On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:
Fortinet 0day Groundhog DayCISA’s new binding directive on exposed management interfacesConfirmed: US intelligence buying commercially available dataMOVEit drama rolls onMuch, much moreThis week’s show is brought to you by Red Canary. Chris Rothe is this week’s sponsor guest and he joins us to talk about how MDR providers are helping customers deal with cloud monitoring.
Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.
Show notes
Fortinet Warns Customers of Possible Zero-Day Exploited in Limited Attacks - SecurityWeekBarracuda Urges Replacing — Not Patching — Its Email Security Gateways – Krebs on SecurityMOVEit announces second vulnerability; Minnesota schools agency breached with original bugConfidential data downloaded from UK regulator Ofcom in cyberattackRansomware group Clop issues extortion notice to ‘hundreds’ of victimsAnother huge US medical data breach confirmed after Fortra mass-hack | TechCrunchCISA orders US civilian agencies to remove tools from public-facing internetMicrosoft says Azure disrupted after a week of repeated service outages | Cybersecurity DiveMicrosoft says Azure outage was caused by ‘anomalous’ traffic spikeMicrosoft investigating threat actor claims following multiple outages in 365, OneDrive | Cybersecurity DiveRisky Biz News: Ukrainian hackers wipe equipment of major Russian telcoU.S. Spy Agencies Buy Vast Quantities of Americans’ Personal Data, U.S. Says - WSJThe US Is Openly Stockpiling Dirt on All Its Citizens | WIREDSrsly Risky Biz: Thursday, July 29 - by Tom UrenNational security officials make case for keeping surveillance powers to skeptical Congress - The Washington PostSenators say Biden administration isn’t close on overhauling surveillance lawRussian nationals accused of Mt. Gox bitcoin heist, shifting stolen funds to BTC-eNorth Korean hacking group Lazarus linked to $35 million cryptocurrency heistNorth Korean hackers stole $100 million in recent cryptocurrency heist -analysts | ReutersAn Illinois hospital links closure to ransomware attackSecurity professional's tweet forces big change to Google email authentication | CyberScoopCan you trust ChatGPT’s package recommendations?LastPass CEO reflects on lessons learned, regrets and moving forward from a cyberattack | Cybersecurity Dive