The Virtual CISO Moment

The Virtual CISO Moment

By Greg SchafferTechnology
Download on the App Store

The Virtual CISO Moment episodes

  • VCM Quick Strike for Monday, September 5, 2022

    IRS leaks taxpayer info, student loan breach, breach affects KeyBank and possibly others, REvil hits Fortune 500 company, phishing scam for American Express customers, and what I did on Labor Day, and how it ties in to information security.

    • https://www.theepochtimes.com/mkt_app/irs-mistakenly-published-confidential-info-of-120000-taxpayers_4708384.html
    • https://threatpost.com/student-loan-breach-exposes-2-5m-records/180492/
    • https://www.securityweek.com/keybank-hackers-third-party-provider-stole-customer-data
    • https://cybernews.com/news/revil-claims-to-have-hit-a-fortune-500-company/
    • https://hackademicus.nl/a-new-phishing-scam-targets-american-express-cardholders/
    • 9 min
    • The Virtual CISO Moment Wrap Up for Friday, September 2, 2022

      Lockbit leaks Entrust data, older iPhone vulns patch available, apps leaking hard-coded AWS creds, organ transplant system needs strengthening, "ghost in the machine" a significant risk, very experienced security reporter gets fooled by a phish, and a lookback at Stuxnet.

      • https://www.bleepingcomputer.com/news/security/lockbit-ransomware-gang-gets-aggressive-with-triple-extortion-tactic/
      • https://www.securityweek.com/ios-12-update-older-iphones-patches-exploited-vulnerability
      • https://thehackernews.com/2022/09/over-1800-android-and-ios-apps-found.html
      • https://www.bankinfosecurity.com/report-organ-transplant-data-security-needs-strengthening-a-19967
      • https://www.darkreading.com/edge-threat-monitor/ghost-data-increases-enterprise-business-risk
      • https://arstechnica.com/information-technology/2022/08/im-a-security-reporter-and-got-fooled-by-a-blatant-phish/
      • https://www.csoonline.com/article/3218104/stuxnet-explained-the-first-known-cyberweapon.html
      • 11 min
      • The Virtual CISO Moment S4E38 - A Conversation with Scott Augenbaum

        Scott Augenbaum was a special agent with the FBI and now continues his mission to help prevent businesses from becoming a victim of cybercrime as an author, speaker, and trainer. His story and mission is educational and inspirational! Check out https://www.cybersecuremindset.com/ and connect with Scott at https://www.linkedin.com/in/saugenbaum/.


        30 min
      • The Virtual CISO Moment S4E37 - A Conversation with Susan Richards

        Susan Richards is a dynamic director of Information Security concentrated in compliance, project management, application development, and database administration. She is skilled in IT Strategy, Management, Compliance Assurance, and Risk Management including HITRUST, NIST and ISO security frameworks. She is also very involved in the information security community, including ISSA chapter leadership and has this year started a local HITRUST chapter - plus we discuss election integrity!

        26 min
      • VCM Quick Strike for Monday, August 29, 2022

        Portland Oregon loses $1.4 million to BEC compromise, stolen Texas data possibly on dark web, 10 new actively exploited vulns added to CISA list, banking trojan targets industries in Spanish-speaking countries, an opinion piece on whether cybercriminals follow a moral code, and a new enterprise browser startup secures massive funding, which prompted my walk down memory lane of browsers over my 30-plus year career.

        • https://www.pcmag.com/news/portland-city-officials-accidentally-send-hacker-14-million
        • https://www.healthcareitnews.com/news/stolen-texas-health-data-may-be-posted-dark-web
        • https://thehackernews.com/2022/08/cisa-adds-10-new-known-actively.html
        • https://gbhackers.com/banking-trojan-targeting-automotive/
        • https://cybernews.com/security/attacking-healthcare-do-cybercriminals-follow-moral-code-/
        • https://www.securityweek.com/enterprise-browser-startup-island-snags-massive-funding-round
        • 16 min
        • The Virtual CISO Moment Wrap Up for Friday, August 26, 2022

          Lastpass breach, counterfeit Microsoft USB installers, deepfake getting scary, dramatic rise in DDoS attacks, Apple iOS VPNs leak, and claiming to stop all malware ignites social media storm.

          • https://blog.lastpass.com/2022/08/notice-of-recent-security-incident/
          • https://news.sky.com/story/criminals-posting-counterfeit-microsoft-products-to-get-access-to-victims-computers-12675123
          • https://www.infosecurity-magazine.com/news/scammers-create-ai-hologram-csuite/
          • https://www.govtech.com/blogs/lohrmann-on-cybersecurity/hacktivism-and-ddos-attacks-rise-dramatically-in-2022
          • https://www.theregister.com/2022/08/19/apple_ios_vpn/
          • https://www.crn.com/news/security/exec-s-claim-that-xcitium-stops-all-malware-ignites-msp-social-media-firestorm
          • 15 min
          • VCM Quick Strike for Monday, August 22, 2022

            Entrust data leaks, cyber war insurance exclusion definition updated, vulnerable RTLS systems, crypto stolen from hacked ATMs, draft US government cybersecurity acquisition requirements, and pragmatic infosec, and why that is important.

            • https://www.bleepingcomputer.com/news/security/lockbit-claims-ransomware-attack-on-security-giant-entrust-leaks-data/https://www.securityweek.com/lloyds-london-introduces-new-war-exclusion-insurance-clauses
            • https://thehackernews.com/2022/08/rtls-systems-found-vulnerable-to-mitm.html
            • https://thehackernews.com/2022/08/hackers-stole-crypto-from-bitcoin-atms.html
            • https://www.threatshub.org/blog/the-truth-about-that-draft-law-banning-uncle-sam-buying-insecure-software/
            • 14 min

            About The Virtual CISO Moment

            From the publisher's feed

            The Virtual CISO Moment dives into the stories of information security, information technology, and risk management pros; what drives them and what makes them successful while helping small and midsized business (SMB) security needs. No frills, no glamour, no transparent whiteboard text, no complex graphics, and no script - just honest discussion of SMB information security risk issues.