Dial 'F' for Fraud: Uncovering IRSF
Blue Security10 Maalis

Dial 'F' for Fraud: Uncovering IRSF

Summary

In this episode of the Blue Security Podcast, hosts Andy and Adam delve into a significant surge in external ID charges experienced by a customer, leading to the discovery of an international revenue share fraud attack. They discuss the mechanics of this fraud, how it exploits telecommunication systems, and the importance of monitoring and mitigating such attacks. The conversation emphasizes the need for organizations to implement security measures, including web application firewalls and billing alerts, to prevent financial losses from similar attacks. The episode concludes with key takeaways and recommendations for enhancing security in external identity management.

----------------------------------------------------

YouTube Video Link: https://youtu.be/6jXBULGx5aA

----------------------------------------------------

Documentation:

https://learn.microsoft.com/en-us/entra/architecture/deployment-external-operations

https://learn.microsoft.com/en-us/entra/identity/authentication/concept-mfa-telephony-fraud

https://learn.microsoft.com/en-us/entra/external-id/customers/how-to-region-code-opt-in

https://learn.microsoft.com/en-us/entra/external-id/customers/concept-multifactor-authentication-customers#sms-pricing-tiers-by-countryregion

----------------------------------------------------

Contact Us:

Website: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://bluesecuritypod.com

Bluesky: https://bsky.app/profile/bluesecuritypod.com

LinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/company/bluesecpod

YouTube: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.youtube.com/c/BlueSecurityPodcast

-----------------------------------------------------------

Andy Jaw

Bluesky: https://bsky.app/profile/ajawzero.com

LinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/in/andyjaw/

Email: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠andy@bluesecuritypod.com⁠

----------------------------------------------------

Adam Brewer

Twitter: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://twitter.com/ajbrewer

LinkedIn: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.linkedin.com/in/adamjbrewer/

Email: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠adam@bluesecuritypod.com

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(326)

Critical infrastructure hacks and rogue AI agents

Critical infrastructure hacks and rogue AI agents

SummaryIn this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss the recent cyberattacks on water systems in Minnesota, attributed to Iran-linked hackers. They explore the v...

11 Elo 54min

Hotel Wi-Fi Hijacks and Border Phone Searches

Hotel Wi-Fi Hijacks and Border Phone Searches

SummaryIn this episode of the Blue Security Podcast, host Andy Jaw and guest Carly Salmon discuss critical issues in data security, focusing on a recent hotel Wi-Fi hack that exploits DNS settings to ...

4 Elo 47min

MDASH in Prod, Intune Sync, OpenAI-Hugging Face Incident

MDASH in Prod, Intune Sync, OpenAI-Hugging Face Incident

SummaryIn this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss significant developments in cybersecurity, including Microsoft's new AI vulnerability scanner, the long-awai...

28 Heinä 50min

Identity Update: Passkeys by Default, Phone Transfers, Physical Key Security

Identity Update: Passkeys by Default, Phone Transfers, Physical Key Security

SummaryIn this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss the upcoming transition to passkeys as the default method for multi-factor authentication (MFA) in Microsoft...

21 Heinä 34min

North Korean IT Worker Scam

North Korean IT Worker Scam

SummaryIn this episode of the Blue Security Podcast, host Andy Jaw delves into the alarming rise of North Korean IT worker scams, exploring their historical context, operational tactics, and the finan...

14 Heinä 48min

Claude Fable, SharePoint RCE, and CISA's KEV list

Claude Fable, SharePoint RCE, and CISA's KEV list

SummaryIn this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss Andy's career transition from Microsoft to Zscaler, the return of the AI model Fable and its user experience...

7 Heinä 22min

Helping or Hurting? - An Honest Conversation About AI

Helping or Hurting? - An Honest Conversation About AI

SummaryIn this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer engage in a deep discussion about the implications of AI on society and the security industry. They explore whether ...

30 Kesä 1h 3min

Your MDM Admin Can Wipe Everything. Are You Protecting Them Like It?

Your MDM Admin Can Wipe Everything. Are You Protecting Them Like It?

SummaryIn this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer delve into the critical topic of Mobile Device Management (MDM) and the associated administrative rights. They discu...

23 Kesä 32min