On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:
Twitter bluechecks face phishing barrageAustralian government goes berserk on Medibank hack responseFormer WSJ journalist sues law firm over email hack and info op that got him firedOpenSSL bug lands with a whimperApple macOS Ventura update breaks security toolsMuch, much moreThis week’s show is brought to you by Thinkst Canary. Marco Slaviero, Thinkst’s head of engineering, joins us this week to talk through the company’s latest release, codenamed Quokka.
Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.
Show notes
Twitter’s verification chaos is now a cybersecurity problem | TechCrunchUnconfirmed hack of Liz Truss’ phone prompts calls for “urgent investigation” | Ars TechnicaChinese hackers are scanning state political party headquarters, FBI says - The Washington PostFormer WSJ reporter says law firm used Indian hackers to sabotage his career | ReutersThe source - Columbia Journalism ReviewUpcoming ‘critical’ OpenSSL update prompts feverish speculation | The Daily SwigOpenSSL vulnerability downgraded to ‘high’ severity | The Daily SwigMedibank says hackers had access to ‘all personal data’ belonging to all customers - The Record by Recorded FutureAustralia to tighten privacy laws, increase fines after series of data breaches - The Record by Recorded FutureVotes in Slovakia's parliament suspended after alleged ‘cybersecurity incident’ - The Record by Recorded FutureNY Post confirms hack after website, Twitter feed flooded with threats toward Biden, AOC - The Record by Recorded FutureApple MacOS Ventura Bug Breaks Third-Party Security Tools | WIREDMicrosoft ties Vice Society hackers to additional ransomware strains - The Record by Recorded FutureHow Vice Society Got Away With a Global Ransomware Spree | WIREDFTC seeks action against Drizly — and its CEO — for cybersecurity failures - The Record by Recorded FutureCritical authentication bug in Fortinet products actively exploited in the wild | The Daily SwigGoogle Play apps with >20M downloads depleted batteries and network bandwidth | Ars TechnicaBattle with Bots Prompts Mass Purge of Amazon, Apple Employee Accounts on LinkedIn – Krebs on SecurityMicrosoft leaked 2.4TB of data belonging to sensitive customer. Critics are furious | Ars TechnicaMicrosoft disputes report on Office 365 Message encryption issue after awarding bug bounty - The Record by Recorded FutureMicrosoft Office Online Server open to SSRF-to-RCE exploit | The Daily SwigMicrosoft's Sociopathic Cybersecurity PedantryBrazilian police announce arrest of alleged Lapsus$ member - The Record by Recorded FutureAccused ‘Raccoon’ Malware Developer Fled Ukraine After Russian Invasion – Krebs on SecurityEuropean gang that sold car hacking tools to thieves arrested - The Record by Recorded FutureHow a Microsoft blunder opened millions of PCs to potent malware attacks | Ars Technica