On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news:
Cyber firms agree to deconflict and cross-reference hacker group namesRussian nuclear facility blueprints gathered from public procurement websitesSomeone audio deepfaked the White House Chief of Staff, but for the dumbest reasonsGermany identifies the Trickbot kingpinGoogle spots China’s MSS using Calendar events for malware C2Meta apps abuse localhost listeners to track web sessions.This week’s episode is sponsored by automation vendor Tines. Its Field CISO, Matt Muller, joins the show to discuss an open letter penned by JP Morgan Chase’s CISO that pleads with Software as a Service suppliers to try to suck less at security.
This episode is also available on Youtube.
Show notes
'Forest Blizzard' vs 'Fancy Bear' - cyber companies hope to untangle weird hacker nicknames | ReutersUkraine's Massive Drone Attack Was Powered by Open Source SoftwareMassive security breach: Russian nuclear facilities exposed onlineHow a Spyware App Compromised Assad’s Army - New Lines MagazineExclusive | Federal Authorities Probe Effort to Impersonate White House Chief of Staff Susie Wiles - WSJMalaysian home minister’s WhatsApp hacked, used to scam contacts | The Record from Recorded Future NewsU.S. Sanctions Cloud Provider ‘Funnull’ as Top Source of ‘Pig Butchering’ Scams – Krebs on SecurityTop counter antivirus service disrupted in global takedown | CyberScoopCops in Germany Claim They’ve ID’d the Mysterious Trickbot Ransomware Kingpin | WIREDAustralian ransomware victims now must tell the government if they pay up | The Record from Recorded Future NewsGoogle: China-backed hackers hiding malware in calendar events | Cybersecurity DiveCoinbase breach linked to customer data leak in India, sources say | ReutersUS military IT specialist arrested for allegedly trying to leak secrets to foreign government | The Record from Recorded Future NewsNSO appeals WhatsApp decision, says it can’t pay $168 million in ‘unlawful’ damages | The Record from Recorded Future NewsConnectWise says nation-state attack targeted multiple ScreenConnect customers | The Record from Recorded Future NewsGoogle Online Security Blog: Sustaining Digital Certificate Security - Upcoming Changes to the Chrome Root StoreMeta and Yandex are de-anonymizing Android users’ web browsing identifiers - Ars TechnicaAn Open Letter to Third-Party Suppliers