Talkin' Bout [Infosec] News

Black Hills Information Security
undefined
Mar 10, 2021 • 1h 30min

Webcast: Sacred Cash Cow Tipping 2021

It is another year for the Sacred Cash Cow Tipping Webcast. For those of you who are new to our email list within the past year, this is a webcast where we cover the various tools and techniques that Black Hills Information Security (BHIS) uses to bypass endpoint security protections. The point of this webcast is not so much to teach people how to bypass these products, but rather to show that they can be bypassed. Hopefully, this leads to some conversations about defense-in-depth and how many vendors exaggerate their capabilities. We also discuss how simply writing signatures for specific strains of malware is a waste of time. Well, I mean, it has its place. But it is not something that should be the primary cornerstone of your security support structure.  There is a lot to unpack in this webcast, one of the main things to unpack is why we are still doing it. We are still doing this because it is still necessary. We still have vendors and CISOs perpetuating the myth that a security product can protect you from all attacks. This is an oversimplification, and it needs to be exterminated like a termite or a cockroach.  In past years we have had vendors threaten to sue… and some cooler vendors send us beer.   Hopefully, this year ends in beer. Join the BHIS Community Discord: https://discord.gg/bhis​ 0:00:00​ – PreShow Banter™ — We Love You 3000 0:02:56​ – PreShow Banter™ — SolarWinds Forever 0:07:26​ – PreShow Banter™ — Watching Bitcoins Being Mined 0:08:53​ – PreShow Banter™ — TeacherCoin™ 0:11:12​ – PreShow Banter™ — Babies’ Toys For Your Hands 0:15:45​ – FEATURE PRESENTATION: Sacred Cash Cow Tipping 2021 0:21:28​ – Ralph May: Due Diligence 0:25:42​ – Ralph May: ScareCrow 0:32:56​ – Ralph May: RDP 0:35:51​ – Marcello: Sentinel One (00:00) - PreShow Banter™ — We Love You 3000 (02:56) - PreShow Banter™ — SolarWinds Forever (07:26) - PreShow Banter™ — Watching Bitcoins Being Mined (08:53) - PreShow Banter™ — TeacherCoin™ (11:12) - PreShow Banter™ — Babies' Toys For Your Hands (14:06) - PreShow Banter™ — This is Huge (15:45) - FEATURE PRESENTATION: Sacred Cash Cow Tipping 2021 (21:28) - Ralph May: Due Dilligence (25:42) - Ralph May: ScareCrow (32:55) - Ralph May: RDP (35:50) - Marcello: Sentinel One (44:52) - Jordan Drysdale: Windows Subsystem for Linux (53:31) - Rob (mubix) Fuller: Initial Access (01:05:15) - Rob (mubix) Fuller: Post Exploitation (01:10:58) - Joff Thyer: Strip PowerShell Script Comments (01:17:49) - Joff Thyer: Build a .NET Assembly to Execute Shellcode (01:20:57) - Joff Thyer: Load/Run DLL/Assembly in PowerShell (01:23:27) - PostShow Banter™
undefined
Mar 9, 2021 • 36min

Talkin’ About Infosec News – 3/8/2021

Originally Aired on March 8, 2021 Check out our Cyber Range, not just a place to work through challenges and play, but also an open direct/hands-on training environment. https://www.blackhillsinfosec.com/services/cyber-range/ Join the BHIS Blog Mailing List – get notified when we post new blogs, webcasts, and podcasts. Join 3,118 other subscribers Email Address Subscribe
undefined
Mar 5, 2021 • 36min

Talkin’ About Infosec News – 3/3/2021

Originally Aired on March 3, 2021 Articles discussed in this episode: * https://www.msn.com/en-us/money/other/microsoft-these-exchange-server-zero-day-flaws-are-being-used-by-hackers-so-update-now/ar-BB1ec0In Check out our Cyber Range, not just a place to work through challenges and play, but also an open direct/hands-on training environment. https://www.blackhillsinfosec.com/services/cyber-range/ Join the BHIS Blog Mailing List – get notified when we post new blogs, webcasts, and podcasts. Join 3,093 other subscribers Email Address Subscribe
undefined
Mar 3, 2021 • 51min

Talkin' About Infosec News - 3/1/2021

Originally Aired on March 1, 2021 Articles discussed in this episode: * https://threatpost.com/yeezy-sneaker-bots-boost-sun/164312/* https://www.darknet.org.uk/2021/02/gitlab-watchman-audit-gitlab-for-sensitive-data-credentials/* https://www.wired.com/story/gab-hack-data-breach-ddosecrets/* https://www.cyberark.com/resources/threat-research-blog/hunting-azure-blobs-exposes-millions-of-sensitive-files* https://github.com/cyberark/blobhunter Check out our Cyber Range, not just a place to work through challenges and play, but also an open direct/hands-on training environment. https://www.blackhillsinfosec.com/services/cyber-range/ Join the BHIS Blog Mailing List – get notified when we post new blogs, webcasts, and podcasts. Join 3,084 other subscribers Email Address Subscribe
undefined
Feb 26, 2021 • 43min

Talkin' About Infosec News - 2/24/2021

Originally Aired on February 24, 2021 Articles discussed in this episode: * https://www.scmagazine.com/home/security-news/government-and-defense/fireeye-and-microsoft-execs-senators-dissect-mandatory-breach-disclosure-in-wake-of-solarwinds/* https://www.wired.com/story/russia-gru-hackers-us-grid/ Check out our Cyber Range, not just a place to work through challenges and play, but also an open direct/hands-on training environment. https://www.blackhillsinfosec.com/services/cyber-range/ Join the BHIS Blog Mailing List – get notified when we post new blogs, webcasts, and podcasts. Join 3,080 other subscribers Email Address Subscribe
undefined
Feb 23, 2021 • 34min

Talkin' About Infosec News - 2/22/2021

Originally Aired on February 22, 2021 Articles discussed in this episode: * https://www.reuters.com/article/us-northkorea-cybercrime-pfizer-idUKKBN2AG0NI* https://threatpost.com/silver-sparrow-malware-30k-macs/164121/* https://www.securityweek.com/chinese-hackers-cloned-equation-group-exploit-years-shadow-brokers-leak Check out our Cyber Range, not just a place to work through challenges and play, but also an open direct/hands-on training environment. https://www.blackhillsinfosec.com/services/cyber-range/ Join the BHIS Blog Mailing List – get notified when we post new blogs, webcasts, and podcasts. Join 3,071 other subscribers Email Address Subscribe
undefined
Feb 18, 2021 • 44min

Talkin' About Infosec News - 2/17/2021

Originally Aired on February 17, 2021 Articles discussed in this episode: * https://www.scmagazine.com/home/security-news/everyones-half-asleep-and-bosses-dont-want-trouble-the-struggle-to-secure-utilities/* https://attack.mitre.org/matrices/enterprise/* https://www.scmagazine.com/home/security-news/network-security/siem-rules-ignore-bulk-of-mitre-attck-framework-placing-risk-burden-on-users/* https://www.securityweek.com/cybercriminals-leak-files-allegedly-stolen-law-firm-jones-day Check out our Cyber Range, not just a place to work through challenges and play, but also an open direct/hands-on training environment. https://www.blackhillsinfosec.com/services/cyber-range/ Join the BHIS Blog Mailing List – get notified when we post new blogs, webcasts, and podcasts. Join 3,063 other subscribers Email Address Subscribe
undefined
Feb 9, 2021 • 45min

Talkin' About Infosec News - 2/8/2021

Originally Aired on February 8, 2021 Articles discussed in this episode: * https://threatpost.com/500-malicious-chrome-extensions-millions/152918/* https://threatpost.com/fake-forcepoint-google-chrome-extension-hacks/163728/* https://threatpost.com/industrial-networks-hackable-security-holes/163708/* https://www.reuters.com/article/us-usa-cyber-florida/hackers-broke-into-florida-towns-water-treatment-plant-attempted-poisoning-sheriff-says-idUSKBN2A82FV* https://twitter.com/SkelSec/status/1346553596855390212 Check out our Cyber Range, not just a place to work through challenges and play, but also an open direct/hands-on training environment. https://www.blackhillsinfosec.com/services/cyber-range/ Join the BHIS Blog Mailing List – get notified when we post new blogs, webcasts, and podcasts. Join 3,027 other subscribers Email Address Subscribe
undefined
Feb 2, 2021 • 1h 2min

Talkin' About Infosec News - 2/1/2021

Originally Aired on February 1, 2021 Articles discussed in this episode: * https://threatpost.com/microsoft-365-bec-innovation/163508/* https://threatpost.com/critical-libgcrypt-crypto-bug-arbitrary-code/163546/* https://www.newyorker.com/magazine/2021/02/08/the-next-cyberattack-is-already-under-way?&web_view=true Check out our Cyber Range, not just a place to work through challenges and play, but also an open direct/hands-on training environment. https://www.blackhillsinfosec.com/services/cyber-range/ Join the BHIS Blog Mailing List – get notified when we post new blogs, webcasts, and podcasts. Join 3,008 other subscribers Email Address Subscribe
undefined
Jan 26, 2021 • 31min

Talkin’ About Infosec News – 1/25/2021

ORIGINALLY AIRED ON JANUARY 25, 2021 Check out our Cyber Range, not just a place to work through challenges and play, but also an open direct/hands-on training environment. https://www.blackhillsinfosec.com/services/cyber-range/ Join the BHIS Blog Mailing List – get notified when we post new blogs, webcasts, and podcasts. Join 2,989 other subscribers Email Address Subscribe

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app