T1SP: Episode 32
Unsupervised Learning28 Maalis 2016

T1SP: Episode 32



[ Subscribe to the Podcast: iTunes | Android | RSS ]

News


* [ ] Verizon Enterprise Solutions had a major data breach of their customer data. This is the group that handles breaches for their customers. “Virtually every attack in this data set (98 percent) was opportunistic in nature, all aimed at easy marks…”
* [ ] Iranians charged with attacks against US banks and a New York dam
* [ ] Hackers steal 81 billion from the Federal reserve bank of New York
* [ ] Uber launches bug bounty program, describes the surface area. Someone said it was really bad, though. Not sure what that’s about
* [ ] New ultra-fast SSD technology coming from Intel soon
* [ ] FBI backs off request for Apple backdoor. Says they have it handled. We find out it’s an Israeli company
* [ ] Water treatment plant hacked, chemical mix changed for tap supplies | http://www.theregister.co.uk/2016/03/24/water_utility_hacked/
* [ ] German steel mill compromised and wrecked a blast furnace
* [ ] This is after a string of attacks against power companies using spear phishing and office malware
* [ ] Microsoft’s AI Chatbot was a teenage girl, but it learned from the people who talked to it, so before long it was talking about loving incest, sex, and hitler
* [ ] Millions of Android devices vulnerable to root exploit due to Snapdragon chip flaw
* [ ] Kentucky-based Methodist Hospital declares state of emergency after it’s wrecked by Locky ransomware
* [ ] Credit Card Breaches Linked To Security Cameras
* [ ] Chinese national pleads guilty to stealing plans for Air Force aircraft
* [ ] Hackers offer Apple’s Ireland staff $23,000 for their login credentials
* [ ] Ransomware hitting major vulns: The Angler, Neutrino, Magnitude, RIG, and Nuclear exploit kits spread the Flash CVE 2015-7645 exploit; Angler spreads Flash 2015-8446; Angler and Neutrino spread Flash CVE 2015-8651; and Angler spreads Silverlight CVE-2016-0034, an exploit exposed in the Hacking Team breach.
* [ ] Microsoft Deploys Macro Blocking Feature in Office to Curb Malware


Ideas, updates, and discussion


* [ ] Innovation Sandbox | Innovative Security Products (2016 Edition)
* [ ] AI and messaging apps are the new mobile apps
* [ ] Human Attention as Attack Surface | https://danielmiessler.com/blog/human-attention-as-influence-attack-surface/
* [ ] Most can’t respond to breach: http://blogs.csc.com/2016/03/15/while-majority-of-orgs-fear-big-breach-theyre-not-prepared-to-respond/?utm_content=bufferc043c&utm_medium=social&utm_source=twitter.com&utm_campaign=buffer
* [ ] How your data is collected and commoditized online by free online services | http://www.troyhunt.com/2016/03/how-your-data-is-collected-and.html


Tools, talks, and projects


* [ ] Innovation Sandbox | Innovative Security Products (2016 Edition)
* [ ] 2016 Data Breach Digest | https://danielmiessler.com/blog/analysis-verizons-2016-data-breach-digest/
* [ ] AI and messaging apps are the new mobile apps | https://danielmiessler.com/blog/ai-assistants-are-the-new-applications/
* [ ] Idea Expansion Format | https://danielmiessler.com/blog/idea-expansion-format-ief/
* [ ] BinDiff is a comparison tool for binary files that helps to quickly find differences and similarities in disassembled code.
* [ ] IntelMQ is a solution for CERTs for collecting and processing security feeds, pastebins, tweets and log files using a message queuing protocol.

Become a Member: https://danielmiessler.com/upgrade

See omnystudio.com/listener for privacy information.

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(541)

Take 1 Security Podcast: Episode 13

Take 1 Security Podcast: Episode 13

Notes * The intro track is from one of my favorite EDM artists: Zomby. The song is ‘Orion’, and it’s from the ‘With Love’ album. Highly recommended if you like chill EDM. Become a Member: https://da...

12 Kesä 201542min

Take 1 Security Podcast: Episode 12

Take 1 Security Podcast: Episode 12

Play Podcast START CONTENT * Singtel buys Trustwave * Snowden does interview with John Oliver * CheckPoint buys Lacoon * Everyone’s trying to do everything, which gives the big people a major adv...

8 Huhti 201513min

Take 1 Security Podcast: Episode 11

Take 1 Security Podcast: Episode 11

Play Podcast START CONTENT * Twitch, a game streaming service owned by Amazon, was hacked last week * Passwords, emails, usernames, addresses, phone numbers, dates of birth * Amazon bought them l...

30 Maalis 201516min

Take 1 Security Podcast: Episode 10

Take 1 Security Podcast: Episode 10

Play Podcast START CONTENT * There was another SQL Injection bug found in SEO by Yoast * It required admins to click a malicious link * Was patched quickly * It’s the plugins that make WordPress ...

16 Maalis 201522min

Take 1 Security Podcast: Episode 9

Take 1 Security Podcast: Episode 9

START CONTENT * Sorry about the audio last week; wireless headsets don’t compare to the Yeti * The CIA is focusing on cyberespionage in its new management * Anthem is refusing an audit by the OIG of...

9 Maalis 201512min

Take 1 Security Podcast: Episode 8

Take 1 Security Podcast: Episode 8

START CONTENT * New SSL attack called FREAK * Has to do with falling RSA back to a deprecated and weak level * Requires the client and server are both vulnerable * The solution is to patch * Many ...

3 Maalis 201516min

Take 1 Security Podcast: Episode 7

Take 1 Security Podcast: Episode 7

START CONTENT * New stuxnet like piece of malware was discovered * Was found by Kaspersky * Has infected thousands of computers, mostly in Iran * The malware is the most advanced ever found * Can ...

24 Helmi 20158min

Take 1 Security Podcast: Episode 6

Take 1 Security Podcast: Episode 6

START CONTENT * Ukrainian banks hacked for up to 1 Billion dollars * Evidently installed malware on bank admin machines using phishing * Not sure they have an FDIC * As if the Ukraine didn’t have ...

17 Helmi 201512min