The Jerich Show Episode 34 – Adrian Sanabria, the Emotet takedown and more

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 34 - Adrian Sanabria, the Emotet takedown and more
Loading
/

This week Javvad and Erich welcome a long time friend and former colleague of Javvad’s, Adrian Sanabria to the show as they discuss news around the takedown of the the Emotet group, a new phishing toolkit that dynamically changes brands and other news from they cybersecurity world. Adrian also discusses his new job and how it will change the future of infosec tool product reviews.

Don’t forget to like and subscribe for more great weekly content! 

Adrian’s Social Media:
Twitter: @sawaba
LinkedIn: https://www.linkedin.com/in/adrian-sanabria/
OnlyFans: TBD

Stories from the show:

Emotet Takedown:
https://www.bbc.com/news/technology-55826258

New Phishing Toolkit:
https://www.zdnet.com/article/new-cybercrime-tool-can-build-phishing-pages-in-real-time/

Krebs on Solarwinds:
https://krebsonsecurity.com/2021/01/solarwinds-what-hit-us-could-hit-others/

The Sonicwall Problem:
https://threatpost.com/sonicwall-breach-zero-days-in-remote-access/163290/

The Security Products We Deserve:
https://youtu.be/GHuQC1qLnJ4

The Jerich Show Episode 33 – Headline Roulette

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 33 - Headline Roulette
Loading
/

Knowing that Erich was going in for doctor visit that morning, Javvad decided rather than a traditional show, to help take his mind off things, he would put Erich on the spot to comment to stories he had no idea were coming. 

Welcome to Headline Roulette, a speed response to the following stories with no time to actually read these articles: 

 

Privacy-focused search engine DuckDuckGo grew by 62% in 2020
https://www.bleepingcomputer.com/news/technology/privacy-focused-search-engine-duckduckgo-grew-by-62-percent-in-2020/

FBI: Disinformation Campaigns Seek to Exploit Capitol Siege
https://www.bankinfosecurity.com/fbi-disinformation-campaigns-seek-to-exploit-capitol-siege-a-15782

FBI warns of vishing attacks stealing corporate accounts
https://www.bleepingcomputer.com/news/security/fbi-warns-of-vishing-attacks-stealing-corporate-accounts/

A Chinese hacking group is stealing airline passenger details
https://www.zdnet.com/article/a-chinese-hacking-group-is-stealing-airline-passenger-details/

70% of UK finance industry hit with cyber-attacks in 2020
https://uk.finance.yahoo.com/news/70-percent-uk-finance-industry-hit-with-cyberattacks-in-2020-000851797.html

Hacker posts 1.9 million Pixlr user records for free on forum
https://www.bleepingcomputer.com/news/security/hacker-posts-19-million-pixlr-user-records-for-free-on-forum/

Coin-Mining Malware Volumes Soar 53% in Q4 2020
https://www.infosecurity-magazine.com/news/coinmining-malware-volumes-soar-53/

When you browse Instagram and find former Australian Prime Minister Tony Abbott’s passport number
https://mango.pdf.zone/finding-former-australian-prime-minister-tony-abbotts-passport-number-on-instagram

X-rated social media app Fleek exposed explicit photos of users
https://www.hackread.com/social-media-app-fleek-explicit-photos-leak/

DON’T FORGET TO LIKE AND SUBSCRIBE

The Jerich Show Episode 32 – Rowenna Fielding – Let’s talk about privacy

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 32 - Rowenna Fielding - Let's talk about privacy
Loading
/

In this episode, Javvad and Erich are joined by privacy expert Rowenna Fielding for a fun and informative show discussing privacy issues around the globe. The group discusses changes made by TikTok, the new WhatsApp privacy debacle, the use crowdsourcing by law enforcement after the capitol fiasco, and how to move from and infosec role to a job focused on privacy. 

Rowenna’s recommended books:
• Surveillance capitalism – https://www.amazon.com/Age-Surveillance-Capitalism-Future-Frontier/dp/1541758005/
• Weapons of math destruction – https://www.amazon.com/Weapons-Math-Destruction-Increases-Inequality/dp/0553418831/
• Algorithms of oppression – https://www.amazon.com/Algorithms-Oppression-Search-Engines-Reinforce/dp/1479837245/

Rowenna’s Patreon link:
http://patreon.com/missiggeek

Links from the show:
TikTok: All under-16s’ accounts made private – https://www.bbc.com/news/amp/technology-55639920

WhatsApp gives users an ultimatum: Share data with Facebook or stop using the app – https://arstechnica.com/tech-policy/2021/01/whatsapp-users-must-share-their-data-with-facebook-or-stop-using-the-app/

Rowenna’s breakdown of the WhatApp privacy changes – https://missinfogeek.net/whatsapp-privacy-policy-translated/

Capitol riots: Who has the FBI arrested so far? – https://www.bbc.com/news/world-us-canada-55626148

@sawaba plotted video uploads from the GPS coordinates of the capital on 1/6/21 – https://twitter.com/sawaba/status/1349056336202522625

I Cut the ‘Big Five’ Tech Giants From My Life. It Was Hell – https://gizmodo.com/i-cut-the-big-five-tech-giants-from-my-life-it-was-hel-1831304194

The Jerich Show Episode 32 – Rowenna Fielding – Let’s talk about privacy

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 32 - Rowenna Fielding - Let's talk about privacy
Loading
/

In this episode, Javvad and Erich are joined by privacy expert Rowenna Fielding for a fun and informative show discussing privacy issues around the globe. The group discusses changes made by TikTok, the new WhatsApp privacy debacle, the use crowdsourcing by law enforcement after the capitol fiasco, and how to move from and infosec role to a job focused on privacy. 

Rowenna’s recommended books:
• Surveillance capitalism – https://www.amazon.com/Age-Surveillance-Capitalism-Future-Frontier/dp/1541758005/
• Weapons of math destruction – https://www.amazon.com/Weapons-Math-Destruction-Increases-Inequality/dp/0553418831/
• Algorithms of oppression – https://www.amazon.com/Algorithms-Oppression-Search-Engines-Reinforce/dp/1479837245/

Rowenna’s Patreon link:
http://patreon.com/missiggeek

Links from the show:
TikTok: All under-16s’ accounts made private – https://www.bbc.com/news/amp/technology-55639920

WhatsApp gives users an ultimatum: Share data with Facebook or stop using the app – https://arstechnica.com/tech-policy/2021/01/whatsapp-users-must-share-their-data-with-facebook-or-stop-using-the-app/

Rowenna’s breakdown of the WhatApp privacy changes – https://missinfogeek.net/whatsapp-privacy-policy-translated/

Capitol riots: Who has the FBI arrested so far? – https://www.bbc.com/news/world-us-canada-55626148

@sawaba plotted video uploads from the GPS coordinates of the capital on 1/6/21 – https://twitter.com/sawaba/status/1349056336202522625

I Cut the ‘Big Five’ Tech Giants From My Life. It Was Hell – https://gizmodo.com/i-cut-the-big-five-tech-giants-from-my-life-it-was-hel-1831304194

The Jerich Show Episode 31 – Garrett Gross, The End Of The Year And Our Favorite Stories Of 2020

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 31 - Garrett Gross, The End Of The Year And Our Favorite Stories Of 2020
Loading
/

Join Javvad and Erich as they trick the ever funny and good humored Garrett Gross in to joining, them one last time before their end of year break, for a solid 9 minutes of great discussion followed by his dismissal. Once rid of him, the team turns the topic to their own favorite infosec stories of 2020. 

After this episode Erich and Javvad will be taking a break until the new year while they try incantations, burning of incense, interprative dance and any other possible method of ensuring 2021 won’t be the dumpster fire that 2020 was. 

This is a great time to catch up on earlier episodes here and on Youtube at: https://www.youtube.com/channel/UCDCt5A9GDeTHWEBE8hHkKeg

Please like and subscribe to be notified of new episodes

Follow Garrett on Twitter at: @breachparty

Links from the show:

A Hacker Nearly Stole $8 Million From An Aussie Hedge Fund Using A Fake Zoom Invite:
https://www.gizmodo.com.au/2020/11/a-hacker-nearly-stole-8-million-from-an-aussie-hedge-fund-using-a-fake-zoom-invite/

Travelex driven into financial straits by ransomware attack:
https://www.scmagazine.com/home/security-news/travelex-driven-into-financial-straits-by-ransomware-attack/

A Hacker Is Threatening to Leak Patients’ Therapy Notes:
https://www.wired.com/story/hacker-threaten-release-therapy-notes-patients/

Patients of Hacked US Surgical Company Hit with Ransom Demands:
https://www.infosecurity-magazine.com/news/patients-of-hacked-surgical/

 

The Jerich Show Episode 30 – Alethe Denis Joins Us, Amazon Scams, and Cyber Attacks at Home

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 30 - Alethe Denis Joins Us, Amazon Scams, and Cyber Attacks at Home
Loading
/

In this episode, Javvad and Erich welcome Althe Denis, winner of the Social Engineering Capture the The Flag (SECTF) at DEFCON and one of the most motivated and awesome people we have met. 

They discuss her path to an infosec career, how she keeps things straight and advice for those interested in getting in to the infosec community from other careers. 

They also discuss some interesting news stories related to cyber attacks on homes, the OGUsers forum hack/ransom, Amazon delivery scams and the value of C-Level executive credentials and accounts. 

All this and more! Be sure to like and subscribe to catch the latest episode each week.

Alethe’s Contact info:
Twitter – @AletheDenis
Website – Alethedenis.com

 

Links from the story:

Hackers attack homes on average 104 times a month, says new Comcast report
https://www.gearbrain.com/are-smart-home-devices-secure-2649035325.html

Stolen credentials forum OGUsers hacked again with user data stolen
https://siliconangle.com/2020/12/02/stolen-credentials-forum-ogusers-hacked-user-data-stolen/

Beware – that email about your Amazon delivery alert could be an online scam
https://www.techradar.com/news/that-amazon-delivery-alert-email-could-be-a-phishing-scam

A hacker is selling access to the email accounts of hundreds of C-level executives
https://www.zdnet.com/article/a-hacker-is-selling-access-to-the-email-accounts-of-hundreds-of-c-level-executives/

 

Alethe’s book recommendations:

The Code of Trust
https://www.amazon.com/Code-Trust-American-Counterintelligence-Experts/dp/1250093465/

Swing Away
https://www.amazon.com/Swing-Away-Conquering-Impostor-Syndrome/dp/B086MKGHVG/

Operator Handbook
https://www.amazon.com/Operator-Handbook-Team-OSINT-Reference/dp/B085RR67H5/

Pentester Blueprint:
https://www.amazon.com/Pentester-BluePrint-Your-Guide-Being/dp/1119684307/

Hacking Multifactor Authentication
https://www.amazon.com/Hacking-Multifactor-Authentication-Roger-Grimes/dp/1119650798/

The Jerich Show Episode 29 – When our Privates Aren’t Private

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 29 - When our Privates Aren't Private
Loading
/

In this special Thanksgiving episode, Erich and Javvad talk about privacy issues related to both the government and in the private sector. Should your employer judge your performance on based on an Office 360 report? Should the government restrict singing in your own home? 

These questions and more will be answered in this episode.

Don’t forget to like and subscribe!

Links from the show:

CDC Guidance:
https://www.cdc.gov/coronavirus/2019-ncov/global-covid-19/shielding-approach-humanitarian.html

California Guidance:
https://www.cdph.ca.gov/Programs/CID/DCDC/Pages/COVID-19/Guidance-for-the-Prevention-of-COVID-19-Transmission-for-Gatherings-November-2020.aspx

Amazon and Employees:
https://www.vice.com/en/article/5dp3yn/amazon-leaked-reports-expose-spying-warehouse-workers-labor-union-environmental-groups-social-movements

Wolfie Christl and O365:
https://twitter.com/WolfieChristl/status/1331221942850949121?s=20

The Jerich Show Episode 28 – That Time Mark Shawa (Afri-CAN) Joined Us

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 28 - That Time Mark Shawa (Afri-CAN) Joined Us
Loading
/

In this show, Javvad and Erich welcome the incredibly entertaining guest, Mark Shawa. Mark discusses ways to improve security culture, why it’s so important, and gives sugeestions for reading materials and people to follow in the industry. 

Erich and Javvad also discuss how stress is impacting employees, the spike in phishing as we get close to Black Friday and a really interesting and scary new attack using browser notifications.

Join us and subscribe for the latest in cybersecurity news delivered every week and check out the podcast version at https://thejerichshow.podbean.com/.

Links from the show:

Mark Shawa – https://markshawa.com/

Stressed Employees:
https://www.securitymagazine.com/articles/93921-stressed-employees-behind-4-in-10-data-breaches

Browser Notification Attacks:
https://krebsonsecurity.com/2020/11/be-very-sparing-in-allowing-site-notifications/

Phishing and Black Friday:
https://www.itpro.co.uk/security/357796/sharp-spike-in-phishing-attacks-in-the-weeks-ahead-of-black-friday

Books Mark Recommended:
Animal Farm – George Orwell: https://www.amazon.com/Animal-Farm-George-Orwell/dp/0451526341/

Start With Why – Simon Sinek: https://www.amazon.com/Start-Why-Leaders-Inspire-Everyone/dp/1591846447/

The Art of Deception – Kevin Mitnick: https://www.amazon.com/Art-Deception-Controlling-Element-Security/dp/076454280X/

The Subtle Art of Not Giving a F*ck – Mark Manson: https://www.amazon.com/Subtle-Art-Not-Giving-Counterintuitive/dp/0062457713/

Transformational Security Awareness – Perry Carpenter : https://www.amazon.com/Transformational-Security-Awareness-Neuroscientists-Storytellers/dp/1119566347/

Mark’s Notable Thought Leaders :
Theo Baloyi – CEO of Bathu Shoes: https://www.linkedin.com/in/theo-baloyi-07b6891a3/

Sylvester Chauke – Founder of DNA Brand Architects: https://www.linkedin.com/in/sylvester-chauke-385a3216/

David and Madeline McQueen – Founder of Madeline McQueen & Founder of David McQueen: https://www.madelinemcqueen.com/ and https://www.davidmcqueen.co.uk/

Anna Collard – KnowBe4 SVP – Founder of Popcorn Training: https://www.linkedin.com/in/anna-collard-606817/

Lisa Ventura – Founder UK Cyber Security Association: https://lisaventura.co.uk/

 

The Jerich Show Episode 27 – Kids Games and Breaches plus Microsoft Says To Ditch SMS MFA

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 27 - Kids Games and Breaches plus Microsoft Says To Ditch SMS MFA
Loading
/

After a week off after a traffic accident, Erich and Javvad discuss another data breach around a kids game and discuss the Microsoft advisory to move away from SMS Multi-Factor Authentication

Links from the show:

Hacking Multifactor Authentication:
https://amzn.to/2K2RMba

Hackers Steal 46 Million Records from Kids’ Game Developer:
https://www.infosecurity-magazine.com/news/hackers-steal-46-million-records/

The Animal Jam data breach notification:
https://www.animaljam.com/en/2020databreach

The difference between two-factor and two-step authentication:
https://paul.reviews/the-difference-between-two-factor-and-two-step-authentication/

Microsoft urges users to stop using phone-based multi-factor authentication:
https://www.zdnet.com/article/microsoft-urges-users-to-stop-using-phone-based-multi-factor-authentication/

The Jerich Show Episode 26 – More Low Blows from the Ransomware Gangs

The Jerich Show Podcast
The Jerich Show Podcast
The Jerich Show Episode 26 - More Low Blows from the Ransomware Gangs
Loading
/

In this episode Javvad and Erich take a look at the new low that the Ryuk ransomware gang is sinking to, that is targeting hospitals and medical clinics. 

They also discuss the incredible amount of money being made in the ransomware game, with one group claiming to have made over $100 million. On the other side of that coin, a ransomware gang donated $10k to charity. Why? Who really knows? Maybe guilt, maybe a PR move, maybe just a way to get mentioned on the show. 

Finally, to wrap up their ransom demanding trend today, they discuss a group that breached a Finnish psychotherapy clinic and then blackmailed the patients.

All of this and more in this week’s show.

Links from the show:
https://www.zdnet.com/article/ransomware-gang-donates-part-of-ransom-demands-to-charity-organizations/

https://krebsonsecurity.com/2020/10/fbi-dhs-hhs-warn-of-imminent-credible-ransomware-threat-against-u-s-hospitals/

https://www.bleepingcomputer.com/news/security/revil-ransomware-gang-claims-over-100-million-profit-in-a-year/

https://www.theregister.com/2020/10/26/finland_psychotherapy_clinic_ransom_attack/