Risky Business Podcast
July 31, 2024
Risky Business #757 – The ClownStrike cleanup continues
Presented by
CEO and Publisher
Technology Editor
On this week’s show, Patrick Gray and Adam Boileau discuss the week’s security news, including:
- The insurance industry’s reaction to CrowdStrike’s mess
- Google’s Workspace email validation flaw and its consequences for OAuth’d applications
- Is the VMWare ESX group membership feature a CVE or an FYI?
- Secureboot continues to under-deliver
- North Korea’s revenue neutral intelligence services
- And much, much more
This episode is sponsored by allowlisting software vendor Airlock Digital. Airlock uses a kernel driver on Windows, so Chief Executive David Cottingham joined to discuss what the CrowdStrike kernel driver bug drama means for security vendors.
This episode is also available on Youtube. If you want to ruin the magic of radio and see the faces behind the show, well, now you can!
Brought to you by Airlock Digital
Allowlisting Software - Allowlist Made Simple
Show notes
Delta hires David Boies to seek damages from CrowdStrike, Microsoft
(1145) Why CrowdStrike's Baffling BSOD Disaster Was Avoidable - YouTube
CrowdStrike offers a $10 apology gift card to say sorry for outage | TechCrunch
Hackers exploit VMware vulnerability that gives them hypervisor admin | Ars Technica
AMI Platform Key leak undermines Secure Boot on 800+ PC models
Chrome will now prompt some users to send passwords for suspicious files | Ars Technica
Google Online Security Blog: Improving the security of Chrome cookies on Windows
A Senate Bill Would Radically Improve Voting Machine Security | WIRED
U.S. told Philippines it made ‘missteps’ in secret anti-vax propaganda effort | Reuters
Cyber firm KnowBe4 hired a fake IT worker from North Korea | CyberScoop
North Korean hacker used hospital ransomware attacks to fund espionage | CyberScoop
North Korean hacking group makes waves to gain Mandiant, FBI spotlight | CyberScoop
ServiceNow spots sales opportunities post-CrowdStrike outage | Cybersecurity Dive
Chaining Three Bugs to Access All Your ServiceNow Data
Cyber Supply Chain Risk Management Conference (CySCRM) 2024 | Conference | PNNL