Risky Business #275 -- Patch Tuesday, Indicator Wednesday?

What to do with all dem hashes and IPs!
28 Mar 2013 » Risky Business

This week's show is brought to you by our longest term sponsor, Tenable Network Security, thanks guys. In this week's sponsor interview we chat with the CEO and co-founder of Tenable, industry stalwart Ron Gula. We're chatting to him about a funny idea -- that the release of indicators of compromise might become so regular that they'll have to be handled in regular info sec team workflow. So we'll have Patch Tuesday and "which IPs owned us" Wednesday.

It's a really interesting chat and it's after the news. It's a short week this week because of Easter, plus I'm in Melbourne taking care of a few things, so there's no feature interview this week.

Show notes

Spamhaus DDoS Attacks Triple Size of Attacks on US Banks | threatpost
http://threatpost.com/en_us/blogs/spamhaus-ddos-attacks-triple-size-atta...

That Internet War Apocalypse Is a Lie
http://gizmodo.com/5992652/that-internet-war-apocalypse-is-a-lie

South Korean cyberattack may not have come from China | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57575767-83/south-korean-cyberattack-ma...

Spear Phishing Cause of South Korean Cyber Attack | threatpost
http://threatpost.com/en_us/blogs/spear-phishing-cause-south-korean-cybe...

Legal Experts: Stuxnet Attack on Iran Was Illegal 'Act of Force' | Threat Level | Wired.com
http://www.wired.com/threatlevel/2013/03/stuxnet-act-of-force/

Top Chinese university linked to alleged military cybercrime unit | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57576051-83/top-chinese-university-link...

Don't Just Hate CISPA - Fix It | Wired Opinion | Wired.com
http://www.wired.com/opinion/2013/03/dont-hate-cispa-fix-it/

Draft US cyber bill seeks 10 years jail for passwords 'traffickers' - Applications - SC Magazine Australia - Secure Business Intelligence
http://www.scmagazine.com.au/News/337906,draft-us-cyber-bill-seeks-10-ye...

Outdated Java weak spots are widespread, Websense says | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57576504-83/outdated-java-weak-spots-ar...

Apple ID security issue fixed, password page back online | Security & Privacy - CNET News
http://news.cnet.com/8301-1009_3-57575955-83/apple-id-security-issue-fix...

Apple Sets May 1 End Date for Apps that Want UDIDs | threatpost
http://threatpost.com/en_us/blogs/apple-sets-may-1-end-date-apps-want-ud...

Missouri Court Rules Against $440,000 Cyberheist Victim - Krebs on Security
http://krebsonsecurity.com/2013/03/missouri-court-rules-against-440000-c...

Attackers Shifting to Delivering Unknown Malware Via FTP and Web Pages | threatpost
http://threatpost.com/en_us/blogs/new-report-confronts-unknown-malware-p...

Privacy 101: Skype Leaks Your Location - Krebs on Security
http://krebsonsecurity.com/2013/03/privacy-101-skype-leaks-your-location/

Researchers Uncover Targeted Attack Campaign Using Android Malware | threatpost
http://threatpost.com/en_us/blogs/researchers-uncover-targeted-attack-ca...

Anonymized Phone Location Data Not So Anonymous, Researchers Find | Threat Level | Wired.com
http://www.wired.com/threatlevel/2013/03/anonymous-phone-location-data/

ICS Vulnerabilities Surface as Monitoring Systems Integrate with Digital Backends | threatpost
http://threatpost.com/en_us/blogs/ics-vulnerabilities-surface-monitoring...

Sensitive Enterprise Data Exposed in Amazon S3 Public Buckets | threatpost
http://threatpost.com/en_us/blogs/sensitive-enterprise-data-exposed-amaz...

83,000 Kiwis exposed in email blunder - Messaging - SC Magazine Australia - Secure Business Intelligence
http://www.scmagazine.com.au/News/337920,83000-kiwis-exposed-in-email-bl...

Google Fixes 11 Flaws in Chrome | threatpost
http://threatpost.com/en_us/blogs/google-fixes-11-flaws-chrome-032613

Egyptian navy captures divers trying to cut undersea internet cables \u2022 The Register
http://www.theregister.co.uk/2013/03/27/egypt_cables_cut_arrest/

We have Microsoft Tuesday, so how long until we have Indicator Wednesday? | Tenable Network Security
http://www.tenable.com/blog/we-have-microsoft-tuesday-so-how-long-until-...

SW&theE | The Simon Wright Band
http://simonwright.com.au/album/sw-thee

,

Of course, the internet apocalypse is a lie. I guess we can be so sure about that one. - James Cullem