Beta
Logo of the podcast The Cybersecurity Digest

The Cybersecurity Digest (The Cybersecurity Digest LLC)

Explorez tous les épisodes de The Cybersecurity Digest

Plongez dans la liste complète des épisodes de The Cybersecurity Digest. Chaque épisode est catalogué accompagné de descriptions détaillées, ce qui facilite la recherche et l'exploration de sujets spécifiques. Suivez tous les épisodes de votre podcast préféré et ne manquez aucun contenu pertinent.

Rows per page:

1–14 of 14

DateTitreDurée
12 Jul 2024Cybersecurity Digest for week of 12 July 202400:12:27

This week we talk about 

  • Microsoft patches 140+ vulnerabilities including 2 zero days, in Patch Tuesday;
  • Adobe patches critical issues in several of its products,
  • 10 Billion Passwords leaked,
  • 39,000 Ticket master tickets leaked,
  • Chinese APT 40 hiijack routers
  • Hackers are Targeting Wordpress plugins,  
  • A new attack bypasses RADIUS authentication
  • CISA adds 3 new CVEs to its KEV
  • and more in this episode

 

 

Articles Mentioned In Order they appear in the Show:  July 2024 Security Updates - Release Notes - Security Update Guide - Microsoft

Windows MSHTML zero-day used in malware attacks for over a year (bleepingcomputer.com)

Resurrecting Internet Explorer: Threat Actors Using Zero-day Tricks in Internet Shortcut File to Lure Victims (CVE-2024-38112) - Check Point Research

Whispers of Atlantida: Safeguarding Your Digital Treasure | Rapid7 Blog

Adobe Product Security Incident Response Team (PSIRT) RockYou2024: 10 billion passwords leaked in the largest compilation of all time | Cybernews

Hackers leak 39,000 print-at-home Ticketmaster tickets for 154 events (bleepingcomputer.com)

Advance Auto Parts data breach impacts 2.3 million people (bleepingcomputer.com) APT40 Advisory | Cyber.gov.au

$3,094 Bounty Awarded and 150,000 WordPress Sites Protected Against Arbitrary File Upload Vulnerability Patched in Modern Events Calendar WordPress Plugin (wordfence.com)

VU#456537 - RADIUS protocol susceptible to forgery attacks. (cert.org)

BLAST RADIUS Palo Alto Networks Patches Critical Flaw in Expedition Migration Tool (thehackernews.com) GitLab Critical Patch Release: 17.1.2, 17.0.4, 16.11.6 | GitLab

Notable CISA KEV Additions:

NVD - CVE-2024-23692 (nist.gov) NVD - CVE-2024-38080 (nist.gov) NVD - CVE-2024-38112 (nist.gov)

02 Aug 2024Revoked Certs, Microsoft Outage, and Sitting Ducks00:28:33
26 Jul 2024Phishing Scams for CrowdStrike Customers Continue, GitHub Vulnerabilities, and North Korea’s Ransomware Shift00:25:07

Cybersecurity Digest for 26 July 2024

Today we discuss the following items: Notable News Crowdstrike Post Incident Report: Falcon Content Update Remediation and Guidance Hub | CrowdStrike Crowdstrike Phishing Campaigns: Malicious Inauthentic Falcon Crash Reporter Installer Distributed to German Entity (crowdstrike.com) Malware Distributed Using Falcon Sensor Update Phishing Lure | CrowdStrike Threat Actor Distributes Python-Based Info Stealer Using Fake Update (crowdstrike.com) Apparent CrowdStrike Threat Actor List Leak: Hacktivist Entity USDoD Claims to Have Leaked CrowdStrike’s Threat Actor List Meta Ousts 63,000 accounts linked to Sextortion : Combating Financial Sextortion Scams From Nigeria | Meta (fb.com) Darknet Diaries Episode related to the Sextortion Scams: The Pig Butcher – Darknet Diaries Rapid7 Malware Campaign using Fake W2: Malware Campaign Lures Users With Fake W2 Form | Rapid7 Blog GitHub Deleted and Private Repo Access: Anyone can Access Deleted and Private Repository Data on GitHub ◆ Truffle Security Co. GitHub Accounts Distributing Malware: Over 3,000 GitHub accounts used by malware distribution service (bleepingcomputer.com) Windows SmartScreen Flaw: Windows SmartScreen Flaw Enabling Data Theft in Major Stealer Attack (hackread.com)

 

Apt45 Shifts from Espionage to Ransomware: APT45: North Korea’s Digital Military Machine | Google Cloud Blog Related CISA Advisory: North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime’s Military and Nuclear Programs | CISA

Prevalent Patches Google Chrome Fixes Vulnerabilities: Chrome Releases: Stable Channel Update for Desktop (googleblog.com) Docker Fixes Authentication Bypass: Docker Security Advisory: AuthZ Plugin Bypass Regression in Docker Engine | Docker Siemens Fixes Closes Backdoors: SSA-071402 (siemens.com) Progress Telerik Vulnerability: Insecure Deserialization Vulnerability - Telerik Report Server

CISA Alert: BIND 9: ISC Releases Security Advisories for BIND 9 | CISA Related news: BIND DNS Server Vulnerability Lets Attackers Flood Server (cybersecuritynews.com)

06 Jul 2024The Cybersecurity Digest Trailer00:01:10

With the cyber threat landscape ever evolving it can be challenging to stay up to date on the latest cybersecurity developments. There are so many fantastic security news sites and blogs out there. However, due to the sheer number of resources, I found it difficult to read them all and I wished there was a consistent way for me to listen to the latest security news…… that’s where the Cybersecurity Digest comes in. The goal of this show is to bring you a summary of the latest news, trends, and information relevant in the cybersecurity community. The hope is that the information you get from the show will help you stay well-informed and ahead of the adversaries out there. If this sounds like something you are interested in listening to, please give us a follow or subscribe and stay tuned for our upcoming first episode! Until Next time… Stay Informed to Stay Secure!

24 Jul 2024Telegram EvilVideo, PlayRansomWare targets ESXi, and a North Korean Infiltration Attempt00:19:23
22 Jul 2024CrowdStrike Catastrophe, GTA6 Beta Scam, and FractalID Data Breach00:15:51
15 Jul 2024AT&T Data Leak, Millions of Email Servers Vulnerable, and Disney's Slack Leaked?00:12:20

Today’s Episode Topics for 15 July 2024

  • AT&T Data Leaks
  • 70%+ of public facing servers could be Vulnerable
  • Apple warns iPhone customers of spyware in certain countries
  • Netgear patches a Stored XSS Vulnerability
  • A look at CrystalRay
  • RiteAid hit with a data breach
  • Disney’s Internal Slack possibly leaked
  • Is your organization able to keep up with hackers?

Articles Referenced in the Show in the order they appear: AT&T Data Leak:

AT&T 8-K Filing

Exim Vulnerability:

Censys Exim MTA Vulnerability

Apple Warns of Spyware:

Apple warns iPhone users in 98 countries of spyware attacks | TechCrunch

NSO – Darknet Diaries

Netgear Vulnerability:

Netgear Security Advisory

Sysdig Report on CRYSTALRAY:

CRYSTALRAY: Inside the Operations of a Rising Threat Actor Exploiting OSS Tools | Sysdig

RiteAid Data Breach:

Rite Aid confirms data breach after June ransomware attack (bleepingcomputer.com)

Disney Internal Slack possibly leaked: NullBulge's Post

Vx-underground's Post

Cloudfare Applicattion Security Report 2024:

Application Security report: 2024 update (cloudflare.com)

 

If you like our show, please share it with others who you think would enjoy it. Also feel free to check out www.thecybersecuritydigest.com to find all of the locations you can listen to us. Please leave us a rating if you have found this show helpful, as it helps us out tremendously.  Thank you! 

06 Aug 2024Vulnerable IP Cameras, BITSLOTH, and a Discord DDoS Campaign00:30:22
26 Aug 2024Locked out of GSuite, ALBeast, Qilin Stealing Chrome Creds, and Velvet Ants!00:30:03

Show notes for this week's show can be found here: https://thecybersecuritydigest.tech/p/the-cybersecurity-digest-podcast-week-in-review-19-23-august-2024 As stated in the show, comments are turned on for the website. I would love to hear from you regarding your feedback! Please also feel free to leave feedback on Spotify or YouTube and I will review those comments ASAP!  If you are interested in subscribing to our newsletter you can do so here: https://thecybersecuritydigest.tech/subscribe 

 

If you would like to see all the platforms our show is available on you can review our podcast here:  https://www.thecybersecuritydigest.com/ 

30 Jul 2024Outlook C2 Framework, VMWare ESXi Vuln, and PKFail leads to UEFI Supply Chain Attacks.00:24:03

Security Digest for 30 July 2024:

Podcast Requested Feedback: https://forms.gle/w2RB5DRzbbvu3ziS7 Notable News: WhatsApp for Windows lets Python, PHP scripts execute with no warning (bleepingcomputer.com)

PKfail: Untrusted Platform Keys Undermine Secure Boot on UEFI Ecosystem (binarly.io) SupplyChainAttacks/PKfail/ImpactedDevices.md at main · binarly-io/SupplyChainAttacks · GitHub Malicious Python Package Targets macOS Developers (checkmarx.com)

SeleniumGreed Cryptomining Campaign Exploiting Grid Services | Wiz Blog Scammer Abuses Microsoft 365 Tenants, Relaying Through Proofpoint Servers to Deliver Spam Campaigns | Proofpoint US HealthEquity says data breach impacts 4.3 million people (bleepingcomputer.com) Two-Step Phishing Campaign Exploits Microsoft Office Forms (perception-point.io) Over 1 Million websites are at risk of sensitive information leakage (salt.security) TrustedSec | Specula - Turning Outlook Into a C2 With One Registry… Ransomware operators exploit ESXi hypervisor vulnerability for mass encryption | Microsoft Security Blog Support Content Notification - Support Portal - Broadcom support portal Prevalent Patches: Security Bulletin: NVIDIA Jetson AGX Xavier Series, Jetson Xavier NX, Jetson TX1, Jetson TX2 Series (including Jetson TX2 NX), and Jetson Nano (including Jetson Nano 2GB) - July 2024 | NVIDIA (custhelp.com) Apple security releases - Apple Support

CISA Corner: NVD - CVE-2024-4879  (nist.gov) NVD - CVE-2024-5217 (nist.gov) NVD - CVE-2023-45249 (nist.gov) Siemens SICAM Products | CISA Positron Broadcast Signal Processor | CISA

02 Sep 2024Tickler, Voldemort, and Roblox Supply Chain Attack00:32:06

Thank you so much for your support and tuning in. Our full show notes can be found here:  https://thecybersecuritydigest.tech/p/cybersecurity-digest-podcast-week-review-2630-aug-2024  Please do not forget to share this show out with someone you know as well as leave this show a rating in your platform of choice!  Thank you so much for your continued support! 

17 Jul 2024MuddyWater’s Cyber Onslaught, AT&T Pays, Trello Leak, and Sys01 Malvertising Campaign00:15:16

Cybersecurity Digest for 17 July 2024: Today we discuss: MuddyWater’s Latest Cyber Onslaught and a sneaky backdoor!

AT&T Pays Hackers – Was it Worth it?

An Update on RiteAid’s Data Breach

SEXi Ransomware group rebrands…. Meet APT INC!

mSpy Breach

SYS01 Stealer Malware: Malvertising across Social Media

15 Million Trello Email Addresses Leaked

Google’s 23 Billion  to acquire Wiz

Octo Tempest, AKA Scattered Spider adds new ransomware payloads

CISA adds one new vulnerability to its Known Exploited Catalog

 

Articles Referenced in the Show in the order they appear:

CheckPoint Research Bugsleep Backdoor:

New BugSleep Backdoor Deployed in Recent MuddyWater Campaigns - Check Point Research

AT&T Paid Threat Actor:

AT&T Paid a Hacker $370,000 to Delete Stolen Phone Records | WIRED

RiteAid Update: Rite Aid says June data breach impacts 2.2 million people (bleepingcomputer.com) SEXi Rebranding:

SEXi ransomware rebrands to APT INC, continues VMware ESXi attacks (bleepingcomputer.com)

Mspy Data Breach:

Mspy data breach exposes millions of customers' information (candid.technology)

 

Malvertising in Facebook, LinkedIn, and YoutTube: Facebook Malvertising Epidemic – Unraveling a Persistent Threat: SYS01 (trustwave.com)

Malvertising_Research.pdf (trustwave.com)

Trello Leak:

Email addresses of 15 million Trello users leaked on hacking forum (bleepingcomputer.com)

Wiz Acquisition:

Exclusive | Google Near $23 Billion Deal for Cybersecurity Startup Wiz - WSJ

Microsoft Tweet Thread: Microsoft Threat Intelligence on X

 

CISA KEV Addition: NVD - CVE-2024-36401 (nist.gov)

19 Jul 2024Chrome Vulns, Cisco Catastrophes, and Ransomware Revelations: Your Friday Cybersecurity Digest00:16:50

Cybersecurity Digest for 19 July 2024: Today we discuss:

 

  • Yet Another Chrome Vulnerability
  • Dual Critical Cisco Vulnerabilities; Including A Max Severity Vulnerability
  • Life360 Data Breach
  • Ivanti EMM Vulnerability
  • New Novel Email Vulnerabilites\
  • A Report on Fin7
  • SOC Radar’s Global Ransomware Report
  • CISA Adds 3 new vulns to its KEV

Articles Referenced in the Show in the order they appear: Yet Another Chrome Vulnerability Chrome Releases: Stable Channel Update for Desktop (googleblog.com) Dual Critical Cisco Vulnerabilities; Including A Max Severity Vulnerability Cisco Smart Software Manager On-Prem Password Change Vulnerability Cisco Secure Email Gateway Arbitrary File Write Vulnerability Life360 Data Breach Over 400,000 Life360 user phone numbers leaked via unsecured API (bleepingcomputer.com) Ivanti EMM Vulnerability Security Advisory Ivanti Endpoint Manager for Mobile (EPMM) July 2024 New Novel Email Vulnerabilites 20 Million Trusted Domains Vulnerable to Email Hosting Exploits (darkreading.com) A Report on Fin7 FIN7 Reboot | Cybercrime Gang Enhances Ops with New EDR Bypasses and Automated Attacks - SentinelOne SOC Radar’s Global Ransomware report SOCRadar’s Global Ransomware Report 2024: Gain Insights Into Worldwide Ransomware Trends - SOCRadar® Cyber Intelligence Inc. CISA Adds 3 new vulns to its KEV

NVD - CVE-2024-34102 (nist.gov) NVD - CVE-2024-28995 (nist.gov) NVD - CVE-2022-22948 (nist.gov)

18 Aug 2024Newsletter Announcement00:02:03

This an announcement for the upcoming Cybersercurity Digest Newsletter that is launching on Aug 19 2024.  If you are interested in subscribing or viewing the newsletter you can do so here: https://thecybersecuritydigest.tech/ 

Améliorez votre compréhension de The Cybersecurity Digest avec My Podcast Data

Chez My Podcast Data, nous nous efforçons de fournir des analyses approfondies et basées sur des données tangibles. Que vous soyez auditeur passionné, créateur de podcast ou un annonceur, les statistiques et analyses détaillées que nous proposons peuvent vous aider à mieux comprendre les performances et les tendances de The Cybersecurity Digest. De la fréquence des épisodes aux liens partagés en passant par la santé des flux RSS, notre objectif est de vous fournir les connaissances dont vous avez besoin pour vous tenir à jour. Explorez plus d'émissions et découvrez les données qui font avancer l'industrie du podcast.
© My Podcast Data