Artwork

Content provided by ACI Learning. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by ACI Learning or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

363: ShinyHunters behind Ticketmaster Breach?! (Half a Billion Customers Exposed!)

1:10:35
 
Share
 

Manage episode 422279493 series 3043211
Content provided by ACI Learning. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by ACI Learning or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.

Daniel is back and the Technado studio got a makeover! We kick off the show with some breaking news: TikTok accounts are being compromised through a zero-click DM attack, and over 360 million stolen accounts were leaked on Telegram cybercrime channels.

After our breaking news segment, we cover Bring Me The Horizon's hacking-themed website promoting their new album (spoiler alert: the website itself got hacked). Then, over half a million SOHO routers were remotely bricked - but we still don't know who did it or why.

In Linux news, hackers are packing malware with Kiteshield to avoid AV detection. CISA also issued an alert to federal agencies to patch an actively exploited (high-severity!) Linux kernel flaw.

After a quick break, it's time for Deja News! The upcoming Windows AI Recall feature has more haters every day: researchers are now calling it a security "disaster." BreachForums is back online thanks to a threat actor known as ShinyHunters (who also claims to be responsible for this week's Ticketmaster and Santander breaches). To wrap up the segment, Okta is warning (again) about credential-stuffing attacks targeting its CIC authentication offering.

In happier news, the US DoJ led an international operation to take down the world's largest botnet, and the man responsible has been arrested. And to wrap up the show, Cox Communications patched an auth-bypass bug that could have been disastrous - thanks to an independent security researcher.

Check out the stories Daniel and Sophie covered below:
https://thehackernews.com/2024/06/celebrity-tiktok-accounts-compromised.html
https://www.bleepingcomputer.com/news/security/361-million-stolen-accounts-leaked-on-telegram-added-to-hibp/
https://techcrunch.com/2024/05/28/rock-bands-hidden-hacking-themed-website-gets-hacked/
https://www.theregister.com/2024/05/31/pumoking_eclipse_remote_router_attack/
https://gbhackers.com/kite-shield-packer-abused/
https://thehackernews.com/2024/05/cisa-alerts-federal-agencies-to-pat

  continue reading

340 episodes

Artwork
iconShare
 
Manage episode 422279493 series 3043211
Content provided by ACI Learning. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by ACI Learning or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.

Daniel is back and the Technado studio got a makeover! We kick off the show with some breaking news: TikTok accounts are being compromised through a zero-click DM attack, and over 360 million stolen accounts were leaked on Telegram cybercrime channels.

After our breaking news segment, we cover Bring Me The Horizon's hacking-themed website promoting their new album (spoiler alert: the website itself got hacked). Then, over half a million SOHO routers were remotely bricked - but we still don't know who did it or why.

In Linux news, hackers are packing malware with Kiteshield to avoid AV detection. CISA also issued an alert to federal agencies to patch an actively exploited (high-severity!) Linux kernel flaw.

After a quick break, it's time for Deja News! The upcoming Windows AI Recall feature has more haters every day: researchers are now calling it a security "disaster." BreachForums is back online thanks to a threat actor known as ShinyHunters (who also claims to be responsible for this week's Ticketmaster and Santander breaches). To wrap up the segment, Okta is warning (again) about credential-stuffing attacks targeting its CIC authentication offering.

In happier news, the US DoJ led an international operation to take down the world's largest botnet, and the man responsible has been arrested. And to wrap up the show, Cox Communications patched an auth-bypass bug that could have been disastrous - thanks to an independent security researcher.

Check out the stories Daniel and Sophie covered below:
https://thehackernews.com/2024/06/celebrity-tiktok-accounts-compromised.html
https://www.bleepingcomputer.com/news/security/361-million-stolen-accounts-leaked-on-telegram-added-to-hibp/
https://techcrunch.com/2024/05/28/rock-bands-hidden-hacking-themed-website-gets-hacked/
https://www.theregister.com/2024/05/31/pumoking_eclipse_remote_router_attack/
https://gbhackers.com/kite-shield-packer-abused/
https://thehackernews.com/2024/05/cisa-alerts-federal-agencies-to-pat

  continue reading

340 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Quick Reference Guide