Security News

S3 Ep92: Log4Shell4Ever, travel tips, and scamminess [Audio + Text]
2022-07-21 18:25

DOUG. Facebook scams, Log4Shell forever, and tips for a cybersafe summer. DOUG. OK, there you go you and I are in the full swings of summer, and we have some tips for the summertime coming up later in the show.

#S3
S3 Ep91: CodeRed, OpenSSL, Java bugs, Office macros [Audio + Text]
2022-07-14 18:47

DOUG. A brief history of Office macros, a Log4Shell style bug, two OpenSSL crypto bugs, and more. DUCK. If you have a Windows network where you can use Group Policy, for example, then as an administrator you can turn this function on to say, "As a company, we just don't want macros off the internet. We're not going to even offer you a button that you can say, Why not? Why not let the macros run?".

SEGA’s Sloppy Security Confession: Exposed AWS S3 Bucket Offers Up Steam API Access & More
2022-01-04 20:49

Gaming giant SEGA Europe recently discovered that its sensitive data was being stored in an unsecured Amazon Web Services S3 bucket during a cloud-security audit, and it's sharing the story to inspire other organizations to double-check their own systems. The laundry list of SEGA's potentially exposed data is nauseating - API keys, internal messaging systems, cloud systems, user data and more.

S3 Ep63: Log4Shell (what else?) and Apple kernel bugs [Podcast+Transcript]
2021-12-16 17:41

Latest episode - listen now! (Yes, there are plenty of critical things to go along with Log4Shell.)

S3 Ep62: The S in IoT stands for security (and much more) [Podcast+Transcript]
2021-12-09 19:40

DUCK. That's worrying, because when I checked my Tor browser version, it didn't have the latest NSS, but it had a more recent one than 1999, so that timestamp may be wrong. DUCK. Yes, of all the browsers that you probably want to avoid having [LAUGHS] exploitable privacy violating holes in.

S3 Ep61: Call scammers, cloud insecurity, and facial recognition creepiness [Podcast+Transcript]
2021-12-02 20:50

Oh! No! The wannabe wizard that went to school with a trainee Sith. LISTEN NOW. Click-and-drag on the soundwaves below to skip to any point in the podcast.

S3 Ep60: Exchange exploit, GoDaddy breach and cookies made public [Podcast]
2021-11-25 19:38

" Cybersecurity tips for the holiday season and beyond. Tech history: What do you mean, "It uses a mouse?" Don't make your cookies public! Oh! No! DDoS attack in progress - unfurl the umbrellas!

S3 Ep59: Emotet, an FBI hoax, Samba bugs, and a hijackable suitcase [Podcast]
2021-11-18 19:00

Emotet malware: "The report of my death was an exaggeration" FBI email hack spreads fake security alerts Tech history: Why tubes are valves, and valves are tubes. Samba update patches plaintext password plundering The hijackable self-driving robot suitcase Oh! No! A virtual-versus-real monitor mixup.

S3 Ep58: Faces on Facebook, scams that pose as complaints, and a Kaseya bust [Podcast]
2021-11-11 19:41

Crooks combine a new social engineering scam with a new way of packaging malware. Oh! No! How to block radio communications in a land with no hills.

S3 Ep57: Europol v. Ransomware, Shrootless bug, and Linux browser flamewars [Podcast]
2021-11-04 19:46

LISTEN NOW. Click-and-drag on the soundwaves below to skip to any point in the podcast. WHERE TO FIND THE PODCAST ONLINE. You can listen to us on Soundcloud, Apple Podcasts, Google Podcasts, Spotify, Stitcher and anywhere that good podcasts are found.