TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    CyberWire Daily

    The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

    Advertise

    Copyright: © 2024 N2K Networks, Inc. 706761

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    8 GoAnywhere MFT breaches and counting. [Research Saturday] May 27, 2023
    Show notes

    This week, our guests are Emily Austin and Himaja Motheram from Censys and their sharing their research - "Months after first GoAnywhere MFT zero-day attacks, Censys still sees about 180 public admin panels." In early February 2023, Censys researchers discovered a zero-day RCE vulnerability in Fortra’s “GoAnywhere MFT” (Managed File Transfer) software.

    After finding this the Clop ransomware gang claimed that they exploited this vulnerability to breach the data of 130 organizations and Censys found other ransomware groups were jumping on the bandwagon. They said " A single vulnerable instance has the potential to serve as a gateway to a data breach that could potentially impact millions of individuals."

    The research can be found here:

    • Months after first GoAnywhere MFT zero-day attacks, Censys still sees ~180 public admin panels

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    CosmicEnergy: OT and ICS malware from Russia, maybe for red teaming. Updates on Volt Typhoon. Legion malware upgraded for the cloud. Natural-disaster-themed online fraud. May 26, 2023
    Show notes

    CosmicEnergy is OT and ICS malware from Russia, maybe for red teaming, maybe for attack. Updates on Volt Typhoon, China’s battlespace preparation in Guam and elsewhere. In the criminal underworld, Legion malware has been upgraded for the cloud. Johannes Ullrich from SANS examines time gaps in logging. Our guest is Kevin Kirkwood from LogRhythm with a look at extortion attempts and ransomware. And Atlantic hurricane season officially opens next week: time to batten down those digital hatches.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/102


    Selected reading.

    COSMICENERGY: New OT Malware Possibly Related To Russian Emergency Response Exercises (Mandiant)

    People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection (Joint Advisory)

    Volt Typhoon targets US critical infrastructure with living-off-the-land techniques (Microsoft)

    China hits back at 'the empire of hacking' over Five Eyes US cyber attack claims (ABC)

    Updates to Legion: A Cloud Credential Harvester and SMTP Hijacker (Cado)

    Legion Malware Upgraded to Target SSH Servers and AWS Credentials (Hacker News)

    CISA Warns of Hurricane/Typhoon-Related Scams (Cybersecurity and Infrastructure Security Agency CISA)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Volt Typhoon goes undetected by living off the land. New gang, old ransomware. KillNet says no to slacker hackers. May 25, 2023
    Show notes

    China's Volt Typhoon snoops into US infrastructure, with special attention paid to Guam. Iranian cybercriminals are seen conducting ops against Israeli targets. A new ransomware gang uses recycled ransomware. A persistent Brazilian campaign targets Portuguese financial institutions. A new botnet targets the gaming industry. Phishing attempts impersonate OpenAI. Pro-Russian geolocation graffiti. Andrea Little Limbago from Interos addresses the policy implications of ChatGPT. Our guest is Jon Check from Raytheon Intelligence & Space, on cybersecurity and workforce strategy for the space community. And KillNet says no to slacker hackers.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/101


    Selected reading.

    People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection (Joint Advisory)

    Volt Typhoon targets US critical infrastructure with living-off-the-land techniques (Microsoft)

    Chinese hackers spying on US critical infrastructure, Western intelligence says (Reuters)

    Agrius Deploys Moneybird in Targeted Attacks Against Israeli Organizations (Check Point)

    Iran-linked hackers Agrius deploying new ransomware against Israeli orgs (The Record)

    Iranian Hackers Set Sights On Israeli Shipping & Logistics Firms (Information Security Buzz)

    Fata Morgana: Watering hole attack on shipping and logistics websites (ClearSky Security)

    Iran suspect in cyberattack targeting Israeli shipping, financial firms (Al-Monitor)

    Buhti: New Ransomware Operation Relies on Repurposed Payloads (Symantec)

    Operation Magalenha | Long-Running Campaign Pursues Portuguese Credentials and PII (SentinelOne)

    The Dark Frost Enigma: An Unexpectedly Prevalent Botnet Author Profile (Akamai)

    Fresh Phish: ChatGPT Impersonation Fuels a Clever Phishing Scam (INKY)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    CISA Alert AA23-144A – People's Republic of China state-sponsored cyber actor living off the land to evade detection. [CISA Cybersecurity Alerts] May 25, 2023
    Show notes

    Cybersecurity authorities are issuing this joint Cybersecurity Advisory to highlight a recent cluster of activity associated with a People’s Republic of China state-sponsored cyber actor, also known as Volt Typhoon.

    AA23-144A Alert, Technical Details, and Mitigations

    Active Directory and domain controller hardening: Best Practices for Securing Active Directory | Microsoft Learn

    CISA regional cyber threats: China Cyber Threat Overview and Advisories

    Microsoft Threat Intelligence blog: Volt Typhoon targets US critical infrastructure with living-off-the-land techniques | Microsoft Security Blog

    No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

    U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov

    To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Cybercriminals favor cyberespionage in North Korea, Russia, and parts unknown. Movements and activity in the cyber underworld. May 24, 2023
    Show notes

    Kimsuky's tailored reconnaissance tools. GoldenJackal is an APT quietly active since 2019. Criminals target Youtube viewers with free cracked software. Rheinmetall’s data was posted to BlackBasta's extortion site. The "Cuba" gang claims credit for the attack on the Philadelphia Inquirer. CERT-UA identifies a probable Russian cyberespionage campaign. Ireland views cyber assistance to Ukraine as a contribution to collective security. Ann Johnson from Afternoon Cyber Tea speaks with Tyrance Billingsley about Black Tech. Our guest is Oz Alashe from CybSafe on raising VC money amidst a down economy. And KillNet's underperforming hacktivists.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/100


    Selected reading.

    Kimsuky | Ongoing Campaign Using Tailored Reconnaissance Toolkit (SentinelOne)

    North Korean Kimsuky Hackers Strike Again with Advanced Reconnaissance Malware (The Hacker News)

    Meet the GoldenJackal APT group. Don’t expect any howls (Kaspersky)

    Follina — a Microsoft Office code execution vulnerability (DoublePulsar)

    YouTube Pirated Software Videos Deliver Triple Threat: Vidar Stealer, Laplas Clipper, XMRig Miner (FortiGuard Labs)

    Arms maker Rheinmetall confirms BlackBasta ransomware attack (Bleeping Computer)

    Inquirer and forensics team investigating computer disruptions to publishing (Philadelphia Inquirer)

    Cuba ransomware claims cyberattack on Philadelphia Inquirer (Bleeping Computer)

    Espionage activity UAC-0063 in relation to Ukraine, Kazakhstan, Kyrgyzstan, Mongolia, Israel, India (CERT-UA#6549) (CERT-UA)

    Ukraine Identifies Central Asian Cyberespionage Campaign (BankInfoSecurity)

    Ireland’s cyber security agency has been providing ‘non-lethal aid’ to Ukraine (Irish Times)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    BlackCat gang crosses your path and evades detection. You’re just too good to be true, can’t money launder for you. Commercial spyware cases. May 23, 2023
    Show notes

    AhRat exfiltrates files and records audio on Android devices. The BlackCat ransomware group uses a signed kernel driver to evade detection. GUI-Vil in the cloud. Unwitting money mules. Ben Yelin unpacks the Supreme Court’s section 230 rulings. Our guest is Mike DeNapoli from Cymulate with insights on cybersecurity effectiveness. And a trio of commercial spyware cases.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/99


    Selected reading.

    Android app breaking bad: From legitimate screen recording to file exfiltration within a year (ESET)

    Love scam or espionage? Transparent Tribe lures Indian and Pakistani officials (ESET)

    BlackCat Ransomware Deploys New Signed Kernel Driver (Trend Micro)

    Unmasking GUI-Vil: Financially Motivated Cloud Threat Actor (Permiso)

    Uncle Sam strangles criminals' cashflow by reining in money mules (The Register)

    German prosecutors charge four over violating trade act to sell spyware to Turkey (Washington Post)

    Israel Torpedoed Morocco Spyware Deal - and NSO Competitor QuaDream Shut Down (Haaretz)

    He Was Investigating Mexico’s Military. Then the Spying Began. (New York Times)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Record GDPR fine. Movements in the cyber underworld. FBI found to have overstepped surveillance authorities. May 22, 2023
    Show notes

    The EU fines Meta for transatlantic data transfers. FIN7 returns, bearing Cl0p ransomware. Python Package Index temporarily suspends new registrations due to a spike in malicious activity. Typosquatting and TurkoRAT. UNC3944 uses SIM swapping to gain access to Azure admin accounts. A Turla retrospective. Rick Howard tackles workforce development. Our guest is Andrew Peterson of Fastly to discuss the intricate challenges of secure software development. And the FBI was found overstepping its surveillance authorities.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/98


    Selected reading.

    Meta Fined $1.3 Billion Over Data Transfers to U.S. (Wall Street Journal)

    Meta fined record $1.3 billion and ordered to stop sending European user data to US (AP News)

    Notorious Cyber Gang FIN7 Returns With Cl0p Ransomware in New Wave of Attacks (The Hacker News)

    Researchers tie FIN7 cybercrime family to Clop ransomware (The Record)

    Cybercrime gang FIN7 returned and was spotted delivering Clop ransomware (Security Affairs)

    PyPI new user and new project registrations temporarily suspended. (Python)

    PyPI repository restored after temporarily suspending new activity (Computing)

    RATs found hiding in the NPM attic (ReversingLabs)

    Legitimate looking npm packages found hosting TurkoRat infostealer (CSO Online)

    SIM Swapping and Abuse of the Microsoft Azure Serial Console: Serial Is Part of a Well Balanced Attack (Mandiant)

    Mozilla Explains: SIM swapping (Mozilla)

    The Underground History of Russia’s Most Ingenious Hacker Group (WIRED)

    Justice Department Announces Court-Authorized Disruption of Snake Malware Network Controlled by Russia’s Federal Security Service (US Department of Justice)

    Hunting Russian Intelligence “Snake” Malware (CISA)

    FBI misused intelligence database in 278,000 searches, court says (Reuters)

    FBI misused controversial surveillance tool to investigate Jan. 6 protesters (The Record)

    FBI broke rules in scouring foreign intelligence on Jan. 6 riot, racial justice protests, court says (AP News)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Dawn Cappelli: Becoming the cyber fairy godmother. [OT] [Career Notes] May 21, 2023
    Show notes

    Dawn Cappelli, OT CERT Director at Dragos, sits down to share what she has learned after her 25+ year career in the industry. She recalls wanting to have been a rockstar when she grew up, now she refers to herself as the fairy godmother of security. She shares some of the amazing things she got to work on throughout her career, including working with the Secret Service when the Olympics came to Salt Lake City, Utah in 2002. She shares how she was able to rise through the ranks to get to where she is now. Dawn talks about how she wasn't ready to retire quite yet because she loved the industry so much, saying "I retired, but I knew I still loved security. I have this passion for protection and so Dragos came along and they offered me this role of Director of OT CERT. I feel like I'm the security fairy godmother." She shares words of wisdom for all trying to get into the industry, saying that you need to always take the risk like she did when she first started her career. We thank Dawn for sharing her story with us.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Dangerous vulnerabilities in H.264 decoders. [Research Saturday] May 20, 2023
    Show notes

    Willy R. Vasquez from The University of Texas at Austin discussing research on "The Most Dangerous Codec in the World - Finding and Exploiting Vulnerabilities in H.264 Decoders." Researchers are looking at the marvel that is modern video encoding standards such as H.264 for vulnerabilities and ultimately hidden security risks.

    The research states "We introduce and evaluate H26FORGE, domain-specific infrastructure for analyzing, generating, and manipulating syntactically correct but semantically spec-non-compliant video files." Using H26FORCE, they were able to uncover insecurities in depth across the video decoder ecosystem, including kernel memory corruption bugs in iOS and video accelerator and application processor kernel memory bugs in Android devices.

    The research can be found here:

    • The Most Dangerous Codec in the World: Finding and Exploiting Vulnerabilities in H.264 Decoders

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Section 230 survives court tests. Pre-infected devices. IRS cyber attachés. DraftKings hack indictment. Notes on the hybrid war. May 19, 2023
    Show notes

    Section 230 survives SCOTUS. Lemon Group's pre-infected devices. The IRS is sending cyber attachés to four countries in a new pilot program. A Wisconsin man is charged with stealing DraftKings credentials. Russian hacktivists conduct DDoS attacks against Polish news outlets. An update on RedStinger. Grayson Milbourne from OpenText Cybersecurity discusses IoT and the price we pay for convenience. Our guest is Matthew Keeley with info on an open source domain spoofing tool, Spoofy. And war principles and hacktivist auxiliaries.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/97


    Selected reading.

    “Honey, I’m Hacked”: Ethical Questions Raised by Ukrainian Cyber Deception of Russian Military Wives (Just Security)

    A Mysterious Group Has Ties to 15 Years of Ukraine-Russia Hacks (Wired)

    CloudWizard APT: the bad magic story goes on (SecureList)

    Ukraine at D+441: Skirmishing along the line of contact, and in cyberspace. (The CyberWire)

    Russian dissident gets three years in prison colony for DDoS attacks on military website (Cybernews)

    Europe: The DDoS battlefield (Help Net Security)

    Russian hackers hit Polish news sites in DDoS attack (Cybernews)

    18-year-old charged with hacking 60,000 DraftKings betting accounts (Bleeping Computer)

    Garrison Complaint (Department of Justice)

    IRS-CI deploys 4 cyber attachés to locations abroad to combat cybercrime (IRS)

    IRS deploys cyber attachés to fight cybercrime abroad (The Hill)

    Cybercrime gang pre-infects millions of Android devices with malware (Bleeping Computer)

    This Cybercrime Syndicate Pre-Infected Over 8.9 Million Android Phones Worldwide (The Hacker News)

    Lemon Group’s Cybercriminal Businesses Built on Preinfected Devices (Trend Micro)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Previous 1 132 133 134 135 136 378 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights