On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:
More Exchange 0days cause more havocA look at some earlier Exchange hack incidentsHow the CIA got its agents killed with its truly awful online opsecEx NSA staffer arrested for espionageMuch, much moreThis week’s show is brought to you by Proofpoint. Ryan Kalember, Proofpoint’s EVP of cybersecurity strategy, joins the show this week to talk about some overlooked detection opportunities – some simple stuff you can look for in your environment that should raise gigantic flashing red flags.
Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.
Show notes
Microsoft confirms two Exchange Server zero days are being used in cyberattacks - The Record by Recorded FutureCISA: Multiple government hacking groups had ‘long-term’ access to defense company - The Record by Recorded FutureMexican president confirms ‘Guacamaya’ hack targeting regional militaries - The Record by Recorded FutureMexican journalists targeted by zero-click spyware infections - The Record by Recorded FutureEx-NSA employee charged with violating Espionage Act, selling U.S. cyber secretsPutin grants citizenship to Edward Snowden, who disclosed US eavesdropping - The Washington PostU.S. fails in bid to extradite Brit for helping North Korea evade sanctions with cryptocurrency - The Record by Recorded FutureBill Marczak on Twitter: "NEW REPORT today from @Reuters @JoelSchectman providing more detail about fatal flaws in the CIA's defunct communications network. Iran and China compromised the network in 2011, and killed dozens of CIA assets https://t.co/AwN8pQtWL2" / TwitterNumerous orgs hacked after installing weaponized open source apps | Ars Technica'Poisoned' Tor Browser tracks Chinese users' online history, locationMystery Hackers Are ‘Hyperjacking’ Targets for Insidious Spying | WIREDA Matrix Update Patches Serious End-to-End Encryption Flaws | WIREDLA officials confirm ransomware group leaked students’ personal data - The Record by Recorded FutureNearly 700 ransomware incidents traced back to wholesale access markets: report - The Record by Recorded FutureSemiconductor industry faced 8 attacks from ransomware groups, extortion gangs in 2022 - The Record by Recorded FutureCISA directs federal agencies to track software and vulnerabilities - The Record by Recorded FutureFake CISO Profiles on LinkedIn Target Fortune 500s – Krebs on SecurityHouse Democrats debut new bill to limit US police use of facial recognition | TechCrunchEP000: Operation Aurora | HACKING GOOGLE - YouTube