CISO Andrew Wilder joins in to discuss AI, phishing, and ransomware. Topics include privacy issues in Microsoft 365 Education, security awareness training with psychology, and the Ticketmaster hack fallout. Guest interview and sponsor acknowledgment round out the episode.
Microsoft's AI recall feature flagged for security risks due to storing data in plain text, leading to concerns over data privacy and malware exploitation.
Ticketmaster's data breach raises accountability questions for third-party cloud providers and highlights the ripple effect of breaches.
Microsoft's new AI-powered recall feature for Windows 11, designed to capture and recall user activity, was flagged by security researchers for potential security risks. The feature, storing data locally in plain text, could be exploited by attackers to extract sensitive information. Despite data encryption using BitLocker, concerns over data privacy and the potential for malware exploitation led Microsoft to make the feature opt-in rather than default.
Ticketmaster Hack and Snowflake Denial
Ticketmaster's data breach impacting over 500 million customers, attributed to unauthorized activity in a third-party cloud database managed by Snowflake, raised questions about accountability. Snowflake denied blame in both the Ticketmaster and Spanish bank breaches, hinting at a potential widespread breach collection. The incident underlines the ripple effect of breaches originating from a single vulnerable point.
FBI's Lockbit Ransomware Decryption Keys
The FBI announced possessing 7,000 decryption keys for victims affected by the Lockbit ransomware, offering assistance through the internet crime complaints center. While the keys provide a relief mechanism for victims, concerns over potential misuse or phishing scams exploiting the situation arose. The move showcases a proactive stance by law enforcement but calls for cautious handling due to cybersecurity implications.
Utah Student's Phishing Defense Program
A high school student from Utah developed VEGA, a program aimed at combating phishing attacks by inundating fraudulent sites with bogus credentials. VEGA's success in disrupting phishing operations highlights a creative approach to cybersecurity defenses. The program's potential for scalability and impact on larger security initiatives sparks discussions on novel strategies to counter cyber threats.
Why did the AI cross the road? To complete your security questionnaires for you. Conveyor, the company using market-leading AI to automate the entire security review, wants you to check them out and book a call so they can stop writing these cheesy podcast ads. If you’re ready for AI to instantly complete security questionnaires for you, visit www.conveyor.com to try a free proof of concept. Mention this podcast for 5 free questionnaire credits when you purchase a Pro plan.
All links and the video of this episode can be found on CISO Series.com
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode