Categories
The Jerich Show

The Jerich Show Episode 55 -Popcorn with Anna Collard as we discuss the attacks of the week and more

This week Anna Collard, founder of Popcorn Training and an all around brillant person, talks through the stories of the week and shares her experience taking a doodle, and turining it into a great company. You don’t want to miss it!

Like, subscribe and share!

About Anna:
LinkedIn: https://www.linkedin.com/in/anna-collard-606817/
Twitter: @AnnaCollard3

Stories from the show:

Majority of employees take cybersecurity shortcuts, despite knowing risks:
https://www.securitymagazine.com/articles/95722-majority-of-employees-take-cybersecurity-shortcuts-despite-knowing-risks

Scam-baiting YouTube channel Tech Support Scams taken offline by tech support scam:
https://www.theregister.com/2021/07/27/youtube_channel_tech_scam/

ICO ends its involvement in dispute between NatWest Bank and data breach whistleblower:
https://www.computerweekly.com/news/252504531/ICO-ends-its-involvement-in-dispute-between-NatWest-Bank-and-data-breach-whistleblower

South Africa port operations halted and workers reportedly put on leave after major cyberattack:
https://www.cnbc.com/2021/07/27/transnet-halts-port-operations-in-south-africa-after-major-cyberattack.html

 

Show Content:
00:00 – Intro
02:52 – Majority of employees take cybersecurity shortcuts, despite knowing risks
10:16 – Scam-baiting YouTube channel Tech Support Scams taken offline by tech support scam
18:35 – ICO ends its involvement in dispute between NatWest Bank and data breach whistleblower
26:02 – South Africa port operations halted and workers reportedly put on leave after major cyberattack
33:50 – Anna talks about starting Popcorn Training
43:07 – Tech sector and the value of professional relationships in South Africa
48:53 – What people can do better to communicate
54:18 – What is next for Anna
56:34 – Outro

Categories
The Jerich Show

The Jerich Show Episode 54 – Black Hat, Swatting, Kaseya Decryptor, (ISC)2, S3 Badness and More

This week Javvad and Erich discuss some of the hottest stories of the past week, including the sentancing of a swatter, the release of a Kaseya universal ransomware decryptor, a $50m demand (possibly being delivered by bicycle), MosaicLoader punishes pirates, the (ISC)2 learning portal for CISSP’s and other members and an insurtech startup that joins the ‘unsecured S3 bucket’ club.

All of this and more. Please like, subscribe and share. Story links and chapter listing is below.

Serial Swatter Who Caused Death Gets Five Years in Prison
https://krebsonsecurity.com/2021/07/serial-swatter-who-caused-death-gets-five-years-in-prison/

Kaseya obtains universal decryptor for REvil ransomware victims
https://www.bleepingcomputer.com/news/security/kaseya-obtains-universal-decryptor-for-revil-ransomware-victims/

Hackers reportedly demand $50m from Saudi Aramco over data leak
https://www.bbc.com/news/business-57924355

New MosaicLoader malware targets software pirates via online ads
https://www.bleepingcomputer.com/news/security/new-mosaicloader-malware-targets-software-pirates-via-online-ads/

An insurtech startup exposed thousands of sensitive insurance applications
https://techcrunch.com/2021/07/16/backnine-insurance-applications-exposed/

 

Other mentions:

Dark Patterns
https://www.darkpatterns.org/

(ISC)2 Learning Portal
https://learn.isc2.org

 

Contents of this video:
00:00 – Javvad’s Minecraft-esque Intro
02:22 – Black Hat Conference and COVID Thoughts
06:00 – Serial Swatter Who Caused Death Gets Five Years in Prison
10:32 – Kaseya obtains universal decryptor for REvil ransomware victims
14:54 – Hackers reportedly demand $50m from Saudi Aramco over data leak
20:05 – New MosaicLoader malware targets software pirates via online ads
25:54 – The (ISC)2 Learning Portal and What They Are Doing Right
30:38 – An insurtech startup exposed thousands of sensitive insurance applications
34:53 – Closing and Profound Insight from Erich

Categories
The Jerich Show

The Jerich Show Episode 54 – Guess who has a breach, Soniwall issues and more

In this episode, Erich and Javvad discuss some data breaches, issues with outdated and End-of-Life (EOL) hardware and software and issues with government collection of zero-day vulnerabilities and issues related to mandatory reporting with too little time to understand the issue. 

Like, subscribe and share!

Fashion retailer Guess discloses data breach after ransomware attack:
https://www.bleepingcomputer.com/news/security/fashion-retailer-guess-discloses-data-breach-after-ransomware-attack/

 

SonicWall warns of ‘critical’ ransomware risk to EOL SMA 100 VPN appliances:
https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-critical-ransomware-risk-to-eol-sma-100-vpn-appliances/

 

22% of exploits for sale in underground forums are more than three years old:
https://www.helpnetsecurity.com/2021/07/15/exploits-for-sale/

 

So nice of China to put all of its network zero-day vulns in one giant database no one will think to break into:
https://www.theregister.com/2021/07/15/china_vulnerability_law/

 

Categories
The Jerich Show

The Jerich Show Episode 52 – Charl van der Walt Chats About Getting Into Infosec & News of the Week

In this episode, Charl van der Walt jions Erich and Javvad as they talk about the news stories related to the new CISA ‘Bad Practices’ guidance, My Book Live devices being remotely wiped, Windows print spoolers being weaponized and data movement by pigeons.

Charl then talks about what it’s like being a CEO, what he looks for in potential employees, the state of security organizations in South Africa, the value of certifications and more.

Remember to hit the ‘Like’ button, then subscribe and share for more great weekly episoded.

About Charl:
Twitter: @charlvdwalt
LinkedIn: https://www.linkedin.com/in/charl-van-der-walt/

Orange Cyberdefense: https://www.linkedin.com/company/orange-cyberdefense/

Stories from the show:

CVE-2021-1675: Proof-of-Concept Leaked for Critical Windows Print Spooler Vulnerability:
https://www.tenable.com/blog/cve-2021-1675-proof-of-concept-leaked-for-critical-windows-print-spooler-vulnerability

Hackers use zero-day to mass-wipe My Book Live devices:
https://www.bleepingcomputer.com/news/security/hackers-use-zero-day-to-mass-wipe-my-book-live-devices/

Bad Practices:
https://www.cisa.gov/BadPractices

 

BONUS STORY:

In Africa, A Pigeon Transfers Data Faster Than The Internet:

https://www.wired.com/2009/09/in-africa-a-pigeon-transfers-data-faster-than-the-internet/

IP over Avian Carriers with Quality of Service:

https://datatracker.ietf.org/doc/html/rfc2549