Take 1 Security Podcast: Episode 5

Take 1 Security Podcast: Episode 5



START CONTENT


* Anthem, the second largest healthcare company, had a major breach


* They lost around 80 million socials, addresses, emails, etc., which is roughly double the Target breach
* There’s speculation that it was China, trying to penetrate government, but it’s early
* Watch for phishing scams related to it
* The megabreaches continue…weee!

* A WordPress plugin called FancyBox had a serious compromise in it last week, which affected thousands of websites


* If you’re going to run WordPress, understand that Plugins are the best way to get yourself hacked
* Specifically, the type of plugins that handle user input and do something with it that affects the site’s output
* Image manipulation plugins have been particularly vulnerable, usually to XSS

* There was another critical Flash vulnerability this week


* Like I said last week, and the week before, there’s a first time for everything

* Three bug hunters at HP received the 125,000 prize for finding a major vulnerability in Internet Explorer


* Because they work for HP they couldn’t take the cash, and instead donated it to charity

* Microsoft released Outlook for iOS last week, which looks pretty slick


* Unfortunately it is riddled with security flaws
* Recommendation: wait for a few updates, and for them to get a security assessment


END CONTENT


Play Podcast

Become a Member: https://danielmiessler.com/upgrade

See omnystudio.com/listener for privacy information.

Episoder(532)

NO. 376 | AI transforms security, existential risk, and how to stay in front…

NO. 376 | AI transforms security, existential risk, and how to stay in front…

NO. 376 | AI transforms security, existential risk, and how to stay in front…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

3 Apr 202320min

NO. 375 — 6 Post-GPT Phases, Github's Private Key, New Assistant Interfaces

NO. 375 — 6 Post-GPT Phases, Github's Private Key, New Assistant Interfaces

6 Post-GPT Phases, Github's Private Key, New Assistant InterfacesBecome a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

27 Mar 202317min

NO. 374 — AI Response Shaping, SpaceX Blueprints, GPT-4 Innovation Explosion…

NO. 374 — AI Response Shaping, SpaceX Blueprints, GPT-4 Innovation Explosion…

NO. 374 — AI Response Shaping, SpaceX Blueprints, GPT-4 Innovation Explosion…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

21 Mar 202312min

NO. 373 — SPQA Architecture, LLaMA on M1 Mac, Loved Ones Voice Scams…

NO. 373 — SPQA Architecture, LLaMA on M1 Mac, Loved Ones Voice Scams…

NO. 373 — SPQA Architecture, LLaMA on M1 Mac, Loved Ones Voice Scams… Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

13 Mar 202317min

Sponsored Interview — Kolide

Sponsored Interview — Kolide

Today I’m doing a Sponsored Interview with Kolide — a company I’ve heard a lot about recently and have been looking forward to chatting with. I’m talking to Jason Meller, the founder and CEO of Kolide and we talk about: The problems in the BOYD space Kolide’s approach to solving the problem A user-centric approach to policy compliance His view of what stops other players from being successful And other topics So with that, here’s Jason Meller… https://kolide.com/unsupervisedlearning  Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

13 Mar 202337min

NO. 372 — LastPass Employee Hack, State AI Propaganda, Crowdstrike Report Analysis…

NO. 372 — LastPass Employee Hack, State AI Propaganda, Crowdstrike Report Analysis…

NO. 372 — LastPass Employee Hack, State AI Propaganda, Crowdstrike Report Analysis…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

7 Mar 202329min

NO. 371 | Covid Lab Leak, Military Server Exposed, OAI Foundry…

NO. 371 | Covid Lab Leak, Military Server Exposed, OAI Foundry…

NO. 371 | Covid Lab Leak, Military Server Exposed, OAI Foundry…Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

27 Feb 202322min

NO. 370 | GoDaddy Hack, EU Chinese APTs, Hacking with ChatGPT

NO. 370 | GoDaddy Hack, EU Chinese APTs, Hacking with ChatGPT

NO. 370 | GoDaddy Hack, EU Chinese APTs, Hacking with ChatGPTBecome a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

21 Feb 202314min

Populært innen Teknologi

romkapsel
rss-avskiltet
teknisk-sett
tomprat-med-gunnar-tjomlid
energi-og-klima
shifter
rss-impressions-2
nasjonal-sikkerhetsmyndighet-nsm
elektropodden
smart-forklart
rss-alt-som-gar-pa-strom
rss-snakk-om-sikkerhet
i-loopen
kunstig-intelligens-med-morten-goodwin
rss-bouvet-bobler
teknologi-og-mennesker
pedagogisk-intelligens
rss-digitaliseringspadden
rss-alt-vi-kan
rss-heis