The episode discusses the recent Klue security incident and various cybersecurity threats including phishing and the FortiBleed attack.
・ 警視庁サイバー on X: "【サイバー攻撃対策センター】 フィッシングメールは巧妙化しています。今回紹介する「二段階式フィッシングメール」は、1通目の不審なメールを見破った人に対して、2通目にさらに巧妙なフィッシングメールを送りつけるもので、メール受信者の注意力を逆手に取った手法と言えます。 #フィッシング [https://t.co/N0xReCVlaZ"](https://t.co/N0xReCVlaZ") / X ・ An Update on the Recent Klue Security Incident – Klue ・ Cybercrime Breaches Klue: Salesforce Data Impacted for Many Victims, including Huntress | Huntress ・ BOD 26-04: Prioritizing Security Updates Based on Risk | CISA ・ GitHub – cisagov/vulnrichment: A repo to conduct vulnerability enrichment. · GitHub ・ Analysis of Reported Credential Compromise of FortiGate Devices | Fortinet Blog ・ CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure | CISA ・ Inside the FortiBleed Open Directory: A Technical Analysis of What the Attacker Left Behind | CloudSEK ・ ぽてとちゃん。 – YouTube 辻伸弘メモ:めっちゃトラックしたろ。初Qi。過去から来てました。2個来るのいやらしい。確立される良さと失われるもの。動き始めてるで。なんからの方法か。またもやこの流れか。ちょっと複雑なほうのサービスサプライチェーン。セキュリティ企業でも使っている人たち、使うことを決めた人たちが専門家とは限らないですもんね。脅威の見積もりをする際の範囲。攻撃者の対象への理解。BOD…
Explore listener stats, chart rankings, contacts and more on the セキュリティのアレ podcast page.