Search this show’s transcripts

CyberWire Daily

en us
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

Episodes

Page 71 · 50 per page

In today's podcast, Dark Web trading post AlphaBay looks buggy, and leaky. Some not-so-bad news on ransomware (and bravo to those Gateway City librarians). Risk Based Security's 2016 breach report says the USA is number one (but not in a good way). Sweden's armed forces recover from a cyberattack by unnamed parties. Saudi Arabia remains on high-alert for fresh infestations of Shamoon. Dan Larson from CrowdStrike weighs in on ransomware evolution. Markus Rauschecker from the University of Maryland Center for Health and Homeland Security highlights a Dept. of Commerce report on the IoT. And the Russian treason case may be closer to what would look like a corruption case under Western eyes.

Extract Knowledge

In today's podcast we hear about Russia's arrest of a Kaspersky Lab threat researcher (charges are said to be unrelated to Kaspersky). Charger ransomware is detected and ejected from the Play Store. Mobile users are urged to watch their apps—too many snakes are still getting into the walled gardens. RATs evolve and return to the wild. Shamoon 2 expands its target set. A database vigilante may be out there. Awais Rashid joins us from Lancaster University to share thoughts on IoT devices in healthcare. Michael Lipinski from Securonix wonders if state actors have become a convenient excue. Cyber fraud rises in the United Kingdom—it's safer for the crooks than stickups. M&A and venture funding news. And that Verizon-Yahoo! deal remains up in the air.

Extract Knowledge

In today's podcast, we discuss a report from Symantec that Shamoon may be connected to Greenbug. Google is purging HummingWhale malware from the Play Store. Apple issues a major set of patches across its product line. CIA has a new director; GCHQ's still looking for one. Yahoo!'s deal with Verizon will be delayed until April at least. Other industry M&A and venture funding news is more upbeat. Lloyds Bank is said to have been targeted with cyber extortion. Ben Gurion University's Yisroel Mirsky describes vulnerabilities with 3D printers. And there's no honor among thieves—if you don't believe us, ask the thieves.

Extract Knowledge

In today's podcast we discuss some fake tweets from hijacked news accounts around the time of the US Presidential transition—OurMine seems to have some at least tangential involvement. BankBot Android Trojan evolves, and Skyfin will quietly buy stuff you don't want from the Google Play Store. Sage 2.0 ransomware distributed by repurposed spam. Ill-named Dharma ransomware hits Indian pony site. Lloyds Bank disclosed DDoS attacks. Cryptographer Matthew Green describes Google new open source Key Transparency project. Jonathan Katz from the University of Maryland explains multivariate encryption. The SEC looks at Yahoo!'s breach disclosure record. And the FBI is taking an interest in the gentleman Krebs fingered as Mirai's master.

Extract Knowledge

In today's podcast, we hear about how the Carbank cyber gang is getting trickier and more ambitious. In other cybercrime news, ransomware takes off after more databases. There's a new ransomware-as-a-service offering in the black market. Emily Wilson from Terbium Labs addresses perceptions of terrorists on the dark web. Simone Petrella from CyberVista provides her perspective on cyber security workforce issues. A new strain of Android ransomware hits Russian-speaking users. Locky's back, but in a feeble sort of way. Cybercriminals lock files at a cancer service not-for-profit. Russian policy wonks seem to suggest that we're not at the point in history where 2016 yielded to 2017. Instead—calling all Cold Warriors—1948 just ticked over into 1949. 

Extract Knowledge

France prepares for election hacking. Ukrenergo [yook-REN-air-go] acknowledges its electrical service was hacked. Malwarebytes reports on Fruitfly, malware swarming about biomedical research facilities. Krebs believes he's found the author of Mirai. Anonymous says it's going to dox US President-elect Trump. Ben Yelin reviews your rights to privacy at the border. Nir Giller from CyberX addresses the false sense of security when it comes to ICS. And the RSA Conference announces the finalists in the Innovation Sandbox.

Extract Knowledge

Carbanak is back, and in the cloud. GhostAdmin quietly assembles a few good bots. Malware writers troll security researchers on VirusTotal. Oracle issues a big patch; Apple is said to be preparing a smaller one. M&A activity is in the news. Australia investigates fallout from the Yahoo! breaches. Experts warn European election officials and politicians to be on the lookout for Bears. Rick Howard from Palo Alto Networks seeks a unified theory of security. David Bianco from Sqrrl offers advice on threat hunting. And US President Obama issues some pardons and commutations—General Cartwright and Private Manning are on the list. Not so Mr. Snowden.

Extract Knowledge

In today's podcast we hear warnings that electrical utilities should regard hacks of Ukraine's power grid as a wake-up call (the squirrel threat notwithstanding). Various nations work to shore up their defenses against Russian government hacking and influence operations. Russia protests its innocence, but there are some reliable reports of Fancy Bear sightings in Norway. Cyber criminals are back, except for those behind Locky ransomware, who seem to still be on holiday break. New approaches to ransomware and phishing. Dale Drew from Level 3 Communications tell us about the BGP Flowspec. And a loyalty program at the Golden Arches may be proving problematic. 

Extract Knowledge

In today's podcast we get updates on grid hacking in Ukraine and the case of the EyePyramid spyware in Italy. Smartphone forensics shop Cellebrite suffers a data breach. WhatsApp appears to have an encryption issue, but most observers think it's not really a backdoor. WordPress gets eight patches. ENISA issues recommended best practices for securing connected cars. A US Justice Department IG will look into the FBI's investigation of classified information handling in the Clinton State Department. President Obama expands NSA's authority to share raw SIGINT with other intelligence agencies. The Johns Hopkins University's Joe Carrigan reminds us to protect our mobile phone numbers. Stanford Cyber Initiative Executive Director Allison Berke shares that organization's mission. Guccifer 2.0 wants to clear a few things up, and the ShadowBrokers say "bye-bye," or maybe "do svidaniya."

Extract Knowledge

In today's podcast, we hear about the arrest of an Italian brother and sister for an EyePyramid spyware crime spree that may have been in progress since 2010. Ukraine confirms that Kiev's power grid was hacked last month, and the Ukrainian government tries to tide over some influence operations of its own. Policy wonks talk information operations and some realize that such ops aren't new. The peace sign hack joins the Gummibear hack as a challenge to biometric authentication. Yisroel Mirsky from Ben Gurion University explains new research using databases of exploits and vulnerabilities. Quick industry notes. And Hamas goes catphishing.

Extract Knowledge

In today's podcast we learn that Shamoon is back, and still a nasty piece of work. Ukraine's grid was hacked again last month, probably by the same people who did it at the end of 2015. A new strain of ransomware offers a tiered extortion model (and unfortunately pretty solid encryption). France and Britain prepare for Russian election hacking. Awais Rashid from Lancaster University outlines the human factors in cyber security. Limor Kessem from IBM Security discusses their recently released ransomware study.The debate over influence operations flares again in the US. And China still finds Pokemon threatening.

Extract Knowledge

California says a nation-state was behind the Anthem hack. The ShadowBrokers hold a yard sale (we'd pass on the malware, but if they had a nice blender out we'd consider it). WikiLeaks says it's interested in relationships, not doxing. The US FDA confirms vulnerabilities in cardiac devices. Hello Kitty gets breached. Yahoo! will become Altaba, and get new leadership. Germany and the UK study ways of increasing cyber capability. The University of Maryland's Jonathan Katz reviews emerging encryption types. Uri Sternfeld from Cybereason explains their free ransomware prevention tool, RansomFree. Russia complains it's the subject of a witch hunt. 

Extract Knowledge

In today's podcast we hear about the report on Russian election hacking and influence operations the US Director of National Intelligence released Friday. Election hacking? Not really, but influence operations? You bet. Robert M. Lee from Dragos Security weighs in on the report. European authorities worry about Russia inserting itself into 2017 elections. Law, and order, torts and Twitter. Emily Wilson from Terbium Labs describes the role of law enforcement on the Dark Web. And a note on she-who-must-not-be-named (our listeners in San Diego will know exactly whom we mean—heck, it's Alexa).

Extract Knowledge

In today's podcast, we hear about a worldwide spearphishing attack against industries in 50 countries. Ransomware is already proving as much of a problem as predicted: exposed data bases are hijacked in a turf-war among extortion gangs, and KillDisk has now appeared in ransomware kits. Investment analysts wonder if Verizon's bid for Yahoo!'s core assets will go through. Ben Yelin from the University of Maryland Center for Health and Homeland Security discusses the IRS demanding info on some bitcoin users. FireEye's Tony Cole reviews their latest report on what to expect in 2017. The US Intelligence Community tells the Senate that, yes indeed, the Russians were hacking during the election. A full report is promised for next week.

Extract Knowledge

In today's podcast we hear about how indiscriminate indicators of compromise spawn fake news about a Vermont grid hack. Meanwhile, the Mounties cautiously, tentatively, investigate some odd potential IOCs at an Ontario utility. A hacker claims he pwned the FBI, but it looks like a hoax. A quick rundown of exploits currently romping in the wild—many of them involve ransomware. Rick Howard from Palo Alto describes Security Orchestration. Marika Chauvin from Threat Connect shares research on Hacktivists vs Faketivists. And yes, your thumbprint will authenticate you to your phone even if you've dozed off, Mom.

Extract Knowledge

In today's podcast, we hear about how some hacktivists are again turning to defacement, which they claim to be doing as a public service to raise security awareness. Recorded Future takes a close look at ransomware's likely course in 2017. ISIS exposes itself online. Attribution controversies: the Vermont hack-that-wasn't, tactical hacks in eastern Ukraine, and the FBI-NCCIC Joint Analysis Report. Malek Ben Salem from Accenture Technology Labs describes how Deep Learning may be applied to cyber security.  And would you hug Skynet, if it looked like Teddy Ruxpin?

Extract Knowledge

In today's podcast, we follow the way in which the Vermont utility hacking story fizzled. We also hear more serious grounds for concern about electrical grid security continue from Joe Weiss of Applied Control Solutions. Observers are disappointed by the Grizzly Steppe Joint Analysis Report—its evidence strikes many as mighty circumstantial. US-Russian cyber strategies and cyber diplomacy. Anonymous greets the Bilderbergers. ISIS claims responsibility for recent massacres as part of its online inspiration. Level 3 Communications' Dale Drew provides his take on the coming year. German police believe they've stopped a Saarland bomb plot.

Extract Knowledge
Published 2016-12-30

Best of: Daniel Ennis

17 min
View

Our podcast team is taking a break this week for the holidays. We’re revisiting some of our favorite interviews from 2016.  
 
Daniel Ennis is former director of the NSA Threat Operations Center, or NTOC, and is currently executive director of the University of Maryland Global Initiative on Cyber. We spoke with Daniel Ennis back in July. 

Extract Knowledge
Published 2016-12-30

Buying Cyber Security [Special Editions]

28 min
View

Every day there seems to be a new security product on the market, with many of them claiming they provide something that you simply can’t live without. Companies appear and disappear, and businesses are faced with difficult, confusing, and often expensive choices. In this CyberWire special edition, we explore how businesses are navigating the process of choosing products and technologies in a crowded marketplace. We talk to some key stakeholders to find out what drives their purchasing decisions, and what they wished their vendors knew before they came knocking on their doors.

Extract Knowledge
Published 2016-12-29

Best of: Tom Coale

17 min
View

Our podcast team is taking a break this week for the holidays. We’re revisiting some of our favorite interviews from 2016.  
 
Tom Coale is an attorney with the law firm Talkin and Oh, in Maryland, where one of his specialties is representing people who have been denied security clearances. Previously, Mr. Coale was Department Counsel for the Department of Defense, representing the government in security clearance due process hearings. We spoke to Tom Coale back in July. 

Extract Knowledge
Published 2016-12-28

Best of: Tom Wingfield

17 min
View

Our podcast team is taking a break this week for the holidays. We’re revisiting some of our favorite interviews from 2016.  
 
Tom Wingfield is Professor of Cyberspace law at the National Defense University, and one of the authors of the Tallin manual, an academic study of how international law applies to cyber conflicts and cyber warfare. We interviewed Tom Wingfield back in October, on location at the 2016 ASUA meeting in Washington DC. 

Extract Knowledge
Published 2016-12-27

Best of: Abby Smith Rumsey

16 min
View

Our podcast team is taking a break this week for the holidays. We’re revisiting some of our favorite interviews from 2016.  
 
Back in May, we spoke with author and historian Abby Smith Rumsey about her latest book, “When We Are No More: How digital memory shapes our future.” The book explores human memory from pre-history to the present, from pictures painted on cave walls to the present, with all the world’s knowledge available in an instant on our mobile devices. 

Extract Knowledge

In today's podcast we hear more about how Fancy Bear has gone to war. Russia denies meddling with US elections. US retaliation for influence operations is still under consideration—some speculate that when it comes, it may be loud. Siemens patches its widely used HVAC controller. Post mortems on the Yahoo! breach continue (and draw attention to cybersecurity EFTs). FBI Special Agent Keith Mularski describes the takedown of the Avalanche botnet. Awais Rashid from Lancaster University on data exfiltration by APTs. And NIST releases its guide to cyber incident response and recovery.

Extract Knowledge

In today's podcast, we hear about ISIS attempts to inspire Christmas attacks. Ukraine is on the receiving end of Russian tactical cyber operations, and yes, it's Fancy Bear. Analysts mull the possibility of a Russo-American détente emerging from cyber conflict. Mirai continues to rope maverick devices into its bot-herd.  Virginia Tech's Hume Center's Dr. Charles Clancy explains mobile device encryption. Adnan Amjad from Deloitte describes creative ways of finding IT talent. And WordPress and Tumblr receive criminal attention.

Extract Knowledge

In today's podcast, we hear about Ukraine's investigation of Saturday's power outages around Kiev—speculation says it was either a demonstration or misdirection. German police track terrorists' spoor online. Pakistani hackers hit Google's Bangladesh domain, possibly for the lulz. (Speaking of the lulz, OurMine is back and messing with Twitter accounts.) Panasonic and IOActive disagree over reports of airline vulnerabilities. Verizon mulls its Yahoo! acquisition plans, post-breach. NIST is looking for some post-quantum standards. Google's Project Wycheproof gets good early reviews. Joe Carrigan from the Johns Hopkins University Information Security Institute discusses the utility of burner email addresses. Sam McLane from Arctic Wolf reviews your incident response plan. Wassenaar renegotiation goes on hold. And the ShadowBrokers offer a low, low price, for Equation Group code, if you act now. (But we say "pass.")

Extract Knowledge

In today's podcast, we discuss another possible cyber incident that hit Ukraine's power grid last Saturday. Flashpoint looks at the ShadowBrokers' alleged Equation Group code and sees a rogue insider behind the leak. WordPress sites are receiving a lot of brute-forcing attempts. New spam and other attack techniques are evading volumetric detection. Mirai is sniffing for new IoT bots, and Dave Larson from Corero Network Security tells us what to expect in 2017. Jonathan Katz from the University of Maryland outlines advances in fully homomorphic encryption. Russian crooks skim ad revenue with the Methbot scam. Wassenaar cyber arms control remains controversial. And informed speculation suggests the ShadowBrokers and Bocephus Cleetus are—da—effectively, the same people.

Extract Knowledge

In today's podcast, we hear about how the ShadowBrokers are stocking their discount rack with Equation Group bargains. Yahoo's data breach attracts regulatory, investor, and due diligence scrutiny. Yahoo's stolen data is also being offered for sale on the dark web. Multiple other data breaches come to light, and skids hit online games with DDoS attacks. Ben-Gurion University's Yisroel Mirsky describes vulnerabilities of the US 911 system. US investigation of Russian election influence operations continues, and the US says it's planning some sort of retaliation.

Extract Knowledge

In today's podcast we hear about "Rasputin," a cybercriminal selling US Election Assistance Commission credentials. US investigation of Russian influence operations continues, with promises of eventual retaliation (nose-thumbing from Moscow received in response). UK and EU officials worry about Russian meddling with 2017 elections. The Yahoo! breach sinks in—some call it the "Exxon Valdez" of cyberspace. New ransomware strains and growing ransomware sector, but help in the form of an international public-private partnership. Markus Rauschecker from the University of Maryland Center for Health and Homeland Security  discusses the National Cyber Incident Response Plan (NCIRP). We talk privacy and encryption policy Jacob Ginsberg from EchoWorx. with And we're closer to seeing robot drivers on the streets.

Extract Knowledge

In today's podcast, we hear about Yahoo's disclosure of a record-setting breach—over a billion customer accounts are affected. CyberWire editor John Petrik collects industry comments on the breach. Microsoft reports finding "FinFisher-like" spyware in the wild. US investigation of Russian election hacking continues. The case for and against Fancy Bear is being made by observers, but the Intelligence Community says it will keep its conclusions to itself until the investigation is complete. ThreatConnect describes "faketivism." And the ShadowBrokers are back, and their broken English hasn’t gotten more convincing. 

Extract Knowledge

In today's podcast, we learn that Ukraine says its Defense Ministry was hacked, probably by Russia. US investigations of apparent Russian influence operations during elections continue. Venezuela talks up cyber threats as contributing to its financial crises. Dr. Web reports a new Loki Trojan variant in the wild. BugSec and Cynet disclose Facebook Messenger flaw (now patched). Level 3's Dale Drew provides insights on nation state hackers. Omri Iluz from PerimeterX warns us about gift card fraud. Colonel's Club breached. And hacktivists go after Russian consular data.

Extract Knowledge

In today's podcast, we learn that SWIFT has warned member banks of ongoing attempts at fraudulent funds transfer. US investigation of Russian influence operations continues, with bipartisan support. German fears of Russian election hacking persist. Apple iOS, McAfee VirusScan Enterprise, and AirDroid get patches. Tor releases a browser with upgraded anonymity. Kevin Bocek from Venafi reminds us of the looming SHA-1 sunsetting. Ben Yelin from the University of Maryland Center for Health and Homeland Security examines a case involving stingray devices and warrantless searches. And some guy steals a million so he can spend it on in-game purchases.

Extract Knowledge

In today's podcast, we hear about how an international police action swept up youths shopping for DDoS tools. Russian banks sustain a mild, easily parried DDoS attack. Mirai gets trickier. US-CERT warns against vulnerabilities in home routers. Popcorn Time ransomware says it's doing good by doing bad, but few will be deceived. US opens an investigation after the Intelligence Community concludes that Russian services tried to throw the US election away from Clinton and toward Trump. Emily Wilson from Terbium labs describes the markets for drugs and pharmaceuticals on the dark web. And North Korea says they didn't do it, you tantrum-throwing conservative puppet regime, you.

Extract Knowledge

In today's podcast, South Korea braces for the North to take cyber advantage of a constitutional crisis, but so far all's quiet. (Or most is quiet, anyway.) Germany takes official notice that Fancy Bear is working to disrupt next year's elections. The US state of Georgia thinks DHS may have tried to penetrate its election system post-election, and it wants to know what's up. ISIS is back online, and calling for attacks against Americans and Shiites. A phishing campaign trolls customer service reps with fileless malware. Experts expect more Mirai-driven DDoS. Rick Howard from Palo Alto Networks tells about the Cybersecurity Canon. Caleb Barlow from IBM Security explains the importance of a well practiced resiliency plan.  And the Avalanche criminal kingpin is on the lam after being sprung from a Ukrainian jail.

Extract Knowledge

In today's podcast, we hear about an industrial espionage campaign against Germany's steel industry. Turkish hacktivists' Sledgehammer gamifies DDoS (and installs backdoors in its gamers). The Floki Bot Trojan is a cheap and evasive addition to the Zeus family. Dridex is back. GPS gets a cybersecurity upgrade. Too many people are still using Windows XP. Joe Carrigan from the Johns Hopkins University Information Security Institute reports back from the Grace Hopper conference. ZScaler's Deepen Desai describes the Stampado strain of ransomware. NSA is said to be struggling to compete with the private sector for cyber talent.

Extract Knowledge

In today's podcast, we hear that more network security cameras have been found vulnerable to bot-herding. Sony's are patched, so patch. Unpatched Flash bugs incorporated into exploit kits. New ransomware strains are out. Russia announces a new national Internet strategy as Canada and the EU grapple with the complexity and ambivalence of controlling extremist content. Steganography is back, alas, and in your banner ads. Dr. Charles Clancy from VA Tech’s Hume Center explains the challenges of developing security solutions that can function in both the federal and commercial realms. Ebba Blitz from Alertsec hasthe results of a survey on what Americans fear most when it comes to cyber security. And Tay's kid sister Zo makes her debut.

Extract Knowledge

In today's podcast, we hear that more state-directed hacking is in the forecast for 2017 (and Pyongyang seems to have a head start). A new DDoS botnet rivals Mirai. Ransomware notes. Android users are advised to stick with Google Play (and so avoid Gooligan). Content filtering in social media. Cris Thomas from Tenable talks about their cybersecurity report card. Awais Rashid from Lancaster University outlines critical national infrastructure. And more connected toys seems to be far too curious about those who play with them.

Extract Knowledge

In today's podcast, we hear what the US Presidential Commission on Cybersecurity recommended in its long-anticipated report. Russia's FSB says today's the day foreign intelligence services are going to try to disrupt the Russian financial system. Ransomware author Pornpoker gets collared. Distributed guessing attacks might have been made against Tesco. Gooligan's business model is mostly advertising and garbage apps. Markus Rauschecker from University of MD's Center for Health and Homeland Security ponders IoT liability. Tenable's Global Cybersecurity Assurance Report Card tells the globe it's got room for improvement.

Extract Knowledge

In today's podcast, we hear about an international take down of the Avalanche cybercrime ring. (Bravo, FBI…and others.) A vulnerability in AirDroid is reported—you can find the app in the Google Play Store. Russia says there's a plot afoot to hack its banks and spread financial panic. US Senators tell the White House they want to know more about Russian attempts to influence US elections. This week has seen more Mirai DDoS, a resurgence of Shamoon, and another round of WikiLeaks doxing. There are also changes to NISPOM and Rule 41 in the US, and Ben Yelin from the University of Maryland Center for Health and Homeland Security fills us in on that. Denim Group's John Dickson helps us understand what we might expect from the coming Trump presidency. In the UK the Snooper's Charter received Royal assent. And what do pacemakers and e-cigarettes have in common? Malware.

Extract Knowledge

In today's podcast, we learn that Shamoon is back, again probably from Iran, and again hitting Saudi targets. Mirai infestations are turning up in the UK; observers see a criminal race to round up the biggest bot herd. Fancy Bear is also back, and still pawing at WADA. Good backup practices enabled San Francisco's Muni light rail to recover from ransomware. Palo Alto warns of a new Android Trojan. Facebook says there's no way ransomware was hidden in Messenger images. Firefox patches the zero-day that threatens Tor anonymity. Professor Jonathan Katz from the University of Maryland explains why ransomware crypto is hard, and Group iB's Dmitry Volkov describes ATM jacking group Colbalt.  Germany mulls going for more surveillance, less privacy, as investigations of ISIS operations continue.

Extract Knowledge

In today's podcast, we hear about Deutsche Telekom's recovery from DDoS, and why there's probably a lot more Mirai where that came from. Omri Iluz from PerimeterX gives us the background on botnets. Germany arrests an alleged mole in the BfV. ISIS claims the Ohio State attacker as its "soldier." The Snooper's Charter becomes law in the UK. San Francisco's Muni hangs tough on ransomware. A new Android malware strain is out in the wild. We welcome Awais Rashid from Lancaster University to the show. And Ross Ulbricht's defense team say they've found a third crooked cop in the Silk Road case.

Extract Knowledge

In today's podcast, we hear about how ISIS sympathizers are celebrating the Ohio State slasher rampage in social media. Germany's BND warns of Russian plans to disrupt elections. Deutsche Telekom recovers from a Mirai-driven DDoS attack. San Francisco's light rail recovers from ransomware (and resumes collecting fares). Holiday retail cyber security trends. A look into the dark web. Continuing security troubles for former and prospective US Secretaries of State. Level 3's Dale Drew takes a look at critical infrastructure. The Carter Administration gets doxed, and xHamster is breached.

Extract Knowledge

In today's podcast, we hear about how military, law enforcement cooperation are taking a toll of ISIS cyber operators. President Obama says the US elections weren't affected by hackers. DDoS in Brussels and Ireland remain under investigation. A Mirai botnet is available for rent on the cyber black market. ATM skimmers threaten holiday users—and the new inset skimmers are tough to detect. Ransomware hits San Francisco light rail (so the Muni lets passengers ride free). Booz Allen's Brad Medairy walks us through the Ukraine grid hack. Emily Wilson from Terbium Labs describes how they celebrate the holidays in the Dark Web. And no, Anthony Bourdain's foodie show wasn't hacked to get banned in Boston

Extract Knowledge

In  today's podcast, we hear about how ISIS is making its way, quietly, back into the cyber news (and how the Australian Signals Directorate is on the case). The Broadband Internet Technology Advisory Group wants the IoT industry to face some unpleasant facts, and the security industry calls for standards. Europol finishes its second sweep of money mules. ATM jackpotting spreads in Europe and Asia. India suffers a wave of carding. Joe Carrigan from the Johns Hopkins University Information Security Institute reports back from the NICE Conference. BBC Journalist and Author Gordon Corera is our guest, discussing his latest book, "Cyber Spies - The secret history of surveillance, hacking and digital espionage." And security experts warn us all to be cyber savvy on Black Friday.

Extract Knowledge

In today's podcast we hear about the FBI's warning that cash-spewing ATMs could be coming to a strip mall near you, courtesy of the Russian mob. Bad news and good news about ransomware. Another Android backdoor is reported. Exploitable security cameras get a patch. The Conficker worm's still crazy after all these years. Lessons for users from the Three Mobile hack. Biometrics meets the Wind in the Willows? (Fujitsu Biometrics' Derek Northrope provides a reality check.) Palo Alto's Rick Howard discusses the disconnect between the board room and the tech crew. China's new Internet law. And what have Fancy and Cozy Bear been up to? Hibernating?

Extract Knowledge

In today's podcast, we talk about thinking twice before opening pictures received via Facebook Messenger. A recruiting site exposes GitHub profiles. Investigation of credential abuse in the Three Mobile upgrade fraud continues. Fortinet warns German users against an Android banking Trojan. Much advice on how to stay safe online during holiday shopping is out. Symantec plans to buy LifeLock, and Optiv is filing an IPO. President Obama says, while in Berlin, that he won't pardon Snowden. Rumors of DNI and SecDef discontent with Director NSA circulate. Markus Rauschecker from the University of MD Center for Health and Homeland Security reviews new automotive security guidelines from the feds. And no, Chinese cabinet ministers don't have a side gig recruiting for the Canadian Forces.

Extract Knowledge

In today's podcast, we hear about US DNI Clapper's long-expected resignation and his contention that attributing election hacking to Russia seems to have induced Moscow to "curtail" such operations. The UK arrests suspects in an upgrade fraud scheme suffered by Three Mobile and its customers. Updates on Android spyware and banking Trojans. Siri might be helping bypass your iPhone's lockscreen. There's good and bad news about ransomware, but, happily, more good than bad. A quick review of the week's industry news, with an emphasis on cyber security start-ups. Dr. Charles Clancy from Virginia Tech's Hume Center outlines Virginia's new Cyber Security Range initiative. Sara Sorcher from the Christian Science Monitor's Passcode provides an overview of what we might expect from the Trump presidency. And, in China, wisdom sees a passing of the Mandate of Heaven in cyberspace. Or that's what wisdom's spokesmen are saying, anyway.

Extract Knowledge

In today's podcast, we hear about German concerns over Russian meddling in elections. In the US, the NSA Director says a nation-state made a conscious attempt to influence American elections. Dictators can use social media, too, it seems. Huawei and ZTE reassure customers about the Adups backdoor. Holiday shopping security warnings are out, and they're not just about online purchases, either—watch out for that in-store Wi-Fi. The UK's Snooper's Charter passes the House of Lords. Ran Yahalom from Ben Gurion University describes USB hardware attacks. John LaCour, CEO of Phishlabs provides advice on avoiding (wait for it…) phishing attacks. And a Russian court tells that country's ISPs to shut down LinkedIn—it's a concern about privacy, don't you know.

Extract Knowledge

In today's podcast, we hear about some lawful intercept tools that have been found prospecting Android. Synack calls shenanigans on Shazam, but maybe no harm, no foul. Carbanak turns from banks to hospitality. Insider threats and how to mitigate them—if you've got a facility clearance, you've got a deadline coming up, and Steven Grossman from Bay Dynamics explains what it means. Arlington Capital merges three of its companies into a new cyber shop, Polaris Alpha. Symantec is rumored to be sniffing at LifeLock. Cyber policy discussions in Germany and the US sound a lot alike. Jonathan Katz from the University of Maryland explains the pros and cons of photonic encryption. A teenager cops to the TalkTalk hack, and, if you're asking for a friend, the tally of accounts affected by the AdultFriendFinder breach hits 412 million.

Extract Knowledge

In today's podcast we hear about a backdoor Kryptowire has found preinstalled in some Android phones. We speak with Ryan Johnson, the researcher who discovered the vulnerability.  The Locky ransomware takes a run at US Army Cyber Command. CrySis ransomware is decrypted. SpamTorte 2.0 is out, and it's thinking big. A Trojan may be implicated in the Tesco fraud campaign, and it may have more banks in its crosshairs. Emily Wilson from Terbium Labs shares the findings of their latest report on the Dark Web, and Ping Identity's Pamela Dingle explains the Digital Transformation Journey. And watch out for the AdultFriendFinder-themed spam that will follow in the breach's wake.

Extract Knowledge
Show details
Episodes
3784
Transcripts
68
2% coverage
Missing transcripts
3716
With chapters
0