Risky Business #756 -- Move fast and break everything
Jul 24, 2024
auto_awesome
In this podcast, they discuss CrowdStrike's faulty update affecting millions, AT&T's breached call records, Squarespace's domain hijack, and SolarWinds' SEC case. They also cover cybercriminal incidents, Ukraine malware attack, and Disney Slack dumps. Internet Explorer vulnerabilities resurface, and email security platform Sublime Security is highlighted. The podcast delves into shadow SaaS accounts, ICS malware attacks, ransomware costs, and efficient email security management.
Implementing customizable email security rules based on business context enhances security measures beyond standard solutions.
Integrating TruffleHog for secrets detection in emails broadens security scope and ensures sensitive information protection.
Automated ingestion of user-reported phishing emails through API streamlines investigation, enabling faster response and reducing cognitive load.
Deep dives
Extensibility and Customization in Email Security Rules
Being able to customize email security rules based on business context and the extensibility of Sublime Security's platform allows for more advanced and configurable email security measures. JJ Agha highlights the importance of having the ability to tailor rules for VIPs and specific business needs to enhance security beyond standard off-the-shelf solutions.
Integration with TruffleHog for Secrets Detection
Integrating TruffleHog for secrets detection in outbound and internal emails broadens the security scope and ensures a higher level of email security. The workflow involves passing potential secrets for validation, potentially blocking or removing sensitive information in emails.
Automated Phishing Reporting and Response
Sublime Security's API-based product allows for automated ingestion of user-reported phishing emails directly from mail providers like O365 or Google Workspace. This automation streamlines the investigation and triaging process, enabling swift responses and reducing the cognitive load on security teams.
Efficiency in User Report Investigations
Automated investigation and response capabilities for user-reported emails help save time and resources by efficiently validating the severity of reported emails. This automation accelerates response times, allowing security analysts to focus on more complex security issues.
Improving Analyst Focus with Automated Remediation
The implementation of Sublime Security reduced manual remediation tasks, freeing up analysts' time to address critical security challenges. This automation optimized operational efficiency, empowering analysts to focus on higher-priority security threats and strategic security initiatives.
The Risky Biz main show returns from a break to the traditional internet-melting mess that happens whenever Patrick Gray takes a holiday. Pat and Adam Boileau talk through the week’s security news, including:
Oh Crowdstrike, no, oh no, honey, no
AT&T stored call records on Snowflake and you’ll never guess what happened next
Squarespace buys Google Domains and makes a hash of it
Some but not all of the SECs case against Solarwinds gets thrown out
Pity the incident responders digging through a terabyte of Disney Slack dumps
Internet Explorer rises from the grave, and it wants SHELLS RAAAAARGH SSHHEEELLLS
And much, much more.
This week’s show is brought to you by Sublime Security, a flexible and modern email security platform. If you’re sick of using a black box email security solution, Sublime is a terrific option for you.