On this week’s show, Patrick Gray and Adam Boileau discuss the week’s security news, including:
The insurance industry’s reaction to CrowdStrike’s messGoogle’s Workspace email validation flaw and its consequences for OAuth’d applicationsIs the VMWare ESX group membership feature a CVE or an FYI?Secureboot continues to under-deliverNorth Korea’s revenue neutral intelligence servicesAnd much, much moreThis episode is sponsored by allowlisting software vendor Airlock Digital. Airlock uses a kernel driver on Windows, so Chief Executive David Cottingham joined to discuss what the CrowdStrike kernel driver bug drama means for security vendors.
This episode is also available on Youtube. If you want to ruin the magic of radio and see the faces behind the show, well, now you can!
Show notes
Business interruption claims will drive insurance losses linked to CrowdStrike IT disruption | Cybersecurity DiveDelta hires David Boies to seek damages from CrowdStrike, MicrosoftCrowdStrike disruption direct losses to reach $5.4B for Fortune 500, study finds | Cybersecurity Dive(1145) Why CrowdStrike's Baffling BSOD Disaster Was Avoidable - YouTubeCrowdStrike offers a $10 apology gift card to say sorry for outage | TechCrunchCrooks Bypassed Google’s Email Verification to Create Workspace Accounts, Access 3rd-Party Services – Krebs on SecurityHackers exploit VMware vulnerability that gives them hypervisor admin | Ars TechnicaMicrosoft calls out apparent ESXi vulnerability that some researchers say is a ‘nothing burger’ | CyberScoopAMI Platform Key leak undermines Secure Boot on 800+ PC modelsChrome will now prompt some users to send passwords for suspicious files | Ars TechnicaGoogle Online Security Blog: Improving the security of Chrome cookies on WindowsA Senate Bill Would Radically Improve Voting Machine Security | WIREDU.S. told Philippines it made ‘missteps’ in secret anti-vax propaganda effort | ReutersCyber firm KnowBe4 hired a fake IT worker from North Korea | CyberScoopNorth Korean hacker used hospital ransomware attacks to fund espionage | CyberScoopNorth Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime’s Military and Nuclear ProgramsNorth Korean hacking group makes waves to gain Mandiant, FBI spotlight | CyberScoopServiceNow spots sales opportunities post-CrowdStrike outage | Cybersecurity DiveChaining Three Bugs to Access All Your ServiceNow DataCyber Supply Chain Risk Management Conference (CySCRM) 2024 | Conference | PNNL