Player FM - Internet Radio Done Right
Checked 9M ago
Added four years ago
Content provided by ACI Learning. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by ACI Learning or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!
Go offline with the Player FM app!
Podcasts Worth a Listen
SPONSORED
N
Netflix Sports Club Podcast


1 America’s Sweethearts: Dallas Cowboys Cheerleaders Season 2 - Tryouts, Tears, & Texas 32:48
32:48
Play Later
Play Later
Lists
Like
Liked32:48
America’s Sweethearts: Dallas Cowboys Cheerleaders is back for its second season! Kay Adams welcomes the women who assemble the squad, Kelli Finglass and Judy Trammell, to the Netflix Sports Club Podcast. They discuss the emotional rollercoaster of putting together the Dallas Cowboys Cheerleaders. Judy and Kelli open up about what it means to embrace flaws in the pursuit of perfection, how they identify that winning combo of stamina and wow factor, and what it’s like to see Thunderstruck go viral. Plus, the duo shares their hopes for the future of DCC beyond the field. Netflix Sports Club Podcast Correspondent Dani Klupenger also stops by to discuss the NBA Finals, basketball’s biggest moments with Michael Jordan and LeBron, and Kevin Durant’s international dominance. Dani and Kay detail the rise of Coco Gauff’s greatness and the most exciting storylines heading into Wimbledon. We want to hear from you! Leave us a voice message at www.speakpipe.com/NetflixSportsClub Find more from the Netflix Sports Club Podcast @NetflixSports on YouTube, TikTok, Instagram, Facebook, and X. You can catch Kay Adams @heykayadams and Dani Klupenger @daniklup on IG and X. Be sure to follow Kelli Finglass and Judy Trammel @kellifinglass and @dcc_judy on IG. Hosted by Kay Adams, the Netflix Sports Club Podcast is an all-access deep dive into the Netflix Sports universe! Each episode, Adams will speak with athletes, coaches, and a rotating cycle of familiar sports correspondents to talk about a recently released Netflix Sports series. The podcast will feature hot takes, deep analysis, games, and intimate conversations. Be sure to watch, listen, and subscribe to the Netflix Sports Club Podcast on YouTube, Spotify, Tudum, or wherever you get your podcasts. New episodes on Fridays every other week.…
378: Oracle Wants its AI to Watch You...️️
Manage episode 442037738 series 3043211
Content provided by ACI Learning. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by ACI Learning or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.
Oracle AI is championing mass surveillance, Microsoft and Cisco layoffs are in the thousands, and millions of D-Link routers are impacted by a critical vulnerability. Technado: Doomsday Edition starts now.
366 episodes
Manage episode 442037738 series 3043211
Content provided by ACI Learning. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by ACI Learning or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.
Oracle AI is championing mass surveillance, Microsoft and Cisco layoffs are in the thousands, and millions of D-Link routers are impacted by a critical vulnerability. Technado: Doomsday Edition starts now.
366 episodes
All episodes
×T
Technado

1 384: Fitness App Gives Away World Leader’s Locations?! (Plus, “Black Ops 6” Staff on Strike) 1:24:56
1:24:56
Play Later
Play Later
Lists
Like
Liked1:24:56
This week on Technado, money talks: Delta and Crowdstrike are in a $500 million legal battle, Russia fined Google for $2.5 decillion, Apple’s offering a $1 million bug bounty, and LinkedIn is facing a fine of $335 million in the EU.
T
Technado

1 383: FBI Arrests Most Wanted Hacker! (Plus, Switch Game Leaks & Sega Sues!) 1:15:47
1:15:47
Play Later
Play Later
Lists
Like
Liked1:15:47
The Internet Archive breach continues, the FBI caught their most wanted hacker, and LinkedIn may be purging user accounts (?!)...all this and more in this episode of Technado.
T
Technado

1 382: Artificial Intelligence: The Good, the Bad, and the GPTHoney 1:19:39
1:19:39
Play Later
Play Later
Lists
Like
Liked1:19:39
In this AI-focused episode of Technado, Daniel and Ronnie dive into the world of artificial intelligence! From the latest news on AI's impact—both good and bad—to why it matters, they cover it all. Plus, don't miss the fun segments like Tinfoil Hat, Porkchop Sandwich, and a discussion on GPTHoney. Tune in for an insightful and entertaining look at the AI revolution!…
T
Technado

1 381: Google & TikTok in Legal Trouble! (Live from WWHF featuring Mike Saunders!) 1:04:57
1:04:57
Play Later
Play Later
Lists
Like
Liked1:04:57
Join Daniel and Sophie for a scenic episode of Technado, live from Deadwood, SD - with special guest Mike Saunders! The US is suing TikTok, the DoJ wants to break up Google, and a Switch modder is taking on Nintendo - mano a Mario. Plus, hear some insights from Mike on this year's Wild West Hackin' Fest! All this and more on this very special episode of Technado.…
T
Technado

1 380: Meta Stored Passwords in Plain Text! (Plus, Apple Backs Out of OpenAI Investment?!) 1:28:05
1:28:05
Play Later
Play Later
Lists
Like
Liked1:28:05
Put on your tinfoil hats - we get into controversial territory on this week’s episode. AI laws, Nintendo legal smackdowns, North Korean infiltration, and Kaspersky force-downloads…all this and more coming up on Technado!
T
Technado

1 379: Telegram Agrees to Turn Over User Data to Authorities?! (Plus, leaked photos of Switch 2!) 1:16:00
1:16:00
Play Later
Play Later
Lists
Like
Liked1:16:00
Hackers are impersonating your HR department! The new iOS update lets others take control of your phone through FaceTime! Kaspersky forcibly installed an unknown program on YOUR device! On this episode of Technado, never fear - Daniel and Sophie are here to shed some light on these topics.
T
Technado

1 378: Oracle Wants its AI to Watch You...️️ 1:15:46
1:15:46
Play Later
Play Later
Lists
Like
Liked1:15:46
Oracle AI is championing mass surveillance, Microsoft and Cisco layoffs are in the thousands, and millions of D-Link routers are impacted by a critical vulnerability. Technado: Doomsday Edition starts now.
T
Technado

1 377: Amazon to Use AI Clones for Audiobooks?! (Plus, Apple Releases Hearing AidPods!) 1:12:53
1:12:53
Play Later
Play Later
Lists
Like
Liked1:12:53
Schools closing in London, VSCode exploited in Asia, WIX users banned in Russia - this week, Technado is going global. Plus, we've got the latest on Apple's Glowtime event and the newest game console to hit the market.
T
Technado

1 376: Real-Life Infinite Money Glitch?! (AKA: Check Fraud for Beginners) 1:14:24
1:14:24
Play Later
Play Later
Lists
Like
Liked1:14:24
Yubico security keys can be cloned, D-Link isn't fixing critical router flaws, and an Ohio city is suing a researcher for colluding with a ransomware gang...but not all is as it seems. This week on Technado, it's time to debunk the clickbait.
T
Technado

1 375: Google Chrome Zero-Day Being EXPLOITED! (Plus, Telegram CEO Arrested?!) 1:07:53
1:07:53
Play Later
Play Later
Lists
Like
Liked1:07:53
In this week’s breaking news, South Korean spies are exploiting a popular office suite and Apache vulnerabilities are being used in attacks! Speaking of vulnerabilities, Apache isn’t the only victim: Google Chrome users, SolarWinds customers, and WordPress enjoyers beware! After the break we come back with lots of legal news: Telegram’s CEO was arrested, Georgia Tech’s getting sued, and some guy from Kentucky faked his death to…avoid child support payments? All this and more on this week’s Technado!…
T
Technado

1 374: Did your SSN get leaked?! (...probably yes) 1:09:46
1:09:46
Play Later
Play Later
Lists
Like
Liked1:09:46
A $14 million crypto heist, a breach exposing over 2 billion records, and an AMD deal worth nearly $5 billion: this week’s news cycle is putting up some big numbers! Plus, a cyberattack disrupts Microchip Technology’s manufacturing facilities, McAfee unveils a tool to sniff out deep fakes, and SteamOS may offer support for rival systems. Catch all this and more on this week’s episode of Technado!…
T
Technado

1 373: "ChatGPT Stole My Voice!" (This is SCARY!) 1:14:03
1:14:03
Play Later
Play Later
Lists
Like
Liked1:14:03
Consider it Patch Thursday, because this Technado has flaw fixes galore! Microsoft fixed 9 zero-days this week and 80 other security vulnerabilities, and 1Password has released an urgent patch for Mac users. We also talk decades-old vulnerabilities (that still have no fix), new cryptography standards released by NIST, and ChatGPT’s new tendency to…steal your voice? All this and more on this week’s Technado!…
T
Technado

This week’s episode is a special edition of Technado! Our hosts try their hand at a few video games - some from Daniel’s generation, some from Sophie’s. Tune in to see how they fare, and how games have changed over the years.
T
Technado

1 371: Meta is Removing Instagram Accounts?! (Plus, Crowdstrike Apology Backfires!) 1:13:56
1:13:56
Play Later
Play Later
Lists
Like
Liked1:13:56
Beware of new ServiceNow critical RCE bugs, a massive phishing campaign, and more outages from Microsoft! This episode is chock full of the good, bad, and ugly of AI: video game voice actors on strike, Big Tech using your data to train its chatbots, and nation-state actors using deepfake tech to snag jobs. We also have some Deja News updates featuring Kaspersky and Crowdstrike. All this and more on this week’s Technado!…
T
Technado

1 370: Crowdstrike Outage: What Happened?! (Plus, MGM Hacker Arrested!) 1:13:10
1:13:10
Play Later
Play Later
Lists
Like
Liked1:13:10
After the events of last week, there’s only one way to start this episode of Technado: Crowdstrike Update! After Daniel and Sophie go over the aftermath of the worldwide outage, we’ve got even more security news in store. The alleged hacker behind the 2023 MGM attack has been arrested, the FTC is pushing back on Xbox Game Pass price hikes, and some big companies may be using AI to price gouge consumers. All this and more in this week’s episode of Technado!…
T
Technado

1 369: Hacktivists Leak Disney Data! (Plus, Signal Finally Fixes Encryption Flaw!) 1:07:20
1:07:20
Play Later
Play Later
Lists
Like
Liked1:07:20
Breaking news: 126 updates from Google Chrome and many more patches abound! On this week's Technado, Sophie and Daniel get into hot topics like hactivism, AI, and banning Russian/Chinese companies from the states. In gaming news, CFB25 isn't even out yet, and its servers are already in shambles. All this and more await in this week's episode!…
T
Technado

1 368: Amazon Prime Day SCAM!? (Plus, HUGE Roblox Breach!) 1:03:46
1:03:46
Play Later
Play Later
Lists
Like
Liked1:03:46
It's Leak Week on Technado: Ticketmaster barcodes and Roblox customer data abound! Almost 10 billion passwords were leaked as well as part of the RockYou2024 compilation of data. In other news, European vishing fraudsters are turning up at victims' homes and Samsung workers are on strike indefinitely. All this and more on this week's episode of Technado! Check out the articles below for more on this week's stories: https://thehackernews.com/2024/07/microsofts-july-update-patches-143.html https://www.theverge.com/2024/7/10/24195541/samsung-union-launch-indefinite-strike-ai-chips-pay https://securityaffairs.com/165460/data-breach/rockyou2024-compilation-10b-passwords.html https://www.securityweek.com/ransomware-gang-leaks-data-allegedly-stolen-from-florida-department-of-... https://cybernews.com/security/amazon-prime-day-2024-phishing-attacks/ https://www.bleepingcomputer.com/news/security/hackers-leak-39-000-print-at-home-ticketmaster-ticket... https://www.darkreading.com/remote-workforce/euro-vishing-fraudsters-add-physical-intimidation-to-ar... https://www.bleepingcomputer.com/news/technology/russia-forces-apple-to-remove-dozens-of-vpn-apps-fr... https://www.cisa.gov/news-events/alerts/2024/07/08/cisa-and-partners-join-asds-acsc-release-advisory... https://gbhackers.com/roblox-data-breach/…
T
Technado

1 367: Temu App is Spyware?! (Plus, More Nintendo Lawsuits!) 1:19:21
1:19:21
Play Later
Play Later
Lists
Like
Liked1:19:21
Gamers rejoice: we've got news on Xbox, Nintendo, and Apple retro game emulators on this week's Technado! In some of our biggest stories this week, there's a new Google Chrome 0-day, Temu's getting sued, and millions of OpenSSH servers may be vulnerable to an attack. We also cover PortSwigger's very first outside investment, a biometric MFA token that doubles as a ring, and Grasshopper: a group of hackers...or pentesters...or hackers pretending to be pentesters. In other news, an Australian man was caught red-handed harvesting credentials while on a flight (yes, DURING the flight), Kadokawa Group got hit with a ransomeware attack, and Sophie and Daniel have some strong opinions on AI-generated commentator Al Michaels. For more on this week's stories, check out the articles below: https://gbhackers.com/claiming-sandboxrce-0-day/ https://www.ign.com/articles/xbox-live-suffers-widespread-outage-xbox-support-investigating https://arstechnica.com/tech-policy/2024/06/shopping-app-temu-is-dangerous-malware-spying-on-your-texts-lawsuit-claims/ https://thehackernews.com/2024/07/how-mfa-failures-are-fueling-500-surge.html https://www.techspot.com/news/103636-nintendo-sues-two-switch-hardware-software-modders.html https://securityaffairs.com/165108/cyber-crime/evil-twin-wifi-attack-plane.html https://arstechnica.com/information-technology/2024/06/ai-generated-al-michaels-to-provide-daily-recaps-during-2024-summer-olympics/ https://gbhackers.com/grasshopper-hackers-penetration-testing-malware-deployment/ https://www.ign.com/articles/fromsoftware-parent-company-hacked-by-ransomware-gang-threatening-to-release-internal-data https://www.securityweek.com/millions-of-openssh-servers-potentially-vulnerable-to-remote-regresshion-attack/ https://www.theverge.com/2024/6/24/24185066/apple-pc-dos-emulators-ios-rejection https://techcrunch.com/2024/06/27/portswigger-the-company-behind-the-burp-suite-of-security-testing-tools-swallows-112m/…
T
Technado

1 366: Julian Assange Released?! (Plus, Biden Bans Kaspersky!) 1:19:38
1:19:38
Play Later
Play Later
Lists
Like
Liked1:19:38
This week on Technado, we've got breaking news: there's a new MOVEit bug, Apple released a firmware update for AirPods, and we've got robot skin to fuel your nightmares. In one of this week's biggest stories, Julian Assange has been released and is homeward bound. SolarWinds is back in the headlines, this time with an exploited Serv-U bug. Apple, Microsoft, and several other big tech companies are in hot water for violating the EU's Digital Markets Act. Hackers are using a Windows XXS flaw to execute arbitrary commands. And to wrap the first half of the show, we take a look at the alleged breach of the US Federal Reserve and the group that's supposedly behind it. After the break, it's time for Deja News: NVIDIA's short-lived time at the top has come to an end as they suffer the biggest short-term loss in history. We may finally have an answer to the Apple-Kaspersky debacle: the Biden administration has banned the software in the US and sanctioned a dozen Kaspersky execs. Then, Google's Project Naptime is using AI to let engineers take more siestas. The ever-litigious Nintendo has officially shut down Yuzu and Citra, two big Nintendo emulators. And the CDK hack affecting car dealerships nationwide is still ongoing - and recovery may take years. Like what you heard? Check out these articles for more: https://www.darkreading.com/remote-workforce/fresh-moveit-bug-under-attack-disclosure https://thehackernews.com/2024/06/apple-patches-airpods-bluetooth.html https://techcrunch.com/2024/06/25/this-smiling-robot-face-made-of-living-skin-is-absolute-nightmare-fuel/ https://gbhackers.com/wikileaks-founder-julian-assange-released/ https://securityaffairs.com/164806/hacking/solarwinds-serv-u-cve-2024-28995-exploit.html https://www.ign.com/articles/apple-becomes-the-first-tech-company-charged-with-violating-eus-digital-markets-act-rules https://arstechnica.com/gaming/2024/06/apple-intelligence-and-other-features-wont-launch-in-the-eu-this-year/ https://www.pcgamer.com/softwa…
T
Technado

1 365: Windows Wi-Fi Takeover Attack! (Update NOW!) 1:14:14
1:14:14
Play Later
Play Later
Lists
Like
Liked1:14:14
This week's Technado starts strong with some breaking news: Nvidia has surpassed Apple and Microsoft to become the most valuable company in the world! Of course, we had to talk about Nintendo Direct, and we even took a look at the upcoming Spaceballs sequel. After our breaking news segment, Daniel warns us of a Wi-Fi takeover attack affecting Windows Users. Then, the feds are suing Adobe for some sneaky cancellation fees that are costing users hundreds. CISA conducted its first AI IR tabletop exercise, and we take a look at not one, not two, but THREE cybercriminals in Behind Bars. Following a quick break, we take a look at a bug that lets users spoof MS security team emails. Then, it's patches on patches on patches: VMWare fixed some RCE and privesc bugs, ASUS corrected a critical auth bypass flaw, and Apple dealt with their very first visionOS-exclusive vulnerability. To wrap up the show, Daniel and Sophie learn about a new mandatory program at First Horizon Bank that forces stressed employees to stop work and...look at family pictures. Check out the articles below to read more about today's stories: https://www.washingtonpost.com/technology/2024/06/18/nvidia-most-valuable-company-microsoft-ai/ https://www.engadget.com/the-morning-after-the-biggest-announcements-from-nintendo-direct-111547910.html https://www.ign.com/articles/spaceballs-sequel-in-the-works-with-josh-gad-starring-mel-brooks-producing https://www.forbes.com/sites/daveywinder/2024/06/14/new-wi-fi-takeover-attack-all-windows-users-warned-to-update-now/ https://www.theregister.com/2024/06/17/adobe_sued_cancel_fees/ https://www.securityweek.com/cisa-conducts-first-ai-cyber-incident-response-exercise/ https://www.darkreading.com/cyberattacks-data-breaches/scattered-spider-boss-cuffed https://www.justice.gov/usao-edny/pr/two-men-charged-breaching-federal-law-enforcement-database-and-posing-police-officers https://techcrunch.com/2024/06/18/security-bug-allows-anyone-to-spoof-microsoft-employee-emails…
T
Technado

1 364: Apple REFUSES to pay $1 Million Bounty! (Plus, WWDC Updates!) 1:09:48
1:09:48
Play Later
Play Later
Lists
Like
Liked1:09:48
Get ready for a lot of opinions on this week’s Technado - Apple’s WWDC 2024 is underway, and we have some thoughts. In other breaking news, Black Basta threat actors may have exploited a Windows 0-day, and Fortinet has patched multiple vulnerabilities in FortiOS. And WWDC isn’t the only Apple news this week: the tech giant is refusing to pay a $1 million bounty to Kaspersky labs for some iOS zero-days. After our Apple tirade, we cover some malicious VSCode extensions with MILLIONS of downloads. Then, we take a look at not one, but TWO 4chan data leaks of some major companies: the New York Times and Disney. Following a quick break, we say hello to an old friend in this week’s D’oh! Segment: it’s LastPass! The company essentially DoS’ed themselves thanks to a faulty Chrome extension. We also have yet another Recall update - Windows heard the call for better security, and they’re responding by…making Recall an opt-in feature. Next up, a new ransomware variant dubbed ‘Fog’ that’s targeting US businesses, and NY is introducing mobile IDs to replace physical ones. To wrap up the episode, British semiconductor giant Arm is warning customers about a use-after-free bug. Want to read further? Check out the articles we covered this week: https://thehackernews.com/2024/06/black-basta-ransomware-may-have.html https://www.securityweek.com/fortinet-patches-code-execution-vulnerability-in-fortios/ https://www.engadget.com/apple-intelligence-ai-ios-18-and-the-biggest-announcements-at-wwdc-2024-184422501.html https://gbhackers.com/apple-kaspersky-zero-days/ https://www.bleepingcomputer.com/news/security/malicious-vscode-extensions-with-millions-of-installs-discovered/ https://www.bleepingcomputer.com/news/security/new-york-times-source-code-stolen-using-exposed-github-token/ https://www.bleepingcomputer.com/news/security/club-penguin-fans-breached-disney-confluence-server-stole-25gb-of-data/ https://www.bleepingcomputer.com/news/security/lastpass-says-12-hour-outage-caused-by-…
T
Technado

1 363: ShinyHunters behind Ticketmaster Breach?! (Half a Billion Customers Exposed!) 1:10:35
1:10:35
Play Later
Play Later
Lists
Like
Liked1:10:35
Daniel is back and the Technado studio got a makeover! We kick off the show with some breaking news: TikTok accounts are being compromised through a zero-click DM attack, and over 360 million stolen accounts were leaked on Telegram cybercrime channels. After our breaking news segment, we cover Bring Me The Horizon's hacking-themed website promoting their new album (spoiler alert: the website itself got hacked). Then, over half a million SOHO routers were remotely bricked - but we still don't know who did it or why. In Linux news, hackers are packing malware with Kiteshield to avoid AV detection. CISA also issued an alert to federal agencies to patch an actively exploited (high-severity!) Linux kernel flaw. After a quick break, it's time for Deja News! The upcoming Windows AI Recall feature has more haters every day: researchers are now calling it a security "disaster." BreachForums is back online thanks to a threat actor known as ShinyHunters (who also claims to be responsible for this week's Ticketmaster and Santander breaches). To wrap up the segment, Okta is warning (again) about credential-stuffing attacks targeting its CIC authentication offering. In happier news, the US DoJ led an international operation to take down the world's largest botnet, and the man responsible has been arrested. And to wrap up the show, Cox Communications patched an auth-bypass bug that could have been disastrous - thanks to an independent security researcher. Check out the stories Daniel and Sophie covered below: https://thehackernews.com/2024/06/celebrity-tiktok-accounts-compromised.html https://www.bleepingcomputer.com/news/security/361-million-stolen-accounts-leaked-on-telegram-added-to-hibp/ https://techcrunch.com/2024/05/28/rock-bands-hidden-hacking-themed-website-gets-hacked/ https://www.theregister.com/2024/05/31/pumoking_eclipse_remote_router_attack/ https://gbhackers.com/kite-shield-packer-abused/ https://thehackernews.com/2024/05/cisa-alerts-federal-agencies-to-pat…
T
Technado

1 362: Biden Deepfake Robocaller Indicted! ($6 Million Fine?!) 1:10:21
1:10:21
Play Later
Play Later
Lists
Like
Liked1:10:21
This week on Technado, Google patched yet ANOTHER 0-day exploit - that's four this month, for those of you counting. Spyware program pcTattletale had their website defaced and database dumped. Several major pharmaceutical companies were affected by Cencora's February data loss. And in other news, hackers are phishing finance orgs using... Minesweeper? After a quick fact-checking break, we have a packed Behind Bars segment. The man behind a deepfake Joe Biden robocall is facing a $6M fine, while a man who stole $37 million in crypto could face up to 20 years in prison. A courtroom recording platform was hijacked in a supply chain attack, and GitHub issued a fix for a maximum severity flaw (that's a 10.0, folks) in their enterprise server software. Finally, we have an update on last week's Apple bug that was causing deleted photos to resurface. Want all the details? Check out this week's stories: https://thehackernews.com/2024/05/google-detects-4th-chrome-zero-day-in.html https://www.bleepingcomputer.com/news/security/hackers-phish-finance-orgs-using-trojanized-minesweeper-clone/ https://www.theregister.com/2024/05/27/security_in_brief/ https://www.bleepingcomputer.com/news/security/hacker-defaces-spyware-apps-site-dumps-database-and-source-code/ https://techcrunch.com/2024/05/25/spyware-app-pctattletale-was-hacked-and-its-website-defaced/ https://www.theregister.com/2024/05/24/biden_robocall_charges/ https://www.bleepingcomputer.com/news/security/indian-man-stole-37-million-in-crypto-using-fake-coinbase-pro-site/ https://www.darkreading.com/cyberattacks-data-breaches/courtroom-recording-platform-javs-hijacked-for-supply-chain-attack https://www.bleepingcomputer.com/news/security/apple-wasnt-storing-deleted-ios-photos-in-icloud-after-all/ https://www.infosecurity-magazine.com/news/github-maximum-severity-flaw/…
T
Technado

1 360: Dell Got Pwned?! (49 MILLION Records Stolen!) 1:16:39
1:16:39
Play Later
Play Later
Lists
Like
Liked1:16:39
This week on Technado, Dell got pwned: 49 million records were stolen & are up for sale on the dark web. Dan & Soph talk privacy as Proton has turned over more customer info to cops, and we also take a look at MITRE's newest framework, EMB3D. In exploit news, Cinterion cellular modems have some severe vulnerabilities to deal with, and a PoC has been released for a critical PuTTY key vulnerability. In our Pork Chop Sandwiches segment, ANOTHER malicious Python package has been found in PyPI. A new LLMjacking attack is being used to exploit stolen cloud creds, and Nmap 7.95 is out with new features! Lastly, in our deep dive, we take a look at Mallox RaaS and how it's being used in MS-SQL exploitation campaigns. And before we sign off, we touch on some of the breaking stories from this week that we couldn't cover in depth. Want to read more? Check out the stories we covered in this week's episode: https://www.theregister.com/2024/05/09/dell_data_stolen/ https://www.theregister.com/2024/05/13/infosec_in_brief/ https://thehackernews.com/2024/05/mitre-unveils-emb3d-threat-modeling.html https://thehackernews.com/2024/05/severe-vulnerabilities-in-cinterion.html https://thehackernews.com/2024/05/malicious-python-package-hides-sliver.html https://www.infosecurity-magazine.com/news/llmjacking-exploits-stolen-cloud/ https://cybersecuritynews.com/nmap-7-95-released/ https://gbhackers.com/putty-private-key-poc-released/ https://blog.sekoia.io/mallox-ransomware-affiliate-leverages-purecrypter-in-microsoft-sql-exploitation-campaigns/#h-mallox-ransomware-deployment…
T
Technado

1 359: NEW IPadOS Changes Incoming! (Also, Don Is Back!) | 1:16:57
1:16:57
Play Later
Play Later
Lists
Like
Liked1:16:57
Join Don and Daniel as they discuss all things happening in the tech and cybersecurity world this week! Article Links: Rapid Fire https://www.tomshardware.com/pc-components/cpus/rising-metal-prices-could-mean-more-expensive-laptops-pc-parts-and-other-electronics-in-the-near-future https://arstechnica.com/apple/2024/05/apple-must-open-ipados-to-sideloading-within-6-months-eu-says/ https://arstechnica.com/gadgets/2024/05/wear-os-will-soon-be-at-50-percent-of-apple-watch-sales/ https://www.darkreading.com/cloud-security/dprks-kimsuky-apt-abuses-weak-dmarc-policies-feds-warn https://gbhackers.com/cybersecurity-consultant-jailed/ https://thehackernews.com/2024/05/hackers-increasingly-abusing-microsoft.html https://www.securitynewspaper.com/2024/05/06/how-safe-is-your-tinyproxy-step-by-step-guide-to-exploiting-tinyproxys-zero-day-vulnerability/ Deep Dive https://blog.kandji.io/malware-cuckoo-infostealer-spyware…
T
Technado

1 358: New Android Banking Malware! (It Tracks EVERYTHING) 1:10:52
1:10:52
Play Later
Play Later
Lists
Like
Liked1:10:52
Patches abound on this week's Technado! In our Rapid Fire segment, we kick things off with the UK ban on weak default passwords. Then, a warning from Okta on cred-stuffing attacks, and a critical bug in R that exposes orgs to supply chain risks. Collection agency FBCS got pwned this week, with millions of records being exposed - but in happier news, the Japanese police are starting a new effort to keep elderly citizens from falling prey to payment card scams. The ArcaneDoor was a big story this week, as was yet anothrer WordPress plugin vulnerability - and in this week's D'oh! segment, the popular iSharing app was found to be sharing users locations (even when services were disabled). FInally, in our deep dive, we take a look at new Android banking malware Brokewell. Like what you heard? Take a look at this week's articles: https://www.theregister.com/2024/04/29/uk_lays_password_legislation/ https://thehackernews.com/2024/04/okta-warns-of-unprecedented-surge-in.html https://www.darkreading.com/application-security/r-programming-language-exposes-orgs-to-supply-chain-risk https://techcrunch.com/2024/04/24/security-flaws-isharing-tracking-app-exposed-millions-precise-locations/ https://www.techradar.com/pro/security/collection-agency-data-breach-affects-millions-of-users https://www.bleepingcomputer.com/news/security/japanese-police-create-fake-support-scam-payment-cards-to-warn-victims/ https://www.msspalert.com/news/cyber-spies-burrow-into-cisco-firewall-platforms-in-zero-day-exploits https://arstechnica.com/security/2024/04/hackers-make-millions-of-attempts-to-exploit-wordpress-plugin-vulnerability/ https://www.threatfabric.com/blogs/brokewell-do-not-go-broke-by-new-banking-malware…
T
Technado

1 357: Malware in Microsoft's GitHub Repo?! 1:11:36
1:11:36
Play Later
Play Later
Lists
Like
Liked1:11:36
Cheats, breaches, and weaknesses abound on this week's Technado! Cybercriminals are threatening to leak millions of records from the World-Check database, and millions more were affected by this week's Frontier Communications broadband shutdown. In our biggest story of the week, MITRE got pwned by nation-state hackers via our old friends, the Ivanti zero-days. CrushFTP is dealing with a vuln that lets attackers download system files, and our Don't Make No Sense feature is a twofer: fake game cheats are being used to spread malware, and it all started with...Microsoft's GitHub repo? Of course, it wouldn't be Technado without a deep dive, and this one's a doozy: a SafeBreach researcher uncovered FOUR CVEs by exploiting a long-standing issue that supports Windows backwards-compatibility. Like what you heard? Check this episode's stories below: https://www.theregister.com/2024/04/19/cybercriminals_threaten_to_leak_all/ https://www.itpro.com/security/cyber-attack-takes-frontier-communications-systems-offline-affecting-millions-of-broadband-customers https://www.helpnetsecurity.com/2024/04/22/mitre-breached/ https://www.infosecurity-magazine.com/news/crushftp-file-transfer/ https://thehackernews.com/2024/04/new-redline-stealer-variant-disguised.html https://www.bleepingcomputer.com/news/security/github-comments-abused-to-push-malware-via-microsoft-repo-urls/ https://www.safebreach.com/blog/magicdot-a-hackers-magic-show-of-disappearing-dots-and-spaces/…
T
Technado

1 356: Russian Spies Stole US Emails?! (Microsoft Breach Update!) 1:09:54
1:09:54
Play Later
Play Later
Lists
Like
Liked1:09:54
This week on Technado, we start off strong with some breaking news: geospatial intelligence firm Space-Eyes has allegedly been breached by IntelBroker. From there, we cover TWO 10.0 command injection vulnerabilities - one affecting Windows, one affecting Palo Alto. Apple has issued warnings to more than 90 countries concerning Mercenary spyware attacks. We've got updates on the most recent Microsoft and AT&T breaches, as well as a new breach involving Sisense. And of course, we can't forget this week's Behind Bars subject: an ex-Amazon engineer who stole millions in cryptocurrency is facing prison time. In our deep dive segment, it's a double whammy: we return to one of our Rapid Fire articles to get into the details of Palo Alto's 10.0 vulnerability. Then, we unpack Blackjack's newest venture, Fuxnet malware. Want to know more? Check out the stories we covered this week: https://www.hackread.com/windows-batbadbut-vulnerability-comment-injection/ https://blog.rust-lang.org/2024/04/09/cve-2024-24576.html https://www.theregister.com/2024/04/12/microsoft_cisa_order/ https://www.bleepingcomputer.com/news/security/att-now-says-data-breach-impacted-51-million-customers/amp/ https://www.hackread.com/iphone-users-mercenary-spyware-attacks/ https://www.securityweek.com/former-security-engineer-sentenced-to-prison-for-hacking-crypto-exchanges/ https://www.infosecurity-magazine.com/news/cisa-urges-reset-sisense-breach/ https://thehackernews.com/2024/04/palo-alto-networks-releases-urgent.html https://www.volexity.com/blog/2024/04/12/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in-globalprotect-cve-2024-3400/ https://unit42.paloaltonetworks.com/cve-2024-3400/ https://claroty.com/team82/research/unpacking-the-blackjack-groups-fuxnet-malware…
T
Technado

1 355: One MILLION Sites Affected by Critical Flaw?! (Technado visits HackSpaceCon!) 1:11:43
1:11:43
Play Later
Play Later
Lists
Like
Liked1:11:43
Live from HackSpaceCon, it's Technado! This week, malware takes center stage: beware of bogus NordVPN downloads and YouTube videos promising Fortnite cheats. If you use a D-Link NAS device that's reached its EoL, you might want to check for a backdoor account. In the return of the beloved Tinfoil Hat segment, Five Eyes data has allegedly been stolen & exposed during a breach. Keeping with our space theme, NASA has finally cracked the case of Voyager 1 sending gibberish data. We wrap up our Rapid Fire articles with a critical flaw affecting one million WordPress websites, an update on the Ivanti debacle (four more vulns!), and a special "Crow" segment featuring million-dollar rewards for zero-days. After a quick break, we dive deep into a new malware variant called Latrodectus - and it's just as dangerous as the venomous spiders it's named after. (Stick around to see Dan and Soph mewing for the camera.) Want to read further? Take a look at the stories we covered this week: https://www.malwarebytes.com/blog/thr... https://www.bleepingcomputer.com/news... https://gbhackers.com/hackers-deliver... https://www.scmagazine.com/brief/alle... https://www.neowin.net/news/after-fiv... https://www.darkreading.com/remote-wo... https://www.darkreading.com/remote-wo... https://thehackernews.com/2024/04/res... https://www.securityweek.com/company-... https://www.proofpoint.com/us/blog/th...…
T
Technado

1 iPhone Users Beware: MFA Bombs Imminent! 1:12:46
1:12:46
Play Later
Play Later
Lists
Like
Liked1:12:46
It's a packed week on Technado! First up in Rapid Fire, we talk about the Linux backdoor that's got everyone fired up - but all is not as it seems. Then, our Pork Chop Sandwiches segment stars Hot Topic in their latest credential stuffing dilemma (and a brief cybergoth appearance thanks to Christian). Activision is looking into some password-stealing malware affecting some of its players (read: cheaters). We wrap up Rapid Fire by discussing the recent MFA bombing attacks plaguing iPhone users, along with a special Deja News double feature: we have updates on the PyPI and AT&T situations! After a quick break, it's time for our deep dive! Daniel gets into the details of the new and improved (?) Android malware Vultur. Finally, we finish up this week's episode with a mini-dive into Imperva Secure Sphere's WAF bypass. Want more details? Check out this week's references: https://thehackernews.com/2024/03/urgent-secret-backdoor-found-in-xz.html https://www.bleepingcomputer.com/news/security/retail-chain-hot-topic-hit-by-new-credential-stuffing-attacks/ https://techcrunch.com/2024/03/28/activision-says-its-investigating-password-stealing-malware-targeting-game-players/ https://www.techopedia.com/news/call-of-duty-hack-alert-malware-drains-bitcoin-from-gamers-wallets https://www.bleepingcomputer.com/news/security/owasp-discloses-data-breach-caused-by-wiki-misconfiguration/ https://www.darkreading.com/cloud-security/mfa-bombing-attacks-target-apple-iphone-users https://securityboulevard.com/2024/03/pypi-suspended-500-fakes-richixbw/ https://techcrunch.com/2024/03/30/att-reset-account-passcodes-customer-data/ https://blog.fox-it.com/2024/03/28/android-malware-vultur-expands-its-wingspan/ https://www.hoyahaxa.com/2024/03/imperva-waf-bypass-cve-2023-50969.html…
Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.