283 avsnitt • Längd: 40 min • Veckovis: Tisdag
The Gate 15 Company is a leader in helping organizations by providing threat-informed, risk-based approaches to analysis, preparedness and operations.
The podcast The Gate 15 Podcast Channel is created by Gate 15. The podcast and the artwork on this page are embedded on this page using the public podcast feed (RSS).
In this week's Security Sprint, Dave and Andy covered the following topics.
Warm Opening:
Quantum Computing Resources:
Main Topics:
China:
Hate, Extremism & Terrorism:
Quick Hits
Cyber Reports:
In this week's Security Sprint, Dave and Andy covered the following topics:
Warm Opening:
• In reversal, CISA workforce now permitted to take deferred resignation offer
• FS-ISAC Releases Timely Data Governance And Generative AI Guidance & read More Opportunity, Less Risk: 8 Steps to Manage Financial Services Data with GenAI.
Cyber Pipeline:
o Chairman Rreen reintroduces “Cyber PIVOTT Act,” Senator Rounds to lead companion legislation
o Lawmakers unite to push forward Cyber Force
o Gate 15’s been arguing for this since 2018… It’s Time for an FBI Cybercrime College Scholarship Program, October 14, 2018
• Blended Threats! Gate 15’s been talking about this since 2017… Unpacking the vicious cycle of climate change and digital security. Blended Threats you say…? Cyberattack on NHS causes hospitals to miss cancer care targets
Main Topics:
CISA Releases Active Assailant Emergency Action Plan Template and Instructional Guide
o Active Assailant Emergency Action Plan Template
o Instructional Guide to the CISA EAP Template
Ransomware & Data Breaches: Ransomware attackers turn to workers for data breach access
o Cyfirma: Tracking Ransomware: January 2025
o 35% Year-over-Year Decrease in Ransomware Payments, Less than Half of Recorded Incidents Resulted in Victim Payments
o Coveware: Will Law Enforcement success against ransomware continue in 2025?
o Halcyon Threat Insights 013: February 2025 Ransomware Report
Scams!Take9! Hackers Hijack JFK File Release: Malware & Phishing Surge
o Take9: Gate 15 is proud to partner with Take9! 9 SECONDS FOR A SAFER WORLD. Cyber threats are everywhere. And getting sneakier. What can you do to protect yourself, your community and our nation? Take a 9 second pause and think before you click, download, share. A short pause goes a long way.
o Threat actor claims to have breached Trump Hotels
Quick Hits:
• Trump's Gaza comments hand jihadist terrorists a 'rallying cry,' experts say
• CSI: Security Considerations for Edge Devices: Executive Guidance
• Canadian Centre for Cyber Security - Virtual private networks (ITSAP.80.101)
• UK NCSC: Network security fundamentals; How to design, use, and maintain secure networks
• National Security Presidential Memorandum/NSPM-2; Imposing Maximum Pressure on the Government of the Islamic Republic of Iran, Denying Iran All Paths to a Nuclear Weapon, and Countering Iran’s Malign Influence
Government Data Security Concerns:
o A US Treasury Threat Intelligence Analysis Designates DOGE Staff as ‘Insider Threat’
o Federal judge blocks Elon Musk’s DOGE from accessing sensitive US Treasury Department material
o Government Security Professionals Grapple with Following Procedure Amid DOGE Demands
o Teen on Musk’s DOGE Team Graduated from ‘The Com’
o As DOGE teams plug into federal networks, cybersecurity risks could be huge, experts say
o Coalition of US states to file lawsuit after Musk’s DOGE gains access to Americans’ personal data
Breaking Encryption:
o U.K. orders Apple to let it spy on users’ encrypted accounts; Secret order requires blanket access to protected cloud backups around the world, which if implemented would undermine Apple’s privacy pledge to its users.
o UK’s secret Apple iCloud backdoor order is a global emergency, say critics
DeepSeek:
o Lawmakers Push to Ban DeepSeek App From U.S. Government Devices
o Researchers say China’s DeepSeek chatbot is linked to state telecom, raising data privacy concerns
• Internet-connected cameras made in China may be used to spy on US infrastructure: DHS
• Exclusive - Chinese Spy Balloon Was Packed With American Tech; The balloon carried technology from at least five US firms.
• Hackers exploiting bug in popular Trimble Cityworks tool used by local gov’ts & Trimble Releases Security Updates to Address a Vulnerability in Cityworks Software
In this week's Security Sprint, Dave and Andy covered the following topics.
Warm Start:
(TLP:CLEAR) WaterISAC – EPA: National Security Information Sharing Bulletin - Q1 2025. WaterISAC and EPA just published the latest quarterly edition of the National Security Information Sharing Bulletin. The Information Sharing Bulletin (ISB) is intended for water and wastewater utility owners and operators to provide information on priority security and resilience topics, including cybersecurity, physical security, and natural disasters.
Main Topics:
Ransomware & Data Breaches:
DeepSeek:
Satellite images reveal China building war command center in Beijing.
Meta's WhatsApp says Israeli spyware company Paragon targeted scores of users.
Common Challenges in Cybercrime: 2024 Review by Eurojust and Europol.
Cybercrime websites selling hacking tools to transnational organized crime groups seized.
Europol: Law enforcement takes down two largest cybercrime forums in the world; The platforms combined had over 10 million users worldwide.
Man Arrested On Capitol Hill Said He Wanted To Kill Trump Cabinet Officials, House Speaker: Police.
Drones over NJ: Why didn’t the FAA admit they authorized the flights? Here’s what we know
FBI Springfield Advises Caution in Online Relationships.
MGM Agrees to Pay $45 Million to Settle Data-Breach Lawsuit.
Quick Hits:
In this episode of The Gate 15 Interview, Andy Jabbour speaks with Brandon Dixon. Brandon has worn many hats, from security engineer to entrepreneur. Today, he serves at a Partner AI Strategist for Microsoft, Strategic Advisory and Partner with NinjaJobs, and is a tremendous athlete. Brandon has dedicated his career to information security, focusing on analysis, solution development, and process refinement. As the Security AI Strategist for Microsoft Research, he is advancing fully autonomous security outcomes. Previously, Brandon led the product release of Copilot for Security. He also served as VP of Strategy and Product at RiskIQ, a San Francisco startup acquired by Microsoft, where he helped integrate the business and launched Defender Threat Intelligence and Defender External Attack Surface Management. Brandon has developed several public solutions, including PassiveTotal (acquired by RiskIQ), NinjaJobs (acquired by Starfish Partners), PDF X-RAY, and Blockade.io. His research and development in various security topics have earned him accolades from major security vendors and industry peers. Learn more about Brandon on LinkedIn.
In the discussion Brandon and Andy discuss:
Selected links:
In this week's Security Sprint, Dave and Andy covered the following topics:
Main Topics:
FBI PSA: North Korean IT Workers Conducting Data Extortion. The Federal Bureau of Investigation (FBI) is providing an update to previously shared guidance regarding Democratic People's Republic of Korea (North Korea) Information Technology (IT) workers to raise public awareness of their increasingly malicious activity, which has recently included data extortion.
China’s Cyber Threat: Under Trump, US Cyberdefense Loses Its Head; Chinese hacks, rampant ransomware, and Donald Trump’s budget cuts all threaten US security. In an exit interview with WIRED, former CISA head Jen Easterly argues for her agency’s survival.
“Everybody should assume that our adversaries, in particular China, are attempting to go after our critical infrastructure. The private sector, they are on the front lines of this fight, because they own and operate the vast majority of our critical infrastructure. It's why companies need to put collaboration over self-preservation.”
“Time For Us To Get A Step Ahead Of The Typhoons”: Chairman Green Opens Hearing On Global Cyber Threats
“Preparation Of The Battlefield”: Cybersecurity Experts Testify On Global Threats To The Homeland
WaterISAC: House Committee Hearing – Unconstrained Actors: Assessing Global Cyber Threats to the Homeland. Witnesses also cited recent incidents at water utilities.
Quick Hits:
Insider Threats:
Orlando Man Pleads Guilty To Conducting Series Of Cyber Intrusions Against Former Employer
British Museum forced to partly close after alleged IT attack by former employee
CISA and FBI Release Updated Guidance on Product Security Bad Practices
Virus season roars back with "quad-demic" of illness
Scammers Are Creating Fake News Videos to Blackmail Victims
TikTok Threat Arrest: "[Trump] needs to be assassinated"
USCP Arrests Man with Gun. Article: Capitol Police: Officer suspended for allowing man with concealed gun into building
Ransomware gang uses SSH tunnels for stealthy VMware ESXi access
Cobalt Strike and a Pair of SOCKS Lead to LockBit Ransomware
Ransomware’s Evolution: Key Threat Groups Targeting the Energy and Utilities Sector in 2025
Ongoing Campaign Targeting Amazon Web Services S3 Buckets
In this week's Security Sprint, Dave and Andy covered the following topics:
Main Topics:
Executive Orders:
Scams:
Quick Hits:
On the latest episode of Nerd Out, Alec Davison and Dave discussed recent terrorist activity and outlook for the future before looking at some of the propoganda that has been published to influence followers. They also looked at world events and the recent cease fire to assess what that may mean going forward before looking at all-hazards preparedness. Finally they wrapped up with some discussion about Skeleton Crew, and some future shows. Plus Alec makes a plea for Severance.
Some references:
Terrorism Threat Landscape
https://www.axios.com/local/new-orleans/2025/01/06/timeline-new-orleans-terror-attack https://www.fbi.gov/contact-us/field-offices/neworleans/news/fbi-releases-investigative-update-in-bourbon-street-attack https://www.asisonline.org/security-management-magazine/latest-news/today-in-security/2024/december/EU-Terror-Incidents-Rose/ https://www.axios.com/local/new-orleans/2025/01/16/lone-actor-terrorism-machine-learning-ai https://www.memri.org/reports/islamic-state-isis-al-qaeda-iran-axis-supporters-rejoice-over-los-angeles-wildfires-promote https://www.counterextremism.com/press/extremist-content-online-isis-propaganda-allegedly-helped-inspire-new-orleans-attackerTerrorgram Designation
https://www.state.gov/office-of-the-spokesperson/releases/2025/01/terrorist-designations-of-the-terrorgram-collective-and-three-leaders https://www.lawfaremedia.org/article/why-the-terrorgram-collective-designation-mattersIsrael-Hamas Hostage Deal & Ceasefire
https://www.nbcnews.com/news/world/israel-hamas-ceasefire-gaza-rcna187913 https://www.memri.org/reports/senior-hamas-official-khalil-al-hayya-upon-signing-ceasefire-agreement-october-7-willLA Wildfires
https://www.bu.edu/articles/2025/how-and-why-the-la-wildfires-grew-so-fast/ https://www.cnn.com/2025/01/10/us/california-la-fires-emergency-prep-invs/index.html https://theconversation.com/a-national-nonpartisan-study-of-the-los-angeles-fires-could-improve-planning-for-future-disasters-247198In the latest Security Sprint, Dave and Andy covered the following topics:
Warm Open:
• Errol Weiss on LinkedIn: Cyber Threats Know No Borders
• Perspective: Cybersecurity Priorities for the New Administration, by Scott Algeier, Executive Director, IT-ISAC.
Main Topics:
Los Angeles Fires:
FEMA: Ready.gov
Attorney General James Reminds New Yorkers to be Cautious in Charitable Giving for Los Angeles Wildfire Relief
HHS Secretary Xavier Becerra Declares Public Health Emergency for California to Aid Health Care Response to Wildfires
Vegas and New Orleans Follow Ups
Las Vegas Cybertruck suspect used ChatGPT to plan blast, police say
Las Vegas police release ChatGPT logs from the suspect in the Cybertruck explosion
ChatGPT advised infamous neo-Nazi on how to attack U.S. electrical grid
FBI IC3 Alert Number: I-011325-PSA: Threat of Copycat Attacks after ISIS-Inspired Vehicle Attack in New Orleans
FBI warns of potential ‘copycat or retaliatory’ New Orleans attacks
How New Orleans failed to protect Bourbon Street from attack, block by block
Ransomware:
Comparitech - Ransomware roundup: 2024 end-of-year report
Ransomware attacks on education declined in 2024, report shows
Emsisoft: The State of Ransomware in the U.S.: Report and Statistics 2024
Health:
CDC - First H5 Bird Flu Death Reported in United States. CDC has carefully studied the available information about the person who died in Louisiana and continues to assess that the risk to the general public remains low.
CDC’s Priorities for Response Readiness
Director Wray
60 Minutes: FBI Director Wray on threats America faces, decision to step down as Trump returns to the White House
Outgoing FBI director calls China and its cyber program the 'defining threat of our generation'
FBI director explains why he’s resigning, defends feds’ raid of Trump’s Mar-a-Lago
Inauguration Workplace Considerations
Quick Hits:
• 2024 was the world’s warmest year on record
• White House Launches “U.S. Cyber Trust Mark”, Providing American Consumers an Easy Label to See if Connected Devices are Cybersecure
• CISA Releases the Cybersecurity Performance Goals Adoption Report
• FACT SHEET: Ensuring U.S. Security and Economic Strength in the Age of Artificial Intelligence
• Prime Minister sets out blueprint to turbocharge AI
• UK throws its hat into the AI fire
In the latest episode of the Security Sprint, Dave and Andy covered the following topics:
FBI: 2 IEDs failed to detonate in New Orleans New Year's Day ramming attack
FBI says New Orleans attacker surveyed area using Meta smart glasses
Cybertruck driver left behind rant praising Trump and Musk, slamming Democrats
‘TIME TO WAKE UP’: Las Vegas police share notes from Cybertruck explosion suspect
Matthew Livelsberger Alleged Manifesto: Read Full Email Sent to Retired Soldier
Additional Resources:
In the latest episode of Nerd Out, Dave brings back Andy Jabbour and Jennifer Lyn Walker to remember the early days of the pod, and talk about some 2024 predictions to see if they hit the mark, were a near miss or were out of left-field. Then they talked about some things organizations should remember heading into 2025 before getting into some holiday cheer. They talked about their favorite holiday drinks, traditions, and movies or television shows before extending their best security wishes for 2025.
Andy Jabbour is the Managing Director, Gate 15 and host of the Gate 15 Interview podcast and co-host of the Security Security Sprint podcast.
Jennifer Lyn Walker is a cybersecurity professional with 24+ years of experience supporting critical infrastructure and SLTT (state, local, tribal, and territorial) governments. Jennifer has provided subject matter expertise regarding cyber threats related to homeland security for multiple critical infrastructure and vital lifeline sectors utilizing her experience in malware analysis, threat assessments, threat intelligence, HIPAA compliance, cybersecurity awareness, insider threat protection, and industrial control systems cybersecurity and safety.
Link for UnDisruptable27: https://securityandtechnology.org/undisruptable27/
In this episode of The Gate 15 Interview, Andy Jabbour speaks with Jeri Rogish and Mitchell Freddura, both with the Cybersecurity and Infrastructure Security Agency (CISA) and CISA’s Joint Cyber Defense Collaborative (JCDC). Jeri serves as Deputy Chief of JCDC’s Product Development Section and Mitch serves in the Partnerships Office.
Discussed in the podcast:
Selected links:
Additional resources:
In the latest episode of the Security Sprint, Dave and Andy covered the following topics:
Warm Start: H2OEx - An Exercise for the Water Sector
Main Topics:
UHC Assassination:
· Health insurers step up security, scrub websites of leadership information
· Luigi Mangione’s sprawling family found success after patriarch’s rise
· Health insurers step up security, scrub websites of leadership information
· What Companies Should Be Asking Their Security Teams Right Now
· A timeline of the fatal shooting of UnitedHealthcare CEO Brian Thompson and search for his killer
· UnitedHealth CEO's killing unleashes social media rage against insurers
· UnitedHealthcare CEO kept a low public profile. Then he was shot to death in New York
· Bullets fired at healthcare CEO in fatal shooting had words carved on them
· Copycat, Contagion, and the Robin Hood Effect as Risk Enhancers in Targeted Violence
Faith-Based Threats
· Terror attack on Bavarian Christmas market foiled by police
· Man in van filled with explosives, guns intended to attack a North Texas church, report states
· FeatherRiver School of Seventh-Day Adventists Shooting:
o 2 kindergarteners wounded and gunman dead after shooting at California religious school
· Five-Eyes security and law enforcement agencies release joint authored analysis of youth radicalization & PDF analysis.
Six password takeaways from the updated NIST cybersecurity framework. Password security is changing — and updated guidelines from the National Institute of Standards and Technology (NIST) reject outdated practices in favor of more effective protections.
Quick Hits:
· FBI IC3 PSA: Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud
· Russian Woman Arrested In U.S. For Alleged Ties To Russian Intelligence
· NGA: 2024 State Experts Roundtable On Protecting Energy Infrastructure From Physical Attacks
· The California tsunami danger is real. The 7.0 earthquake is wake-up call to prepare.
o 'Swaying back and forth': Magnitude 7 earthquake, aftershocks rock California
o Tsunami warning canceled after strong California earthquake
Salt Typhoon:
o White House says at least 8 US telecom firms, dozens of nations impacted by China hacking campaign
o FCC chair proposes cybersecurity rules in response to China's Salt Typhoon telecom hack
Health:
o What is mystery 'disease x' and why have dozens died in DR Congo?
o Unknown disease kills 143 in southwest Congo, local authorities say
· Korea arrests CEO for adding DDoS feature to satellite receivers
· Outraged? You’re more likely to share misinformation, study finds
· Romania hit by major election influence campaign and Russian cyber-attacks
· EU orders TikTok to freeze Romanian elections data
· Choosing secure and verifiable technologies
· CISA Releases New Public Version of CDM Data Model Document
In this week's Security Sprint, Dave and Andy covered the following topics:
Seasonal Scams!
CISA: Shop Safely This Holiday Season
FTC: Scammers are delivering phishing messages this holiday season
ClouDSEK: Cyber Monday Scams: A Comprehensive Analysis of Threats and Mitigation Strategies
Ransomware & Resilience!
UK NCSC: Cyber Security Toolkit for Boards: updated briefing pack released. New presentation includes voiceover and insights on ransomware attack on the British Library.
Cannabis industry is apparent target of Everest Ransomware, security experts warn
The costs of ransomware: Cyber attack prompts Stoli Group USA bankruptcy filing
Risky Biz News - Hoboken ransomware attack
Starbucks, Grocers Revert to Manual Processes After Ransomware Attack on Third-Party Software System
Risky Biz News - Bologna FC ransomware attack
The Evolution of BlackBasta Malware Dissemination
Ransomware-driven data exfiltration: techniques and implications
The ransomware attack that started it all. A North Korean hacker group’s attack on Sony Pictures in 2014 was the precursor to today’s global ransomware menace, according to US intelligence community’s ransomware expert, Laura Galante.
Ransomware Roundup - Interlock
Key Considerations for Legal Compliance in Ransomware Recovery
FBI-Wanted Hacker Behind Global Ransomware Attacks Arrested in Russia
Threats to Public Officials and associated risks
Trump administration picks targeted with bomb threats and swatting
FBI Statement Regarding Threats to Nominees and Appointees
Most of Connecticut's delegation in Congress targeted by bomb threats
Jeffries office: Bomb threats made against Dem lawmakers ‘unacceptable’
Arizona Man Sentenced for Making Online Threats Against Public Servants Including Federal Officials
Quick Hits
Live Virtual Presentations on Targeted Violence Prevention. The U.S. Secret Service National Threat Assessment Center (NTAC) is pleased to offer new opportunities to attend live virtual presentations on preventing targeted violence. In these presentations, our expert researchers will share findings and implications from decades of research on targeted violence and offer strategies for preventing acts of violence impacting the places where we work, learn, worship, and otherwise live our daily lives. This list of available virtual training events is regularly updated, and presentation topics change from month to month. Register Here
HSI Investigation Leads to Seizure of $3.5 Million Dollars Stolen in Business Email Compromise Scam
CISA: AI Red Teaming: Applying Software TEVV for AI Evaluations
Biden tightens tech controls on China as clock ticks down
Russian ‘spy ring plotted high-level espionage, including honey traps.’
In this episode of The Gate 15 Interview, Andy Jabbour speaks with Angela Haun. Angela is the Executive Director with the Oil and Natural Energy Information Sharing and Analysis Center (ONE-ISAC). Appointed as ONE-ISAC Executive Director in September 2018, Angela is a retired FBI Special Agent with extensive experience in cybersecurity and protecting critical assets. Since joining the ONE-ISAC, she has expanded the ONE-ISAC’s membership with a Strategic Partnership Pilot Program, bringing new organizations, expertise, resources and funding to support the ISAC’s efforts. In addition, Angela has been a subject matter expert speaker, organizer and participant in numerous energy-related conferences, briefings, exercises, meetings, webinars and other events. Ms. Haun is actively pursuing upgraded technologies and additional benefits for ONE-ISAC member analysts and executives. Prior to her work in support of ONE-ISAC, Angela served over twenty years at the FBI. Learn more about Angela on LinkedIn.
“Potential gets me so excited!”
In the discussion Angela and Andy discuss:
Selected links:
In this week's Security Sprint, Dave and Andy covered the following topics.
Warm Start:
• Auto-ISAC: Thomas Farmer Assumes Position as Director of Operations
• News from the Auto-ISAC Cybersecurity 2024 Summit
• Follow Up from last Sprint: FBI Statement Regarding Offensive Text Messages
o Bigoted text messages after Trump victory also targeted Latinos, LGBTQ+ communities, FBI says
o FBI investigates new wave of offensive messages targeting Hispanic, LGBTQ people
• Groundbreaking Framework for the Safe and Secure Deployment of AI in Critical Infrastructure Unveiled by Department of Homeland Security
• Media Advisory: Chairman Green Announces Worldwide Threats Hearing Featuring DHS Secretary Mayorkas, FBI Director Wray, NCTC Acting Director Holmgren: November 20, 2024, at 10:00 AM ET
• Senate Judiciary Committee: Big Hacks & Big Tech: China’s Cybersecurity Threat: November 20, 2024, at 2:00 PM ET
Main Topics:
Homeland Security Transitions. Rand Paul has plans to kneecap the nation’s cyber agency. The incoming chair of the Senate Homeland Security Committee has pledged to severely cut the powers of the Cybersecurity and Infrastructure Security Agency or eliminate it entirely.
• CISA Director Jen Easterly to depart on Inauguration Day
• House Homeland Releases “Cyber Threat Snapshot” Highlighting Rising Threats to US Networks, Critical Infrastructure
• Joint Statement from FBI and CISA on the People's Republic of China (PRC) Targeting of Commercial Telecommunications Infrastructure
• Salt Typhoon: T-Mobile Hacked in Massive Chinese Breach of Telecom Networks
• Salt Typhoon: Intelligence community briefed Congress on Chinese telecom intrusions
• Volt Typhoon rebuilds malware botnet following FBI disruption
• China's Hacker Army Outshines America
Liability: Legal Report: A Michigan Agency Agrees to $13 Million Settlement Concerning Surprise Active Shooter Drill.
Cyber Resilience:
• NordPass: Top 200 Most Common Passwords.
• 2023 Top Routinely Exploited Vulnerabilities. PDF: AA24-317A 2023 Top Routinely Exploited Vulnerabilities
Quick Hits:
• Palo Alto! Risky Biz News: Unpatched zero-day in Palo Alto Networks is in the wild.
• CISA Adds Two Known Exploited Vulnerabilities to Catalog
o CVE-2024-9463 Palo Alto Networks Expedition OS Command Injection Vulnerability
o CVE-2024-9465 Palo Alto Networks Expedition SQL Injection Vulnerability
• EPA: Management Implication Report: Cybersecurity Concerns Related to Drinking Water Systems.
o US EPA report cites cybersecurity flaws in drinking water systems, flags disruption risks and lack of incident reporting
o Drinking water systems for 26M Americans face high cybersecurity risks
• Moody’s Cyber Heat Map flags extreme cyber risks for critical infrastructure, impacting telecommunications and airlines
• 35 dead as driver hits crowd at sports center in southern Chinese city
• ODNI - Potential Global Economic Consequences of a Use by Russia of Nuclear Weapons in Ukraine
• Australia-Japan-United States Trilateral Defense Ministers' Meeting November 2024 Joint Statement
• Justice Department Announces Murder-For-Hire and Related Charges Against IRGC Asset and Two Local Operatives
• Iranian “Dream Job” Campaign 11.24
• Fans scuffle despite heavy security presence at France-Israel soccer match
• Hate, Extremism & Terrorism:
o Houston man charged with attempting to provide material support to ISIS
o The FBI says it stopped a possible terrorist attack in Houston
o California Teenager Pleads Guilty in Florida to Making Hundreds of ‘Swatting’ Calls Across the United States
o Nazi Group Marches Through Ohio Town
o Germany: 17-year-old arrested over alleged terror plot
o Teens accused of plotting to bomb pro-Israel rally on Parliament Hill
o Man dead after explosions outside Brazil supreme court ahead of G20
In the latest episode of Nerd Out, Dave is joined by Bridget Johnson and Joe Levy to do their annual talk about holiday threats and ways to be ever vigilant. Then they talked about their favorite foods and things to watch.
Joe Levy is the Assistant General Manager at the Barclays Center.
Bridget Johnson is a terrorism and extremism expert who has decades worth of experience analyze threat activities.
In this week's Security Sprint, Dave and Andy covered the following topics.
Warm Start:
• US cybersecurity chief says disinformation surge hasn't impacted election
• FBI Statement About Fabricated Videos and Statements Falsely Attributed to the FBI.
• Food and Agriculture Sector Eyes Cybersecurity Threats
• Food and Ag Sector 2024 Cyber Threat Report (PDF)
Main Topics:
Black people are receiving racist text messages about picking cotton 'at the nearest plantation.' The FBI and the FCC have weighed in on the messages that multiple Black people across the country received on Wednesday.
• FBI Statement on Offensive and Racist Text Messages
• FB-ISAO reports Antisemitic text messages
• Louisiana attorney general reveals new findings on racist texts
• Text service says it shut down accounts allegedly behind racist messages
Be security curious amid enduring extremism & terrorism threats, mass gatherings:
• Man Arrested and Charged with Attempting to Use a Weapon of Mass Destruction and to Destroy an Energy Facility in Nashville
• Cholo Abdi Abdullah Convicted for Conspiring to Commit 9/11-Style Attack at the Direction of Al Shabaab
• Florida Man Indicted for Posting Threats on the Internet
FBI Cyber Threat Updates:
• Easy Access to Information for Conducting Fraudulent Emergency Data Requests Impacts US-Based Companies and Law Enforcement Agencies. As of August 2024, FBI noted an uptick in criminal forum posts regarding conducting fraudulent emergency data requests and is releasing this notification for industry awareness. Cybercriminals are likely gaining access to compromised US and foreign government email addresses and using them to conduct fraudulent emergency data requests to US based companies, exposing the personal information of customers to further use for criminal purposes.
• HSI and Partners Announce Return of $1.8 Million Stolen During Business Email Compromise Scam
Quick Hits:
• Israel to collect soccer fans from Amsterdam after apparent antisemitic attacks
• Israeli soccer fans attacked in Amsterdam, in what Dutch authorities call antisemitic incidents
• Dave’s Severe Weather threat and preparedness reminders
• China Hack Enabled Vast Spying on U.S. Officials, Likely Ensnaring Thousands of Contacts
• U.S. Agency Warns Employees About Phone Use Amid Ongoing China Hack
• Russia Suspected of Plotting to Send Incendiary Devices on U.S.-Bound Planes
• Mystery fires were Russian 'test runs' to target cargo flights to US
• Halliburton misses profit estimate, buyback target as cyber attack hurts. Halliburton missed Wall Street estimate on a previously disclosed cyber hack that forced the oilfield services provider to pause a share repurchase program, executives said on Thursday.
• Unwrapping the emerging Interlock ransomware attack
• NEWPARK RESOURCES INC. Newpark Resources, Inc. is a worldwide provider of value-added drilling fluids systems and composite matting systems used in oilfield and other commercial markets. NEWPARK’s 8K.
• Major Oilfield Supplier Hit by Ransomware Attack
• 764 Terror Network Member Richard Densmore Sentenced to 30 Years in Prison
In the latest Security Sprint, Dave and Andy covered the following topics.
Warm Start.
• CISA: Critical Infrastructure Security and Resilience Month 2024. “Resilience means doing the work up front to prepare for a disruption, anticipating that it will in fact happen, and exercising not just for response but with a deliberate focus on continuity and recovery, improving the ability to operate in a degraded state, and significantly reducing downtime when an incident occurs.”
o A Proclamation on Critical Infrastructure Security and Resilience Month, 2024
o Biden declares November as critical infrastructure security and resilience month, calls safeguarding these systems
• FS-ISAC: Ransomware Essentials. A Guide for Financial Services Firm Defense (PDF)
Main Topics:
Election Week!
• Joint ODNI, FBI, and CISA Statement.
• US cybersecurity chief says disinformation surge hasn't impacted election
• CISA: Election Security Rumor vs. Reality
• Georgia Poll Worker Arrested for Making Bomb Threat to Election Workers
• FBI PSA: Scammers Exploit 2024 US General Election to Perpetrate Multiple Fraud Schemes
• Colorado accidentally put voting system passwords online, but officials say election is secure
• Joint ODNI, FBI, and CISA Statement on Russian Election Influence Efforts (01 Nov).
Liability:
• Attorney General James Secures $2.25 Million from Capital Region Health Care Provider to Protect Patient Data
• HHS Office for Civil Rights Settles Ransomware Cybersecurity Investigation for $500,000
• HHS Office for Civil Rights Settles HIPAA Ransomware Cybersecurity Investigation for $90,000
Insider Threats! Fired Employee Allegedly Hacked Disney World's Menu System to Alter Peanut Allergy Information
Quick Hits:
• Wiz CEO says company was targeted with deepfake attack that used his voice
• Ripple effect: the devastating impact of data breaches
• Canadian Centre for Cyber Security - Cyber Security Readiness
• Defendants with Ties to White Supremacy Sentenced in Connection with Plot to Destroy Energy Facilities
• United States Welcomes the United Kingdom’s Actions Against Known Purveyors of Kremlin Disinformation
• Hybrid Russian Espionage and Influence Campaign Aims to Compromise Ukrainian Military Recruits and Deliver Anti-Mobilization Narratives
• Army of bots promotes petrostate hosting global climate talks
• Reset Tech Investigation - Clickbait Cures: How Meta and Google Tolerate a Dubious Meds Market in the EU
• Fitness app Strava gives away location of Biden, Trump and other leaders, French newspaper says
• Meet Interlock — The new ransomware targeting FreeBSD servers
• Chinese threat actor Storm-0940 uses credentials from password spray attacks from a covert network
• Spain floods disaster: death toll rises to 205 as extra troops mobilised
• Biden Administration Announces Additional Security Assistance for Ukraine
• Iran Tells Region ‘Strong and Complex’ Attack Coming on Israel
• Cybersecurity Advisory – Threats Posed by Remote Technology Workers with Ties to Democratic People’s Republic of Korea
• Foreign Threat Actor Conducting Large-Scale Spear-Phishing Campaign with RDP Attachments
• New Tradecraft of Iranian Cyber Group Aria Sepehr Ayandehsazan aka Emennet Pasargad
• Cybercriminals Are Stealing Cookies to Bypass Multifactor Authentication
• Canadian Centre for Cyber Security - National Cyber Threat Assessment 2025-2026
• Pacific Rim: Inside the Counter-Offensive—The TTPs Used to Neutralize China-Based Threats
• Massive PSAUX ransomware attack targets 22,000 CyberPanel instances
• Midnight Blizzard conducts large-scale spear-phishing campaign using RDP files
In this week's Security Sprint, Dave and Andy covered the following topics.
Warm Start:
Organizational Cyber Security Culture
• The Gate 15 Interview – Rob Sherman on CISOs: “Focus on risk, focus on resilience.” Plus: A Salt and Pepper America, burnout, beta, and more!
• TribalHub x Gate 15: Organizational Cyber Culture Meets Concert Moments & The Gate 15 Interview – TribalNet! Building a Cybersecurity Culture, Tribal-ISAC, and how we rock!
Memorandum on Advancing the United States’ Leadership in Artificial Intelligence; Harnessing Artificial Intelligence to Fulfill National Security Objectives; and Fostering the Safety, Security, and Trustworthiness of Artificial Intelligence
• Statement from National Economic Advisor Lael Brainard on National Security Memorandum (NSM) on Artificial Intelligence (AI)
• FACT SHEET: Biden-Harris Administration Outlines Coordinated Approach to Harness Power of AI for U.S. National Security
• Biden administration urges US agencies to ‘harness’ AI systems for national security
• White House will order Pentagon and intel agencies to increase use of AI
• US to unveil AI national security memo to avoid China’s ‘strategic surprise’
Main Topics:
Info Ops
• Russian propaganda exploits US hurricane response to undermine FEMA and Ukraine support.
2024 Elections
• Joint ODNI, FBI, and CISA Statement.
• Pennsylvania officials rebut false voter fraud claims from home and abroad
• U.S. officials say Russia smeared Tim Walz, might stoke post-vote violence
• American creating deepfakes targeting Harris works with Russian intel, documents show
• CISA Launches #PROTECT2024 Election Threat Updates Webpage
• Joint Statement by FBI and CISA on PRC Activity Targeting Telecommunications
• Chinese Hackers Are Said to Have Targeted Phones Used by Trump and Vance
• Foreign threats to the US election are on the rise, and officials are moving faster to expose them
• Election Security Update as of Late October 2024
• Foreign Threats to US Elections After Voting Ends in 2024
• Foreign influence operations will expand before election and linger afterward, US agencies say
• Recorded Future: Operation Overload Impersonates Media to Influence 2024 US Election
• Microsoft: As the U.S. election nears, Russia, Iran and China step up influence efforts
• Justice Department Announces Four Cases Brought by Election Threats Task Force
• Secretary of State’s Office says they stopped cyberattack aimed at crashing voter website
• Wisconsin sued over voting system’s allegedly weak cyber protections
• Philadelphia Resident Charged for Election-Related Threat to State Party Representative
• Maine man made homemade bombs and dropped some from drones, officials say
• Dr. Paul Requests Information On DHS & CISA’s Participation At Election Day Cybersecurity Conference
Quick Hits:
Terrorism
• Arizona grand jury indicts juvenile for planning attack at Phoenix Pride Festival
• Maryland Man Charged With Attempting To Provide Material Support To ISIS
• Suburban Chicago Man Sentenced to 18 Years in Prison for Trafficking Fentanyl and Attempting To Support ISIS
Ransomware:
• Black Basta ransomware poses as IT support on Microsoft Teams to breach networks
• New Iranian-based Ransomware Group Charges $2000 for File Retrieval
• Japanese Man Convicted of Making Virus Using AI; Likely 1st Person in Japan to be Convicted in Criminal Case for Abusing Generative AI
• New Qilin.B Ransomware Variant Boasts Enhanced Encryption and Defense Evasion
• Crystal Rans0m: Rust-Based Hybrid Ransomware
• Avast Releases Free Decryptor for Mallox Ransomware
• Decrypted: Mallox ransomware
• Microsoft Threat Intelligence healthcare ransomware report highlights need for collective industry action
• Embargo ransomware: Rock’n’Rust
• macOS NotLockBit | Evolving Ransomware Samples Suggest a Threat Actor Sharpening Its Tools
• Akira Ransomware Evolution: A move towards cross-platform adaptability
In this episode of The Gate 15 Interview, Andy Jabbour speaks with Rob Sherman. Rob is the Chief Information Security Officer (CISO) for American Tower Corporation, a global digital infrastructure provider. Among his role and responsibilities, he established the global information security program responsible for governance, risk, compliance and security operations for the company’s corporate and line-of-business operations. Among his many hats, Rob is a CISO, attorney, cyber program builder, involved in incident response, with over 25+ years of it and infrastructure experience. Learn more about Rob: LinkedIn
In the discussion Rob and Andy discuss:
In this week's Security Sprint, Dave and Andy covered the following topics:
Election 2024:
CISA:
DOJ:
USGS: (Some) Assembly Required. How to sign your organization up for the Great ShakeOut.
Quick Hits
In this week's Security Sprint, Dave covered the following topics.
Warm Start - the importance of taking time off.
Topics.
1. Election Security.
2. Ransomware.
3. Conspiracy Theories.
In the latest episode of Nerd Out, Dave welcomed back a friend of the pod, Bridget Johnson! Bridget caught everyone up on her latest work and new ventures before the two talked about the upcoming election and potential for violence. They transitioned to global terrorism and the potential risks associated with the continued conflict in the Middle East.
Bridget is a part of the McCrary Institute. You can sign up for their products at:
In the latest episode of the Security Sprint, Dave goes solo and talks about the following topics.
Warm Start - the importance of exercises.
October 7th Anniversary PSA.
Hurricane Milton Preparedness and looking ahead.
MDM and Disaster Scams. NWS: Hurricane Milton Approaching Florida. Milton continues to intensify in the Gulf of Mexico today. Heavy rainfall ahead of Milton continues today with localized flooding concerns. This hurricane will approach the west coast of Florida during the middle of the week. Significant impacts are likely with a large and powerful hurricane at landfall in Florida, with life-threatening hazards along portions of the coastline.
In this week's Security Sprint, Dave and Andy covered the following topics:
Warm Open
Water, Water, Everywhere!
§ WaterISAC – EPA: National Security Information Sharing Bulletin
§ WaterISAC - Cybersecurity Fundamentals for Water and Wastewater Utilities
§ WaterISAC: Incident Awareness – Ransomware Attackers Target Kansas Water Treatment Facility
§ Kansas water plant cyberattack forces switch to manual operations
§ WaterISAC: EPA’s Hazard Mitigation for Natural Disasters: A Starter Guide for Water and Wastewater Utilities
§ Fears of Weakness in Water Cybersecurity Grow After Kansas Attack
§ WaterISAC: Potential Supply Chain Impacts from East Coast and Gulf Coast Labor Negotiations (Updated September 26, 2024)
§ Deluge of Threats to Water Utilities: Securing Operational Technology Against Cyberattacks
INC Ransomware had a very active weekend! GRIP subscribers saw some of that in the SUN, and see more in this week’s Ransomware and Data Breach Digest and a special Bricklayer AI-informed TARGET Report on INC Ransomware.
Main Topics
Severe Weather, Hurricane Helene, and Resilience Planning.
Crime
CSAM. A Proclamation on Cybersecurity Awareness Month, 2024.
Quick Hits
In this episode of The Gate 15 Interview, we’re mixing things up! Andy Jabbour recorded this session onsite at TribalNet 2024 with TribalHub’s Senior Marketing & Communications Manager, Michelle Bouschor, who took over as moderator. They were joined by Adam Gruscynski, IT Director, Potawatomi Casino Hotel and Tribal-ISAC Steering Committee member and Drew Ludwick, Director of IT Operations, Muckleshoot Casino Resort, to discuss ideas around cybersecurity and organizational culture.In the discussion the group discusses:
Selected Links:
Michelle Bouschor. With 15 years of experience in tribal casino marketing, tribal government public relations, media, and community relations, I’ve honed my skills in navigating the unique landscape of indigenous communities. For the past 5 years, I’ve proudly contributed to TribalHub, leveraging my expertise to empower tribal entities through innovative solutions and strategic partnerships. Passionate about fostering collaboration and growth within tribal communities, I’m dedicated to driving positive change and sustainable development.
· Michelle on LinkedIn
Adam Gruscynski. Responsible for the day-to-day operations of the IT Department for Potawatomi Casino Hotel while ensuring all of the technology needs, whether current or future, of the organization are met. Adam joined Potawatomi Casino Hotel in 2008. During his time at PCH, Adam has gained an abundance of experience by taking on various roles including IT Security Manager, Senior Cybersecurity Engineer, Lead Network Administrator, Network Administrator, and Application Administrator. Prior to PCH, Adam was Network Engineer at the Milwaukee Journal Sentinel where he began his career as Help Desk Intern.
· Adam on LinkedIn
Drew Ludwick. A seasoned IT executive with over 25 years of progressive leadership experience in technology management, specializing in cybersecurity, strategic planning, and technology governance. Known for shaping and executing technology strategies aligned with business goals, leading diverse technology teams, and fostering innovation.
· Drew on LinkedIn
In the latest episode of Nerd Out, Dave and Alec covered the following areas when Dave wasn't having technical issues.
In this week's Security Sprint, Dave and Andy covered the following topics:
Warm Start:
Main Topics:
Assassiination / Election Security:
BEC. Business Email Compromise: The $55 Billion Scam. The BEC scam continues to target small local businesses to larger corporations, and personal transactions while evolving in their techniques to access those business or personal accounts. Between December 2022 and December 2023, there was a 9% increase in identified global exposed losses. In 2023, the IC3 saw a growth in BEC reporting where funds were sent directly to a financial institution housing custodial accounts held by third-party payment processors, or peer-to-peer payment processors, and cryptocurrency exchanges which directly contributed to the increase in global exposed losses. IC3 data shows the BEC scam has been reported in all 50 states and 186 countries, with over 140 countries receiving fraudulent transfers. Based on the financial data reported to the IC3 for 2023, international banks located in the United Kingdom and Hong Kong often acted as an intermediary stop for funds, followed by China, Mexico, and the UAE. The following BEC statistics were reported to the FBI IC3, law enforcement and derived from filings with financial institutions between October 2013 and December 2023:
o Domestic and international incidents: 305,033
o Domestic and international exposed dollar loss: $55,499,915,582
o Total U.S. victims: 158,436
o Total U.S. exposed dollar loss: $20,089,561,364
o Total non-U.S. victims: 6,546
o Total non-U.S. exposed dollar loss: $1,638,490,375
All-Hazards. The disaster no major U.S. city is prepared for. Experts warn this type of catastrophe — a combined power outage with a heat wave — is a scenario that cities and states are unprepared for. “I don’t think it’s likely — I think it’s an absolute certainty,” said Brian Stone, a professor and director of the Urban Climate Lab at the Georgia Institute of Technology. “I think it’s an absolute certainty that we will have an extreme heat wave and an extended blackout in the United States.”
Quick Hits:
In this week's Security Sprint, Dave and Andy covered the following topics:
Warm Start:
Press Release! Gate 15 Partners with Cyware to Enhance Cybersecurity and Homeland Security Resilience. Gate 15's Resilience and Intelligence Portal (GRIP) now leverages the robust capabilities available in Cyware's Collaborate platform to provide the homeland security community with all-hazards technology-enhanced, human-driven analysis products.
Main Topics:
Physical Threats, Notable Dates:
· Pakistani National Charged for Plotting Terrorist Attack in New York City in Support of ISIS
· Man Plotted to Kill Jews in New York on Oct. 7 Anniversary, U.S. Says
· Man Arrested For Making Threats To Elected Officials
· U.S. charges Hamas leaders with terrorism, citing Oct. 7 attack
Terrorgram Arrests
· Feds say white supremacist leaders of "Terrorgram" group plotted assassinations, inspired attacks
Influence Ops
· Info Ops: ODNI - Election Security Update as of Early September. Foreign actors are increasing their election influence activities as we approach November.
· US seeks to reassure voters that presidential election will be safe.
· Russia focusing on US social media stars to covertly influence voters
· AP: Right-wing influencers were duped to work for covert Russian influence operation, US says
· Conservative Podcasters Respond to Russian Influence Allegations
· The Record: US indicts two RT employees for alleged Russian disinformation effort
· 2024's triple threats on election disinformation
· TikTok: Continuing to protect the integrity of TikTok through the US elections
· Activists Charged With Pushing Russian Propaganda Go on Trial in Florida
· AI-Fakes Detection Is Failing Voters in the Global South
· Activists Charged With Pushing Russian Propaganda Go on Trial in Florida
Quick Hits:
More Russia:
Georgia: Apalachee High School Shooting:
o 14-Year-Old School Shooter Kills Four and Wounds Nine
o At least nine people were injured. Here’s what else to know.
o What we know about the Georgia high school shooting
o Georgia High School Received Threat Warning Of Shooting Before Gunman Opened Fire: Report
o Father of Teen Suspect Charged in Georgia School Shooting
o Georgia school-shooting suspect struggled with mental health, aunt says
o ASIS: Apalachee High School Shooting: What We Know
o Georgia Gunman Colt Gray Was ‘Ridiculed’ and Called Gay by Bullies at School
o Mother of Georgia suspect is said to have called school before shooting, warning of ‘emergency’
Sextortion
o Sextortion Scams Now Include Photos of Your Home.
o Sextortion scam now use your "cheating" spouse’s name as a lure
o Nigerian Brothers Sentenced in Sextortion Scheme that Resulted in Death of Teen
o Nigerian brothers jailed in US for sextortion scam targeting teenagers
o Four Delaware Men Charged with International “Sextortion” and Money Laundering Scheme
In this week's Security Sprint, Dave and Andy covered the following topics:
National Insider Threat Awareness Month!
· Insider Threat! Employee arrested for locking Windows admins out of 254 servers in extortion plot
· Insider Threat: Pa. church member accused of stealing $225K from congregation
· GRIP: Insider Threat Awareness -Don't Let Errors Cost You, 28 August 2024
· Palo Alto: Deepfake report: https://unit42.paloaltonetworks.com/dynamics-of-deepfake-scams/
National Preparedness Month!
Election Security:
· Man Charged with Threatening Election Officials, State Judge, and Federal Law Enforcement Agents
Donald Trump Assassination Updates:
o Would-be Trump assassin saw ex-president as 'target of opportunity.'
o FBI releases photos of the gun used in Trump assassination attempt
· DOD Will Provide Homeland With Support During Presidential Campaigns
· US voters targeted in phishing campaign
· When Get-Out-The-Vote Efforts Look Like Phishing
· Intel officials say they anticipate more hacking attempts as US election nears
· Election Security Partners Host 7th Annual Tabletop the Vote Exercise for 2024
Quick Hits:
· European terror attacks alarm US intelligence, NYPD briefing shows
· Solingen Stabbing Ignites Fears of Resurgent Jihadism Targeting Germany
· CISA - Iran-based Cyber Actors Enabling Ransomware Attacks on US Organizations
· Halliburton cyberattack linked to RansomHub ransomware gang
o FBI: RansomHub ransomware breached 210 victims since February
o US agencies warn against ransomware group behind hundreds of attacks in recent months
· Chinese government hackers penetrate U.S. internet providers to spy
o Lumen: Taking The Crossroads: The Versa Director Zero-Day Exploitation
o Chinese government hackers targeted U.S. internet providers with zero-day exploit, researchers say
o China’s Volt Typhoon Hackers Caught Exploiting Zero-Day in Servers Used by ISPs, MSPs
· Cybercrime and sabotage cost German firms $300 bln in past year
· France formally charges Telegram founder, Pavel Durov, over organized crime on messaging app
· Kasada’s Releases 2024 State of Bot Mitigation Report
· CISA Launches New Portal to Improve Cyber Reporting
· Hate Group’s Anti-Muslim Rhetoric Reflects Anti-LGBTQ+ Conspiracy Theories
· Recorded Future: H1 2024 Check Fraud Report: Geographic Trends and Threat Actor Patterns
In this final episode of Venue Security, The IAVM Podcast Series, Andy Jabbour talks with Byron K. Johnson II, Director of Public Safety and Security, with the Raleigh Convention and Performing Arts Complex, which includes several venues in lovely Raleigh, North Carolina. Raleigh Convention & Performing Arts Complex: “The City is proud to own and manage several marquee venues in the area. Whether you want to see a concert, host a convention, or catch a ballet, we’ve got you covered:
In the discussion Byron and Andy address the concept of a venue, its diverse range of facilities, common and specific risks, and the evolving nature of the industry. They also delved into the aspects of risk management, the importance of understanding unique risks associated with different types of events and facilities, and the role of technology in venue management. In closing, they emphasized the value of diverse perspectives in risk assessment and decision-making, the significance of leadership, and the importance of a strong reputation in the community. Plus:
Venue Security, The IAVM Podcast Series has been a collaboration between Gate 15 and the International Association of Venue Managers’ (IAVM) Venue Safety and Security Committee (VSSC) as Andy Jabbour speaks with special guests from the IAVM community. This episode is our last in this limited run series.
In this week's Security Sprint, Dave and Andy covered the following topics:
Warm Start:
CISA: Shaping the legacy of partnership between government and private sector globally: JCDC
Main Topics:
International Security Incidents:
Forgotten radios and missed warnings: New details emerge about communication failures before Trump rally shooting. The day before the attempted assassination of Donald Trump, a tactical team of local police officers set aside radios for their Secret Service partners so the two agencies could communicate during the former president’s July 13 campaign rally. But those radios were never picked up.
Invest in Resilience! Cyber Resilience Overestimation Leads to Business Continuity Issues, Ransom Payments
Quick Hits:
From cybercrime to terrorism, FBI director says America faces many elevated threats 'all at once'
VFC: Bomb Threats at Jewish Institutions
Bomb threats reported at more than 100 Canadian Jewish institutions
Arizona man in custody amid investigation into alleged threats to kill former President Donald Trump
Iran Tries To 'Storm' U.S. Election With Russian-Style Disinformation Campaign
Meta: Taking Action Against Malicious Accounts in Iran
How Russian Trolls Are Trying to Go Viral on X
Trump attorney was targeted by hackers, sources say
‘Several opportunities’ to prevent Maine mass shooting were missed, commission finds
International report confirms record-high global temperatures, greenhouse gases in 2023
In this week's Security Sprint, Dave and Andy covered the following topics:
Warm Start:
Three Main Topics.
Extremism and Physical Security:
Sabotage:
Cyber Resilience:
Quick Hits:
In this episode of The Gate 15 Interview, Andy Jabbour talks with Adam Vincent. Adam Vincent is the Founder & CEO at Bricklayer AI. Bricklayer AI is the first generative AI solution that brings autonomous AI agents and human experts into a single collaborative and effective security team. Bricklayer AI’s security-trained, generative AI agents execute critical security roles, operations, and procedures, empowering organizations to enhance the scale, speed, and sophistication of their security operations, investigate incidents faster and more thoroughly, enrich and analyze threat intelligence more completely, and enforce compliance standards continuously. Additionally, Adam has a long history of delivering leadership to early-stage companies to drive the development and launch of innovative products, create strategic GTM plans to capture explosive growth, enable sales and marketing, accelerate revenues, and increase profitability. Among his notable achievements, Adam:
Bricklayer AI is the first AI cybersecurity solution that enables autonomous AI specialists to work alongside human experts, to run a smarter, faster, and more effective security operations team. With Bricklayer AI, multiple independent AIs collaborate and use AI tools to accomplish complex cybersecurity procedures, all controlled using natural language. AI Security Analysts, AI Threat Intelligence Analysts, and AI Incident Responders add speed, augment and accelerate security teams’ capabilities in order to stay ahead of today’s most sophisticated AI-enabled threats. Learn more at bricklayer.ai.
In the discussion Adam and Andy discuss:
Selected links:
In this week's Security Sprint, Dave and Andy covered to following topics:
Taylor Swift Terrorism Threat:
· Two held in Vienna over Taylor Swift concert threat
· Officials say suspects in foiled plot at Taylor Swift shows hoped to kill as many people as possible
· Taylor Swift concert terror suspect, 17, began working at venue days before foiled plot, say police
· Alleged Taylor Swift terror plot fits a worrying trend as ISIS targets teens online
· Suspect in Taylor Swift Vienna concert plot confessed to planning suicide attack, officials say
· After Vienna threat: Music venues as terrorist targets
· Iraqi teen held in Vienna after Taylor Swift attack plot foiled
· Officials say suspects in foiled plot at Taylor Swift shows hoped to kill as many people as possible
Hurricanes & Severe Weather.
· CSU's 2024 Atlantic seasonal hurricane forecast was released on 4 April and updated on 6 August
· NOAA: Highly active hurricane season likely to continue in the Atlantic
· Debby finally moves out of the US, some flooding risk and power outages remain
· NOAA: Nation hit with record heat, wildfires and Hurricane Beryl in July
Election Security & Broader Considerations
· Microsoft: Iran Targeting 2024 US Election.
· Iran uses fake news sites to interfere in U.S. election, Microsoft says
· We received internal Trump documents from ‘Robert.’ Then the campaign confirmed it was hacked
· Trump campaign says it is victim of foreign hack after leak of Vance report
· The Hacking of Presidential Campaigns Begins, With the Usual Fog of Motives
· Winchester Man Arrested for Making Threats Against Vice President
· Virginia man charged with threatening to kill Vice President Kamala Harris
Quick Hits:
· CrowdStrike: Channel File 291 Incident: Root Cause Analysis is Available. Read the findings, mitigations and technical details of the Channel File 291 incident.
· Ransomware & Data Breaches:
o Ransomware in 2024: More Attacks, More Leaks, and Increased Sophistication.
o Rapid7: Rapid7’s Ransomware Radar Report Shows Threat Actors are Evolving …Fast.
· Royal Ransomware Actors Rebrand as “BlackSuit,” FBI and CISA Release Update to Advisory
· Research Report: Internet-Connected Industrial Control Systems (Part One)
· White House working on cyber insurance policy proposal for ‘catastrophic’ incidents
· Hackers leak 2.7 billion data records with Social Security numbers
· On the Adoption of the UN Convention Against Cybercrime
· DOJ: Assault of Congregants Outside a Washington D.C. Synagogue Charged as a Federal Hate Crime
· U.S.: SEC ends probe into MOVEit attacks impacting 95 million people
· Critical Infrastructure: Rewards for Justice: CyberAv3ngers.
· White House cyber czar touts regulatory harmonization bill advancing through Congress
In the latest episode of Nerd Out, Dave and Alec looked at some recent security concerns related to venues including the cancellation of Taylor Swift concerts in Austria, and sabotage surround the Olympics. Then they moved to the 2/3 of the year awards - congratulations to our winners!
Then the nerds go all in on the season and the finale's of the Acolyte and House of the Dragon.
Some of the references from the above topics include:
T Swift Plot
French Infrastructure Attacks
In this week's Security Sprint, Dave covered the following topics:
Warm Start. Sheriff's Office hosts summit focusing on safety at houses of worship
Main Topics.
In this episode of Venue Security, The IAVM Podcast Series, Andy Jabbour talks with Ross Girouard, Assistant General Manager, Credit Union of Texas Event Center, an over 6,000 fixed-seat multi-purpose indoor arena located in Allen, Texas, north of Dallas, and Michael McDermott, City of Allen, Texas.
‘If you have a busy IT guy during the event, you’ve got a problem…’-Michael‘Cybersecurity has to be part of your everyday team’-RossIn the discussion we address:
In this week's Security Sprint, Dave and Andy covered the following topics.
North Korea Cyber Threats to U.S. Businesses:
CISA: Resources for Onboarding and Employment Screening Fact Sheet. Resource Materials: Resources for Onboarding and Employment Screening Fact Sheet
Physical Incidents:
Quick Hits
Olympics:
CrowdStrike: Remediation And Guidance Hub: Falcon Content Update For Windows Hosts,
Donald Trump Assassination Attempt: Takeaways from FBI testimony: Trump shooter searched details of JFK assassination and flew drone near rally site
Other items that may be of interest:
In this episode of The Gate 15 Interview, Andy Jabbour talks with Reason Magazine’s Elizabeth Nolan Brown and Jessica Dickinson Goodman in part two of our two-part series on encryption. Jessica and Gate 15 are members of the Global Encryption Coalition.
Elizabeth Nolan Brown. Senior Editor, Reason; President, Feminists for Liberty. Elizabeth Nolan Brown is a senior editor at Reason and the author of Reason’s biweekly Sex & Tech newsletter, which covers issues surrounding sex, technology, bodily autonomy, law, and online culture. She is also co-founder of the libertarian feminist group Feminists for Liberty, and a professional affiliate of the journalism program at the University of Cincinnati. Brown has covered a broad range of political and cultural topics since starting at Reason in 2014, with special emphasis on the politics, policy, and legal issues surrounding sex, speech, tech, justice, reproductive freedom, and women’s rights. She lives in Cincinnati, Ohio, with her husband, sons, and two cats. Andy is a big fan of her cat and family pictures. Read here complete bio at Reason.
Jessica Dickinson Goodman. Jessica Dickinson Goodman is the current chair of the Chapter Seeding Committee of the San Francisco Bay Area ISOC Chapter and past-President, serving in that role for three years. As Board President, encryption protection and education played a major role in her agenda. She ran a monthly tactical tech support webinar series for community members in how to use encryption tools to protect personal privacy in a post-Dobbs world, wrote and published Encryption for Babies, is featured on the front page of the Global Encryption Coalition’s YouTube channel talking about encryption.
In the discussion Liz, Jessica, and Andy discuss:
Selected Links:
In this week's Security Sprint, Dave and Andy covered the following topics: DHS Announces $18.2 Million In First-Ever Tribal Cybersecurity Grant Program Awards. “For far too long, Tribal Nations have faced digital and cybersecurity threats without the resources necessary to build resilience,” said Secretary of Homeland Security Alejandro N. Mayorkas. Main Topics: Beryl!! & Hurricane Preparedness. Port of Corpus Christi announcement. https://portofcc.com/hurricane-beryl-impact-to-the-port-fully-transitioned-to-post-storm-recovery/ Airline impacts. https://www.cbsnews.com/news/hurricane-beryl-houston-texas-travel-flights-airlines/ Ransomware Ransomware Attack Demands Reach a Staggering $5.2m in 2024 Risky Biz News: Ransomware attacks increase hospital mortality rates Risky Biz News: A ransomware attack is putting lives at risk across South Africa Halcyon Whitepaper: What CFOs Should Know about Ransomware FBI Helps Public to Recognize Signs of Concerning Behavior https://www.fbi.gov/news/stories/behavioral-analysis-unit-asks-public-to-talk-to-someone-you-trust-if-you-notice-concerning-behaviors Microsoft: Combatting AI Deepfakes: Our Participation in the 2024 Political Conventions CDC Reports Fourth Human Case of H5 Bird Flu Tied to Dairy Cow Outbreak Quick Hits: Another far right group marches through downtown Nashville Pa. Capitol evacuated over emailed bomb threat 'Local Residents' Terrorizing City Council Meetings Were Actually Overseas, Feds Allege Europol: Taking action against antisemitism – close to 2 000 pieces of content flagged for removal Fifty violent attacks shock France ahead of crunch vote A Hacker Stole OpenAI Secrets, Raising Fears That China Could, Too Europol coordinates global action against criminal abuse of Cobalt Strike CISA: Guide to Operational Security for Election Officials
In this episode of Venue Security, The IAVM Podcast Series, Andy Jabbour talks with Brendan Farley, Vice President of Operations & General Manager, San Diego Theaters.In the discussion we address:
“Safety and security is definitely a team sport.” – Brendan Farley, during our podcastAs discussed in the pod, for additional discussion on this topic, see:
Venue Security, The IAVM Podcast Series is our newest podcast as Gate 15’s founder and Managing Director, Andy Jabbour, hosts short interviews with venue safety and security experts from the International Association of Venue Managers’ (IAVM) Venue Safety and Security Committee (VSSC) and other special guests from the IAVM community.
In this episode of Venue Security, The IAVM Podcast Series, Andy Jabbour talks with Eric Neill, Director of Theatre Operations at the Boch Center in Boston. Eric as worked in Performing Arts Venues for the past 25 years in Boston and NYC. He has over 25 years of security management experience specializing in event security and executive protection. Eric is the holder of many other security and life safety certificates including Executive Protection from LaSorsa & Associates and Emergency Trauma Response and is a certified instructor of the ALIVE Active Shooter. Eric holds memberships in American Society for Industrial Security (ASIS), National Fire Protection Association (NFPA) and International Association of Venuw Managers (IAVM) where is a graduate of the Academy of Venue Safety and Security and is currently the Chairman of Performing Arts Security & Safety Committee. Mr. Neill is honored to have received the National Defense Service Medal while serving in the United States Coast Guard and the Hero’s Among Us Award in 2012 where he was honored at the TD BankGarden and Boston’s City Hall.
In the discussion we address:
• Eric’s background.
• Security Protocols.
• Screening and search procedures.
• Managing VIP areas.
• Handling disruptive attendees.
• More!
In the latest episode of Nerd Out, Alec and Dave talked through a series of topics that include examining the recent arrest of an individual who was planning a hostile event, as well as others that were disrupted speaking to the importance reporting suspicious behaviors. Then they talked about nation-states and their ability to influence through a variety of actions and leading up to the election. They wrapped up the security portion of the pod on severe weather and the importance of preparedness. Finally, the ran through the upcoming slate of Marvel movies and television shows to determine if they are in or out.
Some of the materials discussed in the pod include:
Mass shootings
Foreign Influence
Hurricanes
In the latest episode of Nerd Out, Dave welcomes in Alec Davison as his partner in crime for the podcast. After they get through the excitement of the latest Taylor Swift album, they talked through the latest activity in the Middle East and what it could mean domestically. Then they looked at the latest news related to the U.S. election including the recent incident outside of the Trump trial and potential concerns that may play out over the course of the year especially related to mis/dis/mal-information. They wrap up the pod with some real nerd discussions on Star Wars and what the new series has to offer! Alec Davison is the Lead Analyst at the Water Information Sharing and Analysis Center (WaterISAC). In addition, he works as a Risk Analyst at Gate 15. He holds an M.A. in Security Policy Studies from George Washington University. Some of the resources discussed in the pod include: https://www.cisa.gov/resources-tools/resources/personal-security-considerations-action-guide https://www.cisa.gov/resources-tools/resources/preventing-workplace-violence-security-awareness-considerations-infographic https://www.dni.gov/files/NCTC/documents/jcat/firstresponderstoolbox/89s_-_Violent[…]il_Unrest_and_Public_Assemblies_in_the_United_States-survey.pdf Mobilization/SARs https://www.dni.gov/files/NCTC/documents/news_documents/Mobilization_Indicators_Booklet_2021.pdf https://www.dhs.gov/nationwide-sar-initiative-nsi Info sharing communities https://www.dhs.gov/fusion-centers https://www.nationalisacs.org/
In this episode of Venue Security, The IAVM Podcast Series, Andy Jabbour talks with Christopher Post, Assistant General Manager, Amarillo Civic Center Complex. Christopher graduated from West Texas A&M University with a Bachelor of Business Administration. He has been in venue management for 18 years and prior to that, was a professional musician for a little over 20 years (yes, he started very young!). As Assistant General Manager, his duties have included serving as the Emergency Coordinator and First-Aid Response Trainer for the Amarillo Civic Center since 2009. He is a graduate of IAVM’s AVSS and VMS. Read more at his complete LinkedIn profile.
“It has to be muscle memory, it has to be automatic.”In the discussion we address:
In the latest episode of Nerd Out, Dave is solo and integrating his love for Ted Lasso into the security world. Challenging everyone to be curious, Dave evaluates the famous dart game in Ted Lasso (season 1) and calls out three points for individuals and organizations to be focused on as we evaluate threats. Whether it be the terrorist or extremist threat, or MDM, Dave reminds everyone to be mindful in their security preparedness planning.
In this episode of Venue Security, The IAVM Podcast Series, Andy Jabbour talks with Stella Salyer, Assistant General Manager, Sales & Services, Virginia Beach Convention Center. Stella is a Nationally Registered Advanced Emergency Technician and volunteers every weekend in Virginia Beach’s 911 system. She holds certifications in Mass Casualty and Tactical Emergency Critical Care, Stop the Bleed instructor, and is a Proctor for Virginia Beach EMS’s Advanced EMT Academy. Read more at her complete LinkedIn profile. Contact Stella by email: [email protected].In the discussion we address:
Venue Security, The IAVM Podcast Series is our newest podcast as Gate 15’s founder and Managing Director, Andy Jabbour, hosts short interviews with venue safety and security experts from the International Association of Venue Managers’ (IAVM) Venue Safety and Security Committee (VSSC) and other special guests from the IAVM community.
In this special podcast, Andy welcomes in Dave and key members of the Faith-Based Information Sharing and Analysis Organization (FB-ISAO) to talk about the Lakewood church shooting. They looked at how the event unfolded, security processes, and lessons learned. Guests include: Mayya Saab, the Executive Director of FB-ISAO Ed Heyman, Co-Chair of the FB-ISAO ORG Phil Froehlich, Co-Chair of the FB-ISAO ORG
In this week's Security Sprint, Dave and Andy discussed the following topics: Warm Start: Announcement! WaterISAC is excited to announce that this Spring, it will be hosting H2OSecCon as a one-day virtual event on Thursday, May 23 from 11 AM - 5 PM ET! T National Rural Water Association and WaterISAC Collaborate to Benefit Small Water Utilities Nationwide AMWA reiterates cybersecurity views to Homeland Security Subcommittee Lakewood Church Shooting Shooting at Joel Osteen's Lakewood Church in Houston: Female shooter killed, 5-year-old child shot Joel Osteen statement in response to this incident, post to Threads Woman Opens Fire at Joel Osteen’s Texas Megachurch During Live TV Broadcast Additional physical security items of note: Philadelphia Man Charged with Making Antisemitic and Islamophobic Threats Islamic State, Al-Qaeda Call for Violence Against Jewish Communities Following October 7 Attack Tennessee man who was working with militias planned to act as a sniper and attack Southern border, feds say. U.S. Strike in Baghdad Kills Iranian-Backed Militia Commander Iraq Criticizes US Strikes After Baghdad Attack Killed Iran-Backed Militant Group Commander CISA Releases Violence Prevention through De-escalation Video. AI. FCC Confirms that TCPA Applies to AI Technologies that Generate Human Voices AI-Generated Voices in Robocalls Are Now Illegal How a Biden AI robocall in New Hampshire allegedly links back to a Texas strip mall Taylor Swift deepfakes on X falsely depict her supporting Trump AI Deployed Nukes 'to Have Peace in the World' in Tense War Simulation NYPD and WhatsApp. https://nypost.com/2024/02/05/business/nypd-tests-old-school-tactics-in-the-bronx-to-combat-shoplifting/ Info Ops: Russia Is Boosting Calls for 'Civil War' Over Texas Border Crisis. Chinese Websites Posing as Local News Outlets Target Global Audiences with Pro-Beijing Content CISA Launches #Protect2024 Resources Webpage for State and Local Election Officials Quick Hits: Severe Weather: Historic storm sends debris through LA’s Hollywood Hills and leaves 1.1 million without power 3 dead as storm pummels California, causing flooding and dozens of mudslides in L.A. area More than 120 people are dead and entire neighborhoods have been reduced to ashes in record-breaking Chile wildfires The growing inadequacy of an open-ended Saffir–Simpson hurricane wind scale in a warming world Hurricanes are getting so intense, scientists propose a Category 6 More on Scams & Fraud: Think you know what the top scam of 2023 was? Take a guess As Nationwide Fraud Losses Top $10 Billion in 2023, FTC Steps Up Efforts to Protect the Public IRS warns tax professionals to be aware of EFIN scam email; special webinars offered next week Ransom where? Everywhere. Chainalysis: Ransomware Payments Exceed $1 Billion in 2023, Hitting Record High After 2022 Decline Ransomware Payments Hit a Record $1.1 Billion in 2023 GRIT Ransomware Annual Report 2023 (Q1-Q4) The Record: Ransomware tracker: The latest figures [February 2024] Malwarebytes 2024 State of Malware: Known ransomware attacks up 68% in 2023 Nation States Subcommittee Chairman Garbarino Statement On PRC Persistent Access To U.S. Critical Infrastructure. CISA and Partners Release Advisory on PRC-sponsored Volt Typhoon Activity and Supplemental Living Off the Land Guidance NSA: Combatting Cyber Threat Actors Perpetrating Living Off the Land Intrusions. NSA and Partners Spotlight People’s Republic of China Targeting of U.S. Critical Infrastructure More Cyber News. Verizon insider data breach hits over 63,000 employees Ivanti: CVE-2024-22024 (XXE) for Ivanti Connect Secure and Ivanti Policy Secure Researchers say attackers are mass-exploiting new Ivanti VPN flaw UK NCSC: Vulnerability management Canadian Centre for Cyber Security How updates secure your device (ITSAP.10.096)
In this episode of Venue Security, The IAVM Podcast Series, Andy Jabbour talks with Gil Fried, Professor and Assistant Dean of the College of Business at the University of West Florida and a member of the International Association of Venue Managers (IAVM) Venue Safety and Security Committee. In the discussion we address:
Venue Security, The IAVM Podcast Series is our newest podcast as Gate 15’s founder and Managing Director, Andy Jabbour, hosts short interviews with venue safety and security experts from the International Association of Venue Managers’ (IAVM) Venue Safety and Security Committee (VSSC) and other special guests from the IAVM community.
In this inaugural episode of Venue Security, The IAVM Podcast Series, Andy Jabbour talks with Mark Herrera, Director of Education for the International Association of Venue Managers (IAVM). In the discussion we address:
Venue Security, The IAVM Podcast Series is our newest podcast as Gate 15’s founder and Managing Director, Andy Jabbour, hosts short interviews with venue safety and security experts from the International Association of Venue Managers’ (IAVM) Venue Safety and Security Committee (VSSC) and other special guests from the IAVM community.
In this episode of The Gate 15 Interview, Andy Jabbour welcomes Tom Stockmeyer, Cyware’s Director, Enterprise East, ISAC's and Federal. Cyber security leader with experience in helping threat sharing communities such as ISACs and ISAOs and their Member companies improve the fidelity of their intel and accelerate threat intel sharing amongst Members. Tom served in the Marine Corps from 1979 to 1983. He has an MBA from the Michael Coles School of Business, Kennesaw University. Tom has held several executive positions, has served on numerous technology Boards.
In the discussion we address:
A few references mentioned in or relevant to our discussion include:
In this week's Security Sprint, Dave and Andy talk about the following topics.
Terrorism & Extremism
Severe Weather
Geopolitics & Cascading Effects
Quick Hits
In this week's Security Sprint, Dave and Andy talked about the following topics:
Maine Shootings
FB-ISAO: October 2023 Threat Level Statement Update – Threat Levels Raised to ELEVATED.
Scams
Quick Hits
In this episode of The Gate 15 Interview, Andy Jabbour talks with Robert (Bob) Kolasky, “Advancing National Security Risk Management through Technology, Innovation and Governance,” who is presently serving as Senior Vice President for Critical Infrastructure at Exiger, where he is focusing on developing cutting-edge risk management solutions for critical infrastructure companies and supporting government agencies. Leads market strategy for addressing third party and supply chain risk in critical infrastructure and delivering analysis to support enhanced business and government operations. He also serves in a number of other roles including:
Previously, Bob served as Cybersecurity and Infrastructure Security Agency’s (CISA) Assistant Director, leading the National Risk Management Center (NRMC) and in a number of other critical homeland security roles and responsibilities.
In the discussion:
A few references mentioned in or relevant to our discussion include:
In this episode of The Gate 15 Interview, Andy Jabbour visits with Dr. G. Keith Still, Crowd Dynamic Expert, Visiting Professor of Crowd Science at University of Suffolk and Director, Crowd Risk Analysis Ltd. G. Keith Still BSc PhD FIMA FICPEM SFIIRSM FIPM FHEA MAE has a PhD in “Crowd Dynamics”. He combines risk analysis with crowd behavior in both crowd models and crowd simulations. He is a visiting Professor at University of Suffolk and teaches at Breda University of Applied Science (Holland). Keith has over 30 years of consulting experience across a range of international crowd safety and risk analysis environments and has advised on crowd behavior, crowd risks and crowd safety considerations for events of 500 people to 3,000,000 people. He has published two books on the subject of Crowd Safety and Crowd Risk Analysis “Introduction to Crowd Science” and “Applied Crowd Science.”His project/consulting work includes planning for the Royal Wedding (UK, 2011), Hajj projects, (Saudi Arabia, Jamarat 2000 - 2005, Makkah 2000 - 2013), Olympic Events (Sydney 2000, London 2014), New Year Events (London, Sydney, Dubai), Canada Day (Ottawa).
In the discussion we address:
Some links from our discussion include:
In this episode of The Gate 15 Interview, Andy Jabbour visits with Chris Anderson, Principal Advisor, National Security & Emergency Preparedness, Lumen Technologies. Chris Anderson is an incident management and infrastructure protection expert with three decades of government, military, and private sector experience. He is currently the Principal Advisor for National Security & Emergency Preparedness at Lumen. In addition to his role at Lumen, he is the 2023 Industry Chair of the Communications Sector Information Sharing and Analysis Center.Chris previously held a variety of emergency management and national security positions at the Federal Communications Commission and US Department of Homeland Security. He served as the FCC’s Chief of Operations and Emergency Management, leading the Commission’s incident management activities, operations centers, national security coordination, and Continuity of Operations programs. Prior to joining the Commission, Chris worked in critical infrastructure protection at the Department of Homeland Security, serving in a variety of leadership positions in the Office of Infrastructure Protection, including serving as Director of the National Infrastructure Coordinating Center. Chris began his career with a decade on active duty in the U.S. Navy as a helicopter pilot and retired from the Navy Reserve in 2016.Chris is a 2010 graduate of the National War College with a master’s degree in National Security Strategy; he holds a second master’s degree in Management Information Systems from Bowie State University and received his undergraduate degree from the University of Virginia.
After a month off, the Nerdies get back together to look at 2023. Dave welcomes back Bridget Johnson and Joe Levy to catch up on what has happened in 2023, and talk about what is surprising, and not so surprising in 2023, as well as look ahead for the rest of the year before getting into some fun summer questions. The topics included a look at the various hostile events, to include inspiration from previous threat actors, climate change and challenges addressing it, protests and demonstrations, as well as a reminder not to forget about international terror threats, how economic conditions can affect the workplace and other security challenges.
In the latest episode of the Risk Roundtable, Dave, Jen and Andy return to talk on very real and maybe somewhat less real threats across the all-hazards environment. Jen kicks things off sharing her thoughts on the recent FBI Advisory on jUIcE JaCKiNg!! Dave continues the focus on the FBI, sharing his heartfelt thoughts relating to the new Active Shooter report. Quick hits touch on Hurricane Preparedness, Patching (always patching!) and a new COVID report. The team then talks a little US-Russian history, and some musical history, as they dive into love it, hate it, or don’t care.
In the latest Weekly Security Sprint, Dave and Andy discussed the following topics.
DHS!
See Something, Say Something – Possible Faith-Based Attack Averted & FB-ISAO Turns Five!
FB-ISAO: Five Years Strong. “Happy Anniversary to the Faith-Based Information Sharing and Analysis Organization. 18 April 2023, marks five years of serving the community of faith with information, analysis, and capabilities to help reduce risk while enhancing preparedness, security, and resilience across all-faiths and all-hazards. Our members include Houses of Worship, Charities, Faith-Based Schools, and their affiliated organizations. We are five years strong!”
4-20! Cannabis ISAO Shares Cybersecurity Best Practices for the Cannabis Industry
Quick Hits:
Ransomware – March Was a Record Setting Month & Dragos Ransomware Report
Blended Threats – Critical Infrastructure Space Asset Disruption Impacts Farming Operations
New FBI Elder Fraud Report
3CX – Attack x Within x Attack
SBOM, SBOM, You’re my SBOM!
Chinese Police Outposts
In this week's Security Sprint, Dave and Andy talked about the following topics:
Insiders, hostile events, and data loss
Ransomware
Space as Critical Infrastructure:
Others:
MDM:
In the latest episode of the Weekly Security Sprint, Dave and Andy covered the following topics:
Nashville School Shooting:
Gate 15's Blue Jeans Worksho
Political Violence
Severe Weather:
Cybersecurity Regulations:
Ransomware:
Others:
In this week's Security Sprint, Dave and Andy talked about the following topics:
National Cybersecurity Strategy:
Water Cybersecurity:
Homeland Security:
Cybersecurity & Ransomware:
Other: Gizmodo: Yikes, the U.S. Is Now Using Facial Recognition Rigged Drones for Special Ops, 27 Feb
In the latest episode of Nerd Out, Dave is joined by Bridget Johnson and Joe Levy as they talked about some of the hostile events to date in 2023 and looked ahead to the coming faith-based holidays and celebrations in the coming months. Bridget talked about the California shootings and the power of copy cats, while Joe focused attention on the various ways that organizations can deploy security protocols to reduce risk. The nerds then took a look ahead at the upcoming religious holidays and what that might mean for accelerationists and other hate-based groups. Joe then wrapped up talking about the upcoming AVSS event that is coming up in Pittsburg. Registration Information can be found here: https://iavm.org/events/avss/
Joe Levy is the chairman of the International Associate of Venue Managers (IAVM) Venue Safety and Security Committee. In addition, Joe is the Chief Operating Officer at the Usdan Center for the Creative & Performing Arts. IAVM website https://www.iavm.org/ Venue Safety and Security committee contact information: [email protected]; LinkedIn Profile: https://www.linkedin.com/in/joelevy1/
Bridget Johnson is the Managing Editor for Homeland Security Today. In addition her contributions on Homeland Security Today (hstoday.us), they are also running a series of webinars (Webinar signups, https://www.eventbrite.com/e/le-only-anti-government-extremists-who-they-are-how-to-combat-them-tickets-144507635227?aff=ebdsoporgprofile). Twitter: @BridgetCJ
In the latest episode of the Risk Roundtable, Andy does double duty, first welcoming Jen to get the latest on the ransomware threats, before bringing Dave in to talk about weather and natural disasters. Jen kicked things off talking about all things ransomware to include preparedness items, the recent Hive takedown, the importance of reporting, and ways to protect yourself. Dave then joined Andy to talk about the third-wheel in the all-hazards preparedness model - weather and natural disasters, especially in light of the recent earthquake in Turkey. The roundtable took a split approach to the end of pod questions talking about marathon's, some show dilemmas and the arc of Paul Rudd!
Ransomware and Cyber News:
In this week's Security Sprint, Dave and Andy talked about the following topics:
Ransomware:
DDoS:
Faith-Based Security:
Baking in Cybersecurity:
Others:
On this week's Security Sprint, Dave and Andy provided insights and additional thoughts into the following incidents or security news items.
In the latest episode of the Risk Roundtable, Dave, Jen, and Andy wrap up their third year together and talk through recent events and talk about ways to fight off those seeking to ruin the holiday spirit. Dave and Andy kicked things off talking about the incident at the North Carolina power substation and what it could mean given recent events (Walmart shooting, Colorado Springs) and how to look at it from a preparedness standpoint. Jen dropped down the chimney and spread holiday cheer with a double shot of cybersecurity tips talking about holiday scams (in only the way Jen can do), and passwords (don't be like Dave). Then Dave then took the group back through some of the 2022 predictions to see if they were right, needed more time, or were off base before Andy put a bow on the podcast with a holiday themed question.
Some of the topics discussed on the pod:
In this episode of The Gate 15 Interview, Andy Jabbour visits with James A. DeMeo and Herb Ubbens on their work with Crowdguard, facility security and security best practices and more.
James A. DeMeo, M.S. is a best-selling author, professional speaker, and event security expert. Mr. DeMeo brings vast experience to the public/private, non-profit, sports/entertainment, corporate, higher education & vendor management/contract analyst ecosystems. Mr. DeMeo serves as Vice President for Crowdguard US, a crowd safety solutions provider & CEO of Unified Sports and Entertainment Security Consulting, LLC., (USESC) based in Raleigh, NC. He was recognized by Security Magazine as The Most Influential People in Security 2017. Mr. DeMeo is also the author of the best-selling book, What’s Your Plan? A Step-By-Step Guide To Keep Your Family Safe During Emergency Situations. Mr. DeMeo holds professional memberships with both ASIS International and National Center for Spectator Sports Safety and Security-NCS4. He serves as a remote learning Adjunct Instructor with the following Universities: Tulane University’s School of Professional Advancement-SOPA, Jacksonville State University, Dept. of Kinesiology, Mercer University-Stetson School of Business where he teaches both graduate/undergraduate students about Event Security, Facilities and Risk Assessment. Mr. DeMeo is currently enrolled in an Online Higher Education Graduate Certificate Program at Appalachian State University-Cratis D. Williams School of Graduate Studies.
Herb Ubbens. Guiding organizations to increase their resiliency and emergency preparedness, reduce risk and provide safety and value to their clients and assets. Board Certified in Security Management (CPP) and Physical Security (PSP). SAFETY Act DHS Assessor in BPATS (Best Practices for Anti-Terrorism Security). OSHA general industry and construction trainer, safety expert and Project Manager.
In the discussion we address:
A few references mentioned in or relevant to our discussion include:
It's never a good thing when Jen takes time and leaves Andy and Dave to their own devices. With Jen away, Andy tried to cover down for her and gave a shout out to all the cyber work being down by great security practitioners. Then the boys dug into hostile events and some of the challenges that individuals and organizations can face, even when they do the right thing. At the same time, there are also inherent responsibilities that we all have in identifying behaviors or contributing to a threat actor's pathway to violence by inaction (Michigan school shooting). Dave and Andy then talked about the upcoming election and all the work that is going to make safe and secure elections. However, there are also some potential risks that could occur in the aftermath. Finally, Dave and Andy have some fun talking about their top 5 (or 50) movies that they just can't turn off when they happen to see them on.
Some of the areas covered on the pod include:
In the latest episode of Nerd Out, Dave went without the panel and talked about two topics - Election preparedness and the impacts of a recent attack, specifically analyzing the manfesto from the threat actor in the recent Bratislava attack. Tackling the upcoming U.S. midterm elections, Dave talks through some of the key considerations for individuals and organizations and about the various risks not just leading up to the election, but after as well. Then Dave transitioned to talking about the recent attack against a LGBTQ business in Bratislava and the information that was gleamed from the manifesto. Particularly interesting was the inspiration that was gained from the Buffalo attacker in May. Referencing work by Nerd Out alumni Bridget Johnson, Dave talked through the importance of this analysis and then how it could be used by another threat actor in the future. Dave then wrapped up the pod (technical difficulties aside) with some mailbag questions related to weather preparedness and gaining leadership buy-in.
Referenced in the pod: https://www.hstoday.us/featured/slovak-who-attacked-gay-bar-credits-buffalo-shooter-with-giving-him-final-nudge/
TCE talks Cybersecurity Awareness Month 2022 and Seeing Yourself in Cyber with Chris Foulon of the Breaking into Cybersecurity podcast.
Resources and Mentions (it’s a long list, but we love to share resources and other’s great work)
Not mentioned in this podcast, but a couple of relevant (CS)²AI podcasts hosted by @Derek_Harp that I came across after – I hope they don’t mind the mentions!
On the latest episode of the Risk Roundtable, Andy leads Dave and Jen through a discussion of the various awareness campaigns and how these efforts do a great job of providing resources and materials for all organizations, big and small. Focusing first on Cybersecurity Awareness Month that is ongoing in the month of October, Jen talked through the messaging, the themes (See Yourself in Cyber) and the importance of each of us doing our part. Later in the podcast, Dave shared his thoughts on National Insider Threat Awareness Month that concluded in September and the theme of Critical Thinking for Digital Space and how everyone can do their part. The team also talked about security preparedness for the upcoming holidays. Andy capitalized on the discussion to talk about security awareness and mindfulness to appreciate, regardless of who you are and what your beliefs are. To cap off the episode, Andy took the roundtable through his three questions to include the always spicy debates on pumpkin pie and pumpkin flavored drinks.
Microsoft Exchange links:
Additional links include:
In the latest episode of Nerd Out, Dave, Bridget, and Joe are together again and catch up on all the summer happenings to include an update on Bridget's ever-exciting news. The Nerd Out crew then turns to another list and talk about the significance and importance of the Homeland Security Today Hottest 50 list. Bridget gives some of the background on the list and some of the criteria that brought the list together while Dave and Joe were left to wonder if they might be on the list next year. Next, the gang talked about venue security and how the big summer season went relatively smoothly and what that could mean for the fall season and the upcoming significant events and holidays.
Joe Levy is the chairman of the International Associate of Venue Managers (IAVM) Venue Safety and Security Committee. In addition, Joe is the Chief Operating Officer at the Usdan Center for the Creative & Performing Arts. IAVM website https://www.iavm.org/ Venue Safety and Security committee contact information: [email protected]; LinkedIn Profile: https://www.linkedin.com/in/joelevy1/
Bridget Johnson is the Managing Editor for Homeland Security Today. In addition her contributions on Homeland Security Today (hstoday.us), they are also running a series of webinars (Webinar signups, https://www.eventbrite.com/e/le-only-anti-government-extremists-who-they-are-how-to-combat-them-tickets-144507635227?aff=ebdsoporgprofile). Twitter: @BridgetCJ
TCE is back with another travel-related PSA. In episode 21, it’s another monologue and travel-related public service announcement – this time on the risk of automatic out-of-office notifications.
In the latest of Nerd Out, Bridget and Dave talk about all things extremism with the most recent publication of "The Hard Reset" as well as the latest accelerationist document "Make it Count". Specifically they discussed:
Then Dave and Bridget talked through the Uvalde school shooting and the recent lessons learned report from the Texas House of Representatives and how organizations can use the report to review their own security as well as avoid some of the issues identified. Bridget Johnson is the Managing Editor for Homeland Security Today. In addition her contributions on Homeland Security Today (hstoday.us), they are also running a series of webinars (Webinar signups, https://www.eventbrite.com/e/le-only-anti-government-extremists-who-they-are-how-to-combat-them-tickets-144507635227?aff=ebdsoporgprofile). Twitter: @BridgetCJ
After a drawn out thank you for the success of episode 19 (and 18), The Cybersecurity Evangelist is back to chatting about the human side of cyber in this summer PSA on travel-related scams.
Resources mentioned in this episode:
It started off with sweaty shirts and Jen's big announcement and ended with Dave wondering about green tea. But in-between the latest episode of the risk roundtable saw Andy, Jen and Dave talk about familiar topics - namely persistent threats. Unfortunately for all the times we have talked about them, these threats hang around and continue to strike at individuals and organizations. Whether they are cyber or physical related, threat actor continue to go to the proverbial well again and again because they work. The gang talked about the latest cyber threats and recounted the latest string of hostile events ranging from Buffalo, to Texas, to California, and all the others in-between. Equally important to this discussion was the release of the latest National Terrorism Advisory System (NTAS) bulletin that addressed the latest threats and extremist risks (https://www.dhs.gov/ntas/advisory/national-terrorism-advisory-system-bulletin-june-7-2022). After going through the roulette round, Andy led Jen and a partially paying attention Dave through some fun yes or no questions. Items referenced in the Pod include: @Shadowserver https://twitter.com/Shadowserver - https://www.shadowserver.org Dave post on Active Shooter Incidents https://gate15.global/highlights-fbi-update-on-active-shooter-incidents-in-the-united-states/ Rob Yandow's paper on Physiological Response. https://gate15.global/the-brain-and-the-body-the-physiological-response-that-occurs-when-we-experience-fear-stress-trauma-and-critical-incidents/ HEAC White Paper https://gate15.global/white-paper-the-hostile-event-attack-cycle-heac-2021-update/ KEV: https://www.cisa.gov/known-exploited-vulnerabilities MFA page (new) https://www.cisa.gov/mfa CISA Jen: https://twitter.com/cisajen/status/1534055424600641537?s=21&t=S54nhjh7Vjp_q7Co9wk0fg Water ISAC and Dragos. https://www.waterisac.org/portal/waterisac-partners-new-dragos-ot-cert-help-underserved-water-and-wastewater-systems @RobertMLee Dawn’s active on LinkedIn (Dawn Cappelli, CISSP) https://www.cisa.gov/uscert/ncas/alerts https://www.cisa.gov/uscert/ncas/current-activity Plus many more - listen in
This month, Jen tries to put the “evangelize” in The Cybersecurity Evangelist by spreading the word on some great work in the ICS cybersecurity community.
Resources evangelized in this episode:
In this episode of The Gate 15 Interview, Andy Jabbour speaks with Ben Taylor, Executive Director for the Cannabis ISAO. Ben Taylor is the Executive Director of the Cannabis-ISAO. Ben also serves as a Risk Analyst to several Information Sharing & Analysis Centers and has previous security and operations experience as an Army Officer as well as working through the Department of Homeland Security’s (then) Office of Infrastructure Protection (now part of the Cybersecurity and Infrastructure Security Agency [CISA]). Ben has also spent several years in marketing and partner development roles within the tourism industry, to include working to promote Cannabis tourism in Oakland, California. To learn more about Cannabis ISAO, visit the Cannabis ISAO website, or on Twitter: @CannabisISAO and LinkedIn.
In the discussion we address:
A few references mentioned in or relevant to our discussion include:
A chat with Erin Miller, Executive Director of Space ISAC, from the 37th Space Symposium
Have you ever thought about just how much reliance there is on space systems and how satellites – tons of them – are actually flying computers with IP addresses? In an episode that is out of this world, the Gate 15 Podcast Channel welcomes back a very special guest – Erin Miller, Executive Director of Space ISAC on the 18th episode of The Cybersecurity Evangelist – to talk about all that and more from the 37th Space Symposium at The Broadmoor in Colorado Springs. From an event that Erin called, “bigger than Disneyland,” we talked about the importance of securing space systems, the pivotal role that Space ISAC is playing to increase the cybersecurity posture for the global space community, and the general passion for cybersecurity among attendees and speakers at the symposium.
Resources mentioned in this episode:
The gang is back together as Bridget Johnson and Joe Levy join Dave on the podcast to catch up on what they've missed while turning their attention to Ukraine and outdoor events. Within Ukraine, the nerdites talked about the effects of the current conflict, TikTok and the evolving information wars to include disinformation and misinformation campaigns on all sides, and what some outcomes may be long term. The gang then turned to thoughts of warmer weather and the upcoming outdoor events and activities. Looking at it through a security lens the Bridget, Joe and Dave looked at some important considerations while also keeping focus on those other events leading up to the 2022 election season. Before wrapping up with some pointed security plugs, the team talked about hurricane predictions and outdoor events to look forward to.
Joe Levy is the chairman of the International Associate of Venue Managers (IAVM) Venue Safety and Security Committee. In addition, Joe is the Chief Operating Officer at the Usdan Center for the Creative & Performing Arts. IAVM website https://www.iavm.org/ Venue Safety and Security committee contact information: [email protected]; LinkedIn Profile: https://www.linkedin.com/in/joelevy1/
Bridget Johnson is the Managing Editor for Homeland Security Today. In addition her contributions on Homeland Security Today (hstoday.us), they are also running a series of webinars (Webinar signups, https://www.eventbrite.com/e/le-only-anti-government-extremists-who-they-are-how-to-combat-them-tickets-144507635227?aff=ebdsoporgprofile). Twitter: @BridgetCJ
In this episode of The Gate 15 Interview, Andy Jabbour speaks with Gary Warner, Director of Research in Computer Forensics’ for the University of Alabama at Birmingham (UAB) and the Director of Threat Intelligence for DarkTower. From his LinkedIn bio, “Gary is the ‘Director of Research in Computer Forensics’ for the University of Alabama at Birmingham (UAB). In this role, which brings together the Computer Science and Criminal Justice departments, he is concentrating on research that will help law enforcement and other security professionals to identify, apprehend, prosecute and convict those who are committing cybercrime, and spread information to victims and potential victims about cybercrime issues. 90 analysts and programmers work in the UAB Computer Forensics Lab building tools and providing intelligence for a variety of clients around Cybercrime, Fraud, and Terrorism, as well as the Social Media aspects of more traditional crimes, including Gang Activity and Transnational Drug Networks. In addition to his duties at UAB, Warner serves as the Director of Threat Intelligence for DarkTower, a subsidiary of Queen Associates in Charlotte, North Carolina. Gary Warner was the founding president of the Birmingham InfraGard chapter, and has served as secretary and member of the board of the InfraGard National Members Alliance, among other roles.
Read more on LinkedIn. Gary on Twitter: @GarWarner. Gary’s blog: CyberCrime & Doing Time; A Blog about Cyber Crime and related Justice issues. “Malware analysis is a team sport” – Gary Warner, on information sharing, during our podcast recording In the discussion we address:
• Gary’s backstory and the work he’s doing today
• Information sharing and the value of plugging into information sharing communities
• The great work being done by the FBI and CISA
• The importance of knowing your competition, China, Russia, and ongoing threats
• Some of Gary’s go-to resources
• Gary talks about haikus, Talking Heads, GarBot, birdwatching, and more! “CISA, it's a new era of info sharing in the government” before giving some shout outs to CISA’s first Director, Chris Krebs, and current Director, Jen Easterly
A few references mentioned in or relevant to our discussion include:
• CISA’s Known Exploited Vulnerabilities Catalog (KEVC), something Gate 15’s Jen Walker raves about often, including in our recent Risk Roundtable: The Risk Roundtable EP 27: Don’t let bias guide your preparedness (07 Mar 22). https://www.cisa.gov/known-exploited-vulnerabilities-catalog
• Gary discussed this event: Justice Department Announces Court-Authorized Effort to Disrupt Exploitation of Microsoft Exchange Server Vulnerabilities (13 Apr 21) https://www.justice.gov/opa/pr/justice-department-announces-court-authorized-effort-disrupt-exploitation-microsoft-exchange
• BITNET https://bit.net
• FBI SENTINEL System https://www.fbi.gov/services/information-management/foipa/privacy-impact-assessments/sentinel
• Intellipedia https://en.wikipedia.org/wiki/Intellipedia
• REN-ISAC https://www.ren-isac.net
• Gary’s four CISA “must watch” sites from the CISA cyber landing page:
o Current activity: https://www.cisa.gov/uscert/ncas/current-activity
o Alerts: https://www.cisa.gov/uscert/ncas/alerts
o Bulletins: https://www.cisa.gov/uscert/ncas/bulletins
o Analysis: https://www.cisa.gov/uscert/ncas/analysis-reports
• Gary strongly encouraged listeners to check CISA Director Jen Easterly’s “about” section in her LinkedIn profile to understand why she is so excellently qualified to be the woman leading CISA today (something Chris Krebs, her predecessor at CISA agrees with)
This month, The Cybersecurity Evangelist chats with a couple of budding podcasters. For the third appearance on the Gate 15 Podcast Channel, the Health Information Sharing and Analysis Center (H-ISAC) joins me for episode 17.
I got to put my ISAC analyst hat on and talk with the heart of Health-ISAC – the dynamic duo of Zach Nelson (Threat Operations Center Manager) and Joshua Justice (Senior Cyber Threat Intelligence Analyst) from the Threat Operations Center about what drives Health-ISAC and the goals of the Threat Operations Center – the privacy and security of our protected health information (PHI) and why threat actors want that information – yours and mine! We also talked a little about cross-sector collaboration, especially between the ISACs, and rounded it out with a general reminder for all to be #BeCyberSmart about phishing themes leveraging the Russia-Ukraine conflict.
Resources mentioned in this episode
In the latest Risk Roundtable, Andy, Jen, and Dave talk about the war in Ukraine and what it means for preparedness. Sometimes you just have to call a spade a spade and not allow personal, political or other bias to affect your organization’s analysis or preparedness. While Andy and Dave throw flags on their previous predictions, Jen brings us back to reality and talks about being aware, being prepared, and reminds “don’t panic.” Andy then drills down on bias and how it can have an impact on organizations.
During the Roulette Round, Jen talked about CISA’s Known Exploited Vulnerabilities Catalog, vulnerabilities, and patching (while Dave ensured it wasn’t his Windows 2000 computer exposure that Jen was referring to…), then Dave brought up the importance of disaster preparedness in light of spring and summer severe weather events. Andy wrapped things up with a quick talk about the “People’s Convoy” and the battle of the Washington, D.C. Beltway! The pod wraps up with three questions – from COVID predictions, to Andy’s confusion about when seasons start, to Batman.
Link mentioned in the pod include: CISA’s Shields Up webpage: https://www.cisa.gov/shields-up CISA: Russia Cyber Threat Overview and Advisories. https://www.cisa.gov/uscert/russia#russian And our post on the Gate 15 blog from 03 March, Russian Cybersecurity Threats: 5 Asks from the FBI: https://gate15.global/russian-cybersecurity-threats-5-asks-from-the-fbi/ Bridget Johnson on Twitter, and at Homeland Security Today (HS Today) CISA Adds 95 Known Exploited Vulnerabilities to Catalog (03 Mar 22): https://www.cisa.gov/uscert/ncas/current-activity/2022/03/03/cisa-adds-95-known-exploited-vulnerabilities-catalog WaterISAC: Update (March 3, 2021) – 95 Added to CISA’s Known Exploited Vulnerabilities Catalog (03 Mar 22): https://www.waterisac.org/portal/cisa’s-known-exploited-vulnerabilities-catalog Microsoft: Customer Guidance for WannaCrypt attacks (12 May 17): https://msrc-blog.microsoft.com/2017/05/12/customer-guidance-for-wannacrypt-attacks/ ZDNet Ransomware attack: Hospitals still struggling in aftermath of WannaCrypt's rampage (15 May 17): https://www.zdnet.com/article/ransomware-attack-hospitals-still-struggling-in-aftermath-of-wannacrypts-rampage/
Why Scammers Love Love Too! On Episode 16, The Cybersecurity Evangelist talks about love! Well, more specifically romance scams. I talked about the social engineering component of romance scams, a few fraud reports and financial losses due to romance scams, red flags that could indicate someone you know is caught in a romance scam, some common and practical steps to defeating romance and other types of social engineering based scams, and the importance of reporting romance scams. No matter how painful, falling for a romance scam is nothing to be ashamed of. Romance scams can happen to anyone at any age.
Resources mentioned in this episode:
In this episode of The Gate 15 Interview, Andy Jabbour speaks with Joseph Marks, Washington Post reporter for The Cybersecurity 202. From his Washington Post bio, “Joe Marks writes The Cybersecurity 202 newsletter focused on the policy and politics of cybersecurity. Before joining The Washington Post, Marks covered cybersecurity for Politico and Nextgov, a news site focused on government technology and security. He also covered patent and copyright trends for Bloomberg BNA and federal litigation for Law360. Marks began his career at Midwestern newspapers covering city and county governments, crime, fires and features. He spent two years at the Grand Forks Herald in North Dakota and is originally from Iowa City. Joe on Twitter, @Joseph_Marks_. Joe on LinkedIn. Subscribe to The Cybersecurity 202.
In the discussion we address:
A few references mentioned in or relevant to our discussion include:
In the latest episode of Nerd Out, Dave starts off by talking about his recent quarantine experience in Costa Rica (21 days!) before welcoming in a panel to discuss the Colleyville, Texas synagogue attack. Bringing in Mayya Saab, Seth Ozer, and Ed Heyman the panel went through the hostile event and looked at initial reactions, what can be learned from this situation, and some of the key takeaways. The team then stressed the importance of training in this situation, but also discussed several low cost options and ways to make their location more secure. Mayya Saab is the Executive Director of the Faith-Based Information Sharing and Analysis Organization (FB-ISAO); Seth Ozer is Senior Consultant with Woodstone Consulting, LLC; Ed Heyman is the co-chair of the FB-ISAO Organizational Residence Group
This first TCE episode of 2022 (and first video - on Spotify) includes a few gentle and some not-so-gentle reminders on cybersecurity best practices and practices for better cyber hygiene. I start with a few cybersecurity controls for businesses to buckle down on this year, including identifying assets, vetting vulnerabilities, and pursuing more potent password policies. Then, I actually persist on the password point with some pontification about our predilection for problematic passwords and propose pointers for a more polished password posture.
While there’s probably nothing new in this episode, I hope it serves as a gentle nudge to promote better cyber hygiene habits – not just resolutions for 2022, but positive habits to develop for all-time toward a more cyber secure you! I also evangelize for a new CISA resource - the Known Exploited Vulnerabilities Catalog.
Other resource mentioned in this episode: https://www.consumer.ftc.gov/articles/password-checklist
In the latest episode of the Risk Roundtable, Andy leads the team through a review of the latest risks facing individuals and organizations. Jen decked the halls talking about the latest holiday scams that continue to bring coal to good boys and girls. Then Dave talked about the latest school shooting in Michigan and tried not to be a Scrooge by talking about some positive take-aways while highlighting important lessons still to be learned in Christmas future. Then, while Dave danced to spinning the wheel in his head, the roundtable talked about their favorite moments from across the Gate 15 Podcast Channel, after all, we are living in a physical world (Jen). The podcast wrapped up with some holiday cheer talking about favorite television or movies for the season. From all of us at Gate 15, to all of the security teams and organizations around the world, here is hoping for a happy holidays and a wonderful 2022! Companies Linked to Russian Ransomware Hide in Plain Sight. Cybersecurity experts tracing money paid by American businesses to Russian ransomware gangs found it led to one of Moscow’s most prestigious addresses. https://www.nytimes.com/2021/12/06/world/europe/ransomware-russia-bitcoin.html Gate 15 Releases a White Paper with an Update to the Hostile Event Attack Cycle. https://gate15.global/gate-15-releases-a-white-paper-with-an-update-to-the-hostile-event-attack-cycle/ Known Exploited Vulnerabilities Catalog | CISA. https://www.cisa.gov/known-exploited-vulnerabilities-catalog Advanced threat predictions for 2022. Over the past 12 months, the style and severity of APT threats has continued to evolve. Despite their constantly changing nature, there is a lot we can learn from recent APT trends to predict what might lie ahead in the coming year. https://securelist.com/advanced-threat-predictions-for-2022/104870/
In the latest episode of Nerd Out, this is a very special two parter. In the first part, the nerdies (Bridget and Joe) talk about the fallout from the Houston Astropark disaster ranging from the considerations that go into the event planning, and whether there should be a blame game. And then they look at how threat actors may use this event for future threat planning (note the Hostile Events Attack Cycle) before turning their attention to the latest National Terrorism Advisory System Bulletin release and what it could mean for the holidays. In part two, Dave welcomes in Tamara Herold and goes a little deeper into the Houston incident and what it could mean for events moving forward. Some references brought up in the podcast: Example of Crowd wave: https://www.youtube.com/watch?v=BgpdmAtbhbE Crowd Dynamics: https://www.youtube.com/watch?v=kmqsc7srIfY and https://www.youtube.com/watch?v=Txrs4ssiAz0 Roger Federer saves kid: https://www.youtube.com/watch?v=RymfiBXKuMQ 2018 Concert in Italy: https://celebrityaccess.com/2018/12/08/all-ages-concert-stampede-in-italy-leaves-at-least-6-dead/ Dave Pounder is a Senior Risk Analyst for Gate. Twitter: @dpounder; email: [email protected] Joe Levy is the chairman of the International Associate of Venue Managers (IAVM) Venue Safety and Security Committee. In addition, Joe is the Chief Operating Officer at the Usdan Center for the Creative & Performing Arts. IAVM website https://www.iavm.org/ Venue Safety and Security committee contact information: [email protected]; LinkedIn Profile: https://www.linkedin.com/in/joelevy1/ Bridget Johnson is the Managing Editor for Homeland Security Today. In addition her contributions on Homeland Security Today (hstoday.us), they are also running a series of webinars (Webinar signups, https://www.eventbrite.com/e/le-only-anti-government-extremists-who-they-are-how-to-combat-them-tickets-144507635227?aff=ebdsoporgprofile). Twitter: @BridgetCJ Tamara D. Herold, Ph.D., Associate Professor, Graduate Director, University of Nevada, Las Vegas (UNLV) Director, Crowd Management Research Council Department of Criminal Justice. Twitter: @advancetheline and @herold_tamara
In the latest Risk Roundtable, Andy, Dave and Jen ponder whether or not we live in the physical world or if a little time off took Jen to a whole new dimension. Kicking off with another acronym soup month, the team looks at Critical Infrastructure Security and Resilience Month and the downstream impacts that can affect organizations who fail to incorporate for critical infrastructure into their preparedness plans. Then roundtable talked about the recent warning of terrorist capabilities to strike the U.S. as well as whether organizations are better prepared today to address a crisis than they were pre-COVID. In the process, the team came up with a new term - "Preparedness Calculus" - and whether organizations are evaluating events and factoring that into their preparedness process. The discussions wrapped up with Andy's three questions involving some favorite fall themes - warm clothing, turkey, and the Lion's losing. But before signing off, Dave had to talk about his enjoyment for Dune, but did he show some hypocratic tendencies? Some links to items discussed in the podcast included: White House Critical Infrastructure Month Proclamation. https://www.whitehouse.gov/briefing-room/presidential-actions/2021/10/29/a-proclamation-on-critical-infrastructure-security-and-resilience-month-2021/ CISA Infrastructure Security Month Materials: https://www.cisa.gov/infrastructure-security-month https://www.cisa.gov/publication/guide-critical-infrastructure-security-and-resilience (2019) https://www.cisa.gov/publication/methodology-assessing-regional-infrastructure-resilience (June 2021) Critical Infrastructure Sectors. https://www.cisa.gov/critical-infrastructure-sectors See Something Say Something. https://www.dhs.gov/see-something-say-something See Something Say Something: Report Suspicious Activity. https://www.dhs.gov/see-something-say-something/how-to-report-suspicious-activity Webinar: Getting Started Now: Pandemic Preparedness After-Action Reports, 10 Apr 2020. https://gate15.global/webinar-getting-started-now-pandemic-preparedness-after-action-reports/ Webinar Recording: Getting Started Now: Pandemic Preparedness After-Action Reports, 17 Apr 2020. https://gate15.global/webinar-recording-getting-started-now-pandemic-preparedness-after-action-reports/ REN-ISAC and report: https://www.ren-isac.net/public-resources/workshops/index.html & https://www.ren-isac.net/public-resources/2021_REN-ISAC_Blended_Threat_Workshop_Final_Report.pdf
In this episode of The Gate 15 Interview, Andy Jabbour talks with Erin Miller, Executive Director for Space ISAC (https://s-isac.org). “The Space ISAC serves to facilitate collaboration across the global space industry to enhance our ability to prepare for and respond to vulnerabilities, incidents, and threats; to disseminate timely and actionable information among member entities; and to serve as the primary communications channel for the sector with respect to this information.” Erin on Twitter (@erinmarmiller). Erin on LinkedIn (@erinmarlenemiller). In the discussion we address:
Please enjoy this episode of The Gate 15 Interview podcast on Anchor, Spotify, Apple, Google, as well as other locations accessible via the Anchor link or almost anywhere you listen to your favorite podcasts.
‘We are on a journey and our journey is multi-decades long…’
A few references mentioned in or relevant to our discussion include:
In the most recent episode of Nerd out, and as accurately described by Ron Burgundy it could be a horrible news story but Dave goes solo to talk about the recent events. These include the Norway Bow and Arrow attack, the murder of a British Member of Parliament, and two of the more recent insider threat attacks and how organizations can learn from these events and improve their security posture. Dave then goes a little pop culture to talk about his three favorite security movies and shows. He also uses these references to talk about how organizations can build and nuture their own intelligence analysts and the value they can bring to an organizations. Rough transitions aside and some help from Ron Burgundy and Syndrome aside the panel will return for next month as they look ahead to what should be a busy holiday season.
The Cybersecurity Evangelist "evangelizes" Cybersecurity Awareness Month 2021.
Cybersecurity Awareness Month is co-led by the National Cyber Security Alliance and the Cybersecurity and Infrastructure Agency (CISA) of the U.S. Department of Homeland Security. For more information about ways to keep you and your family safe online visit https://staysafeonline.org/cybersecurity-awareness-month/ and cisa.gov/ncsam.
Other resources mentioned during this episode:
Your favorite cybersecurity evangelist waxes solo and prattles on about patching in this no frills episode of TCE.
After a a busy couple of weeks, the merry band of Nerdies gathered to discuss the latest news on the terrorism and extremist front and how misinformation has shaped so much of these advanced. The group started with Bridget’s reporting of a new Al Qaeda message, which was followed with press reports extremist chatter and then the he National Terrorism Alert System Bulletin. These all gave the group an opportunity to talk to the risks to various locations, especially venues and the Commercial Facilities Sector. Next, the group transitioned to mis-information and how integral it was to both terrorist groups as well as domestic violent extremism. COVID dominated the last part of the discussion with Bridget sharing her personal story and loss before the group went through a rapid fire set of questions! But just like our favorite band of super-heroes, stay for the end credits and you might here about killer mosquitos.
Dave Pounder is a Senior Risk Analyst for Gate. Twitter: @dpounder; email: [email protected]
Joe Levy is the chairman of the International Associate of Venue Managers (IAVM) Venue Safety and Security Committee. In addition, Joe is the Chief Operating Officer at the Usdan Center for the Creative & Performing Arts. IAVM website https://www.iavm.org/ Venue Safety and Security committee contact information: [email protected]; LinkedIn Profile: https://www.linkedin.com/in/joelevy1/
Bridget Johnson is the Managing Editor for Homeland Security Today. In addition her contributions on Homeland Security Today (hstoday.us), they are also running a series of webinars (Webinar signups, https://www.eventbrite.com/e/le-only-anti-government-extremists-who-they-are-how-to-combat-them-tickets-144507635227?aff=ebdsoporgprofile). Twitter: @BridgetCJ
The discussions were lively on the latest edition of the Risk Roundtable as Jen showed off her inner nerd! With Andy nursing an injury, Dave and Jen took off on topics ranging from the latest White House memos on improving critical infrastructure to the troubling trends on COVID and what it all means for businesses and organizations. In the roulette round (Dave is on a 2 pod winning streak with the theme music) the roundtable talked about some all-hazards and preparedness for the upcoming religious holidays before Jen "nerded out" on various reports on new CVEs and displayed a very nerdy t-shirt to boot! Andy got his strength back for his three questions where Dave revealed his disgust over some veggies and lack of love for a historic band!
Some of the links mentioned in the podcast included:
On episode 12 of The Cybersecurity Evangelist (TCE) podcast, I chat with a couple of Baby Boomers with varied perspectives of cybersecurity as I take TCE back to its roots – as the cybersecurity podcast for everyone. Ed Heyman (@El_Grillo1) and a mystery guest to talk about “The Great Bewilderment.” We also discuss why boomers are the generation most likely to take privacy and security seriously, and what bare minimum level of cyber awareness everyone should maintain.
Resources mentioned in this episode (along with other relevant posts not mentioned):
My final ISAC segment for TCE was a great discussion with two Steering Committee Members from Tribal-ISAC. Bill Travitz – Director, Office of Information Technology, Eastern Band of Cherokee Indians, and Lee Edberg - IT Cybersecurity Manager for Mystic Lake Casino Hotel, Shakopee Mdewakanton Sioux Community.
The overall theme of this episode, and the ISAC series in general - We are stronger together! As Lee said, there is invaluable power in numbers with more tribes fighting the threat landscape together; get involved, get to a meeting, and contribute! Similarly for Bill, it’s about being a good neighbor, and that is a value that tribes already have! We all learn from one another.
Tribal-ISAC is open to membership for Native American and Alaskan Native tribal government, operations, and enterprises.
Resources discussed in this episode:
In this episode of The Gate 15 Interview, Andy Jabbour talks with Bryan Ware, founder and CEO of Next5 (next5.co), a technology-focused business intelligence and strategic advisory firm. In addition to being a successful entrepreneur, Bryan is a self-described “analytics geek” and emerging technologies expert. He has formerly served as the CEO at Haystax Technology and more recently served at DHS Cybersecurity and Infrastructure Security Agency (CISA) as the Assistant Director for the Cybersecurity Division. Bryan on Twitter (@bsware). Bryan on LinkedIn. In the discussion we address: Bryan’s background and his experience in the private sector and at DHS’s Cybersecurity and Infrastructure Security Agency (CISA) His new project, Next5 Critical and emerging technology and associated concerns Geopolitical and other security challenges Find out what Bryan means when he says “I believe in Liquid Diplomacy?” Here his call to service And more! “I’m most passionate about the critical and emerging technologies that are emerging now and will be most important to our lives, economies, and national security 5+ years from now” Bryan Ware A few references mentioned in or relevant to our discussion include: We discussed Bryan’s new company, Next5. From the website, “Next5 helps leading companies develop, acquire and protect the game-changing technologies of the future. Our research provides a current and expert perspective on critical emerging technologies, global supply chains, and geo-political and economic factors that shape opportunities and risks.” See more, including the Next 5 Technology Matrix, from the link above. Bryan mentioned the quote “software is eating the world,” stated by Marc Andreessen. Read more on that in the Wall Street Journal, Why Software Is Eating The World (20 Aug 2011). We mentioned the Five Eyes partnership, which is the intelligence alliance comprising Australia, Canada, New Zealand, the United Kingdom, and the United States. You can read a little about that from the Office of the Director of National Intelligence, here, or on Wikipedia.
TCE continues the chat with REN-ISAC’s Krysten Stevens and Brett Zupan.
On this episode:
REN-ISAC Resources discussed on this episode:
Peer Assessment Service - https://www.ren-isac.net/public-resources/pas/index.html
Workshops - https://www.ren-isac.net/public-resources/workshops/index.html
Security Event System - https://www.ren-isac.net/member-resources/SES.html
Our Trust Community - https://www.ren-isac.net/what-we-do/index.html
A year ago, as the pandemic had taken hold around the world, there was a lot of confusion and uncertainty. And while threats were equally as susceptible to COVID, they ultimately rose to exploit the situation. Now that vaccines are being distributed and the world is slowly reopening, does this change the threat environment? The Risk Roundtable crew discusses this potential, as well as other security matters that individuals and organizations should be on guard for moving into the summer months. Then after the risk roulette discussion, complete with music (thanks Dave), Andy leads the gang in a "get to know you" series of questions.
Scams: https://www.ftc.gov/coronavirus/scams-consumer-advice
Combatting Ransomware: https://securityandtechnology.org/ransomwaretaskforce/report/
This month the panel is a party of one - Rob Yandow joins again to talk with Dave about high stress situations and preparedness. This is especially relevant given the reopenings and the latest hostile event situations. Rob goes into detail about the phsiology of fear, as well as how and why individuals respond to high stress situations the way they do. Using various examples, Rob hammers home the various stages in the survival arc - denial, deliberation, and decisive action. And most importantly, the podcast talks about the ways organizations can use this information to train and prepare to respond. Then Dave is joined by a special guest to talk about the greatest band ever.
Rob Yandow is a security expert who is a former police officer and who works with the Faith-Based Information Sharing and Analysis Organization (FB-ISAO) and serves as the Co-Chair of their Business Resilience Group - website: https://faithbased-isao.org. Twitter: @RobYandow
Despite the razzing I got from the guys (David Pounder - host of the NerdOut! Security Panel Discussion, and Andy Jabbour - host of The Gate 15 Interview) during the last Risk Roundtable, the TCE ISAC Series continues!!! This time, REN-ISAC (Research & Education Networks Information Sharing & Analysis Center) joins me. REN-ISAC serves the higher education and research community by promoting cybersecurity operational protections and response.
For this episode, I enjoyed a fun and lively chat with Krysten Stevens, “new” Director of Technical Operations, and Brett Zupan, Risk Analyst and DC Liaison. We talked about threats facing the research and higher education community and bragged on Kim Milford’s (REN-ISAC’s Executive Director) amazing vision in 2019 to execute a series of workshops that had colleges, universities, and relevant community partners, such as state/local health departments and law enforcement working together through an infectious disease scenario – a scenario the team thought might be going too far…
Resources discussed on this episode:
The Risk Roundtable crew looked at the increasingly important idea of security bias and security blindness. The group specifically looked at how bias in analysis can lead to security blindness and the minimization and exaggeration of threats. Within the analytical community it is important to note how bias exists in virtually everything and the team discussed ways in which bias could exist from the analyst, but also by those that receive the data. Andy, Jen and Dave discussed some of the root causes and how this can lead to and continue a cycle of misinformation and disinformation if not handled correctly. In fact, the more divisive our politics become, the more bias our media, the more people – politicians, the media, foreign governments, and others - fan the flames of division, the more challenging the role of the analyst can become. In the end, bias is a discussion that is encouraged to be had by all organizations to ensure they are accurately representing the threat and risk to the organization.
Next the team looked at their roulette items (Dave even shared the theme song on demand!) reminding listeners of the Microsoft Exchange Vulnerability and to update their systems. In addition, as reopenings are occurring around the world in varying degrees, it is important that organizations review security plans and processes.
Items highlighted in the Podcast:
Health ISAC Spring Summit open to members and non-members: https://h-isac.org/summits/secured-in-paradise-spring-2021-summit/
Agenda: https://web.cvent.com/event/cd1e7b44-7e38-487b-bd1f-b4f39cc82a11/websitePage:645d57e4-75eb-4769-b2c0-f201a0bfc6ce
Troy Hunt Confirmation Bias - and good read: https://www.troyhunt.com/lets-stop-the-5g-hysteria-understanding-hoaxes-and-disinformation-campaigns/
Additional information about the Microsoft Exchange Vulnerability:
FortiOS Vulnerability: https://us-cert.cisa.gov/ncas/current-activity/2021/04/02/fbi-cisa-joint-advisory-exploitation-fortinet-fortios
CISA Cybersecurity Directives and Implementation Guidance Site: us-cert.cisa.govus-cert.cisa.gov
In this episode of The Gate 15 Interview, Andy Jabbour talks with James Whalen, SVP, Chief Information & Technology Officer, Boston Properties. In this podcast we address:
James Whalen: James Whalen serves as Senior Vice President, Chief Information & Technology Officer for Boston Properties where he is responsible for the direction and implementation of technology services and solutions. Prior to joining the Company in March 1998, he served as Vice President, Information Systems of Beacon Properties. He is a graduate of the University of Notre Dame and a recipient of the New York City Urban Fellowship. Mr. Whalen is a current trustee and past President of the Boston Chapter of the Society for Information Management (SIM) and serves on the Real Estate Cyber Consortium, Realcomm Advisory Council, Commercial Facilities Cyber Working Group, TechHire Boston and Boston Private Industry Council. LinkedIn.
A few references mentioned in or relevant to our discussion include:
· The Real Estate Information Sharing and Analysis Center (RE-ISAC). “The Real Estate Information Sharing and Analysis Center (RE-ISAC), a not-for-profit information sharing entity organized by The Real Estate Roundtable in February 2003, is a public-private partnership between the US commercial facilities sector and federal homeland security officials which serves as the primary conduit of terrorism, cyber and natural hazard warning and response information between the government and the commercial facilities sector.”
· InfraGardNCR: Commercial Facilities Cyber Working Group (CCWG)
· FBI IC3 Cyber Crime Report: FBI Releases the Internet Crime Complaint Center 2020 Internet Crime Report & PDF: 2020 Internet Crime Report, 17 Mar 21
· Palo Alto Networks: Highlights from the 2021 Unit 42 Ransomware Threat Report & Ransomware Threat Assessments: A Companion to the 2021 Unit 42 Ransomware Threat Report, 17 Mar 21
· Group-IB: ransomware empire prospers in pandemic-hit world. Attacks grow by 150%, 04 Mar 21
In the latest episode of Nerd Out, Dave and his merry band of nerdies, Bridget, Travis, and Joe, look at the latest news around the reopening and what organizations need to be on guard for as crowd sizes and capacity limits will test the ongoing health pandemic. Then the group looks at the way threat actors may respond. Will it be a target of opportunity or will new security measures be disruptive enough. Next, the panel looked at recent protests, and the potential for future protests (did people really forget about May Day!) and what ways they may change in a reopened world. Finally, what is the future of conspiracy theories and the movements that were charged over the past several years? The group then lightened it up a bit and went through some lightning round questions and discovered that the Snyder Cut really isn't a thing because no one particularly cared for it in the first place to even know it was a thing.
Dave Pounder is a Senior Risk Analyst for Gate. Twitter: @dpounder; email: [email protected]
Joe Levy is the chairman of the International Associate of Venue Managers (IAVM) Venue Safety and Security Committee. In addition, Joe is the Chief Operating Officer at the Usdan Center for the Creative & Performing Arts. IAVM website https://www.iavm.org/ Venue Safety and Security committee contact information: [email protected]; LinkedIn Profile: https://www.linkedin.com/in/joelevy1/
Travis Moran is the Assistant Deputy Director, Critical Infrastructure Protection & Physical Security. Twitter: @dronin_on; email: [email protected]
Bridget Johnson is the Managing Editor for Homeland Security Today. In addition her contributions on Homeland Security Today (hstoday.us), they are also running a series of webinars (Webinar signups, https://www.eventbrite.com/e/le-only-anti-government-extremists-who-they-are-how-to-combat-them-tickets-144507635227?aff=ebdsoporgprofile). Twitter: @BridgetCJ
TCE welcomes Faith-Based ISAO Executive Director, Mayya Saab on this episode. And no, this isn't the "FBI" ISAO... ;-) Listen in to find out what Mayya loves most about her role and her heart's desire in helping the entire community of faith be secure and resilient.
Check out FB-ISAO at https://faithbased-isao.org/
In the latest episode of the Risk Roundtable, Andy, Jen, and Dave look at some recent events (Oldsmar) while looking ahead to upcoming events that may present risks (Qanon, the George Floyd murder trial, and upcoming religious holidays) but only after talking about Andy's taste in shirts. Then in the risk roulette, which Dave forgot again to find music for (or did he), Dave wonders about weather preparedness is overhyped while Jen circles back to lessons learned from Solar Winds and the concept of "zero trust" - not in Andy and Dave but in terms of cybersecurity. The gang wraps up talking about some of their struggles and what they are watching. But that's not all - after the credits Dave may have redeemed himself with a new theme for the risk roulette.
Some of the links from today's episode:
YouTube: Treatment Plant Intrusion Press Conference, 08 Feb.
WaterISAC: 15 Cybersecurity Fundamentals for Water and Wastewater Utilities
Gate 15: Blended Threats: Did Florida’s Cyber Attack Whet Your Appetite for Better Preparedness and Security?
NSA: NSA Issues Guidance on Zero Trust Security Model
Forrester: Zero Trust Is Not A Security Solution; It’s A Strategy
The Hacker News: SolarWinds Blame Intern for Weak Password That Led to Biggest Attack in 2020
Vice: QAnon Isn’t So Sure Trump Will Magically Become President Again on March 4
Ready.gov: Plan Ahead for Disasters
Dave "Quarter" Pounder, host of the famed NerdOut! Security Panel Discussion joins me on this episode of The Cybersecurity Evangelist. Dave and I talk about the Real Estate ISAC. And no, it's not just for real estate companies - although I may have dropped a hint in the opening commentary about TCE being a great sponsorship opportunity for Berkshire Hathaway/Warren Buffet... ;-) Wouldn't that be nice!
Dave and I had fun talking about how RE-ISAC shares information about potential physical and cybersecurity threats and vulnerabilities to help protect commercial facilities and the people who use them.
Visit https://www.reisac.org/ to learn more!
After opening up about their love of Groundhog day, the holiday and movie, the Risk Roundtable gang gets into the meat of their security discussions around the latest arrest in Singapore (Hostile Events), upcoming significant events to factor into consideration, and the global takedown of Emotet (the malware, not a weird allusion to the Egyptian god). Then in the Risk Roulette, which Dave still does not have good music for, the group discussions if there is anything to consider when looking at the Robin Hood / Wall Street Bets activity last week and the Capitol Hill riot, as well as the lingering effects of Solar Winds. The gang wraps it all up with some personal preferences before Andy tries to convince himself the Lions are still a football team. Some of the links referenced in the show include: EMOTET: https://www.justice.gov/opa/pr/emotet-botnet-disrupted-international-cyber-operation https://www.eurojust.europa.eu/worlds-most-dangerous-malware-emotet-disrupted-through-global-action https://www.tripwire.com/state-of-security/security-data-protection/cyber-security/emotet-botnet-takedown-what-you-need-to-know/ https://www.bleepingcomputer.com/news/security/fonix-ransomware-shuts-down-and-releases-master-decryption-key/ “Why Joe Biden Can’t Bring His Peloton to the White House” – Popular Mechanics (https://www.popularmechanics.com/technology/security/a35190713/joe-biden-peloton-white-house-security-risk/) Is Joe Biden’s Peloton a cybersecurity risk? Don’t sweat about it - Graham Cluley (https://grahamcluley.com/is-joe-bidens-peloton-a-cybersecurity-risk-dont-sweat-about-it/)
This month, The Cybersecurity Evangelist talks with WaterISAC's Director of Preparedness and Response, Chuck Egli. The conversation ran a little longer than I like to aim for, but it's understandable given that Chuck and I work closely together in support of WaterISAC. Plus, with WaterISAC being one of the oldest ISACs, I'm quite certain they've earned the extra spotlight!
After a much longer than normal opening comment (I sense a trend here) running down a list of many of the ISACs - (most of) which you can find on The National Council of ISAC's webpage at https://www.nationalisacs.org/member-isacs - Chuck and I talk about all the ways WaterISAC supports the security and resilience of the water and wastewater sector with an all-hazards approach (not just cyber).
Chuck's parting thoughts: Look into your ISAC community or ISAO…there is one for you!! While many have membership models, so many of them offer information and assistance for the benefit of all toward the greater global good.
For more information about WaterISAC, check out its webpage at https://www.waterisac.org/
In the latest episode of the Nerd Out Security Panel Discussion podcast the gang reviews the election and what didn't happen and how lessons can be learned from that as well as looking at the current state of protests and how faith-based organizations have been on the front lines of support as well as taking up action. Then the panel looks at the current terrorism threat and how that could impact the upcoming holiday season for stores as well as faith-based organizations. In the lightning round, the panel shares pays tribute to the OG Chris Krebs for his handling of the election and dis/misinformation, as well as tackle other topics. Security expert Rob Yandow joins host Dave Pounder, Bridget Johnson and Joe Levy this month!
Joe Levy is the chairman of the International Associate of Venue Managers (IAVM) Venue Safety and Security Committee. IAVM website https://www.iavm.org/ Venue Safety and Security committee contact information: [email protected]; LinkedIn Profile: https://www.linkedin.com/in/joelevy1/
Rob Yandow is a security expert who is a former police officer and who works with the Faith-Based Information Sharing and Analysis Organization (FB-ISAO) and serves as the Co-Chair of their Business Resilience Group - website: https://faithbased-isao.org. Twitter: @RobYandow
Bridget Johnson is the Managing Editor for Homeland Security Today. In addition her contributions on Homeland Security Today (hstoday.us), they are also running a series of webinars (Webinar signups, https://www.eventbrite.com/o/homeland-security-today-30028526516). Twitter: @BridgetCJ
For this November episode of TCE I’ve decided to take on National Critical Infrastructure Security and Resilience Month, Critical Infrastructure Security and Resilience Month, Critical Infrastructure Month, Infrastructure Security Month, whew! Actually, I’ve been almost as overwhelmed with responses from people wanting to be a part of this edition as I am with the litany of names given to this critical observance. That said, this edition/theme is likely to be in three or four parts so we can evangelize as many ISAC’s (and ISAO’s) as we can!
During this episode we get the ISAC party started with discussions from DNG-ISAC and MM-ISAC!
Links to resources and organizations mentioned in this episode:
Infrastructure Security Month https://www.cisa.gov/ismonth
Critical Infrastructure Sectors https://www.cisa.gov/critical-infrastructure-sectors
National Council of ISACs, list of member ISACs https://www.nationalisacs.org/member-isacs
Downstream Natural Gas ISAC https://www.dngisac.com/
The Social Dilemma film https://www.thesocialdilemma.com/
Mining & Metals ISAC http://www.mmisac.org/
Perch Security https://perchsecurity.com/
At long last, and after countless suggestions, the team channels their inner "Rock" and brings Critical Infrastructure back to the Risk Roundtable. After discussing Critical Infrastructure Security and Resilience Month and some of the key threats facing critical infrastructures. Andy then guides the team through some quick hits including Jorhena's appreciation for November also serving as Gratitude Month, or Dave Pounder Appreciation Month, Dave encouraging us to consider Security Mindfulness and Jen making sure we didn't forget any of the many threats facing Critical Infrastructure. And even though this was generally an "election free" podcast, be sure to catch Jorhena as she talked about election misinformation issues on Good Morning DC - link to follow. Plus someone is a little sensitive about Spookley the Square Pumpkin.
Critical Infrastructure and Resilience Month: https://www.whitehouse.gov/presidential-actions/proclamation-critical-infrastructure-security-resilience-month-2020/
CISA Critical Infrastructure Security Reslience Guide: https://www.cisa.gov/sites/default/files/publications/Guide-Critical-Infrastructure-Security-Resilience-110819-508v2.pdf
Media in Disasters and Emergencies: Social Media Working Group for Emergency Services and Disaster Management: https://www.dhs.gov/sites/default/files/publications/SMWG_Countering-False-Info-Social-Media-Disasters-Emergencies_Mar2018-508.pdf
Andy's Election Blog - Elections Perspective: On November 4th, let us stand together as Americans: https://gate15.global/elections-perspective-on-november-4th-let-us-stand-together-as-americans/
The Nerd Out Security Panel tackles the latest terrorist incidents in France as well as the disrupted plot in Michigan. There are a lot of valuable lessons learned from these incidents, as well as the recent revelations from the 2017 Manchester concert bombing. The group then goes rapid fire through some security topics to include concerns through the end of the year, security issues we may not be talking about, Edward Snowden, Magnum PI, Spencer for Hire and more. Joe Levy is the chairman of the International Associate of Venue Managers (IAVM) Venue Safety and Security Committee. IAVM website https://www.iavm.org/ Venue Safety and Security committee contact information: [email protected]; LinkedIn Profile: https://www.linkedin.com/in/joelevy1/ Travis Moran is the Vice President of Operations at Welund North America. Twitter: @dronin_on; email: [email protected] Bridget Johnson is the Managing Editor for Homeland Security Today. In addition her contributions on Homeland Security Today (hstoday.us), they are also running a series of webinars (Webinar signups, https://www.eventbrite.com/o/homeland-security-today-30028526516). Twitter: @BridgetCJ
Shay Trembley, Information Security Manager of South Blount Utility District, and I finish up the remaining 4 "P's of Basic Cybersecurity" - a timely topic in recognition of National Cybersecurity Awareness Month (NCSAM). We address passwords, privacy, patching, and protection, and include several of our personal favorite resources for cybersecurity awareness for everyone. Shay's final tip: she encourages everyone to speak up and share information. The more everyone shares information about the cyber threats and risks, or even suspected threats and risks, the better we will all be informed and #BeCyberSmart.
In recognition of NCSAM, we individually listed a ton of resources to help businesses and individuals to #BeCyberSmart:
https://staysafeonline.org/, including National Cybersecurity Awareness Month and other NCSA resources
https://www.cisa.gov/information-sharing-and-awareness(for more on Information Sharing and Analysis Centers)
https://www.sans.org/security-awareness-training/ouch-newsletter
https://cybercrimesupport.org/
https://cyberreadinessinstitute.org/
Andy, Jen, Jorhena and Dave go through a plethora of security topics as they introduce the "Opening Shot", before digging deep into some trends they have noted across industries to include the ever present cyber threats (hello ransomware), and social media threats, as well as touching on the upcoming elections. Then the team gets personal and talks about some of the things that have kept them busy over the past couple of months to include Jorhena's upcoming publication! Some references that were dropped during the pod:
National Cybersecurity Awareness Month (NCSAM): https://www.cisa.gov/national-cyber-security-awareness-month
https://staysafeonline.org/cybersecurity-awareness-month/
https://staysafeonline.org/cybersecurity-awareness-month/champions/view-all/
https://www.cisa.gov/national-cyber-security-awareness-month
https://www.shodan.io/
Black Hills Information Security: Backdoors and Breaches Incident Response Game: https://www.blackhillsinfosec.com/projects/backdoorsandbreaches/
FBI Social Media Threat Movie - The Nevernight Connection: https://www.fbi.gov/investigate/counterintelligence/the-china-threat/clearance-holders-targeted-on-social-media-nevernight-connection
On this month's Nerd Out! Security Panel Discussion, Dave Pounder hosts Joe Levy, Bridget Johnson and Travis Moran to talk about venue security and what it means in the coming months with the upcoming election and various outdoor events. The group also talks about drones, wildfires, and touches on National Insider Threat Awareness Month (https://www.cdse.edu/itawareness/index.html#0). Joe Levy is the chairman of the International Associate of Venue Managers (IAVM) Venue Safety and Security Committee. IAVM website https://www.iavm.org/ Venue Safety and Security committee contact information: [email protected] LinkedIn Profile: https://www.linkedin.com/in/joelevy1/ Travis Moran is the Vice President of Operations at Welund North America. Twitter: @dronin_on Bridget Johnson is the Managing Editor for Homeland Security Today. In addition her contributions on Homeland Security Today (hstoday.us), they are also running a series of webinars (Webinar signups, https://www.eventbrite.com/o/homeland-security-today-30028526516). Twitter: @BridgetCJ
I am joined by Shay Trembley on the third episode of The Cybersecurity Evangelist (TCE). Shay and I discuss practical tips to the question “Am I doing enough?” We begin our chat with a very real-world incident that nearly cost a small-town water utility $3.2M in fraudulent wire transfers. Then we make a quick nod to two very “human-oriented” awareness initiatives before wading in to what I am calling on this episode, “the 5 P’s of basic cybersecurity” to help make sure you ARE doing enough!
Resources discussed on this episode:
Mac Help for Mom (the content has not been updated in awhile, but is still useful for “mom” ;-) )
National Insider Threat Awareness Month
National Cyber Security Awareness Month
Sun Tzu’s The Art of War
- For more discussion on The Art of War and cybersecurity, you might enjoy this post, Sun Tzu’s ‘The Art of War’ for Cybersecurity
This month we are airing part two of the inaugural episode of The Cybersecurity Evangelist where Travis Farral and I finish demystifying cybersecurity myth #2 and #1.
Listen to find out where the term “hacking” came from, and more about different types of “hackers”…including the good ones. Travis and I also give a quick nod to our inner geek. We wrap up the discussion with how we are ALL targets of opportunity - even if we don’t have an online presence - and why it is important to overcome the “it won’t happen to me mindset.” Finally, Travis leaves us with his final thought: spend a few minutes trying to educate yourself on ways you can protect your family.
Welcome to the inaugural episode of The Cybersecurity Evangelist - a cybersecurity podcast for everyone. On the last Gate 15 Risk Roundtable (Ep 9), I eluded to following up on the topic of ransomware for this first episode. But after some deliberation, I thought a better place to start a new podcast on cybersecurity and how it is relevant to everyone, was to myth bust some commonly held beliefs. This episode is part 1 of 2, where I phish for answers by demystifying some myths with help from Travis Farral, including how cybersecurity is more than just a technology/computer problem, how increasing your cyber hygiene and security posture does not have to cost a lot of money, and how easy it is to buy a kit or an application if you are looking to launch your miscreant career! Some great resources mentioned in today's episode to help you understand more about the cyber threats that we all face everyday and to help you increase your cyber hygiene include:
Verizon's Data Breach Investigation Report (DBIR)
Center for Internet Security (CIS) Critical Security Controls
En liten tjänst av I'm With Friends. Finns även på engelska.