The Gate 15 Podcast Channel

Gate 15
The Gate 15 Podcast Channel

The Gate 15 Company is a leader in helping organizations by providing threat-informed, risk-based approaches to analysis, preparedness and operations.

  1. Weekly Security Sprint EP 101. Security Updates and Resilience Considerations

    6 NGÀY TRƯỚC

    Weekly Security Sprint EP 101. Security Updates and Resilience Considerations

    Andy goes solo this week, providing some initial updates relating to the ISAC community and last week’s Security Sprint focus on government transition and related concerns, then diving into a quick rundown of enduring threats and issuessecurity leaders may want to think about as part of their broader security and resilience efforts.   ·      Crypto ISAC! FBI PSA - North Korea Responsible for $1.5 Billion Bybit Hack ·      Insider Threats: US intel shows Russia and China are attempting to recruit disgruntled federal employees, sources say ·      US – Russia Cyber Operations: ·    CISA on X: “CISA’s mission is to defend against all cyber threats to U.S. Critical Infrastructure, including from Russia. There has been no change in our posture. Any reporting to the contrary is fake and undermines our national security.” ·      Exclusive: Hegseth orders Cyber Command tostand down on Russia planning ·      Trump administration retreats in fight against Russian cyber threats ·      Risky Bulletin: Trump administration stops treating Russian hackers as a threat ·      Ranking Member Thompson: Trump Weakens National Security and Puts Our Critical Infrastructure at Risk as He Capitulates to Russia   Main Topics  The Physical and Cyber Supply chain! Manmade Threats Terrorism o  Minneapolis Man Arrested for Attempting toProvide Material Support to ISIS o  One dead after car drives into crowd in German city of Mannheim o  Tajik National Arrested in Brooklyn for Conspiring to Provide Material Support to ISIS Protests, Anger, Targeted Threats o  Tesla Takedown and other political protests o  Police Investigate Shooting at InsuranceCEO's Oregon Home: Reports o  State Accident Insurance Fund CEO targeted interrifying attack by hooded gunman at his Oregon home o  Chairmen Gimenez, Green Introduce Bill To Address Vehicular Terrorism As Threat Grows   Weather, Climate & Environment o  Hurricane Season is coming, and the USG may be less prepared and less able to respond o  Wildfires scorch the Carolinas, SC Governor McMaster declares state of emergency o  Wildfires Break Out in the Carolinas, Prompting Evacuations o  Carolina Fire Maps Show Where Blazes Burning in North, South Carolina   Health preparedness o  Texas measles outbreak rises to 146 cases o  Texas Official Warns Against ‘MeaslesParties’ Amid Growing Outbreak o  RFK Jr. urges people to get vaccinated amiddeadly Texas outbreak o  NewsGuard: Vaccines Falsely Blamed for Measles Outbreak   Cyber Threats: o  BEC & ransomware o  Blended Threats: Modat - Doors Wide Open: hundreds of thousands of employees exposed & related: Over 49,000 misconfigured building access systems exposed online. o  Critical dependencies o  Info Ops: Russian propaganda may be flooding AI models   Quick Hits Take9!!! A Disney Worker Downloaded an AI Tool. It Ledto a Hack That Ruined His Life

    20 phút
  2. Weekly Security Sprint EP 100! Hitting the century mark with DOGE, CISA and insider threat

    25 THG 2

    Weekly Security Sprint EP 100! Hitting the century mark with DOGE, CISA and insider threat

    In the 100th episode of the Security Sprint, Dave and Andy covered the following topics: Warm Open: ·      H2OSecCon 2025 Call for Presentations Now Open   Main Topic:   DOGE, the Private Sector. Insider Threats & Info Sharing ·      DOGE Now Has Access to the Top US Cybersecurity Agency ·      DOGE employee Edward Coristine lands at CISAwith DHS email ·      ISAC chief on CISA security rollbacks: ‘The sky isn’t falling, yet.’ ·      The Gate 15 Interview EP 55. Allan Liska, Ransomware Sommelier. Threats, mental health, comic books and Diet Dr. Pepper ·      Trump 2.0 Brings Cuts to Cyber, Consumer Protections ·      DOGE will use AI to assess the responsesof federal workers who were told to justify their jobs via email ·      PERSPECTIVE: Current U.S. GovernmentAdministration and the Risk of Increased Insider Threat ·      Opinion: DOGE’s US worker purge has created aspike in insider risk   Quick Hits: ·  Bybit Hack: Crypto exchange Bybit says it was hacked andlost around $1.4B o  Risky Bulletin: North Korean hackers steal $1.5 billion from Bybit o   Big Day for Crypto Goes South in a Hurry After a Giant Hack o  Ethereum Developer Counters Idea Of Blockchain Rollback Amid Bybit Hack o  Bybit’s Phantom Hacker Becomes Ethereum’s Shadow Whale by Fragmenting Fortune Across 54 Wallets o  Bybit Hack Funds Funneled Through Meme Coins, Onchain Sleuth Reports o  Crisis Management in $1.4 Billion Hack Sets New Industry Standard, Bybit Officials Say o  What the Bybit Hack Means for Crypto Security and the Future of Multisig Protection ·      Stablecoin Bank Infini Earn Latest Hack Victim, Sees $49.5M USDC Flow Out to Attackers ·      Apple is removing iCloud end-to-encryption features from the UK after government compelled it to add backdoors ·      CISA and Partners Release Advisory on Ghost (Cring) Ransomware ·      Risky Bulletin: BlackBasta implodes, internal chats leak online ·      Salt Typhoon hackers exploited stolen credentials and a 7-year-old software flaw in Cisco systems ·      Terror Thwarted: Man Threatening Violent Attacks On New York Shuls Arrested In Lincoln Tunnel On Friday Evening ·      Early data show homicides dropped 16% in 2024

    26 phút
  3. Weekly Security Sprint EP 99. China, hostile events, and more.

    18 THG 2

    Weekly Security Sprint EP 99. China, hostile events, and more.

    In this week's Security Sprint, Dave and Andy covered the following topics. Warm Opening: Quantum Computing Resources: ⁠Canadian Centre for Cyber Security⁠ - ⁠Preparing your organization for the quantum threat to cryptography (ITSAP.00.017)⁠ ⁠Preparing your organization for the quantum threat to cryptography - ITSAP.00.017 (PDF, 335 KB)⁠ ⁠FS-ISAC Releases Guidance to Help the Payment Card Industry Mitigate Risks of Quantum Computing⁠ ⁠Joint Letter on the UK Government’s use of Investigatory Powers Act to attack End-to-End Encryption⁠ ⁠U.K. demand for a back door to Apple data threatens Americans, lawmakers say⁠  Main Topics:  China: ⁠Threat Snapshot: CCP Espionage, Repression On Us Soil Is Growing⁠; ⁠As USAID retreats, China pounces⁠  Recorded Future - ⁠The Risk of a Taiwan Invasion Is RisingFast⁠  Hate, Extremism & Terrorism: ⁠Afghan held after suspected rammingattack injures 28 in Germany⁠ ⁠Would-be Mooresville school shooter hadcollage of mass murderers, court docs reveal⁠ ⁠Indiana teen accused of plotting Valentine’s Day school shooting was inspired by the Parkland massacre⁠ ⁠Singapore detains teenage ‘East Asiansupremacist’ for planning attacks on Malays, Muslims⁠ ⁠Singapore detains teen who ‘aspired’ tokill Muslims, mirroring New Zealand mosque attack⁠⁠The August 2024 Taylor Swift Vienna Concert Plot⁠.   Quick Hits Cyber Reports: ⁠Storm-2372 conducts device code phishingcampaign⁠ ⁠The BadPilot campaign: Seashell Blizzardsubgroup conducts multiyear global access operation⁠ Google: ⁠Stand-Alone Cybercrime is a Threat toCountries' National Security⁠ ⁠January 2025’s Most Wanted Malware: FakeUpdates Continues to Dominate⁠ ⁠Ransomware Gangs Increasingly Prioritize Speed and Volume in Attacks⁠ DOJ: ⁠Phobos Ransomware Affiliates Arrested inCoordinated International Disruption⁠ ⁠Dragos Industrial Ransomware Analysis:Q4 2024⁠ ⁠US cyber agency puts election securitystaffers who worked with the states on leave⁠ ⁠China’s Salt Typhoon hackers continue tobreach telecom firms despite US sanctions⁠ Blended Threats! ⁠Addressing cyber risks of smartinfrastructure, preventing catastrophic fires⁠ ⁠Insider threats loom as Elon Musk's team gains swift government access⁠ SecurityScorecard- ⁠A Deep Peek at DeepSeek⁠. ⁠New York Bans DeepSeek Over Potential Data Risks⁠

    24 phút
  4. Weekly Security Sprint EP 98. A few of our favorite things: EAP, Ransomware, Phishing and more!

    11 THG 2

    Weekly Security Sprint EP 98. A few of our favorite things: EAP, Ransomware, Phishing and more!

    In this week's Security Sprint, Dave and Andy covered the following topics: Warm Opening: • In reversal, CISA workforce now permitted to take deferred resignation offer • FS-ISAC Releases Timely Data Governance And Generative AI Guidance & read More Opportunity, Less Risk: 8 Steps to Manage Financial Services Data with GenAI. Cyber Pipeline: o Chairman Rreen reintroduces “Cyber PIVOTT Act,” Senator Rounds to lead companion legislation o Lawmakers unite to push forward Cyber Force o Gate 15’s been arguing for this since 2018… It’s Time for an FBI Cybercrime College Scholarship Program, October 14, 2018 • Blended Threats! Gate 15’s been talking about this since 2017… Unpacking the vicious cycle of climate change and digital security. Blended Threats you say…? Cyberattack on NHS causes hospitals to miss cancer care targets Main Topics: CISA Releases Active Assailant Emergency Action Plan Template and Instructional Guide o Active Assailant Emergency Action Plan Template o Instructional Guide to the CISA EAP Template Ransomware & Data Breaches: Ransomware attackers turn to workers for data breach access o Cyfirma: Tracking Ransomware: January 2025 o 35% Year-over-Year Decrease in Ransomware Payments, Less than Half of Recorded Incidents Resulted in Victim Payments o Coveware: Will Law Enforcement success against ransomware continue in 2025? o Halcyon Threat Insights 013: February 2025 Ransomware Report Scams!Take9! Hackers Hijack JFK File Release: Malware & Phishing Surge o Take9: Gate 15 is proud to partner with Take9! 9 SECONDS FOR A SAFER WORLD. Cyber threats are everywhere. And getting sneakier. What can you do to protect yourself, your community and our nation? Take a 9 second pause and think before you click, download, share. A short pause goes a long way. o Threat actor claims to have breached Trump Hotels Quick Hits: • Trump's Gaza comments hand jihadist terrorists a 'rallying cry,' experts say • CSI: Security Considerations for Edge Devices: Executive Guidance • Canadian Centre for Cyber Security - Virtual private networks (ITSAP.80.101) • UK NCSC: Network security fundamentals; How to design, use, and maintain secure networks • National Security Presidential Memorandum/NSPM-2; Imposing Maximum Pressure on the Government of the Islamic Republic of Iran, Denying Iran All Paths to a Nuclear Weapon, and Countering Iran’s Malign Influence Government Data Security Concerns: o A US Treasury Threat Intelligence Analysis Designates DOGE Staff as ‘Insider Threat’ o Federal judge blocks Elon Musk’s DOGE from accessing sensitive US Treasury Department material o Government Security Professionals Grapple with Following Procedure Amid DOGE Demands o Teen on Musk’s DOGE Team Graduated from ‘The Com’ o As DOGE teams plug into federal networks, cybersecurity risks could be huge, experts say o Coalition of US states to file lawsuit after Musk’s DOGE gains access to Americans’ personal data Breaking Encryption: o U.K. orders Apple to let it spy on users’ encrypted accounts; Secret order requires blanket access to protected cloud backups around the world, which if implemented would undermine Apple’s privacy pledge to its users. o UK’s secret Apple iCloud backdoor order is a global emergency, say critics DeepSeek: o Lawmakers Push to Ban DeepSeek App From U.S. Government Devices o Researchers say China’s DeepSeek chatbot is linked to state telecom, raising data privacy concerns • Internet-connected cameras made in China may be used to spy on US infrastructure: DHS • Exclusive - Chinese Spy Balloon Was Packed With American Tech; The balloon carried technology from at least five US firms. • Hackers exploiting bug in popular Trimble Cityworks tool used by local gov’ts & Trimble Releases Security Updates to Address a Vulnerability in Cityworks Software

    24 phút
  5. Weekly Security Sprint EP 97. DeepSeek AI, Ransomware report, and more

    5 THG 2

    Weekly Security Sprint EP 97. DeepSeek AI, Ransomware report, and more

    In this week's Security Sprint, Dave and Andy covered the following topics. Warm Start:   (TLP:CLEAR) WaterISAC – EPA: National Security Information Sharing Bulletin - Q1 2025. WaterISAC and EPA just published the latest quarterly edition of the National Security Information Sharing Bulletin. The Information Sharing Bulletin (ISB) is intended for water and wastewater utility owners and operators to provide information on priority security and resilience topics, including cybersecurity, physical security, and natural disasters.   Main Topics: Ransomware & Data Breaches: NCC Group releases Annual Cyber Threat Monitor Report 2024. LockBit‘s empire crumbles in the great ransomware reshuffle of 2024. When ransomware kills: Attacks on healthcare facilities New York Blood Center Enterprises Ransomware Attack Update Halcyon - Arcus Media Ransomware Displays Novel Process Targeting, Selective Encryption and Recovery Disruption. LockBit - Persistent TTPs in the Larger Ecosystem;   DeepSeek:  Pentagon scrambles to block DeepSeek after employees connect to Chinese servers Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information, Including Chat History.  Satellite images reveal China building war command center in Beijing. Meta's WhatsApp says Israeli spyware company Paragon targeted scores of users. Common Challenges in Cybercrime: 2024 Review by Eurojust and Europol. Cybercrime websites selling hacking tools to transnational organized crime groups seized. Europol: Law enforcement takes down two largest cybercrime forums in the world; The platforms combined had over 10 million users worldwide. Man Arrested On Capitol Hill Said He Wanted To Kill Trump Cabinet Officials, House Speaker: Police. Drones over NJ: Why didn’t the FAA admit they authorized the flights? Here’s what we know FBI Springfield Advises Caution in Online Relationships. MGM Agrees to Pay $45 Million to Settle Data-Breach Lawsuit.   Quick Hits: The ‘murder gang’ of computer whizzkids linked to the killings of a Border Patrol agent and a landlord 3,000 miles apart. The Nashville Attack Displayed Several Hallmarks of Modern Terrorism  FBI PSA - Mail Theft-Related Check Fraud is on the Rise. The FBI and USPIS are warning that check fraud is on the rise, with a significant volume enabled through mail theft. X Phishing | Campaign Targeting High Profile Accounts Returns, Promoting Crypto Scams.  Risky Biz News - Twitter account hacks: Multiple high-profile accounts have been hacked over the past week to promote various memecoins. Chinese and Iranian Hackers Are Using U.S. AI Products to Bolster Cyberattacks. CISA employees told they are exempt from federal worker resignation program⁠. ⁠Alarmed by Chinese hacks, Republicans mute attacks on cybersecurity agency⁠ ⁠Top F.B.I. Agent in New York Vows to ‘Dig In’ After Removals at Agency⁠ ⁠Wyden Demands Answers Following Report of Musk Personnel Seeking Access to Highly Sensitive U.S. Treasury Payments System⁠ ⁠Videos Show Massive Anti-ICE Protest Erupt As Demonstrators Take Over LA Highway⁠ ⁠Texas Man Admits to Making Violent Threats Against Sikh Nonprofit Organization⁠. ⁠Watch What You Say: SEC Enforcement Scrutinizes Cybersecurity Incident Disclosures⁠. ⁠Bird flu crisis enters new phase⁠.

    19 phút
  6. 5 THG 2

    The Gate 15 Interview EP 54. Brandon Dixon on Artificial Intelligence, getting your hands dirty & long, long runs

    In this episode of The Gate 15 Interview, Andy Jabbour speaks with Brandon Dixon. Brandon has worn many hats, from security engineer to entrepreneur. Today, he serves at a Partner AI Strategist for Microsoft, Strategic Advisory and Partner with NinjaJobs, and is a tremendous athlete. Brandon has dedicated his career to information security, focusing on analysis, solution development, and process refinement. As the Security AI Strategist for Microsoft Research, he is advancing fully autonomous security outcomes. Previously, Brandon led the product release of Copilot for Security. He also served as VP of Strategy and Product at RiskIQ, a San Francisco startup acquired by Microsoft, where he helped integrate the business and launched Defender Threat Intelligence and Defender External Attack Surface Management. Brandon has developed several public solutions, including PassiveTotal (acquired by RiskIQ), NinjaJobs (acquired by Starfish Partners), PDF X-RAY, and Blockade.io. His research and development in various security topics have earned him accolades from major security vendors and industry peers. Learn more about Brandon on LinkedIn. In the discussion Brandon and Andy discuss: Brandon’s Background. Three “Big Things” in AI Brandon’s paying attention to in 2025. Entrepreneurship: “Make sure the idea is something you personally care about.” The value of falling short. Resilience. Roasting Coffee (see link below!) Balance. Fitness: from BMX to ultras. We play Three Questions! Whippets, Big Sky, and long runs. More! Selected links: Beans to Bots: Hacking My Coffee Machine with AI Security Chaos Engineering: Sustaining Resilience in Software and Systems

    44 phút
  7. Weekly Security Sprint EP 96: Extremist trends, nation-states, and more

    28 THG 1

    Weekly Security Sprint EP 96: Extremist trends, nation-states, and more

    In this week's Security Sprint, Dave and Andy covered the following topics: Main Topics:  House Homeland Releases Updated “Terror Threat Snapshot” Assessment In Wake Of New Year’s Day ISIS-Inspired Terrorist Attack In New Orleans. PDF: “Terror Threat Snapshot.”  US lawmakers warn of 'emboldened' terror threat Nashville school shooter left behind 47-page manifesto detailing hate: report 'God I am ugly': Nashville school shooter's social media shows he embraced white supremacy Nashville School Shooter's Manifesto: Calls To Attack Mosques, Churches, Synagogues, Military Bases, Government Buildings, Power Grids, Schools Madison and Nashville School Shooters Appear to Have Crossed Paths in Online Extremist Communities Antioch, Tenn., Shooter Inspired by Broad Extremist Beliefs and Previous Mass Killers   FBI PSA: North Korean IT Workers Conducting Data Extortion. The Federal Bureau of Investigation (FBI) is providing an update to previously shared guidance regarding Democratic People's Republic of Korea (North Korea) Information Technology (IT) workers to raise public awareness of their increasingly malicious activity, which has recently included data extortion. China’s Cyber Threat: Under Trump, US Cyberdefense Loses Its Head; Chinese hacks, rampant ransomware, and Donald Trump’s budget cuts all threaten US security. In an exit interview with WIRED, former CISA head Jen Easterly argues for her agency’s survival. “Everybody should assume that our adversaries, in particular China, are attempting to go after our critical infrastructure. The private sector, they are on the front lines of this fight, because they own and operate the vast majority of our critical infrastructure. It's why companies need to put collaboration over self-preservation.” “Time For Us To Get A Step Ahead Of The Typhoons”: Chairman Green Opens Hearing On Global Cyber Threats “Preparation Of The Battlefield”: Cybersecurity Experts Testify On Global Threats To The Homeland WaterISAC: House Committee Hearing – Unconstrained Actors: Assessing Global Cyber Threats to the Homeland. Witnesses also cited recent incidents at water utilities.   Quick Hits:   Insider Threats: Orlando Man Pleads Guilty To Conducting Series Of Cyber Intrusions Against Former Employer British Museum forced to partly close after alleged IT attack by former employee CISA and FBI Release Updated Guidance on Product Security Bad Practices Virus season roars back with "quad-demic" of illness Scammers Are Creating Fake News Videos to Blackmail Victims TikTok Threat Arrest: "[Trump] needs to be assassinated" USCP Arrests Man with Gun. Article: Capitol Police: Officer suspended for allowing man with concealed gun into building CISA and FBI Release Advisory on How Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications Ransomware gang uses SSH tunnels for stealthy VMware ESXi access Cobalt Strike and a Pair of SOCKS Lead to LockBit Ransomware Ransomware’s Evolution: Key Threat Groups Targeting the Energy and Utilities Sector in 2025 Ongoing Campaign Targeting Amazon Web Services S3 Buckets

    23 phút

Xếp Hạng & Nhận Xét

5
/5
4 Xếp hạng

Giới Thiệu

The Gate 15 Company is a leader in helping organizations by providing threat-informed, risk-based approaches to analysis, preparedness and operations.

Có Thể Bạn Cũng Thích

Bạn cần đăng nhập để nghe các tập có chứa nội dung thô tục.

Luôn cập nhật thông tin về chương trình này

Đăng nhập hoặc đăng ký để theo dõi các chương trình, lưu các tập và nhận những thông tin cập nhật mới nhất.

Chọn quốc gia hoặc vùng

Châu Phi, Trung Đông và Ấn Độ

Châu Á Thái Bình Dương

Châu Âu

Châu Mỹ Latinh và Caribê

Hoa Kỳ và Canada