Search this show’s transcripts

CyberWire Daily

en us
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.

Episodes

Page 73 · 50 per page

In today's podcast we hear about a successful business email compromise caper, and some more SWIFT fraud. Vanya the RIPPER is on the lam from Thai police. iMessaging issues surface. Cerber ransomware is being spread by Word documents. Adobe's hot fix swats a Cold Fusion bug. Rowhammer attacks are shown to be a real possibility. Election hacking and influence operations. Centrify's Corey Williams weighs in on the Sage Software data breach, and Jonathan Katz from the University of Maryland explains an iMessage vulnerability. And a tip: if you look good for your mugshot, you won't be tempted to Facebook a more flattering one to the authorities.  

Extract Knowledge

In today's podcast we follow the story of alleged Russian hacking of US think tanks and election databases (allegations Russia dismisses as American provocation). US Federal and state officials think about securing November's vote. Mississippi organizes a new public-private cyber security coalition. SWIFT discloses new money transfer fraud attempts. New ransomware strains are out in the wild, and a Trojan is impersonating Google Chrome. Dr. Jim Kent from Nuix shares his thoughts on insider threats, and we welcome Yisroel Mirsky from Ben-Gurion University, our newest Academic and Research Partner. And, producers, rethink your B-roll: we take a look at the best stock picture of a hacker yet.

Extract Knowledge

Whether your bootstrapping your business on your own, borrowing from friends and family or going for your Series A venture capital round, raising money is something most business owners have to deal with, sooner or later. We spoke with experienced business leaders in cyber security to find out what they did to fund their companies, lessons they learned, and what advice they’d give.

Extract Knowledge

In today's podcast we follow concerns about US election hacking brought on by an FBI warning that someone (the Russians, IC and industry sources say) has hacked into Illinois and Arizona voter databases. Lawful intercept vendors receive more scrutiny in the wake of the Trident iPhone zero-day revelations. Analysts raise concerns about data manipulation in both elections and criminal investigations. St. Jude Medical disputes allegations that its pacemakers are hackable, and the security sector does some ethical introspection about disclosure. The IoT is beginning to exploited in DDoS campaigns. Malicious EMV cards are implicated in Thailand's ATM skimming crime wave. University of Maryland CHHS' Ben Yelin weighs in on the legal issues surrounding the Muddy Waters Capital story, and Security Mentor's Dan Lohrmann explains sophisticated attacks on the C-Suite. And Angry Birds join Pokémon on various enterprise blacklists.

Extract Knowledge

In today's podcast, we update the story on SCADA malware in Iran—Iran now thinks it didn't cause petrochemical industry fires. France, India, and Australia investigate theft of submarine design data. Citizen Labs' investigation of iOS spyware renews debate over cyber arms control. The Shadow Brokers haven't yet got their half-billion dollars, but their leaks chill US-Russian relations and prompt both election fears and concerns over zero-day disclosure. The US prepares to revise its anti-ISIS social media operations. Security firm MedSec discloses alleged St. Jude medical device vulnerabilities to a hedge fund, seeking to profit from short-selling. Markus Rauschecker from the University of Maryland Center for Health and Homeland Security gives us the details on PPD 41 from the White House. Fishing and hunting license databases exposed.

Extract Knowledge

In today's podcast, we hear about a spyware case connected to Pegasus, a tool that can jailbreak an iPhone (they say) with a single click. Apple issues an out-of-band patch for the three iOS zero-days Pegasus exploits. Shadow Brokers leaks remain under investigation. Phishlabs and TrapX release anti-ransomware tools. Ramnit and Dreambot are after bank accounts (and Dreambot spreads over Tor). NIST has a de-identification standard out for comment. AT&T's Bindu Sundaresan looks at academic networks as students head back to school. Johns Hopkins' Joe Carrigan discusses option for safely backing up your photos. Industry news includes some interesting short-selling. And Russia isn't feeling the love in cyberspace. 

Extract Knowledge

In today's podcast, we look at ways in which terrorist incidents have motivated France and Germany to seek ways of compelling encrypted messaging apps to open traffic to inspection. In the UK such incidents have also prompted a harsh Parliamentary report on social media companies' efforts to combat radicalization. Shadow Brokers leaked exploits continue to appear in the wild. Investigation continues, but observers begin to see the incident as part of a general attack on US official credibility. Assange promises more leaks of Clinton material. Ransomware appears in India and Vietnam. A new Android banking Trojan uses Twitter for command-and-control. Dale Drew from Level 3 Communications shares tips on setting up a SOC, and Ralph Cita explains how they make free training available at Cybrary. And Ashley Madison gets bad reports in three of the Five Eyes.

Extract Knowledge

In today's podcast we hear about Russian hackers going after New York Times reporters (the FBI is investigating). Exploits in the Shadow Brokers' teaser are "test-driven" in the wild. Some of them may affect Huawei products. The Goznym banking Trojan moves from Poland to Germany. British universities are targeted by ransomware. Researchers give victims of Wildfire ransomware some relief in the form of a decryptor. Gaming sites come under attack. We've all heard of the cloud, but Accenture's Malek Ben Salem tells about the coming fog. There's a new push to restrict encryption in the EU. And a fourth-grade steely-eyed missileman arises in Texas.

Extract Knowledge

In today's podcast we discuss the Shadow Brokers' leaks, reviewing ongoing speculation and speaking with some experts who offer insight into the matter: Jason Healey, the principal investigator in Columbia University's study of NSA zero-day disclosure policy, and RedSeal's CEO and CTO discuss firewall security and vulnerability. Juniper joins Cisco and Fortinet in confirming that Shadow Brokers' zero-days affect its products. IoT encryption R&D updates. Security start-ups attract more investment. And some thoughts on what not to say to your VC.

Extract Knowledge

In today's podcast we continue to follow the Shadow Brokers, and we take a quick look into the shadowy world of hybrid warfare. No fresh leaks in this incident, but someone seems to be using seized Silk Road Bitcoin wallets to bid on leaked files. Election hacking worries persist, and concerns about secret ballots appear. Some users want a general strike against Tor. Point-of-sale malware and what to do about it. Industry notes. A new Wassenaar round will revisit cyber arms control next month. John Leiseboer from QuintessenseLabs addresses data redundancy and replication, and Michael Marriott from Digital Shadows tells us about the shady deer.io online market.

Extract Knowledge

In today's podcast, we hear about emails flooding dot gov in-boxes. A re-tooled version of Locky ransomware is out in the wild. As we look back at the week, the big news surrounds the Shadow Brokers' data dump and implausible auction—they seem to have some genuine NSA goods. The brokers themselves are thought to be either Russian spies or rogue insiders, or some mix of both. Worries about US election hacking rise. More companies are concerned about insider threats. The University of Maryland's Jonathan Katz explains how to reverse engineer encryption, and Chris Fogle from Delta Risk tells us how board members can prepare for cyber challenges. And, yes, there's another Pokémon-GO hack.

Extract Knowledge

In today's podcast we hear more about the Shadow Brokers, who are confirmed to have dropped some genuine zero-days. Most observers now think there was a compromise at NSA; some suspect Russian intelligence services. North Korea is again scrutinized for SWIFT fraud. Operation Ghoul targets industrial intellectual property in thirty countries. We see continued industry churn (including some layoffs as well as M&A rumors). CrowdStrike's Adam Meyers tells us about the Boson Spider gang, and Ben Yelin from the University of Maryland Center for Health and Homeland Security weighs in on the Shadow Brokers.

Extract Knowledge

In today's podcast we follow the continuing story of the Shadow Brokers and their claims of having got their hands on Equation Group attack code (as bizarre as their story is, a lot of informed observers think the code they've posted is the real deal). Many see the Shadow Brokers incident as an escalation of a cyber cold war between Russia and the United States. More banking Trojan activity in South America. DNSSEC is exploited in DDoS attacks, and Cerber is still number one in the ransomware-as-a-service market (where Shark is a dodgy upstart). Kensington's Rob Humphrey shares the results of their recently security survey, and Johns Hopkins University's Joe Carrigan weighs in on securing your devices in the real world.  And yes, more Pokémon stuff.

Extract Knowledge

In today's podcast we learn about claims made by hackers calling themselves "the Shadow Brokers." They say they've pwned the Equation Group, and obtained NSA attack code which they're now selling for one million Bitcoin. Guccifer 2.0 gets a lot more polished and even leakier. A bogus QuadRooter patch is serving malware in Google's Play Store. Fidelis tells us about Vawtrak's evolution. Someone's watching the Veracrypt audit. Iran looks into possible cyber causes of oil-and-gas facility fires. Fake Pokémon installers have trainers choosing ransomware. No more Pokéstops allowed in Germany's Flughafen. Vikram Sharma from Quintessence Labs outlines the challenges and opportunities of combining cutting edge science with market realities. Hardik Modi from Fidelis Cybersecurity expains changes they're tracking in the Vawtrak banking trojan. And British lawyers get a license to hunt hackers. 

Extract Knowledge

In today's podcast we learn that Russian hackers went after Republicans as well as Democrats. An anti-doping whistleblower's account is illegally compromised. ISIS turns to online inspiration to recover jihadist mindshare. The MICROS point-of-sale system hack appears to underlie widespread credit card compromises. Secure Boot's "golden key" exposure is seen as a warning against backdoors. Security industry M &A and IPO notes. Level 3 Communications' Dale Drew tells us about machine-to-machine learning, and how it may improve security. And for some reason researchers develop a proof-of-concept for a DDoS-based cryptocurrency.

Extract Knowledge

In today's podcast we learn that the US Intelligence Community discovered the DNC hack sometime last year—much earlier than its public disclosure this Spring. We hear about threats to critical infrastructure, and we follow developments in the cyber criminal markets—ransomware's getting mighty picky, if you ask us. We hear about ISIS's appeal to disaffected petty criminals. The Olympics see both cybercrime and patriotic hacktivism. Quintessence Labs' John Leiseboer discusses redundancy and replication of data, and we interview Robert M. Lee from Dragos Security about ICS SCADA security, and preparing for cyber security jobs. And, of course, we hear more about how Pokémon-GO is driving security people quite nuts.

Extract Knowledge

In today's podcast, we hear about cyber and information operations in Eastern Europe that look disturbingly like battlespace preparation. The FBI finds that the scope of the Democratic Party hacks is much greater than initially believed. The Bureau seems ready to ask for more authority to unlock devices, but opponents point to Microsoft's inadvertent leak of Secure Boot keys as an object lesson in why that's a bad idea. USENIX proofs-of-concept include Linux and car-hacking exploits. Samsung Pay is criticized as vulnerable to token skimming. Senior Law Analyst Ben Yelin outlines the FBI's request to expand the reach of National Security Letters. Deputy Director Rick Lipsey explains the mission of the ISAO Standards Organization. New ransomware features disappearing extortion emails. And how do you solve a problem like Pokémon-GO?

Extract Knowledge

In today’s podcast we follow developments in nation-state hacking, from Hainan to Tehran. Australia’s online census is taken offline—the Bureau of Statistics cries DDoS, but observers aren’t so sure. A new strain of ransomware under development in the underworld skips encryption and goes straight for deletion. Issues with Oracle’s MICROS point-of-sale systems may be the root cause of recent store and hotel breaches. Google says, thanks Check Point, we appreciate it, but most of QuadRooter has already been mitigated (they’re working on the rest of it). Joe Carrigan from Johns Hopkins University warns us about side-loading Android apps, and Leemon Baird from Swirld describes a new trust-based peer to peer software platform. And we note that yesterday was Patch Tuesday.

Extract Knowledge

In today’s podcast we look at an APT group that’s been active since 2011. We hear about the Quadrooter Android vulnerability. We take a look back at Black Hat, and look for some sensible perspective on cyber risk. We also read some discussion of the differences between espionage, crime, and warfare. The US Marshalls will auction SilkRoad’s forfeited Bitcoin later this month. Dr. Charles Clancy from Virginia Tech's Hume Center tell us what to expect from 5G cellular technology. And yes, there’s more Pokémon-themed malware in the Play Store.

Extract Knowledge

In today’s podcast we hear about Bifinex’s recovery from its recent heist and the possibly temporary haircut its depositors got. We also follow the related Ethereum hard fork. News on Olympic hacks and risks of hacking from Booz Allen Hamilton's Brad Medairy and Grey Burkhart. Trustwave reports home smart thermostat bugs. Checkpoint discloses Qualcomm Android Quadrooter firmware vulnerabilities. More signs that Fancy Bear was prancing through the DNC. A look back at Black Hat, and notes on DARPA’s AI capture-the-flag challenge. Jonathan Katz explains the Etherium fork.

Extract Knowledge

In today’s podcast we look at Black Hat and draw some consensus advice for start-ups. Cyber espionage rises around the South China Sea. Apparent Russian hacking continues to worry election officials and voters in the US. The HEIST exploit is demonstrated. ISIS jockeys with al Qaeda, Boko Haram factions for jihad leadership. Brazil works on cybercrime as the Olympics open tonight. Apple announces a bug bounty. Cyber companies are said to be preparing layoffs. Accenture Technology Labs' Malek Ben Salem explains software based networking. Galina Datskovsky from Vaporstream outlines the security concerns with voice activated devices.  And companies work to keep Pokemon out of places they shouldn’t go.

Extract Knowledge

In today’s podcast, we get some updates from Black Hat. DNC hacks raise questions about US voting security, and Democratic Senators call for hearings on Donald Trump’s request that Russia find the 30,000 emails deleted from Hillary Clinton’s State-Department-era homebrew server. China seems to be probing Philippine networks in conjunction with the dispute over territorial waters in the South China SeaMore signs that Telegram is leaky. Updates on ISIS and its competitors’ information operations. The Gozi banking Trojan is headed for US targets. Bitfinex is looted of tens of millions in Bitcoin. The Real Deal criminal market’s boss is missing. Vikram Sharma from Quintessence Labs shares lessons learned about entrepreneurial course correction. 

Extract Knowledge

In today’s podcast we follow the latest fallout from the DNC hacks (Russia’s still the prime suspect). Fears of election hacking rise in the US. Government electronic surveillance rises worldwide, driven in part by increasing fear of jihadist terrorism. ISIS unit “Emni” is said to have broad responsibility for recruiting and organizing terror cells. Android security upgrades from Johns Hopkins University expert Joe Carrigan. TripWire's Dwayne Melancon explains spearphishing. A quick look over at Black Hat USA. And some observers think Pokemon-GO is a mind control tool. (We don’t, except insofar as any popular mania amounts to mind-control.)

Extract Knowledge

In today’s podcast we give a short update on Black Hat before turning to developments in Syria and Iran. Tension between the US and Russia mounts over alleged Russian hacks of US political campaign networks and more recently alleged US spyware operations in Russian enterprises. ISIS wishes to disrupt the Olympics, and cybercriminals are seeking to profit from the Rio Games. Adware uses steganography, and INTERPOL takes down a Nigerian online scam. Ben Yelin explains a recent court ruling in Microsoft's favor that deals with offshore data privacy, and Sameer Dixit from Spirent outlines emerging threats patterns. 

Extract Knowledge

In today’s podcast we hear about Russian reports of an APT active against military, scientific, defense, and government networks. US investigations into the hacks of the DNC, DCCC, and Clinton campaign continue, with suspicion still directed at Russia. ISIS calls online for an extension of jihad to Russia. The SpyNote Android Trojan is out in the criminal underground. Researchers report vulnerabilities associated with WhatsApp and SwiftKey. And we share some security advice from Level 3's Dale Drew for those attending Black Hat.

Extract Knowledge

In today’s podcast we hear some preliminary news about ISIS information operations as expressed in captured files. Hacktivists experience remorse and debate doxing ethics. We review the speculation about the DNC hack and note that another Democratic Party campaign organization may also have been compromised. State-sponsored hacking is driving enterprises to seek help from security companies. The University of Maryland's Jonathan Katz tells us about post-quantum encryption, and  Daniel Ennis, former NTOC Director at NSA and currently Executive Director of the University of Maryland Global initiative on Cyber, shares his thoughts on his time with the agency, and the need for cooperation in cybersecurity by government, universities, and industry. Pokémon trainers are still going where they shouldn’t.

Extract Knowledge

In today’s podcast we hear about how ISIS continues to pursue its strategy of using information operations to inspire lone wolves, and what investigators in France, Germany, and the United States are seeing as they look at jihadist social media. We learn about advances in facial recognition software. WikiLeaks releases audio files culled from DNC email hacks. More releases are expected, and evidence continues to point (circumstantially but substantially) toward Russian services as the hackers. Trump suggests Russian intelligence would do everyone a favor if it releases the 30,000 deleted Clinton emails many think the Russians have. Gigamon's Shezad Merchant tells us all about metadata, and Marcus Rauschecker explains the privacy implications of facial recognition software. We take a stroll through the crimeware souk (just looking, thanks).

Extract Knowledge

In today’s podcast we discuss ISIS terror and online inspiration. We learn that experts are reaching consensus that Russia hacked the US Democratic National Committee, and we hear some steps that might be taken to protect email. We speak with the company that provided cyber security for the Republican National Convention. New vulnerabilities are discovered in wireless keyboards and smart lightbulbs. Ransomware persists, and the numner of DDoS attacks seems to be spiking, recently. The White House issues PPD-41, “Cyber Incident Coordination.” Level 3's Dale Drew speaks to the uptick in DDoS attacks, and Vince Crisler from Dark Cubed shares his experiences protection the RNC national convention from cyber threats.  And people are still catching Pokémon in places they shouldn’t.

Extract Knowledge

In today’s podcast we catch up on the big story in cyberspace—the expanding scope of the Democratic National Committee email hack. Most observers continue to see a Russian hand behind it, but some point out that the evidence remains circumstantial. Experts see the hack as a cautionary tale in the importance of authentication and encryption. Stu Sjouwerman is the founder and CEO of KnowBe4, and he provides his take on the possible Russian hack. ISIS continues its attempts online to inspire lone-wolf jihadists. A young cyber start-up emerges from stealth, and we get an update on cybersecurity in the automobile industry from CyberWire editor John Petrik.

Extract Knowledge

In today’s podcast we take a look at the doxing of the DNC, a story which will have, as they say, “legs,” if only because essentially everyone now sees Russian intelligence behind the hack. ISIS and al Qaeda continue their competition to inspire lone-wolf jihad. Turkey’s crackdown on would-be putschists continues. Anonymous goes after targets in Turkey. Cyber M&A notes. Dr. Charles Clancy from the Hume Center at Virginia Tech tells us about the challenges and opportunities coming with Smart Cities. And a look back at Friday’s inaugural Billington Global Automotive Cybersecurity Summit.

Extract Knowledge

In today's podcast, Hacktivists return to DDoS—the Library of Congress is hit. AKP emails continue to receive scrutiny. A look at the jihadists' toolbox. Some quick takes on automotive cyber security, as the industry moves toward fully autonomous cars. Wassenaar and the DCMA still aren't getting much industry love. And we talk to attorney Tom Coale about security clearances and Ben Yelin on the constitutionality of Stingrays.

Extract Knowledge

In today’s podcast, we hear about patched vulnerabilities in widely used products—the consensus among experts is that you should patch without delay. A new ransomware variant—“HolyCrypt”-is discovered in development. OurMine hacks the Playstation boss’s Twitter account. Hackers get ready to go after US Presidential campaigns (and some have already started). ISIS information ops continue to concentrate on recruiting and inspiration. Pokemon-GO is too Darwinian for some. The University of Maryland's Jonathan Katz describes a TOR alternative.

Extract Knowledge

In today’s podcast we review some of the cyber implications and sequelae of the apparent failed coup d’état in Turkey. Signs in the Shumukh al Islam leaks suggest ISIS is making inroads among China’s Uighur minority. A Brazilian jihadist group pledges allegiance to ISIS online, adding to Brazil’s cybersecurity (and more importantly, physical security) concerns for the Rio Olympics. enSilo reports widespread code-hooking issues in security software. A look at ransomware, and an actual sockpuppet surfaces in Canada. Morphisec's Ronen Yehoshua describes a technique they call moving target defense, and Markus Raushecker shares his take on the sentencing of a swatter who targeted Brian Krebs.

Extract Knowledge

In today’s podcast we hear about the doxing of a major ISIS forum, and we take a look at the state of play with respect to online information operations in the war with ISIS. We ask whether jihad and kawaii offer contrasting case studies of inspiration. In Turkey, did coup plotters (who might have known better) overlook the Internet? DDoS campaigns rise against governments, companies, and games. A researcher shows how 2FA and account recovery capabilities can be subverted for fraud.  Malicious Excel macros are out in the wild. So are the Cknife web shell, as described to us by Recorded Future's Levi Gundert, and the venerable Enfal malware family. Joe Carrigan reminds us why we she be using two-factor authentication. We look at some recent venture investments.

Extract Knowledge
Published 2016-07-19

Quantifying Cyber Risk [Special Editions]

31 min
View

Cyber security comes down to risk management, and it’s hard to manage what can’t be measured. How can cyber risk be credibly quantified and communicated? We’ll talk to companies developing technology solutions aimed at quantifying cyber risk and hear from insurance experts and other industry stakeholders grappling with this important new challenge facing businesses today.

Extract Knowledge

In today’s podcast, we hear about social media’s role in the suppression of the coup d’ état in Turkey. The United Cyber Caliphate and the competing “Peace Brigades” release overlapping and competing target lists. Ukrainian nationalist hacktivists hit Poland’s Ministry of Defense. “Delilah” is a backdoor Trojan built for blackmail, and “Wildfire” is a new strain of ransomware. Some databases for sale on the Dark Web look like junk. Deloitte's Emily Mossberg shares insights from their latest  report, and John Leiseboer from Quintessence Labs explains the security benefits of interoperability. Pokémon Go looks like the biggest mania since the 17th Century’s tulip craze.

Extract Knowledge

In today’s podcast we hear about ISIS and its response to pressure from its enemies—the news is decidedly mixed, especially given the tragedy in France. Familiar banking Trojans, exploit kits, and ransomware pick up some new functionality. Someone’s jackpotting ATMs in Taiwan. SAP and Cisco patch. US court rulings have privacy and liability implications. Venture capital investments and M&A news. Ben Yelin tells us about a 4th Amendment case involving privacy on your home computer, and Eli Sugarman from the Hewlett Foundation's Cyber Initiative shares their grant making story. And Pokemon-Go continues its irresistible rise—don’t slip into any augmented reality pitfalls.

Extract Knowledge

In today's podcast we hear about some expansive court decisions that may make you uneasy. Chinese spies get into the FDIC, and the victim may have covered it up. Start-ups attract fresh investment. New exploit kits jockey for position. Securing your Bitcoin wallet. What to make of Pokemon's security issues. Dale Drew from Level 3 Communications gives us the low-down on some cyber security lingo, and Darin Stanchfield from KeepKey explains options for securing your Bitcoin. And, in California, an alleged violation of Asimov's First Law of Robotics.

Extract Knowledge

In today's podcast we go over some of the highlights of this week's patches, including fixes from Microsoft, Abode, Drupal, and Niantic. We discuss the security of the industrial Internet-of-things and critical infrastructure, especially the power grid. We hear about the current state of ransomware play, and note the return of xDedic, the hacker server hawker, to the dark web souk. Industry news includes coming cyber upgrades to SWIFT, VC updates, and notes on the markets. The University of Maryland's Jonathan Katz tells us about "fansmitters", and Booz Allen's Scott Stables shares threat data from their latest ICS report. 

Extract Knowledge

In today's podcast we hear some reports that ISIS may be losing some social media ground. NATO agrees to increase cyber cooperation. A newly described malware dropper is apparently tailored to work against specific European energy companies. 600,000 patient records are breached in the US. There's a decryptor out for Jigsaw ransomware, but not for the newly introduced "Alfa" or "Ranscam" (and Ranscam doesn't even bother to decrypt in the first place). Markus Rauschecker highlights some of the challenges with information sharing. Google and Niantic deal with Pokémon Go security issues. And don't enter some strangers' home, even if you see Reshirom EX on their sofa.

Extract Knowledge

In today's podcast we hear about possible hacks of NATO websites during last week's Alliance meetings. South Asia's scissors-and-paste cyber espionage campaign is surprisingly effective. ISIS and al Qaeda vie for jihadist mindshare, and Anonymous hits government sites in Zimbabwe and South Africa. A hacker/hacktivist dumps what he claims to be Kindle credentials, but analysts are dubious about their provenance. Eleanor Mac malware targets webcams. State Department emails remain under investigation. Chris Gerritz from Infocyte tells us about threat hunting, and Charles Clancy from the Hume Center at Virginia Tech shares concerns about data privacy. Plus, Pokémon Go seems to be catching 'em all—Ash Ketcham, call your office.

Extract Knowledge

In today’s podcast, we talk through the ramifications of Android encryption issues. Experts consider the implications of D-Link vulnerabilities for IoT security. The Wendy’s paycard breach has gotten much bigger. Familiar exploits circulate in the wild, and Mac backdoors make a comeback. CryptXXX is joined by a new ransomware variant, Cryptobit, and DedCryptor continues to play the Grinch. Avast’s purchase of AVG encourages the markets. The EU adopts new data regulations aimed at improving resilience. The FBI explains what it found in its investigation of Hillary Clinton’s emails, and defense attorneys find new lines of defense. Accenture's Malek Ben Salem shares how big data can help wth analytics, and we learn about early-stage startup accelerators from Mach 37's Bob Stratton.

Extract Knowledge

In today's podcast we hear about Cymmetria's discovery of a major threat actor in South Asia, Patchwork, which assembles attack code by cutting and pasting from the Internet. HummingBad adware infests Android, and Pirrit (affecting Macs) is attributed to a marketer. D-Link routers may be vulnerable to remote-code execution. Google patches more than 100 Android issues. Symantec works on AV product problems. Avast buys AVG. Blockchain's potential. Cyber workforce development. FBI offers explanations to the House. Cyber crooks go after freelancers. Jonathan Katz explains the many uses for blockchain crypto technology, and Chris Key from Verodin has some advice for those entering the cybersecurity workforce.

Extract Knowledge

In today's podcast we hear about Yingmob's HummingBad Android malware, what it's up to and where it might be headed. We also learn about Eleanor, a Mac OS-X backdoor masquerading as a document conversion app, and we hear about the shifting form of the pseudo-DarkLeech ransomware campaign. The ThinkPwn zero-day may have a wider scope than originally thought. Observers wonder whether ISIS may be overplaying its bloody hand, and, of course, we find out what the FBI concluded in its investigation of former Secretary of State Clinton's emails. Joe Carrigan, from the Johns Hopkins University Information Security Institute, reminds us to take care when setting up a new router.

Extract Knowledge

In today's podcast we look at ISIS's shifting tactics in cyberspace, and the civilized world's response to them. OurMine continues to market its "services" by compromising celebrity accounts through recycled credentials. Two new ransomware varieties--"Satana" and "Zepto"--make their appearance, and researchers track (without attribution) the spoor of MNKit and SBDH malware. A researcher releases, without prior disclosure, a ThinkPad zero-day. The FBI investigation into State Department email issues warms up. Ben Yelin from the University of Maryland Center for Health and Homeland Security tells us about a Florida man in trouble for hacking an election site, and Michael Jacobs brings us the National Cybersecurity Hall of Fame.

Extract Knowledge

In today's podcast we discuss Internet-of-things threats, not only botnets assembled from compromised security cameras, but also medical device hacking (with Conficker) as a way of stealing patient information. More insurance sector breaches appear to be in progress, too. The Sprashivai social network is compromised. The Infy espionage infrastructure is taken down (but may return—they often do). NERC standards for power grid cyber security take effect today. John Leisebeor from Quintessence Labs explains key management within a security framework, and we learn about DevOps from Cybric's Mike Kail and eGlobalTech's Branko Primetica.

Extract Knowledge

In today's podcast we hear about DarkOverlord and the data he's selling online. Guccifer 2.0 returns to blogging, and says he's not working for the Russians, but CrowdStrike, ThreatConnect, and SecureWorks present evidence to suggest otherwise. Thompson-Reuters says it's contained the World-Check database leak. Oculus' Twitter account is briefly hijacked (now restored to company control). Point-of-sale breach disclosures are confirmed. Why hackers hack when they do. Some governments' efforts to control information online seem to be having greater than expected success. Level 3's Dale Drew explains the season nature of cyber attacks, and Cytegic's Dan Pastor offers his view on the recent SWIFT banking attacks.

Extract Knowledge

In today's podcast, we note that in the wake of the ISIS bombings in Istanbul, security services around the world are looking for online intelligence that might help prevent future terror attacks. Another wave of SWIFT fraud appears to have hit--this time the victims are banks in Ukraine and Russia. Ransomware updates (including the unwelcome return of Locky), notes on smishing, and a review of some questionable PlayStore apps. Apple's iPhone turns 9 and The University of Maryland's Jonathan Katz explains that company's move toward "differential privacy." Jon Allen from Booze Allen Hamilton talks about the Automotive ISAC and previews the upcoming Billington Cybersecurity Global Automotive Cybersecurity Summit. 

Extract Knowledge
Show details
Episodes
3784
Transcripts
68
2% coverage
Missing transcripts
3716
With chapters
0