The Gate 15 Podcast Channel

The Gate 15 Podcast Channel

By Gate 15Business
Download on the App Store

The Gate 15 Podcast Channel episodes

  • Weekly Security Sprint EP 43. Workplace Violence, passwords, and security quick hits.
    In this week's Security Sprint, Dave and Andy talk about the following topics:
     
    Workplace Violence. CISA: Preventing Workplace Violence: Security Awareness Considerations Infographic. The Preventing Workplace Violence: Security Awareness Considerations Infographic is a new CISA product designed for critical infrastructure leaders, human resources personnel, managers, and workers of any level.
    Passwords. The worst passwords of 2023 are also the most common, "123456" comes in first. NordPass has published their 2023 edition of the top 200 most common passwords and unsurprisingly very few of the entries are secure. The top 10 can all be cracked in under a second using simple brute-force tools.
     
    Dave Round-UP
    CDC - Flu season. https://www.cidrap.umn.edu/influenza-general/us-flu-activity-continues-rise-steadily
    Taylor Swift. https://abcnews.go.com/International/Culture/taylor-swift-fan-dies-eras-tour-concert-rio/story?id=105006498
    Security guard incident in Canada which was captured on Social Media.
     
    FBI IC3 PSA: 2023 Holiday Shopping Scams
    2023 Holiday Scam Predictions—Here’s What You Should Know
    FBI Warns of Scammers Targeting Senior Citizens in Grandparent Scams and Demanding Funds by Wire, Mail, or Couriers
    Pro Bono Investigations for Elderly Scam Victims
     
    Threats to Homeland
    The Committee on Homeland Security: Worldwide Threats to the Homeland
    Witness testimony can be found here
    Director Wray's Opening Statement to the House Committee on Homeland Security. 
    U.S. political violence driven by new breed of ‘grab-bag’ extremists
     
    Ransomware
    CSA - Scattered Spider
    #StopRansomware: Rhysida Ransomware
    CISA Releases Update to Royal Ransomware Advisory
    AlphV files an SEC complaint against MeridianLink for not disclosing a breach to the SEC (2)
     
    Quick Hits
    Faith-Based and Israel-Gaza Related Updates: FB-ISAO Newsletter, v5, Issue 11.
    Official Tribal-ISAC Announcement: Tribal-ISAC Announces Membership as an Approved Expense of the Tribal Cybersecurity Grant Program
    CISA turns 5 and looks to the future
    Critical infrastructure policy rewrite expected to ‘emphasize’ CISA, NSC official says
    Readout of President Joe Biden’s Meeting with President Xi Jinping of the People’s Republic of China
    China is using the world’s largest known online disinformation operation to harass Americans, a CNN review finds
    NCSC Annual Review 2023 - Looking back at the National Cyber Security Centre's seventh year and its key developments and highlights, between 1 September 2022 and 31 August 2023
    CISA: Secure Tomorrow Series Toolkit
    ACSC and CISA Release Business Continuity in a Box
    HHS Factsheet: National Climate Assessment 5 Unveiled
    FCC Adopts Rules to Protect Consumers' Cell Phone Accounts
    24 min
  • Weekly Security Sprint EP 42: Ransomware, Resilience, MDM and more.
    In the latest epsiode of the Weekly Security Sprint, Dave and Andy talked about the following topics:
    Announcement! Venue Security, The IAVM Podcast Series! A new monthly podcast starting in 2024. Venue Security, The IAVM Podcast Series is our newest podcast as Gate 15’s founder and Managing Director, Andy Jabbour hosts short interviews with venue safety and security experts from the International Association of Venue Managers’ (IAVM) Venue Safety and Security Committee (VSSC) and other special guests from the IAVM community. 
    SHIELDS READY. The Department of Homeland Security (DHS), the Cybersecurity and Infrastructure Security Agency (CISA), and the Federal Emergency Management Agency (FEMA) launched the new Shields Ready campaign to encourage the critical infrastructure community to focus on strengthening resilience. Resilience is the ability to prepare for, adapt to, withstand, and rapidly recover from disruptions caused by changing conditions.
    CISA Launches Critical Infrastructure Security and Resilience Month 2023
     
    Scams. ‘with sales come scams’. https://www.ncsc.gov.uk/news/black-friday-bargain-hunters-warned-of-enhanced-online-scams-after-millions-lost-last-year
     MDM
    The Truth Crisis | The Rising Threat of Online Misinformation and Disinformation
    The Gate 15 Interview: Malicious Info Operations & MDM, the Space Sector, supply chain resilience, the City of Light, and nudging the world in a better direction.
    Nerd Out: EP 41. Dave Clark joins to talk about MDM and other nerd topics.
     
    Ransomware.
    Ransomware Actors Continue to Gain Access through Third Parties and Legitimate System Tools.
    CYBERSECURITY ADVISORY - #StopRansomware: Royal Ransomware, November 13, 2023 update
    Security Affairs: DOLLY.COM PAYS RANSOM, ATTACKERS RELEASE DATA ANYWAY
    Brazen ransomware attack on US unit of Chinese banking giant has financial sector on alert
    Risky Biz News: Clop is coming after your SysAid servers
    Basically all of Maine had data stolen by a ransomware gang; Maine's state agencies are the latest victims in the far-reaching MOVEit file transfer tool hack.
    Boeing data published by Lockbit hacking gang
    Cerber Ransomware Exploits Atlassian Confluence Vulnerability CVE-2023-22518
    Same threats, different ransomware; A threat cluster's switch from Vice Society to Rhysida
    Hive Ransomware's Offspring: Hunters International Takes the Stage
    Ransomed[.]vc Sunsets Operations, Auctions Off Infrastructure
    Critical Vulnerability: SysAid CVE2023-47246
     
    Quick Hits
    Critical infrastructure Updates: Major Australian Ports Affected By Cyber Incident
    Operations at DP World Australia resume, though ‘doesn’t mean the incident has concluded’
    Washington state transportation services partially restored after cyberattack
    The NSA Seems Pretty Stressed About the Threat of Chinese Hackers in US Critical Infrastructure
    Sandworm Disrupts Power in Ukraine Using a Novel Attack Against Operational Technology
    International Terrorism: Five right-wing terrorists arrested throughout Europe with the support of Eurojust and Europol
    Israel: Mossad foils Hezbollah terror plot against Jews in Brazil
    FEMA and CISA Release Joint Guidance on Planning Considerations for Cyber Incidents
    Faith-Based and Israel-Gaza Related Updates: OpenAI blames DDoS attack for ongoing ChatGPT outage. In a series of Telegram messages seen by TechCrunch, hacktivist group Anonymous Sudan took credit for the alleged attack. In the messages, Anonymous Sudan said the reason it targeted OpenAI is due to the company’s “general biasness towards Israel and against Palestine”.
    Earthquake Preparedness. FEMA’s Earthquake & Wind Programs Branch, along with the National Earthquake and Hazard Reduction Program (NEHRP), is excited to announce the updated Earthquake Safety Checklist (FEMA B-526).
    CISA, NSA, and Partners Release New Guidance on Securing the Software Supply Chain
    FEMA’s National Business Emergency Operations Center (NBEOC) - YouTube
    22 min
  • Nerd Out: EP 42. A holiday extravaganza with security tips and the annual holiday food review!
    In the latest episode of Nerd Out, Dave, Joe and Bridget catch up on the latest activity related to the Israeli-Hamas conflict before getting into some holiday security tips. Each Nerd took a spin through some important security preparedness reminders that include increased awareness, impacts from potential protests and demonstrations, winter weather concerns, and holiday travel tips. Finally, the team turned their focus to an annual tradition - their holiday food reviews.
    Joe Levy is the Assistant General Manager at the Barclays Center.
    Bridget Johnson is a terrorism and extremism expert who has decades worth of experience analyze threat activities.
    41 min
  • Weekly Security Sprint EP 41. Normalizing violent threats, Critical Infrastructure Security and Resilience month, cybersecurity resources and tools.
    In this week's Security Sprint, Dave and Andy talked about the following topics:
    Physical Security. Increasing acceptance of threats of violence
    MAGA Commentator Wants People to Shoot Charity Workers Assisting Migrants
    'Be looking over your shoulder': MAGA man arrested for threats against Fani Willis
    Threats to U.S. senator amid spike in anti-Jewish, anti-Muslim activity; U.S. officials say they are responding to a rise in threats against Arab, Jewish and Muslim communities as Gaza war intensifies
    DOJ: Nevada Man Arrested And Charged For Making Threats To United States Senator
    Vehicle Ramming. Nuclear Power Plant. https://www.nbcnews.com/news/us-news/police-searching-suspect-drove-fence-south-carolina-nuclear-station-at-rcna123489
    CISA Security Planning Workbook. https://www.cisa.gov/sites/default/files/2023-10/CISA_AASB_Security_Planning_Workbook_508_Compliant_20230929.pdf
     
    US Senate Hearing: Threats to the Homeland
    Secretary Mayorkas Testimony to Committee on Homeland Security & Governmental Affairs
    FBI Director Wray: Threats to the Homeland
     
    Cybersecurity.
    CISA Launches Critical Infrastructure Security and Resilience Month 2023. The Cybersecurity and Infrastructure Security Agency (CISA) announced the kickoff of Critical Infrastructure Security and Resilience Month. Yesterday, the White House issued a Presidential Proclamation to commemorate November as Critical Infrastructure Security and Resilience Month and called on Americans to recognize the importance of this month to enhance our collective national security and resilience… This November, CISA is asking everyone to Resolve to be Resilient by preparing and investing in resilience today, so that, as a nation, we can recover quickly in the event of an incident tomorrow.  We are highlighting practices critical infrastructure organizations can implement to recover rapidly in the aftermath of any significant disruption:
    Assess Your Risk.
    Make a Plan and Exercise It. 
    Continuously Improve and Adapt.
    NCSC. https://www.ncsc.govt.nz/news/record-high-financially-motivated-cyber-activity/
    Zero-Day. https://cyberscoop.com/cisa-zero-day-ransomware/
     
    Quick Hits
    Maine gunman’s family contacted police months before massacre, sheriff says
    NIJ: Five Things About Protecting Against Mass Attacks
    FACT SHEET: Biden-⁠Harris Administration Convenes Third Global Gathering to Counter Ransomware
    2022 RTF Global Ransomware Incident Map: Attacks continue worldwide, groups splinter, education sector hit hard w reference to our good friends at eCrime – the single best source for ransomware information
    U.S. officials hold their breath for Iranian cyberattacks
    Man Armed with Weapons Found Dead at Colorado Amusement Park, Investigation Underway; Authorities said that the 22-year-old suspect wore body armor and had with him a semi-automatic rifle and IEDs
    FIRST has officially published the latest version of the Common Vulnerability Scoring System (CVSS v4.0)
    FBI Tech Tuesday: Beware of Scams on Popular Peer-to-Peer Payment Apps
    SEC Charges SolarWinds and Chief Information Security Officer with Fraud, Internal Control Failures
    Citrix Bleed: Two ransomware groups now exploiting bug for initial access
    “This vulnerability is now under mass exploitation.” Citrix Bleed bug bites hard; By some estimates, 20,000 devices have already been hacked.
    Unveiling Socks5Systemz: The Rise of a New Proxy Service via PrivateLoader and Amadey
    GCA Launches a User-friendly Cybersecurity Tools Wiki
    NZ NCSC: The NCSC announces record-high financially motivated cyber activity
    28 min
  • Weekly Security Sprint EP 40. Maine, expanded conflict, scams, and more!

    In this week's Security Sprint, Dave and Andy talked about the following topics:

    Maine Shootings

    • Attorney General Merrick B. Garland Statement on the Suspect in the Lewiston, Maine, Mass Shooting
    • Statement from FBI Boston Division Special Agent in Charge Jodi Cohen on the Lewiston, Maine, Mass Shooting
    • Maine shootings: gunman suspected of killing 18 people found dead
    • Maine Shooting Suspect’s Body Found in Trailer: Officials
    • Maine police alerted about ‘veiled threats’ from Robert Card weeks before mass shooting
    • Mystery note left behind by Maine mass shooting suspect revealed
    • Robert Card legally bought rifle believed to be used in Maine massacre days before mental health treatment: report
    •  

      FB-ISAO: October 2023 Threat Level Statement Update – Threat Levels Raised to ELEVATED.

      • The Physical Threat Level is “ELEVATED.” ELEVATED means that FB-ISAO is unaware of any specific threats, but there is concern that an event is more likely than normal. We are also closely monitoring events and are considering an escalation to “SEVERE,” meaning that an event is highly likely, but decided to not escalate to that level at this time.
      • The Cyber Threat Level is “ELEVATED.” ELEVATED means that FB-ISAO is unaware of any specific threats, but there is concern that an event is more likely than normal.
      • Scams

        • FBI IC3 PSA - Scammers Solicit Fake Humanitarian Donations: “The FBI is warning the public that scammers are committing charity fraud by soliciting fake humanitarian donations during the Israel HAMAS conflict. Scammers quickly pivot to charity fraud when catastrophic events occur, such as a war, a natural disaster, or an epidemic.”
        • Anonymous Sudan Claims KFC Cyberattack Amidst Geopolitical Tensions
        • Shooting outside Upper Darby mosque under investigation: police
        • Cops stop car showing anti-Israel slogans, swastikas; say loaded gun found inside. Driver reportedly aimed to 'educate the public' on Israel-Hamas war's 'true events.'
        • Israel flag in front of Nash Co. church vandalized
        • CAIR Video: Muslim Woman Targeted by Hateful Tirade in Maryland

        • AI. FACT SHEET: President Biden Issues Executive Order on Safe, Secure, and Trustworthy Artificial Intelligence.

           

          Quick Hits

          • Risky Biz News: CitrixBleed vulnerability goes from bad to disastrous.
          • Mass exploitation of CitrixBleed vulnerability, including a ransomware group.
          • CVE-2023-4966: Critical security update now available for NetScaler ADC and NetScaler Gateway
          • Neuberger: New global initiatives will include information sharing, ransomware payment tracking
          • DDoS threat report for 2023 Q3
          • CISA Updates Guidance for Addressing Cisco IOS XE Web UI Vulnerabilities
          • Cisco IOS XE Software Web UI Command Injection Vulnerability
          • CISA Adds One Known Exploited Vulnerability to Catalog - CVE-2023-20273 Cisco IOS XE Web UI Unspecified Vulnerability
          • Space ISAC Watch Center Prepares for Cyber Threats in Space
          • Empowering Small and Medium-Sized Businesses; A Resource Guide for Developing a Resilient Supply Chain Risk Management Plan
          • Logging Made Easy. CISA’s newest tool is a free and open logging and protective monitoring solution serving all organizations. Secure your Windows-based equipment today with Logging Made Easy.  
          •  

            24 min
          • Weekly Security Sprint EP 39. ISIS call to action, ransomware, and FBI reporting
            In this week's Security Sprint, Dave and Andy talked about the following Topics.
            Hurricane season thoughts.
            ISIS Calls for Jewish Attacks Around the World. “Terrorist group ISIS has called for violent targeting of Jewish people worldwide in response to the ongoing conflict between Israel and Hamas… Published on Friday in Arabic in Al-Naba, a weekly magazine by ISIS, it advocates for violence and murder against Jewish people worldwide.
             
            Ransomware
            New Portman Report Demonstrates Threat Ransomware Presents to the United States. “This report details the attacks by Russia-based ransomware group REvil on three American companies, and the experiences of those companies during the incident response."
            CISA, NSA, FBI, MS-ISAC Publish Updated #StopRansomware Guide
            UK NCSC: Principles for ransomware-resistant cloud backups; Helping to make cloud backups resistant to the effects of destructive ransomware.
            Our new principles to help make cloud backups more resilient; Introducing a new set of NCSC principles to strengthen the resilience of organisations' cloud backups from ransomware attackers.
            Canadian Centre for Cyber Security - Social engineering – ITSAP.00.166, Social engineering – ITSAP.00.166 (PDF, 267 KB)
            Phishing Guidance: Stopping the Attack Cycle at Phase One
             
            FBI Releases 2022 Crime in the Nation Statistics. The FBI released detailed data on over 11 million criminal offenses reported to the Uniform Crime Reporting (UCR) Program… The FBI’s crime statistics estimates for 2022 show that national violent crime decreased an estimated 1.7% in 2022 compared to 2021 estimates. 
            Statement from President Joe Biden on Hate Crime Statistics
            FBI report: Violent crime decreases to pre-pandemic levels, but property crime is on the rise
            Violent crime down, carjackings up, according to FBI crime statistics
            FBI: Violent Crime Down To Pre-Pandemic Levels, But Property Crimes Rising
            ADL: FBI Data Reflects Deeply Alarming Record-High Number of Reported Hate Crime Incidents in the U.S. in 2022
            UCR’s Crime Data Explorer
             
            Quick Hits:
            Russia, shifting tactics, fans doubt in election integrity, U.S. says; A new intelligence assessment indicates the Kremlin appears to be expanding its long-running efforts to weaken the world’s democracies
            CISA Releases Guidance for Addressing Cisco IOS XE Web UI Vulnerabilities
            "The Phantom Hacker:" FBI Phoenix Warns Public of New Financial Scam
            CISA: Threat Actors Exploit Atlassian Confluence CVE-2023-22515 for Initial Access to Networks
            FBI IC3 PSA: Additional Guidance on the Democratic People's Republic of Korea Information Technology Workers
            26 min
          • The Gate 15 Interview EP 40: The Return of Kim Milford! On being a CISO, cyber resilience in higher ed and… cumquats?
            In this episode of The Gate 15 Interview, Andy Jabbour welcomes back Kim Milford, Deputy Chief Information Officer (CIO) and Chief Information Security Officer (CISO) at the University of Illinois Urbana-Champaign. In April 2023, Kim Milford accepted the role of Deputy CIO and Chief Information Security Officer (CISO) at Illinois. In this role, Ms. Milford draws on her experience in research and education to lead strategy, direction, and innovation related to cybersecurity, identity protection, and privacy. Prior to this role, Kim was the Executive Director and CISO at the REN-ISAC, working with research and education institutions and partners to provide member institutions with the information and tools to better defend their environments from threats. Her service in higher education began in 1998 having held leadership positions at Indiana University, the University of Rochester, and University of Wisconsin-Madison. Kim provides cybersecurity expertise and presentations at national and regional conferences and seminars. She guest lectures and teaches cybersecurity courses and training, and has authored/co-authored many articles on the subject. Ms. Milford has a B.S. in Accounting from Saint Louis University in St. Louis, Missouri and a J.D. from John Marshall Law School in Chicago, Illinois.
            Kim on LinkedIn.
            In the discussion we address:
            Life as a CISO
            Social engineering and taking a more human-centric approach to security
            Identity as an initial attack vector
            Challenges around regulated research
            Private-Public Partnership
            Cyber Resilience
            Liberated thinking on strategy and technology
            Digital Twins and privacy (link to Gartner)
            And we play Three Questions with Kim Milford
            A few references mentioned in or relevant to our discussion include:
            University of Illinois Urbana-Champaign, Office of the Chief Information Officer Technology Services
            EDUCAUSE
            CISA The Power of Resilience, 09 Aug 2023
            The Gate 15 Interview: From Blended Threats to Pandemic Lessons Learned, a Candid Conversation on Higher Education Security and Resilience with REN-ISAC’s Kim Milford (23 November 2020)
            Gate 15: Security Spotlight: An Interview with REN-ISAC Executive Director, Kim Milford (11 June 2018)
            36 min
          • Nerd Out: EP 41. Dave Clark joins to talk about MDM and other nerd topics.
            In the latest episode of Nerd Out, Dave brings in another Dave and fellow Nerd. Dave Clark joins the show to talk all things mis/dis/mal-information (MDM) as well as some other nerd topics. Dave Clark shared his journey from being a linguist in the Army to a sports journalist to working with MDM. He also talked about some of the challenges and then some important steps for individuals and organizations to take to verify the information is as complete as possible. Then taking a break from work, Dave and Dave talked about what they are watching and some of the challenges with some great shows.
            Dave Clark is....
            48 min
          • Weekly Security Sprint EP 38. Protests, hostile events, security vulnerabilities and reports and more.
            In this week's security sprint, Dave and Andy talk about the following topics:
            Israel War
            Director Wray Addresses International Association of Chiefs of Police Conference. 
            FBI director warns of rise in terror threats against Americans, potential copy-cat attacks on US soil.
            Faith Based Updates: FB-ISAO Newsletter, v5, Issue 10
            The White House Office of Faith-Based and Neighborhood Partnerships releases Allied Against Hate: A Toolkit for Faith Communities - Tools and Resources to Protect Places of Worship
            DHS: Resources and Information for Faith and Community Leaders Regarding the Situation in Israel
             
            Hostile Events
            State Fair of Texas evacuated after shooting, one suspect in custody
            Suspect charged in State Fair of Texas shooting that injured 3
            School plot: https://www.news4jax.com/news/local/2023/10/06/3-creekside-high-students-facing-charges-for-school-threat-hit-lists-deputies-say/
             
            Nation State.
            12 October 2023 NCSC / FBI Safeguarding Our Future bulletin – Russian Intelligence Poses a Persistent Threat to the United States. 
            IBM Security Intelligence: 10 years in review: Cost of a Data Breach
             
            Quick Hits
            Signal says there is no evidence rumored zero-day bug is real.
            Ransomware: CISA Releases New Resources Identifying Known Exploited Vulnerabilities and Misconfigurations Linked to Ransomware. As part of the Ransomware Vulnerability Warning Pilot (RVWP), CISA launched two new resources for combating ransomware campaigns:
            Ransomware Vulnerability Warning Pilot updates: Now a One-stop Resource for Known Exploited Vulnerabilities and Misconfigurations Linked to Ransomware
            Colonial Pipeline was hacked. No, wait, Accenture was hacked. No, wait….. untangling claims. (2)
            Colonial Pipeline Denies Breach by RANSOMEDVC Ransomware Group
            Reports of second cyberattack on Colonial Pipeline false, company says
            Robert M. Lee on ransomware group statement.
            Newest Ransomware Trend: Attackers Move Faster with Partial Encryption
            The Week in Ransomware - October 13th 2023 - Increasing Attacks
            US Secret Service: Announcing a New Series of Live Virtual Presentations on Targeted Violence Prevention. 
            CISA, FBI, NSA, and Treasury Release Guidance on OSS in IT/ICS Environments
            CISO Research Reveals 90% of Organizations Suffered At Least One Major Cyber Attack in the Last Year; 83% Report Ransomware Payments
            FTC Data Shows Consumers Report Losing $2.7 Billion to Social Media Scams Since 2021
            UK NCSC: Mastering your supply chain: A new collection of resources from the NCSC can help take your supply chain knowledge to the next level
            EPA calls off cyber regulations for water sector
            26 min
          • Weekly Security Sprint EP 37. Conflict in the Middle East, CISA advisories, lessons learned, and more!
            In this week's Security Sprint, Dave and Andy talked about the following topics.
            War in Israel
            CISA Top 10 Cybersecurity Misconfigurations.
            NSA and CISA Release Advisory on Top Ten Cybersecurity Misconfigurations
            Virginia Beach Shooting Lessons Learned.
            State commission reviewing Virginia Beach mass shooting offers little new insight but recommends more tools for its work.
            Gate 15 offers our Hostile Event Preparedness Series and check out the Gate 15 White Paper on The Hostile Event Attack Cycle (HEAC). and we’d be happy to help your organization with active shooter/hostile events planning, exercising and overall preparedness. Don’t wait. 
             
            CISA: National School Safety Summit. The National Summit on K-12 School Safety and Security, hosted by the Cybersecurity and Infrastructure Security Agency (CISA), brings federal, state and local school leaders together to share actionable recommendations that enhance safe and supportive learning environments in kindergarten through grade 12 (K-12) schools. To register, please visit 2023cisaschoolsummit.eventbrite.com.
             
            Red Cross Issues Wartime Hacktivist Rules; Attackers Shockingly Don’t Care 
            Quick Hits
            Microsoft: Espionage fuels global cyberattacks
            Ransomware: MGM Resorts Refused to Pay Ransom in Cyberattack on Casinos; Fallout will have a $100 million negative impact on quarterly earnings, Las Vegas-based company says
            CISA and NSA Release New Guidance on Identity and Access Management
            FBI Highlights Online Safety Tips During Cybersecurity Awareness Month. 
            Germany Political Event (or something). https://apnews.com/article/germany-afd-chrupalla-rally-incident-hospital-61606f839d8563ee77228dbd914ae35f
            27 min

          About The Gate 15 Podcast Channel

          From the publisher's feed

          The Gate 15 Company is a leader in helping organizations by providing threat-informed, risk-based approaches to analysis, preparedness and operations.