『Skyhigh Security CloudCast』のカバーアート

Skyhigh Security CloudCast

Skyhigh Security CloudCast

著者: Skyhigh Security CloudCast
無料で聴く

このコンテンツについて

Join our Data Experts in the following podcast episodes, as we talk about all things Data. As an organization’s biggest asset, the importance of protecting data in a space with no jurisdiction is paramount; particularly at a time when the risks of data breaches globally have never been more serious. Adhering to compliance regulations is also a key challenge facing organizations including FedGov and a critical component of how these organizations protect their data.
エピソード
  • CloudCast Cybersecurity Headlines for February 12th, 2025
    2025/02/12
    From the CloudCast Studios, I’m Scott Schlee, and these are your cybersecurity headlines for the week of Wednesday, February 12th, 2025. Headlines this week: Critical Remote Code Execution Vulnerability in Microsoft OutlookRansomware Payments Decline by 35% in 2024GrubHub Discloses Data Breach Affecting Users and PartnersSpyware Firm Cuts Ties with Italy Amid Targeting AllegationsMicrosoft Warns of Attacks Exploiting ASP.NET Machine KeysLazarus Group Targets Professionals with Job-Themed MalwareSparkCat Malware Campaign Targets Cryptocurrency WalletsSilent Lynx Group Targets Central Asian OrganizationsEngineer IMI Suffers Cyberattack Following Similar Incident at Smiths GroupTaiwan Bans DeepSeek AI Over National Security Concerns Thank you again for listening to Skyhigh Cloudcast. If you’ve enjoyed this episode, be sure to subscribe on your favorite platform so you never miss an update. If you like the show, please leave us a review. It helps others find the podcast. For more information about Skyhigh Security or CloudCast, please visit skyhighsecurity.com. Sources: Taiwan Bans DeepSeek AI Over National Security Concerns: diesec.comCritical Remote Code Execution Vulnerability in Microsoft Outlook: diesec.comRansomware Payments Decline by 35% in 2024: diesec.comGrubHub Discloses Data Breach Affecting Users and Partners: diesec.comSpyware Firm Cuts Ties with Italy Amid Targeting Allegations: diesec.comMicrosoft Warns of Attacks Exploiting ASP.NET Machine Keys: thehackernews.comLazarus Group Targets Professionals with Job-Themed Malware: thehackernews.comSparkCat Malware Campaign Targets Cryptocurrency Wallets: thehackernews.comSilent Lynx Group Targets Central Asian Organizations: thehackernews.comEngineer IMI Suffers Cyberattack Following Similar Incident at Smiths Group: cybersecurity-review.com ———– CloudCast is hosted by Skyhigh Security’s very own Digital Experience Manager, Scott Schlee. Scott’s engaging demeanor and wit, backed by over 20 years in digital media production and web development, has led to successful collaborations with top-tier brands. His experience includes hosting and producing a wide range of podcasts and videos. Scott has been recognized for his outstanding work, including an award-winning digital short and a Webby Awards nomination for Viral Marketing (Branded). Beyond his professional achievements, Scott’s personal journey as a decade-long pancreatic cancer survivor has led him to share his story with the U.S. Congress and other organizations as an advocate for increased cancer research funding. Transcript From the CloudCast Studios, I’m Scott Schlee, and these are your cybersecurity headlines for the week of Wednesday, February 12th, 2025. A Critical Remote Code Execution Vulnerability Has Been Discovered in Microsoft Outlook: The Cybersecurity and Infrastructure Security Agency issued an urgent alert about an actively exploited vulnerability in Microsoft Outlook. Attackers can execute remote code by bypassing Outlook’s protections using a simple URL trick, endangering sensitive data. Federal agencies and private organizations are urged to apply patches promptly to mitigate this threat. GrubHub Has Disclosed A Data Breach Affecting Users and Partners: Food delivery service GrubHub reported a data breach resulting from a compromised third-party service provider account. Exposed information includes names, emails, phone numbers, and partial payment details of some campus diners. GrubHub has terminated the unauthorized access, enhanced security measures, and advises users to maintain strong, unique passwords. Paragon Solutions Cuts Ties with Italy Amid Targeting Allegations: Israeli spyware company Paragon Solutions has severed relationships with its Italian clients following allegations that its software was used to target government critics. A recent spyware campaign affected 90 users across 24 countries, including journalists and activists, prompting an investigation by Italian authorities into the misuse of surveillance tools. Microsoft Warns of Attacks Exploiting ASP.NET Machine Keys: Microsoft identified over 3,000 publicly disclosed ASP.NET machine keys that attackers are exploiting to inject and execute malicious code using the Godzilla post-exploitation framework. This technique, known as ViewState code injection, poses significant risks to web applications. Organizations are advised to review and secure their ASP.NET configurations to prevent such attacks. Lazarus Group Is Targeting Professionals with Job-Themed Malware: The North Korean-linked Lazarus Group has launched a campaign using fake LinkedIn job offers in the cryptocurrency and travel sectors to distribute malware. The malicious code is capable of infecting Windows, macOS, and Linux systems, highlighting the group’s evolving tactics and the need for vigilance among professionals receiving unsolicited job communications. SparkCat Malware Campaign Is Targeting Cryptocurrency ...
    続きを読む 一部表示
    6 分
  • CloudCast Cybersecurity Headlines for February 5th, 2025
    2025/02/05
    From the Skyhigh Studios, I’m Scott Schlee, and these are your cybersecurity headlines for the week of Wednesday, February 5th, 2025. Headlines this week: Android Users Urged to Update Devices Due to Critical VulnerabilitiesSmiths Group Suffers Global CyberattackTalkTalk Investigates Potential Data BreachApple Releases Critical Security UpdatesLaw Enforcement Shuts Down Illicit Cybercrime ServicesGoogle Blocks Over 2 Million Risky Android Apps in 2024UnitedHealth Discloses Massive Data BreachDeepSeek AI Chatbot’s Data Exposure & Proposed US Government Ban Thank you again for listening to Skyhigh Cloudcast. If you’ve enjoyed this episode, be sure to subscribe on your favorite platform so you never miss an update. If you like the show, please leave us a review. It helps others find the podcast. For more information about Skyhigh Security or CloudCast, please visit skyhighsecurity.com. Sources: Android Users Urged to Update Devices Due to Critical Vulnerabilities: thesun.ieSmiths Group Suffers Global Cyberattack: thetimes.co.ukTalkTalk Investigates Potential Data Breach: thesun.ieApple Releases Critical Security Updates: diesec.comLaw Enforcement Shuts Down Illicit Cybercrime Services: thehackernews.comGoogle Blocks Over 2 Million Risky Android Apps in 2024: diesec.comUnited Health Discloses Massive Data Breach: diesec.comDeepSeek AI Chatbot’s Data Exposure: diesec.comLawmakers Advocate for DeepSeek Ban on Government Devices: wsj.com ———– CloudCast is hosted by Skyhigh Security’s very own Digital Experience Manager, Scott Schlee. Scott’s engaging demeanor and wit, backed by over 20 years in digital media production and web development, has led to successful collaborations with top-tier brands. His experience includes hosting and producing a wide range of podcasts and videos. Scott has been recognized for his outstanding work, including an award-winning digital short and a Webby Awards nomination for Viral Marketing (Branded). Beyond his professional achievements, Scott’s personal journey as a decade-long pancreatic cancer survivor has led him to share his story with the U.S. Congress and other organizations as an advocate for increased cancer research funding. Transcript Google released a security update addressing nearly 50 flaws in the Android operating system, including a high-severity vulnerability that could allow attackers to install malware or steal files without user authentication. Users are strongly advised to update their devices promptly to mitigate these risks. Smiths Group, a multinational engineering firm, experienced a cyberattack leading to unauthorized access to its systems. The company isolated the affected systems and is collaborating with cybersecurity experts to assess and recover from the incident. The breach resulted in a 1.7% drop in the company’s share price. Telecom company TalkTalk is investigating claims of a data breach after a hacker alleged they were selling data from nearly 19 million of the company’s current and former customers. The breach reportedly involves customer names, emails, IP addresses, and phone numbers, though no financial information is believed to be at risk. Apple issued updates to address a zero-day vulnerability (CVE-2025-24085) in its Core Media component, which could allow malicious applications to escalate privileges on affected devices. Users are advised to update their iPhones, Macs, and other Apple devices to the latest software versions to protect against potential exploits. A series of law enforcement operations led to the takedown of online marketplaces such as Cracked, Nulled, Sellix, StarkRDP, and HeartSender, which were involved in selling hacking tools, illegal goods, and crimeware solutions. These actions impacted millions of users and disrupted significant illegal activities. Google reported that it blocked a record 2.3 million harmful Android apps from the Play Store in 2024, utilizing AI-powered reviews to detect threats more efficiently. Additionally, 158,000 developer accounts were banned for attempting to distribute malware, highlighting ongoing efforts to secure the app ecosystem. UnitedHealth revealed that a data breach in 2024 affected approximately 190 million Americans, making it the largest healthcare data breach in U.S. history. The compromised information includes personal and healthcare data, underscoring the critical need for robust data protection measures in the healthcare sector. Our final stories this week focus on DeepSeek, the Chinese-developed AI chatbot, facing major security concerns. Released on January 10, 2025, for iOS and Android, it quickly became the most-downloaded free app on the U.S. iOS App Store by January 27, surpassing even ChatGPT. Researchers have recently discovered that the platform exposed over a million lines of sensitive data online, including software keys and user chat logs, raising serious privacy risks. U.S. lawmakers are now pushing to ban DeepSeek from ...
    続きを読む 一部表示
    5 分
  • CloudCast Cybersecurity Headlines for January 15, 2025
    2025/01/15
    From the Skyhigh Studios at Skyhigh Security, I’m Scott Schlee, it’s Wednesday, January 15, 2025, and these are your cybersecurity headlines. Headlines this week: US Treasury Department Reports A Significant Data BreachChina Protests US Sanctions Over Cyber ActivitiesBayview Asset Management Agrees to a $20 Million SettlementApple Proposes a $95 Million Siri Privacy SettlementSophisticated AI-Driven Phishing Scams Are Targeting Email UsersMyanmar Enacts a Cybersecurity Law Enforcing Internet CensorshipUS Cybersecurity Experts Predict Increased Post-Election Cyber AttacksFormer US Federal Officials Recommend Cybersecurity Policies for the Upcoming Trump AdministrationProject 2025’s Proposed Changes and Their Potential Impact on US Election SecurityAnd Concerns Over Quantum Computing’s Impact on Cybersecurity Before diving into this week’s headlines, we want to take a moment to acknowledge the devastating wildfires currently impacting California. Our thoughts are with everyone affected, including those who have lost homes, loved ones, or are facing displacement. As always, we encourage listeners to support relief efforts if they’re able. Please visit Charity Navigator for a list of trusted organizations offering support. Thank you again for listening to Skyhigh Cloudcast. If you’ve enjoyed this episode, be sure to subscribe on your favorite platform so you never miss an update. If you like the show, please leave us a review. It helps others find the podcast. For more information about Skyhigh Security or CloudCast, please visit skyhighsecurity.com. Sources: US Treasury Department Breach: US NewsChina Protests US Sanctions Over Cyber Activities: US NewsBayview Asset Management’s $20 Million Settlement: WSJApple’s $95 Million Siri Privacy Settlement: VoxAI-Driven Phishing Scams Targeting Email Users: New York PostMyanmar’s Cybersecurity Law Enforces Internet Censorship: AP NewsUS Cybersecurity Experts Predict Increased Cyber Attacks Post-Election: The AustralianQuantum Computing’s Impact on Cybersecurity: The TimesFormer Officials Recommend Cybersecurity Policies for Next Administration: POLITICOProject 2025’s Potential Impact on US Election Security: WIRED ———– CloudCast is hosted by Skyhigh Security’s very own Digital Experience Manager, Scott Schlee. Scott’s engaging demeanor and wit, backed by over 20 years in digital media production and web development, has led to successful collaborations with top-tier brands. His experience includes hosting and producing a wide range of podcasts and videos. Scott has been recognized for his outstanding work, including an award-winning digital short and a Webby Awards nomination for Viral Marketing (Branded). Beyond his professional achievements, Scott’s personal journey as a decade-long pancreatic cancer survivor has led him to share his story with the U.S. Congress and other organizations as an advocate for increased cancer research funding. Transcript From the Skyhigh Studios at Skyhigh Security, I’m Scott Schlee, and these are your cybersecurity headlines for the week of January 6th, 2025. The U.S. Treasury Department reported a significant cyber incident attributed to Chinese state-backed hackers. Attackers remotely accessed employee workstations and unclassified documents, raising concerns about the security of federal systems. The Cybersecurity and Infrastructure Security Agency (CISA) stated there is no indication that other federal agencies were affected. The U.S. Treasury Department imposed sanctions on Beijing-based Integrity Technology Group for its alleged involvement in hacking incidents targeting U.S. critical infrastructure. China condemned the sanctions, denying the allegations and accusing the U.S. of defamation. This development underscores escalating cyber tensions between the two nations. Bayview Asset Management agreed to a $20 million settlement following a 2021 data breach that exposed personal information of 5.8 million customers. The firm faced criticism for inadequate cybersecurity measures and lack of cooperation with regulatory investigations. As part of the settlement, Bayview will enhance its cybersecurity protocols and undergo independent assessments. Apple proposed a $95 million settlement in a class-action lawsuit alleging unlawful surveillance through Siri. The lawsuit followed revelations that Siri had inadvertently recorded private conversations. Affected users between 2014 and 2024 may be eligible for compensation, highlighting ongoing concerns about digital privacy and device eavesdropping. Cybersecurity experts warned Gmail, Outlook, and Apple Mail users about sophisticated phishing scams utilizing artificial intelligence. These AI-generated emails are highly personalized, making them difficult to distinguish from legitimate correspondence. Users are advised to verify email senders, avoid clicking on suspicious links, and implement two-factor authentication to enhance security. ...
    続きを読む 一部表示
    7 分
まだレビューはありません