Talkin’ About Infosec News – 7/25/2022




Black Hills Information Security show

Summary: <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br> ORIGINALLY AIRED ON JULY 25, 2022<br> <br> <br> <br> Articles discussed in this episode:<br> <br> <br> <br> 00:00 – BHIS – Talkin’ Bout [infosec] News 2022-07-25 <br> <br> <br> <br> 03:59 – Story # 1: DOJ seized ransoms paid by health centers in Kansas, Colorado after 2021 attacks – <a href="https://therecord.media/doj-seized-ransoms-paid-by-health-centers-in-kansas-colorado-after-2021-attacks/" target="_blank" rel="noreferrer noopener">https://therecord.media/doj-seized-ransoms-paid-by-health-centers-in-kansas-colorado-after-2021-attacks/</a> <br> <br> <br> <br> 08:38 – Story # 1b: twitter.com/cryptowhale – <a href="https://twitter.com/cryptowhale" target="_blank" rel="noreferrer noopener">https://twitter.com/cryptowhale</a> <br> <br> <br> <br> 17:34 – Story # 2: How Conti ransomware hacked and encrypted the Costa Rican government – <a href="https://www.bleepingcomputer.com/news/security/how-conti-ransomware-hacked-and-encrypted-the-costa-rican-government/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/how-conti-ransomware-hacked-and-encrypted-the-costa-rican-government/ </a><br> <br> <br> <br> 22:29 – Story # 3: Experts Uncover New CloudMensis Spyware Targeting Apple macOS Users – <a href="https://thehackernews.com/2022/07/experts-uncover-new-cloudmensis-spyware.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2022/07/experts-uncover-new-cloudmensis-spyware.html</a> <br> <br> <br> <br> 36:49 – Story # 4: Google Play hides app permissions in favor of developer-written descriptions – <a href="https://arstechnica.com/gadgets/2022/07/google-plays-new-privacy-section-actually-hides-app-permissions/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/gadgets/2022/07/google-plays-new-privacy-section-actually-hides-app-permissions/</a> <br> <br> <br> <br> 39:09 – Story # 4b: Google is reinstating app permissions list on Play Store – <a href="https://techcrunch.com/2022/07/21/google-app-permissions-play-store/" target="_blank" rel="noreferrer noopener">https://techcrunch.com/2022/07/21/google-app-permissions-play-store/</a> <br> <br> <br> <br> 41:31 – Story # 5: Hack the pump: Rising prices lead to more reports of gas theft – <a href="https://www.nbcnews.com/tech/security/hack-pump-rising-prices-lead-reports-gas-theft-rcna35198" target="_blank" rel="noreferrer noopener">https://www.nbcnews.com/tech/security/hack-pump-rising-prices-lead-reports-gas-theft-rcna35198</a> <br> <br> <br> <br> 46:04 – Story # 5b: Gas pump manipulators steal ‘millions of dollars’ in fuel – <a href="https://youtu.be/Bcnjp2PESqw" target="_blank" rel="noreferrer noopener">https://youtu.be/Bcnjp2PESqw</a> <br> <br> <br> <br> 50:40 – Story # 5c: Secret Service agents warn fleets about ‘fuel skimming’ – <a href="https://www.ccjdigital.com/technology/article/15114890/secret-service-agents-warn-fleets-about-fuel-skimming" target="_blank" rel="noreferrer noopener">https://www.ccjdigital.com/technology/article/15114890/secret-service-agents-warn-fleets-about-fuel-skimming</a> <br> <br> <br> <br> 53:13 – Story # 6: Atlassian fixes critical Confluence hardcoded credentials flaw – <a href="https://www.bleepingcomputer.com/news/security/atlassian-fixes-critical-confluence-hardcoded-credentials-flaw/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/atlassian-fixes-critical-confluence-hardcoded-credentials-flaw/</a> <br> <br> <br> <br> 53:33 – Story # 6b: Cisco fixes bug that lets attackers execute commands as root – <a href="https://www.bleepingcomputer.com/news/security/cisco-fixes-bug-that-lets-attackers-ex..."></a>