Skip to content
TrackPodcasts
technologySep 4, 202637:33

Wireguard, Chrome, RMMS, Sonicwall, Microsoft, Sumerian VPNS, Harvard, Josh Marpet... - SWN #613

About this episode

Wireguard, Chrome, RMMS, Sonicwall, Microsoft, Sumerian VPNS, Harvard, Josh Marpet, and More on this episode of the Security Weekly News.

Show Notes: https://securityweekly.com/swn-613

Get every episode summarized

Each time Security Weekly Podcast Network (Video) publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Transcript ready

687 searchable segments. Every word is indexed and playable.

Wireguard, Chrome, RMMS, Sonicwall, Microsoft, Sumerian VPNS, Harvard, Josh Marpet... - SWN #613

Security Weekly Podcast Network (Video)

0:00
37:33

Full transcript

Security Weekly Podcast Network (Video)Wireguard, Chrome, RMMS, Sonicwall, Microsoft, Sumerian VPNS, Harvard, Josh Marpet... - SWN #613. Machine-transcribed; use the interactive transcript above to jump the player to any line.

It's the security weekly news. It's episode 613 and it is Friday, the fourth day of September, 2026. I'm Doug White, welcome aboard. Today we have Wireguard, Chrome, RMMs, Sonic Wall, Microsoft Goths, Sumerian VPNs, Harvard, Josh Barbat and more on this episode of the Security Weekly News. It's the show that keeps you up to date on the latest security news twice a week. You're trusted source for accurate security information and expert analysis. It's time for the security weekly news. I'm Doug White. This is the security weekly news and this weekend is Labor Day in the United States. I don't know what that means exactly but that's what it is. And it does mark the last of summer. It's the last weekend of summer and people go to block Island and Martha's Vineyard. Rich people go to block Island and Martha's Vineyard to visit the beach one last time before

it pretends to be autumn and then gets really, really hot again for a while in New England. Where you are, I have no idea. I don't know what will happen in your unsivenized parts of the world. But you know, oh, and it's also election season in the United States. So we have 40 people a day stopped by our house to tell us how that other person is really terrible and possibly feeds deer, which is illegal in Rhode Island. I learned. It's candy for babies and it's probably addicted to del's lemonade. So you know, autumn, that kind of thing. Another breach, another exposed asset, no one knew about. It keeps happening and for many teams, the hardest part is just knowing what's out there. So what are you missing? Join the attack surface management virtual cybersecurity summit on September 16th to learn how organizations are discovering unknown assets, reducing exposure and staying ahead of attackers. Community Weekly listeners can register for free at securityweekly.com slash ASMR using the exciting promo code CSS26-sw.

Yeah, that code right it down. You should go to that. It's free. You probably even counted for CPE credits, but who knows? Google updated Chrome browser for an actively exploited high severity zero day flaw in the V8 engine. This came to light along with 11 other vulnerabilities. They didn't provide a lot of details, but they said it was a type confusion flaw, which is when social really bad thing. When software misinterprets one object as another, yeah, so it's kind of like brushing your teeth with a toilet brush after a night out at Defcon and thinking, wow, my toothbrush seems to taste a little strange today. I think the lesson here is patch, obviously, but the other lesson is how do we control any sort of level of consistency in our enterprise? Bring your own device means no more deep freeze, no more images, no more ghosting and all that stuff that we used to do.

If this guy has Chrome and those people over there have brave and someone down his sales is running mosaic and I'm running links on my Arch Linux laptop, how do we make sure all those products are patched properly before they connect your networks? I mean, I don't use Chrome, but they do patch it a lot. I mean, I see updates for it all the time. And I think this is more of that. We're just beta testing this on you, but I really felt like bringing your own device was a cheap yet unsettling idea, but knew it wasn't inevitable. I mean, I was like, yeah, I remember them academic articles called user empowerment distributed computing and all that stuff. I mean, we used to have labs for people to use and that was the only way they could connect to our network. I mean, originally it was like a terminal. I controlled it. I could just turn it off. But when we had labs with PCs in them, we used to deep freeze them so that you couldn't change it and if the image changed even a tiny bit, it overwrote itself. I mean, you don't like Firefox?

Tough. You're using Firefox, very mainframe. But today, I think we just go for it. The point being that you have to educate users and ensure that they patch, but warn them that half the patches are click fix attacks that look like patches. So you may want to be very careful about that. You are expert enough to discern that, right? So links, the browser for a better tomorrow. Reduce your world to text only and be happier. And I checked, links still exist. I looked it up. Version 2.9.3 just came out. It's like you want to be hardcore. You use links. Links does not have graphics. It does not support JavaScript. You can't do much of anything with it. You can you, you encode and you, you decode the good old days of no graphics and ask you to porn. And yes, we found you, you encoded ask you to porn on people's machines. One of the earliest internet questions I got asked somebody said, do you have any idea what this is? I think it's some kind of crypto cipher. And I was like, I don't know what it is. Let me run it through some stuff to see if we can figure it out.

What was you, you encoded ask you to porn? That's how desperate people are. The thread landscape just shifted under your feet. Attacks move at machine speed now and you can't defend what you can't see. Tainium Atlas has changed that. One prompt and it queries every endpoint in your fleet. Surfacing machines exposed to a live Axio supply chain compromise in seconds. This is live state, not a stale CMDB. Like pinpoint switch endpoints are truly compromised and traces the attacker's command and control. Atlas then secures the business by isolating patching and remediating all at once. Tainium Atlas, see everything act instantly. Find out more at securityweekly.com slash Tainium. Unlock the full InfoSec World experience with the all access pass featuring premium workshops, of content, VIP experiences and expanded opportunities to connect with cybersecurity leaders across industries. Join us in Orlando October 12th the 14th listeners save 30% on their pass with code ISW26-SWS

SAVI in GTS. You can do that at securityweekly.com slash InfoSec World 2026. Check it out. The French CNIL find hospital, I'm sorry, open to a pre-veille de la lore, 500,000 euros. Sorry, French friends. 500,000 euros for failing to protect patients and their relatives data. More than 727,000 people had their data breach last year. Now in the investigation, the CNIL said some of the problems were in and listened to these problems because this is the important part of the story for you. External users could access the system without a VPN or multi-factor. We all know that's bad, right? I hope you know that. Two, inadequate access controls allowed the compromised account to access records for all patients. I've never seen that before.

On three, they had no real time or near real time monitoring. Four, the hospital notified affected patients but did not directly notify the 202,246 trusted third parties whose data was also stolen. They don't notify you unless they get caught. I'm going to tell you that right now. An attacker named Marac claimed responsibility for the attack and said they got in by breaching a single doctor's account and attempted to sell all the stolen data for between 2,000 and 5,000 euros. I guess it wasn't worth much. They were not able to sell it. But if you were like, we already have all this. Thank you. We breached them last two years ago. But none of this is unusual. Literally this week my landscaping company got breached because I got an email that said your contracts going forward have been revised. Please read here. If you looked at the file, it was a PDF download on Google Docs. It was fake Google Docs.

I happened to notice that. It basically, I put it on my sandbox machine when I tried to open it. It basically immediately tried to download another piece of software which was an info stealer. Then I contacted them and basically what they said was, oh, yeah, we were hacked. I was like, when were you hacked? She was like, oh, I don't know what we must have been hacked. I said, have you considered warning all the customers that got hacked? Maybe they shouldn't open this email that they're going to get from you? They were like, oh, yeah, we'll do that. They did do it. Literally five minutes after that, there was an email went out. I don't know if they had a policy that they don't say anything until somebody asks. There's no consequences in the US, like that GDPR Privacy Act that they used in this case. Businesses only respond to pain and they don't tend to fix things unless there are painful penalties that will cost them more than their repairs. I mean, literally, we were going out to them saying, here's good hygiene for security.

They're like, yeah, son, what a great idea. I'll be on my yacht, but we're not doing that. It's kind of like if parking fines are cheaper than parking, you just pay the fine instead. If you're paying $75 a day to park and you can illegally park on the sidewalk and they give you a $5 fine, which one are you going to choose? I know which one I chose, but when you get into small businesses, good luck. They have no security staff, no security structure, they're probably running Windows 95 on a gateway desktop that they bought used from that guy. Steve, was it? The one they cut, stealing cans of spray paint at the hardware store? Yeah, I think it was Steve. But I mean, don't worry. They only have your home address, your email, your birthday, your mother's maiden name, your pet's names and sizes, the gate codes to your neighborhood, the killed, drone deactivation codes at a warehouse full of chemicals. What could go wrong? So we do need to worry about all businesses, but we need to worry about these small businesses too, and we need to build pain into the model or they won't do anything about it because

it's just another breach. It's another Tuesday, you know? A fishing campaign targeting legitimate mainstream remote management and monitoring platforms or RMMs has been operating in 46 countries. 45% of the activity was focused on the United States. Any dot run said that the attackers who do not appear to yet have a name, I'm going to call them Honey Badger Noddy Bits for now or HBNB. Anyway, Honey Badger Noddy Bits ran the campaign and they were sending out tax documents, social security notices, invoices, vat notices, shipping communications, all of which led you to install some legitimate RMM software. They were using Versel, GitHub, NetLafee, compromised domains, you name it to make it look legitimate. Then they used screen connect, connect wise, and log me in. I mean, all legitimate RMM tools.

I mean, I used log me in for years I had an account. I used it on my dad's computer because my dad would call and go, what does it mean when it's flashing red and blue and a weird sound is playing in my bank site isn't open. I could just jump on log me in and go, you know, dad, you somehow opened staggering beauty somehow, not the bank. Don't go to staggering beauty. It's not a goats of it. It's off in that realm. I mean, my dad would get so confused by this stuff because he had this weird tech block and his friend Tom would send him a leak and say, check this out. I'm like, why did you click this, dad? Well, I don't know. I thought it was the bank. You know, I mean, you know how that is. But I mean, you know, then I could just close it and click his bank icon and open the bank back up. Maybe just transfer myself a little walking around money. Yeah, that kind of thing. But I mean, do you monitor this kind of thing? We caught people with variance on their office machines that they had put there so that they could connect from home, but it created a hole. And some of them weren't very secure.

So even if it's legit, can you tell a legitimate remote access from an illegitimate, log me in connection? I mean, my firewall log, it was, I actually had a rule to prevent it from logging connections between my dad's IP, which was static. I paid for a static IP for his house, so I knew where he was. And my house, which had a static IP. But if my dad had tried to put something else on his machine, you know, I maybe wouldn't have known it. I later had to add firewalling at my dad's house. So we ended up with like, you know, Palo Alto enterprise level firewalls at our houses so I could track this stuff. But does your endpoint management detect this? I mean, if a user tries to install log me in for good or bad reasons and log me in is great. I mean, don't get me wrong, but it's a very dangerous thing if you don't control it. And it seems like that RMM install should be a major admin event. You know, like that thing should light everything up like a Christmas tree. But you know, what if they get infected at home and they bring the laptop in and connect

to your network? Are you monitoring that type of connection? So now there's a laptop that is legit. You got the MAC address, but it also has log me in and installed on it. Do you limit that in your domain? Do you have RMMs in your environment at all? Do you even know? So be sure you weren't your people about this. I, you know, like I say, I got hit with one of these this week and it wasn't an RMM download, but it was, you know, it could just as easily have been and they're very, very prevalent now. Click fixes and so on. Sonic wall warned customers that two zero days could be chained together to create a remote code execution attack and advised users of the SMA 1000 to be patched with the latest hot fix. You've been, you've been checking that, right? You secured those desktops, but did you even change the default password on that three com router? I know I get it on some PID test that way. You know, they're like, oh, yeah, we took care of everything. We got all this end point security. We got anti-virus. We got anti-malware. We got a guy named Bob standing over there with a double barrel sawed off shotgun.

And you're like, but I logged into your three com router with the default password. What? You know, I mean, infrastructure devices are really becoming prime targets currently and they provide attackers with hit, you know, a nice, comfortable place to stage surveillance and internal attacks. Not to mention those portal infrastructure devices haven't had a patch or an oil change since your grandfather ran the farm. I mean, how many days of uptime are there on that 2621 router that's down in the firehouse or that catalyst switch that's in the machine shop? And it's been there since the machine shop was a radioactive waste storage facility and you get a kind of buzzy feeling when you touch the sticky surface of it. You know, you just keep telling yourself, alpha radiation won't hurt me if I wash my hands thoroughly. Alpha radiation will hurt me if I wash my hands. I mean, we've been talking about this a lot, right? I mean, I brought this up many, many times. And I mean, Iran, Russia, all the bad guys, probably us two, are out there trying to compromise these things to establish a foothold and all sorts of networks that they can use if they

need to. I mean, not you, of course. You're the good guys. You know, we've always been at war with those Sionic kind of thing. But where is your infrastructure? Do you know what you have? Do you know where it is? Do you know what version it's running? I saw that so many times where they said, we've got a full handle on this and they said, this guy's hacking us. We air gap the network and I'm like, he's still in. You're connected somewhere else and you know, they're like, well, really? That's not possible. We are a gap that I see that you air gaped here, but how many things are connected to this? We found one time in a high school. We found one time in a police department on and on and on. How do you monitor the logs of these things? Are you collecting those logs and parsing them or are they just, you know, no logs at all? And I mean, you know, some of the people I was auditing just put their hands over their ears and you know, like, la la la la la la. We don't talk about infrastructure here. I mean, you know, you don't have the luxury anymore of saying, come on. No one knows how this stuff works, Doug, just you and your nerdy friends.

Who could get into a Cisco router? Seriously, who would even know what a Cisco router is? Cisco, I thought that was something you used to fry donuts in 1965. But you know, so you know, start building out this list and figuring out what to patch, when to patch, how often you need to patch, how do you patch quickly? Even if you have to climb down into something called a filter pit, put on a respirator and lead gloves and connect your baby blue console cable to that glowing thing in the dark that's running iOS 10. I don't care what it smells like. Get in there. Microsoft said that an August update on win 11 could cause some desktops to change to black and that the user would not be able to restore their desktop background. Ooh, that's like my printer header attacks. I had this script called ENGR 1010 assignments. ENGR 1010 assignment solution. And if you stull it out of my very open Easter eggie honey pot type file folder, it changed

your print header to cheat and basted. Yeah, it was spelled like that. And it was printed in like giant letters like 80 point fonts across the green bar. Is it cheating basted? And you couldn't get rid of it unless you knew an awful lot of tricks. And it also inserted a fake VIM symbolic link in the chain so that if you typed VIM, if you were actually clever enough to try to edit your file and you typed VIM, it ate bit played the black and crazy blues on an endless eight bit loop. Yeah, until you went crazy and then it logged you out and it was still playing and you couldn't log back in. It was fun. But the article promised that there was a goth thing here. But to me black isn't really goth, right? I mean, apparently it was something to do with paint it black by the Rolling Stones. And I'm like, that's about as goth as me in a chicken suit. If it's not playing the cure or a bowhouse or something, it's not goth. Give me a break.

Rolling stones, please. You want to be goth and you can't sing all the lyrics to grimly fiendish. Give me a break. But it is another example of this dangerous game we play with patches. This pressure builds to patch faster and faster. We cut corners and testing. Now having your computer go all goth and start reciting Emily Dickinson poems and getting flaky hairdos and you know, it isn't the end of the world. Not like my dad finding out I had pierced ears and handing me navy and Lisbon papers. But it's still a problem. I mean, how can you trust something that says trust me, but then releases patches for years. 82 zero days have been patched since 2021. I mean, I'm glad they patched them, but 82 zero days have been patched since Windows 11 came out in 2021. So it's not like you could trust that updates are going to behave either. I mean, not to mention, I mean, there's patches for patches for patches and Augustus de Morgan. I mean, it's, and it's not just Microsoft. It's all of them. I mean, it's everything. I mean, no one's perfect. No software is perfect, but it's really hard to trust the patches when, you know, the

first apple has a worm. And the second apple has a worm. And by the third apple, you're pretty much checking for worms or have learned to really enjoy the flavor of a good, wormy apple. Sounds like my grandfather would have been into. It makes it taste better. But I mean, so is it goth? No. The background is black, you know, and they are going to patch the patch. So they say, I don't know, but I think I'll go listen to the dam for a while. Most feast gams, old as the hills or as grandma used to say, is steinert, is steinert. That means stone old. I really like that. I like that expression is steinert. It's a really good one. Yep. Loonon at Hills, Erningirisu that they can get them a better price on barley, but they're going to need 60 shekels before they can get the permit from King Ernama. Yeah.

Often melok, sucker. You know, meloko was a distant land from ancient Sumeria. No Sumerians here tonight. Damn, well, there goes that whole bit. All right. Anyway, large enterprises are being targeted with advanced feast gams that are very convincing. This one is called phantom deal. And basically what they do is they ID a member of the legal team at the target. And then they impersonate one of the company executives with the correct phone number and so forth on WhatsApp. And I'm like companies are using WhatsApp to communicate with their executives. Like WhatsApp should be a big tip off there. But they told this legal guy that this was all sort of hush hush. And they were about to undertake a major corporate acquisition for hundreds of billions of dollars. And you know, and there was a lot of money coming in. It was going to be a big deal. You know, not a lot of detail, but did I mention a lot of money and you would want to be the persistaining in a way of this.

And this went on for a few days with different exchanges until they basically told them. They needed them to transfer 626,735 and 45 Finigs or whatever, whatever a cent in euros. And then all this need to be transferred to a company in Hong Kong to facilitate the deal or the whole deal was going to fall through and guess who was going to be to blame. Now it didn't work because this company they were using as an example had controls in place to force this into a phone conversation. Got them off WhatsApp and said we got to talk on the phone. And of course that put a crimp in the works. It probably shouldn't have if the hacker had tried to think ahead and use AI. But companies put all kinds of info on the internet, right? I mean, we've all used this for pen test or whatever. I mean, I used to use it. It was just printed on the wall. They're like, do you know where the, I need to go to the president's office. And is that still in room 204? Because it's printed right up there behind your head. But names, titles, locations, office numbers, phone numbers, email addresses, all of it is

out there. And in fact, I was thinking the other day I was talking to somebody about a blue die operation where like in your corporate directory, you put some name that's a trigger. Like is Embard Kestermund, you know, fancy title, you know, and then you watch for any kind of email with that or contact attempts with that name or anything like that. I was kind of interesting. But really put a double key operation in place for any kind of funds transfer, even little ones. I know it's a pain, but ensure that more than one set of I sees it. You know, I mean, I used to work for a place and I had the authority to sign off on anything up to $10 million. Remember that I had to get another signature. I'm like, wow, I guess I could steal $9,999,999.99 and 99 cents. And nobody would ever know. Yeah, that's how I bought that island. But, you know, I mean, I did a case and I mean, it was a, he's dead Jim case, which is what I call those, you know, he's dead Jim. But it was a case where an employee got a call from the CEO, Mr. Sprockets, who wanted

to know why the funds transfer had not happened yet and said this was going to bring down the whole company. They needed the $1.5 million payment for supplies rerouted to a different account number. Today, right now, while we're on the phone, do it, do it, do it. One, two, three, do it. You know, and so the clerk who was scared of Mr. Sprockets, the CEO just did it. Poof. The money was transferred and it was gone. Now, Mr. Sprockets asked me if we could find the person who stole the money and get some private security to go, quote, take care of them. I referred them to a friend of mine who has ads in the back of Soldier of Fortune magazine and said, this person can handle it three days of the Condor style. Well, it right between the eyes, walking the streets of Hong Kong. But anyway, AI makes this so much easier. You know, you, how, what if you get a video call from your boss telling you to produce a report, no money involved, just a list of all users and their email addresses? I need that right now. Maybe sooner.

Get on it. Email it to be idiot. My email is MacDaddy at blisterpack.com. I mean, you don't even know your CIO's email. Really? I hear they're hiring down in Uma, cart canal dredgers. Yeah, good luck. That sounds like a really bad pre, you know, pre-civilization job canal dredgers. Maybe it was carnal dredgers. I don't know. Either one that sounds pretty bad. I don't know what a carnal dredger is, but I sure don't want to be doing it. New York City banned AI in public schools. Harvard University in Boston is now offering voluntary lockable phone pouches so students can sign up to lock up their phones for a while. I guess this is supposed to force people to be more social and connected to other students. I don't know. I lived in the phone free world. It wasn't all sunny days in roses. Let me tell you, you walk five kilometers in the rain to find a pay phone to call for a tow truck and find out the phone book hanging in the pay phone booth is actually a hive

of wasps. Yeah, that actually really happened. You know, you want to talk about a phone booth or a call box or whatever you want to call it. Yeah, it's not much fun. Not much fun. That girl you met in the computer lab steals your car and you don't know where she is and try calling the campus cops at 3 a.m. And you don't even know their number. Sure, buddy. It'll turn up. Wait for two hours to get to a pay to get an actual pay phone open at the airport to call your ride and tell them your flight was canceled and you won't need a ride. Hope you aren't already sitting out in front of Kennedy Airport when you get this. So I don't know. I mean, I'm not very social in the first place, but it's an interesting experiment, I guess. Probably somebody from the locking pouch company convinced them that students really wanted and needed this. That's how it usually happens. But they also then said they're going to force all employees to be on campus five days a week and they do not want them using zoom to meet with students. And I'm like, God help us all. You know how convenient it is for students to be able to meet with me on zoom when it's

convenient. I mean, a student called me this morning and said, I'm having problems with this. Can you talk to me? I'm not on campus right now. I'm here doing the news, but I was able to do a zoom call with them. WebEx actually. But and say, okay, let me help you with that. I mean, I hate it when people start trying to turn back the clock. I like my phone. I'm not addicted to it. I can put it down if I need to, but when my EMG breaks down in front of a biker bar, it would sure be nice to be able to call AAA instead of going in the bar. Granted, I did shoot some pool of some outlaw bikers for a while. We were waiting for the tow and they didn't hurt me at all. They were actually super nice. I mean, I made sure I lost, but I don't know. I don't want to give up being able to meet my students whenever it is and allow them to text me or what have you instead of sitting in some dank office with a copy of the New York Times for an hour each day. I literally used to do that. When we had to do it, I had the New York Times. I worked the Crossword Puzzle in Eek every day by God. I didn't say I got it was successful, but you know, I mean, you go to Harvard, roll back that clock. I mean, if students want to voluntary lock their phones and bags, well, more power to

them, but I'm keeping mine. Thanks. And I'd really rather be able to meet with students, you know, when I'm in Las Vegas at a con or something, but hey, you be you. Zero trust is clearly the future as threats get faster, quieter and harder to detect. But implementing it shouldn't disrupt the business. Threat locker enforces default deny at execution in a way that remains enterprise ready, scalable and operationally clean. Unknown software is stopped cold. Trusted apps stay contained and drift is locked down across the environment. It's zero trust that works in real enterprises and prepares you for the threats ahead. CYC'sos are adopting it at securityweekly.com slash threat locker. Get on the other end of the spectrum social butterfly. Josh Marpett. Hi, Josh. Hey, hey, Doug, actually, man, you're all over the place today. So I've never heard that before. And I only think one Augustus to Morgan reference. I'm surprised. Normally, it's at least four or five by this time of the program, but listen, I've got a

big article I want to talk about. So I'm ready to do it. CYC'sos doing more stuff to strip things away. They they had a six different programs. I think it was cyber resilience reviews, cyber resilience, essential surveys, ransomware readiness assessments, incident management reviews, external dependencies management assessments, and cyber infrastructure surveys. And what these were was somebody experienced from CISA would sit down with you at your organization and you'd go over your for that stuff like the ransomware readiness you talk about ransomware. And they would say, Hey, this doesn't look to be good. This looks, basically, you had a free assessment at a CISA. That's lovely. That's smart. That's a great program, especially for smaller organizations, small utilities, maybe the utilities that we've been talking about for weeks and water, water, what are utilities that get hacked all the time. So these reviews have now been killed partially because they don't have the staff anymore. They've reduced all of CISA by one third, more than one third, I think.

So they literally don't have the staff to do these. What they've done is replace it with what they call CPGs. All right, the CPGs are the cross sector cybersecurity performance goals, okay, which should be CCPG, whatever, it's CPGs, except it's not the same. The CPGs is an assessment on a questionnaire. That's great. That tells you where you need to focus. But then what would happen after that is you'd go through to these reviews, which is what they cut, where you have an experienced person sitting in the room with you telling you what to do about the things that are not good. How do you remediate it? Well, we can't afford that. Okay, here's five other things you can do. Having the ability to have an experienced cybersecurity professional in the room with you, sitting down and discussing your plans, no assessment, no accreditation, no harm, no foul, but just basically getting a solid experienced consultant for free for a small utility is an incredibly valuable thing to do. I don't know how to emphasize that enough.

And they just cut that entire thing. And as a matter of fact, even the questionnaires from the CSAT, which is a cybersecurity assessment tool, yeah, they've killed it. Now they're open source. So you can grab the old versions. You might be able to grab the latest version. But I might have, and be working to integrate them with my nonprofit. But the point is, is that you no longer have the ability to sit with an experienced cybersecurity consultant. That's a problem. So every utility out there, I want you to, if you can still schedule one of these assessments, I'm not sure if you can. Do it now. If you can't go get this, the old versions of the CSAT, at least go through them. Do the CPGs. The CPGs are good. Don't get me wrong. They're actually pretty solid. But they're, again, they're a forward looking. They're a triage tool. What are we doing that's wrong? Not how do we fix what's wrong? And well, unfortunately, you've lost that. So CSA, again, kills some abilities to help the people that they were designed to help

in favor of not helping them. And I just, it bothers the hell out of me. Back to you, Doug. Thank you, Josh. I completely agree. We've long neglected that. We actually tried to get something started in Rhode Island. Like, I don't know, it was probably 20 years ago now that was a response unit that the state would back. And they vetted people in the state that had tech skills and security skills and gave us all laminate cards that said, we were vetted. And we could go out when they activated the Rhode Island Emergency Management Association to try to help. And the water department was one of the ones that we did an exercise with straight up. Whose primary security defense was, these two guys have wrenches. And they will stomp you if you go down in that tunnel. And this is so weird and obscure. Nobody would ever figure it out. And I was like, is the password blank for this whole skater system that controls all the valves? And they're like, when you say password, what does that mean exactly?

You know, the login that I just went and typed root and hit enter and it let me log in. And they're like, I don't know what that means, but I'm sure it's got no problem. And you know, and don't worry. I'll fill over here's got a pipe wrench. If somebody's in this room, they get brained. I'm like, oh my god. But yeah, thanks, guys. I did this story was kind of interesting and uplifting, maybe in a sad kind of way. A US Senator has asked the national security agency to which the NSA to provide guidance to the general public on VPN best practice. I mean, you know, we all recommend VPNs. It's highly recommended by me, but I'm usually thinking about external to internal. So you're the endpoint, your company is people want to connect from home or whatever. And you know, you should be using VPN everywhere. I tell my students, use VPN on your phone, I tell my clients, use BVN on your phones and all this stuff to encrypt your traffic. I mean, I do.

I mean, I don't think my ISP, whoever they are, should be able to sniff all my traffic and decide what they're doing. There was a whole movement on that that they're going to, you know, they're going to prioritize and whatever. So everything on mine is on a VPN to an endpoint, ordering food at an airport. Well, if you're connected to free airport Wi-Fi or you're hijacking an open hotspot on that guy sitting right over there in the Met's cap to send text back to work saying you're still sick and absolutely not in Jamaica, you probably need a VPN. But the choices are myriad. I mean, you could set up your own VPN and at least you understand the risks and control the endpoint. You could set one up for your employees to use, you know, basically a relay VPN. So you control the endpoint and your employees can connect to it from wherever they happen to be and that's where they get on the internet. But if you don't, what do you recommend? Single hop commercial VPNs? Well, there's about 10,000 of those. Ooh, that one's based in China and that one's based in Belarus. Oh, what about this one based in Vietnam? Are they okay? Could we use Tor, Nim?

I mean, you know, now you're using who knows what from who knows? I mean, it is good at hiding who you are and, you know, Tor will disguise where the traffic came from, but you don't really know what you're connecting through. Who controls that encryption and on and on and on? Well, the report is due, though later than October 14th and I for one, I'm looking forward to it. I kind of like the idea for me of just building an endpoint relay in my house. You know, I just are in your enterprise house. I mean, that way employees aren't installing OLA VPN free tier, which was a notorious one. But I mean, I don't know. Double VPN was a VPN. You tell them to put a VPN on. Maybe they get double VPN, you know, the Russians control that. So I mean, you don't want to just tell them use a VPN. You deep, I think the best outcome is you build it and you provide it to them. But at least recommend something and maybe watch for the NSA report and see what it says. I'll be watching for it.

Of course, for the current state of affairs, they'll probably tell US citizens to use the special government VPN so they can see all the traffic, you know, and protect you from communists and liberals. But I don't know. Maybe it's time to dust off the old wire guard darker, if you don't know what that is, it's an open source VPN endpoint. And I used to use that. I had it set up for a while and I used to use it with my phone. And it does work and it had an iPhone component and all this. And it's your endpoint portal. I knew where it was sitting. I could go touch it. I could see that box. I knew exactly what was going on there. I could put it in my logging. I mean, I had to maintain it. And when it went down, I had to drive over there and fix it. But it is an interesting project for a client who doesn't trust commercial VPN. But you know, they did trust me with itself. I don't know. Anyway, thank you for watching. Thank you, Josh. And we will see you next time on the Security Weekly News.

More episodes

More from Security Weekly Podcast Network (Video)

View all episodes →