Shared Security Podcast

Shared Security Podcast

By Tom Eston, Scott Wright, Kevin TackettNewsTechnologyTech News
Download on the App Store

Shared Security Podcast episodes

  • The LastPass Attack Gets Worse, What is Gamification, Signal’s Encryption Standoff
    Popular password manager LastPass suffered a second attack that lasted for over two months. Now new and disturbing information is being released about the attack.
    Scott discusses the benefits and challenges of using gamification in security awareness training, emphasizing the importance of individual learning before employing it at the business process level.
    Signal, a very popular encrypted messaging app, warns it may leave the UK if new online safety legislation weakens its end-to-end encryption, sparking controversy and debate over privacy concerns.
    32 min
  • Twitter’s Paywall 2FA, Mental Health Data for Sale, Meta’s Verified Program
    Twitter is phasing out its free text message two-factor authentication (2FA) and putting the feature behind a paywall, prompting security experts to advise Twitter users to switch to other authentication methods.
    How data brokers are selling sensitive mental health data for a few hundred dollars with little attempt to hide identifying information such as names and addresses. A new report highlights how some firms are offering the data for as low as $275 for information on 5,000 people, and Congress has yet to pass significant legislation on data brokers.
    Meta (formerly Facebook) has launched a new program called Meta Verified which aims to unify verification across all of the company's platforms. Users can pay a monthly fee to verify their presence on Facebook and Instagram by submitting their government ID.
    31 min
  • Reddit Hacked, Preventing Accidental Location Sharing, Developer Hacks His Own Company
    Reddit announced that it was the victim of a phishing attack aimed at its employees, resulting in unauthorized access to internal documents, code, and some unspecified business systems.
    Advice on managing device location-tracking settings to ensure you're not sharing your location inadvertently.
    The case of former Ubiquiti employee, Nickolas Sharp, who pled guilty to multiple felony charges after orchestrating a security breach, stealing data, and extorting almost $2m worth of cryptocurrency from his company.
    Plus, our thoughts about UFO's and Chinese spy balloons!
    17 min
  • Layoffs, Recruiting, and The Year Ahead for Cybersecurity Job Seekers
    In this episode host Tom Eston sits down with Kathleen Smith, Chief Outreach Officer at ClearedJobs.net, to discuss the current state of the job market in the cybersecurity industry. With a recent surge in layoffs, Kathleen provides advice for those who were recently let go and discusses how the economic situation has affected recruiters. She also shares her predictions for changes in the recruitment process and offers advice for job seekers. Finally, Kathleen shares more about her role at Cleared Jobs and how listeners can get in touch.
    27 min
  • Password Managers Under Attack, Shady Reward Apps on Google Play, Meta Account Center 2FA Bypass
    The attacks on password managers and their users continue as Bitwarden and 1Password users have reported seeing paid ads for phishing sites in Google search results for the official login page of the password management vendors. Not only that, a new vulnerability in the popular open-source password management software KeePass has also been reported.
    Three health tracking apps available on Google Play (Lucky Step, WalkingJoy, Lucky Habit: health tracker) have been downloaded on over 20 million devices, but a recent report shows that the rewards for using the apps are impossible or only partially available after watching tons of ads.
    A bug in Meta's Accounts Center feature allowed hackers to bypass two-factor authentication (2FA) by brute force guessing a six-digit authentication code.
    22 min
  • U.S. ‘No Fly List’ Leaks, AI-Powered Phishing, Wi-Fi Used to See Humans Through Walls
    A hacker discovered a copy of the US No Fly List, which contains the names of people banned from traveling in or out of the US on commercial flights, on an unsecured Jenkins server connected to a commercial airline.
    Will AI-powered phishing become a threat for organizations?
    Scientists from Carnegie Mellon University have developed a way to sense humans through walls using a deep neural network called DensePose that maps Wi-Fi signals to UV coordinates.
    28 min
  • Social Zombies Revisited: Your Friends Want to Eat Your Brains
    On this week's episode, We're excited to bring you a classic conference talk that Tom Eston gave with co-host Kevin Johnson back in 2009 at DEF CON 17 in Las Vegas. The talk is called "Social Zombies: Your Friends Want to Eat Your Brains" and it explores the various risks and concerns related to malware delivery through social networking sites.
    We discuss how social networks make money and the privacy and security issues that arise due to the trust built on these platforms. We also delve into typical botnets and bot programs, and examine the delivery of malware through social networks and the use of these networks as command and control channels.
    Interestingly, not a lot has changed in terms of the privacy and security of social networks since we gave this presentation, so it's still highly relevant today. We hope you enjoy revisiting this classic talk with us this week on the Shared Security Show!
    27 min
  • Meta’s EU Ad Practices Ruled Illegal, Twitter API Data Breach, Vulnerabilities in Major Car Brands
    Facebook has been ordered to pay a fine of $414m by EU regulators who ruled that the company had broken EU law by forcing users to accept personalized ads. The ruling could have a major impact on Facebook's advertising business in the EU, which is one of the company's largest markets, if it is required to make changes to its advertising practices.
    A hacker has claimed to have the personal data of 400 million Twitter users for sale on the dark web. Attackers have also released the account details and email addresses of 235 million users for free. The information was exposed due to a Twitter API vulnerability shipped in June 2021 and later patched.
    Security researchers have identified security vulnerabilities in the connected vehicle APIs of 16 major car manufacturers, including Acura, BMW, Ferrari, Ford, Genesis, Honda, Hyundai, Infiniti, Jaguar, Kia, Land Rover, Mercedes-Benz, Nissan, Porsche, Rolls Royce, and Toyota.
    23 min
  • LastPass Password Vaults Stolen, Pig Butchering Scams, Okta Source Code Theft
    Things get worse for LastPass as a security breach in November resulted in the theft of customer data, including encrypted password vaults and unencrypted web addresses.
    Pig butchering scams, a variation of business email compromise and romance scams, are on the rise. How do they work and what do you need to know to protect yourself?
    Okta, a major identity and authentication company, has suffered another security breach following the "suspicious access" to its code repositories on Github.
    26 min
  • How to Stop Online Tracking: 3 New Ways
    In this episode, Tom Eston discusses one of the biggest privacy concerns people have today, online tracking by companies and advertisers. Tom will cover the following topics, tips, and new techniques to help you stop being tracked:
    Why should we be concerned about online tracking?
    How to enable and configure the privacy settings in your web browser
    How your smartphone has privacy settings to block online tracking
    Using a privacy focused search engine
    8 min

About Shared Security Podcast

From the publisher's feed

Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy…

More shows like Shared Security Podcast

Hacked by Hacked

Hacked

191 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Click Here by Recorded Future News

Click Here

421 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,054 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

191 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

The 404 Media Podcast by 404 Media

The 404 Media Podcast

397 Listeners