On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:
The SEC is targeting SolarWinds executivesUK to make banks liable for fraudNSA issues advice on UEFI trojanMicrosoft blocks 100+ dodgy driversThe US IC knew what Prihozhin was up to. But what FSB doing?Much, much moreThis week’s show is brought to you by Netwrix. Martin Cannard, Netwrix’s VP of Product Strategy, is this week’s sponsor guest. He talks about why zero standing privilege is a worthy goal.
Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.
Show notes
SEC notifies SolarWinds CISO and CFO of possible action in cyber investigation | Cybersecurity DiveWhile Australian banks refuse most scam victims refunds, the UK is making them mandatory - ABC NewsNew law could allow GCHQ to monitor UK internet logs in real-time to tackle fraudFederal incentives could help utilities overcome major cybersecurity hurdle: money | CyberScoopMajor Japanese port suspends operation following ransomware attackPetro-Canada reports service restoration after suspected Suncor breach | Cybersecurity DiveChinese state-backed hackers accidentally infected a European hospital with malwareHackers exploit gaping Windows loophole to give their malware kernel access | Ars Technica336,000 servers remain unpatched against critical Fortigate vulnerability | Ars TechnicaCISA says latest VMware analytics bug being exploitedMOVEit vulnerability snags almost 200 victims, more expected | Cybersecurity DiveActively exploited vulnerability threatens hundreds of solar power stations | Ars TechnicaU.S. intelligence learned in mid-June Prigozhin was plotting uprising - The Washington PostRussian election-meddling ‘troll factory’ reportedly shut down after Wagner revoltRussian telecom confirms hack after group backing Wagner boasted about an attack | CyberScoopHackers claim to take down Russian satellite communications providerRussian railway site allegedly taken down by Ukrainian hackersSeveral US states investigating ‘SiegedSec’ hacking campaignHacking crew targeting states over transition bans claims cyberattack hitting global satellite systems | CyberScoopHacktivists steal government files from Texas city Fort Worth | TechCrunchBelarusian hacktivists сlaim to breach country’s leading state universityBritish prosecutors say teen Lapsus$ member was behind hacks on Uber, RockstarSilk Road’s Second-in-Command, Variety Jones, Gets 20 Years in Prison | WIREDRussian cyber expert arrested in Kazakhstan, triggering a showdown between US and MoscowMore than 6,500 arrested since French and Dutch police’s EncroChat hackBreachForums seized by FBI three months after arrest of alleged adminBreachForums replacement emerges as robust forum for criminal hackers to trade their spoils | CyberScoopGenesis Market gang tries to sell platform after FBI disruptionHackers using TrueBot malware for phishing attacks in US, Canada, officials warn | Cybersecurity DiveCSI_BlackLotus_Mitigation_Guide.PDFHacks targeting British exam boards raise fears of students cheatingMore than $125 million taken from crypto platform MultichainTwitter’s chaotic weekend of outages and rate limits leaves more questions than answersMastodon fixes critical “TootRoot” vulnerability allowing node hijacking | Ars Technica