PSW #741 – Robert Lee & Saumil Shah
Full Audio
View Show IndexSegments
1. Year in Cyber Review 2021 – Robert Lee – PSW #741
The past year has been filled with incredible changes in the cyber security landscape from ICS, Mobile, Cloud, and increased threats from Ransomware. This discussion will focus on crucial and quick discussions surrounding the cyber landscape that has changed quickly and forced organizations to consider revamping many of their policies and preparations. Join us for a humorous, and insightful journey back over the past year filled with examples for practitioners, organizations, and those just starting in cyber security.
Announcements
Security Weekly listeners, save $100 on your RSA Conference 2022 Full Conference Pass! RSA Conference will be live in San Francisco June 6th-9th, 2022. Security Weekly will be there in full force, delivering real-time, live coverage and interviewing some of the event’s top speakers and sponsors. To register using our discount code, please visit https://securityweekly.com/rsac2022 and use the code 52UCYBER. We hope to see you there!
Guest
Robert M. Lee is the CEO and co-founder of the ICS cybersecurity technology and services firm Dragos. He gained his start in the U.S. Air Force as a Cyber Warfare Operations Officer where he spent most of his career at the National Security Agency where he built and led a first-of-its-kind mission hunting and analyzing state actors targeting ICS. He is also a Senior Instructor at the SANS Institute where he authored the Forensics 578 course on Cyber Threat Intelligence and the ICS 515 course on ICS network monitoring and incident response. He may be found on Twitter @RobertMLee
Hosts
2. Firmware Security – Saumil Shah – PSW #741
In this segment Saumil Shah joins us for a discussion on Firmware Security, complete with a fascinating first-hand demonstration!
Announcements
We're always looking for great guests for all of the Security Weekly shows! Submit your suggestions by visiting https://securityweekly.com/guests and completing the form!
Guest
Saumil is an internationally recognized speaker And instructor, having regularly presented At conferences Like Blackhat, Rsa, Cansecwest, Pacsec, Eusecwest, Hack.lu, Hack-in-the-box And Others. He has Authored Two Books Titled “Web Hacking: Attacks And Defense” And “the Anti-virus Book”.
Saumil Graduated With An M.s. In Computer Science from Purdue University, Usa And A B.e. In Computer Engineering from Gujarat University. He spends his leisure time breaking software, flying kites, traveling around the world and taking pictures.
Hosts
3. Windows GPU Display Vulns, NFT Discord Hack, Costa Rica Vs. Hackers, & Initial Access – PSW #741
In the Security News for this week: Singapore launches safety rating system for e-commerce sites, Watch Out for Zyxel Firewalls RCE Vulnerability, New Bluetooth hack that can unlock your Tesla, Hackers Compromise a String of NFT Discord Channels, a pentester’s attempt to be ‘as realistic as possible’ backfires, & more!
Announcements
Don't forget to check out our library of on-demand webcasts & technical trainings at securityweekly.com/ondemand.
Don't miss any of your favorite Security Weekly content! Visit https://securityweekly.com/subscribe to subscribe to any of our podcast feeds and have all new episodes downloaded right to your phone! You can also join our mailing list, Discord server, and follow us on social media & our streaming platforms!
Hosts
- 1. Watch Out! Hackers Begin Exploiting Recent Zyxel Firewalls RCE VulnerabilityRapid 7 research: https://www.rapid7.com/blog/post/2022/05/12/cve-2022-30525-fixed-zyxel-firewall-unauthenticated-remote-command-injection/ (Also see: https://www.zdnet.com/article/nasty-zyxel-remote-execution-bug-is-being-exploited/)
- 2. NVIDIA fixes ten vulnerabilities in Windows GPU display drivers
- 3. Angry IT admin wipes employer’s databases, gets 7 years in prison
- 4. New Bluetooth hack can unlock your Tesla—and all kinds of other devices
- 5. President Rodrigo Chaves says Costa Rica is at war with Conti hackers
- 6. Hackers Compromise a String of NFT Discord Channels
- 7. Apple emergency update fixes zero-day used to hack Macs, Watches
- 8. US names Venezuelan doctor as notorious ransomware maker – TechCrunch
- 9. NSA, Allies Issue Cybersecurity Advisory on Weaknesses that Allow Initial Access
- 10. How a pentester’s attempt to be ‘as realistic as possible’ alarmed cybersecurity firms
- 1. Singapore launches safety rating scheme for e-commerce sitesAssessing e-commerce marketplaces based on their anti-scam measures, the scheme gives Facebook Marketplace the lowest rating while Lazada and Amazon are amongst those that received the highest.
- 2. Hackers are exploiting critical bug in Zyxel firewalls and VPNsHackers are now actively exploiting a recently patched, critical vulnerability (CVE-2022-30525) affecting Zyxel firewall and VPN devices used by businesses that could be exploited by remote, unauthenticated attackers to inject arbitrary commands that enable the creation of a reverse shell
- 3. Malware is targeting crypto wallets, says Microsoft: Here’s how to protect yourself betterEveryone's heard of ransomware, and many people have heard of 'cryptojackers', banking trojans, and 'info stealers'. Now, Microsoft is introducing 'cryware' into the cybersecurity lexicon, predicting more people will start using so-called 'hot wallets' as they boost cryptocurrency holdings – and that crooks will try to grab them.
- 4. 5 critical questions to test your ransomware preparedness – Help Net SecurityFive questions to ask yourself regarding your ransomware preparedness.
- 5. Wizard Spider hackers hire cold callers to scare ransomware victims into paying upThey will cold call victims and attempt to coerce/scare them into paying the ransom demand.
- 6. BLE vulnerability may be exploited to unlock cars, smart locks, building doors, smartphones – Help Net SecurityA Bluetooth Low Energy (BLE) vulnerability discovered by NCC Group researchers may be used by attackers to unlock cars with automotive keyless entry, residential smart locks, building access systems, mobile phones, laptops, and many other devices.
- 7. US warns over the risk of hiring North Korea IT workersNorth Korean information technology (IT) workers are hiding their true identities in order to land jobs and ultimately steal funds to finance the North Korean Government's weapons program.
- 8. Russians allegedly storm Ukrainian ISP, blackmail it to switch to Russian networksUkraine's State Service of Special Communications and Information Protection (SSSCIP) revealed that Russian forces successfully invaded an internet company operating out of Kherson, disconnected all equipment, and threatened to confiscate the equipment if the company refused to connect to Russian networks.
- 9. EMERGENCY DIRECTIVE 22-03 MITIGATE VMWARE VULNERABILITIESThreat actors, including likely advanced persistent threat (APT) actors, are exploiting vulnerabilities (CVE 2022-22954 and CVE 2022-22960) in the following VMware products: VMware Workspace ONE Access (Access), VMware Identity Manager (vIDM), VMware vRealize Automation (vRA), VMware Cloud Foundation, and vRealize Suite Lifecycle Manager.