![Package manager repository malware detection. [Research Saturday]](https://cdn.podme.com/podcast-images/2314D040A5A2689DFF0F19F617D68766_small.jpg)
Package manager repository malware detection. [Research Saturday]
Researchers at Reversing Labs have been tracking malware hidden in software package manager repositories, and it's use as a supply chain attack vector. Robert Perica is a principal engineer at Reversi...
3 Aug 201913min

Spearphishing utility companies. Bellingcat as gadfly, and target. Facebook takes down more coordinated inauthenticity. Card skimming. Tech regulation. Random acts of cruelty.
LookBack malware used in spearphishing campaigns against US utilities. Phishing Bellingcat. Facebook takes down two campaigns of coordinated inauthenticity that had been active in the Middle East and ...
2 Aug 201925min

Capital One investigation update. Don’t give up on the cloud. Exposed databases and backdoors. Cybercrime as high-stakes poker. Phishing the financials. Bots on holiday.
Investigators pursue the possibility that the alleged Capital One hacker might have hit other companies’ data. An exposed ElastiSearch database, now secured, was found at Honda Motors. Data from beaut...
1 Aug 201921min

Capital One breach update. CISA warns of avionics CAN bus vulnerabilities. More attacks on local Louisiana governments. Change at the SEC. Cyber summer school for NATO, EU diplomats.
Capital One takes a market hit from its data loss. Observers see the incident as a reminder that cloud users need to pay attention to their configurations. CISA warns of vulnerabilities in small, gene...
31 Juli 201921min

Capital One sustains a major data breach. Phishing in LinkedIn. VxWorks patches and mitigations. Brute-forcing NAS credentials. LAPD doxed?
Capital One sustains a major data breach affecting 106 million customers, and a suspect is in custody, thanks largely to her incautious online boasting. Iranian social engineers are phishing in Linked...
30 Juli 201921min

Bears sniff at Bellingcat. Magecart in spoofed domains. MyDoom is still active. Shipboard malware was Emotet. Hutchins sentenced. Digital assistants have big ears. Taxes owed on alt-coin gains.
Bellingcat gets a look-in from the Bears. Magecart card-skimming code found in bogus domains. The MyDoom worm remains active in the wild, fifteen years after it first surfaced. Election security threa...
29 Juli 201921min
![Cult of the Dead Cow author Joseph Menn extended interview. [Special Editions]](https://cdn.podme.com/podcast-images/2314D040A5A2689DFF0F19F617D68766_small.jpg)
Cult of the Dead Cow author Joseph Menn extended interview. [Special Editions]
Our guest today is Joseph Menn. He’s a longtime investigative reporter on technology issues, currently working for Reuters in San Francisco. He’s the author of several books, the latest of which is ti...
28 Juli 201925min
![Day to day app fraud in the Google Play store. [Research Saturday]](https://cdn.podme.com/podcast-images/2314D040A5A2689DFF0F19F617D68766_small.jpg)
Day to day app fraud in the Google Play store. [Research Saturday]
Researchers at bot mitigation firm White Ops have been tracking fraudulent apps in the Google Play store. These apps often imitate legitimate apps, even going so far as to lift code directly from them...
27 Juli 201922min




















