POPULARITY
This week on Hacker And The Fed we break down the SolarWinds hack, there are 8 new vulnerabilities found in SolarWinds, thousands of remote IT workers have been working for North Korea, hackers are targeting a company that handles data requests for law enforcement, and we answer listener questions about VPN services, password managers and patch management. Links from the episode: Critical SolarWinds RCE Bugs Enable Unauthorized Network Takeover https://www.darkreading.com/vulnerabilities-threats/critical-solarwinds-rce-bugs-enable-unauthorized-network-takeover Thousands of Remote IT Workers Sent Wages to North Korea to Help Fund Weapons Program, FBI Says https://apnews.com/article/north-korea-weapons-program-it-workers-f3df7c120522b0581db5c0b9682ebc9b?taid=6531b8b29c11a80001ef2a28 Hackers Target Company That Vets Police Data Requests for Tech Giants https://www.404media.co/hackers-target-kodex-accounts-edrs/ Support our sponsors: Go to JoinDeleteMe.com/FED and use the code FED20 for 20% off Go to Cloudsolvers.com and tell them "Hacker and the Fed sent you" for a free assessment of your current environment Get your Hacker and the Fed merchandise at hackerandthefed.com Send HATF your questions at questions@hackerandthefed.com
Grab a cup of coffee and join Ryan Kovar, Mick Baccio, and Audra Streetman for another episode of Coffee Talk with SURGe. You can watch the livestream of this episode here. The team from Splunk will discuss the latest security news, including: - The DOJ Detected the SolarWinds Hack 6 Months Earlier Than First Disclosed - US Marshals Service still recovering from February ransomware attack affecting system used by fugitive hunters - Industrial security vendors partner to share intelligence about critical infrastructure threats Ryan and Mick competed in a charity challenge to discuss the impact of splintering social media platforms for keeping track of security news and opinions. The trio also recapped the highlights from RSA Conference.
In May 2020, the US Department of Justice stumbled upon Russian hackers in its network. But did not realize the significance of what they had found for six months. Read the story here.
Every time you see a big cybersecurity crisis or incident -- like Colonial Pipeline, Solar Winds, log4j -- leaders and Boards rush out to invest more in monitoring and detection technologies … but are we neglecting the “roads and bridges” of data protection and access management? Why do investments in cryptography infrastructure and access and policy management that protect your organization and data remain a harder sell? Entrust CIO Anudeep Parhar and Dr. Pali Surdhar, Director of Product Security share their unique perspectives – and why enterprises must make the shift from rewarding the cybersecurity hero that saves the day to celebrating “no news is good news”. Background reading for this episode: Wired: A Year After the SolarWinds Hack, Supply Chain Threats Still Loom ZDNet: Ransomware: Hackers are using Log4j flaw as part of their attacks, warns Microsoft Forbes: Let Customers Know Their Data Is Safe: Cybersecurity As A Marketing Tool
Our Guest Bill Alderson has taken an independent look a the SolarWinds breach and provides a detailed look into the attack sequence. Bills paper called "SolarWinds Breach – December 2020 a Comprehensive Paper" walks us through the series of events surrounding the highly publicized breach. This very colorful conversation is an excellent high-level look at the most important things you will need to know to identify how this may have affected you or your organization. Next, we unpack the breach, discuss the components and pieces, and look at how each was performed, what timelines the compromises occurred, and who may be a potential victim. We hope you enjoy this show's topic, as many of you have requested us to have someone on the show to unpack this hack. Visit our sponsors: BlockFrame Inc. SecureSet Academy Murray Security Services
Ein Klick. Fehlermeldung. „Sie wurden gehackt“. Und schon ist man Opfer einer der spektakulärsten Cyber-Angriffe der vergangenen Jahrzehnte - dem SolarWinds-Hack. Hunderte Unternehmen und Behörden waren 2020 davon weltweit betroffen. Aber wie haben die Hacker es geschafft einen so großen Schaden anzurichten und wie können sich Einrichtungen künftig davor schützen?
Leo Laporte walks through some of the highlights of the show and most impactful stories of 2021. Stories include: SolarWinds Hack Detailed By Microsoft Crispy Subtitles from Lay's Remembering Dan Kaminsky REvil Hacks Apple Supplier Quanta Computer The "Doom" CAPTCHA How Colonial Pipeline Was Breached When John McAfee Called Steve Gibson T-Mobile Subscribers: Do This Now Internet Anonymity" is an Oxymoron Hosts: Steve Gibson and Leo Laporte Download or subscribe to this show at https://twit.tv/shows/security-now. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit You can submit a question to Security Now! at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.
Leo Laporte walks through some of the highlights of the show and most impactful stories of 2021. Stories include: SolarWinds Hack Detailed By Microsoft Crispy Subtitles from Lay's Remembering Dan Kaminsky REvil Hacks Apple Supplier Quanta Computer The "Doom" CAPTCHA How Colonial Pipeline Was Breached When John McAfee Called Steve Gibson T-Mobile Subscribers: Do This Now Internet Anonymity" is an Oxymoron Hosts: Steve Gibson and Leo Laporte Download or subscribe to this show at https://twit.tv/shows/security-now. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit You can submit a question to Security Now! at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.
Leo Laporte walks through some of the highlights of the show and most impactful stories of 2021. Stories include: SolarWinds Hack Detailed By Microsoft Crispy Subtitles from Lay's Remembering Dan Kaminsky REvil Hacks Apple Supplier Quanta Computer The "Doom" CAPTCHA How Colonial Pipeline Was Breached When John McAfee Called Steve Gibson T-Mobile Subscribers: Do This Now Internet Anonymity" is an Oxymoron Hosts: Steve Gibson and Leo Laporte Download or subscribe to this show at https://twit.tv/shows/security-now. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit You can submit a question to Security Now! at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.
Leo Laporte walks through some of the highlights of the show and most impactful stories of 2021. Stories include: SolarWinds Hack Detailed By Microsoft Crispy Subtitles from Lay's Remembering Dan Kaminsky REvil Hacks Apple Supplier Quanta Computer The "Doom" CAPTCHA How Colonial Pipeline Was Breached When John McAfee Called Steve Gibson T-Mobile Subscribers: Do This Now Internet Anonymity" is an Oxymoron Hosts: Steve Gibson and Leo Laporte Download or subscribe to this show at https://twit.tv/shows/security-now. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit You can submit a question to Security Now! at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.
Leo Laporte walks through some of the highlights of the show and most impactful stories of 2021. Stories include: SolarWinds Hack Detailed By Microsoft Crispy Subtitles from Lay's Remembering Dan Kaminsky REvil Hacks Apple Supplier Quanta Computer The "Doom" CAPTCHA How Colonial Pipeline Was Breached When John McAfee Called Steve Gibson T-Mobile Subscribers: Do This Now Internet Anonymity" is an Oxymoron Hosts: Steve Gibson and Leo Laporte Download or subscribe to this show at https://twit.tv/shows/security-now. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit You can submit a question to Security Now! at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Sponsor: ZipRecruiter.com/securitynow
Leo Laporte walks through some of the highlights of the show and most impactful stories of 2021. Stories include: SolarWinds Hack Detailed By Microsoft Crispy Subtitles from Lay's Remembering Dan Kaminsky REvil Hacks Apple Supplier Quanta Computer The "Doom" CAPTCHA How Colonial Pipeline Was Breached When John McAfee Called Steve Gibson T-Mobile Subscribers: Do This Now Internet Anonymity" is an Oxymoron Hosts: Steve Gibson and Leo Laporte Download or subscribe to this show at https://twit.tv/shows/security-now. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit You can submit a question to Security Now! at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.
Leo Laporte walks through some of the highlights of the show and most impactful stories of 2021. Stories include: SolarWinds Hack Detailed By Microsoft Crispy Subtitles from Lay's Remembering Dan Kaminsky REvil Hacks Apple Supplier Quanta Computer The "Doom" CAPTCHA How Colonial Pipeline Was Breached When John McAfee Called Steve Gibson T-Mobile Subscribers: Do This Now Internet Anonymity" is an Oxymoron Hosts: Steve Gibson and Leo Laporte Download or subscribe to this show at https://twit.tv/shows/security-now. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit You can submit a question to Security Now! at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.
Leo Laporte walks through some of the highlights of the show and most impactful stories of 2021. Stories include: SolarWinds Hack Detailed By Microsoft Crispy Subtitles from Lay's Remembering Dan Kaminsky REvil Hacks Apple Supplier Quanta Computer The "Doom" CAPTCHA How Colonial Pipeline Was Breached When John McAfee Called Steve Gibson T-Mobile Subscribers: Do This Now Internet Anonymity" is an Oxymoron Hosts: Steve Gibson and Leo Laporte Download or subscribe to this show at https://twit.tv/shows/security-now. Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit You can submit a question to Security Now! at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6.
The Russia-led campaign was a wake-up call to the industry, but there's no one solution to the threat.
The Russia-led campaign was a wake-up call to the industry, but there's no one solution to the threat.
Russian hackers are targeting IT Companies, FTC OK's ISP to monetize your data, the iPod is turning 20 and we look back, AirPods Pro get firmware update with new added features
Getting hit with a large-scale cyber attack is a nightmare scenario for many IT leaders. Repairing the damage caused by hackers once they've infiltrated your system can be both expensive and time-consuming, and the post-breach fallout can be extremely challenging to deal with. But while the technical impact an attack like this can have is one thing, we often overlook the effect it has on the individuals who have to respond to it. Long nights, extreme pressure and high levels of stress are all hallmarks of real-world incident response, and for the teams mobilised to deal with a breach, the experience can often be traumatic.This week, the IT Pro Podcast sits down with Solarwinds CISO Tim Brown and CEO Sudhakar Ramakrishna to dig into one of the most serious and wide ranging attacks of the decade. We find out what it was actually like in the days and weeks following the attack on its Orion platform last year, and how the company's incident response teams coped with one of the most severe security events in its history. We also discuss what it was like for Ramakrishna joining the company in the immediate wake of the incident, and how he rebuilt trust in Solarwinds' partners and resiliency in its IT.For more information on all of the issues we've spoken about this week, head over to https://bit.ly/ITPP-Solarwinds
Nearly 30 top US prosecutors had their office's email accounts hacked in a major breach last year, which the US government has blamed on Russia. Learn more about your ad choices. Visit megaphone.fm/adchoices
## End-of-Sale Ankündigungen Neue Produkte kommen und alte müssen gehen. Bei Sophos herrscht im Moment eine aufregende Phase. Die neue XGS Serie schickt die XG-Firewalls in Pension und auch das Lizenzmodell wurde etwas angepasst. Alle relevanten Änderungen und welche Produkte es bald nicht mehr zu kaufen gibt, erfahrt ihr in dieser Podcastfolge. ## Sophos Central XDR XDR kann seit dem 19. Mai als Overlay-Lizenz erworben werden. Dadurch erhalten XDR-fähigen Produkte die Möglichkeit, Daten bis zu 30 Tagen im Data Lake zu speichern. Bestandskunden, die bisher eine Lizenz mit EDR aktiv hatten, dürfen sich über ein kostenloses Update auf XDR freuen. Sophos hat nämlich am 10. Juli den EDR und XDR Teil zusammengefasst. ## Sophos Central bekommt neuen Speicherort in Kanada (Montreal) Neben den bisherigen Standorten in U.S., Deutschland und Irland, kommt mit Kanada ein weiteres Land hinzu. Sophos bietet Kunden mit einem Enterprise Dashboard bereits die Möglichkeit, ihre Central Daten auf einem Server in Montreal zu speichern. Worauf man aber trotzdem noch achten sollte, erwähnen wir in dieser Podcastfolge. ## Supply-Chain-Angriff auf Kaseya VSA Im Dezember 2020 wurde der Solarwinds-Hack publik und schon im März 2021 sprachen alle von HAFNIUM. Die Welle mit solchen Angriffen reisst nicht ab und der neuste Fall betrifft nun Kaseya VSA. Was dort genau passiert ist, erfährst du ganz am Schluss dieser Podcastfolge.
The SolarWinds Hack And The Future Of Cyber Espionage --- Send in a voice message: https://anchor.fm/darkwebtoday/message
The Massive SolarWinds Hack Explained in Context https://open.spotify.com/show/3XmolWa59mJtPWQsVyrKb9?si=5GE_X1egR7WeLyb6AHg_Jg&dl_branch=1 https://twitter.com/ADanielHill https://Albertohill.com https://darkweb.today “In 2014, Alberto Daniel Hill, an expert in cybersecurity, found a security issue in a medical provider's website. In reporting the issue, it led him to become the first person imprisoned in Uruguay for a computer-related crime—a crime he didn't commit, and one that probably never even happened." I am Alberto and this podcast is about my story, cybersecurity, etc. https://podcast.darkweb.today/ https://twitter.com/ADanielHill https://twitter.com/Darkwebtoday https://twitter.com/todayDarkweb https://darkweb.today --- Send in a voice message: https://anchor.fm/darkwebtoday/message
Chris, Melanie, and Zack dig into Marcus Willett's “Lessons of the SolarWinds Hack” in the latest issue of Survival. They explore the distinction between cyber espionage and cyber defense (Was it an attack? Or a hack? Does it matter?), consider the implications of the offense-defense balance (Is 100 percent defense feasible?), and review possible global norms that can be put in place to limit the harm caused by malicious cyber actors. Melanie and Chris both have grievances toward members of Congress who are reluctant to revisit old Authorizations for Use of Military Force , and Zack gripes about Pakistani Prime Minister Imran Khan's absurd op-ed in the Washington Post. And this week's attafolks were all in the family: Zack welcomed a new niece named Marlowe; Melanie cheered her amazing older brother, David, a renowned physician and educator at the Mayo Clinic; and Chris gives a shout out to his daughter Katelyn —- and all members of the Class of 2021. Marcus Willette, “Lessons of the SolarWinds Hack,” IISS, March 31, 2021 Trey Herr, et al “Broken Trust: Lessons from Sunburst,” Cyber Statecraft Initiative, Atlantic Council Stephen Miles, Twitter, June 21, 2021 Dmitri Alperovitchand Ian Ward, "How Should the U.S. Respond to the SolarWinds and Microsoft Exchange Hacks?," Lawfare, March 12, 2021 "Critical Infrastructure Sectors," S. Department of Homeland Security Imran Khan, "Pakistan is Ready to be a Partner for Peace in Afghanistan, but We Will Not Host US Bases," Washington Post, June 21, 2021
Hackergruppen greifen Unternehmen und Behörden an, legen Pipelines und Krankenhäuser lahm oder leaken vertrauliche E-Mails von Politiker:innen. Wie sicher ist unsere kritische Infrastruktur und wie können wir uns besser schützen? Léa Steinacker und Milena Merten sprechen darüber mit dem Investigativreporter und Cybersecurity-Experten Hakan Tanriverdi.
De groep achter de Solarwinds hack, waarbij aanvallers in netwerken van verschillende Amerikaanse bedrijven en ministeries infiltreerde, slaat opnieuw toe. Microsoft meldt dat de nieuwe aanvalsgolf zich richt op doelwitten in 24 landen, maar met name de Verenigde Staten worden getarget.
Another big federal agency says it escaped unscathed from the Solarwinds hack. Leaders from the Department of Veterans Affairs told Congress yesterday they’re now confident that none of their data was compromised, even though the vulnerable Orion system was installed throughout VA’s networks. But VA’s security practices are still far from perfect. The Federal Drive got an update on the department’s cyber posture from Federal News Network’s Jared Serbu.
The recent Colonial Pipeline attack was yet another example of the escalating threats in cyberspace as many Americans experienced long lines at gas stations amid fears of shortages after a ransomware attack. This incident just comes months after the likely Russian government-sponsored SolarWinds hack that compromised thousands of government and company platforms. Meanwhile, the Facebook Oversight Board recently upheld its ban on former President Donald Trump. With all these disruptions in the digital realm, the line between what is acceptable and unacceptable behavior online—and who should manage cyberspace—has never been blurrier. Companies are exercising their private authorities, paying off ransoms and managing challenging content moderation decisions. Have governments ceded too much ground to the private sector, and is there a way to build a more organized structure to make these groundbreaking decisions in cyberspace?Jon Bateman, a fellow at Carnegie's Cyber Policy Initiative, joins Laura to tackle the growing governance challenges in the technology sector.
As humanitarian organizations become more active in and reliant upon new technologies and the digital domain, they evolve from simple bystanders to full-fledged stakeholders in cyberspace – able to build on the advantages of new technologies but also vulnerable to adverse cyber operations that can impact their capacity to protect and assist people affected by violence or armed conflict. The 2020 cyberattack on SolarWinds, a major US information technology company, demonstrated the chaos a hack can cause by targeting digital supply chain components. What does the hack mean for the humanitarian cyberspace, and what can we learn from it? Massimo Marelli, ICRC's Head of Data Protection Office, draws out some possible lessons and the way forward by exploring the notion of ‘digital sovereignty'.
Russia 'likely' kept access to US networks after SolarWinds hack; Amazon drops the price of its latest Echo Dot to $30
Russia 'likely' kept access to US networks after SolarWinds hack; Amazon drops the price of its latest Echo Dot to $30
Episode #29: On today's show, I will be talking about: Biden's punishment on Russia for the 2020 Solarwinds hack, Apple's decision to let Parler back on the app store, and how Facebook is renewing its calls for Congress to create guidelines about how online services should make users' data available to transfer to other platforms as it expands its own feature to do just that. Pour yourself a nice cup of coffee & get ready to download the latest tech news for the week. Sources: President Biden's decision to punish Russia for the SolarWinds hack broke with years of US foreign policy that tolerated cyber espionage, The Wall Street Journal Apple will let Parler back on the App Store, CNN Business Facebook calls for data portability laws as it expands the types of info users can transfer to other services, CNBC.com Want to support this podcast? Visit https://anchor.fm/coffeyandcode/support or leave a rate & review on Apple Podcasts. *Subscribe to Coffey & Code to be notified when new episodes go live!* If you'd like to give feedback on the show, I'd love to hear from you. Visit https://anchor.fm/coffeyandcode/message to drop me a line, or find me on twitter @ashleycoffey_ and instagram @ashleyrcoffey89. Thanks for listening! Special thank you to Just Good Coffee Company, the official coffee partner of Coffey & Code. Just Good Coffee offers a carefully crafted selection of coffee from some of the most revered coffee-producing regions around the world. Their commitment to offering exceptionally good experiences extends beyond just the products themselves, but extends well into the community. Their mission is simple, to offer good coffee, and coffee for good. From cup, to community. That is the sole purpose of Just Good Coffee. --- This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app Support this podcast: https://anchor.fm/coffeyandcode/support
Never before has a hack of this sophistication and scale been seen. But now that 18,000 organizations are considered breached, what can the hacked information be used for? We walk through the worst case scenario possibilities of what the cyberattackers could do with the SolarWinds hack data -- from espionage to overwhelming electric grids -- and what that could mean for all of us, including those in the high performance computing industry. We also explore the Senate and congressional hearing testimonies given by Kevin Mandia, CEO of FireEye, and Brad Smith, President of Microsoft, about what the hackers went after once they were in the system, and whether the future of cloud poses a greater risk or a stronger solution.
In dieser Folge beschäftigen wir uns mit einem weiteren Ransomware Angriff auf einen Spielehersteller und auch der Solarwinds Hack entwickelt sich in bisher ungekannte Dimensionen. Für Klarheit im Hacking-Dschungel sorgt wieder unser Experte Alexander Busse.
Called a "Cyber Pearl Harbor," the SolarWinds Hack exposes the stark truth of America's cyber security– we're exposed and compromised. But perhaps it's not all doom and gloom. Leading cyber security experts Chuck Brooks and Dr. David Bray with brain hacker Dr. Divya Chander advance the conversation with creative solutions to our complicated cyber landscape.
It was a dark day in cybersecurity when the world realized that the largest and widest reaching data breach in history had hit over 18,000 companies and organizations, including the U.S. Department of Defense, Microsoft, and just about everything in-between. In this episode, we take a look at what in the world happened in the SolarWinds hack. How did it puncture cybersecurity barricades guarding information for some of the world’s most secure organizations? From SolarWinds to Florida’s recent public water facility hack to a thwarted ransomware attack on one of our own computers, we talk about what appears to be our day’s modern wargrounds -- the internet.
In this episode of the Futurum Tech Webcast, host Shelly Kramer joined by fellow analyst Fred McClimans for a conversation about some cybersecurity news you may have missed during the week when unexpected weather across the south, horrifying power grid problems and beyond have captured the attention of the nation. The conversation started with a quick overview of Clubhouse, the current darling of social apps. In a nutshell, Clubhouse, an invitation only social audio app, is powered by Agora, a Chinese-based software company. Other companies using Agora's software include Bilibi, a $53Bn Chinese video-sharing app with 170M plus users and considered the nearest thing China has to YouTube, New Oriental Education, a $33B Chinese ed tech firm and Yalla, a $5.6 billion Chinese-owned app called the Clubhouse of the Middle East. Note the theme: Chinese connections to Agora. So, Agora. And Chinese connections, and cybersecurity — that's what the conversation comes back to including the following: Agora's reported SDK vulnerability that could have allowed an attacker to spy on private video and audio calls. The flaw in Agora's SDK that is used by dating apps like eHarmony, Plenty of Fish, MeetMe, and Skout. It was also found in healthcare apps like Talkspace, Practo, and Dr. First's Backline. McAfee disclosed the flaw in April of 202 and it took Agora seven months to release a new SDK to remediate the threat. The cybersecurity conversation then shifted to the SolarWinds hack and the update figures released by the White House. As of today, it believes (so far), that 9 federal agencies and 100 private sector companies have been impacted. The conversation also explore the news that although the hack remains considered of Russian origin, it's likely that the hackers launched their attack from inside the US. The cybersecurity conversation wrapped with some good news post SolarWinds hack from Microsoft. On Thursday, Microsoft announced in a blog post on its Security Response Center published that its internal investigation has concluded into the activity of the threat actor and that there was no evidence of access to production services or customer data. The investigation also found there were no indications that their systems at Microsoft were used to attack others.
In this episode, Mary talks with Tyler Adams, Co-founder, President and COO at CertifID who lends his expertise to a candid discussion about who fraudsters are targeting, how they further manipulate an already stressful environment for gain and how to identify potential areas of vulnerability. You can reach Tyler via email at tadams@certifid.comDuring the interview, Tyler mentioned the following: Learn more about CertifID's $1,000,000 guarantee when you use their "trip insurance for your wire."CertifID offers a free Security Analysis - start here.Phishing Scams for Business Email - read an article Tyler wrote. The SolarWinds Hack explained. 60 Minutes recently presented this video on the subject, too.CertifID is integrated with a number of tile and settlement software production solutions. You can also read more about their integration through RamQuest's Closing Market.You can also download this infographic highlighting Tyler's interview insights as a companion piece for the episode.If you'd like to contact the Pandemic Podcast, email podcasts@ramquest.com. Don't forget to subscribe, rate, and review this podcast on Apple Podcast, Spotify, or wherever you listen to podcasts, or visit RamQuest.com/pandemicpodcast to download the latest episode. Lastly, we love to see when and how you're listening. Share our posts, or create your own and tag them: #PandemicPracticesPodcast
It appears that not only Russia but also China targeted the company, a reminder of the many ways interconnectedness can go wrong.
The president of Microsoft says "absolutely not" — at least when it comes to his company. Brad Smith discusses Microsoft's new guidelines for political contributions, the six stages of antitrust grief and how corporations — and the U.S. government — missed the SolarWinds Hack.You can find transcripts (posted midday) and more information for all episodes at nytimes.com/sway, and you can find Kara on Twitter @karaswisher.
Chris und Matteo sind in dieser Folge Sevencast aktiv. Sie sprechen über den Solarwinds Hack und weitere aktuelle Themen der IT-Sicherheit. Am Ende hat Chris noch einen richtigen Live-Hack der Matteos Leben für immer verändern wird. --- Send in a voice message: https://anchor.fm/aware7/message
This week, Matt Mosley and Kash Izadseta discuss the SolarWinds Hack of 2020-2021, the saga Continues... What we know Whappened exactly What is the 2021 update on the hack What we did to combat it What the future holds Links mentioned in this episode: https://gist.github.com/ZephrFish/afb6a9c9eeef5cf37301e13d661e0347 https://www.wired.com/story/solarwinds-hack-china-usda/ https://www.complianceweek.com/cyber-security/solarwinds-hack-turning-into-pandoras-box-of-cyber-risk/30001.article http://tevoratalks.com Instagram, Twitter, Facebook: @TevoraTalks
Learn about the topics covered in this episode and check out the daily visual, number, and trust link: yesterdaysnewsletter.com. This show is written by Colin Wright and hosted by his AI-generated robot voice-double. Colin's other podcasts (which the non-robot-Colin hosts): Let's Know Things / Brain Lenses
This week we talk about all the amazing headlines of 2020. From ransomware to DDoS attacks, to a final Christmas coal in the cyber stocking from Santa, 2020 set the bar very high in the world of cyber security! We breakdown the hacker news highlights month by month, and get ready for what is to come for 2021. January - IRS, Wawa, Microsoft February - Estée Lauder, Denmark Tax Portal March - Marriott, Virgin Media, Whisper, NutriBullet April - US SBA May - EasyJet June - Claires, AWS July - BlueLeaks August - Carnival, LG, Xerox September - Clark County Nevada ransomware, German Hospital ransomware October - Boom! Mobile, Barnes Noble November - Capcom, Campari December - Vancouver TransLink, FireEye, SolarWinds Links mentioned in this episode: http://tevoratalks.com Instagram, Twitter, Facebook: @TevoraTalks
The SolarWinds vulnerability, which allows hackers to get into the systems of government agencies like the Departments of Treasury and Defense, and Fortune 500 companies like Microsoft as well, was a massive cybersecurity breach. It's fallout and scope is hard to even imagine. There are important cybersecurity lessons to take away from the situation and to share with clients and members of your team.
Join Scott Young and Shaun Sturby from Optrics Engineering as they discuss FireEye's update on the Solarwinds attack, Flash is dead but Extreme Networks didn't get the memo, DNSpooq and SonicWall joins FireEye, Microsoft and MalwareBytes on the list of network security companies who have been hacked. For more IT tips go to: > www.OptricsInsider.com Timecodes: 0:00 - Intro 0:20 - Today's 3 topics 0:49 - Topic 1: FireEye's update on the Solarwinds attack 2:33 - Topic 2: Flash is dead but Extreme Networks didn't get the memo 4:45 - Topic 3: DNSpooq 10:45 - Bonus Topic: SonicWall joins FireEye, Microsoft and MalwareBytes 14:09 - Closing remarks Learn more about FireEye's update on the Solarwinds Hack: > Remediation and Hardening Strategies for Microsoft 365 to Defend Against UNC2452 > Mandiant Azure AD Investigator Learn more about Extreme Network missing Adobe Flash End-of-Life deadline: > Extreme Networks misses death-of-Flash deadline, suggests winding back PC clocks to keep its GUI alive Learn more about DNSpooq: > DNSpooq - Kaminsky attack is back! 7 new vulnerabilities are being disclosed in common DNS software dnsmasq, reminiscent of 2008 weaknesses in Internet DNS Architecture Learn more about Pi Hole: > Pi-hole - Network-wide ad blocking Learn more about SonicWall being added to security companies who have had a security breach: > Urgent Security Notice: Probable SMA 100 Series Vulnerability [Updated Jan. 25, 2021] > SonicWall says it was hacked using zero-days in its own products > Supply Chain Attacks & 0-Days: Es tu, SonicWall? Learn more about VirusTotal: > www.virustotal.com > https://support.virustotal.com/hc/en-us/articles/115002126889-How-it-works #OptricsInsider #ITSecurityTips #cybersecurity #technews #infosec --- Send in a voice message: https://anchor.fm/optrics-insider/message
Die Operation hinter den Trojanern Sunburst und Supernova gilt schon jetzt als einer der größten Hacks der letzten Jahre. Innerhalb kürzester Zeit wurden per Update bis zu 18.000 Unternehmen infiziert. Wie das genau passieren konnte und wie sich Unternehmen schützen können, berichtet in dieser Sonderfolge Alexander Busse, erfahrener Cyber-Security-Experte bei PwC Deutschland.
01-20-2021 Tom Kelly
Colin Bell, Rob Cuddy and Kris Duer return with a new season of Application Paranoia. A podcast dedicated to Application Security, DevSecOps and AppScan. This episode has guest Panellist Florin Coada helping to navigate through discussions about IaC scanning, Java 11 support, the latest from Codesweep, the Solarwinds hack and the discovery of booze fairies. Join us for the first episode from season 2...
Technovation with Peter High (CIO, CTO, CDO, CXO Interviews)
In this interview, we discuss Dmitri's perspectives on the recent US government hack believed by many to have originated in Russia, including why the hack was not an act of war but instead was traditional espionage, why this hack has potential to be 100X as significant as the OPM hack, as well as some of the silver linings of the hack. We discuss how organizations can protect themselves from adversaries, including why every organization needs to start with the assumption that an attacker is already inside, why trying to build walls around the perimeter of your network is futile, and the importance of planning regularly to defend a cyber attack. We also discuss the importance of using a password manager, why individuals should be suspicious of emails and not click attachments from unknown people, why our government is at its weakest point to be able to respond to this threat, among a variety of other topics.
The headlines were everywhere. Hackers infiltrated the U.S. government and some private firms by exploiting vulnerabilities in SolarWinds' network management software. More than 250 networks were pierced and it's believed that Russia's S.V.R. intelligence service is behind the attack. Other vendors like Microsoft and FireEye also say they were breached in the attack. For IT pros that are accountable for security and returning from the holidays wondering what this means for them, today we will recap the news and explore some practical steps to take to ensure vendors aren't creating security problems. Joining me to help me with that is Howard Solomon, a cyber security reporter that is a main contributor to ITWorldCanada.com. We also have an analyst from Info-Tech's cyber security team. Jimmy Tom.
On this show, we will be discussing Apple patents, Amazon commercial jets, invisible solar panels, Tesla Q4 deliveries, jupe dwelling unit, and the SolarWinds hack. Sources: cnet.com - Apple patents envision MacBook that wirelessly charges iPhone, iPad, and Watch - https://cnet.co/3nrIpQa theverge.com - Amazon just bought a bunch of used commercial jets for the first time - https://bit.ly/3hRGmDM scitechdaily.com - Invisible Solar Panels: How Tomorrow's Windows Will Generate Electricity - https://bit.ly/35jWfhq cnbc.com - Tesla TSLA Q4 2020 vehicle production and deliveries report - https://cnb.cx/2MF1Qs5 jupe.com - Jupe Dwelling Unit - https://jupe.com crn.com - The SolarWinds Hack - https://bit.ly/3bhaVlh
Public document from the court TicketMaster Lawsuit:https://www.justice.gov/usao-edny/pr/ticketmaster-pays-10-million-criminal-fine-intrusions-competitor-s-computer-systems-0 What is Egregor?https://www.trendmicro.com/en_us/research/20/l/egregor-ransomware-launches-string-of-high-profile-attacks-to-en.html Veritas Advisory:https://www.veritas.com/content/support/en_US/securitySANs institute is offering a Free Virtual Summit:https://www.sans.org/event/ics-security-summit-2021?utm_medium=Social&utm_source=LinkedIn&utm_content=ICS+Summit+Training+December+2020&utm_campaign=SANS+Solution+Forum+VendorJoin the Certification Station Discord Group here:https://discord.gg/cD2EgtyQNew to Discord and this community? Check out this video to get started::https://youtu.be/le_CE--Mnvs ---Connect with me:Simply follow me on LinkedIn or Twitter.Subscribe to my Podcast Simplified Security:Google Podcasthttps://podcasts.google.com/feed/aHR0cHM6Ly9mZWVkcy5zb3VuZGVyLmZtLzk3NTgvcnNzLnhtbA Apple Podcasthttps://podcasts.apple.com/us/podcast/security-bits/id1542309317 For all other platforms such as Spotify, Tune IN, Amazon,Go to https://icsbits.com/simplified/ Do not forget to Subscribe to my YouTube Channel and Enable Notifications:https://www.youtube.com/channel/UC9gRPRXg3s3ZPZZafouzOWA?sub_confirmation=1
This week on the Encrypted Economy, my guest is Dyann Heward Mills. Named by Business Insider as one of 28 Power Players driving data policy in the EU, Dyann's thoughts on privacy are critical towards filling in the bigger picture. I was excited to pick her brain on the issues and trends shaping policy in Europe and how they will likely impact the US going forward. We discussed newsworthy events like the SolarWinds Hack, Schrems II Decision, and important topics like Privacy by Design and Bias in Machine Learning. Do not miss this great episode of the Encrypted Economy, and keep an eye on Dyann's work as Europe continues to lead the way on data privacy. Topics Covered Dyann's Background Selling Decision Makers on the Importance of Privacy Balancing AML Compliance With Privacy The Impact of Schrems II UK GDPRCompliance Post-Brexit GDPR in the US When Will the US Pass a Privacy Law? The Cause and Effect of Bias in Technology Privacy by Design – Prevention vs Detection Diversity by Design GDPR Class Action Suit Challenges and Barriers The Benefits of Proactive Privacy Resource Links Dyann's LinkedIn Profile Dyann's Bio Heward Mills DPO Website Business Insider's 28 Power Players List SolarWinds Hack Schrems II Decision California Privacy Rights Act (CPRA) Our Episode With Felix Shipkevich Dyann's Article on GDPR Class Action Suits Various Claimants vs WM Morrisons Supermarket
Ran talks to Israel Barak, Cybereason's CISO and a Cyber-defense and Warfare expert, about the recent SolarWinds hack that impacted upto 18,000(!) enterprise organizations in the US. What is a Supply Chain Attack, how can organizations defend against it - and what does all this have to do with Evolution and Natural Selection?...Visit the podcast website Malicious.Life and follow us on twitter @maliciouslife
Both Segments: Scott Schober. Cyber Security Expert, Correspondent.Scott N. Schober is the President and CEO of Berkeley Varitronics Systems (BVS), a forty-six-year-old New Jersey-based privately held company and leading provider of advanced, world-class wireless test and security solutions. Schober also invented BVS's cell phone detection tools, used to enforce a “no cell phone policy” in prisons and secure government facilities. Scott is a highly sought-after subject expert on the topic of cybersecurity.Topics:Senior Cyber: Best Security Practices for Your Golden Years: Schober, Scott N, Schober, Craig W: 9781736315804: Amazon.com: BooksSolarWinds Adviser Warned of Lax Security Years Before Hack – BloombergUS cyber-attack: Around 50 firms ‘genuinely impacted' by massive breach – BBC NewsA breakthrough year for passwordless technology – Microsoft SecurityUpdates to managing user authentication methods – Microsoft Tech CommunityRussia's hacking frenzy is a reckoning | Ars TechnicaTrump's Twitter account was hacked, Dutch ministry confirms | Donald Trump | The GuardianDOJ charges Zoom employee for helping Chinese government shut down Tiananmen Square commemorationsCylynt Comprehensive Software Protection SolutionsTop 30 Cybersecurity Experts You Should Follow in 2021For more info, interviews, reviews, news, radio, podcasts, video, and more, check out ComputerAmerica.com!
Aaj ke episode me baat karenge SolarWinds Hack ki aur janenge kaise ye impact kar sakta hai hmari digital life.
As of 22 December, 2020!
Setting up a proper home lab can be tons of fun and provide you with invaluable knowledge and increase your productivity, privacy, and security all in one. That's why this week we're going to be discussing the must-have home server setups you don't want to live without. Plus we have our community feedback where we discuss the big SolarWinds Hack and in the Gaming section we check out a great party game with JackBox Party Pack 7. Of course, we've also got our famous tips, tricks and software picks. All of this and so much more this week on Destination Linux. Sponsored by: Digital Ocean - https://do.co/dln Bitwarden - https://bitwarden.com/dln Hosted by 4 Masters of the Sicilian Defense: Ryan (DasGeek) = https://dasgeekcommunity.com Jill Bryant = https://twitter.com/jill_linuxgirl Michael Tunnell = https://tuxdigital.com Want to Support the Show? Support us on Patreon = https://destinationlinux.org/patreon Support us on Sponsus = https://destinationlinux.org/sponsus DLN Store = http://dlnstore.com Want to follow the show and hosts on social media? You can find all of our social accounts at https://destinationlinux.org/contact Full Show Notes (for links and such) https://destinationlinux.org/episode-205 00:00 = Welcome to Destination Linux 205 00:59 = Santa Tux 01:14 = Solarwinds Hack Exploits Government Agencies & more 12:47 = Digital Ocean - VPS / App Platform ( https://do.co/dln ) 14:28 = Must Have Home Server Setups 30:38 = Bitwarden Password Manager ( https://bitwarden.com/dln ) 32:00 = UBports' Ubuntu Touch OTA-15 Released 35:55 = FrontPageLinux.com 36:56 = Firefox To Ship 'Network Partitioning' As A New Anti-tracking Defense 38:55 = Gaming: JackBox Party Pack 7 41:09 = Software Spotlight: Fondo 43:10 = Tip of the Week: how to use git commit 47:39 = Our New Fancy Endscreen :D Linux #OpenSource #Podcast
https://www.wsj.com/articles/russias-solarwinds-hack-11608334292 https://www.wired.com/story/russia-solarwinds-hack-roundup/ __________________________________ للاستماع على المنصات الصوتية https://anchor.fm/techpressoMEEL https://www.meelplus.com https://manylink.co/@meel __________________________________ لا تنسى تقييم البودكاست على Apple Podcasts https://podcasts.apple.com/us/podcast/techpresso/id1529890287 __________________________________ TechPresso بودكاست يأتي باخر اخبارالتكنولوجيا والمعرفه في حلقة خفيفة تطرح المعلومات والاخبار في ساعة او أقل The latest news on technology comes in a light episode that provides information and news in an hour or less تستطيعون طرح ارائكم عبر البريد الالكتروني abrahim@meelplus.com __________________________________ Join Our Telegram Group and Share Your Ideas https://t.me/iraqcreative __________________________________ For supporting Meel https://www.patreon.com/meel https://paypal.me/meelmedia https://www.buymeacoffee.com/meel __________________________________ #تكنلوجيا #بودكاست #اعمال #اقتصاد #بزنس --- This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app
We still don't know the full scale of the damage of that massive SolarWinds hack that breached thousands of systems, including U.S. government agencies and Fortune 500 companies. So what do we know? Dr. Jason Thatcher, Milton F. Stauffer Professor of Management Information Systems at Temple University's Fox School of Business joins KYW Newsradio in Depth to break down what we know right now, how such a huge hack even happened in the first place, and what it means for the very real cyber battlefield that's all around us and only ramping up in scale and intensity. Learn more about your ad choices. Visit podcastchoices.com/adchoices
Episode #17: On today's show, I'll be covering Oracle's big move from CA to ATX, the massive Solarwinds hack impacting the US Department of Homeland Security & thousands of businesses on Monday, and Facebook vs. Apple in the data privacy arena. This week's tech-tip will help you learn about the technology behind Apple Pay and why it is so secure. *Subscribe to Coffey & Code to be notified when new episodes go live!* Want to support this podcast? Visit https://anchor.fm/coffeyandcode/support or leave a review on Apple Podcasts. Your support means the world to me! If you'd like to suggest a topic to be covered, or would like to give feedback on the show, I'd love to hear from you! Visit https://anchor.fm/coffeyandcode/messageto drop me a line, or find me on twitter @ashleycoffey_ and instagram @ashleyrcoffey89. Thanks for listening! Special thank you to Just Good Coffee Company, the official coffee partner of Coffey & Code! Just Good Coffee offers a carefully crafted selection of coffee from some of the most revered coffee-producing regions around the world. Their commitment to offering exceptionally good experiences extends beyond just the products themselves, but extends well into the community. Their mission is simple, to offer good coffee, and coffee for good. From cup, to community. That is the sole purpose of Just Good Coffee. Be sure to checkout their newest Culture Collection. These blends are carefully crafted and roasted to perfection, each with origins from within the great continent of Africa. You can find them at justgoodcoffee.co --- This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app Support this podcast: https://anchor.fm/coffeyandcode/support
(as of 16 December 2020)
Special: The Solarwinds HackAdvertising Inquiries: https://redcircle.com/brands