『Security Squawk - The Business of Cybersecurity』のカバーアート

Security Squawk - The Business of Cybersecurity

Security Squawk - The Business of Cybersecurity

著者: Bryan Hornung Reginald Andre & Randy Bryan
無料で聴く

【Amazonプライム会員限定】今ならプレミアムプランが4か月 月額99円。

10月19日まで。※適用条件あり

Security Squawk is a business podcast dedicated to helping business people fight the war against cyber criminals.

Copyright 2026 by Bryan Hornung Reginald Andre & Randy Bryan
マネジメント マネジメント・リーダーシップ 政治・政府 経済学
エピソード
  • AECOM Hit by Two Gangs at Once, CenterPoint Leaks 7.5M Records, Ransomware Sets a Record
    2026/09/23
    Two ransomware crews are claiming the same Fortune 500 company at the same time. It's the second week in a row this has happened. If you still think your business is too small to be worth a hacker's time, this is the week that idea dies. *You're not facing one attacker anymore, you're facing a market of them.* Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for executives, owners, and operators who don't have time to follow cyber news but can't afford to be blindsided. First up: AECOM, a sixteen-billion-dollar engineering giant, is being claimed by two ransomware gangs in the same week. One lists 1.22 terabytes of stolen data. The other lists about 670 gigabytes. Same victim, side by side. More than 27,000 company email accounts are alleged to be floating around the dark web, and class-action lawyers filed before AECOM confirmed anything. For now, it all remains alleged. When a company this size gets picked over by two crews at once, budget and size aren't the shields many assumed they were. Then Randy takes CenterPoint Energy, the Houston utility serving about seven million customers across four states. A hacker walked off with 7.49 million customer records, including names, addresses, account numbers, and partial Social Security numbers. The wild part: there was no sophisticated break-in. The attacker simply counted upward through the ID numbers on CenterPoint's public website because nobody limited how many records it would return. Any business with a customer-facing app can have this exact hole. The lawsuits arrived before the company even disclosed the breach. Reginald closes with the number tying it all together. August 2026 was the worst month for ransomware ever recorded: 997 attacks, an all-time high averaging thirty-two a day. Business targets took the brunt, with law firms, tech companies, and finance firms rising fastest. Attacks on utilities doubled in a single month. Zoom out, and the picture gets worse: more than 7,500 victims over the past year, up nearly 25 percent, with over 60 brand-new gangs appearing. That's better than one a week. This flood of new crews is exactly why one victim now gets claimed by two of them. Here's the takeaway for owners: the boring basics still win. Turn on that second login code everywhere, quickly patch anything facing the internet, and keep backups you have actually tested. None of that requires a big budget. It stops the large majority of what we cover. • A Fortune 500 engineering firm gets claimed by two ransomware gangs in the same week • A utility leaks 7.5 million customer records through a wide-open public website • August 2026 becomes the worst month for ransomware ever recorded • Why you're now up against a whole market of attackers, not just one • The cheap, boring defenses that still stop most attacks • Why "we're too small to be a target" no longer holds up Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #AECOM #CenterPointEnergy #Ransomware #DataBreach #BusinessRisk #SmallBusiness #MSP #Utilities #Infosec #CyberRisk
    続きを読む 一部表示
    38 分
  • Florida DMV Breached by a Stolen Police Login. 347K Trezor Users Phished
    2026/09/14
    A criminal crew broke into Florida's DMV database and proved it by leaking Jeffrey Epstein's driver record. They didn't hack the system. They used a police login stored on a personal device. If one stolen password can open a government database, what does that say about the logins running your business? Your security is only as strong as the login you handed someone else. Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's cyber stories for executives, owners, and operators who can't afford to be blindsided. First, Florida. The state confirmed its DAVID driver database was breached after a crew called ShinyHunters used login credentials stolen from a single police officer. Those credentials were stored on the officer's personal device. The group claims it took more than 200,000 driver records. Full names, addresses, dates of birth, and license numbers can fuel identity theft and fraud for years. This wasn't a genius hack. It was one careless login. That's what should scare every business owner. Next, Trezor. The company makes hardware wallets designed to keep crypto offline and safe, yet 347,000 newsletter subscribers received a phishing email that sailed past every spam filter. It came through Trezor's own account after attackers breached Brevo, the marketing platform Trezor uses to send email. The message faked an urgent security alert to trick people into surrendering the secret backup that unlocks their crypto. BitBox and CoinTracking were hit through the same vendor. Trezor killed the fake link in about 20 minutes, but 2,500 people had already clicked. Your customers can be attacked through your brand even when everything you control is locked down. Finally, Interim HealthCare. The home-health provider operates across more than 40 states, and two separate ransomware gangs claimed they hit it this summer. Genesis said it took a full terabyte of medical records and patient data. Anubis claimed a separate haul of franchisee financials and internal audits. When the ransom went unpaid, the data was leaked anyway. Paying a criminal buys a promise, not your privacy back. If you run multiple locations, the attacker only needs your weakest one. In this episode, we discuss: • How a police login stored on a personal device opened Florida's DMV database to ShinyHunters. • How attackers phished 347,000 Trezor users by hijacking a trusted email vendor. • How two ransomware gangs hit Interim HealthCare and leaked the data despite the pressure. • Why your security is only as strong as the login you handed someone else. • What business owners should do about vendor access and stolen credentials before it's their turn. • Why paying a ransom is a promise from a criminal, not a recovery plan. Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #DataBreach #Trezor #Ransomware #Phishing #VendorRisk #IdentityTheft #Healthcare #BusinessRisk #ShinyHunters #MSP
    続きを読む 一部表示
    42 分
  • LA Metro Hit by Ransomware, 153M Licenses for Sale, AI Breaches a Network in 10 Hours
    2026/09/08
    LA Metro, the transit system that moves nearly 10 million people in Los Angeles, just appeared on a ransomware gang's extortion site. A dark-web service is selling 153 million scanned driver's licenses. And security researchers watched AI break into a company and steal the master keys in under 10 hours. Three stories, one uncomfortable pattern. *Cybercrime is now an industry, and speed is the whole game.* Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for executives, owners, and operators who can't follow every cyber headline but can't afford to be blindsided. First up: LA Metro. A fast-growing ransomware crew called The Gentlemen posted the country's second-busiest transit system to its leak site, claiming it stole internal data. Here's what most coverage skips: this is a claim on a leak site, not a confirmed breach. There's no ransom demand and no statement from the agency. Bryan explains how to read a scary headline without confusing an allegation for a fact. These crews choose targets based on how much disruption they can cause, and public infrastructure is squarely in their sights. If your business creates real-world chaos when it goes down, you fit the profile. Then Randy tackles the story that should worry every business that scans an ID. A service called Nexus appeared offering searchable access to more than 153 million driver's licenses from the US and Canada. Investigative reporter Brian Krebs traced the data to an identity-verification vendor called IDScan.net. The FBI's New Orleans office opened a case the same day, reportedly after finding IDs belonging to a US Defense Secretary and an FBI Assistant Director in the pile. The vendor runs 21 million ID checks a month for names like Hertz, Target, and FedEx, so a leak there becomes a problem for many other companies. If a business scanned your license, your photo and address may have passed through a vendor you never chose and can't see. Reginald closes with the story that connects everything. Palo Alto Networks' Unit 42 documented a real attack in which a person directed AI agents at a company and let them run the break-in. The agents mapped the network, raided passwords hidden in the company's own code, and grabbed the master credentials in under 10 hours. That work would take a human team about two weeks. One boring control stopped them cold: a basic protection on the code pipeline blocked the backdoor. The lesson for owners is blunt. The fundamentals still work, but your window to catch an attack is now hours, not days. In this episode, we discuss: • A ransomware gang claims LA Metro, and how to tell a claim from a confirmed breach • A dark-web service selling 153 million driver's licenses and the FBI probe into the vendor behind it • AI agents that breached a company and stole root access in under 10 hours • Why cybercrime now scales like a business, and why speed is the whole game • The internet-facing gear and hidden passwords attackers hit first • What to ask every vendor that touches your customers' data Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #Ransomware #LAMetro #DataBreach #FBI #ArtificialIntelligence #VendorRisk #BusinessRisk #SMB #IdentityTheft #MSP Security Squawk
    続きを読む 一部表示
    47 分
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません