On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:
The supply chain attack in the supply chain attackRussia has a China dependency problemRecent research into TLS resumption flawsGoogle and Intel team up on hardware hackingDHS will hack enterprise kitMuch, much moreThis week’s show is brought to you by Corelight. Brian Dye, Corelight’s CEO, is this week’s sponsor guest. He’s talking about the (actually sensible) ChatGPT-driven features Corelight has built into its NDR platform.
Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.
Show notes
Software Maker 3CX Was Compromised in First-of-its-Kind Threaded Supply-Chain Hack - UpdatedRussia China Worries Set Out in Private Memo on Tech Risk - BloombergHackers to show they can take over a European Space Agency satelliteDOJ urges CISOs to continue working with law enforcement ahead of Uber security chief’s sentencingTo combat cybercrime, US law enforcement increasingly prioritizes disruption | CyberScoopCollaboration between CISA, Cyber Command thwarted dangerous cyberattacks, officials said | CyberScoopUS gov’t stopped Iranian hackers who ‘gained access’ to 2020 election infrastructureBill proposes new DHS centers for testing security of critical government techUK says ‘Wagner-like cyber groups’ attacking critical infrastructureRussia's digital warriors adapt to support the war effort in Ukraine, Google threat researchers say | CyberScoopBipartisan legislation aims to ‘arm Taiwan to the teeth in the cyber domain’Ex-NSA boss won $700,000 Saudi consulting deal after Khashoggi death - The Washington PostU.S. approves massive arms sale to Saudi Arabia, United Arab Emirates to counter Iran | PBS NewsHourIntel Let Google Cloud Hack Its New Secure Chips and Found 10 Bugs | WIREDGoogle’s Authenticator App Now Lets You Sync 2FA Codes Across Devices | WIREDWe Really Need to Talk About Session Tickets | System Security GroupInternet protocol vulnerability opens door to ‘massive’ DoS amplification attacksExploit released for 9.8-severity PaperCut flaw already under attack | Ars TechnicaFinding PaperCut MF and NG serversDC health exchange breach traced back to misconfigured Amazon serverUkraine remains Russia’s biggest cyber focus in 2023The hacker Bassterlord in his own words: Portrait of an access broker as a young manHacker Group Names Are Now Absurdly Out of Control | WIRED