Billede af showet Security Bits

Security Bits

Podcast af Durgesh Kalya

engelsk

Nyheder & politik

Begrænset tilbud

2 måneder kun 19 kr.

Derefter 99 kr. / månedOpsig når som helst.

  • 20 lydbogstimer pr. måned
  • Podcasts kun på Podimo
  • Gratis podcasts
Kom i gang

Læs mere Security Bits

Have you ever wondered about getting into Cybersecurity or Information Technology? Have you wondered about the latest developments in Industrial Control Systems and Security? If you are open to learning and getting familiar with Information Security and like to get the most unique stories that matter, then Security Bits is the Podcast for you. This Podcast is also available on Video Format on YouTube. Go to https://icsbits.com/simplified for more details.

Alle episoder

10 episoder

episode Florida Water Treatment Plant Hacked, Chrome Browser Vulnerability, Security Researchers were targeted, Social Media Etiquette, CISCO’s VPN Flaws, Happy Safe Internet Day and more! cover

Florida Water Treatment Plant Hacked, Chrome Browser Vulnerability, Security Researchers were targeted, Social Media Etiquette, CISCO’s VPN Flaws, Happy Safe Internet Day and more!

Hello and welcome to Simplified Security bits Episode Number 7. I am your host, Durgesh and today is Feb 9th 2021, coming to you straight from Houston Texas.  Today is Safe Internet Day. Celebrated around the world. In the US, you can find more information for more information on how you can get involved and spread the word by going to https://saferinternetday.us/ [https://saferinternetday.us/] Tags: Podcast, Cybersecurity Podcast, Durgesh Kalya, Simplified Security,  The Florida Water Treatment Plant was hacked and the attacker managed to increase the amount of Sodium Hydroxide levels from 100 parts per million to 11,100 parts per million. The attacker was able to compromise the remote access system and managed to change parameters for the lye component. This is the worst case scenario for Industrial Control Systems which could have led to a dangerous situation. An operator was able to spot the increase in levels and was able to turn it down.  https://www.nbcnews.com/tech/security/florida-near-miss-cybersecurity-worst-case-scenario-n1257091 [https://www.nbcnews.com/tech/security/florida-near-miss-cybersecurity-worst-case-scenario-n1257091] Project Zero Team at Google have found a zero day bug on Chrome, Which is being actively exploited and you need to update your browser now. Both Chrome and Edge browsers use the Chromium Engine. So patch now. Simply go to your browser, and click About to initiate the update.  https://nakedsecurity.sophos.com/2021/02/05/chrome-zero-day-browser-bug-found-patch-now/ [https://nakedsecurity.sophos.com/2021/02/05/chrome-zero-day-browser-bug-found-patch-now/]  Cisco reported several vulnerabilities which are tracked in various CVEs. The vulnerabilities allow an unauthenticated, remote attacker to execute arbitrary code as the root user on an affected device. Patch them Routers Now!   https://thehackernews.com/2021/02/critical-flaws-reported-in-cisco-vpn.html [https://thehackernews.com/2021/02/critical-flaws-reported-in-cisco-vpn.html]  Google bans the Spanish Certificate Authority (CA) -Camerfirma. CAs In cryptography are certification authority is an entity that issues digital certificates. While this is nothing new, in the past major browsers have issued warnings and requested CAs to fix issues with verification and validation of certificates. The result is that the websites and services that use certificates that were issued by Camerfirma will start to get flagged on Chrome browsers and will start showing a Certificate Error with the release of the new browser version Chrome 90 which will be available in April of 2021. https://www.zdnet.com/article/google-bans-another-misbehaving-ca-from-chrome/ [https://www.zdnet.com/article/google-bans-another-misbehaving-ca-from-chrome/] Google and Microsoft have reported various instances of ongoing attacks on security researchers. Microsoft has outlined the threat actors behind this targeted attack in their security blog. They attribute the attacks to a group called ZINC. More information is in the show notes.  https://www.microsoft.com/security/blog/2021/01/28/zinc-attacks-against-security-researchers/ [https://www.microsoft.com/security/blog/2021/01/28/zinc-attacks-against-security-researchers/] Facebook etiquette: I am always keen to learn more about how one can improve our interactions and behaviors that can benefit the society as a whole. When it is really at a click of a button you can send communication across the wire and increasingly with very little thought or consequence. As today is Safe Internet Day, I wanted to feature an article written by ESET security blogger Amer Owaida. He very beautifully outlines some of the strategies to apply to strengthen your privacy, security and most importantly to remember the famous Vegas Line,  what happens on the internet stays on the internet. Link is in the show notes. https://www.welivesecurity.com/2021/02/04/facebook-etiquette-behaviors-avoid/ [https://www.welivesecurity.com/2021/02/04/facebook-etiquette-behaviors-avoid/] That is it for this episode. Please provide me your feedback by reaching out on my twitter @durgeshkalya. All the links to anything I have discussed in this episode is in the show notes of this podcast. Make sure you subscribe to simplified security episodes available as podcast and on YouTube. Go to icsbits.com/simplified for more details. I am your host Durgesh Kalya. Catch me on my next episode on your favorite podcast app or YouTube, until then be safe and think before you click.

9. feb. 2021 - 4 min
episode Covid 19 Vaccine Info Leaks, Siemens releases multiple vulnerabilities, Ubiquiti tells its users to secure their account and more! cover

Covid 19 Vaccine Info Leaks, Siemens releases multiple vulnerabilities, Ubiquiti tells its users to secure their account and more!

Simplified Security - E6 - Covid 19 Vaccine Info Leaks, Siemens releases multiple vulnerabilities, Ubiquiti tells its users to secure their account and more! Headlines: Leaked information surfaces from the December attack on European Medicines Agency on COVID-19 Vaccine. EMA Original Post: https://www.ema.europa.eu/en/news/cyberattack-european-medicines-agency [https://www.ema.europa.eu/en/news/cyberattack-european-medicines-agency] Bleeping Computer’s Post https://www.bleepingcomputer.com/news/security/hackers-leak-stolen-pfizer-covid-19-vaccine-data-online/ [https://www.bleepingcomputer.com/news/security/hackers-leak-stolen-pfizer-covid-19-vaccine-data-online/]  Siemens releases multiple Vulnerabilities in Web Server for Scalance X Products and Solid Edge. Siemens Scalance X Advisory: https://cert-portal.siemens.com/productcert/pdf/ssa-139628.pdf [https://cert-portal.siemens.com/productcert/pdf/ssa-139628.pdf]  Siemens Solid Edge Advisory: https://cert-portal.siemens.com/productcert/txt/ssa-979834.txt [https://cert-portal.siemens.com/productcert/txt/ssa-979834.txt]  SEPA, Scottish Environment Protection Agency attacked on Christmas Eve. https://www.sepa.org.uk/about-us/cyber-attack/ [https://www.sepa.org.uk/about-us/cyber-attack/]  Ubiquiti News,   https://community.ui.com/questions/Account-Notification/96467115-49b5-4dd6-9517-f8cdbf6906f3 [https://community.ui.com/questions/Account-Notification/96467115-49b5-4dd6-9517-f8cdbf6906f3]  Naked Security article for Homeschooling and how to stay secure. https://nakedsecurity.sophos.com/2021/01/13/home-schooling-how-to-stay-secure/ [https://nakedsecurity.sophos.com/2021/01/13/home-schooling-how-to-stay-secure/]  Symantec, Threat Intelligence Blog article on Solar Winds Attack. https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence [https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence]  --- Connect with me: Simply follow me on LinkedIn [https://www.linkedin.com/in/durgeshkalya/] or Twitter [https://twitter.com/durgeshkalya]. Subscribe to my Podcast Simplified Security: Google Podcast https://podcasts.google.com/feed/aHR0cHM6Ly9mZWVkcy5zb3VuZGVyLmZtLzk3NTgvcnNzLnhtbA [https://podcasts.google.com/feed/aHR0cHM6Ly9mZWVkcy5zb3VuZGVyLmZtLzk3NTgvcnNzLnhtbA]  Apple Podcast https://podcasts.apple.com/us/podcast/security-bits/id1542309317 [https://podcasts.apple.com/us/podcast/security-bits/id1542309317]  For all other platforms such as Spotify, TuneIn, Amazon, Go to  https://icsbits.com/simplified/ [https://icsbits.com/simplified/]  Do not forget to Subscribe to my YouTube Channel and Enable Notifications: https://www.youtube.com/channel/UC9gRPRXg3s3ZPZZafouzOWA?sub_confirmation=1 [https://www.youtube.com/channel/UC9gRPRXg3s3ZPZZafouzOWA?sub_confirmation=1]

23. jan. 2021 - 5 min
episode Simplified Security Bits - Ticketmaster agrees to pay $10 million to Crowdsurge, Microsoft release details on SolarWinds Hack, Veritas released a handful of CVEs and Free Boot camp for CISSP Candidates and more! cover

Simplified Security Bits - Ticketmaster agrees to pay $10 million to Crowdsurge, Microsoft release details on SolarWinds Hack, Veritas released a handful of CVEs and Free Boot camp for CISSP Candidates and more!

Public document from the court TicketMaster Lawsuit: https://www.justice.gov/usao-edny/pr/ticketmaster-pays-10-million-criminal-fine-intrusions-competitor-s-computer-systems-0 [https://www.justice.gov/usao-edny/pr/ticketmaster-pays-10-million-criminal-fine-intrusions-competitor-s-computer-systems-0]  What is Egregor? https://www.trendmicro.com/en_us/research/20/l/egregor-ransomware-launches-string-of-high-profile-attacks-to-en.html [https://www.trendmicro.com/en_us/research/20/l/egregor-ransomware-launches-string-of-high-profile-attacks-to-en.html]  Veritas Advisory: https://www.veritas.com/content/support/en_US/security [https://www.veritas.com/content/support/en_US/security] SANs institute is offering a Free Virtual Summit: https://www.sans.org/event/ics-security-summit-2021?utm_medium=Social&utm_source=LinkedIn&utm_content=ICS+Summit+Training+December+2020&utm_campaign=SANS+Solution+Forum+Vendor [https://www.sans.org/event/ics-security-summit-2021?utm_campaign=SANS+Solution+Forum+Vendor&utm_content=ICS+Summit+Training+December+2020&utm_medium=Social&utm_source=LinkedIn] Join the Certification Station Discord Group here: https://discord.gg/cD2EgtyQ [https://discord.gg/cD2EgtyQ] New to Discord and this community? Check out this video to get started:: https://youtu.be/le_CE--Mnvs [https://youtu.be/le_CE--Mnvs]  --- Connect with me: Simply follow me on LinkedIn [https://www.linkedin.com/in/durgeshkalya/] or Twitter [https://twitter.com/durgeshkalya]. Subscribe to my Podcast Simplified Security: Google Podcast https://podcasts.google.com/feed/aHR0cHM6Ly9mZWVkcy5zb3VuZGVyLmZtLzk3NTgvcnNzLnhtbA [https://podcasts.google.com/feed/aHR0cHM6Ly9mZWVkcy5zb3VuZGVyLmZtLzk3NTgvcnNzLnhtbA]  Apple Podcast https://podcasts.apple.com/us/podcast/security-bits/id1542309317 [https://podcasts.apple.com/us/podcast/security-bits/id1542309317]  For all other platforms such as Spotify, Tune IN, Amazon, Go to https://icsbits.com/simplified/ [https://icsbits.com/simplified/]  Do not forget to Subscribe to my YouTube Channel and Enable Notifications: https://www.youtube.com/channel/UC9gRPRXg3s3ZPZZafouzOWA?sub_confirmation=1 [https://www.youtube.com/channel/UC9gRPRXg3s3ZPZZafouzOWA?sub_confirmation=1]

7. jan. 2021 - 10 min
En fantastisk app med et enormt stort udvalg af spændende podcasts. Podimo formår virkelig at lave godt indhold, der takler de lidt mere svære emner. At der så også er lydbøger oveni til en billig pris, gør at det er blevet min favorit app.
En fantastisk app med et enormt stort udvalg af spændende podcasts. Podimo formår virkelig at lave godt indhold, der takler de lidt mere svære emner. At der så også er lydbøger oveni til en billig pris, gør at det er blevet min favorit app.
Rigtig god tjeneste med gode eksklusive podcasts og derudover et kæmpe udvalg af podcasts og lydbøger. Kan varmt anbefales, om ikke andet så udelukkende pga Dårligdommerne, Klovn podcast, Hakkedrengene og Han duo 😁 👍
Podimo er blevet uundværlig! Til lange bilture, hverdagen, rengøringen og i det hele taget, når man trænger til lidt adspredelse.

Vælg dit abonnement

Mest populære

Begrænset tilbud

Premium

20 timers lydbøger

  • Podcasts kun på Podimo

  • Ingen reklamer i podcasts fra Podimo

  • Opsig når som helst

2 måneder kun 19 kr.
Derefter 99 kr. / måned

Kom i gang

Premium Plus

100 timers lydbøger

  • Podcasts kun på Podimo

  • Ingen reklamer i podcasts fra Podimo

  • Opsig når som helst

Prøv gratis i 7 dage
Derefter 129 kr. / måned

Prøv gratis

Kun på Podimo

Populære lydbøger

Kom i gang

2 måneder kun 19 kr. Derefter 99 kr. / måned. Opsig når som helst.