CISO Talk by James Azar
CyberHub Podcast
Blastradius Attacks, Patch Tuesday with multiple zerodays, Evolve Bank Data Breach, Iran Threats
0:00
Current time: 0:00 / Total time: -15:44
-15:44

Blastradius Attacks, Patch Tuesday with multiple zerodays, Evolve Bank Data Breach, Iran Threats

Today’s top cybersecurity news and the latest threats from Practicing CISO James Azar, tune in to hear how practitioner’s breakdown the latest to bolster their cybersecurity programs

CyberHub Podcast Recap: Patch Tuesday and Major Security Incidents

Good morning, Security Gang!

Today’s episode of the CyberHub Podcast is packed with critical updates and actionable insights. Here’s a breakdown of the latest cybersecurity news and what you need to do to stay protected.

RADIUS Protocol Vulnerability

Researchers have discovered a 30-year-old design flaw in the RADIUS protocol, which is widely used in network access control. The flaw, known as "Blast Radius," can allow attackers to bypass multi-factor authentication (MFA) and gain unauthorized access to networks.

Action Items:

  • Upgrade all RADIUS servers immediately to mitigate this vulnerability.

  • Conduct a thorough review of your network access controls to identify potential risks.

Evolve Bank and Trust Data Breach

Evolve Bank and Trust notified 7.6 million Americans of a data breach following a LockBit ransomware attack. The breach exposed personal and financial information.

Action Items:

  • Enroll in the offered credit monitoring and identity protection services by October 31.

  • Monitor financial accounts for any suspicious activity and report anomalies immediately.

Arabian Travel Agency Data Breach

A significant data breach at the Arabian Travel Agency compromised sensitive information of over 1.2 million individuals, including Air India customers and UAE visa applicants.

Fujitsu Data Breach

Fujitsu confirmed a data breach impacting sensitive information after malware spread to 49 computers within their network.

Share

Patch Tuesday Updates

Microsoft released patches for 143 security flaws, including two critical vulnerabilities under active exploitation.

Action Items:

  • Prioritize patching systems affected by CVE-2024-38080 and CVE-2024-38112.

  • Regularly update all software to the latest versions to mitigate vulnerabilities.

Adobe Security Updates

Adobe released critical patches for Premiere Pro, InDesign, and Bridge, addressing several high-severity vulnerabilities.

Action Items:

  • Apply Adobe’s latest patches to affected software immediately.

  • Regularly check for updates and apply them as soon as they become available.

ICS Vulnerabilities

Siemens and Schneider Electric released patches for multiple vulnerabilities in their industrial control systems, including critical flaws that could allow privilege escalation and code execution.

Action Items:

  • Apply the latest security updates from Siemens and Schneider Electric.

  • Conduct a security audit of all industrial control systems to ensure they are protected.

  • OpenSSH Vulnerability

A new OpenSSH vulnerability (CVE-2024-6409) has been identified, affecting Red Hat Enterprise Linux 9.

Action Items:

  • Update to the latest versions of OpenSSH to mitigate the risk.

  • Regularly review security advisories for any additional patches.

Iranian Cyber Espionage

Iranian-linked cyber actors are using custom Android spyware, "Guard Zoo," to conduct espionage across the Middle East.

Upcoming Events

AI in Cybersecurity: Join us for a conversation with Steve Orrin, CTO at Intel Federal, discussing the practical implementation and impact of AI in cybersecurity. Tune in on YouTube and LinkedIn at 11 a.m. Eastern.

Stay cyber safe, everyone!

Leave a comment

✅ Story Links: 

https://www.securityweek.com/blastradius-attack-exposes-critical-flaw-in-30-year-old-radius-protocol/

https://www.bleepingcomputer.com/news/security/evolve-bank-says-data-breach-impacts-76-million-americans/

https://thecyberexpress.com/arabian-travel-agency-data-breach-exposed-info/

https://www.bleepingcomputer.com/news/security/fujitsu-confirms-customer-data-exposed-in-march-cyberattack/

https://thehackernews.com/2024/07/microsofts-july-update-patches-143.html

https://www.securityweek.com/adobe-issues-critical-patches-for-multiple-products-warns-of-code-execution-risks/

https://www.securityweek.com/ics-patch-tuesday-siemens-schneider-electric-cisa-issue-advisories/

https://thehackernews.com/2024/07/new-openssh-vulnerability-discovered.html

https://www.darkreading.com/threat-intelligence/houthi-aligned-apt-targets-middle-east-militaries-spyware

🔔 Subscribe now for the latest insights from industry leaders, in-depth analyses, and real-world strategies to secure your digital world. https://www.youtube.com/@TheCyberHubPodcast/?sub_confirmation=1  

✅ Important Links to Follow: 

👉Website: https://www.cyberhubpodcast.com

👉Substack:

👉Listen here: https://linktr.ee/cyberhubpodcast   

Stay Connected With Us.

👉Rumble: https://rumble.com/c/c-1353861 

👉Facebook: https://www.facebook.com/CyberHubpodcast/ 

👉LinkedIn: https://www.linkedin.com/company/cyberhubpodcast/ 

👉Twitter (X): https://twitter.com/cyberhubpodcast 

👉Instagram: https://www.instagram.com/cyberhubpodcast 

✅ For Business Inquiries:  info@cyberhubpodcast.com

=============================

About The CyberHub Podcast.

The Hub of the Infosec Community. 

Our mission is to provide substantive and quality content that’s more than headlines or sales pitches. We want to be a valuable source to assist those cybersecurity practitioners in their mission to keep their organizations secure. 

Discussion about this podcast

CISO Talk by James Azar
CyberHub Podcast
Today’s top cybersecurity news and the latest from Practicing CISO James Azar, tune in to hear how practitioners read, view and work after hearing the latest headlines and how these stories help keep practitioners sharp and ready.