On this week’s show Patrick Gray and Adam Boileau discuss the news we missed while on break. Because it’s the first show of the year, we split the discussion into themes:
Attacks against critical online services like Okta, CircleCI, Slack and Lastpass will increase in volumeAll the latest global intrigue, from NSO being noped by the US Supreme Court to DDoS attacks in Serbia, Turla’s latest campaign, supply chain attacks against Ukraine, why Russia has been more active than we realised and much moreA ransomware wrap, a discussion about the rise of data extortion and why it’s unlikely to remain a huge problemWhy automotive security research will actually be interesting this yearPLUS: A bunch of random news!This week’s show is brought to you by Trail of Bits. Dan Guido is this week’s sponsor guest and he joins us to talk about something they’ve developed – a zero knowledge proof of exploit technique. Very interesting stuff!
Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.
Show notes
First LastPass, now Slack and CircleCI. The hacks go on (and will likely worsen) | Ars TechnicaDevs urged to rotate secrets after CircleCI suffers security breach | The Daily SwigLastPass: Hackers accessed and copied customers’ password vaults - The Record from Recorded Future NewsGitHub incident allowed attacker to copy Okta's source code - The Record from Recorded Future NewsSupreme Court dismisses spyware company NSO Group’s claim of immunity - The Record from Recorded Future NewsSerbian government reports ‘massive DDoS attack’ amid heightened tensions in Balkans - The Record from Recorded Future NewsIran’s support of Russia draws attention of pro-Ukraine hackers - The Record from Recorded Future NewsPro-Ukraine hackers leak Russian data in hopes someone will make sense of it - The Record from Recorded Future NewsCISA researchers: Russia's Fancy Bear infiltrated US satellite networkExclusive: Russian hackers targeted U.S. nuclear scientists | ReutersNSA cyber director warns of Russian digital assaults on global energy sector - CyberScoopNotorious Russian hacking group appears to resurface with fresh cyberattacks on UkraineMilitary operations software in Ukraine was hit by Russian hackers - The Record from Recorded Future NewsNew supply chain attack targeted Ukrainian government networks - The Record from Recorded Future NewsMoldovaʼs government hit by flood of phishing attacks - The Record from Recorded Future NewsKremlin-backed hackers targeted a “large” petroleum refinery in a NATO nation | Ars TechnicaCyber Command conducted offensive operations to protect midterm elections - The Record from Recorded Future NewsGuardian newspaper hit by suspected ransomware attack, staff told not to come to office - The Record from Recorded Future NewsBritish company that helps make semiconductors hit by cyber incident - The Record from Recorded Future NewsPort of Lisbon website still down as LockBit gang claims cyberattack - The Record from Recorded Future NewsSickKids: 80% of hospital priority systems back online after LockBit ransomware attack - The Record from Recorded Future NewsCanada's largest children's hospital struggles to recover from pre-Christmas ransomware attack - The Record from Recorded Future NewsCanadian copper mine suffers ransomware attack, shuts down mills - The Record from Recorded Future NewsLos Angeles housing authority says cyberattack disrupting systems - The Record from Recorded Future NewsThe Guardian contacts data protection regulator after suspected ransomware incident - The Record from Recorded Future NewsAustralian fire service operating 85 stations shuts down network after cyberattack - The Record from Recorded Future NewsSan Francisco BART investigating ransomware attack - The Record from Recorded Future NewsHackers leak sensitive files following attack on San Francisco transit policeNew U.S. cyber strategy will require critical infrastructure companies to protect against hacks - The Washington PostCar hackers discover vulnerabilities that could let them hijack millions of vehiclesCompromised dispatch system helped move taxis to front of the line | Ars TechnicaResearcher Deepfakes His Voice, Uses AI to Demand Refund From Wells FargoArmed With ChatGPT, Cybercriminals Build Malware And Plot Fake Girl BotsCybercriminals’ latest grift: powdered milk and sugar by the truckload - The Record from Recorded Future NewsThis app will self-destruct: How Belarusian hackers created an alternative Telegram for activists - The Record from Recorded Future NewsChinese researchers claim to have broken RSA with a quantum computer. Experts aren’t so sure. - The Record from Recorded Future NewsKey bitcoin developer calls on FBI to recover $3.6M in digital coin | Ars TechnicaChick-fil-A acknowledges customer account abuse but denies compromise of internal systems - The Record from Recorded Future NewsMicrosoft ends Windows 7 security updates | TechCrunch