Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
Windows Tipps & SecurityGrafikkarte vor Überhitzung schützen: So geht’s(25.09.2026 um 08:00 Uhr)
••••••••••
Windows Tipps & SecurityGrafikkarte vor Überhitzung schützen: So geht’s(25.09.2026 um 08:00 Uhr)
••••••••••
Intelligence View
⚡ tsecurity.de Intelligence

Black Hill Information Security: REKAST - Talkin' Bout [infosec] News 2025-01-06 #infosecnews #cybersecurity #podcast #podcastclips

Video von Black Hill Information Security auf YouTube: Author: Black Hills Information Security - Bewertung: 1x - Views:4 Join us LIVE on Mondays, 4:430pm EST.…

0
↗ Quelle (youtube.com)
Reagiere als Erste:r — dein Feedback zählt!

Author: Black Hills Information Security - Bewertung: 1x - Views:4

Join us LIVE on Mondays, 4:430pm EST.

Here's a byte-sized highlight reel of our weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories.

(https://blubrry.com/bhis/)



Chat with us on Discord! -

https://discord.gg/bhis



Brought to you by Antisyphon Training

https://www.antisyphontraining.com/



▶️ This FULL EPISODE:

https://www.youtube.com/live/neGFvzff5rU

▶️ The next EPISODE:

https://youtube.com/live/HhIHyifjVAc



🔗 Register for webcasts, summits, and workshops -

https://poweredbybhis.com



/// All Stories From the Full Episode

Story # 1: BeyondTrust says hackers breached Remote Support SaaS instances

https://www.bleepingcomputer.com/news/security/beyondtrust-says-hackers-breached-remote-support-saas-instances/

Story # 2: Classified fighter jet specs leaked on War Thunder – again

https://ukdefencejournal.org.uk/classified-fighter-jet-specs-leaked-on-war-thunder-again/

Story # 3: New Proposed HIPAA Security Rule Changes

https://teachprivacy.com/new-proposed-hipaa-security-rule-changes/

Story # 4: The Breachies 2024: The Worst, Weirdest, Most Impactful Data Breaches of the Year

https://www.eff.org/deeplinks/2024/12/breachies-2024-worst-weirdest-most-impactful-data-breaches-year

Story # 5: AT&T and Verizon say networks secure after Salt Typhoon breach

https://www.bleepingcomputer.com/news/security/atandt-and-verizon-say-networks-secure-after-salt-typhoon-breach/

Story # 6: Net Neutrality Rules Struck Down by Appeals Court

https://www.nytimes.com/2025/01/02/technology/net-neutrality-rules-fcc.html?unlocked_article_code=1.mE4.-uFh.y-1QX1by865j

Story # 7: U.S. Army Soldier Arrested in AT&T, Verizon Extortions

https://krebsonsecurity.com/2024/12/u-s-army-soldier-arrested-in-att-verizon-extortions/

Story # 8: New U.S. DoJ Rule Halts Bulk Data Transfers to Adversarial Nations to Protect Privacy

https://thehackernews.com/2024/12/new-us-doj-rule-halts-bulk-data.html

Story # 9: Meta’s AI Profiles Are Indistinguishable From Terrible Spam That Took Over Facebook

https://www.404media.co/metas-ai-profiles-are-indistinguishable-from-terrible-spam-that-took-over-facebook/

Story # 9b: Meta deletes AI character profiles after backlash, racism accusations

https://mashable.com/article/meta-deletes-ai-character-profiles-after-backlash

Story # 10: Watch: Tiny robot ‘kidnaps’ 12 big Chinese bots from a Shanghai showroom, shocks world

https://interestingengineering.com/innovation/ai-robot-kidnaps-12-robots-in-shanghai

Story # 11: China Arrests 4 Who Weaponized ChatGPT for Ransomware Attacks

https://hackread.com/china-arrests-suspects-chatgpt-ransomware/

Story # 12: Man Accused of SQL Injection Hacking Gets 69-Month Prison Sentence

https://www.securityweek.com/man-accused-of-sql-injection-hacking-gets-69-month-prison-sentence/

Story # 13: Germany cuts hacker access to 30,000 devices infected with BadBox malware

https://therecord.media/germany-hacker-access-malware-cut



///Black Hills Infosec Socials

Twitter: https://twitter.com/BHinfoSecurity

Mastodon: https://infosec.exchange/@blackhillsinfosec

LinkedIn: https://www.linkedin.com/company/antisyphon-training



///Black Hills Infosec Services

Active SOC: https://www.blackhillsinfosec.com/services/active-soc/

Penetration Testing: https://www.blackhillsinfosec.com/services/



///Backdoors & Breaches - Incident Response Card Game

Backdoors & Breaches: https://www.backdoorsandbreaches.com/

Play B&B Online: https://play.backdoorsandbreaches.com/



///Educational Infosec Content

Black Hills Infosec Blogs: https://www.blackhillsinfosec.com/blog/

Wild West Hackin' Fest YouTube: https://www.youtube.com/wildwesthackinfest

Antisyphon Training YouTube: https://www.youtube.com/antisyphontraining

Active Countermeasures YouTube: https://youtube.com/activecountermeasures

Threat Hunter Community Discord: https://discord.gg/threathunter



Join us at Wild West Hackin' Fest: https://wildwesthackinfest.com/



#infosecnews #cybersecurity #podcast #podcastclips

1. Sofort-Triage & Abwehrmaßnahmen

SOC Incident Playbook: Ransomware Outbreak Containment
1 Warnungen
title: Detect Exploitation - Black Hill Information Security: REKAST - Talkin' Bout [infosec] News 2025-01-06 #infosecnews #cybersecurity #podcast  #podcastclips
id: f96db068-bac1-4f99-a60f-8ba8abb1c59f
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-27
logsource:
  category: network_connection
  product: any
detection:
  selection:
      CommandLine|contains:
        - 'exploit'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
  - attack.t1486
Syntax validiert (0 Fehler)
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-27"
        description = "YARA Signature for "
    strings:
        $str = "Black Hill Information Securit" ascii wide
    condition:
        any of them
}
Syntax validiert (0 Fehler)
index=security sourcetype IN ("cisco:asa", "pan:traffic", "zeek_conn", "suricata", "WinEventLog:Security")
("Black Hill Information Security REKAST -")
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, dest_ip, dest_host, signature
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort - count
Syntax validiert (0 Fehler)
message: "*Black Hill Information Security REKAST -*"
Syntax validiert (0 Fehler)
CommonSecurityLog
| where Message has "Black Hill Information Security REKAST -"
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SourceIP, DestinationIP, DestinationPort, Activity
| extend DetectionRule = "iShareStuff-CTI-Compiled"
| sort by EventCount desc

2. Cyber Threat Intelligence & Forensik

CTI Threat Relationship Graph5 Knoten / 4 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
🎯
MITRE ATT&CK Matrix Navigator 14 Taktiken
Identifiziert: T1486Data Encrypted for Impact (Ransomware)
Reconnaissance
-
Resource Development
-
Initial Access
Execution
Persistence
-
Privilege Escalation
Defense Evasion
Credential Access
-
Discovery
-
Lateral Movement
-
Collection
-
Command and Control
Exfiltration
-
Impact
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:

Analyse für identifizierte Bedrohung auf Basis von Live-CTI (ENISA EUVD): CVSS 0.0 · EPSS 0.0% · CISA KEV: nein. Handlungsableitung aus den verlinkten Hersteller-Quellen.

🛡️ Angriffsfläche & Exposure

Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.

⚡ Empfohlene Sofortmaßnahmen
  • 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
  • 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
  • 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten REKAST - Talkin' Bout [infosec] News 2025-01-06 #infosecnews #cybersecurity #podcast #podcastclips

Thematisch verwandte Begriffe: REKAST, Talkin, Bout, infosec · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-100739 | A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag