Risky Business #808 -- Insane megabug in Entra left all tenants exposed

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

On this week’s show Patrick Gray and special guest Rob Joyce discuss the week’s cybersecurity news, including:

  • Secret Service raids a SIM farm in New York
  • MI6 launches a dark web portal
  • Are the 2023 Scattered Spider kids finally getting their comeuppance?
  • Production halt continues for Jaguar Land Rover
  • GitHub tightens its security after Shai-Hulud worm

This week’s episode is sponsored by Sublime Security. In this week’s sponsor interview, Sublime founder and CEO Josh Kamdjou joins host Patrick Gray to chat about the pros and cons of using agentic AI in an email security platform.

This episode is also available on YouTube

Risky Business #808 -- Insane megabug in Entra left all tenants exposed
0:00 / 52:37

Show notes

U.S. Secret Service disrupts telecom network that threatened NYC during U.N. General Assembly

MI6 launches darkweb portal to recruit foreign spies | The Record from Recorded Future News

One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens | dirkjanm.io

Github npm changes

Flights across Europe delayed after cyberattack targets third-party vendor | Cybersecurity Dive

Major European airports work to restore services after cyberattack on check-in systems | The Record from Recorded Future News

When “Goodbye” isn’t the end: Scattered LAPSUS$ Hunters hack on | DataBreaches.Net

UK arrests 2 more alleged Scattered Spider hackers over London transit system breach | Cybersecurity Dive

Alleged Scattered Spider member turns self in to Las Vegas police | The Record from Recorded Future News

Las Vegas police arrest minor accused of high-profile 2023 casino attacks | CyberScoop

DOJ: Scattered Spider took $115 million in ransoms, breached a US court system | The Record from Recorded Future News

vx-underground on X: "Scattered Spider ransoms company for 964BTC - wtf_thats_alot.jpeg - Document says "Cost of BTC at time was $36M" - $36M / 964BTC = $37.5K - BTC value was $37.5K in November, 2023 - Google "Ransomware, November, 2023" - omfg.exe https://t.co/uv2EzbL5HT" | X

JLR ‘cyber shockwave ripping through UK industry’ as supplier share price plummets by 55% | The Record from Recorded Future News

Jaguar Land Rover to extend production pause into October following cyberattack | Cybersecurity Dive

New plan would give Congress another 18 months to revisit Section 702 surveillance powers | The Record from Recorded Future News

AI-powered vulnerability detection will make things worse, not better, former US cyber official warns | Cybersecurity Dive