TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    CyberWire Daily

    The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

    Advertise

    Copyright: © 2024 N2K Networks, Inc. 706761

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    Charity Wright: Pursue what you love [Threat intelligence] [Career Notes] May 22, 2022
    Show notes

    Threat intelligence analyst at Recorded Future, Charity Wright, shares her story from the army to her career today. Transitioning from the army to cybersecurity was an exciting change for her. During college she was recruited by the U.S army where she started her journey and learned new skills paving her pathway to threat intelligence where she is now. She shares that she works with a great team of junior analysts who are constantly checking each others biases which helps keep Charity grounded in her work. Charity spends her days keeping an eye on threats around the world where she says there is never a dull day in her line of work. We thank Charity for sharing her story with us.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    AutoWarp bug leads to Automation headaches. [Research Saturday] May 21, 2022
    Show notes

    Yanir Tsarimi from Orca Security, joins Dave to discuss how researchers have discovered a critical Azure Automation service vulnerability called AutoWarp. The security flaw was discovered this past March causing Yanir to leap into action announcing the issue to Microsoft who helped to swiftly resolve the cross-account vulnerability.

    The research shows how this serious flaw would allow attackers unauthorized access to other customer accounts and potentially full control over resources and data belonging to those accounts, as well as put multiple Fortune 500 companies and billions of dollars at risk. The research shares the crucial time line that the vulnerability was discovered as well as Microsofts response to the vulnerability.

    The research can be found here:

    • AutoWarp: Critical Cross-Account Vulnerability in Microsoft Azure Automation Service

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Is Conti rebranding? Commercial spyware scrutinized. Notes from the cyber phases of a hybrid war. Notes on the underworld. Software supply chain attack. Canada will exclude Huawei from 5G. May 20, 2022
    Show notes

    Was Conti’s digital insurrection in Costa Rica misdirection? Google assesses a commercial spyware threat “with high confidence.” Continuing expectations of escalation in cyberspace. The limitations of an alliance of convenience. Fronton botnet shows versatility. Russian hacktivists hit Italian targets, again. Lazarus Group undertakes new SolarWinds exploitation. Crypters in the C2C market. CrateDepression supply chain attack. Johannes Ullrich describes an advance fee scam hitting crypto markets. Our guest is Marty Roesch, CEO of Netography and inventor of Snort. Canada to exclude Huawei from 5G networks on security grounds.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/11/98


    Selected reading.

    Conti ransomware shuts down operation, rebrands into smaller units (BleepingComputer)

    Protecting Android users from 0-Day attacks (Google)

    Microsoft President: Cyber Space Has Become the New Domain of Warfare (Infosecurity Magazine)

    Twisted Panda: Chinese APT espionage operation against Russian’s state-owned defense institutes (Check Point Research)

    Chinese Hackers Tried to Steal Russian Defense Data, Report Says (New York Times)

    China-linked Space Pirates APT targets the Russian aerospace industry (Security Affairs)

    This Russian botnet does far more than DDoS attacks - and on a massive scale (ZDNet)

    Pro-Russian hackers attack institutional websites in Italy, police say (Reuters)

    Lazarus hackers target VMware servers with Log4Shell exploits (BleepingComputer)

    ITG23 Crypters Highlight Cooperation Between Cybercriminal Groups (Security Intelligence)

    CrateDepression | Rust Supply-Chain Attack Infects Cloud CI Pipelines with Go Malware (SentinelOne)

    Canada to ban Huawei/ZTE 5G equipment, joining Five Eyes allies (Reuters)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    CISA Alert AA22-138B – Threat actors chaining unpatched VMware vulnerabilities for full system control. [CISA Cybersecurity Alerts] May 20, 2022
    Show notes

    CISA is releasing this cybersecurity advisory to warn organizations that malicious cyber actors are exploiting CVE-2022-22954 and CVE-2022-22960. These vulnerabilities affect versions of VMware products. Successful exploitation permits malicious actors to trigger a server-side template injection that may result in remote code execution or escalation of privileges to root level access. Based on this activity, CISA expects malicious cyber actors to quickly develop a capability to exploit newly released VMware vulnerabilities CVE-2022-22972 and CVE-2022-22973 in the same impacted VMware products.

    AA22-138B Alert, Technical Details, and Mitigations

    AA22-138B.stix

    Emergency Directive 22-03 Mitigate VMware Vulnerabilities

    VMware Security Advisory VMSA-2022-0011

    VMware Security Advisory VMSA-2022-0014

    All organizations should report incidents and anomalous activity to CISA’s 24/7 Operations Center at central@cisa.dhs.gov or (888) 282-0870 and to the FBI via your local FBI field office or the FBI’s 24/7 CyWatch at (855) 292-3937 or CyWatch@fbi.gov.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Information operations and the invasion of Ukraine. VMware patches vulnerabilities. F5 BIG-IP vulnerabilities actively exploited. TDI clarifies data incident. Robo-calling the Kremlin. May 19, 2022
    Show notes

    Russian information operations surrounding the invasion of Ukraine. VMware patches vulnerabilities. F5 BIG-IP vulnerabilities undergoing active exploitation. Texas Department of Insurance clarifies facts surrounding its data incident. Robert M. Lee from Dragos is heading to Davos to talk ICS. Rick Howard speaks with author Chase Cunningham on his book "Cyber Warfare –Truth, Tactics and Strategies”. Robo-calling the Kremlin.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/11/97


    Selected reading.

    Information Operations Surrounding the Russian Invasion of Ukraine (Mandiant)

    CISA Issues Emergency Directive and Releases Advisory Related to VMware Vulnerabilities (CISA)

    Emergency Directive 22-03 (CISA)

    Threat Actors Chaining Unpatched VMware Vulnerabilities for Full System Control (CISA)

    Threat Actors Exploiting F5 BIG IP CVE-2022-1388 (CISA)

    CISA Alert AA22-138A – Threat Actors Exploiting F5 BIG-IP CVE-2022-1388. (The CyberWire)

    Additional facts: TDI data security event (Texas Department of Insurance)

    This Hacktivist Site Lets You Prank Call Russian Officials (Wired)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    CISA Alert AA22-138A – Threat Actors Exploiting F5 BIG-IP CVE-2022-1388. [CISA Cybersecurity Alerts] May 19, 2022
    Show notes

    CISA and the Multi-State Information Sharing & Analysis Center (MS-ISAC), are releasing this joint Cybersecurity Advisory in response to active exploitation of CVE-2022-1388. This vulnerability is a critical iControl REST authentication bypass vulnerability affecting multiple versions of F5 Networks BIG-IP.

    AA22-138A Alert, Technical Details, and Mitigations

    F5 Security Advisory K23605346 and indicators of compromise

    F5 guidance K11438344 for remediating a compromise

    Emerging Threats suricata signatures

    Palo Alto Networks Unit 42 Threat Brief: CVE-2022-1388. This brief includes indicators of compromise.

    Cisco Talos Intelligence Group - Comprehensive Threat Intelligence: Threat Advisory: Critical F5 BIG-IP Vulnerability. This blog includes indicators of compromise. Note: due to the urgency to share this information, CISA and MS-ISAC have not yet validated this content.

    Randori’s bash script. This script can be used to identify vulnerable instances of BIG-IP. Note: MS-ISAC has verified this bash script identifies vulnerable instances of BIG-IP.

    All organizations should report incidents and anomalous activity to CISA’s 24/7 Operations Center at central@cisa.dhs.gov or (888) 282-0870 and to the FBI via your local FBI field office or the FBI’s 24/7 CyWatch at (855) 292-3937 or CyWatch@fbi.gov.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Privateering goes fully political. Compromised robots? Conti’s campaign against Costa Rica. Cyberconflict along the Nile. A reset in the cyber insurance market. May 18, 2022
    Show notes

    Chaos ransomware group declares for Russia. Hacktivists claim to have compromised Russian-manufactured ground surveillance robots. Conti's ongoing campaign against Costa Rica. The claimed "international" cyberattack against Nile dam was stopped. Rick Howard speaks with author Caroline Wong on her book “Security Metrics, a Beginner's Guide”. Our guests are Kathleen Smith and Rachel Bozeman, hosts of the new podcast, Security Cleared Jobs. And the cyber insurance market experiences a “reset.”


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/11/96


    Selected reading.

    Chaos Ransomware Variant Sides with Russia (Fortinet Blog)

    Did hackers commandeer surveillance robots at a Russian airport? (The Daily Dot)

    Russian Hacking Cartel Attacks Costa Rican Government Agencies (New York Times)

    Costa Rican president claims collaborators are aiding Conti's ransomware extortion efforts (CyberScoop)

    "We will overthrow the government" - Does Conti have help inside Costa Rica? (Tech Monitor)

    Costa Ricans scrambled to pay taxes by hand after cyberattack took down country’s collection system (Yahoo)

    Ethiopia faces new cyberattacks on its Nile dam (Al-Monitor)

    Cyber Insurers Raise Rates Amid a Surge in Costly Hacks (Wall Street Journal)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    CISA Alert AA22-137A – Weak security controls and practices routinely exploited for initial access. [CISA Cybersecurity Alerts] May 17, 2022
    Show notes

    This joint cybersecurity advisory was coauthored by the cybersecurity authorities of the US, Canada, New Zealand, the Netherlands, and the UK. Cyber actors routinely exploit poor security configurations, weak controls, and other poor cyber hygiene practices to gain initial access or as part of other tactics to compromise a victim’s system. This joint Cybersecurity Advisory identifies commonly exploited controls and practices, and includes best practices to mitigate these risks.

    AA22-137A Alert, Technical Details, and Mitigations

    White House Executive Order on Improving the Nation’s Cybersecurity

    NCSC-NL Factsheet: Prepare for Zero Trust

    NCSC-NL Guide to Cyber Security Measures

    N-able Blog: Intrusion Detection System (IDS): Signature vs. Anomaly-Based

    NCSC-NL Guide to Cyber Security Measures

    National Institute of Standards and Technology SP 800-123 – Keeping Servers Secured

    NCSC-UK Guidance – Phishing Attacks: Defending Your Organisation

    Open Web Application Security Project (OWASP) Proactive Controls: Enforce Access Controls

    All organizations should report incidents and anomalous activity to CISA’s 24/7 Operations Center at central@cisa.dhs.gov or (888) 282-0870 and to the FBI via your local FBI field office or the FBI’s 24/7 CyWatch at (855) 292-3937 or CyWatch@fbi.gov.

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Russian cyber threats and NATO’s Article 5. Conti says it’s going to bring Cost Rica to its knees. BLE proof-of-concept hack. CISA warns of initial access methods. Thanos proprietor indicted. May 17, 2022
    Show notes

    An assessment of the Russian cyber threat. NATO's Article 5 in cyberspace. Conti's ransomware attack against Costa Rica spreads, in scope and effect. Bluetooth vulnerabilities demonstrated in proof-of-concept. CISA and its international partners urge following best practices to prevent threat actors from gaining initial access. Joe Carrigan looks at updates to the FIDO alliance. Rick Howard and Ben Rothke discuss author Andrew Stewart's book "A Vulnerable System: The History of Information Security in the Computer Age". And,the doctor was in, but wow, was he also way out of line.


    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/11/95


    Selected reading.

    Russia Planned a Major Military Overhaul. Ukraine Shows the Result. (New York Times)

    The Cyberwar Against Pro-Ukrainian Countries is Real. Here’s What to Do (CSO Online)

    Collective cyber defence and attack: NATO’s Article 5 after the Ukraine conflict (European Leadership Network)

    Cyber attack on Costa Rica grows as more agencies hit, president says (Reuters)

    Ransomware gang threatens to ‘overthrow’ new Costa Rica government, raises demand to $20 million (The Record by Recorded Future)

    Hacker Shows Off a Way to Unlock Tesla Models, Start Cars (Bloomberg)

    NCC Group uncovers Bluetooth Low Energy (BLE) vulnerability that puts millions of cars, mobile devices and locking systems at risk (NCC Group)

    Technical Advisory – Tesla BLE Phone-as-a-Key Passive Entry Vulnerable to Relay Attacks (NCC Group Research)

    Technical Advisory – Kwikset/Weiser BLE Proximity Authentication in Kevo Smart Locks Vulnerable to Relay Attacks (NCC Group Research)

    Technical Advisory – BLE Proximity Authentication Vulnerable to Relay Attacks (NCC Group Research)

    Alert (AA22-137A) Weak Security Controls and Practices Routinely Exploited for Initial Access (CISA)

    Hacker and Ransomware Designer Charged for Use and Sale of Ransomware, and Profit Sharing Arrangements with Cybercriminals (U.S. Attorney’s Office for the Eastern District of New York)

    US prosecutors allege Venezuelan doctor is ransomware mastermind (ZDNet)

    'Multi-tasking doctor' was mastermind behind 'Thanos' ransomware builder, DOJ says (The Record by Recorded Future)

    U.S. Charges Venezuelan Doctor for Using and Selling Thanos Ransomware (The Hacker News)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Users advised to patch actively exploited Zyxel vulnerability. Hacktivism and influence ops in Russia’s hybrid war. Ransomware notes. Indiscriminate hacktivism? Alt-coin sanctions case will proceed. May 16, 2022
    Show notes

    Users are advised to patch Zyxel firewalls. Battlefield failure and popular morale in Russia’s hybrid war. Nuisance-level hacktivism in the hybrid war. Sweden and Finland move closer to NATO membership; concern over possible Russian cyberattacks rises. Intelligence, disinformation, or wishful thinking? Conti calls for rebellion in Costa Rica. PayOrGrief is just rebranded DoppelPaymer. Anonymous action in Sri Lanka seems indiscriminate and counterproductive. Dinah Davis from Arctic Wolf examines cyber security for startups. Rick Howard looks at two factor authentication. And a judge says cryptocurrency can’t be used to evade sanctions.

    For links to all of today's stories check out our CyberWire daily news briefing:

    https://thecyberwire.com/newsletters/daily-briefing/11/94


    Selected reading.

    Critical Vulnerability Allows Remote Hacking of Zyxel Firewalls (SecurityWeek)

    Zyxel security advisory for OS command injection vulnerability of firewalls (Zyxel)

    Growing evidence of a military disaster on the Donets pierces a pro-Russian bubble. (New York Times)

    OpRussia update: Anonymous breached other organizations (Security Affairs)

    Italy prevents pro-Russian hacker attacks during Eurovision contest (Reuters)

    Finland, Sweden’s NATO moves prompt fears of Russian cyberattacks (The Hill)

    Coup to remove cancer-stricken Putin underway in Russia, Ukrainian intelligence chief says (Fortune)

    Conti ransomware gang calls for Costa Rican citizens to revolt if government doesn't pay (SC Magazine)

    Anonymous wanted to help Sri Lankans. Their hacks put many in grave danger (Rest of World)

    U.S. issues charges in first criminal cryptocurrency sanctions case (Washington Post)

    Learn more about your ad choices. Visit megaphone.fm/adchoices


    Previous 1 174 175 176 177 178 378 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights