Download the App!
show episodes
 
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Storm Center. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
  continue reading
 
Futurum Tech Webcast Leading tech analysts from The Futurum Group share weekly deep dives on the latest tech news, new products and services, mergers, earnings, regulations, and more. The Futurum Tech Webcast will keep you current on what’s happening in the tech space — from startups to industry leaders, emerging tech, and what’s ahead for industries across the globe, along with interviews with tech industry leaders and experts. Subscribe now and stay connected to this exciting journey into ...
  continue reading
 
Loading …
show series
 
Disabling Phish Warning; SSHAMBLE; macOS Permission Prompts; .internal Domain Exploring Anti-Phishing Measures in Microsoft 365 https://certitude.consulting/blog/en/o365-anti-phishing-measures/ SSHamble Security Testing Tool https://www.runzero.com/blog/sshamble-unexpected-exposures-in-the-secure-shell/ macOS Sequoia Weekly Permission Prompts https…
  continue reading
 
0.0.0.0 Requests; Apple Gatekeeper Changes; Windows Downgrade 0.0.0.0 Day Exploiting Localhost APIs from the Browser https://www.oligo.security/blog/0-0-0-0-day-exploiting-localhost-apis-from-the-browser Apple Hardens Gatekeeper https://developer.apple.com/news/?id=saqachfa Downgrade Attacks Using Windows Updates https://www.safebreach.com/blog/dow…
  continue reading
 
In this episode of Enterprising Insights, Futurum Group Enterprise Applications Research Director Keith Kirkpatrick discusses the recent quarterly earnings from several enterprise application vendors and provides his take on how their results are reflective of some of the larger trends in the marketplace. Then, as always, he addresses his Rant or R…
  continue reading
 
In episode 50 of Infrastructure Matters, Steven Dickens and Camberley Bates discuss recent earnings reports and trends in the infrastructure sector. They focus on Amazon Web Services' (AWS) impressive growth, Commvault's strong financial performance, Intel's strategic challenges and changes, and Kyndryl's turnaround efforts. The episode also highli…
  continue reading
 
What does it cost to recover from a disaster? While at NDC Oslo, Richard chatted with Natalie Serebryakova about her work helping companies understand their disaster recovery costs and what that process can teach you about your infrastructure. Natalie talks about different types of disasters, from the deletion of a production server to a major outa…
  continue reading
 
GeoServer Update; Crowdstrike RCA; Kibana Vuln; Android Patch Day; A Survey of Scans For GeoServer Vulnerabilities https://isc.sans.edu/diary/A%20Survey%20of%20Scans%20for%20GeoServer%20Vulnerabilities/31148 Crowdstrike Root Cause Analysis https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/ Kibana Vulnerability https://d…
  continue reading
 
Function Confusion Obfuscation; Crowdstrike LPE Vuln; New OFBiz Vuln; Roundcube XSS Vuln; Script Obfuscation Using Multiple Instances of the Same Function https://isc.sans.edu/diary/Script%20obfuscation%20using%20multiple%20instances%20of%20the%20same%20function/31144 Disclosure of key technical details of CrowdStrike's large-scale blue screen http…
  continue reading
 
Secure Boot CA; OOXML Verifier Hashes; ISP Compromises; DARPA TRACTOR; Current Secure Boot Certifiate Authority Expires in 2026 https://isc.sans.edu/diary/Even+Linux+users+should+take+a+look+at+this+Microsoft+KB+article/31140 OOXML Spreadsheets Protected by Verifier Hashes https://isc.sans.edu/diary/OOXML%20Spreadsheets%20Protected%20By%20Verifier%…
  continue reading
 
ipv4.games; Fake Google Authenticator; Sitting Ducks Domains Tracking Proxy Scans with IPv4.Games https://isc.sans.edu/diary/Tracking%20Proxy%20Scans%20with%20IPv4.Games/31136 Threat Actor Impersonates Google via Fake Ad For Authenticator https://www.malwarebytes.com/blog/news/2024/07/threat-actor-impersonates-google-via-fake-ad-for-authenticator W…
  continue reading
 
OFBiz Scans; Digicert Revocations; MSFT Azure DDoS; Google Chrome App Bound Encryption Increased Activity Against Apache OFBiz CVS-2024-32113 https://isc.sans.edu/diary/Increased%20Activity%20Against%20Apache%20OFBiz%20CVE-2024-32113/31132 Digicert Certificate Revocation Incident https://www.digicert.com/support/certificate-revocation-incident Micr…
  continue reading
 
In this episode of Infrastructure Matters, hosts Camberley Bates, Steven Dickens, and Krista Case discuss various topics including Krista's recent wedding, the CrowdStrike outage, and its implications on cybersecurity, Microsoft's East Coast Azure outage, and the recent earnings reports of IBM and Google Cloud. Krista emphasizes the importance of c…
  continue reading
 
In this episode of Enterprising Insights, host Keith Kirkpatrick discusses Salesforce’s announcement on what it says is the world’s first LLM benchmark for CRM. He discusses the elements of the benchmark, why it’s important, and assesses whether the market will start to see other benchmarks from SaaS companies or third parties begin to come to mark…
  continue reading
 
Ready to move your device certificate authority to the cloud? Richard chats with Richard Hicks about Microsoft Cloud PKI - certificate management for devices and people as part of the Intune Suite. Richard talks about it being early days for Cloud PKI, so not everything you want is there yet. The only way to get a certificate onto a device is throu…
  continue reading
 
Apple Updates; VMWare Vuln Exploited; Weak VoWiFi Encryption Apple Updates Everything: July 2024 Edition https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20July%202024%20Edition/31128 VMWare ESXi Vulnerability Actively Exploited CVE-2024-37085 https://www.microsoft.com/en-us/security/blog/2024/07/29/ransomware-operators-exploit-esxi-hypervi…
  continue reading
 
Observe, Inc CEO, Jeremy Burton, joins CMO Advisor and Host Lisa Martin on this episode of "Marketing: Art & Science". In this conversation, Jeremy shares his CEO-level perspectives and expectations of the marketing function, as he's held several signifiant CMO and CEO roles. He also discusses just how the marketing function differs at early stage …
  continue reading
 
On this episode of DevOps Dialogues: Insights & Innovations, I am joined by Guy Currier, VP & CTO of Visible Impact at The Futurum Group and Scott King, Managing Partner at Sprinter Associates for a discussion on the impacts of outsourcing skill gaps. Our conversation covers: Challenges and complexity, tech stack issues, and the impacts of skill ga…
  continue reading
 
CrowdStrike Maldoc; HotJar XSS; Proofpoint Echospoofing; CrowdStrike Outage Themed Maldoc https://isc.sans.edu/diary/CrowdStrike%20Outage%20Themed%20Maldoc/31116 HotJar XSS Puts OAuth at Risk https://salt.security/blog/over-1-million-websites-are-at-risk-of-sensitive-information-leakage---xss-is-dead-long-live-xss Proofpoint Echospoofing https://la…
  continue reading
 
ExelaStealer and more; BSOD Practice; PK Fail; @CrowdStrike Recovery; #pkfail #bsod ExelaStealer Delivered "From Russia With Love" https://isc.sans.edu/diary/31118 Create Your Own BSOD: NotMyFault https://isc.sans.edu/diary/Create%20Your%20Own%20BSOD%3A%20NotMyFault/31120 PKFail Vulnerability https://pk.fail/ CrowdStrike Recovery https://arstechnic…
  continue reading
 
XWorm Analysis; Private/Deleted GitHub Leak; Google Chrome Scanning Encrypted Files X-Worm Hidden With Process Hollowing https://isc.sans.edu/diary/XWorm%20Hidden%20With%20Process%20Hollowing/31112 Anyone Can Access Deleted and Private Repo Data on GitHub https://trufflesecurity.com/blog/anyone-can-access-deleted-and-private-repo-data-github Google…
  continue reading
 
In this episode of Enterprising Insights, host Keith Kirkpatrick discusses the state of Omnichannel Communications, delving into some statistics around the current utilization of omnichannel engagement strategies and channels, discusses a survey highlighting retailers’ use of the approach and discusses the challenges that are still facing the marke…
  continue reading
 
Mouse Logger; Crowdstrike PIR; Fake Developers; "Mouse Logger" Malicious Python Script https://isc.sans.edu/diary/%22Mouse%20Logger%22%20Malicious%20Python%20Script/31106 Crowdstrike Preliminary Post Incident Review https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/ How a North Korean Fake IT Worker Tried to Infiltrate …
  continue reading
 
How are you protecting your organization's data? Richard chats with Joanne Klein about her work with Microsoft Purview to help with data protection, management, and governance. Joanne talks about a spike in data protection concerns from Microsoft Copilot - if you have been securing data through obscurity, you're in for a nasty surprise! Copilot has…
  continue reading
 
D-Link NAS Exploit; Android Fake Video Exp; Windows Hello For Bussines Phishing; The end of OCSP; Google Cookie Update; New Exploit Variation Against D-Link NAS Devices https://isc.sans.edu/diary/New%20Exploit%20Variation%20Against%20D-Link%20NAS%20Devices%20%28CVE-2024-3273%29/31102 APKs Masquerading as Videos on Telegram https://www.welivesecurit…
  continue reading
 
On this episode of DevOps Dialogues: Insights & Innovations, I am joined by Alan Shimel, CEO and President of TechStrong Group, and Stephen Foskett, President of Tech Field Day, for a discussion on impacts of how CIOs are managing the cost of DevOps. Our conversation covers: Past, present, and future applications 24% of organizations have a desire …
  continue reading
 
CrowdStrike Update; SANSFIRE Keynote Recording; CrowdStrike Update https://isc.sans.edu/diary/CrowdStrike%3A%20The%20Monday%20After/31098 https://www.theregister.com/2024/07/21/crowdstrike_linux_crashes_restoration_tools/ Keynote Recording https://www.sans.org/services/video-player/?key=1goL2vPrltnj keywords: sansfire; keynote; crowdstrike; linux;…
  continue reading
 
Crowdstrike Configuration File Update Crashes Windows Systems @crowdstrike Widespread Windows Crashes Due to Crowdstrike Updates https://isc.sans.edu/diary/Widespread%20Windows%20Crashes%20Due%20to%20Crowdstrike%20Updates/31094 https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/ https://www.crowdstrike.com/blog/falcon-up…
  continue reading
 
Loading …

Quick Reference Guide