Épisodes

  • Cybersecurity Month in Review: Uncovering Digital and Physical Threats
    Jun 7 2025

    In this episode of the 'Cybersecurity Today: The Month in Review' show, host Jim welcomes regular guests Laura Payne and David Shipley, along with newcomer Anton Levaja. The trio dives deep into various cybersecurity stories, analyzing trends, threats, and recent incidents. Topics include the intriguing Mystery Leaker exposing cyber criminals, the rise and sophistication of LockBit ransomware, the devastating ransomware attack on Coinbase and their bold counter-response, and the physical dangers faced by cryptocurrency entrepreneurs. The episode also highlights the innovation in law enforcement tactics and the pressing need for better cybersecurity awareness and education. They wrap up on a hopeful note, showcasing a young scout's inspiring project on cyber fraud prevention that gained support from the local police.

    00:00 Introduction and Panelist Welcome
    00:38 Show Format and Story Introduction
    01:28 The Mystery Leaker Story
    03:35 Law Enforcement and Cyber Crime
    10:51 Coinbase Ransomware Incident
    18:04 Physical Threats in the Crypto World
    24:56 Operation Shamrock and Organized Crime
    25:19 Breaking News: Kidnapping Mastermind Arrested
    26:18 Quishing: The Clever Side of Cybercrime
    27:11 QR Code Scams and Consumer Protection
    31:08 Generational Differences in Cyber Threats
    32:05 The Evolution of Cyber Attacks
    38:40 Physical Crime in the Digital Age
    41:10 Law Enforcement and Cybersecurity
    43:55 Government Surveillance and Privacy Concerns
    46:08 Feel-Good Story: Young Cybersecurity Advocate

    Voir plus Voir moins
    49 min
  • Cyber Extortion, Ukraine's Cyber Offensive, and Chrome Trust Shake-up
    Jun 6 2025

    Cybersecurity Today, hosted by Jim Love, delves into the latest in cyber threats. Cyber criminals have breached 20 organizations via convincing fake IT support calls, targeting Salesforce data for extortion. Ukraine's intelligence claims a significant cyber operation against Russia's aircraft manufacturer, stealing sensitive data and highlighting Ukraine's growing cyber capabilities. Google Chrome will stop trusting certificates from two major authorities due to compliance failures, affecting millions of web visitors. Lastly, a $400 million hack on Coinbase was executed using phone cameras, reminding us of the potency of simple attacks.

    00:00 Introduction and Headlines
    00:23 Fake IT Support Scam Hits 20 Companies
    03:52 Ukraine's Cyber Operation Against Russia
    07:05 Google Chrome Stops Trusting Two Certificate Authorities
    09:11 $400 Million Hack from a Phone Camera
    11:24 Conclusion and Contact Information

    Voir plus Voir moins
    12 min
  • Emergency Patches, Ransomware Exposes, and Rising QR Code Scams
    Jun 4 2025

    In this episode of Cybersecurity Today, host Jim Love discusses the latest urgent security updates and cyber threats. Google has released an emergency Chrome patch to fix a high-severity zero-day vulnerability, while Microsoft issued an emergency patch to resolve Windows 11 boot failures caused by their May 2025 update. A mysterious whistleblower known as 'Gang Exposed' is doxing major ransomware leaders, providing invaluable intelligence for global cybersecurity efforts. Additionally, 'Quishing,' or QR code phishing, is emerging as a new threat, with cybercriminals taping malicious QR codes on public lampposts and street corners. This trend bypasses traditional digital defenses, underscoring the need for public awareness and vigilance. The episode emphasizes the importance of immediate updates, informed vigilance, and proactive cybersecurity measures.

    00:00 Emergency Chrome Patch and Windows 11 Boot Fix
    00:28 Google's Zero-Day Vulnerability in Chrome
    02:28 Microsoft's Emergency Update for Windows 11
    05:35 Gang Exposed: Unmasking Ransomware Leaders
    07:55 Quishing: The New QR Code Phishing Threat
    10:22 Conclusion and Viewer Engagement

    Voir plus Voir moins
    11 min
  • Cybersecurity Incidents: Eddie Steeler Malware, ConnectWise Breach, and Nova Scotia Power Data Theft
    Jun 2 2025

    In this episode of Cybersecurity Today, host David Shipley discusses several key cyber incidents affecting organizations and individuals. A new rust-based information stealer, known as Eddie Steeler, is being distributed via deceptive CAPTCHA verification pages. ConnectWise, a management software firm, has been breached in an attack suspected to be linked to a nation-state actor, affecting a limited number of its ScreenConnect customers. Additionally, threat actors are now abusing Google App Script to bypass phishing defenses, exploiting the trusted Google brand to trick users. Lastly, a significant data breach at Nova Scotia Power has exposed the social insurance numbers of up to 140,000 customers, making it one of the largest utility data breaches in North America.

    00:00 Introduction to Today's Cybersecurity News
    00:31 Eddie Steeler Malware Campaign
    02:32 ConnectWise Cyber Attack
    04:49 Google App Script Phishing Attacks
    06:50 Nova Scotia Power Data Breach
    08:02 Conclusion and Listener Engagement

    Voir plus Voir moins
    8 min
  • Pig Butchering: Operation Shamrock Fights Back
    May 31 2025

    In this episode, the host delves into the alarming rise of 'pig butchering' scams, a form of fraud that preys on vulnerable and trusting individuals, often leaving them financially and emotionally devastated. These scams are orchestrated by organized crime syndicates that use brutal methods, including violence and human trafficking, to sustain their operations. Erin West, a former prosecutor, discusses her transition to founding Operation Shamrock, a nonprofit focused on combatting these scams through education, law enforcement support, and victim assistance. West explains the severity of the issue, sharing insights into the terrifying environments where these scams are executed and the challenges victims face in reporting and recovering their losses. She emphasizes the need for public awareness, empathy, and collaborative efforts to tackle the global crisis. The episode concludes with actionable steps for cybersecurity professionals and the public to join the fight against this pervasive fraud.

    00:00 Introduction to Cybersecurity and Pig Butchering Scams
    01:42 The Human Impact of Scams
    03:33 Operation Shamrock: Fighting Back
    04:04 Interview with Erin West: From Prosecutor to Advocate
    06:24 Understanding the Scale and Evolution of Scams
    08:33 The Role of Technology in Modern Scams
    12:17 Operation Shamrock's Mission and Strategies
    15:13 Empowering Victims and Law Enforcement
    29:28 Raising Awareness and Taking Action
    37:50 Conclusion and Call to Action

    Voir plus Voir moins
    39 min
  • Cybersecurity Today: Hijacker Scams, Ransomware Attacks, and Summer Travel Threats
    May 30 2025

    In this episode of Cybersecurity Today, host Jim Love covers critical updates in the world of cyber threats. The FBI warns of hijackers posing as IT support to infiltrate law firms, a Wisconsin city reveals a ransomware attack affecting 67,000 residents, and a Texas city refuses to pay a ransom, risking the public release of sensitive data. The episode also highlights the 3-2-1-1-0 backup strategy as a defense against ransomware and reports on sophisticated scams targeting summer travelers. Additionally, Jim previews tomorrow’s discussion on scammers targeting vulnerable groups.

    00:00 Introduction and Headlines
    00:29 FBI Warns of IT Support Scams Targeting Law Firms
    03:18 Ransomware Attack on Sheboygan, Wisconsin
    05:24 Texas City Refuses Ransom Payment
    07:05 Understanding the 3-2-1-1-0 Backup Strategy
    09:37 Summer Travel Scams on the Rise
    12:55 Conclusion and Upcoming Topics

    Voir plus Voir moins
    14 min
  • Phishing Scams, DNS Hijacking, and Cybersecurity Leadership Shakeup
    May 28 2025

    In this episode of Cybersecurity Today, host Jim Love explores the intricacies behind phishing emails that cleverly spoof Microsoft addresses, making many fall for scams despite appearing legitimate. Love emphasizes the need for a stringent 'zero trust' approach to counter these advanced tactics.

    Additionally, the episode delves into the activities of the hacking group Hazy Hawk, which exploits misconfigured DNS records to hijack trusted domains and propagate malware. Organizations are warned about the importance of regular DNS audits to prevent such attacks. The episode also covers the alarming wave of departures at the Cybersecurity and Infrastructure Security Agency (CISA), raising concerns over the agency's effectiveness amid increasing cyber threats.

    In another segment, Love discusses a sophisticated fraud operation out of Hanoi, where perpetrators manipulated X's Creator Revenue Sharing Program to siphon funds through fraudulent engagement metrics. The need for built-in fraud prevention mechanisms in digital reward systems is stressed. The episode concludes with a call for listener feedback and support.

    00:00 Introduction and Overview
    00:27 Phishing Scams: Authentic-Looking Emails
    02:58 DNS Misconfigurations and Hazy Hawk
    05:36 CISA Leadership Exodus
    08:16 X's Creator Revenue Sharing Fraud
    10:56 Conclusion and Contact Information

    Voir plus Voir moins
    12 min
  • Unraveling Cyber Threats: Ransomware, Kidnapping, and Record-Breaking DDoS Attacks
    May 26 2025

    In this episode of Cybersecurity Today, host David Shipley dives into several alarming cyber incidents.

    The show starts with Nova Scotia Power's confirmation of a ransomware attack that forced the shutdown of customer-facing systems and led to data being published on the dark web. The company decided not to pay the ransom, adhering to law enforcement guidance and sanctions laws.

    A shocking case in New York follows, involving a crypto investor charged with kidnapping and torturing a man to obtain his Bitcoin wallet password.

    The next segment highlights a record-setting DDoS botnet, Aisuru, which performed a test attack that peaked at 6.3 terabits per second, posing a disproportionate threat to online retailers.

    The final story covers Microsoft's controversial AI feature, Recall, which takes screenshots every three seconds and raises significant privacy concerns. The episode underscores the growing need for robust cybersecurity measures and effective legislation.

    00:00 Introduction and Headlines
    00:30 Nova Scotia Power Ransomware Attack
    02:57 Ransomware Trends and Statistics
    03:51 Operation End Game: A Global Win Against Ransomware
    04:25 Crypto Investor's Shocking Crime
    05:57 Record-Breaking DDoS Botnet
    07:36 Microsoft's Controversial AI Feature Recall
    09:10 Conclusion and Sign-Off

    Voir plus Voir moins
    10 min