TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    CyberWire Daily

    The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

    Advertise

    Copyright: © 2024 N2K Networks, Inc. 706761

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    Downloading cracked software. [Research Saturday] Sep 30, 2023
    Show notes

    David Liebenberg from Cisco Talos joins to discussing Talos' discovery of cracked Microsoft Windows software being downloaded by enterprise users across the globe. Downloading and running this compromised software not only serves as an entry point for threat actors, but can serve as a gateway to access control systems and establish backdoors.

    Talos identified additional malware, including RATs, on endpoints running this cracked software, which allows an attacker to gain unauthorized remote access to the compromised system, providing the attacker with various capabilities, such as controlling the system, capturing screenshots, recording keystrokes and exfiltrating sensitive information.

    This research article was not published by Cisco Talos' team.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Malicious ads in a chatbot. A vulnerability gets some clarification. Cl0p switches from Tor to torrents. Influence operations as an adjunct to WMD. And NSA’s new AI Security Center. Sep 29, 2023
    Show notes

    Malicious ads in a chatbot. Google provides clarification on a recent vulnerability. Cl0p switches from Tor to torrents. Influence operations as an adjunct to weapons of mass destruction. Our guest Jeffrey Wells, former Maryland cyber czar and partner at Sigma7 shares his thoughts on what the looming US government shutdown will mean for the nation’s cybersecurity. Tim Eades from Cyber Mentor Fund discussing the 3 who’s a cybersecurity entrepreneur needs to consider. And NSA has a new AI Security Center.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/187


    Selected reading.

    Malicious ad served inside Bing's AI chatbot (Malwarebytes)

    Critical Vulnerability: WebP Heap Buffer Overflow (CVE-2023-4863) (Huntress)

    Google gives WebP library heap buffer overflow a critical score, but NIST rates it as high-severity (SC Media)

    A new Chrome 0-day is sending the Internet into a new chapter of Groundhog Day (Ars Technica)

    Google "confirms" that exploited Chrome zero-day is actually in libwebp (CVE-2023-5129) (Help Net Security)

    Google quietly corrects previously submitted disclosure for critical webp 0-day (Ars Technica)

    CL0P Seeds ^_- Gotta Catch Em All! (Unit 42)

    A ransomware gang innovates, putting pressure on victims but also exposing itself (Washington Post)

    2023 Department of Defense Strategy for Countering Weapons of Mass Destruction (US Department of Defense)

    NSA chief announces new AI Security Center, 'focal point' for AI use by government, defense industry (Breaking Defense)

    NSA starts AI security center with eye on China and Russia (Fortune)

    NSA is creating a hub for AI security, Nakasone says (Record)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Buckworm APT’s specialized tools. Cyberattack against Johnson Controls. Oversight panel reports on Section 702. Cyber in election security, and in the US industrial base. Hacktivism versus Russia. Sep 28, 2023
    Show notes

    The Budworm APT's bespoke tools. Johnson Controls sustains a cyberattack. The US Privacy and Civil Liberties Oversight Board reports on Section 702. The looming government shutdown and cyber risk. Cybersecurity in the US industrial base. X cuts back content moderation capabilities. In our Industry Voices segment, Nicholas Kathmann from LogicGate describes the struggle when facing low cost attacks. Sam Crowther from Kasada shares his team's findings on Stolen Auto Accounts. And Ukrainian hacktivists target Russian airline check-in systems.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/186


    Selected reading.

    Budworm: APT Group Uses Updated Custom Tool in Attacks on Government and Telecoms Org (Symantec Enterprise Blogs)

    Johnson Controls reports data breach after severe ransomware attack (BeyondMachines)

    Report on the Surveillance Program Operated Pursuant to Section 702 of the Foreign Intelligence Surveillance Act (U.S. Privacy and Civil Liberties Oversight Board)

    Split privacy board urges big changes to Section 702 surveillance law (Washington Post)

    Democrats fear cyberattacks as government shutdown looms (Nextgov.com)

    Aprio Releases U.S. National Manufacturing Survey, Highlighting the Need for Improved Operational Excellence, Digitization and Cybersecurity Practices (Aprio)

    Musk's X disabled feature for reporting electoral misinformation - researcher (Reuters)

    Musk’s X Cuts Half of Election Integrity Team After Promising to Expand It (The Information)

    Aeroflot, other airlines’ flights delayed over DDoS attack (Cybernews)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    What up in the underworld’s C2C markets. An update on the Sony hack claims. Notes on cyberespionage, from Russia, China, and parts unknown. And there’s a market for bugs. Sep 27, 2023
    Show notes

    A Joint Advisory warns of Beijing's "BlackTech" threat activity. ShadowSyndicate is a new ransomware as a service operation. A Smishing Triad in the UAE. Openfire flaw actively exploited against servers. AtlasCross is technically capable and, above all, "cautious." Xenomorph malware in the wild. DDoS and API attacks hit the financial sector. In our Industry Voices segment, Joe DePlato from Bluestone Analytics demystified dark net drug markets. Our guest is Richard Hummel from Netscout with the latest trending DDoS vectors. And the FCC chair announces plans to restore net neutrality.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/185


    Selected reading.

    CISA, NSA, FBI and Japan Release Advisory Warning of BlackTech, PRC-Linked Cyber Activity (Cybersecurity and Infrastructure Security Agency)

    Dusting for fingerprints: ShadowSyndicate, a new RaaS player? (Group-IB)

    Smishing Triad Stretches Its Tentacles into the United Arab Emirates (Security Affairs)

    Hackers actively exploiting Openfire flaw to encrypt servers (BleepingComputer)

    Vulnerability in Openfire messaging software allows unauthorized access to compromised servers (Dr.Web)

    Suspicious New Ransomware Group Claims Sony Hack (Dark Reading)

    Sony investigates cyberattack as hackers fight over who's responsible (BleepingComputer)

    Sony Investigating After Hackers Offer to Sell Stolen Data (SecurityWeek)

    Xenomorph Malware Strikes Again: Over 30+ US Banks Now Targeted (Threat Fabric)

    The High Stakes of Innovation: Attack Trends in Financial Services (Akamai)

    FACT SHEET: FCC Chairwoman Rosenworcel Proposes to Restore Net Neutrality Rules (Federal Communications Commission)

    Ukraine: Russian hackers infiltrating software supply chains (Computing)

    Russian hacking operations target Ukrainian law enforcement (CyberScoop)

    Ukraine accuses Russian spies of hacking law enforcement (Register)

    Russian hackers target Ukrainian government systems involved in war crimes investigations (Record)

    Ukraine Cyber Defenders Prepare for Winter (Bank Info Security)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Crooks phish for guests; spies phish for drone operators. ZenRAT is used in an info-stealing campaign. More MOVEit-related incidents (some involving Cl0p). DeFi platforms hit. The UK hunts forward. Sep 26, 2023
    Show notes

    An advanced phishing campaign hits hospitality industry. An information-stealing campaign deploys ZenRAT. More MOVEit-related data breaches are disclosed. Mixin Network suspends deposits and withdrawals. The OpenSea NFT market warns of third-party risk to its API. Phishing for Ukrainian military drone operators. Mr. Security Answer Person John Pescatore shares thoughts in Cisco acquiring Splunk. Ann Johnson from the Afternoon Cyber Tea podcast interviews Deb Cupp sharing a lesson in leadership. And the UK adopts a hunt-forward approach to cyber war.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/184


    Selected reading.

    Luxury Hotels Major Target of Ongoing Social Engineering Attack (Cofense)

    ZenRAT: Malware Brings More Chaos Than Calm (Proofpoint)

    More MOVEit-related data breaches are disclosed. (CyberWire)

    Mixin Network suspends deposits and withdrawals. (CyberWire)

    OpenSea NFT market warns of third-party risk to its API. (CyberWire)

    Threat Labs Security Advisory: New STARK#VORTEX Attack Campaign: Threat Actors Use Drone Manual Lures to Deliver MerlinAgent Payloads (Securonix)

    Ukrainian Military Targeted in Phishing Campaign Leveraging Drone Manuals (The Hacker News)

    British Army general says UK now conducting ‘hunt forward’ operations (Record)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Cyberespionage in East and Southeast Asia, for both intelligence collection and domestic security, Spyware tools tracked. Shifting cyber targets in Russia’s hybrid war. Securing the Super Bowl. Sep 25, 2023
    Show notes

    The Gelsemium APT is active against a Southeast Asian government. A multi-year campaign against Tibetan, Uighur, and Taiwanese targets. Stealth Falcon's new backdoor. Predator spyware is deployed against Apple zero-days. An update on Pegasus spyware found in Meduza devices. There’s a shift in Russian cyberespionage targeting. A rumor of cyberwar in occupied Crimea. In our Industry Voices segment, Amit Sinha, CEO of Digicert, describes digital trust for the software supply chain. Our guest is Arctic Wolf’s Ian McShane with insights on the MGM and Caesars ransomware incident. And if you’re looking for a Super Bowl pick, go with an egg-laying animal…and, oh, the NFL and CISA are noodling cyber defense for the big game.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/183


    Selected reading.

    Rare Backdoors Suspected to be Tied to Gelsemium APT Found in Targeted Attack in Southeast Asian Government (Unit 42)

    Rare Backdoors Suspected to be Tied to Gelsemium APT Found in Targeted Attack in Southeast Asian Government (IBM X-Force Exchange)

    Evasive Gelsemium hackers spotted in attack against Asian govt (BleepingComputer)

    Unit 42 Researchers Discover Multiple Espionage Operations Targeting Southeast Asian Government (Unit 42)

    EvilBamboo Targets Mobile Devices in Multi-year Campaign (Volexity)

    From Watering Hole to Spyware: EvilBamboo Targets Tibetans, Uyghurs, and Taiwanese (The Hacker News)

    Stealth Falcon preying over Middle Eastern skies with Deadglyph (We Live Security) t

    Deadglyph: Covertly preying over Middle Eastern skies (LABScon)

    New stealthy and modular Deadglyph malware used in govt attacks (BleepingComputer)

    Deadglyph: New Advanced Backdoor with Distinctive Malware Tactics (The Hacker News)

    0-days exploited by commercial surveillance vendor in Egypt (Google).

    PREDATOR IN THE WIRES: Ahmed Eltantawy Targeted with Predator Spyware After Announcing Presidential Ambitions (The Citizen Lab)

    New Apple Zero-Days Exploited to Target Egyptian ex-MP with Predator Spyware (The Hacker News)

    Egyptian presidential hopeful targeted by Predator spyware (Washington Post)

    Russian news outlet in Latvia believes European state behind phone hack (the Guardian)

    Exclusive: Russian hackers seek war crimes evidence, Ukraine cyber chief says (Reuters).

    Russian hackers trying to steal evidence of Moscow’s war crimes in Ukraine - cyber chief (Ukrinform).

    Large-scale cyberattack reported in occupied Crimea (The Kyiv Independent)

    NFL, CISA Look to Intercept Cyber Threats to Super Bowl LVIII (Dark Reading)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Threat intelligence discussion with Chris Krebs. [Special Edition] Sep 25, 2023
    Show notes

    In this extended interview, Simone Petrella sits down with Chris Krebs of the Krebs Stamos Group at the mWise 2023 Cybersecurity Conference to discuss threat intelligence .

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Merritt Baer: No one has to go down for you to go up. [CISO] [Career Notes] Sep 24, 2023
    Show notes

    This week our guest is Merritt Baer, a Field CISO from Lacework, and a cloud security unicorn, sits down to share her incredible story working through the ranks to get to where she is today. Before working at Lacework Merritt served in the Office of the CISO at Amazon Web Services, as part of a small elite team that formed a Deputy CISO. She provided technical cloud security guidance to AWS’ largest customers, like the Fortune 100, on security as a bottom line proposition. She also has experience in all three branches of government and the private sector and served as Lead Cyber Advisor to the Federal Communications Commission. Merritt shares some amazing advice for up and comers into the field, saying "my personal philosophy is that no one has to go down for you to go up. I'm always encouraging my colleagues, um, and other executives to be thinking about how we can, you know, steal, sharpen, steal, how we can be good for each other, how we can collaborate, how we can, um, create more strengths in one another." We thank Merritt for sharing her story with us.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Behind the Google shopping ad masks. [Research Saturday] Sep 23, 2023
    Show notes

    Maxim Zavodchik from Akamai joins Dave to discuss their research on "Xurum: New Magento Campaign Discovered." Akamai researchers have discovered an ongoing server-side template injection campaign that is exploiting digital commerce websites. This campaign targets Magento 2 shops, and was dubbed Xurum in reference to the domain name of the attacker’s command and control (C2) server.

    The research states "The attacker uses an advanced web shell named “wso-ng” that is activated only when the attacker sends the cookie “magemojo000” to the backdoor “GoogleShoppingAds” component."

    The research can be found here:

    • Xurum: New Magento Campaign Discovered

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Enter Sandman. A look at an initial access broker. Iran’s OilRig hits Israeli targets. Cyber ops and soft power. Update on casino ransomware attacks. Bermuda’s government sustains cyberattacks. Sep 22, 2023
    Show notes

    A new APT is found: enter Sandman. Tracking an initial access broker called Gold Melody. Iran’s OilRig group is active against Israeli targets. Cyber ops as an instrument of soft power. Recovery and investigation in the casino ransomware attacks. In our Solutions Spotlight, Simone Petrella speaks with MK Palmore from Google Cloud about talent retention and the cybersecurity skills gap. Our guest is Kristen Marquardt of Hakluyt with advice for cyber startups. And Bermuda points to Russian threat actors.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/182


    Selected reading.

    Sandman APT | A Mystery Group Targeting Telcos with a LuaJIT Toolkit (SentinelOne)

    GOLD MELODY: Profile of an Initial Access Broker (Secureworks)

    OilRig’s Outer Space and Juicy Mix: Same ol’ rig, new drill pipes (We Live Security)

    Cyber Soft Power | China's Continental Takeover (SentinelOne)

    MGM Resorts computers back up after 10 days as analysts eye effects of casino cyberattacks (AP News)

    MGM Restores Casino Operations 10 Days After Cyberattack (Dark Reading)

    MGM Resorts computers back up after being down 10 days due to casino cyberattacks (CBS News)

    MGM says its recovered from cyberattack, employees tell different story (Cybernews)

    'Power, influence, notoriety': The Gen-Z hackers who struck MGM, Caesars (Reuters)

    Apple emergency updates fix 3 new zero-days exploited in attacks (BleepingComputer)

    Russia linked to cyberattack on government services (Royal Gazette)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Previous 1 119 120 121 122 123 378 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights