
CISA Alert AA22-277A – Impacket and exfiltration tool used to steal sensitive information from defense industrial base organization.
From November 2021 through January 2022, the CISA responded to APT activity against a Defense Industrial Base organization’s enterprise network. During incident response activities, CISA discovered th...
4 Loka 20222min

CISA issues Binding Operational Directive 23-01. LAUSD says ransomware operators missed most sensitive PII. Trends in API protection SaaS security. Making a pest of oneself in a hybrid war.
CISA issues a Binding Operational Directive. An LA school district says ransomware operators missed most sensitive PII. An API protection report describes malicious transactions. Analysis of cyber ris...
4 Loka 202232min

Microsoft Exchange zero-days exploited. Supply chain attack reported. New Lazarus activity. Mexican government falls victim to hacktivism. Hacking partial mobilization. Former insider threat.
Two Microsoft Exchange zero-days exploited in the wild. A supply chain attack, possibly from Chinese intelligence services. There’s new Lazarus activity: bring-your-own-vulnerable-driver. The Mexican ...
3 Loka 202230min
![The OSINT revolution: How cyber and physical security teams are leveraging open source intelligence. [CyberWire-X]](https://cdn.podme.com/podcast-images/2314D040A5A2689DFF0F19F617D68766_small.jpg)
The OSINT revolution: How cyber and physical security teams are leveraging open source intelligence. [CyberWire-X]
On this episode of CyberWire-X, we dive into the essential role of open-source intelligence in identifying cyber and physical threats and reducing risk across your organization. The CyberWire's CSO, C...
2 Loka 202227min
![Kayla Williams: Not everything related to cybersecurity is a fire drill. [CISO] [Career Notes]](https://cdn.podme.com/podcast-images/2314D040A5A2689DFF0F19F617D68766_small.jpg)
Kayla Williams: Not everything related to cybersecurity is a fire drill. [CISO] [Career Notes]
Kayla Williams, CISO of Devo, sits down to share her story, from graduating with a finance degree to rising to where she is now. She quickly learned that finance was not for her and changed paths, wor...
2 Loka 20228min
![Targeting your browser bookmarks? [Research Saturday]](https://cdn.podme.com/podcast-images/2314D040A5A2689DFF0F19F617D68766_small.jpg)
Targeting your browser bookmarks? [Research Saturday]
David Prefer from SANS sits down with Dave to discuss how a new covert channel exfiltrates data via a browser's built-in bookmark sync. David goes on to describe how this research will "describe how t...
1 Loka 202218min

Espionage, both online and in-person. Sabotage, both kinetic and (maybe eventually) cyber. Waterin holes, deepfakes, and the pushing of naughty words.
North Korean operators "weaponize" open-source software. The SolarMarker info-stealer returns. A quick review of Fast Company's WordPress hijacking incident. Deepfakes, and their evolution into an und...
30 Syys 202230min

Hackers support Iranian dissidents. Notes on C2C markets. Cyberespionage campaigns. Intercepted mobile calls from Russian troops expose morale problems.
Gray-hat support for Iranian dissidents. Selling access wholesale in the C2C market. Novel malware’s discovered targeting VMware hypervisors. The Witchetty espionage group uses an updated toolkit. Dee...
29 Syys 202223min




















