TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    CyberWire Daily

    The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

    Advertise

    Copyright: © 2024 N2K Networks, Inc. 706761

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    GRU operators masquerade as Ukrainian telecommunications providers. 2K Games Support compromised to spread malware. Developments in the cyber underworld. Sep 22, 2022
    Show notes

    GRU operators masquerade as Ukrainian telecommunications providers. Another video game maker is compromised to spread malware. Noberus may be a successor to Darkside and BlackMatter ransomware. Robert M. Lee from Dragos explains Crown Jewel analysis. Our guest is Nathan Hunstad from Code42 with thoughts on insider risk events. Threat actors have their insider threats, too.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/11/183


    Selected reading.

    Russia-Nexus UAC-0113 Emulating Telecommunication Providers in Ukraine (Recorded Future)

    Russian Cyberspies Targeting Ukraine Pose as Telecoms Providers (SecurityWeek)

    Shadowy Russian Cell Phone Companies Are Cropping Up in Ukraine (WIRED)

    CISA Alert AA22-264A – Iranian state actors conduct cyber operations against the government of Albania. (CyberWire)

    Iranian State Actors Conduct Cyber Operations Against the Government of Albania (CISA)

    2K Games says hacked help desk targeted players with malware (BleepingComputer)

    2K Games helpdesk hacked to spread malware to players (TechRadar)

    Rockstar parent company hacked again as 2K Support sends users malware (Dexerto)

    ‘Grand Theft Auto VI’ leak is Rockstar’s nightmare, YouTubers’ dream (Washington Post)

    Noberus Ransomware: Darkside and BlackMatter Successor Continues to Evolve its Tactics (Symantec)

    LockBit ransomware builder leaked online by “angry developer” (BleepingComputer)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    CISA Alert AA22-265A – Control system defense: know the opponent. [CISA Cybersecurity Alerts] Sep 22, 2022
    Show notes

    This alert builds on previous NSA and CISA guidance to stop malicious ICS activity and reduce OT exposure. The alert documentation linked in the show notes describes TTPs that malicious actors use to compromise OT/ICS assets. It also recommends mitigations that owners and operators can use to defend their systems from each of the listed TTPs. NSA and CISA encourage OT and ICS owners and operators to apply the recommendations in this documentation.

    AA22-265A Alert, Technical Details, and Mitigations

    NSA and CISA guidance to stop malicious ICS activity and reduce OT exposure

    For NSA client requirements or general cybersecurity inquiries, contact Cybersecurity_Requests@nsa.gov. To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov.

    To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov, or call (888) 282-0870, or report incidents to your local FBI field office.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    CISA Alert AA22-264A – Iranian state actors conduct cyber operations against the government of Albania. [CISA Cybersecurity Alerts] Sep 22, 2022
    Show notes

    In July 2022, Iranian state cyber actors—identifying as “HomeLand Justice”—launched a destructive cyber attack against the Government of Albania which rendered websites and services unavailable. An FBI investigation indicates Iranian state cyber actors acquired initial access to the victim’s network approximately 14 months before launching the destructive cyber attack, which included a ransomware-style file encryptor and disk wiping malware.

    AA22-264A Alert, Technical Details, and Mitigations

    CISA’s free Cyber Hygiene Services (CyHy)

    CISA’s zero–trust principles and architecture.

    Iran Cyber Threat Overview and Advisories.

    All organizations should report incidents and anomalous activity to CISA’s 24/7 Operations Center at central@cisa.dhs.gov or (888) 282-0870 and to the FBI via your local FBI field office or the FBI’s 24/7 CyWatch at (855) 292-3937 or CyWatch@fbi.gov.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    A call-up of Russian reserves, and more notes on the IT Army's claimed hack of the Wagner Group. Netflix phishbait. The Rockstar Games and LastPass incidents. CISA releases eight ICS Advisories. Sep 21, 2022
    Show notes

    It’s partial mobilization in Russia, and airline flights departing Russia are said to be sold out. Further notes on the IT Army's claimed hack of the Wagner Group. Leveraging Netflix for credential harvesting. Rockstar Games suffers a leak of new Grand Theft Auto footage. Ben Yelin has the latest on regulations targeting crypto. Our guest is Amy Williams from BlueVoyant discussing the value of feminine energy in the male dominated field of cybersecurity. CISA releases eight ICS Advisories.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/11/182


    Selected reading.

    Russia moves toward annexing Ukraine regions in a major escalation (Washington Post)

    Four occupied Ukraine regions plan imminent ‘votes’ on joining Russia (the Guardian)

    Putin sets partial military call-up, won’t ‘bluff’ on nukes (AP NEWS)

    Putin announces partial military mobilization for Russian citizens (Axios)

    Pro-Ukraine Hacktivists Claim to Have Hacked Notorious Russian Mercenary Group (Vice)

    Fresh Phish: Netflix Bad Actors Go Behind the Scenes to Stage a Credential Harvesting Heist (INKY)

    Leveraging Netflix for credential harvesting. (CyberWire)

    Social Engineering: How A Teen Hacker Allegedly Managed To Breach Both Uber And Rockstar Games (Forbes)

    Rockstar Games suffers leak of new Grand Theft Auto footage. (CyberWire)

    LastPass source code breach – incident response report released (Naked Security)

    Notice of Recent Security Incident (The LastPass Blog)

    The LastPass incident. (CyberWire)

    Medtronic NGP 600 Series Insulin Pumps (CISA)

    Hitachi Energy PROMOD IV (CISA)

    Hitachi Energy AFF660/665 Series (CISA)

    Dataprobe iBoot-PDU (CISA)

    Host Engineering Communications Module (CISA)

    AutomationDirect DirectLOGIC with Ethernet (CISA)

    AutomationDirect DirectLOGIC with Serial Communication (CISA)

    MiCODUS MV720 GPS tracker (Update A) (CISA)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    An overview of Russian cyber operations. The IT Army of Ukraine says it’s doxed the Wagner Group. Lapsus$ blamed for Uber hack. A look at the risk of stolen single sign-on credentials. Sep 20, 2022
    Show notes

    An overview of Russian cyber operations. The IT Army of Ukraine claims to have doxed the Wagner Group. Who dunnit? Lapsus$ dunnit. Emily Mossburg from Deloitte and Shelley Zalis of the Female Quotient on why gender equality is essential to the success of the cyber industry. We’ve got a special preview of the International Spy Museum's SpyCast's latest episode with host Andrew Hammond interviewing Robert Gates on the 75th anniversary of the CIA. And a look at the risk of stolen single sign-on credentials.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/11/181


    Selected reading.

    Ukraine's IT Army hacks Russia's Wagner Group (Computing)

    Untangling the Russian web: Spies, proxies, and spectrums of Russian cyber behavior (Atlantic Council)

    Security update | Uber Newsroom (Uber Newsroom)

    Tentative attribution in the Uber breach. (CyberWire)

    Uber says Lapsus$-linked hacker responsible for breach (Reuters)

    Uber blames security breach on Lapsus$, says it bought credentials on the dark web (ZDNET)

    Uber's breach shows how hackers keep finding a way in (Protocol)

    Uber attributes hack to Lapsus$, working with FBI and DOJ on investigation (The Record by Recorded Future)

    Uber data breach spotlights need for enterprises to ‘get the basics right’, say experts (ITP.net)

    "Keys to the Kingdom" at Risk: Analyzing Exposed SSO Credentials of Public Companies (Bitsight)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    An update on the Uber breach. Emotet and other malware delivery systems. Belarusian Cyber Partisans work against the regime in Minsk. And risky piracy sites. Sep 19, 2022
    Show notes

    An update on the Uber breach. Emotet and other malware delivery systems. Belarusian Cyber Partisans work against the regime in Minsk. Grayson Milbourne of OpenText Security Solutions on the arms race for vulnerabilities. Rick Howard continues his exploration of cyber risk. And risky piracy sites–that’s on the Internet, kids, not the high seas.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/11/180


    Selected reading.

    Developments in the case of the Uber breach. (CyberWire)

    Preliminary lessons from the Uber breach. (CyberWire)

    Uber says “no evidence” user accounts were compromised in hack (The Verge)

    Uber Claims No Sensitive Data Exposed in Latest Breach… But There's More to This (The Hacker News)

    Uber apparently hacked by teen, employees thought it was a joke (The Verge)

    Uber hacker claims to have full control of company's cloud-based servers (9to5Mac)

    The Uber Hack’s Devastation Is Just Starting to Reveal Itself (WIRED)

    Uber was breached to its core, purportedly by an 18-year-old. Here’s what’s known (Ars Technica)

    Uber hacked by teen who annoyed employee into logging them in - report (Jerusalem Post)

    18-year-old allegedly hacks Uber and sends employees messages on Slack (Interesting Engineering)

    Uber Investigating Massive Security Breach by Alleged Teen Hacker (Gizmodo)

    Uber cyber attack: protecting against social engineering (Information Age)

    Threat actor breaches many of Uber’s critical systems (Cybersecurity Dive)

    Uber hacker claims to have full control of company's cloud-based servers (9to5Mac)

    Uber confirms hack in the the latest access and identity nightmare for corporate America (SC Media)

    Uber hacked, attacker tears through the company's systems (Help Net Security)

    Uber confirms it is investigating cybersecurity incident (The Record by Recorded Future)

    UBER HAS BEEN HACKED, boasts hacker – how to stop it happening to you (Naked Security)

    Emotet and other malware delivery systems. (CyberWire)

    Emotet botnet now pushes Quantum and BlackCat ransomware (BleepingComputer)

    AdvIntel's State of Emotet aka "SpmTools" Displays Over Million Compromised Machines Through 2022 (AdvIntel)

    August’s Top Malware: Emotet Knocked off Top Spot by FormBook while GuLoader and Joker Disrupt the Index (Check Point Software)

    How Belarusian hacktivists are using digital tools to fight back (The Record by Recorded Future)

    Malvertising on piracy sites. (CyberWire)

    Unholy Triangle (Digital Citizens' Alliance)

    Piracy Advertising Researchers Fall Victim to Ransomware Attacks (TorrentFreak)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Jaya Baloo: Don't be afraid to bounce ideas off your teammates. [CISO] [Career Notes] Sep 18, 2022
    Show notes

    Jaya Baloo, a Chief Information Security Officer from Avast sits down to share her story, sharing how she got into the technology field at a younger age with being introduced to computers and games on her PS 24. She started off going to college for political science and after not knowing what to do after that, she got her first start in cybersecurity. After falling in love with cybersecurity she kept moving up the ranks in different organizations before finding herself at Avast. She shares that at Avast she leans on her team quite a bit and you should never be afraid to bounce ideas off of your teammates. She says "The best ideas come from like bouncing ideas off of each other, sharing within the group and then if I can't figure it out myself, that's why I hire these amazing individuals it's to help me figure it out." We thank Jaya for sharing her story.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    An increase in bypassing bot management? [Research Saturday] Sep 17, 2022
    Show notes

    Sam Crowther, CEO of Kasada join's Dave to discuss their work on "The New Way Fraudsters Bypass Bot Management." Kasada researchers recently discovered a new type of bot called Solver Services, which is used and created by bad actors to bypass the majority of bot management systems.

    The research states "Now it’s easier than ever for mainstream bot operators to scrape content, take over accounts, hoard inventory, and commit other forms of automated fraud against organizations using legacy bot management solutions." Attackers are able to by these “Solver” bots, APIs, and services for less than $500 per month to make a profit.

    The research can be found here:

    • The Emergence of Solver Services: The New Way Fraudsters Bypass Bot Management Vendors

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Uber sustains a major data breach. Notes on the underworld. A large DDoS attack is stopped in Eastern Europe. An FBI alert and a brace of CISA advisories. Congress deliberates cyber policy. Sep 16, 2022
    Show notes

    Uber suffers a data breach. Social media executives testify before Congress. A Large DDoS attack is thwarted in Eastern Europe. The FBI warns of increased cyberattacks against healthcare payment processors. Policy makers consider new OT security incentives. Malek Ben Salem from Accenture on future-proof cloud security. Our guest Diana Kelley from Cybrize discusses the need for innovation and entrepreneurship in cybersecurity. And if you’ve been hoping for a LockerGoga decryptor, you’re in luck.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/11/179


    Selected reading.

    Uber hacked, internal systems breached and vulnerability reports stolen (BleepingComputer)

    Uber suffers computer system breach, alerts authorities (Washington Post)

    Uber Investigating Data Breach After Hacker Claims Extensive Compromise (SecurityWeek)

    Uber Investigating Breach of Its Computer Systems (New York Times)

    Uber investigating "total compromise" of its internal systems (Computing)

    There’s No Honor Among Thieves: Carding Forum Staff Defraud Users in an ESCROW Scam (Digital Shadows)

    Social media hearings highlight lack of trust, transparency in sector (The Record by Recorded Future)

    Breaking the Boycott (Cybersixgill)

    Record-Breaking DDoS Attack in Europe (Akamai)

    Cyber Criminals Targeting Healthcare Payment Processors, Costing Victims Millions in Losses (FBI)

    Siemens Mobility CoreShield OWG Software (CISA)

    Siemens Simcenter Femap and Parasolid (CISA)

    Siemens RUGGEDCOM ROS (CISA)

    Siemens Mendix SAML Module (CISA)

    Siemens SINEC INS (CISA)

    Siemens RUGGEDCOM ROS (Update A) (CISA)

    Simcenter Femap and Parasolid (CISA)

    Siemens Industrial Products Intel CPUs (Update A) (CISA)

    Siemens OpenSSL Affected Industrial Products (CISA)

    Siemens OpenSSL Vulnerability in Industrial Products (Update E) (CISA)

    Siemens SCALANCE (CISA)

    CISA Adds Six Known Exploited Vulnerabilities to Catalog (CISA)

    Building on our Baseline: Securing Industrial Control Systems Against Cyberattacks (House Committee on Homeland Security)

    Bitdefender Releases Universal LockerGoga Decryptor in Cooperation with Law Enforcement (Bitdefender Labs)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    CISA Alert AA22-257A – Iranian Islamic Revolutionary Guard Corps-Affiliated Cyber Actors Exploiting Vulnerabilities for Data Extortion and Disk Encryption for Ransom Operations. [CISA Cybersecurity Alerts] Sep 15, 2022
    Show notes

    This joint Cybersecurity Advisory highlights continued malicious cyber activity by advanced persistent threat actors affiliated with the Iranian Government’s Islamic Revolutionary Guard Corps. The IRGC-affiliated actors are actively targeting a broad range of entities, including entities across multiple U.S. critical infrastructure sectors as well as Australian, Canadian, and United Kingdom organizations.

    AA22-257A Alert, Technical Details, and Mitigations

    AA22-257A.stix

    CISA’s Iran Cyber Threat Overview and Advisories

    FBI’s Iran Threat webpage.

    Iranian Government-Sponsored APT Cyber Actors Exploiting Microsoft Exchange and Fortinet Vulnerabilities in Furtherance of Malicious Activities

    Technical Approaches to Uncovering and Remediating Malicious Activity

    All organizations should report incidents and anomalous activity to CISA’s 24/7 Operations Center at central@cisa.dhs.gov or (888) 282-0870 and to the FBI via your local FBI field office or the FBI’s 24/7 CyWatch at (855) 292-3937 or CyWatch@fbi.gov.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Previous 1 160 161 162 163 164 378 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights