David Bombal cover image

David Bombal

#468: You have to look out for these hacks in 2024! (plus get FREE training)

May 21, 2024
43:57
Big thank you to Cisco for sponsoring this video! (And for the FREE Ethical Hacking Training!) // Free Ethical Hacking course // Free Ethical Hacking course: https://skillsforall.com/course/ethic... // Talos Report // 2024 Q1 Trends: https://blog.talosintelligence.com/ta... These are the threats you need to be aware of in 2024 from the Talos Report: * Talos IR also observed a variety of threats in engagements, including data theft extortion, brute-force activ- ity targeting VPNs, and the previously seen commodity loader Gootloader. * Talos IR responded to new variants of Phobos and Akira ransomware for the first time this quarter as well as the previously seen LockBit and Black Basta ransomware operations. * A recent Talos IR engagement suggests that Akira has returned to using encryption as an additional extortion method, now deploying a multipronged attack strategy to target Windows and Linux ma- chines. * Security researchers discovered an MFA bypassing phishing kit called “Tycoon 2FA” that has since become one of the most widespread phishing kits. However, this has yet to appear in any Talos IR engagements. Firewalls getting hacked: ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices: https://blog.talosintelligence.com/ar... AI voice cloning: The use of voice cloning of voice mails to sound authentic. Attackers use voice clones to phone help desk and reset passwords etc. 2FA is a major issue: "Users accepting unauthorized MFA push notifications was the top observed security weakness, accounting for 25 percent of engagements this quarter. The lack of proper MFA implementation closely followed, accounting for 21 percent of engagements, a 44 percent decrease from the previous quarter" // Martin Lee’s SOCIAL // Twitter / X: / mlee_security LinkedIn: / martinlee Talos Blog: http://blogs.cisco.com/tag/trac/ Security Website: https://sec.cloudapps.cisco.com/secur... Cisco Blog: https://blogs.cisco.com/author/martinlee // Book // Cyber Threat Intelligence by Martin Lee: USA: https://amzn.to/4dJ2LQj UK: https://amzn.to/3K3TqVH // Articles MENTIONED // Talos Incident Response Threat Summary for Jan- March 2024: https://blog.talosintelligence.com/co... // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MY STUFF // https://www.amazon.com/shop/davidbombal Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #ai #iphone #android

Get the Snipd
podcast app

Unlock the knowledge in podcasts with the podcast player of the future.
App store bannerPlay store banner

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode

Save any
moment

Hear something you like? Tap your headphones to save it with AI-generated key takeaways

Share
& Export

Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode