Risky Business

Risky Business #783 -- Evil webcam ransomwares entire Windows network


Listen Later

On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news with special guest Rob Joyce, a Former Special Assistant to the US President and Director of Cybersecurity for NSA.

They talk through:

  • A realistic bluetooth-proximity phishing attack against Passkeys
  • A very patient ransomware actor encrypts an entire enterprise with a puny linux webcam processor
  • The ESP32 backdoor that is neither a door nor at the back
  • The X DDoS that Elon said was Ukraine is claimed by pro-Palestinian hacktivists
  • Years later, LastPass hackers are still emptying crypto-wallets
  • …and it turns out North Korea nailed {Safe}Wallet with a malicious docker image. Nice!
  • Rob Joyce recently testified to the US House Select Committee on the Chinese Communist Party, and he explains why DOGE kicking probationary employees to the curb is “devastating” for the national security staff pipeline.

    This week’s episode is sponsored by SpecterOps, makers of the BloodHound identity attack path mapping tool. Chief Product Officer Justin Kohler and Principal Security Researcher Lee Chagolla-Christensen discuss their pragmatic approach to disabling NTLM authentication in Active Directory using BloodHound’s insight.

    This episode is also available on Youtube.

    Show notes
    • CVE-2024-9956 - PassKey Account Takeover in All Mobile Browsers | Tobia Righi - Security Researcher
    • Feds Link $150M Cyberheist to 2022 LastPass Hacks – Krebs on Security
    • Camera off: Akira deploys ransomware via webcam
    • Tarlogic detects a hidden feature in the mass-market ESP32 chip that could infect millions of IoT devices
    • Alleged Co-Founder of Garantex Arrested in India – Krebs on Security
    • 37K+ VMware ESXi instances vulnerable to critical zero-day | Cybersecurity Dive
    • Apple patches 0-day exploited in “extremely sophisticated attack” - Ars Technica
    • What Really Happened With the DDoS Attacks That Took Down X | WIRED
    • Eleven11bot estimates revised downward as researchers point to Mirai variant | Cybersecurity Dive
    • Previously unidentified botnet infects unpatched TP-Link Archer home routers | The Record from Recorded Future News
    • Safe.eth on X: "Investigation Updates and Community Call to Action" / X
    • How to verify Safe{Wallet} transactions on a hardware wallet | Safe{Wallet} Help Center and Support.
    • US charges Chinese nationals in cyberattacks on Treasury, dissidents and more | The Record from Recorded Future News
    • Former top NSA cyber official: Probationary firings ‘devastating’ to cyber, national security | CyberScoop
    • U.S. pauses intelligence sharing with Ukraine used to target Russian forces - The Washington Post
    • ...more
      View all episodesView all episodes
      Download on the App Store

      Risky BusinessBy Patrick Gray

      • 4.6
      • 4.6
      • 4.6
      • 4.6
      • 4.6

      4.6

      352 ratings


      More shows like Risky Business

      View all
      Security Now (Audio) by TWiT

      Security Now (Audio)

      1,960 Listeners

      SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

      SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

      634 Listeners

      Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

      Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

      368 Listeners

      Hacked by Hacked

      Hacked

      176 Listeners

      CyberWire Daily by N2K Networks

      CyberWire Daily

      1,011 Listeners

      Smashing Security by Graham Cluley & Carole Theriault

      Smashing Security

      312 Listeners

      Click Here by Recorded Future News

      Click Here

      386 Listeners

      Malicious Life by Malicious Life

      Malicious Life

      923 Listeners

      Darknet Diaries by Jack Rhysider

      Darknet Diaries

      7,852 Listeners

      Cybersecurity Today by Jim Love

      Cybersecurity Today

      142 Listeners

      CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

      CISO Series Podcast

      182 Listeners

      Hacking Humans by N2K Networks

      Hacking Humans

      308 Listeners

      Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

      Defense in Depth

      71 Listeners

      Cyber Security Headlines by CISO Series

      Cyber Security Headlines

      117 Listeners

      Risky Bulletin by risky.biz

      Risky Bulletin

      33 Listeners