Digital Shadows

  • Author: Vários
  • Narrator: Vários
  • Publisher: Podcast
  • Duration: 223:38:20
  • More information

Informações:

Synopsis

Digital Shadows monitors and manages an organization’s digital risk, providing relevant threat intelligence across the widest range of data sources within the open, deep, and dark web to protect their brand, and reputation.

Episodes

  • Special: David Thejl-Clayton Talks Data Driven Incident Response and Verizon DBIR

    14/05/2021 Duration: 43min

    Digital Shadows CISO Rick hosts this edition of ShadowTalk. He’s joined by special guest David Thejl-Clayton , Senior Advisor in Cyber Defense at Combitech. They discuss: - David talks origin story, his journey through CTI, and his current role at Combitech - His obsession with data driven response and how that data-love came to be- He and Rick reminisce about favorite speakers at SANS- They discuss the Verizon DBIR - what’s to come?- Purple-teaming - how to bring value to organizations through data***Resources from this week’s podcast***Find David on Twitter: https://twitter.com/DCSecuritydk Find David on LinkedIn: https://www.linkedin.com/in/davidclayton454/ Data Driven Incident Response: https://www.youtube.com/watch?v=Ll60XUJnRTw SANS CTI Summit - VERISIZE your way into CTI: https://www.youtube.com/watch?v=AwMC6INC5TE https://www.sans.org/blog/a-visual-summary-of-sans-cyber-threat-intelligence-summit/ Vocabulary for Event Recording and Information Sharing (VERIS): http://veriscommunity.net/ 2020 Data Brea

  • Weekly: VPN Vulnerabilities, Supply Chain Attacks, and Babuk Says “Bye”!

    07/05/2021 Duration: 34min

    ShadowTalk hosts Alec, Ivan, Sean, and Digital Shadows CISO, Rick, bring you the latest in threat intelligence. This week they cover:- Sean discusses Pulse Secure VPN vulnerabilities - what are the latest updates and who is being targeted?- The team talks about supply chain compromise - what is it?- Sean takes us through the DDoS attack on Belnet - Babuk is hanging up their hat - Ivan brings us the latest- Ryuk gets ahold of bio research through a studentGet this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/weekly-intelligence-summary-07-may ***Resources from this week’s podcast***Pulse Secure: https://www.bleepingcomputer.com/news/security/pulse-secure-fixes-vpn-zero-day-used-to-hack-high-value-targets/ Belnet: https://www.zdnet.com/article/this-massive-ddos-attack-took-large-sections-of-a-countrys-internet-offline/ Babuk: https://threatpost.com/babuk-ransomware-gang-mulls-retirement/165742/ Ryuk: https://www.zdnet.com/article/ryuk-ransomware-finds-foothold-in-bio-resea

  • Special: Amy Bejtlich Talks Culture of Candor Within Intel Teams and More!

    06/05/2021 Duration: 33min

    Digital Shadows CISO, Rick, hosts this edition of ShadowTalk. He’s joined by special guest Amy Bejtlich, Director of Intelligence Analysis at Dragos, Inc. They discuss: - Amy’s origin story and journey from traditional intelligence to cyber intelligence- How to "bloom where you are planted" - Her various SANS cyber threat intel presentations- How to build a "culture of candor" within an intel team - Minimizing burnout and supporting the mental health of teams***Resources from this week’s podcast***Find Amy on Twitter: https://twitter.com/_Silent_J Find Amy on LinkedIn: https://www.linkedin.com/in/amybejtlich/ SANS New to Cyber Summit: "Job Role Spotlight - Cyber Threat Intelligence": https://sansorg.egnyte.com/dl/TjsPnHluNo/? SANS 2019 CTI Summit Video: "Analytic Tradecraft In The Real World": https://www.youtube.com/watch?v=MWJZsW9HooY SANS 2019 CTI Summit slides: Analytic Tradecraft In The Real World": https://sansorg.egnyte.com/dl/MnytUZPcOU/?

  • Special: ShadowTalk’s 200th Episode!

    30/04/2021 Duration: 01h09min

    It’s a full house with ShadowTalk hosts Stefano, Alec, Charles, Kim, Dylan, Adam, and Digital Shadows CISO, Rick! The team is looking back at three years of ShadowTalk and taking us on a journey through changes in the threat landscape. They discuss: - Adam and Alec take us through ransomware heavy hitters from the last few years - Big game hunting, double-extortion, and more- The team reminisce about their first time joining ShadowTalk - Kim and Rick tackle supply-chain attacks - looking back at SolarWinds and the role of trust- Most embarrassing moments in ShadowTalk history- Dylan and Charles talk CVE’s - more on opportunistic attackers taking advantage of Covid-19 and remote work- Final thoughts from the team - what would you tell your 2018 self?Check out the video recording of the podcast here: https://resources.digitalshadows.com/digitalshadows/special-shadowtalk-s-200th-episode Get this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/weekly-intelligence-summary-30-apr

  • Weekly: Supply Chain Attacks Rule The Day, Plus The FBI Takes On Web-Shells

    23/04/2021 Duration: 24min

    ShadowTalk hosts Alec, Ivan, Charles, and newcomer, Sean, bring you the latest in threat intelligence. This week they cover:- Ivan dives into FBI actions against web-shells from compromised Exchange servers- Codecov supply chain attacks - Charles brings us the latest - The team discuss the Pulse Secure VPN bug - Plus, don’t forget our special 200th episode next week! Get this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/weekly-intelligence-summary-23-april ***Resources from this week’s podcast***FBI Web Shells: https://www.welivesecurity.com/2021/04/14/fbi-removes-malware-compromised-exchange-servers/Codecov: https://www.bleepingcomputer.com/news/security/hundreds-of-networks-reportedly-hacked-in-codecov-supply-chain-attack/REvil vs. Apple: https://www.bleepingcomputer.com/news/security/revil-gang-tries-to-extort-apple-threatens-to-sell-stolen-blueprints/Pulse Secure VPN: https://www.bleepingcomputer.com/news/security/pulse-secure-vpn-zero-day-used-to-hack-defense-firms-

  • Weekly: Q1 Ransomware Round-Up - Looking Back at Early 2021

    16/04/2021 Duration: 01h10min

    ShadowTalk hosts Stefano, Adam, Kim, and Chris bring you the latest in threat intelligence. This week they cover:- Kim takes us back to SolarWinds, the Centreon breach, the Accellion incident, and the Microsoft Exchange supply chain attack- The team discusses attributing attacks - state sponsored threat actors leverage sophisticated tactics, allowing lower level cybercriminals to ride their coattails - Chris takes the teams through mitigating risks and proxy logon vulnerabilities- How Covid-19 and WFH has affected the threat landscape - VPN vulnerabilities - Advice for security teams - what to prioritize- Adam discusses ransomware trends in Q1 2021- The team touches on law enforcement activity and more! Get this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/20210416-ds-weekly-intsum-updated ***Resources from this week’s podcast*** Q1 Ransomware Blog: https://www.digitalshadows.com/blog-and-research/q1-ransomware-roundup/ IABs Q1 Blog: https://www.digitalshadows.com/blog-a

  • Weekly: Facebook Data Breach, Ransomware Cartel, and More!

    09/04/2021 Duration: 37min

    ShadowTalk hosts Alec, Ivan, Charles, and Digital Shadows CISO Rick bring you the latest in threat intelligence. This week they cover:- Ivan talks through the latest updates on the Facebook data breach - threat actors selling old data for cheap and what was potentially exposed- Charles discusses Fortinet vulnerabilities - what are the technical details and how do defenders protect their data?- The team dives deeper into the ransomware cartel - Clop updates - what’s the latest and who are they targeting?Get this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/weekly-intelligence-summary-09-april ***Resources from this week’s podcast***Facebook Breach: https://www.theguardian.com/technology/2021/apr/06/facebook-breach-data-leak Fortinet Vulnerabilities: https://www.ic3.gov/Media/News/2021/210402.pdfhttps://www.bleepingcomputer.com/news/security/fbi-and-cisa-warn-of-state-hackers-attacking-fortinet-fortios-servers/ Ransomware Cartel: https://analyst1.com/file-assets/RANSOM-MA

  • Weekly: It’s A Ransomware Round-Up - CNA , Clop, and Much More!

    02/04/2021 Duration: 49min

    ShadowTalk hosts Stefano, Dylan, Kim, and Chris bring you the latest in threat intelligence. This week they cover:- Kim and her recent ransomware round-up - insurance company CNA suffers attack, Clop holds victims for ransom, and more- Chris takes the team through the PHP Git Server backdoor - Dylan and the group talk pandemic, remote-working, and cyber hygiene Get this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/weekly-intelligence-summary-02-april ***Resources from this week’s podcast***Tax Fraud 2021 Blog: https://www.digitalshadows.com/blog-and-research/tax-and-unemployment-fraud-in-2021/ Microsoft Exchange Hafnium Blog: https://www.digitalshadows.com/blog-and-research/microsoft-exchange-server-exploit-what-happened-next/ Cyber Threat Intelligence: Solutions Guide and Best Practices: https://resources.digitalshadows.com/digitalshadows/cyber-threat-intelligence-solutions-guide Also, don’t forget to reach out to - shadowtalk@digitalshadows.com

  • Special: Dr. Chase Cunningham Talks Zero Trust, His Book on Cyber Warfare, and More!

    30/03/2021 Duration: 35min

    Digital Shadows CISO Rick hosts this edition of ShadowTalk. He’s joined by special guest Dr. Chase Cunningham, author, Retired Navy Chief Cryptologist, and Chief Strategy Officer at Ericom Software. They discuss: -Dr. Chase's origin story -How to use Zero Trust to take back initiative from the adversary -How the VPN is the Palm Pilot of your network infrastructure -Why there is no Zero Trust easy button -Chase's romance novel on cyber warfare -Threat modeling vacations***Resources from this week’s podcast***Find Dr. Chase Cunningham on LinkedIn: https://www.linkedin.com/in/dr-chase-cunningham-54b26243/ Find Dr. Chase Cunningham on Twitter: https://twitter.com/CynjaChaseCCyber Warfare – Truth, Tactics, and Strategies: Strategic concepts and truths to help you and your organization survive on the battleground of cyber warfare: https://www.amazon.com/gp/product/B084ZN2HBD/ref=dbs_a_def_rwt_bibl_vppi_i0Ericom Software: https://www.ericom.com/r/dr-zero-trust/ZT Edge: https://www.zerotrustedge.com/

  • Weekly: More on Microsoft and Acer Receives $50 Million in Ransom Demands

    26/03/2021 Duration: 21min

    ShadowTalk hosts Alec, Austin, Charles, and Digital Shadows CISO Rick bring you the latest in threat intelligence. This week they cover:-The team discusses the latest on Exchange Servers vulnerabilities - should guards still be up? -Austin takes us through the timeline of ransomware taking advantage of vulnerabilities regarding Microsoft -Austin talks $50 million ransom against Acer - biggest known ransom request in modern history. What does this mean for the threat landscape going forward? -A phishing campaign has stolen 400,000 OWA/O365 creds - how to make yourself the hardest target possibleGet this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/weekly-intelligence-summary-26-march ***Resources from this week’s podcast***Microsoft Vulnerabilities: https://www.bleepingcomputer.com/news/security/microsoft-92-percent-of-exchange-servers-safe-from-proxylogon-attacks/ Acer Ransom: https://www.bleepingcomputer.com/news/security/computer-giant-acer-hit-by-50-million-ransomware

  • Special: Creator of Zero Trust John Kindervag Talks Origins and the Future of Zero Trust!

    23/03/2021 Duration: 39min

    Digital Shadows CISO Rick hosts this edition of ShadowTalk. He’s joined by special guest John Kindervag, creator of Zero Trust and Senior Vice President, Cybersecurity Strategy, ON2IT Group Fellow at ON2IT Cybersecurity. They discuss: -John’s origin story and influences - what led to the creation of Zero Trust?- Zero Trust - origin, design principles, and terminology - What are your protect surfaces? - using Zero Trust- John’s new position at ON2IT***Resources from this week’s podcast***Find John Kindervag on LinkedIn: https://www.linkedin.com/in/john-kindervag-40572b1/ Find John Kindervag on Twitter: https://twitter.com/Kindervag Understanding Zero Trust Terminology: https://www.paloaltonetworks.com/resources/zero-trust Antifragile: Things That Gain from Disorder: https://www.amazon.com/Antifragile-Things-That-Disorder-Incerto/dp/0812979680

  • Weekly: Ransomware Resurgence - The Return of FIN8, DarkSide, and More!

    19/03/2021 Duration: 42min

    ShadowTalk hosts Stefano, Adam, Kim, and first-timer Chris bring you the latest in threat intelligence. This week they cover:-Kim takes us through the return of FIN8 - what are the updates to the “BadHatch” backdoor-Chris discusses DarkSides recent resurgence after a quiet period - what’s the latest?-Microsoft Exchange exploit update - the team discuss -How are threat actors and cybercriminals using ProxyLogon vulnerabilities?Get this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/weekly-intelligence-summary-19-march ***Resources from this week’s podcast***FIN8: https://labs.bitdefender.com/2021/03/fin8-group-is-back-in-business-with-improved-badhatch-kit/ DarkSide: https://www.infosecurity-magazine.com/news/darkside-20-ransomware-fastest/ ProxyLogon: https://www.welivesecurity.com/2021/03/10/exchange-servers-under-siege-10-apt-groups/ https://www.vice.com/en/article/n7vpaz/researcher-publishes-code-to-exploit-microsoft-exchange-vulnerabilities-on-github AC Features: https

  • Weekly: Supply Chain Compromise Round-Up - Microsoft, Verkada, and More!

    12/03/2021 Duration: 23min

    ShadowTalk hosts Alec, Ivan, Charles, and Austin bring you the latest in threat intelligence. This week they cover:- The team discuss HAFNIUM and Microsoft Servers Exchange- Updates on the Accellion incident - what’s the latest regarding Flagstar?- The Verkada compromise - who were the victims affected by the breach of private video footage?Get this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/weekly-intelligence-summary-12-march ***Resources from this week’s podcast***Hafnium: https://krebsonsecurity.com/2021/03/a-basic-timeline-of-the-exchange-mass-hack/Microsoft Exchange Compromise: https://www.ic3.gov/Media/News/2021/210310.pdfFlagstar: https://www.cyberscoop.com/flagstar-bank-accellion-breach-clop/Verkada: https://www.washingtonpost.com/technology/2021/03/10/verkada-hack-surveillance-risk/ Mapping MITRE ATT&CK To The DPRK Blog: https://www.digitalshadows.com/blog-and-research/mapping-mitre-attack-to-dprk-financial-crime-indictment/ Year In Review: COVID-19 C

  • Weekly: New Australian Legislature, VMware Bugs, and More!

    05/03/2021 Duration: 45min

    ShadowTalk hosts Stefano, Adam, Dylan, and Kim bring you the latest in threat intelligence. This week they cover:- The Australian Criminal Intelligence Commission (ACIC) issues three new warrants for dealing with cybercrime - how does this new legislation increase law enforcement powers?- VMware has revealed a critical-rated bug - what should security teams know?- Adam covers ICEDID Infection and ransomware - The team discuss the DPRK IndictmentGet this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/weekly-intelligence-summary-05-march ***Resources from this week’s podcast***New Australian Legislature: https://www.aph.gov.au/Parliamentary_Business/Bills_Legislation/Bills_Search_Results/Result?bId=r6623https://www.zdnet.com/article/australias-new-hacking-powers-considered-too-wide-ranging-and-coercive-by-oaic/ Vulnerability Round-Up: https://www.vmware.com/security/advisories/VMSA-2021-0002.html https://www.bleepingcomputer.com/news/security/working-windows-and-linux-

  • Weekly: When Initial Access Brokers Attack

    26/02/2021 Duration: 25min

    ShadowTalk hosts Alec, Ivan, Charles, and Digital Shadows CISO Rick bring you the latest in threat intelligence. This week they cover:- The team talks Initial Access Brokers (IAB) - what role do these middle- men play in the ransomware game?- How can your company mitigate risks against IABs?- The latest on the Accellion incident - Third party attacks - where does the blame fall?Get this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/weekly-intelligence-summary-26-february ***Resources from this week’s podcast***Accellion: https://www.zdnet.com/article/fireeye-links-0-day-attacks-on-fta-servers-extortion-campaign-to-fin11-group/https://www.fireeye.com/blog/threat-research/2021/02/accellion-fta-exploited-for-data-theft-and-extortion.htmlIAB Report: https://resources.digitalshadows.com/whitepapers-and-reports/initial-access-brokers-report Monitoring IABs in SearchLight: https://www.digitalshadows.com/blog-and-research/how-to-monitor-initial-access-broker-listings/ 5 Ways To

  • Weekly: Egregor Arrests, SIM-Swapping, and Oldsmar Updates!

    19/02/2021 Duration: 52min

    ShadowTalk hosts Stefano, Adam, Dylan, and Kim bring you the latest in threat intelligence. This week they cover:- Adam takes us through the latest on Egregor and related arrests - is the threat group down but not out?- Dylan talks SIM-swapping - who was targeted?- Kim brings us the most recent news on the Centreon breach- Plus, the team reviews the Oldsmar water treatment facility attackGet this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/weekly-intelligence-summary-19-february ***Resources from this week’s podcast***Egregor operators arrested: https://www.zdnet.com/article/egregor-ransomware-operators-arrested-in-ukraine/SIM Swapping: https://www.europol.europa.eu/newsroom/news/ten-hackers-arrested-for-string-of-sim-swapping-attacks-against-celebrities https://www.youtube.com/watch?v=fHhNWAKw0bY Centreon breach: https://www.zdnet.com/article/france-russian-state-hackers-targeted-centreon-servers-in-years-long-campaign/ Oldsmar updates: https://www.mass.gov/service-det

  • Weekly: Ransomware Updates - CDPR Victimized, Ziggy’s End, and the Oldsmar Water Incident

    12/02/2021 Duration: 23min

    ShadowTalk hosts Alec, Ivan, Austin, and Digital Shadows CISO Rick bring you the latest in threat intelligence. This week they cover:- Cyberpunk and Witcher fans beware - threat actors target the CD Projekt Red source code- Ziggy ransomware calls it quits - is law enforcement activity driving this impact?- Oldsmar, FL water treatment facility gets hacked - could other critical infrastructure be at risk?- Researcher impacts dozens of tech firms through a supply chain attack, winning a $130,000 ‘bug bounty’Get this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/weekly-intelligence-summary-12-february ***Resources from this week’s podcast***Cyberpunk hack: https://www.theverge.com/2021/2/10/22276664/cyberpunk-witcher-hackers-auction-source-code-ransomware-attack Ziggy: https://www.bleepingcomputer.com/news/security/ziggy-ransomware-shuts-down-and-releases-victims-decryption-keys/ Oldsmar: https://www.cnn.com/2021/02/08/us/oldsmar-florida-hack-water-poison/index.html Security

  • Weekly: Lebanese Cedar, Nefilim Ghost Credentials, and More on SolarWinds and Emotet

    05/02/2021 Duration: 41min

    ShadowTalk hosts Stefano, Adam, and Kim bring you the latest in threat intelligence. This week they cover:- More threat actors and attack vectors are being investigated in the SolarWinds compromise- Law enforcement officials in the Netherlands are delivering an Emotet update that will remove it from infected devices- Kim talks Lebanese Cedar - What’s new in their latest attack?- Adam reviews Nefilim ransomware - how were they able to gain access and why it reinforces the need for securing employee accounts - Plus, don’t miss the malware name of the week! Get this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/weekly-intelligence-summary-05-february ***Resources from this week’s podcast***SolarWinds Update: https://www.wsj.com/articles/suspected-russian-hack-extends-far-beyond-solarwinds-software-investigators-say-11611921601 Lebanese Cedar: https://www.clearskysec.com/wp-content/uploads/2021/01/Lebanese-Cedar-APT.pdf Nefilim Ghost Credentials: https://news.sophos.com/en-us

  • Weekly: Law Enforcement Wins the Week - The Fall of NetWalker and Emotet!

    29/01/2021 Duration: 27min

    ShadowTalk hosts Alec, Charles, Austin, and Digital Shadows CISO Rick bring you the latest in threat intelligence. This week they cover:- Mimecast confirms SolarWinds attackers breached security certificate the latest updates- The rise and fall of Emotet plus unique video footage of the takedown- NetWalker ransomware targeted and taken down by US and Bulgarian Law Enforcement - Avaddon adopts a new tactic - could it become the MO of other threat groups?- North Korean threat actors go phishing for security researchers with fake social media profilesGet this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/weekly-intelligence-summary-29-january ***Resources from this week’s podcast***Mimecast SolarWinds Update: https://www.mimecast.com/blog/important-security-update/ 23 Sunburst Targets Identified: https://www.netresec.com/?page=Blog&month=2021-01&post=Twenty-three-SUNBURST-Targets-Identified Emotet: https://www.zdnet.com/article/emotet-worlds-most-dangerous-malware-bo

  • Weekly: CISA Security Advisory, IObit Attack, and more SolarWinds!

    22/01/2021 Duration: 39min

    ShadowTalk hosts Stefano, Adam, Kim, and Dylan bring you the latest in threat intelligence. This week they cover:- Adam and the team discuss more SolarWinds updates - what’s the latest?- Kim talks CISA security advisory - trends in recent attacks and cyber hygiene- Dylan dives into new ransomware attack on IObit - how threat actors spread the malware to its membersGet this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/weekly-intelligence-summary-22-january ***Resources from this week’s podcast***Cryptocurrency: https://www.bleepingcomputer.com/news/security/iobit-forums-hacked-to-spread-ransomware-to-its-members/https://twitter.com/BleepinComputer/status/1351261442536861697 Lokibot: https://blog.talosintelligence.com/2021/01/a-deep-dive-into-lokibot-infection-chain.html 3 Takeaways from Forrester: https://www.digitalshadows.com/blog-and-research/top-3-takeaways-from-forrester-ti-nowtech-2020/ AzureAD: https://www.digitalshadows.com/blog-and-research/azure-ad-auto-validate

page 13 from 23