Digital Shadows

  • Author: Vários
  • Narrator: Vários
  • Publisher: Podcast
  • Duration: 230:49:24
  • More information

Informações:

Synopsis

Digital Shadows monitors and manages an organization’s digital risk, providing relevant threat intelligence across the widest range of data sources within the open, deep, and dark web to protect their brand, and reputation.

Episodes

  • Special: Bryson Bort, Cyber Gandalf and MORE!

    15/07/2021 Duration: 49min

    Digital Shadow’s CISO Rick Holland and Senior Cyber Threat Intel Analyst Sean Nikkel host this special edition of ShadowTalk. They are joined by special guest CEO and Founder at SCYTHE, Bryson Bort.

  • Weekly: Kaseya Attack Updates, Fancy Lazarus, and Spyware on Google Play

    09/07/2021 Duration: 57min

    ShadowTalk hosts Stefano, Dylan, Adam, and Xue, bring you the latest in threat intelligence. This week they cover:- Xue takes us through the Kaseya ransomware supply-chain attack -REvil’s involvement and “Happy Blog” - Adam discusses a new threat group, Fancy Lazarus - where did they come from and what are their methods?- Dylan dives into malicious spyware apps found on Google Play that steal Facebook users’ logins and passwords - what we know so far - Plus, Adam’s malware name of the week and more!Get this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/weekly-intelligence-summary-9th-july ***Resources from this week’s podcast***Fancy Lazarus: https://www.proofpoint.com/uk/blog/threat-insight/ransom-ddos-extortion-actor-fancy-lazarus-returns Spyware Apps: https://news.drweb.com/show/?i=14244&lng=en Kaseya Blog: https://www.digitalshadows.com/blog-and-research/kaseya-ransomware-supply-chain-attack/ Domain Monitoring Part 2 Blog: https://www.digitalshadows.com/blog-and-r

  • Weekly: LinkedIn Breach, Marketo Marketplace, Playstation Breach, Western Digital MyBook, Nobelium

    02/07/2021 Duration: 35min

    ShadowTalk hosts Sean, Ivan and Digital Shadows CISO, Rick Holland, bring you the latest in threat intelligence. This week they cover:- The team touch on the most recent LinkedIn breach exposing 700 Million user details- Sean and Rick talk about the latest developments of the PrintNightmare incident- Ivan dives into the Marketo data theft marketplace - What’s the future for this group?- Rick discusses the latest PlayStation 3 console ID’s leak and how it’s different to previous breaches- What we know about the mysterious Western Digital MyBook attack Get this week’s intelligence summary at: https://resources.digitalshadows.com/weekly-intelligence-summary/weekly-intelligence-summary-2nd-july***Resources from this week’s podcast***What We’re Reading this month: https://www.digitalshadows.com/blog-and-research/what-were-reading-this-month-june-2021/ Why Do Users Get Banned From Cybercriminal Forums https://www.digitalshadows.com/blog-and-research/why-do-users-get-banned-from-cybercriminal-forums/ Typosquatting

  • Special: Cyber Threat Intel Leader Gert-Jan Bruggink, legos, and MORE!

    30/06/2021 Duration: 42min

    Digital Shadows’ CISO Rick hosts this edition of ShadowTalk. He is joined by special guest Gert-Jan Bruggink. They discuss:●Gert-Jan’s origin story●Legos●Threat intelligence-based pen testing and red-teaming●Writing better threat landscape reports

  • Weekly: Google Releases Supply-Chain Framework, New NATO Agreements, and More!

    25/06/2021 Duration: 29min

    ShadowTalk hosts Stefano, Chris, and Kim, bring you the latest in threat intelligence. This week they cover:- Kim dives into Google’s new Supply Chain Attack framework - how will it operate?- Chris discusses South Korea's energy research institute networks being compromised by North Korean threat actors - how did they gain access?- The team talk new NATO agreements that put cybersecurity at the forefrontGet this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/weekly-intelligence-summary-25-june ***Resources from this week’s podcast***Google Supply Chain Attach Framework - https://security.googleblog.com/2021/06/introducing-slsa-end-to-end-framework.html Supply Chain Awareness: https://www.sonatype.com/hubfs/Corporate/Software%20Supply%20Chain/2020/SON_SSSC-Report-2020_final_aug11.pdf South Korea Energy Compromise: https://www.bleepingcomputer.com/news/security/south-koreas-nuclear-research-agency-hacked-using-vpn-flaw/ VPN Attack Study: https://www.helpnetsecurity.com/

  • Special: Pulsedive Founders Dan and Grace Talk Origins, IOCs, and More

    24/06/2021 Duration: 43min

    Digital Shadows CISO Rick and Senior Cyber Threat Intel Analyst Sean Nikkel host this edition of ShadowTalk. They're joined by special guests Dan Sherry and Grace Chi, founders of Pulsedive. They discuss:-Dan & Grace's origin stories and how Pulsedive came to be -Grace's LinkedIn “Sides of Cyber” campaign, promoting unknown talents and how they enrich people's lives-IOCs aren't dead - how IOCs can be leveraged as part of a broader program-How to kick the tires on Pulsedive - they even include free API access ***Resources from this special podcast***Find Dan on Twitter: https://twitter.com/netbroom Find Dan on LinkedIn: https://www.linkedin.com/in/netbroom/ Find Grace on Twitter: https://twitter.com/euphoricfall Find Grace on LinkedIn: https://www.linkedin.com/in/graceschi/ Company Homepage: https://pulsedive.com/about/

  • Weekly: VPN Vulnerabilities, EA Gets Attacked, Plus Clop Deals With Affiliate Arrests

    18/06/2021 Duration: 20min

    ShadowTalk hosts Sean, Ivan, and Charles bring you the latest in threat intelligence. This week they cover:- The team discusses the most recent EA breach - what’s the history of attacks against software/game developers?- Charles dives into the latest on VPN vulnerabilities - why does this problem persist? - Ivan talks about Clop arrests - how big of a player is Clop in the world of cyber crime?- Predictions for the ransomware scene in the future - can we expect more intervention by law enforcement? Get this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/weekly-intelligence-summary-18-june ***Resources from this week’s podcast***EA Breach: https://www.vice.com/en/article/7kvkqb/how-ea-games-was-hacked-slack https://www.vice.com/en/article/wx5xpx/hackers-steal-data-electronic-arts-ea-fifa-source-code VPN Vulnerabilities: https://apnews.com/article/government-and-politics-hacking-technology-business-7350235e07d46ba5afc1238b553ea4b9 Clop arrests: https://krebsonsecurity.com/20

  • Special: Anomali’s AJ Nash Talks Origin Story, Building Threat Intel Teams, and More!

    16/06/2021 Duration: 51min

    Digital Shadows CISO Rick and Senior Cyber Threat Intel Analyst Sean host this guest edition of ShadowTalk. Anomali's Sr. Director of Cyber Intelligence Strategy, AJ Nash, joined them to discuss:- AJ's origin story with the U.S. Air Force - AJ's lessons from building threat intelligence teams - The need for intelligence leaders to be more strategic and move beyond IOCs and the SOC - AJ's new blog where he proposed the Chief Intelligence Officer (CINO)***Resources from this special podcast***Find AJ on LinkedIn: https://www.linkedin.com/in/nashaj/Rise of the Chief Intelligence Officer (CINO): https://www.anomali.com/blog/rise-of-the-chief-intelligence-officer-cino

  • Weekly: Chinese Cyber Espionage, GitHub Takedowns, and EURO 2020 Predictions

    11/06/2021 Duration: 56min

    ShadowTalk hosts Stefano, Adam, Chris, and newcomer, Rory, bring you the latest in threat intelligence. This week they cover:-Adam takes us through the latest cyber espionage campaigns attributed to Chinese-state-sponsored APT groups-Rory discusses a sophisticated law enforcement campaign targeting criminal syndicates all over the world-Chris dives into the new GitHub policies - what led to these new guidelines?-The team talks about updates on the Colonial Pipeline incident - what’s the latest?-Plus, the group makes EURO 2020 predictionsGet this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/weekly-intelligence-summary-11-june ***Resources from this week’s podcast***SharpPanda/Chinese APT - https://research.checkpoint.com/2021/chinese-apt-group-targets-southeast-asian-government-with-previously-unknown-backdoorLaw Enforcement Op - https://www.bleepingcomputer.com/news/security/fbi-and-afp-created-a-fake-encrypted-chat-platform-to-catch-criminals/ GitHub Takedown Policy: ht

  • Weekly: Nobelium Attacks, VMWare Exploits, and the Biden Administration’s Letter on Ransomware

    04/06/2021 Duration: 23min

    ShadowTalk hosts Sean, Alec, Charles, and Digital Shadows CISO, Rick Holland, bring you the latest in threat intelligence. This week they cover:- Alec dives into Nobelium - who are they and what happened in the latest attack?- Charles takes us through VMWare exploits - how does it compare to earlier vulnerabilities?- Rick discusses the Biden Administration’s open letter to business leaders on the state of ransomware - Plus, check out our latest content including thoughts on the 2021 Verizon DBIRGet this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/weekly-intelligence-summary-04-june ***Resources from this week’s podcast***Nobelium: https://www.techrepublic.com/article/solarwinds-hackers-resurface-to-attack-government-agencies-and-think-tanks/ VMWare: https://arstechnica.com/gadgets/2021/05/vulnerability-in-vmware-product-has-severity-rating-of-9-8-out-of-10/ https://www.vmware.com/security/advisories/VMSA-2021-0010.html President’s Note on Ransomware Threats: https://ww

  • Special: The State of the APAC Cyber Threat Landscape

    03/06/2021 Duration: 51min

    ShadowTalk hosts Stefano, Adam, and Xue bring you the latest in threat intelligence for the APAC region. They cover:- Xue take us through how the APAC threat landscape has changed in the last 18 months- What are the prominent ransomware and APT groups and what are they up to?- The team discusses how cybersec institutions are using new regulations to offset some traditional challenges- Adam talks about the Tokyo 2020 threat landscape and how it's been shaped by the event postponement due to COVID-19***Resources from this week’s podcast***State of APAC: https://www.paloaltonetworks.com/blog/2020/03/policy-asia-pacific/ https://techwireasia.com/2019/10/cybersecurity-customer-experience-trust-asia-apac/ https://techwireasia.com/2021/03/apac-is-in-need-for-more-cybersecurity-experts/ https://www.zdnet.com/article/colonial-pipeline-attack-used-to-justify-australias-critical-infrastructure-bill/ https://www.zdnet.com/article/security-crucial-as-5g-connects-more-industries-devices/ https://www.zdnet.com/article/

  • Weekly: Drug Kingpin Taken Down by Cheese and Ransomware Makes a Comeback

    28/05/2021 Duration: 45min

    ShadowTalk hosts Stefano, Adam, Kim, and Dylan bring you the latest in threat intelligence. This week they cover:- Dylan discusses how cheese was the downfall of a drug dealer in the UK and how a cybercriminal messaging forum contributed- Kim talks ransomware - how ransom demands stole the spotlight from supply-chain attacks- Avaddon victims refuse to pay ransom demands - what happened?- Adam dives into politically motivated ransomware Get this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/weekly-intelligence-summary-28-may ***Resources from this week’s podcast***Stilton Incident: https://en.wikipedia.org/wiki/Geronimo_Stilton https://www.theguardian.com/food/2021/may/24/feeling-blue-drug-dealers-love-of-stilton-leads-to-his-arrest Politically Motivated Ransomware: https://assets.sentinelone.com/sentinellabs/evol-agrius MTNOW: https://blog.malwarebytes.com/cybercrime/malware/2021/05/bizarro-a-banking-trojan-full-of-nasty-tricks/ MTTPOTW: https://attack.mitre.org/techniqu

  • Special: Jeff Stone Discusses His Origin Story, Interviewing Cybercriminals, and More!

    25/05/2021 Duration: 45min

    Digital Shadows CISO Rick hosts this edition of ShadowTalk. He’s joined by special guest and friend Jeff Stone, Editor at CyberScoop News. They discuss: - Jeff's origin story - Parallels between journalism and threat intelligence - How journalists validate sources - Why "It's better to be right than first"- The go-to defense lawyer for Russian and Eastern European cybercriminals- The nuance around interviewing cybercriminals***Resources from this special podcast*** Find Jeff on Twitter: https://twitter.com/jeffstone500 CyberScoop:https://www.cyberscoop.com/ https://twitter.com/CyberScoopNews CyberScoop CyberTalks Virtual Summit https://www.cyberscoop.com/events/cybertalks/ "How Arkady Bukh, a New York-based immigrant from the former Soviet bloc, emerged as the go-to defense lawyer for the cybercrime underworld."https://www.cyberscoop.com/story/arkady-bukh-man-in-the-middle/

  • Weekly: Colonial Pipeline Updates, DarkSide Feels the Pressure, and More!

    21/05/2021 Duration: 29min

    ShadowTalk hosts Sean, Alec, Ivan, and Charles bring you the latest in threat intelligence. This week they cover:- Ivan takes us through the latest updates on DarkSide and the Colonial Pipeline incident - DarkSide faces consequences - The team talks about new legislation from the US government - better late than never?- Plus, our hosts dive into all things ransomware - what’s happening with the cyber threat landscape?- Alec brings us the latest on Conti ransomware targeting Ireland's Department of Health - what was the impact?- Charles discusses a new web skimmer indicating ongoing Magecart activityGet this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/weekly-intelligence-summary-21-may ***Resources from this week’s podcast***Colonial Pipeline Updates: https://www.bankinfosecurity.com/2-bills-introduced-in-wake-colonial-pipeline-attack-a-16666 Conti Ransomware: https://www.bleepingcomputer.com/news/security/conti-ransomware-also-targeted-irelands-department-of-healt

  • Weekly: The Colonial Pipeline Incident, BEC Gift Card Campaigns, and More!

    14/05/2021 Duration: 47min

    ShadowTalk hosts Stefano, Chris, Kim, and Xue bring you the latest in threat intelligence. This week they cover:- Xue takes us through the Colonial Pipeline ransomware incident - DarkSide’s involvement and more - What does the attack on the Colonial Pipeline indicate for future cyber threats against critical infrastructure?- Chris dives into the BEC incident - what does it mean and what happened? - Kim discusses the Bulletproof Hosting indictment - what is the impact?Get this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/weekly-intelligence-summary-14-may ***Resources from this week’s podcast***Colonial Pipeline: https://www.fbi.gov/news/pressrel/press-releases/fbi-statement-on-compromise-of-colonial-pipeline-networksDarkSide: https://www.digitalshadows.com/blog-and-research/darkside-the-new-ransomware-group-behind-highly-targeted-attacks/ Gift Card Scam: https://www.microsoft.com/security/blog/2021/05/06/business-email-compromise-campaign-targets-wide-range-of-orgs-with-

  • Special: David Thejl-Clayton Talks Data Driven Incident Response and Verizon DBIR

    14/05/2021 Duration: 43min

    Digital Shadows CISO Rick hosts this edition of ShadowTalk. He’s joined by special guest David Thejl-Clayton , Senior Advisor in Cyber Defense at Combitech. They discuss: - David talks origin story, his journey through CTI, and his current role at Combitech - His obsession with data driven response and how that data-love came to be- He and Rick reminisce about favorite speakers at SANS- They discuss the Verizon DBIR - what’s to come?- Purple-teaming - how to bring value to organizations through data***Resources from this week’s podcast***Find David on Twitter: https://twitter.com/DCSecuritydk Find David on LinkedIn: https://www.linkedin.com/in/davidclayton454/ Data Driven Incident Response: https://www.youtube.com/watch?v=Ll60XUJnRTw SANS CTI Summit - VERISIZE your way into CTI: https://www.youtube.com/watch?v=AwMC6INC5TE https://www.sans.org/blog/a-visual-summary-of-sans-cyber-threat-intelligence-summit/ Vocabulary for Event Recording and Information Sharing (VERIS): http://veriscommunity.net/ 2020 Data Brea

  • Weekly: VPN Vulnerabilities, Supply Chain Attacks, and Babuk Says “Bye”!

    07/05/2021 Duration: 34min

    ShadowTalk hosts Alec, Ivan, Sean, and Digital Shadows CISO, Rick, bring you the latest in threat intelligence. This week they cover:- Sean discusses Pulse Secure VPN vulnerabilities - what are the latest updates and who is being targeted?- The team talks about supply chain compromise - what is it?- Sean takes us through the DDoS attack on Belnet - Babuk is hanging up their hat - Ivan brings us the latest- Ryuk gets ahold of bio research through a studentGet this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/weekly-intelligence-summary-07-may ***Resources from this week’s podcast***Pulse Secure: https://www.bleepingcomputer.com/news/security/pulse-secure-fixes-vpn-zero-day-used-to-hack-high-value-targets/ Belnet: https://www.zdnet.com/article/this-massive-ddos-attack-took-large-sections-of-a-countrys-internet-offline/ Babuk: https://threatpost.com/babuk-ransomware-gang-mulls-retirement/165742/ Ryuk: https://www.zdnet.com/article/ryuk-ransomware-finds-foothold-in-bio-resea

  • Special: Amy Bejtlich Talks Culture of Candor Within Intel Teams and More!

    06/05/2021 Duration: 33min

    Digital Shadows CISO, Rick, hosts this edition of ShadowTalk. He’s joined by special guest Amy Bejtlich, Director of Intelligence Analysis at Dragos, Inc. They discuss: - Amy’s origin story and journey from traditional intelligence to cyber intelligence- How to "bloom where you are planted" - Her various SANS cyber threat intel presentations- How to build a "culture of candor" within an intel team - Minimizing burnout and supporting the mental health of teams***Resources from this week’s podcast***Find Amy on Twitter: https://twitter.com/_Silent_J Find Amy on LinkedIn: https://www.linkedin.com/in/amybejtlich/ SANS New to Cyber Summit: "Job Role Spotlight - Cyber Threat Intelligence": https://sansorg.egnyte.com/dl/TjsPnHluNo/? SANS 2019 CTI Summit Video: "Analytic Tradecraft In The Real World": https://www.youtube.com/watch?v=MWJZsW9HooY SANS 2019 CTI Summit slides: Analytic Tradecraft In The Real World": https://sansorg.egnyte.com/dl/MnytUZPcOU/?

  • Special: ShadowTalk’s 200th Episode!

    30/04/2021 Duration: 01h09min

    It’s a full house with ShadowTalk hosts Stefano, Alec, Charles, Kim, Dylan, Adam, and Digital Shadows CISO, Rick! The team is looking back at three years of ShadowTalk and taking us on a journey through changes in the threat landscape. They discuss: - Adam and Alec take us through ransomware heavy hitters from the last few years - Big game hunting, double-extortion, and more- The team reminisce about their first time joining ShadowTalk - Kim and Rick tackle supply-chain attacks - looking back at SolarWinds and the role of trust- Most embarrassing moments in ShadowTalk history- Dylan and Charles talk CVE’s - more on opportunistic attackers taking advantage of Covid-19 and remote work- Final thoughts from the team - what would you tell your 2018 self?Check out the video recording of the podcast here: https://resources.digitalshadows.com/digitalshadows/special-shadowtalk-s-200th-episode Get this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/weekly-intelligence-summary-30-apr

  • Weekly: Supply Chain Attacks Rule The Day, Plus The FBI Takes On Web-Shells

    23/04/2021 Duration: 24min

    ShadowTalk hosts Alec, Ivan, Charles, and newcomer, Sean, bring you the latest in threat intelligence. This week they cover:- Ivan dives into FBI actions against web-shells from compromised Exchange servers- Codecov supply chain attacks - Charles brings us the latest - The team discuss the Pulse Secure VPN bug - Plus, don’t forget our special 200th episode next week! Get this week’s intelligence summary at: https://resources.digitalshadows.com/digitalshadows/weekly-intelligence-summary-23-april ***Resources from this week’s podcast***FBI Web Shells: https://www.welivesecurity.com/2021/04/14/fbi-removes-malware-compromised-exchange-servers/Codecov: https://www.bleepingcomputer.com/news/security/hundreds-of-networks-reportedly-hacked-in-codecov-supply-chain-attack/REvil vs. Apple: https://www.bleepingcomputer.com/news/security/revil-gang-tries-to-extort-apple-threatens-to-sell-stolen-blueprints/Pulse Secure VPN: https://www.bleepingcomputer.com/news/security/pulse-secure-vpn-zero-day-used-to-hack-defense-firms-

page 13 from 23