Your Security Kit Is their Way In okładka

Your Security Kit Is their Way In

Your Security Kit Is their Way In

Słuchaj bezpłatnie, bez subskrypcji

Zobacz szczegóły

Saisonale Sparangebote | 0,99 € pro Monat für die ersten 3 Monate

Danach 6,99 €/Monat. Bedingungen gelten. Monatlich kündbar.
Your Security Kit Is the Way In The things you bought to keep attackers out are how they’re getting in. Citrix, Fortinet, forgotten WordPress backups, fake ChatGPT adverts, and the AI in your business that nobody owns. Some time in early September, somebody found a way through a door that thousands of businesses use to let their staff in from home. The owners didn’t know. Then the emergency fix arrived, patched boxes started rebooting, and that turned out to be another hole attackers were already using. This week Noel Bradford, Lucy Harper, and Graham Falkner follow one thread through every story: something was trusted, and nobody was in charge of checking that trust. Citrix NetScaler zero-days exploited for weeks before disclosure. A FortiMail flaw with fixes still pending, and Noel’s long-running grievance with Fortinet’s track record. Forgotten WordPress backups handing over email and cloud passwords. Microsoft’s Digital Defense Report showing phishing back as the front door. And fake ChatGPT adverts on Google that walk staff straight into installing a remote access tool. Then the conversation turns to the AI in your business that nobody owns. Prompted by John Wernfeldt’s LinkedIn post on AI teams and governance teams talking past each other, the hosts translate the problem for Gary Mott’s twelve-person building firm and land on three conditions that take twenty minutes to agree. Noel also announces GRCBolt, his own AI policy pack for UK small businesses, now taking waitlist sign-ups. What to do this week Email your IT provider and anyone who holds your data. Ask whether they run Citrix NetScaler or Fortinet FortiMail, and whether they’ve patched and checked for signs of compromise. For Citrix, ask whether they’ve applied the second fix released on Sunday 4 October.Find out who looks after your website. Ask them to clear old backup files out of public folders, update WordPress, and change the email password stored in your contact form plugin.Turn on passkeys for the accounts that matter most: whoever runs Microsoft 365 or Google Workspace, and whoever approves payments. Both platforms include passkeys at no extra charge. Forcing everyone to use them needs an extra licence on some Microsoft plans.Tell everyone one rule. No genuine website will ever ask you to press the Windows key and R, then paste something in.Agree three things about AI: which tools are allowed, which data never goes in, and who checks the output before a client sees it. Put a name next to each. Chapters 00:00 Cold open00:56 Welcome01:33 The doors you don’t own: Citrix NetScaler and Fortinet FortiMail10:15 The back door you forgot: WordPress backups leaking passwords13:36 Borrowed trust: Microsoft’s report and fake ChatGPT adverts19:13 The AI nobody owns23:00 Introducing GRCBolt25:03 Your Monday morning actions26:57 Close Sources Citrix NetScaler NCSC: Exploitation of vulnerabilities affecting Citrix NetScaler ADC and GatewayCitrix security bulletin for CVE-2026-88771 to CVE-2026-88778, including indicators of compromiseSophos: Citrix NetScaler vulnerabilities in active exploitationThe Hacker News: Mandiant and Google Threat Intelligence on the NetScaler campaignCyber Security News: NetScaler appliances rebooting after the zero-day patchBleepingComputer: Citrix patches NetScaler SAML zero-day exploited in attacks Fortinet FortiMail Help Net Security: Critical FortiMail zero-day exploited in the wildwatchTowr: FortiMail CVE-2026-104286 FAQRadical Notion: Fortinet CVE report card (third-party aggregator)MazeHQ: 2025 known exploited vulnerabilities by vendor WordPress backups Cyber Security News: Exposed WordPress backups leaking cloud and email credentials Microsoft Digital Defense Report 2026 Microsoft Digital Defense Report 2026 Microsoft’s figures come from its own customer and incident response data, so treat them as vendor telemetry. Fake ChatGPT adverts and ClickFix Huntress: Attackers abuse ChatGPT Custom GPTs to deliver a RAT via ClickFixIsland: How attackers use sponsored search and Custom GPTs in malware delivery Passkeys CoreView: Enabling and enforcing passkeys in Microsoft Entra IDGoogle Workspace Updates: Passkeys for Workspace users AI and governance The governance discussion was prompted by a LinkedIn post from John Wernfeldt on why AI teams and governance teams need to be in the same room.John writes about data governance, analytics, and AI in his newsletter, Data Governance Field Library. GRCBolt GRCBolt is Noel’s own product, and this episode has no sponsor. It’s an AI policy pack for UK small businesses: four documents written around your business, a one-off price under £100, no subscription, and editable Word files. It’s guidance only, and it doesn’t replace legal advice or certify you against any standard. Join the waitlist and see the partial sample pack at grcbolt.co.uk. Related episodes Mentioned in this episode: The Firewall Fallacy: Fortinet, KEVs and the Cost of ...
adbl_web_anon_alc_button_suppression_t1
Brak recenzji