Take 1 Security Podcast: Episode 19

Take 1 Security Podcast: Episode 19



Topics for this episode:

News and analysis


* [ ] A couple of months into my job with IOActive
* [ ] Paris Attacks: resilience vs. prevention
* [ ] Updating the OWASP IoT Project (no longer the Top 10) It’s an umbrella project.
* [ ] Adding to the IoT project the SCADA Top 10 List (read the list), and Nabil Ouchn is going to be project leader on that project
* [ ] Pentagon farms coding to Russia
* [ ] Crypto email service pays ransom, gets taken out anyway
* [ ] Blackout Europe shows vulnerabilities in LTE. Forced leak of location within 2-KM radius. Were also able to block LTE and force 3G or 2G.
* [ ] Onapsis talks SAP HANA vulnerabilities. They’re config issues, and aren’t patchable, and include: remote file writes, remote directory deletions, moving files to where they can be access remotely, remote command execution, and remote python execution. To fix, you have to upgrade to the latest version and reconfigure your system. Also two issues with the database that allow HTTP RCE and SQL RCE.
* [ ] TPP : how did we even get an agreement that was secret in the first place. Forget the details. This should never be allowed to happen again
* [ ] Linux ransomware now hitting websites (broken by Brian Krebs)
* [ ] Linux.Encoder.1 has a predictable key for its ransomware, and a tool was released to decrypt victims’ systems. Good to know that even attackers make dumb encryption implementation mistakes.
* [ ] Visio smart tracking turned on for 10 million users. Here was the pitch “revolutionary shift across all screens that brings measurability, relevancy and personalization to the consumer like never before!”
* [ ] Ring-0 theory of devops: history of the o-ring. Small thing that everything else depends on. for serial tasks you need A players to have an A process. As you lower the whole thing tumbles down
* [ ] The Chinese Great Cannon: so we know about the Great Firewall, now learn about the Great Cannon
* [ ] Must read article: What ISIS Really Wants, by the Atlantic
* [ ] Two must follows: Gunnar Peterson, and Benedict Evans. Gunnar is brilliant in security, and Benedict works for Adresesen Horowitz


Updates and announcements


* Hit me up at IOActive if you have any security consulting needs.


Notes


* The intro track is from one of my favorite EDM artists: Zomby. The song is ‘Orion’, and it’s from the ‘With Love’ album. Highly recommended if you like chill EDM.
* It’s better to listen via iTunes or with the player embedded above, but you can also download the sound file directly.

Become a Member: https://danielmiessler.com/upgrade

See omnystudio.com/listener for privacy information.

Avsnitt(532)

NO. 387 — Modern Parenting and Narcissism?, New Russian Hacking Unit, McKinsey AI Predictions, and more…

NO. 387 — Modern Parenting and Narcissism?, New Russian Hacking Unit, McKinsey AI Predictions, and more…

In this episode: 🧠 Is modern parenting creating narcissists?🔒 Top cybersecurity official warns of Chinese hackers🇷🇺 New Russian hacking unit identified🚀 NVIDIA's AI red team philosophy📈 McKinsey says AI will massively boost productivity💊 MDMA helps white supremacist move away from hate🔎 Google further soils the bedBecome a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

20 Juni 202324min

NO. 386 — DBIR 2023, Vision, Smol-Developer, and more…

NO. 386 — DBIR 2023, Vision, Smol-Developer, and more…

In this episode: 🔥 Human Immortality Using LLMs🤖 Generative AI Reshaping Enterprises🔒 Verizon DBIR 2023 Analysis🪳 Chrome Zero-Day Patched💰 Lazarus Atomic Wallet Link🚀 Tame Your Compliance Beast🪳 MOVEit Vulnerability Exploitation📰 North Korean Hackers Impersonate Journalists📱 Apple ID-sharing🌐 Apple Vision Announced🔑 Password Crackdown Success📈 AI-Driven Stock Surge📱 iOS17 Features Summary🔐 Apple Passkey SharingBecome a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

12 Juni 202326min

NO. 384 — World AI Coin, Russian Power Attacks, Guidance AI Workflow…

NO. 384 — World AI Coin, Russian Power Attacks, Guidance AI Workflow…

In this episode:👁️ Worldcoin, OpenAI, and eye scanning: A global ID and currency?⚡ Grid Threat: Russia-linked malware targets power grids🧠 Neuralink gets FDA approval for clinical trials🤖 Bing integrated into ChatGPT for enhanced AI chatbot experience🚗 Tesla Model Y becomes world's best-selling car🌈 LGBTQ searches soar 1,300% since 2004Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

3 Juni 202321min

NO. 382 — AI Attack Surface Map, Digital Assistants, Dragos Nope, Rogue AI Girlfriend…

NO. 382 — AI Attack Surface Map, Digital Assistants, Dragos Nope, Rogue AI Girlfriend…

In this episode:🛡️ Support DEFCON's AI Village event🧠 Dive into AI attack surfaces🤖 Uncover digital assistants' future🔒 Investigate Dragos Incident & Snake takedown🎵 Experience Google's MusicLM magic🚀 Secure the cloud with a free guide👩‍💻 Witness an AI girlfriend gone rogueBecome a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

16 Maj 202317min

The Right Amount of Trauma

The Right Amount of Trauma

In this standalone episode I read my essay titled "The Right Amount of Trauma". https://danielmiessler.com/blog/the-right-amount-of-trauma/   Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

11 Maj 20237min

NO: 381 — Reviving Conference Strategies, Nurturing High-Performers, AI Business Takeover, Cyber Threats, and Diversifying Production 🧠🏢🦈📱🚗

NO: 381 — Reviving Conference Strategies, Nurturing High-Performers, AI Business Takeover, Cyber Threats, and Diversifying Production 🧠🏢🦈📱🚗

🧠 The Right Amount of Trauma: Nurturing high-performers🏢 Universal Business Components: AI's business takeover🦈 North Korean ReconShark: New global cyber threat📱 Apple's Brazil production: Diversifying from China🚗 NYPD's AirTag advice: Protect your car💵 US dollar losing reserve currency status🤖 IBM's hiring pause: AI and automation's impact🌐 World Economic Forum: Job disruption predictions 📺 YouTube views: Half on TV📞 GenZ's dumbphone trend: Reducing distractions🌿 A Post AI Future for Humans: Local community model💡 The Self-checkout Tipping Anti-Pattern: Dark pattern or generosity?Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

9 Maj 202311min

NO. 380 — LLM-Mind-Reading, Automated War, Rusty Sudo, Eliezer Bitterness Theory...

NO. 380 — LLM-Mind-Reading, Automated War, Rusty Sudo, Eliezer Bitterness Theory...

📚 Pre and Post-LLM Software: Adapt or be replaced🎙️ RSnake Show Appearance: AI-focused conversation🔐 RSA Live Podcast: Industry insights and advice🔮 Palantir AI: Automated war and terror🍏 New Apple Update Mechanism: Rapid Security Response🧠 LLM Mind-reading: Extracting text from brain activity🚫 Chatbanning: Samsung's response to data leak🔧 VMware & Zyxel Patches: Addressing vulnerabilities🔒 Google Security AI: Cloud Security AI Workbench🦀 Sudo Rust: Safer sudo and su in Rust🎥 Palo Alto Cameras: License plate tracking🏃‍♂️ Apple Coach: AI-powered health app🏦 First Republic Falls: FDIC intervention💡 Eliezer Bitterness Theory: AI doomsday predictions🤖🔥 Prompting Superpower: Advanced AI prompting techniques🛠️ ShadowClone & FigmaChain: Useful tools🐍 Recommendation: Learn Python and Langchain💬 Aphorism: Carl Jung on creativityBecome a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

2 Maj 202318min

NO. 378 — AI Resilience Scale, Moloch The Demon, Ukraine Data Leak, and more...

NO. 378 — AI Resilience Scale, Moloch The Demon, Ukraine Data Leak, and more...

NO. 378—AI Resilience Scale, Moloch The Demon, Ukraine Data Leak, and more...Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

17 Apr 202325min

Populärt inom Teknik

uppgang-och-fall
rss-racevecka
elbilsveckan
bilar-med-sladd
market-makers
skogsforum-podcast
rss-laddstationen-med-elbilen-i-sverige
natets-morka-sida
rss-technokratin
rss-elektrikerpodden
mediepodden
developers-mer-an-bara-kod
hej-bruksbil
ai-sweden-podcast
solcellskollens-podcast
rss-uppgang-och-fall
rss-veckans-ai
bli-saker-podden
bosse-bildoktorn-och-hasse-p
rss-it-sakerhetspodden