All episodes

Newscast

Apple Podcasts Spotify SoundCloud

News from AXS, Amazon, SCL Health, TTEC, Matillion, JumpCloud, Optiv, Ping Identity, Luman, Red Canary and a lot more!

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript4624 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 225 for the week of September 20th, right? Sure, sounds right.

2021. The September month is gone. This week, Alex, my goodness, fall starts this week. Oh my gosh. This summer just disappeared.

I feel like there was not much of a summer this year. I don't know why, but it just went really fast. Yeah, I agree. I mean, obviously, I did a lot of traveling this summer and came back and it's fall. Right.

That's been interesting. But anyway, I think it's the 22nd or 23rd that it officially becomes fall. So it's not too early to go look at leaves changing, which some of us have done. And it's homecoming season in the world, right? It is, which others of us have done.

It's always great to have tons of high school kids hanging out at your house. Good times. Good times. I guess it's good that it's at your house versus somewhere else. That's true.

You can be the one who's liable for whatever bad things happen. Speaking of liability, we have a Slack channel where we've got over 2,000 community members who are out there. Saying all kinds of fun things. And if you want to join that Slack channel and get to know the local security community, you can go out to colorado-security.com and click the Slack button. We also have a mailing list while you're on the website.

Please sign up for that. You'll get an email every week with the show notes. We'd also love it if you went to your favorite podcaster and subscribed so that you got the, uh, the podcast automatically downloaded every week. And then while you're there, rate up— rate us and let everybody know how great, uh, Colorado Equal Security is. And while you're letting us tell you how to live your life, next thing you should do is tell a friend about how good the podcast is.

And after that, sign up to give us money every month through our Patreon campaign. Yeah, we're going to tell you how to manage your finances too. And while you're at it, we'll give you a new diet regimen and send me a note. I'll help you out. Oh man, if we give people a new diet regimen, people are in trouble.

All right, let's jump in and let's talk about some news, Robb. Hey, some interesting news at Red Rocks this week. Amazon has partnered with AXS, which is a ticket provider, to install Amazon One palm readers at entertainment venues. So basically, this is— if anyone has done the CLEAR process at airports to get through security, this is Amazon's version. But rather than using— what do they use at CLEAR?

It's fingerprints, right? They use fingerprints and they use retina eye scans. This one, instead of using those, is using a palm reader. So you hover your palm over the screen, it sees who you are and we'll use that to get your ticket, to do your ticket to get into the facility whenever this goes live. I actually don't know when it goes live.

Yeah, I mean, I think it's actually pretty shortly here. And similar, if you've done CLEAR, you know, you go and you do a registration process and link it with your access account and things like that. And then when you next time or shortly thereafter, when you go to go in, you just go to the special lane that has those things and just hover your palm over and walk right in. The— this is interesting to me. You know, this is an expansion of what Amazon has done for allowing payments at the Amazon stores, right, where you can use your palm.

Actually, I think it's when you walk in the store, you can do it and then you can just take stuff and walk out of the store, which is mind-blowing. It is weird, but true. But it's an extension of what they're doing there. It's weird to me. Is this good or bad?

Is it risky? Is it not risky? You know, some folks on on the Slack channel, we're talking about the concern about if someone steals your biometrics. And I don't personally believe that, that if it's done well, that's not a real risk. Like, what your palm print looks like is not supposed to be a secret.

It's the combination of your palm print with the liveness detection that shouldn't be— shouldn't— someone shouldn't be able to counterfeit. That's, that's the whole idea of the technology. But it's still a little scary, right? Yeah. I mean, the other part with You know, Amazon hasn't had the greatest record with privacy.

So, you know, if you are providing your information to them, then there is the risk that they could do something with it that you're not thinking that they will do with it. So who knows? But it's also cool. I mean, it's pandemic friendly, right? So you're going in, you're not having to touch anything or come in contact with people as you go into the venue, except for all the people that are gonna be there with the concert with you.

But, you know, I think that as most technologies develop, I very seldom have been like, hey, that's part of the future that just happened. Like, this seems like part of the future that just happened. Yeah. Having it— having your, your body recognized relatively easily to get you authenticated or authorized for things is kind of weird. And it's interesting to see it happening.

Yeah. I mean, going back to the CLEAR example, I mean, I use CLEAR as long as it's available at whatever airport I'm at. Yeah, super easy. I love it. The lines are always shorter.

The lines are always shorter. And so if that's the case for something like this, it seems like overall a win to me. All right, jumping into our next story. We have some acquisition news. One of our big local healthcare companies, SCL Health, has agreed to merge with Utah's Intermountain Health.

This is a pretty big merger. And I'd say in some ways kind of a loss for the Colorado community as the headquarters will be moving to Utah. Yeah. It's an interesting announcement there. These are 2, sounds like fairly similar health systems, but that they don't overlap in physical footprint.

So from a merger perspective, I suppose it makes sense to make a larger organization that can theoretically be more cost-effective and provide better care. Yeah. And the difference between the systems, they're similar in some ways, but they're very different in others that You know, SCL Health is a Catholic, a faith organization, and Intermountain Health is not. So having a faith-focused healthcare organization owned by a secular one is interesting. And, you know, I wonder what kind of challenges that will have with those Catholic hospitals, which, you know, they have some— whether you like it or not, they believe in certain things and as a result don't offer some kinds of service.

And I wonder how that works in a bigger Yeah, I mean, they did mention in the article that the hospitals that are faith-based will still continue to be faith-based in the new organization. Also, the new organization will keep the Intermountain name as opposed to the SCL name. SCL is a much newer and I think less recognized brand. So Intermountain has been around for an awfully long time according to the article. So they're going to keep that.

And, you know, hopefully it'll be a good thing for the folks that work for SCL, even though the headquarters won't be here. It occurs to me that it actually might be more convenient to have both the faith-based and non in the same system. If there's something you're trying to have accomplished medically that one place won't do, maybe you can go to another one and still be in system and still have your healthcare. I don't know. Anyway, maybe it's a good thing.

Moving on to a not so good thing. In fact, an outright bad thing. Customer care giant TTEC, formerly TeleTech, has been hit by ransomware, which is no fun at all. Yeah, this is obviously a sad story based on a local company where we got friends over there helping run security. This is published on Krebs on Security.

And, you know, the joke among CISOs is always, you know, you don't want to find out about a breach through Krebs. And I don't think that this is how they found out about it, but it is a bummer to see their, you know, their incident on the front of this website. Krebs goes into detail about some internal communications that were sent out Basically, the summary though is the— there was some kind of ransomware that stopped some subset of TTEC call center folks from having access to systems, so they're not able to do call center support for, you know, some of their large enterprise customers. I don't know if this is now resolved. This is, you know, a few days old, but clearly a big thing that's being worked on.

And obviously having ransomware across one of the biggest companies in Colorado is, is a a cruddy week. And, you know, we're feeling for those guys over there who are working on this incident. Yeah, definitely. Um, good luck to those guys over there. Hopefully it gets resolved quickly and, um, is, uh, pain— as less— least painful as possible, right?

So, all right, I think I'm next. Up next, uh, we have a couple of stories this week, uh, very similar stories, um, from different tech companies. 2 different tech companies have raised over $150 million in the last week, giving them a unicorn valuation. Starting off with this first one, um, is it Mittelian? Uh, it's as good a pronunciation as I got.

I didn't know Mittelian. Uh, I think we've talked about them on the show once or twice, but I don't really know them. And I remember as I was prepping for this and trying to understand what they do, that I don't really understand what they do. And I didn't before either. Uh, they're, they're definitely a, a data enterprise data platform where you're gonna get insights from your data.

They're gonna help pull stuff out of logs and other systems and help you make business decisions based on that. Like, that's the vague understanding I have of what they do. Yeah. The, uh, the thing that stuck out to me in terms of what they do is at one point in the story, they, they call themselves a low-code ETL platform. So ETL being extract, transform, load.

So you're taking data from one place, putting it somewhere else, you know, munging it in between. And the low-code part being theoretically, you know, any schmo could do it as opposed to having to have, you know, extraordinary technical skills to make the connections between them. So is calling yourself a low-code ETL platform in the data world kind of the same as calling yourself an AI cyber platform in the security world? Is that— it could be, it could be, or, you know, um, you know, you have magical APIs or, you know, something like that. But, uh, yeah, in any case, uh, congratulations to them.

They raised, uh, what did we say, $150 million? Uh, bringing their valuation up to $1.5 billion. It's actually the second raise of this year, and so that's about a little over $300 million total that they've raised this year. Yeah, a couple interesting stats. They have about 350 employees.

They are dual headquartered in Denver and in London. About 50 of those employees are here in Denver. They're looking to grow up to 400 this year, and they're going to be using the, the new raise to, to help get better insights. But basically, they don't say a lot about what it's used for other than we're going to get even better at what we already do, right? Uh, speaking of money, JumpCloud announced that they raised $159 million, uh, on the strength of Apple enterprise adoption.

So we've talked about JumpCloud a number of times on the show. They are, you know, an enterprise— or sorry, a small-medium business, um, identity store and other things, you know, sort of a, uh, you know, cloud-based version of Active Directory or, you know, whatever you want to look at. And yeah, so they've— this is a Series F for them and they're moving right along. Yeah, I'm not sure, but I think that the, the reason that that headline said based on Apple adoption is because the, the source for our story is like an Apple 9to5. Could be.

So when I, when I click to other places to find coverage of this, it doesn't specifically talk about Apple adoption. I got it. Anyway, they are, you know, they're a 9-year-old company, so they're not brand new. But it looks to me like I'd love to actually get to sit down with their CEO or one of their leaders to understand. It looks to me like they've maybe pivoted somewhere in the last several years to be focused more on this IDaaS space, and it's worked very well for them.

Yeah. Yeah. They also mentioned that, and I think we've covered it before, you know, their new multifactor authentication piece that they have added, which obviously if you're an identity provider, you want to have that as a component to your solution. Yeah. Alex, when you read this, did you think Um, man, this seems an awful lot like— I'm having a total brain fart— the company that, that sold to SailPoint a while back that you helped advise with.

Um, oh, um, uh, yes. And now you're gonna put me on the spot. I'm not gonna remember it either. Uh, sorry, Cam. Um, uh, Overwatch ID.

Does it— but like, the, the suite of things that JumpCloud's doing looks very similar to what Overwatch— yeah, I mean, I think a little bit. Um, you know, they were for focus a little bit more on the privileged side as opposed to just the identity directory. JumpCloud does do— yeah, I mean, not that they don't do it, but it's where the focus was. Yeah, yeah, yeah, gotcha. Anyway, interesting to know.

I, I kind of wonder why is Colorado spitting up these, you know, this kind of genre of stuff. Maybe it's related to Ping being here, or maybe it's just— could be just for good luck. Well, I think, um, you know, we could talk to, uh, David Campbell about that one too, because he— I think he was one of the guys at the beginning when they decided to create the company. So yeah, that'd be awesome. All right.

I don't— I think it's me. So next we have a story that came out this last week. This is an interesting one, right? This is probably the most interesting story of the week. Yeah.

So Technology Review is where we got this source from. But it's— the headline is this US company sold iPhone hacking tools to UAE spies. And this, you know, kind of to to not bury the lead, this US company is Acuvant, right? Yeah. So if, Robb, if I came to you and said, name me a leading provider of exploit research and sales from, from 10 years ago, I guess, because whether that's when this really happened, who would you say?

Yeah, I think that I would have gone through every company I could think of before I would have said Acuvant. Yeah, me too. So definitely an interesting story. It feels like obviously we're going to throw the words allegedly and, you know, and we're referencing an article. We have no idea about any of these details.

Right. But the article is talking about this, the AccuVant at the time back in the 2000— was it 2011, 2012 timeframe? They were doing research on exploits for iPhones and And apparently, you know, according to the article, they'd sold some of those to individuals who were helping support UAE spies to— and then those things were used to help get to some dissidents. Yes. Yeah.

So again, this is very strange to me because one, I didn't know Acuvant did this stuff at all, let alone that someone would call them a leader. Or that's what they specialized in. Or that's what they specialized in. But they specialize in selling Palo Alto. Right.

Well, or back at that time, they would have specialized in selling, you know, Symantec antivirus or, you know, whatever you want to do. And, but yeah, so, so Dark Matter, which was sort of this front company that these, the 3 former intelligence folks had started, which was really just a front for the UAE government to spy on people. They had bought this from Acuvant. And so yeah, I, I would have never said that in a million years. I know that Acuvant did have a, a division, a, a piece called Acuvant Labs, which I, is I think where this came out of.

Um, and I'm sure they had really smart people there. Um, but I, I thought, you know, more like a, you know, just a sort of standard pen testing or other, you know, kind of research kind of group like that. Uh, anyway, I, I guess if there are still folks that are around, uh, in the community that were, uh, former Acuvant or, or knew about this stuff and, and have any more details, I'd love to hear about it because This is such a weird article to me. And just to be clear, even if it's true that they had a section that was creating these exploits and that they sold it, that doesn't necessarily mean that they did anything wrong here. Right.

Right. And I feel like the article is written in such a way that one might think, well, we've caught them doing something bad. Right. And, you know, who did they sell to? How did that get from the person they sold to to doing bad things?

That's, that's totally unknowable for us right now. Right. But, but it's an interesting story and it's so surprising to us because We did not think Akivon would be the one fingered here. Well, the other thing is, I think in sort of in the layman's view, you know, they're talking about them selling this to someone like they're selling a, like a military weapon, right? It's like, hey, they, they researched and found this military weapon, and then they sold it to some other company that was doing work for, for UAE.

And I think, you know, we know if you do vulnerability research, Yeah, I mean, it's probably not super glamorous and, you know, someone may have just stumbled upon something. Oh, hey, it's, you know, something we can do, an exploit for, for iOS. And, um, then, uh, somebody else might've just asked them and, hey, oh yeah, sure. We'll, we'll share this with you. It sounds like they've shared it with other people as well.

And who knows, maybe they even shared it with Apple. I, I don't know. But, um, it, it's not as, as sort of glamorous, I guess, in my mind as the, the article makes it seem where they're, you know, some cyber ninjas that are developing these, these crazy exploits to do all this bad stuff. Yeah. And anyway, interesting stuff.

And, uh, uh, like I said, it'd be interesting to know what actually happened there. All right. Next we have a blog, or excuse me, not a blog post. We have a press release coming from, uh, uh, Ping Identity announcing the hire of their new Chief Information Security Officer, Jason Keys. Wait, Ping Identity didn't have a CISO?

What's going on, Robb? Ping Identity has been CISO-less for a few months as they sought out the perfect person to replace the previous CISO there. And Jason is coming to Ping from Groupon where he was there, man, like a decade. He gave Groupon a lot of years running security. He also helped them run IT and some of their other engineering functions over there.

Awesome. Well, yeah, Jason looks like he has a great deal of experience and congratulations to him. Sounds like Ping finally has somebody good in that position. Shots fired, shots fired. Um, I guess, Robb, do you know, is he moving to Colorado?

He's not. He's, uh, he's remote. We will not have a CISO for Ping in Colorado. But I'd say that with the pandemic, Ping's had some other recent hires of leaders where they're just finding the best people wherever they can. And Jason's in Seattle, actually.

Yeah, good stuff. All right, uh, moving on. We have a blog post from Lumen's Black Lotus Labs talking about uncovering Linux executables deployed as Windows stealthy loaders. Yeah, they did a good job kind of setting the history here back in 2016. I remember this when Windows announced their, what do they call it, Windows Subsystem for Linux.

So you could run Linux on your Windows operating system. And now 5 years later, they're like, hey, we're seeing exploits where people are creating— they're using Linux vulnerabilities to impact your Windows operating system because who would look for that, right? So they're finally seeing some evidence that folks are looking to abuse this. Yeah. And according to Black Lotus Labs, people— and when I say people, I mean security tools— are not seeing this.

So they saw indications of weird things going on and found these executables and Yeah, the security tools that were there were not detecting this because it's weird and no one would expect to do it. Yeah, so really good research by Black Lotus Labs. And I think Mike Benjamin shared this with us, or I know his team's part of this. So, or his team, his team is Black Lotus Labs. Right.

So good work by that team and excited to see what follows on. Hopefully we have detections in place and preventions in place for all of the major platforms before anyone bad uses this at scale. Yeah, I will also say that for the specific ones that they saw, you know, Lumen had added the command and control infrastructure to their blacklist. So if you're protected by their network defenses, then you should be safe already anyway. Good stuff.

All right, last security news for the week. We have a blog post from Red Canary around Microsoft Identity, an introduction to Windows Active Directory. Yeah, so this was an interesting blog post talking about— I think many of us know what Active Directory is and how it works, but this is really looking into the ways that it can be attacked. And specifically MITRE ATT&CK techniques that are used against Windows Active Directory. Yeah, so they call out 4 particular MITRE techniques: steal or forge a Kerberos ticket, modified authentication processes, domain controller authentication— that's one thing— rogue domain controller, and operating system credential dumping, DC sync.

Yeah, so, uh, pretty cool stuff, and Then they go into, you know, how it is that you could detect these things happening, as well as some things that you can do to help prevent them. And then the very last little bit is a sales pitch because Red Canary is now doing some integration with Microsoft Defender for Identity and Azure Defender. So if, uh, if one wanted some Red Canary coverage on these, now they offer it. Sweet. All right, that is our news.

Robb, why don't we move over to events? Yep, we have a calendar of events on the website, so if you're If you're thinking, you know, I don't like to listen to them talk about events, I just want to read about them, we got you covered. Sweet. You can go out to the calendar of events and see what's coming over the next several months. First up on September 20th, CSA Colorado is doing their September meeting, Protecting Ephemeral Workloads.

On the 21st, OWASP Denver and Boulder is doing a joint meeting called Cover Your Assets. On the 22nd, ISC² Pikes Peak is doing a September hybrid meeting. On the 23rd, we have 2 events. ACES, the physical security group here in town, is doing their meeting called The Complexity Paradox. And SecureSet is doing a virtual event, Introduction to Machine Learning for Cybersecurity.

On the 24th, DC303, which I don't know if they've had a meeting in a while, is doing Using Emacs for Software Development. On the 28th, SecureSet is doing an Introduction to Social Engineering. And then finally, on September 30th, in conjunction with ISSA Denver, DISH is doing a job fair. So pretty good stuff if you want to work at DISH. I think there's some other companies that are involved in that as well.

Yeah, I think DISH is just like the headliner. Yeah, I'm not sure who the opening bands are, but there's others. All right, let's jump over to jobs. Speaking of jobs, we got jobs at Ping. We are— oh my goodness, I just backed up 6 months.

At Red Canary, we're looking to hire some folks. I'm looking to hire a director of corporate security. And I'm looking to hire multiple product security engineers. And we are also hiring an IT support manager. You'll have to reach out to me for your IT support manager role as it's not open to just random posting because we got too many applicants.

You'll need to open a ticket with Robb to get your IT support work done. All right. Oxtrobot is looking for a CISO. Do you know Oxtrobot? I don't.

I read that they're— looks like they're based in Boulder. Yeah, up north. But yeah, I hadn't— I was not familiar with them before this. Interesting stuff. G H X Health—that's Global Healthcare Exchange—is hiring a VP of Global Cybersecurity.

Contentful is looking for a Director of IT Security. Poly, which is formerly known as Polycom, is hiring a Senior Manager of Enterprise Security. Graybull is looking for a Privacy Risk and Compliance Manager. Alteryx is hiring a Senior Analyst of Cybersecurity Operations. And Gates Corporation is looking for a Senior Security Analyst.

That gets us to the end of the news. We don't—we did not have an interview this week because you and I are both slackers. Yes, and so folks have a little bit of free time to to turn just turn off the podcast and enjoy your drive. Yeah, just enjoy the scenery. It's a beautiful time of year.

Look for leaves changing. Good stuff. All right, we'll look forward to talking to you guys again next week. Thanks, Robb. Learn more about the Colorado security scene at Colorado Dash.

Where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes