Threat actors are really enjoying home networks and BYOD these days…
On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:
Why our LastPass/DPRK hunch weakenedCISA launches ransomware warning programIs the Ring data extortion real?White House flags cloud service security regulationPig Butchering overtakes BEC as top cybercrime earnerMuch more!This week’s show is sponsored by Yubico. The company’s COO, Jerrod Chong, is this week’s sponsor guest.
Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.
Show notes
Stealing the LIGHTSHOW (Part One) — North Korea's UNC2970 | MandiantStealing the LIGHTSHOW (Part Two) — LIGHTSHIFT and LIGHTSHOW | MandiantNorth Korean hackers target security researchers with a new backdoor | Ars TechnicaRing won’t say if it was hacked after ransomware gang claims attack | TechCrunchBiden admin’s cloud security problem: ‘It could take down the internet like a stack of dominos’ - POLITICOCISA unveils ransomware warning pilot for critical infrastructureData breach hits lawmakers and staff on Capitol HillHacker posts more D.C. Health Link data online, exposing lawmakers' personal information | CyberScoopCancer patient sues medical provider after ransomware group posts her photos online | CyberScoopTelehealth startup Cerebral shared millions of patients’ data with advertisers | TechCrunchThe FBI Just Admitted It Bought US Location Data | WIRED‘Pig Butchering’ Scams Are Now a $3 Billion Threat | WIREDMalware infecting widely used security appliance survives firmware updates | Ars TechnicaPeople Used Facebook's Leaked AI to Create a 'Based' Chatbot that Says the N-WordOpenAI releases GPT-4, artificial intelligence that can 'see' and do taxesAustralian official demands Russia bring criminal hackers ‘to heel’DEV-1101 enables high-volume AiTM campaigns with open-source phishing kit - Microsoft Security BlogSued by Meta, Freenom Halts Domain Registrations – Krebs on SecurityTwitter’s Most Important Anti-Censorship Tool Is Currently DeadCVE-2023-23415 - Security Update Guide - Microsoft - Internet Control Message Protocol (ICMP) Remote Code Execution VulnerabilityCVE-2023-23397 - Security Update Guide - Microsoft - Microsoft Outlook Elevation of Privilege Vulnerability