Take 1 Security Podcast: Episode 4

Take 1 Security Podcast: Episode 4



START CONTENT


* Ghost bug in PHP could affect millions of servers


* Flaw is in glibc, which is extensively by all Linux distributions
* Patch and reboot using yum or aptitude

* The US Army Released DShell, a malware forensics tool


* This is an interesting trend where we see tons of formerly secret groups flock to Github. Great to see

* Reddit released its first transparency report last week


* Says it received 55 requests for user information
* Says it complied with 64% of state and federal requests
* Says it received 218 requests for content removal, and complied with 31 percent of those
* I am pleased to see them releasing these numbers, and I hope more organizations do the same

* The GHCQ was using a program called BADASS to collect data leaked by games such as Angry Birds


* Luckily it only affected the 11 people still playing that game

* Russian dating site, Topface, got hacked for 20 million usernames
* The FBI busted up a Tom Clancy book plot in New York City


* The plan was to get information about wall street trading algorithms and hopefully destabilize the markets
* All they managed to do was embarrass themselves by commenting on how they couldn’t recruit young women

* China is demanding to be able to build backdoors into any code sold to its banking sector


* Some people call this news, but with China we just call this Wednesday

* Apple released a Yosemite update that fixed Thunderstrike, among other things
* Anonymous and Lizard Squad are going after each other


* Anonymous is the famous hacking group known for all sorts of things
* Lizard Squad is known for taking down the XBox and Playstation networks around Christmas time
* Anonymous DDoS’d the Lizard Squad website, and then Twitter suspended a couple of their handles
* Interesting to see these groups going after each other

* BMW and the internet of things is in the news, with BMW owners receiving an automatic push to around 2 million cars


* A vulnerability was present that could allow attacks to spoof cell towers and possibly control onboard systems
* BMW pushed a patch that ensures all such communications go over HTTPS
* It’s interesting that, like printers, cars are likely to become a primary IoT platform just because there are so many of them
* The key is to figure out what normal things exist in the world today en mass, and then imagine those things being connected
* Printers, cars, furniture, clothing, etc. It’s the regular stuff that makes it interesting because of how much attack surface they represent, and how prevalent the perspective they’ll offer into our daily lives



END CONTENT

Play Podcast

Notes


* Intro is from Zomby. The song is ‘Orion’, and it’s from the ‘With Love’ album. Highly recommended if you like chill EDM.

Become a Member: https://danielmiessler.com/upgrade

See omnystudio.com/listener for privacy information.

Episoder(532)

UL NO. 401: Sony hit again?, Taiwan Disinformation, Corporations Demand Hardcore Workers, and GPTVision Examples…

UL NO. 401: Sony hit again?, Taiwan Disinformation, Corporations Demand Hardcore Workers, and GPTVision Examples…

We also look at Lex's first meaningful conversation in the metaverse, fixing Science, and TikTok's impact on reading 📢 Sponsored by Kolide: Concerned about data breaches and hacks? 🔒 Discover Kolide, the device trust solution that secures your company's devices and credentials, making phishing attempts useless to hackers. See it in action at www.kolide.com/unsupervisedlearning View today's episode online here: https://danielmiessler.com/p/ul-no-401-sony-hit-taiwan-disinformation-corporations-demand-hardcore-workers-gptvision-examples-9f9Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

3 Okt 202325min

UL NO. 400: What Hiring Managers Want, CVE Farming, Hunt Forward Operations, and AI vs. B2B Services

UL NO. 400: What Hiring Managers Want, CVE Farming, Hunt Forward Operations, and AI vs. B2B Services

Discover how AI is set to revolutionize the B2B services economy and the implications for GDP. Plus, unravel the paradox of the cyber job market, explore the urgent need for a content source authentication system, and delve into the controversial practice of CVE farming 📢Sponsored by Vanta.com - scales with your business, helping you enter new markets, land bigger deals, and earn customer loyalty. 📢Sponsored by: Mimecast.com - Protect yourself against vulnerabilities with an added layer of security To view online, visit https://danielmiessler.com/p/400Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

28 Sep 202331min

UL NO. 399: Wisdom Extraction From Any Text, Vegas Gets Cyber Jesus, AI Creativity Performance, Pentagon Cyber Strategy…

UL NO. 399: Wisdom Extraction From Any Text, Vegas Gets Cyber Jesus, AI Creativity Performance, Pentagon Cyber Strategy…

This week we talk about how I extract manual-quality wisdom from any text/transcript, what I learn from biographies, 25 lessons in 17 years of infosec, and tons of new tools and projects. 📢Sponsored by Vanta.com - scales with your business, helping you enter new markets, land bigger deals, and earn customer loyalty. 📢Sponsored by Moonlock — cybersecurity wing of MacPaw. Developers ofthe antimalware tech in CleanMyMac X — Moonlock Engine.Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

19 Sep 202338min

UL NO. 398: Storm Vuln Stacking, CloudRecon, The S-Tier Guide to AI Whispering, Full-body MRIs…

UL NO. 398: Storm Vuln Stacking, CloudRecon, The S-Tier Guide to AI Whispering, Full-body MRIs…

Explore the explosive separation of society into the Thriving 10% vs. the Suffering 90%, how AI is becoming an integral part of our brains, and how to defend your family's privacy 📢Sponsored by Vanta Building a SaaS business? Get ready for the compliance questions! 📈 Achieving SOC 2, ISO 27001, or HIPAA compliance can be a game-changer, but it's often tough. Automate up to 90% of work, save time & money, and scale effortlessly. www.vanta.com/unsupervisedBecome a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

12 Sep 202320min

UL NO. 397: Propaganda in a Box, Glacier-like Security, AGI by 2028?, Ancient Wisdom via AI, and Newsletter Differentiation

UL NO. 397: Propaganda in a Box, Glacier-like Security, AGI by 2028?, Ancient Wisdom via AI, and Newsletter Differentiation

🎥 Embracing Short-Form Video Creation🔬 Piping into Portscanner: A Guide📚 Long/Slow Content: The UL Book of the Month🛡️ Defensive Security: A Glacier's Pace🧠 Predicting AGI Attainment by 2025-2028📜 Timeless Concepts from Ancient Myths📰 Russian Impersonation Disinformation Exposed🤖 AI Disinformation: Counteracting Propaganda👗 Forever 21 Data Breach: Half a Million Impacted🚗 Automotive Hacking Contest: Pwn2Own Automotive🍏 Apple's Private Access Tokens: A Sneak Peek📡 WiFi Vision Surveillance: Tracking Living Beings🔭 Tool & Article Discovery➡️ The Recommendation of the Week🗣️ The Aphorism of the Week 📢Sponsored by Panoptica.app - Simplify container deployment, monitoring, and security 📢Sponsored by Vanta - Save up to 85% on compliance costs. Join 5,000+ clients cutting 300+ hours of work. 200+ integrations for easy tool security. Vanta.com/unsupervisedBecome a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

7 Sep 202326min

No. 396 - Elon's Doxxing FSD, ATHI AI Threat Modeling Framework, Cardboard Drones, and GPT Enterprise…

No. 396 - Elon's Doxxing FSD, ATHI AI Threat Modeling Framework, Cardboard Drones, and GPT Enterprise…

In this episode: 🤔 Thoughts on the Eliezer vs. Hotz AI Safety Debate🎥 Musk's FSD and Privacy Demo🔒 Duolingo Data Breach💥 MOVEit Mass Hack🔎 Putin Critics' Fate🚨 Leaseweb Security Breach🔬 Lazarus's New Malware🚁 Cardboard Drones in Combat🕵️ Taiwan Espionage Alert🔐 CloudNordic Ransomware Attack📱 Kroll's SIM Swap👾 GPT-4's API Misuses🔭 Tool & Article Discovery➡️ The Recommendation of the Week🗣️ The Aphorism of the Week 📢Sponsored by: Mimecast.com - Protect yourself against vulnerabilities with an added layer of security 📢Sponsored by Vanta.com - scales with your business, helping you enter new markets, land bigger deals, and earn customer loyalty.Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

29 Aug 202326min

What I'm Doing and How It's Going

What I'm Doing and How It's Going

How I went from a $350K FTE to $700K+ doing my own thing. This is the first time I've ever shared anything about what I'm doing and how I make money. It covers: Why I got out of the corporate game What I'm doing for income streams How much I make on each Why I think YOU should consider jumping as well Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

21 Aug 202322min

NO. 395 — How I Make Money as an Independent, Tesla's Insider Data Breach, Bots Beating CAPTCHAs, and Escaping the Maze…

NO. 395 — How I Make Money as an Independent, Tesla's Insider Data Breach, Bots Beating CAPTCHAs, and Escaping the Maze…

In this episode: 🎙️ "What I’m Doing And How It’s Going" 🔐 Tesla's Data Breach: An Inside Job🔍 Example’s Matter: Canary's Domain Name Issue🚨 NetScaler Instances Hacked: CVE-2023-3519 Exploited🤖 Bots Outperform Humans at Solving CAPTCHAs🔒 Infrastructure Security Boost: Israel-US Collaboration🔎 Microsoft Breach Investigation by DHS's CSRB🇨🇳 China's Cyber Threat to US Infrastructure🇯🇵 China's Damaging Cyber Attack on Japan🕵️‍♂️ Hacker Accounts Exposed: Cybercrime Forum Logins Stolen🔭 Tool & Article Discovery➡️ The Recommendation of the Week🗣️ The Aphorism of the Week 📢Sponsored by Vanta.com - scales with your business, helping you enter new markets, land bigger deals, and earn customer loyalty. 📢Sponsored by: Panoptica.app - Simplify container deployment, monitoring, and securityBecome a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

21 Aug 202332min

Populært innen Teknologi

romkapsel
rss-avskiltet
teknisk-sett
tomprat-med-gunnar-tjomlid
energi-og-klima
shifter
rss-impressions-2
nasjonal-sikkerhetsmyndighet-nsm
elektropodden
smart-forklart
rss-alt-som-gar-pa-strom
rss-snakk-om-sikkerhet
i-loopen
kunstig-intelligens-med-morten-goodwin
rss-bouvet-bobler
teknologi-og-mennesker
pedagogisk-intelligens
rss-digitaliseringspadden
rss-alt-vi-kan
rss-heis