TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    CyberWire Daily

    The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

    Advertise

    Copyright: © 2024 N2K Networks, Inc. 706761

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    Chinese threat actors reel in Barracuda appliances. Diicot: the gang formerly known as Mexals, with Romanian ties. Recent Russian cyberespionage against Ukraine and its sympathizers. Jun 15, 2023
    Show notes

    A Chinese threat actor exploits a Barracuda vulnerability. The upgraded version of the Android GravityRAT can exfiltrate WhatsApp messages. Cybercriminals pose as security researchers to propagate malware. Updates on the Vidar threat operation. A new Romanian hacking group has emerged. Shuckworm collects intelligence, and may support targeting. The Washington Post’s Tim Starks explains the section 702 debate. Our guest is Rotem Iram from At-Bay with insights on email security. And Russia's Cadet Blizzard.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/115


    Selected reading.

    Android GravityRAT goes after WhatsApp backups (ESET)

    Quarterly Adversarial Threat Report (Facebook)

    Barracuda ESG Zero-Day Vulnerability (CVE-2023-2868) Exploited Globally by Aggressive and Skilled Actor, Suspected Links to China (Mandiant)

    GravityRAT - The Two-Year Evolution Of An APT Targeting India (Cisco Talos)

    Fake Security Researcher GitHub Repositories Deliver Malicious Implant (VulnCheck)

    Darth Vidar: The Aesir Strike Back (Team Cymru)

    Tracking Diicot: an emerging Romanian threat actor (Cado Security)

    Shuckworm: Inside Russia’s Relentless Cyber Campaign Against Ukraine (Symantec)

    Cadet Blizzard emerges as a novel and distinct Russian threat actor (Microsoft)

    Destructive malware targeting Ukrainian organizations (Microsoft)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    CISA Alert AA23-165A – Understanding Ransomware Threat Actors: LockBit. Jun 15, 2023
    Show notes

    CISA, FBI, the MS-ISAC, and international partners are releasing this Cybersecurity Advisory to detail LockBit ransomware incidents and provide recommended mitigations to enable network defenders to proactively improve their organization’s defenses against this ransomware operation.

    AA23-165A Alert, Technical Details, and Mitigations

    Stopransomware.gov is a whole-of-government approach that gives one central location for ransomware resources and alerts.

    See the Center for Internet Security (CIS) Critical Security Controls (CIS Controls) https://www.cisecurity.org/insights/white-papers/cis-community-defense-model-2-0 for information on strengthening an organization’s cybersecurity posture through implementing a prescriptive, prioritized, and simplified set of best.

    See the CIS Community Defense Model 2.0 (CDM 2.0) for the effectiveness of the CIS Controls against the most prevalent types of attacks and how CDM 2.0 can be used to design, prioritize, implement, and improve an organization’s cybersecurity program.

    See Blueprint for Ransomware Defense for a clear, actionable framework for ransomware mitigation, response, and recovery built around the CIS Controls.

    No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

    U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov

    To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    A Joint Advisory on LockBit. AI chatbots: the grammarians of tomorrow. KillNet makes a deal with the Devil (Sec). The private-sector’s piece in the hybrid war puzzle. Jun 14, 2023
    Show notes

    The Five Eyes, alongside a couple of allies, issue a LockBit advisory. AI aids in proofreading phishing attacks. Anonymous Sudan mounts nuisance-level DDoS attacks against US companies. France alleges a disinformation campaign conducted by Russian actors. KillNet says it's partnered with the less-well-known Devil Sec. The private cybersecurity industry's effect on the war in Ukraine. Carole Theriault ponders oversharing on social media. Our guest is Duncan Jones from Quantinuum on the threats of Harvest Now, Decrypt Later tactics. And a note on this month’s Patch Tuesday.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/114


    Selected reading.

    Understanding Ransomware Threat Actors: LockBit (Joint Cybersecurity Advisory)

    U.S. Measures in Response to the Crisis in Sudan (US Department of State)

    Generative AI Enables Threat Actors to Create More (and More Sophisticated) Email Attacks (Abnormal Security)

    France Accuses Russia of Online Disinformation Campaign (Bloomberg)

    The Private Sector’s Evolving Role in Conflict—From Cyber Assistance to Intelligence (R Street)

    Microsoft Patches Critical Windows Vulns, Warns of Code Execution Risks (SecurityWeek)

    Patch Tuesday: Critical Flaws in Adobe Commerce Software (SecurityWeek)

    Patch Tuesday fixes 4 critical RCE bugs, and a bunch of Office holes (Naked Security)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    CISA's new Binding Operational Directive. “CosmicEnergy” tool doesn’t pose a cosmic threat. Hackers’ homage to fromage in attacks against the Swiss government. Industry advice for the White House. Jun 13, 2023
    Show notes

    CISA issues a new Binding Operational Directive. An update on CosmicEnergy. Hackers’ homage to fromage in attacks against the Swiss government. Ukraine's Cyber Police shut down a pro-Russian bot farm. Clothing and footwear retailers see impersonation and online fraud. A 2021 ransomware attack contributed to a hospital closing. A proof-of-concept exploit of a patched MOVEit vulnerability. An industry letter calls for a new framework on the White House cybersecurity strategy. Joe Carrigan examines a ChatGPT fueled phishing scam. Our guest is Neha Rungta, Applied Science Director at AWS Identity discussing Amazon Verified Permissions. And trends in cyber risks for small and medium businesses.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/113


    Selected reading.

    Binding Operational Directive 23-02 (US Cybersecurity and Infrastructure Security Agency)

    COSMICENERGY: New OT Malware Possibly Related To Russian Emergency Response Exercises (Mandiant)

    Dragos Analysis Determines COSMICENERGY Is Not an Immediate Threat (Dragos)

    More than 4,000 bots to discredit the Defense Forces of Ukraine and spread propaganda in favor of Russia: the police of Vinnytsia eliminated a large-scale bot farm (Ukraine Cyber Police)

    Ukraine police raid social media bot farm accused of pro-Russia propaganda (The Record)

    Widespread Brand Impersonation Scam Campaign Targeting Hundreds of the Most Popular Apparel Brands (Bolster)

    An Illinois hospital is the first health care facility to link its closing to a ransomware attack (NBC News)

    Ransomware attack causes Illinois hospital to close (Becker’s Hospital Review)

    New BlackFog research: 61% of SMBs were victims of a cyberattack in the last year (BlackFog)

    Switzerland warns that a ransomware gang may have accessed government data (The Record)

    Swiss government warns of ongoing DDoS attacks, data leak (BleepingComputer)

    Swiss Government Targeted by Series of Cyber-Attacks (Infosecurity Magazine)

    DDoS attack on Federal Administration: various Federal Administration websites and applications unavailable (The Federal Council of the Swiss Government)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Unpatched instances and vulnerabilities rear their ugly heads. Russian telecom provider targeted in an act of “cyber anarchy.” Alleged crypto heist conspirators face charges. Jun 12, 2023
    Show notes

    Attacks against unpatched versions of Visual Studio and win32k continue. Progress Software patches two MOVEit vulnerabilities. The Cyber Anarchy Squad claims to have taken down a Russian telecommunications provider's infrastructure. RomCom resumes its activity in the Russian interest. Deepen Desai of Zscaler describes Nevada ransomware. Our guest is Clarke Rodgers from Amazon Web services with insights on what CISOs say to each other when no one else is listening?. And the Mt. Gox hacking indictment has been unsealed.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/112


    Selected reading.

    Online muggers make serious moves on unpatched Microsoft bugs (The Register)

    Analysis of CVE-2023-29336 Win32k Privilege Escalation Vulnerability (with POC) (Numen)

    MOVEit Transfer and MOVEit Cloud Vulnerability (Progress Software)

    MDE Affected by Global Data Breach (Minnesota Department of Education)

    Hackers Use Stolen Student Data Against Minneapolis Schools in Brazen New Threat (The 74)

    Ofcom statement on MOVEit cyber attack (Ofcom)

    Ukrainian hackers take down service provider for Russian banks (BleepingComputer)

    Pro-Ukraine hackers claim to take down Russian internet provider (The Record)

    Pro-Ukraine Cyber Anarchy Squad claims the hack of the Russian telecom provider Infotel JSC (Security Affairs)

    RomCom Resurfaces: Targeting Politicians in Ukraine and U.S.-Based Healthcare Providing Aid to Refugees from Ukraine (BlackBerry)

    Mt. Gox's Hackers Are 2 Russian Nationals, U.S. DOJ Alleges in Indictment (CoinDesk)

    Russian nationals accused of Mt. Gox bitcoin heist, shifting stolen funds to BTC-e (The Record)

    Russian Nationals Charged With Hacking One Cryptocurrency Exchange and Illicitly Operating Another (US Department of Justice)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Nadir Izrael: Play to your strengths. [CTO] [Career Notes] Jun 11, 2023
    Show notes

    Nadir Izrael, co-founder and CTO from Armis, sits down to share his story. Nadir started his love of cyber when he became a software developer at the age of 12. He always had a passion for making things work better and asking questions. Once he joined the 8200 unit in Israel, he was able to focus his interests on physics, which led him to making the discovery of wanting to start his own business. After he started building his company is when he learned to take smart and innovative risks at work and making it a way of life. Nadir shares advice, saying "Playing to your strengths, maximizes the odds of success and every other consideration lowers them inevitably, or at least, uh, um, kind of shrinks, I guess the, the probability space for success." He thinks playing to ones strengths is the best a leader can do to create the most success for their team. We thank Nadir for sharing his story with us.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    A new botnet takes a frosty bite out of the gaming industry. [Research Saturday] Jun 10, 2023
    Show notes

    Our guest, Allen West from Akamai's SIRT team, joins Dave to discuss their research on "The Dark Frost Enigma: An Unexpectedly Prevalent Botnet Author Profile." Akamai found this new botnet was targeting the gaming industry, modeled after Qbot, Mirai, and other malware strains. The botnet has expanded to encompass hundreds of compromised devices.

    The research states "through reverse engineering and patching the malware binary, our analysis determined the botnet's attack potential at approximately 629.28 Gbps with its UDP flood attacks." Akamai researchers do a deep dive into the motives behind the attacks, the effectiveness of the attack, and how the law has been handling similar cases.

    The research can be found here:

    • The Dark Frost Enigma: An Unexpectedly Prevalent Botnet Author Profile

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    “Better Minecraft” improves gameplay, while also lifting your data. Hallucinations, defamation, and legal malpractice, oh my! Asylum Ambuscade and other wartime notes. Jun 09, 2023
    Show notes

    Barracuda Networks urges replacement of their gear. Fractureiser infects Minecraft mods. ChatGPT sees a court date over hallucinations and defamation. Asylum Ambuscade engages in both crime and espionage. The US delivers Ukraine Starlink connectivity. DDoS attacks hit the Swiss parliament's website. My conversation with Eric Goldstein, Executive Assistant Director for Cybersecurity at CISA. Our guest is Delilah Schwartz from Cybersixgill discussing how the Dark Web is evolving with new technologies like ChatGPT. And BEC crooks see their day in court.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/111


    Selected reading.

    Barracuda Email Security Gateway Appliance (ESG) Vulnerability (Barracuda)

    CVE-2023-2868 (MITRE)

    ACT government falls victim to Barracuda’s ESG vulnerability (CSO Online)

    CVE-2023-2868: Total Compromise of Physical Barracuda ESG Appliances (Rapid7)

    CVE-2023-2868 Detail (National Institute of Standards and Technology)

    Infected Minecraft Mods Lead to Multi-Stage, Multi-Platform Infostealer Malware (Bitdefender)

    New Fractureiser malware used CurseForge Minecraft mods to infect Windows, Linux (BleepingComputer)

    IN THE SUPERIOR COURT OF FULTON COUNTY (Superior Court of Fulton County)

    OpenAI Hit With First Defamation Suit Over ChatGPT Hallucination (Bloomberg Law)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    CISA Alert AA23-158A – #StopRansomware: CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability. Jun 09, 2023
    Show notes

    FBI and CISA are releasing this joint CSA to disseminate known CL0P ransomware IOCs and TTPs identified through FBI investigations as recently as June 2023.

    AA23-158A Alert, Technical Details, and Mitigations

    Stopransomware.gov is a whole-of-government approach that gives one central location for ransomware resources and alerts.

    Resource to mitigate a ransomware attack: CISA-Multi-State Information Sharing and Analysis Center (MS-ISAC) Joint Ransomware Guide.

    Zero-Day Vulnerability in MOVEit Transfer Exploited for Data Theft | Mandiant

    MOVEit Transfer Critical Vulnerability (May 2023) - Progress Community

    MOVEit Transfer Critical Vulnerability CVE-2023-34362 Rapid Response (huntress.com)

    No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

    U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov

    To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    ChatGPT continues to become more human, this time through hallucinations. Following Cl0p. Instagram works against CSAM. And data protection advice from an expert in attacking it. Jun 08, 2023
    Show notes

    ChatGPT takes an unexpectedly human turn in having its own version of hallucinations. Updates on Cl0p’s ransom note, background, and recent promises. Researchers look at Instagram’s role in promoting CSAM. A look at KillNet's reboot. Andrea Little Limbago from Interos shares insight on cyber’s human element. Our guest is Aleksandr Yampolskiy from SecurityScorecard on how CISOs can effectively communicate cyber risk to their board. And a hacktivist auxiliary’s stellar advice for protecting your data.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/110


    Selected reading.

    Can you trust ChatGPT’s package recommendations? (Vulcan)

    Ransomware group Clop issues extortion notice to ‘hundreds’ of victims (The Record)

    MOVEit cyber attack: Cl0p sparks speculation that it’s lost control of hack (ITpro)

    Responding to the Critical MOVEit Transfer Vulnerability (CVE-2023-34362) (Kroll)

    MOVEit Transfer Critical Vulnerability (May 2023) (Progress)

    Cybergang behind N.S. breach says it erased stolen data, but experts urge caution (CBC Canada)

    Most SMBs admit to paying ransomware demands - here's why (TechRadar)

    Instagram Connects Vast Pedophile Network (Wall Street Journal)

    Addressing the distribution of illicit sexual content by minors online (Stanford University)

    Rebooting Killnet, a New World Order and the End of the Tesla Botnet (Radware)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Previous 1 130 131 132 133 134 378 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights