
Sign up to save your podcasts
Or


Things are a little different chez Cyber Humanity this week, as we're joined by cyber start-up savants, Grace Cassy of Cylon and Rob Newby of Procordr.
We hear about how our guests fell into cybersecurity (always an interesting topic of conversation) and what's being done to produce and nurture more quality security start ups, particularly in the UK and EU. We take a look at the differences between US and UK-founded cyber start ups and the relationship between the public and private sectors in both. What can the government do to encourage innovation in start ups?
Next we hear from Rob about the transition between a cushy full time job and starting up your own company. What does it take to bite the bullet and jump into the unknown like that?
Grace Cassy
Grace co-founded CyLon in 2015, having worked in the UK Diplomatic Service and as an advisor to Prime Minister Tony Blair. Read her story here: https://cylonlab.com/our-team/grace-cassy/
Rob Newby
Rob was CISO for SmartDCC, the company responsible for rolling out Smart Meters across the UK, before founding Procordr this year. Read his story here: https://www.procordr.com/about
First up in today's episode: 16,000 confirmed COVID-19 cases mysteriously go missing from an Excel spreadsheet as part of the UK's 'track & trace' system. We don't like to speculate, but it looks like someone might have been using a legacy version of Excel... But Kev tries hard to stay upbeat about it all.
Experienced fraudsters have made off with $15m from an American company after gaining access to email conversations about a commercial conversation with "surgical precision". Kev talks us through what a 'man in the email' attack – which is what this was – entails and how to mitigate it (spoiler alert: JUST USE 2FA!).
Next, Cisco got hit with a $1.9billion judgement in a security patent lawsuit and the team struggles to pronounce 'Centripetal'. Said impossible-to-pronounce company raised the complaint against Cisco for infringing on four security patents related to encrypted traffic and packet filtering technology them. Of course, Paul is thrilled (we all know his feelings on Webex – and if you don't, you're about to...).
And in this week's 'Hackers could...', we have an absolutely ridiculous (*ahem*) story about hackers locking users into a product called Cellmate – which is a male chastity gadget. Cue much giggling...
***
Excel-ent security:
https://www.theverge.com/2020/10/5/21502141/uk-missing-coronavirus-cases-excel-spreadsheet-error
Man in the email:
https://www.infosecurity-magazine.com/news/experts-warn-of-15-million-global/
Cisco's expensive week:
https://www.networkworld.com/article/3584836/cisco-slapped-with-19-billion-judgement-in-security-patent-lawsuit.html
Cellmate:
https://www.bbc.co.uk/news/technology-54436575
It's that time of the month: Patch Tuesday October 2020 has just passed so naturally we need to talk about it. Kev has clearly been bottling up some feelings about Bad Neighbor/ping of death attacks, and we wonder whether the hype is really merited.
Next up, the most famous ballerina in cyber. If you've been anywhere near Twitter over the past few weeks, you've probably seen the advert we're talking about, which depicts a ballerina and the caption "Fatima's next job could be in cybersecurity (she just doesn't know it yet)". Naturally outrage – and many many memes – ensued, and there's nothing we like talking about more than Twitter-based fury. Although interestingly we did spot some tumbleweed in the infosec community...
Who nuked Trickbot? U.S. Cyber Command said it was them – then Microsoft and co piped up and said they should get the credit! We take a deep dive into just what's going on.
***
Microsoft fixes Ping of Death Flaw in Windows:
https://duo.com/decipher/microsoft-fixes-ping-of-death-flaw-in-windows
"Fatima" Advert:
https://www.infosecurity-magazine.com/news/fatima-advert-removed-backlash/
Trickbot:
https://securityboulevard.com/2020/10/u-s-cyber-command-says-it-nuked-trickbot-but-microsoft-and-chums-claim-credit/
We love stories about the Dark Web – and we're apparently not alone in that. This week, we're talking about HackTown, which seems to be Hogwarts for wannabe hackers (just without the...magic). HackTown promises to teach registrants how to become professional cyber criminals in 2020, which is both amusing and intriguing.
The HackTown/Dark Web chat brings us neatly onto REvil, who have deposited $1m in Bitcoin on a Russian-speaking hacker forum to attract new hacker talent to join their criminal activities.
Also featuring this week is HP. A researcher uncovered a severe vulnerability in HP Device Manager – yeah, not that exciting in itself. What is exciting, however, is all the tantrums and drama around the disclosure process that followed. Maybe next time HP will learn to lock the backdoor.
***
HackTown:
https://www.forbes.com/sites/daveywinder/2020/09/28/this-hacker-university-offers-dark-web-cybercrime-degrees-for-125/#41c700c145f2
REvil are hiring:
https://www.cpomagazine.com/cyber-security/revil-ransomware-gang-deposits-1-million-for-recruitment-on-a-russian-speaking-hacker-forum/
HP forgot to lock the backdoor:
https://www.bleepingcomputer.com/news/security/hp-device-manager-backdoor-lets-attackers-take-over-windows-systems/
This episode is a little different to normal – and all because Kev went poking around in Fitbit.
Kev, doing what Kev does, found a flaw in the Fitbit App Store that allowed him to deliver a malicious application from fitbit.com. The spyware/stalkerware was capable of stealing everything from location and personal body data to to connection got company networks for a range of malicious actions – and because it was delivered from fitbit.com, it bypassed protections and installed inside the Fitbit app as if it were legitimate. The flaw was reported to Fitbit who have since moved to mitigate it.
In this special edition of Cyber Humanity, we join Chris Pace, Kev Breen and our guest cyber PR Svengali, Anthony D’Alton, to discuss Kev’s findings and their implications from every perspective. If you’re more of a reader than a listener, you can check out this blog post on Kev’s research.
First up in this week’s episode is news that, as part of its ‘notarization’ process, Apple approved code used by Shlayer, the most common threat faced by Macs last year. Is it reasonable to expect Apple – or any app store – to keep their entire ecosystem squeaky clean at all times, or is it up to the user to always be sceptical about what they’re downloading?
Next up, another perfect 10 vulnerability. This one, Zerologon, was (luckily) patched back in August, but had the potential for eye-watering consequences. Considering the details of the vulnerability were not made public at the time, users and admins never knew how severe it really was – until now. Thanks to Kev, we get to see it in all its glory. Oh and by the way, we have a lab on this vulnerability, so if you’re a user, log on to check it out. And if you’re not a user…well, maybe you should be.
APT 41 makes an appearance next as five alleged Chinese citizens have been accused of hacking over 100 companies. Paul borders on seriously ranty territory (nothing new here) and Kev sheds some light on the ridiculous Zone-H.
And finally, our ever-popular ‘Hackers could…’ feature covers everything from the fairly noteworthy to the downright groan-inducing. Do people *really* still share photos of their shiny new credit cards?
***
Apple vs Shlayer:
https://arstechnica.com/information-technology/2020/09/mac-malware-gets-apples-seal-of-approval-thanks-to-notarization-goof/
Zerologon:
https://www.zdnet.com/article/zerologon-attack-lets-hackers-take-over-enterprise-networks/
APT 41:
https://techcrunch.com/2020/09/16/justice-department-charges-apt41-chinese-hackers/
We want to talk about Edward Snowden. It’s harder than you would imagine, considering most of the Cyber Humanity team have at some point worked for government agencies and therefore can’t quite remember what they do and “don’t” know about him. Even so, he’s still in the public eye even after all this time, and there are certainly some lessons to be learnt and ridiculous happenings to puzzle over.
Hopefully Paul, Immersive Labs’ resident International Man of Mystery, won’t be facing a prison sentence by the end of this episode.
***
https://www.theguardian.com/us-news/2020/sep/03/edward-snowden-nsa-surveillance-guardian-court-rules
https://www.wired.com/story/edward-snowden-in-his-own-words-why-i-became-a-whistle-blower/
What’s been bugging the team recently? Slack’s bug bounty – if it can even be called that – causes some consternation in this episode and raises serious questions about bug bounty programs. The bug in question was classified as a ‘critical’ RCE vulnerability and yet the researcher who discovered it only got $1750. Yup, you read that right. Apparently doing the right thing doesn’t always pay, but if you’re like Kev you might end up with some free chicken or a heartfelt ‘thank you’. We’re absolutely certain that such rewards are enough to keep people on the responsible disclosure side of the fence…
Also covered in this episode is the strange news that a Russian national was arrested for trying to convince a Tesla employee into installing malware onto the company’s network for the tasty sum of $1m. Color us intrigued…
***
Slack Bug Bounty:
https://mashable.com/article/slack-fixes-critical-remote-code-execution-vulnerabilitybug-bounty/?europe=true
Tesla Hacking Plot:
https://www.zdnet.com/article/elon-musk-confirms-russian-hacking-plot-targeted-tesla-factory/
We have a vaccine! No, not that one. The Emotet vaccine has been quietly doing the rounds over the last few months. Kev gives a nice overview of malware vaccines and how this particular one works.
We also chat about circles of trust, old boys’ networks and secret handshakes, and the part they pay in intelligence sharing and international collaboration on cybersecurity. Who decides who’s inside the circle?
Next up, the secret service has been buying location data. This in itself isn’t new; however, they’re now getting around getting warrants by buying location data off private companies. Sure, it’s publicly available – but should governments and law enforcement be buying it when they should be held to a higher standard? Of course the ex gov type believes that governments couldn’t possibly break the law (listen carefully – this might be the only time Chris has ever been shocked to silence), so isn’t it in safe hands?
And finally, could hackers hack your car?! Hack your kettle?! Listen to your keys?! GASP! More to the point: why would they want to? If you’re looking for some light entertainment, these articles are well worth a read.
Emotet Vaccine:
https://threatpost.com/emocrash-exploit-emotet-6-months/158414/
Australia's new cybersecurity strategy:
https://www.itnews.com.au/news/govt-finally-unveils-australias-new-cyber-security-strategy-551358
Secret Service buys location data that would otherwise need a warrant:
https://arstechnica.com/tech-policy/2020/08/secret-service-other-agencies-buy-access-to-mobile-phone-location-data/
Hackers could hijack lane keeping systems to control your car:
https://www.autoevolution.com/news/hackers-could-hijack-lane-keeping-systems-to-control-your-car-experts-warn-147642.html
If you notice the team being a little bit more careful with their words than usual, it's because the topic of this episode is...a SANSitive one.
We'll leave it like that, shall we?
We also chat about the NCC/CREST/GitHub debacle, which sparks debate over how valuable certifications are when they can be played with 'leaked' step-by-step guides. Is there any real-world value in simply learning how to pass an exam? Does a certification truly indicate aptitude?
The topic turns next to facial recognition in law enforcement, following the news that Liberty won the first international case banning the use of facial recognition technology for policing. It's a serious debate – that gets a bit dystopian at times – and we take a look at it from every angle.
***
SANS data breach:
https://www.bleepingcomputer.com/news/security/sans-shares-details-on-attack-that-led-to-their-data-breach/
NCC/Crest:
https://www.theregister.com/2020/08/14/crest_investigates_ncc_group/
Liberty wins facial recognition technology case:
https://iottechnews.com/news/2020/aug/11/liberty-wins-case-banning-police-facial-recognition/
From the publisher's feed