Week in Review: CrowdStrike releases Falcon, ransomware as terrorist threat
Aug 9, 2024
auto_awesome
DJ Schleen, a distinguished security architect at Yahoo, joins the discussion on vital cybersecurity topics. They delve into the implications of a class action lawsuit against CrowdStrike, shedding light on service reliability misunderstandings. The conversation digs deep into voting system vulnerabilities in Georgia, emphasizing the need for robust cybersecurity in elections. Schleen also shares insights on the importance of safeguarding personal and health information amidst rising cyber threats, highlighting the emotional impact on individuals.
CrowdStrike's class action lawsuit highlights the essential need for companies to implement disaster recovery plans for software updates.
The ethical concerns surrounding Jericho Pictures' data breach underscore the urgency for stricter regulations on corporate responsibility in data privacy.
Deep dives
CrowdStrike's Investor Lawsuit After Update Failures
CrowdStrike is facing a class action lawsuit from investors, primarily due to a significant outage that led to a drastic decline in its stock price. The lawsuit alleges that the company falsely claimed that its Falcon platform was thoroughly tested and validated, which was proven untrue by the recent software failure. Investors, like the Plymouth County Retirement Association, argue that this incident exemplifies negligence in the deployment of their software updates and are seeking compensatory damages for their losses. The situation underscores the critical need for companies to have disaster recovery plans in place to mitigate risks associated with software updates.
Customer Control Over Software Updates by CrowdStrike
In light of the recent incident, CrowdStrike announced it will grant customers more control over the deployment of Falcon sensor updates. This decision follows criticism regarding the reliance on auto-updating practices without customer input, which can lead to unexpected failures. While giving customers the ability to choose when to deploy updates may seem beneficial, it raises concerns about the risks associated with untested configurations that could ultimately compromise security. The conversation highlights the need for a balance between timely updates to address security vulnerabilities and the necessity for thorough testing to prevent operational disturbances.
Massive Data Breach at Jericho Pictures
Jericho Pictures, the parent company of National Public Data, faces a class action lawsuit due to a significant data breach affecting the personal information of around 3 billion individuals. This breach involved scraping data from non-public sources, raising ethical concerns about how personal data is collected and handled. The plaintiffs argue they never consented to the sharing of their personally identifiable information, placing scrutiny on corporate responsibility regarding data privacy. Experts emphasize that, as breaches become increasingly frequent, there needs to be more stringent regulations and accountability measures to ensure proper protection of consumer data.
This week’s Cyber Security Headlines – Week in Review is hosted by Rich Stroffolino with guest DJ Schleen, distinguished security architect, Yahoo
Thanks to our show sponsor, Vanta
Whether you’re starting or scaling your security program, Vanta helps you automate compliance across frameworks like SOC 2, ISO 27001, and more. With Vanta, you can streamline security reviews by automating questionnaires and demonstrating your security posture with a customer-facing Trust Center. Over 7,000 global companies like Atlassian, Flo Health, and Quora use Vanta to manage risk and prove security. Our listeners get $1,000 off at Vanta.com/headlines. That’s vanta.com/headlines.
All links and the video of this episode can be found on CISO Series.com
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode