On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:
The Citrixbleed ransomware crisisWhy the FBI hasn’t arrested Scattered Spider membersDPRK is in your supply chainsMicrosoft has a brainwave and buys a HSMWhen civil war meets pig butcheringMuch, much moreThis week’s show is brought to you by Airlock Digital. David Cottingham and Daniel Schell are this week’s sponsor guests.
Links to everything that we discussed are below and you can follow Patrick or Adam on Mastodon if that’s your thing.
Show notes
‘Citrix Bleed’ vulnerability targeted by nation-state and criminal hackers: CISAAustralian ports operator recovering after major cyber incidentMinister lashes DP World hack failureGang says ICBC paid ransom over hack that disrupted US Treasury market | ReutersCyberattack on US hospital owner diverts ambulances from emergency rooms in multiple states | CNN PoliticsFidelity National Financial investigating cyberattack that led to service disruption | Cybersecurity DivePotentially hundreds of UK law firms affected by cyberattack on IT provider CTSNorth Texas water utility serving 2 million hit with cyberattackHealthcare manufacturer Henry Schein expects platform restored this week after cyberattackHigh-profile ransomware gang suspects arrested in UkraineFBI struggled to disrupt dangerous casino hacking gang, cyber responders say | ReutersChinese spies had acces to Dutch chip maker NXP's systems for over two years: report | NL TimesNorth Korean supply chain attacks prompt joint warning from Seoul and LondonNorth Korean attack on CyberLink impacted devices around the world, Microsoft saysNorth Korean ‘BlueNoroff’ group targeting financial institutions with macOS malwareMicrosoft upgrades security for signing keys in wake of Chinese breach | CyberScoop(14) Microsoft Should Look to the Past for Its Security FutureSacked Ukrainian cyber chief released on bail amid corruption probeSecond top Ukrainian cyber official arrested amid corruption probeReport claims to reveal identity of Russian hacktivist leaderRebel offensive in Myanmar takes aim at online scam industryMyanmar Rebel Offensive Helps China's Cybercrime CrackdownShadowy hacking group targeting Israel shows outsized capabilities | CyberScoopNearly two dozen Danish energy companies hacked through firewall bug in MaySenate proposes surveillance bill without FBI warrant requirementThe FCC says new rules will curb SIM swapping. I’m pessimistic | Ars TechnicaEU urged to drop new law that could allow member states to intercept and decrypt global web trafficGoogle researchers discover 'Reptar,’ a new CPU vulnerability | Google Cloud BlogSpavor blames fellow prisoner Kovrig for Chinese detention, alleges he was used for intelligence gathering - The Globe and MailThe Mirai Confessions: Three Young Hackers Who Built a Web-Killing Monster Finally Tell Their Story | WIRED