Go offline with the Player FM app!
Risky Business #793 -- Scattered Spider is hijacking MX records
Manage episode 485421731 series 3234705
In this week’s edition of Risky Business Dmitri Alperovitch and Adam Boileau join Patrick Gray to talk through the week’s news, including:
- EXCLUSIVE: A Scattered Spider-style crew is hijacking DNS MX entries and compromising enterprises within minutes
- The SVG format brings the all horrors of HTML+JS to image files, and attackers have noticed
- Brian Krebs eats a 6.3Tbps DDoS … ‘cause that’s how you demo your packet cannon
- Law enforcement takes out Lumma Stealer, Qakbot, Danabot and some dark web drug traffickers
- Iranian behind 2019 Baltimore ransomware mysteriously appears in North Carolina and pleads guilty
- CISA’s leadership is fleeing in droves, even though the US needs them more than ever.
This week’s episode is sponsored by Thinkst Canary. Long time friend of the show Haroon Meer joins and talks through where he feels the industry is at, having just returned home from the AI-fueled hype at this year’s RSA conference.
This episode is also available on Youtube.
Show notes
- China-linked ‘Silk Typhoon’ hackers accessed Commvault cloud environments, person familiar says - Nextgov/FCW
- Risky Bulletin: SVG use for phishing explodes in 2025 - Risky Business Media
- KrebsOnSecurity Hit With Near-Record 6.3 Tbps DDoS – Krebs on Security
- Midwestern telco Cellcom confirms cyber incident after days of service outages | The Record from Recorded Future News
- Microsoft leads international takedown of Lumma Stealer | Cybersecurity Dive
- Who said what? on X: "Message from the administrator of Lumma Stealer on the forums about the recent events🕊️👀 https://t.co/MOjCSMMErK" / X
- Ransomware hackers charged, infrastructure dismantled in international law enforcement operation | The Record from Recorded Future News
- Oops: DanaBot Malware Devs Infected Their Own PCs – Krebs on Security
- DOJ charges man allegedly behind Qakbot malware | The Record from Recorded Future News
- US, Europol arrest 270 dark web drug traffickers in Operation RapTor | The Record from Recorded Future News
- Iranian pleads guilty to launching Baltimore ransomware attack, faces 30 years behind bars | The Record from Recorded Future News
- Decentralized crypto platform Cetus hit with $223 million hack | The Record from Recorded Future News
- Nearly 70,000 impacted by Coinbase breach involving $20 million ransom demand | The Record from Recorded Future News
- USA: Crypto investor charged with kidnapping, torturing man in an NYC apartment
- Vietnam orders ban on Telegram messaging app over security concerns | The Record from Recorded Future News
- Exclusive: Hacker who breached communications app used by Trump aide stole data from across US government | Reuters
- CISA loses nearly all top officials as purge continues | Cybersecurity Dive
- White House dismisses scores of National Security Council staff - The Washington Post
129 episodes
Manage episode 485421731 series 3234705
In this week’s edition of Risky Business Dmitri Alperovitch and Adam Boileau join Patrick Gray to talk through the week’s news, including:
- EXCLUSIVE: A Scattered Spider-style crew is hijacking DNS MX entries and compromising enterprises within minutes
- The SVG format brings the all horrors of HTML+JS to image files, and attackers have noticed
- Brian Krebs eats a 6.3Tbps DDoS … ‘cause that’s how you demo your packet cannon
- Law enforcement takes out Lumma Stealer, Qakbot, Danabot and some dark web drug traffickers
- Iranian behind 2019 Baltimore ransomware mysteriously appears in North Carolina and pleads guilty
- CISA’s leadership is fleeing in droves, even though the US needs them more than ever.
This week’s episode is sponsored by Thinkst Canary. Long time friend of the show Haroon Meer joins and talks through where he feels the industry is at, having just returned home from the AI-fueled hype at this year’s RSA conference.
This episode is also available on Youtube.
Show notes
- China-linked ‘Silk Typhoon’ hackers accessed Commvault cloud environments, person familiar says - Nextgov/FCW
- Risky Bulletin: SVG use for phishing explodes in 2025 - Risky Business Media
- KrebsOnSecurity Hit With Near-Record 6.3 Tbps DDoS – Krebs on Security
- Midwestern telco Cellcom confirms cyber incident after days of service outages | The Record from Recorded Future News
- Microsoft leads international takedown of Lumma Stealer | Cybersecurity Dive
- Who said what? on X: "Message from the administrator of Lumma Stealer on the forums about the recent events🕊️👀 https://t.co/MOjCSMMErK" / X
- Ransomware hackers charged, infrastructure dismantled in international law enforcement operation | The Record from Recorded Future News
- Oops: DanaBot Malware Devs Infected Their Own PCs – Krebs on Security
- DOJ charges man allegedly behind Qakbot malware | The Record from Recorded Future News
- US, Europol arrest 270 dark web drug traffickers in Operation RapTor | The Record from Recorded Future News
- Iranian pleads guilty to launching Baltimore ransomware attack, faces 30 years behind bars | The Record from Recorded Future News
- Decentralized crypto platform Cetus hit with $223 million hack | The Record from Recorded Future News
- Nearly 70,000 impacted by Coinbase breach involving $20 million ransom demand | The Record from Recorded Future News
- USA: Crypto investor charged with kidnapping, torturing man in an NYC apartment
- Vietnam orders ban on Telegram messaging app over security concerns | The Record from Recorded Future News
- Exclusive: Hacker who breached communications app used by Trump aide stole data from across US government | Reuters
- CISA loses nearly all top officials as purge continues | Cybersecurity Dive
- White House dismisses scores of National Security Council staff - The Washington Post
129 episodes
All episodes
×Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.