TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    CyberWire Daily

    The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

    Advertise

    Copyright: © 2024 N2K Networks, Inc. 706761

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    Cybercrime and cyberespionage: IceFire, DUCKTAIL, LIGHTSHOW, Remcsos, and a tarot card reader. US cyber budgets, strategy, and a DoD cyber workforce approach. Five new ICS advisories. Mar 10, 2023
    Show notes

    New IceFire version is out. A DUCKTAIL tale. Social engineering by Tehran. DPRK's LIGHTSHOW cyberespionage. The President's Budget and cybersecurity. The US Department of Defense issues its cyber workforce strategy. Remcos surfaces in attacks against Ukrainian government agencies. DDoS at a Ukrainian radio station. Dave Bittner sits down with Beth Robinson of Bishop Fox to share their 2023 Offensive Security Resolutions. Caleb Barlow from Cylete on the security implications of gigapixel images. And CISA releases five ICS advisories.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/47


    Selected reading.

    IceFire Ransomware Returns | Now Targeting Linux Enterprise Networks (SentinelOne)

    DUCKTAIL: Threat Operation Re-emerges with New LNK, PowerShell, and Other Custom Tactics to Avoid Detection (Deep Instinct)

    Iran-linked hackers used fake Atlantic Council-affiliated persona to target human rights researchers (CyberScoop)

    Iranian APT Targets Female Activists With Mahsa Amini Protest Lures (Dark Reading).

    Iran threat group going after female activists, analyst warns (Cybernews)

    Stealing the LIGHTSHOW (Part One) — North Korea's UNC2970 (Mandiant)

    Stealing the LIGHTSHOW (Part Two) — LIGHTSHIFT and LIGHTSHOW (Mandiant)

    Cybersecurity in the US President's Budget for Fiscal Year 2024. (CyberWire)

    Biden’s budget proposal underscores cybersecurity priorities (Washington Post)

    Biden Budget Proposal: $200M for TMF, CISA With 4.9% Budget Boost (Meritalk)

    Cybersecurity Poised for Spending Boost in Biden Budget (Gov Info Security)

    Deputy Secretary of Defense Signs 2023-2027 DoD Cyber Workforce Strategy (U.S. Department of Defense)

    In new cyber workforce strategy, DoD hopes 'bold' retention initiatives keep talent coming back (Breaking Defense)

    Remcos Trojan Returns to Most Wanted Malware List After Ukraine Attacks (Infosecurity Magazine)

    February 2023’s Most Wanted Malware: Remcos Trojan Linked to Cyberespionage Operations Against Ukrainian Government (Check Point Software)

    Radio Halychyna cyber-attacked following appeal by Russian hacker group (International Press Institute)

    CISA Releases Five Industrial Control Systems Advisories | CISA (Cybersecurity and Infrastructure Security Agency CISA)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    PlugX is now wormable. Compromised webcams found. Emotet is back. AI builds a keylogger. Cyber in the hybrid war. BEC comes to productivity suites. Mar 09, 2023
    Show notes

    A wormable version of the PlugX USB malware is found. Compromised webcams as a security threat. Emotet botnet out of hibernation. Proof-of-concept: AI used to generate polymorphic keylogger. Turning to alternatives as conventional tactics fail. Dave Bittner speaks with Eve Maler of ForgeRock to discuss how digital identity can help create a more secure connected car experience. Johannes Ullrich from SANS on configuring a proper time server infrastructure. And Phishing messages via legitimate Google notifications.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/46


    Selected reading.

    A border-hopping PlugX USB worm takes its act on the road (Sophos News)

    BitSight identifies thousands of global organizations using insecure webcams and other IoT devices, finding many susceptible to eavesdropping (BitSight)

    Emotet malware attacks return after three-month break (BleepingComputer)

    BlackMamba: Using AI to Generate Polymorphic Malware (HYAS)

    Russian Cyberwar in Ukraine Stumbles Just Like Conventional One (Bloomberg)

    Australian official demands Russia bring criminal hackers ‘to heel’ (The Record by Recorded Future)

    Russia will have to rely on nukes, cyberattacks, and China since its military is being thrashed in Ukraine, US intel director says (Business Insider)

    BEC 3.0 - Legitimate Sites for Illegitimate Purposes (Avanan)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Data breaches and IP. Current cyberespionage campaigns. A warning that the cyber phases of the hybrid war can’t be expected to be over, yet. Exfiltration via machine learning inference. Mar 08, 2023
    Show notes

    CISA adds three known exploited vulnerabilities to its Catalog. A data breach at Acer exposes intellectual property. Sharp Panda deploys SoulSearcher malware in cyberespionage campaigns. US Cyber Command’s head warns against underestimating Russia in cyberspace. Dave Bittner sits down with Simone Petrella of N2K Networks to discuss the recently-released Defense Cyber Workforce Framework. Betsy Carmelite from Booz Allen Hamilton speaks about CISA's year ahead. And are large language models what the lawyers call an attractive nuisance.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/45


    Selected reading.

    CISA Adds Three Known Exploited Vulnerabilities to Catalog (Cybersecurity and Infrastructure Security Agency CISA)

    March 7 CISA KEV Breakdown | Zoho, Teclib, Apache (Nucleus Security)

    Acer Confirms Breach After Hacker Offers to Sell Stolen Data (SecurityWeek)

    Acer confirms breach after 160GB of data for sale on hacking forum (BleepingComputer)

    “Sharp Panda”: Check Point Research puts a spotlight on Chinese origined espionage attacks against southeast asian government entities (Check Point Software)

    Pandas with a Soul: Chinese Espionage Attacks Against Southeast Asian Government Entities (Check Point Research)

    What can security teams learn from a year of cyber warfare? (Computer Weekly)

    Russian cyberattacks could intensify during spring offensives in Ukraine, US Cyber Command general says (Stars and Stripes)

    US Bracing for Bolder, More Brazen Russian Cyberattacks (VOA)

    Russia remains a ‘very capable’ cyber adversary, Nakasone says (C4ISRNet)

    Employees Are Feeding Sensitive Business Data to ChatGPT (Dark Reading)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    A new threat to routers. DoppelPaymer hoods collared. Ransomware hits a Barcelona hospital. Phishing in productivity suites. Espionage, hacktiism, and prank phone calls. Mar 07, 2023
    Show notes

    HiatusRAT exploits business-grade routers. International law enforcement action against the DoppelPaymer gang. Ransomware hits a major Barcelona hospital. Productivity suites are increasingly attractive as phishing grounds. Transparent Tribe’s romance scams. Cyberattacks briefly disrupt Russian websites and media outlets. Ashley Leonard, CEO of Syxsense, sits down with Dave to discuss their "Advancing Zero Trust Priorities'' report. Joe Carrigan on a warning from Microsoft about a surge in token theft. And trolling for disinfo raw material.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/44


    Selected reading.

    Black Lotus Labs uncovers another new malware that targets compromised routers (Lumen Newsroom)

    Germany and Ukraine hit two high-value ransomware targets | Europol (Europol)

    European Police, FBI Bust International Cybercrime Gang (VOA)

    German police lift lid on worldwide cyber blackmail gang (Deutsche Welle)

    Europol Hits Alleged Members of DoppelPaymer Ransomware Group (Decipher)

    An international sting brings another win against ransomware gangs (Washington Post)

    European police move in on DoppelPaymer (Computing)

    Police Looking for Russian Suspects Following DoppelPaymer Ransomware Crackdown (SecurityWeek)

    Cyberattack hits major hospital in Spanish city of Barcelona (AP NEWS).

    Cyberattack Hits Major Hospital in Spanish City of Barcelona (SecurityWeek)

    Barcelona's Hospital Clinic hit by ransomware cyberattack 'from outside Spain' (Euro Weekly News)

    Phishers’ Favorites 2022 Year-in-Review (Vade)

    Kremlin Website Down Amid Reports of Cyber Attacks on Russia (The Daily Beast)

    Russian diplomat blames West for recruiting hackers for operations against Moscow (TASS)

    Don’t Answer That! Russia-Aligned TA499 Beleaguers Targets with Video Call Requests (Proofpoint)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    That crane might know what you’re shipping. Addressing the cybersecurity of water systems. Oakland’s ransomware incident is now a breach. Hybrid war. Investment scams. Mar 06, 2023
    Show notes

    Cranes as a security threat. EPA memo addresses cybersecurity risks to water systems. Oakland's ransomware incident becomes a data breach. Carding rises in the Russian underworld. Sandworm's record in Russia's war. Rick Howard sits down with Andy Greenberg from Wired to discuss how Ukraine suffered more data-wiping malware last year than anywhere, ever. Dave Bittner speaks with Kathleen Smith of ClearedJobs.Net to talk about hiring veterans and setting them (and yourself) up for success. And AI’s latest misuse: bogus investment schemes.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/43


    Selected reading.

    WSJ News Exclusive | Pentagon Sees Giant Cargo Cranes as Possible Chinese Spying Tools (Wall Street Journal)

    EPA Takes Action to Improve Cybersecurity Resilience for Public Water Systems (US EPA)

    EPA presses states to include cybersecurity in water safety reviews (SC Media)

    EPA Calls on States to Improve Public Water Systems’ Cybersecurity (Meritalk)

    EPA issues water cybersecurity mandates, concerning industry and experts (CyberScoop)

    City of Oakland Targeted by Ransomware Attack, Work Continues to… (City of Oakland).

    Ransomware gang leaks data stolen from City of Oakland (BleepingComputer)

    Ransomware hackers release some stolen Oakland data (CBS News)

    Oakland officials say ransomware group may release personal data on Saturday (The Record from Recorded Future News)

    Cybercrime site shows off with a free leak of 2 million stolen card numbers (The Record from Recorded Future News)

    A year of wipers: How the Kremlin-backed Sandworm has attacked Ukraine during the war (The Record from Recorded Future News)

    Bitdefender Labs warns of fresh phishing campaign that uses copycat ChatGPT platform to swindle eager investors (Hot for Security)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Gabriela Smith-Sherman: Thriving in the chaos. [Cyber governance] [Career Notes] Mar 05, 2023
    Show notes

    Gabriela Smith-Sherman, a former Federal agency CISO with over 15 years of experience in leading and implementing comprehensive enterprise cybersecurity programs and initiatives, sits down to share her journey. She is a U.S. combat disabled veteran who understands the importance of mission and is dedicated to delivering high-quality results and value to customers through innovative solutions. Gabriela shares about her time in the military and how her being apart of the service was one of the best decisions she made and dedicates all her hard work to her time in the military. She also shares how it was tough getting out of the routine of the military and being a civilian now was a hard transition, but she says that she thrives in the chaos of the IT world and that the military helped her to prepare for the cyber industry. She said "I think my military experience has prepared me, uh, to be in those kind of chaotic positions and be very calm about the approach." We thank Gabriela for sharing her story with us.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    New exploits are tricking Chrome. [Research Saturday] Mar 04, 2023
    Show notes

    Dor Zvi, Co-Founder and CEO from Red Access to discuss their work on "New Chrome Exploit Lets Attackers Completely Disable Browser Extensions." A recently patched exploit is tricking Chrome browsers on all popular OSs to not only give attackers visibility of their targets’ browser extensions, but also the ability to disable all of those extensions.

    The research states the exploit consists of a bookmarklet exploit that allows threat actors to selectively force-disable Chrome extensions using a handy graphical user interface making Chrome mistakenly identify it as a legitimate request from the Chrome Web Store.

    The research can be found here:

    • New Chrome Exploit Lets Attackers Completely Disable Browser Extensions

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    More on how the US will implement its new National Cybersecurity Strategy. Emissary Panda and Mustang Panda are back. Responding to phishing. Royal ransomware. Water utility security. Mar 03, 2023
    Show notes

    Implementing the US National Cybersecurity Strategy. The US National Cybersecurity Strategy was informed by lessons from Russia's war. Two threat actors from China up their game. Responding to a phishing campaign. #StopRansomware: Royal Ransomware. CISA releases five ICS advisories. Sameer Jaleel, Kent State University Associate CIO on closing functionality gaps and creating a safer digital environment for students.Johannes Ullrich from SANS on establishing an "End of Support" inventory.EPA issues a memo on water system cybersecurity.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/12/42


    Selected reading.

    National Cybersecurity Strategy (The White House)

    US cyber leaders discuss the new National Cyber Strategy. (CyberWire)

    Biden vows to wield ‘all instruments’ in fighting cyberthreats (Defense News)

    Chinese state-backed hackers Iron Tiger target Linux devices with new malware (Tech Monitor)

    Chinese hackers use new custom backdoor to evade detection (BleepingComputer)

    Scam alert: Trezor warns users of new phishing attack (Cointelegraph)

    FBI and CISA Release #StopRansomware: Royal Ransomware | CISA (Cybersecurity and Infrastructure Security Agency CISA)

    CISA Releases Five Industrial Control Systems Advisories | CISA (Cybersecurity and Infrastructure Security Agency CISA)

    EPA Takes Action to Improve Cybersecurity Resilience for Public Water Systems (US EPA)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    CISA Alert AA23-061A – #StopRansomware: Royal ransomware. Mar 03, 2023
    Show notes

    CISA and FBI are releasing this joint advisory to disseminate known Royal ransomware IOCs and TTPs identified through recent FBI threat response activities.

    AA23-061A Alert, Technical Details, and Mitigations

    AA23-061A STIX XML

    Royal Rumble: Analysis of Royal Ransomware (cybereason.com)

    DEV-0569 finds new ways to deliver Royal ransomware, various payloads - Microsoft Security Blog

    2023-01: ACSC Ransomware Profile - Royal | Cyber.gov.au

    See Stopransomware.gov, a whole-of-government approach, for ransomware resources and alerts.

    No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

    See CISA Insights Mitigations and Hardening Guidance for MSPs and Small- and Mid-sized Businesses for guidance on hardening MSP and customer infrastructure.

    U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov

    To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    CISA Alert AA23-059A – CISA red team shares key findings to improve monitoring and hardening of networks. [CISA Cybersecurity Alerts] Mar 03, 2023
    Show notes

    The Cybersecurity and Infrastructure Security Agency is releasing this Cybersecurity Advisory detailing activity and key findings from a recent CISA red team assessment—in coordination with the assessed organization—to provide network defenders recommendations for improving their organization's cyber posture.

    AA23-059A Alert, Technical Details, and Mitigations

    No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

    See CISA Insights Mitigations and Hardening Guidance for MSPs and Small- and Mid-sized Businesses for guidance on hardening MSP and customer infrastructure.

    U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov

    To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Previous 1 141 142 143 144 145 378 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights