Loading summary
Dave Bittner
You're listening to the Cyberwire Network, powered by N2K.
Steve Schmidt
Your business needs AI solutions that are not only ambitious, but also practical and adaptable. That's where Domo's AI and data products platform comes in. With Domo, you can channel AI and data into innovative uses that deliver measurable impact. Secure AI agents connect, Prepare and automate your data workflows, helping you gain insights, receive alerts, and act with ease through guided apps tailored to your role. Data is hard. Domo is easy. Learn more@AI.domo.com that's AI.domo.com the Senate confirms Kash Patel is FBI director the SEC rebrands its crypto assets and cyber unit. Microsoft's quantum chip signals an urgent need for post quantum security. Chat log leaks reveal the inner workings of Black Basta CISA advisories highlight craft CMS and ICS devices. Researchers release proof of concepts for Ivanti Endpoint Manager vulnerabilities. Warby Parker gets a $1.5 million HIPPA fine. Our guest is Steve Schmidt, Amazon's chief security officer, with a behind the scenes look at securing a major event. And researchers explore the massive, mysterious YouTube wormhol it's Friday, February 21st, 2025. I'm Dave Buettner and this is your Cyberwire Intel Briefing. Thanks for joining us here today and happy Friday. It is great to have you with us. The Senate confirmed Kash Patel as FBI director in a narrow 51 to 49 vote despite concerns over his qualifications and political loyalties. A Trump loyalist, Patel has been vocal about reforming the FBI, shifting its focus from intelligence gathering to traditional law enforcement. His confirmation follows Justice Department shakeups and demands for agent names tied to January 6 investigations, raising fears of political retribution. Patel's past remarks, labeling FBI investigators as criminal gangsters and suggesting January 6th rioters are political prisoners alarmed Democrats. Critics fear he will use the FBI to target Trump's adversaries, undermining its independence. Republicans, however, back him as a reformer who will restore accountability. From a cybersecurity perspective, Patel's leadership could impact federal investigations into cyber threats, foreign influence campaigns and domestic extremism. His shift away from intelligence driven operations might weaken nationwide cybersecurity efforts, leaving agencies and critical infrastructure more vulnerable to cyber threats. The securities and Exchange Commission has rebranded its crypto assets and cyber unit as the Cyber and Emerging Technologies Unit, expanding its focus beyond cryptocurrency fraud to include hacking, social media scams and AI related threats. Led by Laura de Allaire, the unit will still investigate crypto related fraud, but critics worry. The change signals a weakened enforcement stance under the Trump administration, which is seen as more crypto friendly. The rebrand follows SEC enforcement actions against major crypto firms like FTX and Binance and its previous focus on unregistered asset offerings and securities violations. Some former officials argue the shift diminishes crypto oversight, while others believe it allows for a broader focus on AI and quantum tech risks. The change reflects ongoing political shifts in US Crypto regulation, raising questions about how aggressively the SEC will police blockchain related fraud and market abuses moving forward. Microsoft has unveiled Majorana one, the first quantum chip accelerating the timeline for quantum computers capable of breaking encryption from decades to years. The breakthrough, powered by a new topological core architecture, could lead to million qubit systems capable of solving problems beyond the reach of classical computers. However, this also raises serious cybersecurity risks. Quantum machines will be able to crack encryption protocols like RSA and AES, exposing sensitive data. Cybercriminals are already harvesting encrypted data to decrypt later when quantum systems mature. To counter this, NIST formalized post quantum cryptography standards in 2024, urging organizations to adopt quantum secure algorithms. Still, challenges remain, including unclear ownership of transitions and poor cryptographic visibility. The financial sector is leading in developing quantum resistant solutions, but broader adoption is essential before quantum computers become a widespread threat. Internal chat logs from the Black Basta ransomware gang have been leaked online, revealing nearly 200,000 messages detailing internal conflicts, network access and key threat actors. The logs, spanning September 2023 to September 2024, were first shared on Mega by a user named Exploit Whispers before being moved to Telegram. Cybersecurity firm Prodaft confirmed the leak is likely legitimate and sheds light on Black Basta's decline. The group, once a major ransomware player, struggled with internal disputes, particularly over financial priorities and leadership issues. A figure known as Tramp, responsible for Q Bot distribution, caused significant friction, leading to members leaving. Many former Black Boston members have since joined the Cactus and Akira ransomware groups, continuing operation under new banners. The leak provides valuable intelligence, further proving that cybercriminal groups often collapse due to internal conflicts. CISA has added a high severity remote code execution vulnerability in CRAFT CMS to its known Exploited Vulnerabilities catalog. Though CRAFT CMS has a small market share, over 41,000 instances may be affected. The flaw was patched in January and affects installations where the security key is already compromised. While no public reports confirm attacks, federal agencies Must patch by March 13. Another RCE vulnerability was actively exploited in late 2024, though it has not yet been added to CISA's catalog. The growing exploitation of craft CMS flaws highlights the importance of timely patching to prevent Web server compromises. Additionally, CISA has issued seven advisories detailing critical vulnerabilities in industrial control systems from abb, Siemens, Mitsubishi Electric, and others. These flaws pose severe risks to critical infrastructure and require urgent patching. CISA urges organizations to apply patches immediately to mitigate exploitation risks and safeguard critical infrastructure from cyber threats. Notable is a vulnerability affecting ABB Flexion controllers, scoring a 10 out of 10 on the CVSS scale. This allows remote code execution and sensitive data exposure. Patch EM if you got em Security engineers have released a Proof of concept exploit for four critical vulnerabilities in Ivanti Endpoint Manager, all rated 9.8 out of 10 on the CVSS scale. The flaws were patched in January, but unpatched systems remain at risk. The vulnerabilities allow unauthenticated attackers to leak NTLM v2 hashes by tricking the software into authentication with a remote server, enabling account impersonation and system compromise. Researcher Zach Hanley discovered the flaws and published the technical details and Proof of Concept exploit earlier today. Ivanti states there is no evidence of active exploitation, but with the proof of concept now public, the risk has increased. The company urges immediate patching, including a v2 patch update that fixes issues caused by the original January patch. Eyeglass retailer Warby Parker has been hit with a $1.5 million HIPAA fine by the US Department of Health and Human Services Office of Civil Rights over credential stuffing attacks that compromised nearly 200,000 customer accounts. The attacks, which occurred between September and November 2018, allowed hackers to access electronic protected health information, including names, addresses, payment card details and eyewear prescriptions. Subsequent breaches in 2020 and 2022 prompted further investigations. OCR found three HIPAA security rule violations, citing Warby Parker's failure to conduct risk assessments, implement security measures, and review system activity logs. Though notified in September 2024, the company waived its right to a hearing, likely to avoid further scrutiny of its security practices. Coming up after the break, my conversation with Steve Schmidt, chief security officer at Amazon. We've got a behind the scenes look at securing a major event, and researchers explore the massive, mysterious YouTube wormhole. Stay with us. Cyber threats are evolving every second, and staying ahead is more than just a challenge, It's a necessity. That's why we're thrilled to partner with ThreatLocker, the cybersecurity solution trusted by businesses worldwide. ThreatLocker is a full suite of solutions designed to give you total control, stopping unauthorized applications, securing sensitive data, and ensuring your organization runs smoothly and securely. Visit threatlocker.com today to see how a default deny approach can keep your company safe and compliant.
Foreign.
Dave here. Have you ever wondered where your personal information is lurking online? Like many of you, I was concerned about my data being sold by data brokers, so I decided to try delete me. I have to say, delete me is a game changer. Within days of signing up, they started removing my personal information from hundreds of data brokers. I finally have peace of mind knowing my data Privacy is protected. DeleteMe's team does all the work for you with detailed reports so you know.
Unknown
Exactly what's been done.
Steve Schmidt
Take control of your data and keep your private life private by signing up for Deleteme now at a special discount for our listeners today. Get 20% off your DeleteMe plan when you go to JoinDeleteMe.com N2K and use promotion promo code N2K at checkout. The only way to get 20% off is to go to JoinDeleteMe.com n2k and enter code N2K at checkout. That's JoinDeleteMe.com N2k code N2K. Steve Schmidt is Chief Security Officer at Amazon. I recently caught up with him for a behind the scenes look at securing a major event.
As the Chief Security Officer for Amazon, my job is really all about protecting customers. It's about ensuring the services that AWS provides meet customer expectations for privacy and security of their data, while also focusing on ensuring our shoppers have a secure experience whether they're discovering, ordering or delivering the products that they seek. I think that the area that is most intriguing though is the new stuff. A few years ago AWS was the new thing. The new thing now satellites in space and figuring out how do we securely connect them to our data centers and allow customers to enjoy access to the Internet and to AWS services wherever they are around the world.
Well, before we dig into some of the specific details here, can you give our listeners an idea of what your day to day is like and how your know delegating these responsibilities amongst your team?
My day to day is really one of combining both strategic and tactical. Amazon has a series things that we live by, our mission statement and the way we think about our businesses and one of them is dive deep. It's one of the things that I really love about the company and it allows me the freedom to go into the minutia of Individual components of the businesses. Now, in my position, you have to do that in an auditing fashion. You can't go deeply into everything, even though it's actually probably the most fun part of the business. And instead what I do is focus on auditing specific areas to ensure that the people who are running our individual businesses are doing so in a way that's consistent with what our customers expect. That means ensuring that they've got the security standards up to date, that they're developing software in the right way, that they're responding rapidly when something is reported to us, and discovering problems before our customers are impacted by them, and coupling that at the same time with thinking, what's going to happen two years, three years, five years down the road in our industry? How are we going to make sure that we've got the investments going right now that allow us to be sufficiently protected down the road? A great example of that was multi factor authentication, for example. You're hearing quite a bit about that right now. A lot of businesses are pushing their customers to use multi factor authentication. We chose to invest in hardware based multi factor authentication almost 10 years ago because we saw that it was going to be the one thing that was really effective against stopping certain kinds of social engineering attacks, ones that some of the really good adversaries employ against our customers and they try and employ against our staff.
One of the things that you talk about is the integration of physical security and logical security. Could you explain the difference between those two?
So physical security is what people think of as, do I have a barrier around something that I'm protecting? Is it a lock on the door or a fence around a building, an alarm system, making sure that things are secure, maybe some CCTV cameras, that sort of thing? It's a barrier to keep a person from getting to a thing. Logical security, on the other hand, are all of the controls that we apply to data, the kinds of things that we wrap around data to protect it, Whether it be something like encryption or firewalls or access control systems. And if you think about access to data, that's really been what adversaries have wanted for a very, very long time. Spies back in the early days of humanity were always focused on getting information, data. And they would do that by visiting somebody else's castle or corrupting one of their staff to give them information, et cetera. When we got better at that, we put up walls around things, we put things in safes, we encoded them or encrypted it to make it harder to steal. And that meant that Our adversaries had to think about new ways to get access to that data. Same thing happened in the logical world. When we put stuff on computer systems, the adversaries realized all of a sudden, wait a minute, I don't have to break into that building anymore. I can break into the computer network quite often because that computer network is connected to the outside world. And if I can break into the computer network, I can get to the data that's stored within that computer network. And so to wrap that all back to the beginning, one of the jobs that I have at Amazon is combining the disciplines of physical and logical security, because we have to do both of them correctly in order to ensure that our customers data is safe.
And how do you dial that in? How do you make sure that you have the proper balance between those two things?
So it's not as much a balance between the two as it is sufficiency in both. What I mean by sufficiency is, are we doing enough in each area? A lot of people will say, well, can't you protect that particular thing completely? Like, well, yes, but it would also be completely unusable at that point. You know, I could take the data and I could put in a block of concrete and sink it to the bottom of the ocean.
Right.
But that really isn't terribly useful at that point. So we have to find ways to do enough to dissuade the adversaries that we're faced with. And we do that in a lot of ways. It's often focused on layered defenses. So layered defenses means, for example, in the physical world, you don't just have a lock on a room, you also secure the room with cctv and that room is within a building that's separately secured and that building has fences around it that have intrusion detection systems on it, et cetera. Same thing happens in the logical world quite often. In the old days of computer systems, people said, ah, I have a firewall, I am safe. Well, we all know now that is not a thing. In fact, firewalls often give people a false sense of safety. So really good control over data in the logical world now means that it has to be encrypted, it has to be access controlled. You have to monitor the access to ensure that it's being used appropriately and so forth. And in order to make sure that you are doing enough, you have to test your defenses constantly. Tests happen in the physical world and they happen in the logical world. So in the physical world, this, by the way, is one of the best jobs in the company. Is we employ people who are physical penetration testers. That means their job is to break into our buildings and to try and get access to our stuff. So we literally have people who scale walls and tunnel under fences and try and defeat alarm systems. It's like stuff out of a spy movie. And it is their job every day to try and do that. And it's the job of our defenders to catch them and make sure that they can't actually get in. And so there really is no better way to test anything than to red team it. That happens in the logical world too. We have a red team whose job it is, is to break into our systems and to ensure that whatever is in there is appropriately protected and to test our defenders to make sure that our defenders are doing their job appropriately as well.
Well, looking at an event like Re Invent and the high profile nature of that, what sorts of cyber threats do you prepare for?
So Re Invent is something that we start preparing for literally when one year conference ends, we start preparing for the next year. We go through a hot wash to determine what worked well and where. We need improvements to be made both in the physical world and in a logical world. And the first thing that we do in ensuring that our customers are safe and secure from a logical perspective, is to provide them with a safe network. And so quite often when you go to a conference, you're going to use whatever WI FI is there. We've chosen to put our own WI FI networks in place because that allows us to ensure that they're appropriately encrypted from one end to the other, but more importantly that they're monitored. And we have a team whose job it is to keep an eye on the networks, to identify situations where people might try and spoof our networks, to trick our customers. That happens every year. And we catch people every year who are trying to do that. And what the adversaries are trying to do there is to get access to the traffic in between the customer and something else on the outside world. Now, because AWS encrypts all the traffic that goes to and from our API endpoints, it really isn't gonna do any good for someone to get in the middle of that. But our customers use a lot of services beyond aws and since they're at our conference, we wanna make sure we're doing whatever we can to help them be safe and secure, whether they're using AWS or using something else.
I'm curious, you know, kind of flipping it around for the folks who are attending your conference. Do you have any words of wisdom or best practices for them to both get the most out of it but also make sure that they are as secure as possible, certainly.
So get the most out of it. The best thing that people can do is plan in advance what they want to see. A lot of the sessions are very, very well attended and there are waiting lines for them sometimes. But we offer reserve seating. So for those customers who are interested they should always get in the reserve CQ and grab the seats that they want for the conference areas that they want and plan out their path so that they can have a reasonable time to get between various different things to be safe. It's very straightforward. Keep your eyes open. Don't leave your valuables out where other people could see them and they might have access to them. And make sure you keep your head about you when you're going around on the town.
Unknown
If you're outside of our venues, wear comfortable shoes, right?
Steve Schmidt
You know, there is so much truth to that. Every year I end up hitting my steps way early in the week. When you go to Las Vegas. Yep.
Yeah, yeah. That's Steve Schmidt, Chief Security Officer at Amazon.
Unknown
And now a message from our sponsor. Zscaler, the leader in cloud security. Enterprises have spent billions of dollars on firewalls and VPNs, yet breaches continue to rise by an 18% year over year increase in ransomware attacks and a $75 million record payout in 2024. These traditional security tools expand your attack surface with public facing IPs that are exploited by bad actors more easily than ever with AI tools. It's time to rethink your security. Zscaler Zero Trust plus AI stops attackers by hiding your attack surface making apps and IPs invisible eliminating lateral movement Connecting users only to specific apps, not the entire network. Continuously verifying every request based on identity and context Simplifying security management with AI powered automation and detecting threats using AI to analyze over 500 billion daily transactions. Hackers can't attack what they can't see. Protect your organization with Zscaler Zero Trust and AI. Learn more@zscaler.com Security.
Dave Bittner
I can say to my new Samsung Galaxy S25 Ultra hey, find a keto friendly restaurant nearby and text it to Beth and Steve. And it does without me lifting a finger so I can get in more squats anywhere I can.
Steve Schmidt
1, 1, 2, 3 will that be cash or credit? Credit.
Unknown
4 Galaxy S25 Ultra the AI companion that does the heavy lifting. So you can do you get yours@samsung.com compatible with select apps requires Google Gemini account results may vary based on input. Check responses for accuracy.
Steve Schmidt
And finally, YouTube is turning 20. And while we know it's a global juggernaut, there's a lot Google won't say, like exactly how many videos exist or how much time humanity spends glued to it. So researchers took matters into their own hands, running a randomized number generator to guess video URLs. The result? An estimated 14.8 billion videos live on YouTube, with users watching the equivalent of millions of years of content every month. But there's a twist. Most of it goes unnoticed. Nearly 4% of videos have never been watched, 74% have no comments, and the median view count is just 41. While YouTube sells itself as a stage for superstars, the reality is far messier. As we enter YouTube's third decade, one thing is clear. It's everywhere. It's massive. And we still don't fully understand it. And that's the Cyberwire. Be sure to check out this weekend's episode of Research Saturday and my conversation with Selena Larson from proofpoint. We're discussing their research why biasing advanced persistent threats over cybercrime is a security risk. That's Research Saturday. Check it out. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to cyberwire2k.com N2K's senior producer is Alice Carruth. Our Cyberwire producer is Liz Stokes. We're mixed by Trey Hester with original music and sound design by Elliot Pelxman. Our executive producer is Jennifer Ibin. Peter Kilby is our publisher, and I'm Dave Bittner. Thanks for listening. We'll see you back here next week.
CyberWire Daily: The Political Shake-Up at the FBI
Release Date: February 21, 2025
Host: N2K Networks
The podcast opens with a detailed analysis of the recent Senate confirmation of Kash Patel as the new FBI Director. Confirmed by a narrow 51-49 vote, Patel's appointment has stirred significant controversy due to his staunch loyalty to former President Donald Trump and his vocal stance on reforming the FBI.
Shift in FBI Focus: Patel advocates for transitioning the FBI's emphasis from intelligence gathering to traditional law enforcement. This shift follows recent Justice Department upheavals and demands for agent disclosures related to the January 6 investigations, sparking fears of political retaliation.
"His confirmation follows Justice Department shakeups and demands for agent names tied to January 6 investigations, raising fears of political retribution."
Political Ramifications: Democrats are alarmed by Patel's previous remarks, where he referred to FBI investigators as "criminal gangsters" and suggested that January 6 rioters are "political prisoners." Critics worry that Patel may leverage the FBI to target political opponents of Trump, potentially undermining the agency's independence.
"Patel's past remarks, labeling FBI investigators as criminal gangsters and suggesting January 6th rioters are political prisoners alarmed Democrats."
Cybersecurity Implications: From a cybersecurity standpoint, Patel’s leadership could influence federal investigations into cyber threats, foreign influence operations, and domestic extremism. His inclination away from intelligence-driven operations may weaken nationwide cybersecurity initiatives, increasing vulnerabilities within agencies and critical infrastructure.
"From a cybersecurity perspective, Patel's leadership could impact federal investigations into cyber threats, foreign influence campaigns and domestic extremism."
The Securities and Exchange Commission (SEC) has rebranded its Crypto Assets and Cyber Unit to the Cyber and Emerging Technologies Unit (CETU). This change broadens the unit’s focus beyond cryptocurrency fraud to encompass hacking, social media scams, and AI-related threats.
Leadership and Scope: Under the leadership of Laura de Allaire, CETU continues to investigate crypto-related fraud but also addresses a wider array of technological threats.
"Led by Laura de Allaire, the unit will still investigate crypto related fraud, but critics worry."
Impact of Rebranding: Critics argue that the rebranding signals a diminished enforcement stance, particularly under the Trump administration, which is perceived as more crypto-friendly. This shift follows significant SEC actions against major crypto firms like FTX and Binance.
"The change follows SEC enforcement actions against major crypto firms like FTX and Binance and its previous focus on unregistered asset offerings and securities violations."
Future of Crypto Regulation: The rebrand reflects ongoing political shifts in U.S. crypto regulation, raising questions about the SEC’s future aggressiveness in policing blockchain-related fraud and market abuses.
"The change reflects ongoing political shifts in US Crypto regulation, raising questions about how aggressively the SEC will police blockchain related fraud and market abuses moving forward."
Microsoft has introduced Majorana One, the first quantum chip designed to accelerate the development of quantum computers capable of breaking current encryption standards within years instead of decades.
Technological Breakthrough: Powered by a new topological core architecture, Majorana One could lead to million-qubit systems that solve problems beyond classical computers' reach.
"The breakthrough, powered by a new topological core architecture, could lead to million qubit systems capable of solving problems beyond the reach of classical computers."
Cybersecurity Risks: This advancement presents significant cybersecurity threats as quantum machines could potentially crack encryption protocols like RSA and AES, exposing sensitive data.
"Quantum machines will be able to crack encryption protocols like RSA and AES, exposing sensitive data."
NIST’s Response: In 2024, NIST formalized post-quantum cryptography standards, urging organizations to adopt quantum-secure algorithms. However, challenges such as unclear ownership of transitions and poor cryptographic visibility persist.
"To counter this, NIST formalized post quantum cryptography standards in 2024, urging organizations to adopt quantum secure algorithms."
Adoption in the Financial Sector: While the financial sector leads in developing quantum-resistant solutions, broader adoption is essential to mitigate threats before quantum computing becomes widespread.
"The financial sector is leading in developing quantum resistant solutions, but broader adoption is essential before quantum computers become a widespread threat."
A significant breach has exposed nearly 200,000 internal messages from the Black Basta ransomware group, revealing deep-seated conflicts and the gang’s decline.
Details of the Leak: The chat logs, dated from September 2023 to September 2024, were first shared on Mega by a user named Exploit Whispers before migrating to Telegram. Cybersecurity firm Prodaft has confirmed the leak's authenticity.
"Cybersecurity firm Prodaft confirmed the leak is likely legitimate and sheds light on Black Basta's decline."
Internal Conflicts: The group's struggles were primarily over financial priorities and leadership disputes, particularly involving a member known as Tramp, who was responsible for Q Bot distribution.
"The group, once a major ransomware player, struggled with internal disputes, particularly over financial priorities and leadership issues."
Aftermath: Many former members have migrated to other ransomware groups like Cactus and Akira, continuing operations under new banners. The leak underscores how internal conflicts can destabilize cybercriminal organizations.
"The leak provides valuable intelligence, further proving that cybercriminal groups often collapse due to internal conflicts."
The Cybersecurity and Infrastructure Security Agency (CISA) has issued advisories highlighting severe vulnerabilities in CRAFT CMS and various Industrial Control Systems (ICS).
CRAFT CMS Vulnerability: A high-severity remote code execution (RCE) vulnerability has been added to CISA's Exploited Vulnerabilities catalog. Despite CRAFT CMS’s small market share, over 41,000 instances may be affected, especially if security keys are compromised.
"The flaw was patched in January and affects installations where the security key is already compromised."
Industrial Control Systems Risks: CISA has also released seven advisories detailing critical vulnerabilities in ICS from companies like ABB, Siemens, and Mitsubishi Electric. These flaws pose severe threats to critical infrastructure, with one vulnerability in ABB Flexion controllers scoring a perfect 10 on the CVSS scale.
"Notable is a vulnerability affecting ABB Flexion controllers, scoring a 10 out of 10 on the CVSS scale. This allows remote code execution and sensitive data exposure."
Urgent Patching Recommended: Organizations are urged to apply patches immediately to mitigate exploitation risks and protect critical infrastructure.
"CISA urges organizations to apply patches immediately to mitigate exploitation risks and safeguard critical infrastructure from cyber threats."
Security engineers have unveiled proof-of-concept exploits for four critical vulnerabilities in Ivanti Endpoint Manager, each rated 9.8 out of 10 on the CVSS scale.
Nature of Vulnerabilities: These flaws, patched in January, allow unauthenticated attackers to leak NTLM v2 hashes by manipulating the software into authenticating with a remote server. This can lead to account impersonation and full system compromise.
"The vulnerabilities allow unauthenticated attackers to leak NTLM v2 hashes by tricking the software into authentication with a remote server, enabling account impersonation and system compromise."
Increased Risk Post-Disclosure: Although Ivanti reports no evidence of active exploitation, the public release of these exploits heightens the risk for unpatched systems.
"Ivanti states there is no evidence of active exploitation, but with the proof of concept now public, the risk has increased."
Immediate Actions Advised: Ivanti is urging users to apply the latest patches, including a version 2 update that addresses issues from the original January patch.
"The company urges immediate patching, including a v2 patch update that fixes issues caused by the original January patch."
Eyeglass retailer Warby Parker has been fined $1.5 million by the U.S. Department of Health and Human Services Office for Civil Rights (OCR) following credential stuffing attacks that compromised nearly 200,000 customer accounts.
Details of the Breach: Between September and November 2018, hackers accessed electronic protected health information (ePHI), including personal and payment details, through credential stuffing attacks. Further breaches occurred in 2020 and 2022, prompting comprehensive investigations.
"The attacks, which occurred between September and November 2018, allowed hackers to access electronic protected health information, including names, addresses, payment card details and eyewear prescriptions."
Regulatory Findings: OCR identified three HIPAA security rule violations, highlighting Warby Parker's failures in conducting risk assessments, implementing necessary security measures, and reviewing system activity logs.
"OCR found three HIPAA security rule violations, citing Warby Parker's failure to conduct risk assessments, implement security measures, and review system activity logs."
Company's Response: Although notified in September 2024, Warby Parker waived its right to a hearing, likely to avoid further scrutiny of its security practices.
"Though notified in September 2024, the company waived its right to a hearing, likely to avoid further scrutiny of its security practices."
The episode features an in-depth conversation with Steve Schmidt, Amazon’s Chief Security Officer, providing insights into securing major events like AWS’s Re:Invent conference.
Role and Responsibilities: Schmidt emphasizes his dual focus on strategic and tactical security measures, ensuring that AWS services meet customer expectations for privacy and data security.
"As the Chief Security Officer for Amazon, my job is really all about protecting customers." [13:25]
Integration of Physical and Logical Security: Schmidt explains the distinction and synergy between physical security (e.g., locks, CCTV) and logical security (e.g., encryption, firewalls). He highlights Amazon’s layered defense approach, employing both physical and logical measures to protect customer data.
"Physical security is what people think of as, do I have a barrier around something that I'm protecting?... Logical security, on the other hand, are all of the controls that we apply to data..." [16:18]
Red Team Operations: To ensure the effectiveness of security measures, Amazon employs red teams for both physical and logical security. These teams simulate attacks to identify and rectify vulnerabilities.
"We literally have people who scale walls and tunnel under fences and try and defeat alarm systems... we have a red team whose job it is, is to break into our systems..." [18:39]
Securing Large-Scale Events: For events like Re:Invent, Amazon establishes secure, encrypted Wi-Fi networks monitored by dedicated teams to prevent spoofing and protect customer traffic.
"Our first thing in ensuring that our customers are safe and secure from a logical perspective, is to provide them with a safe network." [20:51]
Advice for Conference Attendees: Schmidt advises attendees to plan their schedules in advance, secure their valuables, and remain vigilant to maximize both their experience and security.
"Keep your eyes open. Don't leave your valuables out where other people could see them and they might have access to them." [22:34]
The episode concludes with a segment on YouTube's staggering growth and the unknowns surrounding its vast content library.
Scale of Content: Researchers estimate that YouTube hosts approximately 14.8 billion videos, with users collectively watching millions of years’ worth of content each month.
"The result? An estimated 14.8 billion videos live on YouTube, with users watching the equivalent of millions of years of content every month." [25:40]
Engagement Metrics: Despite its popularity, a significant portion of YouTube’s content remains underutilized, with nearly 4% of videos never being watched and 74% receiving no comments. The median view count stands at just 41.
"Nearly 4% of videos have never been watched, 74% have no comments, and the median view count is just 41." [25:40]
Complex Ecosystem: As YouTube celebrates its third decade, it remains a complex and omnipresent platform with many aspects still not fully understood.
"As we enter YouTube's third decade, one thing is clear. It's everywhere. It's massive. And we still don't fully understand it." [25:40]
This episode of CyberWire Daily provided a comprehensive overview of significant developments in the cybersecurity landscape, from political shifts within the FBI and regulatory changes at the SEC to technological advancements and emerging threats. The in-depth interview with Amazon's Chief Security Officer offered valuable insights into large-scale event security, while discussions on ransomware leaks and critical vulnerabilities underscored the ever-evolving challenges in cybersecurity. The episode concluded with an intriguing exploration of YouTube's vast and largely uncharted digital expanse.
Notable Quotes:
Production Credits:
For more insights, visit CyberWire's website or subscribe to the podcast on your favorite platform.