Yaron Levi, CISO at Dolby, discusses the GoFetch vulnerability in Apple's Silicon M series chips, espionage tactics by APT 31 using family surveillance, evolution of military forces into cyberspace, rising vulnerabilities from bad input and zero-day exploits, consumer influence on online services, and empowering consumers for privacy advocacy.
Vulnerability in Apple's new Silicon chips exposes encryption keys, emphasizing the necessity of robust threat modeling.
APT 31 group's social engineering tactics target high-ranking officials' family members, showcasing evolving cyber threat strategies.
Deep dives
Apple Silicon Vulnerability
Academic researchers discovered a vulnerability in Apple's new Silicon M series chips that allows hackers to access secret encryption keys on Apple computers. Named GoFetch, the vulnerability is unpatchable due to the chip architecture. This highlights the importance of thorough threat modeling and the challenges of hardening hardware against such vulnerabilities.
Chinese Hacking Tactics
APT 31 hacking group used an unconventional tactic of targeting family members of high-ranking US government officials with malicious emails to gain access to networks. This tactic underscores the risks of social engineering and showcases the evolving strategies of cyber threat actors.
MFA Bombing Attacks on Apple Users
Phishing attacks targeting Apple users involve a bug in Apple's password reset feature, prompting victims with multi-factor authentication alerts. Scammers also resort to calling targets, posing as Apple support. Apple's apparent lack of response raises concerns about the effectiveness of mitigating such attacks and the need for improved security measures.
Ready to reduce your risk without taking any? Try Varonis’ free data risk assessment. It takes minutes to set up and in 24 hours you’ll have a clear, risk-based view of the data that matters most and a clear path to automated remediation. Get started for free today at varonis.com/cisoseries.
All links and the video of this episode can be found on CISO Series.com
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode