Episode 182: "Good" hack for SolarWinds, "Bad" security for Twitter, and "Sock Puppet" phishing

Episode 182: "Good" hack for SolarWinds, "Bad" security for Twitter, and "Sock Puppet" phishing

Topic 1: Could it actually be possible that the SolarWinds hack was “good” for their business?

https://www.scmagazine.com/feature/incident-response/why-solarwinds-just-may-be-one-of-the-most-secure-software-companies-in-the-tech-universe

No one would argue that being the victim of “the largest and most damaging security breach in US history” is a good thing. But as a result of the hack, SolarWinds took unprecedented steps to fundamentally reengineer their approach to security and dev-ops … and they are telling a surprisingly compelling story about how this makes them the most secure system in the industry. What’s more, it seems like customers are listening … and buying. Do you buy it?

Topic 2: Headline: Twitter is bad at data security and privacy.

Conclusion: No duh.

https://www.protocol.com/policy/mudge-twitter-whistleblower-hearing

The Twitter whistleblower testified in congress yesterday … and he made the “shocking” accusation that Twitter doesn’t have (and never has had) sufficient control systems for data protection. Thank you, Captain Obvious. This brings up a few questions: 1) does any social media company have sufficient data controls (no); 2) is there any appetite to make social media companies accountable for actual privacy / security (no); and 3) why does our society accept the presence of a tech platform that is “too big to control” and not simply turn it off if it can’t be made secure?

Topic 3: Because Security needs another piece of jargon: Beware Sock Puppet phishing

https://www.bleepingcomputer.com/news/security/hackers-now-use-sock-puppets-for-more-realistic-phishing-attacks/

Or would you rather call the attack 'multi-persona impersonation' (MPI)? That’s the name used by researchers at Proofpoint.

Basically, this is an orchestrated attack where the bad guys control multiple email accounts and email back and forth with the target in the middle of the cc: string. The idea is to provide (fake) social proof.

Sponsor Memo: SBTTC

This podcast is sponsored by the Small Biz Thoughts Technology Community. Check us out at https://www.SmallBizThoughts.org

Forms, templates, and checklists are just the start. Our Community includes ALL of the best-selling books on managed services in all available formats, plus free training, members-only programs, and the best business training available to managed service providers anywhere.

Plus, we have weekly live members-only Zoom calls. The average member saves more than 200% of their membership cost each year. We are totally dedicated to YOUR success.

Just because you're in business for yourself doesn't mean you have to go it alone. Join us today at https://www.SmallBizThoughts.org

:-)


Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(103)

Episode 215 - How Power, Policy, and Private Equity Are Shaping the Future of IT Services

Episode 215 - How Power, Policy, and Private Equity Are Shaping the Future of IT Services

Welcome to episode 215 of the Killing IT Podcast! In this lively installment, hosts Karl Palachuk, Dave Sobel, and Ryan Morris kick off the new year by comparing winter experiences across the country—...

17 Feb 31min

Episode 214 - Bitcoin's Relevance, Cybersecurity's Future in Private Sector, and Innovation Outpacing Adoption

Episode 214 - Bitcoin's Relevance, Cybersecurity's Future in Private Sector, and Innovation Outpacing Adoption

Topic 1: Is there a valid reason for Bitcoin to exist? You can now use Venmo (a subsidiary of PayPal) to pay for your tacos at Taco Bell. This is just the latest addition (see Apple Pay and Google Pay...

13 Nov 202530min

Episode 213 - AI Conspiracy Theories, GTIA's ChannelCon Insights, and US-China Chip Trade Dynamics

Episode 213 - AI Conspiracy Theories, GTIA's ChannelCon Insights, and US-China Chip Trade Dynamics

The episode delves into the evolving landscape of artificial intelligence (AI) and its implications for businesses, particularly in the IT sector. The hosts discuss the current state of AI, emphasizin...

18 Aug 202530min

Episode 212 - CISA updates, taxing IT professionals, and standing by generative AI

Episode 212 - CISA updates, taxing IT professionals, and standing by generative AI

Welcome to Episode 212 At 212 degrees fahrenheit, water becomes steam. At 211 it’s hot. At 212 you can move a locomotive or make electricity. We are happy to bring you episode 212 of the Killing IT Po...

23 Maj 202532min

Episode 211 - CISA, DeepSeek, and Competing with Microsoft

Episode 211 - CISA, DeepSeek, and Competing with Microsoft

Topic 1: CISA Under the Microscope CISA was called out in the Project 2025 document as a left-wing organization inside the government due to their warning about election interference. It is now subjec...

20 Feb 202531min

KIT Episode Episode 210 - Robots, Industry Finance, and a Practical Approach to AI

KIT Episode Episode 210 - Robots, Industry Finance, and a Practical Approach to AI

The Q4 2024 Killing IT Podcast features what may be our last discussion of robots for a long time! Topic One - Where Are My Robots??? We’ve been talking about this for five years - So where are the ro...

25 Nov 202432min

KIT Episode 209 - AI Risk Repository, Google Monopoly, and Quantum Cryptography. Or Not.

KIT Episode 209 - AI Risk Repository, Google Monopoly, and Quantum Cryptography. Or Not.

We're back for Q3 2024. Quick question of the day ... then onto the topics of the day. Topic 1: MIT Releases the AI Risk Repository Thanks to the Massachusetts Institute of Technology for a major reso...

20 Aug 202431min

Episode 208 - Botnet Battles, the State of AI, and M&A Activity in SMB

Episode 208 - Botnet Battles, the State of AI, and M&A Activity in SMB

Topic 1: Massive Botnet Network Taken Down Police coordinated by the European Union's justice and police agencies have taken down computer networks responsible for spreading ransomware via infected em...

18 Juni 202429min

Populärt inom Politik & nyheter

p3-krim
aftonbladet-daily
svenska-fall
rss-krimstad
aftonbladet-krim
flashback-forever
rss-krimreportrarna
tv4-nyheterna-story
rss-sanning-konsekvens
politiken
motiv
rss-vad-fan-hande
mannen-utan-spar
svd-ledarredaktionen
de-fyras-gang
rss-flodet
spar
rss-aftonbladet-krim
rss-frandfors-horna
olyckan-inifran