

Talkin' Bout [Infosec] News
Black Hills Information Security
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
Join us live on YouTube, Monday's at 4:30PM ET
Join us live on YouTube, Monday's at 4:30PM ET
Episodes
Mentioned books

Feb 17, 2023 • 1h 4min
Talkin’ About Infosec News – 2/17/2023
00:00 – PreShow Banter™ — Scalping Valentine’s Day Reservations04:13 – BHIS – Talkin’ Bout [infosec] News 2023-06-2305:52 – Story # 1: 5 Chinese companies and a research institute blacklisted by […]
The post Talkin’ About Infosec News – 2/17/2023 appeared first on Black Hills Information Security.
(00:00) - PreShow Banter™ — Scalping Valentine's Day Reservations
(04:13) - BHIS - Talkin' Bout [infosec] News 2023-06-23
(05:52) - Story # 1: 5 Chinese companies and a research institute blacklisted by U.S. over spy balloon program
(12:00) - Story # 2: We had a security incident. Here’s what we know.
(15:19) - Ean Reports Live!
(21:44) - Story # 3: NameCheap's email hacked to send Metamask, DHL phishing emails
(26:49) - Story # 4: Top mobile finance app Money Lover has some worrying security flaws
(31:24) - Story # 5: Ukraine war: Elon Musk's SpaceX firm bars Kyiv from using Starlink tech for drone control
(36:58) - Story # 6: NATO websites hacked, including that of the Headquarters of Special Operations Forces
(38:58) - Story # 7: Khinshtein said that hackers acting in the interests of the Russian Federation should be released from liability
(40:52) - Story # 8 NIST Standardizes Ascon Cryptographic Algorithm for IoT and Other Lightweight Devices
(43:29) - Story # 9: Americans don't understand what companies can do with their personal data—and that's a problem
(45:15) - Story # 9b: AMERICANS CAN’T CONSENT TO COMPANIES’ USE OF THEIR DATA
(54:33) - Story # 10: Pentagon Staffers Found Installing Dating Apps, Games on Government Phones
(57:34) - Story # 10b: Management Advisory: The DoD’s Use of Mobile Applications (Report No. DODIG-2023-041)
(58:14) - Story # 11: When Facebook came for your battery, feudal security failed

Feb 13, 2023 • 1h 1min
Talkin’ About Infosec News – 2/13/2023
00:00 – PreShow Banter™ — We’ve got nothing to say03:07 – BHIS – Talkin’ Bout [infosec] News 2023-06-2305:56 – Story # 1: Cybercrime job ads on the dark web pay […]
The post Talkin’ About Infosec News – 2/13/2023 appeared first on Black Hills Information Security.
(00:00) - PreShow Banter™ — We've got nothing to say
(03:07) - BHIS - Talkin' Bout [infosec] News 2023-06-23
(05:56) - Story # 1: Cybercrime job ads on the dark web pay up to $20k per month
(10:52) - Story # 2: Discrepancies Discovered in Vulnerability Severity Ratings
(25:27) - Story # 3: GitHub Breach: Hackers Stole Code-Signing Certificates for GitHub Desktop and Atom
(28:48) - Story # 4: Ex-Ubiquiti worker pleads guilty to data theft, extortion, and smear plot
(34:47) - Story # 5: North Korean hackers stole research data in two-month-long breach
(42:19) - Story # 6: Hacker Group Releases 128GB Of Data Showing Russia's 'Wide-Ranging' Illegal Surveillance Of Citizens

Feb 3, 2023 • 1h 1min
Talkin’ About Infosec News – 2/3/2023
00:00 – PreShow Banter™ — Woke Up Like This03:20 – BHIS – Talkin’ Bout [infosec] News 2023-01-3005:04 – Story # 1: GoTo says hackers stole customers’ backups and encryption keyhttps://www.bleepingcomputer.com/news/security/goto-says-hackers-stole-customers-backups-and-encryption-key/09:48 […]
The post Talkin’ About Infosec News – 2/3/2023 appeared first on Black Hills Information Security.
(00:00) - PreShow Banter™ — Woke Up Like This
(03:20) - BHIS - Talkin' Bout [infosec] News 2023-01-30
(05:04) - Story # 1: GoTo says hackers stole customers' backups and encryption key
(09:48) - Story # 2: T-Mobile hacked to steal data of 37 million accounts in API data breach
(11:29) - Story # 3: Appliance makers sad that 50% of customers won’t connect smart appliances
(23:11) - Story # 4: More Ransomware Victims Are Refusing to Pay Hackers
(25:34) - Story # 5: DOJ, FBI hack Hive Network, save US$130 mln from crypto ransomware attacks
(27:27) - Story # 6: Ransomware gang steals data from KFC, Taco Bell, and Pizza Hut brand owner
(29:35) - Story # 7: Pet fish commits credit card fraud on owner using a Nintendo Switch
(34:15) - Story # 8: how to completely own an airline in 3 easy steps
(38:43) - Story # 9: Nearly 35,000 PayPal users had SSNs, tax info leaked during December cyberattack
(46:43) - Story # 10: The semiconductor monopoly: How one Dutch company has a stranglehold over the global chip industry
(55:59) - Story # 11: Swipe right on our new credit card tokens!

Jan 25, 2023 • 1h 5min
Talkin’ About Infosec News – 1/25/2023
00:00 – PreShow Banter™ — Wade’s Googly Eyes00:41 – BHIS – Talkin’ Bout [infosec] News 2023-01-2301:26 – Story # 1: BIG TECH LAYOFFS. LAYOFFS! DOOM! RECESSION!
The post Talkin’ About Infosec News – 1/25/2023 appeared first on Black Hills Information Security.
(00:00) - PreShow Banter™ — Wade's Googly Eyes
(00:41) - BHIS - Talkin' Bout [infosec] News 2023-01-23
(01:26) - Story # 1: BIG TECH LAYOFFS. LAYOFFS! DOOM! RECESSION!

Jan 17, 2023 • 58min
Talkin’ About Infosec News – 1/17/2023
00:00 – PreShow Banter™ — Ralph’s Guide to Satellite Bands 04:33 – BHIS – Talkin’ Bout [infosec] News 2023-01-16 05:25 – Story # 1: Microsoft’s new AI can simulate anyone’s […]
The post Talkin’ About Infosec News – 1/17/2023 appeared first on Black Hills Information Security.
(00:00) - PreShow Banter™ — Ralph’s Guide to Satellite Bands
(04:33) - BHIS - Talkin' Bout [infosec] News 2023-01-16
(05:25) - Story # 1: Microsoft’s new AI can simulate anyone’s voice with 3 seconds of audio
(13:29) - Story # 2: Russian Hackers Tried to Break Into the U.S.'s Top Nuclear Labs: Report
(16:42) - Story # 3: CircleCI breach post-mortem: Attackers got in by stealing engineer’s session cookie
(26:59) - Story # 4: How a single developer dropped AWS costs by 90%, then disappeared
(36:46) - Story # 5: A Widespread Logic Controller Flaw Raises the Specter of Stuxnet
(48:38) - Story # 6: Meta sues “scraping-for-hire” service that sells user data to law enforcement

Jan 12, 2023 • 52min
Talkin’ About Infosec News – 1/12/2023
00:00 – PreShow Banter™ — Twitch Airways International00:59 – BHIS – Talkin’ Bout [infosec] News 2023-01-1003:56 – Story # 1: How ChatGPT could become a hacker’s friendhttps://betanews.com/2023/01/05/how-chatgpt-could-become-a-hackers-friend/14:05 – Story # […]
The post Talkin’ About Infosec News – 1/12/2023 appeared first on Black Hills Information Security.
(00:00) - PreShow Banter™ — Twitch Airways International
(00:59) - BHIS - Talkin' Bout [infosec] News 2023-01-10
(03:56) - Story # 1: How ChatGPT could become a hacker's friend
(14:05) - Story # 2: Cybersecurity experts gaze into the 2023 crystal ball and see good, bad, ugly
(16:40) - Story # 3: Chick-Fil-A and other Breaches to snack on
(31:01) - Story # 4: Identity Thieves Bypassed Experian Security to View Credit Reports
(36:29) - Story # 5: CircleCI security alert: Rotate any secrets stored in CircleCI (Updated Jan 7)
(40:45) - Story # 6: Air France and KLM notify customers of account hacks
(43:27) - Story # 7: Guardian offices closed until 23 January due to ongoing fallout from suspected ransomware attack

Jan 3, 2023 • 55min
Talkin’ About Infosec News – 1/3/2023
00:00 – PreShow Banter™ — Seven People00:51 – BHIS – Talkin’ Bout [infosec] News 2023-01-0201:37 – Story # 1: LastPass Admits to Severe Data Breach, Encrypted Password Vaults Stolenhttps://www.theverge.com/2022/12/28/23529547/lastpass-vault-breach-disclosure-encryption-cybersecurity-rebuttal32:22 – […]
The post Talkin’ About Infosec News – 1/3/2023 appeared first on Black Hills Information Security.
(00:00) - PreShow Banter™ — Seven People
(00:51) - BHIS - Talkin' Bout [infosec] News 2023-01-02
(01:37) - Story # 1: LastPass Admits to Severe Data Breach, Encrypted Password Vaults Stolen
(32:22) - Story # 2: Southwest Airlines’ post-Christmas meltdown thanks to ‘outdated IT’ systems, poor scheduling
(42:18) - Story # 3: McGraw Hill's S3 buckets exposed 100,000 students' grades
(47:59) - Story # 4: Okta confirms another breach after hackers steal source code

Dec 21, 2022 • 59min
Talkin’ About Infosec News – 12/21/2022
00:00 – PreShow Banter™ — Talkin’ Bout [Elon] News00:51 – BHIS – Talkin’ Bout [infosec] News 2022-12-1902:46 – Story # 1: Antivirus and EDR solutions tricked into acting as data […]
The post Talkin’ About Infosec News – 12/21/2022 appeared first on Black Hills Information Security.
(00:00) - PreShow Banter™ — Talkin' Bout [Elon] News
(00:51) - BHIS - Talkin' Bout [infosec] News 2022-12-19
(02:46) - Story # 1 : Antivirus and EDR solutions tricked into acting as data wipers
(12:11) - Story # 2: Twitter suspends @ElonJet after Musk promises not to ban it
(12:48) - Story # 2b: Elon Musk starts banning critical journalists from Twitter
(14:37) - Story # 2c: Twitter abruptly bans all links to Instagram, Mastodon, and other competitors
(15:08) - Story # 2d: Elon Musk should step down as head of Twitter, says poll
(16:18) - Story # 2e: Your Car is Trackable by Law
(22:41) - Story # 2f: AirNav RadarBox FlightStick - ADS-B USB Receiver with Integrated Filter, Amplifier and ESD Protection
(26:41) - Story # 3: FBI’s Vetted Info Sharing Network ‘InfraGard’ Hacked
(32:24) - Story # 4: Reno mayor sues after finding tracking device on vehicle
(36:43) - Story # 5: Email hijackers scam food out of businesses, not just money
(42:46) - Story # 6: Bugs in LEGO Resale Site Allowed Hackers to Hijack Accounts
(45:41) - Story # 7: CISA Alert: Veeam Backup and Replication Vulnerabilities Being Exploited in Attacks
(50:05) - Story # 8: CISA researchers: Russia's Fancy Bear infiltrated US satellite network

Dec 15, 2022 • 52min
Talkin’ About Infosec News – 12/15/2022
00:00 – PreShow Banter™ — Scissors Vs Paper00:15 – BHIS – Talkin’ Bout [infosec] News 2022-12-1202:12 – Story # 1: Rackspace confirms ransomware attack behind days-long email meltdownhttps://www.theregister.com/2022/12/06/rackspace_confirms_ransomware/07:56 – Story […]
The post Talkin’ About Infosec News – 12/15/2022 appeared first on Black Hills Information Security.
(00:00) - PreShow Banter™ — Scissors Vs Paper
(00:15) - BHIS - Talkin' Bout [infosec] News 2022-12-12
(02:12) - Story # 1: Rackspace confirms ransomware attack behind days-long email meltdown
(07:56) - Story # 1b: Rackspace Hit With Lawsuits Over Ransomware Attack
(09:13) - Story # 2: Uber suffers new data breach after attack on vendor, info leaked online
(13:18) - Story # 3: Apple Plans New Encryption System to Ward Off Hackers and Protect iCloud Data
(14:20) - Story # 3b: Apple Newsroom: Apple advances user security with powerful new data protections
(16:46) - Story # 3c: FBI Calls End-to-End Encryption 'Deeply Concerning' as Privacy Groups Hail Apple's Advanced Data Protection as a Victory for Users
(21:17) - Story # 3d: Learn more about iCloud in China mainland
(22:53) - Story # 3e: Apple Kills Its Plan to Scan Your Photos for CSAM. Here’s What’s Next
(25:02) - Story # 4: Pet Dog Unmasks Drug Trafficker on Encrypted Chat
(28:34) - Story # 4b: Operation Venetic: Pet dog and accidental selfies help convict international drugs traffickers
(30:06) - Story # 5: ChatGPT
(45:43) - Story # 6: San Francisco decides killer police robots aren’t such a great idea

Dec 6, 2022 • 1h 4min
Talkin’ About Infosec News – 12/6/2022
00:00 – PreShow Banter™ — Florida Bobsledding Team01:29 – PreShow Banter™ — Open AI Phishing Campaign05:17 – BHIS – Talkin’ Bout [infosec] News 2022-12-0507:53 – Story # 1: There are […]
The post Talkin’ About Infosec News – 12/6/2022 appeared first on Black Hills Information Security.
(00:00) - PreShow Banter™ — Florida Bobsleding Team
(01:29) - PreShow Banter™ — Open AI Phishing Campaign
(05:17) - BHIS - Talkin' Bout [infosec] News 2022-12-05
(07:53) - Story # 1: There are no episodes of Darknet Diaries scheduled Q1
(09:45) - Story # 2: Elon Musk Meets With Apple CEO Tim Cook Amid Claims of Twitter App Store Dispute
(14:46) - Story # 3: Anker's Eufy Cameras Caught Uploading Content to the Cloud Without User Consent
(23:20) - Story # 3b: Eufy caught lying about local-only security cameras with footage sent to cloud, accessible in unencrypted streams
(26:54) - Story # 4: FCC faces long road in stripping Chinese tech from US telecom networks
(34:19) - Story # 5: TikTok NSFW if you work for the South Dakota government
(37:40) - Story # 6: Never-before-seen malware is nuking data in Russia’s courts and mayors’ offices
(41:56) - Story # 7: Lessons from Russia’s cyber-war in Ukraine
(44:15) - Story # 8: DHS Cyber Safety Review Board to focus on Lapsus$ hackers
(49:49) - Story # 8b: Cyber Safety Review Board to Conduct Second Review on Lapsus$
(50:42) - Story # 9: Rackspace rocked by ‘security incident’ that has taken out hosted Exchange services
(57:05) - Story # 10: Red Alert: The SFPD Want the Power to Kill with Robots


