Making Security Great Again!
State of Cybercrime4 Marras 2016

Making Security Great Again!

Since October was Cyber Security Awareness month, we decided to look at what’s holding back our efforts to make security—to coin a phrase—“great again”.

In this episode of the Inside Out Security Show panel – Cindy Ng, Kilian Englert, Kris Keyser, and Mike Buckbee – shared their thoughts on insider threats as discussed on a recent Charlie Rose show, the brilliant but evil use of steganography (the practice of concealing a file, message, image, or video within another file, message, image, or video), and the dark market for malware hidden in underground forums.

For a taste of the podcast, here are a few data security ideas and quotes from our panelists.

Insider Threat. According to Keyser, an insider attack might not necessarily be the fault of employees. It could be that a hacker obtained their credentials—by guessing or pass-the-hash-- and the attack was executed under their name. So don’t make an employee the ‘fall guy’ for what was really an outsider. Blame IT instead. Kidding!

Steganography. On hackers hiding credit card information on images, Keyser says, “It’s reminiscent of the skimmer attack, you might find on an ATM or a card reader at shop you go to, but it’s applying that same concept to data, the nonphysical world.”

Like the rest of us, Englert was fascinated by the use of steganography. Englert says, “It’s always been kind of an interesting concept that I played with just for fun, but to see this used as an exfilitration method, it’s terrifying and it’s also brilliant. Having the website serve up the information you’re stealing, publicly, hidden in image files, it’s such a great way to get data out.”

What will hackers think up next?

Underground Forums. Englert thinks these underground sites are fulfilling a market need. He says, “Why not be enterprising? Makes sense from a business perspective. It’s not moral, but a way to make money.” Hackers are certainly displaying an entrepreneurial spirit.

Thinking Like a Hacker
With DDos attacks on the rise – up 125% in 2016-- Buckbee shares what he learned from Marek Majkowski’s presentation, “Are DDoS attacks a threat to the decentralized internet?” A united Internet makes us strong, and with a divided one we may fall.

A Tool for Sysadmins
Mosh (mobile shell) is a remote terminal application that supports intermittent connectivity, allows roaming, and speculatively and safely echoes user keystrokes for better interactive response over high-latency paths.

Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrime

More from Varonis ⬇️

Visit our website: https://www.varonis.com

LinkedIn: https://www.linkedin.com/company/varonis

X/Twitter: https://twitter.com/varonis

Instagram: https://www.instagram.com/varonislife/

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(211)

The Ransomware That Ran Itself

The Ransomware That Ran Itself

More from Varonis ⬇️ Visit our website: https://www.varonis.com LinkedIn: linkedin.com/company/varonis X/Twitter: x.com/varonis Instagram: instagram.com/varonislife Want to join us live? Save a seat h...

18 Heinä 38min

Megalodon Poisons Github

Megalodon Poisons Github

More from Varonis ⬇️ Visit our website: https://www.varonis.com LinkedIn: linkedin.com/company/varonis X/Twitter: x.com/varonis Instagram: instagram.com/varonislife Want to join us live? Save a seat h...

12 Kesä 29min

The Canvas Breach

The Canvas Breach

More from Varonis ⬇️ Visit our website: https://www.varonis.com LinkedIn: linkedin.com/company/varonis X/Twitter: x.com/varonis Instagram: instagram.com/varonislife Want to join us live? Save a seat h...

19 Touko 29min

The Axios Supply Chain Attack

The Axios Supply Chain Attack

The Axios supply chain attack proves attackers don’t need vulnerabilities if they can hit the assembly line. By compromising a single npm maintainer account, they were able to slip a trojan into Axios...

10 Huhti 43min

Salesforce Aura Data Theft

Salesforce Aura Data Theft

ShinyHunters has once again placed Salesforce customers in their crosshairs – this time abusing guest user misconfigurations in public-facing Experience Cloud sites. The group claims to have compromis...

20 Maalis 29min

OpenClaw & Moltbook (w/ Moriah Hara!)

OpenClaw & Moltbook (w/ Moriah Hara!)

OpenClaw – an opensource AI agent dubbed “Claude with hands” – has exploded across GitHub, rocketing from obscurity to 170,000 stars in just two weeks. It’s now the fastest spreading form of shadow IT...

14 Helmi 43min

The React2Shell Crisis

The React2Shell Crisis

React2Shell, the zero-click RCE exploit, is rapidly becoming one of the most significant cybersecurity incidents this year. From emergency patches causing a massive Cloudflare outage to active exploi...

15 Joulu 202522min

AI-Powered Espionage

AI-Powered Espionage

A Chinese state-sponsored group weaponized Anthropic’s Claude tool to launch the first large-scale AI-driven espionage campaign, targeting more than 30 organizations across tech, finance, manufacturin...

24 Marras 202523min

Suosittua kategoriassa Liike-elämä ja talous

sijotuskasti
psykopodiaa-podcast
mimmit-sijoittaa
ostan-asuntoja-podcast
rss-oivalluksia-rahasta-elamasta
oppimisen-psykologia
hyva-paha-johtaminen
rss-hilden-kaira-podcast
rss-rahapodi
pomojen-suusta
rss-inderes
rss-laiskan-yrittajan-markkinointi-podcast
rss-sami-miettinen-neuvottelija
rahapuhetta
rss-ysin-muijat
rss-paasipodi
rss-rentotapaus
rss-10x-finland
rss-rahamania
rss-myycast