00:00:00 - PreShow Banter™ — The Grey Times
00:04:33 - BHIS - Talkin’ Bout [infosec] News 2024-11-04
00:05:54 - Story # 1: Midnight Blizzard conducts large-scale spear-phishing campaign using RDP files
00:16:45 - Story # 2: Follow Up - 5 Things To Know On Delta’s Lawsuit Against CrowdStrike
00:17:43 - Story # 2b: CrowdStrike Sues Delta: 5 Key Takeaways
00:22:04 - Story # 3: Russian charged by U.S. for creating RedLine infostealer malware
00:22:59 - Story # 3b: How a series of opsec failures led US authorities to the alleged developer of the Redline password-stealing malware
00:28:09 - Story # 4: Fired Disney staffer accused of hacking menu to add profanity, wingdings, removes allergen info
00:30:02 - Story # 4b: ‘We strive to put humanity above all’: Disney drops arbitration demand over wrongful death lawsuit after woman died from fatal food allergy
00:37:10 - Story # 5: OCR Announces First Financial Penalty Under HIPAA Risk Analysis Enforcement Initiative
00:44:54 - Story # 6: Security researchers found a serious zero-click bug in Synology’s Photos app
00:50:10 - Story # 7: Inside a Firewall Vendor’s 5-Year War With the Chinese Hackers Hijacking Its Devices
00:52:21 - Story # 8: Microsoft wants $30 if you want to delay Windows 11 switch
01:00:03 - Story # 9: Colorado Secretary of State posted spreadsheet with voting system passwords
00:00:00 - PreShow Banter™ — Sarsaparilla
00:05:50 - BHIS - Talkin’ Bout [infosec] News 2024-10-28
00:06:46 - Story # 1: AWS, Azure auth keys found in Android and iOS apps used by millions
00:15:02 - Story # 2: Burning Zero Days: FortiJump FortiManager vulnerability used by nation state in espionage via MSPs
00:29:03 - Story # 3: Delta officially launches lawyers at $500M CrowdStrike problem
00:40:60 - Story # 4: New Rules for US National Security Agencies Balance AI’s Promise With Need to Protect Against Risks
00:46:25 - Story # 4b: CISA proposes new security requirements to protect govt, personal data
00:51:03 - Story # 5: Largest Retail Breach in History: 350 Million “Hot Topic” Customers’ Personal & Payment Data Exposed — As a Result of Infostealer Infection
00:55:35 - Story # 6: Throne’s toilet camera takes pictures of your poop
01:04:57 - A Community Support Moment - https://www.crisistextline.org
00:00:00 - PreShow Banter™ — Log Con
00:11:41 - BHIS - Talkin’ Bout [infosec] News 2024-10-21
00:12:51 - Story # 1: Internet Archive exposed again – this time through Zendesk
00:14:57 - Story # 1b: Hackers steal information from 31 million Internet Archive users
00:20:42 - Story # 2: Sophos buys Secureworks for $859 mln to beef up cybersecurity portfolio
00:24:21 - Story # 3: USDoD hacker behind National Public Data breach arrested in Brazil
00:27:12 - Story # 4: Debunking Hype: China Hasn’t Broken Military Encryption With Quantum
00:32:14 - Story # 5: Microsoft said it lost weeks of security logs for its customers’ cloud products
00:35:03 - Story # 6: Should We Chat, Too? FAQ
00:40:05 - Story # 7: More than two dozen countries have used internet outages to sway elections
00:43:50 - Story # 8: Pokemon dev Game Freak confirms breach after stolen data leaks online
00:46:32 - Story # 9: Hackers made robot vacuums randomly yell racial slurs
00:49:19 - Story # 9b: We hacked a robot vacuum — and could watch live through its camera
00:50:19 - Story # 10: The government is getting fed up with ransomware payments fueling endless cycle of cyberattacks
00:54:55 - Story # 11: Google’s Chrome Browser Starts Disabling uBlock Origin
01:01:00 - WWHF Recorvery
00:00:00 - PreShow Banter™ — Cast of Special Characters
00:06:37 - BHIS - Talkin’ Bout [infosec] News 2024-09-30
00:08:06 - Story # 1: CUPS flaws enable Linux remote code execution, but there’s a catch
00:23:40 - Story # 2: US Capitol Hit by Massive Dark Web Cyber Attack - Newsweek
00:27:40 - Story # 2b: ‘I’m a black NAZI!’: NC GOP nominee for governor made dozens of disturbing comments on porn forum
00:35:57 - Story # 3: NIST proposes barring some of the most nonsensical password rules
00:47:01 - Story # 3b: Why Two-Factor Authentication Is So Important - Teen Vogue
00:54:04 - Story # 4: Hacker plants false memories in ChatGPT to steal user data in perpetuity
01:00:42 - Story # 5: Millions of Vehicles Could Be Hacked and Tracked Thanks to a Simple Website Bug
01:02:54 - Story # 6: Massive E-Learning Platform Udemy Gave Teachers a Gen AI ‘Opt-Out Window’. It’s Already Over.
00:00 - PreShow Banter™ — Plane Talk
05:50 - BHIS - Talkin’ Bout [infosec] News 2024-09-23
06:16 - A SANS Difference Maker Award Finalist
09:47 - Story # 1: Pagers attack brings to life long-feared supply chain threat
24:08 - Story # 2: Recaptcha Phish - John Hammond
25:49 - Story # 2b: Clever ‘GitHub Scanner’ campaign abusing repos to push malware
30:05 - Story # 3: Lazarus Group Targets Developers in Fresh VMConnect Campaign
35:22 - Story # 4: LinkedIn Addresses User Data Collection for AI Training
37:40 - Story # 5: Disney ditching Slack after massive July data breach
41:42 - Story # 6: FTC exposes massive surveillance of kids, teens by social media giants
51:35 - Story # 7: Kaspersky deletes itself, installs UltraAV antivirus without warning
00:00 - PreShow Banter™ — Pour Over News
06:01 - BHIS - Talkin’ Bout [infosec] News 2024-09-16
07:14 - Story # 1: Fortinet confirms data breach after hacker claims to steal 440GB of files
15:37 - Story # 2: Snowflake slams ‘more MFA’ button again – months after Ticketmaster, Santander breaches
21:30 - Story # 3: Omnipresent AI cameras will ensure good behavior, says Larry Ellison
28:11 - Story # 4: Mastercard bolsters threat intelligence capabilities with $2.65 billion deal for Recorded Future
34:27 - Story # 5: Cyber insurance set for explosive growth
40:20 - Story # 6: 23andMe will pay $30 million to settle 2023 data breach lawsuit
45:25 - Story # 7: Google faces EU investigation over AI data compliance
50:35 - Story # 8: Rogue WHOIS server gives researcher superpowers no one should ever have
00:00 - Introduction
01:22 - The Scenario
02:50 - First Steps
03:48 - Endpoint Analysis Roll
04:22 - Logon Scripts Were installed
05:09 - I.R. Team Introductions
07:17 - Second Step
10:32 - Network Threat Hunting Roll
11:36 - Third Step
15:12 - Anyway Here’s Firewall Roll
15:43 - Fourth Step
18:26 - SIEM Roll
19:41 - Fifth Step
20:47 - UEBA Roll
21:19 - Senario Recap
22:20 - Senario Plausibility?
25:51 - Wrap-up Takeaways
00:00 - PreShow Banter™ — Revenge of the Nerds / More Chicken Related Crimes
05:19 - N.Y. Official Charged With Taking Money, Travel and Poultry to Aid China
09:23 - BHIS - Talkin’ Bout [infosec] News 2024-09-09
09:50 - Story # 1: YubiKeys are vulnerable to cloning attacks thanks to newly discovered side channel
20:35 - Story # 2: Therapy Sessions Exposed by Mental Health Care Firm’s Unsecured Database
25:24 - Story # 3: California legislature passes sweeping AI safety bill
38:02 - Story # 4: Brain Cipher claims attack on Olympic venue, promises 300 GB data leak
41:59 - Story # 5: How Navy chiefs conspired to get themselves illegal warship Wi-Fi
42:45 - Story # 5b: After seeing Wi-Fi network named “STINKY,” Navy found hidden Starlink dish on US warship
49:18 - Story # 6: Researchers say a bug let them add fake pilots to rosters used for TSA checks
51:32 - Story # 7: Durex India spilled customers’ private order data
54:53 - Story # 8: City of Columbus Sues Researcher Who Disclosed Impact of Ransomware Attack
00:00 - PreShow Banter™ — Move to Signal
03:47 - BHIS - Talkin’ Bout [infosec] News 2024-08-26
04:37 - Story # 1: Pavel Durov’s Arrest Leaves Telegram Hanging in the Balance
11:03 - Story # 1b: Moxie on X.com
23:17 - Story # 2: Unveiling “sedexp”: A Stealthy Linux Malware Exploiting udev Rules
29:39 - Story # 3: Seattle airport ‘possible cyberattack’ snarls travel yet again
32:42 - Story # 4: Iran named as source of Trump campaign phish, leaks
38:53 - Story # 5: Man who hacked Hawaii state registry to forge his own death certificate sentenced to 81 months
44:11 - Story # 6: Hardware Backdoor Discovered in RFID Cards Used in Hotels and Offices Worldwide
47:26 - Story # 7: New ‘ALBeast’ Misconfiguration Exposes Weakness in AWS Application Load Balancer
48:52 - Story # 8: “We will hold them accountable”: General Motors sued for selling customer driving data to third parties
00:00:00 - PreShow Banter™ — Nine Years for Chicken Wings
00:08:19 - BHIS - Talkin’ Bout [infosec] News 2024-08-19
00:09:03 - Story # 1: NationalPublicData.com Hack Exposes a Nation’s Data
00:18:17 - Story # 1b: National Public Data Published Its Own Passwords
00:25:01 - Story # 2: RansomHub Group Deploys New EDR-Killing Tool in Latest Cyber Attacks
00:26:52 - Story # 3: T-Mobile fined $60 million for failing to stop data breaches
00:34:03 - Story # 4: Massive Cyber Attack On AWS Targets 230 Million Unique Cloud Environments
00:45:43 - Story # 5: The US wants to use facial recognition to identify migrant children as they age
00:54:16 - Story # 6: Six ransomware gangs behind over 50% of 2024 attacks
00:59:56 - Story # 7: US accuses man of being ‘elite’ ransomware pioneer they’ve hunted for years
01:01:57 - Rinsed: From Cartels to Crypto: How the Tech Industry Washes Money for the World’s Deadliest Crooks
00:00 - PreShow Banter™ — Scotty’s Pizza (Not Sponsored)
03:38 - BHIS - Talkin’ Bout [infosec] News 2024-08-12
03:59 - Hacker Summer Camp Report 2024
08:56 - Story # 1: ‘Sinkclose’ Flaw in Hundreds of Millions of AMD Chips Allows Deep, Virtually Unfixable Infections
14:26 - Story # 2: Black Hat USA 2024, DEF CON 32 attendees treated like children – or criminals – with invasive hotel room checks
29:49 - Story # 3: DEF CON Badge Maker Pulled Off Stage Amid Claims of Non-Payment and Failed Work
30:06 - New raspberry pi chip in badge
33:31 - Story # 4: Exploit released for Cisco SSM bug allowing admin password changes
34:12 - Story # 5: 0.0.0.0 Day: Exploiting Localhost APIs From the Browser
38:02 - Story # 6: Intelligence bill would elevate ransomware to a terrorist threat
44:36 - Story # 6b: Proposed bill would block large ransomware payments by financial institutions
46:26 - Story # 6c: Report shows decreased ransomware payments
54:26 - Story # 7: After global IT meltdown, CrowdStrike courts hackers with action figures and gratitude
55:12 - Story # 8: CrowdStrike pursuing deal to buy patch management specialist Action1
57:24 - Story # 9: Microsoft punches back at Delta Air Lines and its legal threats
00:00 - PreShow Banter™ — What’s the f___
03:34 - BHIS - Talkin’ Bout [infosec] News 2024-08-05
06:57 - Story # 1: Proofpoint Email Routing Flaw Exploited to Send Millions of Spoofed Phishing Emails
23:57 - Story # 2: Bumble and Hinge allowed stalkers to pinpoint users’ locations down to 2 meters, researchers say
36:47 - Story # 3: Eavesdropping on HDMI cables can reveal computer screen’s content
37:43 - Story # 3b Hak5 Screen Crab
39:18 - Story # 4: Microsoft says massive Azure outage was caused by DDoS attack
43:31 - Story # 5: CrowdStrike says it’s not to blame for Delta’s days-long outage
55:34 - Story # 6: CrowdStrike sued by investors over massive global IT outage
00:00 - PreShow Banter™ — Microsoft Sad Face
02:13 - BHIS - Talkin’ Bout [infosec] News 2024-07-29
03:08 - Story # 1: Fake CrowdStrike repair manual pushes new infostealer malware
15:26 - Story # 1b: 83-year-old man found safe a week after going missing when CrowdStrike outage canceled flight
20:39 - Story # 2: Multifactor Authentication Is Not Enough to Protect Cloud Data
38:59 - Graphrunner
47:19 - Story # 3: Data pilfered from Pentagon IT supplier Leidos
57:57 - Story # 4: How a North Korean Fake IT Worker Tried to Infiltrate Us
00:00 - PreShow Banter™ — CrowdStroke Memes
05:59 - BHIS - Talkin’ Bout [infosec] News 2024-07-22
07:01 - Story # 1: A Windows version from 1992 is saving Southwest’s butt right now
07:36 - Crowdstrike Global Outage - BHIS - Talkin’ Bout [infosec] #News
09:48 - Story # 1b: CrowdStrike’s faulty update crashed 8.5 million Windows devices, says Microsoft
12:13 - Story # 1c: Let’s blame the dev who pressed “Deploy”
17:23 - Figure 1
22:14 - Story # 2: DHS Has a DoS Robot to Disable Internet of Things ‘Booby Traps’ Inside Homes
25:58 - Story # 3: Notorious Hacker Kingpin ‘Tank’ Is Finally Going to Prison
28:08 - Story # 4: UK Police Arrest Suspect in MGM Ransomware Attack
30:49 - Story # 5: Russians plead guilty to involvement in LockBit ransomware attacks
33:24 - Story # 6: DHS watchdog rebukes CISA and law enforcement training center for failing to protect data
38:32 - Story # 7: Yacht giant MarineMax data breach impacts over 123,000 people
40:38 - Story # 8: Sizable Chunk of SEC Charges Against SolarWinds Tossed Out of Court
47:14 - Story # 9: The US Supreme Court Kneecapped US Cyber Strategy
52:12 - Story # 10: War Thunder does it again, this time with classified documents relating to 3 Russian tanks
00:00 - PreShow Banter™ — Absolute Madmen
02:28 - BHIS - Talkin’ Bout [infosec] News 2024-07-15
03:18 - Wi-Fi Forge
07:31 - Story # 1: CISA Red Team’s Operations Against a Federal Civilian Executive Branch Organization Highlights the Necessity of Defense-in-Depth
22:39 - Story # 2: AT&T says criminals stole phone records of ‘nearly all’ customers in new data breach
33:35 - Story # 3: FTC study finds ‘dark patterns’ used by a majority of subscription apps and websites
38:48 - Story # 4: Club Penguin fans breached Disney Confluence server, stole 2.5GB of data
41:52 - Story # 5: Heritage Foundation Exec Threatens ‘Gay Furry Hackers’ in Unhinged Texts
47:51 - Story # 6: German Navy to replace aging 8-inch floppy drives with an emulated solution for its anti-submarine frigates
50:14 - Story # 7: 1.4 GB NSA Data Leaked Online – Email Address, Phone Number & Gov Classified Data Exposed
53:56 - Story # 8: Hackers Claim to Have Leaked 1.1 TB of Disney Slack Messages
00:00 - PreShow Banter™ — A Bunch of Lunatics
05:09 - BHIS - Talkin’ Bout [infosec] News 2024-07-08
08:41 - Story # 1: Europol takes down 593 Cobalt Strike servers used by cybercriminals
09:54 - Story # 1b: National Crime Agency leads international operation to degrade illegal versions of Cobalt Strike
15:17 - Story # 2: ‘RockYou2024’: Nearly 10 billion passwords leaked online
22:12 - Story # 3: Ticketmaster Breach: ShinyHunters Leak 440K Taylor Swift Eras Tour Ticket Data
24:20 - Story # 3b: Hackers reverse-engineer Ticketmaster’s barcode system to unlock resales on other platforms
27:41 - Story # 4: US Supreme Court ruling will likely cause cyber regulation chaos
39:39 - Story # 5: California Advances Unique Safety Regulations for AI Companies Despite Tech Firm opposition
41:13 - Story # 5b: Senator Scott Wiener
43:45 - Story # 6: OpenAI Did Not Disclose 2023 Breach to Feds, Public: Report
53:10 - Story # 7: Microsoft’s Midnight Blizzard source code breach also impacted federal agencies
55:27 - Story # 8: Japan’s Government Finally Stops Using Floppy Disks
57:48 - Story # 9: This smart toilet paper monitor tells you when you need a new roll
58:50 - Story # 10: Twilio says hackers identified cell phone numbers of two-factor app Authy users
00:00 - PreShow Banter™ — Ice Cream Season
07:22 - BHIS - Talkin’ Bout [infosec] News 2024-07-01
07:48 - Story # 1: TeamViewer’s corporate network was breached in alleged APT hack
09:11 - Story # 1b: TeeamViewer Security Update – June 28, 2024, 12:10 PM CEST
16:33 - Story # 2: Supreme Court orders new look at Texas, Florida social media laws
21:32 - Story # 3: New OpenSSH Vulnerability Could Lead to RCE as Root on Linux Systems
24:52 - Story # 4: CISA: Most critical open source projects not using memory safe code
40:03 - Story # 5: Exploit for critical Fortra FileCatalyst Workflow SQLi flaw released
42:35 - Story # 6: South Korean telecom company attacks customers with malware — over 600,000 torrent users report missing files, strange folders, and disabled PCs
49:24 - Story # 7: Drone As First Responder Programs Are Swarming Across the United States
55:22 - GRC Rapid Fire
00:00 - PreShow Banter™ — Life is a Highway
04:28 - BHIS - Talkin’ Bout [infosec] News 2024-06-24
05:30 - Story # 1: Colorado Privacy Act Amended To Include Biometric Data Provisions
14:18 - Story # 2: Scathing report on Medibank cyberattack highlights unenforced MFA
24:30 - Story # 3: CDK suffered another data breach as it was attempting to recover
35:08 - Story # 4: LockBit claims the hack of the US Federal Reserve
40:00 - Story # 5: Amazon-Powered AI Cameras Used to Detect Emotions of Unwitting UK Train Passengers
45:36 - Story # 6: That PowerShell ‘fix’ for your root cert ‘problem’ is a malware loader in disguise
51:13 - Story # 7: US sanctions Kaspersky Lab executives, board members over ‘cooperation’ with Russia
53:23 - Story # 7b: Treasury Sanctions Kaspersky Lab Leadership in Response to Continued Cybersecurity Risks
00:00 - PreShow Banter™ — Hungry Hungry Hipaa
03:39 - BHIS - Talkin’ Bout [infosec] News 2024-06-17
05:40 - Story # 1: Windows security hole allows attackers to install malware via Wi-Fi — new patch plugs gaping vulnerability
16:27 - Story # 2: Microsoft’s all-knowing Recall AI feature is being delayed
25:34 - Story # 3: Here’s how Apple’s AI model tries to keep your data private
32:27 - Story # 4: New Linux malware is controlled through emojis sent from Discord
35:28 - Story # 5: Pure Storage confirms data breach after Snowflake account hack
38:44 - Story # 6: Microsoft Chose Profit Over Security and Left U.S. Government Vulnerable to Russian Hack, Whistleblower Says
00:00 - PreShow Banter™ — Louie is Live
04:53 - BHIS - Talkin’ Bout [infosec] News 2024-06-10
07:09 - Story # 1: UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion
18:39 - Story # 2: Stealing everything you’ve ever typed or viewed on your own Windows PC is now possible with two lines of code — inside the Copilot+ Recall disaster.
39:02 - Story # 3: TikTok fixes zero-day bug used to hijack high-profile accounts
41:34 - Story # 4: The Age of the Drone Police Is Here
52:07 - Story # 5: London hospitals declare emergency following ransomware attack
54:45 - Story # 6: Former Senior Executive and Former Sales Manager Convicted of Selling Data on Millions of U.S. Consumers to Perpetrators of Mail Fraud Schemes
56:40 - Story # 7: FBI Kicks Hackers In The Teeth With Free 7,000 Ransomware Key Giveaway
57:32 - Story # 8: FCC OKs pilot to bolster school, library cybersecurity
00:00:00 - PreShow Banter™ — In an RV down by the dumpster
00:07:39 - BHIS - Talkin’ Bout [infosec] News 2024-06-03
00:09:21 - Story # 1: Ticketmaster confirms massive breach after stolen data for sale online
00:10:46 - Story # 1b: Snowflake, Cloud Storage Giant, Suffers Massive Breach: Hacker Confirms to Hudson Rock Access Through Infostealer Infection
00:13:03 - Story # 1c: Detecting and Preventing Unauthorized User Access: Instructions
00:13:42 - Story # 1d: Snowflake Denies Responsibility for Ticketmaster, Santander Breaches
00:21:21 - Story # 2: Chinese hackers hide on military and govt networks for 6 years
00:29:17 - Story # 3: Federal agency warns critical Linux vulnerability being actively exploited
00:34:19 - Story # 4: US dismantles 911 S5 botnet used for cyberattacks, arrests admin
00:39:19 - Story # 4b: How the FBI’s fake cell phone company put criminals into real jail cells
00:43:48 - Story # 5: Exploit released for maximum severity Fortinet RCE bug, patch now
00:46:09 - Story # 6: Enforcement Alert: Drinking Water Systems to Address Cybersecurity Vulnerabilities
00:54:44 - Story # 6b: Hackers attempt to poison Florida city’s water supply near Super Bowl
01:03:32 - Story # 7: GPT-4o’s Chinese token-training data is polluted by spam and porn websites
00:00 - PreShow Banter™ — Antichafing Training.
04:31 - BHIS - Talkin’ Bout [infosec] News 2024-05-20
07:12 - Story # 1: Linux maintainers were infected for 2 years by SSH-dwelling backdoor with huge reach
29:49 - Story # 2: Palo Alto Networks is buying security assets from IBM to expand customer base
36:50 - Story # 3: Charges and Seizures Brought in Fraud Scheme Aimed at Denying Revenue for Workers Associated with North Korea
43:55 - Story # 4: FCC might require telecoms to report on securing internet’s BGP technology
52:45 - Story # 5: Slack under attack over sneaky AI training policy
00:00 - PreShow Banter™ — World Class RSA Cookies
04:49 - BHIS - Talkin’ Bout [infosec] News 2024-05-14
06:33 - Story # 1: Zscaler takes “test environment” offline after rumors of a breach
18:48 - Story # 2: Okta’s security chief on the company’s own cyberattack and how the ‘battleground’ has shifted
43:36 - Story # 3: Leaked FBI email stresses need for warrantless surveillance of Americans
48:46 - Story # 4: Despite big tech lobbying, Maryland passes two internet privacy bills
52:26 - Story # 4b: The Anxious Generation
53:46 - Story # 5:Hackers are now targeting the children of corporate executives in elaborate ransomware attacks
00:00 - PreShow Banter™ — RSA Power Moves
08:14 - BHIS - Talkin’ Bout [infosec] News 2024-05-06
09:49 - Story # 1: Shortridge Makes Sense of the 2024 Verizon DBIR
15:04 - Story # 2: A recent security incident involving Dropbox Sign
20:30 - Story # 3: Sandbox Escape Vulnerabilities in Judge0 Expose Systems to Complete Takeover
28:40 - Story # 4: Millions of Docker repos found pushing malware, phishing sites
32:53 - Story # 5: 1,400 GitLab Servers Impacted by Exploited Vulnerability
42:07 - Story # 6: LastPass goes independent over a year after serious breaches
50:16 - Cyber Security Basics for Muggles & Minions with Ashley and Chris
50:40 - Story # 7: Ukrainian REvil Hacker Sentenced to 13 Years and Ordered to Pay $16 Million
54:12 - Story # 8: Lockbit’s seized site comes alive to tease new police announcements
56:27 - Story # 9: Systemd v256 Introduces run0: A Safer Alternative to sudo
00:00 - BHIS - Talkin’ Bout [infosec] News 2024-04-29
02:33 - Story # 1: Cyber Hygiene Helps Organizations Mitigate Ransomware-Related Vulnerabilities
10:38 - Story # 2: ‘Admin’ and ‘12345’ banned from being used as passwords in UK crackdown on cyber attacks
16:34 - Story # 3: Maximum severity Flowmon bug has a public exploit, patch now
21:06 - Story # 3b: CVE-2024-2389: Command Injection Vulnerability In Progress Flowmon
22:45 - Story # 4:GitHub comments abused to push malware via Microsoft repo URLs
30:52 - Story # 5: Security bugs in popular phone-tracking app iSharing exposed users’ precise locations
36:47 - Story # 6: Biden signs bill criticized as “major expansion of warrantless surveillance”
49:38 - Story # 7: ChatGPT’s hallucinations draw EU privacy complaint
57:46 - Story # 8: Sweden’s liquor shelves to run empty this week due to ransomware attack
00:00 - PreShow Banter™ — A Parent Process
03:01 - BHIS - Talkin’ Bout [infosec] News 2024-04-22
04:13 - Story # 1: Exploit code for Palo Alto Networks zero-day now public
07:44 - Story # 1b: (Timeline) Zero-Day Exploitation of Unauthenticated Remote Code Execution Vulnerability in GlobalProtect (CVE-2024-3400)
23:22 - Story # 2: MGM says FTC can’t possibly probe its ransomware downfall – watchdog chief Lina Khan was a guest at the time
31:37 - Story # 3: MITRE was breached through Ivanti zero-day vulnerabilities
32:27 - Story # 4: Cisco Integrated Management Controller CLI Command Injection Vulnerability
41:20 - Story # 5: Cisco Duo’s Multifactor Authentication Service Breached
46:01 - Story # 6: DevSecOps security practices are doggone disastrous
54:57 - Story # 7: FYI: This site claims to have harvested 4B+ Discord chats, today all yours for a price
00:00 - PreShow Banter™ — Retro Actions
04:48 - BHIS - Talkin’ Bout [infosec] News 2024-04-15
07:05 - Story # 1: FCC to vote on net neutrality rules on April 25
18:52 - Story # 2: “All Your Secrets Are Belong To Us” — A Delinea Secret Server AuthN/AuthZ Bypass
23:40 - Story # 2b: Delinea has cloud security incident in Thycotic Secret Server gaff
28:23 - Story # 3: CISA Releases Malware Next-Gen Analysis System for Public Use
40:36 - Story # 4: Hacker Leaks 8.5M U.S. Environmental Protection Agency (EPA) Contact Data
45:55 - Story # 5: SoCal Man Arrested on Federal Charges Alleging He Schemed to Advertise and Sell ‘Hive’ Computer Intrusion Malware
00:00 - PreShow Banter™ — BHIS Bees Corp®
04:08 - The FUTURE IS…… Kickstarter
05:29 - BHIS - Talkin’ Bout [infosec] News 2024-04-08
06:03 - Story # 1: New draft bipartisan US federal privacy bill unveiled
11:03 - Story # 2: How To Opt Out Of GM Sharing Your Driving Data With Insurance Companies
13:04 - Story # 2b: Request a Consumer Disclosure Report
14:25 - Story # 3: Hackers Hijacked Notepad++ Plugin To Execute Malicious Code
29:19 - Story # 4: A Vigilante Hacker Took Down North Korea’s Internet. Now He’s Taking Off His Mask
46:15 - Story # 5: It’s Time to Hand Cybersecurity Over to the Computers
00:00 - PreShow Banter™ — Zippers, Jokes, & Lawyers (Not to be confused with the song "Lawyers, Guns and Money")
02:59 - BHIS - Talkin’ Bout [infosec] News 2024-04-01
03:57 - Story # 1: New Darcula phishing service targets iPhone users via iMessage
11:57 - Story # 2: Recent ‘MFA Bombing’ Attacks Targeting Apple Users
17:22 - Story # 3: Thousands of phones and routers swept into proxy service, unbeknownst to users
22:11 - Story # 4: Digital signs around Brookline are collecting data from your phone as you walk by
26:57 - Story # 5: Backdoor found in widely used Linux utility targets encrypted SSH connections
28:22 - Story # 5b: XZ Outbreak diagram
37:32 - Story # 6: Vans warns customers of data breach
40:00 - Story # 7: Worldwide Agenda Ransomware Wave Targets VMware ESXi Servers
50:32 - Story # 8: Criminals Are Weaponizing Child Abuse Imagery to Ban Discord Servers
56:41 - Story # 9: International car theft tool seized in Australia, sparking police warning
58:14 - Story # 9b: Investigation into electronic device at Utah high school raises larger concerns for police
00:00 - PreShow Banter™ — “Allegedly”
03:18 - BHIS - Talkin’ Bout [infosec] News 2024-03-25
08:00 - Story # 1: Cisco Completes Acquisition of Splunk
10:47 - Story # 2: General Motors Quits Sharing Driving Behavior With Data Brokers
15:27 - Story # 3: Ron DeSantis signs bill requiring parental consent for kids under 16 to hold social media accounts
24:34 - Story # 4: House passes bill to prevent the sale of personal data to foreign adversaries
28:19 - Story # 5: Unsaflok - vulnerability impacts over 3 million hotel doors
33:57 - Story # 6: Canada revisits decision to ban Flipper Zero
36:57 - Story # 7: Truck-to-truck worm could infect – and disrupt – entire US commercial fleet
42:59 - Story # 8: Cybercriminals Beta Test New Attack to Bypass AI Security
46:31 - Story # 9: Russians will no longer be able to access Microsoft cloud services, business intelligence tools
50:36 - Story # 10: New ‘Loop DoS’ Attack Impacts Hundreds of Thousands of Systems
55:05 - Story # 11: New surveillance video of man catching a flight without ticket
Brought to you by Antisyphon Training — https://www.antisyphontraining.com
00:00:00 - PreShow Banter™ — New Arms Again
00:03:24 - BHIS - Talkin’ Bout [infosec] News 2024-03-18
00:04:54 - Story # 1: NIST Releases Version 2.0 of Landmark Cybersecurity Framework
00:10:50 - Story # 2: The FCC has finally decreed that 25Mbps and 3Mbps are not ‘broadband’ speed
00:14:33 - Story # 3: Welcome to the 2024 Threat Detection Report
00:33:40 - Story # 4: NSA Releases Top Ten Cloud Security Mitigation Strategies
00:47:33 - Story # 5: US government agencies demand fixable ice cream machines
00:53:14 - Story # 6: Homeland Security is testing AI to help with immigration, trafficking investigations, and disaster relief
01:03:19 - Story # 7: Feds seize $1.4 million of tech support scam proceeds with the help of crypto firm
00:00 - PreShow Banter™ — Death to Clippy
05:18 - BHIS - Talkin’ Bout [infosec] News 2024-03-11 – Featuring Josh Mason
06:58 - Story # 1: Behind the doors of a Chinese hacking company, a sordid culture fueled by influence, alcohol, and sex
13:43 - Story # 2: Top US cybersecurity agency hacked and forced to take some systems offline
23:39 - Story # 3: Microsoft admits Russian state hack still not contained. ‘This has tremendous national security implications’
30:27 - Story # 4: FBI’s 2023 Internet Crime Report
38:18 - Story # 5: QNAP warns of critical auth bypass flaw in its NAS devices
50:42 - Story # 6: Automakers Are Sharing Consumers’ Driving Behavior With Insurance Companies
A weekly Podcast with BHIS and Friends. stories. We discuss notable Infosec, and infosec-adjacent news stories.
Brought to you by:
Black Hills Information Security
https://www.blackhillsinfosec.com/
Antisyphon Training
https://www.antisyphontraining.com/
Story # 1: Executive Order on Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern
https://www.whitehouse.gov/briefing-r...
Story # 2: A leaky database spilled 2FA codes for the world’s tech giants
https://techcrunch.com/2024/02/29/lea...
Story # 3: eBay, VMware, McAfee Sites Hijacked in Sprawling Phishing Operation
https://www.darkreading.com/applicati...
23:36 - LokiHakanin's related Post
/ sean-reilly-techopssec_8000-domains-of-tru...
Story # 4: Ivanti Connect Secure hackers hide in plain sight, evading protections
https://www.cybersecuritydive.com/new...
Story # 5: Over 100,000 Infected Repos Found on GitHub
https://apiiro.com/blog/malicious-cod...
Story # 6: Hackers backed by Russia and China are infecting SOHO routers like yours, FBI warns
https://arstechnica.com/security/2024...
Story #1: Mr. Cooper leak exposes over two million customers
Story #2: ConnectWise ScreenConnect attacks deliver malware
Story #3: LockBit Infrastructure Seized by US, UK Police
Story #4: US health tech giant Change Healthcare hit by cyberattack
Story #5: The reported leak of Chinese hacking documents supports experts’ warnings about how compromised the US could be
The post Talkin’ About Infosec News – 2/20/24 appeared first on Black Hills Information Security.
The post Talkin’ About Infosec News – 2/14/2024 appeared first on Black Hills Information Security.
The post Talkin’ About Infosec News – 2/6/24 appeared first on Black Hills Information Security.
The post Talkin’ About Infosec News – 1/31/2024 appeared first on Black Hills Information Security.
The post Talkin’ About Infosec News – 1/24/2024 appeared first on Black Hills Information Security.
The post Talkin’ About Infosec News – 1/16/2024 appeared first on Black Hills Information Security.
The post Talkin’ About Infosec News – 1/10/24 appeared first on Black Hills Information Security.
The post Talkin’ About Infosec News – 12/21/2023 appeared first on Black Hills Information Security.
https://youtu.be/MaThvw_VWJ8 Brought to you by Antisyphon Training https://www.antisyphontraining.com
The post Talkin’ About Infosec News – 12/06/2023 appeared first on Black Hills Information Security.
The post Talkin’ About Infosec News – 11/30/2023 appeared first on Black Hills Information Security.
Brought to you by Antisyphon Training — https://www.antisyphontraining.com
The post Talkin’ About Infosec News – 8/28/2023 appeared first on Black Hills Information Security.
🔵Join us for the Antisyphon Blue Team Summit! https://www.antisyphontraining.com/training/blue-team/2023/06/blue-team-summit-coming-in-august-2023/ Blue Team Summit Coming in August 2023! – Antisyphon Training
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories. Brought to you by: /// 📄 Antisyphon Training August 2023 Blue Team Summit: https://www.antisyphontraining.com/training/blue-team/2023/06/blue-team-summit-coming-in-august-2023/ /// 📄 […]
The post Talkin’ About Infosec News – 5/26/2023 appeared first on Black Hills Information Security.
The post Talkin’ About Infosec News – 5/17/2023 appeared first on Black Hills Information Security.
The post Talkin’ About Infosec News – 5/11/2023 appeared first on Black Hills Information Security.
The post Talkin’ About Infosec News – 5/5/2023 appeared first on Black Hills Information Security.
The post Talkin’ About Infosec News – 4/18/2023 appeared first on Black Hills Information Security.
The post Talkin’ About Infosec News – 4/11/2023 appeared first on Black Hills Information Security.
The post Talkin’ About Infosec News – 4/5/2023 appeared first on Black Hills Information Security.
The post Talkin’ About Infosec News – 4/3/2023 appeared first on Black Hills Information Security.
00:00 – PreShow Banter™ — Tossing Money at Problems00:58 – BHIS – Talkin’ Bout [infosec] News 2023-03-1301:41 – Story # 1: Silicon Valley Bank collapse: Treasury, Fed, and FDIC announce […]
The post Talkin’ About Infosec News – 3/16/2023 appeared first on Black Hills Information Security.
THIS IS A TEST
The post Talkin’ About Infosec News – 3/8/2023 (v2) appeared first on Black Hills Information Security.
00:00 – PreShow Banter™ — Lil NAS06:52 – BHIS – Talkin’ Bout [infosec] News 2023-03-0608:13 – Story # 1: LastPass says employee’s home computer was hacked and corporate vault takenhttps://arstechnica.com/information-technology/2023/02/lastpass-hackers-infected-employees-home-computer-and-stole-corporate-vault/28:32 […]
The post Talkin’ About Infosec News – 3/8/2023 appeared first on Black Hills Information Security.
Story # 1: A Basic iPhone Feature Helps Criminals Steal Your Entire Digital Lifehttps://www.wsj.com/articles/apple-iphone-security-theft-passcode-data-privacya-basic-iphone-feature-helps-criminals-steal-your-digital-life-cbf14b1a Story # 1b: Apple’s iPhone Passcode Problem: Thieves Can Ruin Your Entire Digital Life in Minutes […]
The post Talkin’ About Infosec News – 3/3/2023 appeared first on Black Hills Information Security.
00:00 – PreShow Banter™ — Pop Tart Pizza04:15 – BHIS – Talkin’ Bout [infosec] News 2023-02-2005:39 – Story # 1: Employee data from a major cybersecurity firm posted for sale […]
The post Talkin’ About Infosec News – 2/22/2023 appeared first on Black Hills Information Security.
00:00 – PreShow Banter™ — Scalping Valentine’s Day Reservations04:13 – BHIS – Talkin’ Bout [infosec] News 2023-06-2305:52 – Story # 1: 5 Chinese companies and a research institute blacklisted by […]
The post Talkin’ About Infosec News – 2/17/2023 appeared first on Black Hills Information Security.
00:00 – PreShow Banter™ — Woke Up Like This03:20 – BHIS – Talkin’ Bout [infosec] News 2023-01-3005:04 – Story # 1: GoTo says hackers stole customers’ backups and encryption keyhttps://www.bleepingcomputer.com/news/security/goto-says-hackers-stole-customers-backups-and-encryption-key/09:48 […]
The post Talkin’ About Infosec News – 2/3/2023 appeared first on Black Hills Information Security.
00:00 – PreShow Banter™ — Wade’s Googly Eyes00:41 – BHIS – Talkin’ Bout [infosec] News 2023-01-2301:26 – Story # 1: BIG TECH LAYOFFS. LAYOFFS! DOOM! RECESSION!
The post Talkin’ About Infosec News – 1/25/2023 appeared first on Black Hills Information Security.
00:00 – PreShow Banter™ — Ralph’s Guide to Satellite Bands 04:33 – BHIS – Talkin’ Bout [infosec] News 2023-01-16 05:25 – Story # 1: Microsoft’s new AI can simulate anyone’s […]
The post Talkin’ About Infosec News – 1/17/2023 appeared first on Black Hills Information Security.
00:00 – PreShow Banter™ — Twitch Airways International00:59 – BHIS – Talkin’ Bout [infosec] News 2023-01-1003:56 – Story # 1: How ChatGPT could become a hacker’s friendhttps://betanews.com/2023/01/05/how-chatgpt-could-become-a-hackers-friend/14:05 – Story # […]
The post Talkin’ About Infosec News – 1/12/2023 appeared first on Black Hills Information Security.
00:00 – PreShow Banter™ — Seven People00:51 – BHIS – Talkin’ Bout [infosec] News 2023-01-0201:37 – Story # 1: LastPass Admits to Severe Data Breach, Encrypted Password Vaults Stolenhttps://www.theverge.com/2022/12/28/23529547/lastpass-vault-breach-disclosure-encryption-cybersecurity-rebuttal32:22 – […]
The post Talkin’ About Infosec News – 1/3/2023 appeared first on Black Hills Information Security.
00:00 – PreShow Banter™ — Talkin’ Bout [Elon] News00:51 – BHIS – Talkin’ Bout [infosec] News 2022-12-1902:46 – Story # 1: Antivirus and EDR solutions tricked into acting as data […]
The post Talkin’ About Infosec News – 12/21/2022 appeared first on Black Hills Information Security.
00:00 – PreShow Banter™ — Scissors Vs Paper00:15 – BHIS – Talkin’ Bout [infosec] News 2022-12-1202:12 – Story # 1: Rackspace confirms ransomware attack behind days-long email meltdownhttps://www.theregister.com/2022/12/06/rackspace\_confirms\_ransomware/07:56 – Story […]
The post Talkin’ About Infosec News – 12/15/2022 appeared first on Black Hills Information Security.
00:00 – PreShow Banter™ — Florida Bobsledding Team01:29 – PreShow Banter™ — Open AI Phishing Campaign05:17 – BHIS – Talkin’ Bout [infosec] News 2022-12-0507:53 – Story # 1: There are […]
The post Talkin’ About Infosec News – 12/6/2022 appeared first on Black Hills Information Security.
00:00 – PreShow Banter™ — Inflatable Turkey00:15 – BHIS – Talkin’ Bout [infosec] News 2022-11-2802:34 – Story # 1: Musk recruits engineers for “Twitter 2.0”https://arstechnica.com/tech-policy/2022/11/musk-recruits-engineers-for-twitter-2-0-after-mass-layoffs-and-resignations/06:28 – Story # 2: Security […]
The post Talkin’ About Infosec News – 11/30/2022 appeared first on Black Hills Information Security.
00:00 – BHIS – Talkin’ Bout [infosec] News 2022-11-1402:26 – Story # 1: Hackers Dump Australian Health Records Online After Insurer Refuses to Pay Ransom– https://gizmodo.com/hackers-health-info-online-medibank-pay-onion-dark-web-184976074210:04 – Story # 2: TransUnion […]
The post Talkin’ About Infosec News – 11/16/2022 appeared first on Black Hills Information Security.
00:00 – PreShow Banter™ — A is for All Team00:33 – BHIS – Talkin’ Bout [infosec] News 2022-11-0703:56 – Story # 1: Musk to cut half of Twitter jobs and […]
The post Talkin’ About Infosec News – 11/11/2022 appeared first on Black Hills Information Security.
00:00 – PreShow Banter™ — Spook Show00:58 – BHIS – Talkin’ Bout [infosec] News 2022-10-3104:00 – Story # 1: OpenSSL warns of critical security vulnerability with upcoming patch– https://www.zdnet.com/article/openssl-warns-of-critical-security-vulnerability-with-upcoming-patch/04:42 – Story […]
The post Talkin’ About Infosec News – 11/1/2022 appeared first on Black Hills Information Security.
00:00 – PreShow Banter™ — Best WWHF Ever!00:31 – BHIS – Talkin’ Bout [infosec] News 2022-10-1704:55 – Story # 1: The Verge: Cybersecurity Week 2022– https://www.theverge.com/23365380/cybersecurity-week-series-phishing-encryption-device-security07:02 – Story # 2: Google […]
The post Talkin’ About Infosec News – 10/17/2022 appeared first on Black Hills Information Security.
00:00 – PreShow Banter™ — Dumpster Fire Friends03:07 – PreShow Banter™ — WHHF Deadwood – https://wildwesthackinfest.com/deadwood/ 03:48 – BHIS – Talkin’ Bout [infosec] News 2022-10-0307:37 – Story # 1: High-severity […]
The post Talkin’ About Infosec News – 10/17/2022 appeared first on Black Hills Information Security.
02:28 – Story # 1: American Airlines Breach Exposes Customer and Staff Information– https://www.infosecurity-magazine.com/news/american-airlines-breach-customer/18:59 – Story # 2: London police arrest, charge teen hacking suspect but won’t confirm GTA 6, Uber […]
The post Talkin’ About Infosec News – 10/5/2022 appeared first on Black Hills Information Security.
The post Talkin’ About Infosec News – 9/22/2022 appeared first on Black Hills Information Security.
The post Talkin’ About Infosec News – 9/13/2022 appeared first on Black Hills Information Security.
The post Talkin’ About Infosec News – 9/9/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON AUGUST 22, 2022 00:00 – PreShow Banter™ — Ralph’s Birthday00:53 – BHIS – Talkin’ Bout [infosec] News 2022-08-2203:27 – Story # 1: PC store told it can’t […]
The post Talkin’ About Infosec News – 8/26/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON AUGUST 15, 2022 Articles discussed in this episode: 00:00 – PreShow Banter™ — Sneaking Candy03:32 – BHIS – Talkin’ Bout [infosec] News 2022-08-1507:06 – Story # 1: […]
The post Talkin’ About Infosec News – 8/18/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON JULY 25, 2022 Articles discussed in this episode: 00:00 – BHIS – Talkin’ Bout [infosec] News 2022-07-25 03:59 – Story # 1: DOJ seized ransoms paid by […]
The post Talkin’ About Infosec News – 8/1/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON JULY 18, 2022 Articles discussed in this episode: 00:00 – PreShow Banter™ — Talkin’ Bout Audio 07:23 – BHIS – Talkin’ Bout [infosec] News 2022-07-18 09:28 – […]
The post Talkin’ About Infosec News – 7/18/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON JULY 11, 2022 Articles discussed in this episode: 00:00 – PreShow Banter™ — Cons, China, and Florida Man, oh my! 07:03 – Story # 1: North Korean […]
The post Talkin’ About Infosec News – 7/11/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON JUNE 27, 2022 Articles discussed in this episode: 02:13 – Story # 1: The #1 Period Tracker on the App Store Will Hand Over Data Without a […]
The post Talkin’ About Infosec News – 6/27/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON JUNE 20, 2022 Articles discussed in this episode: 00:00 – BHIS – Talkin’ Bout [infosec] News 2022-06-20 01:31 – Story # 1: Internal TikTok Meetings Shows That […]
The post Talkin’ About Infosec News – 6/20/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON JUNE 13, 2022 Articles discussed in this episode: 00:00 – BHIS – Talkin’ Bout [infosec] News 2022-06-13 02:26 – Story # 1: Roblox Game Pass store used […]
The post Talkin’ About Infosec News – 6/13/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON JUNE 6, 2022 Articles discussed in this episode: 00:00 – PreShow Banter™ — Boat Facts 01:38 – BHIS – Talkin’ Bout [infosec] News 2022-06-06 03:51 – Story […]
The post Talkin’ About Infosec News – 6/6/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON MAY 23, 2022 Articles discussed in this episode: 00:00 – BHIS – Talkin’ Bout [infosec] News 2022-05-23 02:38 – Story # 1 – National bank trolls hackers with dick pics – https://www.bleepingcomputer.com/news/security/national-bank-hit-by-ransomware-trolls-hackers-with-dick-pics/ 06:59 – Story # 2 – Ransomware attack exposes data of 500,000 Chicago students – https://www.bleepingcomputer.com/news/security/ransomware-attack-exposes-data-of-500-000-chicago-students/ 14:09 – Story # […]
The post Talkin’ About Infosec News – 5/23/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON MAY 16, 2022 Articles discussed in this episode: 00:56 – Microsoft’s May Patch Tuesday Updates Cause Windows AD Authentication Errors – https://threatpost.com/microsofts-may-patch-tuesday-updates-cause-windows-ad-authentication-errors/179631/ 08:56 – Update rings for Windows 10 and later policy in Intune – https://docs.microsoft.com/en-us/mem/intune/protect/windows-10-update-rings 09:06 – Infosec Weather Report With Bud Patches – 12:26 – FBI, CISA, and NSA warn […]
The post Talkin’ About Infosec News – 5/16/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON MAY 9, 2022 Articles discussed in this episode: 00:00 – Bud Patches Reporting 02:27 – BHIS – Talkin’ Bout [infosec] News 2022-05-09 03:47 – Story # 1 – CISA Shields Up – https://www.cisa.gov/shields-up 09:44 – Story # 2 – Critical BIG-IP Remote Code Execution Vulnerability – https://thehackernews.com/2022/05/f5-warns-of-new-critical-big-ip-remote.html 29:25 – Story # 3 […]
The post Talkin’ About Infosec News – 5/9/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON APRIL 25, 2022 Articles discussed in this episode: 00:00 – PreShow Banter™ — Broken Twitter Finger 01:38 – ISO – Talkin’ Bout [infosec] News 2022-04-26 03:08 – Elon Buys Twitter 09:27 – Leaked Chats Show LAPSUS$ Stole T-Mobile Source Code – https://krebsonsecurity.com/2022/04/leaked-chats-show-lapsus-stole-t-mobile-source-code/ 15:48 – Threat actors exploited more zero-day vulnerabilities in 2021 […]
The post Talkin’ About Infosec News – 4/25/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON APRIL 18, 2022 Articles discussed in this episode: 00:00 – BHIS – Talkin’ Bout [infosec] News 2022-04-18 02:05 – Current Activity | CISA | https://www.cisa.gov/uscert/ncas/current-activity 02:58 – CISA orders agencies to fix actively exploited VMware, Chrome bugs | https://www.bleepingcomputer.com/news/security/cisa-orders-agencies-to-fix-actively-exploited-vmware-chrome-bugs/ 08:45 – Russian invasion of Ukraine exposes cybersecurity threat to commercial satellites | […]
The post Talkin’ About Infosec News – 4/25/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON APRIL 11, 2022 Articles discussed in this episode: The US Navy had cybersecurity wrong. Expect change. – https://www.c4isrnet.com/digital-show-dailies/navy-league/2022/04/05/us-navy-had-cybersecurity-wrong-expect-change/ Hackers have found a clever new way to steal your Microsoft 365 credentials. – https://www.techradar.com/news/hackers-have-found-a-clever-new-way-to-steal-your-microsoft-365-credentials Exclusive: Senior EU officials were targeted with Israeli spyware. – https://www.reuters.com/technology/exclusive-senior-eu-officials-were-targeted-with-israeli-spyware-sources-2022-04-11/ Snap-on discloses data breach claimed by Conti ransomware […]
The post Talkin’ About Infosec News – 4/12/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON APRIL 4, 2022 Articles discussed in this episode: 00:00 – PreShow Banter™ — Blame it on the Intern 06:24 – Spring Time for Java – https://www.darkreading.com/application-security/zero-day-vulnerability-discovered-in-java-spring-framework 09:10 – GitLab for Account Access – https://www.bleepingcomputer.com/news/security/critical-gitlab-vulnerability-lets-attackers-take-over-accounts/ 10:33 – No Passwords for Okta – https://www.bleepingcomputer.com/news/security/sitel-on-okta-breach-spreadsheet-did-not-contain-passwords/ 11:11 – Legacy Networks for Okta – https://therecord.media/sitel-blames-okta-breach-on-legacy-network-from-acquisition/ 12:40 – […]
The post Talkin’ About Infosec News – 4/6/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON MARCH 28, 2022 Articles discussed in this episode: 01:42 – Suspected Okta hackers arrested by British police – https://www.reuters.com/world/uk/british-police-say-seven-people-arrested-after-okta-hack-2022-03-24/ 11:16 – A Closer Look at the LAPSUS$ Data Extortion Group – https://krebsonsecurity.com/2022/03/a-closer-look-at-the-lapsus-data-extortion-group/ 14:04 – Anonymous Starts ‘Huge’ Data Dump That Will ‘Blow Russia Away,’ Leaks Rostproekt Emails – https://www.ibtimes.com/anonymous-starts-huge-data-dump-will-blow-russia-away-leaks-rostproekt-emails-3452789 22:28 – Most […]
The post Talkin’ About Infosec News – 3/31/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON MARCH 22, 2022 Articles discussed in this episode: 00:00 – BHIS – 2022-03-22 Special Newscast –Okta and Microsoft — Everything’s not burning down 10:27 – https://github.com/SigmaHQ/sigma/tree/master/rules/cloud/okta 13:29 – https://github.com/elastic/detection-rules/tree/main/rules/integrations/okta 18:20 – https://www.dsolutionsgroup.com/pci-dss-password-requirements/ 27:44 – https://twitter.com/BushidoToken/status/1506338850557337603
The post Talkin’ About Infosec News – 3/30/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON MARCH 21, 2022 Articles discussed in this episode: 03:27 – Netflix to clamp down on password sharing – https://about.netflix.com/en/news/paying-to-share-netflix-outside-your-household 10:15 – Ransomeware is still a thing 12:31 – Ransomeware Tell-All – https://www.zdnet.com/article/hit-by-ransomware-or-paid-a-ransom-now-some-companies-will-have-to-tell-the-government/ 24:01 – Microsoft Defender tags Office Updates as ransomware – https://www.bleepingcomputer.com/news/security/microsoft-defender-tags-office-updates-as-ransomware-activity/ 31:01 – Microsft Double Patch Tuesday – https://www.bleepingcomputer.com/news/microsoft/windows-zero-day-flaw-giving-admin-rights-gets-unofficial-patch-again/ 32:28 […]
The post Talkin’ About Infosec News – 3/29/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON MARCH 7, 2022 Articles discussed in this episode: 00:08:57 – Hacker Group Anonymous and Others Targeting Russian Data – https://www.websiteplanet.com/blog/cyberwarfare-ukraine-anonymous/
The post Talkin’ About Infosec News – Special Ukraine Edition – 3/10/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON FEBRUARY 28, 2022 Articles discussed in this episode: 00:00 – PreShow Banter™ — Off-Brand Trickx 00:43 – BHIS – Talkin’ Bout [infosec] News 2022-02-28 02:40 – BHIS Anti-Vigilante PSA 04:17 – Biden has been presented with options for massive cyberattacks against Russia – https://www.nbcnews.com/politics/national-security/biden-presented-options-massive-cyberattacks-russia-rcna17558?mc_cid=e57638ad42 09:46 – Russia has been preparing to have […]
The post Talkin’ About Infosec News – 3/4/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON FEBRUARY 7, 2022 Articles discussed in this episode: 00:00 – PreShow Banter™ — I’m a Rocket Mail 01:21 – BHIS – Talkin’ Bout [infosec] News 2022-02-07 02:18 – Story # 1: Be Careful When Sharing Data in Photos – https://twitter.com/amateuradam/status/1490394034900197388 03:44 – Story # 2: China-Linked Group Attacked Taiwanese Financial Firms for […]
The post Talkin’ About Infosec News – 2/11/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON JANUARY 31, 2022 Articles discussed in this episode: 00:00 – PreShow Banter™ — Legions of the Undead 01:26 – BHIS – Talkin’ Bout [infosec] News 2022-01-31 04:06 – Story # 1: Hacktivists say they hacked Belarus rail system to stop Russian military buildup – https://arstechnica.com/information-technology/2022/01/hactivists-say-they-hacked-belarus-rail-system-to-stop-russian-military-buildup/ 08:46 – Story # 2: Ukrainian government […]
The post Talkin’ About Infosec News – 2/4/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON JANUARY 24, 2022 Articles discussed in this episode: 00:00 – PreShow Banter™ — The Monkey Dance 00:25 – BHIS – Talkin’ Bout [infosec] News 2022-01-24 01:49 – Story # 1: New Log4j attacks target SolarWinds, ZyXEL devices – https://therecord.media/new-log4j-attacks-target-solarwinds-zyxel-devices/ 08:18 – Story # 2: New MoonBounce UEFI bootkit can’t be removed by […]
The post Talkin’ About Infosec News – 1/27/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON JANUARY 17, 2022 Articles discussed in this episode: 0:00:00 – PreShow Banter™ — Whose Ears Are Buring? 0:01:06 – BHIS – Talkin’ Bout [infosec] News 2022-01-17 0:02:27 – Story # 1: Russia takes down REvil hacking group at U.S. request – https://www.reuters.com/technology/russia-arrests-dismantles-revil-hacking-group-us-request-report-2022-01-14/ 0:07:00 – Story # 2: White House: Arrested Russian hacker […]
The post Talkin’ About Infosec News – 1/21/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON JANUARY 10, 2022 Articles discussed in this episode: 01:58 – Story # 1: WordPress Core Vulnerabilities – https://www.searchenginejournal.com/wordpress-core-vulnerabilities/432042/#close 11:32 – Story # 2: Card-stealing code on over 100 Sotheby’s luxury real estate sites – https://therecord.media/card-stealing-code-found-on-more-than-100-sothebys-luxury-real-estate-sites/ 14:55 – Story # 3: France hits Facebook & Google with $210 million in fines – https://www.bleepingcomputer.com/news/legal/france-hits-facebook-and-google-with-210-million-in-fines/ […]
The post Talkin’ About Infosec News – 1/14/2022 appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON JANUARY 4, 2022 Articles discussed in this episode: 00:00 – PreShow Banter™ — Who’s Job Is It Anyway? 00:20 – BHIS – Talkin’ Bout [infosec] News 2022-01-04 01:58 – Story # 1: iLOBleed Rootkit – https://thehackernews.com/2021/12/new-ilobleed-rootkit-targeting-hp.html 08:39 – Story # 2: Firmware attack can drop persistent malware in hidden SSD area – https://www.bleepingcomputer.com/news/security/firmware-attack-can-drop-persistent-malware-in-hidden-ssd-area/ […]
The post Talkin’ About Infosec News – 1/7/2022 appeared first on Black Hills Information Security.
This is a special joint webcast from the teams of Black Hills Information Security, Wild West Hackin’ Fest, and Active Countermeasures, presented by John Strand. In this webcast, we cover the recent wave of attacks we are seeing, and we cover some of the history that got us to where we are. Consider this to […]
The post Webcast: New Wave of Ransomware Attacks: How did this happen? appeared first on Black Hills Information Security.
ORIGINALLY AIRED ON DECEMBER 20, 2021 Articles discussed in this episode: 00:00 – PreShow Banter™ — Getting Nerdy With It 04:18 – BHIS – Talkin’ Bout [infosec] News 2021-12-20 – The Final Broadcast … of 2021 05:34 – Story # 1: Apple releases Android app to find rogue AirTags – https://therecord.media/apple-releases-android-app-to-find-malicious-airtags/ 18:24 – Story # […]
The post Talkin’ About Infosec News – 12/22/2021 appeared first on Black Hills Information Security.
Ransomware attacks have been growing in popularity, especially in critical infrastructure. Due to the importance of critical infrastructure, the need to secure the environments is an impending issue. The technology used in ICS environments is sensitive and often based on older protocols. The desire for connectivity has created an opportune target for malicious actors. Join […]
The post Webcast: Intro to Ransomware and Industrial Control Systems (ICS) appeared first on Black Hills Information Security.
At Black Hills Information Security (BHIS), we make our living doing pentesting, but we’ve never once been paid for a pentest. Penetration Testers get paid for their reports. For their explanations. For their story of the environment as it appears to an attacker. The scanning and testing and exploiting (and failing at those things) is […]
The post Webcast: Hack for Show, Report For Dough: Part 2 appeared first on Black Hills Information Security.