psw741

Paul’s Security Weekly Episode #741 – May 18, 2022

Subscribe to all of our shows and mailing list by visiting: https://securityweekly.com/subscribe

1. Year in Cyber Review 2021 – 06:00 PM-06:45 PM

Announcements

  • Security Weekly listeners, save $100 on your RSA Conference 2022 Full Conference Pass! RSA Conference will be live in San Francisco June 6th-9th, 2022. Security Weekly will be there in full force, delivering real-time, live coverage and interviewing some of the event’s top speakers and sponsors. To register using our discount code, please visit https://securityweekly.com/rsac2022 and use the code 52UCYBER. We hope to see you there!

Description

The past year has been filled with incredible changes in the cyber security landscape from ICS, Mobile, Cloud, and increased threats from Ransomware. This discussion will focus on crucial and quick discussions surrounding the cyber landscape that has changed quickly and forced organizations to consider revamping many of their policies and preparations. Join us for a humorous, and insightful journey back over the past year filled with examples for practitioners, organizations, and those just starting in cyber security.

Guest(s)

Robert Lee

Robert Lee – CEO & Co-Founder at Dragos

@dragosinc

Robert M. Lee is the CEO and co-founder of the ICS cybersecurity technology and services firm Dragos. He gained his start in the U.S. Air Force as a Cyber Warfare Operations Officer where he spent most of his career at the National Security Agency where he built and led a first-of-its-kind mission hunting and analyzing state actors targeting ICS. He is also a Senior Instructor at the SANS Institute where he authored the Forensics 578 course on Cyber Threat Intelligence and the ICS 515 course on ICS network monitoring and incident response. He may be found on Twitter @RobertMLee

Hosts

AaranLeyland

Aaran Leyland

CEO at Restricted Access, Ltd

JoshMarpet

Josh Marpet

@quadling

Executive Director at RM-ISAO

PaulAsadoorian

Paul Asadoorian

@securityweekly

Founder at Security Weekly

TylerRobinson

Tyler Robinson

@tyler_robinson

Director of Offensive Security & Research at Trimarc Security, Founder & CEO at Dark Element

2. Firmware Security – 07:00 PM-07:45 PM

Announcements

  • Do you have a specific guest or topic that you want us to cover on one of the shows? Submit your suggestions for guests by visiting https://securityweekly.com/guests and completing the form! We review suggestions monthly and will reach out to you once reviewed!

Description

In this segment Saumil Shah joins us for a discussion on Firmware Security, complete with a fascinating first-hand demonstration!

Guest(s)

Saumil Shah

Saumil Shah – Organizer at Ringzer0 Training

@therealsaumil

Saumil is an internationally recognized speaker And instructor, having regularly presented At conferences Like Blackhat, Rsa, Cansecwest, Pacsec, Eusecwest, Hack.lu, Hack-in-the-box And Others. He has Authored Two Books Titled “Web Hacking: Attacks And Defense” And “the Anti-virus Book”.

Saumil Graduated With An M.s. In Computer Science from Purdue University, Usa And A B.e. In Computer Engineering from Gujarat University. He spends his leisure time breaking software, flying kites, traveling around the world and taking pictures.

Hosts

JoshMarpet

Josh Marpet

@quadling

Executive Director at RM-ISAO

LeeNeely

Lee Neely

@lelandneely

Information Assurance APL at Lawrence Livermore National Laboratory

PaulAsadoorian

Paul Asadoorian

@securityweekly

Founder at Security Weekly

TylerRobinson

Tyler Robinson

@tyler_robinson

Director of Offensive Security & Research at Trimarc Security, Founder & CEO at Dark Element

3. Windows GPU Display Vulns, NFT Discord Hack, Costa Rica Vs. Hackers, & Initial Access – 08:00 PM-09:30 PM

Announcements

  • Don’t miss any of your favorite Security Weekly content! Visit https://securityweekly.com/subscribe to subscribe to any of our podcast feeds and have all new episodes downloaded right to your phone! You can also join our mailing list, Discord server, and follow us on social media & our streaming platforms!

  • Join us June 29th for a webcast with Tyler Robinson and Beau Bullock to learn how to pivot into the world of Crypto security. Visit https://securityweekly.com/webcasts to register with only your name and email! Don’t forget to check out our library of on-demand webcasts & technical trainings at securityweekly.com/ondemand.

Description

In the Security News for this week: Singapore launches safety rating system for e-commerce sites, Watch Out for Zyxel Firewalls RCE Vulnerability, New Bluetooth hack that can unlock your Tesla, Hackers Compromise a String of NFT Discord Channels, a pentester’s attempt to be ‘as realistic as possible’ backfires, & more!

Hosts

JoshMarpet

Josh Marpet

@quadling

Executive Director at RM-ISAO

LeeNeely

Lee Neely

@lelandneely

Information Assurance APL at Lawrence Livermore National Laboratory

  1. Singapore launches safety rating scheme for e-commerce sites – Assessing e-commerce marketplaces based on their anti-scam measures, the scheme gives Facebook Marketplace the lowest rating while Lazada and Amazon are amongst those that received the highest.
  2. Hackers are exploiting critical bug in Zyxel firewalls and VPNs – Hackers are now actively exploiting a recently patched, critical vulnerability (CVE-2022-30525) affecting Zyxel firewall and VPN devices used by businesses that could be exploited by remote, unauthenticated attackers to inject arbitrary commands that enable the creation of a reverse shell
  3. Malware is targeting crypto wallets, says Microsoft: Here’s how to protect yourself better – Everyone’s heard of ransomware, and many people have heard of ‘cryptojackers’, banking trojans, and ‘info stealers’. Now, Microsoft is introducing ‘cryware’ into the cybersecurity lexicon, predicting more people will start using so-called ‘hot wallets’ as they boost cryptocurrency holdings – and that crooks will try to grab them.
  4. 5 critical questions to test your ransomware preparedness – Help Net Security – Five questions to ask yourself regarding your ransomware preparedness.
  5. Wizard Spider hackers hire cold callers to scare ransomware victims into paying up – They will cold call victims and attempt to coerce/scare them into paying the ransom demand.
  6. BLE vulnerability may be exploited to unlock cars, smart locks, building doors, smartphones – Help Net Security – A Bluetooth Low Energy (BLE) vulnerability discovered by NCC Group researchers may be used by attackers to unlock cars with automotive keyless entry, residential smart locks, building access systems, mobile phones, laptops, and many other devices.
  7. US warns over the risk of hiring North Korea IT workers – North Korean information technology (IT) workers are hiding their true identities in order to land jobs and ultimately steal funds to finance the North Korean Government’s weapons program.
  8. Russians allegedly storm Ukrainian ISP, blackmail it to switch to Russian networks – Ukraine’s State Service of Special Communications and Information Protection (SSSCIP) revealed that Russian forces successfully invaded an internet company operating out of Kherson, disconnected all equipment, and threatened to confiscate the equipment if the company refused to connect to Russian networks.
  9. EMERGENCY DIRECTIVE 22-03 MITIGATE VMWARE VULNERABILITIES – Threat actors, including likely advanced persistent threat (APT) actors, are exploiting vulnerabilities (CVE 2022-22954 and CVE 2022-22960) in the following VMware products: VMware Workspace ONE Access (Access), VMware Identity Manager (vIDM), VMware vRealize Automation (vRA), VMware Cloud Foundation, and vRealize Suite Lifecycle Manager.
PaulAsadoorian

Paul Asadoorian

@securityweekly

Founder at Security Weekly

  1. Watch Out! Hackers Begin Exploiting Recent Zyxel Firewalls RCE Vulnerability – Rapid 7 research: https://www.rapid7.com/blog/post/2022/05/12/cve-2022-30525-fixed-zyxel-firewall-unauthenticated-remote-command-injection/ (Also see: https://www.zdnet.com/article/nasty-zyxel-remote-execution-bug-is-being-exploited/)
  2. NVIDIA fixes ten vulnerabilities in Windows GPU display drivers
  3. Angry IT admin wipes employer’s databases, gets 7 years in prison
  4. New Bluetooth hack can unlock your Tesla—and all kinds of other devices
  5. President Rodrigo Chaves says Costa Rica is at war with Conti hackers
  6. Hackers Compromise a String of NFT Discord Channels
  7. Apple emergency update fixes zero-day used to hack Macs, Watches
  8. US names Venezuelan doctor as notorious ransomware maker – TechCrunch
  9. NSA, Allies Issue Cybersecurity Advisory on Weaknesses that Allow Initial Access
  10. How a pentester’s attempt to be ‘as realistic as possible’ alarmed cybersecurity firms
TylerRobinson

Tyler Robinson

@tyler_robinson

Director of Offensive Security & Research at Trimarc Security, Founder & CEO at Dark Element