
Loading summary
Rich
From the CISO series, it's Cybersecurity Headlines. Cybersecurity firm CEO charged with installing malware on hospital systems. Cloudflare sees a big jump in DDoS attacks and the FBI, they want your help with Salt Typhoon. These are some of the stories that my colleagues and I have selected from this past week's cybersecurity headlines. And now we're looking for some insight opinion and expertise from our returning guest making his triumphant second appearance, DJ Schlien, head of security, oh, over at Boats Group. Dj, thanks for being here. I gotta ask, how was your week in cybersecurity?
DJ Schlien
My week was awesome, Rich. Thanks for having me back on the show. There's nothing like a bunch of good global incidents to keep you on your toes, right? So definitely looking forward to talking about these topics today. We got a good, good list of articles to look through.
Rich
Yeah, if, if I can get just like one good spit take out of a CISO in the course of this show, that's really or in the course of the headlines in the week, that's really all we can ask for as producers of this show. So I am thrilled to have you on here helping keep the reflexes nice and fast here. Also helping us out here today is our sponsor for today, Threat Locker Zero Trust Endpoint protection platform. Remember, you can join us on YouTube live. To do so, go to cisoseries.com, hit the events dropdown and look for the Cybersecurity Headlines weekend review image. You can contribute your comments. You don't contribute our comments. Contribute your comments in the chat. Like, I already see CCL getting busy in the chat room. We want lots of other people to join them in there and help us make the show better. Can't wait to see you there. Before we jump into the news, just a quick reminder that all of DJs opinions are in fact his own, not necessarily those of his employer, staff, affiliates, family, friends or indeed enemies. Let's just be clear, DJ. We've got about 20 minutes, so let's get get started. First up here. This one was, I saw this one was blowing up on the cybersecurity subreddit here. Cybersecurity firm CEO charged with installing malware on hospital systems. Jeffrey Bowie is CEO of the cybersecurity firm Veritico. That's the only way other way to pronounce it is veri taco. So I'm going to give it the more the more charitable Veritico, regardless of how it's pronounced. He is now facing two counts of Violating Oklahoma's Computer Crimes act for allegedly infecting employee computers at the Oklahoma City St. Anthony Hospital on August 6, 2024. He was arrested in April based on security footage showing a man attempting to access multiple offices. The malware was designed to capture screenshots every 20 minutes and then transmit them to an external IP address. Officials have stated that no patient data was accessed in this action. DJ There are always going to be some bad apples in any profession, but this makes it harder for customers, for users to trust the people in charge of their data. Hey, it's not just Microsoft Recall. Who knew you selected this story as one to discuss what strikes you about it?
DJ Schlien
Well, first off, I can't believe it. First, what's his motive and intent? This guy's the CEO of this security company. He's walking in and installing it. Was it an exercise? Was it something that was preplanned? Did he take it too far? There's a lot that's in that story that's still developing. So that's what I love about watching this show is like, we get the latest and greatest news and it's always developing. But two points on this. One is he's using phishing to go through and social pretext when he's getting encountered by people on the floor as he's walking from room to room in the hospital trying to infect these machines.
Rich
Gosh.
DJ Schlien
Like if he's a vendor of this company, of the hospital, did they vet the vendor? How good is our vetting process? So it brings in a bunch of different security issues. For me, it's the physical security, it's the hardware security. Are your machines locked? There's so many questions that come out of it. I do like that he was encountered by one of the employees who didn't recognize him, which shows that there's people on the lookout. But it makes me scared, especially when someone's walking freely around a hospital trying to infect machines and using the excuse that his daughter's in the ER room. That was an interesting one.
Rich
Yeah. That's where it goes from. Okay, We've all seen the story of, like, pen tester. You know, they call the cops on a pen tester or something like that. Right. Like there are scenarios where there's a lack of communication maybe or something like that. But this has all of, like the red flags, doesn't pass the smell test. Now we will see more, you know, details come out of this. We will keep providing updates for that as relevant on cyber security headlines. But yeah, there's. There's A lot head scratchers and. Yeah, that, that, yeah. Telling stories about family members to. To get access and stuff like that.
DJ Schlien
That's.
Rich
That goes into the creep line for sure.
DJ Schlien
It's, you know, there's no ethics sometimes in unethical hacking. Right.
Rich
So, yeah, a good point to. Yeah, well, yes, yes. If you're acting unethically, then everything's on the table for sure.
DJ Schlien
Most don't make appointments either. Right. So always be prepared.
Rich
This is. Yes, hopefully. I mean, the only silver line to this is hopefully the hospital system or anybody like, seeing the story can be like, okay, how can we learn from this? Right. Maybe lock down the terminals in the room. Let's revisit a lot of our security practices. It doesn't help, but it's coming from your security provider or something like that. But yeah, definitely a lot to think about on that one.
DJ Schlien
Yeah. Look at the risk of what industry you're in and where your risk points are. In that case, lock down your USB ports, make sure your machines auto lock when you walk away from them. You've got the technology to do this kind of stuff. Seems like they found out what was going on pretty quickly. But you can always be better and especially expect the unexpected sometimes. Right?
Rich
Absolutely, absolutely. Speaking of unexpected, Cloudflare sees a big jump in DDoS attacks. Cloudflare's Q1 DDoS report disclosed that the company mitigated 20.5 million DDoS attacks in the quarter in Q1. That's compared to 21.3 million DDoS attacks it mitigated in all of 2024, which notably has four quarters. The Q1 figure is up 358% on the year and up almost 200% compared to Q4. For 2024 numbers, attacks on Cloudflare accounted for 32% of that Q1 figure. So, you know, a lot of that number coming from a single target. Understandably, Cloudflare network layer attacks accounted for this huge spike, especially attacks using connectionless Lightweight Directory Access Protocol, or cldap, and encapsulating Security Payload, or ESP floods. Cloudflare also saw over 700 attacks with at least 1 terabit of bandwidth per second, which is a lot. So, DJ, big numbers here, what is the significance of using protocols like CLDAP and esp, I guess. What do people need to know about these in terms of a DDoS attack?
DJ Schlien
Well, you know, first off, when I saw this article, I was like, what is a cl? What's esp? You know, it's like constantly learning about new technology. So you know, one of the key takeaways is always be up to date on the new attack vectors that are coming in. The CLDAP vulnerability was an amplification attack, which was sort of interesting. You take a small request and it just amplifies it every time it goes through. And eventually these things are just massive amounts of volume coming in. It doesn't surprise me that ddos is on the rise, but when I looked at this article, I was blown away. I was like, that's almost like 2x of what it was last year. So, you know, it tells me, as you know someone who's in security, like, I really got to ensure that the perimeter of all of the properties that we have are protected from ddos. You know, I was thinking about a good analogy to use for this, and this is like, you know, if you don't have DDoS protection, it's like leaving a screen door open in the middle of a hot summer day and let the mosquitoes come in. Like it's. You, you're gonna get bit, right? It's. And you're gonna spend a lot of money too. If you're getting your edge hit and you're serving a lot of traffic. Definitely hardening, you know, hardening is the thing that you gotta do with, with these, understand the attack vectors. You know, I was thinking about, especially with Cloudflare, like, you know, managed rules. You know, a lot of, a lot of vendors who provide DDoS protection have managed rules where they'll, they'll be able to mitigate some of these new attack vectors and the things that you're not necessarily aware of. This is really important to understand the offerings of your vendors as well as some of the attacks that are coming out.
Rich
Yeah, that's one of the things that stood out to me over the years with these reports from Cloudtra and with other vendors too, but specifically with the DDoS attacks. Really seeing how fast that, I guess, industry of DDoS attacks has shifted in terms of tactics, in terms of traditionally all of this coming from botnets and now increasingly coming from cloud providers attacking the network layer. How quickly that can shift in terms of the order of magnitude as well, just completely shifting over the last couple of years. That can be tough to keep an eye on too. Definitely make sure you're aware of one, that you have some sort of protection. Not advocating for cloudflare here, but and to making sure you know what you're paying for, what services are available out there. For sure. Yeah, you gotta, you got, you gotta have something out there because it's it's getting pretty nasty out there.
DJ Schlien
It is, absolutely. Get the, get the umbrella and protect yourself from those hail storms.
Rich
Get your. Yeah, your. Well, I won't say I can't raid. I don't know what mosquitoes pick it. Was that something I saw in a drive in one time? It's like a little coil.
DJ Schlien
I think it's deet. Oh, I haven't seen those coils in a long time.
Rich
Let's not, let's not use citronella. Yeah, there you go.
DJ Schlien
Sure. Why not?
Rich
Okay, next up here, the FBI wants your help with Salt Typhoon. The Federal Bureau of Investigation has released a public service announcement asking the public to come forward with any actionable intelligence about the China linked threat actor Salt Typhoon, which as we all know was seen accessing US Telecommunications companies back in November. Big, huge campaign, huge story we covered on the show. In addition, the U.S. department of State's Reward for Justice is offering up to $10 million in reward for any information on a foreign state linked threat actor targeting US Critical infrastructure. Doesn't have to be Salt Typhoon. I'm sure they wouldn't mind if it was. Dj I guess just broadly, is this a good thing to be putting out there by the FBI? Does this shine a good light? Hey, let's raise the tide. We'll rise all boats here. Or is this, I don't know, maybe a bad light for the FBI's brand? Would such a campaign, I guess also maybe open up to, to fraud, to kind of false leads, that kind of stuff? $10 million is a lot of motivation. Well, that's 10 million reasons why I.
DJ Schlien
Don'T have to do things illegally. Right. Go down the hey, let's snitch route, I guess you could say. But you know, from the FBI perspective, I think bringing the conversation mainstream, it's a good thing. I think there's definitely pros and cons and I'm pretty certain that a lot of that's been weighed when the decision was made to actually come out and bring this reward to bear. My concern, is it going to result in a flood of reports and tips that are coming in. One of the biggest things that we've seen on the media is disinformation campaigns and false truths. How much of that is going to be, you know, a social engineering disinformation campaign from our adversaries or national adversaries trying to divert attention away from the true, you know, the, the true attackers, the true state, nation, state actors. So I think it's up in the air there, but you know, maybe the FBI hit a bit of a wall in their investigations opening it up, looking for some help. We can look at it a bunch of different ways.
Rich
I'll put the shoe on the other foot. This could be a false information campaign by the FBI to make people think that they, you know, like once you start talking about disinformation in terms of, you don't realize, I guess I'm constantly have to remind myself how incredibly sophisticated these operations when you hit the nation state level can be in terms of the resources they can do, the amount of disinformation or counter information or counter intel or whatever you want to call it can be in any of these situations. So and on both sides of the equations, right, no side is stationary in this regard. It's, you know, what we see publicly is probably a relatively small sliver, admittedly Salt Typhoon big giant story. I hope they get some information as a result of this. But I always have to remind myself of that. We only have a very narrow window into a lot of this surreptitious work that's going on between these two nation state actors for sure. Before I move on to our next story, I have to spend a few moments and thank our sponsor for today, ThreatLocker. ThreatLocker is a global leader in zero trust endpoint security, offering cybersecurity controls to protect businesses from zero day attacks and ransomware. ThreatLocker operates with a default deny approach to reduce the attack surface and mitigate potential cyber vulnerabilities. To learn more and start your free trial, visit threatlocker.com CISO that's T H R E A T L O C K E R All right, next up here, House passes Bill to Study Routers National Security Risks the US House of Representatives passed the Routers act which mandates the Department of Commerce to study national security risks posed by routers and modems controlled by foreign adversaries, especially not surprisingly, China. This builds on previous efforts to remove untrusted equipment following cybersecurity threats such as the aforementioned Salt Typhoon. But there's kind of been an ongoing effort to remove foreign made telecommunications equipment since at least 2016. DJ for many people, talking about routers is much like talking about vacuum cleaners. A little on the boring side, but they are a primary attack point simply because most people have no idea how to configure a password on a home router. And even if you do, your firmware might not be up to date. It's a set it and forget it. We think of kind of device for a lot of people. Then there's the whole issue of buying from China when we are not supposed to be buying from China, but we all need routers. And hey, it turns out they at least up until now, were cheap. Curious, what's your take on this?
DJ Schlien
Well, first, I love the comparison of routers to vacuum cleaners.
Rich
Everybody needs one.
DJ Schlien
Yeah, everybody needs one. And, you know, I'm just, I was in my head, I was like, is there a smart vacuum? Like, can we wi fi enable our vacuums? Oh, roombas.
Rich
I guess you can, absolutely.
DJ Schlien
But, you know, when we're talking about devices that we use at home, that's any device, like an IoT device. It could be something on the wall, could be your smart fridge, smart dishwasher, whatever it might be. You know, I got a couple of concerns here, but first, I'm really glad the government's getting involved in this. You know, routers, the acronym. When I was reading the article, I was like, wow, that's a clever acronym. Somebody had to think really hard for that, you know. But reading through the article, it was really interesting that there's this push to help protect from, you know, nation states or, you know, nations like manufacturers. But manufacturers can really be anywhere. I, I hope it's broad enough that it's, it's not necessarily looking at what one specific region is doing. It's looking at all hardware from all manufacturers. Because it's like trust and verify, right? Like, we could be making vulnerable hardware and BIOS software here and in the United States for all that matters. Yeah. Our. It is this box, right, that you put in your house. I configure mine to the nines. Some people might not even know what their password is, or they might use wps, God forbid, to authenticate their printers or something like that. But I think there's going to be a bigger issue that comes out of this investigation and this deep dive into these manufacturers and the processes, again, software, bill of materials are going to come into this, where you're looking at the hardware, you're looking at, at the versions of components that are in those routers, where they're coming from, but the software, like we haven't even figured out as a society how to patch a lot of these wireless smart plugs. We have much less anything else. Even if we do find an issue or a vulnerability, how are we going to update the public and ensure that we don't have botnets sparking up on our routers? Right.
Rich
Yeah, that's the thing I always think of is like, if, if I gave If I said I will give you $100 if you upgrade the firmware on your router, I'm not sure how many people I know would I would have to pay, like quite honestly, like, I'm sure there's a bunch of people that motivated could figure it out. But if you give them just a vague oh, hey, one, how do you even let them know? Because unless you're like, like a D link superfan, like are you getting what security notifications are you even getting from your hardware to begin with? And so like there's a, just outside of that, like consumer facing part of that. And then on top of that, the very complicated, you know, kind of supply chain. You're absolutely right. From wherever the routers are going to be, but wherever those chips are coming from, you know, are you using open firmware? Are you using, you know, is it all proprietary? What kind of visibility do we even have into that? Our producer Steve is a dealing super fan. So Steve, I'm glad you're getting those notifications for everybody that's out there. That's great. But yes, I am very interested to see what kind of comes out of there and then what are the legislative responses to that. Right. Because it seems like the response would be we should regulate this or set standards or something like that. I don't know what the will for that we've seen in the UK they've made some very meaningful and in the EU that made some very meaningful steps to regulating and setting IoT security standards, software update standards and that kind of stuff. If we'll see the same kind of response in the US that is an open question.
DJ Schlien
Yeah, absolutely. I think the biggest question is like, how do we regulate consumer trust, you know, or how do we build consumer trust and do regulations address that? You know, the. We'll see how this story evolves too, which is, you know, we're at the, at the start of this. It's going to be interesting to see how this happens. But again, having having some oversight and some eyes looking into this on behalf of the consumer, I think is a very positive way to go.
Rich
Schmooze doesn't in our chat, does not seem very positive. He says Congress isn't aware that Lenovo thinkpads are a Chinese company. Oh, schmooze. How dare you be cynical? How dare you. Oh man.
DJ Schlien
I'm sure that it hasn't like lit on fire with a whole bunch of like, well, we don't have that government organization anymore, so now what do we do? Right.
Rich
Well, just we'll just unbundle that acquisition and we'll go back to IBM. I'm sure it'll all go great. Our next story here. Maryland man pleads guilty to outsourcing U.S. government work to a foreign national. The individual is a Vietnamese born naturalized US Citizen who applied for a job with a US Government software contractor that was seeking a Full Stack web developer. The individual participated in multiple job interviews to land the position, then worked on a software development contract for the Federal Aviation Administration. He then installed remote access software on a company issued laptop, allowing the developer access from China between March and July of 2023 while masking the user's location. He has admitted to similar frauds targeting at least 13 U.S. companies between 2021 and 2024 and is due to be sentenced in August and could face up to 20 years in prison. You know DJ, almost every show there's a story where I feel like I have to look over my metaphorical glasses and my Aqualine profile in a school army style. This seems to be the one lowering these. Now there appears to be several internal security lapses in this story. If the Daily show covered cybersecurity more, I could see Jon Stewart staring at the camera while he crushes his cup of coffee. I'm curious, what's your take on this.
DJ Schlien
In this one here? This isn't necessarily smash worthy for me, but this is definitely spit my coffee out because I can't believe this is actually happening. Unfortunately. It's not the first time I've heard about this kind of thing though. I know it's a big concern. In some of the past companies I've been at, you know, hiring international or hiring just even in the COVID age doesn't even really matter, right? Like, you know, we have people working remote now. Gosh, I I worked at a couple companies where I never met one person that in person that I worked with. It was all on screen. There's the world is changing quick, quickly and when I hear about something like this I'm like, man A, that takes a lot of guts to do it takes a lot of orchestration to do. This is like social engineering at its finest when it comes to you're socially engineering your HR department to get hired. But this kind of story is the kind of thing that brings to light the results or the things that can happen when somebody is allowed into your infrastructure and your ecosystem that shouldn't be there. Like secret data leaked to nation states that you don't want them, don't want them to have competition. Having competition gosh imagine if you're running a company A and company B makes the same product as you have, and you just hired somebody from company, baby, it's the same kind of thing, right? You're letting somebody into your ecosystem. I was looking through that and thinking, like, how would I protect against this? Well, definitely background checks, lots of vetting, meet people in person. I saw a article on buzzfeed a while back that somebody participated in an interview, a video interview, and, you know, interviewed a potential employee. They hired that employee, they were introduced to that employee at the office when they were hired, and they're like, this is not the person that I interviewed. Definitely speak up if you see things like that. So tell your HR department. But, you know, just make sure you have some of your processes defined in place. Also make sure that your endpoints, you know, if you're looking at data loss, having a VPN connection, you know, if you're expecting it to be in one Geo and it's coming from another into your, into your development environments, you know, there's red flags. Watch out for that stuff.
Rich
And to do that at 13 companies, it's one thing. It's like, okay, our insider threat program wasn't very mature and yeah, we weren't monitoring this kind of stuff. It is not just one company, you know, not to shame any. Like this clearly is a much wider problem that this per, you know, this individual was able to essentially perform the same scheme over and over again without raising any red flags up until this point. So, you know, again, not, not shaming any one particular company. Clearly just a wider problem of, of trust when it comes to, to remote employees and that kind of stuff.
DJ Schlien
Yeah, it's just having visibility into the, the fact that these kind of things happen. Right. You know, and again, as you said, nothing against the 13 companies, because I bet you each one of those 13 companies, and probably every company has phishing problems where people still click on links right when they shouldn't in their email. So again, it's understanding the problems that are there, keeping your pulse on the industry and the markets, and really understanding what your threats are.
Rich
All right, our last story of today, that Windows folder in NetPub might be a problem after all. Two Mondays ago, we reported on an issue following Patch Tuesday in which a new empty folder had been created on Windows subscribers hard drives. Microsoft issued a statement telling users the folder was part of a fix for a Windows process activation elevation of privilege vulnerability and that it should not be removed. However, cybersecurity expert Kevin Beaumont says he's Discovered that this fix introduces a denial of service vulnerability in the Windows servicing stack that allows non admin users to stop all future Windows security updates. Which last time I checked my notes, bad. So dj, does your spidey sense react to the story at all? Is there not something disturbing about a mystery folder that clearly has a weakness being installed without consent on millions of computers or normal?
DJ Schlien
You know what? This is where I would smash that coffee cup Rich.
Rich
I only have ceramic here. I'm sorry, I don't want to ruin it.
DJ Schlien
Yeah, I'm looking at a bunch of different stuff. I might throw my keyboard or something like that or you know first off, I can't get over the fact that people are still hosting websites on Windows machines in the day of ephemeral small workloads. I could go down a whole rabbit hole with this one. Right? Teach their own. But like, like come on. Even beyond what my personal opinions are about what you should host, your websites are on reading through this article, it was classified as a medium vulnerability or medium issue. And anything where you can have a user that's unprivileged create a junction. Which I was like what? You can do that in Windows and all of a sudden disrupt your Windows updates? Now all of a sudden your endpoint detection software is not going to work. You're not going to be able to push out patches to your machines. It's going to be disruptive to any IT organization who's trying to manage a large fleet of machines. So to me that's a big issue. And if I'm looking at this and saying okay, what's the risk here? Well a can I push my people away from Windows machines in a harmoniously awesome world of rainbows and unicorns? Let's go. But again, this kind of thing is to each their own. Pick your poison of what you want to do, but minimum footprint. Make sure you understand these kind of issues and how you can remediate them and make sure people aren't locking their machines up so that they can't get updates.
Rich
Yeah, that's worked. Again, a non privileged user to be able to do that is. It ain't great. It ain't great.
DJ Schlien
That's like uber root, right? Unprivileged user just means uber root.
Rich
Yeah, if you just type that in and you type uber root backwards, that's the password for that. All your Linux admins will love you for that. Next, before we get out of here, I just want to give a big thank you to all of our commenters helping us make the show better. I always love when I see CCL in the chat was sharing ship often fail early. Really just wisdom that I always, you know, I always love to see ccl. Thank you so much for that and schmooze helping us stay cynical when it comes to laptop manufacturers potentially. And Kevin Farrell just wishing us all Happy Friday. Kevin, you help make my Friday better. Thank you so much. Before we get out of here, DJ for you, was there any story that was a thumbs up or an eye roller for you?
DJ Schlien
Well, I think all those stories were thumbs up ones. Definitely must reads. I encourage folks to, you know the plane Rhino from rsa.
Rich
Yeah, you know we're getting over the con crud. You have a lot of reading material while you recuperate.
DJ Schlien
You got it. And definitely look into it. The the eye roller was man, I thought we were over Windows server hosting. But anyway.
Rich
Someday, someday we'll cover that. We'll bury it with IE6 someday, I'm sure.
DJ Schlien
Oh my God. Yeah, that's still around too. It's still around.
Rich
DJ Shaleen, head of security over at Boats Group, thank you so so much for being here. For lending your wisdom, your expertise, your wit even. Truly, truly appreciated. Where can people find you on the cyberspace if they are so inclined?
DJ Schlien
Well, I'm on Bluesky now. Closed up the Twitter account. So if you're looking for me there, you're gonna be looking at a ghost town. So come find me on Blue Sky. Definitely hit me up on LinkedIn if you want to chat. Always willing to give my 2 cents and my opinions and you know we got a lot of really cool things in the cyberspace coming up this year and with AI my gosh, the there's a lot to talk about. So please reach out to me if you want to talk about anything and dig in deeper to these topics that we talked about today.
Rich
Absolutely fantastic. Follow. I'm following you on Blue sky now. So I'm looking forward to some more DJ Shaleen in my life. I'm also looking forward to some more from our sponsor In My Life Threat Locker Zero Trust, Endpoint protection platform. Thanks to them for their support for today. If you are hankering for some more technology news, maybe not cybersecurity specific, but technology news. You are in luck. The big boss man himself, David Spark is going to be on Daily Tech News Show. It's starting right now at 4pm Eastern. So if you are watching live, head on over. Head on over to dailytechnewshow.com live. He's going to be running down a lot of the major themes and things that he saw at rsa. Speaking of rsa, David's just back from that. So if you want to check that out, like I said, dailytechnewshow.com live it is a fantastic show. Then you can join us next week. First we got Super Cyber Friday. It's coming back where our topic will be hacking the validity of Gen AI. An hour of critical thinking about embracing these new tools while still meeting your compliance requirements. It's all about how we can integrate that into a compliance workflow that starts at 1pm Eastern. And then we'll have our weekend review at 3:30pm Eastern. To get information and register for both, head to the events page@ciso series.com in the meantime, you can still get your daily news fix every single day through Cybersecurity headlines. Give us about six minutes. We'll get you all caught up. Until the next time we meet. For myself for our producer, Steve Prentice for DJ for David Spark and all of us here at the CISO Series Family, here's wishing you and yours to have a Super Sparkly day.
DJ Schlien
Cybersecurity headlines are available every weekday.
Rich
Head to csoseries.com for the full stories behind the headlines.
Cybersecurity Headlines: Week in Review Summary
Hosted by CISO Series, Episode Released on May 2, 2025
The latest episode of Cybersecurity Headlines, hosted by Rich from the CISO Series, delves into a series of critical cybersecurity developments from the past week. Joined by returning guest DJ Schlien, Head of Security at Boats Group, the discussion spans significant incidents, emerging threats, and regulatory measures shaping the information security landscape.
Overview: The episode opens with a shocking revelation about Jeffrey Bowie, CEO of the cybersecurity firm Veritico, who has been charged with violating Oklahoma's Computer Crimes Act. Bowie is accused of installing malware on the systems of St. Anthony Hospital in Oklahoma City on August 6, 2024.
Key Details:
Discussion: DJ Schlien expresses disbelief and concern over the incident, emphasizing the severe breach of trust it represents within the cybersecurity profession.
Notable Quotes:
Insights: Both hosts highlight the multifaceted security lapses, including physical security and vendor vetting processes. They stress the importance of robust security protocols to prevent such insider threats and maintain trust in cybersecurity firms.
Overview: Cloudflare's Q1 DDoS report reveals a dramatic increase in distributed denial-of-service (DDoS) attacks, with the company mitigating 20.5 million attacks in just one quarter, compared to 21.3 million in the entirety of 2024.
Key Details:
Discussion: DJ Schlien underscores the evolving nature of DDoS attack vectors and the necessity for continuous learning and adaptation within cybersecurity defenses.
Notable Quotes:
Insights: The conversation highlights the critical need for advanced DDoS protection measures and the role of managed security services in mitigating increasingly sophisticated attacks. Both hosts draw analogies to emphasize the importance of proactive defenses, likening inadequate protection to "leaving a screen door open in the middle of a hot summer day."
Overview: The FBI has issued a public service announcement soliciting information on Salt Typhoon, a China-linked threat actor previously involved in targeting US telecommunications companies since November.
Key Details:
Discussion: DJ Schlien debates the efficacy and potential risks of such broad public appeals, including the possibility of disinformation and false leads.
Notable Quotes:
Insights: The hosts consider the balance between leveraging public assistance for intelligence gathering and the dangers of inundating law enforcement with unreliable information. They acknowledge the sophistication of nation-state operations, emphasizing the complexity of combating such threats.
Overview: The U.S. House of Representatives has passed the Routers Act, mandating the Department of Commerce to evaluate the national security risks posed by routers and modems manufactured by foreign adversaries, particularly China.
Key Details:
Discussion: DJ Schlien appreciates the comparison of routers to everyday devices like vacuum cleaners, highlighting their ubiquitous presence and potential vulnerabilities.
Notable Quotes:
Insights: The discussion underscores the challenges in securing consumer-grade hardware, advocating for comprehensive oversight and standardized security practices. The hosts explore the broader implications of the Act, including supply chain transparency and the necessity for ongoing firmware updates to prevent exploitation.
Overview: A naturalized U.S. citizen from Vietnam has pleaded guilty to outsourcing government work to China. The individual secured a position as a Full Stack Web Developer with a U.S. government software contractor and illicitly facilitated remote access to his workstation from China between March and July 2023.
Key Details:
Discussion: DJ Schlien expresses frustration over recurring insider threats, emphasizing the need for rigorous background checks and enhanced vetting processes in remote hiring practices.
Notable Quotes:
Insights: The hosts discuss the broader implications for remote work security, highlighting the importance of robust insider threat programs and vigilant monitoring to prevent similar incidents. They stress the evolving nature of work environments and the corresponding need for adaptable security measures.
Overview: Following a Patch Tuesday update, Microsoft introduced an empty folder in the Windows NetPub directory intended to fix an elevation of privilege vulnerability. However, cybersecurity expert Kevin Beaumont discovered that this update inadvertently creates a denial of service (DoS) vulnerability by allowing non-admin users to halt future Windows security updates.
Key Details:
Discussion: DJ Schlien expresses significant concern over the oversight, critiquing the persistence of outdated practices like hosting websites on Windows machines and the ease with which unprivileged users can exploit such vulnerabilities.
Notable Quotes:
Insights: The conversation highlights the critical need for meticulous quality assurance in software updates and the potential repercussions of seemingly minor oversights. The hosts advocate for minimizing attack surfaces and ensuring that systems remain resilient against both privileged and unprivileged threats.
The episode concludes with acknowledgments of listener contributions and a brief mention of upcoming shows, including a focus on Gen AI compliance and a weekend review. Hosts Rich and DJ Schlien emphasize the importance of continuous vigilance and adaptive security practices in an ever-evolving threat landscape.
Notable Quotes:
Key Takeaway: This week's headlines underscore the multifaceted challenges in cybersecurity, from insider threats and sophisticated DDoS attacks to regulatory efforts and software vulnerabilities. The episode serves as a crucial reminder of the dynamic nature of cybersecurity threats and the necessity for robust, adaptive defenses.
For more detailed analyses and daily updates, visit cisoseries.com.