Threat Wire by Hak5 is a weekly short format video show by Shannon Morse of Hak5 that covers the biggest news stories about what's threatening our privacy, security, and internet freedom. Stay up to date with #ThreatWire, every Tuesday.
The biggest hacks of 2021! All that coming up now on ThreatWire. Click for links and more info ⬇️⬇️⬇️ #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins, information security professionals, and consumers. Watch this on youtube (video may be “private” until the scheduled publish time): https://youtu.be/eSH5_Si3G94 Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Follow Shannon on Social Media: https://snubsie.com/links Links: https://www.youtube.com/watch?v=Qx-PHk2cgqM https://www.theverge.com/2021/10/6/22712365/twitch-data-leak-breach-security-confirmation-comments https://www.washingtonpost.com/video-games/2021/10/08/twitch-hack-leak-minimum-wage-pay-hasan/ https://www.youtube.com/watch?v=mdTnhUJFnno&t=285s https://news.linkedin.com/2021/april/an-update-from-linkedin https://threatpost.com/data-500m-linkedin-users-online/165329/ https://www.youtube.com/watch?v=QjLvIDWnc3w https://www.colpipe.com/news/press-releases/media-statement-colonial-pipeline-system-disruption https://www.bleepingcomputer.com/news/security/largest-us-pipeline-shuts-down-operations-after-ransomware-attack/ https://www.bloomberg.com/news/articles/2021-03-07/hackers-breach-thousands-of-microsoft-customers-around-the-world https://www.cnn.com/2021/06/01/business/jbs-cyberattack-meat-shortage/index.html https://www.bleepingcomputer.com/news/security/computer-giant-acer-hit-by-50-million-ransomware-attack/ https://www.youtube.com/watch?v=ysFB6JKTs5U https://www.ncsc.gov.uk/information/log4j-vulnerability-what-everyone-needs-to-know https://www.zdnet.com/article/apache-releases-new-2-17-0-patch-for-log4j-to-solve-denial-of-service-vulnerability/ https://www.zdnet.com/article/belgian-defense-ministry-confirms-cyberattack-through-log4j-exploitation/ Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005: -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ ____________________________________________ Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.
Log4Shell & Log4j Explained, Google Disrupts Major Botnet, and NPM Packages Steal Discord Creds! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins, information security professionals, and consumers. Watch this on youtube (video may be “private” until the scheduled publish time): https://youtu.be/ysFB6JKTs5U Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Follow Shannon on Social Media: https://snubsie.com/links Links: https://arstechnica.com/information-technology/2021/12/minecraft-and-other-apps-face-serious-threat-from-new-code-execution-bug/ https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce https://www.randori.com/blog/cve-2021-44228/ https://arstechnica.com/information-technology/2021/12/the-log4shell-zeroday-4-days-on-what-is-it-and-how-bad-is-it-really/ https://www.lunasec.io/docs/blog/log4j-zero-day/ https://twitter.com/chvancooten/status/1469340927923826691 https://twitter.com/AlyssaM_InfoSec/status/1470463098523955202 https://twitter.com/llkkaT/status/1470411739829350407 https://twitter.com/eastdakota/status/1469800951351427073 https://github.com/YfryTchsGD/Log4jAttackSurface https://gist.github.com/SwitHak/b66db3a06c2955a9cb71a8718970c592 https://www.bleepingcomputer.com/news/security/hackers-start-pushing-malware-in-worldwide-log4shell-attacks/ https://www.microsoft.com/security/blog/2021/12/11/guidance-for-preventing-detecting-and-hunting-for-cve-2021-44228-log4j-2-exploitation/ https://nakedsecurity.sophos.com/2021/12/13/log4shell-explained-how-it-works-why-you-need-to-know-and-how-to-fix-it/ https://blog.google/technology/safety-security/new-action-combat-cyber-crime/ https://blog.google/threat-analysis-group/disrupting-glupteba-operation/ https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/1_Complaint.pdf https://www.cnet.com/tech/google-breaks-up-botnet-infecting-1-million-devices/ https://arstechnica.com/information-technology/2021/12/malicious-packages-sneaked-into-npm-repository-stole-discord-tokens/ https://jfrog.com/blog/malicious-npm-packages-are-after-your-discord-tokens-17-new-packages-disclosed/ https://thehackernews.com/2021/12/over-dozen-malicious-npm-packages.html Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005: -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ ____________________________________________ Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.
Click for links and more info ⬇️⬇️⬇️ Spyware was found on government employee phones, several popular routers are riddled with flaws, and cryptocurrency scams are on the rise! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins, information security professionals, and consumers. Watch this on youtube (video may be “private” until the scheduled publish time): https://youtu.be/ZmoP-GgpKEE Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Follow Shannon on Social Media: https://snubsie.com/links Links: https://www.reuters.com/technology/exclusive-us-state-department-phones-hacked-with-israeli-company-spyware-sources-2021-12-03/ https://www.bleepingcomputer.com/news/security/us-state-dept-employees-phones-hacked-using-nso-spyware/ https://www.vice.com/en/article/5dggxk/us-state-department-employees-targeted-with-nso-group-malware https://www.commerce.gov/news/press-releases/2021/11/commerce-adds-nso-group-and-other-foreign-companies-entity-list https://arstechnica.com/information-technology/2021/12/iphones-of-us-diplomats-hacked-using-0-click-exploits-from-embattled-nso/ https://threatpost.com/pegasus-spyware-state-department-iphones/176779/ https://www.iot-inspector.com/wp-content/uploads/2021/11/Chip-IoT-Inspector-Router-Sicherheit-Test.pdf https://www.iot-inspector.com/blog/extracting-decryption-keys-dlink/ https://www.bleepingcomputer.com/news/security/nine-wifi-routers-used-by-millions-were-vulnerable-to-226-flaws/ https://www.iot-inspector.com/blog/router-security-check-2021/ https://thehackernews.com/2021/12/hackers-steal-200-million-worth-of.html https://www.vice.com/en/article/akvewk/hackers-steal-dollar150m-from-crypto-exchange-billed-as-most-trusted https://www.vice.com/en/article/pkpp4n/hackers-steal-dollar119m-from-web3-crypto-project-with-old-school-attack https://www.vice.com/en/article/epxxe7/received-some-random-cryptocurrency-it-might-be-a-phishing-scam https://www.cnet.com/personal-finance/crypto/what-to-do-if-your-bitcoin-ether-or-other-cryptocurrency-gets-stolen/ Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005: -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ ____________________________________________ Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.
Apple Sues NSO Group, GoDaddy Discloses Another Hack, and Attackers Could Eavesdrop on Your Phone Using a MediaTek Vulnerability! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins, information security professionals, and consumers. Watch this on youtube (video may be “private” until the scheduled publish time): xxx Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Follow Shannon on Social Media: https://snubsie.com/links Links: Apple Suing NSO Group over Pegasus Spyware: https://citizenlab.ca/2018/09/hide-and-seek-tracking-nso-groups-pegasus-spyware-to-operations-in-45-countries/ https://www.bleepingcomputer.com/news/apple/new-zero-click-iphone-exploit-used-to-deploy-nso-spyware/ https://www.apple.com/newsroom/pdfs/Apple_v_NSO_Complaint_112321.pdf https://www.vice.com/en/article/7kbvyb/apple-sues-nso-group-for-hacking-its-users https://threatpost.com/apple-nso-lawsuit-pegasus-spyware/176565/ https://www.cnet.com/tech/mobile/apple-sues-pegasus-for-spyware-maker-how-to-check-if-your-iphone-has-nso-group-software/ https://www.cnet.com/tech/mobile/apple-sues-pegasus-spyware-developer-what-you-need-to-know/ GoDaddy Data Breach https://www.sec.gov/Archives/edgar/data/1609711/000160971121000122/gddyblogpostnov222021.htm https://www.bleepingcomputer.com/news/security/godaddy-data-breach-hits-12-million-managed-wordpress-customers/ https://threatpost.com/godaddys-latest-breach-customers/176530/ https://www.wordfence.com/blog/2021/11/godaddy-tsohost-mediatemple-123reg-domain-factory-heart-internet-host-europe/ MediaTek Eavesdropping Vulnerability https://www.counterpointresearch.com/global-smartphone-ap-market-share/ https://www.bleepingcomputer.com/news/security/mediatek-eavesdropping-bug-impacts-30-percent-of-all-android-smartphones/ https://research.checkpoint.com/2021/looking-for-vulnerabilities-in-mediatek-audio-dsp/ https://thehackernews.com/2021/11/eavesdropping-bugs-in-mediatek-chips.html Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005: -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ ____________________________________________ Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.
Click for links and more info ⬇️⬇️⬇️ BIOS Flaws Hit Intel Processors, Robinhood was Hacked and 7 Million are Affected , and the FBI's Email Server was used to Send Spoofed Emails ! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins, information security professionals, and consumers. Watch this on youtube (video may be “private” until the scheduled publish time): https://youtu.be/j3vQJNMiTMk Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Follow Shannon on Social Media: https://snubsie.com/links Links: https://www.bleepingcomputer.com/news/security/high-severity-bios-flaws-affect-numerous-intel-processors/ https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00562.html https://www.bleepingcomputer.com/news/security/fbi-system-hacked-to-email-urgent-warning-about-fake-cyberattacks/ https://twitter.com/spamhaus/status/1459451401269043201 https://twitter.com/vinnytroia/status/1459515619838251010 https://thehackernews.com/2021/11/fbis-email-system-hacked-to-send-out.html https://krebsonsecurity.com/2021/11/hoax-email-blast-abused-poor-coding-in-fbi-website/ https://www.fbi.gov/news/pressrel/press-releases/fbi-statement-on-incident-involving-fake-emails https://blog.robinhood.com/2021/11/8/data-security-incident https://www.vice.com/en/article/epxdmn/robinhood-hackers-internal-tool-security-features https://www.bleepingcomputer.com/news/security/7-million-robinhood-user-email-addresses-for-sale-on-hacker-forum/ https://www.cnet.com/tech/services-and-software/robinhood-data-breach-exposed-7-million-customers/ Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005: -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ ____________________________________________ Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.
Click for links and more info ⬇️⬇️⬇️ Facebook is deleting over 1 billion users facial recognition records, an android bug is being actively exploited so update now, and the US is offering a huge reward to anyone who ousts Darkside ransomware leaders ! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins, information security professionals, and consumers. Watch this on youtube (video may be “private” until the scheduled publish time): https://youtu.be/fgqraGM-RnE Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Follow Shannon on Social Media: https://snubsie.com/links Links: https://about.fb.com/news/2021/11/update-on-use-of-face-recognition/ https://www.facebook.com/help/122175507864081 https://www.bleepingcomputer.com/news/technology/facebook-to-delete-1-billion-faceprints-in-face-recognition-shutdown/ https://thehackernews.com/2021/11/facebook-to-shut-down-facial.html https://source.android.com/security/bulletin/2021-11-01 https://www.bleepingcomputer.com/news/security/android-november-patch-fixes-actively-exploited-kernel-bug/ https://thehackernews.com/2021/11/google-warns-of-new-android-0-day.html https://threatpost.com/android-patches-exploited-kernel-bug/175931/ https://www.state.gov/reward-offers-for-information-to-bring-darkside-ransomware-variant-co-conspirators-to-justice/ https://www.bleepingcomputer.com/news/security/us-targets-darkside-ransomware-rebrands-with-10-million-reward/ https://www.bleepingcomputer.com/news/security/blackmatter-ransomware-claims-to-be-shutting-down-due-to-police-pressure/ https://threatpost.com/feds-offer-10-million-bounty-on-darkside-info/176030/ Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005: -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ ____________________________________________ Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.
Click for links and more info ⬇️⬇️⬇️ Trojan Source affects source code, attackers are using Squid Game to lure in victims, and watch out for this new spam campaign! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins, information security professionals, and consumers. Watch this on youtube (video may be “private” until the scheduled publish time): https://youtu.be/D4QMssZgaXM Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Follow Shannon on Social Media: https://snubsie.com/links Links: Trojan source code: https://trojansource.codes/trojan-source.pdf https://www.trojansource.codes/ https://github.com/nickboucher/trojan-source https://blog.rust-lang.org/2021/11/01/cve-2021-42574.html https://threatpost.com/trojan-source-invisible-bugs-source-code/175891/ https://www.zdnet.com/article/this-sneaky-trick-could-allow-attackers-to-hide-invisible-vulnerabilities-in-code/ https://thehackernews.com/2021/11/new-trojan-source-technique-lets.html Squid Game: https://www.proofpoint.com/us/blog/threat-insight/ta575-uses-squid-game-lures-distribute-dridex-malware https://www.zdnet.com/article/ta575-criminal-group-using-squid-game-lures-for-dridex-malware/ https://www.techrepublic.com/article/you-definitely-dont-want-to-play-squid-game-themed-malware-is-here/ https://www.cnet.com/tech/services-and-software/researchers-spot-dangerous-squid-game-themed-phishing-emails/ SquirrelWaffle: https://blog.talosintelligence.com/2021/10/squirrelwaffle-emerges.html https://www.bleepingcomputer.com/news/security/emotet-botnet-disrupted-after-global-takedown-operation/ https://threatpost.com/squirrelwaffle-loader-malspams-packing-qakbot-cobalt-strike/175775/ https://www.bleepingcomputer.com/news/security/spammers-use-squirrelwaffle-malware-to-drop-cobalt-strike/ Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005: -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ ____________________________________________ Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.
Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins, information security professionals, and consumers. Watch this on youtube (video may be “private” until the scheduled publish time): https://youtu.be/B1MjSqwXaTk Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Follow Shannon on Social Media: https://snubsie.com/links Links: YT: https://www.bleepingcomputer.com/news/security/massive-campaign-uses-youtube-to-push-password-stealing-malware/ https://www.bleepingcomputer.com/news/security/google-youtubers-accounts-hijacked-with-cookie-stealing-malware/ https://thehackernews.com/2021/10/hackers-stealing-browser-cookies-to.html https://arstechnica.com/information-technology/2021/10/how-hackers-hijacked-thousands-of-high-profile-youtube-accounts/ https://www.zdnet.com/article/google-disrupts-massive-phishing-and-malware-campaign/ https://threatpost.com/google-youtube-channel-hijackers-cryptocurrency-scams/175617/ Sim swapper: https://www.vice.com/en/article/jgmep7/sim-swapper-doxes-and-swats-his-accomplice https://www.justice.gov/usao-md/pr/defendant-who-stole-more-16000-cryptocurrency-and-orchestrated-swat-attack-his-accomplice REvil: https://www.bleepingcomputer.com/news/security/revil-ransomware-shuts-down-again-after-tor-sites-were-hijacked/ https://www.cnet.com/tech/services-and-software/notorious-ransomware-group-knocked-offline-according-to-report/ https://thehackernews.com/2021/10/feds-reportedly-hacked-revil-ransomware.html https://www.zdnet.com/article/multiple-governments-involved-in-coordinated-takedown-of-revil-ransomware-group-reuters/ https://threatpost.com/revil-servers-offline-governments/175675/ Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005: -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ ____________________________________________ Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.
Click for links and more info ⬇️⬇️⬇️ OpenSea had a malicious NFT problem, a twitch hack update, and whatsapp officially adds end to end encrypted backups! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins, information security professionals, and consumers. Watch this on youtube (video may be “private” until the scheduled publish time): https://youtu.be/Qx-PHk2cgqM Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Follow Shannon on Social Media: https://snubsie.com/links Links: Opensea https://research.checkpoint.com/2021/check-point-research-prevents-theft-of-crypto-wallets-on-opensea-the-worlds-largest-nft-marketplace/ https://thehackernews.com/2021/10/critical-flaw-in-opensea-could-have-let.html https://threatpost.com/opensea-nfts-cryptowallet-balances/175453/ Twitch https://blog.twitch.tv/en/2021/10/15/updates-on-the-twitch-security-incident/?utm_referrer=https://t.co/ https://www.bleepingcomputer.com/news/security/twitch-downplays-this-months-hack-says-it-had-minimal-impact/ https://threatpost.com/twitch-leak-emails-passwords/175390/ https://www.zdnet.com/article/twitch-downplays-massive-breach-says-no-passwords-or-login-credentials-leaked/ Whatsapp https://about.fb.com/news/2021/10/end-to-end-encrypted-backups-on-whatsapp/ https://www.bleepingcomputer.com/news/security/whatsapp-rolls-out-ios-android-end-to-end-encrypted-chat-backups/ https://www.zdnet.com/article/whatsapp-starts-slowly-rolling-out-encrypted-backups/ Thumbnail Credit: https://cryptoslate.com/wp-content/uploads/2021/03/opensea-sea-1024x538.jpg Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005: -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ ____________________________________________ Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.
Click for links and more info ⬇️⬇️⬇️ Fraudsters stole millions from veterans, SMS infrastructure was hacked, and Facebook is having a worst week ever! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins, information security professionals, and consumers. Watch this on youtube (video may be “private” until the scheduled publish time): https://youtu.be/roznl90rljU Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Follow Shannon on Social Media: https://snubsie.com/links Links: Fraudsters Stole From Veterans: https://www.bleepingcomputer.com/news/security/transnational-fraud-ring-stole-millions-from-army-members-veterans/ https://threatpost.com/transnational-fraud-military-members/175298/ https://www.zdnet.com/article/fraudster-jailed-for-stealing-us-military-health-records-millions-in-benefits/ https://www.zdnet.com/article/army-contractor-sentenced-for-stealing-1-5-million-from-veterans-through-dod-benefit-sites/ SMS Infrastructure Was Hacked: https://www.syniverse.com/products/operator-messaging https://www.businessinsider.com/syniverse-hackers-access-billions-of-texts-through-breach-2021-10 https://www.sec.gov/Archives/edgar/data/1839175/000119312521284329/d234831dprem14a.htm https://www.vice.com/en/article/z3xpm8/company-that-routes-billions-of-text-messages-quietly-says-it-was-hacked Facebook Down: https://arstechnica.com/information-technology/2021/10/facebook-instagram-whatsapp-and-oculus-are-down-heres-what-we-know/ https://www.bleepingcomputer.com/news/technology/facebook-whatsapp-and-instagram-down-due-to-dns-outage/ https://www.cbsnews.com/news/facebook-whistleblower-frances-haugen-misinformation-public-60-minutes-2021-10-03/ https://arstechnica.com/tech-policy/2021/09/facebooks-latest-apology-reveals-security-and-safety-disarray/ https://www.wsj.com/articles/facebook-whistleblower-frances-haugen-says-she-wants-to-fix-the-company-not-harm-it-11633304122?mod=djemalertNEWS https://www.cnet.com/news/facebook-whistleblower-to-testify-before-congress-how-to-watch/?ftag=COS-05-10aaa0b&PostType=link&ServiceType=twitter&UniqueID=ACA16F60-2556-11EC-B5CD-A6BE4744363C&TheTime=2021-10-04T21%3A04%3A33 https://www.vice.com/en/article/4avjqb/conspiracy-theories-about-facebook-outage-spread-even-without-facebook https://9to5mac.com/2021/10/04/instagram-facebook-whatsapp-down/ https://krebsonsecurity.com/2021/10/what-happened-to-facebook-instagram-whatsapp/ Thumbnail Credit: https://cdn.pixabay.com/photo/2015/09/26/13/38/facebook-959060_1280.jpg Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005: -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ ____________________________________________ Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.
Click for links and more info ⬇️⬇️⬇️ 100,000 credentials leaked due to an autodiscover flaw, 3 Apple zero days were published online, and the FBI secretly held a ransomware decryptor key! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins, information security professionals, and consumers. Watch this on youtube (video may be “private” until the scheduled publish time): https://youtu.be/2XZqx6Coa2Y Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Follow Shannon on Social Media: https://snubsie.com/links Links: Links: 100k windows exchange emails https://www.bleepingcomputer.com/news/microsoft/microsoft-rushes-to-register-autodiscover-domains-leaking-credentials/ https://www.guardicore.com/labs/autodiscovering-the-great-leak/ https://thehackernews.com/2021/09/microsoft-exchange-bug-exposes-100000.html https://arstechnica.com/information-technology/2021/09/exchange-outlook-autodiscover-bug-exposed-100000-email-passwords/ https://www.bleepingcomputer.com/news/microsoft/microsoft-rushes-to-register-autodiscover-domains-leaking-credentials/ https://www.blackhat.com/asia-17/briefings/schedule/#all-your-emails-belong-to-us-exploiting-vulnerable-email-clients-via-domain-name-collision-5301 https://github.com/guardicore/labs_campaigns/tree/master/Autodiscover Apple Stuff: https://arstechnica.com/information-technology/2021/09/three-ios-0-days-revealed-by-researcher-frustrated-with-apples-bug-bounty/ https://www.bleepingcomputer.com/news/security/researcher-drops-three-ios-zero-days-that-apple-refused-to-fix/ https://habr.com/en/post/579714/ https://www.vice.com/en/article/k78dpx/researcher-publishes-source-code-for-three-unpatched-iphone-exploits https://habr.com/en/post/580272/ https://www.reddit.com/r/jailbreak/comments/pvaztb/free_release_entitlementfix_workaround_for_the_3/ Ransomware Key https://arstechnica.com/gadgets/2021/07/kaseya-gets-master-decryptor-to-help-customers-still-suffering-from-revil-attack/ https://arstechnica.com/information-technology/2021/09/ransomware-victims-panicked-while-fbi-secretly-held-revil-decryption-key/ https://www.cnet.com/tech/services-and-software/fbi-reportedly-withheld-ransomware-key-from-business-for-3-weeks-in-failed-sting/ https://twitter.com/BitdefenderLabs/status/1438489191491440646?s=20 https://www.washingtonpost.com/national-security/ransomware-fbi-revil-decryption-key/2021/09/21/4a9417d0-f15f-11eb-a452-4da5fe48582d_story.html Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005: -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ ____________________________________________ Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.
Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005: An Epic Hack of Epik Customer Data, Apple Patches Exploit Used By Pegasus Spyware, and ExpressVPN Comes Under Fire! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins, information security professionals, and consumers. Watch this on youtube (video may be “private” until the scheduled publish time): https://youtu.be/W5YDss-olvA Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Follow Shannon on Social Media: https://snubsie.com/links Links: Epik: https://arstechnica.com/information-technology/2021/09/anonymous-leaks-gigabytes-of-data-from-epik-web-host-of-gab-and-parler/ https://twitter.com/stevanzetti/status/1437482759241469958 https://twitter.com/stevanzetti/status/1437818671712329748 https://arstechnica.com/information-technology/2021/09/epik-data-breach-impacts-15-million-users-including-non-customers/ https://haveibeenpwned.com/ Apple: https://www.vice.com/en/article/3aq9q3/apple-patches-zero-click-imessage-hack-used-by-nso https://citizenlab.ca/2021/09/forcedentry-nso-group-imessage-zero-click-exploit-captured-in-the-wild/ https://thehackernews.com/2021/09/apple-issues-urgent-updates-to-fix-new.html https://arstechnica.com/information-technology/2021/09/apple-fixes-imessage-zero-day-exploited-by-pegasus-spyware/ https://www.cnet.com/tech/services-and-software/apples-ios-14-8-security-fix-protect-your-iphone-from-pegasus-now/ ExpressVPN: https://www.zdnet.com/article/expressvpn-sells-to-kape-technologies-for-936-million/ https://www.expressvpn.com/blog/expressvpn-joining-kape/ https://www.vice.com/en/article/3aq9a5/us-company-sold-zero-click-exploit-project-raven-uae https://www.reuters.com/investigates/special-report/usa-spying-raven https://www.expressvpn.com/blog/daniel-gericke-expressvpn/ https://www.documentcloud.org/documents/21062379-raven_charge -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ ____________________________________________ Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.
Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005: 60 Million+ Fitness Records Exposed, A record breaking botnet hit Yandex, and WhatsApp Rolls Out E2EE Backups! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins, information security professionals, and consumers. Watch this on youtube (video may be “private” until the scheduled publish time): https://youtu.be/s2QFPS5Bqd8 Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Follow Shannon on Social Media: https://snubsie.com/links Links: 60 Million+ Fitness Records Exposed https://www.macobserver.com/news/gethealth-data-leak/ https://www.zdnet.com/article/over-60-million-records-exposed-in-wearable-fitness-tracking-data-breachover-60-million-wearable-fitness-tracking-records-exposed-via-unsecured-database/ https://www.websiteplanet.com/blog/gethealth-leak-report/ https://www.programmableweb.com/api/gethealth-rest-api Record Breaking Botnet https://www.bleepingcomputer.com/news/security/new-m-ris-botnet-breaks-ddos-record-with-218-million-rps-attack/ https://www.bleepingcomputer.com/news/security/mikrotik-patches-zero-day-flaw-under-attack-in-record-time/ https://thehackernews.com/2021/09/meris-botnet-hit-russias-yandex-with.html https://www.reuters.com/technology/russias-yandex-says-it-repelled-biggest-ddos-attack-history-2021-09-09/ https://threatpost.com/yandex-meris-botnet/169368/ https://blog.qrator.net/en/meris-botnet-climbing-to-the-record_142/ WhatsApp Rolls Out E2EE Backups https://engineering.fb.com/2021/09/10/security/whatsapp-e2ee-backups/ https://thehackernews.com/2021/09/whatsapp-to-finally-let-users-encrypt.html https://www.zdnet.com/article/whatsapp-details-plans-to-offer-encrypted-backups/ https://arstechnica.com/gadgets/2021/09/whatsapp-end-to-end-encrypted-messages-arent-that-private-after-all/ https://www.propublica.org/article/how-facebook-undermines-privacy-protections-for-its-2-billion-whatsapp-users -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ ____________________________________________ Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.
Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005: A severe flaw was found in the RealTek SDK, national cybersecurity initiatives happen at a government meeting, and that Razer privilege escalation flaw? Yeah, it works with other devices too! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins and users. Watch this on youtube (video may be “private” until the scheduled publish time): xxx Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Links: Realtek https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain/ https://www.bleepingcomputer.com/news/security/botnet-targets-hundreds-of-thousands-of-devices-using-realtek-sdk/ https://securingsam.com/realtek-vulnerabilities-weaponized/ https://www.bleepingcomputer.com/news/security/actively-exploited-bug-bypasses-authentication-on-millions-of-routers/ Cybersecurity Initiatives https://www.whitehouse.gov/briefing-room/statements-releases/2021/08/25/fact-sheet-biden-administration-and-private-sector-leaders-announce-ambitious-initiatives-to-bolster-the-nations-cybersecurity/ https://www.cnet.com/tech/services-and-software/apple-google-amazon-ceos-head-to-white-house-for-cybersecurity-meeting/ https://www.zdnet.com/article/tech-giants-make-cybersecurity-commitments-after-white-house-meeting/ https://www.bleepingcomputer.com/news/security/microsoft-and-google-to-invest-billions-to-bolster-us-cybersecurity/ https://thehackernews.com/2021/08/microsoft-google-to-invest-30-billion.html Razer Peripheral Zero Day https://twitter.com/j0nh4t/status/1429049506021138437 https://www.bleepingcomputer.com/news/security/steelseries-bug-gives-windows-10-admin-rights-by-plugging-in-a-device/ https://www.forbes.com/sites/daveywinder/2021/08/28/new-windows-10-hacking-warning-for-millions-of-users/?sh=60a1002b1bb7 https://twitter.com/hak5darren/status/1429463473700888577 https://twitter.com/_MG_/status/1431059999866843137 -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ ____________________________________________ Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.
Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005: Razer mice plus a windows machine can give you admin privileges, contact tracing data is exposed in a data leak, and a t-mobile hack followup - yes, it's real! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins and users. Watch this on youtube (video may be “private” until the scheduled publish time): https://youtu.be/NA1ocWiAMVg Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Links: Razer: https://www.bleepingcomputer.com/news/security/razer-bug-lets-you-become-a-windows-10-admin-by-plugging-in-a-mouse/ https://www.razer.com/synapse-3 https://twitter.com/j0nh4t/status/1429049506021138437 https://threatpost.com/windows-10-admin-rights-razer-devices-mouse-peripherals/168855/ https://twitter.com/Lechatquirit/status/1429374730860208128 Power Apps: https://www.upguard.com/breaches/power-apps https://www.wired.com/story/microsoft-power-apps-data-exposed/ https://threatpost.com/covid-contact-tracing-exposed-fake-vax-cards/168821/ https://apnews.com/article/technology-health-indiana-coronavirus-pandemic-557a7dce07a39bd0ec9b36140cc53219 T-Mobile: https://threatpost.com/t-mobile-investigates-100m-records/168689/ https://www.t-mobile.com/news/network/additional-information-regarding-2021-cyberattack-investigation https://arstechnica.com/gadgets/2021/08/hackers-who-breached-t-mobile-stole-personal-data-for-49-million-accounts/ https://threatpost.com/t-mobile-40-million-customers-data-stolen/168778/ https://www.cnet.com/tech/services-and-software/t-mobiles-2021-cyberattack-4-ways-to-protect-your-personal-data-after-a-breach/ -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ ____________________________________________ Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.
Support ThreatWire! https://www.patreon.com/threatwire Shop ThreatWire Merch Directly! - https://snubsie.com/shop Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005: Is this the biggest crypto hack ever? Print Spooler is an actual Nightmare, and a hacker claims t-mobile data was stolen in a server hack! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins and users. Watch this on youtube (video may be “private” until the scheduled publish time): https://youtu.be/UW38I60EmX4 Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Links: Poly Network Hack: https://arstechnica.com/information-technology/2021/08/hackers-siphon-600-million-in-digital-tokens-crypto-network-says/ https://www.bleepingcomputer.com/news/security/over-600-million-reportedly-stolen-in-cryptocurrency-hack/ https://www.zdnet.com/article/poly-network-hackers-potentially-stole-610-million-is-bitcoin-still-safe/ https://twitter.com/PolyNetwork2/status/1425130017546149891 https://www.reuters.com/technology/how-hackers-stole-613-million-crypto-tokens-poly-network-2021-08-12/ https://twitter.com/PolyNetwork2/status/1425123153009803267/photo/1 https://twitter.com/PolyNetwork2/status/1425870262067548163/photo/1 https://www.bbc.com/news/business-58193396 https://cointelegraph.com/news/poly-network-hacker-returns-258m-conducts-ama-on-how-it-went-down PrintNightmare: https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-print-spooler-printnightmare-vulnerability/ https://www.zdnet.com/article/microsoft-fixes-windows-10-printnightmare-flaw-with-this-update/ https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-another-windows-print-spooler-zero-day-bug/ https://twitter.com/gentilkiwi/status/1416429860566847490 https://www.bleepingcomputer.com/news/security/ransomware-gang-uses-printnightmare-to-breach-windows-servers/ https://blog.talosintelligence.com/2021/08/vice-society-ransomware-printnightmare.html T-Mobile Data: https://www.vice.com/en/article/akg8wg/tmobile-investigating-customer-data-breach-100-million https://threatpost.com/t-mobile-investigates-100m-records/168689/ https://twitter.com/UnderTheBreach/status/1426923538099970050 https://www.cnet.com/tech/services-and-software/t-mobile-investigating-claim-of-stolen-personal-data-for-sale/ https://www.bleepingcomputer.com/news/security/hacker-claims-to-steal-data-of-100-million-t-mobile-customers/ -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ ____________________________________________ Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.
Stealing audio through LEDs, is Apple's new CSAM scanning tech privacy invasive? and Synology warns of botnet malware! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins and users. Watch this on youtube (video may be “private” until the scheduled publish time): https://youtu.be/75XYa3dKals Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Links: Read all the links via the RSS feed: https://shannonmorse.podbean.com/ Stealing Audio from LEDs https://arstechnica.com/gadgets/2021/08/new-glowworm-attack-recovers-audio-from-devices-power-leds/ https://www.nassiben.com/glowworm-attack https://www.youtube.com/watch?v=z4-OFLTHtiw&t=7s Apple Scans for Sensitive Imagery https://www.apple.com/child-safety/ https://www.zdnet.com/article/apple-child-abuse-material-scanning-in-ios-15-draws-fire/ https://www.cnet.com/tech/services-and-software/apples-plan-to-scan-phones-for-child-abuse-worries-privacy-advocates/ https://www.apple.com/child-safety/pdf/Expanded_Protections_for_Children_Technology_Summary.pdf https://www.apple.com/child-safety/pdf/CSAM_Detection_Technical_Summary.pdf https://www.apple.com/child-safety/pdf/Expanded_Protections_for_Children_Frequently_Asked_Questions.pdf https://www.eff.org/deeplinks/2021/08/apples-plan-think-different-about-encryption-opens-backdoor-your-private-life https://www.wired.com/story/apple-csam-detection-icloud-photos-encryption-privacy/ https://appleprivacyletter.com/ Synology Warns of Botnet https://www.howtogeek.com/746871/synology-nas-devices-under-attack-from-stealthworker-botnet/ https://www.bleepingcomputer.com/news/security/synology-warns-of-malware-infecting-nas-devices-with-ransomware/ https://www.synology.com/en-global/company/news/article/BruteForce/Synology%C2%AE%20Investigates%20Ongoing%20Brute-Force%20Attacks%20From%20Botnet https://kb.synology.com/en-us/DSM/tutorial/How_to_add_extra_security_to_your_Synology_NAS https://blog.malwarebytes.com/threat-analysis/2019/02/new-golang-brute-forcer-discovered-amid-rise-e-commerce-attacks/ -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubs Host: Darren Kitchen → https://www.twitter.com/hak5darren Host: Mubix → http://www.twitter.com/mubix -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
PwnedPiper Threatens Hospitals, Meteor Malware Causes a Train Disruption, and BlackMatter is the new DarkSide! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins and users. Watch this on youtube (video may be “private” until the scheduled publish time): https://youtu.be/5ofYqjC1s40 Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Links: https://www.armis.com/research/pwnedpiper https://info.armis.com/rs/645-PDC-047/images/Armis-PwnedPiper-WP.pdf https://www.wired.com/story/pneumatic-tubes-hospitals-hacking/ https://www.bleepingcomputer.com/news/security/pwnedpiper-critical-bug-set-impacts-major-hospitals-in-north-america/ https://thehackernews.com/2021/08/pwnedpiper-pts-security-flaws-threaten.html https://www.swisslog-healthcare.com/en-us/company/news/2021/07/translogic-firmware-vulnerabilities https://www.theguardian.com/world/2021/jul/11/cyber-attack-hits-irans-transport-ministry-and-railways https://labs.sentinelone.com/meteorexpress-mysterious-wiper-paralyzes-iranian-trains-with-epic-troll/ https://www.bleepingcomputer.com/news/security/new-destructive-meteor-wiper-malware-used-in-iranian-railway-attack/ https://thehackernews.com/2021/07/a-new-wiper-malware-was-behind-recent.html https://threatpost.com/novel-meteor-wiper-used-in-attack-that-crippled-iranian-train-system/168262/ https://www.bleepingcomputer.com/news/security/darkside-ransomware-gang-returns-as-new-blackmatter-operation/ https://thehackernews.com/2021/05/us-pipeline-ransomware-attackers-go.html https://www.bleepingcomputer.com/news/security/blackmatter-ransomware-gang-rises-from-the-ashes-of-darkside-revil/ https://thehackernews.com/2021/07/new-ransomware-gangs-haron-and.html -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubs Host: Darren Kitchen → https://www.twitter.com/hak5darren Host: Mubix → http://www.twitter.com/mubix -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
The REvil Decryption Key is Obtained, Windows & Linux are Vulnerable to Privilege Escalation Attacks, and the Pegasus Project Reveals Phone Spyware Targeting! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins and users. Watch this on youtube: https://youtu.be/mJfCTJRs1io Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Links: https://krebsonsecurity.com/2021/07/kaseya-left-customer-portal-vulnerable-to-2015-flaw-in-its-own-software/ https://csirt.divd.nl/2021/07/04/Kaseya-Case-Update-2/ https://www.bleepingcomputer.com/news/security/kaseya-obtains-universal-decryptor-for-revil-ransomware-victims/ https://arstechnica.com/gadgets/2021/07/kaseya-gets-master-decryptor-to-help-customers-still-suffering-from-revil-attack/ https://www.bleepingcomputer.com/news/security/biden-asks-putin-to-crack-down-on-russian-based-ransomware-gangs/ https://threatpost.com/kaseya-universal-decryptor-revil-ransomware/168070/ https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-workaround-for-windows-10-serioussam-vulnerability/ https://twitter.com/jonasLyk https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36934 https://thehackernews.com/2021/07/how-to-mitigate-microsoft-windows-10-11.html https://www.zdnet.com/article/microsoft-just-published-a-workaround-for-this-important-windows-10-flaw/ https://thehackernews.com/2021/07/new-windows-and-linux-flaws-give.html https://blog.qualys.com/vulnerabilities-threat-research/2021/07/20/sequoia-a-local-privilege-escalation-vulnerability-in-linuxs-filesystem-layer-cve-2021-33909 https://www.washingtonpost.com/investigations/interactive/2021/nso-spyware-pegasus-cellphones/ https://www.theguardian.com/world/2021/jul/18/revealed-leak-uncovers-global-abuse-of-cyber-surveillance-weapon-nso-group-pegasus https://threatpost.com/nso-group-data-pegasus/167897/ https://www.zdnet.com/article/whatsapp-chief-says-government-officials-us-allies-targeted-by-nso-groups-pegasus-spyware/ https://www.cnet.com/news/amazon-kicks-nso-group-off-its-cloud-service-after-spying-reports/ https://threatpost.com/apple-iphone-pegasus-zero-day/168040/ Photo credit: https://p1.pxfuel.com/preview/325/241/266/horse-with-wings-pegasus-myth-sunset.jpg -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubs Host: Darren Kitchen → https://www.twitter.com/hak5darren Host: Mubix → http://www.twitter.com/mubix -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
3 Vulnerabilities were Found In Netgear Routers, Ransomware Hits Businesses Worldwide, and PrintNightmare Leads to remote code execution attacks! All that coming up now on ThreatWire. #threatwire #hak5 Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins and users. Watch this on youtube: https://youtu.be/iCGuqW7NL9U Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Links: https://www.zdnet.com/article/microsoft-reveals-firmware-vulnerabilities-in-netgear-routers-leading-to-full-system-hijacking/ https://threatpost.com/netgear-authentication-bypass-router-takeover/167469/ https://www.microsoft.com/security/blog/2021/06/30/microsoft-finds-new-netgear-firmware-vulnerabilities-that-could-lead-to-identity-theft-and-full-system-compromise/ https://kb.netgear.com/000062646/Security-Advisory-for-Multiple-HTTPd-Authentication-Vulnerabilities-on-DGN2200v1 https://www.cnet.com/news/ransomware-attack-on-kaseya-a-software-firm-threatens-businesses-worldwide/ https://www.bleepingcomputer.com/news/security/revil-ransomware-hits-1-000-plus-companies-in-msp-supply-chain-attack/ https://therecord.media/revil-gang-asks-70-million-to-decrypt-systems-locked-in-kaseya-attack/ https://news.sophos.com/en-us/2021/07/04/independence-day-revil-uses-supply-chain-exploit-to-attack-hundreds-of-businesses/ https://us-cert.cisa.gov/ncas/current-activity/2021/07/04/cisa-fbi-guidance-msps-and-their-customers-affected-kaseya-vsa https://threatpost.com/poc-exploit-windows-print-spooler-bug/167430/ https://www.bleepingcomputer.com/news/security/public-windows-printnightmare-0-day-exploit-allows-domain-takeover/ https://www.zdnet.com/article/microsoft-adds-second-cve-for-printnightmare-remote-code-execution/ https://threatpost.com/cisa-mitigation-printnightmare-bug/167515/ https://www.bleepingcomputer.com/news/security/microsoft-shares-mitigations-for-windows-printnightmare-zero-day-bug/ https://www.bleepingcomputer.com/news/security/actively-exploited-printnightmare-zero-day-gets-unofficial-patch/ Photo credit: https://media.threatpost.com/wp-content/uploads/sites/103/2021/06/03084327/ransomware-e1622724224226.jpeg -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubs Host: Darren Kitchen → https://www.twitter.com/hak5darren Host: Mubix → http://www.twitter.com/mubix -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
Dude, Millions of Dell PCs are at risk of RCEs, disconnect your Western Digital My Book, and RIP John McAfee! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins and users. Watch this on youtube: https://youtu.be/27QQUHbOtVw Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Links: Dell: https://www.bleepingcomputer.com/news/security/dell-supportassist-bugs-put-over-30-million-pcs-at-risk/ https://eclypsium.com/2021/06/24/biosdisconnect/ https://arstechnica.com/information-technology/2021/06/a-well-meaning-feature-leaves-millions-of-dell-pcs-vulnerable/ https://threatpost.com/dell-bios-attacks-rce/167195/ https://www.dell.com/support/kbdoc/en-us/000188682/dsa-2021-106-dell-client-platform-security-update-for-multiple-vulnerabilities-in-the-supportassist-biosconnect-feature-and-https-boot-feature WD My Book https://www.bleepingcomputer.com/news/security/wd-my-book-nas-devices-are-being-remotely-wiped-clean-worldwide/ https://arstechnica.com/gadgets/2021/06/mass-data-wipe-in-my-book-devices-prompts-warning-from-western-digital/ https://community.wd.com/t/help-all-data-in-mybook-live-gone-and-owner-password-unknown/268111/54 https://www.westerndigital.com/support/productsecurity/wdc-21008-recommended-security-measures-wd-mybooklive-wd-mybookliveduo https://threatpost.com/my-book-live-wiped-rce-attacks/167270/ https://www.zdnet.com/article/own-a-wd-my-book-disconnect-it-from-the-internet-right-now/ McAfee https://elpais.com/economia/2021-06-23/el-fundador-del-antivirus-mcafee-john-mcafee-se-suicida-en-una-prision-de-barcelona.html https://abcnews.go.com/US/rise-fall-rise-john-mcafee-tech-pioneer-person/story?id=47346015 https://www.cnet.com/how-to/john-mcafees-tumultuous-life-in-tech-what-you-need-to-know/ https://www.bleepingcomputer.com/news/technology/antivirus-creator-john-mcafee-reportedly-found-dead-in-prison-cell/ https://arstechnica.com/gadgets/2021/06/john-mcafee-the-eccentric-av-tycoon-dead-at-75-by-apparent-suicide/ https://www.vice.com/en/article/3aqp83/john-mcafee-reportedly-dead-from-suspected-suicide-in-spanish-jail Photo credit: https://www.techadvisor.com/cmsdata/reviews/3796015/dell_xps_15__2020__review_thumb800.jpg -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubs Host: Darren Kitchen → https://www.twitter.com/hak5darren Host: Mubix → http://www.twitter.com/mubix -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins and users. Watch this on youtube: https://youtu.be/5BRNz_etXQA Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Links: Peloton https://www.zdnet.com/article/mcafee-discovers-vulnerability-in-peloton-bike/ https://www.mcafee.com/blogs/other-blogs/mcafee-labs/a-new-program-for-your-peloton-whether-you-like-it-or-not/ https://threatpost.com/peloton-bike-bug-hackers-control/166960/ https://www.cnet.com/health/fitness/peloton-fixes-flaw-on-bikes-that-could-have-let-bad-actors-access-tablets/ https://www.youtube.com/watch?v=RLjXfvb0ADw https://support.onepeloton.com/hc/en-us/articles/4402287359380-How-Do-I-Verify-That-I-Have-The-Latest-System-Updates- Carnival https://threatpost.com/carnival-cruise-cyberattack/167065/ https://www.bleepingcomputer.com/news/security/carnival-cruise-hit-by-data-breach-warns-of-data-misuse-risk/ https://www.documentcloud.org/documents/20949884-carnival-march-bc-data-breach-notice KAERI https://www.bleepingcomputer.com/news/security/south-koreas-nuclear-research-agency-hacked-using-vpn-flaw/ https://www.sisajournal.com/news/articleView.html?idxno=219152 https://www.kaeri.re.kr/board/view?menuId=MENU00326&linkId=9181 https://www.zdnet.com/article/north-korean-hacking-group-allegedly-behind-breach-of-south-korean-nuclear-institute/ Photo credit: https://live.staticflickr.com/65535/49765921462_13795dab8e_b.jpg -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubs Host: Darren Kitchen → https://www.twitter.com/hak5darren Host: Mubix → http://www.twitter.com/mubix -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
EA Source Code was Stolen, a 7 Year Old Linux Flaw was Discovered, and 1.2 Terabytes of Data was Mysteriously Stolen from millions of Windows pcs! All that coming up now on ThreatWire. #threatwire #hak5 Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins and users. Watch this on youtube: https://youtu.be/12oSZ3FVXBA Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Links: EA https://www.vice.com/en/article/wx5xpx/hackers-steal-data-electronic-arts-ea-fifa-source-code https://www.bleepingcomputer.com/news/security/hackers-breach-gaming-giant-electronic-arts-steal-game-source-code/ https://www.cnet.com/news/hackers-hit-ea-steal-source-code-for-fifa-21-and-more/ https://raidforums.com/Thread-SELLING-FIFA-21-SOURCECODE-TOOLS?pid=3954620&highlight=Frostbite#pid3954620 https://www.vice.com/en/article/7kvkqb/how-ea-games-was-hacked-slack Linux Root Bug https://www.bleepingcomputer.com/news/security/linux-system-service-bug-lets-you-get-root-on-most-modern-distros/ https://gitlab.freedesktop.org/polkit/polkit/ https://thehackernews.com/2021/06/7-year-old-polkit-flaw-lets.html https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/ https://access.redhat.com/security/cve/CVE-2021-3560 https://www.youtube.com/watch?v=QZhz64yEd0g Database of PWs https://nordlocker.com/blog/malware-case-study/ https://threatpost.com/custom-malware-stolen-data/166753/ https://nordlocker.com/malware-analysis/ https://arstechnica.com/gadgets/2021/06/nameless-malware-collects-1-2tb-of-sensitive-data-and-stashes-it-online/ https://www.troyhunt.com/nameless-malware-discovered-by-nordlocker-is-now-in-have-i-been-pwned/ Photo credit: https://www.zdnet.com/a/hub/i/r/2020/06/05/30d74ab5-e703-4b01-8dd1-e1895f627516/resize/1200x900/72293020dcb25664c0336abb906c8f71/linux-penguin-in-windows-10-pc.png -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubs Host: Darren Kitchen → https://www.twitter.com/hak5darren Host: Mubix → http://www.twitter.com/mubix -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
Amazon Sidewalk is LIVE - Opt Out NOW, The CFAA gets some clarification thanks to the Supreme Court, REvil Beefs Up Attacks on Supply Chains! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins and users. Watch this on youtube: https://youtu.be/6w2ePAePHQk Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Links: Amazon: https://www.zdnet.com/article/do-you-trust-amazon-to-share-your-internet-connection-with-others-how-to-opt-out/ https://www.zdnet.com/article/yes-i-trust-amazon-to-share-my-internet-connection-with-my-neighbors/ https://threatpost.com/amazon-sidewalk-to-sweep-you-into-its-mesh/166581/ https://arstechnica.com/gadgets/2021/05/amazon-devices-will-soon-automatically-share-your-internet-with-neighbors/ https://www.bleepingcomputer.com/news/technology/amazon-to-share-your-internet-with-neighbors-on-tuesday-how-to-opt-out/ CFAA: https://www.zdnet.com/article/us-supreme-court-limits-scope-of-cfaa-and-rules-bribing-cops-for-data-is-not-hacking/ https://www.zdnet.com/article/supreme-court-ruling-limits-use-of-hacking-law/ https://threatpost.com/court-limits-scope-hacking-law/166672/ https://www.bleepingcomputer.com/news/security/us-supreme-court-restricts-broad-scope-of-cfaa-law/ JBS Meat: https://www.zdnet.com/article/usda-delays-release-of-wholesale-prices-for-beef-and-pork-after-ransomware-attack-on-jbs-confirmed-by-white-house/ https://threatpost.com/revil-ransomware-ground-down-jbs-sources/166597/ https://www.cnet.com/news/jbs-meat-plants-reopening-in-us-after-ransomware-attack/ https://arstechnica.com/gadgets/2021/06/attack-on-meat-supplier-came-from-revil-ransomwares-most-cut-throat-gang/ https://arstechnica.com/gadgets/2021/06/ransomware-striking-the-worlds-biggest-meat-producer-threatens-shortages/ https://www.bleepingcomputer.com/news/security/us-russian-threat-actors-likely-behind-jbs-ransomware-attack/ https://www.bleepingcomputer.com/news/security/fbi-revil-cybergang-behind-the-jbs-ransomware-attack/ https://www.bleepingcomputer.com/news/security/meat-giant-jbs-now-fully-operational-after-ransomware-attack/ Photo credit: https://blog.malwarebytes.com/wp-content/uploads/2021/06/Amazon-van-on-sidewalk-scaled.jpg -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubs Host: Darren Kitchen → https://www.twitter.com/hak5darren Host: Mubix → http://www.twitter.com/mubix -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
Android 12 makes security and privacy front & center, the UK & US Consider New CyberSecurity Legislation, and 23 Android Apps Exposed Millions of users! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins and users. Watch this on youtube: https://youtu.be/lbNWtnB519Q Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Links: Android 12 https://blog.google/products/chrome/automated-password-changes/ https://support.google.com/chrome/answer/95606?co=GENIE.Platform%3DAndroid#:~:text=Get%20alerts%20to%20change%20your%20passwords https://www.bleepingcomputer.com/news/security/chrome-now-automatically-fixes-breached-passwords-on-android/ https://thehackernews.com/2021/05/a-simple-1-click-compromised-password.html https://android-developers.googleblog.com/2021/05/whats-new-in-android-12-beta.html https://blog.google/products/android/android-12-beta/ UK and US CyberSecurity Laws https://www.theverge.com/2021/5/18/22436367/google-io-android-private-computer-core-machine-learning-data-privacy https://www.gov.uk/government/publications/call-for-views-on-supply-chain-cyber-security/call-for-views-on-cyber-security-in-supply-chains-and-managed-service-providers https://www.zdnet.com/article/supply-chain-hacking-attacks-government-eyes-new-rules-to-tighten-security/ https://www.ncsc.gov.uk/collection/caf https://www.bleepingcomputer.com/news/security/us-introduces-bills-to-secure-critical-infrastructure-from-cyber-attacks/ https://homeland.house.gov/imo/media/doc/BILLS-117hr2980ih-Jackson%20Lee.pdf https://homeland.house.gov/imo/media/doc/BILLS-117hr3138ih-Clarke.pdf https://homeland.house.gov/imo/media/doc/BILLS-117hr3223ih-Slotkin.pdf https://homeland.house.gov/imo/media/doc/Pipeline%20Security%20Act%20Text.pdf https://www.tsa.gov/sites/default/files/pipeline_security_guidelines.pdf https://homeland.house.gov/imo/media/doc/BILLS-117hr____-Katko.pdf https://www.theverge.com/2021/5/20/22444515/amy-klobuchar-data-privacy-protection-facebook-state-laws https://www.congress.gov/bill/116th-congress/senate-bill/189/text https://arstechnica.com/tech-policy/2021/05/privacy-bill-would-force-big-tech-to-offer-tracking-opt-out-breach-notices/ 23 Android Apps Exposed Millions https://blog.checkpoint.com/2021/05/20/misconfiguration-of-third-party-cloud-services-exposed-data-of-over-100-million-users/ https://thehackernews.com/2021/05/these-23-android-apps-expose-over.html https://threatpost.com/100m-android-users-cloud-leaks/166372/ https://research.checkpoint.com/2021/mobile-app-developers-misconfiguration-of-third-party-services-leave-personal-data-of-over-100-million-exposed/ https://www.bleepingcomputer.com/news/security/data-of-100-plus-million-android-users-exposed-via-misconfigured-cloud-services/ -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubs Host: Darren Kitchen → https://www.twitter.com/hak5darren Host: Mubix → http://www.twitter.com/mubix -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
The DarkSide ransomware group goes offline, the Apple Find My network could be exploited, and Your WiFi Devices Are Vulnerable to hacks! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins and users. Watch this on youtube: https://youtu.be/Kf-em03N2Fg Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Links: Colonial Pipeline and DarkSide: https://thehackernews.com/2021/05/us-pipeline-ransomware-attackers-go.html https://arstechnica.com/gadgets/2021/05/pipeline-attacker-darkside-suddenly-goes-dark-heres-what-we-know/ https://www.bleepingcomputer.com/news/security/darkside-ransomware-servers-reportedly-seized-operation-shuts-down/ https://thehackernews.com/2021/05/colonial-pipeline-paid-nearly-5-million.html https://www.cnet.com/news/pipeline-hack-update-colonial-reopens-across-the-map-ransomware-payment/ https://www.intel471.com/blog/darkside-ransomware-shut-down-revil-avaddon-cybercrime https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html Apple Find My Network: https://positive.security/blog/send-my https://github.com/seemoo-lab/openhaystack https://threatpost.com/apple-find-my-exploited-bluetooth/166121/ https://github.com/positive-security/send-my https://thehackernews.com/2021/05/apples-find-my-network-can-be-abused-to.html FragAttacks: https://www.fragattacks.com/ https://thehackernews.com/2021/05/nearly-all-wifi-devices-are-vulnerable.html?m=1 https://threatpost.com/fragattacks-wifi-bugs-millions-devices/166080/ https://www.zdnet.com/article/time-to-patch-against-fragattacks-but-good-luck-with-home-routers-and-iot-devices/ Photo credit: https://www.fragattacks.com/images/logo.png -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubs Host: Darren Kitchen → https://www.twitter.com/hak5darren Host: Mubix → http://www.twitter.com/mubix -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
A Qualcomm SoC could be exploited by attackers, the US’s biggest gas pipeline is hit with ransomware, and Apple AirTags get hacked! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins and users. Watch this on youtube: https://youtu.be/QjLvIDWnc3w Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Links: Qualcomm https://research.checkpoint.com/2021/security-probe-of-qualcomm-msm/ https://www.zdnet.com/article/qualcomm-chip-vulnerability-found-in-millions-of-google-samsung-and-lg-phones/ https://www.counterpointresearch.com/mediatek-biggest-smartphone-chipset-vendor-q3-2020/ https://threatpost.com/qualcomm-chip-bug-android-eavesdropping/165934/ https://arstechnica.com/gadgets/2021/05/fix-for-critical-qualcomm-chip-flaw-is-making-its-way-to-android-devices/ Pipeline: https://www.colpipe.com/news/press-releases/media-statement-colonial-pipeline-system-disruption https://threatpost.com/pipeline-crippled-ransomware/165963/ https://www.bleepingcomputer.com/news/security/largest-us-pipeline-shuts-down-operations-after-ransomware-attack/ https://www.wsj.com/articles/cyberattack-forces-closure-of-largest-u-s-refined-fuel-pipeline-11620479737?mod=djemalertNEWS https://www.cnet.com/news/cyberattack-shuts-down-major-us-gas-pipeline-emergency-move-maintains-fuel-supply/ https://www.transportation.gov/briefing-room/us-department-transportations-federal-motor-carrier-administration-issues-temporary https://twitter.com/FBI/status/1391783864016703493 https://twitter.com/darktracer_int/status/1391735232991092738 https://arstechnica.com/information-technology/2021/05/major-ransomware-attack-cripples-gas-pipeline-on-us-east-coast/ https://www.zdnet.com/article/colonial-pipeline-aims-to-restore-operations-by-end-of-the-week-after-cyberattack/ AirTags hack https://www.cnet.com/news/apple-airtags-apparently-hacked-by-security-researcher/ https://9to5mac.com/2021/05/09/airtag-hacked-for-the-first-time-by-security-researcher-video/ https://twitter.com/ghidraninja/status/1391148503196438529 Photo credit: https://bloximages.chicago2.vip.townnews.com/fltimes.com/content/tncms/assets/v3/editorial/b/2e/b2ed107a-2a1c-5ba1-9c7b-92368b3c8a04/6098a24beb180.image.jpg?resize=1200%2C799 -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubs Host: Darren Kitchen → https://www.twitter.com/hak5darren Host: Mubix → http://www.twitter.com/mubix -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
Microsoft finds a bunch of IoT vulnerabilities, a Linux backdoor existed for over two years undetected, and Emotet email addresses are now in have I been pwned! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins and users. Watch this on youtube: https://youtu.be/6d7EN1tbxQY Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Links: BadAlloc: https://msrc-blog.microsoft.com/2021/04/29/badalloc-memory-allocation-vulnerabilities-could-affect-wide-range-of-iot-and-ot-devices-in-industrial-medical-and-enterprise-networks/ https://threatpost.com/microsoft-warns-25-critical-iot-industrial-devices/165752/ https://us-cert.cisa.gov/ics/advisories/icsa-21-119-04 https://www.bleepingcomputer.com/news/security/microsoft-finds-critical-code-execution-bugs-in-iot-ot-devices/ Linux Vulnerabilities: https://www.zdnet.com/article/linux-kernel-vulnerability-exposes-stack-memory/ https://blog.talosintelligence.com/2021/04/vuln-spotlight-linux-kernel.html https://threatpost.com/linux-kernel-bug-wider-cyberattacks/165640/ RotaJakiro: https://blog.netlab.360.com/stealth_rotajakiro_backdoor_en/ https://www.zdnet.com/article/rotajakiro-a-linux-backdoor-that-has-flown-under-the-radar-for-years/ https://www.bleepingcomputer.com/news/security/new-stealthy-linux-malware-used-to-backdoor-systems-for-years/ Emotet: https://www.zdnet.com/article/emotet-botnet-harvested-4-3-million-email-addresses-now-the-fbi-is-using-have-i-been-pwned-to-alert-the-victims/ https://www.bleepingcomputer.com/news/security/emotet-malware-nukes-itself-today-from-all-infected-computers-worldwide/ https://www.troyhunt.com/data-from-the-emotet-malware-is-now-searchable-in-have-i-been-pwned-courtesy-of-the-fbi-and-nhtcu/ https://www.bleepingcomputer.com/news/security/fbi-shares-4-million-email-addresses-used-by-emotet-with-have-i-been-pwned/ Photo credit: https://cdn.pixabay.com/photo/2017/05/17/19/30/linux-2321631_1280.jpg -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubs Host: Darren Kitchen → https://www.twitter.com/hak5darren Host: Mubix → http://www.twitter.com/mubix -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
An Airdrop vulnerability remains unpatched, Signal makes an epic clap back at Cellebrite, and Emotet begins a mass deletion of itself! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins and users. Watch this on youtube: https://youtu.be/6fKv5F3HtXQ Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ Support ThreatWire! https://www.patreon.com/threatwire Links: Apple AirDrop Leak https://gizmodo.com/airdrop-security-flaw-exposes-1-5-billion-apple-devices-1846747548 https://arstechnica.com/gadgets/2021/04/apples-airdrop-leaks-users-pii-and-theres-not-much-they-can-do-about-it/ https://www.cnet.com/news/airdrop-could-be-hacked-to-reveal-personal-information-researchers-suggest/ https://www.usenix.org/system/files/sec21fall-heinrich.pdf https://github.com/seemoo-lab/privatedrop Signal Cellebrite: https://signal.org/blog/cellebrite-vulnerabilities/ https://signal.org/blog/cellebrite-and-clickbait/ https://www.haaretz.com/israel-news/.premium-israeli-phone-hacking-firm-cellebrite-halts-sales-to-russia-after-haaretz-report-1.9633312 https://arstechnica.com/information-technology/2021/04/in-epic-hack-signal-developer-turns-the-tables-on-forensics-firm-cellebrite/ https://www.vice.com/en/article/k78q5y/signal-ceo-hacks-cellebrite-iphone-hacking-device-used-by-cops https://www.zdnet.com/article/signal-rattles-sabre-and-exposes-crackable-cellebrite-underbelly/ https://www.cyberscoop.com/cellebrite-signal-moxie-marlinspike-ufed/ https://www.bleepingcomputer.com/news/security/signal-ceo-gives-mobile-hacking-firm-a-taste-of-being-hacked/ https://www.cellebrite.com/en/cellebrites-new-solution-for-decrypting-the-signal-app/ Emotet: https://www.zdnet.com/article/police-just-delivered-this-killswitch-update-to-finish-off-a-notorious-botnet/ https://www.cyberscoop.com/law-enforcement-emotet-botnet-ransomware/ https://www.bleepingcomputer.com/news/security/emotet-malware-nukes-itself-today-from-all-infected-computers-worldwide/ https://www.bleepingcomputer.com/news/security/emotet-botnet-disrupted-after-global-takedown-operation/ Photo credit: https://www.iphonehacks.com/wp-content/uploads/2017/08/iOS-11-AirDrop-1.jpg -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubs Host: Darren Kitchen → https://www.twitter.com/hak5darren Host: Mubix → http://www.twitter.com/mubix -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
FLoC is being blocked, the US Government hits Russia with sanctions, and the FBI hacks into vulnerable Exchange servers! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins and users. Watch this on youtube: https://youtu.be/38Xa0CV5cDI Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://teespring.com/stores/morsecode Support ThreatWire! https://www.patreon.com/threatwire Links: FLoC Is Being Blocked: https://blog.google/products/ads-commerce/2021-01-privacy-sandbox/ https://github.com/WICG/floc https://www.eff.org/deeplinks/2021/03/googles-floc-terrible-idea https://www.theverge.com/2021/3/30/22358287/privacy-ads-google-chrome-floc-cookies-cookiepocalypse-finger-printing https://www.zdnet.com/article/wordpress-could-treat-google-floc-as-a-security-issue/ https://www.bleepingcomputer.com/news/security/vivaldi-brave-duckduckgo-reject-googles-floc-ad-tracking-tech/ https://www.zdnet.com/article/brave-browser-disables-googles-floc-tracking-system/ https://amifloced.org/ https://chrome.google.com/webstore/detail/duckduckgo-privacy-essent/bkdgflcldnnnapblkhphbgpggdiikppg Russian Sanctions by the US Government: https://www.theverge.com/2021/4/15/22385371/russia-sanctions-solarwinds-biden-white-house-putin-hack https://www.nsa.gov/News-Features/Feature-Stories/Article-View/Article/2573391/russian-foreign-intelligence-service-exploiting-five-publicly-known-vulnerabili/#pop5008885 https://www.whitehouse.gov/briefing-room/statements-releases/2021/04/15/fact-sheet-imposing-costs-for-harmful-foreign-activities-by-the-russian-government/ https://home.treasury.gov/news/press-releases/jy0127 https://www.cyberscoop.com/us-government-accuses-russian-companies-recruiting-spies-hacking/ https://www.cyberscoop.com/biden-russia-solarwinds-sanctions-white-house/ https://twitter.com/NSACyber/status/1382667579458777088 https://threatpost.com/nsa-security-bugs-active-nation-state-cyberattack/165446/ FBI Hacks Into Vulnerable Servers: https://www.bleepingcomputer.com/news/security/fbi-nuked-web-shells-from-hacked-exchange-servers-without-telling-owners/ https://www.justice.gov/usao-sdtx/pr/justice-department-announces-court-authorized-effort-disrupt-exploitation-microsoft https://www.justice.gov/opa/press-release/file/1386631/download https://www.vice.com/en/article/y3dmjg/fbi-removes-web-shells-microsoft-exchange https://www.theverge.com/2021/4/13/22382821/fbi-doj-hafnium-remote-access-removal-hack https://www.cyberscoop.com/fbi-court-order-microsoft-exchange-server-web-shells/ https://threatpost.com/fbi-proxylogon-web-shells/165400/ Photo credit: https://vivaldi.com/wp-content/uploads/Google_FloC_-Vivaldi_browser.png -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubs Host: Darren Kitchen → https://www.twitter.com/hak5darren Host: Mubix → http://www.twitter.com/mubix -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
Facebook downplays the data leak, linkedin appears to be targeted in a similar attack, and Discord and Slack are being used to spread remote access trojans! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins and users. Watch this on youtube: https://youtu.be/mdTnhUJFnno Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://teespring.com/stores/morsecode Support ThreatWire! https://www.patreon.com/threatwire Links: Facebook: https://threatpost.com/facebook-stolen-data-scraped/165285/ https://about.fb.com/news/2021/04/facts-on-news-reports-about-facebook-data/ https://www.vice.com/en/article/88awzp/facebook-says-its-your-fault-that-hackers-got-half-a-billion-user-phone-numbers https://twitter.com/intidc/status/1379498790844039177 https://www.theverge.com/2021/4/7/22372707/facebook-responds-533-million-data-leak-notify-users https://www.bleepingcomputer.com/news/security/have-i-been-pwned-adds-search-for-leaked-facebook-phone-numbers/ https://www.bleepingcomputer.com/news/security/facebook-data-leak-now-under-eu-data-regulator-investigation/ https://www.vice.com/en/article/qj8dj5/facebook-phone-number-data-breach-telegram-bot LinkedIn: https://www.theverge.com/2021/4/8/22374464/linkedin-data-leak-500-million-accounts-scraped-microsoft https://news.linkedin.com/2021/april/an-update-from-linkedin https://threatpost.com/data-500m-linkedin-users-online/165329/ https://www.slashgear.com/hackers-offer-to-sell-information-from-500-million-linkedin-user-accounts-09667691/ https://cybernews.com/personal-data-leak-check/ Discord and Slack: https://blog.talosintelligence.com/2021/04/collab-app-abuse.html https://threatpost.com/discord-stealing-malware-npm-packages/163265/ https://threatpost.com/attackers-discord-slack-malware/165295/ https://www.cyberscoop.com/hackers-discord-slack-file-sharing-malware/ Photo credit: https://www.healio.com/~/media/slack-news/stock-images/infectious-disease/r/rat_face.jpeg -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubs Host: Darren Kitchen → https://www.twitter.com/hak5darren Host: Mubix → http://www.twitter.com/mubix -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
553 Million Users are Affected In the Facebook Leak, No Denial In Ubiquiti Breach, and Why You Shouldn’t Download Video Game Cheat Codes! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins and users. Watch this on youtube: https://youtu.be/LvNjRsIGI24 Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://teespring.com/stores/morsecode Support ThreatWire! https://www.patreon.com/threatwire Links: Facebook: https://www.cnet.com/news/facebook-data-for-over-500m-users-reportedly-leaks-online/ https://twitter.com/UnderTheBreach/status/1349671294808285184 https://www.cyberscoop.com/533-million-facebook-users-leaked-online-fraud-cybercrime/ https://www.theverge.com/2021/4/4/22366822/facebook-personal-data-533-million-leaks-online-email-phone-numbers https://about.fb.com/news/2021/03/more-control-and-context-in-news-feed/ https://twitter.com/troyhunt/status/1378463581604220931 https://www.theverge.com/22367727/facebook-data-breach-haveibeenpwned Ubiquiti: https://www.bleepingcomputer.com/news/security/networking-giant-ubiquiti-alerts-customers-of-potential-data-breach/ https://krebsonsecurity.com/2021/03/whistleblower-ubiquiti-breach-catastrophic/ https://www.theverge.com/2021/3/31/22360409/ubiquiti-networking-data-breach-response-whistleblower-cybersecurity-incident https://community.ui.com/questions/Update-to-January-2021-Account-Notification/3813e6f4-b023-4d62-9e10-1035dc51ad2e https://www.bleepingcomputer.com/news/security/ubiquiti-cyberattack-may-be-far-worse-than-originally-disclosed/ https://arstechnica.com/gadgets/2021/03/ubiquiti-breach-puts-countless-cloud-based-devices-at-risk-of-takeover/ COD: https://research.activision.com/publications/2021/03/cheating-cheaters-malware-delivered-as-call-of-duty-cheats https://www.activision.com/cdn/research/cheating_cheaters_final.pdf https://www.theverge.com/2021/3/31/22360826/call-of-duty-warzone-malware-cheats-hack https://threatpost.com/call-of-duty-cheats-gamers-malware/165209/ Photo credit: https://www.callofduty.com/content/dam/atvi/callofduty/cod-touchui/warzone/social/wz-social-share.jpg -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubs Host: Darren Kitchen → https://www.twitter.com/hak5darren Host: Mubix → http://www.twitter.com/mubix -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
Was Acer just hit with a ransomware attack?, F5 warns customers about multiple critical vulnerabilities, and Microsoft is doing everything they can to get people to patch Exchange vulnerabilities! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins and users. Watch this on youtube: https://youtu.be/zPm8mzd5roI Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://teespring.com/stores/morsecode Support ThreatWire! https://www.patreon.com/threatwire Links: Acer: https://www.zdnet.com/article/acer-reportedly-targeted-with-50-million-ransomware-attack/ https://www.bleepingcomputer.com/news/security/computer-giant-acer-hit-by-50-million-ransomware-attack/ https://www.theverge.com/2021/3/20/22341642/acer-ransomware-microsoft-exchange-revil-security F5: https://arstechnica.com/gadgets/2021/03/to-security-pros-dread-another-critical-server-vulnerability-is-under-exploit/?utm_brand=arstechnica&utm_source=twitter&utm_social-type=owned&utm_medium=social https://support.f5.com/csp/article/K02566623 https://twitter.com/buffaloverflow/status/1372861157317435394 https://twitter.com/Unit42_Intel/status/1373017186818781190 https://threatpost.com/critical-f5-big-ip-flaw-now-under-active-attack/164940/ https://us-cert.cisa.gov/ncas/current-activity/2021/03/10/f5-security-advisory-rce-vulnerabilities-big-ip-big-iq https://www.cyberscoop.com/f5-networks-big-ip-exploit-vulnerability/ Exchange updates: https://www.zdnet.com/article/microsoft-exchange-server-these-quarterly-updates-include-fixes-for-security-flaws/ https://blog.f-secure.com/microsoft-exchange-proxylogon/ https://www.bleepingcomputer.com/news/security/microsoft-exchange-servers-now-targeted-by-black-kingdom-ransomware/ https://mspoweruser.com/microsoft-defender-antivirus-will-now-automatically-mitigate-on-premises-exchange-server-vulnerabilities/ https://msrc-blog.microsoft.com/2021/03/15/one-click-microsoft-exchange-on-premises-mitigation-tool-march-2021/ Photo credit: https://live.staticflickr.com/7597/16862138042_539eb9d413_b.jpg Youtube thumbnail title: $50 Mil Ransomware! -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubs Host: Darren Kitchen → https://www.twitter.com/hak5darren Host: Mubix → http://www.twitter.com/mubix -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
Thousands of surveillance cameras were hacked, Molson Coors breweries were attacked, and we’ve got a bunch of updates to the Windows Exchange vulnerabilities! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins and users. Watch this on youtube: https://youtu.be/gF4XAw6xbKE Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://teespring.com/stores/morsecode Support ThreatWire! https://www.patreon.com/threatwire Links: Verkada Cameras Hacked: https://arstechnica.com/information-technology/2021/03/hackers-access-security-cameras-inside-cloudflare-jails-and-hospitals/ https://www.cnet.com/roadshow/news/tesla-factory-cameras-hacked/ https://www.theverge.com/2021/3/9/22322122/verkada-hack-150000-security-cameras-tesla-factory-cloudflare-jails-hospitals https://threatpost.com/breach-verkada-security-camera-tesla-cloudflare/164635/ https://www.theverge.com/2021/3/11/22324876/surveillance-camera-firm-verkada-breached-hacked-super-admin-access-employees https://www.zdnet.com/article/verkada-disables-accounts-after-reports-its-security-cameras-were-breached/ https://www.cyberscoop.com/verkada-tillie-kottmann-raid-switzerland/ https://www.theverge.com/2021/3/12/22328344/tillie-kottmann-hacker-raid-switzerland-verkada-cameras Molson Coors Cyberattack: http://d18rn0p25nwr6d.cloudfront.net/CIK-0000024545/7884b842-2ea4-4831-ab2f-5d30b06d612a.pdf https://threatpost.com/molson-coors-cyberattack-investigation/164722/ https://www.cyberscoop.com/molson-coors-hack-ransomware-beer-brewing/ https://www.bleepingcomputer.com/news/security/molson-coors-brewing-operations-disrupted-by-cyberattack/ Microsoft Exchange Vulnerabilities Updates: https://www.cyberscoop.com/microsoft-exchange-china-exploitation-eset/ https://www.bleepingcomputer.com/news/security/more-hacking-groups-join-microsoft-exchange-attack-frenzy/ https://www.bleepingcomputer.com/news/security/norway-parliament-data-stolen-in-microsoft-exchange-attack/ https://arstechnica.com/gadgets/2021/03/security-unicorn-exchange-server-0-days-were-exploited-by-6-apts/ https://www.cyberscoop.com/microsoft-exchange-server-china-dhs-cyber/ https://www.bleepingcomputer.com/news/security/ransomware-now-attacks-microsoft-exchange-servers-with-proxylogon-exploits/ https://www.bleepingcomputer.com/news/security/microsoft-exchange-exploits-now-used-by-cryptomining-malware/ https://arstechnica.com/gadgets/2021/03/critics-fume-after-github-removes-exploit-code-for-exchange-vulnerabilities/ https://www.cyberscoop.com/github-exploit-exchange-server-microsoft/ https://docs.github.com/en/github/site-policy/github-community-guidelines https://www.zdnet.com/article/microsoft-exchange-server-hacks-doubling-every-two-hours/ Photo credit: Verkada Youtube thumbnail title: Surveillance Cameras Hacked -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubs Host: Darren Kitchen → https://www.twitter.com/hak5darren Host: Mubix → http://www.twitter.com/mubix -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
Microsoft Exchange has zero days - make sure to update!, 3 new malware strains related to SolarWinds were found, and passenger data for multiple airlines were compromised in a breach! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins and users. Watch this on youtube: https://youtu.be/NzmvkeEbp6I Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://teespring.com/stores/morsecode Support ThreatWire! https://www.patreon.com/threatwire Links: 0:00 Welcome! Microsoft Exchange https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/ https://arstechnica.com/information-technology/2021/03/microsoft-issues-emergency-patches-for-4-exploited-0days-in-exchange/ https://blogs.microsoft.com/on-the-issues/2021/03/02/new-nation-state-cyberattacks/ https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/ https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server/ https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26855 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26857 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26858 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-27065 https://support.microsoft.com/en-us/topic/description-of-the-security-update-for-microsoft-exchange-server-2019-2016-and-2013-march-2-2021-kb5000871-9800a6bb-0a21-4ee7-b9da-fa85b3e1d23b https://www.bleepingcomputer.com/news/security/microsoft-fixes-actively-exploited-exchange-zero-day-bugs-patch-now/ https://github.com/GossiTheDog/scanning/blob/main/http-vuln-exchange.nse https://threatpost.com/microsoft-exchange-zero-day-attackers-spy/164438/ https://www.bleepingcomputer.com/news/security/state-hackers-rush-to-exploit-unpatched-microsoft-exchange-servers/ https://www.zdnet.com/article/update-immediately-microsoft-rushes-out-patches-for-exchange-server-zero-day-attacks/ https://www.cyberscoop.com/dhs-microsoft-exchange-flaws-patch-china/ https://cyber.dhs.gov/ed/21-02/ https://www.cnet.com/news/microsoft-exchange-attackers-strike-more-than-30000-us-organizations/ https://twitter.com/C_C_Krebs/status/1368004411545579525 https://www.cyberscoop.com/microsoft-exchange-server-czech-republic-norway-hafnium-chinese-hackers/ https://www.cyberscoop.com/exchange-server-microsoft-hacks-china-biden/ SolarWinds malware strains - 3 new ones https://www.cyberscoop.com/white-house-executive-order-software-solarwinds-neuberger/ https://www.microsoft.com/security/blog/2021/03/04/goldmax-goldfinder-sibot-analyzing-nobelium-malware/ https://www.bleepingcomputer.com/news/security/microsoft-reveals-3-new-malware-strains-used-by-solarwinds-hackers/ https://www.cyberscoop.com/researchers-uncover-four-more-malware-strains-linked-to-solarwinds-hackers/ https://www.fireeye.com/blog/threat-research/2021/03/sunshuttle-second-stage-backdoor-targeting-us-based-entity.html SITA https://threatpost.com/supply-chain-cyberattack-airlines/164549/ https://www.bleepingcomputer.com/news/security/sita-data-breach-affects-millions-of-travelers-from-major-airlines/ https://www.sita.aero/pressroom/news-releases/sita-statement-about-security-incident/ https://www.zdnet.com/article/singapore-airlines-frequent-flyer-members-hit-in-third-party-data-security-breach/ https://www.singaporeair.com/en_UK/sg/media-centre/news-alert/?id=kltm93p0 Photo credit: https://www.windowsmanagementexperts.com/wp-content/uploads/2020/11/Microsoft-building-.jpg -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubs Host: Darren Kitchen → https://www.twitter.com/hak5darren Host: Mubix → http://www.twitter.com/mubix -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
VMware Has a Severe Vulnerability, Microsoft Open Sources Their Malicious Code Hunter, and Yet Another Reason To Leave LastPass! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins and users. Watch this on youtube: https://youtu.be/qvZX5AuBxxo Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://teespring.com/stores/morsecode Support ThreatWire! https://www.patreon.com/threatwire Links: 0:00 Welcome! https://threatpost.com/vmware-patches-critical-rce-flaw-in-vcenter-server/164240/ https://www.vmware.com/security/advisories/VMSA-2021-0002.html http://noahblog.360.cn/vcenter-6-5-7-0-rce-lou-dong-fen-xi/ https://github.com/QmF0c3UK/CVE-2021-21972-vCenter-6.5-7.0-RCE-POC https://www.zdnet.com/article/more-than-6700-vmware-servers-exposed-online-and-vulnerable-to-major-new-bug/ https://arstechnica.com/information-technology/2021/02/armed-with-exploits-hackers-on-the-prowl-for-a-critical-vmware-vulnerability/ https://swarm.ptsecurity.com/unauth-rce-vmware/ https://www.cyberscoop.com/solarwinds-fireeye-microsoft-crowdstrike-senate-ssci/ https://www.washingtonpost.com/national-security/biden-russia-sanctions-solarwinds-hacks/2021/02/23/b77039d6-71fa-11eb-85fa-e0ccb3660358_story.html https://www.cyberscoop.com/solarwinds-sudhakar-ramakrishna-ceo-hack/ https://www.bleepingcomputer.com/news/security/nasa-and-the-faa-were-also-breached-by-the-solarwinds-hackers/ https://www.bleepingcomputer.com/news/microsoft/microsoft-solarwinds-hackers-downloaded-some-azure-exchange-source-code/ https://www.microsoft.com/security/blog/2021/02/25/microsoft-open-sources-codeql-queries-used-to-hunt-for-solorigate-activity/ https://www.cyberscoop.com/microsoft-solarwinds-breach-compromise-open-source-codeql/ https://www.bleepingcomputer.com/news/security/microsoft-shares-codeql-queries-to-scan-code-for-solarwinds-like-implants/ https://www.kuketz-blog.de/lastpass-android-drittanbieter-ueberwachen-jeden-schritt/ https://reports.exodus-privacy.eu.org/en/reports/165465/ https://www.theverge.com/2021/2/26/22302709/lastpass-android-app-trackers-security-research-privacy https://www.theregister.com/2021/02/25/lastpass_android_trackers_found/ https://www.theregister.com/2021/02/16/lastpass_pricing_changes/ Photo credit: https://blog.lastpass.com/wp-content/uploads/sites/20/2020/04/android-blog-tips-2.png -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubs Host: Darren Kitchen → https://www.twitter.com/hak5darren Host: Mubix → http://www.twitter.com/mubix -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
Clubhouse uses Agora, and audio data was leaked by a user, Apple’s new M1 Chip already has malware designed for it, and the Brave Browser Leaked Tor Addresses! All that coming up now on ThreatWire. #threatwire #hak5 Links: Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins and users. Watch this on youtube: https://youtu.be/yu4ujL-7G6Q Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://teespring.com/stores/morsecode Support ThreatWire! https://www.patreon.com/threatwire Links: 0:00 Welcome! Agora SDK Bug & Clubhouse https://www.mcafee.com/blogs/other-blogs/mcafee-labs/dont-call-us-well-call-you-mcafee-atr-finds-vulnerability-in-agora-video-sdk/ https://threatpost.com/sdk-bug-spy-calls-dating-healthcare-apps/164068/ https://thehackernews.com/2021/02/agora-sdk-bug-left-several-video.html https://www.cyberscoop.com/flaw-agora-video-calling-software-eavesdroppers/ https://docs.agora.io/en/Agora%20Platform/security_practice?platform=Android https://www.theverge.com/2021/2/14/22282772/clubhouse-improve-security-stanford-researchers-china-security https://twitter.com/stanfordio/status/1360423156356325377 https://www.theverge.com/2021/2/22/22294938/clubhouse-audio-data-siphon-vulnerability-ios-app https://www.bloomberg.com/news/articles/2021-02-22/clubhouse-chats-are-breached-raising-concerns-over-security Apple M1 Malware https://objective-see.com/blog/blog_0x62.html https://www.virustotal.com/gui/file/b94e5666d0afc1fa49923c7a7faaa664f51f0581ec0192a08218d68fb079f3cf/detection https://9to5mac.com/2021/02/17/first-apple-silicon-optimized-malware/ https://threatpost.com/macos-malware-apple-m1-processor/164075/ https://support.apple.com/guide/security/welcome/web https://threatpost.com/apple-2021-platform-security-guide/164094/ Brave Browser https://www.bleepingcomputer.com/news/security/brave-privacy-bug-exposes-tor-onion-urls-to-your-dns-provider/ https://github.com/brave/brave-core/pull/7769 https://www.zdnet.com/article/brave-browser-leaks-onion-addresses-in-dns-traffic/ https://twitter.com/bcrypt/status/1362796915063021569 v -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆ Our Site → https://www.hak5.org Shop → http://hakshop.myshopify.com/ Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1 Support → https://www.patreon.com/threatwire Contact Us → http://www.twitter.com/hak5 Threat Wire RSS → https://shannonmorse.podbean.com/feed/ Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubs Host: Darren Kitchen → https://www.twitter.com/hak5darren Host: Mubix → http://www.twitter.com/mubix -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
Morse Code is being used for phishing attacks, Signal responds to their ban in Iran, and Chrome has a zero day vulnerability! All that coming up now on ThreatWire. #threatwire #hak5 Links:Weekly security and privacy news, brought to you by Shannon Morse. ThreatWire is a weekly news journalism show covering security and privacy topics for network admins and users. Watch this on youtube: https://youtu.be/iEgAPexXRPI Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://teespring.com/stores/morsecode Support ThreatWire! https://www.patreon.com/threatwire Links:0:00 Welcome! Morse Code:https://www.bleepingcomputer.com/news/security/new-phishing-attack-uses-morse-code-to-hide-malicious-urls/https://www.itproportal.com/news/new-phishing-scam-uses-morse-code-to-conceal-malicious-links/ Signal Proxy TLS Vuln:https://signal.org/blog/help-iran-reconnect/https://twitter.com/signalapp/status/1353839763388649473https://www.rferl.org/a/iran-deems-signal-criminal-content-removes-from-local-app-stores/31048089.htmlhttps://www.cyberscoop.com/signal-iran-encryption-ban-app/https://www.bleepingcomputer.com/news/security/removal-notice-for-signal-article/https://twitter.com/moxie/status/1358588649919549440https://twitter.com/search?q=%23IRanASignalProxy&src=typed_query Chromehttps://threatpost.com/google-chrome-zero-day-windows-mac/163688/https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop_4.htmlhttps://blog.google/threat-analysis-group/new-campaign-targeting-security-researchers/https://www.zdnet.com/article/google-chrome-syncing-features-can-be-abused-for-c-c-and-data-exfiltration/https://thehackernews.com/2021/02/warning-hugely-popular-great-suspender.htmlhttps://arstechnica.com/information-technology/2021/02/chrome-users-have-faced-3-security-concerns-over-the-past-24-hours/chrome://settings/safetyCheck Photo credit:https://i.ytimg.com/vi/RNhinA8ajoI/maxresdefault.jpg -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆Our Site → https://www.hak5.orgShop → http://hakshop.myshopify.com/Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1Support → https://www.patreon.com/threatwireContact Us → http://www.twitter.com/hak5Threat Wire RSS → https://shannonmorse.podbean.com/feed/Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubsHost: Darren Kitchen → https://www.twitter.com/hak5darrenHost: Mubix → http://www.twitter.com/mubix-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
A flaw was found in libgcrypt, the notorious Emotet Is sinkholed by police, and Apple makes a slew of security updates! All that coming up now on ThreatWire. #threatwire #hak5 Links:Weekly security and privacy news, brought to you by Shannon Morse. Watch this on youtube: https://youtu.be/F-nYtHFgDSA Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://teespring.com/stores/morsecode Support ThreatWire! https://www.patreon.com/threatwire Links:0:00 Welcome! Libgcrypt:https://bugs.chromium.org/p/project-zero/issues/detail?id=2145https://thehackernews.com/2021/01/google-discloses-severe-bug-in.htmlhttps://threatpost.com/critical-libgcrypt-crypto-bug-arbitrary-code/163546/https://gnupg.org/download/index.htmlhttps://www.zdnet.com/article/libgcrypt-developers-release-urgent-update-to-tackle-severe-vulnerability/ Emotet:https://www.cyberscoop.com/emotet-europol-us-ukraine-takedown-botnet/https://threatpost.com/emotet-takedown-infrastructure-netwalker-offline/163389/https://www.zdnet.com/article/authorities-plan-to-mass-uninstall-emotet-from-infected-hosts-on-april-25-2021/https://www.youtube.com/watch?v=_BLOmClsSpchttps://www.npu.gov.ua/news/kiberzlochini/kiberpolicziya-vikrila-transnaczionalne-ugrupovannya-xakeriv-u-rozpovsyudzhenni-najnebezpechnishogo-v-sviti-komp-yuternogo-virusu-EMOTET/https://www.europol.europa.eu/newsroom/news/world%E2%80%99s-most-dangerous-malware-emotet-disrupted-through-global-actionhttps://www.politie.nl/nieuws/2021/januari/27/11-internationale-politieoperatie-ladybird-botnet-emotet-wereldwijd-ontmanteld.htmlhttps://www.zdnet.com/article/emotet-worlds-most-dangerous-malware-botnet-disrupted-by-international-police-operation/https://www.politie.nl/themas/controleer-of-mijn-inloggegevens-zijn-gestolen.html#englishhttps://thehackernews.com/2021/01/european-authorities-disrupt-emotet.html Apple:https://thehackernews.com/2021/01/google-uncovers-new-ios-security.htmlhttps://threatpost.com/apple-ios-imessage-blastdoor/163479/https://thehackernews.com/2021/01/apple-warns-of-3-ios-zero-day-security.htmlhttps://threatpost.com/apple-patches-zero-days-ios-emergency-update/163374/https://www.theverge.com/2021/1/28/22253366/apple-app-tracking-transparency-opt-in-requirement-beta-launchhttps://www.theverge.com/2021/2/1/22260274/facebook-prompt-apple-ios-ad-tracking-opt-in-permission-privacy-updatehttps://blog.google/products/ads-commerce/preparing-developers-and-advertisers-for-policy-updates/ Photo credit:Apple -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆Our Site → https://www.hak5.orgShop → http://hakshop.myshopify.com/Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1Support → https://www.patreon.com/threatwireContact Us → http://www.twitter.com/hak5Threat Wire RSS → https://shannonmorse.podbean.com/feed/Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubsHost: Darren Kitchen → https://www.twitter.com/hak5darrenHost: Mubix → http://www.twitter.com/mubix-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
Kindles could be hacked using e-books, the DIA collects location data without a warrant, and an ADT tech was spying on couples! All that coming up now on ThreatWire. #threatwire #hak5 Weekly security and privacy news, brought to you by Shannon Morse. Watch this on youtube: https://youtu.be/V-wJkmmGMXU Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://teespring.com/stores/morsecode Support ThreatWire! https://www.patreon.com/threatwire Links:0:00 Welcome! Kindle Ebook Email Hack Allows Attackers to Hijack Accounts:https://medium.com/realmodelabs/kindledrip-from-your-kindles-email-address-to-using-your-credit-card-bb93dbfb2a08 https://thehackernews.com/2021/01/sharing-ebook-with-your-kindle-could.htmlhttps://threatpost.com/amazon-kindle-attack-email/163282/https://www.vice.com/en/article/93wgzy/bugs-allowed-hackers-to-hack-kindle-accounts-with-malicious-ebooks DIA Bought Cell Phone Location Data Without Warrants:https://int.nyt.com/data/documenttools/dia-memo-for-wyden-on-commercially-available-smartphone-locational-data/d7d41dccdd1d46b0/full.pdf https://www.cnet.com/news/intelligence-agency-buys-location-data-on-us-residents-without-warrants/ https://www.cyberscoop.com/phone-location-data-privacy-dia-dhs/ https://www.theverge.com/2021/1/22/22244848/us-intelligence-memo-admits-buying-smartphone-location-data ADT Tech Spies On Couples and Women:https://www.justice.gov/usao-ndtx/pr/adt-technician-pleads-guilty-hacking-home-security-footage https://www.cyberscoop.com/adt-technician-aviles-spying-women/https://threatpost.com/adt-hacks-home-security-cameras/163271/ https://arstechnica.com/information-technology/2021/01/home-alarm-tech-backdoored-security-cameras-to-spy-on-customers-having-sex/ Photo credit:https://cdn.pixabay.com/photo/2016/08/01/09/53/kindle-update-1560728_1280.jpg -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆Our Site → https://www.hak5.orgShop → http://hakshop.myshopify.com/Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1Support → https://www.patreon.com/threatwireContact Us → http://www.twitter.com/hak5Threat Wire RSS → https://shannonmorse.podbean.com/feed/Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubsHost: Darren Kitchen → https://www.twitter.com/hak5darrenHost: Mubix → http://www.twitter.com/mubix-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
Ring Adds E2E Encryption, Ubiquiti Suffers A Data Breach, and the EMA Leak Shows Up On the Dark Web! All that coming up now on ThreatWire. #threatwire #hak5 Links:Weekly security and privacy news, brought to you by Shannon Morse. Host: Shannon Morse → https://www.twitter.com/snubs Threat Wire RSS → https://shannonmorse.podbean.com/feed/Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Watch this on youtube: https://youtu.be/W3MB9PdSpBM Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://teespring.com/stores/morsecode Support ThreatWire! https://www.patreon.com/threatwire Links:0:00 Welcome! Why you didn’t see ThreatWire last week Ring Adds E2EE:https://techcrunch.com/2021/01/14/ring-neighbors-exposed-locations-addresses/https://threatpost.com/ring-adds-end-to-end-encryption-to-quell-security-uproar/163042/https://assets.ctfassets.net/a3peezndovsu/5jmqFoKyaCXpL2qBG46Zqn/72d138d896e7460c5bdae07992ad491e/Ring_Encryption_Whitepaper.pdfhttps://www.zdnet.com/article/ring-trials-customer-video-end-to-end-encryption/ Ubiquiti Data Breach:https://www.zdnet.com/article/ubiquiti-tells-customers-to-change-passwords-after-security-breach/https://www.theverge.com/2021/1/11/22226061/ubiquiti-data-breach-email-third-party-unathorized-accesshttps://krebsonsecurity.com/2021/01/ubiquiti-change-your-password-enable-2fa/ Vaccine Data Leak:https://threatpost.com/hackers-leak-pfizer-covid-19-vaccine-data/163008/https://www.ema.europa.eu/en/news/cyberattack-ema-update-4https://www.ema.europa.eu/en/news/cyberattack-ema-update-5https://www.yarix.com/news/documenti-riservati-di-ema-sul-vaccino-pfizer-trovati-nel-dark-web/https://arstechnica.com/information-technology/2021/01/hackers-alter-stolen-regulatory-data-to-sow-mistrust-in-covid-19-vaccine/ Photo credit:https://cdn.pocket-lint.com/r/s/1200x630/assets/images/142320-smart-home-review-ring-video-doorbell-2-image1-uar8mu7stn.jpg -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆Our Site → https://www.hak5.orgShop → http://hakshop.myshopify.com/Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1Support → https://www.patreon.com/threatwireContact Us → http://www.twitter.com/hak5 Host: Darren Kitchen → https://www.twitter.com/hak5darrenHost: Mubix → http://www.twitter.com/mubix-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
Cloning Google Titan 2fa keys, facial recognition is being used to identify rioters, and a SolarWinds update! All that coming up now on ThreatWire. #threatwire #hak5 Links: Watch this on youtube: [no link] Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://teespring.com/stores/morsecode Support ThreatWire! https://www.patreon.com/threatwire Links: 0:00 Welcome! Cloning Titan Security Keys https://thehackernews.com/2021/01/new-attack-could-let-hackers-clone-your.html https://ninjalab.io/a-side-journey-to-titan/ https://ninjalab.io/wp-content/uploads/2021/01/a_side_journey_to_titan.pdf https://www.androidpolice.com/2021/01/08/googles-2fa-titan-security-keys-are-vulnerable-to-an-attack-that-can-clone-them/ https://www.zdnet.com/article/should-you-worry-about-hackers-cloning-your-2fa-hardware-security-keys/ Facial Recognition at Capitol Hill https://www.zdnet.com/article/capitol-attacks-cybersecurity-fallout-stolen-laptops-lost-data-and-possible-espionage/ https://www.vice.com/en/article/qjpwam/rioters-had-physical-access-to-lawmakers-computers-how-bad-is-that https://www.cyberscoop.com/capitol-hill-unrest-trump-cybersecurity/ https://www.theverge.com/2021/1/9/22222200/social-media-telco-urged-preserve-evidence-capitol-attack-twitter-facebook-google-verizon-apple https://cdn.vox-cdn.com/uploads/chorus_asset/file/22224462/capitol_attack_twitter.pdf https://www.theverge.com/2021/1/10/22223349/clearview-ai-facial-recognition-law-enforcement-capitol-rioters https://www.washingtonpost.com/technology/2021/01/08/trump-mob-tech-arrests/ SolarWinds Update https://theintercept.com/2020/12/24/solarwinds-hack-power-infrastructure/ https://www.cisa.gov/news/2021/01/05/joint-statement-federal-bureau-investigation-fbi-cybersecurity-and-infrastructure https://www.cyberscoop.com/solarwinds-fbi-dhs-russia-biden-trump/ https://arstechnica.com/information-technology/2021/01/doj-says-solarwinds-hackers-breached-its-office-365-system-and-read-email/ https://www.theverge.com/2021/1/7/22219275/federal-judiciary-system-further-securing-sealed-documents-solarwinds-hack https://securelist.com/sunburst-backdoor-kazuar/99981/ https://www.cyberscoop.com/solarwinds-chris-krebs-alex-stamos/ https://www.cyberscoop.com/solarwinds-cisa-brandon-wales-russia/ Photo credit: https://images.newscientist.com/wp-content/uploads/2017/10/16104524/1m7.3-flare.jpg
The top 10 biggest hacks of 2020! Coming up now on ThreatWire. #threatwire #hak5 Links:Watch this on youtube: https://youtu.be/5pxpomAgd5Y Support me on alternative platforms! https://snubsie.com/support Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://teespring.com/stores/morsecode Join now to support ThreatWire! https://www.patreon.com/threatwire Links:MGM resorts - 2019 breach - 142 millionhttps://www.zdnet.com/article/a-hacker-is-selling-details-of-142-million-mgm-hotel-guests-on-the-dark-web/ Pakistani mobile users - 44million - Mayhttps://www.zdnet.com/article/details-of-44m-pakistani-mobile-users-leaked-online-part-of-bigger-115m-cache/ Wishbone - May - 40 millionhttps://cybleinc.com/2020/05/20/large-database-of-wishbone-posted-for-sale-online-sensitive-data-for-sale/ Wawa - January - 30 millionhttps://www.zdnet.com/article/wawa-card-breach-may-rank-as-one-of-the-biggest-of-all-times/ CouchSurfing - July - 17 millionhttps://www.zdnet.com/article/couchsurfing-investigates-data-breach-after-17m-user-records-appear-on-hacking-forum/ EasyJet - May - 9 million customershttps://www.bbc.com/news/technology-52722626#:~:text=EasyJethttps://www.bbc.com/news/technology-52722626#:~:text=EasyJet Marriott - March - 5.2 million guestshttps://news.marriott.com/news/2020/03/31/marriott-international-notifies-guests-of-property-system-incident BlueLeak - June - over 200 state, local, and fed agencieshttps://www.wired.com/story/blueleaks-anonymous-law-enforcement-hack/ COVID-19 Attackshttps://www.zdnet.com/article/first-death-reported-following-a-ransomware-attack-on-a-german-hospital/ https://www.bbc.com/news/technology-55165552https://www.zdnet.com/article/roundup-the-coronavirus-pandemic-delivers-an-array-of-cyber-security-challenges/https://www.zdnet.com/article/cybersecurity-one-in-three-attacks-are-coronavirus-related/https://www.csoonline.com/article/3584759/the-covid-19-pandemic-has-become-a-catalyst-for-cyberattacks.html SolarWindshttps://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html Photo credit:https://cdn.pixabay.com/photo/2019/09/19/05/38/happy-4488255_1280.jpg -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆Our Site → https://www.hak5.orgShop → http://hakshop.myshopify.com/Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1Support → https://www.patreon.com/threatwireContact Us → http://www.twitter.com/hak5Threat Wire RSS → https://shannonmorse.podbean.com/feed/Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubsHost: Darren Kitchen → https://www.twitter.com/hak5darrenHost: Mubix → http://www.twitter.com/mubix-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
Malware hits four popular browsers, the EMA Breach Affects COVID-19 Vaccine Firms, and SolarWinds. Yes. SolarWinds! All that coming up now on ThreatWire. #threatwire #hak5 Watch this on youtube: https://youtu.be/JkdHmqnxuZ8 Send me a Christma s card (if ya want!)! https://snubsie.com/contact Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://teespring.com/stores/morsecode Support ThreatWire! https://www.patreon.com/threatwire Links:Adrozek:https://www.microsoft.com/security/blog/2020/12/10/widespread-malware-campaign-seeks-to-silently-inject-ads-into-search-results-affects-multiple-browsers/https://arstechnica.com/information-technology/2020/12/ongoing-malware-attacks-are-hitting-users-of-4-major-browsers/https://threatpost.com/adrozek-malware-fake-ads-30k-devices/162217/ EMA:https://www.ema.europa.eu/en/news/cyberattack-european-medicines-agencyhttps://arstechnica.com/information-technology/2020/12/hackers-unlawfully-access-data-related-to-promising-covid-19-vaccines/https://investors.biontech.de/news-releases/news-release-details/statement-regarding-cyber-attack-european-medicines-agencyhttps://threatpost.com/pfizer-covid-19-vaccine-cyberattack/162170/ SolarWindshttps://www.cyberscoop.com/fireeye-says-hackers-stole-its-red-team-tools-suggests-state-sponsored-group-is-to-blame/https://www.solarwinds.com/solutions/orionhttps://www.zdnet.com/article/sec-filings-solarwinds-says-18000-customers-are-impacted-by-recent-hack/https://www.cyberscoop.com/russian-hacking-treasury-commerce-fireeye/https://www.reuters.com/article/global-cyber-idUSKBN28O26Xhttps://www.reuters.com/article/us-usa-cyber-amazon-com-exclsuive-idUSKBN28N0PGhttps://www.theverge.com/2020/12/9/22165027/fireeye-cybersecurity-attack-red-team-toolshttps://www.fireeye.com/blog/products-and-services/2020/12/global-intrusion-campaign-leverages-software-supply-chain-compromise.htmlhttps://github.com/fireeye/sunburst_countermeasureshttps://msrc-blog.microsoft.com/2020/12/13/customer-guidance-on-recent-nation-state-cyber-attacks/https://threatpost.com/dhs-sophisticated-cyberattack-foreign-adversaries/162242/https://arstechnica.com/information-technology/2020/12/russian-hackers-hit-us-government-using-widespread-supply-chain-attack/https://www.zdnet.com/article/microsoft-fireeye-confirm-solarwinds-supply-chain-attack/https://www.solarwinds.com/securityadvisoryhttps://twitter.com/k8em0/status/1338619172079603712 Photo credit:https://pixy.org/src2/594/5942346.jpghttps://upload.wikimedia.org/wikipedia/commons/e/e3/Magnificent_CME_Erupts_on_the_Sun_-_August_31.jpg -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆Our Site → https://www.hak5.orgShop → http://hakshop.myshopify.com/Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1Support → https://www.patreon.com/threatwireContact Us → http://www.twitter.com/hak5Threat Wire RSS → https://shannonmorse.podbean.com/feed/Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubsHost: Darren Kitchen → https://www.twitter.com/hak5darrenHost: Mubix → http://www.twitter.com/mubix-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
This epic iphone hack is like WatchDogs but in RL, TrickBot could now brick devices, and attackers are targeting covid-19 vaccine distribution firms! All that coming up now on ThreatWire. #threatwire #hak5 LinksWatch this on youtube: https://youtu.be/MwGyz8UFCrs Support me on alternative platforms! https://snubsie.com/support Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://teespring.com/stores/morsecode (Use the coupon code TURKEY for 15% off til Dec 10!) Join now for a limited edition signed Christmas Card and to support ThreatWire! https://www.patreon.com/threatwire Links:Iphone hackhttps://www.theverge.com/2020/12/1/21877603/apple-iphone-remote-hack-awdl-google-project-zerohttps://www.vice.com/en/article/4ad3jm/watch-google-hacker-ha-26-iphones-with-zero-day-exploithttps://googleprojectzero.blogspot.com/2020/12/an-ios-zero-click-radio-proximity.htmlhttps://www.cyberscoop.com/iphone-takeover-apple-hack-ios-ian-beer-google/https://www.youtube.com/watch?v=_sTw7GGoJ6ghttps://arstechnica.com/gadgets/2020/12/iphone-zero-click-wi-fi-exploit-is-one-of-the-most-breathtaking-hacks-ever/https://www.cnet.com/news/google-researcher-demonstrates-iphone-exploit-with-wi-fi-takeover/https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-3843 Trickbot:https://www.cyberscoop.com/trickbot-status-microsoft-cyber-command-takedown/https://arstechnica.com/information-technology/2020/12/dangerous-uefi-malware-is-rare-a-botnet-called-trickbot-may-change-that/https://threatpost.com/trickbot-returns-bootkit-functions/161873/https://www.cyberscoop.com/trickbot-firmware-vulnerability-detection-ability-eclypsium-bricking-devices/ Covid19:https://securityintelligence.com/posts/ibm-uncovers-global-phishing-covid-19-vaccine-cold-chain/https://www.cyberscoop.com/coronavirus-vaccine-hacking-ibm/https://arstechnica.com/information-technology/2020/12/covid-vaccine-supply-chain-targeted-by-hackers-say-security-experts/https://www.cnet.com/news/hackers-are-going-after-covid-19-vaccines-rollout/https://threatpost.com/attacks-covid-cold-chain-orgs/161838/ Photo credit:https://www.gannett-cdn.com/-mm-/70b4cd59be29df8697308165711948ed641c0add/c=0-111-2119-1303/local/-/media/2020/09/10/USATODAY/usatsports/coronavirus-vaccine-bottles.jpg -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆Our Site → https://www.hak5.orgShop → http://hakshop.myshopify.com/Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1Support → https://www.patreon.com/threatwireContact Us → http://www.twitter.com/hak5Threat Wire RSS → https://shannonmorse.podbean.com/feed/Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubsHost: Darren Kitchen → https://www.twitter.com/hak5darrenHost: Mubix → http://www.twitter.com/mubix-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
A severe MobileIron flaw was discovered, Google’s Messages app will soon be end to end encrypted, and Teslas can be hacked (again!)! All that coming up now on ThreatWire. #threatwire #hak5 Links:Watch this on youtube: https://youtu.be/LxqNnKsQUeI Support me on alternative platforms! https://snubsie.com/support Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://teespring.com/stores/morsecode Join now for access to extra perks and to support ThreatWire! https://www.patreon.com/threatwire Links:https://www.ncsc.gov.uk/news/alert-multiple-actors-attempt-exploit-mobileiron-vulnerabilityhttps://www.mobileiron.com/enhttps://threatpost.com/critical-mobileiron-rce-flaw-attack/161600/https://www.zdnet.com/article/this-software-flaw-is-being-used-to-break-into-networks-now-so-update-fast/https://us-cert.cisa.gov/ncas/alerts/aa20-283a https://blog.google/products/messages/helping-you-connect-around-world-messages/https://www.cyberscoop.com/android-encryption-phones-google-rcs-messaging/https://www.theverge.com/2020/11/19/21574451/android-rcs-encryption-message-end-to-end-betahttps://www.gstatic.com/messages/papers/messages_e2ee.pdfhttps://www.zdnet.com/article/google-is-adding-end-to-end-encryption-to-android-messages-app/ https://www.imec-int.com/en/press/belgian-security-researchers-ku-leuven-and-imec-demonstrate-serious-flaws-tesla-model-xhttps://www.cnet.com/roadshow/news/tesla-model-x-bluetooth-hack-theft/https://threatpost.com/tesla-hacked-stolen-key-fob/161530/https://www.zdnet.com/article/tesla-model-x-hacked-and-stolen-in-minutes-using-new-key-fob-hack/ Photo credit:https://tesla-cdn.thron.com/delivery/public/image/tesla/efbb6471-e1b8-4533-b41a-6df9d50c0a42/bvlatuR/std/0x0/performance-hero@2 -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆Our Site → https://www.hak5.orgShop → http://hakshop.myshopify.com/Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1Support → https://www.patreon.com/threatwireContact Us → http://www.twitter.com/hak5Threat Wire RSS → https://shannonmorse.podbean.com/feed/Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubsHost: Darren Kitchen → https://www.twitter.com/hak5darrenHost: Mubix → http://www.twitter.com/mubix-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
DNS Cache Poisoning is back, POS systems are vulnerable to a new attack, and New Hacks are Targeting COVID-19 Vaccine Organizations! All that coming up now on ThreatWire. #threatwire #hak5 Links:Watch this on youtube: https://youtu.be/iJjrM3KlTjU Support me on alternative platforms! https://snubsie.com/support Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://teespring.com/stores/morsecode Join now for access to extra perks and to support ThreatWire! https://www.patreon.com/threatwire Links:Sad DNS:https://www.zdnet.com/article/how-opendns-powerdns-and-maradns-remained-unaffected-by-the-dns-cache-poisoning-vulnerability/https://789498207.www.saddns.net/https://arstechnica.com/information-technology/2020/11/researchers-find-way-to-revive-kaminskys-2008-dns-cache-poisoning-attack/https://thehackernews.com/2020/11/sad-dns-new-flaws-re-enable-dns-cache.htmlhttps://www.zdnet.com/article/dns-cache-poisoning-poised-for-a-comeback-sad-dns/ POS Malware:https://www.welivesecurity.com/2020/11/12/hungry-data-modpipe-backdoor-hits-pos-software-hospitality-sector/https://www.oracle.com/industries/food-beverage/products/res-3700/https://thehackernews.com/2020/11/new-modpipe-point-of-sale-pos-malware.htmlhttps://www.zdnet.com/article/new-modpipe-malware-targets-hospitality-hotel-point-of-sale-systems/https://www.cyberscoop.com/point-of-sale-backdoor-modpipe-eset/ Covid19 attacks:https://blogs.microsoft.com/on-the-issues/2020/11/13/health-care-cyberattacks-covid-19-paris-peace-forum/https://arstechnica.com/information-technology/2020/11/hackers-sponsored-by-russia-and-north-korea-are-targeting-covid-19-researchers/https://www.cnet.com/news/russian-and-north-korean-hackers-are-targeting-covid-19-vaccine-researchers/https://threatpost.com/russia-north-korea-attacking-covid-19-vaccine-makers/161205/https://www.zdnet.com/article/microsoft-says-three-apts-have-targeted-seven-covid-19-vaccine-makers/ Photo credit:https://posquote.com/wp-content/uploads/2019/06/restaurant-pos-systems.jpg -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆Our Site → https://www.hak5.orgShop → https://www.hakshop.comSubscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1Support → https://www.patreon.com/threatwireContact Us → http://www.twitter.com/hak5Threat Wire RSS → https://shannonmorse.podbean.com/feed/Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubsHost: Darren Kitchen → https://www.twitter.com/hak5darrenHost: Mubix → http://www.twitter.com/mubix-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
Feds Seize $1 Billion in Bitcoin, Apple Patches 3 Zero Days, and Election Security and California’s new Prop 24! All that coming up now on ThreatWire. #threatwire #hak5 Links:Watch this on youtube: https://youtu.be/Br4_Ez-ONCc Support me on alternative platforms! https://snubsie.com/support Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://teespring.com/stores/morsecode Join now for access to extra perks and to support ThreatWire! https://www.patreon.com/threatwire Links:1B $ Seized from Silk Road:https://arstechnica.com/tech-policy/2020/11/feds-seize-1-billion-in-bitcoin-from-silk-road-drug-marketplace/https://arstechnica.com/information-technology/2020/11/someone-has-withdrawn-1-billion-from-a-bitcoin-wallet-dormant-since-2015/https://threatpost.com/feds-seize-1b-bitcoin-silk-road/161027/https://www.vice.com/en/article/akdgz8/us-feds-seize-1-billion-in-bitcoin-from-wallet-linked-to-silk-roadhttps://www.vice.com/en/article/g5bbaj/someone-emptied-out-bitcoin-wallet-with-964000000-millionhttps://www.zdnet.com/article/us-weve-just-seized-1bn-in-bitcoin-stolen-from-silk-road-by-individual-x-hacker/https://www.cyberscoop.com/silk-road-bitcoin-billion-wallet/ iOS Updates:https://thehackernews.com/2020/11/update-your-ios-devices-now-3-actively.htmlhttps://arstechnica.com/information-technology/2020/11/apple-patches-ios-against-3-actively-exploited-0days-found-by-google/https://threatpost.com/apple-patches-bugs-zero-days/161010/https://www.zdnet.com/article/apple-fixes-three-ios-zero-days-exploited-in-the-wild/https://www.cyberscoop.com/apple-ios-update-vulnerabilities-exploited-google/ Cybersecurity and the Election:https://www.cnet.com/news/election-day-was-hack-free-but-cybersecurity-officials-are-still-bracing-for-attacks/https://www.cyberscoop.com/election-night-cybersecurity-cisa-results/https://www.cyberscoop.com/election-misinformation-protest-maricopa-arizona-trump-social-media-twitter-facebook/https://www.theverge.com/2020/11/4/21549514/california-prop-24-data-privacy-2020-election-andrew-yanghttps://www.cnet.com/news/prop-24-passes-in-california-pushing-privacy-rights-to-the-forefront-again/ Photo credit:https://cdn.pixabay.com/photo/2017/01/25/12/31/bitcoin-2007769_1280.jpg -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆Our Site → https://www.hak5.orgShop → https://www.hakshop.comSubscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1Support → https://www.patreon.com/threatwireContact Us → http://www.twitter.com/hak5Threat Wire RSS → https://shannonmorse.podbean.com/feed/Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubsHost: Darren Kitchen → https://www.twitter.com/hak5darrenHost: Mubix → http://www.twitter.com/mubix-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
Ransomware is hitting hospitals, home depot canada leaks customer data through no fault but their own, and researchers found a new way to extract security keys from Intel CPUs! All that coming up now on ThreatWire. #threatwire #hak5 Links: Watch this on youtube: https://youtu.be/vndloinbALk WIN A WIFI PINEAPPLE MARK VII! Comment on this video and subscribe to my channel! - https://youtu.be/j_Rtl4g7sZY Support me on alternative platforms! https://snubsie.com/support Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://teespring.com/stores/morsecode Join now for access to extra perks and to support ThreatWire! https://www.patreon.com/threatwire Links:Hospital hacks:https://us-cert.cisa.gov/sites/default/files/publications/AA20-302A_Ransomware%20_Activity_Targeting_the_Healthcare_and_Public_Health_Sector.pdfhttps://us-cert.cisa.gov/ncas/alerts/aa20-302ahttps://thehackernews.com/2020/10/ransomware-attack-hospital.htmlhttps://thehackernews.com/2020/10/trickbot-computer-virus.htmlhttps://www.cnet.com/news/fbi-warns-imminent-wave-of-ransomware-attacks-hitting-hospitals/ Home Depot data breach:https://twitter.com/HomeDepotCanada/status/1321600523485745152https://threatpost.com/home-depot-data-breach-order-confirmation/160728/https://twitter.com/HomeDepotCanada/status/1321485206260514818https://www.bleepingcomputer.com/news/security/home-depot-blunder-emails-customer-order-info-to-strangers/https://twitter.com/bethanyfrances/status/1321503250907103232 Intel:https://arstechnica.com/gadgets/2020/10/in-a-first-researchers-extract-secret-key-used-to-encrypt-intel-cpu-code/?comments=1https://en.m.wikipedia.org/wiki/Goldmonthttps://www.intel.com/content/www/us/en/support/articles/000025619/software.htmlhttps://www.intel.com/content/dam/www/public/us/en/security-advisory/documents/the-intel-csme-dam-vulnerability-cve-2018-3659-and-cve-2018-3643-whitepaper.pdf Photo credit:https://cdn.pixabay.com/photo/2016/09/01/15/10/hospital-1636334_1280.jpg -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆Our Site → https://www.hak5.orgShop → https://www.hakshop.comSubscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1Support → https://www.patreon.com/threatwireContact Us → http://www.twitter.com/hak5Threat Wire RSS → https://shannonmorse.podbean.com/feed/Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubsHost: Darren Kitchen → https://www.twitter.com/hak5darrenHost: Mubix → http://www.twitter.com/mubix-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
A ransomware gang donated $20000 to charity, Windows gamers - update Geforce Experience now to patch some security issues, and an election disinformation campaign is being attributed to hacking groups in another country! All that coming up now on ThreatWire #threatwire #hak5 Links:WIN A WIFI PINEAPPLE MARK VII! - https://youtube.com/shannonmorse Support me on alternative platforms! https://snubsie.com/support Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://teespring.com/stores/shannons-store-24 Join now for access to extra perks and to support ThreatWire! https://www.patreon.com/threatwire Links:Ransomware Charity:https://www.bbc.com/news/technology-54591761https://threatpost.com/ransomware-20k-donation-charities/160386/https://www.zdnet.com/article/ransomware-gang-donates-part-of-ransom-demands-to-charity-organizations/https://www.zdnet.com/article/ransomware-gang-donates-part-of-ransom-demands-to-charity-organizations/ Nvidia:https://nvidia.custhelp.com/app/answers/detail/a_id/5076 https://threatpost.com/nvidia-gamers-geforce-experience-flaws/160487/https://www.zdnet.com/article/nvidia-tackles-code-execution-data-leaks-in-geforce-experience/ Email Attackshttps://www.zdnet.com/article/us-slaps-sanctions-on-iranian-entities-for-interfering-with-2020-presidential-election/https://www.cyberscoop.com/iran-treasury-sanctions-irgc-elections/https://www.zdnet.com/article/us-blames-iran-for-spoofed-proud-boys-emails-threatening-democrat-voters/https://www.vice.com/en/article/qjpdgd/threatening-voter-emails-included-highly-suspicious-hacking-videohttps://www.vice.com/en/article/88a43b/proud-boys-emails-threatening-florida-voters-appear-to-use-spoofed-email-addresshttps://www.vice.com/en/article/akdzgp/the-goal-of-irans-fake-proud-boys-emails-was-chaoshttps://www.cyberscoop.com/ratcliffe-fbi-iran-proud-boys-voting-email/ Photo credit:https://cdn.pixabay.com/photo/2017/08/29/12/44/international-2693210_1280.jpg -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆Our Site → https://www.hak5.orgShop → https://www.hakshop.comSubscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1Support → https://www.patreon.com/threatwireContact Us → http://www.twitter.com/hak5Threat Wire RSS → https://shannonmorse.podbean.com/feed/Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubsHost: Darren Kitchen → https://www.twitter.com/hak5darrenHost: Mubix → http://www.twitter.com/mubix-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
Bluetooth vulnerabilities hit linux devices, the APT31 hacking group is mimicking McAfee Antivirus, and Barnes & Noble confirms a cyberattack! All that coming up now on ThreatWire. #threatwire #hak5 Subscribe for my next Wifi Pineapple Mk VII Giveaway! https://youtube.com/shannonmorse Links:Support me on alternative platforms! https://snubsie.com/support Shop ThreatWire Merch Directly! - https://snubsie.com/shop Shop ThreatWire Merch on Teespring! - https://teespring.com/stores/shannons-store-24 Join now for access to extra perks and to support ThreatWire! https://www.patreon.com/threatwire Links:Bluetooth Linux Flaw:https://thehackernews.com/2020/10/linux-Bluetooth-hacking.htmlhttps://twitter.com/theflow0/status/1316071793707364353https://arstechnica.com/information-technology/2020/10/google-and-intel-warn-of-high-severity-bluetooth-security-bug-in-linux/https://threatpost.com/google-intel-kernel-bug-linux-iot/160067/https://www.zdnet.com/article/google-warns-of-severe-bleedingtooth-bluetooth-flaw-in-linux-kernel/ APT31 Posing as McAfee Antivirus:https://sea.pcmag.com/security/39714/google-chinese-hackers-are-posing-as-mcafee-antivirus-to-phish-victimshttps://www.theverge.com/2020/10/17/21520799/google-chinese-hackers-biden-campaign-mcafee-malwarehttps://www.cyberscoop.com/biden-chinese-hacking-google-security-russia/https://blog.google/threat-analysis-group/how-were-tackling-evolving-online-threats Barnes and Noble Hack:https://www.zdnet.com/article/barnes-noble-confirms-cyberattack-customer-data-breach/https://twitter.com/nookBN/status/1316406326898102273https://www.bleepingcomputer.com/news/security/barnes-and-noble-hit-by-cyberattack-that-exposed-customer-data/https://www.cyberscoop.com/barnes-noble-cyber-incident-customer-data/ Photo credit:https://www.mepixels.com/cache/64ffe466/penguin-jumping-1140x1140-AAaGpB7gF.jpeg -----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆Our Site → https://www.hak5.orgShop → https://www.hakshop.comSubscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1Support → https://www.patreon.com/threatwireContact Us → http://www.twitter.com/hak5Threat Wire RSS → https://shannonmorse.podbean.com/feed/Threat Wire iTunes → https://itunes.apple.com/us/podcast/threat-wire/id1197048999 Host: Shannon Morse → https://www.twitter.com/snubsHost: Darren Kitchen → https://www.twitter.com/hak5darrenHost: Mubix → http://www.twitter.com/mubix-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆