Talkin’ About Infosec News – 1/17/2023




Black Hills Information Security show

Summary: <br> <br> <br> <br> <br> <br> 00:00 – PreShow Banter™ — Ralph’s Guide to Satellite Bands<br> <br> <br> <br> 04:33 – BHIS – Talkin’ Bout [infosec] News 2023-01-16<br> <br> <br> <br> 05:25 – Story # 1: Microsoft’s new AI can simulate anyone’s voice with 3 seconds of audio<br> <br> <br> <br> <a href="https://arstechnica.com/information-technology/2023/01/microsofts-new-ai-can-simulate-anyones-voice-with-3-seconds-of-audio/">https://arstechnica.com/information-technology/2023/</a><a href="https://arstechnica.com/information-technology/2023/01/microsofts-new-ai-can-simulate-anyones-voice-with-3-seconds-of-audio/" target="_blank" rel="noreferrer noopener">01</a><a href="https://arstechnica.com/information-technology/2023/01/microsofts-new-ai-can-simulate-anyones-voice-with-3-seconds-of-audio/">/microsofts-new-ai-can-simulate-anyones-voice-with-3-seconds-of-audio/</a><br> <br> <br> <br> 13:29 – Story # 2: Russian Hackers Tried to Break Into the U.S.’s Top Nuclear Labs: Report<br> <br> <br> <br> <a href="https://www.vice.com/en/article/jgpz88/russian-hackers-tried-to-break-into-the-uss-top-nuclear-labs-report" target="_blank" rel="noreferrer noopener">https://www.vice.com/en/article/jgpz88/russian-hackers-tried-to-break-into-the-uss-top-nuclear-labs-report</a><br> <br> <br> <br> 16:42 – Story # 3: CircleCI breach post-mortem: Attackers got in by stealing engineer’s session cookie <a href="https://www.helpnetsecurity.com/2023/01/16/circleci-breach/" target="_blank" rel="noreferrer noopener">https://www.helpnetsecurity.com/2023/01/16/circleci-breach/</a><br> <br> <br> <br> 26:59 – Story # 4: How a single developer dropped AWS costs by 90%, then disappeared<br> <br> <br> <br> <a href="https://bootcamp.uxdesign.cc/how-a-single-developer-dropped-aws-costs-by-90-then-disappeared-2b46a115103a" target="_blank" rel="noreferrer noopener">https://bootcamp.uxdesign.cc/how-a-single-developer-dropped-aws-costs-by-90-then-disappeared-2b46a115103a</a><br> <br> <br> <br> 36:46 – Story # 5: A Widespread Logic Controller Flaw Raises the Specter of Stuxnet<br> <br> <br> <br> <a href="https://www.wired.com/story/siemens-s7-1500-logic-controller-flaw/" target="_blank" rel="noreferrer noopener">https://www.wired.com/story/siemens-s7-1500-logic-controller-flaw/</a><br> <br> <br> <br> 48:38 – Story # 6: Meta sues “scraping-for-hire” service that sells user data to law enforcement<br> <br> <br> <br> <a href="https://arstechnica.com/information-technology/2023/01/meta-sues-scraping-for-hire-service-that-sells-user-data-to-law-enforcement/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/information-technology/2023/01/meta-sues-scraping-for-hire-service-that-sells-user-data-to-law-enforcement/</a><br> <br> <br> <br> <br>