N2K Networks
CyberWire Daily
The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Bear prints around the Czech Foreign Ministry. Tinker, tailor, soldier, hacker, Humpty Dumpty. Gamer forum breaches. Where in the world is Phineas Phisher? 01.02.2017 16:30
Bear prints in the Czech foreign ministry. Tinker, tailor, soldier, hacker in Moscow, with a side of Humpty Dumpty. Gamer forum data breaches go undetected for seventeen months. Credential reuse (and the limitations of human memory) are seen as a big threat to security. An IBM study throws up its hands over the state of healthcare cyber security. Trustwave's Chris Schueler reviews their latest rep...
Ransomware updates. Netgear vulnerabilities and patches. Breaking Android pattern lock. Delegated Recovery. Information operations. 31.01.2017 16:15
In today's podcast, we review some ransomware developments: the good, the bad, and the ugly. Netgear routers and the mom-and-pop dilemma. Breaking Android pattern locks. Facebook has a novel approach to password recovery. Keysight will buy Ixia, and IBM's acquisition of Agile 3 Solutions gets positive analyst reviews. Australia's Data61 innovation shop wants to go all-in for cyber. ISIS makes hay...
2017 Cyber Security Forecast [Special Editions] 31.01.2017 38:37
WWhat are you expecting in 2017 when it comes to cyber security? There are sure to be attacks like we saw last year, ransomware and botnets, IoT vulnerabilities we just didn’t see coming. And what about all of those unfilled jobs? Can automation help fill the gap? Is the board room finally going to give cyber the attention it deserves? How will president Trump affect cyber policy? Learn more about...
Russian treason arrests may be tied to espionage. ANSSI director warns of cyber jihad. Symantec remediates Shamoon 2. U.S. Cellular was not breached. 30.01.2017 13:53
In today's podcast we discuss some updates on the Russian treason arrests, with side suspicions being cast in the direction of underworld in-fighting. A principal victim of Shamoon 2 reports its recovery. IoT threats and the risk of always-on, always-listening devices. French security officials warn that cyber jihad could enlist cyber mercenaries. Cisco patches its telepresence software. Joe Carri...
LeakedSource is down. DoubleFlag's called out for bogus stolen goods. Fancy Bear is in UK, German networks. Shamoon alert in Saudi Arabia. Scamming tech support scammers. 27.01.2017 21:08
In today's podcast, we hear that LeakedSource is down, maybe for good. DoubleFlag seems to be selling bogus data on the black market. (And where, we ask, is the Ripper review? If you can't trust a criminal, who can you trust these days? Sad.) Fancy Bear is back—actually, she never really left—now snuffling at British and German networks. Saudi Arabia remains on Shamoon alert. The Dridex banking Tr...
Dark Web trading post compromised. Ransomware updates. Reactions to Risk Based Security's 2016 breach report. International cyber conflict notes, and a treason case in Russia. 26.01.2017 16:19
In today's podcast, Dark Web trading post AlphaBay looks buggy, and leaky. Some not-so-bad news on ransomware (and bravo to those Gateway City librarians). Risk Based Security's 2016 breach report says the USA is number one (but not in a good way). Sweden's armed forces recover from a cyberattack by unnamed parties. Saudi Arabia remains on high-alert for fresh infestations of Shamoon. Dan Larson f...
Cleaning ransomware out of the Play Store (but snakes still get into the walled garden, so watch your apps). Vigilantes, vulnerabilities, and industry news. 25.01.2017 16:20
In today's podcast we hear about Russia's arrest of a Kaspersky Lab threat researcher (charges are said to be unrelated to Kaspersky). Charger ransomware is detected and ejected from the Play Store. Mobile users are urged to watch their apps—too many snakes are still getting into the walled gardens. RATs evolve and return to the wild. Shamoon 2 expands its target set. A database vigilante may be o...
Shamoon and Greenbug. HummingWhale purged from Play Store. Apple patches across its product line. Leadership changes at CIA, GCHQ. Lloyds Bank incident update. Honor among thieves? Nope. 24.01.2017 13:23
In today's podcast, we discuss a report from Symantec that Shamoon may be connected to Greenbug. Google is purging HummingWhale malware from the Play Store. Apple issues a major set of patches across its product line. CIA has a new director; GCHQ's still looking for one. Yahoo!'s deal with Verizon will be delayed until April at least. Other industry M&A and venture funding news is more upbeat. Llo...
Fake news tweets (from hijackers, not opinion-makers). Ransomware. New Android Trojans. Closing in on Mirai's master? 23.01.2017 16:28
In today's podcast we discuss some fake tweets from hijacked news accounts around the time of the US Presidential transition—OurMine seems to have some at least tangential involvement. BankBot Android Trojan evolves, and Skyfin will quietly buy stuff you don't want from the Google Play Store. Sage 2.0 ransomware distributed by repurposed spam. Ill-named Dharma ransomware hits Indian pony site. Llo...
Carbanak gets trickier and more ambitious. Ransomware updates. It's beginning to look a lot like 1949 (at least from Moscow). 20.01.2017 21:24
In today's podcast, we hear about how the Carbank cyber gang is getting trickier and more ambitious. In other cybercrime news, ransomware takes off after more databases. There's a new ransomware-as-a-service offering in the black market. Emily Wilson from Terbium Labs addresses perceptions of terrorists on the dark web. Simone Petrella from CyberVista provides her perspective on cyber security wor...
France braces for election hacking. Ukrainian utility says December blackouts were hacker-induced. Finding "Fruitfly." Tracking Mirai's master. 19.01.2017 16:01
France prepares for election hacking. Ukrenergo [yook-REN-air-go] acknowledges its electrical service was hacked. Malwarebytes reports on Fruitfly, malware swarming about biomedical research facilities. Krebs believes he's found the author of Mirai. Anonymous says it's going to dox US President-elect Trump. Ben Yelin reviews your rights to privacy at the border. Nir Giller from CyberX addresses th...
Carbanak gang is back. GhostAdmin works on data theft. Trolling security researchers. M&A notes. Pardons, commutations, and extraditions. 18.01.2017 15:46
Carbanak is back, and in the cloud. GhostAdmin quietly assembles a few good bots. Malware writers troll security researchers on VirusTotal. Oracle issues a big patch; Apple is said to be preparing a smaller one. M&A activity is in the news. Australia investigates fallout from the Yahoo! breaches. Experts warn European election officials and politicians to be on the lookout for Bears. Rick Howard f...
Election influence and election security. Threats to power grids. Ransomware and phishing updates. Loyalty program risks. 17.01.2017 15:38
In today's podcast we hear warnings that electrical utilities should regard hacks of Ukraine's power grid as a wake-up call (the squirrel threat notwithstanding). Various nations work to shore up their defenses against Russian government hacking and influence operations. Russia protests its innocence, but there are some reliable reports of Fancy Bear sightings in Norway. Cyber criminals are back,...
Grid hacking in Ukraine. Cellebrite breached. WhatsApp encryption issue. EyePyramid notes. Sharing SIGINT. IG looks at FBI. Guccifer 2.0 and the ShadowBrokers take their bows. 13.01.2017 20:33
In today's podcast we get updates on grid hacking in Ukraine and the case of the EyePyramid spyware in Italy. Smartphone forensics shop Cellebrite suffers a data breach. WhatsApp appears to have an encryption issue, but most observers think it's not really a backdoor. WordPress gets eight patches. ENISA issues recommended best practices for securing connected cars. A US Justice Department IG will...
Grid hacks and influence operations. Propaganda sauce spread liberally over geese and ganders. Peace sign hacks? Hamas catphishes the IDF. 12.01.2017 14:19
In today's podcast, we hear about the arrest of an Italian brother and sister for an EyePyramid spyware crime spree that may have been in progress since 2010. Ukraine confirms that Kiev's power grid was hacked last month, and the Ukrainian government tries to tide over some influence operations of its own. Policy wonks talk information operations and some realize that such ops aren't new. The peac...
Shamoon is back, now with credentials for virtual desktops. Ukraine believes it was hacked again. Ransomware updates. Elections, investigations, and influence operations. The Pokemon threat? 11.01.2017 16:30
In today's podcast we learn that Shamoon is back, and still a nasty piece of work. Ukraine's grid was hacked again last month, probably by the same people who did it at the end of 2015. A new strain of ransomware offers a tiered extortion model (and unfortunately pretty solid encryption). France and Britain prepare for Russian election hacking. Awais Rashid from Lancaster University outlines the h...
Witch hunts and yard sales. See relationships, not dox. Rebrandings, mergers, acquisitions, and executive moves. Building anti-witch capabilities. 10.01.2017 16:14
California says a nation-state was behind the Anthem hack. The ShadowBrokers hold a yard sale (we'd pass on the malware, but if they had a nice blender out we'd consider it). WikiLeaks says it's interested in relationships, not doxing. The US FDA confirms vulnerabilities in cardiac devices. Hello Kitty gets breached. Yahoo! will become Altaba, and get new leadership. Germany and the UK study ways...
Election hacking, influence operations, and official reports. EU hacking concerns. Lawsuit over email's invention. Twitter frowns on unrequited love. Billy Bass, meet Alexa. 09.01.2017 16:22
In today's podcast we hear about the report on Russian election hacking and influence operations the US Director of National Intelligence released Friday. Election hacking? Not really, but influence operations? You bet. Robert M. Lee from Dragos Security weighs in on the report. European authorities worry about Russia inserting itself into 2017 elections. Law, and order, torts and Twitter. Emily W...
Spearphishing in industrial espionage. Ransomware gets more widespread, ruthless, and perfidious. The US Intelligence Community assures the Senate that the Russians hacked the DNC. 06.01.2017 21:07
In today's podcast, we hear about a worldwide spearphishing attack against industries in 50 countries. Ransomware is already proving as much of a problem as predicted: exposed data bases are hijacked in a turf-war among extortion gangs, and KillDisk has now appeared in ransomware kits. Investment analysts wonder if Verizon's bid for Yahoo!'s core assets will go through. Ben Yelin from the Universi...
Indiscriminate IOCs erode confidence in attributions. Official leaks erode trust in information sharing. Exploit updates. 05.01.2017 16:20
In today's podcast we hear about how indiscriminate indicators of compromise spawn fake news about a Vermont grid hack. Meanwhile, the Mounties cautiously, tentatively, investigate some odd potential IOCs at an Ontario utility. A hacker claims he pwned the FBI, but it looks like a hoax. A quick rundown of exploits currently romping in the wild—many of them involve ransomware. Rick Howard from Palo...
Hacktivists claim to perform a public service. Once and Recorded Future ransomware. Attribution controversies. Disturbing toys. 04.01.2017 15:54
In today's podcast, we hear about how some hacktivists are again turning to defacement, which they claim to be doing as a public service to raise security awareness. Recorded Future takes a close look at ransomware's likely course in 2017. ISIS exposes itself online. Attribution controversies: the Vermont hack-that-wasn't, tactical hacks in eastern Ukraine, and the FBI-NCCIC Joint Analysis Report....
Attribution issues: one story fizzles; another looks disappointingly circumstantial. Great powers jostle in cyberspace. Hacktivists resurface online. So, alas, do terrorists. 03.01.2017 15:47
In today's podcast, we follow the way in which the Vermont utility hacking story fizzled. We also hear more serious grounds for concern about electrical grid security continue from Joe Weiss of Applied Control Solutions. Observers are disappointed by the Grizzly Steppe Joint Analysis Report—its evidence strikes many as mighty circumstantial. US-Russian cyber strategies and cyber diplomacy. Anonymo...
Best of: Daniel Ennis 30.12.2016 17:15
Our podcast team is taking a break this week for the holidays. We’re revisiting some of our favorite interviews from 2016. Daniel Ennis is former director of the NSA Threat Operations Center, or NTOC, and is currently executive director of the University of Maryland Global Initiative on Cyber. We spoke with Daniel Ennis back in July. Learn more about your ad choices. Visit megaphone.fm/adchoice...
Buying Cyber Security [Special Editions] 30.12.2016 28:56
Every day there seems to be a new security product on the market, with many of them claiming they provide something that you simply can’t live without. Companies appear and disappear, and businesses are faced with difficult, confusing, and often expensive choices. In this CyberWire special edition, we explore how businesses are navigating the process of choosing products and technologies in a crow...
Best of: Tom Coale 29.12.2016 17:14
Our podcast team is taking a break this week for the holidays. We’re revisiting some of our favorite interviews from 2016. Tom Coale is an attorney with the law firm Talkin and Oh, in Maryland, where one of his specialties is representing people who have been denied security clearances. Previously, Mr. Coale was Department Counsel for the Department of Defense, representing the government in sec...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.