The Jerich Show Episode 39 – James McQuiggan, Elder Fraud, AOL Phishing and More

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 39 - James McQuiggan, Elder Fraud, AOL Phishing and More
Loading
/

In this episode, Erich and Javvad are joined by their colleague and friend, James McQuiggan, as they discuss Elder Fraud, phishing attacks targeting AOL users,  Cash App phishing kits and bogus Capital Calls among other things.

James McQuiggans info:
Twitter: @James_McQuiggan
LinkedIn: https://www.linkedin.com/in/jmcquiggan/

His book Pick:
Transformational Security Awareness: What Neuroscientists, Storytellers, and Marketers Can Teach Us About Driving Secure Behaviors
https://www.amazon.com/Transformational-Security-Awareness-Neuroscientists-Storytellers/dp/1119566347/

Stories from the show:

Elder Fraud:
https://www.fbi.gov/scams-and-safety/common-scams-and-crimes/elder-fraud

Beware: AOL phishing email states your account will be closed:
https://www.bleepingcomputer.com/news/security/beware-aol-phishing-email-states-your-account-will-be-closed/

Cash App phishing kit deployed in the wild, courtesy of 16Shop:
https://www.bleepingcomputer.com/news/security/cash-app-phishing-kit-deployed-in-the-wild-courtesy-of-16shop/

Investors are the next target of large-scale cyberattacks:
https://www.bleepingcomputer.com/news/security/investors-are-the-next-target-of-large-scale-cyberattacks/

 

The Jerich Show Episode 38 – Mohammed Aldoub discussed API and Cloud security

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 38 - Mohammed Aldoub discussed API and Cloud security
Loading
/

Mohammed Aldoub AKA @voulnet is an API and Cloud security expert. While Erich is off nursing a sore neck, Mohammed keeps Javvad quiet and drops some serious API security knowledge.

Links discussed:
Clubhouse https://twitter.com/_DanielSinclair/status/1363738761339826177?s=19 

Hacking Starbucks https://samcurry.net/hacking-starbucks/ 

Cloud pricing specialists https://www.duckbillgroup.com/

API vulnerability https://hackerone.com/reports/810320

Exploiting Drupal8’s REST RCE https://www.ambionics.io/blog/drupal8-rce

Stop using JWT for sessions http://cryto.net/~joepie91/blog/2016/06/19/stop-using-jwt-for-sessions-part-2-why-your-solution-doesnt-work/ 

 

Mohammed’s Github (tools, upcoming training schedule) https://github.com/Voulnet 

Follow Mohammed on twitter @voulnet

The Jerich Show Episode 37 – Javvad’s internet is broken, we talk ransomware and the new M1 virus

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 37 - Javvad's internet is broken, we talk ransomware and the new M1 virus
Loading
/

Javvad’s internet is broken, so he is a pixelated mess, but we still talk ransomware and the new Mac M1 virus. 

Stories from the show:

Kia Motors Hit With $20M Ransomware Attack – Report  (with a cameo ad for Erich’s upcoming ThreatPost panel)
https://threatpost.com/kia-motors-ransomware-attack/164085/

When Cyber Gangs Disregard Ransomware Payments, Victims Can Be Hit Twice
https://securityintelligence.com/news/when-cyber-gangs-disregard-ransomware-payments/

First Malware Running Natively on M1 Chip Discovered
https://www.macrumors.com/2021/02/17/first-m1-chip-malware/

The Jerich Show Episode 36 – Kylee Lockwood, ICS issues, a lawyer that is not a cat and more.

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 36 - Kylee Lockwood, ICS issues, a lawyer that is not a cat and more.
Loading
/

In this episode, Erich and Javvad welcome Kylee Lockwood, a pro in the field of compliance, to the show as they discuss issues with ICS, the impact of cat filters on professional people and another loss of source code.

Kylee’s contact information:
LinkedIn – https://www.linkedin.com/in/kyleemarie/
Twitter – @kyleemariel

Links from the show:

Hackers steal StormShield firewall source code in data breach
https://www.bleepingcomputer.com/news/security/hackers-steal-stormshield-firewall-source-code-in-data-breach/

ICS Challenges 
https://www.zdnet.com/article/hacker-modified-drinking-water-chemical-levels-in-a-us-city/

Lawyer is NOT a cat:
https://www.entrepreneur.com/article/365148

Cat filter accidentally used in Pakistani minister’s live press conference:
https://www.bbc.com/news/world-asia-48663289

The Jerich Show Episode 35 – Ransomware, WiFi Ownage and Facial Recognition

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 35 - Ransomware, WiFi Ownage and Facial Recognition
Loading
/

In this episode Erich and Javvad discuss stories related to ransomware, vulnerabilites in some WiFi chipsets and issues related to the Greek police officers being issued hardware allowing for facial recognition and fingerprint identification.

Stories in this episode:

Critical Bugs Found in Popular Realtek Wi-Fi Module for Embedded Devices:
https://thehackernews.com/2021/02/critical-bugs-found-in-popular-realtek.html

Ransomware attacks increasingly destroy victims’ data by mistake:
https://www.bleepingcomputer.com/news/security/rise-in-ransomware-attacks-mistakenly-causing-data-destruction/

Ransomware: A company paid millions to get their data back, but forgot to do one thing. So the hackers came back again:
https://www.zdnet.com/article/ransomware-this-is-the-first-thing-you-should-think-about-if-you-fall-victim-to-an-attack/

Greek Police to Introduce Live Facial Recognition:
https://www.infosecurity-magazine.com/news/greek-police-to-introduce-live

The Jerich Show Episode 34 – Adrian Sanabria, the Emotet takedown and more

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 34 - Adrian Sanabria, the Emotet takedown and more
Loading
/

This week Javvad and Erich welcome a long time friend and former colleague of Javvad’s, Adrian Sanabria to the show as they discuss news around the takedown of the the Emotet group, a new phishing toolkit that dynamically changes brands and other news from they cybersecurity world. Adrian also discusses his new job and how it will change the future of infosec tool product reviews.

Don’t forget to like and subscribe for more great weekly content! 

Adrian’s Social Media:
Twitter: @sawaba
LinkedIn: https://www.linkedin.com/in/adrian-sanabria/
OnlyFans: TBD

Stories from the show:

Emotet Takedown:
https://www.bbc.com/news/technology-55826258

New Phishing Toolkit:
https://www.zdnet.com/article/new-cybercrime-tool-can-build-phishing-pages-in-real-time/

Krebs on Solarwinds:
https://krebsonsecurity.com/2021/01/solarwinds-what-hit-us-could-hit-others/

The Sonicwall Problem:
https://threatpost.com/sonicwall-breach-zero-days-in-remote-access/163290/

The Security Products We Deserve:
https://youtu.be/GHuQC1qLnJ4

The Jerich Show Episode 33 – Headline Roulette

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 33 - Headline Roulette
Loading
/

Knowing that Erich was going in for doctor visit that morning, Javvad decided rather than a traditional show, to help take his mind off things, he would put Erich on the spot to comment to stories he had no idea were coming. 

Welcome to Headline Roulette, a speed response to the following stories with no time to actually read these articles: 

 

Privacy-focused search engine DuckDuckGo grew by 62% in 2020
https://www.bleepingcomputer.com/news/technology/privacy-focused-search-engine-duckduckgo-grew-by-62-percent-in-2020/

FBI: Disinformation Campaigns Seek to Exploit Capitol Siege
https://www.bankinfosecurity.com/fbi-disinformation-campaigns-seek-to-exploit-capitol-siege-a-15782

FBI warns of vishing attacks stealing corporate accounts
https://www.bleepingcomputer.com/news/security/fbi-warns-of-vishing-attacks-stealing-corporate-accounts/

A Chinese hacking group is stealing airline passenger details
https://www.zdnet.com/article/a-chinese-hacking-group-is-stealing-airline-passenger-details/

70% of UK finance industry hit with cyber-attacks in 2020
https://uk.finance.yahoo.com/news/70-percent-uk-finance-industry-hit-with-cyberattacks-in-2020-000851797.html

Hacker posts 1.9 million Pixlr user records for free on forum
https://www.bleepingcomputer.com/news/security/hacker-posts-19-million-pixlr-user-records-for-free-on-forum/

Coin-Mining Malware Volumes Soar 53% in Q4 2020
https://www.infosecurity-magazine.com/news/coinmining-malware-volumes-soar-53/

When you browse Instagram and find former Australian Prime Minister Tony Abbott’s passport number
https://mango.pdf.zone/finding-former-australian-prime-minister-tony-abbotts-passport-number-on-instagram

X-rated social media app Fleek exposed explicit photos of users
https://www.hackread.com/social-media-app-fleek-explicit-photos-leak/

DON’T FORGET TO LIKE AND SUBSCRIBE

The Jerich Show Episode 32 – Rowenna Fielding – Let’s talk about privacy

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 32 - Rowenna Fielding - Let's talk about privacy
Loading
/

In this episode, Javvad and Erich are joined by privacy expert Rowenna Fielding for a fun and informative show discussing privacy issues around the globe. The group discusses changes made by TikTok, the new WhatsApp privacy debacle, the use crowdsourcing by law enforcement after the capitol fiasco, and how to move from and infosec role to a job focused on privacy. 

Rowenna’s recommended books:
• Surveillance capitalism – https://www.amazon.com/Age-Surveillance-Capitalism-Future-Frontier/dp/1541758005/
• Weapons of math destruction – https://www.amazon.com/Weapons-Math-Destruction-Increases-Inequality/dp/0553418831/
• Algorithms of oppression – https://www.amazon.com/Algorithms-Oppression-Search-Engines-Reinforce/dp/1479837245/

Rowenna’s Patreon link:
http://patreon.com/missiggeek

Links from the show:
TikTok: All under-16s’ accounts made private – https://www.bbc.com/news/amp/technology-55639920

WhatsApp gives users an ultimatum: Share data with Facebook or stop using the app – https://arstechnica.com/tech-policy/2021/01/whatsapp-users-must-share-their-data-with-facebook-or-stop-using-the-app/

Rowenna’s breakdown of the WhatApp privacy changes – https://missinfogeek.net/whatsapp-privacy-policy-translated/

Capitol riots: Who has the FBI arrested so far? – https://www.bbc.com/news/world-us-canada-55626148

@sawaba plotted video uploads from the GPS coordinates of the capital on 1/6/21 – https://twitter.com/sawaba/status/1349056336202522625

I Cut the ‘Big Five’ Tech Giants From My Life. It Was Hell – https://gizmodo.com/i-cut-the-big-five-tech-giants-from-my-life-it-was-hel-1831304194

The Jerich Show Episode 32 – Rowenna Fielding – Let’s talk about privacy

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 32 - Rowenna Fielding - Let's talk about privacy
Loading
/

In this episode, Javvad and Erich are joined by privacy expert Rowenna Fielding for a fun and informative show discussing privacy issues around the globe. The group discusses changes made by TikTok, the new WhatsApp privacy debacle, the use crowdsourcing by law enforcement after the capitol fiasco, and how to move from and infosec role to a job focused on privacy. 

Rowenna’s recommended books:
• Surveillance capitalism – https://www.amazon.com/Age-Surveillance-Capitalism-Future-Frontier/dp/1541758005/
• Weapons of math destruction – https://www.amazon.com/Weapons-Math-Destruction-Increases-Inequality/dp/0553418831/
• Algorithms of oppression – https://www.amazon.com/Algorithms-Oppression-Search-Engines-Reinforce/dp/1479837245/

Rowenna’s Patreon link:
http://patreon.com/missiggeek

Links from the show:
TikTok: All under-16s’ accounts made private – https://www.bbc.com/news/amp/technology-55639920

WhatsApp gives users an ultimatum: Share data with Facebook or stop using the app – https://arstechnica.com/tech-policy/2021/01/whatsapp-users-must-share-their-data-with-facebook-or-stop-using-the-app/

Rowenna’s breakdown of the WhatApp privacy changes – https://missinfogeek.net/whatsapp-privacy-policy-translated/

Capitol riots: Who has the FBI arrested so far? – https://www.bbc.com/news/world-us-canada-55626148

@sawaba plotted video uploads from the GPS coordinates of the capital on 1/6/21 – https://twitter.com/sawaba/status/1349056336202522625

I Cut the ‘Big Five’ Tech Giants From My Life. It Was Hell – https://gizmodo.com/i-cut-the-big-five-tech-giants-from-my-life-it-was-hel-1831304194

The Jerich Show Episode 31 – Garrett Gross, The End Of The Year And Our Favorite Stories Of 2020

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 31 - Garrett Gross, The End Of The Year And Our Favorite Stories Of 2020
Loading
/

Join Javvad and Erich as they trick the ever funny and good humored Garrett Gross in to joining, them one last time before their end of year break, for a solid 9 minutes of great discussion followed by his dismissal. Once rid of him, the team turns the topic to their own favorite infosec stories of 2020. 

After this episode Erich and Javvad will be taking a break until the new year while they try incantations, burning of incense, interprative dance and any other possible method of ensuring 2021 won’t be the dumpster fire that 2020 was. 

This is a great time to catch up on earlier episodes here and on Youtube at: https://www.youtube.com/channel/UCDCt5A9GDeTHWEBE8hHkKeg

Please like and subscribe to be notified of new episodes

Follow Garrett on Twitter at: @breachparty

Links from the show:

A Hacker Nearly Stole $8 Million From An Aussie Hedge Fund Using A Fake Zoom Invite:
https://www.gizmodo.com.au/2020/11/a-hacker-nearly-stole-8-million-from-an-aussie-hedge-fund-using-a-fake-zoom-invite/

Travelex driven into financial straits by ransomware attack:
https://www.scmagazine.com/home/security-news/travelex-driven-into-financial-straits-by-ransomware-attack/

A Hacker Is Threatening to Leak Patients’ Therapy Notes:
https://www.wired.com/story/hacker-threaten-release-therapy-notes-patients/

Patients of Hacked US Surgical Company Hit with Ransom Demands:
https://www.infosecurity-magazine.com/news/patients-of-hacked-surgical/