The latest episode of the CyberHub Podcast, hosted by security practitioner & CISO James Azar, delves into a range of pressing cybersecurity issues facing today's digital landscape.
The episode kicks off with a discussion on the evolving nature of ransomware attacks, emphasizing the slow and process-driven nature of cybersecurity responses contrary to the immediate gratification desired by many in the modern era.
Key highlights of the podcast include:
1. Ransomware Attacks on Water Companies: The episode reports on ransomware attacks targeting Viola North America and Southern Water in the UK. Viola, a significant player in the water sector, faced an IT ransomware attack impacting their backend systems but not their water treatment operations. Southern Water, serving millions in England, was listed on the Black Basta ransomware group's leak site, with a threat to release 750 gigabytes of data including personal and corporate information.
2. CISA's Proactive Measures: The Cybersecurity and Infrastructure Security Agency (CISA) was spotlighted for its proactive stance in combating ransomware. The agency notified nearly 60 entities across various sectors about potential pre-ransomware intrusions, significantly ramping up its notification activities.
3. Trello API Data Leak: Trello, a popular project management tool, faced a data leak due to a publicly accessible API, enabling a threat actor to link private email addresses with Trello accounts and create profiles containing public and private information.
4. SolarWinds and Microsoft Breach: The podcast sheds light on the Microsoft breach attributed to the Russian group behind the SolarWinds hack. Despite no vulnerabilities found in Microsoft products, the incident underscored the ongoing threats from sophisticated nation-state actors.
5. Chrome Vulnerabilities and Updates: Google Chrome's recent update addressed 17 vulnerabilities, with significant bug bounties paid out to researchers who identified high-severity issues.
6. Fortress Go Anywhere Vulnerability: A critical vulnerability in the Fortress Go Anywhere managed file transfer product, with a CVSS score of 9.8, was discussed, highlighting the risks of authentication bypass flaws.
7. Ivanti's Challenges and Moody's Downgrade: Ivanti faced a downgrade in its credit rating by Moody's due to multiple zero-day vulnerabilities, reflecting the broader financial and reputational impacts of cybersecurity incidents.
8. UN Cybercrime Treaty Critique: The podcast concludes with a critique of the UN's cybercrime treaty, noting concerns from various stakeholders about its potential to criminalize cybersecurity research and erode data privacy.
The episode underscores the multifaceted challenges in cybersecurity, from infrastructure threats to regulatory issues, and emphasizes the importance of staying informed and proactive in this ever-evolving field.
Show Notes and Story Links:
https://www.securityweek.com/major-us-uk-water-companies-hit-by-ransomware/
https://www.cybersecuritydive.com/news/cisa-pre-ransomware-alerts/705046/
https://therecord.media/russian-hackers-accessed-emails-of-senior-microsoft-leaders
https://www.securityweek.com/chrome-121-patches-17-vulnerabilities/
https://www.securityweek.com/poc-code-published-for-just-disclosed-fortra-goanywhere-vulnerability/
https://www.cybersecuritydive.com/news/ivanti-exploitation-moodys-credit-negative/705035/
https://therecord.media/consensus-growing-around-cybercrime-treaty
Thank you for watching and Please Don't forget to Like this video and Subscribe to my Channel!
Apply now to be a featured partner on the show: https://www.cyberhubpodcast.com/contact
******
Listen here: https://linktr.ee/cyberhubpodcast
SubStack:
******
Website: https://www.cyberhubpodcast.com
Youtube: https://www.youtube.com/c/TheCyberHubPodcast
Rumble: https://rumble.com/c/c-1353861
Facebook: https://www.facebook.com/CyberHubpodcast/
Linkedin: https://www.linkedin.com/company/cyberhubpodcast/
Twitter: https://twitter.com/cyberhubpodcast
Instagram: https://www.instagram.com/cyberhubpodcast
The Hub of the Infosec Community.
Our mission is to provide substantive and quality content that’s more than headlines or sales pitches. We want to be a valuable source to assist those cybersecurity practitioners in their mission to keep their organizations secure.
Share this post