The Virtual CISO Moment

The Virtual CISO Moment

By Greg SchafferTechnology
Download on the App Store

The Virtual CISO Moment episodes

  • The Virtual CISO Moment Wrap Up for Friday, August 19, 2022

    Apple zero-day vulns. poop hack, pregnancy app privacy concerns, UK water supply ransomware, tips for SMBs to avoid ransomware risks, and the most interesting CVE? Plus a few more thoughts on Twitter cyber drama.

    • https://thehackernews.com/2022/08/apple-releases-security-updates-to.html
    • https://www.bleepingcomputer.com/news/security/anonymous-poop-gifting-site-hacked-customers-exposed/
    • https://www.theregister.com/2022/08/17/mozilla_pregnancy_app/
    • https://www.bleepingcomputer.com/news/security/hackers-attack-uk-water-supplier-but-extort-wrong-company/
    • https://www.csoonline.com/article/3669855/ransomware-safeguards-for-small-to-medium-sized-businesses.html
    • https://www.techspot.com/news/95671-janet-jackson-song-1989-declared-cybersecurity-vulnerability-crashing.html
    • 14 min
    • The Virtual CISO Moment S4E35 - Briefing for Small Businesses
      In this presentation from 2014, Greg discusses SMB information security concerns with a group of small business owners in Tennessee. Most is relevant still today (though Greg notes he'd reevaluate his antivirus recommendations). Most of the video is dark (lights turned down to view slide deck off-screen).
      50 min
    • VCM Quick Strike for Monday, August 16, 2022

      BHG brief affects almost 200K, hackers target cybersecurity pros with fake job offers, Zeppelin ransomware multiple encryption, Russia wiper attacks on Ukraine, smartphone ransomware, 5G IOT API vulns, and thoughts on how to police the infosec community.

      • https://www.scmagazine.com/analysis/breach/behavioral-health-group-informs-198k-patients-of-data-theft-from-december
      • https://hackercombat.com/north-korean-hackers-target-crypto-experts-with-fake-coinbase-job-offers/
      • https://www.bleepingcomputer.com/news/security/fbi-zeppelin-ransomware-may-encrypt-devices-multiple-times-in-attacks/amp/
      • https://www.cybersecurity-insiders.com/russia-launching-wiper-malware-cyber-attacks-against-ukraine/
      • https://www.forbes.com/sites/daveywinder/2022/08/14/gmail-and-gpay-cookies-targeted-by-new-smartphone-ransomware-threat-to-200-apps/?sh=65e59f936743
      • https://arstechnica.com/information-technology/2022/08/one-of-5gs-biggest-features-is-a-security-minefield/
      • 14 min
      • The Virtual CISO Moment Wrap Up for Friday, August 12, 2022

        Starlink hack, Ukraine cyber chief at BlackHat, new GitHub alerts to potential vulns, new Malware as a Service, what caused that Google outage, Cloudflare phishing attack, two new tools for nonbank financial services companies, and a Cisco breach involving "MFA fatigue".

        • https://www.wired.com/story/starlink-internet-dish-hack/
        • https://www.reuters.com/world/europe/ukraine-cyber-chief-pays-surprise-visit-black-hat-hacker-meeting-las-vegas-2022-08-11/
        • https://thehackernews.com/2022/08/github-dependabot-now-alerts-developers.html
        • https://www.theregister.com/2022/08/08/dark_utilities_c2_service/
        • https://cybernews.com/news/google-apologizes-for-a-global-services-outage/
        • https://cybernews.com/news/cloudflare-targeted-by-a-sophisticated-phishing-attack/
        • https://www.csbs.org/newsroom/csbs-releases-nonbank-cybersecurity-exam-procedures
        • https://www.bleepingcomputer.com/news/security/cisco-hacked-by-yanluowang-ransomware-gang-28gb-allegedly-stolen/
        • 12 min
        • Throwback Thursday for August 11, 2022 - A Conversation with Don Baham

          On this week's Throwback Thursday from April 19, 2022, Don Baham is very active in both the local and on-line information security communities, as well as having extensive experience helping SMBs with information security needs. He joins us to discuss challenges and opportunities including observations on the cyber security supply chain issue and possible ways to address.

          22 min
        • VCM Quick Strike for Monday, August 8, 2022

          Critical flaws in Emergency Alert System and in some Cisco SOHO routers, new IoT threat, CISA adds Zimbra vulnerability to its Known Exploited Vulnerabilities Catalog, and what you need to do to land a six-figure cybersecurity job.

          • https://www.threatshub.org/blog/warning-critical-flaws-found-in-us-emergency-alert-system/
          • https://www.theregister.com/2022/08/05/cisco_smb_routers_critical_flaws/
          • https://thehackernews.com/2022/08/new-iot-rapperbot-malware-targeting.html
          • https://thehackernews.com/2022/08/cisa-adds-zimbra-email-vulnerability-to.html
          • https://fortune.com/education/business/articles/2022/07/27/what-you-need-to-land-a-six-figure-cybersecurity-job/
          • https://youtube.com/playlist?list=PLZkMMBCZshiO0gu44pAZUM__fpHOrvTcv
          • 13 min
          • The Virtual CISO Moment Wrap Up for Friday, August 5, 2022

            Motherboard malware that survives OS reinstall, mobile apps leaking Twitter API keys, TVA EDR not OK, Defender defends against ransomware better, ransomware big brands migrating to more smaller bands, and Ukraine shutters major Russian bot network.

            • https://www.pcmag.com/news/malware-that-can-survive-os-reinstalls-found-on-asus-gigabyte-motherboards
            • https://thehackernews.com/2022/08/researchers-discover-nearly-3200-mobile.html
            • https://www.scmagazine.com/analysis/zero-trust/feds-begin-measuring-edr-at-tennessee-valley-authority-but-gaps-cited-in-audit
            • https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-now-better-at-blocking-ransomware-on-windows-11/
            • https://www.bankinfosecurity.com/blogs/ransomware-ecosystem-value-big-name-brands-diminishing-p-3257
            • https://www.infosecurity-magazine.com/news/ukraine-shutters-major-russian-bot/
            • 12 min

            About The Virtual CISO Moment

            From the publisher's feed

            The Virtual CISO Moment dives into the stories of information security, information technology, and risk management pros; what drives them and what makes them successful while helping small and midsized business (SMB) security needs. No frills, no glamour, no transparent whiteboard text, no complex graphics, and no script - just honest discussion of SMB information security risk issues.