Talkin’ About Infosec News – 11/30/2022




Black Hills Information Security show

Summary: <br> <br> <br> <br> <br> <br> 00:00 – PreShow Banter™ — Inflatable Turkey00:15 – BHIS – Talkin’ Bout [infosec] News 2022-11-2802:34 – Story # 1: Musk recruits engineers for “Twitter 2.0”<a href="https://arstechnica.com/tech-policy/2022/11/musk-recruits-engineers-for-twitter-2-0-after-mass-layoffs-and-resignations/" target="_blank" rel="noreferrer noopener">https://arstechnica.com/tech-policy/2022/11/musk-recruits-engineers-for-twitter-2-0-after-mass-layoffs-and-resignations/</a>06:28 – Story # 2: Security experts are laying Mastodon’s flaws bare<a href="https://www.techradar.com/news/security-experts-are-laying-mastodons-flaws-bare" target="_blank" rel="noreferrer noopener">https://www.techradar.com/news/security-experts-are-laying-mastodons-flaws-bare</a>15:01 – Story # 3: 5.4 million Twitter users’ stolen data leaked online — more shared privately<a href="https://www.bleepingcomputer.com/news/security/54-million-twitter-users-stolen-data-leaked-online-more-shared-privately/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/54-million-twitter-users-stolen-data-leaked-online-more-shared-privately/</a>18:23 – Story # 4: 34 Russian Cybercrime Groups Stole Over 50 Million Passwords with Stealer Malware<a href="https://thehackernews.com/2022/11/34-russian-hacker-groups-stole-over-50.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2022/11/34-russian-hacker-groups-stole-over-50.html</a>19:48 – Story # 5: Sonder confirms data breach, documents and other PII potentially compromised<a href="https://www.infosecurity-magazine.com/news/sonder-confirms-data-breach/" target="_blank" rel="noreferrer noopener">https://www.infosecurity-magazine.com/news/sonder-confirms-data-breach/</a>27:49 – Story # 6: Why Medibank should have paid the hackers<a href="https://www.smh.com.au/business/consumer-affairs/this-is-a-business-for-them-why-medibank-should-have-paid-the-hackers-20221121-p5bzzn.html" target="_blank" rel="noreferrer noopener">https://www.smh.com.au/business/consumer-affairs/this-is-a-business-for-them-why-medibank-should-have-paid-the-hackers-20221121-p5bzzn.html</a>30:43 – Story # 7: Hackers are locking out Mars Stealer operators from their own servers<a href="https://techcrunch.com/2022/11/22/mars-stealers-flaw-lock-out/" target="_blank" rel="noreferrer noopener">https://techcrunch.com/2022/11/22/mars-stealers-flaw-lock-out/</a>33:42 – Story # 8: Ransomware gang says it won’t attack AirAsia again due to the “chaotic organisation” and sloppy security of hacked airline’s network<a href="https://grahamcluley.com/ouch-ransomware-gang-says-it-wont-attack-airasia-again-due-to-the-chaotic-organisation-and-sloppy-security-of-hacked-companys-network/" target="_blank" rel="noreferrer noopener">https://grahamcluley.com/ouch-ransomware-gang-says-it-wont-attack-airasia-again-due-to-the-chaotic-organisation-and-sloppy-security-of-hacked-companys-network/</a>40:09 – Story # 9: Over 1,600 Docker Hub Repositories Were Found to Hide Malware<a href="https://heimdalsecurity.com/blog/over-1600-docker-hub-repositories-were-found-to-hide-malware/" target="_blank" rel="noreferrer noopener">https://heimdalsecurity.com/blog/over-1600-docker-hub-repositories-were-found-to-hide-malware/</a>46:25 – Story # 10: New Windows Server updates cause domain controller freezes, restarts<a href="https://www.bleepingcomputer.com/news/microsoft/new-windows-server-updates-cause-domain-controller-freezes-restarts/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/microsoft/new-windows-server-updates-cause-domain-controller-freezes-restarts/</a>53:39 – Story # 11: Making Cobalt Strike harder for threat actors to abuse<a href="https://cloud.google.com/blog/products/identity-security/making-cobalt-strike-harder-for-threat-actors-to-abuse" target="_blank" rel="noreferrer noopener">https://...</a>