
Sign up to save your podcasts
Or


So it turns out that 81% of developers have knowingly released vulnerable applications into the wild.
Worrying, right?
And that's the topic of conversation on today's episode: how do imperfect people lead to vulnerable applications and, most importantly, what we can do about it.
Chris is joined by OWASP experts, Andrew van der Stock and Brian Glas, as well as our own in-house AppSec whisperer, Sean Wright, to discuss all things application security.
Welcome back to Cyber Humanity! We've got our shades on and we're ready for a busy summer of cyber.
And what better way to herald our return than with a news story that's been hitting every headline?
Unless you've been living under a rock, you must have heard of the Colonial Pipeline ransomware attack. Basically, ransomware hit pipeline, pipeline got shut down, America entered a state of emergency, and then someone did something about it, and...here we are.
Despite what Paul thinks, there's more to it than that.
Tune in to discover what happens when IT meets OT – and what the DarkSide has to do with it.
***
https://www.rt.com/russia/523798-kaspersky-cia-colonial-pipeline-attack/
https://www.elliptic.co/blog/elliptic-follows-bitcoin-ransoms-paid-by-darkside-ransomware-victims
https://www.nytimes.com/2021/05/08/us/cyberattack-colonial-pipeline.html
We haf to talk about HAFNIUM.
You can't have missed the news of the Exchange Server hack that's been running the InfoSec world in circles for the past few weeks. Of course we had to get the crew together to go through all things Exchange!
From attribution and exploitation to... deception? We dip our toes in some tasty conspiracy theories (because who doesn't love a good conspiracy theory?!) and take a dive into the tech behind it all to see how this incident went from small fry to 'holy sh*t it's everywhere!'.
***
https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/
https://www.zdnet.com/article/microsoft-exchange-zero-day-vulnerabilities-exploited-in-attacks-against-us-local-govts-university/
We love looking at how to hack things you didn't think would or could be hacked. Last time, it was an election. This time, it's cars.
We're joined by car hacking expert, Mark Adams, to help us navigate our way through these murky waters. From car jacking to car hacking, we take a deep dive into CANBus, the potential motivations for hacking a vehicle (or a fleet of vehicles), and the kind of damage that can be done. We cover everything from cyber extortion to good old-fashioned theft, and explore how uniquely vulnerable vehicles can truly be.
If you'd rather read – and get hands-on with CANBus – head over to our latest blog to learn more about how to hack a car.
Find out more:
Have you ever lost an irretrievable password? Max knows that pain – as does a certain programmer from San Francisco who is one lost password away from $250million in Bitcoin. Ouch...
Next up, the Parler palaver. Trump has been 'de-platformed' and Parler is seeing huge back-lash for its role in recent political happenings.
And just when you thought you'd had enough of it, we come back round to SolarWinds. Kev delves into the third malware strain directly involved in the SUNBURST attack: SUNSPOT.
***
Lost Bitcoin:
https://technology.inquirer.net/107293/man-locked-out-of-his-bitcoin-account-with-250-million-has-two-password-guesses-left
Parler deplatforming:
https://www.forbes.com/sites/jemimamcevoy/2021/01/10/parler-at-risk-of-going-offline-after-bans-from-amazon-apple-and-google/?sh=151f2c3c312b
SolarLeaks:
https://www.bleepingcomputer.com/news/security/solarleaks-site-claims-to-sell-data-stolen-in-solarwinds-attacks/
"Hacking" Titan 2FA:
https://thehackernews.com/2021/01/new-attack-could-let-hackers-clone-your.html
SolarWinds and SUNBURST are still consuming the Infosec community and a few things have happened since our last episode. Since the Department of Justice has admitted that they were breached and that email inboxes were accessed, Kev tells us just how bad it is. We cover the saga from all angles, from Jetbrains to attribution and techniques to stock prices.
And a cybersecurity podcast in 2021 wouldn’t be a cybersecurity podcast in 2021 if we didn’t talk about WhatsApp and the Twittersphere histrionics that have been going on. We shed some light over whether the changes to their privacy policy truly heralds a U-turn – or whether it's all just another excuse for some #outrage.
Next up, cyber crackdowns and criminal marketplaces as the UK's National Crime Agency goes softly, softly.
And finally, in "Hackers Could ..." Google's ReCaptcha can hack itself?
***
JetBrains in Solarwinds supply chain
https://www.nytimes.com/2021/01/06/us/politics/russia-cyber-hack.html
Justice Department breached
https://www.theguardian.com/technology/2021/jan/06/doj-email-systems-solarwinds-hackers
WhatsApp, Facebook, and our data
https://www.talkandroid.com/361823-whatsapp-facebook-data-privacy/
Hacking audio ReCaptcha with Google speech to text
https://www.youtube.com/watch?v=xh145UIeN9M&feature=emb_title
21 arrests in cyber crackdown
https://www.nationalcrimeagency.gov.uk/news/21-arrests-in-nationwide-cyber-crackdown
Unless you’ve been living under a rock for the past few days, you would have heard about Sunburst – a sprawling cyberattack allegedly masterminded by Russian nation-state hackers, UNC2452 (also known as Cozy Bear). Because we love talking about stuff like this, we couldn’t resist getting the crew together to go over the events of the past few days with a fine-tooth comb. There’ll be no cruising into Christmas for us!
From what SolarWinds is exactly all the way through to the impact of the attack, Chris, Kev and Paul take a proper look at Sunburst, SolarWinds, and what this means for 2021. And, because we’re a generous bunch and it is Christmas after all, we’ve created a series of labs dedicated to helping you understand and get hands-on with Sunburst – that you can access entirely for free. Check them out here.
***
Fireeye summary (including detections):
https://www.fireeye.com/blog/threat-reseaalse">ffc53578-2a09-42ac-a9e8-a06aa8514381
All aboard the hype train! We jump straight into the latest news that the supply "cold chain" for the much-awaited COVID vaccine could have been compromised. Apparently, a cyber espionage campaign has targeted the supply chain for the cold storage. BUT – and this is a big but – this all sounds a little tenuous to the team. Considering we didn't even know we had a vaccine by September, which is when the campaign was supposed to have started, how could attackers have already started targeting the supply chain?
The team also strays into 'flat earth' territority for a brief and surprising pitstop – listen out for Kev "the Director of Truth's" excellent rant, it's very enjoyable.
We also get into firmware. When was the last time you updated your firmware? From anti-adultery mattresses (yup, you read that right) to smart mugs (and you read that right too!), we somehow end up with a long episode of 'hackers could...'.
***
https://www.bbc.co.uk/news/technology-55165552
https://arstechnica.com/gadgets/2020/12/iphone-zero-click-wi-fi-exploit-is-one-of-the-most-breathtaking-hacks-ever/
As part of our series on the Psychology of Cyber, we're joined by special guests, Rebecca McKeown and Swati Singh to discuss the human challenges that are inherent in cyber crises. We take a deep dive into how do organizations prepare for the worse – and how their all important human capabilities factored in.
Rebecca McKeown is a Psychologist specialising in how humans respond in pressurised situations. She is a guest lecturer at Cranfield University and has worked with the UK's Ministry of Defence to help the armed forces build more agile human assets.
Swati Singh is the Head of Business Information Security and Resilience at Close Brothers, and has 20 years of IT industry experience working in multinational companies.
Oh and we have Chief Cyber Officer, Max Vetter too, who might pipe up at some point...
You might have guessed from the title, but in this episode, we’re looking at how to hack an election. It’s basically one long “hackers could…” feature.
We cover everything from outright deception to social engineering to power cuts to…well, real hacking. Naturally, we couldn’t have this conversation without Cambridge Analytica, the 2016 election and Brexit coming into it. Does what Cambridge Analytica did count as ‘hacking an election’ or is it just political campaigning in the 21st Century? What would happen if someone were to take control of the algorithm of a social media platform that people trust for their news?
From the publisher's feed