On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news. They cover:
SEC Twitter account hack moves bitcoin priceKaspersky admires Triangulation hackers’ fine workTelcos hacked all overIsrael hacks Iranian gasoline pumps againIran up in Albania, Sudan, Egypt and Tanzaniaand much, much more…This week’s show is brought to you by Nucleus Security. Co-founder Scott Kuffer joins us to talk about why patch management is more nuanced than just “patch fast!”
Show notes
U.S. Securities and Exchange Commission on X: "The @SECGov X account was compromised, and an unauthorized post was posted. The SEC has not approved the listing and trading of spot bitcoin exchange-traded products." / XMandiant, the security firm Google bought for $5.4 billion, gets its X account hacked | Ars Technica4-year campaign backdoored iPhones using possibly the most advanced exploit ever | Ars TechnicaSpyware attack chain used previously unknown iPhone hardware feature, report says"Dutch engineer carried out Iranian nuclear sabotage": VK - DutchNews.nlRussian hackers infiltrated Ukrainian telecom giant months before cyberattackUkraine telecom cyberattack one of ‘highest-impact’ hacks of the warPro-Ukraine hackers claim breach of Russian internet providerUkraine says Russia hacked web cameras to spy on targets in KyivOptus outage: Banks, telcos to be quizzed at Senate hearingA “ridiculously weak” password causes disaster for Spain’s No. 2 mobile carrier | Ars TechnicaAlbanian parliament, telecom company hit by cyberattacksParaguay military warns of ‘significant impact’ of ransomware after attack on internet providerIran confirms nationwide cyberattack on gas stationsHackers disrupt Beirut airport with anti-Hezbollah messageTelecom organizations in Africa targeted by Iran-linked hackersMyanmar rebels take control of ‘pig butchering’ scam city amid Chinese pressure on juntaAlphV ransomware site is “seized” by the FBI. Then it’s “unseized.” And so on. | Ars TechnicaBreachForums administrator detained after violating paroleAutistic teen behind spate of Lapsus$ hacks sentenced to indefinite hospital stayGlobal law enforcement seizes $300 million, arrests 3,500 involved in transnational cybercrime operationToronto Zoo says it remains open after ransomware attackCentral Bank of Lesotho facing outages after cyberattackKansas City-area hospital transfers patients, reschedules appointments after cyberattackCyberattack on Massachusetts hospital disrupted records system, emergency servicesLockBit claims November attack on New Jersey hospital that disrupted patient careFirst American becomes latest real estate industry giant hit with cyberattackIvanti warns of critical vulnerability in its popular line of endpoint protection software | Ars TechnicaUS officials say Russian targeting JetBrains servers for potential SolarWinds-style operations | ReutersSSH protects the world’s most sensitive networks. It just got a lot weaker | Ars TechnicaLastPass enforces 12-character master password lengths | Cybersecurity DiveFTC soliciting contest submissions to help tackle voice cloning technologyBiden signs short-term FISA extension before year-end deadlineFoone: "The 37C3 talk on TEA1 encrypti…" - Infosec ExchangeCrypto hedge fund CEO may not exist; probe finds no record of identity | Ars Technica