TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    CyberWire Daily

    The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

    Advertise

    Copyright: © 2024 N2K Networks, Inc. 706761

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    BlackByte’s back, as BlackByte 2.0. Iranian cyber ops against Israel. Wipers and cyberespionage as tools in Russia’s hybrid war. Cyber war clauses coming to cyber insurance policies. Aug 18, 2022
    Show notes

    BlackByte is back. Iran suspected of cyber operations against four Israeli sectors. A look at wipers as a tool in hybrid war. A Russian cyber ops scorecard. Josh Ray from Accenture on how dark web actors are focusing on VPNs. Our guest is Corey Nachreiner from WatchGuard with findings of their latest Internet Security Report. Cyber war clauses coming to cyber insurance policies.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/11/159


    Selected reading.

    BlackByte ransomware gang is back with new extortion tactics (BleepingComputer)

    Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors | Mandiant (Mandiant)

    Russia-Ukraine cyberwar creates new malware threats (VentureBeat)

    Global Threat Landscape Report: A Semiannual Report by FortiGuard Labs (Fortinet)

    Overview of the Cyber Weapons Used in the Ukraine - Russia War (Trustwave SpiderLabs)

    Lloyd’s sets requirements for state-backed cyber attack exclusions (Insurance Day)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Cyber incidents and lessons from Russia's hybrid war. Zimbra vulnerabilities exploited. New Lazarus Group activity reported. ICS security advisories .Insider trading charges from 2017 Equifax breach. Aug 17, 2022
    Show notes

    A DDoS attack against a Ukrainian nuclear power provider. The US Army draws some lessons from the cyber phases of Russia's hybrid war. Vulnerabilities in Zimbra are undergoing widespread exploitation.Reports of new Lazarus Group activity. CISA releases eight ICS security advisories. Carole Theriault looks at scammers and cryptocurrencies. Our guest is Jennifer Reed from Aviatrix on the changing landscape of cloud security. And the SEC charges three with insider trading during the 2017 Equifax breach.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/11/158


    Selected reading.

    Ukrainian Nuclear Operator Accuses Russians Hackers Of Attacking Its Website (RadioFreeEurope/RadioLiberty)

    Ukraine nuclear power company says Russia attacked website (Al Jazeera)

    Ukraine Nuclear Operator Reports Cyberattack on Its Website (The Defense Post)

    How electronic warfare is reshaping the war between Russia and Ukraine (The Record by Recorded Future)

    Army lesson from Ukraine war: cyber, EW capabilities not decisive on their own (FedScoop)

    Learning from Ukraine, Army cyber schoolhouse focuses on electromagnetic spectrum (Breaking Defense)

    Cyber and full-spectrum operations push the Great Power conflict left of boom (Breaking Defense)

    Microsoft Exchange alternative Zimbra is getting widely exploited, 1000s hit (The Stack)

    CISA Alert AA22-228A – Threat actors exploiting multiple CVEs against Zimbra Collaboration suit (CyberWire)

    Threat Actors Exploiting Multiple CVEs Against Zimbra Collaboration Suite (CISA)

    A signed Mac executable… (ESET)

    Yokogawa CENTUM Controller FCS (CISA)

    LS ELECTRIC PLC and XG5000 (CISA)

    Delta Industrial Automation DRAS (CISA)

    Softing Secure Integration Server (CISA)

    B&R Industrial Automation Automation Studio 4 (CISA)

    Emerson Proficy Machine Edition (CISA)

    Sequi PortBloque S (CISA)

    Siemens Industrial Products with OPC UA (CISA)

    U.S. SEC charges 3 people with insider trading tied to Equifax hack (Reuters)

    SEC Charges Three Chicago-Area Residents with Insider Trading Around Equifax Data Breach Announcement (US Securities and Exchange Commission)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    CISA Alert AA22-228A – Threat actors exploiting multiple CVEs against Zimbra Collaboration suite. [CISA Cybersecurity Alerts} Aug 17, 2022
    Show notes

    CISA and the Multi-State Information Sharing & Analysis Center, or MS-ISAC are publishing this joint Cybersecurity Advisory in response to active exploitation of multiple Common Vulnerabilities and Exposures against Zimbra Collaboration Suite, an enterprise cloud-hosted collaboration software and email platform.

    AA22-228A Alert, Technical Details, and Mitigations

    Volexity’s Mass Exploitation of (Un)authenticated Zimbra RCE: CVE-2022-27925

    Hackers are actively exploiting password-stealing flaw in Zimbra

    CISA adds Zimbra email vulnerability to its exploited vulnerabilities catal…

    CVE-2022-27925 detail

    Mass exploitation of (un)authenticated Zimbra RCE: CVE-2022-27925

    CVE-2022-37042 detail

    Authentication bypass in MailboxImportServlet vulnerability

    CVE-2022-30333 detail

    UnRAR vulnerability exploited in the wild, likely against Zimbra servers

    Zimbra Collaboration Kepler 9.0.0 patch 25 GA release

    Zimbra UnRAR path traversal

    Operation EmailThief: Active exploitation of zero-day XSS vulnerability in…

    Hotfix available 5 Feb for zero-day exploit vulnerability in Zimbra 8.8.15

    All organizations should report incidents and anomalous activity to CISA’s 24/7 Operations Center at central@cisa.dhs.gov or (888) 282-0870 and to the FBI via your local FBI field office or the FBI’s 24/7 CyWatch at (855) 292-3937 or CyWatch@fbi.gov.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Russian cyberespionage and influence op disrupted. RedAlpha versus Chinese minorities and (of course) Taiwan. Evil PLC proof-of-concept. Cl0p takes a poke at a water utility. Aug 16, 2022
    Show notes

    Microsoft identifies and disrupts Russian cyberespionage activity. An update on RedAlpha. An evil PLC proof-of-concept shows how programmable logic controllers could be "weaponized." Ben Yelin has an update on right to repair. Our guest is Arthur Lozinski of Oomnitza with a look at attack surface management maturity. And the Cl0p gang hits an English water utility (but tries to extort the wrong one–stuff happens, y’know?).


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/11/157


    Selected reading.

    Disrupting SEABORGIUM’s ongoing phishing operations (Microsoft Security

    Microsoft disrupts Russian-linked hackers targeting NATO countries (Breaking Defense)

    Microsoft Announces Disruption of Russian Espionage APT (SecurityWeek)

    Microsoft disrupts Russia-linked hacking group targeting defense and intelligence orgs (The Record by Recorded Future)

    Microsoft shuts down accounts linked to Russian spies (Register)

    RedAlpha Conducts Multi-Year Credential Theft Campaign Targeting Global Humanitarian, Think Tank, and Government Organizations (Recorded Future)

    Hackers linked to China have been targeting human rights groups for years (MIT Technology Review)

    Evil PLC Attack: Using a Controller as Predator Rather than Prey (Claroty)

    Hackers attack UK water supplier but extort wrong victim (BleepingComputer)

    South Staffordshire Water victim of cyber attack, customers not at risk (Computing)

    South Staffordshire Water says it was target of cyber attack as criminals bungle extortion attempt (Sky News)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Shuckworm and Killnet continue to hack in the interest of Russia. Iron Tiger's supply chain campaign. TikTok and national security. And an arrest in the case of the Tornado Cash crypto mixer. Aug 15, 2022
    Show notes

    Shuckworm maintains its focus on Ukrainian targets. Killnet's DDoS and dubious proof-of-work. Iron Tiger's supply chain campaign. TikTok and national security. Dinah Davis from Arctic Wolf shares insights on Dark Utilities. Rick Howard digs into identity management. And an arrest in the case of the Tornado Cash crypto mixer.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/11/156


    Selected reading.

    Shuckworm: Russia-Linked Group Maintains Ukraine Focus (Symantec)

    Killnet Releases 'Proof' of its Attack Against Lockheed Martin (SecurityWeek)

    Killnet greift lettisches Parlament an (Tagesspiegel)

    Iron Tiger Compromises Chat Application Mimi, Targets Windows, Mac, and Linux Users (Trend Micro)

    How Frustration Over TikTok Has Mounted in Washington (New York Times)

    3 ways China's access to TikTok data is a security risk (CSO Online)

    Arrest of suspected developer of Tornado Cash (FIOD)

    Tornado Cash Developer Arrested After U.S. Sanctions the Cryptocurrency Mixer (The Hacker News)

    Arrested Tornado Cash developer is Alexey Pertsev, his wife confirms (The Block)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Red teamer's perspective on demotivating attackers. [CyberWire-X] Aug 14, 2022
    Show notes

    Cybercriminals are motivated by one simple incentive - money. Their favorite tools are bots to leverage sophistication, scalability, and ease of use. The effect is the creation of the underground bot ecosystem. This community allows threat actors to work together and continually improve their tactics. They sell bypasses for rule-based anti-bot solutions to other less technical fraudsters.

    In this episode of CyberWire-X, the CyberWire's CSO, Chief Analyst, and Senior Fellow, Rick Howard, is joined in the first half by Hash Table member Etay Maor. Cato Networks’ Senior Director Security Strategy. They discuss this reality that has put defenders at a serious disadvantage and the mitigation steps to consider for future attacks.. In the second half of the show, CyberWire podcast host Dave Bittner talks with our episode sponsor Kasada's founder Sam Crowther talking about what he saw first-hand as a red teamer at a major Australian bank and what inspired him to reimagine bot mitigation with the founding principle of undermining the attacker’s ROI.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Christian Lees: it's not always textbook. [CTO] [Career Notes] Aug 14, 2022
    Show notes

    Christian Lees, CTO at Resecurity, shares his story and insight on coming into the cybersecurity world. He considers himself a late bloomer because he did not go to college until he was 23. He wasn’t sure of what he wanted to do, and a family friend gave him a computer and the rest was history, he says. He fell in love with computers and started working at different companies trying to get ahead. He says it's not always textbook, and sometimes you just need to cut your teeth on something to get where you're going. Throughout his journey, he was constantly questioning whether he made the right decision, and in the end he says you have to be willing to "define friction points in it, you may join security field, not knowing what you're gonna do, but by being that curious person and breaking things and putting it back together, you'll find the right way and just never stop being curious." We thank Christian for sharing his story.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Fake job ads and how to spot them. [Research Saturday] Aug 13, 2022
    Show notes

    Ashley Taylor from SANS.edu, joins Dave to discuss fake job ads and methods to proactively detect these scams. The research shares how job seekers are under attack, with scammers posing as fake job recruiters to steal information from people who are interested in the job posting. The brands being impersonated as are at risk of losing credibility to their brand identity.

    The research shares exactly how these doppelgängers are posing a threat to job seekers and the best practices to detect these scams. It also shares how one company that works in medical device manufacturing industry has been a target for these scams. It concludes with sharing some of the ways to proactively spot these scams before they happen.

    The research can be found here:

    • Doppelgängers: Finding Job Scammers Who Steal Brand Identities

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    The optempo of a hybrid war's cyber phase. Hacktivists as cyber partisans. Zeppelin ransomware alert. DoNot Team update. Rewards for Justice offers $10 million for info on Russian bad actors. Aug 12, 2022
    Show notes

    The optempo of the war's cyber phase, and Ukraine’s response. Organizing and equipping hacktivists. Joint warning on Zeppelin ransomware. Update on the DoNot Team, APT-C-35. Rewards for Justice offers $10 million for information on Conti operators. Rob Boyce from Accenture shares insights from BlackHat. Caleb Barlow ponders closing the skills gap while shifting to remote work. And, hey, Mr. Target: pick one, OK?


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/11/155


    Selected reading.

    Black Hat 2022‑ Cyberdefense in a global threats era (WeLiveSecurity)

    How one Ukrainian ethical hacker is training 'cyber warriors' in the fight against Russia (The Record by Recorded Future)

    #StopRansomware: Zeppelin Ransomware (CISA)

    APT-C-35: New Windows Framework Revealed (Morphisec)

    The US Offers a $10M Bounty for Intel on Conti Ransomware Gang (Wired)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    CISA Alert AA22-223A – #StopRansomware: Zeppelin Ransomware. [CISA Cybersecurity Alerts} Aug 11, 2022
    Show notes

    Zeppelin ransomware functions as a ransomware-as-a-service (RaaS), and since 2019, actors have used this malware to target a wide range of businesses and critical infrastructure organizations. Actors use remote desktop protocol (RDP), SonicWall firewall vulnerabilities, and phishing campaigns to gain initial access to victim networks and then deploy Zeppelin ransomware to encrypt victims’ files.

    AA22-223A Alert, Technical Details, and Mitigations

    Zeppelin malware YARA signature

    What is Zeppelin Ransomware? Steps to Prepare, Respond, and Prevent Infection

    Stopransomware.gov is a whole-of-government approach that gives one central location for ransomware resources and alerts.

    No-cost cyber hygiene services: Cyber Hygiene Services and Ransomware Readiness Assessment.

    This joint Cybersecurity Advisory is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed TTPs and IOCs to help organizations protect against ransomware. Visit stopransomware.gov to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources.

    All organizations should report incidents and anomalous activity to CISA’s 24/7 Operations Center at central@cisa.dhs.gov or (888) 282-0870 and to the FBI via your local FBI field office or the FBI’s 24/7 CyWatch at (855) 292-3937 or CyWatch@fbi.gov.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Previous 1 164 165 166 167 168 378 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights