Posts

UNSECURITY Episode 138 Show Notes

Hope you had a wonderful Independence Day (July 4th)! We’ve gone through a lot together in this country, and I love this place we call home. Lots to do in making the USA better, but this will always be the case. This is the best country in the world, and I’m grateful!

In case you missed it, two big events last week; the Kaseya ransomware attack and Microsoft’s PrintNightmare.

Kaseya Ransomware

So, you might have heard. On Friday (going into July 4th weekend), computers around the world (not all of them, but maybe ~1,000,000 of them) started to lock up. The announcement came around midday that Kaseya’s VSA servers were being used to distribute ransomware, primarily to MSP customers. My first thought was “Oh shit! We might have another SolarWinds.” Thank God, this wasn’t the case.

Facts started to come in, and it became evident that this was an attack directed at VSA servers hosted by MSPs. Some MSPs (about 2,200 of them) installed their VSA servers so that they were accessible from the Internet. I’m not a VSA expert, but this high number implies this as standard practice. A zero day vulnerability (and exploit) was discovered by the REvil ransomware gang (or an affiliate) and was used to infect clients.

Kaseya already knew about the vulnerability thanks to the good work by Wietse Boonstra and his compatriots at NIVD. The vulnerability was reported to Kaseya and the two groups were working on a patch at the time of the ransomware attack. The end result was somewhere between 60-70 MSPs affected and somewhere between 1,200-1,500 companies infected. Kaseya did a good job responding, and so did many MSPs. Lessons learned are TBD after the dust settles.

Links referenced in today’s show are below.

Microsoft PrintNightmare

If it hadn’t been for Kaseya, this would have been top news. In terms of scope, this is much bigger, affecting many millions of servers (and companies). In terms of potential impact, this also exceeds the Kaseya attack. News broke on June 30th about an impressive and potentially very damaging vulnerability in the Microsoft Print Spooler service. On July 1st, Microsoft released additional information about the vulnerability and offered (un)helpful guidance.

There is an exploit in the wild for this vulnerability that allows complete control over a server (and Active Directory).

We’ll talk a little about this too. Links referenced in today’s show are also below.

 

OK. Show notes for episode 138…


SHOW NOTES – Episode 138 – Tuesday July 6th, 2021

Opening

[Evan] Welcome listeners! It’s good to have you join us. Thanks for tuning into this episode of the UNSECURITY Podcast. This is episode 138, and the date is July 6th, 2021. Joining me is my good friend, Mr. Brad Nigh. Good Morning Brad!

[Evan] Hope you had a wonderful 4th of July. Many people had the day off yesterday, but some people were fighting the fire caused by ransomware deployed through Kaseya’s VSA servers. This is where we’ll start.

Kaseya Ransomware Attack

Here’s a list of links/articles we’re explore in this episode:

All in all, this attack could have been MUCH worse than it was. Incident responders did a great job and communicated well. More to come in time…

Microsoft PrintNightmare

This one is a doozy. Here are the three links/articles we’ll reference in this episode:

Last week’s show was all about Microsoft security debacles, and now this. A patch is not available yet and many IT teams are scrambling right now. I’m become less and less of a Microsoft fan with each passing day.

That’s it for today’s show. Lots of work to do!

Wrapping Up – Shout Outs

Who’s getting shout outs this week?

Thank you to all our listeners! Thank you Brad for a great conversation! If you have something you’d like to tell us, feel free to email the show at unsecurity@protonmail.com. If you’re the social type, socialize with us on Twitter, I’m @evanfrancen, and Brad’s @BradNigh.

Other Twitter handles where you can find some of the stuff we do, UNSECURITY is @unsecurityP, SecurityStudio is @studiosecurity, and FRSecure is @FRSecure.

That’s it. Talk to you all again next week!

…and we’re done.

UNSECURITY Episode 137 Show Notes

It’s been a few weeks since I posted show notes, and even then, I’m late!

If you working in the information security industry, you’re probably extremely busy. My busyness is what’s kept me from updating show notes and things.

Episode 137 was a fun one. Brad was back and we talked about all Microsoft’s recent blunders/issues.

John McAfee

Before we get into it, I want to take a moment to remember John McAfee. On June 23, he was found unresponsive in his jail cell at the Brians 2 Penitentiary Center near Barcelona, Spain. Sadly, he passed away at the age of 75 after an apparent suicide by hanging. He had just lost his hearing for extradition to the United States.

John McAfee was a very interesting guy, and some might say he was nuts and a crook. While that might be true (I don’t have evidence to say either way), I remember him before the mid-2000s, when he was an icon in our industry. The guy was smart as hell!

  • 1968 – 1970, programmer for NASA working on the Apollo Program
  • Software designed for Univac
  • Operating system architect for Xerox
  • Software consultant for Computer Sciences Corporation
  • Consultant for Booz Allen Hamilton
  • Software engineer for Lockheed (where he first learned about computer viruses and came up with the idea to remove them programmatically)
  • 1987, founded McAfee Associates Inc which sold the world’s first anti-virus software
  • 1990, sold millions of copies of McAfee anti-virus software leading to John’s $5M/year salary
  • 1992, McAfee’s initial public offering (IPO)
  • August 1993, steps down as CEO.
  • 1994, sold all his remaining stake in McAfee Associates Inc.

In January 2014, after Intel (who’d acquired McAfee in August 2010) announced that McAfee products would be marketed as “Intel Security”:

I am now everlastingly grateful to Intel for freeing me from this terrible association with the worst software on the planet.” – John McAfee

Soon afterwards, the business was de-merged from Intel and re-acquired the McAfee name.

John McAfee was all over the place after divesting from the company with his name. He invested in many ventures, travelled, dabbled in politics (two U.S. presidential candidacies), was a person of interest in a Belize homicide investigation, charged with tax evasion, posted hundreds of public remarks and videos on social media, before it all eventually ended on June 23rd. He was a very interesting person who was influential in our industry.

I will miss him.

OK, now the show notes. Here’s the notes (with relevant links). Episode 137…


SHOW NOTES – Episode 137 – Tuesday June 29th, 2021

Opening

[Evan] Welcome listeners! It’s good to have you join us. Thanks for tuning into this episode of the UNSECURITY Podcast. This is episode 137, and the date is June 29th, 2021. Joining me is my good friend, Mr. Brad Nigh. Good Morning Brad!

[Evan] Welcome back sir. Happy that you’re back in the saddle again. Microsoft was front and center in the information security news this week. Let’s dissect some of this.

Microsoft in the (Information Security) News

Here’s a list of articles that we talk about in this episode:

Obviously, Microsoft has its hands full. Don’t we all? One issue with Microsoft is how much control they have over our industry and how much data they hold. Significant information security events at Microsoft have a significant impact for millions of organizations.

Just one other news article of interest this week: One billion dollars lost by over-60s through online fraud in 2020, says FBI – https://hotforsecurity.bitdefender.com/blog/one-billion-dollars-lost-by-over-60s-through-online-fraud-in-2020-says-fbi-26049.html

That’s a lot to unpack! Hopefully you caught all that.

Wrapping Up – Shout Outs

Who’s getting shout outs this week?

Thank you to all our listeners! Thank you Brad for a great conversation! If you have something you’d like to tell us, feel free to email the show at unsecurity@protonmail.com. If you’re the social type, socialize with us on Twitter, I’m @evanfrancen, and Brad’s @BradNigh.

Other Twitter handles where you can find some of the stuff we do, UNSECURITY is @unsecurityP, SecurityStudio is @studiosecurity, and FRSecure is @FRSecure.

That’s it. Talk to you all again next week!

…and we’re done.

The UNSECURITY Podcast – Episode 89 Show Notes – Women in Security Pt6

Ready for another installment of the UNSECURITY Women in Security Podcast Series?

NOTE: I forgot to post these notes ahead of the podcast recording. Episode 89 with Judy Hatchett was awesome! It’s been recorded and published here. THANK YOU JUDY! Now the show notes…

We have another GREAT special guest joining us! One of my favorites, Judy Hatchett, Vice President and Chief Information Security Officer (CISO) at Surescripts will share her story and opinions in this episode (#89).

First, a quick recap of the Women in Security series thus far…

Women in Security Series

Brad and I started this series because we wanted to learn more about challenges women face in the information security industry. It would be shallow and dry if Brad and I chose to discuss this subject ourselves. Instead, we chose to interview women that we know and ones who were referred to us.

What better way to get a woman’s perspective on things than to ask them directly?!

So far, we’ve had five women join us as guests on the show. Each woman brought her own set of experiences, perspectives, and opinions. No two guests have been alike, and we’ve learned a TON!

Here’s our guest line up thus far:

  • Episode 84 – Renay Ruter (an information security business/IT executive)
  • Episode 85 – Lori Blair (a 35-year information security veteran)
  • Episode 86 – Victoria Fogarty (relatively new to the industry)
  • Episode 87 – Kristin Judge (founder and CEO of the Cybercrime Support Network, SC Media “Women in IT Security Influencer” in 2017, former Director of Government Affairs at the National Cyber Security Alliance (NCSA), thought leader, and all-around amazing information security expert)
  • Episode 88 – Andrea Hatcher (Senior majoring in Cybersecurity Analytics and Operations at Pennsylvania State University)
  • Episode 89 – Judy Hatchett (this show) (Information security corporate leader and expert formerly with Accenture, Best Buy, SUPERVALU, 3M, Fairview Health Services, and current VP, Information Security and CISO at Surescripts)
  • Episode 90 – Amy McLaughlin (Information security leader and expert in education, having served with the State of Oregon, the Consortium for School Network (CoSN), Chemeketa Community College, and Oregon State University)
  • Episode 91 – Theresa Semmens (Chief Information Security Officer at the Nevada System of Higher Education, former AVP/Chief Information Security Officer at the University of Miami, and former Chief Information Security Officer at North Dakota State University)
    /not-yet-confirmed (information security executive in healthcare, CISO in higher education, or senior information security sales executive)
  • Episode 92 – Lee Ann Villella (Senior Enterprise Security Sales Consultant at FRSecure, Program Director for the Minnesota Chapter of the Information Systems Security Association, and member of the Cyber Security Summit Advisory Board Committee)
  • Episode 93 – TBD/not-yet-confirmed (information security executive in healthcare, CISO in higher education, or senior information security sales executive)

This is an amazing lineup of information security professionals! These women represent our information security industry extremely well, and we’re honored to speak with each of them on our show!

Here’s what we’ve done so far…

Women in Security Series – Part One

We kicked off the Women in Security series on June 15th, and we couldn’t have chosen a better first guest! Renay Rutter, FRSecure’s COO, got the series started by sharing the experience, wisdom, and insight she’s gained over her 30+ year IT career. Renay expressed how important it has been for her to be strong throughout her career, and in her opinion, women need to be strong to survive in the information security industry. This was a great show!

If you missed this episode, you can catch up here; https://podcasts.apple.com/us/podcast/unsecurity-episode-84-women-in-security-pt-1-renay-rutter/id1442520920?i=1000478037575

Thank you Renay!

Women in Security Series – Part Two

We kept things in the FRSecure family for week two, hosting Lori Blair. Lori is full of information security knowledge and wisdom! She started her career in the industry in 1985, working for the federal government. Over the next 35 years, she’s traveled the world helping organizations with their information security needs and held various leadership positions. She’s excelled everywhere she’s gone and even found time to raise children along the way! Today, Lori is a Senior Information Security Consultant at FRSecure, tackling difficult challenges and mentoring other women.

I have a TON of respect for Lori, and her opinions carry weight for me (and many others). It’s not just her experience that makes Lori amazing, she’s a wonderful, practical, and level-headed person who loves mentoring others. This is a can’t miss episode, go give a listen here; https://podcasts.apple.com/us/podcast/unsecurity-episode-85-women-in-security-pt-2-lori-blair/id1442520920?i=1000479175255

Thank you Lori!

Women in Security Series – Part Three

We welcomed up and comer Victoria Fogarty to the show for Part Three. Victoria is an Associate Information Security Analyst at FRSecure, where she started her career in 2019. She possesses natural gifts for this industry, and her perspectives were fresh. She’s intelligent, relatable, and an excellent communicator. She did a great job explaining how she researched a career in information security while she was an Insurance Adjuster, a job she disliked. Her journey is pretty cool so far, and her future is VERY bright! She even shared a shocker (at least for Brad and me) in this episode. Definitely worth the listen!

If you missed episode 86, here it is; https://podcasts.apple.com/us/podcast/unsecurity-episode-86-women-in-security-pt-3-victoria/id1442520920?i=1000480167348

Thank you Victoria!

Women in Security Series – Part Four

Kristin was our first non-FRSecure guest in the series. This was a great interview! Kristin shared how she got her introduction to information security while she was serving as an elected official (Washtenaw County Commissioner). She has an incredible journey so far, especially considering she has only been in the industry for a little more than 10 years.

She held some very exciting roles before founding the Cybercrime Support Network in late-2017. Her passion for helping people is inspiring, and we’re looking forward to making a difference in this industry together!

Learn about Kristin Judge, her journey, her opinions, and her work founding and running the Cybercrime Support Network in episode 87. If you missed it, go give it a listen; https://podcasts.apple.com/us/podcast/unsecurity-episode-87-women-in-security-pt-4-kristin-judge/id1442520920?i=1000482892565

Truly an amazing person; we loved chatting with her!

Thank you Kristin!

Women in Security Series – Part Five

It was a pleasure having Andrea join us in this episode! She is a Senior at Pennsylvania State University (Penn State), majoring in Cybersecurity Analytics and Operations. She is an avid listener to our show who contacted us through email about a question she had. She was shocked and VERY appreciative when we asked her to join us. We were pleasantly surprised by how well-spoken and determined she was.

Andrea has an incredible future ahead of her in the information security industry! Here’s her take on things in episode 88, WARNING: You’ll be impressed!

Thank you Andrea!

This brings us to today’s episode…

Women in Security Series – Part Six

Today’s guest is Judy Hatchett, a top-notch, no nonsense information security leader. She is the first Chief Information Security Officer we’ve had on the show in the series, and she’s more than worthy. We first met Judy back when she was the CISO at Fairview, and we’ve  been cheering her on (from a distance) in her new role at Surescripts. You’re going to love her perspectives and opinions!

WELCOME JUDY!

 

Let’s get to the show, shall we?

Brad’s leading the show this week, and these are his notes…


SHOW NOTES – Episode 89

Date: Monday, July 20th, 2020

Episode 89 Topics

  • Opening
  • Introducing Our Special Guest: Judy Hatchett (Vice President and Chief Information Security Officer at Surescripts)
  • Catching Up (as per usual)
  • Women in Security
  • News
  • Wrapping Up – Shout outs
Opening

[Brad] Welcome back! This is episode 89 of the UNSECURITY Podcast, and I’m your host this week, Brad Nigh. Today is July 20th, and joining me this morning as usual is Evan Francen. Good morning Evan.

[Evan] Cue Evan

[Brad] Today we’re recording Part Six of the Women in Security Series, and I’m excited to welcome our guest! She’s someone we greatly respect and someone with the experience to demand it! Today we welcome Judy Hatchett (Information security corporate leader and expert formerly with Accenture, Best Buy, SUPERVALU, 3M, Fairview Health Services, and current VP, Information Security and CISO at Surescripts) to the show. Welcome Judy!

[Judy] We know Judy and we expect something positive and/or funny

[Brad] Before we get going let’s recap our week.

Catching Up

[Evan] I don’t know if I talked to Evan since the last podcast (episode 88), I don’t know what’s up…

[Brad] And how about you Judy?

[Judy] Probably something cool…

Quick discussion about last week, the weekend, or whatever else comes to mind.

  • How are you guys?
  • Tell me about your weekend quick.
  • Anything in particular that you’re excited about?

[Brad] Thanks guys! Alright, let’s get to it.

Women in Security, Part Six

[Brad] This is the sixth week of our series discussing the topic of women in the information security industry.  I think we are starting to see some commonalities from the last five guests and I’m curious to see if Judy has similar insights. I’m also really looking forward to hearing another “outsider’s” perspective and continue this conversation. So with that let’s dive in!

Do we have a shortage of women in our industry? If so, what’s the big deal? Why is the topic important for us to talk about? Lot’s of questions and I’m sure just about everyone has an opinion. Instead of people listening to our opinions, we’re going to talk to the people this relates to the most; women! What better way to get a woman’s perspective on things than to talk to a woman? Let’s do this.

Open Discussion (~30 minutes)

  • How did you get started in this field (information security)?
  • Tell us how you got to where you’re at today.
  • Each of the ladies we’ve had on the show has given us some great insight and wisdom:
    • Part 1 – Renay mentioned the importance of being strong.
    • Part 2 – Lori mentioned the importance of mentoring
    • Part 3 – Victoria mentioned the importance of staying focused.
    • Part 4 – Kristin mentioned the importance of being yourself.
    • Part 5 – Andrea mentioned the importance of finding support.
    • Have you listened to what these ladies had to say in their interviews? If so, what were your thoughts?
  • What advice do you have for someone who’s just starting out?
  • Have you experienced the “bro culture” in our industry? If so, can you share the experience with us?
  • Have you heard about our (alleged) industry talent shortage?
    • Do you think we need more women in our industry and why?
    • Opinions about the talent shortage in our industry.
  • What can we do better in recruiting more people, and specifically more women in our industry?
  • Whatever else we’d like to share.

[Brad] Thank you Judy! Good information and things to think about more. Much appreciated! How about some quick news stuff?

Judy, please stick around. If you’ve got anything to add to our commentary, please don’t hesitate.

News

[Brad] More newsy things…

Lastly, I don’t think we need to spend any time on it as it’s been covered extensively but I thought Krebs had a really good writeup on the Twitter hack that the listeners will probably enjoy.

Wrapping Up – Shout outs

[Brad] There you go, episode 89 is in the bag. Thank you Judy for a great sixth installment of to the Women in Security series. Either of you have any shout outs this week?

[Evan and/or Judy] We’ll see.

[Brad] Thank you to all our listeners! Thank you to our listeners! Keep the questions and feedback coming. Send things to us by email at unsecurity@protonmail.com. If you’re the social type, socialize with us on Twitter, I’m @BradNigh, and Evan is @evanfrancen. Judy, is there a particular way you’d prefer people to find you?

Lastly, be sure to follow SecurityStudio (@studiosecurity) and FRSecure (@FRSecure) for more goodies.

That’s it! Talk to you all again next week!