meta_pixel
Tapesearch Logo
Log in
CyberWire Daily

An unprecedented surge in credential stuffing.

CyberWire Daily

N2K Networks, Inc.

Daily News, Tech News, News, Technology

4.61K Ratings

🗓️ 29 April 2024

⏱️ 28 minutes

🧾️ Download transcript

Summary

Okta warns of a credential stuffing spike. A congressman looks to the EPA to protect water systems from cyber threats. CISA unveils security guidelines for critical infrastructure. Researchers discover a stealthy botnet-as-a-service coming from China. The UK prohibits easy IoT passwords. New vulnerabilities are found in Intel processors. A global bank CEO shares insights on cybersecurity. Users report mandatory Apple ID resets. A preview of N2K CyberWire activity at RSA Conference. Police in Japan find a clever way to combat gift card fraud. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest It’s the week before the 2024 RSA Conference. Today, we have N2K’s own Rick Howard, Brandon Karpf, and Dave Bittner previewing N2K’s upcoming activities and where you can find our team at RSAC 2024. Special Edition: Threat Vector Understanding the Midnight Eclipse Activity and CVE 2024-3400: Host David Moulton and Andy Piazza, Sr. Director of Threat Intelligence at Unit 42, dive into the critical vulnerability CVE-2024-3400 found in PAN-OS software of Palo Alto Networks, emphasizing the importance of immediate patching and mitigation strategies for such vulnerabilities, especially when they affect edge devices like firewalls or VPNs. Selected Reading Okta warns customers about credential stuffing onslaught (Help Net Security) Crawford puts forward bill on cybersecurity risks to water systems (The Arkansas Democrat-Gazette) CISA unveils guidelines for AI and critical infrastructure (FedScoop) Chinese Botnet As-A-Service Bypasses Cloudflare & Other DDoS Protection Services (GB Hackers) UK becomes first country to ban default bad passwords on IoT devices (The Record) Researchers unveil novel attack methods targeting Intel's conditional branch predictor (Help Net Security) Standard Chartered CEO on why cybersecurity has become a 'disproportionately huge topic' at board meetings (The Record) Security Bite: Did Apple just declare war on Adload malware? (9to5Mac) Apple users are being locked out of their Apple IDs with no explanation (9to5Mac) Japanese police create fake support scam payment cards to warn victims (Bleeping Computer) Share your feedback. We want to ensure that you are getting the most out of the podcast. Please take a few minutes to share your thoughts with us by completing our brief listener survey as we continually work to improve the show. Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here’s our media kit. Contact us at [email protected] to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © 2023 N2K Networks, Inc.

Transcript

Click on a timestamp to play from that location

0:00.0

You're listening to the CyberWire Network, powered by N2K.

0:07.0

The IT world used to be simpler. You only had to secure and manage environments that you controlled.

0:20.0

Then came new technologies and new ways to work. Now employees, apps, and networks are everywhere.

0:27.0

This means poor visibility, security gaps, and added risk.

0:31.0

That's why Cloudflare created the first ever connectivity cloud.

0:35.6

Visit Cloud.com to protect your business everywhere you do business. Ockta warns of a credential. A

0:57.0

Congressman looks to the EPA to protect water systems from cyber threats.

1:01.0

CISA unveil security guidelines for critical infrastructure.

1:04.0

Researchers discover a stealthy botnet as a service coming from China.

1:08.0

The UK prohibits easy IOT passwords.

1:12.0

New vulnerabilities are found in Intel processors. A Global Bank CEO

1:16.4

shares insights on cyber security. Users report mandatory Apple ID Resets. A preview of N2K cyberwire activity at

1:25.3

RSA conference, and police in Japan find a clever way to combat gift card

1:30.8

fraud.

1:33.0

It's Monday, April 29, 2024.

1:37.0

It's Monday, April 29, 2024. I'm Dave Bitner and this is your CyberWire Intel briefing. Identity and Access Management Company, Octa, warns of what they're describing as an unprecedented

2:07.4

surge in credential stuffing attacks, where attackers use stolen user names and passwords from previous breaches

2:14.7

to access online services. These attacks often involve anonymizing proxies like

2:20.7

Tor and residential proxies including En Sox,

2:24.6

Luminati, and Data Impulse automated through scripting tools.

2:29.8

Octa's observations align with recent findings by Duo Security and

2:34.2

Cisco Talos on similar tactics used in brute force attacks? A significant

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from N2K Networks, Inc., and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of N2K Networks, Inc. and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.