Secure Ideas (Mostly Kevin)

950 Followers
122 Following
41 Posts

Father, CEO, Security Consultant, Instructor, Presenter, Course Author, Nerd, Former Member of the 501st Legion. SL-42265

My opinions are my employer's.

Websitehttps://www.secureideas.com
Twitterhttps://twitter.com/secureideas

In our latest episode of Shared Security, we're discussing the latest in the world of cybercrime and privacy concerns. Here's the stories we'll be unpacking this week:

📰 The FBI vs. Qakbot
We discuss the FBI's takedown of the Qakbot botnet, a saga involving ransomware, cryptocurrency, and the FBI pushing an uninstaller to thousands of victim PCs. 🕵️‍♂️💼 #CyberSecurity

📰 QR Code Phishing Emails
Next, we explore how a major U.S. energy organization fell victim to a QR code phishing attack, highlighting the ever-evolving tactics used by attackers. ⚡️🔐 #PhishingAttack

📰 Dox anyone in America for $15?
Finally, we discuss the world of personal data exploitation through credit header information and a TransUnion subsidiary 🕵️‍ It's a data goldmine that attackers are exploiting for just $15! 😱 #DataPrivacy

Stay informed and stay safe online! 🌐💻

Listen on our website:
https://sharedsecurity.net/2023/09/11/the-fbis-qakbot-takedown-qr-code-phishing-attacks-dox-anyone-in-america-for-15/

Watch on YouTube:
https://youtu.be/BdtSnT1si3s

Subscribe on Apple Podcasts, Spotify, or your favorite podcast platform:
https://sharedsecurity.net/subscribe

#SharedSecurityPodcast #Cybersecurity #Privacy #DataProtection #StayInformed

The FBI's Qakbot Takedown, QR Code Phishing Attacks, Dox Anyone in America for $15 - Shared Security Podcast

Details on the FBI's massive takedown of the Qakbot botnet, QR Code phishing attacks evolve, and how credit header information is being used to dox anyone in America for only $15.

Shared Security Podcast
So I am running for the OWASP Global Board of Directors. You can find my candidate page at https://owasp.org/www-board-candidates/2023/kevin_johnson If you want to vote, even for someone other than me, you must be a member by Sept 30th. Thanks! I really feel like this is important.
Kevin Johnson | OWASP Foundation

Kevin Johnson on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to improve the security of software.

🎧 Get ready for an action-packed episode on the Shared Security Podcast, dropping this Monday! Tune in for our discussion covering the latest cybersecurity headlines you won't want to miss! 🎧

1️⃣ Microsoft Security Breach 💻🔑: Uncover the details of the recent security breach where China-backed hackers got hold of email inboxes of federal government agencies using a stolen Microsoft signing key!

2️⃣ Voice Cloning Exposé 🗣️🎙️: Join us as we discuss how a TikTok influencer used a voice cloning app to unveil a cheating partner. But the story doesn't end there! Learn about the serious risks of voice cloning and how it's fueling new types of phone scams. 😱

3️⃣ Biden-Harris Cybersecurity Labeling Program 🛡️💡: The latest announcement from the Biden-Harris administration unveils a new cybersecurity labeling program for smart devices. But will this initiative enhance or hinder the security of our beloved smart gadgets? We'll analyze the pros and cons!

🔊 Don't miss this episode filled with expert insights, analysis, and practical tips to safeguard your digital world! 🔊

🗓️ Subscribe to the Shared Security Podcast wherever you like to listen to podcasts to be among the first to listen: https://sharedsecurity.net/subscribe

Got questions or thoughts on these critical topics? Drop them below, and we'll discuss them on the next episode of the podcast! Let's stay informed and #SecureTogether! 🤝

Subscribe - Shared Security Podcast

You can find us on all popular podcast apps listed below: YouTube Apple Podcasts Google Podcasts Spotify Amazon Music Overcast iHeartRadio Stitcher Pandora TuneIn RadioPublic Luminary Podbean Deezer Podchaser Castbox Have an Amazon Echo? You can simply say “Alexa, play the Shared Security Podcast” Add us manually to your podcast player via our RSS feed

Shared Security Podcast

👋​Join us on the latest Shared Security Podcast as we tackle important issues around privacy, data security, and surveillance. Here's a sneak peek of what's in store for this week's episode:

Massachusetts Location Shield Act 🗺️
Massachusetts lawmakers are pushing a groundbreaking bill to ban the buying and selling of location data from mobile devices. This legislation raises vital questions about consumer privacy, digital stalking, and national security threats. Tune in to explore the controversy, the opposition faced, and the potential impact on law enforcement restrictions. #PrivacyMatters #LocationShieldAct

Pros and Cons of External Password Managers 🔐
Should organizations prohibit the use of external password managers? 🤔 Discover the benefits and downsides of this debate on our podcast. Join the discussion as we explore the importance of credential storage concerns, and best practices for effective password management. Share your thoughts and experiences! #DataSecurity #PasswordManagers

Real-Time Crime Centers and Privacy 👁️
Real-time crime centers have become ubiquitous across the US, but what are the implications for privacy and civil liberties? 🕵️‍♂️ We explore the potential misuse of surveillance data, the lack of oversight, and the concerns surrounding predictive policing. Join us to learn about efforts to limit these technologies and protect individual rights. #Surveillance #PrivacyRights

Also, don't miss out on Kevin's rant about the recent ISC(2) board-approved candidates for the board! 😆​Listen now on your favorite podcast platform and be part of the conversation! 🎧✨ #SharedSecurityPodcast #PrivacyDebate #DataProtection

Watch on YouTube:
https://youtu.be/lP1UQKDqezE

Listen now:
https://sharedsecurity.net/2023/07/17/first-ban-on-selling-location-data-prohibiting-password-managers-real-time-crime-center-concerns/

#Podcast #TechNews #Privacy #Security #Cybersecurity

First Ban on Selling Location Data, Prohibiting Password Managers, Real-Time Crime Center Concerns

YouTube
Pssst! New version of my Linux Forensics class now downloadable at https://archive.org/download/HalLinuxForensics/HalLinuxForensics_archive.torrent More formal announcement forthcoming, but let's get that torrent swarm humming!
Seminole schools offer to remove LGBTQ+ pages from high school yearbook

Seminole County Public Schools is offering to remove LGBTQ+ content from high school yearbooks if parents are upset, prompting complaints that district officials aren’t standing up to bigotry…

Orlando Sentinel

I am incredibly sad to be writing this on the first day of Pride month, but Mama Mia, here we go again...

Last year Seminole County (Florida) Public Schools found themselves receiving national attention for attempting to censor LGBTQ+ content in the Lyman High School yearbook. https://www.clickorlando.com/news/local/2022/05/10/yearbook-fight-pits-lyman-high-students-against-seminole-school-officials/ After massive public outcry, the School Board reversed Superintendent Serita Beamon's order and the books went out to students without the content being covered up.

Here we are one year later and once again Serita Beamon is attempting to censor LGBTQ+ content in the Lyman Yearbook. This year's debacle was energized by Lyman parent Sharmon Craft and an astroturf campaign thanks to her "Mom's For Liberty" cronies. https://www.foxnews.com/media/florida-yearbook-defining-lgbtq-terms-genderfluid-pansexual-parent-outrage

Former Lyman student and yearbook editor Madi Koesler does an excellent job of explaining where we are in the current fight and suggesting how you can help: https://www.instagram.com/p/Cs7UNyFOZC4/ If you are in the greater Orlando area, we would love to see you at the School Board meeting this Tuesday. If you are not local, please make your voices heard via email.

My wife Danielle has been a teacher and the yearbook advisor at Lyman for the last five years, so please allow me to add a bit of additional color commentary to what has already been reported.

Even after the School Board ordered the books not to be censored last year, Serita Beamon lawyered the decision and attempted to introduce changes not authorized by the School Board. This led to further delays and negotiations around releasing last year's book.

In her email to parents this year, Beamon notes that the yearbook is subject to review prior to publication. The email leaves open whether or not the book was reviewed. I can assure you that the book was reviewed prior to publication and no concerns were raised about this content until Sharmon Craft and the Mom's for Liberty crew got involved.

You may also be interested at this point in reading the Student Press Law Center's brief article on prior review vs. prior restraint in student publications: https://splc.org/2020/10/ask-splc-what-is-the-difference-between-prior-restraint-and-prior-review/

In the email to parents, Beamon offers to allow parents to trade in their current yearbook for a new yearbook with the offending two-page spread blanked out. Understand that the Lyman yearbook has already been published and distributed to students. Providing new books with a blank spread will require printing another (short) run of yearbooks at the cost of thousands of dollars. Surely this is not an appropriate use of school funds given the already unprecedentedly low public school funding levels.

Conservative estimates are that 9-10% of the high school age population identifies as LGBTQ+. By erasing these two pages (less than 1% of the total yearbook) we erase their identities and lives from the Lyman community. This must not stand.

As was said in the 1980's, "We here. We're queer. Get used to it!"

#Pride #LGBTQ+ #Censorship

District requires Lyman High School to cover ‘Don’t Say Gay’ protest photos in yearbook

The material in question are photos and captions documenting a student walk-out in March, a response to the Parental Rights in Education law, also known as the “Don’t Say Gay” law.

WKMG News 6 & ClickOrlando
I know I am late to the game, but I am really enjoying ARK: Survival Evolved.

🚨​The Top 10 Episodes of 2022🚨​

As we come to the end of another year, we wanted to take a moment to thank you for your support of the Shared Security Show. Your continued listening and engagement with the podcast means the world to us, and we are grateful for the opportunity to share our thoughts and insights on the latest in cybersecurity and privacy with you.

As we look back on the past year, we wanted to share with you the top 10 episodes of the podcast that received the most attention and engagement. We hope you will enjoy revisiting these popular episodes, or maybe even discovering them for the first time:

1. Google Android vs Apple iOS: Which is Better for Privacy and Cybersecurity?
https://youtu.be/dVjmDs3arVg
https://sharedsecurity.net/2022/04/04/google-android-vs-apple-ios-which-is-better-for-privacy-and-cybersecurity/

2. LAPSUS$ Hacks Okta, Browser-in-the Browser Phishing Attack, Popular Software Package Updated to Wipe Russian Systems
https://youtu.be/NViClPl65u0
https://sharedsecurity.net/2022/03/28/lapsus-hacks-okta-browser-in-the-browser-phishing-attack-popular-software-package-updated-to-wipe-russian-systems/

3. Multi-Factor Authentication Fatigue Attack, Signal Account Twilio Hack, Facebook and Instagram In-App Browser
https://youtu.be/SBnzn16xt1E
https://sharedsecurity.net/2022/08/22/multi-factor-authentication-fatigue-attack-signal-account-twilio-hack-facebook-and-instagram-in-app-browser/

4. Russia Gets Hacked, Microsoft 365 Credential Stuffing, McDonald's Ice Cream Machine Hackers
https://youtu.be/8xFZ9WZoz8k
https://sharedsecurity.net/2022/03/07/russia-gets-hacked-microsoft-365-credential-stuffing-mcdonalds-ice-cream-machine-hackers/

5. FBI Warrantless Searches, Passwordless Sign-Ins, Keylogging Web Forms
https://youtu.be/kyLp0bgTzuU
https://sharedsecurity.net/2022/05/16/fbi-warrantless-searches-passwordless-sign-ins-keylogging-web-forms/

6. Ukraine Invasion Hacktivists, Insta360 ONE X2 Vulnerabilities, Google Location Tracking Lawsuits
https://youtu.be/SDXmcrd6CiE
https://sharedsecurity.net/2022/01/31/ukraine-invasion-hacktivists-insta360-one-x2-vulnerabilities-google-location-tracking-lawsuits/

7. DuckDuckGo Browser Allows Microsoft Trackers, Stolen Verizon Employee Database, Attacking Powered Off iPhones
https://youtu.be/Bdag8jAKex0
https://sharedsecurity.net/2022/06/06/duckduckgo-browser-allows-microsoft-trackers-stolen-verizon-employee-database-attacking-powered-off-iphones/

8. LastPass Master Passwords, New Cars and Your Privacy, Amazon Alexa Lethal Challenge
https://youtu.be/C23QQF3VMnw
https://sharedsecurity.net/2022/01/03/lastpass-master-passwords-new-cars-and-your-privacy-amazon-alexa-lethal-challenge/

9. The State of Application Security with Tanya Janca (@SheHacksPurple)
https://youtu.be/LJ5RkD-qLjQ
https://sharedsecurity.net/2022/05/30/the-state-of-application-security-with-tanya-janca/

10. Hacking Ham Radio: Why It's Still Relevant and How to Get Started
https://youtu.be/EDJKbEXydq0
https://sharedsecurity.net/2022/06/13/hacking-ham-radio/

🙏​Thank you again for your support and for being a part of the Shared Security Show community! Happy New Year! 🥳​

#podcast #podcasting #cybersecurity #privacy

Google Android vs Apple iOS: Which is Better for Privacy and Cybersecurity?

YouTube

At the recommendation of people I trust and respect, I would like to say that Secure Ideas is looking to hire a COO in 2023. We are currently looking at the job description and such to start the search.

So basically if you have any recommendations on this process or people (based on your experience) we would love to hear from you. We are currently a 27 person security consulting company. So basically a services organization. We are in the process of expanding our offerings to include a couple of products Jason and I are designing.

Thanks!