SS-News-098: New CyberInsurance Requirements, Frameworks for Supply Chain Security

Episode 98 February 13, 2023 00:38:28
SS-News-098: New CyberInsurance Requirements, Frameworks for Supply Chain Security
Security Serengeti
SS-News-098: New CyberInsurance Requirements, Frameworks for Supply Chain Security

Feb 13 2023 | 00:38:28

/

Show Notes

In this episode, we discuss Ransomware affecting ships and 3rd party service organizations, new cyberinsurance requirements around MFA and service account, supply chain woes, and finally, attackers getting fancy with MS Verified Publisher status!

Article 1 - Ransomware severs 1,000 ships from on-shore servers
Supporting Articles:
The Untold Story of NotPetya, the Most Devastating Cyberattack in History
Testing Autonomous Remote Control of Ships in Singapore

Article 2 - Tackling the New Cyber Insurance Requirements: Can Your Organization Comply?

Article 3 - Have we learnt nothing from SolarWinds supply chain attacks? Not yet it appears
Supporting Articles:
Open Software Supply Chain Attack Reference (OSC&R)
OpenVEX Specification

Article 4 - Attackers abuse Microsoft’s 'verified publisher' status to steal data
Supporting Articles:
How to defend against OAuth-enabled cloud-based attacks
Protect against consent phishing
Audit apps and consented permissions

If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!

Other Episodes

Episode 86

November 15, 2022 00:45:21
Episode Cover

SS-NEWS-086: Solarwinds facing Lawsuit and Gov Action

Matthew ran a little late this weekend, so apologies for being a day late deploying the latest security news into your earhole! We talk...

Listen

Episode 8

May 09, 2021 00:52:17
Episode Cover

SS-NEWS-009: Phone Number Recycling, Malicious O365 Apps and Drone Hacking!

In this episode, we deep dive into two articles, with a bonus on hacking from drones where we wildly speculate on hacking attacks from...

Listen

Episode 107

April 17, 2023 00:49:11
Episode Cover

SS-NEWS-107: Cofense State of Email Security 2023

Cofense released their annual State of Email Security 2023 report, so we take a deep dive and see what it has to offer.  A...

Listen