Transcript
A (0:00)
This is Rich Drofalino with the Department of no. Janet Hines, the CISO over at ChedMed. Gotta ask, what is your priority this week?
B (0:09)
So my priority is AI security awareness and not using AI for security awareness. But we put this very powerful tool into all of our employees hands and we really need to raise their awareness about what they can and should or should not do.
A (0:25)
I feel like everyone is simultaneously figuring out what that means in real time and I would love to hear like I want the debrief of how that goes because I think we're all trying to figure that out in real time. That's awesome. Tczakowski, the head of IT and security at Opendoor. Gotta ask, what is your priority this week?
C (0:43)
Well, it's Friday, right? We just finished it. We did a huge technology migration that touches every piece of internal corporate infrastructure. So we landed it. It went great, no hiccups. So it's to relax over the weekend. Come back next week and start to digest what this new infrastructure means for our practices going forward.
A (1:07)
I like that it's taking a moment to recharge the batteries and a job well done. I think we don't talk enough about that. That's awesome. Love to hear it and I hope it is a restful weekend for you at least. Right after this, Producer Josh let's run that open and get into the show
C (1:25)
from the CISO series.
A (1:27)
It's Department of no. Yes, indeed, indeed, it is the department of no. Welcome all watching live or later. Appreciate having you here for your virtual Friday strategy meeting. Our sponsor for today helping us make the show possible is Guard Square. We'll talk about them more in a little bit here. Remember, you can get involved in the live chat on YouTube. We stream there every Friday at 4pm so make sure if you're listening to this later, join us next week. Or you can send an electronic mail. It's a new type of correspondence feedbackiso series.com. we had to drop a story today that involved POP3 mail and I was very disappointed because when do you get to talk about pop3mail? So just know post office protocol. You are always in my heart. Quick, before we get into the show, just let everybody know that the opinions expressed by our wonderful guests are in fact their own, not necessarily those of their employers. Let's get started with our no or no segment. This is where there's so much news of the week. We need to get down to brass tacks. Is this something that you want to know about that you need to bring to your team or is this maybe more noise than signal here. First up here critical cPanel and WHM bug exploited as a zero day experts are warning about a critical authentication ByPass vulnerability in cPanel, a Linux based web hosting control panel as well as WHM and WP Squared hosting provider. Known host which uses cPanel said was noticed successful exploits in the wild on the very day that the vulnerability was disclosed. Mazel tov cPanel released the fix on Tuesday after receiving pressures from hosting providers to give some sense of how much exposure there is here. Shodan Internet scan showed that There was approximately 1.5 million cPanel instances exposed online, and domain registrars like Namecheap and others have warned that customers may see restricted access to cPanel as part of their mitigation. C says added it to the KEV with the patch date of May 3rd so they are not recharging their batteries over the weekend. Tc, I'm going to start with you here. We've got a bug here with some wide reach. It's being actively exploded. Lots of hosts to patch. Obviously anyone using cPanel WP Squareds patch asap. I don't think I'm breaking any news there, but do you see any kind of knock on effects that you would want to know more about here or does this seem like something it's bad but we have a path to containment. There's a patch out there. What are your thoughts here?
