The Gate 15 Podcast Channel

Gate 15

The Gate 15 Company is a leader in helping organizations by providing threat-informed, risk-based approaches to analysis, preparedness and operations.

  1. Weekly Security Sprint EP 128. Telecom risk, Ransomware, Cybersecurity legislation, and physical security threats

    HACE 1 DÍA

    Weekly Security Sprint EP 128. Telecom risk, Ransomware, Cybersecurity legislation, and physical security threats

    In this week's Security Sprint, Dave and Andy covered the following topics: Warm Open: • TribalNet: Casino-systems suppliers protecting operations from cyberattacks • TribalNet: AI main focus of tribal technology conference • TribalNet 2025: Cybersecurity Is Central to IT Modernization for Tribes • The Gate 15 Interview EP 62: Justine Bone, Executive Director, Crypto ISAC Main Topics: U.S. Secret Service dismantles imminent telecommunications threat in New York tristate area. The U.S. Secret Service dismantled a network of electronic devices located throughout the New York tristate area that were used to conduct multiple telecommunications-related threats directed towards senior U.S. government officials, which represented an imminent threat to the agency’s protective operations. This protective intelligence investigation led to the discovery of more than 300 co-located SIM servers and 100,000 SIM cards across multiple sites. In addition to carrying out anonymous telephonic threats, these devices could be used to conduct a wide range of telecommunications attacks. This includes disabling cell phone towers, enabling denial of services attacks and facilitating anonymous, encrypted communication between potential threat actors and criminal enterprises. While forensic examination of these devices is ongoing, early analysis indicates cellular communications between nation-state threat actors and individuals that are known to federal law enforcement. Ransomware! • EU cyber agency says airport software held to ransom by criminals • A Cyberattack on Jaguar Land Rover Is Causing a Supply Chain Disaster • Rising cyberattacks on K-12 schools prompt concern as Uvalde CISD grapples with ransomware Cyber threat information law hurtles toward expiration, with poor prospects for renewal • Rand Paul's last-minute demands push key cybersecurity law to the brink • Peters Urges Senate to Quickly Extend Critical Cybersecurity Protections That Expire on October 1st • Health-ISAC CSO: A Looming Deadline: The Cybersecurity Information Sharing Act of 2015 • RER and Coalition Urges TRIA Reauthorization • Commentary: Shrinking cyber budgets and rising threats: Why public-private partnerships are now mission-critical US threats and violence • MN man threatened people via email as retaliation for Charlie Kirk's death: Charges • NH Man Arrested for Allegedly Plotting to Kill Republican Governor Kelly Ayotte With Pipe Bombs • NCTC Supports U.S. Law Enforcement, First Responders by Sharing Intel Product Aimed at Deterring Attacks by Al-Qa’ida • ISIS calls for slaughter of Christians and Jews in UK attacks – 'shoot, stab, and ram' Quick Hits: • FBI PSA: Threat Actors Spoofing the FBI IC3 Website for Possible Malicious Activity • NHC issuing advisories for the Atlantic on Hurricane Gabrielle • UK NPSA: Vehicle Security Barriers at Event Venues • TikTok: Statement from ByteDance o Deal to Keep TikTok in U.S. Is Near. These Are the Details. o Trump expected to approve TikTok deal via executive order later this week, WSJ reports • OpenAI admits AI hallucinations are mathematically inevitable, not just engineering flaws

    20 min
  2. HACE 2 DÍAS

    The Gate 15 Interview EP 62: Justine Bone, Executive Director, Crypto ISAC

    In this episode of The Gate 15 Interview, Andy Jabbour speaks with Justine Bone, Executive Director, Crypto ISAC. She has worked at the intersection of technology, governance, and investment for over twenty years from her start in the intelligence community with the New Zealand GCSB and the U.S. NSA, and has since spanned CEO roles, multinational board appointments, and global advisory positions. Today she serves as Executive Director of the Crypto ISAC, leading global collaboration at the nexus of digital assets, cybersecurity, and governance, and working with public and private stakeholders to build trust and resilience in international markets. She has also held leadership roles at Dow Jones, Bloomberg, and MedSec, and worked with public–private collaborations alongside the FDA, DHS, and DOD. Learn more about Justine on LinkedIn.In the discussion Justine and Andy cover: Justine’s background.Crypto ISAC’s mission and community.Threats to the blockchain and crypto industry, including the threat from North Korea.Personal and organizational crypto security considerations.What’s ahead in 2026.Resilience and the power of information sharing.We play 3 Questions!“there’s a lot that’s the same, but there’s a lot that’s different” Selected links: Crypto ISAC(TLP:CLEAR) North Korea IT Worker Threat Report: Threat Overview and Mitigation. This report is a collaboration that incorporates analysis from several leading Information Sharing and Analysis Centers (ISACs), including Crypto ISAC, Oil and Natural Energy ISAC (ONE-ISAC), Real Estate ISAC, Tribal ISAC, WaterISAC, the Faith-Based Information Sharing and Analysis Organization (ISAO), and Gate 15

    46 min
  3. Weekly Security Sprint EP 127. Kirk fallout and considerations, AI risks, and more

    16 SEP

    Weekly Security Sprint EP 127. Kirk fallout and considerations, AI risks, and more

    In that latest episode of the Security Sprint, Dave and Andy covered the following topics: Warm Open: • TribalNet 2025! • FB-ISAO Releases an All-Faiths Analysis of Attacks on U.S. Houses of Worship in 2024, FB-ISAO Releases an All-Faiths Analysis of Attacks on U.S. Houses of Worship in 2024 & FB-ISAO Newsletter • Water at the 2025 WaterPro Conference • Errol LinkedIn: A Looming Deadline: The Cybersecurity Information Sharing Act of 2015 • Health-ISAC and CI-ISAC Australia joint white paper Main Topics: Charlie Kirk Assassination • The Hostile Event Attack Cycle (HEAC) • De-escalation Reference Card: CISA De-escalation Reference Card & CISA De-escalation Reference Card Printer Friendly Insider Threat Awareness Month: Fake Faces, Real Damage: The Corporate Risk of AI-Powered Manipulation. Security professionals are rapidly confronting a new reality: artificial intelligence (AI) and big data, while excellent tools for improving productivity and business operations, are equally lowering the barriers for sophisticated attacks by a wide range of threat groups. From hostile nation-states to issue-motivated groups to cybercriminals, these technologies are enabling attacks that are more personalized, scalable, and harder to detect. The widespread availability of our personal data—from what we post on social media to the massive resale of information gathered by data brokers from both our devices and our online activity—has made open-source data the key ingredient for highly effective AI-driven deception and disruption and enabled the creation of deepfakes. Quick Hits: • NOAA - Hurricane Erin: When distant storms pose a danger to America’s coastal communities • Exclusive: US warns hidden radios may be embedded in solar-powered highway infrastructure • 'Chilling reminder': Multiple historically Black universities under lockdown after receiving threats • 1 injured while U.S. Naval Academy building was cleared after reported threat • Police Swarm UMass Boston After Unconfirmed Shooting Report Sparks Campus Chaos • USCP Clears False Bomb Threat & Police clear possible bomb threat at DNC headquarters • A shooting at Denver-area high school leaves community shaken during third week of school • Man Pleads Guilty to Attempting to Use a Weapon of Mass Destruction and Attempting to Destroy an Energy Facility in Nashville • Out of the woodwork: Examining the global aspirations of The Base • The Online Radicalization of Youth Remains a Growing Problem Worldwide • CTC - The Global State of al-Qa`ida 24 Years After 9/11 • 18 Popular Code Packages Hacked, Rigged to Steal Crypto • Hackers Exploit JavaScript Accounts in Massive Crypto Attack Reportedly Affecting 1B+ Downloads • npm Supply chain Attack: Oops, No Victims: The Largest Supply Chain Attack Stole 5 Cents • Salesloft: March GitHub repo breach led to Salesforce data theft attacks • Ransomware Losses Climb as AI Pushes Phishing to New Heights • Stopping ransomware before it starts: Lessons from Cisco Talos Incident Response

    24 min
  4. Weekly Security Sprint EP 126. Information Sharing progress, ransomware report and news, and Alphabet Soup Month!

    9 SEP

    Weekly Security Sprint EP 126. Information Sharing progress, ransomware report and news, and Alphabet Soup Month!

    In this week's Security Sprint, Dave and Andy covered the following topics: Warm Open: • Patch It or Pay: Closing the Door on Exploits. This blog is part of Gate 15’s Summer of Security: Ransomware Resilience Series, highlighting the essential considerations for organizational leaders and cybersecurity professionals. Main Topics: • House panel approves cyber information sharing, grant legislation as expiration deadlines loom • CISA Delays Cyber Incident Reporting Rule for Critical Infrastructure Ransomware & Data Breaches: • Australian Government - Australian Institute of Criminology: Examining the activities and careers of ransomware criminal groups. PDF • Stopping ransomware before it starts: Lessons from Cisco Talos Incident Response • Cyberattack on Jaguar Land Rover threatens to hit British economic growth • Hackers linked to M&S breach claim responsibility for Jaguar Land Rover cyber-attack • How JLR's Cyber Breach is Disrupting Global Operations • Jaguar Land Rover staff home for another day as company reels from cyber attack Presidential Message on National Preparedness Month • National Insider Threat Awareness Month; Help prevent the exploitation of authorized access from causing harm to your organization • Plan to avoid scams this National Preparedness Month • ABA Foundation and FBI Release New Infographic to Help Americans Spot and Avoid Deepfake Scams Quick Hits: • All IT work to involve AI by 2030, says Gartner, but jobs are safe. All work in IT departments will be done with the help of AI by 2030, according to analyst firm Gartner, which thinks massive job losses won’t result. • Salesloft Drift updates • Not Safe for Work: Tracking and Investigating Stealerium and Phantom Infostealers • Over 6,700 Private Repositories Made Public in Nx Supply Chain Attack • Frostbyte10 flaws in Copeland E2 and E3 controllers highlight cyber threats to refrigeration, HVAC, lighting infrastructure • Czech NUKIB alerts critical infrastructure sector to rising cyber risks from Chinese data transfers, remote management • ‘Unrestrained’ Chinese Cyberattackers May Have Stolen Data From Almost Every American • Chinese Hackers Impersonate US Lawmaker in Malware Scheme During Trade Talks • US military kills 11 in strike on alleged drug boat tied to Venezuelan cartel, Trump says • Targeting Iran’s Leaders, Israel Found a Weak Link: Their Bodyguards • U.S. and Canadian Intelligence Partners Issue Guidance to Protect Western Tech Startups from Exploitation in International Pitch Competitions • The Blockchain Is Not Your Friend: Examining EtherHiding and using Blockchain for Attacks • New Cyber Resources from the Canadian Centre for Cyber Security: Cyber security hygiene best practices for your organization - ITSAP.10.102 o Virtualizing your infrastructure (ITSAP.70.011) o Universal plug and play (ITSAP.00.008)

    19 min
  5. Weekly Security Sprint EP 125. Hostile Events, AI driven Ransomware, and more!

    2 SEP

    Weekly Security Sprint EP 125. Hostile Events, AI driven Ransomware, and more!

    In this week's Security Sprint, Dave and Andy covered the following topics: Main Topics: Annunciation Catholic Church Attack • Minneapolis Suspect Knew Her Target, but Motive Is a Mystery • Shooter who opened fire on Minneapolis Catholic school posted rambling videos • Robin Westman: Minneapolis gunman was son of church employee • Robin Westman posted a manifesto on YouTube prior to Annunciation Church shooting • Minneapolis school shooter wrote “I am terrorist” and “Kill yourself” in Russian on weapon magazines and listened to Russian rappers • Minneapolis Catholic Church shooter mocked Christ in video before attack • Minneapolis school shooter 'obsessed with idea of killing children', authorities say • Minnesota Mass Shooter Steeped in Far-Right Lore, White Nationalist Murderers • In Secret Diaries, the Church Shooter’s Plans for Mass Murder • Minneapolis church shooting search warrants reveal new details and evidence • 'There is no message': The search for ideological motives in the Minneapolis shooting • Minneapolis Church Shooting: Understanding the Suspect’s Video • More Of Minnesota Shooter’s Writings Uncovered: ‘Gender And Weed F***ed Up My Head’ • Classmates say Minnesota school shooter gave Nazi salutes and idolized school shootings back in middle school Hoax Active Shooter Reports • More than a dozen universities have been targeted by false active shooter reports • This Is the Group That's Been Swatting US Universities • FBI urges students to be vigilant amid wave of swatting hoaxes AI & Cyber Threats • The Era of AI-Generated Ransomware Has Arrived • Researchers flag code that uses AI systems to carry out ransomware attacks & First known AI-powered ransomware uncovered by ESET Research • Anthropic: Detecting and countering misuse of AI: August 2025 • A quick look at sextortion at scale: 1,900 messages and 205 Bitcoin addresses spanning four years Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System • FBI warns Chinese hacking campaign has expanded, reaching 80 countries • Allied spy agencies blame 3 Chinese tech companies for Salt Typhoon attacks • UK NCSC: UK and allies expose China-based technology companies for enabling global cyber campaign against critical networks Quick Hits: • Storm-0501’s evolving techniques lead to cloud-based ransomware • Why Hypervisors Are the New-ish Ransomware Target • FBI Releases Use-of-Force Data Update • Denmark summons US envoy over report on covert American ‘influence operations’ in Greenland • Falsos Amigos • Surge in coordinated scans targets Microsoft RDP auth servers • Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424 • Citrix patches trio of NetScaler bugs – after attackers beat them to it • U.S., Japan, and ROK Join Mandiant to Counter North Korean IT Worker Threats • US sanctions fraud network used by North Korean ‘remote IT workers’ to seek jobs and steal money • H1 2025 Malware and Vulnerability Trends • The FDA just overhauled its COVID vaccine guidance. Here’s what it means for you • 25 August 2025 NCSC, AFOSI, ACIC, NCIS, DCSA, FBI, ED, NIST, NSF bulletin • DOGE Put Critical Social Security Data at Risk, Whistle-Blower Says • Blistering Wyden letter seeks review of federal court cybersecurity, citing ‘incompetence,’ ‘negligence’ • Email Phishing Scams Increasingly Target Churches

    19 min
  6. Weekly Security Sprint EP 124. Targeting Critical Infrastructure, MDM again, and other security risks

    26 AGO

    Weekly Security Sprint EP 124. Targeting Critical Infrastructure, MDM again, and other security risks

    In this week's Security Sprint, Dave and Andy covered the following topics: Warm Open: • Nerd Out EP 61. The 2/3 of the Year Awards! Main Topics: FBI PSA - Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure. The Federal Bureau of Investigation (FBI) is warning the public, private sector, and international community of the threat posed to computer networks and critical infrastructure by cyber actors attributed to the Russian Federal Security Service's (FSB) Center 16. The FBI detected Russian FSB cyber actors exploiting Simple Network Management Protocol (SNMP) and end-of-life networking devices running an unpatched vulnerability (CVE-2018-0171) in Cisco Smart Install (SMI) to broadly target entities in the United States and globally. Info Ops: • Most Adults in 25 Countries Say Spread of False Information Is a Top National Threat. The findings come from Pew’s seventh iteration of its Global Attitudes Survey: International Opinion on Global Threats, which was last published in 2022. • Foreign disinformation enters AI-powered era. At least one China-based technology company, GoLaxy, seems to be using generative AI to build influence operations in Taiwan and Hong Kong… Documents also show that GoLaxy has created profiles for at least 117 members of Congress and over 2,000 American political figures and thought leaders. • Toxic politics and TikTok engagement in the 2024 U.S. election • Why wind farms attract so much misinformation and conspiracy theory UN - Terror threat posed by ISIL ‘remains volatile and complex,’ Security Council hears. The threat posed by the terrorist group ISIL – known more widely in the Middle East as Da’esh – remains dynamic and diverse, with Africa currently experiencing the highest level of activity worldwide. • PDF: Remarks by Mr. Vladimir Voronkov, Under-Secretary-General for Counter-Terrorism, United Nations Office of Counter-Terrorism. • PDF: Remarks by Mr. Vladimir Voronkov, Under-Secretary-General, United Nations Office of Counter-Terrorism. • UN Report: ISIS Fighters’ Migration to Afghanistan and the Taliban’s Failure • ISIS-K poses major threat with 2,000 fighters in Afghanistan, UN says FEMA Employees Warn That Trump Is Gutting Disaster Response. After Hurricane Katrina, Congress passed a law to strengthen the nation’s disaster response. FEMA employees say the Trump administration has reversed that progress. Employees at the Federal Emergency Management Agency wrote to Congress on Monday warning that the Trump administration had reversed much of the progress made in disaster response and recovery since Hurricane Katrina pummeled the Gulf Coast two decades ago. The letter to Congress, titled the “Katrina Declaration,” rebuked President Trump’s plan to drastically scale down FEMA and shift more responsibility for disaster response — and more costs — to the states. It came days before the 20th anniversary of Hurricane Katrina, one of the deadliest and costliest storms to ever strike the United States. Quick Hits: • 25% of security leaders replaced after ransomware attack • Gate 15: Hack Yourself First: Pen Testing for Prevention • FB-ISAO: Ransomware Incident Review January to June 2025 • Dissecting PipeMagic: Inside the architecture of a modular backdoor framework • Maryland Transit Administration says cybersecurity incident is affecting some of its servicesNevada state government offices closed after network security incident • Audit of Antisemitic Incidents 2024 • MIT report: 95% of generative AI pilots at companies are failing • Report: Russian Sabotage Operations In Europe Have Quadrupled Since 2023 • CISA Requests Public Comment for Updated Guidance on Software Bill of Materials • Risky Bulletin: NIST releases face-morphing detection guideline • CVE-2025–41688: Bypassing Restrictions in an OT Remote Access Device • Think before you Click(Fix): Analyzing the ClickFix social engineering technique

    20 min

Calificaciones y reseñas

5
de 5
4 calificaciones

Acerca de

The Gate 15 Company is a leader in helping organizations by providing threat-informed, risk-based approaches to analysis, preparedness and operations.

También te podría interesar