<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="/stylesheet.xsl" type="text/xsl"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:podcast="https://podcastindex.org/namespace/1.0">
  <channel>
    <atom:link rel="self" type="application/atom+xml" href="https://feeds.transistor.fm/30-day-infosec" title="MP3 Audio"/>
    <atom:link rel="hub" href="https://pubsubhubbub.appspot.com/"/>
    <podcast:podping usesPodping="true"/>
    <title>30-Day InfoSec</title>
    <generator>Transistor (https://transistor.fm)</generator>
    <itunes:new-feed-url>https://feeds.transistor.fm/30-day-infosec</itunes:new-feed-url>
    <description>30-Day InfoSec, a monthly information security recap show for the latest news, stories, and happenings from around the cybersecurity community.</description>
    <copyright>© 2025 TJ Nel, Ryan Hays</copyright>
    <podcast:guid>5255cc98-dcf6-55d5-a1a0-4c450e40e6aa</podcast:guid>
    <podcast:locked owner="tj@30dayinfosec.com">no</podcast:locked>
    <language>en</language>
    <pubDate>Wed, 23 Jul 2025 10:36:36 -0400</pubDate>
    <lastBuildDate>Tue, 02 Dec 2025 16:13:20 -0500</lastBuildDate>
    <link>https://30dayinfosec.com</link>
    <image>
      <url>https://img.transistor.fm/lU4U2Z827z1VHqty1PJOosl92bn3UWr_GNo2VSpdjqU/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9zaG93/LzEwNDYyLzE1ODg4/MDA4MDItYXJ0d29y/ay5qcGc.jpg</url>
      <title>30-Day InfoSec</title>
      <link>https://30dayinfosec.com</link>
    </image>
    <itunes:category text="Technology"/>
    <itunes:category text="Technology"/>
    <itunes:type>episodic</itunes:type>
    <itunes:author>TJ Nel, Ryan Hays</itunes:author>
    <itunes:image href="https://img.transistor.fm/lU4U2Z827z1VHqty1PJOosl92bn3UWr_GNo2VSpdjqU/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9zaG93/LzEwNDYyLzE1ODg4/MDA4MDItYXJ0d29y/ay5qcGc.jpg"/>
    <itunes:summary>30-Day InfoSec, a monthly information security recap show for the latest news, stories, and happenings from around the cybersecurity community.</itunes:summary>
    <itunes:subtitle>30-Day InfoSec, a monthly information security recap show for the latest news, stories, and happenings from around the cybersecurity community..</itunes:subtitle>
    <itunes:keywords>Computer, Security, Information Security</itunes:keywords>
    <itunes:owner>
      <itunes:name>TJ Nel</itunes:name>
    </itunes:owner>
    <itunes:complete>No</itunes:complete>
    <itunes:explicit>Yes</itunes:explicit>
    <item>
      <title>Episode 05: Insecure IoT, Trickbot Takedown, Nation-state Hacking and Charitable Hackers</title>
      <itunes:episode>5</itunes:episode>
      <podcast:episode>5</podcast:episode>
      <itunes:title>Episode 05: Insecure IoT, Trickbot Takedown, Nation-state Hacking and Charitable Hackers</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">b88fdfc6-7a04-4595-beb8-0b71142ba38f</guid>
      <link>https://share.transistor.fm/s/739c04ab</link>
      <description>
        <![CDATA[<p><strong>IoT is Vulnerable</strong><br>IoT Homefootage on sale in the deep and dark web and an intimate IoT device is found to have an exploit.</p><ul><li>https://www.hackread.com/3tb-clips-hacked-home-security-cameras-leaked/</li><li>https://gizmodo.com/a-security-flaw-could-send-your-dick-to-jail-forever-1845286359</li></ul><p><strong>Trickbot Takedown via Private and Public Sector<br></strong>Both Microsoft and USCybercom both try to disrupt the Trickbot gang using different approaches</p><ul><li>https://krebsonsecurity.com/2020/10/microsoft-uses-copyright-law-to-disrupt-trickbot-botnet/</li><li>https://krebsonsecurity.com/2020/10/report-u-s-cyber-command-behind-trickbot-tricks/</li></ul><p><strong>Government Sponsored Cyber Attacks <br></strong>The UK reveals it carried out cyberattacks against Russia, Iran and Russia found to be interfering with US elections. The NSA releases a list of the 25 most used exploits in attack from China.</p><ul><li>https://www.cnn.com/2020/10/21/politics/fbi-election-security/index.html</li><li>https://www.ibtimes.sg/uk-carried-out-secret-cyberattacks-russia-retaliation-says-former-national-security-adviser-52806</li><li>https://www.zdnet.com/article/nsa-publishes-list-of-top-25-vulnerabilities-currently-targeted-by-chinese-hackers/</li></ul><p><strong>Bug Bounty crew spends 3 months hacking Apple<br></strong>A bug bounty crew cashes in big hacking apple infrastructure.</p><ul><li>https://samcurry.net/hacking-apple/</li></ul><p><strong>Ransomware actor gives to charity<br></strong>Darkside ransomware actors show proof of their philanthropy by press releasing a receipt of their donation.</p><ul><li>https://www.hackread.com/3tb-clips-hacked-home-security-cameras-leaked/</li></ul><p><strong>Upcoming Events:</strong></p><ul><li>Blackhat EU 2020 - Nov. 9</li><li>OSDF Con - Nov 18</li><li>Cyber Security &amp; Data Protection Summit - Nov 19</li></ul><p><strong>Intro/Outro Music Credits<br></strong>Something Elated (Broke For Free: https://freemusicarchive.org/music/Broke_For_Free/Something_EP/Broke_For_Free_-_Something_EP_-_05_Something_Elated) / CC BY 3.0: https://creativecommons.org/licenses/by/3.0/us/</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>IoT is Vulnerable</strong><br>IoT Homefootage on sale in the deep and dark web and an intimate IoT device is found to have an exploit.</p><ul><li>https://www.hackread.com/3tb-clips-hacked-home-security-cameras-leaked/</li><li>https://gizmodo.com/a-security-flaw-could-send-your-dick-to-jail-forever-1845286359</li></ul><p><strong>Trickbot Takedown via Private and Public Sector<br></strong>Both Microsoft and USCybercom both try to disrupt the Trickbot gang using different approaches</p><ul><li>https://krebsonsecurity.com/2020/10/microsoft-uses-copyright-law-to-disrupt-trickbot-botnet/</li><li>https://krebsonsecurity.com/2020/10/report-u-s-cyber-command-behind-trickbot-tricks/</li></ul><p><strong>Government Sponsored Cyber Attacks <br></strong>The UK reveals it carried out cyberattacks against Russia, Iran and Russia found to be interfering with US elections. The NSA releases a list of the 25 most used exploits in attack from China.</p><ul><li>https://www.cnn.com/2020/10/21/politics/fbi-election-security/index.html</li><li>https://www.ibtimes.sg/uk-carried-out-secret-cyberattacks-russia-retaliation-says-former-national-security-adviser-52806</li><li>https://www.zdnet.com/article/nsa-publishes-list-of-top-25-vulnerabilities-currently-targeted-by-chinese-hackers/</li></ul><p><strong>Bug Bounty crew spends 3 months hacking Apple<br></strong>A bug bounty crew cashes in big hacking apple infrastructure.</p><ul><li>https://samcurry.net/hacking-apple/</li></ul><p><strong>Ransomware actor gives to charity<br></strong>Darkside ransomware actors show proof of their philanthropy by press releasing a receipt of their donation.</p><ul><li>https://www.hackread.com/3tb-clips-hacked-home-security-cameras-leaked/</li></ul><p><strong>Upcoming Events:</strong></p><ul><li>Blackhat EU 2020 - Nov. 9</li><li>OSDF Con - Nov 18</li><li>Cyber Security &amp; Data Protection Summit - Nov 19</li></ul><p><strong>Intro/Outro Music Credits<br></strong>Something Elated (Broke For Free: https://freemusicarchive.org/music/Broke_For_Free/Something_EP/Broke_For_Free_-_Something_EP_-_05_Something_Elated) / CC BY 3.0: https://creativecommons.org/licenses/by/3.0/us/</p>]]>
      </content:encoded>
      <pubDate>Mon, 09 Nov 2020 23:38:26 -0500</pubDate>
      <author>TJ Nel, Ryan Hays</author>
      <enclosure url="https://media.transistor.fm/739c04ab/c644df29.mp3" length="48937517" type="audio/mpeg"/>
      <itunes:author>TJ Nel, Ryan Hays</itunes:author>
      <itunes:duration>3054</itunes:duration>
      <itunes:summary>In this episode, TJ and Guest Zach discuss Insecure IoT, Trickbot Takedown, Nation-state Hacking and Charitable Hackers</itunes:summary>
      <itunes:subtitle>In this episode, TJ and Guest Zach discuss Insecure IoT, Trickbot Takedown, Nation-state Hacking and Charitable Hackers</itunes:subtitle>
      <itunes:keywords>Computer, Security, Information Security</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 04: Emotet, Twitter Hack, Sev10 CVEs, and the Tesla Ransomware Scandal</title>
      <itunes:episode>4</itunes:episode>
      <podcast:episode>4</podcast:episode>
      <itunes:title>Episode 04: Emotet, Twitter Hack, Sev10 CVEs, and the Tesla Ransomware Scandal</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">d1671ff5-e243-4a8f-8dd9-18cf39cc362b</guid>
      <link>https://share.transistor.fm/s/c50ce040</link>
      <description>
        <![CDATA[<p><strong>Emotet Is back and then not</strong></p><p>The group behind the Emotet malware has popped back up but shortly after that it appears the C2 infrastructure was compromised and started sharing out memes.</p><ul><li><a href="https://www.bleepingcomputer.com/news/security/emotet-malware-operation-hacked-to-show-memes-to-victims/">https://www.bleepingcomputer.com/news/security/emotet-malware-operation-hacked-to-show-memes-to-victims/</a></li><li><a href="https://www.bleepingcomputer.com/news/security/emotet-spam-trojan-surges-back-to-life-after-5-months-of-silence/">https://www.bleepingcomputer.com/news/security/emotet-spam-trojan-surges-back-to-life-after-5-months-of-silence/</a></li></ul><p><br></p><p><strong>Garmin HACKED!!!</strong></p><p>Garmin was hacked recently and the intrusion was used to spread ransomware on the network. The attackers also ended up being paid out $10M by Garmin. </p><ul><li><a href="https://arstechnica.com/information-technology/2020/07/garmans-four-day-service-meltdown-was-caused-by-ransomware/">https://arstechnica.com/information-technology/2020/07/garmans-four-day-service-meltdown-was-caused-by-ransomware/</a></li></ul><p><br></p><p><strong>Twitter Admin Panel Exposed</strong></p><p>Recently a teenager was able to get access to a twitter management panel which allowed them to take over high profile accounts to include Barack Obama, Beyonce as well as Elon Musk. The take over was being used a scam to attempt to get bitcoin from people.</p><ul><li><a href="https://www.cnn.com/2020/07/15/tech/twitter-hack-elon-musk-bill-gates/index.html">https://www.cnn.com/2020/07/15/tech/twitter-hack-elon-musk-bill-gates/index.html</a></li></ul><p><br></p><p><strong>High Profile Exploits Recently Released</strong></p><p>Recently there were several high profile exploits released that were all remote code execution exploits. Vendors such as F5, SAP and Microsoft were all among the vendors affected by these exploits. </p><ul><li><a href="https://threatpost.com/thousands-f5-big-ip-users-takeover/157543/">https://threatpost.com/thousands-f5-big-ip-users-takeover/157543/</a></li><li><a href="https://threatpost.com/critical-sap-bug-enterprise-system-takeover/157392/">https://threatpost.com/critical-sap-bug-enterprise-system-takeover/157392/</a></li><li><a href="https://www.bleepingcomputer.com/news/security/critical-sigred-windows-dns-bug-gets-micropatch-after-pocs-released/">https://www.bleepingcomputer.com/news/security/critical-sigred-windows-dns-bug-gets-micropatch-after-pocs-released/</a></li></ul><p><br></p><p><strong>Tesla Attempted Hack</strong></p><p>A Tesla employee was approached by a supposed Russian sponsored individual in an attempt to compromise the entire organization and spread ransomware. </p><ul><li><a href="https://www.databreachtoday.com/russian-indicted-in-tesla-ransom-scheme-a-14960">https://www.databreachtoday.com/russian-indicted-in-tesla-ransom-scheme-a-14960</a></li></ul><p><strong>Upcoming Events:</strong></p><ul><li><a href="https://ekoparty.org/en_US/%20">https://ekoparty.org/en_US/ </a></li><li><a href="https://www.bsidesclt.org/%20">https://www.bsidesclt.org/ </a></li><li><a href="https://shellcon.io/">https://shellcon.io/ </a></li></ul><p><br><strong>Intro/Outro Music Credits</strong><br>Something Elated (Broke For Free: <a href="https://freemusicarchive.org/music/Broke_For_Free/Something_EP/Broke_For_Free_-_Something_EP_-_05_Something_Elated">https://freemusicarchive.org/music/Broke_For_Free/Something_EP/Broke_For_Free_-_Something_EP_-_05_Something_Elated</a>) / CC BY 3.0: <a href="https://creativecommons.org/licenses/by/3.0/us/">https://creativecommons.org/licenses/by/3.0/us/</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>Emotet Is back and then not</strong></p><p>The group behind the Emotet malware has popped back up but shortly after that it appears the C2 infrastructure was compromised and started sharing out memes.</p><ul><li><a href="https://www.bleepingcomputer.com/news/security/emotet-malware-operation-hacked-to-show-memes-to-victims/">https://www.bleepingcomputer.com/news/security/emotet-malware-operation-hacked-to-show-memes-to-victims/</a></li><li><a href="https://www.bleepingcomputer.com/news/security/emotet-spam-trojan-surges-back-to-life-after-5-months-of-silence/">https://www.bleepingcomputer.com/news/security/emotet-spam-trojan-surges-back-to-life-after-5-months-of-silence/</a></li></ul><p><br></p><p><strong>Garmin HACKED!!!</strong></p><p>Garmin was hacked recently and the intrusion was used to spread ransomware on the network. The attackers also ended up being paid out $10M by Garmin. </p><ul><li><a href="https://arstechnica.com/information-technology/2020/07/garmans-four-day-service-meltdown-was-caused-by-ransomware/">https://arstechnica.com/information-technology/2020/07/garmans-four-day-service-meltdown-was-caused-by-ransomware/</a></li></ul><p><br></p><p><strong>Twitter Admin Panel Exposed</strong></p><p>Recently a teenager was able to get access to a twitter management panel which allowed them to take over high profile accounts to include Barack Obama, Beyonce as well as Elon Musk. The take over was being used a scam to attempt to get bitcoin from people.</p><ul><li><a href="https://www.cnn.com/2020/07/15/tech/twitter-hack-elon-musk-bill-gates/index.html">https://www.cnn.com/2020/07/15/tech/twitter-hack-elon-musk-bill-gates/index.html</a></li></ul><p><br></p><p><strong>High Profile Exploits Recently Released</strong></p><p>Recently there were several high profile exploits released that were all remote code execution exploits. Vendors such as F5, SAP and Microsoft were all among the vendors affected by these exploits. </p><ul><li><a href="https://threatpost.com/thousands-f5-big-ip-users-takeover/157543/">https://threatpost.com/thousands-f5-big-ip-users-takeover/157543/</a></li><li><a href="https://threatpost.com/critical-sap-bug-enterprise-system-takeover/157392/">https://threatpost.com/critical-sap-bug-enterprise-system-takeover/157392/</a></li><li><a href="https://www.bleepingcomputer.com/news/security/critical-sigred-windows-dns-bug-gets-micropatch-after-pocs-released/">https://www.bleepingcomputer.com/news/security/critical-sigred-windows-dns-bug-gets-micropatch-after-pocs-released/</a></li></ul><p><br></p><p><strong>Tesla Attempted Hack</strong></p><p>A Tesla employee was approached by a supposed Russian sponsored individual in an attempt to compromise the entire organization and spread ransomware. </p><ul><li><a href="https://www.databreachtoday.com/russian-indicted-in-tesla-ransom-scheme-a-14960">https://www.databreachtoday.com/russian-indicted-in-tesla-ransom-scheme-a-14960</a></li></ul><p><strong>Upcoming Events:</strong></p><ul><li><a href="https://ekoparty.org/en_US/%20">https://ekoparty.org/en_US/ </a></li><li><a href="https://www.bsidesclt.org/%20">https://www.bsidesclt.org/ </a></li><li><a href="https://shellcon.io/">https://shellcon.io/ </a></li></ul><p><br><strong>Intro/Outro Music Credits</strong><br>Something Elated (Broke For Free: <a href="https://freemusicarchive.org/music/Broke_For_Free/Something_EP/Broke_For_Free_-_Something_EP_-_05_Something_Elated">https://freemusicarchive.org/music/Broke_For_Free/Something_EP/Broke_For_Free_-_Something_EP_-_05_Something_Elated</a>) / CC BY 3.0: <a href="https://creativecommons.org/licenses/by/3.0/us/">https://creativecommons.org/licenses/by/3.0/us/</a></p>]]>
      </content:encoded>
      <pubDate>Wed, 23 Sep 2020 18:37:27 -0400</pubDate>
      <author>TJ Nel, Ryan Hays</author>
      <enclosure url="https://media.transistor.fm/c50ce040/92f89a36.mp3" length="19743289" type="audio/mpeg"/>
      <itunes:author>TJ Nel, Ryan Hays</itunes:author>
      <itunes:duration>1229</itunes:duration>
      <itunes:summary>In this episode, TJ and Ryan discuss Emotet, Twitter Hack, Sev10 CVEs, the Tesla Ransomware Scandal, and More!</itunes:summary>
      <itunes:subtitle>In this episode, TJ and Ryan discuss Emotet, Twitter Hack, Sev10 CVEs, the Tesla Ransomware Scandal, and More!</itunes:subtitle>
      <itunes:keywords>Computer, Security, Information Security</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 03: Honda Cyberattack, Chinese App Banning and MongoDB Leaks </title>
      <itunes:episode>3</itunes:episode>
      <podcast:episode>3</podcast:episode>
      <itunes:title>Episode 03: Honda Cyberattack, Chinese App Banning and MongoDB Leaks </itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">753c17ee-aab5-4e62-bf09-094017a50cdb</guid>
      <link>https://share.transistor.fm/s/96720c6a</link>
      <description>
        <![CDATA[<p><strong>Honda hit by Cyberattack </strong></p><p>Honda was hit by a cyber attack shutting down its manufacturing plant for several days. It appears to be the Ekans variant of ransomware. The company has insisted no data has been breached and added that "at this point, we see minimal business impact".</p><ul><li><a href="https://www.bbc.com/news/technology-52982427">https://www.bbc.com/news/technology-52982427</a></li></ul><p><br></p><p><strong>59 Chinese Apps Banned</strong></p><p>Apps such as TikTok are starting to be banned within the Indian government. Many other countries and businesses are now also considering banning the applications from there networks. These applications were exposed to collecting too much detailed information about their users. </p><ul><li><a href="https://twitter.com/ShivAroor/status/1277619905269989378">https://twitter.com/ShivAroor/status/1277619905269989378</a></li></ul><p><br></p><p><strong>MongoDB Exposed Millions of Medical Insurance Records</strong></p><p>Millions of records containing personal information and medical insurance data were exposed by a database belonging to the insurance marketing website MedicareSupplement.com.</p><ul><li><a href="https://www.cybersecurity-review.com/news-june-2019/mongodb-leak-exposed-millions-of-medical-insurance-records/%20">https://www.cybersecurity-review.com/news-june-2019/mongodb-leak-exposed-millions-of-medical-insurance-records/ </a></li></ul><p><br><strong>Upcoming Events:</strong></p><ul><li><a href="https://conference.hitb.org/hitb-lockdown002/">https://conference.hitb.org/hitb-lockdown002/</a></li><li><a href="https://www.opcde.com/">https://www.opcde.com/</a></li></ul><p><br><strong>Intro/Outro Music Credits</strong><br>Something Elated (Broke For Free: <a href="https://freemusicarchive.org/music/Broke_For_Free/Something_EP/Broke_For_Free_-_Something_EP_-_05_Something_Elated">https://freemusicarchive.org/music/Broke_For_Free/Something_EP/Broke_For_Free_-_Something_EP_-_05_Something_Elated</a>) / CC BY 3.0: <a href="https://creativecommons.org/licenses/by/3.0/us/">https://creativecommons.org/licenses/by/3.0/us/</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>Honda hit by Cyberattack </strong></p><p>Honda was hit by a cyber attack shutting down its manufacturing plant for several days. It appears to be the Ekans variant of ransomware. The company has insisted no data has been breached and added that "at this point, we see minimal business impact".</p><ul><li><a href="https://www.bbc.com/news/technology-52982427">https://www.bbc.com/news/technology-52982427</a></li></ul><p><br></p><p><strong>59 Chinese Apps Banned</strong></p><p>Apps such as TikTok are starting to be banned within the Indian government. Many other countries and businesses are now also considering banning the applications from there networks. These applications were exposed to collecting too much detailed information about their users. </p><ul><li><a href="https://twitter.com/ShivAroor/status/1277619905269989378">https://twitter.com/ShivAroor/status/1277619905269989378</a></li></ul><p><br></p><p><strong>MongoDB Exposed Millions of Medical Insurance Records</strong></p><p>Millions of records containing personal information and medical insurance data were exposed by a database belonging to the insurance marketing website MedicareSupplement.com.</p><ul><li><a href="https://www.cybersecurity-review.com/news-june-2019/mongodb-leak-exposed-millions-of-medical-insurance-records/%20">https://www.cybersecurity-review.com/news-june-2019/mongodb-leak-exposed-millions-of-medical-insurance-records/ </a></li></ul><p><br><strong>Upcoming Events:</strong></p><ul><li><a href="https://conference.hitb.org/hitb-lockdown002/">https://conference.hitb.org/hitb-lockdown002/</a></li><li><a href="https://www.opcde.com/">https://www.opcde.com/</a></li></ul><p><br><strong>Intro/Outro Music Credits</strong><br>Something Elated (Broke For Free: <a href="https://freemusicarchive.org/music/Broke_For_Free/Something_EP/Broke_For_Free_-_Something_EP_-_05_Something_Elated">https://freemusicarchive.org/music/Broke_For_Free/Something_EP/Broke_For_Free_-_Something_EP_-_05_Something_Elated</a>) / CC BY 3.0: <a href="https://creativecommons.org/licenses/by/3.0/us/">https://creativecommons.org/licenses/by/3.0/us/</a></p>]]>
      </content:encoded>
      <pubDate>Wed, 15 Jul 2020 18:18:17 -0400</pubDate>
      <author>TJ Nel, Ryan Hays</author>
      <enclosure url="https://media.transistor.fm/96720c6a/a8afa47c.mp3" length="47019252" type="audio/mpeg"/>
      <itunes:author>TJ Nel, Ryan Hays</itunes:author>
      <itunes:duration>2934</itunes:duration>
      <itunes:summary>In this episode, TJ and Ryan discuss the Honda Cyberattack, Chinese App Banning, MongoDB Exposure and More!</itunes:summary>
      <itunes:subtitle>In this episode, TJ and Ryan discuss the Honda Cyberattack, Chinese App Banning, MongoDB Exposure and More!</itunes:subtitle>
      <itunes:keywords>Computer, Security, Information Security</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 02: Ransomware Leaks, Contact Tracing and Verizon DBIR</title>
      <itunes:episode>2</itunes:episode>
      <podcast:episode>2</podcast:episode>
      <itunes:title>Episode 02: Ransomware Leaks, Contact Tracing and Verizon DBIR</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">a08e0082-fa7c-48fc-aa74-22f3a8df0a76</guid>
      <link>https://share.transistor.fm/s/f50985f5</link>
      <description>
        <![CDATA[<p><strong>US President target of hackers</strong></p><p>In a press conference in May The White House Press Secretary held up the check being donated from the president's salary which held his account number and the routing number of an account within Citibank. This has placed a large target on the bank as they now have ties with the administration and government accounts. Hackers will be targeting them similar to how the REvil group is targeting Trump with the release of information collected during the hack of a law firm said to contain information about the president. </p><ul><li><a href="https://thehill.com/homenews/administration/499268-trump-routing-number-bank-revealed-coronavirus-response">https://thehill.com/homenews/administration/499268-trump-routing-number-bank-revealed-coronavirus-response</a></li><li><a href="https://twitter.com/ransomleaks/status/1261105634159800321?s=21">https://twitter.com/ransomleaks/status/1261105634159800321</a></li></ul><p><br></p><p><strong>Contact Tracing Apps and Jailbroken Phones</strong></p><p>Governments around the world have started encouraging citizens to install tracking application to hopefully get an idea of the spread of the virus. It’s gone as far as Apple and Google baking this into the operating system of the devices. Tracking applications present huge security concerns and risks to everyone. We should all be looking at these to ensure personal safety is being maintained while using them. </p><ul><li><a href="https://www.unc0ver.dev">https://www.unc0ver.dev</a></li></ul><p><br></p><p><strong>Increased Unemployment Fraud</strong></p><p>With the world under its current situation, Brian Krebs has been reporting on increased unemployment fraud along with Microsoft report huge upticks of malicious documents related to COVID-19. With the world in crisis and working from home everyone's guard is down so scammers and malicious attackers will be taking advantage of this. </p><ul><li><a href="https://krebsonsecurity.com/2020/05/riding-the-state-unemployment-fraud-wave/#more-51743">https://krebsonsecurity.com/2020/05/riding-the-state-unemployment-fraud-wave/</a></li><li><a href="https://www.infosecurity-magazine.com/news/microsoft-warns-of-massive-covid19/">https://www.infosecurity-magazine.com/news/microsoft-warns-of-massive-covid19/</a></li></ul><p><br></p><p><strong>Verizon DBIR</strong></p><p>The Verizon Databreach Investigation Report was released and covers the current attack surfaces being exploited at least during 2019 but a majority of these will continue on into 2020. </p><ul><li><a href="https://enterprise.verizon.com/resources/reports/dbir/">https://enterprise.verizon.com/resources/reports/dbir/</a></li></ul><p><br></p><p><strong>Upcoming Events</strong></p><ul><li>https://www.sans.org/event/hackfest-ranges-summit-2020 SANs Hackfest</li><li>https://www.securitysummits.com/event/enterprise-lockdown/ Enterprise Lockdown 6/25</li><li>https://securecon.streameventlive.com/login SecureCon 6/16-18</li><li>https://www.eventbrite.com/e/bsides-greenville-2020-tickets-84602497347 BSides Greenville 6/13</li><li>https://www.womenhackerz.com/whackzcon-2020 WomenHackerz Con 6/6-7</li><li>https://2020.pass-the-salt.org Pass the Salt 6/29</li></ul><p><strong>Intro/Outro Music Credits</strong><br>Something Elated (Broke For Free: <a href="https://freemusicarchive.org/music/Broke_For_Free/Something_EP/Broke_For_Free_-_Something_EP_-_05_Something_Elated">https://freemusicarchive.org/music/Broke_For_Free/Something_EP/Broke_For_Free_-_Something_EP_-_05_Something_Elated</a>) / CC BY 3.0: <a href="https://creativecommons.org/licenses/by/3.0/us/">https://creativecommons.org/licenses/by/3.0/us/</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>US President target of hackers</strong></p><p>In a press conference in May The White House Press Secretary held up the check being donated from the president's salary which held his account number and the routing number of an account within Citibank. This has placed a large target on the bank as they now have ties with the administration and government accounts. Hackers will be targeting them similar to how the REvil group is targeting Trump with the release of information collected during the hack of a law firm said to contain information about the president. </p><ul><li><a href="https://thehill.com/homenews/administration/499268-trump-routing-number-bank-revealed-coronavirus-response">https://thehill.com/homenews/administration/499268-trump-routing-number-bank-revealed-coronavirus-response</a></li><li><a href="https://twitter.com/ransomleaks/status/1261105634159800321?s=21">https://twitter.com/ransomleaks/status/1261105634159800321</a></li></ul><p><br></p><p><strong>Contact Tracing Apps and Jailbroken Phones</strong></p><p>Governments around the world have started encouraging citizens to install tracking application to hopefully get an idea of the spread of the virus. It’s gone as far as Apple and Google baking this into the operating system of the devices. Tracking applications present huge security concerns and risks to everyone. We should all be looking at these to ensure personal safety is being maintained while using them. </p><ul><li><a href="https://www.unc0ver.dev">https://www.unc0ver.dev</a></li></ul><p><br></p><p><strong>Increased Unemployment Fraud</strong></p><p>With the world under its current situation, Brian Krebs has been reporting on increased unemployment fraud along with Microsoft report huge upticks of malicious documents related to COVID-19. With the world in crisis and working from home everyone's guard is down so scammers and malicious attackers will be taking advantage of this. </p><ul><li><a href="https://krebsonsecurity.com/2020/05/riding-the-state-unemployment-fraud-wave/#more-51743">https://krebsonsecurity.com/2020/05/riding-the-state-unemployment-fraud-wave/</a></li><li><a href="https://www.infosecurity-magazine.com/news/microsoft-warns-of-massive-covid19/">https://www.infosecurity-magazine.com/news/microsoft-warns-of-massive-covid19/</a></li></ul><p><br></p><p><strong>Verizon DBIR</strong></p><p>The Verizon Databreach Investigation Report was released and covers the current attack surfaces being exploited at least during 2019 but a majority of these will continue on into 2020. </p><ul><li><a href="https://enterprise.verizon.com/resources/reports/dbir/">https://enterprise.verizon.com/resources/reports/dbir/</a></li></ul><p><br></p><p><strong>Upcoming Events</strong></p><ul><li>https://www.sans.org/event/hackfest-ranges-summit-2020 SANs Hackfest</li><li>https://www.securitysummits.com/event/enterprise-lockdown/ Enterprise Lockdown 6/25</li><li>https://securecon.streameventlive.com/login SecureCon 6/16-18</li><li>https://www.eventbrite.com/e/bsides-greenville-2020-tickets-84602497347 BSides Greenville 6/13</li><li>https://www.womenhackerz.com/whackzcon-2020 WomenHackerz Con 6/6-7</li><li>https://2020.pass-the-salt.org Pass the Salt 6/29</li></ul><p><strong>Intro/Outro Music Credits</strong><br>Something Elated (Broke For Free: <a href="https://freemusicarchive.org/music/Broke_For_Free/Something_EP/Broke_For_Free_-_Something_EP_-_05_Something_Elated">https://freemusicarchive.org/music/Broke_For_Free/Something_EP/Broke_For_Free_-_Something_EP_-_05_Something_Elated</a>) / CC BY 3.0: <a href="https://creativecommons.org/licenses/by/3.0/us/">https://creativecommons.org/licenses/by/3.0/us/</a></p>]]>
      </content:encoded>
      <pubDate>Mon, 01 Jun 2020 17:00:00 -0400</pubDate>
      <author>TJ Nel, Ryan Hays</author>
      <enclosure url="https://media.transistor.fm/f50985f5/6fffec41.mp3" length="36940633" type="audio/mpeg"/>
      <itunes:author>TJ Nel, Ryan Hays</itunes:author>
      <itunes:duration>2304</itunes:duration>
      <itunes:summary>In this episode, TJ and Ryan discuss the POTUS data allegedly leaked by REvil ransomware group, Contact tracing apps on iOS and Android, the Verizon DBIR report, and More!</itunes:summary>
      <itunes:subtitle>In this episode, TJ and Ryan discuss the POTUS data allegedly leaked by REvil ransomware group, Contact tracing apps on iOS and Android, the Verizon DBIR report, and More!</itunes:subtitle>
      <itunes:keywords>Computer, Security, Information Security</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Episode 01: COVID, IoT Botnets, Ransomware and Online Events</title>
      <itunes:episode>1</itunes:episode>
      <podcast:episode>1</podcast:episode>
      <itunes:title>Episode 01: COVID, IoT Botnets, Ransomware and Online Events</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">997ec730-2ffb-4407-bb01-503eee22f71f</guid>
      <link>https://share.transistor.fm/s/4c2c483d</link>
      <description>
        <![CDATA[<p>COVID-19 Related Attacks</p><ul><li>COVID-19 has hit the entire world extremely hard. We have seen an uptick in COVID-19 related attacks targeting businesses and consumers around the world. Recently we have witnessed spear phishing attacks related to streaming platforms as well as an uptick in malicious mobile applications related to COVID-19. <ul><li>References<ul><li><a href="https://research.checkpoint.com/2020/covid-19-goes-mobile-coronavirus-malicious-applications-discovered/">https://research.checkpoint.com/2020/covid-19-goes-mobile-coronavirus-malicious-applications-discovered/</a></li><li><a href="https://www.infosecurity-magazine.com/news/hackers-target-netflix-disney/">https://www.infosecurity-magazine.com/news/hackers-target-netflix-disney/</a></li></ul></li></ul></li></ul><p><br></p><p>Dark Nexus IOT Botnet</p><ul><li>IoT attacks have seen an uptick in IoT related attacks over the past few years. One of the largest currently operating in the Dark Nexus botnet. <ul><li>References<ul><li><a href="https://labs.bitdefender.com/2020/04/new-dark_nexus-iot-botnet-puts-others-to-shame/">https://labs.bitdefender.com/2020/04/new-dark_nexus-iot-botnet-puts-others-to-shame/</a></li></ul></li></ul></li></ul><p><br></p><p>Ransomware Attacks (Travelx and Cognizant)</p><ul><li>Ransomware attacks have always been an issue, but with employees in work from home mode and using VPNs, it increases the risk to the corporate network for attack. Two companies that we have seen hit recently Travelex were hit with Sodinokibi ransomware causing them to pay out $2.3M in ransom to unlock the systems. Cognizant is an MSP for some large organizations, and they were hit with MAZE ransomware. The difference here is attackers are exporting this data so the victims can no longer just restore from backups they are forced to pay out the ransom. <ul><li>References<ul><li><a href="https://threatpost.com/travelex-pays-2-3m-in-bitcoin-to-hackers-who-hijacked-network-in-january/154666/">https://threatpost.com/travelex-pays-2-3m-in-bitcoin-to-hackers-who-hijacked-network-in-january/154666/</a></li><li><a href="https://www.infosecurity-magazine.com/news/maze-wage-ransomware-attack-on/">https://www.infosecurity-magazine.com/news/maze-wage-ransomware-attack-on/</a></li></ul></li></ul></li></ul><p><br></p><p>Online Training/Events</p><ul><li>It seems with the world in its current state all of the infosec conferences have quickly adapted to still providing training within the virtual space. TJ and I collected several upcoming events and listed them for everyone to enjoy hopefully. <ul><li>References<ul><li><a href="https://wildwesthackinfest.com/deadwood/tickets-and-training-info/">https://wildwesthackinfest.com/deadwood/tickets-and-training-info/</a></li><li><a href="https://www.sans.org/blog/and-now-for-something-awesome-sans-launches-new-series-of-worldwide-capture-the-flag-cyber-events/">https://www.sans.org/blog/and-now-for-something-awesome-sans-launches-new-series-of-worldwide-capture-the-flag-cyber-events/</a></li></ul></li></ul></li></ul><p><br>Intro/Outro Music Credits</p><p>Something Elated (Broke For Free: <a href="https://freemusicarchive.org/music/Broke_For_Free/Something_EP/Broke_For_Free_-_Something_EP_-_05_Something_Elated">https://freemusicarchive.org/music/Broke_For_Free/Something_EP/Broke_For_Free_-_Something_EP_-_05_Something_Elated</a>) / CC BY 3.0: <a href="https://creativecommons.org/licenses/by/3.0/us/">https://creativecommons.org/licenses/by/3.0/us/</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>COVID-19 Related Attacks</p><ul><li>COVID-19 has hit the entire world extremely hard. We have seen an uptick in COVID-19 related attacks targeting businesses and consumers around the world. Recently we have witnessed spear phishing attacks related to streaming platforms as well as an uptick in malicious mobile applications related to COVID-19. <ul><li>References<ul><li><a href="https://research.checkpoint.com/2020/covid-19-goes-mobile-coronavirus-malicious-applications-discovered/">https://research.checkpoint.com/2020/covid-19-goes-mobile-coronavirus-malicious-applications-discovered/</a></li><li><a href="https://www.infosecurity-magazine.com/news/hackers-target-netflix-disney/">https://www.infosecurity-magazine.com/news/hackers-target-netflix-disney/</a></li></ul></li></ul></li></ul><p><br></p><p>Dark Nexus IOT Botnet</p><ul><li>IoT attacks have seen an uptick in IoT related attacks over the past few years. One of the largest currently operating in the Dark Nexus botnet. <ul><li>References<ul><li><a href="https://labs.bitdefender.com/2020/04/new-dark_nexus-iot-botnet-puts-others-to-shame/">https://labs.bitdefender.com/2020/04/new-dark_nexus-iot-botnet-puts-others-to-shame/</a></li></ul></li></ul></li></ul><p><br></p><p>Ransomware Attacks (Travelx and Cognizant)</p><ul><li>Ransomware attacks have always been an issue, but with employees in work from home mode and using VPNs, it increases the risk to the corporate network for attack. Two companies that we have seen hit recently Travelex were hit with Sodinokibi ransomware causing them to pay out $2.3M in ransom to unlock the systems. Cognizant is an MSP for some large organizations, and they were hit with MAZE ransomware. The difference here is attackers are exporting this data so the victims can no longer just restore from backups they are forced to pay out the ransom. <ul><li>References<ul><li><a href="https://threatpost.com/travelex-pays-2-3m-in-bitcoin-to-hackers-who-hijacked-network-in-january/154666/">https://threatpost.com/travelex-pays-2-3m-in-bitcoin-to-hackers-who-hijacked-network-in-january/154666/</a></li><li><a href="https://www.infosecurity-magazine.com/news/maze-wage-ransomware-attack-on/">https://www.infosecurity-magazine.com/news/maze-wage-ransomware-attack-on/</a></li></ul></li></ul></li></ul><p><br></p><p>Online Training/Events</p><ul><li>It seems with the world in its current state all of the infosec conferences have quickly adapted to still providing training within the virtual space. TJ and I collected several upcoming events and listed them for everyone to enjoy hopefully. <ul><li>References<ul><li><a href="https://wildwesthackinfest.com/deadwood/tickets-and-training-info/">https://wildwesthackinfest.com/deadwood/tickets-and-training-info/</a></li><li><a href="https://www.sans.org/blog/and-now-for-something-awesome-sans-launches-new-series-of-worldwide-capture-the-flag-cyber-events/">https://www.sans.org/blog/and-now-for-something-awesome-sans-launches-new-series-of-worldwide-capture-the-flag-cyber-events/</a></li></ul></li></ul></li></ul><p><br>Intro/Outro Music Credits</p><p>Something Elated (Broke For Free: <a href="https://freemusicarchive.org/music/Broke_For_Free/Something_EP/Broke_For_Free_-_Something_EP_-_05_Something_Elated">https://freemusicarchive.org/music/Broke_For_Free/Something_EP/Broke_For_Free_-_Something_EP_-_05_Something_Elated</a>) / CC BY 3.0: <a href="https://creativecommons.org/licenses/by/3.0/us/">https://creativecommons.org/licenses/by/3.0/us/</a></p>]]>
      </content:encoded>
      <pubDate>Wed, 06 May 2020 23:00:00 -0400</pubDate>
      <author>TJ Nel, Ryan Hays</author>
      <enclosure url="https://media.transistor.fm/4c2c483d/fca0ccaf.mp3" length="36165393" type="audio/mpeg"/>
      <itunes:author>TJ Nel, Ryan Hays</itunes:author>
      <itunes:duration>2256</itunes:duration>
      <itunes:summary>In this first episode, TJ and Ryan discuss the rash of COVID-19 related attacks, IoT Botnets, Ransomware, and online events in the time of "stay-at-home" orders.</itunes:summary>
      <itunes:subtitle>In this first episode, TJ and Ryan discuss the rash of COVID-19 related attacks, IoT Botnets, Ransomware, and online events in the time of "stay-at-home" orders.</itunes:subtitle>
      <itunes:keywords>Computer, Security, Information Security</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
  </channel>
</rss>
