Take 1 Security Podcast: Episode 5

Take 1 Security Podcast: Episode 5



START CONTENT


* Anthem, the second largest healthcare company, had a major breach


* They lost around 80 million socials, addresses, emails, etc., which is roughly double the Target breach
* There’s speculation that it was China, trying to penetrate government, but it’s early
* Watch for phishing scams related to it
* The megabreaches continue…weee!

* A WordPress plugin called FancyBox had a serious compromise in it last week, which affected thousands of websites


* If you’re going to run WordPress, understand that Plugins are the best way to get yourself hacked
* Specifically, the type of plugins that handle user input and do something with it that affects the site’s output
* Image manipulation plugins have been particularly vulnerable, usually to XSS

* There was another critical Flash vulnerability this week


* Like I said last week, and the week before, there’s a first time for everything

* Three bug hunters at HP received the 125,000 prize for finding a major vulnerability in Internet Explorer


* Because they work for HP they couldn’t take the cash, and instead donated it to charity

* Microsoft released Outlook for iOS last week, which looks pretty slick


* Unfortunately it is riddled with security flaws
* Recommendation: wait for a few updates, and for them to get a security assessment


END CONTENT


Play Podcast

Become a Member: https://danielmiessler.com/upgrade

See omnystudio.com/listener for privacy information.

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(541)

A Conversation with Rob Allen from ThreatLocker

A Conversation with Rob Allen from ThreatLocker

In this conversation, I speak with Rob Allen, Chief Product Officer at ThreatLocker. We talk about: ThreatLocker’s Unique Zero Trust Approach to Cybersecurity:How ThreatLocker’s "deny by default, perm...

18 Marras 202432min

UL NO. 458: Ollama Vulnerabilities, Rating AI Using AI, The Mantis Hack-back Framework

UL NO. 458: Ollama Vulnerabilities, Rating AI Using AI, The Mantis Hack-back Framework

My conversation with Jason Haddix from Flare, Google finds a Zero-Day with AI, Robot Dogs Protecting Mar-a-Lago, and more... Subscribe to the newsletter at: https://danielmiessler.com/subscribe Join t...

17 Marras 202432min

A Conversation with Jason Haddix from Flare

A Conversation with Jason Haddix from Flare

Streamline Your Cybersecurity with Flare Here: https://try.flare.io/unsupervised-learning/ In this conversation, I speak with Jason Haddix, founder of Arcanum Security and CISO at Flare. We talk about...

11 Marras 202430min

UL NO. 454: The First AI Breaches

UL NO. 454: The First AI Breaches

AI Avatar Breaches, Gullibility is Vulnerability: Conspiracy is Threat, Caldera's New Plugin, and more... Try Out the ThreatLocker to take your security to the next level: https://www.threatlocker.com...

18 Loka 202435min

How My Projects Fit Together (Substrate, Fabric, Telos, Daemon, and Human 3.0)

How My Projects Fit Together (Substrate, Fabric, Telos, Daemon, and Human 3.0)

This episode, "How My Projects Fit Together," is a follow-up to a previous post called "What I Am Doing & How It's Going". Here, Daniel Miessler addresses the most commonly asked questions: "I see all...

15 Loka 20241h 1min

Human 3.0—The Skills & Mental Frames Required To Thrive In An AI World

Human 3.0—The Skills & Mental Frames Required To Thrive In An AI World

Human 3.0 is here. In this conference for the United Nations, Daniel Miessler introduces the topic of Human 3.0 philosophy and the skills and mental frameworks needed to thrive in an AI-driven world. ...

9 Loka 202430min

UL NO. 452: The New Hotness: NotebookLM

UL NO. 452: The New Hotness: NotebookLM

China prepping for kinetic using cyber?, Automatic podcast creation using NotebookLM, VM + AI, and more... Subscribe to the newsletter at: https://danielmiessler.com/subscribe Join the UL community at...

7 Loka 202450min

NotebookLM Podcast: David Deutsch, Understanding, and AI

NotebookLM Podcast: David Deutsch, Understanding, and AI

This is a NotebookLM podcast based on a long conversation I had with my AI, DARSA, on the topic of whether AIs truly understand things and/or are capable of creativity.Become a Member: https://danielm...

2 Loka 202412min