• Articles
    • Editorial Articles
    • Research Articles
    • WatchGuard Articles
  • The 443 Podcast
  • Threat Landscape
  • About
    • About Us
    • Contact Us
    • Contribute to Secplicity

Secplicity - Security Simplified

Powered by WatchGuard Technologies

Premera, CISA, and OpenSSL – WSWiR Episode 144

March 20, 2015 By Corey Nachreiner

This week’s security news covered topics from biometrics, to nation-state cyber teams, to big data breaches, to new vulnerabilities. How’s the average network Joe to keep up? Let my weekly video help by quickly summarizing the important stuff.

Today’s show covers a US healthcare data breach, a new OpenSSL update, and the US CISA law. You’ll find it all in this week’s video, and more in the Reference section below.

(Episode Runtime: 11:23)

Direct YouTube Link: https://www.youtube.com/watch?v=nigzxITwPvI

EPISODE REFERENCES:

  • Daily Security Bytes:
    • Monday: Securing HTTPS – Daily Security Byte EP.45
    • Tuesday: Premera Healthcare Breach – Daily Security Byte EP.46
    • Wednesday: Proof China Hacks – Daily Security Byte EP.47
    • Thursday: OpenSSL DoS – Daily Security Byte EP.48
    • Friday: CISA Passes Committee- Daily Security Byte EP.49
  • HTTPS continues becoming a default
    • Pinterest beefs up security with HTTPS – Venture Beat
    • WatchGuard Firebox M500 keeps HTTPS safe – eWeek
    • WatchGuard Infographic on accelerated security – WatchGuard
  • Premera data breach
    • Premera’s public announcement about their data breach – Premera
    • Me talking about the breach on local news – Q13 Fox
    • Bloomberg’s article on the Premera breach – Bloomberg
  • Chinese government confirms cyber teams
    • Article describing proof that China admits to cyber attack teams – The Daily Beast
    • My article on how government hacking makes us all less secure – Dark Reading
  • OpenSSL update not so bad
    • OpenSSL update to fix critical vulnerabilities – Krebs on Security
    • OpenSSL update is not as critical as first worried – Ars Technica
    • The OpenSSL advisory – OpenSSL
  • CISA passes first Senate step
    • CISA passes the Senate intelligence committee – Wired
    • The full updated CISA bill – Scribd

EXTRAS:

  • Popular Viner alleges that a hacker deleted all his Vines – BBC
  • Snowden says Gov. will target IT admins – ZDNet
  • Healthcare IoT exposes risk – Help Net Security
  • More health insurers report breaches – Dark Reading
  • Healthcare the new targeted vertical? – Dark Reading
  • German Vice Chancellor said US threatened them over Snowden – The Intercept
  • Tails (a secure OS) still vulnerable to BIOS malware – Forbes
  • Bad software still found on Google Play – Betanews
  • Great article on the increase InfoSec attack surface – Network World
  • US gov. wants researchers to trust them about CFAA changes – Motherboard
  • Is the President’s (US) fitbit a risk to his security? – IB Times
  • Safari uses should update to fix 17 issues – ITPro
  • DDoSers target Xbox’s latest popular online FPS – Daily Star
  • Operation Woolen Goldfish targets European firms – Trend Micro
  • Kaspersky allegedly has ties to Russian gov. – Bloomberg
  • Litchfield finds critical Yahoo! Stores vulnerabilities – The Register
  • $300 device cracks iOS passcodes in 17 hours – The Register
  • Facial recognition becomes nouveau
    • Alibaba to use facial recognition for payments – Ubergizmo
    • Windows 10 Hello; built in biometric support – Microsoft News
    • Yet, it’s still easy to trick facial recognition – Popsci
  • South Korea blames North Korea for nuclear reactor hacks – Reuters
  • X-Force say 1B records leaked in 2014 – ZDNet
  • Malware sets records in 2014 (again) – ITPro Portal
  • Google play will adopt a human vetting process – Neowin
  • Will USB-C limit our ability to avoid potentially malicious USB? – The Verge
  • Krebs finds another healthcare hack [PDF] – KrebsonSecurity
  • PCI Security Standards site suffers from XSS – Xssposed
  • Cisco to change shipping practices to avoid interdiction – The Register
  • Judicial committee approves FBI remote hacks – TechDirt
  • Fed says it warned Premera of security issues – Seattle Times
  • China wants source code and new encryption if you bank with them – Reuters
  • Why law firms are a “cyber” target – Bloomberg
  • Individual apps may still be vulnerable to FREAK – V3.co.uk
  • A simple fake ID evades GoDaddy security (social engineering) – CSO Online
  • Techniques link healthcare hacks – Computer World
  • Great post on Anthem attack techniques – Threat Connect
  • Did China hack Register.com? – Reuters
  • Lots of new vulnerabilities ousted at Pwn2Own – The Register

— Corey Nachreiner, CISSP (@SecAdept)

Share This:

Related

Filed Under: Security Bytes Tagged With: CISPA, Cyber Espionage, cyber security, Hacking, Healthcare, HTTPS, Infosec news, nation-state hacking, OpenSSL, Pinterest, Premera, Security breach, Senate, Software vulnerabilities

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

The 443 Podcast

A weekly podcast featuring the leading white-hat hackers and security researchers. Listen Now
the 443 podcast

Threat Landscape

Filter and view Firebox Feed data by type of attack, region, country, and date range. View Now
threat landscape

Top Posts

  • Cybersecurity News: Free Cybersecurity Training, TrickBot Group Exposed, Major GoDaddy Breach, and Russia to Legalize cybercrime?!
  • US National Cybersecurity Strategy
  • Here Come The Regulations
  • Cybersecurity’s Toll on Mental Health

Email Newsletter

Sign up to get the latest security news and threat analysis delivered straight to your inbox

By signing up you agree to our Privacy Policy.


The views and opinions expressed on this website are those of the authors and do not necessarily reflect the policy or position of WatchGuard Technologies.

Stay in Touch

Recent Posts

  • Cybersecurity News: LastPass Incident Revealed, White House Issues Cybersecurity Strategy, FBI Purchases Leaked USHOR PII Data, and a Slew of Other Breaches
  • An Update on Section 230
  • Here Come The Regulations
  • US National Cybersecurity Strategy
  • Cybersecurity News: Free Cybersecurity Training, TrickBot Group Exposed, Major GoDaddy Breach, and Russia to Legalize cybercrime?!
View All

Search

Archives

Copyright © 2023 WatchGuard Technologies · Cookie Policy · Privacy Policy · Terms of Use