
Sign up to save your podcasts
Or


This week's cybersecurity updates cover three critical stories: Workday discloses a data breach connected to ongoing Salesforce compromises by the Shiny Hunters group, CEO impersonation scams using deepfake technology surge past $200 million in Q1 losses, and transcription service Otter AI faces a class action lawsuit over alleged mishandling of sensitive meeting data. Drex emphasizes the importance of security awareness training, multi-factor authentication, and establishing "trust but verify" cultures that protect employees who take extra verification steps.
Remember, Stay a Little Paranoid
X: This Week Health
LinkedIn: This Week Health
Donate: Alex’s Lemonade Stand: Foundation for Childhood Cancer
Drex covers three critical cybersecurity trends: companies swapping full-time security staff for platform subscriptions (requiring premium salaries for contract managers), the rise of AI agents in both cyber defense and attacks, and voice phishing campaigns targeting CRM systems like Salesforce that have compromised major brands including Adidas and Victoria's Secret. Healthcare organizations face unique risks from PHI exposure and must balance automation with human oversight while training staff on voice-based social engineering attacks.
This episode covers three critical cybersecurity developments affecting healthcare organizations. First, FBI warnings about Scattered Spider ransomware group targeting employees through Slack and Microsoft Teams, including their alarming tactic of creating fake identities to join incident response calls and monitor remediation efforts. Second, leaked chat logs from the Conti ransomware group reveal these criminal organizations operate like structured tech startups with HR policies, management layers, and performance reviews - highlighting the sophisticated nature of modern cyber threats. Finally, CrowdStrike intelligence reveals over 900 North Korean operatives have quietly embedded themselves in US companies using deepfakes and fake identities, wiring paychecks back to the regime. The episode also mentions CISA's new free Thorium tool for malware analysis and forensic investigations.
X: This Week Health
LinkedIn: This Week Health
Donate: Alex’s Lemonade Stand: Foundation for Childhood Cancer
Drex covers three critical cybersecurity threats impacting healthcare and beyond: North Korean operatives using deepfakes and stolen identities to infiltrate US companies as remote workers, the Allianz life insurance breach affecting 1.4 million customers through social engineering attacks, and the TTEA dating app's massive data exposure that compromised women's safety information. Essential insights on vetting remote employees, defending against social engineering, and app security risks.
Remember, Stay a Little Paranoid
X: This Week Health
LinkedIn: This Week Health
Donate: Alex’s Lemonade Stand: Foundation for Childhood Cancer
This week's cybersecurity roundup covers three critical healthcare security developments. Microsoft patched an actively exploited SharePoint zero-day vulnerability (CVE-2024-38023) that allows attackers with basic permissions to execute remote code and pivot through networks. Two major dermatology practice breaches - Mount Laurel Dermatology and Anne Arundel Dermatology - exposed over 1.9 million patient records through third-party vendor compromises, highlighting the risks of business associate agreements. Plus, cybersecurity expert Paul Conley challenges the healthcare industry's reliance on annual training and phishing simulations, advocating for personalized, continuous human risk management approaches that build actual cyber culture rather than just checking compliance boxes.
Remember, Stay a Little Paranoid
X: This Week Health
LinkedIn: This Week Health
Donate: Alex’s Lemonade Stand: Foundation for Childhood Cancer
From the publisher's feed

111,799 Listeners