TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    CyberWire Daily

    The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

    Advertise

    Copyright: © 2024 N2K Networks, Inc. 706761

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    BEC attack exploits Dropbox services. Ransomware in the name of charity. API protection trends. Hybrid war hacktivism. Executive digital protection. May 18, 2023
    Show notes

    Business email compromise (BEC) exploits legitimate services. A hacktivist ransomware group demands charity donations for encrypted files. Trends and threats in API protection. The effects of hacktivism on Russia's war against Ukraine. Executive digital protection. Deepen Desai of Zscaler explains security risks in OneNote. Our guest is Ajay Bhatia of Veritas Technologies with advice for onboarding new employees. And news organizations as attractive targets.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/96


    Selected reading.

    Leveraging Dropbox to Soar Into Inbox (Avanan)

    MalasLocker ransomware targets Zimbra servers, demands charity donation (Bleeping Computer)

    Shadow API Usage Surges 900%, Revealing Alarming Lack of API Visibility Among Enterprises (Business Wire)

    APIs are Top Cybersecurity Priority for Most Organizations, Yet 40% Do Not Have an API Security Solution (PR Newswire)

    Evolving Cyber Operations and Capabilities (CSIS)

    Following the long-running Russian aggression against Ukraine. (The CyberWire)

    Executive Digital Protection whitepaper (Agency)

    The Philadelphia Inquirer’s operations continue to be disrupted by a cyber incident (The Philadelphia Inquirer)

    Cyberattack at the Philadelphia Inquirer. (The CyberWire)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    CISA Alert AA23-136A – #StopRansomware: BianLian Ransomware Group. [CISA Cybersecurity Alerts] May 18, 2023
    Show notes

    FBI, CISA, and the Australian Cyber Security Centre are releasing this joint Cybersecurity Advisory to disseminate known BianLian ransomware and data extortion group IOCs and TTPs identified through FBI and ACSC investigations as of March 2023.

    AA23-136A Alert, Technical Details, and Mitigations

    AA23-136A.STIX_.xml

    Stopransomware.gov, a whole-of-government approach with one central location for U.S. ransomware resources and alerts.

    cyber.gov.au for the Australian Government’s central location to report cyber incidents, including ransomware, and to see advice and alerts. The site also provides ransomware advisories for businesses and organizations to help mitigate cyber threats.

    CISA-Multi-State Information Sharing and Analysis Center (MS-ISAC) Joint Ransomware Guide for guidance on mitigating and responding to a ransomware attack

    No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

    See CISA Insights Mitigations and Hardening Guidance for MSPs and Small- and Mid-sized Businesses for guidance on hardening MSP and customer infrastructure.

    U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov

    To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    A joint warning on BianLian ransomware. Fleeceware offers AI as bait for the gullible. Cyberespionage updates. And Ukraine formally joins NATO’s CCDCOE. May 17, 2023
    Show notes

    Cyber agencies warn of BianLian ransomware. There’s a new gang using leaked Baduk-based ransomware. Chinese government-linked threat actors target TP-link routers with custom malware. ChatGPT-themed fleeceware is showing up in online stores. Ukraine is now a member of NATO's Cyber Centre. Tim Starks from the Washington Post shares insights on section 702 renewal. Our guest is Ismael Valenzuela from BlackBerry sharing the findings from their Global Threat Intelligence Report. And the CIA's offer to Russian officials may have had some takers.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/95


    Selected reading.

    #StopRansomware: BianLian Ransomware Group (Cybersecurity and Infrastructure Security Agency CISA)

    Newly identified RA Group compromises companies in U.S. and South Korea with leaked Babuk source code (Cisco Talos Blog)

    The Dragon Who Sold His Camaro: Analyzing Custom Router Implant (Check Point Research)

    Fake ChatGPT Apps Scam Users Out of Thousands of Dollars, Sophos Reports (GlobeNewswire News Room)

    Ukraine joins NATO Cyber Centre (Computing)

    Russian Officials Unnerved by Ukraine Bloodshed Are Contacting CIA, Agency Says (Wall Street Journal)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    What is data centric security and why should anyone care? [CyberWire-X] May 17, 2023
    Show notes

    In today’s world, conventional cyber thinking remains largely focused on perimeter-centric security controls designed to govern how identities and endpoints utilize networks to access applications and data that organizations possess internally. Against this backdrop, a group of innovators and security thought leaders are exploring a new frontier and asking the question: shouldn’t there be a standard way to protect sensitive data regardless of where it resides or who it’s been shared with? It’s called “data-centric” security and it’s fundamentally different from “perimeter-centric” security models. Practicing it at scale requires a standard way to extend the value of “upstream” data governance (discovery, classification, tagging) into “downstream” collaborative workflows like email, file sharing, and SaaS apps.

    In this episode of CyberWire-X, the CyberWire’s Rick Howard and Dave Bittner explore modern approaches for applying and enforcing policy and access controls to sensitive data which inevitably leaves your possession but still deserves just as much security as the data that you possess internally. Rick and Dave are joined by guests Bill Newhouse, Cybersecurity Engineer at National Institute of Standards and Technology (NIST) National Cybersecurity Center of Excellence (NCCoE), and Dana Morris, Senior Vice President for Product and Engineering of our episode sponsor Virtru.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    DDoS trends. Asia sees a Lancefly infestation. Lessons from cyber actuaries. Infostealers in the C2C market. False flags. May 16, 2023
    Show notes

    DDoS "carpet bombing." Lancefly infests Asian targets. Cyber insurance trends. Infostealers in the C2C market. A Russian espionage service is masquerading as a criminal gang. KillNet’s running a psyop radio station of questionable quality. Joe Carrigan describes baiting fraudsters with fake crypto. Our guest is Gemma Moore of Cyberis talking about how red teaming can upskill detection and response teams. And geopolitical DDoS.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/94


    Selected reading.

    2023 DDoS Threat Intelligence Report (Corero)

    Lancefly: Group Uses Custom Backdoor to Target Orgs in Government, Aviation, Other Sectors (Symantec)

    2023 Cyber Claims Report (Coalition)

    The Growing Threat from Infostealers (Secureworks)

    Cybercriminals who targeted Ukraine are actually Russian government hackers, researchers say (TechCrunch)

    DDoS Attacks Targeting NATO Members Increasing (Netscout)

    Following the long-running Russian aggression against Ukraine. (The CyberWire)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Ransomware, doxxing, and data breaches, oh my! State fronts and cyber offensives. May 15, 2023
    Show notes

    Discord sees a third-party data breach. Black Basta conducts a ransomware attack against technology company ABB. Intrusion Truth returns to dox APT41. Anonymous Sudan looks like a Russian front operation. Attribution and motivation of "RedStinger" remain murky. CISA summarizes Russian cyber offensives. Remote code execution exploits Ruckus in the wild. Our guest is Dave Russell from Veeam with insights on data protection. Matt O'Neill from the US Secret Service on their efforts to thwart email compromise and romance scams. And espionage by way of YouTube comments.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/93


    Selected reading.

    Discord discloses data breach after support agent got hacked (Bleeping Computer)

    Discord suffered a data after third-party support agent was hacked (Security Affairs)

    Multinational tech firm ABB hit by Black Basta ransomware attack (Bleeping Computer)

    Breaking: ABB confirms cyberattack; work underway to restore operations (ET CISO)

    Black Basta conducts ransomware attack against Swiss technology company ABB (The CyberWire)

    They dox Chinese hackers. Now, they’re back. (Washington Post)

    What’s Cracking at the Kerui Cracking Academy? (Intrusion Truth)

    Posing as Islamists, Russian Hackers Take Aim at Sweden (Bloomberg)

    Anonymous Sudan: Threat Intelligence Report (TrueSec)

    Uncovering RedStinger - Undetected APT cyber operations in Eastern Europe since 2020 (Malwarebytes)

    Russian ‘Red Stealer’ cyberattacks target breakaway territories in Ukraine (Cybernews)

    Russia Cyber Threat Overview and Advisories (CISA)

    Known Exploited Vulnerabilities Catalog (CISA)

    CISA Adds Seven Known Exploited Vulnerabilities to Catalog (CISA)

    CISA warns of critical Ruckus bug used to infect Wi-Fi access points (Bleeping Computer)

    Security Bulletins (Ruckus)

    ROK union leaders charged with spying for North Korea in ‘movie-like’ scheme (NK News)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Steve Benton: Mixing like a DJ. [VP] [Career Notes] May 14, 2023
    Show notes

    Steve Benton, Vice President at Anomali Threat Research & GM Belfast, sits down to share his story as a cybersecurity expert with a surplus of strategic leadership experience across cyber and physical security rooted in substantial operational directorship and accountability. Steve shares his beginnings, where he wanted to grow up to be a rockstar, slowly moving into the world of tech with his first ever computer and falling in love with it. After graduating from Queens University with a degree in information technology, he joined British Telecommunications or BT, where he got to put his new found skills to use. Steve mentions how his job is kind of like being a DJ almost and says " a typical day for me is looking at the intelligence that we're bringing in, mixing it as it were to think of a slight, like DJs with a set of headphones on creating the right kind of mixes of intelligence for our clients." We thank Steve for sharing his story with us.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Running away from operation Tainted Love. [Research Saturday] May 13, 2023
    Show notes

    Aleksandar Milenkoski and Juan Andres Guerrero-Saade from SentinelOne's SentinelLabs join Dave to discuss their research "Operation Tainted Love | Chinese APTs Target Telcos in New Attacks." Researchers found initial phases of attacks against telecommunication providers in the Middle East in Q1 in 2023.

    The research states "We assess that this activity represents an evolution of tooling associated with Operation Soft Cell." While the exact grouping is unclear, researchers think it is highly likely that the threat actor is a Chinese cyberespionage group in the nexus of Gallium and APT41.

    The research can be found here:

    • Operation Tainted Love | Chinese APTs Target Telcos in New Attacks

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    CISA Alert AA23-131A – Malicious Actors Exploit CVE-2023-27350 in PaperCut MF and NG. May 12, 2023
    Show notes

    FBI and CISA are releasing this joint Cybersecurity Advisory in response to the active exploitation of CVE-2023-27350. This vulnerability occurs in certain versions of PaperCut NG and PaperCut MF, software applications that help organizations manage printing services, and enables an unauthenticated actor to execute malicious code remotely without credentials.

    AA23-131A Alert, Technical Details, and Mitigations

    PaperCut: URGENT | PaperCut MF/NG vulnerability bulletin (March 2023)

    Huntress: Critical Vulnerabilities in PaperCut Print Management Software

    No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

    See CISA Insights Mitigations and Hardening Guidance for MSPs and Small- and Mid-sized Businesses for guidance on hardening MSP and customer infrastructure.

    U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov

    To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Babuk resurfaces for criminal inspiration. Alert on PaperCut vulnerability exploitation. Too many bad bots. Phishing-as-a-service in the C2C market. KillNet's PMHC regrets. May 12, 2023
    Show notes

    Babuk source code provides criminal inspiration. CISA and FBI release a joint report on PaperCut. There are more bad bots out there than anyone would like. Phishing-as-a-service tools in the C2C market. CISA’s Eric Goldstein advocates the adoption of strong controls, defensible networks and coordination of strategic cyber risks. Our cyberwire producer Liz Irvin speaks with Crystle-Day Villanueva, Learning and Development Specialist for Lumu Technologies. And KillNet’s short-lived venture, with a dash of regret.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/92


    Selected reading.

    Babuk code used by 9 ransomware gangs to encrypt VMWare ESXi servers (Bleeping Computer)

    Ransomware actors adopt leaked Babuk code to hit Linux systems (Decipher)

    Hypervisor Ransomware | Multiple Threat Actor Groups Hop on Leaked Babuk Code to Build ESXi Lockers (SentinelOne)

    Malicious Actors Exploit CVE-2023-27350 in PaperCut MF and NG (CISA)

    CVE-2023-27350 Detail (NIST)

    Proofpoint Emerging Threats Rules (Proofpoint)

    2023 Imperva Bad Bot Report (Imperva)

    New phishing-as-a-service tool “Greatness” already seen in the wild (Cisco Talos)

    Ukraine at D+442: Russians say the Ukrainian counteroffensive has begun. (CyberWire)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Previous 1 133 134 135 136 137 378 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights