Persist Cyber Defenders

Persist Cyber Defenders

By Persist SecurityTechnologyTrue Crime
Download on the App Store

Persist Cyber Defenders episodes

  • Remote Control on the Highway — Fiat Chrysler Automobiles (FCA), 2015

    This is the story of The Jeep Cherokee Hack: Remote Control on the Highway. It began quietly — the way these stories almost always do. No injuries or fatalities occurred.

    Chapters

    00:00 — Prologue
    00:54 — Cold Open
    01:40 — The System
    02:26 — The Way In
    03:12 — Inside The Walls
    03:58 — The Turning Point
    04:44 — The Cost
    05:30 — The Human Toll
    06:16 — Recovery
    07:02 — The Defenders
    07:48 — What It Left Behind
    08:34 — Disclosure
    08:42 — Epilogue

    Sources

    Hackers Remotely Kill a Jeep on the Highway—With Me in It (Wired, Andy Greenberg)
    FCA US LLC Safety Recall V36 - Software Update for Radio/Uconnect Software
    Remote Exploitation of an Unaltered Passenger Vehicle (Miller & Valasek research paper)
    Black Hat USA 2015: Remote Exploitation of an Unaltered Passenger Vehicle
    NHTSA Opens Investigation into Fiat Chrysler Handling of Uconnect Vulnerability

    This is a dramatized retelling based on public reporting. Some moments were reconstructed from the record to convey how events unfolded; no words were ever put in the mouth of a real, named person. Everything treated as fact is drawn from government reports and first-hand journalism, cited below.

    Persist Security helps teams stay resilient against threats like these. Learn more at https://persistsec.com.

    10 min
  • The Most Destructive Cyberattack in History — A.P. Moller-Maersk (and global), 2017

    Maersk shipping traffic (20% of global trade) paralyzed for a week, disrupting supply chains worldwide.

    Chapters

    00:00 — Prologue
    00:54 — Cold Open
    03:05 — The System
    05:16 — The Way In
    07:27 — Inside The Walls
    09:38 — The Turning Point
    11:49 — The Cost
    14:00 — The Human Toll
    16:10 — Recovery
    18:21 — The Defenders
    20:32 — What It Left Behind
    22:43 — Disclosure
    23:07 — Epilogue

    Sources

    The Untold Story of NotPetya, the Most Devastating Cyberattack in History
    Grand Jury Indictment: United States v. Yuriy Sergeyevich Andrienko et al.
    Statement from the Press Secretary on the Attribution of NotPetya to Russia
    NCSC and International Partners Condemn Russian Cyber Activity
    Statement on Cyber Attack - Update 3
    Alert (TA17-181A): Petya Ransomware
    New ransomware, old techniques: Petya adds worm capabilities
    ExPetr/Petya/NotPetya is a Wiper, Not Ransomware

    This is a dramatized retelling based on public reporting. Some moments were reconstructed from the record to convey how events unfolded; no words were ever put in the mouth of a real, named person. Everything treated as fact is drawn from government reports and first-hand journalism, cited below.

    Persist Security helps teams stay resilient against threats like these. Learn more at https://persistsec.com.

    24 min
  • The Teenage Phone Call That Broke the Internet — Twitter,, 2020

    This is the story of Twitter 2020 Account Hijacking: The Teenage Phone Call That Broke the Internet. It began quietly — the way these stories almost always do. 130 Twitter accounts were compromised, with 45 actually used to post scam tweets.

    Chapters

    00:00 — Prologue
    00:54 — Cold Open
    01:41 — The System
    02:27 — The Way In
    03:14 — Inside The Walls
    04:00 — The Turning Point
    04:46 — The Cost
    05:33 — The Human Toll
    06:19 — Recovery
    07:05 — The Defenders
    07:52 — What It Left Behind
    08:38 — Disclosure
    08:46 — Epilogue

    Sources

    DOJ: Three Individuals Charged for Alleged Roles in Twitter Hack
    Twitter: An update on our security incident (July 30, 2020)
    FBI investigating cyber intrusion at Twitter
    Senate Select Committee on Intelligence inquiry

    This is a dramatized retelling based on public reporting. Some moments were reconstructed from the record to convey how events unfolded; no words were ever put in the mouth of a real, named person. Everything treated as fact is drawn from government reports and first-hand journalism, cited below.

    Persist Security helps teams stay resilient against threats like these. Learn more at https://persistsec.com.

    10 min
  • The Ransomware That Stopped the World — NHS (UK) and global, 2017

    19,000 NHS appointments cancelled.

    Chapters

    00:00 — Prologue
    00:54 — Cold Open
    03:13 — The System
    05:32 — The Way In
    07:51 — Inside The Walls
    10:10 — The Turning Point
    12:29 — The Cost
    14:48 — The Human Toll
    17:07 — Recovery
    19:26 — The Defenders
    21:45 — What It Left Behind
    24:03 — Disclosure
    24:27 — Epilogue

    Sources

    UK Foreign Office attributes WannaCry to North Korea
    DOJ indicts Park Jin Hyok for WannaCry and other attacks
    UK National Audit Office investigation: WannaCry cyber attack and the NHS
    NCSC confirms North Korea behind WannaCry
    Microsoft WannaCry ransomware analysis
    US-CERT Alert on WannaCry ransomware

    This is a dramatized retelling based on public reporting. Some moments were reconstructed from the record to convey how events unfolded; no words were ever put in the mouth of a real, named person. Everything treated as fact is drawn from government reports and first-hand journalism, cited below.

    Persist Security helps teams stay resilient against threats like these. Learn more at https://persistsec.com.

    25 min
  • The World's First Digital Weapon — Natanz enrichment facility (Iran), 2010

    No direct human casualties.

    Chapters

    00:00 — Prologue
    00:54 — Cold Open
    03:16 — The System
    05:38 — The Way In
    08:00 — Inside The Walls
    10:21 — The Turning Point
    12:43 — The Cost
    15:05 — The Human Toll
    17:26 — Recovery
    19:48 — The Defenders
    22:10 — What It Left Behind
    24:32 — Disclosure
    24:55 — Epilogue

    Sources

    W32.Stuxnet Dossier (Symantec Security Response)
    To Kill a Centrifuge (Ralph Langner)
    IAEA Report on Iran (November 2010)
    Stuxnet and the Future of Cyber War (ETH Zurich Center for Security Studies)
    The Stuxnet Enigma (Kaspersky Lab)

    This is a dramatized retelling based on public reporting. Some moments were reconstructed from the record to convey how events unfolded; no words were ever put in the mouth of a real, named person. Everything treated as fact is drawn from government reports and first-hand journalism, cited below.

    Persist Security helps teams stay resilient against threats like these. Learn more at https://persistsec.com.

    26 min
  • A 75-Cent Error That Uncovered a KGB Spy — Lawrence Berkeley National Laboratory, 1986

    One conscientious system manager's stubborn curiosity, backed by his partner and a handful of allies, exposed a state-sponsored espionage operation that bureaucracies had been slow to take seriously.

    Chapters

    00:00 — Prologue
    00:54 — Cold Open
    03:27 — The System
    05:59 — The Way In
    08:31 — Inside The Walls
    11:04 — The Turning Point
    13:36 — The Cost
    16:08 — The Human Toll
    18:40 — Recovery
    21:13 — The Defenders
    23:45 — What It Left Behind
    26:17 — Disclosure
    26:24 — Epilogue

    Sources

    Stalking the Wily Hacker — Clifford Stoll, Communications of the ACM (1988)
    Stalking the Wily Hacker (archival PDF of the CACM paper)

    This is a dramatized retelling based on public reporting. Some moments were reconstructed from the record to convey how events unfolded; no words were ever put in the mouth of a real, named person. Everything treated as fact is drawn from government reports and first-hand journalism, cited below.

    Persist Security helps teams stay resilient against threats like these. Learn more at https://persistsec.com.

    27 min
  • The Six Days the Fuel Stopped — Colonial Pipeline, 2021

    This is the story of how a single forgotten password shut off the fuel to the Eastern Seaboard. And it is the story of the people who followed the money into the dark, and took it back. Panic buying, hours-long gas-station lines, and dry pumps across the U.S. Southeast; airlines rerouted or added fuel stops; emergency declarations in 17 states.

    Chapters

    00:00 — Prologue
    00:54 — Cold Open
    02:28 — The Story
    04:03 — Before It Happened
    05:37 — The Way In
    07:11 — Escalation
    08:45 — Impact
    10:19 — The Response
    11:53 — The Reckoning
    13:27 — What It Means
    15:01 — Closing
    16:35 — Disclosure
    16:58 — Epilogue

    Sources

    DOJ seizes $2.3M in cryptocurrency paid to DarkSide
    DarkSide Ransomware: Best Practices for Preventing Business Disruption
    Senate Homeland Security hearing: Colonial Pipeline cyberattack (Blount testimony)
    FBI Statement on Compromise of Colonial Pipeline Networks
    FMCSA Regional Emergency Declaration No. 2021-002 (17 states + DC)
    DHS/TSA announces new cybersecurity requirements for critical pipeline owners
    GAO: Pipeline Security — TSA needs to strengthen oversight

    This is a dramatized retelling based on public reporting. Some moments were reconstructed from the record to convey how events unfolded; no words were ever put in the mouth of a real, named person. Everything treated as fact is drawn from government reports and first-hand journalism, cited below.

    Persist Security helps teams stay resilient against threats like these. Learn more at https://persistsec.com.

    18 min

About Persist Cyber Defenders

From the publisher's feed

A hospital's screens go dark. A pipeline stops and a coastline runs dry. A bank, a phone, a password nobody thought about — and then the people who trace it back. Persist Cyber Defenders tells the…