The Host Unknown Podcast

By: Host Unknown Thom Langford Andrew Agnes Javvad Malik
  • Summary

  • Host Unknown is the unholy alliance of the old, the new and the rockstars of the infosec industry in an internet-based show that tries to care about issues in our industry. It regularly fails. With presenters that have an inflated opinion of their own worth and a production team with a pathological dislike of them (or “meat puppets” as it often refers to them), it is with a combination of luck and utter lack of good judgement that a show is ever produced and released. Host Unknown is available for sponsorship, conferences, other web shows or indeed anything that pays a little bit of money to keep the debt collectors away. You can contact them at contact@hostunknown.tv for details
    All rights reserved - Hands Off!
    Show More Show Less
activate_Holiday_promo_in_buybox_DT_T2
Episodes
  • Episode 211 - The Last of the Year Episode
    Dec 11 2024
    This week in InfoSec (11:10)With content liberated from the “today in infosec” twitter account and further afield4th December 2013: Troy Hunt launched the free-to-search site "Have I Been Pwned? (HIBP)". At launch, passwords from the Adobe, Stratfor, Gawker, Yahoo! Voices, and Sony Pictures breaches were indexed. Today? Billions of compromised records from hundreds of breaches.https://twitter.com/todayininfosec/status/1864299155583127739 5th December 1996: Julian Assange pleaded guilty to 25 of 31 hacking charges and related charges and was ordered to repay $2,100 to Australian National University. He had been arrested in 1994 for hacking crimes committed in 1991. The court case details weren't released until 2011.https://twitter.com/todayininfosec/status/1864664694243434977 Rant of the Week (17:21)Severity of the risk facing the UK is widely underestimated, NCSC annual review warnsThe number of security threats in the UK that hit the country's National Cyber Security Centre's (NCSC) maximum severity threshold has tripled compared to the previous 12 months.Published Tuesday 3rd December, GCHQ's tech offshoot's 2024 review reveals that 12 incidents topped the NCSC's severity classification system out of a total 430 cases that required support from its Incident Management (IM) team between September 2023 and August 2024. The finding represents a 16 percent increase year-over-year.The number of nationally significant incidents also rose from 62 last year to 89 in the latest data, six of which were caused by exploiting two Palo Alto and Cisco zero-days. This number includes the 12 deemed maximally severe and an undetermined number of attacks on the UK's central government. Billy Big Balls of the Week (25:50)Badass Russian techie outsmarts FSB, flees Putinland all while being tracked with spywareA Russian programmer defied the Federal Security Service (FSB) by publicizing the fact his phone was infected with spyware after being confiscated by authorities.Kirill Parubets was detained in Russia for 15 days after being accused of sending money to Ukraine, during which time the man was beaten and subjected to aggressive efforts to recruit him as an FSB informant on his contacts in Ukraine.According to his account of the story, published with his consent by Toronto University's Citizen Lab and First Department legal organization, he says he was threatened with life imprisonment if he failed to comply with the recruitment drive.In order to secure release, he agreed but before he was indoctrinated he and his wife fled the country. Always keep a second passport, if possible. Industry News (32:21)Crypto.com Launches Massive $2m Bug Bounty ProgramGerman Police Shutter Country’s Largest Dark Web MarketENISA Launches First State of EU Cybersecurity ReportWirral Hospital Recovery Continues One Week After Cyber IncidentFBI Warns GenAI is Boosting Financial FraudEuropol Dismantles Major Online Fraud Platform in Major Blow to FraudstersDeloitte Denies Breach, Claims Cyber-Attack Targeted Single ClientRomania Exposes TikTok Propaganda Campaign Supporting Pro-Russian CandidateFCC Proposes Stricter Cybersecurity Rules for US Telecoms Tweet of the Week (43:43) https://twitter.com/McGrewSecurity/status/1865050788369772974 Come on! Like and bloody well subscribe!
    Show More Show Less
    51 mins
  • Episode 210 - The Is Andy Paying Attention? Episode
    Dec 3 2024
    This week in InfoSec With content liberated from the “today in infosec” twitter account and further afield24th November 2014: The Washington Post published an article which included a photo of TSA master keys. A short time later functional keys were 3-d printed using the key patterns in the photo. Oops.https://twitter.com/todayininfosec/status/1860803840620044356 22nd November 2010: Matt Blaze published the PowerPoint slides he was contractually required to submit for his 2011 RSA Security Conference presentation. Matt hates PowerPoint. Take a moment to admire the slides he submitted.https://twitter.com/todayininfosec/status/1860027850369519669 Rant of the Week (12:47)https://www.theregister.com/2024/11/26/third_major_cyber_incident_declared/A UK hospital is declaring a "major incident," cancelling all outpatient appointments due to "cybersecurity reasons."The Wirral University Teaching Hospital NHS Trust, located in North West England, said the so-called "incident" affects the whole Trust, which oversees Wirral Women and Children's Hospital, Clatterbridge Hospital, and Arrowe Park Hospital.Although the tech problems began on Monday, officials confirmed to The Register it is still dealing with the fallout as of Tuesday morning. All outpatient appointments were canceled on Monday and the same decision was made today, according to Arrowe Park and Clatterbridge's social media posting. All patients whose appointments were canceled will be contacted to rearrange them. Billy Big Balls of the Week (20:48)Put your usernames and passwords in your will, advises Japan's governmentJapan's National Consumer Affairs Center on Wednesday suggested citizens start "digital end of life planning" and offered tips on how to do it.The Center's somewhat maudlin advice is motivated by recent incidents in which citizens struggled to cancel subscriptions their loved ones signed up for before their demise, because they didn't know their usernames or passwords. The resulting "digital legacy" can be unpleasant to resolve, the agency warns, so suggested four steps to simplify ensure our digital legacies aren't complicated:Ensuring family members can unlock your smartphone or computer in case of emergency;Maintain a list of your subscriptions, user IDs and passwords;Consider putting those details in a document intended to be made available when your life ends;Use a service that allows you to designate someone to have access to your smartphone and other accounts once your time on Earth ends.The Center suggests now is the time for it to make this suggestion because it is aware of struggles to discover and resolve ongoing expenses after death. With smartphones ubiquitous, the org fears more people will find themselves unable to resolve their loved ones' digital affairs – and powerless to stop their credit cards being charged for services the departed cannot consume.Some entrepreneurs have already identified end of life services as an opportunity. "Dead Man's Switch" apps can be set to contact whomever you choose if you do not sign in to certain accounts after a period you select as a likely indicator of your departure from this world.Meta also offers the chance to nominate a "legacy contact" who can manage your account.Such services aren't just opportunistic: grieving people have a lot on their plate, and executing wills is not always straightforward. Industry News (31:08)ICO Urges More Data Sharing to Tackle Fraud EpidemicOver a Third of Firms Struggling With Shadow AIDarknet Services Fuel Holiday Scams and E-Commerce ExploitsNHS Trust Declares Major Incident for “Cybersecurity Reasons”Nuclear Decommissioning Authority Opens Sellafield Cyber CenterNew EU Commission to Unveil Healthcare Cybersecurity Plan in First 100 DaysT-Mobile Claims Salt Typhoon Did Not Access Customer DataAlbanian Drug Smugglers Busted After Cops Decrypt CommsUK Justice System Failing Cybercrime Victims, Cyber Helpline Finds Tweet of the Week (39:43)https://bsky.app/profile/mattpotteruk.bsky.social/post/3lbyu4dy3b22f Come on! Like and bloody well subscribe!
    Show More Show Less
    47 mins
  • Episode 209 - The Javvad Is In Big Trouble Episode
    Nov 18 2024

    This week in InfoSec (08:24)

    With content liberated from the “today in infosec” twitter account and further afield

    12th November 2012: John McAfee went into hiding because his neighbour, Gregory Faull, was found dead from a gunshot. Belize police wanted him to come in for questioning, but he fled to Guatemala where he was then arrested. He was never charged, though he lost a $25 million wrongful death suit.

    https://x.com/todayininfosec/status/1856538748361515355

    12th November 2000: Bill Gates demonstrates a functional prototype of a Tablet PC. Microsoft claims “the Tablet PC will represent the next major evolution in PC design and functionality.” However, the Tablet PC initiative never really took off and it wasn't until Apple introduced the iPad in 2010 that tablet computing was widely adopted.

    Microsoft Declares Tablets Are the Future

    Rant of the Week (15:41)

    Amazon MOVEit Leaker Claims to Be Ethical Hacker

    A threat actor who posted 2.8 million lines of Amazon employee data last week has taken to the dark web to claim they are doing so to raise awareness of poor security practice.

    The individual, who goes by the online moniker “Nam3L3ss,” claimed in a series of posts to have obtained data from 25 organisations whose data was compromised via last year’s MOVEit exploit.

    Billy Big Balls of the Week (24:12)

    O2's AI granny knits tall tales to waste scam callers' time

    Watch out, scammers. O2 has created a new weapon in the fight against fraud: an AI granny that will keep you talking until you get bored and give up.

    O2, the mobile operator arm of Brit telecoms giant Virgin Media, says it has built the human-like AI to answer calls from fraudsters in real time, keeping them busy on the phone and wasting their time by pretending to be a potential vulnerable target.

    "Daisy" is claimed to be indistinguishable from a real person, fooling scammers into thinking they've found perfect prey thanks to its ability to engage in "human-like" rambling chat, the biz claims.

    For several weeks in the run-up to International Fraud Awareness Week (November 17–23), the AI has already frustrated scam callers with meandering stories about her family and talked at length about her passion for knitting, according to O2.

    Industry News (28:20)

    Amazon MOVEit Leaker Claims to Be Ethical Hacker

    Bank of England U-turns on Vulnerability Disclosure Rules

    Massive Telecom Hack Exposes US Officials to Chinese Espionage

    Microsoft Power Pages Misconfiguration Leads to Data Exposure

    Sitting Ducks DNS Attacks Put Global Domains at Risk

    O2’s AI Granny Outsmarts Scam Callers with Knitting Tales

    Ransomware Groups Use Cloud Services For Data Exfiltration

    Bitfinex Hacker Jailed for Five Years Over Billion Dollar Crypto Heist

    Palo Alto Networks Confirms New Zero-Day Being Exploited by Threat Actors

    Tweet of the Week (36:05)

    https://x.com/J4vv4D/status/1856981250306687143

    Come on! Like and bloody well subscribe!

    Show More Show Less
    44 mins

What listeners say about The Host Unknown Podcast

Average customer ratings

Reviews - Please select the tabs below to change the source of reviews.