

Talkin' Bout [Infosec] News
Black Hills Information Security
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
Join us live on YouTube, Monday's at 4:30PM ET
Join us live on YouTube, Monday's at 4:30PM ET
Episodes
Mentioned books

Mar 3, 2023 • 59min
Talkin’ About Infosec News – 3/3/2023
Story # 1: A Basic iPhone Feature Helps Criminals Steal Your Entire Digital Lifehttps://www.wsj.com/articles/apple-iphone-security-theft-passcode-data-privacya-basic-iphone-feature-helps-criminals-steal-your-digital-life-cbf14b1a Story # 1b: Apple’s iPhone Passcode Problem: Thieves Can Ruin Your Entire Digital Life in Minutes […]
The post Talkin’ About Infosec News – 3/3/2023 appeared first on Black Hills Information Security.
(00:00) - PreShow Banter™ — Farm Raised Artificial Intelligence
(04:01) - BHIS - Talkin' Bout [infosec] News 2023-02-27
(05:09) - Story # 1: A Basic iPhone Feature Helps Criminals Steal Your Entire Digital Life
(18:52) - Story # 2: Sensitive US military emails spill online
(27:55) - Story # 3: Fruit giant Dole suffers ransomware attack impacting operations
(33:01) - Story # 4: Well-hidden Mac cryptomining malware found in pirate copies of Final Cut Pro; expect more
(37:30) - Story # 5: AI Helps Crack NIST-Recommended Post-Quantum Encryption Algorithm
(40:38) - Story # 6: Snapchat launches ChatGPT integration, warns to not share your secrets
(43:28) - Story # 7: How I Broke Into a Bank Account With an AI-Generated Voice
(47:55) - Story # 8: Firms Who Pay Ransom Subsidise 10 New Attacks: Report
(53:51) - Story # 9: Valve set a trap to catch and ban 40,000 Dota 2 cheaters

Feb 22, 2023 • 1h 7min
Talkin’ About Infosec News – 2/22/2023
00:00 – PreShow Banter™ — Pop Tart Pizza04:15 – BHIS – Talkin’ Bout [infosec] News 2023-02-2005:39 – Story # 1: Employee data from a major cybersecurity firm posted for sale […]
The post Talkin’ About Infosec News – 2/22/2023 appeared first on Black Hills Information Security.
(00:00) - PreShow Banter™ — Pop Tart Pizza
(04:15) - BHIS - Talkin' Bout [infosec] News 2023-02-20
(05:39) - Story # 1: Employee data from a major cybersecurity firm posted for sale on a hacker forum
(13:43) - Story # 2: FBI is investigating a cybersecurity incident on its network
(16:44) - Story # 3: GoDaddy: Hackers stole source code, installed malware in multi-year breach
(21:44) - Story # 4: Hyundai, Kia pushing updates so you can’t just steal their cars with USB cables
(30:21) - Story # 5: Eurostar forces 'password resets' — then fails and locks users out
(33:37) - Story # 6: Hacker Uncovers How to Turn Traffic Lights Green With Flipper Zero
(39:30) - Story # 7: Namecheap denies system breach after email service used to spread phishing scams
(43:11) - Story # 8: Official: Twitter will now charge for SMS two-factor authentication
(48:24) - Story # 9: Software suite of Israeli security firm Cellebrite leaks online
(51:22) - Story # 10: The US Air Force may have shot down an Amateur Radio Pico Balloon over Canada
(55:48) - Story # 11: ChatGPT Is Ingesting Corporate Secrets

Feb 17, 2023 • 1h 4min
Talkin’ About Infosec News – 2/17/2023
00:00 – PreShow Banter™ — Scalping Valentine’s Day Reservations04:13 – BHIS – Talkin’ Bout [infosec] News 2023-06-2305:52 – Story # 1: 5 Chinese companies and a research institute blacklisted by […]
The post Talkin’ About Infosec News – 2/17/2023 appeared first on Black Hills Information Security.
(00:00) - PreShow Banter™ — Scalping Valentine's Day Reservations
(04:13) - BHIS - Talkin' Bout [infosec] News 2023-06-23
(05:52) - Story # 1: 5 Chinese companies and a research institute blacklisted by U.S. over spy balloon program
(12:00) - Story # 2: We had a security incident. Here’s what we know.
(15:19) - Ean Reports Live!
(21:44) - Story # 3: NameCheap's email hacked to send Metamask, DHL phishing emails
(26:49) - Story # 4: Top mobile finance app Money Lover has some worrying security flaws
(31:24) - Story # 5: Ukraine war: Elon Musk's SpaceX firm bars Kyiv from using Starlink tech for drone control
(36:58) - Story # 6: NATO websites hacked, including that of the Headquarters of Special Operations Forces
(38:58) - Story # 7: Khinshtein said that hackers acting in the interests of the Russian Federation should be released from liability
(40:52) - Story # 8 NIST Standardizes Ascon Cryptographic Algorithm for IoT and Other Lightweight Devices
(43:29) - Story # 9: Americans don't understand what companies can do with their personal data—and that's a problem
(45:15) - Story # 9b: AMERICANS CAN’T CONSENT TO COMPANIES’ USE OF THEIR DATA
(54:33) - Story # 10: Pentagon Staffers Found Installing Dating Apps, Games on Government Phones
(57:34) - Story # 10b: Management Advisory: The DoD’s Use of Mobile Applications (Report No. DODIG-2023-041)
(58:14) - Story # 11: When Facebook came for your battery, feudal security failed

Feb 13, 2023 • 1h 1min
Talkin’ About Infosec News – 2/13/2023
00:00 – PreShow Banter™ — We’ve got nothing to say03:07 – BHIS – Talkin’ Bout [infosec] News 2023-06-2305:56 – Story # 1: Cybercrime job ads on the dark web pay […]
The post Talkin’ About Infosec News – 2/13/2023 appeared first on Black Hills Information Security.
(00:00) - PreShow Banter™ — We've got nothing to say
(03:07) - BHIS - Talkin' Bout [infosec] News 2023-06-23
(05:56) - Story # 1: Cybercrime job ads on the dark web pay up to $20k per month
(10:52) - Story # 2: Discrepancies Discovered in Vulnerability Severity Ratings
(25:27) - Story # 3: GitHub Breach: Hackers Stole Code-Signing Certificates for GitHub Desktop and Atom
(28:48) - Story # 4: Ex-Ubiquiti worker pleads guilty to data theft, extortion, and smear plot
(34:47) - Story # 5: North Korean hackers stole research data in two-month-long breach
(42:19) - Story # 6: Hacker Group Releases 128GB Of Data Showing Russia's 'Wide-Ranging' Illegal Surveillance Of Citizens

Feb 3, 2023 • 1h 1min
Talkin’ About Infosec News – 2/3/2023
00:00 – PreShow Banter™ — Woke Up Like This03:20 – BHIS – Talkin’ Bout [infosec] News 2023-01-3005:04 – Story # 1: GoTo says hackers stole customers’ backups and encryption keyhttps://www.bleepingcomputer.com/news/security/goto-says-hackers-stole-customers-backups-and-encryption-key/09:48 […]
The post Talkin’ About Infosec News – 2/3/2023 appeared first on Black Hills Information Security.
(00:00) - PreShow Banter™ — Woke Up Like This
(03:20) - BHIS - Talkin' Bout [infosec] News 2023-01-30
(05:04) - Story # 1: GoTo says hackers stole customers' backups and encryption key
(09:48) - Story # 2: T-Mobile hacked to steal data of 37 million accounts in API data breach
(11:29) - Story # 3: Appliance makers sad that 50% of customers won’t connect smart appliances
(23:11) - Story # 4: More Ransomware Victims Are Refusing to Pay Hackers
(25:34) - Story # 5: DOJ, FBI hack Hive Network, save US$130 mln from crypto ransomware attacks
(27:27) - Story # 6: Ransomware gang steals data from KFC, Taco Bell, and Pizza Hut brand owner
(29:35) - Story # 7: Pet fish commits credit card fraud on owner using a Nintendo Switch
(34:15) - Story # 8: how to completely own an airline in 3 easy steps
(38:43) - Story # 9: Nearly 35,000 PayPal users had SSNs, tax info leaked during December cyberattack
(46:43) - Story # 10: The semiconductor monopoly: How one Dutch company has a stranglehold over the global chip industry
(55:59) - Story # 11: Swipe right on our new credit card tokens!

Jan 25, 2023 • 1h 5min
Talkin’ About Infosec News – 1/25/2023
00:00 – PreShow Banter™ — Wade’s Googly Eyes00:41 – BHIS – Talkin’ Bout [infosec] News 2023-01-2301:26 – Story # 1: BIG TECH LAYOFFS. LAYOFFS! DOOM! RECESSION!
The post Talkin’ About Infosec News – 1/25/2023 appeared first on Black Hills Information Security.
(00:00) - PreShow Banter™ — Wade's Googly Eyes
(00:41) - BHIS - Talkin' Bout [infosec] News 2023-01-23
(01:26) - Story # 1: BIG TECH LAYOFFS. LAYOFFS! DOOM! RECESSION!

Jan 17, 2023 • 58min
Talkin’ About Infosec News – 1/17/2023
00:00 – PreShow Banter™ — Ralph’s Guide to Satellite Bands 04:33 – BHIS – Talkin’ Bout [infosec] News 2023-01-16 05:25 – Story # 1: Microsoft’s new AI can simulate anyone’s […]
The post Talkin’ About Infosec News – 1/17/2023 appeared first on Black Hills Information Security.
(00:00) - PreShow Banter™ — Ralph’s Guide to Satellite Bands
(04:33) - BHIS - Talkin' Bout [infosec] News 2023-01-16
(05:25) - Story # 1: Microsoft’s new AI can simulate anyone’s voice with 3 seconds of audio
(13:29) - Story # 2: Russian Hackers Tried to Break Into the U.S.'s Top Nuclear Labs: Report
(16:42) - Story # 3: CircleCI breach post-mortem: Attackers got in by stealing engineer’s session cookie
(26:59) - Story # 4: How a single developer dropped AWS costs by 90%, then disappeared
(36:46) - Story # 5: A Widespread Logic Controller Flaw Raises the Specter of Stuxnet
(48:38) - Story # 6: Meta sues “scraping-for-hire” service that sells user data to law enforcement

Jan 12, 2023 • 52min
Talkin’ About Infosec News – 1/12/2023
00:00 – PreShow Banter™ — Twitch Airways International00:59 – BHIS – Talkin’ Bout [infosec] News 2023-01-1003:56 – Story # 1: How ChatGPT could become a hacker’s friendhttps://betanews.com/2023/01/05/how-chatgpt-could-become-a-hackers-friend/14:05 – Story # […]
The post Talkin’ About Infosec News – 1/12/2023 appeared first on Black Hills Information Security.
(00:00) - PreShow Banter™ — Twitch Airways International
(00:59) - BHIS - Talkin' Bout [infosec] News 2023-01-10
(03:56) - Story # 1: How ChatGPT could become a hacker's friend
(14:05) - Story # 2: Cybersecurity experts gaze into the 2023 crystal ball and see good, bad, ugly
(16:40) - Story # 3: Chick-Fil-A and other Breaches to snack on
(31:01) - Story # 4: Identity Thieves Bypassed Experian Security to View Credit Reports
(36:29) - Story # 5: CircleCI security alert: Rotate any secrets stored in CircleCI (Updated Jan 7)
(40:45) - Story # 6: Air France and KLM notify customers of account hacks
(43:27) - Story # 7: Guardian offices closed until 23 January due to ongoing fallout from suspected ransomware attack

Jan 3, 2023 • 55min
Talkin’ About Infosec News – 1/3/2023
00:00 – PreShow Banter™ — Seven People00:51 – BHIS – Talkin’ Bout [infosec] News 2023-01-0201:37 – Story # 1: LastPass Admits to Severe Data Breach, Encrypted Password Vaults Stolenhttps://www.theverge.com/2022/12/28/23529547/lastpass-vault-breach-disclosure-encryption-cybersecurity-rebuttal32:22 – […]
The post Talkin’ About Infosec News – 1/3/2023 appeared first on Black Hills Information Security.
(00:00) - PreShow Banter™ — Seven People
(00:51) - BHIS - Talkin' Bout [infosec] News 2023-01-02
(01:37) - Story # 1: LastPass Admits to Severe Data Breach, Encrypted Password Vaults Stolen
(32:22) - Story # 2: Southwest Airlines’ post-Christmas meltdown thanks to ‘outdated IT’ systems, poor scheduling
(42:18) - Story # 3: McGraw Hill's S3 buckets exposed 100,000 students' grades
(47:59) - Story # 4: Okta confirms another breach after hackers steal source code

Dec 21, 2022 • 59min
Talkin’ About Infosec News – 12/21/2022
00:00 – PreShow Banter™ — Talkin’ Bout [Elon] News00:51 – BHIS – Talkin’ Bout [infosec] News 2022-12-1902:46 – Story # 1: Antivirus and EDR solutions tricked into acting as data […]
The post Talkin’ About Infosec News – 12/21/2022 appeared first on Black Hills Information Security.
(00:00) - PreShow Banter™ — Talkin' Bout [Elon] News
(00:51) - BHIS - Talkin' Bout [infosec] News 2022-12-19
(02:46) - Story # 1 : Antivirus and EDR solutions tricked into acting as data wipers
(12:11) - Story # 2: Twitter suspends @ElonJet after Musk promises not to ban it
(12:48) - Story # 2b: Elon Musk starts banning critical journalists from Twitter
(14:37) - Story # 2c: Twitter abruptly bans all links to Instagram, Mastodon, and other competitors
(15:08) - Story # 2d: Elon Musk should step down as head of Twitter, says poll
(16:18) - Story # 2e: Your Car is Trackable by Law
(22:41) - Story # 2f: AirNav RadarBox FlightStick - ADS-B USB Receiver with Integrated Filter, Amplifier and ESD Protection
(26:41) - Story # 3: FBI’s Vetted Info Sharing Network ‘InfraGard’ Hacked
(32:24) - Story # 4: Reno mayor sues after finding tracking device on vehicle
(36:43) - Story # 5: Email hijackers scam food out of businesses, not just money
(42:46) - Story # 6: Bugs in LEGO Resale Site Allowed Hackers to Hijack Accounts
(45:41) - Story # 7: CISA Alert: Veeam Backup and Replication Vulnerabilities Being Exploited in Attacks
(50:05) - Story # 8: CISA researchers: Russia's Fancy Bear infiltrated US satellite network


