The Gate 15 Podcast Channel

Gate 15

The Gate 15 Company is a leader in helping organizations by providing threat-informed, risk-based approaches to analysis, preparedness and operations.

  1. 4d ago

    Nerd Out EP 73: 5th Annual 2/3rd of the Year Awards with the Cybersecurity Evangelist

    On the latest episode of Nerd Out, Dave and Alec welcome in special guest Jennifer Lyn Walker, the Cybersecurity Evangelist, to go through the 2/3rd of the year awards. We review nominations for each award and discuss each. Awards: MVP The Cobra (Sly Stallone) Award - you are the disease and I’m the cure - what has been a great security process or procedure that can really help orgs.The Dennis Green (Former Viking Coach - they are who we thought they are award. What is a threat or tactic that threats use that really showed their true colors.The Aldus Snow (Infant Sorrow) - don’t forget about me. What is the security threat that remains always present.Dumpster Fire award - what incident or threat will just make things a mess.Scotty Doesn’t Know award (EuroTrip) - what threat is out there that orgs aren’t thinking about but should.Avengers Team Up award - is there a great product or paper that involved multiple groups that orgs should know about.Heath Ledger Joker award - what threat just takes it to another level - when you think last time was bad, the next time is worse. Some references made during the call include: Cyber Readiness Institute https://cyberreadinessinstitute.org/UnDisruptable27 https://securityandtechnology.org/undisruptable27/National Council of ISACs https://www.nationalisacs.org/Idaho National Laboratory | Cyber Informed Engineering https://inl.gov/national-security/cie/

  2. 5d ago

    Weekly Security Sprint EP 170. NK IT worker scams, blended attacks, and the weatherman!

    On this week's Security Sprint, Dave and Andy covered the following topics: Opening: • Operation Vital Signs: First-of-its-kind exercise stress tests health sector cyber resilience — Health-ISAC — 11 Aug 2026. Health-ISAC and the Health Sector Coordinating Council Cybersecurity Working Group conducted the inaugural Operation Vital Signs national tabletop exercise to test healthcare's collective response to major cyber disruption. The exercise brought together organizations spanning hospitals, pharmaceutical companies, medical device manufacturers, payers, health IT, laboratories, pharmacies, and other components of the healthcare ecosystem. • Testimonial: “Over the past two years, our company has implemented several technology and security enhancements and has worked closely with Gate 15 to conduct a series of executive-level exercises, a post-mortem of a cyber event, and a cybersecurity assessment. Through these initiatives, we achieved a 34% reduction in our cyber insurance costs.” - Director Cybersecurity & Infrastructure for a leading U.S. solar and energy manufacturer. Main Topics : North Korea IT Worker Threat: FBI investigating North Korean remote IT staffer working for US agency — Federal News Network — 10 Aug 2026. The FBI is investigating how an unidentified federal agency became involved in the longstanding North Korean scheme in which operatives fraudulently obtain remote IT employment. The development represents an escalation from documented infiltration of private-sector organizations into a reported federal government environment. Experts cited by Federal News Network warned that contractors and support personnel can create pathways into government environments even when their positions are not directly associated with government contracts. • Inside North Korea’s Operation to Conquer the American Job Market • The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In Blended Threats: Ransomware Attack disrupts Hospital Doors, Elevators, Ventilation and Air Conditioning in Canada — Cybersecurity Insiders — 11 Aug 2026. A ransomware attack affecting Health Sciences Centre in Winnipeg disrupted facility-management systems controlling doors, elevators, heating, ventilation, and air conditioning, demonstrating a direct physical consequence from a cyberattack. The hospital reported that patient care and clinical operations continued, but the incident interfered with maintenance and operation of building services. The event is significant because compromise was not confined to data or conventional business systems and instead affected infrastructure required to operate the physical hospital environment. • When Ransomware Turns Off the HVAC: Lessons from the Winnipeg Hospital Incident Severe Weather: Contiguous US breaks its record for hottest month ever, NOAA says — Associated Press — 11 Aug 2026. NOAA reported that July 2026 was the hottest month recorded across the contiguous United States since national records began in 1895. The nationwide average exceeded the previous July record set during the Dust Bowl era, with above-average temperatures recorded across all 48 contiguous states. Scientists cited by AP identify human-caused climate change as the primary driver of the long-term warming trend, with unusually warm nighttime temperatures contributing significantly to the record. Quick Hits: • Victim Decision-Making During Ransomware — Gate 15 — 13 Aug 2026 • Opportunities for AI in cyber defence — Australian Signals Directorate — 27 May 2026 • Expanding Capabilities to Combat Transnational Cyber-Enabled Crime — The White House • Russia pushes narratives aimed at reviving divisions between eastern and western Germany — NewsGuard Reality Check

    Weekly Security Sprint EP 170. NK IT worker scams, blended attacks, and the weatherman!
  3. Aug 4

    Weekly Security Sprint EP 169. Water ISAC review with Chase Snow

    On this week's Security Sprint, Dave and Andy are joined by Chase Snow to talk about the latest cyber incident involving water facilities. They covered some of these topics: Opening: • Crypto security breaches surpass $1B in H1 2026, hit record high — Crypto Briefing • CISA, ASD’s ACSC, and Partners Release Joint Guidance on Isolating Vital Operational Technology and Enabling Systems During Crisis. The Cybersecurity and Infrastructure Security Agency (CISA) and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), in collaboration with the Federal Bureau of Investigation (FBI) and international partners, published joint guidance CI Fortify – Advice for isolating vital systems. • CI Fortify – Advice for isolating vital systems — Australian Signals Directorate • When cyber attacks happen: helping organisations recover — United Kingdom National Cyber Security Centre Water Sector Cyberattacks: • Iran’s CyberAv3ngers claim ‘attacks on U.S. infrastructure,’ vow more in first statement since Minnesota water hacks • Trump rejects Iran blame for Minnesota cyberattack, points finger at 'corrupt' political foe • Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world — CyberScoop — 31 Jul 2026. With commentary from Gate 15 and WaterISAC. • Several states report cyberattacks as spy agencies suspect Iran is targeting water — The Washington Post — 01 Aug 2026. WaterISAC analyst Alec Davison said attackers used relatively unsophisticated methods against internet-connected programmable logic controllers, then changed passwords, locked out operators, and disconnected controllers, resulting in boil-water notices and sustained manual operations. • (TLP:CLEAR) CISA Issues Alert Urging Water and Wastewater Utilities to Protect OT Against Activity Targeting PLCs — WaterISAC • Iran suspected of conducting cyberattacks on US water suppliers in 45 municipalities — small towns mostly targeted, with utilities switching to manual control

    Weekly Security Sprint EP 169. Water ISAC review with Chase Snow
  4. Jul 29

    Nerd Out EP 72. Iran across the threat domains, fall events, and Odyssey talk

    In the latest episode of Nerd Out, Dave and Alec break down recent developments in the conflict with Iran and consider whether the situation could widen, along with the broader factors event professionals should keep in mind. They also discuss the Berlin vehicle ramming attack and what it may signal for future outdoor event planning and security. Looking ahead to the fall event season, they explore how current geopolitical dynamics could shape risk considerations. The episode wraps with a lighter segment as Dave and Alec share their thoughts on The Odyssey, catch up on Game of Thrones, and look forward to the latest Spider-Man. References from the pod include: Iran Conflict - Horizontal Escalation https://www.reuters.com/world/asia-pacific/us-saudis-attack-iran-backed-groups-iraq-threatening-intensify-conflict-2026-07-29/https://www.france24.com/en/middle-east/20260727-yemen-says-ready-for-houthi-escalation-after-rebels-target-saudi-arabiahttps://oilprice.com/Energy/Energy-General/Ukraines-Attack-on-Iranian-Cargo-Ship-Links-Two-Wars.html Iran Cyber Activity in the Homeland https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a https://www.dataminr.com/resources/blog/implications-of-recent-cisa-disclosures-on-iranian-ot-targeting/ Berlin Terrorist Attack and Security Resources for Large Gatherings and Outdoor Events https://www.bbc.com/news/articles/cevmdxz4872ohttps://archive.dni.gov/index.php/nctc-how-we-work/joint-ct-assessment-team/first-responder-toolbox/opportunistic-attacks/vehicle-borne-attacks-tactics-and-mitigationhttps://www.cisa.gov/resources-tools/resources/vehicle-incident-prevention-and-mitigation-security-guidehttps://www.cisa.gov/topics/physical-security/securing-public-gatherings

  5. Jul 28

    Weekly Security Sprint EP 168. Berlin and event planning, plus cyber reports

    On this week's Security Sprint, Dave and Andy covered the following topics: Opening: • Cybersecurity Regulations: Multiple Sectors Are Subject to Potentially Duplicative Reporting Requirements — U.S. Government Accountability Office & 70% of federal cybersecurity reporting rules are duplicated, GAO finds — CyberScoop • ANCHOR-CI could fix 20 years of broken government-industry collaboration — CyberScoop • Project Pilot: Can AI models fly drones? — Anthropic — • OpenAI and Hugging Face partner to address security incident during model evaluation — OpenAI — • Bluesky Thread: OpenAI and Hugging Face incident demonstrates both autonomous cyber risk and defensive potential — Pwnallthethings • Hugging Face CISO Post Mortem — Cloud Security Alliance Main Topics: 1 dead, 16 injured after car ramming at Berlin CSD Pride event — DW — 25 Jul 2026. One person was killed and 16 others were injured after a vehicle was driven into people attending Berlin’s CSD Pride event. Authorities investigated the circumstances and potential motive behind the incident as emergency personnel treated victims and secured the area. The attack underscores the vulnerability of large public gatherings to vehicle-based violence and the potential for mass casualties within seconds. • The suspect in the deadly Berlin Pride attack is killed in a confrontation with police • Car Plows Into Crowd at Berlin Pride Event in Suspected Terror Attack ‘Integrated’ cyber and physical attacks concerned FIFA planners — StateScoop — 20 Jul 2026. Security planners for the 2026 FIFA World Cup prepared for blended attacks combining cyber disruption, physical violence, disinformation, swatting, infrastructure attacks, and interference with emergency communications. • The Gate 15 Interview EP 60 – Sasha Larkin: “I like the chaos, chaos makes sense to me.” 2026H1 Threat Review: Vulnerabilities Up 51% Year Over Year — Forescout — 20 Jul 2026. Forescout reports a 51 percent year-over-year increase in vulnerabilities during the first half of 2026 as organizations contend with accelerating disclosure volumes across IT, Internet of Things, operational technology, and connected devices. Email threat landscape: Q2 2026 trends and insights — Microsoft Security — 23 Jul 2026. Microsoft detected approximately 7.6 billion email-based phishing threats during the second quarter, while monthly volumes declined modestly from April through June. Quick Hits: • Weekly ransomware & data leak landscape — eCrime.ch — 27 Jul 2026. eCrime.ch recorded 236 public ransomware and data-leak claims involving 45 active groups during the seven-day period ending 27 July, with 63 events showing public evidence of data leakage. Qilin led with 37 claims, followed by Gentlemen and Global Secret Group with 31 each, while construction was the most frequently targeted sector with 17 incidents. The United States accounted for 103 claims, and healthcare recorded 10 incidents among the 88 sectors represented. • Pay up or not? Ransomware surge has victims facing tough choices — Ars Technica • If you pay a hacker’s ransom, chances are that they’ll come back for more • Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569) — Ransom-ISAC — 22 Jul 2026. Ransom-ISAC, eCrime.ch, and DEFUSED warn that Cl0p ransomware affiliates are actively exploiting internet-exposed PTC Windchill and FlexPLM systems. • Black Kite’s 2026 Ransomware Report: Ransomware Accelerates 60% in Six Months and Shows No Signs of Slowing as New Ransomware Groups Emerge Weekly

    Weekly Security Sprint EP 168. Berlin and event planning, plus cyber reports
  6. Jul 21

    Weekly Security Sprint EP 167. Cyber trends, kidnapping risks, and more!

    On this week's Security Sprint, Dave and Andy covered the following topics: Opening: • The Gate 15 Interview EP 72. Amira Dhalla on Take9, the Power of the Pause, SS26 and the World Cup! • Defending the Collective — AI Powered Threats and the New ISAC Playbook — Cyber Threat Alliance Main Topics: Ransomware & Cyber Threats • Health-ISAC: Health Sector Heartbeat 2026 Q2 - 2026: Q2 Cybersecurity Trends and Threats in the Health Sector • June Incident Response Insights — Health-ISAC • 2026 Health-ISAC CISO Benchmarking Report — Health-ISAC • 15 Latest Cyber Threat Trends Shaping Cybersecurity in 2026 — CloudSEK — 19 Jul 2026. CloudSEK identified ransomware, phishing, artificial intelligence-enabled attacks, deepfakes, zero-day exploitation, supply-chain compromise, insider threats, cloud weaknesses, credential abuse and quantum threats, among the major cyber risks shaping 2026. Kidnappings Increased 60 Percent Between 2020 and 2025, Analysis Says — Security Management — 16 Jul 2026. Recorded kidnappings increased 60 percent globally between 2020 and 2025, with every region except Asia Pacific reporting growth. Mass kidnappings increased 154 percent as criminal groups exploited conflict, displacement, inequality, and weak state security, particularly in parts of Africa. Perpetrators are also draining victims’ mobile banking accounts, making repeated ransom demands, and targeting cryptocurrency holders based on information gathered through social media. Iran hackers resume threats to hit critical infrastructure with ‘unforgettable lessons’ — Threat Beat — 19 Jul 2026. The Iran-linked Handala group resumed public threats against U.S. and allied critical infrastructure following the collapse of the ceasefire and renewed military strikes. The group referenced electricity, water, fuel, retail, and information technology targets and warned of future actions intended to deliver unforgettable lessons. Handala previously claimed destructive attacks against a U.S. medical technology company and alleged compromises involving water utilities, ports, and government personnel, although individual claims require independent verification. Target is energy, water, healthcare, maritime, retail, government, and information technology organizations in the United States and allied countries. Dig highlights renewed Iranian cyber signaling that may precede disruptive, destructive, or hybrid operations against civilian infrastructure during the expanding conflict. • Iran strikes Kuwait plant critical to drinking water supply — Straight Arrow News Quick Hits: • Beware of Disaster Fraud — Federal Emergency Management Agency • DHS network intrusion was twice ruled a false positive before breach confirmed • The Explosive Diarrhea Outbreak Is About to Get Much Bigger • Cyclosporiasis Outbreak with Unknown Source — Centers for Disease Control and Prevention • Everyone Thinks They Have This Diarrhea Parasite. Do They? • House Passes Seven-Year TRIA Reauthorization — The Real Estate Roundtable

    Weekly Security Sprint EP 167. Cyber trends, kidnapping risks, and more!
  7. Jul 14

    Weekly Security Sprint EP 166. Wearable devices, Europol report, weather and more.

    On this week's Security Sprint, Dave and Andy covered the following topics: Opening: • The Show Must Go On: Building Cyber Resilience for Venues — Global Awareness Professionals — 08 Jul 2026. Global Awareness Professionals published a Gate 15 guest post on strengthening venue cyber resilience through assessment, planning, exercises, and post-incident learning. • Lessons from CISA's Cyber Incident — Cybersecurity and Infrastructure Security Agency — 09 Jul 2026. CISA disclosed lessons from its response to an incident involving credentials exposed through a publicly accessible software repository. Main Topics: New York to ban smart glasses from all courthouses. All courts in New York state will ban smart glasses starting later this month. Beginning on July 20, all eyewear or headwear that contains cameras, microphones or other recording technology will not be allowed inside any Unified Court System facilities, according to a memo from the Office of Court Administration. The ban applies to more than 1,240 state, county, city, town and village courts. Terrorism / Extremism • When violence shapes identities: In a larger pool of perpetrators. — Europol — 13 Jul 2026. Europol's European Union Terrorism Situation and Trend Report 2026 assesses that terrorism in Europe is becoming increasingly decentralized, with a broader and more diverse pool of perpetrators motivated by jihadist, right-wing extremist, left-wing extremist, anarchist, separatist, and single-issue ideologies. The report notes continued growth in lone-actor violence, online radicalization, youth involvement, and hybrid ideological influences that blur traditional threat categories. Europol emphasizes that violent extremist ecosystems increasingly reinforce one another through online platforms, propaganda, and shared narratives even when ideological goals differ. • Feared for years, an Iranian attack on US soil has not materialized. Here’s why. — Christian Science Monitor — 10 Jul 2026. The article examines why Iran has not conducted a large-scale retaliatory attack inside the United States despite decades of concern from U.S. intelligence and security officials. • Blurring Terrorism and War: Russia’s Counter-Terrorism Framework and the Risks for International Partners — International Centre for Counter-Terrorism — 09 Jul 2026 • 8 men indicted in planned drone and sniper attack on White House UFC cage-fighting show — Associated Press — 10 Jul 2026 Severe Weather: • CSU Hurricane Seasonal Forecasting — Colorado State University — 08 Jul 2026. Colorado State University’s initial seasonal hurricane forecast and press release for 2026 was released on Thursday, April 9, 2026 and updated on Wednesday, June 10, 2026 and Wednesday, July 8, 2026. • Taiwan, Japan and south-eastern China brace for Typhoon Bavi as landslides kill 15 in Philippines • 100 million Americans face dangerous heat as temperatures surge • A ‘super’ El Niño is brewing. Experts fear historic dangers from extreme weather Quick Hits: • NSA and Partners Release Guidance on Improving Router Hygiene to Protect Against Russian State-Sponsored Targeting — National Security Agency — 13 Jul 2026 • Frontier AI models and their impact on cyber security – an update on AI model harnesses — Australian Signals Directorate — 13 Jul 2026 • Cyber Shield: The path to an agentic AI future for cyber defence — National Cyber Security Centre — 07 Jul 2026 • National Day of Protest Against Data Centers on July 18—Map, List of Cities — Newsweek — 09 Jul 2026 • CISA expects to finalize key cyber reporting rule by September — Nextgov/FCW — 06 Jul 2026

    Weekly Security Sprint EP 166. Wearable devices, Europol report, weather and more.

Ratings & Reviews

5
out of 5
4 Ratings

About

The Gate 15 Company is a leader in helping organizations by providing threat-informed, risk-based approaches to analysis, preparedness and operations.

You Might Also Like