Skyhigh Security CloudCast

Skyhigh Security CloudCast
Skyhigh Security CloudCast

Collaborate with ease across all applications without sacrificing security.

  1. 2 DAYS AGO

    CloudCast Cybersecurity Headlines for December 18, 2024

    From the Skyhigh Studios at Skyhigh Security, I’m Scott Schlee, it’s Wednesday, December 18th, 2024, and these are your cybersecurity headlines. Headlines this week: Microsoft’s AI Tool Privacy Concerns North Korean IT Worker Indictments Mysterious Drone Sightings Sanctions on Chinese Hackers Apple Users Urged to Update Devices SEC Cybersecurity Enforcement UK's Cybersecurity Concerns Game Freak Data Breach Geico and Travelers Fined for Data Breaches Krispy Kreme Cyberattack Thank you again for listening to Skyhigh Cloudcast. This is our last episode of CloudCast for 2024. We sincerely hope you have a wonderful holiday break. We'll be back in January and hope you will be too. If you've enjoyed this episode, be sure to subscribe on your favorite platform so you never miss an update. If you like the show, please leave us a review. It helps others find the podcast. For more information about Skyhigh Security or CloudCast, please visit skyhighsecurity.com. Sources: Wired - Microsoft’s AI Tool Privacy Concerns and Mysterious Drone Sightings The Times (UK) - North Korean IT Worker Indictments and UK's Cybersecurity Concerns Reuters - Sanctions on Chinese Hackers and SEC Cybersecurity Enforcement New York Post - Apple Users Urged to Update Devices The Scottish Sun - Game Freak Data Breach Wall Street Journal (WSJ) - Geico and Travelers Fined for Data Breaches MarketWatch - Krispy Kreme Cyberattack ----------- CloudCast is hosted by Skyhigh Security’s very own Digital Experience Manager, Scott Schlee. Scott’s engaging demeanor and wit, backed by over 20 years in digital media production and web development, has led to successful collaborations with top-tier brands. His experience includes hosting and producing a wide range of podcasts and videos. Scott has been recognized for his outstanding work, including an award-winning digital short and a Webby Awards nomination for Viral Marketing (Branded). Beyond his professional achievements, Scott’s personal journey as a decade-long pancreatic cancer survivor has led him to share his story with the U.S. Congress and other organizations as an advocate for increased cancer research funding. Transcript From the Skyhigh Studios at Skyhigh Security, I’m Scott Schlee, it’s Wednesday, December 4th, 2024, and these are your cybersecurity headlines. Microsoft’s AI Tool Privacy Concerns: Microsoft's AI tool, Recall, has been found capturing sensitive data, including credit card and Social Security numbers, every five seconds. Despite safeguards, this raises significant privacy and security concerns. North Korean IT Worker Indictments: Fourteen North Koreans have been indicted for posing as IT workers to fund nuclear programs. They infiltrated American and Western IT companies, using sophisticated fake identities and VPNs to mimic legitimate employees. This highlights the geopolitical cyber risks posed by state-sponsored actors. Mysterious Drone Sightings: Unexplained drone activity in New Jersey and neighboring states has triggered federal investigations into potential security threats. The drones have caused concern among authorities, leading to increased scrutiny and efforts to identify their origin and purpose. Sanctions on Chinese Hackers: The U.S. has sanctioned Chinese cybersecurity company Sichuan Silence Information Technology for deploying ransomware that posed significant risks to human life. In April 2020, the company used malicious software on over 80,000 firewalls globally, including critical infrastructure, leading to data theft and network disruptions. Apple Users Urged to Update Devices: Cybersecuri...

    5 min
  2. DEC 12

    Top 10 Cybersecurity Headlines of 2024

    From the CloudCast Studios at Skyhigh Security, I’m your host Scott Schlee, and today we’re counting down the top 10 cybersecurity headlines of 2024. The Top Headlines for 2024: RockYou2024: 10 billion passwords leaked in the largest compilation of all time Microsoft Falls Victim to Russia-Backed 'Midnight Blizzard' Cyberattack UnitedHealth says Change Healthcare hack affects over 100 million, the largest-ever US healthcare data breach National Public Data breach publishes private data of 2.9B people Hackers steal “significant volume” of data from hundreds of Snowflake customers Notorious hacking group responsible for Ticketmaster data breach Crooks Steal Phone, SMS Records for Nearly All AT&T Customers Ascension hacked after employee downloaded malicious file CDK Global outage caused by BlackSuit ransomware attack Widespread IT Outage Due to CrowdStrike Update Thank you for listening to Skyhigh CloudCast. If you’ve enjoyed this episode, be sure to subscribe on your favorite podcast platform so you never miss an update. If you like the show, please leave us a review. It helps others find the podcast. For more information about Skyhigh Security or CloudCast, please visit skyhighsecurity.com. Sources: Wikipedia · Krebs On Security · CyberNews · Dark Reading · TechCrunch · Microsoft · ARS Technica · Ticketmaster · HIPPA Journal · Bleeping Computer ----------- CloudCast is hosted by Skyhigh Security’s very own Digital Experience Manager, Scott Schlee. Scott’s engaging demeanor and wit, backed by over 20 years in digital media production and web development, has led to successful collaborations with top-tier brands. His experience includes hosting and producing a wide range of podcasts and videos. Scott has been recognized for his outstanding work, including an award-winning digital short and a Webby Awards nomination for Viral Marketing (Branded). Beyond his professional achievements, Scott’s personal journey as a decade-long pancreatic cancer survivor has led him to share his story with the U.S. Congress and other organizations as an advocate for increased cancer research funding. Transcript From the Skyhigh Studios at Skyhigh Security, I’m Scott Schlee, it’s Thursday, December 12th, 2024, and today, we’re counting down the top 10 cybersecurity headlines of 2024. This year brought no shortage of challenges—from healthcare breaches exposing millions of records, to CrowdStrike’s worldwide outage that disrupted businesses across the globe, and even one breach that cascaded from one company to another. These stories reflect the ever-evolving threats we face and some of the critical lessons learned along the way. And now, in no particular order, let’s dive into the year that was, in cybersecurity.” In July 2024, a massive compilation of nearly 10 billion unique plaintext passwords, dubbed "RockYou2024," was leaked on a popular hacking forum. This dataset amalgamated passwords from thousands of previous breaches, both old and recent, creating an unprecedented repository of compromised credentials. The leak significantly heightened the risk of credential stuffing attacks, where cybercriminals exploit reused passwords to gain unauthorized access to various accounts. Security experts urged individuals to immediately reset compromised passwords, adopt strong and unique passwords for each account, utilize password managers, and enable multi-factor authentication to mitigate potential threats. In January 2024, Microsoft revealed that the Russian state-sponsored group Midnight Blizzard (also known as APT29 or Nobelium) had infiltrated its corporate email systems. The attackers employed a password spray attack to compromise a legac...

    9 min
  3. DEC 4

    CloudCast Cybersecurity Headlines for December 4, 2024

    From the CloudCast Studios at Skyhigh Security, I’m your host Scott Schlee and these are your Cybersecurity Headlines for the week of Wednesday, December 4, 2024. Headlines this week: The White House Struggles to Contain Massive Chinese Telco Hacks Americans to Receive Up to $5,000 from $1.6 Million Data Breach Settlement New York State Fines Geico and Travelers $11.3 Million for Data Breaches Britain Now Worse at Dealing with Cyberattackers, GCHQ Says CrowdStrike Raises Annual Forecast on Steady Cybersecurity Demand Google Chrome Users Warned to Avoid Scam Websites Smartphone Users Urged to Delete 15 Malicious 'SpyLoan' Apps Netflix Subscribers Targeted by Phishing Scam Interpol takes down over 1,000 cybercrime suspects in Africa Thank you for listening to Skyhigh CloudCast. If you’ve enjoyed this episode, be sure to subscribe on your favorite podcast platform so you never miss an update. If you like the show, please leave us a review. It helps others find the podcast. For more information about Skyhigh Security or CloudCast, please visit skyhighsecurity.com. Sources: Politico · The Sun · Wall Street Journal · The Times · Reuters · New York Post · New York Post · New York Post · Reuters · AP News ----------- CloudCast is hosted by Skyhigh Security’s very own Digital Experience Manager, Scott Schlee. Scott’s engaging demeanor and wit, backed by over 20 years in digital media production and web development, has led to successful collaborations with top-tier brands. His experience includes hosting and producing a wide range of podcasts and videos. Scott has been recognized for his outstanding work, including an award-winning digital short and a Webby Awards nomination for Viral Marketing (Branded). Beyond his professional achievements, Scott’s personal journey as a decade-long pancreatic cancer survivor has led him to share his story with the U.S. Congress and other organizations as an advocate for increased cancer research funding. Transcript From the Skyhigh Studios at Skyhigh Security, I’m Scott Schlee, it’s Wednesday, December 4th, 2024, and these are your cybersecurity headlines. President Joe Biden's administration is intensively addressing breaches of multiple U.S. telecommunications providers by the China-backed hacking group, Salt Typhoon. Despite daily meetings of a special White House response group and collaboration with affected telecoms, the hackers remain entrenched, leaving many Americans vulnerable to surveillance. The intrusion, which began in the spring and was publicly acknowledged in October, has targeted high-profile individuals and accessed extensive communications data. The administration emphasizes the need for collaboration between telecoms, cybersecurity firms, and international partners to mitigate further damage and suggests that new security mandates may be necessary to prevent future breaches. Individuals affected by a data breach at Hilb Group can claim up to $5,000 from a $1.6 million settlement by providing proof of losses, such as receipts. The breach, occurring between December 1, 2022, and January 12, 2023, exposed sensitive information, including Social Security numbers and financial data. Hilb Group denies wrongdoing but agreed to the settlement. Claimants must file by December 13, 2024. New York State imposed fines totaling $11.3 million on auto insurers Geico and Travelers Indemnity for cybersecurity lapses that led to data breaches affecting 120,000 individuals during the COVID-19 pandemic. Hackers accessed Geico's online quoting tool, stealing personal data of approximately 116,000 people starting in 2020. In a separate incident, hackers infiltrated Travelers' quoting tool,

    8 min
  4. NOV 20

    CloudCast Cybersecurity Headlines for November 20, 2024

    From the CloudCast Studios at Skyhigh Security, I’m your host Scott Schlee and these are your Cybersecurity Headlines for the week of Wednesday, November 20, 2024. Headlines this week: Trump's Second Term Expected to Bring Big Changes to U.S. Cyber Agency The DHS issues recommendations for AI in critical infrastructure. New York Department of Financial Services Issues AI Cybersecurity Guidance The EPA Reports Cybersecurity Concerns Related to Drinking Water Systems Chinese Hackers Target Tibetan Websites in Malware Attack Bitfinex Hacker Sentenced to 5 Years for $10 Billion Bitcoin Heist U.S. Introduces New Data Rules to Combat Cybercrime Bitdefender Releases Free Decryptor for ShrinkLocker Ransomware Microsoft Releases November 2024 Security Updates ESET Research Analyzes RedLine Stealer's Backend Modules Thank you for listening to Skyhigh CloudCast. If you’ve enjoyed this episode, be sure to subscribe on your favorite platform so you never miss an update. If you like the show, please leave us a review. It helps others find the podcast. For more information about Skyhigh Security or CloudCast, please visit skyhighsecurity.com. Sources: The Wall Street Journal · The Australian · AP News · Wired · Wired · Reuters · World Economic Forum · The Hacker News · CISA · We Live Security ----------- CloudCast is hosted by Skyhigh Security’s very own Digital Experience Manager, Scott Schlee. Scott’s engaging demeanor and wit, backed by over 20 years in digital media production and web development, has led to successful collaborations with top-tier brands. His experience includes hosting and producing a wide range of podcasts and videos. Scott has been recognized for his outstanding work, including an award-winning digital short and a Webby Awards nomination for Viral Marketing (Branded). Beyond his professional achievements, Scott’s personal journey as a decade-long pancreatic cancer survivor has led him to share his story with the U.S. Congress and other organizations as an advocate for increased cancer research funding. Transcript Trump's Second Term Expected to Bring Big Changes to U.S. Cyber Agency, The DHS issues recommendations for AI in critical infrastructure, New York Department of Financial Services Issues AI Cybersecurity Guidance, The EPA Reports Cybersecurity Concerns Related to Drinking Water Systems, Chinese Hackers Target Tibetan Websites in Malware Attack, Bitfinex Hacker Sentenced to 5 Years for $10 Billion Bitcoin Heist, U.S. Introduces New Data Rules to Combat Cybercrime, Bitdefender Releases Free Decryptor for ShrinkLocker Ransomware, Microsoft Releases November 2024 Security Updates, and ESET Research Analyzes RedLine Stealer's Backend Modules. From the Skyhigh Studios at Skyhigh Security, I’m Scott Schlee, it’s Wednesday, November 20th, and these are your cybersecurity headlines. President-elect Donald Trump's upcoming administration is anticipated to significantly alter the focus and structure of the Cybersecurity and Infrastructure Security Agency. Critics argue that CISA's mission has expanded beyond its core responsibilities, prompting discussions about refocusing on federal and critical infrastructure protection. The appointment of Elon Musk and Vivek Ramaswamy to lead a government restructuring initiative may impact CISA's funding and operations. Despite potential changes, experts believe the agency's dissolution is unlikely due to bipartisan support for its mission. The Department of Homeland Security has issued new recommendations for integrating artificial intelligence into critical infrastructure sectors to enhance s...

    8 min
  5. NOV 6

    CloudCast Cybersecurity Headlines for November 6, 2024

    From the CloudCast Studios at Skyhigh Security, I’m your host Scott Schlee and these are your Cybersecurity Headlines for the week of Tuesday, November 6, 2024. Headlines this week: Fortinet Flaw Exploited AWS CDK Vulnerability Patched SEC Charges Over SolarWinds Disclosures REvil Members Sentenced in Russia Meta's WhatsApp Security Update CISA and FBI Probe China-Linked Hacks Change Healthcare Data Breach Delta Sues CrowdStrike Over Outage Thank you for listening to Skyhigh CloudCast. If you’ve enjoyed this episode, be sure to subscribe on your favorite platform so you never miss an update. If you like the show, please leave us a review. It helps others find the podcast. For more information about Skyhigh Security or CloudCast, please visit skyhighsecurity.com. ----------- CloudCast is hosted by Skyhigh Security’s very own Digital Experience Manager, Scott Schlee. Scott’s engaging demeanor and wit, backed by over 20 years in digital media production and web development, has led to successful collaborations with top-tier brands. His experience includes hosting and producing a wide range of podcasts and videos. Scott has been recognized for his outstanding work, including an award-winning digital short and a Webby Awards nomination for Viral Marketing (Branded). Beyond his professional achievements, Scott’s personal journey as a decade-long pancreatic cancer survivor has led him to share his story with the U.S. Congress and other organizations as an advocate for increased cancer research funding. Transcript From the CloudCast Studios at Skyhigh Security, I'm Scott Schlee, and these are your Cybersecurity Headlines for the week of Tuesday, November 6th, 2024. Fortinet recently disclosed a critical flaw in its FortiManager software, which has been actively exploited in zero-day attacks to compromise systems. This vulnerability, known as an out-of-bounds write, allows remote attackers to execute arbitrary code, giving them unauthorized control over affected systems and the ability to steal sensitive data. Organizations using Fortinet products have been strongly urged to apply patches immediately to mitigate potential risks. Critical vulnerability in Amazon's cloud development kit allowed potential account takeovers, exposing users to security risks. This flaw, if exploited, could enable attackers to gain full control over AWS accounts through improperly secured S3 bucket configurations. Amazon has since released a patch for the CDK urging all users to update to the latest version to secure their cloud environments against this risk. The SEC has charged four companies, including Unisys and Avaya, for misleading disclosures regarding their cybersecurity practices following the 2020 SolarWinds cyberattack. These firms allegedly failed to adequately inform investors about the extent of their exposure to cybersecurity risks, instead providing only generic or incomplete risk information. As a result, fines totaling $6 million have been imposed on the companies, with Unisys paying the largest penalty of $4 million. Four members of the notorious REvil Ransomware group were sentenced by the St. Petersburg Garrison Military Court to several years in prison. These individuals were found guilty of crimes related to the illegal circulation of payment methods, marking a rare sentencing for cybercriminals within Russia. This group, linked to high-profile ransomware attacks had been apprehended in 2022, and this verdict signals a significant stance by Russian authorities against certain cybercrime activities. Meta recently introduced an enhanced security feature for WhatsApp known as Identity Proof Linked Storage, IPLS, which provides encrypted storage for user contacts.

    5 min

About

Collaborate with ease across all applications without sacrificing security.

To listen to explicit episodes, sign in.

Stay up to date with this show

Sign in or sign up to follow shows, save episodes, and get the latest updates.

Select a country or region

Africa, Middle East, and India

Asia Pacific

Europe

Latin America and the Caribbean

The United States and Canada