NOTE: Patrick’s audio is a bit degraded in a few parts of this episode. It’s still clear enough, but if you hear some degradation in parts then yes, it’s us, not you.
On this week’s show Patrick Gray, Adam Boileau and Tom Uren discuss the week’s security news. They cover:
The Biden White House’s executive order on spywareWhy the infosec community writ large is wrong on TikTokClop campaign: it’s time to ditch your file transfer gatewaysMajor Android app booted from store because it was full of 0day privesc exploits lolMore detail on the BreachForums admin arrestMuch, much moreThis week’s show is brought to you by runZero. HD Moore, co-founder of runZero, is this week’s sponsor guest.
Links to everything that we discussed are below and you can follow Patrick, Adam and Tom on Mastodon if that’s your thing.
Show notes
At least 50 U.S. government employees hit with spyware, White House saysKevin McCarthy says House 'will be moving forward' with TikTok legislationUS lawmakers tell TikTok CEO the app ‘should be banned’Between Two Nerds: The Real Problem with TikTok - Risky BusinessNew victims come forward after mass-ransomware attack | TechCrunchUK Pension Protection Fund latest victim of GoAnywhere hackCrown Resorts investigating potential data breach after being contacted by hacking group - ABC NewsFortra told breached companies their data was safe | TechCrunchWhen to use Dropbox vs. MFT: Best Versatile File Sharing and Security | GoAnywhere MFTCity of Toronto and Virgin confirm hackers accessed data through file transfer systemsTasmania investigating attack after Clop ransomware group adds to victim listLatitude Financial faces possible class action after millions affected by data breach | Australia news | The GuardianAndroid app from China executed 0-day exploit on millions of devices | Ars TechnicaTelecom giant Lumen says it discovered two separate cyber intrusionsTennessee city hit with ransomware attackFBI, CISA investigating cyberattack on Puerto Rico’s water authorityBritish hospital investigating impact of ‘contained’ cyber incidentLargest telecom in Guam starts restoring services after cyberattackFrustrated Dish customers still spending hours on hold weeks after ransomware attack, they sayUK National Crime Agency reveals it ran fake DDoS-for-hire sites to collect users’ dataHow the FBI caught the BreachForums admin | TechCrunchHacker tied to D.C. Health Link breach says attack 'born out of Russian patriotism' | CyberScoopNorth Korean APT group ‘Kimsuky’ targeting experts with new spearphishing campaignNorth Korea Is Now Mining Crypto to Launder Its Stolen Loot | WIRED“Committed Partners in Cyberspace”: Following cyberattack, US conducts first defensive Hunt Operation in Albania > U.S. Cyber Command > NewsBad magic: new APT found in the area of Russo-Ukrainian conflict | SecurelistBeloved hacking veteran Kelly ‘Aloria’ Lum passes away at 41 | TechCrunch