges and Seizures Brought in Fraud Scheme Aimed at Denying Revenue for Workers Associated with North Korea

43:55 - Story # 4: FCC might require telecoms to report on securing internet’s BGP technology

52:45 - Story # 5: Slack under attack over sneaky AI training policy

View Details

00:00 - PreShow Banter™ — World Class RSA Cookies

04:49 - BHIS - Talkin’ Bout [infosec] News 2024-05-14

06:33 - Story # 1: Zscaler takes “test environment” offline after rumors of a breach

18:48 - Story # 2: Okta’s security chief on the company’s own cyberattack and how the ‘battleground’ has shifted

43:36 - Story # 3: Leaked FBI email stresses need for warrantless surveillance of Americans

48:46 - Story # 4: Despite big tech lobbying, Maryland passes two internet privacy bills

52:26 - Story # 4b: The Anxious Generation

53:46 - Story # 5:Hackers are now targeting the children of corporate executives in elaborate ransomware attacks

View Details

00:00 - PreShow Banter™ — RSA Power Moves

08:14 - BHIS - Talkin’ Bout [infosec] News 2024-05-06

09:49 - Story # 1: Shortridge Makes Sense of the 2024 Verizon DBIR

15:04 - Story # 2: A recent security incident involving Dropbox Sign

20:30 - Story # 3: Sandbox Escape Vulnerabilities in Judge0 Expose Systems to Complete Takeover

28:40 - Story # 4: Millions of Docker repos found pushing malware, phishing sites

32:53 - Story # 5: 1,400 GitLab Servers Impacted by Exploited Vulnerability

42:07 - Story # 6: LastPass goes independent over a year after serious breaches

50:16 - Cyber Security Basics for Muggles & Minions with Ashley and Chris

50:40 - Story # 7: Ukrainian REvil Hacker Sentenced to 13 Years and Ordered to Pay $16 Million

54:12 - Story # 8: Lockbit’s seized site comes alive to tease new police announcements

56:27 - Story # 9: Systemd v256 Introduces run0: A Safer Alternative to sudo

View Details

00:00 - BHIS - Talkin’ Bout [infosec] News 2024-04-29

02:33 - Story # 1: Cyber Hygiene Helps Organizations Mitigate Ransomware-Related Vulnerabilities

10:38 - Story # 2: ‘Admin’ and ‘12345’ banned from being used as passwords in UK crackdown on cyber attacks

16:34 - Story # 3: Maximum severity Flowmon bug has a public exploit, patch now

21:06 - Story # 3b: CVE-2024-2389: Command Injection Vulnerability In Progress Flowmon

22:45 - Story # 4:GitHub comments abused to push malware via Microsoft repo URLs

30:52 - Story # 5: Security bugs in popular phone-tracking app iSharing exposed users’ precise locations

36:47 - Story # 6: Biden signs bill criticized as “major expansion of warrantless surveillance”

49:38 - Story # 7: ChatGPT’s hallucinations draw EU privacy complaint

57:46 - Story # 8: Sweden’s liquor shelves to run empty this week due to ransomware attack

View Details

00:00 - PreShow Banter™ — A Parent Process

03:01 - BHIS - Talkin’ Bout [infosec] News 2024-04-22

04:13 - Story # 1: Exploit code for Palo Alto Networks zero-day now public

07:44 - Story # 1b: (Timeline) Zero-Day Exploitation of Unauthenticated Remote Code Execution Vulnerability in GlobalProtect (CVE-2024-3400)

23:22 - Story # 2: MGM says FTC can’t possibly probe its ransomware downfall – watchdog chief Lina Khan was a guest at the time

31:37 - Story # 3: MITRE was breached through Ivanti zero-day vulnerabilities

32:27 - Story # 4: Cisco Integrated Management Controller CLI Command Injection Vulnerability

41:20 - Story # 5: Cisco Duo’s Multifactor Authentication Service Breached

46:01 - Story # 6: DevSecOps security practices are doggone disastrous

54:57 - Story # 7: FYI: This site claims to have harvested 4B+ Discord chats, today all yours for a price

View Details

00:00 - PreShow Banter™ — Retro Actions

04:48 - BHIS - Talkin’ Bout [infosec] News 2024-04-15

07:05 - Story # 1: FCC to vote on net neutrality rules on April 25

18:52 - Story # 2: “All Your Secrets Are Belong To Us” — A Delinea Secret Server AuthN/AuthZ Bypass

23:40 - Story # 2b: Delinea has cloud security incident in Thycotic Secret Server gaff

28:23 - Story # 3: CISA Releases Malware Next-Gen Analysis System for Public Use

40:36 - Story # 4: Hacker Leaks 8.5M U.S. Environmental Protection Agency (EPA) Contact Data

45:55 - Story # 5: SoCal Man Arrested on Federal Charges Alleging He Schemed to Advertise and Sell ‘Hive’ Computer Intrusion Malware

View Details

00:00 - PreShow Banter™ — BHIS Bees Corp®

04:08 - The FUTURE IS…… Kickstarter

05:29 - BHIS - Talkin’ Bout [infosec] News 2024-04-08

06:03 - Story # 1: New draft bipartisan US federal privacy bill unveiled

11:03 - Story # 2: How To Opt Out Of GM Sharing Your Driving Data With Insurance Companies

13:04 - Story # 2b: Request a Consumer Disclosure Report

14:25 - Story # 3: Hackers Hijacked Notepad++ Plugin To Execute Malicious Code

29:19 - Story # 4: A Vigilante Hacker Took Down North Korea’s Internet. Now He’s Taking Off His Mask

46:15 - Story # 5: It’s Time to Hand Cybersecurity Over to the Computers

View Details

00:00 - PreShow Banter™ — Zippers, Jokes, & Lawyers (Not to be confused with the song "Lawyers, Guns and Money")

02:59 - BHIS - Talkin’ Bout [infosec] News 2024-04-01

03:57 - Story # 1: New Darcula phishing service targets iPhone users via iMessage

11:57 - Story # 2: Recent ‘MFA Bombing’ Attacks Targeting Apple Users

17:22 - Story # 3: Thousands of phones and routers swept into proxy service, unbeknownst to users

22:11 - Story # 4: Digital signs around Brookline are collecting data from your phone as you walk by

26:57 - Story # 5: Backdoor found in widely used Linux utility targets encrypted SSH connections

28:22 - Story # 5b: XZ Outbreak diagram

37:32 - Story # 6: Vans warns customers of data breach

40:00 - Story # 7: Worldwide Agenda Ransomware Wave Targets VMware ESXi Servers

50:32 - Story # 8: Criminals Are Weaponizing Child Abuse Imagery to Ban Discord Servers

56:41 - Story # 9: International car theft tool seized in Australia, sparking police warning

58:14 - Story # 9b: Investigation into electronic device at Utah high school raises larger concerns for police

View Details

00:00 - PreShow Banter™ — “Allegedly”

03:18 - BHIS - Talkin’ Bout [infosec] News 2024-03-25

08:00 - Story # 1: Cisco Completes Acquisition of Splunk

10:47 - Story # 2: General Motors Quits Sharing Driving Behavior With Data Brokers

15:27 - Story # 3: Ron DeSantis signs bill requiring parental consent for kids under 16 to hold social media accounts

24:34 - Story # 4: House passes bill to prevent the sale of personal data to foreign adversaries

28:19 - Story # 5: Unsaflok - vulnerability impacts over 3 million hotel doors

33:57 - Story # 6: Canada revisits decision to ban Flipper Zero

36:57 - Story # 7: Truck-to-truck worm could infect – and disrupt – entire US commercial fleet

42:59 - Story # 8: Cybercriminals Beta Test New Attack to Bypass AI Security

46:31 - Story # 9: Russians will no longer be able to access Microsoft cloud services, business intelligence tools

50:36 - Story # 10: New ‘Loop DoS’ Attack Impacts Hundreds of Thousands of Systems

55:05 - Story # 11: New surveillance video of man catching a flight without ticket

View Details

Brought to you by Antisyphon Training — https://www.antisyphontraining.com

00:00:00 - PreShow Banter™ — New Arms Again

00:03:24 - BHIS - Talkin’ Bout [infosec] News 2024-03-18

00:04:54 - Story # 1: NIST Releases Version 2.0 of Landmark Cybersecurity Framework

00:10:50 - Story # 2: The FCC has finally decreed that 25Mbps and 3Mbps are not ‘broadband’ speed

00:14:33 - Story # 3: Welcome to the 2024 Threat Detection Report

00:33:40 - Story # 4: NSA Releases Top Ten Cloud Security Mitigation Strategies

00:47:33 - Story # 5: US government agencies demand fixable ice cream machines

00:53:14 - Story # 6: Homeland Security is testing AI to help with immigration, trafficking investigations, and disaster relief

01:03:19 - Story # 7: Feds seize $1.4 million of tech support scam proceeds with the help of crypto firm

View Details

00:00 - PreShow Banter™ — Death to Clippy

05:18 - BHIS - Talkin’ Bout [infosec] News 2024-03-11 – Featuring Josh Mason

06:58 - Story # 1: Behind the doors of a Chinese hacking company, a sordid culture fueled by influence, alcohol, and sex

13:43 - Story # 2: Top US cybersecurity agency hacked and forced to take some systems offline

23:39 - Story # 3: Microsoft admits Russian state hack still not contained. ‘This has tremendous national security implications’

30:27 - Story # 4: FBI’s 2023 Internet Crime Report

38:18 - Story # 5: QNAP warns of critical auth bypass flaw in its NAS devices

50:42 - Story # 6: Automakers Are Sharing Consumers’ Driving Behavior With Insurance Companies

View Details

A weekly Podcast with BHIS and Friends. stories. We discuss notable Infosec, and infosec-adjacent news stories.

Brought to you by:

Black Hills Information Security

https://www.blackhillsinfosec.com/

Antisyphon Training

https://www.antisyphontraining.com/

Story # 1: Executive Order on Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern

https://www.whitehouse.gov/briefing-r...

Story # 2: A leaky database spilled 2FA codes for the world’s tech giants

https://techcrunch.com/2024/02/29/lea...

Story # 3: eBay, VMware, McAfee Sites Hijacked in Sprawling Phishing Operation

https://www.darkreading.com/applicati...

23:36 - LokiHakanin's related Post

/ sean-reilly-techopssec_8000-domains-of-tru...

Story # 4: Ivanti Connect Secure hackers hide in plain sight, evading protections

https://www.cybersecuritydive.com/new...

Story # 5: Over 100,000 Infected Repos Found on GitHub

https://apiiro.com/blog/malicious-cod...

Story # 6: Hackers backed by Russia and China are infecting SOHO routers like yours, FBI warns

https://arstechnica.com/security/2024...

View Details

Story #1: Mr. Cooper leak exposes over two million customers

Story #2: ConnectWise ScreenConnect attacks deliver malware

Story #3: LockBit Infrastructure Seized by US, UK Police

Story #4: US health tech giant Change Healthcare hit by cyberattack

Story #5: The reported leak of Chinese hacking documents supports experts’ warnings about how compromised the US could be

View Details

The post Talkin’ About Infosec News – 2/20/24 appeared first on Black Hills Information Security.

View Details

The post Talkin’ About Infosec News – 2/14/2024 appeared first on Black Hills Information Security.

View Details

The post Talkin’ About Infosec News – 2/6/24 appeared first on Black Hills Information Security.

View Details

The post Talkin’ About Infosec News – 1/31/2024 appeared first on Black Hills Information Security.

View Details

The post Talkin’ About Infosec News – 1/24/2024 appeared first on Black Hills Information Security.

View Details

The post Talkin’ About Infosec News – 1/16/2024 appeared first on Black Hills Information Security.

View Details

The post Talkin’ About Infosec News – 1/10/24 appeared first on Black Hills Information Security.

View Details

The post Talkin’ About Infosec News – 12/21/2023 appeared first on Black Hills Information Security.

View Details

https://youtu.be/MaThvw_VWJ8 Brought to you by Antisyphon Training https://www.antisyphontraining.com

View Details

The post Talkin’ About Infosec News – 12/06/2023 appeared first on Black Hills Information Security.

View Details

The post Talkin’ About Infosec News – 11/30/2023 appeared first on Black Hills Information Security.

View Details

Brought to you by Antisyphon Training — https://www.antisyphontraining.com

The post Talkin’ About Infosec News – 8/28/2023 appeared first on Black Hills Information Security.

View Details

Brought to you by Antisyphon Training — https://www.antisyphontraining.com

View Details

🔵Join us for the Antisyphon Blue Team Summit! https://www.antisyphontraining.com/training/blue-team/2023/06/blue-team-summit-coming-in-august-2023/ Blue Team Summit Coming in August 2023! – Antisyphon Training

View Details

A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories. Brought to you by: /// 📄 Antisyphon Training August 2023 Blue Team Summit: https://www.antisyphontraining.com/training/blue-team/2023/06/blue-team-summit-coming-in-august-2023/ /// 📄 […]

View Details

00:00 – PreShow Banter™ — Tossing Money at Problems00:58 – BHIS – Talkin’ Bout [infosec] News 2023-03-1301:41 – Story # 1: Silicon Valley Bank collapse: Treasury, Fed, and FDIC announce […]

The post Talkin’ About Infosec News – 3/16/2023 appeared first on Black Hills Information Security.

View Details

00:00 – PreShow Banter™ — Lil NAS06:52 – BHIS – Talkin’ Bout [infosec] News 2023-03-0608:13 – Story # 1: LastPass says employee’s home computer was hacked and corporate vault takenhttps://arstechnica.com/information-technology/2023/02/lastpass-hackers-infected-employees-home-computer-and-stole-corporate-vault/28:32 […]

The post Talkin’ About Infosec News – 3/8/2023 appeared first on Black Hills Information Security.

View Details

Story # 1: A Basic iPhone Feature Helps Criminals Steal Your Entire Digital Lifehttps://www.wsj.com/articles/apple-iphone-security-theft-passcode-data-privacya-basic-iphone-feature-helps-criminals-steal-your-digital-life-cbf14b1a Story # 1b: Apple’s iPhone Passcode Problem: Thieves Can Ruin Your Entire Digital Life in Minutes […]

The post Talkin’ About Infosec News – 3/3/2023 appeared first on Black Hills Information Security.

View Details

00:00 – PreShow Banter™ — Pop Tart Pizza04:15 – BHIS – Talkin’ Bout [infosec] News 2023-02-2005:39 – Story # 1: Employee data from a major cybersecurity firm posted for sale […]

The post Talkin’ About Infosec News – 2/22/2023 appeared first on Black Hills Information Security.

View Details

00:00 – PreShow Banter™ — Scalping Valentine’s Day Reservations04:13 – BHIS – Talkin’ Bout [infosec] News 2023-06-2305:52 – Story # 1: 5 Chinese companies and a research institute blacklisted by […]

The post Talkin’ About Infosec News – 2/17/2023 appeared first on Black Hills Information Security.

View Details

00:00 – PreShow Banter™ — Woke Up Like This03:20 – BHIS – Talkin’ Bout [infosec] News 2023-01-3005:04 – Story # 1: GoTo says hackers stole customers’ backups and encryption keyhttps://www.bleepingcomputer.com/news/security/goto-says-hackers-stole-customers-backups-and-encryption-key/09:48 […]

The post Talkin’ About Infosec News – 2/3/2023 appeared first on Black Hills Information Security.

View Details

00:00 – PreShow Banter™ — Wade’s Googly Eyes00:41 – BHIS – Talkin’ Bout [infosec] News 2023-01-2301:26 – Story # 1: BIG TECH LAYOFFS. LAYOFFS! DOOM! RECESSION!

The post Talkin’ About Infosec News – 1/25/2023 appeared first on Black Hills Information Security.

View Details

00:00 – PreShow Banter™ — Ralph’s Guide to Satellite Bands 04:33 – BHIS – Talkin’ Bout [infosec] News 2023-01-16 05:25 – Story # 1: Microsoft’s new AI can simulate anyone’s […]

The post Talkin’ About Infosec News – 1/17/2023 appeared first on Black Hills Information Security.

View Details

00:00 – PreShow Banter™ — Twitch Airways International00:59 – BHIS – Talkin’ Bout [infosec] News 2023-01-1003:56 – Story # 1: How ChatGPT could become a hacker’s friendhttps://betanews.com/2023/01/05/how-chatgpt-could-become-a-hackers-friend/14:05 – Story # […]

The post Talkin’ About Infosec News – 1/12/2023 appeared first on Black Hills Information Security.

View Details

00:00 – PreShow Banter™ — Seven People00:51 – BHIS – Talkin’ Bout [infosec] News 2023-01-0201:37 – Story # 1: LastPass Admits to Severe Data Breach, Encrypted Password Vaults Stolenhttps://www.theverge.com/2022/12/28/23529547/lastpass-vault-breach-disclosure-encryption-cybersecurity-rebuttal32:22 – […]

The post Talkin’ About Infosec News – 1/3/2023 appeared first on Black Hills Information Security.

View Details

00:00 – PreShow Banter™ — Talkin’ Bout [Elon] News00:51 – BHIS – Talkin’ Bout [infosec] News 2022-12-1902:46 – Story # 1: Antivirus and EDR solutions tricked into acting as data […]

The post Talkin’ About Infosec News – 12/21/2022 appeared first on Black Hills Information Security.

View Details

00:00 – PreShow Banter™ — Scissors Vs Paper00:15 – BHIS – Talkin’ Bout [infosec] News 2022-12-1202:12 – Story # 1: Rackspace confirms ransomware attack behind days-long email meltdownhttps://www.theregister.com/2022/12/06/rackspace\_confirms\_ransomware/07:56 – Story […]

The post Talkin’ About Infosec News – 12/15/2022 appeared first on Black Hills Information Security.

View Details

00:00 – PreShow Banter™ — Florida Bobsledding Team01:29 – PreShow Banter™ — Open AI Phishing Campaign05:17 – BHIS – Talkin’ Bout [infosec] News 2022-12-0507:53 – Story # 1: There are […]

The post Talkin’ About Infosec News – 12/6/2022 appeared first on Black Hills Information Security.

View Details

00:00 – PreShow Banter™ — Inflatable Turkey00:15 – BHIS – Talkin’ Bout [infosec] News 2022-11-2802:34 – Story # 1: Musk recruits engineers for “Twitter 2.0”https://arstechnica.com/tech-policy/2022/11/musk-recruits-engineers-for-twitter-2-0-after-mass-layoffs-and-resignations/06:28 – Story # 2: Security […]

The post Talkin’ About Infosec News – 11/30/2022 appeared first on Black Hills Information Security.

View Details

00:00 – BHIS – Talkin’ Bout [infosec] News 2022-11-1402:26 – Story # 1: Hackers Dump Australian Health Records Online After Insurer Refuses to Pay Ransom– https://gizmodo.com/hackers-health-info-online-medibank-pay-onion-dark-web-184976074210:04 – Story # 2: TransUnion […]

The post Talkin’ About Infosec News – 11/16/2022 appeared first on Black Hills Information Security.

View Details

00:00 – PreShow Banter™ — A is for All Team00:33 – BHIS – Talkin’ Bout [infosec] News 2022-11-0703:56 – Story # 1: Musk to cut half of Twitter jobs and […]

The post Talkin’ About Infosec News – 11/11/2022 appeared first on Black Hills Information Security.

View Details

00:00 – PreShow Banter™ — Spook Show00:58 – BHIS – Talkin’ Bout [infosec] News 2022-10-3104:00 – Story # 1: OpenSSL warns of critical security vulnerability with upcoming patch– https://www.zdnet.com/article/openssl-warns-of-critical-security-vulnerability-with-upcoming-patch/04:42 – Story […]

The post Talkin’ About Infosec News – 11/1/2022 appeared first on Black Hills Information Security.

View Details

00:00 – PreShow Banter™ — Best WWHF Ever!00:31 – BHIS – Talkin’ Bout [infosec] News 2022-10-1704:55 – Story # 1: The Verge: Cybersecurity Week 2022– https://www.theverge.com/23365380/cybersecurity-week-series-phishing-encryption-device-security07:02 – Story # 2: Google […]

The post Talkin’ About Infosec News – 10/17/2022 appeared first on Black Hills Information Security.

View Details

00:00 – PreShow Banter™ — Dumpster Fire Friends03:07 – PreShow Banter™ — WHHF Deadwood – https://wildwesthackinfest.com/deadwood/ 03:48 – BHIS – Talkin’ Bout [infosec] News 2022-10-0307:37 – Story # 1: High-severity […]

The post Talkin’ About Infosec News – 10/17/2022 appeared first on Black Hills Information Security.

View Details

02:28 – Story # 1: American Airlines Breach Exposes Customer and Staff Information– https://www.infosecurity-magazine.com/news/american-airlines-breach-customer/18:59 – Story # 2: London police arrest, charge teen hacking suspect but won’t confirm GTA 6, Uber […]

The post Talkin’ About Infosec News – 10/5/2022 appeared first on Black Hills Information Security.

View Details

The post Talkin’ About Infosec News – 9/22/2022 appeared first on Black Hills Information Security.

View Details

The post Talkin’ About Infosec News – 9/13/2022 appeared first on Black Hills Information Security.

View Details

The post Talkin’ About Infosec News – 9/9/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON AUGUST 22, 2022 00:00 – PreShow Banter™ — Ralph’s Birthday00:53 – BHIS – Talkin’ Bout [infosec] News 2022-08-2203:27 – Story # 1: PC store told it can’t […]

The post Talkin’ About Infosec News – 8/26/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON AUGUST 15, 2022 Articles discussed in this episode: 00:00 – PreShow Banter™ — Sneaking Candy03:32 – BHIS – Talkin’ Bout [infosec] News 2022-08-1507:06 – Story # 1: […]

The post Talkin’ About Infosec News – 8/18/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON JULY 25, 2022 Articles discussed in this episode: 00:00 – BHIS – Talkin’ Bout [infosec] News 2022-07-25 03:59 – Story # 1: DOJ seized ransoms paid by […]

The post Talkin’ About Infosec News – 8/1/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON JULY 18, 2022 Articles discussed in this episode: 00:00 – PreShow Banter™ — Talkin’ Bout Audio 07:23 – BHIS – Talkin’ Bout [infosec] News 2022-07-18 09:28 – […]

The post Talkin’ About Infosec News – 7/18/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON JULY 11, 2022 Articles discussed in this episode: 00:00 – PreShow Banter™ — Cons, China, and Florida Man, oh my! 07:03 – Story # 1: North Korean […]

The post Talkin’ About Infosec News – 7/11/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON JUNE 27, 2022 Articles discussed in this episode: 02:13 – Story # 1: The #1 Period Tracker on the App Store Will Hand Over Data Without a […]

The post Talkin’ About Infosec News – 6/27/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON JUNE 20, 2022 Articles discussed in this episode: 00:00 – BHIS – Talkin’ Bout [infosec] News 2022-06-20 01:31 – Story # 1: Internal TikTok Meetings Shows That […]

The post Talkin’ About Infosec News – 6/20/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON JUNE 13, 2022 Articles discussed in this episode: 00:00 – BHIS – Talkin’ Bout [infosec] News 2022-06-13 02:26 – Story # 1: Roblox Game Pass store used […]

The post Talkin’ About Infosec News – 6/13/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON JUNE 6, 2022 Articles discussed in this episode: 00:00 – PreShow Banter™ — Boat Facts 01:38 – BHIS – Talkin’ Bout [infosec] News 2022-06-06 03:51 – Story […]

The post Talkin’ About Infosec News – 6/6/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON MAY 23, 2022 Articles discussed in this episode: 00:00 – BHIS – Talkin’ Bout [infosec] News 2022-05-23 02:38 – Story # 1 – National bank trolls hackers with dick pics – https://www.bleepingcomputer.com/news/security/national-bank-hit-by-ransomware-trolls-hackers-with-dick-pics/ 06:59 – Story # 2 – Ransomware attack exposes data of 500,000 Chicago students – https://www.bleepingcomputer.com/news/security/ransomware-attack-exposes-data-of-500-000-chicago-students/ 14:09 – Story # […]

The post Talkin’ About Infosec News – 5/23/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON MAY 16, 2022 Articles discussed in this episode: 00:56 – Microsoft’s May Patch Tuesday Updates Cause Windows AD Authentication Errors – https://threatpost.com/microsofts-may-patch-tuesday-updates-cause-windows-ad-authentication-errors/179631/ 08:56 – Update rings for Windows 10 and later policy in Intune – https://docs.microsoft.com/en-us/mem/intune/protect/windows-10-update-rings 09:06 – Infosec Weather Report With Bud Patches – 12:26 – FBI, CISA, and NSA warn […]

The post Talkin’ About Infosec News – 5/16/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON MAY 9, 2022 Articles discussed in this episode: 00:00 – Bud Patches Reporting 02:27 – BHIS – Talkin’ Bout [infosec] News 2022-05-09 03:47 – Story # 1 – CISA Shields Up – https://www.cisa.gov/shields-up 09:44 – Story # 2 – Critical BIG-IP Remote Code Execution Vulnerability – https://thehackernews.com/2022/05/f5-warns-of-new-critical-big-ip-remote.html 29:25 – Story # 3 […]

The post Talkin’ About Infosec News – 5/9/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON APRIL 25, 2022 Articles discussed in this episode: 00:00 – PreShow Banter™ — Broken Twitter Finger 01:38 – ISO – Talkin’ Bout [infosec] News 2022-04-26 03:08 – Elon Buys Twitter 09:27 – Leaked Chats Show LAPSUS$ Stole T-Mobile Source Code – https://krebsonsecurity.com/2022/04/leaked-chats-show-lapsus-stole-t-mobile-source-code/ 15:48 – Threat actors exploited more zero-day vulnerabilities in 2021 […]

The post Talkin’ About Infosec News – 4/25/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON APRIL 18, 2022 Articles discussed in this episode: 00:00 – BHIS – Talkin’ Bout [infosec] News 2022-04-18 02:05 – Current Activity | CISA | https://www.cisa.gov/uscert/ncas/current-activity 02:58 – CISA orders agencies to fix actively exploited VMware, Chrome bugs | https://www.bleepingcomputer.com/news/security/cisa-orders-agencies-to-fix-actively-exploited-vmware-chrome-bugs/ 08:45 – Russian invasion of Ukraine exposes cybersecurity threat to commercial satellites | […]

The post Talkin’ About Infosec News – 4/25/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON APRIL 11, 2022 Articles discussed in this episode: The US Navy had cybersecurity wrong. Expect change. – https://www.c4isrnet.com/digital-show-dailies/navy-league/2022/04/05/us-navy-had-cybersecurity-wrong-expect-change/ Hackers have found a clever new way to steal your Microsoft 365 credentials. – https://www.techradar.com/news/hackers-have-found-a-clever-new-way-to-steal-your-microsoft-365-credentials Exclusive: Senior EU officials were targeted with Israeli spyware. – https://www.reuters.com/technology/exclusive-senior-eu-officials-were-targeted-with-israeli-spyware-sources-2022-04-11/ Snap-on discloses data breach claimed by Conti ransomware […]

The post Talkin’ About Infosec News – 4/12/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON APRIL 4, 2022 Articles discussed in this episode: 00:00 – PreShow Banter™ — Blame it on the Intern 06:24 – Spring Time for Java – https://www.darkreading.com/application-security/zero-day-vulnerability-discovered-in-java-spring-framework 09:10 – GitLab for Account Access – https://www.bleepingcomputer.com/news/security/critical-gitlab-vulnerability-lets-attackers-take-over-accounts/ 10:33 – No Passwords for Okta – https://www.bleepingcomputer.com/news/security/sitel-on-okta-breach-spreadsheet-did-not-contain-passwords/ 11:11 – Legacy Networks for Okta – https://therecord.media/sitel-blames-okta-breach-on-legacy-network-from-acquisition/ 12:40 – […]

The post Talkin’ About Infosec News – 4/6/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON MARCH 28, 2022 Articles discussed in this episode: 01:42 – Suspected Okta hackers arrested by British police – https://www.reuters.com/world/uk/british-police-say-seven-people-arrested-after-okta-hack-2022-03-24/ 11:16 – A Closer Look at the LAPSUS$ Data Extortion Group – https://krebsonsecurity.com/2022/03/a-closer-look-at-the-lapsus-data-extortion-group/ 14:04 – Anonymous Starts ‘Huge’ Data Dump That Will ‘Blow Russia Away,’ Leaks Rostproekt Emails – https://www.ibtimes.com/anonymous-starts-huge-data-dump-will-blow-russia-away-leaks-rostproekt-emails-3452789 22:28 – Most […]

The post Talkin’ About Infosec News – 3/31/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON MARCH 22, 2022 Articles discussed in this episode: 00:00 – BHIS – 2022-03-22 Special Newscast –Okta and Microsoft — Everything’s not burning down 10:27 – https://github.com/SigmaHQ/sigma/tree/master/rules/cloud/okta 13:29 – https://github.com/elastic/detection-rules/tree/main/rules/integrations/okta 18:20 – https://www.dsolutionsgroup.com/pci-dss-password-requirements/ 27:44 – https://twitter.com/BushidoToken/status/1506338850557337603

The post Talkin’ About Infosec News – 3/30/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON MARCH 21, 2022 Articles discussed in this episode: 03:27 – Netflix to clamp down on password sharing – https://about.netflix.com/en/news/paying-to-share-netflix-outside-your-household 10:15 – Ransomeware is still a thing 12:31 – Ransomeware Tell-All – https://www.zdnet.com/article/hit-by-ransomware-or-paid-a-ransom-now-some-companies-will-have-to-tell-the-government/ 24:01 – Microsoft Defender tags Office Updates as ransomware – https://www.bleepingcomputer.com/news/security/microsoft-defender-tags-office-updates-as-ransomware-activity/ 31:01 – Microsft Double Patch Tuesday – https://www.bleepingcomputer.com/news/microsoft/windows-zero-day-flaw-giving-admin-rights-gets-unofficial-patch-again/ 32:28 […]

The post Talkin’ About Infosec News – 3/29/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON MARCH 7, 2022 Articles discussed in this episode: 00:08:57 – Hacker Group Anonymous and Others Targeting Russian Data – https://www.websiteplanet.com/blog/cyberwarfare-ukraine-anonymous/

The post Talkin’ About Infosec News – Special Ukraine Edition – 3/10/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON FEBRUARY 28, 2022 Articles discussed in this episode: 00:00 – PreShow Banter™ — Off-Brand Trickx 00:43 – BHIS – Talkin’ Bout [infosec] News 2022-02-28 02:40 – BHIS Anti-Vigilante PSA 04:17 – Biden has been presented with options for massive cyberattacks against Russia – https://www.nbcnews.com/politics/national-security/biden-presented-options-massive-cyberattacks-russia-rcna17558?mc_cid=e57638ad42 09:46 – Russia has been preparing to have […]

The post Talkin’ About Infosec News – 3/4/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON FEBRUARY 7, 2022 Articles discussed in this episode: 00:00 – PreShow Banter™ — I’m a Rocket Mail 01:21 – BHIS – Talkin’ Bout [infosec] News 2022-02-07 02:18 – Story # 1: Be Careful When Sharing Data in Photos – https://twitter.com/amateuradam/status/1490394034900197388 03:44 – Story # 2: China-Linked Group Attacked Taiwanese Financial Firms for […]

The post Talkin’ About Infosec News – 2/11/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON JANUARY 31, 2022 Articles discussed in this episode: 00:00 – PreShow Banter™ — Legions of the Undead 01:26 – BHIS – Talkin’ Bout [infosec] News 2022-01-31 04:06 – Story # 1: Hacktivists say they hacked Belarus rail system to stop Russian military buildup – https://arstechnica.com/information-technology/2022/01/hactivists-say-they-hacked-belarus-rail-system-to-stop-russian-military-buildup/ 08:46 – Story # 2: Ukrainian government […]

The post Talkin’ About Infosec News – 2/4/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON JANUARY 24, 2022 Articles discussed in this episode: 00:00 – PreShow Banter™ — The Monkey Dance 00:25 – BHIS – Talkin’ Bout [infosec] News 2022-01-24 01:49 – Story # 1: New Log4j attacks target SolarWinds, ZyXEL devices – https://therecord.media/new-log4j-attacks-target-solarwinds-zyxel-devices/ 08:18 – Story # 2: New MoonBounce UEFI bootkit can’t be removed by […]

The post Talkin’ About Infosec News – 1/27/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON JANUARY 17, 2022 Articles discussed in this episode: 0:00:00 – PreShow Banter™ — Whose Ears Are Buring? 0:01:06 – BHIS – Talkin’ Bout [infosec] News 2022-01-17 0:02:27 – Story # 1: Russia takes down REvil hacking group at U.S. request – https://www.reuters.com/technology/russia-arrests-dismantles-revil-hacking-group-us-request-report-2022-01-14/ 0:07:00 – Story # 2: White House: Arrested Russian hacker […]

The post Talkin’ About Infosec News – 1/21/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON JANUARY 10, 2022 Articles discussed in this episode: 01:58 – Story # 1: WordPress Core Vulnerabilities – https://www.searchenginejournal.com/wordpress-core-vulnerabilities/432042/#close 11:32 – Story # 2: Card-stealing code on over 100 Sotheby’s luxury real estate sites – https://therecord.media/card-stealing-code-found-on-more-than-100-sothebys-luxury-real-estate-sites/ 14:55 – Story # 3: France hits Facebook & Google with $210 million in fines – https://www.bleepingcomputer.com/news/legal/france-hits-facebook-and-google-with-210-million-in-fines/ […]

The post Talkin’ About Infosec News – 1/14/2022 appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON JANUARY 4, 2022 Articles discussed in this episode: 00:00 – PreShow Banter™ — Who’s Job Is It Anyway? 00:20 – BHIS – Talkin’ Bout [infosec] News 2022-01-04 01:58 – Story # 1: iLOBleed Rootkit – https://thehackernews.com/2021/12/new-ilobleed-rootkit-targeting-hp.html 08:39 – Story # 2: Firmware attack can drop persistent malware in hidden SSD area – https://www.bleepingcomputer.com/news/security/firmware-attack-can-drop-persistent-malware-in-hidden-ssd-area/ […]

The post Talkin’ About Infosec News – 1/7/2022 appeared first on Black Hills Information Security.

View Details

This is a special joint webcast from the teams of Black Hills Information Security, Wild West Hackin’ Fest, and Active Countermeasures, presented by John Strand.  In this webcast, we cover the recent wave of attacks we are seeing, and we cover some of the history that got us to where we are. Consider this to […]

The post Webcast: New Wave of Ransomware Attacks: How did this happen? appeared first on Black Hills Information Security.

View Details

ORIGINALLY AIRED ON DECEMBER 20, 2021 Articles discussed in this episode: 00:00 – PreShow Banter™ — Getting Nerdy With It 04:18 – BHIS – Talkin’ Bout [infosec] News 2021-12-20 – The Final Broadcast … of 2021 05:34 – Story # 1: Apple releases Android app to find rogue AirTags – https://therecord.media/apple-releases-android-app-to-find-malicious-airtags/ 18:24 – Story # […]

The post Talkin’ About Infosec News – 12/22/2021 appeared first on Black Hills Information Security.

View Details

Ransomware attacks have been growing in popularity, especially in critical infrastructure. Due to the importance of critical infrastructure, the need to secure the environments is an impending issue. The technology used in ICS environments is sensitive and often based on older protocols. The desire for connectivity has created an opportune target for malicious actors. Join […]

The post Webcast: Intro to Ransomware and Industrial Control Systems (ICS) appeared first on Black Hills Information Security.

View Details

At Black Hills Information Security (BHIS), we make our living doing pentesting, but we’ve never once been paid for a pentest. Penetration Testers get paid for their reports. For their explanations. For their story of the environment as it appears to an attacker. The scanning and testing and exploiting (and failing at those things) is […]

The post Webcast: Hack for Show, Report For Dough: Part 2 appeared first on Black Hills Information Security.