On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:
Germans charge FinFisher executivesThe got FBI busted misusing 702 dataSpecial guest Chris Krebs talks China, new CISA mandates and moreNew research breaks Android fingerprint authMuch, much moreThis week’s show is brought to you by Trail of Bits. Dan Guido is this week’s sponsor guest and he joins us to talk about the work Trail of Bits is doing in securing AI systems, and making them safe.
Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.
Show notes
Congress looks to expand CISA's role, adding responsibilities for satellites and open source software | CyberScoopBiden nominates Lt. Gen. Timothy Haugh for top position at NSA, Cyber CommandUnsere Strafanzeige: Staatsanwaltschaft erhebt Anklage gegen FinFisherThe Real Risks in Google’s New .Zip and .Mov Domains | WIREDFBI misused controversial surveillance tool to investigate Jan. 6 protestersSuspicion stalks Genesis Market’s competitors following FBI takedownCrimephones Are a Cop's Best Friend - by Tom UrenThe Underground History of Turla, Russia's Most Ingenious Hacker Group | WIREDSome Of Russia’s Most Dangerous Cybercriminals Just Had Their Malware Dealer UnmaskedShifting tactics fuel surge in Business Email CompromiseTreasury Department sanctions entities tied to North Korean IT scams, hacking | CyberScoopChinese Labs Are Selling Fentanyl Ingredients for Millions in Crypto | WIREDLeaked EU Document Shows Spain Wants to Ban End-to-End Encryption | WIREDHere’s how long it takes new BrutePrint attack to unlock 10 different smartphones | Ars TechnicaIt took 48 hours, but the mystery of the mass Asus router outage is solved | Ars TechnicaPopular Android TV boxes sold on Amazon are laced with malware | TechCrunchTeen hacker charged in scheme to siphon funds from sports betting accountsResearchers tie FIN7 cybercrime family to Clop ransomwareGerman arms company Rheinmetall confirms Black Basta ransomware group behind cyberattackDallas courts still closed 2 weeks post-ransomware attack | Cybersecurity DiveHealth insurer says patients’ information was stolen in ransomware attackPatients angered after Oklahoma allergy clinic blames cyberattack for shutdownUK steel industry supplier Vesuvius says ‘cyber incident’ cost £3.5 millionResearchers infiltrate Qilin ransomware group, finding lucrative affiliate payoutsA different kind of ransomware demand: Donate to charity to get your data back | CyberScoopJoe Tidy on Twitter: "A bizarre one from Reading courts - an IT Security worker pleads guilty to piggy-backing off a cyber attack against his own firm. Liles switched the ransom payment details to his own Bitcoin wallet and changed the hacker's email to secretly apply pressured on bosses to pay up. https://t.co/Ze4yAJA6vM" / TwitterChatGPT Scams Are Infiltrating Apple's App Store and Google Play | WIRED