This week on the podcast, we cover the National Public Data breach that may have leaked every American’s social security number. After that, we discuss research from TALOS on how attackers can abuse Microsoft applications on macOS to gain access to your camera and microphone. We end the episode by discussing recent research on how […]
Read More - Leaking Every American’s SSN
This week on the podcast, we round out our takeaways from the Black Hat and Def Con security conferences in Las Vegas. We go through 4 talks across both conferences that were especially interesting either for nostalgia or modern impact.
Read More - Summer Camp 2024 Recap
On this episode of the podcast, we have another recap from the BlackHat security conference in Las Vegas. This time we discuss a new initiative to protect the world from deepfakes, followed by a penetration testing engagement that proved immutable backups doesn’t always mean available backups.
Read More - BlackHat 2024 Day 2 Recap
On this episode of the podcast, we cover our two favorite briefings from the first day at the Black Hat security conference. We start with our thoughts on “shadow resources” in cloud environments before giving an update to last week’s episode with additional research into AI-as-a-Service attacks.
Read More - BlackHat 2024 Day 1 Recap
This week we will be attending Hacker Summer camp in Las Vegas. We will be publishing a recap each day focusing on our key takeaways.
Read More - Stay Tuned for Hacker Summer Camp Recaps
This week on the episode, we walk through CrowdStrike’s preliminary post incident report to understand exactly what happened during the July 19th outage and what all software vendors can learn from the event. After that, we cover a clever plot that lead to KnowBe4 hiring a North Korean threat actor. We end with some research […]
Read More - CrowdStrike’s Incident Report
In this daily security byte with WatchGuard CSO, Corey Nachreiner, he explains the recent Global IT outage cause by a CrowdStrike update. We also follow-up on RockYou and the RockYou2024 data dump of 10 billion records
Read More - Global Security Outage
This week on the podcast we discover the newly-disclosed protocol vulnerability in certain RADIUS implementations. Before that, we give an update on the continued fallout from the Snowflake customer databreaches including a new disclosure from AT&T. We also discuss a blog post from JFrog that details how they saved the world from what could have […]
Read More - Blast RADIUS
This week on the podcast, we cover OpenSSH’s recent critical vulnerability and what it means for systems administrators. Before that, we discuss the CDK Global ransomware attack impacting car dealerships across the us, a Korean internet service provider delivering malware to their customers, and a takeover of a popular JavaScript library gone hostile.
Read More - OpenSSH regreSSHion Vulnerability
This week on the podcast we doscuss two issues from this month’s Microsoft patch tuesday that deserve your attention. After that we discuss the recent data theft campain targeting Snowflake customers that has impacted over 100 organizations. We end the episode with an update on the hackers behind the MGM and Caesar’s Entertainment breaches last […]
Read More - Snowflake Breach Campaign
Introduction This research began with finding a simple malware sample to extract strings for an unrelated topic. In my day-to-day malware analysis workflow, I stumbled upon a JavaScript (JS) file with what I would call trivial obfuscation. I knew it was malware but wanted to understand the infection chain. After some cleanup, I understood it […]
Read More - Yet Another TA558 Campaign Targets South America’s Hospitality Industry With AsyncRAT
This week on the podcast we cover the WatchGuard Threat Lab’s Internet Security Report from Q1. In this episode, we discuss the latest trends in malware detections at the network and the endpoint, network attack trends, and malicious domains that targeted WatchGuard customers around the world.
Read More - Q1 2024 Internet Security Report
This week on the podcast, we discuss a new Microsoft Windows feature that is shaping up to be a security nightmare. Before that, we discuss a new research initiative from the Advanced Research Projects Agency for Health (ARPA-H) that could make big improvements in healthcare cybersecurity.
Read More - Recall Windows Recall
This week on the podcast, we cover a newly disclosed weakness in the 802.11 Wi-Fi standard that affects common enterprise Wi-Fi deployments. Before that, we discuss CISA’s Secure by Design Pledge for technology vendors before ending with a Microsoft research post on Quick Assist social engineering.
Read More - SSID Confusion Attacks
In a very special episode of #the443Podcast, WatchGuard Director of Security Operations, Marc Laliberte sits down with Seattle Kraken Cybersecurity Engineer, Ryan Willgues to discuss how Ryan got his start in IT, what it’s like working for an NHL franchise, how the Kraken have deployed WatchGuard’s Unified Security Platform, and much more.
Read More - Seattle Kraken IT Joins The 443 Podcast
This week on the podcast, we cover guidance from CISA and its international partners that guides organizations on the right questions to ask during the technology procurement process to make sure the products they buy are secure. Before that, we cover Microsoft’s research into a common vulnerability impacting over 4 billion Android application installations followed […]
Read More - Picking Secure Technologies
This week on the podcast, we cover the key takeaways from the 2024 Verizon Data Breach Investigations Report. Before that, we discuss what we learned from United Healthcare CEO Andrew Witty’s congressional testimony on their ransomware attack in February. We also discuss a research article from JFrog on malicious Docker Hub repositories.
Read More - The 2024 Verizon DBIR
This week on the podcast, we cover a nation-state backed attack against Cisco ASA appliances which Cisco TALOS themselves have dubbed “ArcaneDoor.” After that, we discuss a phishing tookit being used to target LastPass users before ending with a new way to deliver malware payloads using legitimate services.
Read More - Cisco ArcaneDoor Attack
This week on the podcast, we cover a report from the Department of Homeland Security’s Cyber Safety Review Board that analyzes Microsoft’s Exchange Online 2023 security incident in excruciating detail. Before that, we cover CISA’s new rules around cyber incident reporting and an unsealed indictment against 7 Chinese nationals.
Read More - A Postmortem of Microsoft’s Security Incident
This week on the podcast, we cover a Google initiative to kill off session hijacking attacks once and for all. Before that, we give an analysis of CVE-2023-3400, the Palo Alto zero-day vulnerability currently under active exploit. Additionally, we discuss a recent white paper from CISA on securely deploying artificial intelligence systems.
Read More - Ending Session Hijacking
This week on the podcast, we cover a research post that describes a code injection vulnerability caused by the way nearly every high level programming language runs on Windows. We also discuss a series of vulnerabilities in LG televisions that allow remote attackers to root the device before ending with a chat about new adversarial […]
Read More - BatBadBut What?
This week on the podcast, we cover a software supply chain attack years in the making that was days away from a devastating global impact. After that, we cover Facebook’s Project Ghostbusters and its impact on user privacy before ending with another software supply chain attack that successfully compromised developers in the gaming world.
Read More - Bad Month for Software Supply Chains
This week on the podcast we discuss a vulnerability in required commercial truck hardware that could enable an automatically propagating worm across the entire US. Before that, we cover Apple’s “un-patchable” vulnerability in their M-series processors as well as a vulnerability that could let attackers unlock hotel room doors at will.
Read More - Trucking Worms
This week on the podcast, we’re joined by Ryan Estes, a member of WatchGuard’s Zero-Trust Application Service classification team and resident ransomware expert to discuss the wild month in ransomware news. We start the episode with a story about a fake ransomware operator that scammed cybercriminals out of tens of thousands of dollars before discussing […]
Read More - A Wild Month in Ransomware
Check out LockBit 3.0 on our new Ransomware Tracker Beta! Hear more about Operation Cronos on The 443 Podcast. If you’ve followed the ransomware space for the past few years, it’s very likely you’ve heard of LockBit. If you don’t follow the cybersecurity landscape, there’s still a good chance you’ve heard of them or at […]
Read More - Operation Cronos: A Breakdown of the LockBit Disruption
This week on the podcast, we cover an international law enforcement takedown of the LokBit ransomware group’s infrastructure. After that, we cover a novel malware delivery vector involving an IoT “toy.” We end the podcast by covering the latest White House Executive Order addressing cybersecurity in critical infrastructure.
Read More - Locking Up LockBit
This week on the podcast we cover Canada’s attempt to ban the Flipper Zero. Before that, we review a recent research post on a new class of vulnerability on the Ubuntu operating system. We end the episode with a chat bout a the impacts of artificial intelligence on data security. Menlo Report on Business AI […]
Read More - Flipping Out Over Flipper Zero
On February 2nd, remote access software vendor AnyDesk disclosed they had been the victim of a cyberattack where an unknown threat actor obtained access to production systems. AnyDesk appears to have contained the incident before the adversaries were able to leverage their access into a supply chain attack against AnyDesk customers but out of an […]
Read More - AnyDesk Remote Access Vendor Compromise
This week on the podcast, we cover a recent news post about an army of 3 million compromised toothbrushes taking down a Swiss website, causing millions in damages. After that, we discuss the United States DOJ’s latest botnet takedown, this time targeting Volt Typhoon. We end the episode by walking through a CISA joint-publication giving […]
Read More - Could a Toothbrush Botnet Happen?
This week on the podcast, we cover Apple’s recent announcement describing how they will comply with the European Union’s new Digital Markets Act and what that means for the iPhone walled garden. Before that, we cover a databreach at Mercedez-Benze thanks to an alternative authentication method. Additionally, we cover the roundup of vulnerabilities in Ivanti’s […]
Read More - A Door in Apple’s Walled Garden
This week on the podcast, we cover two “Blizzard” threat actors targeting governments and private organizations. We also give an update to the SEC’s compromised Twitter/X Account, and then end with a discussion of an EU program designed to improve their citizen’s privacy while browsing the internet.
Read More - A Blizzard of Threats
This week on the podcast, we review a CISA and FBI joint advisory on the Androxgh0st malware. Before that we cover recent Volt Typhoon activity targeting SMB routers exposed on the internet. We end the episode with a fun research blog post about a series of flaws in an Indian insurance provider.
Read More - Androxgh0st Analysis
This week on the podcast, we review NIST’s new publication that defines a taxonomy for how we talk about Adversarial Machine Learning. Before that, we cover a recent discovery of threat actors retaining access to Google accounts even through a password reset. We round out the episode with an account compromise that lead to a […]
Read More - NIST Tackles Adversarial AI
This week, we cover a password compromise that lead to a mobile telco in Spain losing control of their IP address space. We also give a quick update on the Lapsus$ ringleader’s court case before discussing a recently discovered macOS backdoor malware that evades most endpoint protection. We end the episode by covering Microsoft’s research […]
Read More - RIPE for the Taking
This week on the podcast, we cover a supply chain attack against one of the largest hardware cryptocurrency wallet manufacturers. After that, we discuss the latest Apache Struts vulnerability under active exploit by threat actors. We end the episode with our thoughts on a research blog post about a set of threat actors using an […]
Read More - Hacking the Crypto Supply Chain
This week on the podcast, we cover a new unauthenticated keystroke injection vulnerability in the Bluetooth implementation on nearly every type of device. After that we discuss Logofail, a suite of vulnerabilities in most UEFI boot implementations that could let threat actors easily hide their tracks. We end by covering a recent CISA advisory on […]
Read More - Bluetooth Busted
This week on the podcast we discuss our cybersecurity predictions for 2024. We’ll cover each of the 6 predictions for the coming year including the trends behind them and how to protect your organization if they come true!
Read More - Our 2024 Security Predictions
This week on the podcast, we look back to our 2023 security predictions and grade ourselves on how well we were able to see the future. We’ll go through each of our 6 predictions, explain the trends that fueled them, and then provide either evidence that they came true or discuss reasons why they may […]
Read More - Grading our 2023 Security Predictions
This week on the podcast, we dive in to the EU’s Network and Information Security directive update, aka NIS2. We’ll cover who might be impacted and what to expect in terms of requirements in the coming year. Before that, we give an update to on the latest Scattered Spider threat actor activity followed by an […]
Read More - What to Expect from NIS2
This week on the podcast, we cover an analysis from Mandiant on an attack lead by the Russian state-sponsored threat actor Sandworm that came alongside missiles strikes against Ukraine. Before that, we review Okta’s post mortum from their recent cyber incident. We end the episode by discussing udpated research from Jamf on a North Korean […]
Read More - Combined Cyber and Kinetic Warfare
This week on the podcast we cover an Executive Order from the US White House on the topic of Artificial Intelligence. After that, we discuss the latest CISO that has found themselves in hot water with the law. We then cover an update to the Common Vulnerability Scoring System and end with a researcher claiming […]
Read More - The White House Tackles AI
This week on the podcast, we review a thorough unmasking of Octa Tempest, the threat actor beind the MGM and Caesars Entertainment attacks in September. Before that, we give an update on the Cisco IOS XE vulnerability that head to an implant installed on thousands of exposed devices. We round out the episode with an […]
Read More - The Threat Actor That Hacked MGM
This week on the podcast, we cover CISA’s newly updated whitepaper on guidance for both software manufacturers and customers on the principals of secure-by-design and secure-by-default. Before that, we cover the Cisco IOS XE vulnerability that is under active exploitation in the wild, give an update on the EPA’s efforts to regulate cybersecurity practices in […]
Read More - CISA’s Secure by Design Whitepaper
This week on the podcast, we cover the recent HTTP/2 protocol vulnerability that lead to the largest DDoS attack ever recorded by CloudFlare. After that, we discuss Microsoft’s announcement about the deprecation of VBScript and the impending removal of NTLM. We then cover a collection of data allegedly stolen from the genealogy website 23 and […]
Read More - Microsoft is Killing NTLM
This week on the podcast, we go through the latest Internet Security Report from the WatchGuard Threat Lab. We’ll cover the top malware and network attack trends from Q2 2023 impacting small and mid-market organization globally before ending with defensive tips anyone can take back to their company.
Read More - Q2 2023 Internet Security Report
This week on the podcast, we discuss an alert from CISA on nation state threat actors embedding malware into legacy Cisco router firmware. After that, we cover a research post on malicious advertisements served up via Bing’s ChatGTP integration. We then end with an analysis of North Korea’s Lazarus group’s latest social engineering techniques.
Read More - Bing Chat Malvertising
This week on the podcast, we get up to speed on the MGM and Caesars Entertainment ransomware incidents from the previous week. After that, we take a deep dive into a blog post from Meta’s application security team for their VR headsets. After that, we cover Microsoft’s analysis of an ATP’s pivot from email to […]
Read More - Meta’ One Good Deed
This week on the podcast, we cover Microsoft’s final report on their July incident involving nation-state actors compromising enterprise email accounts. After that, we discuss a zero-day, zero-click vulnerability in iOS being actively exploited in the wild before ending with a chat about an upcoming change to how Android handles CA certificates.
Read More - iPhone’s Latest 0-Day
This week on the podcast, we cover the FBI-lead, multinational takedown of the Qakbot botnet of over 700,000 victim devices. After that, we cover two android malware variants including one targeting victims in southeast Asia and another built by the Russian GRU.
Read More - The Qakbot Takedown
This week on the podcast we cover the latest evolutions of the North Korean threat actor Lazarus before covering an actively-exploited 0day vulnerability in the popular unarchiver WinRAR. We end the episode with an AI-related attack that doesn’t actually use AI.
Read More - Weaponizing WinRAR
This week on the podcast we cover the FCC’s proposal for a security assurance labeling program for IoT devices. Before that, we discuss the latest AI research challenge hosted by DARPA as well as some research into a novel attack against the AI/ML supply chain.
Read More - U.S. Cyber Trust Mark
On this week’s episode, we chat about some of our favorite talks from this year’s Def Con security conference. We’ll cover several topics including artificial intelligence, hacking mobile point of sale devices, and how worried we should or shouldn’t be about cyber warfare.
Read More - Def Con 2023 Recap
In this special end-of-week episode of The 443, we cover some of our favorite talks from this year’s edition of the BlackHat cybersecurity conference in Las Vegas. We’ll discuss the trends we saw and summaries of interesting topics including AI, nation state warfare, and improving cyber defense.
Read More - BlackHat 2023 Recap
This week we look back to an episode that originally aired in May 2021 where we remember a Def Con legend then dive in to two web browsing security acronyms. Keep an eye out later this week as we come to you from this year’s Black Hat and Def Con cybersecurity conferences!
Read More - What Is Same-Origin Policy? Replay
This week on the podcast, we cover the latest evolutions of the decade-old Qakbot malware including changes in how attackers deliver it. After that, we give an update on the SEC’s new rules around mandatory security disclosure. We then end by reviewing CISA’s analysis of Risk and Vulnerability Assessments they completed for their constituents in […]
Read More - Qakbot Qacktivity
This week on the podcast, we give an update on last week’s discussion around a China-based APT targeting government organizations. After that, we cover the latest uses of generative AI like ChatGPT by malicious hackers. Finally, we end with a report from Google on their efforts around Red Teaming Artificial Intelligence systems.
Read More - Red Teaming AI Systems
This week on the podcast we cover two stories that came out of Microsoft’s July Patch Tuesday. The first involves an incident within Microsoft that lead to foreign cybercriminals compromising the email accounts of multiple government agencies. The second story involves an actively exploited 0-day vulnerability in Office that at the time of recording, remains […]
Read More - New Microsoft Office 0-Day
This week on the podcast, we cover WatchGuard Threat Lab’s Internet Security Report for Q1 2023. Throughout the episode, we’ll discuss the key trends for cyber threats impacting small and midsize organizations globally including the top malware and network attach detections as well as a look specifically at the endpoint. We round out the episode […]
Read More - Q1 2023 Internet Security Report
On this week’s podcast we discuss a recent analysis on the risks of GitHub RepoJacking. After that, we dive in to the Barracuda 0-day that China-based threat actors are actively exploiting as well as a novel command and control distribution method for a separate China-based APT.
Read More - RepoJacking
On this week’s episode we discuss the newly named threat actor Cadet Blizzard, including their typical tools, tactics and procedures. We also cover CISA’s newest binding directive to federal agencies. Before that, we give an update on exploited MOVEit Transfer servers and the latest Bitcoin laundering technique.
Read More - A New Russian APT
This week on the podcast we cover a supply chain attack of sorts against Minecraft gamers. After that, we cover a vulnerability in MOVEit Transfer that threat actors are exploiting in the wild to steal data and deploy ransomware. Finally, we wne with our review of the latest Verizon Data Breach Investigations Report (DBIR).
Read More - Minecraft Mod Malware
This week on the podcast, we give a quick update on the latest Volt Typhoon activity before covering a newly for sale EDR bypass tool. After that, we discuss Gigabyte’s decision to rootkit their own motherboards before ending with a new macOS vulnerability.
Read More - How Not to Update Software
This week on the podcast, we cover Microsoft’s latest refresh of naming conventions for advanced persistent threat (APT) actors worldwide, as well as an update on two specific threat actors and their latest tactics. We also cover a ransomware event targeting a biotechnology company with an interesting twist.
Read More - Naming APTs
This week on the podcast, we cover the recent TikTok ban coming from the state of Montana and discuss whether it was justified and what the potential security impact is. Before that, we give an update on two US Supreme Court cases that were poised to potentially strip away Section 230 protections. We also highlight […]
Read More - TikTok is Banned, Kind Of
A few days ago, I was scrolling through Twitter and came across a post by the MalwareHunterTeam briefly discussing a new Ransomware group – Rhysida. A lack of results from a Google search shows this is a newer group prepping to start operations. I grabbed a sample and downloaded it, and the executable confirmed that […]
Read More - Scratching the Surface of Rhysida Ransomware
This week on the podcast, Marc kick’s Corey off the podcast and interview’s ChatGPT to learn its thoughts on AI applications in cybersecurity, both on offense and defense.
Read More - An Interview with ChatGPT
This week on the podcast, we cover two new malware research pieces, including the latest evolution of a delivery vehicle as old as time. After that, we cover recent regulations in the healthcare industry that have a chance to push the industry to a more secure future.
Read More - Securing Healthcare Tech
This week on the podcast, we cover a recently discovered macOS malware attack that uses a multi-stage delivery mechanism. Before that, we discuss an actively-exploited vulnerability in the print management software PaperCut, as well as an update on the 3CX supply chain attack.
Read More - Rustbuckets and Papercuts
This week’s podcast comes from the WatchGuard Apogee partner conference for the Americas where we bring on special guests Kevin Willette of Verus Corporation and Neil Holme of Impact Business Technology to discuss the challenges and opportunities MSPs and MSSPs will face in the coming years. This is the first of a multipart series where […]
Read More - MSPs Around the World – Americas
This week on the podcast, we cover two new publications out of CISA. First, we dive into CISA’s guidance to manufacturers and customers on products that are secure-by-design and secure-by-default. Next, we discuss CISA’s latest Zero Trust Maturity Model which any organization can use to gauge how far along they are on the ZTA path […]
Read More - Zero Trust Maturity Model 2.0
This post arrives later than usual, but as they say, “Better late than never.” Researchers and the media have highlighted various unique, interesting, or destructive vulnerabilities in the last few weeks. We decided to pick three of these vulnerabilities and talk about them. One was patched with Microsoft’s Patch Tuesday in March; another affects the […]
Read More - Cybersecurity News: A Trio of Vulnerabilities, BreachForums Admin Arrested, Hundreds of Ransomware Victims, and The Rise of AI
This week on the podcast, we discuss another cybercrime marketplace takedown dubbed Operation Cookie Monster. After that, we discuss Microsoft’s attempts to limit the distribution of a popular hacking toolkit. Finally, we discuss a recent analysis by Dr. Ken Tindell of Canis Automotive Labs around how criminals were able to steal his friend’s Toyota Rav4. […]
Read More - Operation Cookie Monster
This week on The 443, we discuss the latest software supply chain attack with a potential blast radius of thousands of organizations. Then we cover a new protocol vulnerability in the Wi-Fi wireless standard before ending with some research into insecure Microsoft Azure applications.
Read More - Another Software Supply Chain Attack
3CX created the desktop phone app 3CXDesktopApp and now finds itself in the middle of a supply chain attack. One that perhaps went on for too long. As a recognized company in the softphone space 3CX provides services to many large companies including Honda, Coca cola, BMW, Holiday Inn among others according to […]
Read More - 3CX Supply Chain Attack
This week we have all the acronyms as we cover a joint publication by CISA and the NSA with Identity and Access Management (IAM) best practices. We then cover some new proposed cybersecurity rules out of the Securities and Exchange Commission (SEC) before ending with an FBI takedown of a popular hacking forum.
Read More - The NSA’s Guidance on Securing Authentication
It’s Monday, and there’s no better way to start a new week than with some cybersecurity-related news. So, if you need an excuse to procrastinate a bit more, allow us to fill that void. For this iteration, we made a few minor improvements, as always. In addition to the table of contents from last time, […]
Read More - Cybersecurity News: LastPass Incident Revealed, White House Issues Cybersecurity Strategy, FBI Purchases Leaked USHOR PII Data, and a Slew of Other Breaches
On this week’s episode we look back to our initial monologue on Section 230 protections that allow the social media and the internet as a whole to function. We cap off the episode replay with a new discussion on a recent supreme court case that has the potential to dramatically impact the internet as […]
Read More - An Update on Section 230
On today’s episode, we cover two new sets of cybersecurity regulations, fresh off the heels of the White House’s National Cybersecurity Strategy publication, targeting different critical infrastructure sectors in the United States. We’ll also cover the latest in nation state activity targeting network connectivity appliances and end with some fun research into an oldie but […]
Read More - Here Come The Regulations
This week’s episode is all about the White House’s recently released National Cybersecurity Strategy. We’ll walk through the strategy from top to bottom and discuss the key elements most likely to impact individuals and organizations as well as our overall thoughts on the direction the US Federal Government is planning to take.
Read More - US National Cybersecurity Strategy
A new week, a new month, and a new Cybersecurity News post! This iteration contains a whopping eight (8) stories covering the last two to four weeks. Since cybersecurity is a diverse field of assorted specializations, we attempt to match that with various stories touching on all aspects of cybersecurity. This time we cover a […]
Read More - Cybersecurity News: Free Cybersecurity Training, TrickBot Group Exposed, Major GoDaddy Breach, and Russia to Legalize cybercrime?!
This week on the episode we have a discussion about stress related issues impacting cybersecurity professionals and ways to combat them. Before that, we cover the latest news including new 0click exploit protection from Samsung, the latest update on GoDaddy’s security woes, and Twitters latest erratic move.
Read More - Cybersecurity’s Toll on Mental Health
In today’s episode, we discuss a recent court case resulting in the succesful conviction of a Russian national tied to breaking in to several publicly traded US companies. We also cover the latest details on the ESXiArgs ransomware attacks that have been impacting organizations globally as well as the latest CISA alert on nation-state ransomware […]
Read More - Successfully Prosecuting a Russian Hacker
Welcome to another iteration of Cybersecurity News. The fairly new and unorthodox, semi-monthly news article that highlights a handful of noteworthy cybersecurity-related stories and provides extra references and resources to do further research if you desire. We aim to solidify a more concrete release schedule going forward and will release more information once we have […]
Read More - Cybersecurity News: Automated Ransomware Attacks, U.S. No Fly List Leaked, and A.I. Detecting A.I.
On this week’s very special episode of the podcast, we sit down with Matt Lee, Calvin Engen, and Scott Williamson, three MSP security and business experts for a Q&A panel in front of a live audience! We’ll cover everything from how MSPs and MSSPs should address the cyber threat landscape to what vendors can do […]
Read More - Live Audience MSP Q&A Panel
Shortly after Putin launched his “special military operation” in Ukraine on February 24th, 2022, researchers from ESET published information about two novel destructive malware families – HermeticWiper and ISAACWiper. HermeticWiper was part of a three-pronged campaign that included a worm and pseudo-ransomware component known as HermeticWizard and HermeticRansom, respectively. HermeticWiper is the data-wiping component. ISAACWiper, […]
Read More - A Technical Analysis of ISAACWiper
This week on the podcast we cover the Common Vulnerability Scoring System (CVSS) including how it works and some of its limitations. Before that though, we discuss a recent survey on the risks of ChatGPT’s usage in cyberattacks and the latest activity from Lazarus, the North Korean government hacking operation.
Read More - What is CVSS?
On today’s episode, we cover a recent Department of Justice operation that resulted in taking down a major ransomware organization. After that, we cover two recent publications from CISA, the first on malicious use of legitimate RRM software and the second giving guidance to K-12 on how to address cybersecurity concerns.
Read More - CISA Warns of Weaponized RMM Software
Sifting through the most recent cybersecurity-related news may seem daunting, and keeping up with the latest developments is arduous. However, the WatchGuard Threat Lab is happy to filter through the latest cybersecurity news and highlight some stories we believe are important, noteworthy, or interesting. The goal is to focus on a few recent cybersecurity-related stories, […]
Read More - Cybersecurity News: ACLU Unveils Mass Surveillance Program, (More) Malvertising, and Breaches
In a sudden, stunning announcement today, the United States Department of Justice, the FBI, and federal agencies from 13 countries from Europol, announced the seizure of the transnational Hive ransomware operation. The seizure was part of a months-long operation that began in late July 2022 when the FBI infiltrated the Hive network. Deputy Attorney General […]
Read More - Law Enforcement Infiltrate and Seize Hive Ransomware Operation
Regarding malware, breaches, and the overall threat landscape, 2023 is off to a dynamic start. Malvertising (malicious advertising) continues to be a successful attack vector for hackers, especially from sponsored ads via Google searches. Jon DiMaggio released his long-awaited Ransomware Diary series beginning with the first iteration of the LockBit ransomware group. Also, a new […]
Read More - Cybersecurity News: Malvertising, Ransomware, and Alleged IRS Breach
This week on the podcast we cover a recently-disclosed vulnerability in the popular JavaScript library JsonWebToken. After that, we give an update to weaponizing ChatGPT, the currently free Artificial Intelligence chat bot that has made waves since it’s release in November. We round out the episode with a wave farewell to Windows 7 and Windows […]
Read More - The RCE Vulnerability That Wasn’t
Recently, researchers have observed threat actors using a website previously associated with the popular AR game, PokemonGo to distribute a remote access trojan (RAT). The method of delivery is a cleverly disguised game installer that includes a copy of the commonly used NetSupport Manager application, which on its own is technically a trusted application. The […]
Read More - When Trying to Catch ‘Em All, Leave This RAT Alone
This week on the podcast we cover a recent analysis by Mandiant on a Russia-based APT using a decade old botnet to deliver new attacks. Before that, we cover an update from LastPass about their most recent breach as well as the 200 million Twitter accounts leaked last week.
Read More - Reviving a Dead Botnet
This week on the podcast we discuss key findings from the WatchGuard Threat Lab’s Q3 2022 Internet Security Report. We’ll cover everything from the top malware threats to the latest network attack trends targeting small and midsize enterprises globally and give practical defensive tips that anyone can use to keep their organizations safe. [PowerPress]
Read More - Q3 2022 Internet Security Report
It’s that time of year for us to discuss the WatchGuard Threat Lab’s 2023 cyber security predictions! On this episode, we will cover the six predictions plus another two that didn’t make the cut as well as some defensive strategies to try and help stop them from coming true.
Read More - 2023 Security Predictions
This week on the podcast, we cover Apple’s latest announcement of expanded privacy and security features for their users. Before that, we cover a major breach in the Android ecosystem followed by a new Internet Explorer (yes, that still exists) 0-day vulnerability.
Read More - Apple’s New Privacy Expansion
On this week’s episode, we cover the latest in car hacking, this time involving a vulnerability that could have given remote attackers full control over certain Hyundai models’ doors, lights and engine. After that, we discuss the latest breach impacting a major password management app and how it’s different from previous ones we’ve seen. We […]
Read More - Hacking Hyundai
On today’s episode we cover a pair of alerts from the Cybersecurity Infrastructure and Security Agency (CISA), one detailing the tools, tactics and procedures from a prolific ransomware organization and another walking through a recent incident response engagement CISA completed with a federal agency. Before that though, we learn about what happens when you use […]
Read More - CISA Incident Response Learnings
This week on the podcast we dive into the world of attack surface management. We discuss what your attack surface is made up of including some areas you may not have thought of and then cover the best ways to reduce and ultimately protect it.
Read More - Attack Surface Management
The WatchGuard Security Team spends a lot of time chasing ransomware extortion groups throughout the dark web. So, it only fits that one of the newer ransomware extortion groups is named Endurance Ransomware. It appears this “group” is one individual known as IntelBroker, who has allegedly breached several entities of the US government and two […]
Read More - Endurance Ransomware Claims Breach of US Federal Government
This week on the podcast we take a look back at our 2022 cybersecurity predictions and give ourselves a grading on how well we did. From cyber insurance to space hacks, we’ll cover each of the 6 predictions we made last December and discuss why we think they did or did not come to fruition. […]
Read More - 2022 Cybersecurity Predictions Recap
On this episode we cover the much anticipated OpenSSL vulnerabilities that were disclosed and patched on November 1st and why the 6 year streak of no critical issues continues. After that, we dive back in to election security and the hacking activity that could have the most impact. We end with an update from Apple […]
Read More - Why OpenSSL Downgraded Their Vulnerability
This week on the podcast we cover CISA’s freshly-released Cybersecurity Performance Goals (CPGs) designed to help smaller organizations bridge the gap between frameworks and practical implementation. After that, we discuss a new bill working its way through the US Senate designed to address open source software security risks. Finally, we end with a research post […]
Read More - CISA’s Cybersecurity Performance Goals
This week on the podcast, we cover another remote code execution vulnerability that looks extremely concerning on the surface but might be less serious in reality. After that, we cover two research articles by Microsoft on ransomware campaigns including defensive takeaways for all organizations.
Read More - Ransomware TTPs Deep Dive
This week on the podcast we cover a proposed program from the White House to create an Energy Star-like label for cybersecurity in consumer products. Before that, we cover two other updates from the federal government including a new open source tool from CISA and the latest reincarnation of Privacy Shield.
Read More - Cyber Energy Star
This week on the podcast, we focus on highlighting WatchGuard’s Q2 Internet Security Report, covering the latest threat trends and what you can do to avoid them. However, we also pack in our security news segment, with an Optus breach update from an Australian IT and security expert and WatchGuard Partner, the latest on the […]
Read More - Q2 Threats and Guilty CSOs
This week on the podcast, we cover an Optus data breach that could affect over 10 million Australian customers, and what they should do to protect themselves. We highlight a new malware-as-a-service (MaaS) information stealer that lowers the cost and technical bar for cybercriminals. Finally, we end with some good news about how the FBI […]
Read More - Optus Opts Out of PII Protection
Microsoft has published guidance on new zero-day vulnerabilities affecting all versions of Microsoft Exchange Server released since 2013. The combination of two vulnerabilities allows an attacker to remotely execute code (known as a remote code execution or RCE flaw) on vulnerable versions of Exchange. If an attacker has authenticated access to the server, they can […]
Read More - Two Microsoft Exchange Server Zero-Day Vulnerabilities
This week on the podcast, we cover Uber’s most recent security incident and the alleged individual behind it. After that, we dive into the world of gas station operational technology and potential security weaknesses in one tool. Finally, we end with a chat about the FBI CISO Academy and how the FBI as a whole […]
Read More - An Uber Hack
This week on the podcast we cover a court case that is attempting to hold the ex-CISO of a popular tech company accountable for their actions involving a data breach dating back to 2016. Before that though, we dive in to a novel command and control (C2) method as well as the latest commoditization of […]
Read More - Are CISOs Legally Accountable for Security?
This week on the podcast we sit down with Ryan Estes, a malware analyst on the WatchGauard Threat Lab team, to discuss what it takes to rapidly differentiate malware from goodware. In this interview, we discuss what it takes to get in to malware analytics, popular tools to help with the task, and resources anyone […]
Read More - A Day in the Life of a Malware Analyst
This week on the podcast, we cover the big whistleblower complaint against Twitter including our hot takes on who to believe. We then cover an FBI alert on evasion techniques cyber criminals are deploying in their authentication attacks before finishing with a highlight of a very convincing phish.
Read More - The Twitter Thing
This week on the podcast we review our time at this year’s Black Hat and Def Con cybersecurity conferences in Las Vegas. We’ll cover how the WatchGuard CTF contest went this year and discuss takeaways from a few of the briefings we attended.
Read More - 2022 Black Hat and Def Con Recap
This week on the podcast, we give our preview of the Black Hat and Def Con cybersecurity conferences, aka Hacker Summer Camp. Throughout the episode, we’ll discuss the briefings and panels we’re most excited to see and what we hope to get out of them. If you’re not able to attend either conference in person […]
Read More - Hacker Summer Camp 2022
This week on the podcast we discuss the shifting landscape of phishing attacks in the wake of Microsoft’s efforts to block malicious Office macros. We then cover a private organization that has been found not just selling exploit tools but also participating in offensive cyber operations. We end the episode with a review of IBM […]
Read More - Private Sector Offensive Actors
This week on the podcast, we discuss the current cyber skills gab and a federal program designed to help combat it. After that, we dive in to the American Data Privacy protection Act and what it potentially means if passed by US Congress. We end this week with a quick update on Microsoft’s attempts to […]
Read More - USA’s Answer to GDPR
This week on the podcast we cover the latest in car hacking research, this time targeting vulnerabilities in remote keyless entry. We then dive in to Microsoft’s latest research on Adversary in the Middle (AitM) attacks and end with key findings from the latest WatchGuard Threat Lab quarterly Internet Security Report.
Read More - Rolling PWN
This past week, a hacker by the name of ChinaDan allegedly breached the Shanghai National Police (SHGA) database and has put the nearly 23 TB of data up for sale for 10 bitcoin (BTC), or a little over $200k USD as of this writing. ChinaDan claims the data contains “information on 1 Billion Chinese national […]
Read More - Over a Billion Records Leaked in Shanghai National Police Database Hack
The LockBit ransomware group has unveiled a new website – LockBit 3.0 – to host their ransom extortions and data leaks. The website includes several new features, including an unprecedented bug bounty program to assist the group in securing their site; acceptance of the privacy cryptocurrency, Zcash; and the addition of receiving payments from users […]
Read More - LockBit Ransomware Group Introduces Bug Bounties and More
This week on the podcast, we discuss two recent security reports, one on the topic of open source software and the other on “insecure by design” in the Operational Technology (OT) space. We go through the key findings from each report and what our thoughts are on their accuracy within the real world. We end […]
Read More - Grading Gartner’s Guesses
In celebration of our 200th episode, this week on the podcast we take a look back at the last few years and revisit some of our favorite episodes. Along the way, we’ll give updates on a few of our cybersecurity predictions from years past that took just a little bit longer than anticipated to come […]
Read More - 200th Episode Extravaganza
This week on the podcast we cover the latest and most bizarre ransomware extortion demand we’ve seen in recent memory. Before that though, we cover the latest updates on nation state hacking activity including threats of escalating attacks leading to physical retaliation.
Read More - Robux Ransomware
This week on the podcast we cover two fresh 0-day vulnerabilities, one in Windows and another in Atlassian’s Confluence, both under active exploitation in the wild. Additionally, we cover Costa Rica’s no good, terrible month in Cybersecurity.
Read More - 0-Days for Days
This week on the podcast, we discuss the line between ethical security research and malicious activity thanks to a compromised open source software package. After that we cover the latest industry to fall victim to Ransomware and end by highlighting a 0-click vulnerability in Zoom’s message system discovered by Google Project Zero.
Read More - Package Hijacking
WatchGuard’s Product Security Incident Response Team (PSIRT) has launched our public PSIRT page to provide a consolidated resource where network administrators can find advisories and information about security vulnerabilities in WatchGuard products, as well as WatchGuard’s investigations into industry-wide security issues that may impact our products or services. Our PSIRT page also provides information for […]
Read More - WatchGuard Launches PSIRT Page
This week on the podcast we sit down for a chat with Matt Lee, Sr. Director of Security and Compliance at Pax8 and well-known cyber security educator, to discuss security strategies for MSPs and midsize enterprises in the face of a dynamic threat landscape. We cover everything from picking a framework to getting buy in […]
Read More - Building Security Strategies with Matt Lee
This week on the podcast we walk through CISA alert AA222-131A which gives bulleted guidance to MSPs and customers of MSPs on how to navigate their relationship security as threats targeting service providers continue to grow. We’ll walk through the list and hit each recommendation and give our own guidance on top of them for […]
Read More - CISA Guidance for MSPs
This week on the podcast we discuss the latest rumblings around the return of the prolific ransomware-as-a-service organization REvil. Before that though, we dive in to the latest tools, tactics and procedures of the Lazarous nation state hacking group as well as a recently discovered form of fileless malware evasion.
Read More - The REturn of REvil?
This week on the podcast, we dive into CISA’s list of the 15 most exploited vulnerabilities in 2021. We’ll walk through each flaw and give a refresher on their history and how attackers have exploited them. After that, we cover the latest ransomware-as-a-service threat that has victimized over 60 organizations worldwide before ending with a […]
Read More - Most Exploited Vulnerabilities of 2021
This week on the podcast we cover a critical and easily-exploited vulnerability in how some recent versions of Java handle cryptography. We also discuss the latest in a series of alerts from CISA and international intelligence organizations on cyber threats to critical infrastructure. Finally, we end with a condensed overview of the latest internet security […]
Read More - Psychic Signatures
This week on the podcast, we cover the latest evasion and persistence techniques from the state-sponsored threat actors known as Hafnium. Then, we dive into the world of ICS and SCADA devices to discuss the latest joint-agency alert from the US Government. We then round out the episode by highlighting some recent research into spoofing […]
Read More - Hidden Hafnium
This week on the podcast we discuss one of the most rampant yet easily resolved risks facing many organizations today, not installing vendor-supplied security fixes. We’ll cover some of the reasons why organizations might fall behind on patching as well as the potentially serious consequences. After that, we cover the latest 0-day Chromium vulnerability before […]
Read More - Patch Management Lag
When talking to IT and Security professionals, everyone seems to know they shouldn’t overly-expose management portals. And yet, every year we learn some new statistic showing tens of thousands of devices or software products with management portals exposed on the Internet. In hopes of changing this trend, this article talks about why management portals sometimes […]
Read More - For the Love of InfoSec, Don’t Over-Expose Administrative Management Portals
This week on the podcast we cover the hacking organization Lapsus$ including their tactics, targets, and how they ended up with several members arrested last week. After that, we cover the cyber cold war and threats of Russian revenge attacks against the US energy sector that prompted classified meetings with potentially targeted organizations.
Read More - The Rise and Fall of Lapsus$
At WatchGuard, we understand the importance of sharing threat intelligence with the information security (infosec) community when safe and appropriate. Not only does this information sharing help to directly defend against known threats, but it also helps the community at large learn from the attacks found in the wild, and appropriately adjust detection and defense […]
Read More - Sharing Cyclops Blink Threat Intelligence with the Community
This week on the podcast, we cover a CISA alert on securing satellite communications (SATCOM) in the wake of several recent incidents involving providers and networks in eastern Europe. After that, we check in on the TSA’s cybersecurity rules for pipeline distribution networks and how adoption is going so far in the industry.
Read More - SATCOM Security
This week on the podcast, we cover last week’s Executive Order from the White House that lays the foundation for a United States Central Bank Digital Currency, or CBDC, and what it means for the future of Cryptocurrency. We also discuss recent research from Mandiant on APT41, a Chinese threat actor that has recently turned […]
Read More - US-Backed Cryptocurrency
This week on the podcast we cover the recent leaks highlighting the inner workings of the Conti ransomware group that started with chat logs and grew to entire source code dumps. We then round out the episode by discussing the recent Nvidea breach and how some of the stolen information might fuel future attacks.
Read More - Conti Leaks
5G didn’t put malware on these Mazda’s entertainment systems but many Seattle Mazda drivers couldn’t change their radio station after turning it to the local NPR station, KUOW. As one reddit user put it, “the whole audio system and Bluetooth just keeps trying to reboot.” Some users also reported they couldn’t use their backup cameras. […]
Read More - 5G Didn’t Break Your Car
This week on the podcast we dig back into our archives for an episode that originally aired back in July 2020 where we discussed one of our analysts first-hand research into facial recognition biases.
Read More - Rewind: Can We Trust Facial Recognition
Microsoft’s monthly Patch Tuesday already occurred this month, so you know what that means – more disclosed vulnerabilities. This iteration of patches included fixes for a combined 70 vulnerabilities, including one zero-day. Thankfully, none of these fall into Microsoft’s “critical” category. However, there are four Elevation of Privilege vulnerabilities targeting the Windows Print Spooler service […]
Read More - SpoolFool: Windows Print Spooler Fooled Again
This week on the podcast we cover a cryptocurrency heist that abused the backbone of the internet to steal millions of dollars of coins. In related news, we also cover the FBI’s new Virtual Asset Exploitation Team and their focus on tracking cryptocurrency-related cybercrime as well as a recent alert on business email compromise from […]
Read More - BGP-Powered Crypto Theft
This week on the podcast we cover Russia’s latest crackdown on cybercriminals within their borders and try to answer the “why now?” question. We also discuss a multi-billion dollar cryptocurrency recovery by the US Justice Department including the arrest of two New Yorkers allegedly responsible for the 2016 Bitfinex hack.
Read More - Russia, Fighters of Cybercrime?
In early 2020, during the emergence of the COVID-19 pandemic, researchers discovered a novel malware named Oski Stealer, capable of stealing browser data such as cookies, history, payment information, and autofill information, as well as cryptocurrency wallets, login credentials of applications, and Authy 2FA information. It can also take screenshots of your desktop and perform […]
Read More - New Oski Stealer Variant, “Mars Stealer”, Targets Credentials, Crypto, and 2FA
The US IRS has plans to use a 3rd party identification system to prevent tax-related identity theft. The IRS plans to contract with ID.me to identify people using, among other factors, face recognition. James Hendler, professor of Computer, Web and Cognitive Sciences, wrote about some issues with the IRS’s plan. How will the data be […]
Read More - Face Recognition and Privacy Concerns Works Its Way Into Taxes
This week on the podcast, we cover the heist of $322 million in cryptocurrency from the distributed exchange Wormhole, including a long discussion on the why it feels like cryptocurrency is still the wild west of technology. After that, give an update on our brief mention in last week’s episode about North Korea’s internet seemingly […]
Read More - Hacking Back at North Korea
This week on the podcast, we cover Pwnkit, a privilege escalation vulnerability impacting almost every modern Linux release worldwide. We also dive in to the world of macOS malware with DazzleSpy, a remote a remote access trojan targeting Hong Kong pro-democracy advocates. Finally, we end with an update on North Korea’s Lazarus APT and their […]
Read More - The Pwnkit Problem
This week on the podcast we discuss the latest Internet Security Report from the WatchGuard Threat Lab. Built with threat intelligence gathered from tens of thousands of Firebox UTM appliances that have opted-in to sharing data, the quarterly report lets us talk about the latest malware and attack trends targeting organizations globally. On this episode, […]
Read More - Q3 2021 Internet Security Report
Log4Shell attacks have spread throughout the Internet due to the ease with which attackers can perform them. The WatchGuard Threat Lab sees a sample of these attacks from our customers’ perspectives when they opt to provide anonymized threat intelligence data from their Fireboxes. This limited data, along with our analysis, gives us a unique opportunity […]
Read More - Log4j Becomes The Highest Detected Vulnerability Days After Release
This week on the podcast we give a quick update to the Log4Shell saga after the researchers detected the first significant campaign that uses the critical vulnerability. After that, we dive in to the world of carding marketplaces where cybercriminals buy and sell stolen credit card information and discuss possible reasons for why these marketplaces […]
Read More - The Death of the Carding Marketplace
This week on the podcast we give an update on log4j2 and it’s most recently-disclosed vulnerabilities before covering a recent report on credential stuffing by the New York Attorney General. Then, we discuss this recent article in DarkReading on whether or not cybersecurity jobs should be considered professional or vocational.
Read More - Is Cybersecurity Vocational?
Iranian researchers at Amnpardaz security firm have discovered rootkits in HPs iLO (Integrated Lights-Out) management modules. These optional chips are added to servers for remote management and grant full high-level access to the system. This includes the ability to turn the server on and off, configure hardware and firmware settings, and additional administrator functions. The […]
Read More - HP iLO and the Newly Discovered iLOBleed Rootkit
The internet came by storm. Yes, for years it wasn’t accessible to the major populace, but over time it found its way into the office, school, home, and now more specifically into the living room. With the evolution of the internet came few rules. In came the market makers who began to define basic expectations […]
Read More - Post-Purchase Monetization of the TV and Your Diminishing Privacy
Every so often, there is a phish that stands out because of its brazenness. Today, we came across a bank phish that requested a few verification details: Username and Password Social Security Number Email address and email password used for 2-Step verification Security Questions: What was your dream job as a child? Who is your […]
Read More - Give Us Your SSN, Your Email Password, and Your Dream Job
Much of what we see exploiting the log4j2 vulnerability, CVE-2021-44228, appears like a scan for the vulnerability, not necessarily exploitation. However, our own honey pot https://github.com/WatchGuard-Threat-Lab/log4shell-iocs has seen activity from this exploit to install coin miners. In one of the first targeted cases for this vulnerability, a ransomware gang have exploited VMware vCenter with Conti […]
Read More - Active Compromises of vCenter Using The Log4J Vulnerability
This week we take a deep dive into CVE-2021-44228, better known as Log4Shell, a critical vulnerability in the massively popular log4j2 logging library for Java applications. We discuss how the flaw came about, how it works, and why this specific issue has the potential to cause lasting headaches for the security industry for years to […]
Read More - Log4Shell Deep Dive
Politico published a short piece about Kamala Harris’s hesitancy with Bluetooth devices. They considered this a bit amusing, perhaps considering her paranoid based on their tone. While the article’s content was light, it did discuss some important security concerns that any Jane Doe might care about. Besides Kamala Harris opting for wired headphones instead of […]
Read More - Bluetooth Is Safe Enough For You
As we move in to the end of the year it’s time for us to discuss WatchGuard Threat Lab’s 2022 cybersecurity predictions. While many of our predictions tend to come off as extreme, they’re all grounded in the trends that we’ve been following and what we expect to see continue into the coming year. If […]
Read More - Our 2022 Security Predictions
[Updated 13-12-2021: Additional information for WatchGuard customers] On Thursday, security researchers disclosed a critical, unauthenticated remote code execution (RCE) vulnerability in log4j2, a popular and widely used logging library for java applications. CVE-2021-44228 is a full 10.0 on the CVSS vulnerability scoring system due to a combination of how trivial the exploit is and damaging […]
Read More - Critical RCE Vulnerability in Log4J2
Its getting to be the end of the year which means its time to take a look back at WatchGuard Threat Lab’s 2021 security predictions and give ourselves a grading on how well we did! On this episode, we’ll go through our 8 predictions for 2021, recap the trends that fueled them, and discuss either […]
Read More - 2021 Security Predictions Grading
We have seen interpolation in the news concerning a recent court case. Here we cover what interpolation does to an image, not only because of the recent news but also because face recognition uses interpolation to better recognize a face – something we have covered in the past. Interpolation means to take pixels in an image and calculate what their […]
Read More - Dangers of Bicubic Interpolation In Pictures
This week on the podcast we discuss how a recent CISA alert on specific threat actor activity tipped off a separate adversary, leading to a new wave of attacks against vulnerable systems across multiple industries. We also cover the latest US and international law enforcement crackdowns on ransomware operators as well as a breakthrough on […]
Read More - CISA Alert Tips Off Adversaries
Phishing is a type of social engineering attack where threat actors attempt to trick users into providing sensitive information via email. Typically, this involves creating a phishing campaign where threat actors will send the same phishing email to a large batch of recipients in an attempt to trick at least a small subset of these […]
Read More - The Evolution of Phishing: A WatchGuard Real-World Example
On this week’s episode of the podcast, we cover a newly discovered method for hiding malicious source code in plain sight, CISA’s new Known Exploited Vulnerabilities Catalog, and action from the US Department of Commerce on the Pegasus spyware manufacturer NSO Group.
Read More - Trojan Source
Facebook’s face recognition has one of the largest training databases in the world, built from photos that users have uploaded since Facebook’s inception, but that database’s time may be coming to an end. In a blog post on Facebook they recently announced that they are going to remove the controversial face recognition technology from Facebook. “We’re shutting down the Face Recognition system […]
Read More - Face Recognition Removed from Facebook But Added to Metaverse
The NRA has found itself in the middle of a potential breach and ransomware attack. This happened last week after the Russian hacking group Greif reportedly gained access. Greif has close ties to Evil Corp (another advanced hacking group currently sanctioned by the US) or may even just be the same group rebranded. Grief posted […]
Read More - The Security Conscious NRA Breached by Russian Hacking Group
This week on the podcast, we cover a heist of over $130 million worth of cryptocurrency from a distributed financial (DeFi) organization and have an in depth discussion on why cryptocurrency-related platforms continue to suffer substantial breaches. Before that though, we cover an apparent ransomware attack against the National Rifle Association and an FBI raid […]
Read More - Stealing Make-believe Money
The Microsoft Threat Intelligence Center (MSTIC) detected attacks by the Nobelium group targeting IT services providers. The intent was to “gain access to downstream customers” such as Cloud Service Providers (CSP) and Managed Service Providers (MSP). If the Nobelium name sounds familiar, it’s because they were the threat actor behind the 2020 SolarWinds compromise. MSTIC […]
Read More - Nobelium Threat Group Sets Sights on IT Providers
Many cellular network protocols don’t have clear documentation explaining them, especially when it comes to the proprietary protocols used by 4G and 5G networks. This makes them difficult to understand by the average person, but also potentially vulnerable to anyone willing to take the time to research them and find issues. We haven’t yet seen attacks […]
Read More - China Linked Hacking Group Compromises 13 Telcos
This week on the podcast, we cover the latest news on REvil, the ransomware-as-a-service organization responsible for the Kaseya attack earlier this year among many others. After that, we cover an update from the US Commerce Department on new export rules around selling hacking tools outside of the United States, nearly 6 years after the […]
Read More - Schrödinger’s REvil
Exploit Broker Zerodium Increasing Focus on VPNs The exploit broker Zerodium announced they are seeking exploits for ExpressVPN, NordVPN, and Surfshark VPNs. VPNs are becoming a more lucrative target. Zerodium’s announcement has brought attention to that. Many use VPNs because they believe it protects their privacy. However, it also puts the responsibility of that […]
Read More - InfoSec News From Last Week October 25th, 2021
The US Department of Commerce announced export controls on hacking tools used for surveillance. The aim is to curb access to authoritarian governments who have been identified for human rights violations and abuses. Any companies who intend to sell their wares abroad will need to acquire a License Exception Authorized Cybersecurity Exports (ACE). An additional […]
Read More - US Government Sets Rules for Hacking Tool Exports
Azure, BitBucket, GitHub, and GitLab revoke SSH Keys After GitKraken Vulnerability Git software client GitKraken disclosed an SSH key generation flaw in a post this past Monday. The flaw was discovered in versions 7.6.x, 7.7.x, and 8.0.0 for releases available between mid-May to late-June this year. GitKraken uses the library keypair to generate SSH keys […]
Read More - InfoSec News From Last Week October 18th, 2021
This week on the podcast we cover VirusTotal’s first ever global ransomware report which analyzes ransomware trends over the last year from the unique position of the world’s largest malware intelligence platform. Before that though, we cover another APT group with a ridiculous name found exploiting a zero-day vulnerability in Windows.
Read More - VirusTotal Global Ransomware Report
By now you have probably heard of Missouri governor Mike Parson tweet threatening to prosecute a journalist for responsibly disclosing a data breach. If you missed it though, according to the tweet and the governor’s ensuing press conference, a journalist from the St. Louis Post-Dispatch found teachers’ SSNs embedded in a public web page […]
Read More - HTML Basics That We Often Miss
This week on the podcast we discuss a breach that lasted over 5 years involving a company responsible for routing SMS messages for 95 of the top 100 mobile carriers in the world. Before that though, we’ll cover the recent Facebook downtime incident as well as the seemingly total compromise of the video game streaming […]
Read More - The SMS Breach You Didn’t Hear About
SMS Routing Company Syniverse Discloses Breach Spanning 5 Years Syniverse claims to be “the world’s most connected company” serving so many large telecommunication companies that it should be assumed that your provider is one of their customers. Their reach is significant, acting as the intermediary for text messages between carriers and routing calls between networks. […]
Read More - InfoSec News Weekly Wrap-Up October 8th, 2021
U.S. Agencies have been making headlines recently for a lot of their new cyber related regulations. The following are several noteworthy of examples of what they have been up to. The Federal Communications Commission (FCC) and Robocalls The FCC expects phone carriers to block illegal robocalls from providers not yet registered with the Robocall Mitigation […]
Read More - US Agencies Have Been Busy
A recent survey of 700 SMBs (small and medium businesses) by Untangle shows an increase in cybersecurity budgets and awareness. While some companies still have users working remotely, 50% of respondents have moved back into the office or at least some form of hybrid work environment. Most companies – 64% – see breaches as the […]
Read More - How SMBs Deal With An Uptick in Breaches
Update 1: Twitch believes login credentials have not been exposed (October 7th, 2021): Twitch posted a statement on their blog that, “At this time, we have no indication that login credentials have been exposed.” Additionally, as credit card details are not stored by Twitch, they have ruled out exposure. We recommend changing your password […]
Read More - Twitch Affected by Large Data Leak
October is Cybersecurity (or, for the less civilized, ‘cyber security’) Awareness Month. Every October, CISA hosts security awareness presentations. Additionally, Cybersecurity Awareness month means an increase in jaded by posts by InfoSec professionals on Twitter and emails from corporate reiterating security basics. There are plenty of positives to be found. Individuals are increasingly familiar with […]
Read More - To Not Share is To Care
This week on the podcast we cover the latest quarterly Internet Security Report from the WatchGuard Threat Lab. We’ll go over the latest attack trends and key findings from Q2 2021 as well as defensive tips for keeping your systems safe from the latest threat landscape.
Read More - Q2 2021 Internet Security Report
Earlier this year Kaseya, who provides IT management software to service providers that support tens of thousands of organizations from schools to hospitals, was involved in a ransomware attack fueled by a compromise of their VSA Remote Monitoring and Management (RMM) software. While the ransomware only impacted a small percentage of their customer base, thousands […]
Read More - FBIs Botched Plan to Catch REvil Cost Victims Millions
We often write about passwords and password policies from the IT/security administrator side, usually after a password becomes compromised. We recently found a survey that looked at compromised passwords from the user’s side to better understand how users feel about them. The survey shows a few key points that shed light on the social […]
Read More - Half of Respondents Admitted to Sharing Their Passwords
This week on the podcast we discuss the recently disclosed identify of the”Trusted Third Party” that Kaseya acquired the REvil ransomware master decryption key from, as well as the morals around a decision to hold on to the decryption key for multiple weeks before handing it off to Kaseya. We then cover a new APT […]
Read More - Kaseya’s Trusted Third Party
This week on the podcast we discuss the recently patched zero-click vulnerability in iOS, macOS and WatchOS that researchers at TheCitizen Lab discovered while investigating NSO Group’s Pegasus spyware. After that, we cover a vulnerability in the OMI Agent that comes automatically installed on all Azure Linux virtual machines. We finish by covering Microsoft’s latest […]
Read More - OMIGOD!
This week on the podcast we discuss the first update to the OWASP Top 10 since 2017. OWASP servers as an excellent resource for improving web application security so we’re excited to run through the latest refresh of their top security weaknesses. We also discuss phishing attacks that abuse Internationalized Domain Names (IDNs) in emails […]
Read More - OWASP Update
Update 1: OMI agent is not installed on Azure FireboxV/Cloud instances (September 17th, 2021): We reviewed our FireboxV/Cloud instance for Azure and confirmed that the OMI agent cannot be installed on the image. We recommend reviewing the additional guidance Microsoft published on September 16th, 2021 for securing the OMI affected resources/tools. Original Post (September 16th, […]
Read More - Azure Linux VMs Vulnerable Due to Pre-Installed Agents
This week on the podcast we cover ProxyWare, a form of malware that monetizes your internet access for the benefit of the attacker. After that, we discuss ChaosDB, a vulnerability that could have enabled any Azure user to gain full access to any other user’s CosmosDB instance. Finally, we end with a discussion of location […]
Read More - ProxyWare
This week on the podcast we dig back in the archives to 2019 where we discussed how web servers manage to track users across sites using browser fingerprinting methods. Even though some improvements like removing third-party cookies have been made to limit tracking, plenty of additional fingerprinting options still remain.
Read More - Stop Following Me – Rewind
This week on the podcast we cover one of the largest cryptocurrency heists in history, with a surprising twist of an ending! Before that we’ll chat about the latest T-Mobile data breach and what we can learn about protecting user identity. We end the episode with a discussion about one of the latest episodes of […]
Read More - PolyNetwork Heist
Over the last week we saw 70 million AT&T customers and 53 million T-Mobile customers have their personal data leaked to hackers. While we didn’t find any connections between these two breaches the timing of the incidents is strange. AT&T has so far denied the breach involving their customers. While we don’t have confirmation from […]
Read More - Mobile Carriers Leak 123 million Customer Records in One Week
This week on the podcast we chat about a few of our favorite presentations from the 2021 edition of the DEF CON security conference out of Las Vegas. If haven’t checked them out yourself, visit the DEF CON YouTube channel or media.defcon.org to view this year’s and all previous year’s content.
Read More - DEF CON 29 Recap
David Dworken, a Google security researcher, presented a recent Defcon talk about how he found over 30 vulnerabilities in various Integrated Development Environments (IDEs) over the course of a few months of research. Many believe that source code on its own is benign as long as you don’t compile and run it, but as Dworken proved, simply loading code into an IDE can cause infections. A popular example of this comes from […]
Read More - Supply Chain Attacks Through an IDE
With the 2021 editions of the BlackHat and DEF CON security conferences all wrapped up, one of the presentation that made the biggest waves was the latest research from Orange Tsai of Devcore Security Consulting. Tsai was the researcher responsible for identifying and disclosing CVE-2021-26855, better known as ProxyLogon, to Microsoft back in January 2021, […]
Read More - ProxyShell, Exchange Servers Under Attack Again
This week on the podcast, we chat about a recent report from Qrator that highlights some of the massive weaknesses in the backbone of the internet. After that, we discuss a recent research blog post from Yan (@bcrypt) showing her work in finding a CSRF flaw in OK Cupid that bypassed Cross-Origin Resource Sharing (CORS) […]
Read More - Bad BGP
A recent Defcon talk by Tom Van Goethem and Mathy Vanhoef, “Timeless Timing Attacks” made significant progress on ways to create timing attacks over a network. Timing attacks work by extracting data form devices based on how long it takes to respond. To successfully run a timing attack, the attacker usually must be directly […]
Read More - Defcon Talk Timeless-Timing-Attacks
This week on the podcast we talk Zero-Trust. What is it? How do you implement it? And why should all IT professionals work towards updating their networks to this security architecture? We’ll answer all that and more after a quick Kaseya update and a security memorandum from the White House.
Read More - What Is Zero-Trust Security?
Yesterday, the Biden Administration unveiled a new initiative to help improve the cybersecurity stance of the industrial control systems (ICS) that manage the nation’s critical infrastructure. As recent events (like the Colonial Pipeline ransomware incident) have shown, disruptions to critical infrastructure can have serious, potentially even fatal consequences. In short, this is a very real need and […]
Read More - What to Make of the Biden Administration’s New ICS Cybersecurity Initiative
This week on the podcast we cover the latest Microsoft Windows privilege escalation vulnerability, SeriousSAM aka HaveNightmare. Before that, we discuss NSO Group and their spyware software known as Pegasus and whether private organizations should be allowed to market and sell spyware to government agencies.
Read More - Why So SeriousSAM
With the White House announcing this month that it plans to investigate potential changes to Section 230, the safe harbor laws that enable websites to moderate content without risk of liability for content they fail to remove, we wanted to bring back an episode from last year where we discuss exactly what these laws are […]
Read More - Section 230 – Rewind
Many of the recent high-profile ransomware attacks like those against Acer, JBS and more recently, customers of Kaseya, have been the work of the ransomware as a service group REvil. After the most recent attack that exploited multiple zero-day vulnerabilities in Kaseya’s VSA software and left thousands of organizations encrypted, REvil appears to have gone […]
Read More - REvil Hasn’t Gone Anywhere (Probably)
Update 1: Third PrintNightmare CVE published (July 16th, 2021): Microsoft published CVE-2021-34481 on July 15th for a local privilege escalation vulnerability. The third Print Spooler service vulnerability is considered separate from PrintNightmare (CVE-2021-34527), but it is still within a similar sphere of printer driver vulnerabilities. Gentilkiwi, the author of the Mimikatz utility, posted a […]
Read More - The PrintNightmare Saga Continues to Frustrate System Administrators
This week on the podcast we cover the Kaseya mass ransomware incident from July 7. While the event is still ongoing, we already have evidence for how the attack occurred and exactly what the threat actors did on affected endpoints. In this episode we dive in to the details around the incident and defensive tips […]
Read More - Kaseya & PrintNightmare
We recorded this episode before news of the massive attack against Kasaye users broke on Friday. Suffice to say, next week’s episode will give a full debrief of the incident including how it happened, who it affected, and what all MSPs can learn from it. In the meantime, check out Corey’s post on the Kaseya […]
Read More - A Market for Lemons?
Managed Service Providers (MSPs), especially ones using Kaseya VSA, should read this and take action as soon as possible. High-level Summary: On Friday, July 2, some MSPs using the on-premises version of Kaseya VSA suffered ransomware attacks that trickled down to their customers. Kaseya says around 1500 companies (so far), many customers of MSPs, have […]
Read More - Breaking Alert: MSP Targeted Ransomware Attack (Kaseya Supply Chain Attack)
Its that time of year again! This week on the podcast, we cover the latest internet security report from the WatchGuard Threat Lab. We’ll go over the latest trends in malware and network attacks targeting WatchGaurd customer networks through the first quarter of the year, as well as defensive tips for all organizations.
Read More - Q1 2021 Internet Security Report
What is malware? Its goal is to bypass computer defenses, infect a target, and often remain on the system if possible. A variety of evasion techniques depend on a mix between the skill of the author and the defenses of the intended victim. One of the most widely used tactics in malware is obfuscation. Obfuscation […]
Read More - AutoIt Malware: To obfuscate, or not to obfuscate
We normally think of malware and threats coming from executables, packages, and scripts. Researchers recently found a supply chain attack using a different method. Programs use Python scripts to manage and run services. You especially see this in Unix-based operating systems. When it comes to security many professionals use Python to automate tasks. Because […]
Read More - Python Modules: Not As Safe As You Think
It has been 11 years since the Google Doodle Pac-Man game was published. Many of us may remember this Google Doodle as it was the first interactive Google Doodle made. Unfortunately, like many fun things, there are those who see opportunity and take advantage of that. We recently noticed DNSWatch traffic blocking googlepacman[.]net. After some […]
Read More - Domain Parking, PUPs, and Annoying Push Notifications
This week on the podcast we discuss an often overlooked item for sale on underground forums, authentication cookies. Before that though, we’ll cover a few surprising stats from a recent ransomware study by Cybereason and an update from NATO on cyber warfare.
Read More - Dark Web Bake Sale
This week on the podcast, we discuss operation Trojan Shield, a multi-year program where the FBI in partnership with international law enforcement agencies developed and distributed an encrypted communications application on the underground that gave them full access into criminal messages. We’ll also cover the latest news from the recent Colonial Pipeline and JBS ransomware […]
Read More - Anom
In an operation headed by the US Federal Bureau of Investigation (FBI) and Australian Federal Police (AFP), international law enforcement agencies managed to gather 27 million encrypted messages used for criminal communications, through an elaborate operation that involved development and distribution of a custom communications application for modified phones. Unsurprisingly, organized crime groups take extraordinary […]
Read More - Law Enforcement Agencies Went the Extra Mile with An0m
A KickAss hacking group member (not the Torrent group) who goes by Leakbook claims to have the full FIFA 21 source code, which they have listed for sale on a popular hacking forum. In addition to the FIFA 21 source code they also claim to have access to the matchmaking servers, Frostbite source code, private […]
Read More - FIFA 21 Source Code Leak From Member of Reemerging Hacking Group
This week on the podcast, we take a look at how soldiers unknowingly leaked highly-sensitive information about the United States’ foreign nuclear arsenal and discuss how we can reprogram humans to not make similar mistakes. We also cover the latest major ransomware incident targeting manufacturing and industrial control, a damning privacy admission from Google’s own […]
Read More - Atomic Flashcards
A large cyber attack has caused chaos in the New Zealand healthcare system over the past few weeks. Multiple hospitals in New Zealand became crippled due to locked phone lines and computers from a large ransomware attack. Though the ransom note didn’t contain a dollar amount the note indicates a “ransomware event” according to the […]
Read More - “The Biggest Cyber Attack In New Zealand’s History”
A few years ago, in 2017, researchers Mathy Vanhoef and Frank Piessens published a whitepaper showcasing serious vulnerabilities within practically all modern protected Wi-Fi networks. The vulnerabilities lie within the Wi-Fi standard itself and are exploited using Key Reinstallation Attacks (KRACKs). These attacks primarily target the 4-way handshake of the WPA2 protocol – the current […]
Read More - WiFi FragAttacks
This week on the podcast we cover an epic battle between a video game giant and a tech behemoth that has the potential to change mobile security forever. After that, we cover updates to several recent security events including the SolarWinds breach, the attempted poisoning of the Oldsmar, FL water supply, and the ransomware attack […]
Read More - An Epic Battle
This week on the podcast we cover the ransomware attack against Colonial Pipeline which left the east coast of the United States in fear of gas shortages for more than a week. We’ll discuss the threat actors behind it, how they possibly got in, and what the response was from Colonial and the United States […]
Read More - Oil for Ransom
In response to recent cybersecurity incidences like the SolarWinds breach, Microsoft Exchange Server vulnerabilities, and the Colonial Pipeline ransomware attack, President Biden signed an executive order to increase the cybersecurity stance of the federal government and all civilian agencies it contracts with. The 34-page executive order implements minimum security standards for the government and contractors. […]
Read More - Biden Orders Massive Overhaul of Federal Agency Security
This week on the podcast we cover a 12 year old vulnerability in Dell’s firmware update driver impacting hundreds of millions of servers, workstations and tablets. Then, we dive in to 21 nails, a collection of vulnerabilities in the Exim Mail Transfer Agent (MTA) which has wide use across the internet. We’ll go over a […]
Read More - 21 Nails
Another day, another breach. Although, this time, the victim is the Metropolitan Police Department in Washington D.C. and the breach was induced by double-extortion ransomware known as Babuk. The group behind the ransomware attack, the Babuk Ransomware Group, hosts a webpage of their leaks with their most recent addition being the DC Police. The original […]
Read More - DC Police Alleged Victim of Double-Extortion Ransomware Attack
In the past few months there has been a dramatic increase in cryptocurrency prices. In fact, the crypto market value topped $2 trillion for the first time in history and bitcoin, the largest form of digital currency, hit a record high of more than $61,000, rallying over 100% in 2021 alone. As a result of growing crypto prices, individual investors and businesses have become bigger targets for cryptojacking – and no industry is immune. For example […]
Read More - Understanding How Rising Cryptocurrency Prices Affect Cybersecurity
You know what they say about passwords… You’re only one weak password away from a breach. Despite the increasing sophistication of hacker technologies and tools, the easiest step of a hack is still cracking the password. In fact, it’s so easy that many times it doesn’t even involve guessing at all. The scariest part about […]
Read More - 2021 World Password Day: How Many Will Be Stolen This Year?
This week on the podcast, we mourn a Dan Kaminsky, a well-loved hacker responsible for identifying one of the biggest vulnerabilities in the history of the internet. Then, we continue our dive into web app security standards with a discussion on Same-Origin Policy and Cross Origin Resource Sharing (CORS) and how they help protect us […]
Read More - What Is Same-Origin Policy?
According to an article by Techdirt, the Chinese government has created “Uyghur alarms” by an explicitly biased face recognition service which they are using. China uses face recognition to identify and target Uyghur people. Under the guise of identifying the different races in China, the model used appears to specifically identify Uyghur and Tibetan face […]
Read More - China’s Explicitly Biased Face Recognition Model
This week on the podcast, we cover Signal CEO Moxie Marlinspike’s analysis of a phone forensic analysis tool made by the grey-hat hacking organization Cellebrite. Before that though, we cover another solved mystery from the SolarWinds Orion saga.
Read More - Cellebrite Good Times
(Updated 04/22/2021 to include court order) For the last few months, we have seen Exchange Servers fall to vulnerabilities from the HAFNIUN attacks. Even after Microsoft released patches for the serious flaws, we continue to see attacks on Exchange Servers and hear of more Exchange Servers becoming compromised. This shouldn’t be news as many publications […]
Read More - Judge Rules FBI Can Hack Into Exchange Servers
This week on the podcast we cover a couple of major events from April’s Patch Tuesday including four new remote code execution vulnerabilities in Exchange Server and some additional developments in the saga of March’s Exchange Server exploits.
Read More - On A Tuesday
This week on the podcast, we go back to one of our favorite episodes from last year near the start of the pandemic where we sat down with security expert Nina Jankowicz to discuss what the rapid change to remote work would mean for security.
Read More - Combating Disinformation with Nina Jankowicz Rewind
Its that time of year again! This week on the podcast we dive in to the latest internet security report out of the WatchGuard Threat Lab. We’ll cover the latest trends in malware, both at the perimeter and the endpoint, as well as network attacks and malicious domains. Additionally, we’ll recap the top security incident […]
Read More - Q4 2020 Internet Security Report
On March 18th, 2021, the DNSWatch Tailored Analysis Team received an email from an internal WatchGuard employee who deemed the email as suspicious. The initial email included an attachment with the title Attachment_57904. A DNSWatch Analyst performed an initial assessment of the file in search of any malicious indicators or behaviors only to discover that […]
Read More - Deobfuscating a Dropper for a ZLoader Trojan Variant
At the beginning of March, as many Americans were eagerly awaiting another round of stimulus payments, news began to circulate about cybercriminals taking advantage of the American Rescue Plan offering financial assistance (payments and other aids) as part of COVID-19 relief. We got a hold of some of these phishing emails and upon scrutiny, we […]
Read More - Analysis of a Dridex Banking Trojan Phish
Ubiquiti may have a lot to answer to after recent allegations of their possible downplaying of January’s breach. The allegation involves an attacker gaining access to Ubiquiti’s Amazon Web Services (AWS) account via an employee’s account with root (read/write admin or higher permissions) level access to all of Ubiquiti’s AWS accounts. The whistleblower alleged that […]
Read More - Ubiquitous for all the Wrong Reasons
CRN has honored WatchGuard with a prestigious five-star rating in its 2021 Partner Program Guide. This is the eighth year in a row WatchGuard has achieved top marks in CRN’s definitive directory of the most rewarding partner programs for the IT channel. The coveted ranking is the result of WatchGuard’s continued commitment to helping its […]
Read More - WatchGuard Earns Another 5-Star Rating in CRN’s 2021 Partner Program Guide
This week on the podcast we take a look at Content Security Policy, a web app security standard designed to combat Cross Site Scripting attacks against websites and web apps. Before that though, we’ll cover the latest security news including a resurgence in ransomware attacks and the long overdue death of TLS versions 1.0 and […]
Read More - What Is Content Security Policy?
Over the last few weeks, we continue to see HAFNIUM attacks against Exchange Servers through our threat intelligence. Our Firebox feed data shows Fireboxes identifying the signature almost every day over the HTTPS proxy. Yet, Many Exchange servers remain unprotected. With Exchange Outlook Web Access (OWA)servers, Fireboxes must inspect the content of HTTPS traffic […]
Read More - Fireboxes Detect HAFNIUM Attacks in the Wild
The PHP Group, the collection of developers responsible for maintaining the reference source code and implementation for the popular web scripting language PHP, made the decision to retire their self-maintained code repository server and move to GitHub after an unknown threat actor inserted a backdoor into the core PHP code library through a git pull […]
Read More - Attempted PHP Backdoor Foiled
Sporting and competition are a mainstay of the human spirit. And in that spirit, we find new ways to compete. A classic example of this is website defacement, where a malicious hacker compromises a website and uses the page itself to show off their conquest. A WatchGuard customer recently submitted a domain that they flagged […]
Read More - DevilXploit and Website Defacement
The REvil ransomware group has come to prominence recently by infecting networks around the world with ransomware and demanding large sums of money from their victims. The group commonly posts proof of their successful ransomware efforts on their blog, called Happy Blog, where one of their most recent victims, Acer, has appeared on the list. […]
Read More - Alleged Acer REvil Ransomware Infection Breaks Record with $50+ Million Demand
This week on the podcast we cover key findings from the 2020 FBI Internet Crime Report and the latest reflective amplification vector for DDoS attacks. Then, we discuss a recent blog post from penetration tester Fabian Mosch that details the top weaknesses they target during their engagements. You can read more from Fabian here.
Read More - Defense Tips from a Pentester
As reported by ABC Australia, an Australian government email server fell victim to what we suspect was the Exchange server vulnerability disclosed earlier this month. Officials detected Chinese hackers targeting Western Australia’s parliamentary email server just nine days before the state’s elections, March 13th. The attack comes after another cyber attack last June, again from […]
Read More - China Suspected of Targeting Email Server During Elections in Australia
This week on the podcast we take a deep dive into the Exchange Server vulnerabilities that Microsoft issued an emergency patch for after discovering foreign adversaries were actively exploiting the flaws in the wild. We’ll go over the vulnerabilities, how they work, and give some tips for defending against similar attacks in the future.
Read More - Popping Webmail Shells
There is a considerable amount of attention geared towards traditional computer security, especially for Windows PCs. As Mac’s have been a small portion of the total active users it makes sense that attackers have focused their effort on Windows operating systems. Therefore, Windows exploits tend be pervasive in the news leaving some to believe Mac’s […]
Read More - iOS Security Primer
This week on the podcast we cover Gootkitand Gootloader, two oddly-named pieces of an evasive trojan that researchers have been watching evolve into a fileless threat. We also discuss the security benefits and drawbacks of Apple’s closed-door approach to security. Finally, we end with some research on what happens when a cosmic ray causes your […]
Read More - Hacked by Cosmic Rays
(Updated 03/10/2021 to include defensive tips) As the cybersecurity community continues to reel with the sweeping effects of the SolarWinds attack, the Microsoft Threat Intelligence Center (MSTIC) has released information about another widespread campaign targeting Exchange servers. It has been found that a state-sponsored threat actor operating out of China, which they are calling HAFNIUM, […]
Read More - Exchange Server Vulnerabilities Actively Exploited in the Wild
The alternative social media site Gab, favored by the political right-wing, leaked private information though a SQL injection vulnerability according to Gab.com. Gab CEO Andrew Torba initially denied the breach over the weekend but has since acknowledged it. A hacker by the name JaXpArO provided the stolen data to the hacktivist group DDoSecrets. DDoSecrets says […]
Read More - Gab.com Leaks 70 Gigabytes of Usernames Hashed Passwords and More
This week on the podcast we cover an upcoming Chrome browser update with important behind-the-scenes changes, a 9.8/10 severity vulnerability in VMWare vCenter, and a plea from Microsoft for more breach disclosure regulation in the wake of the SolarWinds breaches.
Read More - Microsoft Says “Regulate Us”
This week on the podcast, we chat about an authentication attack against one of the world’s internet address registrars, another Russian threat actor targeting a popular IT software company, and research on a credential theft trojan and its delivery methods.
Read More - RIPE for the Taking
The water treatment system of the city of Oldsmar, FL has been in the news lately after attackers breached its control systems and increased the levels of sodium hydroxide. The targeted treatment plant provides water to businesses and about 15,000 residents in the Tampa, FL suburb. Was the attacker’s intention to harm these residents? Could […]
Read More - Oldsmar Water Treatment Plant Hack
This week on The 443, we cover a cyber-attack against the water supply of a small Florida town and research into a new class of vulnerabilities in software libraries called Dependency Confusion.
Read More - So Confused
The answer to that question still remains open, but we expect it might return in some form or fashion. Yes, the takedown of EMOTET was successful, but anyone in the world of cybersecurity will tell you that malware has a habit of resurfacing in clever and unexpected ways. Therefore, the same could hold true for […]
Read More - Is EMOTET Really Gone Forever?
This week on the podcast, we cover the latest research from Avast on evasion techniques in use by malicious Chrome extensions. After that, we discuss the latest report from Google’s Threat Analysis Group on nation-state threat actors targeting white hat security researchers.
Read More - CacheFlow
Complexity is the enemy of security, and many businesses find that security takes up a disproportionate amount of their IT team’s time. Managed service providers are increasingly filling the security gap allowing their clients to stay safe, while letting them focus on their digital transformation goals. For MSPs transitioning from an IT support services practice, […]
Read More - WatchGuard Cloud Accelerates the Era of Simplified Security Management for MSPs
It’s 2021 and you probably have several Wi-Fi deployments lined up. Every organization expects access to Wi-Fi at all times, but delivering a powerful and secure solution is easier said than done. One of the last things any Wi-Fi integrator needs when climbing ladders to set up new access points for a customer, is well… […]
Read More - Don’t Fall Victim to the Most Common Wi-Fi Deployment Mistakes
In a dynamic world, where user mobility impacts security almost 100% of the time, multi-factor authentication (MFA) has become imperative and key to deploying a zero-trust network. Why? • Users are connecting to company resources from different, unprotected networks • Working hours have become more flexible, so they could be working from early hours to […]
Read More - Identity Management and Risk Authentication: Core Technologies to Achieve Zero-Trust Security
For the fourth year in a row, CRN has recognized several WatchGuard leaders in its annual Channel Chiefs list. This elite awards program recognizes leading IT channel vendor executives who continually demonstrate tremendous influence, leadership, innovation and growth. CRN recognized Michelle Welch, Sean Price, Brian Thomas, Mark Romano, Shari McLaren, Adam Otis, Joseph Tavano and Stan Kelly as exclusive technology executives from WatchGuard that influence, innovate and disrupt the IT channel. In addition, […]
Read More - Eight WatchGuard Leaders Honored in the 2021 CRN Channel Chiefs List
Swift new developments have continued to pour out on the SolarWinds breach. Under normal circumstances it is difficult to keep up to date on the news and especially so with a story that continues to grow. Nevertheless, the Threat Lab team at WatchGuard has been keeping an eye out on the latest updates. Beyond the […]
Read More - SolarWinds Catch-Up
This week on the podcast, we bring on Trevor Collins from the WatchGuard Threat Lab to chat about a the recently disclosed MalwareBytes breach and a series of vulnerabilities in a popular DNS forwarder, dubbed DNSPOOQ.
Read More - It’s Always DNS
This week on the podcast, we cover a cloud security alert courtesy of Cybersecurity & Infrastructure Security Agency (CISA) and encrypted DNS guidance from the NSA. We also discuss a macOS malware evasion technique that has eluded analysis for over 5 years, until now.
Read More - AppleScryptominers
Nvidia released updates to its users after security researchers and the Nvidias Product Security Team found 16 vulnerabilities in the Nvidia driver and software packages. One of the vulnerabilities found in the driver package allows for an escalation of privileges and could allow full control of the system. Drivers tend to have administrative privileges and […]
Read More - 11 High Severity Vulnerabilities found in Nvidia Software
Zyxel, a firewall and AP vendor, released a firmware update to their devices that included an unexpected, built-in admin user account called “zyfwp”. Folks in information security often characterize this sort of hidden and hardcoded accounts as a “backdoor” account, even though it is hard to say if the vendors who do this do so […]
Read More - Zyxel Adds a Built-in User With A Easy To Find Password
This week on the podcast we dive into what will likely be remembered as the hack of the decade. With victims including dozens of Fortune 500 companies and US Federal agencies, the SolarWinds supply chain breach has had a massive impact on the industry and as the potential to change client/vendor trust relationships going forward.
Read More - The Hack of the Decade
For the second year in a row, WatchGuard’s award-winning WatchGuardONE Partner Program has been named “Security Partner Program of the Year” at Channel Partner Insight’s 2020 Channel Innovation Awards! This annual awards program honors vendors and partners that have brought true value and innovation to the managed services market. Taking home the prestigious “Security Partner Program of the […]
Read More - Channel Partner Insight Names WatchGuardONE Security Partner Program of the Year
Fileless malware has been making headlines over the past year, taking center stage as one of today’s most prominent threat categories. According to Cisco, fileless attacks were the most common threat targeting endpoints in the first half of 2020. To prevent this type of malware effectively, organizations need to establish a deep understanding of how […]
Read More - Understanding Fileless Malware Outside the Network
Happy Holidays! This week on the podcast, we’re going back to one of our favorite episodes from 2019 where we sat down with Biohacking pioneer Amal Graafstra to discuss implants, RFID technology and the future of human/technology interactions.
Read More - Biohacking with Amal Graafstra Rewind
The SolarWinds debacle has reminded us all of one crucial aspect of vital infrastructure: human error. Standards, procedures, and processes are in place to ensure the implementation of a secure baseline. These plans and mechanisms are developed so that organizations have clear instructions to follow for best security practices. The challenge with technology is it is developed by humans, and we are imperfect. Our mistakes are not only accidental but can also be […]
Read More - SolarWinds Lenient Security Practices Are Not Unique to Any One Organization
As news of the recent SolarWinds hack still unfolds, new information about APT29 possibly hacking a second major technology supplier could cause major disruptions. “CISA is investigating other initial access vectors in addition to the SolarWinds Orion supply chain compromise. ” the CISA report reads. This statement replaces a previous statement indicating there was another […]
Read More - FBI Indicates Possible Second Hack By APT29
Last week, the cybersecurity consulting company FireEye announced they had suffered a breach where attackers stole sensitive “red team” hacking tools and potentially information related to certain government customers. FireEye has historically been one of if not the most prominent consultants brought in to investigate attacks against large organizations and government entities. By targeting FireEye, […]
Read More - SolarWinds Supply Chain Hack Responsible for FireEye Breach
We recently found XRSI, through their now-removed blog site post, claiming to have root access to Oculus Quest 2, a Virtual Reality game platform. New information from a Reddit user question if XRSI gained root access and the truthfulness of their claims. Since we published their claim, we thought it appropriate to also review what […]
Read More - XRSI May Have Lie About Gaining Root Access The Quest 2
Find an online store you trust, pick an item with reliable reviews, enter your payment details and/or sign-in to the websites account, and finally, click ‘Purchase’. This process is all it takes to purchase gifts this holiday season. There is one final step: Receive the package. Though this may not feel like a step, the […]
Read More - Phishing Deep in the Amazon
Apple is a very polished company, both in how it designs and advertises its products. The latest macOS release of Big Sur, however, was anything but smooth. This can be partially attributed to Apple’s decision to use Online Certificate Status Protocol (OCSP) for certificate authentication and certificate revocation tracking. The issue is not only due […]
Read More - Concerns Over Apple’s New Privacy and Security Decisions with Big Sur
This week on the podcast, we jump in to WatchGuard Threat Lab’s 2021 security predictions. From automated spear phishing to booby-trapped electric vehicle chargers, we’ll discuss each of the 8 predictions we made and why we made them. You can read about the predictions in full at watchguard.com/predictions.
Read More - 2021 Security Predictions
Last month, the FCC again rejected the Chinese device manufacturer ZTE’s request for its removal off of the US national security threat designation. Both ZTE and Huawei fall under this category as a possible risk of espionage. While both manufacturers deny the threat, Chinese law does allow their government to spy on users with […]
Read More - FCC Again Labels ZTE A ‘National Security Threat
Annual planning and budgeting has always been a critical, albeit potentially cumbersome aspect of establishing a successful security posture. Information security doesn’t contribute directly to the bottom line for most companies and management often views it as a cost. That’s why it’s essential for CISO and security leaders to allocate the budget they do get […]
Read More - Tackling 2021 Security Planning and Budgeting
Authentication is the cornerstone of strong security. With billions of usernames and passwords ripe for the picking on the dark web and the prevalence of automated authentication attacks, we believe that any service without MFA enabled will be compromised in 2021. Interested in how this trend will play out and what other emerging security issues […]
Read More - 2021 Security Predictions: Every Service Without MFA Will Suffer a Breach
As the COVID-19 outbreak devastated the travel industry, many hotels launched “work-from-hotel” programs to appeal to locals who needed an escape from their home workspace. Hotels now offer daytime room reservations for people who wanted a quiet, distraction-free place to work, with the added amenities one would expect in a hotel. Unfortunately, cyber criminals have […]
Read More - FBI Sounds the Alarm: Hotel Wi-Fi Poses an Increased Security Risk for Teleworkers
Next year you can expect to see at least one major new Windows 7 vulnerability make headlines as attackers continue to find and target flaws in legacy systems. Microsoft just ended its extended support program and with tons of organizations still relying on it and attackers looking to target flaws in endpoints due to widespread […]
Read More - 2021 Security Predictions: Attackers Pinpoint Security Gaps in Legacy Endpoints
As more companies adopt Remote Desktop Protocol and VPN solutions to provide secure connections to remote employees, we predict attacks against them will double in 2021. If an attacker can compromise VPN, RDP or remote connection servers, they have an unobstructed path into your corporate network. Interested in how this trend will play out and […]
Read More - 2021 Security Predictions: Attackers Swarm VPNs and RDPs as the Remote Workforce Swells
Every November, WatchGuard Threat Lab tries to make predictions about potential security events in the coming year. While some predictions might come off as a bit extreme, they’re all grounded in actual trends that we see and expect to continue. With 2020 almost under wraps, its time for us to look back to the predictions […]
Read More - 2020 Predictions Recap
In 2021, consumers will begin to fully understand the privacy concerns associated with smart devices and start advocating that legislators regulate IoT tech companies to better protect user data. It isn’t connected dog monitors or smart doorbell cameras that caused this tipping point, rather the cumulative deterioration of privacy brought on by the countless IoT […]
Read More - 2021 Security Predictions: Users Revolt Over Smart Device Privacy
Smart car popularity will continue to rev up in 2021. As a result, we predict that security researchers and/or hackers will identify and demonstrate a major vulnerability in a smart car charger that will allow them to disrupt the use of your car by preventing charging. Interested in how this trend will play out and […]
Read More - 2021 Security Predictions: Booby-trapped Smart Chargers Lead to Smart Car Hacks
Widespread remote work will stick around into 2021 and beyond. As businesses continue to adjust their operations, so too will attackers. Next year, we believe attackers will evolve their malware with worm functionality to not only spread across home networks, but to seek out connected devices that indicate corporate use. For more information and to […]
Read More - 2021 Security Predictions: Hackers Infest Home Networks with Worms
Over the first week of November, we saw an increase in the malware family Phishing.ADA reporting into the Firebox Feed, our threat intelligence feed fueled by opt-in reports from Firebox security appliances deployed around the world. We found this phishing email primarily targeted users in Southeast Asia to steal email credentials. We retrieved a sample […]
Read More - Recent Phishing Research Leads Us To Access Scammers Logs
This week on the podcast, we sit down with ESG Analyst John Grady again, this time to chat about the topic of SMB Security. We’ll cover how the cyber threat landscape has changed throughout 2020 and what SMBs got right, and wrong when it came to adapting.
Read More - Securing SMBs with John Grady
2021 will be the year Cloud hosting providers like Amazon, Google, and Microsoft finally begin to crack down on phishing and other malicious activities that abuse their reputation and services. Attackers have abused custom subdomains to lure in victims for too long, and it’s about to come to an end. Interested in how this trend […]
Read More - 2021 Security Predictions: Cloud-Hosting Providers Finally Crack Down on Cyber Abuse
This year has brought dramatic and extreme change at every turn. The global COVID-19 pandemic has transformed business and life as we know it, accelerating the move to remote operations where employees work outside the protection of the corporate firewall. As we look ahead at what 2021 has in store with our annual cybersecurity predictions, […]
Read More - 2021 Security Predictions: Automation Drives Tidal Wave of Spear Phishing Campaigns
SC Media recently released the results of its annual review of the industry’s latest powerhouse Unified Threat Management (UTM) platforms. WatchGuard is excited to share that its Firebox T80 was named SC Labs’ Pick of the Litter, achieving a 5-star rating in every category measured! In the review, SC Labs explains that the UTM market has […]
Read More - WatchGuard’s Firebox T80 Earns 5-Star Rating in SC Labs Review
WatchGuard Cloud has been honored as a top cloud-delivered security solution in the 2020 Cloud Computing Security Excellence Awards! A leading, trusted platform for delivering managed security services, the WatchGuard Cloud platform earned this recognition for its ability to eliminate the complexity and cost typically required to manage, log, and report on security services by consolidating […]
Read More - WatchGuard Takes Home 2020 Cloud Computing Security Excellence Award
CRN has included WatchGuard Senior Security Analyst Marc Laliberte in its “100 People You Don’t Know But Should” list for 2020! This annual CRN roster pays tribute to the channel’s best and brightest people who make an important impact in the partner community, yet still somehow fly under the radar. Described as a “security nerd, white-hat […]
Read More - CRN Recognizes Marc Laliberte as One of the Channel’s Best and Brightest
The decoupling of hardware and software in the telecom industry has opened several technological possibilities while concurrently introducing new threats. An exciting change to the industry, with the opportunity to make Radio Access Network (RAN) architecture more dynamic in terms of vendor choice and software upgradability. The need for structure and compatibility for future RAN […]
Read More - Open RAN Will Define the Future of 5G Expansion but Security Questions Remain
CRN just announced its 2020 Tech Innovator Awards and WatchGuard is proud to share that the Firebox T35-R was named the winner of the “Security – Internet of Things” category. Designed to recognize true channel-friendly innovation, this awards program highlights products and services that offer both major advancements in technology, as well as partner growth […]
Read More - WatchGuard Wins Big in CRN 2020 Tech Innovator Awards
If you have read our recent Internet Security Report you will see there is a rise in probe requests over public Wi-Fi. Penetration testing tools are getting more sophisticated, it’s becoming easier for cyber criminals to eavesdrop and steal personal information from people over Wi-Fi. If we look at the original Mark I pineapple from […]
Read More - I am not worried about my Wi-Fi!
This week on the podcast we sit down with John Grady, analyst at Enterprise Strategy Group, to break down the latest industry industry terms Secure Access Service Edge (SASE) and Zero Trust Network Access (ZTNA). We’ll dive in to exactly what they encompass and then get John’s thoughts on where they stand in small and […]
Read More - Getting SASE with John Grady
For the fourth consecutive year, the Puget Sound Business Journal has named WatchGuard in its prestigious list of Washington’s Best Workplaces. WatchGuard is honored to be recognized yet again as a top employer in The Evergreen State. The workplace might function a little different in 2020 than in years’ past, but our incredible employees are truly what makes WatchGuard special and successful […]
Read More - Puget Sound Business Journal Names WatchGuard a Top Washington Workplace
Over the last few years, the US justice department has been tracking Bitcoin that was associated with the dark-web marketplace Silk Road. Silk Road allowed its users to buy and sell illegal drugs, weapons, and services that you might expect in a criminal marketplace. In 2013, the US department of justice arrested and ultimately convicted the founder of the marketplace, Ross Ulbricht, on counts ranging from money laundering to narcotics trafficking. Just before […]
Read More - US Justice Department Makes One Billion Dollar Drug Related Seizure
Green fingered individuals looking to share tips or expand their knowledge on growing the “Kind Bud” on the website GrowDiaries may be disappointed to discover their data was left vulnerable. The information left exposed by two Kibana applications, each connected to an Elasticsearch database, risked exposure of account credentials and IP addresses. GrowDiaries resolved […]
Read More - Data Breaches, A Thorn in Both Your Side and Mine
This week on the podcast we discuss a previously unsolved mystery from the dark web that was just solved with a little help from the IRS. We’ll then discuss the growing issue of malicious opensource packages and libraries after researchers last week discovered a malicious package masquerading as a popular communications service.
Read More - Packaged Attacks
(update 12/11/20: XRSI may not have rooted the Quest 2, see XRSI May Have Lie About Gaining Root Access The Quest 2) XRSI may have found a way around the new Oculus Quest 2 Facebook login. Technical users will sometimes root a device to gain complete control over the device. This option for users commonly occurs with most of the popular phones and tablets available so usually, it doesn’t mean much. We do find a reason […]
Read More - Researchers May Already have Compromised The Quest 2 VR
This week on the podcast, we’ll discuss an alert from US-CERT and the FBI that details an “imminent threat” to hospitals and other healthcare facilities, as well as some recently disclosed critical vulnerabilities in a popular healthcare records software. After that, we’ll give you your (hopefully) last dose of election security news with some election […]
Read More - Healthcare Hacking
With the US elections only a week away, we’re talking election security on this week’s episode. We’ll cover what we do and don’t think attackers will target in the coming week and what we can do as a country to improve our security posture.
Read More - Top Election Security Threats
In another series of attacks on COVID-19 research, an attacker disrupted Dr. Reddy’s servers in India, Brazil, Russia, the United Kingdom and the United States. Headquartered in India, Dr. Reddy’s has connections with other major pharmaceuticals in the US and Europe. While we saw previous attacks on hospitals and research centers, this attack for the […]
Read More - How the Vulnerable Healthcare Industry can Protect Themselves
With only a week left to the U.S. Presidential Election, voting is in the news and on most people’s minds (though many of us are also looking forward to the conclusion of this election cycle). This is especially true because of all the voting security stories that have been in the news lately. Whether its […]
Read More - 7 Myths About U.S. Election Voting Security
According to a recent advisory published by the NSA, Chinese state-sponsored actors use several techniques to access sensitive intellectual property, economic, political, and military information. The NSA has identified the most often used techniques that can cause the most damage. These include 25 vulnerabilities they know Chinese state-sponsored actors use. 21 of these vulnerabilities became […]
Read More - 25 Dangerous Vulnerabilities Actively Exploited by China Sponsored Actors
This week on the podcast, we discuss the latest round of indictments against foreign intelligence agents for cyber espionage. After that, we cover a Microsoft-lead coalition that has so far made a significant impact in taking down the infrastructure behind one of the largest active botnets. Finally, we highlight key takeaways from the latest Google […]
Read More - Trickbot Takedown
Thanks to WatchGuard’s Panda Adaptive Defense 360 zero-trust service, WatchGuard Threat Lab was able to identify and stop a sophisticated fileless malware loader before execution on the victim’s computer. Upon further detailed analysis by our attestation team, we identified several recent browser vulnerabilities that the malware targeted as part of its exploit chain. Malware Behavior The attack that WatchGuard Threat Lab analyzed […]
Read More - Analyzing a Fileless Malware Loader
For those running the latest operating systems for your computers, phones, and tablets, you may have noticed the changes to how your device connects to wireless networks. Apple has made headlines for their iOS 14 update that enables randomized Mac addresses by default. While this implementation is somewhat unique in that it does more to […]
Read More - Can I Have Both Privacy and Security? MAC Address Privacy in Public
This week on The 443, we cover research from Microsoft’s security team on a new Android ransomware variant that gets around Google’s latest protections. We also cover a UEFI malware loader discovered by Kaspersky and the US Department of Justice’s actions against a popular video game console mod chip manufacturer.
Read More - Android Ransomware Evolution
This week on the podcast we circle back to cover a critical vulnerability in Windows Server, that could allow an attacker to obtain the keys to the kingdom with minimal effort. After that, we discuss a pair of alerts from the US Department of Treasury Office of Foreign Assets Control and Financial Crimes Enforcement Network […]
Read More - ZeroLogon
Last month while onboarding a new customer to Panda EDR with the Orion threat hunting console, WatchGuard Threat Lab discovered an existing advanced persistent threat (APT) on the organization’s network. WatchGuard Threat Lab investigated the incident and were able to identify much of the threat actor’s tools, techniques and procedures including several indicators of compromise […]
Read More - Identifying an Existing APT Intrusion
This week on the podcast, we cover the latest internet security report from WatchGuard Threat Lab. We’ll go over the key takeaways from the Q2 2020 report including malware and network attacks that targeted WatchGuard customer networks. Before that though, we’ll discuss an alert from the US Cybersecurity and Infrastructure Security Agency (CISA) that detailed […]
Read More - Q2 2020 Internet Security Report
A recent malware payload found by Nviso Labs showed a new way of hiding VBA scripts (Visual Basic for Applications) in Microsoft Office documents. The malware authors created the malicious documents with 3rd party programs which allowed them to bypass some anti-malware services. Antivirus programs typically search for signatures in a file to identify […]
Read More - New Technique Found for Hiding Microsoft Office Malware
Higher education institutions work constantly to build smarter campuses. These advances tend to focus on digital transformation and overall more accessible, user-friendly resources to enable the academic experience from any device, anywhere. Colleges strive to be a big, fun, stimulating, shared macrocosm: the place to learn together and share knowledge and unique experiences. From an […]
Read More - Security in Higher Ed: Trust, Student Experience, and Multi-Factor Authentication
This week on The 443 – Security Simplified, we sit down for a chat on disinformation with Nina Jankowicz, author of How to Lose the Information War. From the US to Estonia, we’ll discuss how nation states are weaponizing social discussion against their adversaries to sow discord and advance their own influence and agenda, in […]
Read More - Combating Disinformation with Nina Jankowicz
The dark web is a collection of anonymous websites that are publicly available, yet hide the IP addresses to make it impossible for users to identify the host. It’s very common that sensitive information made available by data breaches ends up becoming available illicitly for sale on the dark web. According to the 2019 Global […]
Read More - Are Your Company Credentials Exposed on the Dark Web?
This week on the podcast, we cover the city of Portland’s ban on facial recognition technology for both public and private organizations, malware targeting VOIP soft switches, and an update from Microsoft on foreign hacking attempts into entities involved in this year’s US elections.
Read More - Election Security Update
This week on the podcast we cover an update on the MYSTIC surveillance platform, one of several covert and potentially illegal spying programs that former NSA contractor Edward Snowden leaked the existence of in 2014. Additionally, we’ll discus an update on the payment card skimming malware MageCart and a Python Remote Access Trojan. Episode Note: […]
Read More - Snowden Vindication?
The Netflix show (and even better book series) Altered Carbon (AC) takes place in a dark and dystopian future. Humanity has figured out how to “digitize” our brains and place them into other bodies, effectively allowing the richest in society to live forever. Although AC is fiction, it illustrates several real-life information security challenges extremely well. Let’s dive into three specifically. […]
Read More - Three Cybersecurity Tips from the Sci-Fi Hit Altered Carbon
Facial recognition software has been in the hot seat in recent months. Researchers, industry experts, businesses and policymakers have all raised concerns ranging from potential privacy repercussions to its role in discrimination and more. In fact, the University of Michigan recently published a study that linked the on-campus use of facial recognition to these issues. […]
Read More - Understanding Gender Bias in Facial Recognition Technology
Last week Graphiks reported multiple instances of Chinees Twitter bots promoting propaganda from China related to US elections. According to the report, Spamouflage, who has ties to the Chinees government, created this bot. Graphika called these pro-China bots “Dracula Botnet” because comments and profile descriptions come from Bram Stoker’s “Dracula.” A random sentence generator, or […]
Read More - Twitter Bots with Ties to China Spread Misinformation
This week on the podcast we cover the latest updates on Uber’s cover up of their 2016 data breach that impacted 57 million customers and employees. After that, we discuss a DDoS attack against the New Zealand Stock Exchange and an interesting malware delivery technique that researchers at ProofPoint recently disclosed.
Read More - Uber Cover Up
Once again, WatchGuard has dominated the competition in Network Product Guide’s annual IT World Awards for 2020 – securing a Grand Trophy Winner title and taking home a total of eight awards across several executive leadership and security product categories. As one of the industry’s premier excellence awards programs, the IT World Awards honors achievements […]
Read More - WatchGuard Named Grand Trophy Winner, Earns Eight Total Awards in Network Products Guide’s 2020 IT World Awards
WatchGuard is thrilled to share that Prakash Panjwani has been named in The Software Report’s prestigious list of the Top 50 SaaS CEOs of 2020! Based on nomination submissions from colleagues, peers and other software industry participants, this premier awards program recognizes exceptional CEOs at high performing organizations for their unique and effective leadership skills. To […]
Read More - WatchGuard’s Prakash Panjwani Recognized in The Software Report’s Top 50 SaaS CEOs of 2020
This week on the podcast, we cover Generative Pre-trained Transformer 3 or GPT-3, an AI model that a UC Berkeley student recently used to generate blog posts that fooled humans enough to propel one of them to the top of Hacker News. Additionally, we’ll discuss a P2P botnet that has been targeting SSH servers on […]
Read More - AI Bloggers
WatchGuard’s DNS-level protection and filtering service, DNSWatch, receives and processes numerous phishes every day. Many of these phishing attempts are monotonous and lack any unique qualities. However, periodically, a phishing attempt is triaged by our DNSWatch Support Team that stands out more than others. This short post will show a real-world phish caught by DNSWatch and how analysts were able to garner further information using trivial open-source tools because of a unique mistake by the attacker.
Read More - Catching a Rookie Mistake in a Facebook Phish
When it comes to cybersecurity practices and technologies, most would agree that the construction industry wouldn’t fall into the “early adopter” category. In a recent Industry Today article, WatchGuard CTO Corey Nachreiner explored the topic, noting that despite nearly half of all construction executives worrying their firms are vulnerable to threats, the majority of them […]
Read More - Four Key Steps to Securing the Construction Industry
This week on the podcast, we’re bringing back a favorite episode from the very beginnings of The 443 – Security Simplified where we dove in to the Dark Web and discussed how It works, where it came from, and who uses it now. This episode originally aired in 2018.
Read More - The Dark Web Rewind
With BlackHat’s online-only 2020 edition conference in the bag we take a look back at a few of our favorite briefings and discuss the takeaways as they apply to our industry. From a penetration test gone wrong to what security professionals can learn from an EMT, we cover the best talks from this year’s event.
Read More - BlackHat 2020 Recap
Controversy over social media giant TikTok has continued to soar in 2020. In July, WatchGuard CTO Corey Nachreiner explained the true personal privacy and security risks associated with using such foreign-based apps in the first segment of a two-part series for Forbes. His newly published second installment explores the potential dangers from a national security perspective. This is […]
Read More - Are TikTok and Other Foreign-Based Apps Dangerous? Part II
As part of its annual Black Unicorn Awards program, Cyber Defense Magazine has named WatchGuard’s Senior Vice President of Marketing and Channel, Michelle Welch, and Senior Vice President of Operations, Shari McLaren, in its list of the Top 100 Women in Cybersecurity for 2020! This awards program showcases those who are shaping the future of cybersecurity […]
Read More - WatchGuard’s Michelle Welch and Shari McLaren Honored in Cyber Defense Magazine’s Top 100 Women in Cybersecurity for 2020
With the Black Hat and DEF CON security conferences starting this week, albeit in an online-only mode, we decided to take a look through this year’s agenda and pick some of the talks we are most looking forward to. We’ve picked out talks ranging from new research to updates on recent vulnerabilities to discuss on […]
Read More - BlackHat and DEF CON Online
On Wednesday of this week, Eclypsium released a report on a vulnerability in GRUB2 that affects millions of devices with few exceptions. Normally used on a Linux system, GRUB2 accepts control from the UEFI secure boot process and starts bootup programs as well as the computers OS if it has one. This level of control […]
Read More - GRUB2 Boot Hole Breaks Secure Boot For Now
Last Thursday, the GPS and smartwatch firm Garmin suffered what was allegedly a massive, system-wide ransomware attack, forcing them to take down all of their services ranging from their apps to their support call centers. While Garmin has been tight-lipped as to the cause of the outage, multiple publications have reported that the company was […]
Read More - Garmin Suffers Massive WastedLocker Ransomware Attack
This week on The 443 – Security Simplified we discuss yet another alert from the UK National Cyber Security Center, this time on cyber-attacks targeting sporting organizations. We also take a quick dive into Meowing, a wave of destructive hacking that’s been targeting exposed databases online. Finally, with only a few weeks to go before […]
Read More - Meowing Databases
According to the indictment from the Eastern District of Washington, for at least the last 10 years hacker’s Li and Dong, sponsored by China, targeted US and international businesses including COVID-19 research and a chat app used by protestors in Hong Kong. In all, these men targeted companies in 11 countries. China won’t extradite them, […]
Read More - US Court Details State Sponsored Hackers From China
What is the new normal? One of the biggest challenges facing businesses today is navigating the COVID-19 pandemic and its aftermath. Opening and keeping businesses going while minimizing the risk to employees has meant that most companies have adopted new ways of working, often leading their offices, factories, retail stores and other facilities more or […]
Read More - Innovative Social Distancing Technology for the Post COVID-19 Pandemic
CRN has named WatchGuard Product Manager Sharon Li to its inaugural 2020 list of 100 Rising Female Stars Of The IT Channel! This exclusive new awards program identifies extraordinary women who are helping to shape the future of the IT channel through their dedication, hard work and innovation, positioning themselves as leaders and helping their organization succeed. Sharon’s recognition in this prestigious CRN list […]
Read More - CRN Recognizes WatchGuard’s Sharon Li in 2020 Rising Female Stars List
This week on The 443 – Security Simplified we cover a massive security breach at Twitter that resulted in an attacker taking over dozens of high-profile accounts ranging from former presidents to Apple. We also discuss the latest Microsoft patch Tuesday which included a fix for a critical security vulnerability in Windows DNS Server.
Read More - Twoops
The UK Cyber Security Center (NCSC) and Canada’s Communications Security Establishment (CSE) with the help of the NSA released an advisory today on attacks from APT29 (also known as ‘the Dukes’ or ‘Cozy Bear’), a group with ties to the Russian intelligence services. “APT29 is using custom malware known as ‘WellMess’ and ‘WellMail’ to target […]
Read More - UK, Canada and US All Warn of New Attacks on Covid-19 Research
Updated 07-16-2020 to include information gained by Vice’s Motherboard Twitter suffered what appeared to be a major breach midway through the day today when dozens of high-profile accounts ranging from former president Barack Obama to Apple in an attempt to peddle a bitcoin scam. Many of these accounts were protected using multi-factor authentication, indicating the […]
Read More - Twitter Suffers Major Security Breach
TikTok has been in the news lately over growing concerns about its privacy and security practices. In the first segment of a two-part series for Forbes, WatchGuard’s CTO Corey Nachreiner explains why many are worried about foreign-based apps like TikTok and explores the realistic personal privacy and security risks they present for users. Practices as simple as […]
Read More - Are TikTok and Other Foreign-based Apps Dangerous?
If you already had plans to test and roll out the various Microsoft Windows and Server updates that came out today as a part of Microsoft’s Patch Tuesday, you probably want to move a bit quicker. Among the various bug fixes are a series of patches for a critical “wormable” vulnerability in Windows DNS Server, […]
Read More - Critical Microsoft DNS Server Vulnerability – SIGRRed
Welcome back to another episode of The 443 – Security Simplified. This week in the news, we cover an open source vulnerability scanner from Google and phishing campaign that combines Microsoft 365 and Zoom. After that, we dive in to the world of facial recognition and discuss recent research from WatchGuard Threat Lab and other […]
Read More - Can We Trust Facial Recognition?