On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:
Ron Wyden’s “please explain” letter to MicrosoftChinese APT crews prepositioning to disrupt US military logisticsChina claims US hacked its seismology sensorsIvanti/MobileIron exploitation going verticalMuch, much moreThis week’s show is brought to you by Stairwell. Mike Wiacek, Stairwell’s founder and CEO, is this week’s sponsor guest. He’s joined by Eric Foster, Stairwell’s VP of Business Development.
Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.
Show notes
Wyden letter to CISA, DOJ, FTC re 2023 Microsoft breachSenator calls on DOJ to investigate alleged China hack of Microsoft cloud toolsU.S. Hunts Chinese Malware That Could Disrupt American Military Operations - The New York TimesMultiple Chinese APTs establish major beachheads inside sensitive infrastructure | Ars TechnicaJohn Hultquist🌻 on Twitter: "We found this actor in land, air, and sea transportation targets which could be leveraged for a serious disruption to logistics." / XChina accuses U.S. of hacking earthquake monitoring equipmentExclusive: Pentagon Investigates ‘Critical Compromise’ Of Air Force Communications SystemsCISA: Ivanti hacks targeting Norway began in AprilUS, Australia cyber agencies warn IDOR security flaws can be exploited ‘at scale’ | TechCrunchIvanti warns of second vulnerability used in attacks on Norway gov’tAndrew Morris on Twitter: "Exploitation of Ivanti EPMM (MobileIron Core) CVE-2023-35078 is currently popping off https://t.co/tkRoWqvtv1 https://t.co/XOaWEZ3U3X" / XTrail of Bits | ProductsUS contractor says info of up to 10 million leaked in MOVEit breachBritish ambulances unable to access patient records system following cyberattackValid account credentials are behind most cyber intrusions, CISA finds | Cybersecurity DiveAn Unexpected Endorsement for WebAuthn | Okta SecuritySEC votes to overhaul disclosure rules for material cyber events | Cybersecurity DiveWhite House unveils ‘whole of society’ push to expand cybersecurity workforceSection 702 surveillance powers are necessary, but FBI access needs limits, panel saysThe NSA Is Lobbying Congress to Save a Phone Surveillance 'Loophole' | WIREDKazakhstan refuses to extradite detained Russian cyber expert to USRussia Sends Cybersecurity CEO to Jail for 14 Years – Krebs on SecurityMillions stolen from crypto platforms through exploited ‘Vyper’ vulnerabilityA New Attack Impacts ChatGPT—and No One Knows How to Stop It | WIREDCloud company assisted 17 different government hacking groups, U.S. researchers say | ReutersNo evidence ransomware victims with cyber insurance pay up more often, UK report says‘Worm-like’ botnet malware targeting popular Redis storage toolHackers are infecting Call of Duty players with a self-spreading malware | TechCrunchBug in Minecraft mods allows hackers to exploit players' devices