TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    CyberWire Daily

    The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

    Advertise

    Copyright: © 2024 N2K Networks, Inc. 706761

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    Payal Chakravarty: Overcoming bias in the workplace. [Security and Risk] [Career Notes] Oct 09, 2022
    Show notes

    Payal Chakravarty, Head of Product for Security and Risk from Coalition, sits down to share her story of working at several different organizations, including interning for IBM and Microsoft. After obtaining her master's degree, she worked with IBM a bit more closely and fell in love with one of the projects she was working on. Payal had a very interesting career path going from physical to virtual, virtual to cloud now, cloud to containers. She says that there is still some bias she has dealt with as a woman in her field, she says, "I think the way you handle it is you negotiate or you kind of calmly handle the situation, there's no ego involved." Payal shares that in working in this field you need to be in love with it, giving the advice that don't just choose a job because of the money or because it's cool, but because you feel connected to it as a profession. We thank Payal for sharing her story.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Google Drive used for malware? [Research Saturday] Oct 08, 2022
    Show notes

    Jen Miller-Osborn from Palo Alto Networks' Unit 42 joins Dave to discuss their recent work on "Russian APT29 Hackers Use Online Storage Services, DropBox and Google Drive." The research shares the insight into an active campaign from Russia’s Foreign Intelligence Service, that is leveraging the use of trusted, legitimate cloud services including Google Drive as a staging platform to deliver malware.

    The research states that when these tactics are used, it is extremely difficult for organizations to detect the malicious activity in connection with the campaign. These tactics are used to collect victim information, evade detection, and deliver Cobalt Strike.

    The research can be found here:

    • Russian APT29 Hackers Use Online Storage Services, DropBox and Google Drive

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    A US EO addresses EU data privacy concerns. China’s favorite CVEs. Election security and credit risk. COVID phishbait. Notes from the hybrid war, including some really motivated draft evaders. Oct 07, 2022
    Show notes

    A US Executive Order outlines US-EU data-sharing privacy safeguards. CISA, NSA, and the FBI list the top vulnerabilities currently being exploited by China. A look at election security and credit risk to US states. COVID-19-themed social engineering continues. Robert M. Lee from Dragos on securing the food and beverage industry. Carole Theriault interviews Joel Hollenbeck from Check Point Software on threat actors phishing school board meetings. Notes from the hybrid war: Killnet and US state government sites, the prospects of deterrence in cyberspace, and, finally, maybe the most motivated draft evaders in military history.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/11/194


    Selected reading.

    FACT SHEET: President Biden Signs Executive Order to Implement the European Union-U.S. Data Privacy Framework (The White House)

    Top CVEs Actively Exploited By People’s Republic of China State-Sponsored Cyber Actors (CISA)

    Government credit risk associated with election risk (CyberWire)

    Exploiting COVID-19: how threat actors hijacked a pandemic (Proofpoint)

    Ukraine at D+125: Abandoned tanks and discontented hawks. (CyberWire)

    Department Press Briefing – October 6, 2022 - United States Department of State (United States Department of State)

    2 Russians fleeing military service reach remote Alaska island (Military Times)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    CISA Alert AA22-279A – Top CVEs actively exploited by People’s Republic of China state-sponsored cyber actors. Oct 07, 2022
    Show notes

    This joint Cybersecurity Advisory provides the top CVEs used by the People’s Republic of China state-sponsored cyber actors. PRC cyber actors continue to exploit these known vulnerabilities and use publicly available tools to target networks of interest. PRC state-sponsored cyber actors have actively targeted U.S. and allied networks as well as software and hardware companies to steal intellectual property and develop access into sensitive networks.

    AA22-279A Alert, Technical Details, and Mitigations

    For more information on PRC state-sponsored malicious cyber activity, see CISA’s China Cyber Threat Overview and Advisories webpage, FBI’s Industry Alerts, and NSA’s Cybersecurity Advisories & Guidance.

    People’s Republic of China State-Sponsored Cyber Actors Exploit Network Providers and Devices

    CISA offers several no-cost scanning and testing services to help organizations reduce their exposure to threats by taking a proactive approach to mitigating attack vectors. See www.cisa.gov/cyber-hygiene-services

    U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System (PDNS) services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov

    To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Updated mitigations for ProxyNotShell. Lloyd’s investigates cyber incident. Killnet hits US state government sites. Election security. Credential theft. Verdict in Uber breach case. Oct 06, 2022
    Show notes

    Microsoft updates mitigations for ProxyNotShell. Lloyd's of London investigates a suspected cyberattack. Killnet hits networks of US state governments. The FBI and CISA weigh in on election security. Credential theft in the name of Zoom. Tim Eades from Cyber Mentor Fund on the move to early-stage investing in times of war and recession. Our guest is Nick Lumsden of Tenacity Cloud on cloud infrastructure sprawl. The former security chief at Uber was found guilty in a case involving data breach cover-up.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/11/193


    Selected reading.

    Customer Guidance for Reported Zero-day Vulnerabilities in Microsoft Exchange Server (Microsoft Security Response Center)

    Microsoft updates guidance for ‘ProxyNotShell’ bugs after researchers get around mitigations (The Record by Recorded Future)

    Microsoft Updates Mitigation for Exchange Server Zero-Days (Dark Reading)

    Microsoft updates mitigation for ProxyNotShell Exchange zero days (BleepingComputer)

    Lloyd's of London investigates possible cyber attack (Reuters)

    Insurance giant Lloyd’s of London investigating cyberattack (The Record by Recorded Future)

    Russian-speaking hackers knock US state government websites offline (CNN)

    Malicious Cyber Activity Against Election Infrastructure Unlikely to Disrupt or Prevent Voting (FBI and CISA)

    FBI: Cyberattacks targeting election systems unlikely to affect results (BleepingComputer)

    Zoom: 1 Phish, 2 Phish Email Attack (Armorblox)

    Former Uber Security Chief Found Guilty of Obstructing FTC Probe (Wall Street Journal)

    Former Uber security chief convicted of covering up 2016 data breach (Washington Post)

    Uber’s Former Security Chief Convicted of Data Hack Coverup (Bloomberg)

    Former Uber Security Chief Found Guilty of Hiding Hack From Authorities (New York Times)

    Former Uber CISO Joe Sullivan Found Guilty Over Breach Cover Up (SecurityWeek)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Sniffing at the DIB. Sideloading cryptojacking campaign. Nord Stream and threats to critical infrastructure. US Cyber Command describes hunting forward in Ukraine. Fraud meets romance. Oct 05, 2022
    Show notes

    Data’s stolen from a US "Defense Industrial Base organization." Major sideloading cryptojacking campaign is in progress. Nord Stream and threats to critical infrastructure. US Cyber Command describes "hunt forward" missions in Ukraine. Andrew Hammond from SpyCast speaks with hacker Eric Escobar about the overlap of traditional intelligence and cybersecurity. Our guest is AJ Nash from ZeroFox with an update on the current threat landscape. Fraud meets romance.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/11/192


    Selected reading.

    Impacket and Exfiltration Tool Used to Steal Sensitive Information from Defense Industrial Base Organization (CISA)

    CISA: Multiple government hacking groups had ‘long-term’ access to defense company (The Record by Recorded Future)

    US Govt: Hackers stole data from US defense org using new malware (BleepingComputer)

    Side-Loading OneDrive for profit – Cryptojacking campaign detected in the wild (Bitdefender Labs)

    Drone-loaded seabed ship is latest weapon in Royal Navy's arsenal to counter Russian threat (The Telegraph)

    Opinion Undersea pipeline sabotage demands the West prepare for more attacks (Washington Post)

    Ukraine Hasn’t Won the Cyber War Against Russia Yet (World Politics Review)

    USCYBERCOM Executive Director David Frederick Outlines Cyber Threats & Highlights Importance of Industry Partnerships (GovCon Wire)

    Romance scammer and BEC fraudster sent to prison for 25 years (Naked Security)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    CISA Alert AA22-277A – Impacket and exfiltration tool used to steal sensitive information from defense industrial base organization. Oct 04, 2022
    Show notes

    From November 2021 through January 2022, the CISA responded to APT activity against a Defense Industrial Base organization’s enterprise network. During incident response activities, CISA discovered that multiple APT groups compromised the organization’s network, and some APT actors had long-term access to the environment. APT actors used an open-source toolkit called Impacket to gain their foothold within the environment and further compromise the network, and also used a custom data exfiltration tool, CovalentStealer, to steal the victim’s sensitive data.

    AA22-277A Alert, Technical Details, and Mitigations

    CISA Cyber Hygiene Services

    Malware Analysis Report (MAR)-10365227-1.stix

    MAR-10365227-2.stix

    MAR-10365227-3.stix

    CISA offers several no-cost scanning and testing services to help organizations reduce their exposure to threats by taking a proactive approach to mitigating attack vectors. See www.cisa.gov/cyber-hygiene-services

    U.S. DIB sector organizations may consider signing up for the NSA Cybersecurity Collaboration Center’s DIB Cybersecurity Service Offerings, including Protective Domain Name System (PDNS) services, vulnerability scanning, and threat intelligence collaboration for eligible organizations. For more information on how to enroll in these services, email dib_defense@cyber.nsa.gov

    To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    CISA issues Binding Operational Directive 23-01. LAUSD says ransomware operators missed most sensitive PII. Trends in API protection SaaS security. Making a pest of oneself in a hybrid war. Oct 04, 2022
    Show notes

    CISA issues a Binding Operational Directive. An LA school district says ransomware operators missed most sensitive PII. An API protection report describes malicious transactions. Analysis of cyber risk in relation to SaaS applications. Joe Carrigan describes underground groups using stolen identities and deepfakes. Our guest is Eve Maler from ForgeRock on consumer identity breaches. And someone is making a nuisance of themself in Russia.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/11/191


    Selected reading.

    Binding Operational Directive 23-01 (CISA)

    CISA Directs Federal Agencies to Improve Cybersecurity Asset Visibility and Vulnerability Detection (Cybersecurity and Infrastructure Security Agency)

    CISA aims to expand cyber defense service across fed agencies, potentially further (Federal News Network)

    CISA directs federal agencies to track software and vulnerabilities (The Record by Recorded Future)

    Student, Teacher Data Not Affected in Los Angeles School District Hack (Wall Street Journal)

    ‘No evidence of widespread impact,’ LAUSD says of data released by hackers (KTLA)

    New API Threat Research Shows that Shadow APIs Are the Top Threat Vecto (Cequence Security)

    Secureworks State of the Threat Report 2022: 52% of ransomware incidents over the past year started with compromise of unpatched remote services (Secureworks)

    Russian Citizens Wage Cyberwar From Within (Kyiv Post)

    Russian Hackers Take Aim at Kremlin Targets: Report (Infosecurity Magazine) Russian retail chain 'DNS' confirms hack after data leaked online (BleepingComputer)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Microsoft Exchange zero-days exploited. Supply chain attack reported. New Lazarus activity. Mexican government falls victim to hacktivism. Hacking partial mobilization. Former insider threat. Oct 03, 2022
    Show notes

    Two Microsoft Exchange zero-days exploited in the wild. A supply chain attack, possibly from Chinese intelligence services. There’s new Lazarus activity: bring-your-own-vulnerable-driver. The Mexican government falls victim to apparent hacktivism. Flying under partial mobilization’s radar. Betsy Carmelite from Booz Allen Hamilton talks about addressing the cyber workforce skills gap. Our guest Rachel Tobac from SocialProof Security brings a musical approach to security awareness training. How’s your off-boarding program working out?


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/11/190


    Selected reading.

    Microsoft Releases Guidance on Zero-Day Vulnerabilities in Microsoft Exchange Server (CISA)

    Customer Guidance for Reported Zero-day Vulnerabilities in Microsoft Exchange Server (Microsoft Security Response Center)

    Warning: New attack campaign utilized a new 0-day RCE vulnerability on Microsoft Exchange Server (GTSC)

    URGENT! Microsoft Exchange double zero-day – “like ProxyShell, only different” (Naked Security)

    Microsoft confirms two Exchange Server zero days are being used in cyberattacks (The Record by Recorded Future)Microsoft confirms new Exchange zero-days are used in attacks (BleepingComputer)

    Two Microsoft Exchange zero-days exploited in the wild. (CyberWre)

    CISA Adds Three Known Exploited Vulnerabilities to Catalog (CISA)

    Suspected Chinese hackers tampered with widely used customer chat program, researchers say (Reuters)

    Report: Commercial chat provider hijacked to spread malware in supply chain attack (The Record by Recorded Future)

    CrowdStrike Falcon Platform Identifies Supply Chain Attack via a Trojanized Comm100 Chat Installer (crowdstrike.com)

    Amazon‑themed campaigns of Lazarus in the Netherlands and Belgium (WeLiveSecurity)

    Lazarus & BYOVD: evil to the Windows core (Virus Bulletin)

    Lazarus hackers abuse Dell driver bug using new FudModule rootkit (BleepingComputer)

    Mexican government suffers major data hack, president's health issues revealed (Reuters)

    Mexican president confirms ‘Guacamaya’ hack targeting regional militaries (The Record by Recorded Future)

    Analysis: Mexico data hack exposes government cybersecurity vulnerability (Reuters)

    Russians dodging mobilization behind flourishing scam market (BleepingComputer)

    Honolulu Man Pleads Guilty to Sabotaging Former Employer’s Computer Network (US Department of Justice)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Kayla Williams: Not everything related to cybersecurity is a fire drill. [CISO] [Career Notes] Oct 02, 2022
    Show notes

    Kayla Williams, CISO of Devo, sits down to share her story, from graduating with a finance degree to rising to where she is now. She quickly learned that finance was not for her and changed paths, working towards gaining an information security certificate. From there she was able to excel and was offered the opportunity to move to England which changed her life. Working in her new role, she really enjoys thriving with her team. She says "We really try to be the department of no problem versus the department of no." She mentions how her and her team work on a day to day basis together solving issues and yet she says not everything related to cybersecurity needs to be a fire drill. She would rather her and her team build bridges in the face of adversity and in the face of people who may be naysayers. We thank Kayla for sharing her story.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Previous 1 158 159 160 161 162 378 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights