On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:
Half of all UK COBRA meetings are ransomware relatedRansomware biggest risk to US port securityWhite House to move on spyware industryEU to launch its own Starlink equivalentMuch, much moreAttackIQ’s Jonathan Reiber will be joining us in this week’s sponsor interview to talk about how companies and their boards are really moving towards outcomes-based security programs.
Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.
Show notes
Ransomware incidents now make up majority of British government’s crisis management COBRA meetings - The Record by Recorded FutureDHS Secretary: Cyberattacks are the most significant threat to port infrastructure - The Record by Recorded FutureMichigan school districts reopen after three-day closure due to ransomware attack - The Record by Recorded FutureMicrosoft: Royal ransomware group using Google Ads in campaign - The Record by Recorded FutureResearchers Quietly Cracked Zeppelin Ransomware Keys – Krebs on SecurityRisky Biz News: Cyber Partisans hack and disrupt Kremlin censorUS, Estonian authorities arrest two over $575 million cryptocurrency fraud - The Record by Recorded FutureNew FTX CEO details 'complete failure of corporate controls' at crypto platformOpenSSL Usage in UEFI Firmware Exposes Weakness in SBOMsEU reaches agreement on new satellite constellation - The Record by Recorded FutureUkraine’s Engineers Dodged Russian Mines To Get Kherson Back Online–With A Little Help From Elon Musk’s SatellitesSenate Democrats call on FTC to investigate Twitter's data security11.17.22 - FTC - Twitter LetterTwitter has a lot of your data. Here's what you can do about it.Mastodon vulnerable to multiple system configuration problems | The Daily SwigSystem misconfiguration is the number one vulnerability, at least for MastodonWhite House expected to issue executive order reining in spywareH20220930-005_Himes-Speier cc's - DocumentCloudA Leak Details Apple's Secret Dirt on Corellium, a Trusted Security Startup | WIREDRisky Biz News: Iranian state hackers breached US government agency and deployed a cryptominer, out of all thingsIndia removes ban on VLC media player after cybersecurity concerns addressed - The Record by Recorded FutureAmazon addresses vulnerability affecting AWS AppSync - The Record by Recorded FutureCVE-2022-41924 - RCE in Tailscale, DNS Rebinding, and YouIranian Islamic Revolutionary Guard Corps-Affiliated Cyber Actors Exploiting Vulnerabilities for Data Extortion and Disk Encryption for Ransom Operations | CISAImpacket and Exfiltration Tool Used to Steal Sensitive Information from Defense Industrial Base Organization | CISA