CISO Talk by James Azar
CyberHub Podcast
🚨 Cyber News: Microsoft Scathed by Federal Report, SEXi Ransomware Targets ESXi, The China Threat, AT&T Suit
1×
0:00
Current time: 0:00 / Total time: -16:48
-16:48

🚨 Cyber News: Microsoft Scathed by Federal Report, SEXi Ransomware Targets ESXi, The China Threat, AT&T Suit

Today’s top cybersecurity news and the latest threats from Practicing CISO James Azar, tune in to hear how practitioners breakdown the latest to bolster their cybersecurity programs

Microsoft's Cybersecurity Woes - The Hypocrisy

The CyberHub Podcast episode kicked off with a detailed discussion on the recent federal reports criticizing Microsoft for its cybersecurity practices. These reports, issued by a Biden administration-appointed review board, pinpointed a series of errors that allowed Chinese cyber operators to breach the email accounts of high-ranking U.S. officials.

The board highlighted Microsoft's "shoddy cybersecurity practices" and a "lax corporate culture," stressing the need for substantial improvements in security measures and a cultural shift within the company.

Give this a listen as host James Azar discusses how the idea that private companies are expected to handle nation state attacks.

Action Points:

1. Microsoft is urged to prioritize security enhancements over new features, especially in its cloud computing services.

2. Companies using Microsoft products should closely monitor the situation and review their own cybersecurity practices in light of these findings.

The Expanding Influence of Chinese Technology

The podcast also delved into the growing presence of Chinese technology in the U.S., despite widespread security concerns. Despite efforts to curb the use of Chinese-made products in critical infrastructure, their penetration into U.S. networks has reportedly increased by over 40% in the past year. This trend raises questions about the effectiveness of current strategies to mitigate the risks associated with Chinese technology.

Action Points:

1. Businesses and government agencies should reassess their supply chains and consider the security implications of using Chinese-made devices.

2. A collaborative approach between the U.S. government and private sector is essential to develop more effective measures against the infiltration of potentially compromised technology.

Ransomware Attacks on the Rise - SEXi Ransomware

The episode highlighted recent ransomware attacks, including a significant one on Jackson County, Missouri, which disrupted county services, and another on a Chilean data center by a new ransomware gang known as SEXi. These incidents underscore the ongoing threat of ransomware to both public and private sectors.

Action Points:

1. Organizations are advised to enhance their cybersecurity defenses and conduct regular backups to mitigate the impact of potential ransomware attacks.

2. Awareness and education on cybersecurity best practices should be intensified to prevent such breaches.

Global and National Cybersecurity Efforts

Lastly, the podcast touched on various cybersecurity initiatives, like Singapore's cyber essential certification program, which aims to improve cybersecurity preparedness among businesses.

However, the episode also criticized the U.S. government's approach to cybersecurity, particularly in its handling of the Microsoft situation, suggesting a need for a more supportive and collaborative stance towards private companies facing cyber threats.

Action Points:

1. Businesses should consider adopting similar cybersecurity certification programs to enhance their security posture.

2. There's a call for a more unified approach between the government and the private sector to tackle cybersecurity challenges effectively.

In summary, this episode of the CyberHub Podcast provided a comprehensive overview of the current cybersecurity landscape, highlighting key issues such as the criticism of Microsoft's security practices, the challenge of Chinese technology, the persistent threat of ransomware, and the importance of collaborative efforts in cybersecurity.

Story Links:

https://www.securityweek.com/scathing-federal-report-rips-microsoft-for-shoddy-security-insincerity-in-response-to-chinese-hack/

https://www.bleepingcomputer.com/news/security/microsoft-still-unsure-how-hackers-stole-msa-key-in-2023-exchange-attack/

https://www.bleepingcomputer.com/news/security/jackson-county-in-state-of-emergency-after-ransomware-attack/

https://www.bleepingcomputer.com/news/security/hosting-firms-vmware-esxi-servers-hit-by-new-sexi-ransomware/

https://www.bleepingcomputer.com/news/security/ivanti-fixes-vpn-gateway-vulnerability-allowing-rce-dos-attacks/

https://www.darkreading.com/cyberattacks-data-breaches/oil-gas-sector-falling-for-fake-vehicle-incident-email-lure

https://www.securityweek.com/number-of-chinese-devices-in-us-networks-growing-despite-bans/

https://www.darkreading.com/cybersecurity-analytics/singapore-sets-high-bar-in-cybersecurity-preparedness

https://www.bleepingcomputer.com/news/security/atandt-faces-lawsuits-over-data-breach-affecting-73-million-customers/

Apply now to be a featured partner on the show: https://www.cyberhubpodcast.com/contact

******

Listen here: https://linktr.ee/cyberhubpodcast

SubStack:

******

Website: https://www.cyberhubpodcast.com

Youtube: https://www.youtube.com/c/TheCyberHubPodcast

Rumble: https://rumble.com/c/c-1353861

Facebook: https://www.facebook.com/CyberHubpodcast/

Linkedin: https://www.linkedin.com/company/cyberhubpodcast/

Twitter: https://twitter.com/cyberhubpodcast

Instagram: https://www.instagram.com/cyberhubpodcast

The Hub of the Infosec Community.

Our mission is to provide substantive and quality content that’s more than headlines or sales pitches. We want to be a valuable source to assist those cybersecurity practitioners in their mission to keep their organizations secure.

Discussion about this podcast

CISO Talk by James Azar
CyberHub Podcast
Today’s top cybersecurity news and the latest from Practicing CISO James Azar, tune in to hear how practitioners read, view and work after hearing the latest headlines and how these stories help keep practitioners sharp and ready.