惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

U
Unit 42
罗磊的独立博客
博客园 - 聂微东
T
The Blog of Author Tim Ferriss
博客园 - 司徒正美
Stack Overflow Blog
Stack Overflow Blog
F
Fortinet All Blogs
A
About on SuperTechFans
腾讯CDC
Apple Machine Learning Research
Apple Machine Learning Research
B
Blog RSS Feed
IT之家
IT之家
V
Visual Studio Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
宝玉的分享
宝玉的分享
C
Check Point Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Vercel News
Vercel News
爱范儿
爱范儿
Microsoft Security Blog
Microsoft Security Blog
月光博客
月光博客
T
Tailwind CSS Blog
The Cloudflare Blog
Hugging Face - Blog
Hugging Face - Blog

Black Hills Information Security, Inc.

Bad Habits: An ANTISOC Operation Same Problem, Different Angles: When Red Team and Blue Team Actually Talk to Each Other How to Identify and Exploit New Vulnerabilities Swapper – A Pure Regex Match/Replace Burp Extension A Practical Guide to BloodHound Data Collection Network Engineering Basics Signed, Trusted, and Abused: Proxy Execution via WebView2 Getting Started In Pentesting – Advice From The BHIS Pentest Lead Cloud Security: Tips and Resources for Securing the Cloud Lessons From A Chatbot Incident How to Lead Effective Tabletops Understanding GRC: How to Navigate Risks and Compliance Standards The “P” in PAM is for Persistence: Linux Persistence Technique Malware Analysis: How to Analyze and Understand Malware OSINT: How to Find, Use, and Control Open-Source Intelligence What to Do with Your First Home Lab When the SOC Goes to Deadwood: A Night to Remember Social Engineering and Microsoft SSPR: The Road to Pwnage is Paved with Good Intentions Common Cyber Threats Finding the Right Penetration Testing Company Deceptive-Auditing: An Active Directory Honeypots Tool The Curious Case of the Comburglar How to Set Smart Goals (That Actually Work For You) Inside the BHIS SOC: A Conversation with Hayden Covington Abusing Delegation with Impacket (Part 3): Resource-Based Constrained Delegation Why You Got Hacked – 2025 Super Edition Abusing Delegation with Impacket (Part 2): Constrained Delegation Abusing Delegation with Impacket (Part 1): Unconstrained Delegation GoSpoof – Turning Attacks into Intel Model Context Protocol (MCP)
Talkin’ About Infosec News – 7/25/2022
BHIS · 2022-08-03 · via Black Hills Information Security, Inc.

, , ,



ORIGINALLY AIRED ON JULY 25, 2022

Articles discussed in this episode:

00:00 – BHIS – Talkin’ Bout [infosec] News 2022-07-25

03:59 – Story # 1: DOJ seized ransoms paid by health centers in Kansas, Colorado after 2021 attacks – https://therecord.media/doj-seized-ransoms-paid-by-health-centers-in-kansas-colorado-after-2021-attacks/

08:38 – Story # 1b: twitter.com/cryptowhale – https://twitter.com/cryptowhale

17:34 – Story # 2: How Conti ransomware hacked and encrypted the Costa Rican government – https://www.bleepingcomputer.com/news/security/how-conti-ransomware-hacked-and-encrypted-the-costa-rican-government/

22:29 – Story # 3: Experts Uncover New CloudMensis Spyware Targeting Apple macOS Users – https://thehackernews.com/2022/07/experts-uncover-new-cloudmensis-spyware.html

36:49 – Story # 4: Google Play hides app permissions in favor of developer-written descriptions – https://arstechnica.com/gadgets/2022/07/google-plays-new-privacy-section-actually-hides-app-permissions/

39:09 – Story # 4b: Google is reinstating app permissions list on Play Store – https://techcrunch.com/2022/07/21/google-app-permissions-play-store/

41:31 – Story # 5: Hack the pump: Rising prices lead to more reports of gas theft – https://www.nbcnews.com/tech/security/hack-pump-rising-prices-lead-reports-gas-theft-rcna35198

46:04 – Story # 5b: Gas pump manipulators steal ‘millions of dollars’ in fuel – https://youtu.be/Bcnjp2PESqw

50:40 – Story # 5c: Secret Service agents warn fleets about ‘fuel skimming’ – https://www.ccjdigital.com/technology/article/15114890/secret-service-agents-warn-fleets-about-fuel-skimming

53:13 – Story # 6: Atlassian fixes critical Confluence hardcoded credentials flaw – https://www.bleepingcomputer.com/news/security/atlassian-fixes-critical-confluence-hardcoded-credentials-flaw/

53:33 – Story # 6b: Cisco fixes bug that lets attackers execute commands as root – https://www.bleepingcomputer.com/news/security/cisco-fixes-bug-that-lets-attackers-execute-commands-as-root/

53:57 – Story # 7: New Air-Gap Attack Uses SATA Cable as an Antenna to Transfer Radio Signals – https://thehackernews.com/2022/07/new-air-gap-attack-uses-sata-cable-as.html