
Risky Business #672 -- "Expected behaviour" is in the eye of the beholder
Lord Sky
Description
<p>On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:</p> <ul> <li>A look at the DHS Cyber Safety Review Board’s Log4j report</li> <li>Joshua Schulte no longer the “alleged” Vault7 leaker</li> <li>Chinese APT crews targeted US political journalists before Jan 6</li> <li>Ransomware gangs make leak sites searchable</li> <li>Why recovering plaintext passwords from Okta is expected behaviour</li> <li>US Government seizes North Korean ransomware payment</li> <li>Much, much more</li> </ul> <p>This week’s show is brought to you by Trail of Bits. Dan Guido is this week’s sponsor guest and he’ll tell us about work Trail of Bits did for DARPA on investigating blockchain security fundamentals.</p> <p>Links to everything that we discussed are below and you can follow <a href="https://twitter.com/riskybusiness">Patrick</a> or <a href="https://twitter.com/metlstorm">Adam</a> on Twitter if that’s your thing.</p> <div class="panel panel-default"> <div class="panel-heading"> <h3 class="panel-title">Show notes</h3> </div> <div class="panel-body"> <ul> <li><a href="https://twitter.com/riskybusiness/status/1547335152715825153">Patrick Gray on Twitter: "During our discussion yesterday on the show we didn’t know pre-existing MDM was preserved when iOS lockdown mode is enabled, which is great!" / Twitter</a></li> <li><a href="https://www.cyberscoop.com/cyber-safety-review-board-china-log4j/">DHS Cyber Safety Review Board found no evidence China knew of Log4j before disclosure</a></li> <li><a href="https://www.vice.com/en/article/m7geyn/ex-cia-hacker-convicted-for-one-of-the-most-damaging-acts-of-espionage-in-american-history">Ex-CIA Hacker Convicted for ‘One of the Most Damaging
Uploader
Episodes
Risky Business #672 -- "Expected behaviour" is in the eye of the beholder
Lord Sky