All episodes

Newscast

Apple Podcasts Spotify SoundCloud

News from Lumen, Guild Education, Contentful, Healthgrades, Optiv, Red Canary, Webroot, Automox, Security Pursuit … and a lot more!

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript4983 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 220. This is for the week of August 9th, 2021.

Alex, how you doing this week? I'm doing pretty well. How are you, Robb? I'm doing very well. It's, uh, the— what are we in, like the worst, uh, air quality city in North America right now or something like that?

Oh man, it's driving me crazy. Like anytime I go outside, I'm sneezing and eyes are watery. It's no fun. Yeah, I, I don't know how much of this is the wildfires and how much of this is some kind of other pollution, but, um, it really is sad to be outside and you can't, you can't even see the sky. Yeah, and I mean, it's weird colors.

I almost feel like we're in Star Wars on, you know, on Tatooine with the weird sky and the sort of, uh, weird orange ball in the sky that, that you probably think is the sun. I'll make sure you send a dollar to Lucasfilms for that reference. Yeah, I will. Sorry, George. Or you're welcome, one or the other.

You're welcome. Yeah. All right, let's jump into, uh, our housekeeping for the week. Uh, we have a Slack channel with Man, we've got to be closing in on 2,000 people. I don't know what it was, but this last week we had a big rush of new folks who are looking to join the Slack channel.

We are now up to 1,975, coming up to 2,000 very quickly. Very, very close. Yeah, I guess with that, you know, sort of a shout out to the folks at SecureSet. I feel like they're doing a pretty good job of referring Colorado Equal Security to the folks that are taking their classes, and when they get near the end of their Uh, their courses, we get a rush of them that come in and want to join the community, which is great. So I love it.

I mean, this is, this is the way that the community grows. And, you know, all these jobs that we need to fill, SecureSet's doing a good job bringing us folks to, to do those and giving them the introduction to the security. So shout out to SecureSet, shout out to those folks who are joining the community. Yep. We also have a mailing list, Robb.

If you go to the website and sign up there, you will get one email a week, uh, sent from us with the show notes, so you'll get all the details when you're listening to the podcast. You can then just, you know, click on links and things like that and know exactly what, uh, what's going on. Um, and I forgot to mention, to join Slack, if you're not already on there, on our website there's a button, you know, right above where you sign up for the mailing list. You can click a button to join Slack as well. And, you know, even more, uh, one more forgetting thing, you know, our website is colorado-security.com.

So, uh, go there, sign up for Slack, sign up for the mailing list. Um, not there though, uh, you should rate us and subscribe on your, uh, favorite podcast application. That way you get the show delivered to you every week and people know how great the show is. We'd also love it if you would tell a friend about the show. You know, not— you don't have to do everything in the cybers.

You can do it in real life, you know, whenever you get out and talk to people. If you have your mailman coming up and be like, hey mailman, I got a tip for you. Um, you know, we'd love to have those folks listening to the show. So it's like Tron, is that like in the cybers? I think we're— that we are in the cybers, yes.

Yeah, uh, yeah. So, uh, yeah, let people know also we have a Patreon campaign. We love people to support the show in many ways, and if you would like to do that financially, we would love to have you be a patron of the show. We have many different levels of giving, uh, both monthly or yearly, and depending on the level that you sign up for, you will get some cool stuff from us. And that reminds me, Alex, did you know we have a— excuse me, a new patron this week?

I did. Cole Meitzner. Cole is joining. Yeah, good stuff, Cole. We thank you very much for becoming a new sponsor.

Cole joined us at the level of, uh, $10 a month. As, as a fallout from that, he gets mentioned on the show and he gets an awesome Colorado Equal Security shirt. Yeah, thanks, Cole. And, uh, in case everybody was wondering, Cole is the director of information security over at Unifocus. I love it.

All right, let's jump into the news, Alex. Let's do it. Uh, Robb, did you know that, uh, Lumen, formerly CenturyLink, uh, is trying to sell off their, their, uh, consumer side, uh, for $7.5 billion to a private equity fund? Yeah, they got Apollo Global Management, which is the, uh, the fund, uh, it's gonna spend that $7.5 billion. It looks like About $1.2 billion of that is to service some debt, but that's a lot of cheddar to go to Lumen with the rest of that.

I was interested to hear that this $7.5 billion acquisition is just for 20 of the 36 states that Lumen services. So they're going to maintain 16 states and continue doing that and let the rest of them go. I looked at the map and Colorado is one that's going to stay with Lumen. So they're not selling us off to Apollo. Yeah, I, I feel like the, uh, the, the states that they are keeping are some of the sort of the legacy CenturyLink, you know, formerly US West, uh, Quest sort of states.

And many of the other ones that they are selling off are things that they have acquired over the years. So I think that, you know, they've got a good footprint of stuff that had been together before, and they're going to try and keep that. All right, moving on to our next story. Uh, a Denver tech unicorn is providing Target with education an education program for frontline workers. We've talked about Guild Education on the show numerous times over the last few years.

This is a pretty big deal. It is. And I mean, I just love what Guild does in general. You know, their mission is to help folks that are in, you know, hourly, lower-paying, entry-level kind of jobs get additional education so that they can further their career. In this partnership with Target, now opens that up to 340,000 of their frontline workers to help them get a debt-free education through Guild.

Yeah. So this is for all part-time and full-time Target employees. Target is investing over $200 million into this program over the next 4 years. And this program is going to allow those employees to attend courses at 40 different colleges with— and they have a set of programs or degrees that you can get for free, which includes business administration, IT, and computer science. But there's some other ones.

And if you don't pick one of those programs, they still have a benefit. It's just, uh, not quite, not quite as generous, uh, but still an incredibly generous program, uh, that Target's offering. And it's awesome to see Guild facilitating that. Yeah, I think it said that they were going to be giving folks up to $10,000 a year towards this. So that, that is pretty cool.

That's a great benefit. Uh, so one other interesting factoid from this article, Guild works with Fortune 500 companies, and they, they, uh, basically this is all they do is really helping those companies get educational opportunities for those frontline workers. And, um, and, and really having a lot of success in growing. And, you know, as a tech unicorn, I, I imagine that this— the future looks really bright. Yeah.

One other thing that I picked up that I thought was interesting is They noted that, uh, when Guild had their last round of funding, which I believe was around the beginning of the year, they were at about 450 employees. And as of this announcement, they are at about 1,000. So they've, they've doubled, more than doubled, um, in, you know, half, a little over half a year. Pretty crazy. That's awesome.

All right, moving us forward here, we have, uh, news from a building downtown. So, you know, Unfortunately, Molson Coors left us. Their headquarters left us here in Colorado. But the— I love the intro here for this article: Out with the booze and in with the tech firm. The floors in the 1801 California Street building are being filled by Contentful.

Yeah, so this is— looks like 3 of the 4 floors that Molson Coors had. And, you know, these are pretty prime floors. I think that the The building is 48 stories or something like that, and these are in the 40s. So it's pretty far up there. So yeah, Contentful, which is a leading content platform for digital-first businesses.

I think from that description, you probably don't have any idea what they do. But they're building out a headquarter— not a headquarters, an office here. I believe that they were originally based in Germany, but then also have another office in the United States. Um, had announced recently that they were going to be bringing an office here to Denver, and looks like this is where it's going to be. Yeah, we actually talked about this last year, almost exactly a year ago last summer.

Um, so it's good to see, you know, these folks who said they were going to be hiring 50 to 100 people in, in this year, well, they've taken up 3 floors in a big building. So I'm guessing that's a lot more than 100 people who they're going to be hiring. Yeah, definitely. Uh, one of the other things I noted in the story is that, uh, in that same 1801 California building, uh, Healthgrades has their office there. And Robb, speaking of Healthgrades, uh, did you know that they have just rebranded and they have sold off the marketplace side of their business?

Folks, they don't call Alex the best segue man in the business for nothing. This is, this is smooth. Well done. Very, very, very. Yeah, so I, I did see that.

Um, so Healthgrades, who I've known them as a place that kind of has a marketplace for helping you find, um, healthcare providers with ratings associated with them so, you know, people can you know, kind of like your Uber driver, give them a rating. People could do that with— for healthcare providers. Well, that's actually not going to be what they do in the future. They've sold off that healthgrades.com consumer-facing part of the business to a company called— was it RV— RV Health? RV Health, yeah.

Um, and, and really, they're going to be refocusing what Healthgrades, or what that, what that remaining company is called. So it's going to be called Mercury Healthcare, and it's going to be focused on software and data for its for its healthcare customers who, who use them to get business intelligence. Yeah, and, uh, to be honest with you, I didn't know this was something that they did. Um, granted, I didn't know a whole lot about, uh, Healthgrades other than the marketplace side, so, um, I, I guess it— and since this isn't, uh, consumer-facing, not a surprise to me. Um, but, uh, but yeah, it seems like this is a pretty cool market for them, and I imagine that it, it's, uh more lucrative as they are, you know, going to be doubling down and focusing on this.

They're going to be taking that— the money from the sale of the online consumer marketplace and using it to further their products for the business analytics piece. Well, good stuff. I have one other little note. Our friend Jay Wilson, the CISO of Healthgrades, is now the CISO of Mercury Healthcare. He is— he's still going to be around, and he— but he's moving over to that business analytics side and really kind of serving a different customer base.

Yeah, it's funny, I saw his LinkedIn change this week And I was just about to reach out to him and congratulate him on the new job. And then, uh, then I realized that he doesn't actually have a new job. Uh, it's just that the company changed names. New title. New title.

You know, Alex, if you, if you stand on the— what is it, the 45th floor of the 1801 building— and you gaze off to the, to the southwest, you know what you might see in the skyline? Um, you know, I bet that direction you might see the Optiv building. You might see the Optiv building. And, you know, speaking of the Optiv building, as smoothly as I just did, The Optiv has come out with a new release. They are now launching a managed extended detection and response service.

Alex, I'm gonna put you on the spot here. I pasted a little clip from the article into the card here for this. I would love to hear you read this sentence for me and just see how well you do with that. All right, I will try, Robb. The Optiv MXDR is the only managed cloud-based next-gen advanced threat detection and response service that ingests data across various layers of technologies correlate, normalize, enrich, and enable automated responses to malicious activity in real time.

I think that says it all. I mean, everything you want to know about this release all in one sentence. Exactly. It's a very long sentence. I almost ran out of breath.

I, I do— I mean, I love to make fun of marketing language, and there's a lot of buzzwords in there, but I mean, Optiv, who obviously has a lot of great partnerships, um, both with the vendor side where— so they can put together a service, and with the enterprise side so they customers who want to buy it, it makes a lot of sense for them to look to, to capitalize on that and put together a service that will hopefully give people great visibility to what's happening inside their environment. Yeah, it looks like they're basing this platform on, uh, DEVO, which I am not, uh, super familiar with but have heard of. And I believe that they have, you know, sort of an MDR platform that they're gonna be leveraging. And, um, you know, Optiv is going to be doing the managed part on top of that. Well, if Devo is— if their, if their managed platform is anywhere as good as their hit from the '80s, Whip It, um, I have nothing but great expectations for this new offering.

I sure hope that in, uh, in Devo SOC everyone wears the Devo hats. All right, uh, speaking of local MDR providers, we have, uh, we have a blog post this week from Red Canary, um, and, and this one also has, you know, they love the clever names for their, for their blog posts. This one is called Windridex and Cobalt Strike: Give You Grief. And this is really diving into Grief, which is a ransomware/extortion threat actor that emerged earlier this year, and they're doing a good job diving into the details of this threat actor. Yeah, and, uh, not surprisingly, as part of the way that Grief appears to work, they are using Dridex and Cobalt Strike as part of the, uh, the infection mechanisms, and there's commonality there.

So they go into some great detail in the, uh, the blog post talking about things that you can use to potentially detect this Um, in only the way that Red Canary does. Yeah, if you want to spend— if you want to understand like high level what is Grief and how does this work, you can read the first like 10th of the blog post, read like 4 paragraphs, and like, I got it. And then you scroll down and you're like, holy smokes, they get into really good technical detail around, all right, here's what the exploitation chain has looked like, and here's the detectors you can put in place to, to stop it or to, uh, or alert yourself when these things start to be— start to happen, um, which is amazing for those SOC analysts, right? So I think this is a blog post that has value for for those, you know, those who are hands-on keyboard and also those who are having to, to just stay on top of the trends. Yeah, I mean, and if you're not a Red Canary customer, which, you know, maybe you should be because they could detect this for you, but, you know, they've got a lot of IOCs and other things in the, the blog post that you can use for detection on your own.

So pretty cool there. Um, you know, if you wanted to prevent this infection though, uh, according to Passmark, Webroot might be one of the ways to do that because they were a top performer in security products In the PassMark software testing. Yeah, you know, I don't know PassMark, but you know, this is one of the third-party companies that does testing of different security solutions. It looks like mostly the focus of this testing was on like performance-type testing. So they highlighted a few pullouts from it like installation size, boot time, CPU usage during idle and scan, memory usage.

Are the things that they highlighted as being part of this assessment, which, you know, I'd love to see them actually also talk about, you know, did they catch things? Uh, but obviously, you know, your antivirus tool, you want to make sure it's not, it's not killing your systems. And I think we get some of that, that information here. Yeah, so I guess I'll amend my previous statement, Robb. Um, if you want to use up the least amount of resources on your computer while your legacy antivirus doesn't detect grief, uh, maybe Webroot is the way to go.

Whoa, holy smokes. Shots fired, Alex. I love it. We're fiery here today. Um, I, I don't— I actually have no idea if they're— what the other categories here are because there's a paywall, or not a paywall but a registration wall, in order to get the full reports.

Um, but good, good for Webroot to be the one who's, uh, who, who won against Bitdefender, McAfee, and ESET. Yes, congratulations to Webroot. And, uh, yeah, no offense, I'm not really taking shots. Yeah, take a shot here and there. All right, let's talk about the next, next blog.

Let's move on. Automox, who do automated patch remediation, vulnerability management type stuff, you know, they've been on fire recently with, um, with growth and with raising funds. They put out a blog this week around IT operations, the expectations versus reality in the patch management market. Uh, I'm gonna, I'm gonna give you a quick summary here, Robb. Um, legacy patch management tools are a patchwork of horribleness, and, uh, Automox is uh, you know, a cloud-first, um, amazing solution, and you should use them instead.

I think it's— I think it's reasonable to say that it's really hard to, to move from an on-prem, in-the-data-center focus on patch management to one where employees are distributed. And that is what Automox is playing on here. It's a hard— it's a hard problem to solve, and, uh, it's nice to know that there's someone local who's, who's helping solve it. Yeah, I mean, I think, uh, not only distributed users but, uh, systems in the cloud and other things like that that maybe your legacy on-prem patch management solution also does not work well with. Yep.

So, all right, uh, good stuff, Automox. Moving on to our last news item of the week, uh, we have a blog from Security Pursuit, which we don't get too many from them, but this one is, is pretty good. This is talking about the total cost of ransomware, and they kind of break that down into 7 categories, which I think is cool. Uh, some of these are ones that you may not think of in terms of ransomware. Yeah, so obviously we all think of paying the ransom as the first one, and maybe you also think of number 2, which is double extortion costs.

So paying the ransom and giving my key back, the double extortion cost is, by the way, if you don't pay me, I'm going to leak the information. So it's not just unavailable, it's also that as well. Yeah, of course there's, uh, you know, system downtime. So, uh, you know, your systems, uh, are going to be offline if they're infected with ransomware, and so that's going to cost you some, uh, some cashola there. You're probably going to have some legal costs for outside counsel giving you advice on what to do, as well as, uh, hopefully not, but potentially, you know, a class action lawsuit against you because, uh, your systems were infected with ransomware and cost people, uh, issues.

Yeah, and anytime you bring in lawyers, you got to think that they might say, let's bring in an incident response team from outside to, to give us that third-party objectivity. So incident response team costs. And, you know, I think we all are well aware of reputational damages. It's hard to put a dollar amount on it, but I think we're all thinking about reputation impact. And then finally, And finally, the government may look your way and give you a fine for noncompliance if you're GDPR or CCPA or the new California one soon.

If you're not in compliance with one of those, you may see some fines coming from one of those guys. Yeah. And of course, depending on the industry vertical that you're in, if you're in financial services or healthcare or other things like that, there are some other lovely government agencies that will be knocking on your door and asking you for some cashola too. All right, good stuff. Uh, we don't have— this is not an official piece of news, but it is worth talking about.

The BSides Denver, uh, call for papers or call for presentations is currently open. You know, this is, uh, one of the great local conferences we have. Um, it is— the CFP is only open until August 15th, so, you know, you don't have a ton of time. You probably should stop listening right now and start, start writing your CFP and get that in. Uh, we'd love to see you guys there.

It's going to be all virtual this year, which, you know, I would say a month or so ago looked like you know, maybe they missed the chance to get together in person. And, uh, with the rise of, uh, the new variants, you know, maybe they look like they know the future. Yeah, um, I hope that they don't, but, uh, good on them for playing it safe. All right, uh, that is it for the news. Let's move over to the Slack Message of the Week.

Thanks to Andre Gaeta who supports this initiative for us. This is trying to get people to join our Slack workspace because it is awesome, lots of good stuff going on there, and to highlight people that are in there who are giving good contributions. So each week we pick one winner for Slack Message of the Week and they get to pick pick one item from the Colorado Equals Security store. Robb, who's our winner this week? This week, Gene McGowan, who's also, FYI, the local ISSA Denver president.

He posted one of my favorite memes of the week, which is a picture of a shotgun shell with a little flower on it, which is rather than being filled with buckshot or any other kind of actual shot that's meant to hurt people, it's filled with flower seeds. And they say it's a much faster way for you to plant flowers in your backyard, which caused an amazing conversation. With someone talking about how they they knew someone who lived in a neighborhood where someone would go fire a gun in their backyard once a month just to keep the property values down.

Look at this! You could you could keep that. You could keep shooting once a month and also plant flowers at the same time. Seems like a win-win. A lot more fun than normal gardening too.

Good stuff. Anyway, Gene, thank you for your contribution and congratulations on getting some sweet sweet swag. All right, let's go over to events. Uh, of course we have an event calendar on the website where we have all of the events that we know about for as long as we know about them. In the podcast, however, we highlight the next 2 weeks of events, so we'll talk about those.

But if you want to see the rest of them, go over to the website colorado-security.com and look at the event calendar. All right, uh, so coming up on the 11th, we have 2 events. We have ISSA Denver doing their August chapter meeting, and we We also have SecureSet getting back into business doing a Hacking the Cybersecurity Job Market in-person event. On the 13th, the Application Security Meetup group is doing Measuring Your Software Security Program. On the 17th, they got 2 more events.

ISSA Colorado Springs is doing their August meeting and SecureSet's doing a virtual meeting. This time it's around breaking into cybersecurity with an alumni speaker. Awesome. On the 20th, ACES Denver is doing a Grizzly Rose networking party. I know, I love it.

If you're looking for any excuse to get to the Grizzly Rose, it seems like our local physical security group ACES may be giving you the ticket. Good stuff. And finally, last event for the next 2 weeks, ISSA Colorado Springs has their mini seminar on the 21st. Uh, this is a chance to get some CPEs. It's usually like 9 AM to 12 PM.

Good content and good, good networking as well. All right, uh, let's jump over to jobs. Robb, any Red Canary jobs this week? Yeah, I got a few jobs to highlight. I actually opened up a new one this week, a corp— a Director of Corporate Security.

This will be the person who's responsible for building out the, the program for securing the internal Red Canary organization. We also still have the Director of Product Security, which is, you know, obviously for that customer product environment. And finally, a Program Manager focused on my trust program, uh, which is what does security, privacy, compliance, all that good stuff rolling up to, to that one program manager. Great. Praetorian is looking for a security program and strategy engineer.

Lumen is hiring a product, uh, software development security engineer, and I think they actually posted a very long list of open positions in the Slack channel and the jobs, uh, and the jobs channel this week. So if you're looking to work at Lumen, there's a lot of opportunities. For sure. But none of them are entry-level, right? They're all, they're all experienced.

Kaiser Permanente is looking for a risk assessment services principal consultant. Hey, I didn't know Devo had a presence here, but Devo, who we were just talking about earlier, is hiring a solution engineer focused on channel. How about that? Elevations Credit Union is looking for a cloud security architect. UCAR, that's U-C-A-R, is looking to hire a manager Uh, of office and— excuse me, a manager in the Office of Information Security.

And for those that don't know, uh, UCAR is the University Corporation for Atmospheric Research in Boulder. And finally, Vail Resorts is looking for a senior information security analyst. And actually, it looked like Vail Resorts was hiring a number of positions as well. Good stuff. Well, Alex, that is it for the end of news.

And believe it or not, for the first time since last December, we don't have a feature interview. I think, you know, it's end of summer, everybody's been on vacation taking it easy, and, uh, no time for interviews. Um, well, so you guys get some time back. Feel free to use this to meditate or drink or whatever it is you do with time you've been given back that you didn't expect. I think you should, uh, drink while meditating.

I think that's, that's a business idea. We shouldn't have talked about it in front of all these people. Ah, damn it, Robb. All right, we'll talk to you guys again next week. Thanks, Robb.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes