
Sign up to save your podcasts
Or


The dust from Garmin's scrimmage with WastedLocker is just about settling – potentially at the cost of $10 million dollars. Kev sheds light on the matter from a technical standpoint, and we learn why it's really unlikely Garmin would have been able to decrypt their files without paying up to the perpetrators.
It seems we can't go a week without talking TikTok and privacy – and if anyone will let Max get a word in sideways, we might even hear his thoughts on it. Privacy advocates be warned!
Maze makes another appearance. In an altruistic turn of events, they're giving their targets a chance to pay up before outing them to the public. They'll only encrypt the important bits...colour us intrigued.
Oh and PSA: if you haven't checked out our WastedLocker labs yet, you can log in here or book a demo to check them out.
As you might have guessed from the title, the Twitter hack is the focus of this episode – specifically, the kids behind the attack. Why are youngsters so much more likely to turn to cyber crime? How can we guide them onto a more ethical path, while still giving them the opportunity to explore their incredible cyber talents?
Kev shares a blast from the past and tells us about his path to cyber. Buckle up, because it’s a good’un! Of course, he maintains that he’s stayed firmly away from any shades of grey during his early cyber years. We totally believe you, Kev!
We couldn’t cover the Twitter hack story without discussing the somewhat salacious interlude during the court case. How is it that Max can’t even share his screen on Zoom due to security restrictions, but someone can get onto a major court case and share porn?
Finally, and most importantly, we puzzle over why these kids merited an entire task force when there are entire criminal organizations out there monetizing malware and doing real harm. Tune in to find out!
UK and US Teens Arrested over Twitter Hack
https://www.theguardian.com/technology/2020/jul/31/twitter-hack-arrests-florida-uk-teenagers
Twitter Hack Hearing Zoom Bombed
https://www.bloomberg.com/news/articles/2020-08-05/twitter-hacker-s-virtual-bail-hearing-is-hacked-by-porn-bombs
He ransomware, she ransomware, they all ransomware!
Yup, you guessed it: this week's episode is all about ransomware. We start with Garmin's interesting handling of their recent tryst with WastedLocker, which largely involved them saying nothing at all to anyone. Then we move on to Blackbaud, who took the opposite stance by telling everyone everything and promising that absolutely on no account has the breached data gone any further than the cybercriminals responsible. Because criminals are renowned for their honesty, right?
Staying on the ransomware theme, we wonder whether Garmin could – or should – have learned lessons from Travelex's new year nightmare and Norsk Hydro's run in with LockerGoga in 2019.
We also take a look at app sec with Sean Wright, Mr App Sec himself at Immersive Labs and our guest for this week.
Incidentally, Immersive Labs released three new labs on WastedLocker this week, so if you want to learn more about how it works and the part it played in the Garmin hack, head over to this blog. If you already have a license (alright, no need to boast), log in here.
Garmin WastedLocker attack
https://www.forbes.com/sites/leemathews/2020/07/23/garmins-alleged-ransomware-wastedlocker-evil-corp
Blackbaud pay the ransom
https://www.computerweekly.com/news/252486910/List-of-Blackbaud-breach-victims-tops-120
Imagine our surprise when we were casually browsing Twitter one evening and then got offered $2,000 for every $1,000 we sent to Jeff Bezos. Now that's a good deal... Naturally our curiosity was piqued and in today's episode we take a deeper look at this high profile hack.
Apparently you can now hack chargers to destroy devices. What a world we live in!
And Charming Kitten – the cyberwarfare group also known as APT35 – has hit headlines this week as IBM X-Force discovered videos of the group's hackers teaching others to efficiently take control of social media accounts, email accounts etc. It's basically cybersecurity training for state-sponsored hackers... Colour us intrigued.
Twitter hack:
https://www.bbc.co.uk/news/technology-53425822
BadPower
https://gizmodo.com/new-hack-can-trick-power-bricks-into-starting-fires-1844441247
Charming Kitten videos
https://www.zdnet.com/article/iranian-cyberspies-leave-training-videos-exposed-online/
The one that got Huawei. We discuss the controversy around the Chinese company and the role it plays in the UK’s network, which has been rumbling on for years. Now it seems to be coming to a head – and headlines proclaiming the potential for the ‘9/11 of cybersecurity’ aren’t helping matters…
Next, we need to do talk about TikTok. Or do we? Is it as much of a sh*t storm as the media is making it out to be, or does all it boil down to good old fashioned paranoia with a sprinkling of personal vendetta from a certain politician thrown in?
Kev reaches level 10 on the rant-o-meter over his latest findings in F5 – you have been warned – and another two CVEs with perfect 10 CVSS scores hit the headlines.
Huawei kit to be removed from UK 5G:
https://www.bbc.co.uk/news/technology-53403793
Trump wants TikTok ban:
https://www.theguardian.com/technology/2020/jul/16/tiktok-video-sharing-app-should-you-delete-it
In this week’s episode, we take a look at the recent critical vulnerabilities in F5, which scored a perfect 10 CVSS score, and Kev sheds some light on what made it such a perfect storm.
We also have a little think about why companies with the most security tools and platforms in place feel the least secure. Does more always mean better?
Next, we debate the fact that there’s surely no debate around changing names like ‘blacklist’ and ‘whitelist’ for far more logical and inclusive terminology. Approve and deny lists, anyone?
And what do £54m in cash, a lot of drugs, a torture chamber, and an encrypted phone system have in common? Let us – or the NCA – tell you. And no, it’s not a really great party.
F5 vulnerability:
https://www.helpnetsecurity.com/2020/07/06/exploit-cve-2020-5902/
IBM security technology report:
https://www.zdnet.com/article/the-more-cybersecurity-tools-an-enterprise-deploys-the-less-effective-their-defense-is/
NCA cracks EncroChat:
https://www.independent.co.uk/news/uk/crime/encrochat-phone-network-encryption-organised-crime-uk-arrests-police-a9597501.html
In this week’s episode, we revisit the thin blue line, this time with a focus on a Wikileaks-style data dump called ‘Blue Leaks’. 270GB of police data – 24 years’ worth from over 200 departments – was leaked in what has been dubbed ‘a more transparent alternative to Wikileaks’. Could it be a catalyst for change or a danger to life?
We also spin the Random Ransom Generator and try to wrap our heads around Maze’s recent official announcement that they’re disappointed to see companies trying to decrypt their files themselves. Yup, you read that one right.
And what’s going on Down Under? The Australian government grapples with a sophisticated state-based actor. We take a look at their advisory to see what we can find out.
Blue Leaks
https://www.forbes.com/sites/thomasbrewster/2020/06/22/blueleaks-huge-leak-of-police-department-data-follows-george-floyd-protests/
Maze Ransomware announcement
https://securityboulevard.com/2020/06/stuck-between-a-data-breach-and-a-ransom/
Australian Advisory includes MITRE T-numbers
https://portswigger.net/daily-swig/know-thine-enemy-australian-cyber-security-centre-spotlights-most-popular-cyber-attack-techniques
In this episode, we take a look at some recent faux-pas that have been making headlines. Facebook helps develop a zero-day exploit in Tails to catch a prolific predator and then keeps it all very quiet. A South African bank discovers what happens when a single master key can decrypt literally everything – and one of their employees decides to print it out. And it’s fappening all over again as 845GB of explicit pictures, audio files and dirty laundry are leaked from a number of dating sites’ insecure AWS buckets. Oh, and we find out what Kev really thinks about the internet. Warning: it’s explicit.
Facebook vs Predator: https://www.schneier.com/blog/archives/2020/06/facebook_helped.html
Postbank's master key nightmare: https://www.zdnet.com/article/south-african-bank-to-replace-12m-cards-after-employees-stole-master-key/
More reasons to avoid Herpes Dating: https://www.wired.com/story/dating-apps-leak-explicit-photos-screenshots/
In this episode we take a much closer look at the applications of Open Source Intelligence (OSINT) in both offensive and defensive operations, including Paul's growing excitement about the dark web (mainly because he thinks it sounds like Geocities. Google it, kids).
Now it's automotive giant Honda's turn to fall victim to what seems to be a fairly crippling cyberattack. And while they aren't giving anything away, it seems cloud malware analyzer VirusTotal did have enough accessible information to tip off security researchers that Snake ransomware was the culprit. We also dive into Dark Basin with a look at The Citizen Lab's hacker-for-hire intelligence analysis. And Call Stranger: cool name, great logo, but how bad is it?
Honda attack: https://www.darkreading.com/attacks-breaches/ics-threat-snake-ransomware-suspected-in-honda-attack/d/d-id/1338075
Dark Basin report: https://citizenlab.ca/2020/06/dark-basin-uncovering-a-massive-hack-for-hire-operation/
Call Stranger: https://www.zdnet.com/article/callstranger-vulnerability-lets-attacks-bypass-security-systems-and-scan-lans/
From the publisher's feed