CyberAttack Grab Bag - Episode 207

CyberAttack Grab Bag - Episode 207

On this episode, the CU Guys uncover the latest cyber threats, from AI-driven breaches to cloud misconfigurations, that put your data at risk. Learn about real-world examples of high-profile breaches and simple social engineering tricks that can compromise your security. Discover the role of AI and quantum computing in cyberattacks and get practical steps to enhance your defenses. Perfect for cybersecurity professionals and anyone serious about data protection, this episode offers essential insights to stay ahead of cybercriminals. Don't wait for a breach, arm yourself with knowledge and strategies today.


Episode Transcript:

So I wanted to go through some of the top breaches and whatnot that were happening and we're all of what, about 10 weeks or so into 2026. So I figure we'll give the folks a little bit of an update. We've got some AI-powered attacks, supply chain vulnerabilities, a little ransomware sprinkled into the mix. So yeah, it's been a lot of exciting stuff happening out there.


So I'll just kind of bebop around and we can talk about some of these. But one of the public sector breaches was a contractor and suffered a ransomware attack that exposed something along the lines of 25 million individuals, which was having some pretty substantive impacts on state benefit systems. So it's definitely interesting seeing that type of exposure, but it's just one of the things that folks don't realize is just how much all of this security and compliance, layers of controls all work together to help to protect you. But it's one of the areas that organizations don't focus heavily enough on is the security and compliance of the folks that are working for them, if you will.


Why do you think that is, Arut?


Well, a lot of people will go under the, you know, under the guiding assumption that, oh, you know, and especially based on, you know, the name of the company or, you know, whatever, and they just don't take that that threat as as seriously as they should or need to, you know, and nobody out there is perfect, right? But you do expect that, you know, larger scale organizations have their act together, but time after time, they end up kind of proving out that that's not necessarily the case.


And so, but, you know, in the grand scheme of things, we've got, shit, we even had the FBI had, you know, had an issue. This is another vendor driven, you know, another vendor driven, you know, incident where there was a vendor's internet service provider that was compromised so that they could access a federal digital collection system network. So, you know, you've got, you know, you got the bad guys out there, kind of indirectly, indirectly hitting critical FBI systems as well. So it's not just the corporate arena, you know, out there that, you know, that gets hit. But yeah, this one, this one was in like mid, mid February. They were.


There seems to be a rash of federal mishandlings in the information realm these days.


They're not immune, so apparently around the middle of February they were seeing some irregular network activity that was leading them straight to the digital collection system network and finding out that there's sensitive data with court-authorized wiretaps, FISA warrants and personal information on active FBI agents, etc. They claim that they've identified and addressed the suspicious activity, but they're not saying, go figure.


They're not saying a lot more than that, shall we say. The government is definitely not immune, shall we say.


That is a, uh, that is a very fair statement. Uh, one of the ones that really hurt my heart, because I like what they bring to the table, tell us what happened on the Cargoo roost front.

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(233)

Join TCT at the PCI-NACM in Vancouver - Episode 233

Join TCT at the PCI-NACM in Vancouver - Episode 233

PCI has evolved from checkbox audits toward continuous assurance, but are organizations truly keeping pace? Todd Coshow and Adam Goslin explore how AI, cloud-native payments, software supply chain ris...

10 Sep 14min

PCI Engagement Masterclass - Episode 232

PCI Engagement Masterclass - Episode 232

On this week's Compliance Unfiltered, PCI engagement chaos doesn’t have to be the norm. Todd Coshow and Adam Goslin explore how smarter compliance workflows can eliminate repetitive evidence collectio...

3 Sep 33min

What Compliance Problems Arise when AI is Writing Your Policies?- Episode 231

What Compliance Problems Arise when AI is Writing Your Policies?- Episode 231

On this episode of Compliance Unfiltered, AI can speed up policy drafting, but it can also create hidden compliance risk when no one validates the result. Listen, as Todd Coshow and Adam Goslin discus...

27 Aug 25min

PCI FAQs When You’re Starting Your Compliance Program - Episode 230

PCI FAQs When You’re Starting Your Compliance Program - Episode 230

Think PCI compliance is something you can outsource? Think again. Todd Coshow and Adam Goslin break down the biggest misconceptions about PCI DSS, from third-party payment processors and SAQs to merch...

20 Aug 33min

The Control Worked Yet The Company Still Got Breached - Episode 229

The Control Worked Yet The Company Still Got Breached - Episode 229

Passing an audit doesn't mean you're secure. In this episode of Compliance Unfiltered, Todd Coshow and Adam Goslin expose the critical gap between compliance and real cybersecurity. Learn why controls...

13 Aug 24min

Government AI Regulations That Could Impact Your Company - Episode 228

Government AI Regulations That Could Impact Your Company - Episode 228

AI regulation is no longer a future problem. It’s creating legal, financial, and product risk today. Todd Coshow and Adam Goslin break down the evolving AI regulatory landscape, from FTC enforcement a...

6 Aug 29min

Making Sure Your Compliance Program Keeps Up - Episode 227

Making Sure Your Compliance Program Keeps Up - Episode 227

Compliance is changing fast, and many organizations are already behind without realizing it. In this episode, Todd Coshow and Adam Goslin break down why AI, cybersecurity, privacy, and third-party ris...

30 Jul 21min

Ready to Get Serious About Compliance? - Episode 226

Ready to Get Serious About Compliance? - Episode 226

Compliance doesn't have to be expensive, slow, or overwhelming. In this episode, the CU Guys reveal the blueprint for building a successful compliance program from the ground up. Learn why the right p...

23 Jul 36min

Populært innen Teknologi

lydartikler-fra-aftenposten
energi-og-klima
tomprat-med-gunnar-tjomlid
nasjonal-sikkerhetsmyndighet-nsm
shifter
elektropodden
teknisk-sett
rss-alt-som-gar-pa-strom
rss-ai-forklart
kortslutning
rss-kunstig-intelligens-med-elisabeth-maren-og-morten
smart-forklart
rss-teknologioptimistene-en-podkast-om-teknologi-og-mennesker
digital-forretningsforstaelse
rss-ki-praten
rss-larervarelset
pedagogisk-intelligens
rss-alt-vi-kan
rss-heis
rss-bak-skyen