TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    CyberWire Daily

    The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

    Advertise

    Copyright: © 2024 N2K Networks, Inc. 706761

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    DPRK cyberespionage update. New cybercriminal TTPs. The state of DevSecOps. Hacktivism and the nation-state. Cyberwar lessons learned. A free decryptor for Key Group ransomware. Sep 01, 2023
    Show notes

    A VMConnect supply chain attack is connected to the DPRK. Reports of an aledgedly "fully undetectable information stealer." DB#JAMMER brute forces exposed MSSQL databases. A Cyberattack on a Canadian utility. The state of DevSecOps. A look at hacktivism, today and beyond. Betsy Carmelite from Booz Allen on threat intelligence as part of a third-party risk management program. Our guest is Adam Marré from Arctic Wolf Networks, with an analysis of Chinese cyber tactics. And a free decryptor is released for Key Group ransomware.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/168


    Selected reading.

    VMConnect supply chain attack continues, evidence points to North Korea (ReversingLabs)

    Securonix Threat Labs Security Advisory: Threat Actors Target MSSQL Servers in DB#JAMMER to Deliver FreeWorld Ransomware (Securonix)

    Montreal electricity organization latest victim in LockBit ransomware spree (Record)

    LockBit ransomware gang targets electrical infrastructure organization in Montreal (teiss)

    [Analyst Report] SANS 2023 DevSecOps Survey (Synopsys)

    SANS 2023 DevSecOps Survey (Application Security Blog)

    Government Agencies Report New Russian Malware Targets Ukrainian Military (National Security Agency/Central Security Service)

    Russian military hackers take aim at Ukrainian soldiers' battle plans, US and allies say (CNN)

    Ukraine: The First Cyber Lessons (AFCEA International)

    The Return of Hacktivism: A Temporary Reprise or Here for Good? (ReliaQuest)

    Decrypting Key Group Ransomware: Emerging Financially Motivated Cyber Crime Gang (EclecticIQ)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    GREF and Earth Estries from China. GRU’s Sandworm surfaces again, wielding “Infamous Chisel.” Hacktivist nuisances in the hybrid war. A zero-day is discovered. And the Wolverines are back online. Aug 31, 2023
    Show notes

    China deploys tools used against Uyghurs in broader espionage. The Five Eyes call out a GRU cyberespionage campaign. Russian hacktivist auxiliaries hit Czech banks and the platform formerly known as Twitter. A Spring-Kafka zero-day is discovered. Deepen Desai from Zscaler explains RedEnergy Stealer-as-a-Ransomware attacks. Luke Nelson of UHY Consulting on ransomware’s impact on schools. And, hey, go Wolverines: the University of Michigan overcomes a cyberattack that delayed the academic year.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/167


    Selected reading.

    BadBazaar espionage tool targets Android users via trojanized Signal and Telegram apps (We Live Security)

    Earth Estries Targets Government, Tech for Cyberespionage (Trend Micro)

    Infamous Chisel Malware Analysis Report (Cybersecurity and Infrastructure Security Agency CISA)

    UK and allies support Ukraine calling out Russia's GRU for new malware campaign (NCSC)

    Hackers Attack Czech Banks, Demanding End of Support For Ukraine (Brno Daily)

    More Russian attacks on Czech banks: Hackers call for end of support to Ukraine (Expats.cz)

    Anonymous Sudan hacks X to put pressure on Elon Musk over Starlink (BBC News)

    Contrast Assess uncovers Spring-Kafka deserialization zero day (Contrast Security)

    U. Michigan restores campus internet after cyberattack disrupts first week of classes (EdScoop)

    Internet restored on University of Michigan campus, ongoing issues still expected (mlive)

    University of Michigan isn't disclosing details of internet outage cyberattack (Detroit Free Press)

    Expert weighs in on school cyberattacks as University of Michigan makes progress on internet outages (CBS News)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    An international hunt bags Qakbot’s infrastructure. Anticipating remediation. Adversaries in the middle. More effective phishbait. Air travel disruption was a glitch, not an attack. Hybrid war update. Aug 30, 2023
    Show notes

    An international operation takes down Qakbot. Chinese threat actors anticipated Barracuda remediations. A look at adversary-in-the-middle attacks, making phishbait more effective and the emergence of a new ransomware threat. Narrative themes in Russian influence operations. My conversation with Natasha Eastman from (CISA), Bill Newhouse from (NIST), and Troy Lange from (NSA) to discuss their recent joint advisory on post-quantum readiness. Microsoft’s Ann Johnson from Afternoon Cyber Tea speaks with Cyber Threat Alliance President and CEO Michael Daniel about the current state of cybercrime. And when toilet bowls are outlawed, only outlaws will have toilet bowls.


    Listen to the full conversation with Natasha Eastman, Bill Newhouse, and Troy Lange here: A joint advisory on post-quantum readiness.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/165


    Selected reading.

    Operation Duck Hunt bags Qakbot. (CyberWire)

    FBI, Partners Dismantle Qakbot Infrastructure in Multinational Cyber Takedown (Federal Bureau of Investigation)

    Qakbot Malware Disrupted in International Cyber Takedown (US Department of Justice)

    Law Enforcement Takes Down Qakbot (Secureworks)

    Qakbot: Takedown Operation Dismantles Botnet Infrastructure (Symantec)

    Chinese APT Was Prepared for Remediation Efforts in Barracuda ESG Zero-Day Attack (SecurityWeek)

    Phishing-as-a-Service Gets Smarter: Microsoft Sounds Alarm on AiTM Attacks (The Hacker News)

    The Lure of Subject Lines in Phishing Emails - How Threat Actors Utilize Dates to Trick Victims (Cofense)

    The Emergence of Ransomed: An Uncertain Cyber Threat in the Making (Flashpoint)

    Cancelled flights: Air traffic disruption caused by flight data issue (BBC News)

    Russian Offensive Campaign Assessment, August 29, 2023 (Institute for the Study of War)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    A joint advisory on post-quantum readiness. [Special Edition] Aug 30, 2023
    Show notes

    In this extended interview, Dave Bittner sits down with Natasha Eastman from the Cybersecurity and Infrastructure Security Agency (CISA), Bill Newhouse from the National Institute of Standards and Technology (NIST), and Troy Lange from the National Security Agency (NSA) to discuss their their recent joint advisory on post-quantum readiness and how to prepare for post-quantum cryptography.

    You can find the joint advisory here:

    • Quantum-Readiness: Migration to Post-Quantum Cryptography
    • Quantum computing: A threat to asymmetric encryption.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Name collision. Spawn of LockBit. Quishing the unwary and the hasty. Trends in healthcare cybersecurity. Inquiries surrounding Russia’s hybrid war against Ukraine. Aug 29, 2023
    Show notes

    Name collision as a DNS risk. A LockBit derivative is active against targets in Spain. QR codes as phishbait. Cybersecurity trends in Healthcare. A Russian hacktivist auxiliary hits Polish organizations, while investigation of railroad incidents in Poland continues. Ben Yelin looks at the SEC cracking down on NFTs. Mr. Security Answer Person John Pescatore opens up the listener mail bag. And a look at a probably accidental glitch affecting air travel in the UK.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/164


    Selected reading.

    What's in a name? Strange behaviors at top-level domains creates uncertainty in DNS (Cisco Talos)

    Spain warns of LockBit Locker ransomware phishing attacks (BleepingComputer)

    Think Before You Scan: The Rise of QR Codes in Phishing (Trustwave SpiderLabs)

    78% of Healthcare Organizations Experienced Cyber Incidents in Past Year, 60% of Which Impacted Patient Care (Claroty)

    Polish stock exchange, banks knocked offline by pro-Russian hackers (Cybernews)

    Two Men Arrested Following Poland Railway Hacking (SecurityWeek)

    Century-old technology hack brought 20 trains to a halt in Poland (Cybernews)

    Poland investigates train mishaps for possible Russian connection (Washington Post)

    Flight chaos ‘to last for days’ after air traffic control failure (The Telegraph)

    UK flight chaos could last for days, airline passengers warned (the Guardian)

    Government can’t rule out cyber attack caused air traffic chaos (MSN)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    DPRK's Lazarus Group exploits ManageEngine issues. SIM swapping as a threat to organizations. Ransomware hits a cloud provider. Spawn of LockBit. Train whistling. Influence laundering. Aug 28, 2023
    Show notes

    The DPRK's Lazarus Group exploits ManageEngine issues. A Data breach at Kroll is traced to SIM swapping. Unusually destructive ransomware hits CloudNordic. Spawn of LockBit. Polish trains are disrupted by hacktivists. Rick Howard looks at the MITRE attack framework. Our guests are Andrew Hammond and Erin Dietrick from the International Spy Museum. And Influence laundering as a long-term disinformation tactic.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/163


    Selected reading.

    North Korean APT Hacks Internet Infrastructure Provider via ManageEngine Flaw (SecurityWeek)

    Lazarus Group exploited ManageEngine vulnerability to target critical infrastructure (Help Net Security)

    Cyber scams keep North Korean missiles flying (Radio Free Asia)

    Claimant Data Breached in Genesis, FTX and BlockFi Bankruptcy Cases (Wall Street Journal)

    Kroll data breach exposes info of FTX, BlockFi, Genesis creditors (BleepingComputer)

    Crypto investor data exposed by a SIM swapping attack against a Kroll employee (Security Affairs)

    Kroll Employee SIM-Swapped for Crypto Investor Data (KrebsOnSecurity)

    Kroll Suffers Data Breach: Employee Falls Victim to SIM Swapping Attack (The Hacker News)

    FTX bankruptcy handler Kroll discloses data breach (The Stack)

    CloudNordic Faces Severe Data Loss After Ransomware Attack (Hackread)

    CloudNordic loses most customer data after ransomware attack | TechTarget (Security)

    Lockbit leak, research opportunities on tools leaked from TAs (SecureList)

    LockBit 3.0 Ransomware Builder Leak Gives Rise to Hundreds of New Variants (The Hacker News)

    Poland investigates cyber-attack on rail network (BBC News)

    Poland investigates hacking attack on state railway network (Reuters)

    Hackers bring down Poland’s train network in massive cyber attack (Ticker News)

    The Cheap Radio Hack That Disrupted Poland's Railway System (WIRED)

    Russia Pushes Long-Term Influence Operations Aimed at the U.S. and Europe (New York Times)

    Newly declassified US intel claims Russia is laundering propaganda through unwitting Westerners (CNN Politics)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Dina Haines: Keep the boat afloat. [Partnership manager] [Career Notes] Aug 27, 2023
    Show notes

    This week, we welcome Dina Haines, an Industry Partnership Manager with the National Security Agency's Cybersecurity Collaboration Center. Dina found from a young age, she was always interested in the field, taking after her father who worked in the space industry, paving the way for her to fall in love with the field. She worked in the private sector for a bit, moving around every now and again, eventually landing the position she works now. Dina says her day to day job is helping the NSA to bend and protect cyberspace by bringing in private industry. She says "I try to spend a lot of time listening and seeing where people, where they're coming from, where they're at, you know, potentially in their career, where they're at in their job that day, and then try to, um, support them and bring them up and, and float the entire boat." We thank Dina for sharing her story with us.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Google's not being ghosted from vulnerabilities. [Research Saturday] Aug 26, 2023
    Show notes

    Tal Skverer from Astrix Security joins to discuss their work on "GhostToken – Exploiting GCP application infrastructure to create invisible, unremovable trojan app on Google accounts." Astrix’s Security Research Group revealed a 0-day flaw in Google’s Cloud Platform (GCP) on June 19, 2022, which was found to affect all Google users.

    The research states "The vulnerability, dubbed “GhostToken”, could allow threat actors to change a malicious application to be invisible and unremovable, effectively leaving the victim’s Google account infected with a trojan app forever." Google issued a patch to this vulnerability in April of this year, but researchers explain why this can be severe.

    The research can be found here:

    • GhostToken – Exploiting GCP application infrastructure to create invisible, unremovable trojan app on Google accounts

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Phishing kits in the C2C market. Cyberespionage, Pyongyang and Beijing editions. Ransomware under the radar. A new hacktivist group says it doesn’t much care for NATO corruption. Aug 25, 2023
    Show notes

    Telekopye and the rise of commodified phishing kits. Lazarus Group fields new malware. Implications of China's campaign against vulnerable Barracuda appliances. Abhubllka ransomware's targeting and low extortion demands. Malek Ben Salem of Accenture outlines generative AI Implications to spam detection. Jeff Welgan, Chief Learning Officer at N2K Networks, unpacks the NICE framework and strategic workforce intelligence. And a new hacktivist group emerges, and takes a particular interest in NATO members.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/162


    Selected reading.

    eBay Users Beware Russian 'Telekopye' Telegram Phishing Bot (Dark Reading)

    Telekopye: Hunting Mammoths using Telegram bot (ESET)

    Lazarus Group's infrastructure reuse leads to discovery of new malware (Cisco Talos Blog)

    FBI fingers China for attacks on Barracuda email appliances (Register)

    Suspected PRC Cyber ActorsContinue to Globally Exploit Barracuda ESG Zero-Day Vulnerability (CVE-2023-2868) (FBI)

    Identifying ADHUBLLKA Ransomware: LOLKEK, BIT, OBZ, U2K, TZW Variants (Netenrich)

    Ransomware ecosystem targeting individuals, small firms remains robust (Record)

    Ransomware With an Identity Crisis Targets Small Businesses, Individuals (Dark Reading)

    Hacking group KittenSec claims to 'pwn anything we see' to expose corruption (CyberScoop)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Trends in the cybercriminal underworld. The prosecution of Lapsus$ and Tornado Cash. More developments in Russia’s hybrid war. Aug 24, 2023
    Show notes

    There’s a new sophistication in BEC campaigns. Trends in brand impersonation–crooks still like to pretend they’re from Redmond. The future of Russian influence operations in the post-Prigozhin era. Andrea Little Limbago from Interos shares insights on the new cyber workforce strategy. In our latest Threat Vector segment David Moulton of Palo Alto Networks is joined by Stephanie Ragan, Senior Consultant at Unit 42 to discuss Muddled Libra. And more on the doxing of a deputy Duma chair, who seems to have been selling hot iPhones as a side hustle (maybe). And the growing problem of Synthetic identity fraud.


    On this segment of Threat Vector, Stephanie Ragan, Senior Consultant at Unit 42, joins host David Moulton to discuss Muddled Libra.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/162


    Selected reading.

    BEC Trends: Payroll Diversion Dominates and Sneaky Multi-Persona Attacks Emerge (Trustwave)

    Q2 2023 Threat Landscape Report: All Roads Lead to Supply Chain Infiltrations (Kroll)

    Microsoft Impersonated Most in Phishing Attacks Among Nearly 350 Brands (Abnormal Security)

    TransUnion Analysis Finds Synthetic Identity Fraud Growing to Record Levels (TransUnion)

    Ukraine at D+546: Yevgeny Prigozhin dies in a plane crash. (CyberWire)

    Without Prigozhin, expect some changes around the edges on Russian influence operations (Washington Post)

    2023 H1 Global Threat Analysis Report (Radware)

    Lapsus$: Court finds teenagers carried out hacking spree (BBC News)

    British court convicts two teen Lapsus$ members of hacking tech firms (Record)

    Treasury Designates Roman Semenov, Co-Founder of Sanctioned Virtual Currency Mixer Tornado Cash (U.S. Department of the Treasury)

    Tornado Cash Founders Charged With Money Laundering And Sanctions Violations (U.S. Attorney for the Southern District of New York)

    Russian Duma leader’s emails hacked and leaked (Cybernews)

    Ukrainian hackers expose money laundering and sanction evasion by senior Russian politician (teiss)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Previous 1 122 123 124 125 126 378 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights