
CyberWire Daily Cyberespionage in East and Southeast Asia, for both intelligence collection and domestic security, Spyware tools tracked. Shifting cyber targets in Russia’s hybrid war. Securing the Super Bowl.
Sep 25, 2023
Amit Sinha, CEO of Digicert, talks about digital trust in the software supply chain. The podcast also covers cyberespionage activities in East and Southeast Asia, including campaigns against Tibetan, Uighur, and Taiwanese targets. It discusses the use of Telegram groups to share spyware tools and the discovery of new backdoors. The episode highlights the importance of security coaching and incident detection. It also explores the risks of code signing key leaks and the need to inspect the software development supply chain. The podcast concludes with speculation on a recent ransomware incident and the challenges of incident analysis.
Chapters
Transcript
Episode notes
1 2 3 4 5 6 7
Introduction
00:00 • 4min
Telegram Groups and New Spyware Tools
04:06 • 5min
Security Coaching and Enhancing Incident Detection
09:03 • 7min
Leaked Code Signing Keys and the Importance of Protecting Them
15:35 • 2min
Inspecting the Software Development Supply Chain and the Risks of Not Scanning Packages
17:49 • 4min
Speculation on Ransomware and Social Engineering Incident
22:01 • 4min
Analyzing a Recent Incident
26:29 • 6min
