Risk & Repeat The seemingly endless stream of cyberattacks and data breaches have put enterprises and the information security industry on their heels. TechTarget SearchSecurity editors Rob Wright and Peter Loshin travel through this dark world of hacks, vulnerabilities and repeated infosec failings to discuss why we’ve arrived at this point, and what can be done to improve things.
- Risk & Repeat: Sorting out Snowflake’s security messby Alexander Culafi on June 5, 2024 at 7:44 pm
This podcast episode discusses the recent attacks against Snowflake customers and a controversial report that claimed the cloud storage and analytics giant had been breached.
- Risk & Repeat: Alphv/BlackCat’s chaotic exit (scam)by Alexander Culafi on March 7, 2024 at 9:06 pm
This podcast episode discusses the possible exit scam of ransomware-as-a-service gang Alphv/BlackCat, as well as the chaotic months the gang had leading up to its closure.
- Risk & Repeat: LockBit resurfaces after takedownby Alexander Culafi on February 27, 2024 at 9:04 pm
LockBit returns just days after an international law enforcement operation infiltrated the ransomware gang’s network and seized infrastructure, source code and decryption keys.
- Risk & Repeat: Breaking down SEC charges against SolarWindsby Alexander Culafi on November 1, 2023 at 9:51 pm
This episode covers the SEC charges against SolarWinds and CISO Timothy Brown for allegedly hiding known cybersecurity risks prior to the 2020 supply chain attack it suffered.
- Risk & Repeat: Okta under fire after support system breachby Alexander Culafi on October 26, 2023 at 7:03 pm
This podcast episode covers a security breach suffered by identity vendor Okta involving its customer support systems, which has sparked criticism from customers.
- Risk & Repeat: Rapid Reset and the future of DDoS attacksby Alexander Culafi on October 12, 2023 at 7:09 pm
This podcast episode covers the record-breaking DDoS attack Rapid Reset, why it stands out among other DDoS campaigns and whether it will be widely replicated in the future.
- Risk & Repeat: MGM, Caesars casino hacks disrupt Las Vegasby Alexander Culafi on September 19, 2023 at 8:09 pm
This podcast episode compares the cyber attacks suffered by casino giants MGM Resorts and Caesars Entertainment in recent weeks and the fallout from them.
- Risk & Repeat: Big questions remain on Storm-0558 attacksby Alexander Culafi on September 12, 2023 at 7:33 pm
Microsoft revealed that Storm-0558 threat actors stole a consumer signing key from its corporate network, but many questions about the breach and subsequent attacks remain.
- Risk & Repeat: Digging into Microsoft security criticismsby Alexander Culafi on August 30, 2023 at 8:51 pm
Executives, researchers and former employees told TechTarget Editorial about issues with Microsoft security practices, including patch bypasses, poor transparency and more.
- Risk & Repeat: Highlights from Black Hat USA 2023by Alexander Culafi on August 17, 2023 at 6:58 pm
Black Hat USA 2023 in Las Vegas covered several trends, such as generative AI and cloud security issues, as well as new vulnerabilities, including the Downfall flaw in Intel chips.
- Risk & Repeat: Microsoft takes heat over Storm-0558 attacksby Alexander Culafi on August 3, 2023 at 5:48 pm
The Storm-0558 attacks have raised questions about Microsoft’s response to a cloud flaw and a stolen MSA key that was used to compromise customer email accounts.
- Risk & Repeat: Are data extortion attacks ransomware?by Alexander Culafi on July 20, 2023 at 6:29 pm
Ransomware gangs are focusing more on data theft and extortion, while skipping the encryption of networks. But should these attacks still be considered ransomware?
- Risk & Repeat: How bad is Clop’s MoveIt Transfer campaign?by Alexander Culafi on July 11, 2023 at 8:39 pm
Clop’s data theft and extortion campaign against MoveIt Transfer customers marks some of the most high-profile threat activity this year, but its success level remains unclear.
- Risk & Repeat: More victims emerge from MoveIt Transfer flawby Alexander Culafi on June 20, 2023 at 9:56 pm
CISA last week said several federal agencies suffered data breaches resulting from a MoveIt Transfer zero-day vulnerability, though it’s unclear what type of data was stolen.
- Risk & Repeat: Mandiant sheds light on Barracuda ESG attacksby Alexander Culafi on June 15, 2023 at 9:52 pm
Barracuda Networks attempted to fix the critical ESG zero-day vulnerability, but a Chinese nation-state threat actor was able to maintain access on compromised devices.
- Risk & Repeat: Moveit Transfer flaw triggers data breachesby Alexander Culafi on June 8, 2023 at 7:04 pm
Several organizations, predominantly in the U.K., have confirmed data breaches that stemmed from exploitation of the critical Moveit Transfer zero-day vulnerability.
- Risk & Repeat: A troubling trend of poor breach disclosuresby Alexander Culafi on May 25, 2023 at 4:30 pm
This Risk & Repeat episode covers three data breach disclosures from Dish Network, Gentex Corporation and Clarke County Hospital and the troubling trends that connect all three.
- Risk & Repeat: Ex-Uber CSO Joe Sullivan sentencedby Alexander Culafi on May 9, 2023 at 3:40 pm
This podcast episode covers the sentencing of former Uber CSO Joe Sullivan over the 2016 breach cover-up, and what it means for other security executives and the industry at large.
- Risk & Repeat: Security industry bets on AI at RSA Conferenceby Alexander Culafi on May 2, 2023 at 4:52 pm
This podcast episode covers the focus on AI-powered security products and uses at RSA Conference 2023 in San Francisco last week, as well as other trends at the show.
- Risk & Repeat: Inside the 3CX supply chain attackby Alexander Culafi on April 4, 2023 at 6:54 pm
This podcast episode discusses the 3CX supply chain attack, where it may have started, who was behind it and how the unified communications vendor has responded to the incident.
- BreachForums taken down after arrest of alleged ownerby Alexander Culafi on March 22, 2023 at 7:29 pm
This Risk & Repeat podcast episode covers the arrest of BreachForums’ alleged owner and the site’s subsequent closure, as well as possible connections to the DC Health Link breach.
- Hacker claims exposed database led to DC Health Link breachby Alexander Culafi on March 15, 2023 at 12:55 pm
This Risk & Repeat podcast episode covers the breach of health insurance exchange DC Health Link, as well as a hacker’s claim that the breach was caused by an exposed database.
- Biden administration raises software liability questionsby Alexander Culafi on March 7, 2023 at 8:41 pm
This Risk & Repeat podcast episode discusses the White House’s National Cybersecurity Strategy and its proposal to hold technology companies liable for insecure software.
- ESXiArgs attack vector unclear as infections continueby Alexander Culafi on February 15, 2023 at 2:26 pm
This Risk & Repeat podcast episode discusses the recent developments involving ESXiArgs, the ransomware variant that has been infecting vulnerable VMware ESXi servers this month.
- ESXiArgs ransomware campaign raises concerns, questionsby Rob Wright on February 8, 2023 at 6:29 pm
This Risk & Repeat podcast looks at the widespread ESXiArgs ransomware attacks and the questions they’ve raised about the threat landscape, vulnerability patching and more.
- Risk & Repeat: The FBI’s Hive ransomware takedownby Alexander Culafi on January 31, 2023 at 9:24 pm
This podcast episode discusses the law enforcement operation that led to the infiltration and takedown of the Hive network and what it could mean for other ransomware gangs.
- Risk & Repeat: Another T-Mobile data breach disclosedby Alexander Culafi on January 24, 2023 at 8:35 pm
This podcast episode discusses the latest T-Mobile breach — the third in less than three years — in which a threat actor stole personal data from 37 million customer accounts.
- Risk & Repeat: Breaking down the LastPass breachby Alexander Culafi on January 20, 2023 at 5:04 pm
This podcast episode discusses the fallout of the recent LastPass breach, in which a threat actor stole encrypted logins and unencrypted website URLs from the password manager.
- Risk & Repeat: Analyzing the Rackspace ransomware attackby Alexander Culafi on January 10, 2023 at 3:55 pm
This Risk & Repeat podcast episode discusses new details of the Rackspace ransomware attack, as well as the questions remaining following the company’s final status update.
- Risk & Repeat: OT security progress, threats in 2022by Alexander Culafi on December 21, 2022 at 4:20 pm
This Risk & Repeat podcast episode discusses the current state of OT security, including the convergence with IT environments and an ever-evolving threat landscape.
- Risk & Repeat: Breaking down Rackspace ransomware attackby Alexander Culafi on December 8, 2022 at 9:47 pm
This Risk & Repeat podcast episode discusses the recent ransomware attack against cloud provider Rackspace, as well as the major service outage affecting its customers.
- Risk & Repeat: Twitter, Elon Musk and security concernsby Alexander Culafi on November 30, 2022 at 4:40 pm
This podcast episode discusses Twitter’s security concerns following Elon Musk’s acquisition last month, as well as a possible data breach from 2021 that came to light recently.
- Risk & Repeat: Researchers criticize HackerOneby Alexander Culafi on November 16, 2022 at 6:48 pm
This podcast episode discusses a recent TechTarget Security article about bug bounty platform HackerOne in which researchers aired several complaints about the company.
- Risk & Repeat: Microsoft, SOCRadar spar over data leakby Alexander Culafi on October 28, 2022 at 4:55 pm
This podcast episode discusses threat intelligence vendor SOCRadar’s disclosure of a large Microsoft data leak and the contentious exchange between the two companies that followed.
- Risk & Repeat: Breaking down the Joe Sullivan convictionby Alexander Culafi on October 14, 2022 at 2:59 pm
This podcast episode discusses conviction of former Uber CSO Joe Sullivan, who was found guilty last week of covering up the company’s 2016 data breach.
- Risk & Repeat: Uber and Rockstar Games hackedby Alexander Culafi on September 23, 2022 at 2:44 pm
This podcast episode discusses recent hacks against Uber and Rockstar Games, the techniques of the attackers and the possible connection to the Lapsus$ cybercrime group.
- Risk & Repeat: The White House wants secure softwareby Alexander Culafi on September 16, 2022 at 6:37 pm
This podcast episode discusses the implications of the Biden administration’s new purchasing and usage guidelines for software utilized by U.S. federal agencies.
- Risk & Repeat: Whistleblower spells trouble for Twitterby Alexander Culafi on August 24, 2022 at 8:48 pm
A new whistleblower report unveiled troubling accusations against Twitter from the social media company’s former head of security, Peiter ‘Mudge’ Zatko.
- Risk & Repeat: Black Hat 2022 recapby Alexander Culafi on August 17, 2022 at 8:42 pm
This Risk & Repeat podcast episode discusses the Black Hat 2022 conference in Las Vegas and the notable sessions, major themes and hot topics from the show.
- Risk & Repeat: Ransomware in 2022 so farby Alexander Culafi on July 15, 2022 at 3:10 pm
This podcast episode discusses ransomware in 2022, including an apparent decrease in attacks, the evolution of cybercrime operations and the lack of visibility into the threat.