Talkin’ About Infosec News – 8/18/2022




Black Hills Information Security show

Summary: <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> ORIGINALLY AIRED ON AUGUST 15, 2022<br> <br> <br> <br> Articles discussed in this episode:<br> <br> <br> <br> 00:00 – PreShow Banter™ — Sneaking Candy03:32 – BHIS – Talkin’ Bout [infosec] News 2022-08-1507:06 – Story # 1: Blackhat 2022 recap – Trends and highlights – <a href="https://sysdig.com/blog/blackhat-2022-recap/" target="_blank" rel="noreferrer noopener">https://sysdig.com/blog/blackhat-2022-recap/</a>09:52 – Story # 2: The Zoom installer let a researcher hack his way to root access on macOS – <a href="https://www.theverge.com/2022/8/12/23303411/zoom-defcon-root-access-privilege-escalation-hack-patrick-wardle" target="_blank" rel="noreferrer noopener">https://www.theverge.com/2022/8/12/23303411/zoom-defcon-root-access-privilege-escalation-hack-patrick-wardle</a>14:14 – Story # 3: Researchers Find Vulnerabilities in Software Underlying Discord, Microsoft Teams, and Other Apps – <a href="https://www.vice.com/en/article/m7gb7y/researchers-find-vulnerability-in-software-underlying-discord-microsoft-teams-and-other-apps" target="_blank" rel="noreferrer noopener">https://www.vice.com/en/article/m7gb7y/researchers-find-vulnerability-in-software-underlying-discord-microsoft-teams-and-other-apps</a>16:17 – Story # 4: Starlink Successfully Hacked Using $25 Modchip – <a href="https://threatpost.com/starlink-hack/180389/" target="_blank" rel="noreferrer noopener">https://threatpost.com/starlink-hack/180389/</a>21:46 – Story # 5: Anonymous poop gifting site hacked, customers exposed – <a href="https://www.bleepingcomputer.com/news/security/anonymous-poop-gifting-site-hacked-customers-exposed/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/anonymous-poop-gifting-site-hacked-customers-exposed/</a>28:56 – Story # 6: Automotive supplier breached by 3 ransomware gangs in 2 weeks – <a href="https://www.bleepingcomputer.com/news/security/automotive-supplier-breached-by-3-ransomware-gangs-in-2-weeks/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/automotive-supplier-breached-by-3-ransomware-gangs-in-2-weeks/</a>33:47 – Story # 7: Man who built ISP instead of paying Comcast $50K expands to hundreds of homes – <a href="https://arstechnica.com/tech-policy/2022/08/man-who-built-isp-instead-of-paying-comcast-50k-expands-to-hundreds-of-homes/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/tech-policy/2022/08/man-who-built-isp-instead-of-paying-comcast-50k-expands-to-hundreds-of-homes/</a>38:07 – Story # 8: Slack leaked hashed passwords from its servers for years – <a href="https://www.theregister.com/2022/08/08/slack_passwords/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2022/08/08/slack_passwords/</a>40:31 – Story # 9: Cisco Talos shares insights related to recent cyber attack on Cisco – <a href="https://blog.talosintelligence.com/2022/08/recent-cyber-attack.html" target="_blank" rel="noreferrer noopener">https://blog.talosintelligence.com/2022/08/recent-cyber-attack.html</a>48:04 – Story # 10: Incident Report: Employee and Customer Account Compromise – <a href="https://www.twilio.com/blog/august-2022-social-engineering-attack" target="_blank" rel="noreferrer noopener">https://www.twilio.com/blog/august-2022-social-engineering-attack</a>50:51 – Story # 11: Hackers Behind Twilio Breach Also Targeted Cloudflare Employees – <a href="https://thehackernews.com/2022/08/hackers-behind-twilio-breach-also_10.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2022/08/hackers-behind-twilio-breach-also_10.html</a><br> <br> <br> <br> <br> <br> <br> <br> <br> <br>