

Talkin' Bout [Infosec] News
Black Hills Information Security
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
Join us live on YouTube, Monday's at 4:30PM ET
Join us live on YouTube, Monday's at 4:30PM ET
Episodes
Mentioned books

Apr 21, 2021 • 53min
Talkin’ About Infosec News – 4/19/2021
Originally Aired on April 19, 2021
Articles discussed in this episode:
* https://www.theverge.com/2021/4/13/22382821/fbi-doj-hafnium-remote-access-removal-hack* https://apnews.com/article/russia-safe-harbor-ransomeware-hacking-c9dab7eb3841be45dff2d93ed3102999* https://threatpost.com/critical-cloud-bug-vmware-carbon-black/165278/* https://www.theverge.com/2021/4/18/22390379/federal-investigators-breach-software-codecov-solarwinds* https://threatpost.com/google-project-zero-cuts-bug-disclosure-timeline-to-a-30-day-grace-period/165432/
Check out our Cyber Range, not just a place to work through challenges and play, but also an open direct/hands-on training environment.
https://www.blackhillsinfosec.com/services/cyber-range/
Join the BHIS Blog Mailing List – get notified when we post new blogs, webcasts, and podcasts.
Join 3,264 other subscribers
Email Address
Subscribe

Apr 14, 2021 • 39min
Talkin’ About Infosec News – 4/12/2021
Originally Aired on April 12, 2021
Articles discussed in this episode:
* https://threatpost.com/azure-functions-privilege-escalation/165307/* https://www.theverge.com/2021/4/8/22374464/linkedin-data-leak-500-million-accounts-scraped-microsoft* https://news.linkedin.com/2021/april/an-update-from-linkedin* https://www.bbc.com/news/world-middle-east-56708778* https://www.tenable.com/blog/cve-2018-13379-cve-2019-5591-cve-2020-12812-fortinet-vulnerabilities-targeted-by-apt-actors
Check out our Cyber Range, not just a place to work through challenges and play, but also an open direct/hands-on training environment.
https://www.blackhillsinfosec.com/services/cyber-range/
Join the BHIS Blog Mailing List – get notified when we post new blogs, webcasts, and podcasts.
Join 3,241 other subscribers
Email Address
Subscribe

Apr 8, 2021 • 57min
Talkin’ About Infosec News – 4/7/2021
Originally Aired on April 7, 2021
Articles discussed in this episode:
* https://www.scmagazine.com/home/security-news/phishing/array-of-recent-phishing-schemes-use-personalized-job-lures-voice-manipulation/* https://www.coindesk.com/hackers-mined-crypto-on-githubs-servers-report* https://www.securityweek.com/white-hats-earn-440000-hacking-microsoft-products-first-day-pwn2own-2021* https://www.infosecurity-magazine.com/news/consulting-firm-data-breach/* https://github.com/Neo23x0/Raccine* https://github.com/ralphte/build_a_phish* https://support.microsoft.com/en-us/windows/protect-your-pc-from-ransomware-08ed68a7-939f-726c-7e84-a72ba92c01c3* https://www.infosecurity-magazine.com/news/florida-school-district-40m-ransom/
Check out our Cyber Range, not just a place to work through challenges and play, but also an open direct/hands-on training environment.
https://www.blackhillsinfosec.com/services/cyber-range/
Join the BHIS Blog Mailing List – get notified when we post new blogs, webcasts, and podcasts.
Join 3,208 other subscribers
Email Address
Subscribe

Apr 6, 2021 • 57min
Talkin’ About Infosec News – 4/5/2021
Originally Aired on April 5, 2021
Articles discussed in this episode:
* https://www.bleepingcomputer.com/news/security/533-million-facebook-users-phone-numbers-leaked-on-hacker-forum/* https://krebsonsecurity.com/2021/03/whistleblower-ubiquiti-breach-catastrophic/* https://threatpost.com/call-of-duty-cheats-gamers-malware/165209/* https://outflank.nl/services/outflank-security-tooling/* https://thehackernews.com/2021/04/22-year-old-charged-with-hacking-water.html* https://www.paulosyibelo.com/2021/04/this-man-thought-opening-txt-file-is.html
Check out our Cyber Range, not just a place to work through challenges and play, but also an open direct/hands-on training environment.
https://www.blackhillsinfosec.com/services/cyber-range/
Join the BHIS Blog Mailing List – get notified when we post new blogs, webcasts, and podcasts.
Join 3,198 other subscribers
Email Address
Subscribe

Mar 31, 2021 • 50min
Talkin’ About Infosec News – 3/29/2021
Originally Aired on March 29, 2021
Articles discussed in this episode:
* https://www.bleepingcomputer.com/news/security/engineer-reports-data-leak-to-nonprofit-hears-from-the-police/* https://thehackernews.com/2021/03/solarwinds-orion-vulnerability.html* https://thehackernews.com/2021/03/apple-issues-urgent-patch-update-for.html* https://unit42.paloaltonetworks.com/malicious-cryptojacking-images/
Check out our Cyber Range, not just a place to work through challenges and play, but also an open direct/hands-on training environment.
https://www.blackhillsinfosec.com/services/cyber-range/
Join the BHIS Blog Mailing List – get notified when we post new blogs, webcasts, and podcasts.
Join 3,178 other subscribers
Email Address
Subscribe

Mar 29, 2021 • 38min
Talkin’ About Infosec News – 3/24/2021
Originally Aired on March 24, 2021
Articles discussed in this episode:
* https://www.theverge.com/2021/3/22/22345792/microsoft-discord-acquisition-report-10-billion* https://krebsonsecurity.com/2021/03/weleakinfo-leaked-customer-payment-info/* https://grahamcluley.com/police-raid-apartment-alleged-verkada-hacker/
Check out our Cyber Range, not just a place to work through challenges and play, but also an open direct/hands-on training environment.
https://www.blackhillsinfosec.com/services/cyber-range/
Join the BHIS Blog Mailing List – get notified when we post new blogs, webcasts, and podcasts.
Join 3,176 other subscribers
Email Address
Subscribe

Mar 25, 2021 • 1h 41min
Webcast: OPSEC Fundamentals for Remote Red Teams
During remote red team exercises, it can be difficult to keep from leaking information to the target organization’s security team. Every interaction with the target’s website, every email sent, and every network service probed leaves some trace that the red team was there.
Mature blue teams can correlate those pieces of information to identify red team actions and infrastructure, and use that information to either block the red team outright or execute deception operations to frustrate further attacks.
In this Black Hills Information Security (BHIS) webcast, Michael will discuss common sources of data leakage during remote red team exercises and steps red teamers can take to eliminate or disguise the leakage outright, or to compartmentalize their actions and keep the blue team from connecting the dots.
He’ll also discuss how red teamers can see the attack from the defender’s point of view so that these concepts can be applied to new tools and technologies in the future.
Join the BHIS Community Discord: https://discord.gg/bhis
0:00:00 – PreShow Banter™ — It’s Not Delivery, Its Frozen
0:09:36 – PreShow Banter™ — One Rural to Rule Them All
0:11:51 – PreShow Banter™ — Proudly Sucking at Charity
0:13:08 – PreShow Banter™ — SPECIAL GUEST: Rural Tech Fund
0:20:39 – PreShow Banter™ — Meth Lab For Computers
0:25:41 – FEATURE PRESENTATION: OPSEC Fundamentals for Remote Red Teams
0:27:00 – WHOAMI
0:30:42 – Why OPSEC is Important For Red Teams
0:34:01 – Possible Countermeasures
0:36:37 – Other Red Team Threats
0:38:06 – Assessing Red Team Actions
(00:00) - PreShow Banter™ — It's Not Delivery, Its Frozen
(09:36) - PreShow Banter™ — One Rural to Rule Them All
(11:51) - PreShow Banter™ — Proudly Sucking at Charity
(13:08) - PreShow Banter™ — SPECIAL GUEST: Rural Tech Fund
(20:39) - PreShow Banter™ — Meth Lab For Computies
(25:41) - FEATURE PRESENTATION: OPSEC Fundamentals for Remote Red Teams
(26:59) - WHOAMI
(30:42) - Why OPSEC is Important For Red Teams
(34:01) - Possible Countermeasures
(36:37) - Other Red Team Threats
(38:06) - Assessing Red Team Actions
(39:26) - Building OPSEC Standard Procedures
(40:42) - Local Workstation Setup
(45:01) - OS Modifications
(49:44) - TOOL Configurations
(56:35) - Source IP Addresses
(01:01:36) - Fail-Safe VPN
(01:02:57) - Other Third-Party Services
(01:10:05) - Network Services
(01:15:19) - Testing New Tools
(01:21:42) - Got Questions
(01:27:03) - PostShow Banter™ — Access Granted

Mar 23, 2021 • 41min
Talkin’ About Infosec News – 3/22/2021
Originally Aired on March 22, 2021
Articles discussed in this episode:
* https://threatpost.com/google-spectre-poc-exploit-chrome/164787/* https://threatpost.com/office-365-phishing-attack-financial-execs/164925/* https://krebsonsecurity.com/2021/03/weleakinfo-leaked-customer-payment-info/* https://arstechnica.com/gadgets/2021/03/critics-fume-after-github-removes-exploit-code-for-exchange-vulnerabilities/* https://arstechnica.com/information-technology/2021/03/expert-hackers-used-11-zerodays-to-infect-windows-ios-and-android-users/
Check out our Cyber Range, not just a place to work through challenges and play, but also an open direct/hands-on training environment.
https://www.blackhillsinfosec.com/services/cyber-range/
Join the BHIS Blog Mailing List – get notified when we post new blogs, webcasts, and podcasts.
Join 3,168 other subscribers
Email Address
Subscribe
(00:00) - Intro
(01:00) - Critics fume after Github removes exploit code for Exchange vulnerabilities
(17:44) - Google Releases Spectre PoC Exploit For Chrome
(28:40) - “Expert” hackers used 11 0-days to infect Windows, iOS, and Android users

Mar 19, 2021 • 48min
Talkin’ About Infosec News – 3/17/2021
Originally Aired on March 17, 2021
Articles discussed in this episode:
* https://www.bloomberg.com/news/articles/2021-03-09/hackers-expose-tesla-jails-in-breach-of-150-000-security-cams* https://media.cert.europa.eu/static/SecurityAdvisories/2021/CERT-EU-SA2021-014.pdf* https://security.googleblog.com/2021/03/introducing-sigstore-easy-code-signing.html* https://krebsonsecurity.com/2021/03/weleakinfo-leaked-customer-payment-info/* https://twitter.com/PythonResponder/status/1372023079719817218?s=20
Check out our Cyber Range, not just a place to work through challenges and play, but also an open direct/hands-on training environment.
https://www.blackhillsinfosec.com/services/cyber-range/
Join the BHIS Blog Mailing List – get notified when we post new blogs, webcasts, and podcasts.
Join 3,163 other subscribers
Email Address
Subscribe

Mar 18, 2021 • 46min
Backdoors & Breaches LIVE - 3/10/2021
The Livestream of our first Backdoors & Breaches (B&B) session using our new Tabletop Simulator (TTS) version of the game was a success! If you have STEAM / TABLETOP SIMULATOR / BACKDOORS & BREACHES WORKSHOP, you can play using the same version of the game.
11:05 – Backdoors & Breaches Session Begins!
Our good friend Edward Miro wrote an extensive guide on how to install and use B&B on TTS. Check it out below!
https://www.blackhillsinfosec.com/backdoors-breaches-tabletop-simulator-guide/
Join the BHIS Blog Mailing List – get notified when we post new blogs, webcasts, and podcasts.
Join 3,144 other subscribers
Email Address
Subscribe


