The Other Side of the Firewall | Ask A CISSP & PMP
The Other Side of the Firewall | Ask A CISSP & PMP
  • 1 458
  • 49 082
How A Cyber-Researcher Took Down A Ransomware Gang?
In this episode, the hosts discuss an article about a cybersecurity researcher who befriended and then exposed the leader of a ransomware gang. They explore whether this approach could be a future strategy for dealing with ransomware gangs. They also discuss the risks and implications of such actions, as well as the difference between cybersecurity researchers and reporters in terms of their objectives and responsibilities.
Article: How a cybersecurity researcher befriended, then doxed, the leader of LockBit ransomware gang
techcrunch.com/2024/08/09/how-a-cybersecurity-researcher-befriended-then-doxed-the-leader-of-lockbit-ransomware-gang/?fbclid=IwY2xjawEp0xxleHRuA2FlbQIxMAABHRCBIUR786T92fuY20a3T9tE4JEwcX0zrU1LQZm_L95eMm9h4nLxp1L_kw_aem_5JNtSCNqnbR1oUiWrF5xmA
TED Talk: This is what happens when you reply to spam email
www.ted.com/talks/james_veitch_this_is_what_happens_when_you_reply_to_spam_email?
Please LISTEN 🎧 LIKE 👍🏿 and SHARE ❤️ Thanks!
Socials:
Website - www.heroesmediagroup.com/shows/the-other-side-of-the-firewall/
Audio - podcasts.apple.com/us/podcast/the-other-side-of-the-firewall/id1542479181
UA-cam - www.youtube.com/@theothersideofthefirewall7511
Facebook - profile.php?id=61556539026086
Instagram - theothersideofthefw
X (Twitter) - Ask_a_CISSP
TikTok - www.tiktok.com/@ryanwilliams683
Medium - medium.com/@ryanwilliamssenior
Subscribe to LinkedIn Newsletter - www.linkedin.com/build-relation/newsletter-follow?entityUrn=7172626552545865728
LinkedIn - www.linkedin.com/company/the-other-side-of-the-firewall/
Ryan on Twitter, LinkedIn, Clubhouse, and Threads - @ryrysecurityguy
Chris on LinkedIn - www.linkedin.com/in/chrisabacon/
Daniel on LinkedIn - www.linkedin.com/in/daniel-acevedo-3a8b641b/
Chapters
00:00 Introduction and Podcast Overview
01:20 Befriending and Exposing Ransomware Gang Leaders
04:01 The Fascinating Story of the Cybersecurity Researcher
08:02 The Difference Between Cybersecurity Researchers and Reporters
11:17 The Future of Dealing with Cybercriminals
13:15 The Importance of Collaboration with Law Enforcement
15:23 The Risks and Implications of Taking on Cybercriminals
#cybersecurity #socialnetworking #scams
Переглядів: 6

Відео

How A Cyber-Researcher Took Down A Ransomware Gang?
Переглядів 122 години тому
In this episode, the hosts discuss an article about a cybersecurity researcher who befriended and then exposed the leader of a ransomware gang. They explore whether this approach could be a future strategy for dealing with ransomware gangs. They also discuss the risks and implications of such actions, as well as the difference between cybersecurity researchers and reporters in terms of their ob...
Protecting Hospitals From Cyberattacks
Переглядів 104 години тому
The conversation discusses the constant cyber attacks on the healthcare sector and the need to boost healthcare cybersecurity. The healthcare sector is a soft target and is frequently targeted by ransomware attacks, putting lives at risk. The article highlights the importance of protecting hospitals and the healthcare sector as they are critical endpoints for patients. The conversation also tou...
Protecting Hospitals From Cyberattacks
Переглядів 234 години тому
The conversation discusses the constant cyber attacks on the healthcare sector and the need to boost healthcare cybersecurity. The healthcare sector is a soft target and is frequently targeted by ransomware attacks, putting lives at risk. The article highlights the importance of protecting hospitals and the healthcare sector as they are critical endpoints for patients. The conversation also tou...
Chrome, Firefox, and Safari Security Broken By ‘0.0.0.0 Day’
Переглядів 307 годин тому
The conversation discusses a vulnerability known as the '0.0.0.0 day' that has been present for 18 years and allows attackers to bypass browser security. The hosts express concern that this vulnerability is still widely used and that it could lead to unauthorized access and remote code execution on local services. They debate whether a complete rebuild of the internet is necessary or if patchin...
Chrome, Firefox, and Safari Security Broken By ‘0.0.0.0 Day’
Переглядів 617 годин тому
The conversation discusses a vulnerability known as the '0.0.0.0 day' that has been present for 18 years and allows attackers to bypass browser security. The hosts express concern that this vulnerability is still widely used and that it could lead to unauthorized access and remote code execution on local services. They debate whether a complete rebuild of the internet is necessary or if patchin...
The Weekly Run Down 8/9/24
Переглядів 616 годин тому
In this episode, the hosts discuss their week, including watching UA-cam videos, the Olympics, and TV shows. They also talk about their media consumption, such as movies and manga. The conversation then shifts to Marvel movies and their disappointment with recent releases. They also mention their beach trips and vacations, including a stay at a Sandals resort. The hosts encourage listeners to l...
The Weekly Run Down 8/9/24
Переглядів 414 годин тому
In this episode, the hosts discuss their week, including watching UA-cam videos, the Olympics, and TV shows. They also talk about their media consumption, such as movies and manga. The conversation then shifts to Marvel movies and their disappointment with recent releases. They also mention their beach trips and vacations, including a stay at a Sandals resort. The hosts encourage listeners to l...
Record-Breaking $75M Ransomware Heist
Переглядів 2519 годин тому
In this episode, the hosts discuss a news article about a Fortune 50 company that paid a record-breaking $75 million ransom to the Dark Angels ransomware gang. They express frustration with the current state of cybersecurity hiring and the need to attract talented individuals to the field. The hosts also highlight the importance of building security into organizations and the potential risks of...
Record-Breaking $75M Ransomware Heist
Переглядів 5621 годину тому
Record-Breaking $75M Ransomware Heist
The DigiCert Dilemma & Why Business Continuity Is So Important
Переглядів 15День тому
The DigiCert Dilemma & Why Business Continuity Is So Important
The DigiCert Dilemma & Why Business Continuity Is So Important
Переглядів 6День тому
The DigiCert Dilemma & Why Business Continuity Is So Important
Critical VMware ESXi Hypervisor Vulnerability
Переглядів 85День тому
Critical VMware ESXi Hypervisor Vulnerability
Critical VMware ESXi Hypervisor Vulnerability
Переглядів 21День тому
Critical VMware ESXi Hypervisor Vulnerability
The Weekly Run Down 8/2/24
Переглядів 8День тому
The Weekly Run Down 8/2/24
The Weekly Run Down 8/2/24
Переглядів 5День тому
The Weekly Run Down 8/2/24
CrowdStrike Incident Casts Shadow On Cyber Insurance
Переглядів 2014 днів тому
CrowdStrike Incident Casts Shadow On Cyber Insurance
CrowdStrike Incident Casts Shadow On Cyber Insurance
Переглядів 3214 днів тому
CrowdStrike Incident Casts Shadow On Cyber Insurance
How Did Russia Shutoff Ukrainian Heat During The Winter?
Переглядів 1114 днів тому
How Did Russia Shutoff Ukrainian Heat During The Winter?
How Did Russia Shutoff Ukrainian Heat During The Winter?
Переглядів 2914 днів тому
How Did Russia Shutoff Ukrainian Heat During The Winter?
N. Korean Hacker Infiltrates Cybersecurity Company
Переглядів 4314 днів тому
N. Korean Hacker Infiltrates Cybersecurity Company
N. Korean Hacker Infiltrates Cybersecurity Company
Переглядів 1414 днів тому
N. Korean Hacker Infiltrates Cybersecurity Company
Teaching and Sharing Expertise Ft. Professor Roger Whyte's Passion
Переглядів 1414 днів тому
Teaching and Sharing Expertise Ft. Professor Roger Whyte's Passion
Teaching and Sharing Expertise Ft. Professor Roger Whyte's Passion
Переглядів 3321 день тому
Teaching and Sharing Expertise Ft. Professor Roger Whyte's Passion
Microsoft Chops DE&I Department
Переглядів 3421 день тому
Microsoft Chops DE&I Department
Microsoft Chops DE&I Department
Переглядів 3421 день тому
Microsoft Chops DE&I Department
Why The U.S. Forced Kaspersky To Close
Переглядів 13321 день тому
Why The U.S. Forced Kaspersky To Close
Why The U.S. Forced Kaspersky To Close
Переглядів 17321 день тому
Why The U.S. Forced Kaspersky To Close
CrowdStrike & “The Update Heard ‘Round The World”
Переглядів 2921 день тому
CrowdStrike & “The Update Heard ‘Round The World”
CrowdStrike & “The Update Heard ‘Round The World”
Переглядів 3721 день тому
CrowdStrike & “The Update Heard ‘Round The World”

КОМЕНТАРІ

  • @LightWarriors4Life
    @LightWarriors4Life 6 днів тому

    Awesome and very informational podcast! If you’re a veteran, you should absolutely subscribe to this channel. The host is a fellow veteran as well. #veteranshelpingveterans

    • @theothersideofthefirewall7511
      @theothersideofthefirewall7511 6 днів тому

      Thank you for the awesome recommendation! All four hosts are vets as well. Ryan, Shannon, and Daniel are Air Force and Chris is Navy. #veteranshelpingveterans indeed.

  • @ziggyinta
    @ziggyinta 6 днів тому

    Subscribed, non invasive presentation with fair opinions and deep dives without needing a submarine to keep up👍

    • @theothersideofthefirewall7511
      @theothersideofthefirewall7511 6 днів тому

      Thank you for the amazing feedback and the sub! The team tries very hard to make sure we remain fair and balanced while discussing the facts.

  • @ziggyinta
    @ziggyinta 6 днів тому

    Thanks for the quality content

  • @hasanulrafi3174
    @hasanulrafi3174 6 днів тому

    Which masters

    • @theothersideofthefirewall7511
      @theothersideofthefirewall7511 6 днів тому

      Cybersecurity and Information Assurance but be ware that Jacob had many years of experience prior to taking the “challenge”.

  • @antonioredding2419
    @antonioredding2419 6 днів тому

    great topics as always. keep getting some feedback from Dan's mic

    • @theothersideofthefirewall7511
      @theothersideofthefirewall7511 6 днів тому

      Thanks for the feedback Antonio! I have it on my short list of technical things to work out next recording session.

  • @antonioredding2419
    @antonioredding2419 7 днів тому

    Being consistent at the basics is such a huge part of making your organization a "harder" cyber target. Also, Chris's hair is definitely embracing the veteran status!

  • @user-od5fh3gn4d
    @user-od5fh3gn4d 12 днів тому

    It’s not just Russia. There are a ton of troll farms (or farmers) in Germany openly bragging about it on Facebook

  • @eps3154
    @eps3154 15 днів тому

    If you want to know what your insurance covers... read the policy?

  • @nohjrd
    @nohjrd 15 днів тому

    Amazing work. This kind of thing makes me feel inspired!

  • @balenciaga1010
    @balenciaga1010 15 днів тому

    Dude high af

  • @majamoore6209
    @majamoore6209 15 днів тому

    Great interview! I think a key takeaway for me is learning to work in a corporate environment. I am trying to transition from the medical field into IT/cybersecurity. So, I have experience with dealing with colleagues in a professional manner & patients when they are at a low/stressful point in their life, but I did really think about the transition into a more corporate setting. I have my CompTIA Net+ & Sec+, but have yet to apply for jobs. Kinda feeling like I don't know enough yet. Especially after hearing so many people say it is hard to get hired. I think I will finally start putting in applications next month. Thanks for sharing!

    • @theothersideofthefirewall7511
      @theothersideofthefirewall7511 6 днів тому

      You will be surprised that you know more than you think. Are you looking at your current employers job board/postings. IMHO you have leverage in your current organization because you can have your current management sponsor you, access to job openings and vacancies before the public, and are already knowledgeable about friction points and practical experience with the systems your colleagues use on a daily basis.

  • @EloTheSource
    @EloTheSource 17 днів тому

    Thank you for the post how can I connect

    • @theothersideofthefirewall7511
      @theothersideofthefirewall7511 16 днів тому

      Thank you for reaching out. Here is Professor Roger's Linktree with all of his points of contact: linktr.ee/Professorroger

  • @redjoker365
    @redjoker365 23 дні тому

    I feel the exact opposite. I'd much rather a foreign country whose police can't touch me in the US be spying on me over the US government whose police can harass me or worse, which happens to moderate police reformers. Stop excusing the US becoming a police state

  • @ProgrammingRainbow
    @ProgrammingRainbow 23 дні тому

    When you're talking about antivirus software, that is kernal level code. It has complete control of your system by default at ring 0. It also uploads your files to the servers to inspect files that haven't been fingerprinted yet. It also has the ability to push code. So, on a good day, it is software that is kernel level and looking at all your files and can update your system. Just like crowdstrike. But the thing is they are a russian company and subject to russian laws, meaning turning over all data they have available as in any of your files. And they have the ability to push kernel boot code like crowdstrike. So it's an espionage and atteck vector. Purely because of them being under russian law. No matter if they wish to be a good company or not. TikTok is similarly chinese controlled data collection but not of the same power as antivirus.

  • @stevenmartin1773
    @stevenmartin1773 24 дні тому

    Great discussion guys!

  • @adamwhaley3766
    @adamwhaley3766 24 дні тому

    It's hard to test every Windows environment. There are millions of different variables and setups. You can't test for them all.

    • @theothersideofthefirewall7511
      @theothersideofthefirewall7511 6 днів тому

      Adam, this is a great point and I think the team understands how difficult this process is. Both Shannon and Daniel did something similar while still in the military and in the grand scheme of things that environment was more homogeneous and still required thorough testing before patches were pushed out.

  • @v1nc3nt_bl4ck4
    @v1nc3nt_bl4ck4 29 днів тому

    And the US hasn’t?

  • @nealdavidson3715
    @nealdavidson3715 Місяць тому

    Wow! This is an exciting topic. You guys gave a great breakdown of the technical exposure that is happening!!! I wonder if this is a bigger issue for sys administration or network admins???

    • @theothersideofthefirewall7511
      @theothersideofthefirewall7511 6 днів тому

      Thank you for the feedback and great question. Ryan wanted to pass along, “As a former network guy, I feel it would be more work on our part. The sys admin folks may need to patch the RADIUS server(s) but the network team will have to patch and service every network device that relies on the AAA protocol.”

  • @nealdavidson3715
    @nealdavidson3715 Місяць тому

    Great episode guys! There’s a balance between everything with politics, true data protection, and government oversight/regulations. I think that until it becomes too costly to not manage all this data properly, corps will get away with abusing its use or neglecting its protections

    • @theothersideofthefirewall7511
      @theothersideofthefirewall7511 6 днів тому

      Thank you and well said. Nothing meaningful will be done until it starts to impact the bottom line.

  • @matthewstarek5257
    @matthewstarek5257 Місяць тому

    You guys seem cool. Rooting for you hitting your sub goals 🎉 keep it up!

  • @tedhampton9498
    @tedhampton9498 Місяць тому

    Try posting your diarrhea

  • @nealdavidson3715
    @nealdavidson3715 Місяць тому

    Sometimes the smallest things can add a lot of security. It should be prudent for smaller financial institutions to use the simple practices to need there security. I don’t think you need the highest tech in security tools do you ????

    • @theothersideofthefirewall7511
      @theothersideofthefirewall7511 6 днів тому

      No, we agree. Building a solid foundation by adhering to regulatory compliance and industry best practices is key. Standards, culture, and practicality are more important than the latest and greatest toys IMHO.

  • @nealdavidson3715
    @nealdavidson3715 Місяць тому

    Gotta level up and get like Chris! BIG BANK Chris!

  • @CyberCoffeeHour_Alfredzo
    @CyberCoffeeHour_Alfredzo Місяць тому

    No Truer story told!

  • @dougfurr5217
    @dougfurr5217 Місяць тому

    Why would anyone care, no matter what bank u use its only insured up to $250k and thats by the Fed, not the bank. They are all the same. So only people with no clue would believe or care.......

  • @MrJusticle
    @MrJusticle Місяць тому

    When ur guests look bored, ur viewers are too

  • @petervaczovsky9211
    @petervaczovsky9211 Місяць тому

    Chief Engineer Scott is correct: "The more complicated you make the plumbing the easier it is to stop up the drain."

  • @CyberCoffeeHour_Alfredzo
    @CyberCoffeeHour_Alfredzo Місяць тому

    BDR,IRP BCP, ISP, SSP, all funny acronyms. "Everyone Hates the Cyber Warrior until the Enemy is at the gates" 🎉🎉🎉🎉

  • @CyberCoffeeHour_Alfredzo
    @CyberCoffeeHour_Alfredzo Місяць тому

    That's more like it! Don't pay the Ransomware #DontBugUS

  • @gamingsincethe80z59
    @gamingsincethe80z59 2 місяці тому

    I talk about this all the time to people asking my opinion on whether they should go to school or not for IT I always tell them get the certs and do the degree on the side if you still want to pursue that.

  • @lizziemoratti8353
    @lizziemoratti8353 2 місяці тому

    One of the authors of TunnelVision here. We actually did reach out to CISA and also the EFF prior to public disclosure. We ended up getting the CVE assigned through CISA since we collectively thought folks would want an official way to track the problem. Also re: streamlining the issue - we're doing that with our tool ArcaneTrickster that will eventually be open source and designed for researchers. Great show guys!

    • @theothersideofthefirewall7511
      @theothersideofthefirewall7511 Місяць тому

      Thank you for these important corrections. If you would like, please connect with Ryan on LinkedIn to schedule some time on the podcast. Thanks!

  • @nealdavidson3715
    @nealdavidson3715 2 місяці тому

    This is always a good conversation. Daniel you brought up such a good point. I never thought about some companies NOT knowing what they are really looking for. That’s probably why to Ryan point the Triad is weighted in the wrong places. This is always a good necessary conversation. While it would be nice for companies to have a pipeline, yet since they don’t we have to take innovative solutions to garner experience ourselves.

  • @brooksd-lg9lg
    @brooksd-lg9lg 2 місяці тому

    Good conversation! Ryan for “King For A Day”!!! You nailed the issue concerning employers and job seekers.

  • @brooksd-lg9lg
    @brooksd-lg9lg 2 місяці тому

    Good conversation! Ryan for “King For A Day”!!! You nailed the issue concerning employers and job seekers.

  • @derrichphillips7996
    @derrichphillips7996 2 місяці тому

    Wow! Passed the CISSP after 3 months of studying is super impressive!

  • @QueseShotIt
    @QueseShotIt 2 місяці тому

    ✊🏁

  • @The100Percenttruth
    @The100Percenttruth 2 місяці тому

    Who do I call

  • @The100Percenttruth
    @The100Percenttruth 2 місяці тому

    I never got an email....just a letter of cyber attack

  • @RollingLiving
    @RollingLiving 2 місяці тому

    The ARRL is also one of the largest conduits of HAM license test certifications and applications to the FCC. The hacking took down that capability. I passed a test on the 20th and the FCC still doesn't have any record of that. Normally it happens same day or next day.

  • @CyberCoffeeHour_Alfredzo
    @CyberCoffeeHour_Alfredzo 2 місяці тому

    Check out @americanrivers legislation and many more that have SO much pushback. As Cyber pros, we dont have the level of transparency to folks that keep these legacy systems in place for XYZ justification

  • @CyberCoffeeHour_Alfredzo
    @CyberCoffeeHour_Alfredzo 2 місяці тому

    I dont want to even imagine the level of concern I have for how long these assessment being 5 YEARS. I cant agree with Shannon more, EPA "God Bless Em" alongside FDA, NPS, etc. Additionally, I cant agree about the whole access to "soft targets". You dont have to be in the military or former military to assemble "Green Teams". Food, Water, Shelter, Cyber...

  • @MaryABJM
    @MaryABJM 2 місяці тому

    How do we get our part of this lawsuit or do we get our own attorney

  • @cdkilo77
    @cdkilo77 2 місяці тому

    I'm an amateur radio operator and I use a site called QRZ to log my contacts. I have it synced with LOTW, which means that all of my logged contacts get copied to LOTW. I do this because not everyone uses QRZ and it's another way to verify my logs. Anyhow, after this hack happened, I began receiving weird notifications from obvious scammers and a also a scam email, claiming to be me, was sent to my workplace. I'm not sure if they're linked to this hack, but I'm guessing they are.

    • @theothersideofthefirewall7511
      @theothersideofthefirewall7511 Місяць тому

      Has this issue been cleared up or has it worsened since your last comment?

    • @cdkilo77
      @cdkilo77 Місяць тому

      @@theothersideofthefirewall7511 It seems like it cleared up.

  • @alfredzo
    @alfredzo 2 місяці тому

    Oh hell no. Not AARL

  • @derickmcmillian
    @derickmcmillian 2 місяці тому

    Love the show guys. Keep it up! Also, the audio sounds kind of funky when you’re speaking Ry. That happened with Chris audio in some of the previous shows too.

    • @theothersideofthefirewall7511
      @theothersideofthefirewall7511 2 місяці тому

      @derickmcmillian, thank you for listening! Unfortunately, Ryan changed locations within his house and forgot to set up the audio properly. Your hearing him through his webcam instead of the headphones... We'll make sure we fix it for next week's episodes.

  • @joeclark2909
    @joeclark2909 3 місяці тому

    🤩 P R O M O S M

  • @stanley3895
    @stanley3895 3 місяці тому

    🐒

  • @freethepeople9075
    @freethepeople9075 3 місяці тому

    when they allowed operators to work from home over outside coms.......... They are negligent.

    • @theothersideofthefirewall7511
      @theothersideofthefirewall7511 3 місяці тому

      If a negligent remote worker or lacks remote security enforcement was the culprit, do you think it’s inherent to WFH culture or poor training?