Talkin’ About Infosec News – 12/6/2022




Black Hills Information Security show

Summary: <br> <br> <br> <br> <br> <br> 00:00 – PreShow Banter™ — Florida Bobsledding Team01:29 – PreShow Banter™ — Open AI Phishing Campaign05:17 – BHIS – Talkin’ Bout [infosec] News 2022-12-0507:53 – Story # 1: There are no episodes of Darknet Diaries scheduled Q1<a href="https://twitter.com/JackRhysider/status/1599115984262270977" target="_blank" rel="noreferrer noopener">https://twitter.com/JackRhysider/status/1599115984262270977</a>09:45 – Story # 2: Elon Musk Meets With Apple CEO Tim Cook Amid Claims of Twitter App Store Dispute<a href="https://www.macrumors.com/2022/11/30/elon-musk-tim-cook-meeting-apple-park/" target="_blank" rel="noreferrer noopener">https://www.macrumors.com/2022/11/30/elon-musk-tim-cook-meeting-apple-park/</a>14:46 – Story # 3: Anker’s Eufy Cameras Caught Uploading Content to the Cloud Without User Consent<a href="https://www.macrumors.com/2022/11/29/eufy-camera-cloud-uploads-no-user-consent/" target="_blank" rel="noreferrer noopener">https://www.macrumors.com/2022/11/29/eufy-camera-cloud-uploads-no-user-consent/</a>23:20 – Story # 3b: Eufy caught lying about local-only security cameras with footage sent to cloud, accessible in unencrypted streams<a href="https://9to5google.com/2022/12/01/eufy-camera-cloud-security-leak/" target="_blank" rel="noreferrer noopener">https://9to5google.com/2022/12/01/eufy-camera-cloud-security-leak/</a>26:54 – Story # 4: FCC faces long road in stripping Chinese tech from US telecom networks<a href="https://www.cyberscoop.com/fcc-huawei-zte-security-risks/" target="_blank" rel="noreferrer noopener">https://www.cyberscoop.com/fcc-huawei-zte-security-risks/</a>34:19 – Story # 5: TikTok NSFW if you work for the South Dakota government<a href="https://www.theregister.com/2022/11/30/tiktok_nsfw_if_you_work/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2022/11/30/tiktok_nsfw_if_you_work/</a>37:40 – Story # 6: Never-before-seen malware is nuking data in Russia’s courts and mayors’ offices<a href="https://arstechnica.com/information-technology/2022/12/never-before-seen-malware-is-nuking-data-in-russias-courts-and-mayors-offices/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/information-technology/2022/12/never-before-seen-malware-is-nuking-data-in-russias-courts-and-mayors-offices/</a>41:56 – Story # 7: Lessons from Russia’s cyber-war in Ukraine<a href="https://www.economist.com/science-and-technology/2022/11/30/lessons-from-russias-cyber-war-in-ukraine" target="_blank" rel="noreferrer noopener">https://www.economist.com/science-and-technology/2022/11/30/lessons-from-russias-cyber-war-in-ukraine</a>44:15 – Story # 8: DHS Cyber Safety Review Board to focus on Lapsus$ hackers<a href="https://www.cyberscoop.com/cybersecurity-review-board-lapsus/" target="_blank" rel="noreferrer noopener">https://www.cyberscoop.com/cybersecurity-review-board-lapsus/</a>49:49 – Story # 8b: Cyber Safety Review Board to Conduct Second Review on Lapsus$<a href="https://www.dhs.gov/news/2022/12/02/cyber-safety-review-board-conduct-second-review-lapsus" target="_blank" rel="noreferrer noopener">https://www.dhs.gov/news/2022/12/02/cyber-safety-review-board-conduct-second-review-lapsus</a>50:42 – Story # 9: Rackspace rocked by ‘security incident’ that has taken out hosted Exchange services<a href="https://www.theregister.com/2022/12/03/rackspace_security_incident_hosted_exchange/" target="_blank" rel="noreferrer noopener">https://www.theregister.com/2022/12/03/rackspace_security_incident_hosted_exchange/</a>57:05 – Story # 10: Red Alert: The SFPD Want the Power to Kill with Robots<a href="https://www.eff.org/deeplinks/2022/11/red-alert-sfpd-want-power-kill-robots" target="_blank" rel="noreferrer noopener">https://www.eff.org/deeplinks/2022/11/red-alert-sfpd-want-power-kill-robots</a><br> <br> <br> <br> <br> <br> <br> <br> <br> <br> <br>