
Welcome to Week 4 of NCSAM. This week, we're going to cover protecting your children online. Notations are taken from a presentation I heard about the topic, and I've summarized it to tell possibly some stories that may be similar to something you've heard or seen. We'll also have news, notes and other comments as the program gets started.
Protecting Our Children online
Protecting your kids online. Including topics like grooming, cyberbullying and more.
News Notes
The following are some of the items that have been read within the past week. Feel free to read the ones that are of interest to you.
FBI, others crush REvil using ransomware gang’s favorite tactic against it Ars Technica
PurpleFox Adds New Backdoor That Uses WebSockets Trend Micro
Sinclair Broadcast Group suffers ransomware attack, the latest affecting media Cyberscoop
Candy corn producer says ransomware incident 'not likely' to sour Halloween supplies Cyberscoop
Conti Ransom Gang Starts Selling Access to Victims Krebs On Security
I'll try and blog some of this older news we've got, so stay tuned. Hope you enjoy the show!
Oct 28, 2021
2 hr 47 min

Welcome to the Security Box, podcast 66. Is 66 a lucky number? T-Mobile and Verizon are in the news with Spam messages, AT&T is in the mix as well in passing, Google is getting in the mix with two-factor authentication on more accounts, as well as news, notes and more.
Topics
Verizon subscribers are the target of a phishing expedition; do not respond to this text message Phone Arena
T-Mobile customers are receiving spam texts possibly related to August's data breach Phone Arena
NCSAM
Google will enable two-step verification by default on 150 million accounts before year's end Phone Arena
News Notes read from around the landscape
The following are links to stories that have been read from across the landscape. In October, we do news notes live so that you, the listener, can get a benefit of this being a discussion. If you like the way this is being done, please let us know and I may do it full time.
How Coinbase Phishers Steal One-Time Passwords Krebs On Security
Some versions of Android share users' personal data with no chance to opt-out Phone Arena
US gov’t will slap contractors with civil lawsuits for hiding breaches Ars Technica
Millionaire Twitch streamers react to their leaked earnings Ars Technica
Hope you all enjoy the program, and thanks for listening!
Oct 23, 2021
2 hr 40 min

A few technical issues, but what is a show without those? In this 3 hour episode, we've got quite a lot for you, so sit back and check out the links to the following items for your perusal.
Welcome to the Security Box, podcast 65. On this podcast, let's discuss an article we read after the release of last week's program in regards to Twitch and their recent breach we were alerted to during the live taping of the program. After that, we're going to cover more NCSAM and even have some news notes. We'll do news notes the same as we did last week, as it turned in to a lively discussion. I hope you'll enjoy the program, and thanks so much for listening!
Breach topics
Stolen Twitch source code, creator payment data revealed in apparent data leak Cyberscoop
Trolls defaced Twitch's website with pictures of Jeff Bezos, the latest security concern Cyberscoop
NCSAM: Scam apps
Hundreds of scam apps hit over 10 million Android devices Ars Technica
News Notes read from around the landscape
Electronic Frontier Foundation will deprecate HTTPS Everywhere plugin Ars Technica
Company that routes SMS for all major US carriers was hacked for five years Ars Technica
Former TD Bank, Bank of America employee allegedly helped email scammers launder money Cyberscoop
Suspected Chinese hackers masqueraded as Indian government to send COVID-19 phishing emails Cyberscoop
Oct 13, 2021
3 hr 7 min

NCSAM is now in full swing, this week, Are You Cyber Smart? A Checklist from Lastpass will be what you need to look at with 5 great tips and things that might be of interest to you. In my writeup of this, I talked about the Neiman Marcus breach and how people should be aware of it even if they aren't affected. We'll have news, notes and more. Hope you'll enjoy the show!
News Notes
Police raid in Ukraine results in arrests of 2 alleged ransomware hackers Cyberscoop
The Rise of One-Time Password Interception Bots Krebs On Security
Thanks so much for reading and participating in the show!
Oct 6, 2021
2 hr 40 min

Welcome to podcast number 63 of the Security Box series. On this podcast, come and learn about the password trends of 2021, thanks to lastpass's article. Next, a 5.9 million dollar ransomware paid by a farming co-op and a very interesting discussion I heard recently about this. We'll definitely have some news and notes from around the landscape, and even some commentary from any guests that participated through Clubhouse on the live program as well as anyone else through email, imessage and other contact points.
Topics
New Report: 2021 Psychology of Passwords Lastpass
$5.9 million ransomware attack on farming co-op may cause food shortage Ars Technica
">Phone scammers use COVID-19 vaccine appointments to try tricking victims into downloading malware Cyberscoop
Nation-state espionage group breaches Alaska Department of Health Ars Technica
Hackers are using CAPTCHA techniques to scam email users Cyberscoop
Apple users warned: Clicking this attachment will take over your macOS Ars Technica
Thanks so much for listening to today's program, and we'll be back for a month of NCSAM. Enjoy!
Sep 29, 2021
2 hr 6 min

Welcome to the Security box, program number 62. On this program, we're going to cover Windows Update as well as a very interesting article from Krebs about a new botnet that seems to have done quite a bit of damage. It is an IOT botnet called Meris. We'll also have news, notes and lots more.
<h3> Windows Update </h3>
There are the usual two articles on Windows Update. This time, Krebs has quite a bit on these updates while Trend Micro covers the highlights but also gives some info of value too. They're both good for their reasons, so read them both.
<ul title="windows update">
<li> <a href="https://krebsonsecurity.com/2021/09/microsoft-patch-tuesday-september-2021-edition/">Microsoft Patch Tuesday, September 2021 Edition </a> Krebs on Security </li>
<li> <a href="https://www.trendmicro.com/en_us/research/21/i/september-patch-tuesday--66-bulletins--only-3-critical.html">September Patch Tuesday: 66 Bulletins, Only 3 Critical </a> Trend Micro </li>
</ul>
<h3> Meris </h3>
There is one article which we're taking from for this one, but did you listen to podcast 836?
<ul title="Meris Botnet">
<li> <a href="https://krebsonsecurity.com/2021/09/krebsonsecurity-hit-by-huge-new-iot-botnet-meris/">KrebsOnSecurity Hit By Huge New IoT Botnet “Meris” </a> Krebs On Security </li>
</ul>
<h3> News Notes </h3>
<ul title="news notes">
<li> <a href="https://arstechnica.com/?p=1794117">Security researchers at Wiz discover another major Azure vulnerability </a> Ars Technica </li>
<li> <a href="https://arstechnica.com/?p=1794411">Apple patches “FORCEDENTRY” zero-day exploited by Pegasus spyware </a> Ars Technica </li>
<li> <a href="https://krebsonsecurity.com/2021/09/trial-ends-in-guilty-verdict-for-ddos-for-hire-boss/">Trial Ends in Guilty Verdict for DDoS-for-Hire Boss </a> Krebs On Security </li>
<li> <a href="https://krebsonsecurity.com/2021/09/customer-care-giant-ttec-hit-by-ransomware/">Customer Care Giant TTEC Hit By Ransomware </a> Krebs On Security </li>
</ul>
I hope you enjoy the program and thanks so much for listening!
Sep 22, 2021
2 hr 22 min

Scott Schober is on Clubhouse, and he invited me over to his club which talks about cyber security topics. Here is a link to his Cyber Security club where members can join the conversation. The discussion started with whether we've gotten the vaccine or not, whether restaurants and other places are collecting that data let alone securely, and more. I decided to join the stage and while I applauded the conversation about covid-19 vaccines, what aout other problems we're still dealing with lik the open databases problem? Take a listen to this, and let's discuss whether I'm right, or whether we need to be concerned about this. I'll have more talks soon.
Scott Schober's web site
Sep 20, 2021
1 hr 3 min

Welcome to the Security Box, podcast 61. On this podcast, let's discuss the updates on CSAM as it pertains to Apple. We'll have news, notes and more.
<h3> Topics </h3>
<ul title="topics">
<li> <a href="https://www.cyberscoop.com/apple-child-sex-abuse-imagery-delay-privacy/">Under fire from privacy advocates, Apple delays controversial photo scanning plan </a> Cyberscoop </li>
</ul>
<h3> News Notes </h3>
<ul title="News Notes">
<li> <a href="https://krebsonsecurity.com/2021/09/fudco-spam-empire-tied-to-pakistani-software-firm/">“FudCo” Spam Empire Tied to Pakistani Software Firm </a> Krebs On Security </li>
<li> <a href="https://krebsonsecurity.com/2021/09/15-year-old-malware-proxy-network-vip72-goes-dark/">15-Year-Old Malware Proxy Network VIP72 Goes Dark </a> Krebs on Security </li>
<li> <a href="https://krebsonsecurity.com/2021/09/microsoft-attackers-exploiting-windows-zero-day-flaw/">Microsoft: Attackers Exploiting Windows Zero-Day Flaw </a> Krebs on Security </li>
<li> <a href="https://www.cyberscoop.com/irs-ukraine-scammer-vape-store-receipts/">IRS used vape store receipts to gather evidence against alleged Ukrainian scammer </a> Cyberscoop </li>
</ul>
Sep 19, 2021
2 hr 16 min

The Security box, podcast 60: The Security Landscape as a whole from broadcasting software and web site services to T-Mobile's Fiasco
What has changed on the security landscape? We learn about T-Mobile's recent failure, and even web sites are braught up as well as broadcasting software among other things. This turned out to be a very interesting show. What do you think has changed? What have we done wrong? What do you think it'll take to fix it if it can be fixed at all? No news notes this week, but they'll be back next week.
Sep 10, 2021
2 hr 15 min

Hello folks, welcome to the Security box, podcast 59. On this edition of the program we have two different prerecorded segments for you.
First, we interview Scott Schober of Berkeley Varitronics Systems, Inc. He's written various books which we talk about, as well as some of what is going on in the security landscape.
Next, we have a talk that was done by Phishlabs, who did the Quarter 2 Phishing Trends report.
To top it all off, we'll have news and notes from around the landscape as well as questions and comments after each segment if any.
> BV Systems
Scott's Web Site
new-quarterly-threat-trends-intelligence-report-now-available Phishlabs
News Notes from around the web
FBI warns that Hive ransomware hackers are calling victims by phone Cyberscoop
What the Norton-Avast Merger Means for Cybersecurity Trend Micro
FCC proposes record $5 million robocall fine for voter suppression scam Cyberscoop
Poly Network fully recovers assets stolen in unusual $600M cryptocurrency hack Cyberscoop
Microsoft Azure vulnerability exposed thousands of cloud databases Cyberscoop
Scammers impersonate Europol chief in an effort to defraud Belgians Cyberscoop
Thanks for listening!
Sep 3, 2021
4 hr 25 min
Load more
