Defensive Security is a weekly information security podcast which reviews recent high profile security breaches, data breaches, malware infections and intrusions to identify lessons that we can learn and apply to the organizations we protect.
Defensive Security Podcast Episode 270
Defensive Security Podcast Episode 269
Defensive Security Podcast Episode 268
jerry: [00:00:00] All right, here we go today. Sunday, July 17th. 2022. And this is episode 268. Of the defensive security podcast. My name is Jerry Bell and joining me tonight as always is Mr. Andrew Kellett.
Andy: Hello, Jerry. How are you, sir?
jerry: great. How are you doing?
Andy: I’m doing good. I see nobody else can see it, but I see this amazing background that you’ve done with your studio and all sorts of cool pictures. Did you take those.
jerry: I It did not take those. They are straight off Amazon actually. It’s.
jerry: I’ll have to post the picture at some [00:01:00] point, but the pictures are actually sound absorbing panels.
Andy: Wow. I there’s jokes. I’m not going to make them, but anyway, I’m doing great. Good to see ya..
jerry: Awesome. Just a reminder that the thoughts and opinions we express on the show are ours and do not represent those of our employers. But as you are apt to point out, they could be for the right price.
Andy: That’s true. That’s true. And that, and by the way, what that really means is you’re not going to change our opinions. You’re just going to to hire them.
jerry: Correct. right. Sponsor our existing opinions.
Andy: Someday that’ll work.
jerry: All right. So we have some interesting stories today. The first one comes from SC magazine dot com. The title is why solar winds just might be one of the most secure software companies. In the tech universe.
Andy: It’s a pretty interesting one. I went into this a little.
Andy: Cynical. But there’s a lot of [00:02:00] really interesting stuff in here.
jerry: Yeah there, there is, I think
jerry: What I found interesting. A couple of things. One is very obvious. That this is a. Planted attempt to get back into the good graces of the it world. But at the same time, It is very clear that they have made some pretty significant improvements in their security posture. And I think for that, it deserves a.
jerry: A discussion.
Andy: Yeah, not only improvements, but they’re also.
Andy: Having these strong appearance of transparency and sharing lessons learned. Which we appreciate.
jerry: Correct. The one thing that I so we’ll get into it a little bit, but they still don’t really tell you. How. The thing happened.
jerry: Obviously it was aliens. They did tell you what happened. And so in the. Article here they describe this the [00:03:00] CISO of solar winds describes that the attack didn’t actually. Change their code base. So the attack wasn’t against their code repository. It was actually against one of their build systems.
jerry: And so they were the adversary here. Was injecting code. At build time, basically. So it wasn’t something that they could detect through code reviews. It was actually being added as part of the build proc...
Defensive Security Podcast Episode 267
Defensive Security Podcast Episode 267
jerry: [00:00:00] Alright, here we go. Today is Sunday, July 10th, 2022. And this is episode 267 of the defensive security podcast. My name is Jerry Bell and joining me tonight as always. Is Mr. Andrew Kellett.
Andy: Good evening, Jerry, how are you? Good, sir.
jerry: I’m doing great. How are you doing?
Andy: I’m good man. It’s hot and steamy in Atlanta. Tell you that much.
jerry: Yeah. I ‘ve been back for a month from my beach place. And I think today’s the first day that we’ve not had a heat advisory. [00:01:00]
Andy: Yeah, that’s crazy.
jerry: which it has been brutally hot here.
Andy: Now, when you say beach place, you might have to be more specific, cause you’ve got one like seven beach houses now.
jerry: Well, the Southern most beach house. Yes.
Andy: Yeah. One is the Chateau. One’s technically a compound.
jerry: One’s an island,
Andy: We’re going to have to probably name them because. They’re tough to keep straight.
jerry: They definitely are. Yup.
Andy: But, I, for one. Appreciate your new land barronness activities. And look forward to.
Andy: Jerry Landia being launched and seceding from the United States.
jerry: Hell. Yeah. That’s right.
Andy: I’ll start applying for citizenship whenever I can.
jerry: Good plan. Good plan. All right. A reminder. We should probably already said this, but the thoughts and opinions we expressed on the show are ours and do not represent those of our employers.
Andy: But for enough money, they could
jerry: yeah. Everything is negotiable. [00:02:00] All right. Couple of really interesting stories crossed my desk. Recently and the first one comes from the US department of justice of all places. And the title here is Aerojet , Rocketdyne agrees to pay $9 million to resolve false claims act allegations.
jerry: Of cybersecurity violations in federal government contracts. So the story here is that there’s this act, as you could probably tell by the title called the false claims act that permits an employee of a company who specifically does business with the US government to Sue the company under the false claims act claiming that the company is misrepresenting itself in the execution of its contracts. And if that [00:03:00] lawsuit is successful, the person making the allegation, basically it’s a whistleblower kind of arrangement. The person making the allegation gets a cut of the settlement. And so in this particular case the whistleblower received $2.61 million dollars of the $9 million.
Andy: Wow. So his company. In theory was lying on their security controls. And he found out about it or knew about it. And was a whistleblower. About it is getting 2.61 million.
jerry: Correct. Correct.
Andy: Have to go check everything in my company. I’ll be right back.
jerry: I’m guessing that his lawyers will probably take about 2 million of the 2.61, but, Hey, it’s still.
jerry: still. money, right?
Andy: That’s crazy. It reminds me, it’s probably a lot of our listeners are too young for this, but.
Defensive Security Podcast Episode 266
Defensive Security Podcast Episode 265
Google Exposes Initial Access Broker Ties With Ransomware Actors (bankinfosecurity.com)
Okta says hundreds of companies impacted by security breach | TechCrunch
Okta: “We made a mistake” delaying the Lapsus$ hack disclosure (bleepingcomputer.com)
Microsoft confirms Lapsus$ breach after hackers publish Bing, Cortana source code | TechCrunch
DEV-0537 criminal actor targeting organizations for data exfiltration and destruction – Microsoft Security Blog
Sabotage: Code added to popular NPM package wiped files in Russia and Belarus | Ars Technica
President Biden Signs into Law the Cyber Incident Reporting Act (natlawreview.com)
SEC Proposes Rules On Cybersecurity Risk Management, Strategy, Governance, And Incident Disclosure By Public Companies – Technology – United States (mondaq.com)