The 443 - Security Simplified show

The 443 - Security Simplified

Summary: Get inside the minds of leading white-hat hackers and security researchers. Each week, we’ll educate and entertain you by breaking down and simplifying the latest cyber security headlines and trends. Using our special blend of expertise, wit, and cynicism, we’ll turn complex security concepts into easily understood and actionable insights.

Podcasts:

 The White House Tackles AI | File Type: audio/mpeg | Duration: 59:43

https://youtu.be/67SMv6JtJbc This week on the podcast we cover an Executive Order from the US White House on the topic of Artificial Intelligence. After that, we discuss the latest CISO that has found themselves in hot water with the law. We then cover an update to the Common Vulnerability Scoring System and end with a researcher claiming the end of encryption as we know it.

 The Threat Actor That Hacked MGM | File Type: audio/mpeg | Duration: 49:19

https://youtu.be/kvSA53ncRlg This week on the podcast, we review a thorough unmasking of Octa Tempest, the threat actor beind the MGM and Caesars Entertainment attacks in September. Before that, we give an update on the Cisco IOS XE vulnerability that head to an implant installed on thousands of exposed devices. We round out the episode with an analysis of CitrixBleed, an information disclosure vulnerability in Citrix NetScaler that was just patched last week.

 CISA’s Secure by Design Whitepaper | File Type: audio/mpeg | Duration: 49:03

https://youtu.be/GYoWiEKod38 This week on the podcast, we cover CISA's newly updated whitepaper on guidance for both software manufacturers and customers on the principals of secure-by-design and secure-by-default. Before that, we cover the Cisco IOS XE vulnerability that is under active exploitation in the wild, give an update on the EPA's efforts to regulate cybersecurity practices in water districts, and then discuss research into the latest "bullet proof hosting" options for malicious web content.

 Microsoft is Killing NTLM | File Type: audio/mpeg | Duration: 40:09

https://youtu.be/dSUkvBUDum4 This week on the podcast, we cover the recent HTTP/2 protocol vulnerability that lead to the largest DDoS attack ever recorded by CloudFlare. After that, we discuss Microsoft's announcement about the deprecation of VBScript and the impending removal of NTLM. We then cover a collection of data allegedly stolen from the genealogy website 23 and Me before ending with a fun bit of research targeting private servers for the Grand Theft Auto Online video game.

 Q2 2023 Internet Security Report | File Type: audio/mpeg | Duration: 49:53

https://youtu.be/NVvX02rwlEA This week on the podcast, we go through the latest Internet Security Report from the WatchGuard Threat Lab. We'll cover the top malware and network attack trends from Q2 2023 impacting small and mid-market organization globally before ending with defensive tips anyone can take back to their company.

 Bing Chat Malvertising | File Type: audio/mpeg | Duration: 30:02

https://youtu.be/Io_lubfJgKE This week on the podcast, we discuss an alert from CISA on nation state threat actors embedding malware into legacy Cisco router firmware. After that, we cover a research post on malicious advertisements served up via Bing's ChatGTP integration. We then end with an analysis of North Korea's Lazarus group's latest social engineering techniques.

 Meta’ One Good Deed | File Type: audio/mpeg | Duration: 42:39

https://youtu.be/Yo5GO14F5N0 This week on the podcast, we get up to speed on the MGM and Caesars Entertainment ransomware incidents from the previous week. After that, we take a deep dive into a blog post from Meta's application security team for their VR headsets. After that, we cover Microsoft's analysis of an ATP's pivot from email to another form of phishing.

 iPhone’s Latest 0-Day | File Type: audio/mpeg | Duration: 39:01

https://youtu.be/UwuG1U1fZhE This week on the podcast, we cover Microsoft's final report on their July incident involving nation-state actors compromising enterprise email accounts. After that, we discuss a zero-day, zero-click vulnerability in iOS being actively exploited in the wild before ending with a chat about an upcoming change to how Android handles CA certificates.

 The Qakbot Takedown | File Type: audio/mpeg | Duration: 52:01

https://youtu.be/NLO0DYuTZp4 This week on the podcast, we cover the FBI-lead, multinational takedown of the Qakbot botnet of over 700,000 victim devices. After that, we cover two android malware variants including one targeting victims in southeast Asia and another built by the Russian GRU.

 Weaponizing WinRAR | File Type: audio/mpeg | Duration: 28:02

https://youtu.be/BVbVwm0dMgg This week on the podcast we cover the latest evolutions of the North Korean threat actor Lazarus before covering an actively-exploited 0day vulnerability in the popular unarchiver WinRAR. We end the episode with an AI-related attack that doesn't actually use AI.

 U.S. Cyber Trust Mark | File Type: audio/mpeg | Duration: 52:33

https://youtu.be/Drx3kF3sllQ This week on the podcast we cover the FCC's proposal for a security assurance labeling program for IoT devices. Before that, we discuss the latest AI research challenge hosted by DARPA as well as some research into a novel attack against the AI/ML supply chain.

 Def Con 2023 Recap | File Type: audio/mpeg | Duration: 53:09

https://youtu.be/LldPfSZY0uU On this week's episode, we chat about some of our favorite talks from this year's Def Con security conference. We'll cover several topics including artificial intelligence, hacking mobile point of sale devices, and how worried we should or shouldn't be about cyber warfare.

 BlackHat 2023 Recap | File Type: audio/mpeg | Duration: 58:12

https://youtu.be/ltW3DQVrZ28 In this special end-of-week episode of The 443, we cover some of our favorite talks from this year's edition of the BlackHat cybersecurity conference in Las Vegas. We'll discuss the trends we saw and summaries of interesting topics including AI, nation state warfare, and improving cyber defense.

 What Is Same-Origin Policy? Replay | File Type: audio/mpeg | Duration: 40:25

https://youtu.be/Gfvg7dywu8A This week we look back to an episode that originally aired in May 2021 where we remember a Def Con legend then dive in to two web browsing security acronyms. Keep an eye out later this week as we come to you from this year's Black Hat and Def Con cybersecurity conferences!

 Qakbot Qacktivity | File Type: audio/mpeg | Duration: 35:50

https://youtu.be/FZKalGbK90A This week on the podcast, we cover the latest evolutions of the decade-old Qakbot malware including changes in how attackers deliver it. After that, we give an update on the SEC's new rules around mandatory security disclosure. We then end by reviewing CISA's analysis of Risk and Vulnerability Assessments they completed for their constituents in 2022.  

Comments

Login or signup comment.