Cybersecurity experts Chris Krebs and Dmitri Alperovitch discuss SEC action, AI Executive Order, CitrixBleed exploit, Kaspersky's iOS 0day, and Elon Musk's ventures. Greynoise CEO Andrew Morris talks about using language models to analyze malicious internet traffic.
CISO accountability highlighted by SolarWinds SEC enforcement action prompts industry scrutiny on cybersecurity preparedness.
Biden's AI executive order signifies a comprehensive approach to governance, emphasizing model safety, industry protection, and technical standards.
Kaspersky's research on sophisticated malware posing as a crypto miner showcases threat actors' evasive tactics, challenging defense mechanisms.
Deep dives
Response to SolarWinds SEC Enforcement Action
The recent SEC enforcement action against SolarWinds and the SolarWinds CISO has led to significant repercussions in the industry. The action raises concerns about the accountability and preparedness of CISOs in publicly traded companies, emphasizing the need for robust cybersecurity measures. Companies may experience a chilling effect on risk tolerance, potential turnover in CISO roles, and scrutiny on security policies and insurance coverage.
Analysis of Executive Order on AI
The executive order on AI has sparked discussions within policy circles, highlighting the evolving landscape of technology and policy. The comprehensive nature of the order, spanning various agencies and issues related to AI, indicates a thorough and strategic approach to governing AI technologies. The order's focus on model safety, industry protection, and technical standards underscores the importance of addressing AI governance proactively.
Uncovering Intriguing Malware Campaigns
Kaspersky's research unveiling a malware campaign masquerading as a crypto miner reveals sophisticated tactics used by threat actors. The malware's concealment as a coin miner showcases a trend in evasive techniques adopted by threat actors to avoid detection. By blending into noise and leveraging supply chain infiltration, threat actors enhance their covert operations, posing challenges for defenders in identifying and mitigating such threats.
North Korean Supply Chain Intrusions
North Korea's strategic approach to supply chain intrusions, as evidenced in Lazarus campaigns targeting vendors, underscores their innovative and persistent cyber capabilities. By infiltrating supply chains and leveraging access for diverse cyber operations, North Korea demonstrates a formidable threat actor profile. The complexity and impact of North Korean supply chain breaches highlight the need for enhanced cybersecurity measures and vigilance within the global supply chain ecosystem.
Terrorist Attack in Southern Israel by Hamas
The podcast discusses the large-scale terrorist attack carried out by Hamas in southern Israel. There is confusion surrounding how Hamas orchestrated such an attack, with speculation suggesting that they maintained operational security by avoiding modern technologies and communicating in person. The Israeli intelligence apparatus is questioned for missing this threat, highlighting the need for improved operational security measures to evade interception by advanced technologies.
Advanced Telemetry Analysis by Grey Noise
Grey Noise's founder and CEO, Andrew Morris, introduces 'Sift,' an innovative technology that automates the analysis of network traffic by leveraging large language models (LLMs). 'Sift' enables Grey Noise to swiftly identify and categorize new and potentially dangerous network activities, streamlining threat detection and response processes. By employing LLMs, Grey Noise aims to enhance the efficiency of detecting and mitigating cyber threats, particularly for government entities and security teams dealing with vast amounts of network data.
On this week’s show Patrick Gray talks through the news with Chris Krebs and Dmitri Alperovitch. They discuss:
The SEC enforcement action against Solarwinds’ CISO
The White House AI Executive Order
CitrixBleed exploitation goes wide
How Kaspersky captured some (likely) Five Eyes iOS 0day
Elon Musk’s Gaza Strip adventures
Much, much more
This week’s show is brought to you by Greynoise. Andrew Morris, Greynoise’s founder and CEO, is this week’s sponsor guest. He talks about how Greynoise is using large language models to help them analyse massive quantities of malicious internet traffic.