The Jerich Show Episode 43 – FBI playing geek squad, PII via real estate and Derrick Thomas joins us

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 43 - FBI playing geek squad, PII via real estate and Derrick Thomas joins us
Loading
/

Have you ever wanted to start an infosec conference of your very own? This week Erich and Javvad talk with Derrick Thomas, a co-founder of BSides Tampa, about what it’s like to start and grow a conference, some pitfalls and reaching for stars. 

They will also discuss the FBI fixing Exchange servers via search warrants, Derrick will be distracted by a clickbait ad about twerking, and realtors showing PII in a virtual tour will be discussed.

Don’t forget to like and subscribe to the podcast and video versions.

About Derrick:
Twitter: @BSidesTampa
LinkedIn: https://www.linkedin.com/in/ddthomas-tampa/

Stories from the show:

FBI blasts away web shells on US servers in wake of Exchange vulnerabilities
https://www.zdnet.com/article/fbi-blasts-away-web-shells-on-us-servers-in-wake-of-exchange-vulnerabilities/

Estate agent’s hi-tech house tour exposes personal data
https://www.bbc.co.uk/news/technology-56718046

Why Australia is in hysterics over a ‘navy twerking’ dance
https://www.bbc.co.uk/news/world-australia-56754868

Fyre Festival
https://en.wikipedia.org/wiki/Fyre_Festival

The Jerich Show Episode 42 – The Dramatic Reading Episode with @TriciaKicksSaaS

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 42 - The Dramatic Reading Episode with @TriciaKicksSaaS
Loading
/

In this great episode, Erich and Javvad welcome Tricia Howard to the show as they discuss the Ziggy ransomware game giving refunds (no, really), the 500 million user LinkedIn profile scrape, getting in to the cybersecurity industry from outside, and more.

Trisha even uses her amazing theatrical skills to do a dramatic reading of a ransomware note. 

Remember to watch, like, and subscribe!

Trisha’s information:
Twitter and Instagram: @TriciaKicksSaaS
LinkedIn: https://www.linkedin.com/in/triciakickssaas/ 

Stories from the show:
Ziggy ransomware admin announces refunds for all targeted victims
https://www.teiss.co.uk/ziggy-ransomware-admin-to-refund-victims/

Scraped data of 500 million LinkedIn users being sold online, 2 million records leaked as proof:
https://cybernews.com/news/stolen-data-of-500-million-linkedin-users-being-sold-online-2-million-leaked-as-proof-2/

 

The Jerich Show Episode 41 – Talking culure with Kai Roer

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 41 - Talking culure with Kai Roer
Loading
/

In the episode, Javvad and Erich welcome Kai Roer to the show to talk about a Twitter account takeover, a big potential data leak, responsibility in a phishing click and of course, about security culture.

About Kai:
Twitter: @kairoer
LinkedIn: https://www.linkedin.com/in/kairoer/

Stories From the Show:

Phish Leads to Breach at Calif. State Controller
https://krebsonsecurity.com/2021/03/phish-leads-to-breach-at-calif-state-controller/

NHS boss’s Twitter accounts hacked by PS5 scammers:
https://www.bbc.co.uk/news/technology-56456002

Forex Broker Leaks Billions of Customer Records Online:
https://www.infosecurity-magazine.com/news/forex-leaks-millions-customer/

The Jerich Show Episode 40 – The Camera Episode. Pwned Cameras, Tracking and More

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 40 - The Camera Episode. Pwned Cameras, Tracking and More
Loading
/

From security camera feeds being pwned to tracking people through lens scratches and dust and big issues with some Adobe software, cameras and related items are the topic today for Javvad and Erich.

Links from the show: 

FB can track you via dust and scratches:
https://www.tiktok.com/@jengolbeck/video/6936959507356486918

The FB patent for associating cameras with users and objects in a social networking system
https://patents.google.com/patent/US9485423B2/en

Dr. Jen Golbeck:
Twitter: https://twitter.com/jengolbeck

TikTok: https://www.tiktok.com/@jengolbeck?

 

Security startup Verkada hack exposes 150,000 security cameras in Tesla factories, jails, and more:
https://www.theverge.com/2021/3/9/22322122/verkada-hack-150000-security-cameras-tesla-factory-cloudflare-jails-hospitals

Adobe releases batch of security fixes for Framemaker, Creative Cloud, Connect:
https://www.zdnet.com/article/adobe-releases-batch-of-security-fixes-for-framemaker-creative-cloud-connect/

The Jerich Show Episode 39 – James McQuiggan, Elder Fraud, AOL Phishing and More

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 39 - James McQuiggan, Elder Fraud, AOL Phishing and More
Loading
/

In this episode, Erich and Javvad are joined by their colleague and friend, James McQuiggan, as they discuss Elder Fraud, phishing attacks targeting AOL users,  Cash App phishing kits and bogus Capital Calls among other things.

James McQuiggans info:
Twitter: @James_McQuiggan
LinkedIn: https://www.linkedin.com/in/jmcquiggan/

His book Pick:
Transformational Security Awareness: What Neuroscientists, Storytellers, and Marketers Can Teach Us About Driving Secure Behaviors
https://www.amazon.com/Transformational-Security-Awareness-Neuroscientists-Storytellers/dp/1119566347/

Stories from the show:

Elder Fraud:
https://www.fbi.gov/scams-and-safety/common-scams-and-crimes/elder-fraud

Beware: AOL phishing email states your account will be closed:
https://www.bleepingcomputer.com/news/security/beware-aol-phishing-email-states-your-account-will-be-closed/

Cash App phishing kit deployed in the wild, courtesy of 16Shop:
https://www.bleepingcomputer.com/news/security/cash-app-phishing-kit-deployed-in-the-wild-courtesy-of-16shop/

Investors are the next target of large-scale cyberattacks:
https://www.bleepingcomputer.com/news/security/investors-are-the-next-target-of-large-scale-cyberattacks/

 

The Jerich Show Episode 38 – Mohammed Aldoub discussed API and Cloud security

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 38 - Mohammed Aldoub discussed API and Cloud security
Loading
/

Mohammed Aldoub AKA @voulnet is an API and Cloud security expert. While Erich is off nursing a sore neck, Mohammed keeps Javvad quiet and drops some serious API security knowledge.

Links discussed:
Clubhouse https://twitter.com/_DanielSinclair/status/1363738761339826177?s=19 

Hacking Starbucks https://samcurry.net/hacking-starbucks/ 

Cloud pricing specialists https://www.duckbillgroup.com/

API vulnerability https://hackerone.com/reports/810320

Exploiting Drupal8’s REST RCE https://www.ambionics.io/blog/drupal8-rce

Stop using JWT for sessions http://cryto.net/~joepie91/blog/2016/06/19/stop-using-jwt-for-sessions-part-2-why-your-solution-doesnt-work/ 

 

Mohammed’s Github (tools, upcoming training schedule) https://github.com/Voulnet 

Follow Mohammed on twitter @voulnet

The Jerich Show Episode 37 – Javvad’s internet is broken, we talk ransomware and the new M1 virus

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 37 - Javvad's internet is broken, we talk ransomware and the new M1 virus
Loading
/

Javvad’s internet is broken, so he is a pixelated mess, but we still talk ransomware and the new Mac M1 virus. 

Stories from the show:

Kia Motors Hit With $20M Ransomware Attack – Report  (with a cameo ad for Erich’s upcoming ThreatPost panel)
https://threatpost.com/kia-motors-ransomware-attack/164085/

When Cyber Gangs Disregard Ransomware Payments, Victims Can Be Hit Twice
https://securityintelligence.com/news/when-cyber-gangs-disregard-ransomware-payments/

First Malware Running Natively on M1 Chip Discovered
https://www.macrumors.com/2021/02/17/first-m1-chip-malware/

The Jerich Show Episode 36 – Kylee Lockwood, ICS issues, a lawyer that is not a cat and more.

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 36 - Kylee Lockwood, ICS issues, a lawyer that is not a cat and more.
Loading
/

In this episode, Erich and Javvad welcome Kylee Lockwood, a pro in the field of compliance, to the show as they discuss issues with ICS, the impact of cat filters on professional people and another loss of source code.

Kylee’s contact information:
LinkedIn – https://www.linkedin.com/in/kyleemarie/
Twitter – @kyleemariel

Links from the show:

Hackers steal StormShield firewall source code in data breach
https://www.bleepingcomputer.com/news/security/hackers-steal-stormshield-firewall-source-code-in-data-breach/

ICS Challenges 
https://www.zdnet.com/article/hacker-modified-drinking-water-chemical-levels-in-a-us-city/

Lawyer is NOT a cat:
https://www.entrepreneur.com/article/365148

Cat filter accidentally used in Pakistani minister’s live press conference:
https://www.bbc.com/news/world-asia-48663289

The Jerich Show Episode 35 – Ransomware, WiFi Ownage and Facial Recognition

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 35 - Ransomware, WiFi Ownage and Facial Recognition
Loading
/

In this episode Erich and Javvad discuss stories related to ransomware, vulnerabilites in some WiFi chipsets and issues related to the Greek police officers being issued hardware allowing for facial recognition and fingerprint identification.

Stories in this episode:

Critical Bugs Found in Popular Realtek Wi-Fi Module for Embedded Devices:
https://thehackernews.com/2021/02/critical-bugs-found-in-popular-realtek.html

Ransomware attacks increasingly destroy victims’ data by mistake:
https://www.bleepingcomputer.com/news/security/rise-in-ransomware-attacks-mistakenly-causing-data-destruction/

Ransomware: A company paid millions to get their data back, but forgot to do one thing. So the hackers came back again:
https://www.zdnet.com/article/ransomware-this-is-the-first-thing-you-should-think-about-if-you-fall-victim-to-an-attack/

Greek Police to Introduce Live Facial Recognition:
https://www.infosecurity-magazine.com/news/greek-police-to-introduce-live

The Jerich Show Episode 34 – Adrian Sanabria, the Emotet takedown and more

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 34 - Adrian Sanabria, the Emotet takedown and more
Loading
/

This week Javvad and Erich welcome a long time friend and former colleague of Javvad’s, Adrian Sanabria to the show as they discuss news around the takedown of the the Emotet group, a new phishing toolkit that dynamically changes brands and other news from they cybersecurity world. Adrian also discusses his new job and how it will change the future of infosec tool product reviews.

Don’t forget to like and subscribe for more great weekly content! 

Adrian’s Social Media:
Twitter: @sawaba
LinkedIn: https://www.linkedin.com/in/adrian-sanabria/
OnlyFans: TBD

Stories from the show:

Emotet Takedown:
https://www.bbc.com/news/technology-55826258

New Phishing Toolkit:
https://www.zdnet.com/article/new-cybercrime-tool-can-build-phishing-pages-in-real-time/

Krebs on Solarwinds:
https://krebsonsecurity.com/2021/01/solarwinds-what-hit-us-could-hit-others/

The Sonicwall Problem:
https://threatpost.com/sonicwall-breach-zero-days-in-remote-access/163290/

The Security Products We Deserve:
https://youtu.be/GHuQC1qLnJ4