{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Distilled Security Podcast","title":"Episode 3: Crowdstrike, North Korean Spies, and CISO Scapegoats","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/5adb7b9c\"></iframe>","width":"100%","height":180,"duration":4252,"description":"Episode 3 of the Distilled Security Podcast is here!\n\nJoin us this week as we jump into: \n\nCrowdStrike Incident Analysis: A deep dive into a recent mishap by CrowdStrike that led to significant financial losses and operational disruptions, including 5.4 billion in estimated losses.\nVendor Accountability: Exploring the legal and financial repercussions of security vendor failures.\nBusiness Continuity Planning: The importance of preparing for security vendor failures, including considering alternate vendors and the complexities of implementing such strategies.\nKernel-Level Security Risks: A discussion surrounding kernel-level operations in security software, focusing on the controversy between CrowdStrike and SentinelOne.\nManual Workarounds and Legacy Systems: The challenges of maintaining business operations during security incidents.\nRansomware Recovery vs. Vendor Failures: Comparing ransomware attacks' impact and recovery processes with security vendor-induced failures.\nPassword Management Vulnerabilities: The risks associated with dependency on password management systems like Thycotic/Delinea and LastPass, and the potential fallout if these systems experience downtime.\nBSides Pittsburgh Recap: the biggest BSidesPGH event yet. Hear the notes and highlights from the conference.\nNorth Korean Spy Hired By KnowBe4: Hear how a spy for N. Korea got by the defenses of KnowBe4, how they caught them, and steps they implemented to avoid this in the future.\nCISOs as Scapegoats: Are CISOs being pegged as scapegoats unfairly?\n\nLinks\nCrowdstrike Incident - https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/\nSentinelOne Response to Crowdstrike - SentinalOne on Crowdstrike Outage - https://www.crn.com/news/security/2024/sentinelone-ceo-on-crowdstrike-outage-not-just-an-honest-mistake\nBSidesPGH - https://www.bsidespgh.com/\nTRISS - https://www.threeriversinfosec.com/\nKnowBe4 // N. Korean Spy -...","thumbnail_url":"https://img.transistorcdn.com/MJdG3-EB1xgpmosNU-oEduyFhaC1R3HoELIm4f9vQDM/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9iMjk1/MTk1NTkwZTA3OThl/NzAxOGMwZjM4NTEy/MjVmOS5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}