
Loading summary
Nick Espinosa
From the CISO series, it's cybersecurity headlines.
David Spark
Oncd set to consolidate power in US Cyber. Undocumented commands found in Bluetooth chip used by billions of devices. And the DOJ seeks to break up a little startup called Google. These are some of the stories that my colleagues and I have selected from this past week's cybersecurity headlines. And now we're looking forward to some insight opinion and expertise from our returning guest, Nick Espinosa, host of the nationally syndicated Deep Dive radio show. It's been about two years, Nick, I gotta ask you, how was your week in cybersecurity?
Nick Espinosa
So we're basically starting this with open bar. Is that what we're. Yeah, yeah.
David Spark
Pretty. We'll keep it wide open.
Nick Espinosa
All right, let's go there. All right. No, this week has felt like many past weeks have felt like a million years crammed into seven days. Right. I mean, think about what we talked about outside of the headlines. You know, you got Zuckerberg, you got Russian propaganda, you got, you know, just a whole bunch of privacy issues. It's been been absolutely nuts. So.
David Spark
Yeah. And to that point, I just want to give a quick disclaimer here right at the top of the show. You know, many of the stories that at the CISO series and that you as ciso's encounter will have some direct connection to substantial to news items that are happening in the change of any presidential administration. And we are seeing them in this one for sure. We can't ignore these changes since they directly impact cyber here and elsewhere in the world. But it's our aim to refrain from getting political. We're not choosing sides here. We're calling ball and strikes. Nick, I'll steal a line from you here, but always we're trying to look at these developments and how they impact CISOs, cybersecurity, cybersecurity practitioners and the companies they protect. So I hope everybody keep that. That's the rubric I always use when we're looking at these stories. And that's really the only way to kind of go about it.
Nick Espinosa
Yeah, well, on my own radio show, I have a saying that says cyber security is agnostic to politics, but we're not immune from it, Right?
David Spark
Absolutely.
Nick Espinosa
We got to talk about these things openly. Otherwise we're just not going to get things done.
David Spark
Before we jump into news, though, I want to take a moment and thank our sponsor for today. That's Vanta A new way to GRC. I already see some people on our YouTube chat if you want to join those people like TJ Williams, David Spark, the big boss man, of course, CCL and Kevin Farrell. You need to go to cisoceries.com look for the event dropdown for the Week in Review show. Click on it and you are joining us. You're having a good time and it's all gravy. We want you to contribute. Your chats help make the show better. Let us know what you think. Just a quick reminder that Nick's opinions here are his own, not necessarily those of any staff, affiliates or intergalactic overlords. So, Nick, I do appreciate you giving us those. We've got about 20 minutes, though, so I need to jump right into the news here. And this is one of the big stories we led off the show with here. Oncd set to consolidate power in US Cyber. If you're not familiar with the acronym, that's. The Office of the National Cyber Director is poised to gain strength and will operate as the executive branch for cybersecurity policy. Sean Cairncross was selected by the President to lead the office. While he has no experience as a cybersecurity leader, it is believed his close personal ties to the President are a significant asset for the office, which until now has been overshadowed by the National Security Council, or nsc. This is the position previously held by Harry Coker. The ONCD is also being described as the pinnacle guiding the National Security Council, which does foreign policy and offensive cyber, and cisa, which takes care of doing domestic and defensive cyber. So a lot of positioning here, you know, kind of shuffling the chess pieces. I don't know what metaphor I was going for there. But Nick, if it's one thing that we've seen a lot over the past decades, it's a large number of administrative bodies taking over various parts of the cyber frontier, kind of ad hoc, as we've kind of needed them to do. You see this new development as a positive step for national cybersecurity.
Nick Espinosa
So I think this could be a good thing, honestly. Could be a good thing. And I'm hesitant, really, honestly to start throwing the parade right at the moment. But think about it this way, and let's forget the new leadership, Karen Cross, for a second and just talk about the logistics of these departmental changes. Now, this move centralizes decision making and oversight. You know, you just mentioned that. So it could possibly enhance coordination across federal agencies and make it easier to respond to threats like, you know, those kinds of things. So the oncds enhanced role could ensure that cybersecurity strategy and policy is more integrated across the board. Right. That's not a bad thing. Nobody's going to deny that. We all know uniformity is centralized and centralization is key to success here. And that's honestly a stark difference, as you mentioned, from what we've got. CISA's national and Defense National Security Council is offensive, et cetera, et cetera. And so with that, I think it honestly could be an improvement of our overall security posture. But let's talk about Sean Caine Cross for a second because he's got a lack of leadership in this field. Right. He's not a full on nerd like we're sitting here. So by virtue of that, you know, he got the job because he has close ties to the President as you mentioned. And I think here's the good with this, that could honestly probably improve communications and influence at the highest level of government, assuming that he's going to advocate for cybersecurity controls, you know, offensive, defensive, whatever it is, you know, that's the hope here. Right? That's my hope. So this might allow cybersecurity to receive the attention it needs, you know, especially in terms of funding, legislative action, public awareness, more so than what CISA's been doing. And I do love me some CISA, they're good folks, you know, but, but, and I think it's a big but. I'm a little more concerned right now and I think there is a lot to be concerned with this as well because Caine Cross lacks that direct experience in cybersecurity. And that's, that's the obvious one. And at the moment the current administration seems to be appointing heads of departments, you know, of government agencies that have questionable credentials for getting that job. That's again, balls and strikes. Right. So the concern for me here is a possible lack of independence of this leadership and therefore the ability to push back on the executive branch when let's say the President says I want X and that's counterintuitive to what cybersecurity needs. And so that's the concern. And we've already started to see this. So the US military, for example, in the last week or two was already ordered to stand down and see cyber offensive planning operations against Russia, which I think we can all agree for the most part from a cyber security and cyber warfare standpoint is pretty much a wrong move. So will Cain Cross do the same thing? I mean, we'll see, right? I mean, that's kind of the name of the game here.
David Spark
Yeah, we talk about it all the time on Defense In Depth, CISO series podcast, you know, A security leader really needs to be a communicator with the business or an organization, in this case the government. Yeah, I appreciate Nick, that you don't like that is not an inconsiderable factor in this. Whether he has, you know, whether there's the staff beneath them to make those decisions quickly, you know, especially in the event of a crisis. That is something that we'll have to see play out down the road. And you know, as with any administration, you know, there are the whims of politics. Could take the heads of departments any which way. So we shall definitely see next up here, undocumented commands found in Bluetooth chip used by a billion devices. Just a cool B as we like to call it in the biz. As described in Bleeping computer, the ubiquitous ESP32 microchip made by Chinese manufacturer espressifies. I'm going to go with that. And used by over 1 billion units as of 2023, contains undocumented commands that could be leveraged for attacks. The undocumented commands allow for spoofing of trusted devices, unauthorized data access, pivoting to other devices on the network and potentially establishing long term persistence. Researchers from Tarlogic Security speaking at RootedCon in Madrid, pointed out that ESP32 is one of the world's most widely used chips for WI fi and bluetooth connectivity in IoT devices. So the risk is significant. Nick, this is an extension of the whole lurking in infrastructure theme which we talk. Well, we're going to be touching on later on in the show, but with an additional angle of persistence within a range of tools and devices that would be extremely difficult to detect and fix. A whole range of white label IoT that's out there, let alone the stuff that's more supported. I'm curious, what do you think about this and about similar instances that have yet to be reported? Probably not the only one out there.
Nick Espinosa
Yeah. Well, I think you could also allude to the fact that this is why the McCain act came around a while ago. Just throw that out there. But I mean the obvious and most biggest risk that we have here is the surface area for ATT and CK to both compromise and weaponize a whole bunch of stuff. I mean, a billion devices, A billion of them, that is a lot. And so I think overarchingly, if we're looking at this, you know, here from this perspective, I think we have from a high level view a really a challenge that's essentially like a twofold issue here. The first one is detection. Right. This is super hard to detect until it becomes known. Right. So even the most stringent of, like, let's say cybersecurity audits or vulnerability testing would miss this until this stuff is identified. Right. And the other side of the coin is actually fixing the problem. You know, updating a microchip embedded into an IoT device is going to be nearly impossible in some of these use cases, which means we may not be able to cut down that billion, assuming everybody actually patches their stuff. You.
David Spark
We can dream, Right?
Nick Espinosa
Right, we can, we can, but that's what the open bar is for, you know, So I think that's. That's a huge thing. And on top of that, like I said, some, some stuff just can't be upgraded. And so if we're looking at where the cases are actually feasible to update this stuff, it may require an absolute ton, ton of effort to roll out to basically a huge population of devices. Right. We have remote industrial devices where downtime could be very costly or maybe you can't slow down production, so you've got to run with a vulnerability. And not even to mention, like, the home users, like, you know, they don't even update their stuff. Right. I mean, it said it and forget it. You know, you bought the printer when the Macarena was popular and it's still running and you haven't touched it.
David Spark
Right.
Nick Espinosa
I mean, that's how this works. And that is a deep, deep, deep concern. Right. And so by virtue of that, we've also seen similar events to this, right? The St. Jude pacemakers, where, you know, somebody, I can't remember who at Black Hat showed how you could just blow up a pacemaker, you know, in your heart, like, my God. You know, and so. So the thing is that if I were betting, man, I would bet that there's an absolute ton of flaws out there like this that we just haven't discovered, whether they're intentionally baked in or accidentally. Here it is. And I think this really calls for cybersecurity requirements in the development process that we're just really not fully baking in right now.
David Spark
Yeah. And as TJ Williams points out in the chat, even the vaunted Flipper Zero, the thing that you might use to take advantage of a Bluetooth vulnerability, or at least test for it, has these chips inside. So even our own favorite tools and toys, so that's what's pumping my data to China. And I would also point out the UK in the last couple of years has put out some stronger requirements around Iot. Oh, that is. That is. Oh, man, you're Going to make me put one in my cart today.
Nick Espinosa
There you go.
David Spark
All right. Speaking of someone that will serve me the ad for those the doj seeks to break up Google. The Cyber Wire reported this week that last Friday the Department of justice submitted a request that would aim to break up Google by forcing the company to sell Chrome. In its filing, the DOJ stated that Google's illegal conduct has created an economic Goliath, one that wreaks havoc over the marketplace to ensure that no matter what occurs, Google always wins. Emphasis mine. The ruling expected this summer, has the potential to significantly impact how Google operates, how users interact with its services, and the overall landscape of the search engine business. So, Nick, what is it about Google that's placed it in the DOJ sites? Certainly not the only big tech platform to receive scrutiny, but we have other companies like Apple and Microsoft equally as dominant. The market not facing quite as severe. Apple probably getting the most scrutiny with a lot of their app store fees and stuff like that. But is it fair to request from the DOJ in terms of a breakup of Google and what do you think would happen if it actually succeeded and what would the impact look like for cybersecurity?
Nick Espinosa
Yeah, well, first things first, let me whip out my super tiny violin for both Larry and Sergey on this one. So yeah, obviously they're in the gun sights of the DOJ for an absolute ton of very valid reasons in my opinion. First things first, I mean market dominance alone, My God, 90% of the world uses them as a search engine. So they have a absolute metric ton of influence over what users find on the Internet, how business advertise literally operate. They're the 800 pound gorilla in the room, right? So I mean by virtue of that, I mean that that's going to target them automatically. On top of it, they have put together exclusivity agreements anti can, you know, that are anti competitive. I mean, so think about what they did with Apple. You know, they, they paid their largest competitor billions and billions of billions of dollars to make sure that it wasn't Apple Search or Apple Maps, it was Google Search, right? You know, and Samsung, they had an agreement with them as well. And again, that truckload of money basically ensures that if you're rocking an iPhone or even a Samsung, your default is going to be Google. And how many users for the record are going to go find DuckDuckGo or start page or even know what those are unless you're in cybersecurity. So this is a huge thing. So they're clearly trying to prevent Rivals, I think, from gaining any kind of significant market share, which then obviously puts them on the map for this. And if I were teaching a class on anti competitive behavior in the modern era, I would probably start with Google. And so think about it this way. The sheer size and scope of Google services creates that network effect where people use their ecosystem, their services, and by virtue of that, they become more valuable. Microsoft and Apple do this a little bit as well. But Google, ooh, they're the king at this right now. So think about it this way. If you're in their ecosystem, you've got your search, your maps, your email, videos through YouTube, you know, an ecosystem for the App Store. You can even get a free second phone number from them. And on and on and on. So, so this is a huge thing and it makes it super difficult for smaller competitors to challenge. And that's the whole point of this, is to have a more even playing field because there may be innovation that is being stifled. I love me some, some Proton mail on my Android, but I need a Gmail account to run it, right? And so that's a huge thing. Now if you ask if this was fair. Yeah, next question. You know, I mean, seriously, I hope it succeeds. I really do, you know, but obviously there would be some disruption, right? You know, if Chrome were to get spun off or whatever, there would be temporary disruptions as Chrome is deeply integrated into how Google runs their ecosystem. Right. So that would be a huge blow to them. Again, tiny violin, you know, and so, so here we are. But I think this is, this is a good thing overall.
David Spark
TJ is definitely bringing the comments here. Google love even more ways to win like the Bell system did. If you're not familiar, hey, guess What? Verizon and AT&T, they're, they're just all old Ma Bell companies.
Nick Espinosa
We don't care. We don't care. We don't have to. We're the phone system, it turns out.
David Spark
Yeah, it, it will be interesting to see if they follow that more. Microsoft. What happened with Microsoft, where just the threat of future litigation caused them to move slower, which caused them to miss the boat on some of the, you know, some other categories. Now, Microsoft still doing fine. Turns out they, they knew what they were doing well, but.
Nick Espinosa
Well, to be fair though, Microsoft did throw a funeral for the iPhone back in 2007 when they launched the Windows Phone or whatever it was, so.
David Spark
And we have to give them the nailed it award there. Good call, Steve. All right, before we move on to our next story, I have to give a Few moments and thank our sponsor for today. Vanta, do you know the status of your compliance controls right now? Like right now? We know that real time visibility is critical for security, but when it comes to our GRC programs, we rely on point in time checks. But more than 9,000 companies have continuous visibility into their controls with Vanta. Vanta brings automation to evidence collection across over 35 frameworks like SoC2 and ISO 27001. They also centralize key workflows, policies, access review and reporting and helps you get security questionnaires done five times faster with AI. Now that's a new to GRC. Get started@vanta.com headlines. That's V A N T A dot com headlines. All right, next up here, UK banks ordered to compensate customers for outages. Nine major UK banks and building societies, kind of the UK version of a credit union, were found to have accumulated the equivalent of 33 days of tech outages in the past two years. So I'm going to go less than two nines there. According to figures published by Parliamentary Treasury Group and must now deliver compensation payments amounting to 12.5 million pounds. The data does not include the Barclay outage in January or the Lloyds bank outage last week. The committee's chair, Dame Meg Hillier, sympathized with working people and companies for whom losing access to banking services on payday can be a terrifying experience. But Patrick burgess of the UK's Chartered Institute for it says the findings once again highlight that the traditional banking sector hasn't kept pace with the investment needed to modernize its infrastructure. So, Nick, it's not often that we hear stories like this, especially given that banks have all kinds of ways of making money back that they lose. Turns out your ATM fee went up a couple shillings. I'm curious, is this a proactive approach to modernizing the banking system? One that might spread to other countries? Hey, here's a nice incentive to update that. It maybe are we going to get to a place where we can maybe replace the band aids of 2 years of free credit monitoring when something gets leaked or breaks down? Are we any closer? Give me hope. Is there hope?
Nick Espinosa
Yeah. So short answer is, is this modernizing the banking system? Yeah, actually I think it is. And I think it has a multi, multi benefit, multifold benefit here. So by holding banks accountable for these outages and then demanding compensation for the customers, basically the UK is sending a clear message. I think that financial institutions have to invest in their infrastructure and invest they will. So on my own radio show, I actually Have a segment entitled, you know, if you just spent money on cybersecurity, you wouldn't be getting sued, you won't be getting fined, you wouldn't be losing your reputation, and I sure as heck wouldn't be talking about you right now. So. And by virtue of that, here we are. Right. I call it out when you see it. So they're invent, they're basically incentivized to spend money. Right. It also seems to align with a customer first mentality and I'm a big fan of that. Right, because you are a customer of the bank. And so customers access to critical services like payday transactions like you mentioned, etc. Is a priority. My God, imagine depending on that paycheck and it's not there. And so I wish more countries basically took that approach at leveling sanctions. I think it's proactive and so I do hope it spreads to multiple countries as well. And I mean there's a ton of challenges that. Right. There's regulatory differences. Every country has their own banking regulations and laws and all of that. You know, like in the United States, you know, you have a, there's a million different banks, you know, a million different credit unions, all of that in Canada, there's like five major banks and like six credit unions that fail every other week. You know, so like everybody is different, right. When it, when it comes to that kind of stuff. And banks also are going to resist these policies, right. It's going to require them to pay direct compensation or overhaul their infrastructure, which they should be doing anyway, you know, and that's potential cost, logistics, all that kind of stuff. So it's going to take probably years potentially for regulators in various countries to really I think enforce these kinds of changes. So in other words, the lobbyists here are all going to get like basically be heating their pools and their third houses 247 during the summer with you know, the amount of money the banks are going to spend to try to avoid this when they could just be upgrading their infrastructure and we wouldn't be talking about them if they did that. Right. So, so here it is now. Is this a band aid? I do think it has basically the, the, the, the, the ability to replace a typical band aid like the free credit monitoring. I'm pretty sure I have like 16 free credit monitors right now at this point. Yeah, right. You know, like, like every year, you know, because this actually focuses, it shifts the focus I think to long term infrastructure improvements and accountability in a way that free credit monitoring simply does, just doesn't do that. Right. So I think it could compel banks to invest in more robust systems, you know, be a little more secure. And I'm all, I'm a big fan of that resilience.
David Spark
So we're going to stick in the UK for our next story here. UK calls for improvements to open source supply chain security. This comes from the UK's Department for Science, Innovation and Technology, or DSIT. They outlined weaknesses in a report in the open source supply chain citing a lack of industry specific practices, a lack of formal process for judging component trustworthiness and the dominant influence of large tech companies. See our Google story earlier as best practices, it recommends organizations create internal OSS policy that details the criteria for evaluating the trustworthiness and maturity of OSS components. Basically have a process, develop software, bill of Materials or SBOMs for their products and actively engage and contribute to the open source community. A novel concept. So Nick, similar story to the UK bank situation too. I mean a lot of threads kind of coming together here. Again, proactivity or political theater at this point. What could any one country do for a supply chain that is global? Does this help shift the balance?
Nick Espinosa
Yeah, so I'm more on the proactive side than political theater side of this. Providing it, they make it effective.
David Spark
Right.
Nick Espinosa
So think about it this way. The fact that the DSIT has actually recognized the weakness in open source supply chain is a, it's a huge step. Open source software is integral. I mean it's integral to software development, but it's also highly fragmented. Right. It doesn't have really any formal oversight or industry specific standards and that's obviously a huge issue. So then for the record, this is something that President Biden was tackling in his one term by creating that certification for software developers that could help to affirm security controls. I was a big fan of that. But unfortunately I do believe that executive order was rescinded with the new administration. So I think personally offering concrete recommendations like this is good overall. I think it encourages organizations to find clear criteria for evaluating open source components. And that definitely ain't a bad thing. Right. So I think it's also a step towards that standardization that I think President Biden was trying to go for as well. And the UK is pushing for it and I think that's a good thing. I think that leads to broader implications to basically a global practice for open source. So does that really work for this? I think so, because no one country can fully address the supply chain issues on their own. Right. We have to do this, you know, together and by Virtue of that, if one company is country is stepping up and saying, our country requires all open source everywhere that, everywhere that open source is being made, they're now going to possibly meet that standard in order to be able to be used in the UK and then the next country, the next country and the next country. So I think that's good. And we can't forget organizations like the Open Source Security foundation as well. Right. Open ssf. I mean, similar groups like that in the EU and the US Are already working on best practice guidelines. So coordinating with these governments, I think is the best thing to do. In the same way that like last year, I was basically yelling at the heads of the data protection authorities at a symposium last year in Italy, you know, basically saying, we've got to coordinate, we've got to step up. And I mean, I think that's super, super, super important, you know, because again, it also, to your point, the dominant influence of large tech companies that can control these projects too, I think, really comes on the table as well. You know, it democratizes the process and I think that's a good thing. Yeah.
David Spark
When you look at the contributors to open source projects, it's like 60% Microsoft, 40%. You know, it's all dominated by the big tech platforms in terms of percentage of contributions and stuff like that. I always think about this as raising, you know, that cybersecurity poverty line. Right. Like, S BOMs are not a cure for the open source supply chain, but they do help give you a little bit more visibility. And when you have these best practices like that, I always think it makes it easier for a CISO to bring like, hey, we need to take this seriously. That starts the conversation in a way that can be really useful.
Nick Espinosa
Right. And we don't have to reinvent the wheel here either. We have platforms like OWASP, you know, ASVs and a whole bunch of others. So, you know, let's get to it.
David Spark
Yeah.
Nick Espinosa
All right.
David Spark
Our last story for today. China's Volt Typhoon hackers lurked in US electoral grid for 300 days, which if you look at the Math, that's about 10 months. Security firm Dragos published a case study revealing that the Chinese hacker group Vault Typhoon infiltrated the US Electrical grid through a breach at the Littleton electric light and water departments in Massachusetts. The hackers had access to the utility's network for over 300 days, collecting sensitive operational technology data, including information on energy grid operations. This data could be used for future targeted attacks. Now, Nick, the Security Week article does not elaborate how Voltaifun penetrated the Massachusetts utility. But. But we're pretty much daily covering stories about vulnerabilities that make this possible. So dealer's choice, I guess. The article does elaborate on how hackers like Volt Typhoon can develop and test specific and meaningful attacks on industrial control systems, and that it was observed exfiltrating Geographic Information System data containing critical information about the spatial layout of energy systems. So literally, like physical layout stuff. I'm curious, what's your take on this?
Nick Espinosa
Yeah, so I don't think open bar is going to be enough, you know, like, can we open this up a little more? So, I mean, this is. This is the problem, right? I mean, OT is one of the biggest problems we have there, ics, et cetera, for targeting. I mean, look at how easy it is to go on to Shodan, log in right now, find a video camera somewhere on the planet or an H VAC controller, and essentially just basically connect and get a. You know, and get in. This is a huge issue. So by virtue of that, let's break this down a bit, because we know that utilities like the electrical grid have traditionally been more difficult to protect than just a standard IT perimeter or IT infrastructure. And the major problems are basically across the critical infrastructure sectors, right? So water and wastewater in the United States, for example, there's over 50,000 water and wastewater districts has a huge problem with this, per the Inspector General's report. We're not spending on defenses. Oldsmar, Florida. Somebody hacked in, introduced lie, could have killed 15,000 men, women and children, not to mention animals drinking from that water source if they hadn't found it accidentally and quickly corrected it. Look at Colonial Pipeline, right? Or even the reports that nuclear power plants have been accessed around the world. One in India, you know, and some others I'll talk about in a second here. But like, in this case, it seems like Volt Typhoon was able to not just access the network, but also exfiltrate sensitive data like geographic information data, right? Information system like GIS data, which maps out critical infrastructure that's invaluable to an attacker, planning future operations. And so by virtue of that, this can be weaponized to create just insane attacks on energy systems as well. So Volt Typhoon having that knowledge is a huge issue. And the fact they went undetected for 300 days, I mean, Security Information Events Monitoring System. To the front, to the front stage, please. Like, holy cow, that's insane. We have a serious need for continuing monitoring, proactivity monitoring, all this kind of stuff on ot. In the same way we would with it for special like suspicious behavior. And we know this isn't cybercriminals going for financial gain. This is a state backed effort. Right. This is cyber espionage. And so by virtue of that, this is basically we have to look at this as them trying to gain geopolitical power in the long term. Infiltrating our critical systems is important because they can then gather intelligence for future leverage or shut us down. What are you doing in an invasion? You make them deaf and blind. Right. So this is a huge issue. The Russians did this to the Ukrainians back in 2015 in Crimea. They had a power plant, knocked it out, knocked out the phone system. Now we're starting a trade war with China. So like this is a huge, huge thing. And I think it's important to note that we have basically only three real types of war. Kinetic war, boots on the ground, people shooting at each other, economic war sanctions, tariffs, et cetera, et cetera, and cyber warfare, which is oftentimes not viewed as war because nobody's shooting at anybody. Right. So it goes under the radar. But we've been in these kinds of cyber wars for years at this point. It's a huge problem.
David Spark
Yeah. And I would say, if not, not to try and pull good things out of what is abject tragedy. But if we've learned anything from the Russian invasion of Ukraine. Right. It's like, like cyber warfare. To me that, that is the marking point like in, in the history of cyber warfare where we, where I think there was a mass consensus of cyber warfare is just a continuation of like there is, there is almost no difference. It's being conducted, you know, hand in hand with all of these operations on both sides. Y. Yes, that it is, it is. It is really remarkable to see what could be done with this kind of information. But I will say silver lining alert from the chat room. Okay. TJ Williams was wondering who is the leader in OT protection in terms of like vendors and stuff out there. And CCL was saying it's too diverse. Can't you know, there's no one, no one's like necessarily the market leader. Guess what TJ pointed out sounds like there is a market opportunity. So if you're a startup that can solve all OT visibility issues, congrats, congratulations. There is a huge market for you and we would love to talk to you.
Nick Espinosa
Well, and to be fair, if they do knock out the electrical grid, the OT goes down. So now it's secure. So think about it that way. There you go.
David Spark
You know what? That's a department of yes answer. Right.
Nick Espinosa
Right there.
David Spark
So congratulations, Nick. That was. That was amazing. And thank you to ccl, to tj, to Schmooze. I see coming in there as well. Big boss man David Spark, of course, in there, and Kevin Farrell all helping us out there in the chat, helping make the show better. Thank you so much. Before we get out of here, Nick, was there any story this week that was a thumbs up or an eye roller for you? Busy news. A week. There are weeks when years happen and years when weeks happen.
Nick Espinosa
Yeah. So you're looking at the guy that did a viral video years ago called it's time to put Mark Zuckerberg in Jail. And we got. We got more evidence this week of that.
David Spark
Oh, boy.
Nick Espinosa
How Tao went backwards and forwards to the Chinese government to the point where he would let them in, let them surveil the data, actually bring in their own sensors because he was trying to break into the Chinese market. Even said that he would kill and did kill, basically American Chinese pages that were dissident to him, dissident to China. So. Oh, my God, like, the guy's all about money. There's no. There's nothing else there. It just.
David Spark
I mean, the good thing about big tech and social media is they're all a flat circle where they all start out as we want to connect the world and be free speech platforms. And at the end they're like, it turns out we'll stay in any market that we can.
Nick Espinosa
Right. At all costs.
David Spark
At all costs.
Nick Espinosa
Yes. It's crazy.
David Spark
All right now, Nick Espinoza, host of the Deep Dive radio show, just crushing it, having a blast, talking to you. Thank you so much for that. Where can people find you on the cyberspace if they're so inclined?
Nick Espinosa
Yeah, yeah. LinkedIn. Nick Espinoza. You'll see my mug shot there. Like everybody else's YouTube. Nick Espinoza. You can find me on Bluesky. Also Twitter, Nick A. Esp. And yeah, come say hi. I love hanging out.
David Spark
And we have a link to your SoundCloud too, and you can find all of those in your show notes. Lots of ways to hear more from Nick and just really appreciate it. Nick, this was just a treat. Thank you so much.
Nick Espinosa
Thanks for having me. I always enjoy this. Anytime, anytime.
David Spark
Another thing that we love to do on this show is thank our sponsor for today and that's Vanta. A new way to grc. Thanks again to our audience. I know we can't get every single comment and stuff up on the screen. Acknowledge. Give it its time that it's due and its acknowledgement, but we deeply, deeply appreciate it. They were all noting on the irony that we're talking about breaking up Google while streaming on YouTube. So that's always fun. Remember to please join us next week. We've got a busy Friday as always. First up we got Super Cyber Friday where our topic will be Hacking Narrative Threats, an hour of critical thinking about measuring the risks you least control. A really fascinating topic that we haven't really touched on on the show. Fascinated to hear about that at 1pm Eastern. And then we're going to have our weekend review show 3:30 Eastern. You just to register for both, you need to just head on over to the events page@cisoseries.com and heck, subscribe to our YouTube channel as well before it gets broken up by the doj. In the meantime, you can get your daily news fix every single day through cybersecurity headlines. Give us about six minutes. We'll get you all caught up. Until the next time we meet. For myself, for Nick, for our producer Steve Prentice, for all of us here in the CISO series Family, here's wishing you and yours to have a super sparkly day. Cybersecurity headlines are available every weekday. Head to cisoseries.com for the full stories behind the headlines.
Cyber Security Headlines: Week in Review – Detailed Summary
Hosted by CISO Series’ David Spark with guest Nick Espinosa
Release Date: March 14, 2025
Episode Title: Week in Review: ONCD Dominates Cyber, Undocumented Bluetooth Commands, DoJ Google Breakup
Overview:
The episode opens with a discussion on the Office of the National Cyber Director (ONCD) gaining significant authority within the U.S. cybersecurity framework. David Spark introduces the topic, highlighting the appointment of Sean Cairncross as the new head of the ONCD, despite his lack of direct cybersecurity experience.
Key Points:
Notable Quotes:
Insights: Nick Espinosa emphasizes the potential benefits of centralized decision-making, such as improved coordination and a more cohesive security posture. However, he also voices concerns about the appointment of leaders without substantial cybersecurity expertise, which could impact the agency’s effectiveness in advocating for necessary cybersecurity measures.
Overview:
The podcast delves into a critical vulnerability discovered in the ESP32 microchips, widely used in billions of IoT devices. Researchers identified undocumented commands that could be exploited for malicious purposes.
Key Points:
Notable Quotes:
Insights: Espinosa highlights the dual challenges of detecting such vulnerabilities and the difficulty of patching embedded microchips in widespread devices. He underscores the necessity for robust cybersecurity measures during the development process to mitigate these risks. The discussion also touches on global efforts, such as the UK’s enhanced IoT regulations, aiming to strengthen supply chain security.
Overview:
A major story discussed is the Department of Justice’s (DoJ) move to dismantle Google’s dominance by compelling the company to sell its Chrome browser, aiming to foster a more competitive market environment.
Key Points:
Notable Quotes:
Insights: Espinosa argues that breaking up Google is a positive move towards leveling the playing field, encouraging innovation, and reducing monopolistic practices. He acknowledges the temporary disruptions that may arise from such a breakup but believes the long-term benefits for market competition and cybersecurity are substantial.
Overview:
The conversation shifts to the UK’s regulatory actions against major banks and building societies due to prolonged tech outages, resulting in significant customer compensation mandates.
Key Points:
Notable Quotes:
Insights: Espinosa views this regulatory approach as a proactive measure to compel banks to invest in robust and reliable infrastructures, rather than applying short-term fixes like free credit monitoring. He believes this strategy aligns with a customer-first mentality, ensuring that critical services remain uninterrupted and secure.
Overview:
The UK’s Department for Science, Innovation and Technology (DSIT) issued a report addressing vulnerabilities in the open-source software supply chain, advocating for enhanced security practices.
Key Points:
Notable Quotes:
Insights: Espinosa supports the UK’s recommendations, emphasizing the importance of standardization and global cooperation in securing the open-source supply chain. He highlights the role of organizations like the Open Source Security Foundation (OpenSSF) in developing best practices and underscores the necessity for comprehensive monitoring and proactive cybersecurity measures in software development.
Overview:
The final major story covers the prolonged infiltration of China’s Volt Typhoon hacker group into the US electrical grid, exposing significant vulnerabilities in critical infrastructure.
Key Points:
Notable Quotes:
Insights: Espinosa underscores the critical need for enhanced security measures in operational technology (OT) environments, noting the ease with which attackers can exploit vulnerabilities in critical infrastructure. He draws parallels to previous cyber-attacks on utilities, emphasizing that cyber warfare operates alongside kinetic and economic conflicts, posing significant risks to national security.
Closing Remarks: The episode concludes with reflections on the pervasive influence of big tech companies and the importance of robust cybersecurity practices in safeguarding critical infrastructure. Hosts express optimism for ongoing regulatory and technological advancements aimed at mitigating these pervasive cyber threats.
Notable Quotes:
Conclusion:
This episode of Cyber Security Headlines provides an in-depth analysis of significant cybersecurity developments, ranging from governmental restructuring and corporate antitrust actions to critical vulnerabilities in widely-used technologies and cyber espionage threats. With expert insights from Nick Espinosa and David Spark, listeners gain a comprehensive understanding of the current cybersecurity landscape and the evolving challenges within it.
For more detailed discussions and daily updates, visit CISOseries.com.