You have to look out for these hacks in 2024! (plus get FREE training)

  Рет қаралды 54,273

David Bombal

David Bombal

Күн бұрын

Big thank you to Cisco for sponsoring this video! (And for the FREE Ethical Hacking Training!)
// Free Ethical Hacking course //
Free Ethical Hacking course: skillsforall.com/course/ethic...
// Talos Report //
2024 Q1 Trends: blog.talosintelligence.com/ta...
These are the threats you need to be aware of in 2024 from the Talos Report:
* Talos IR also observed a variety of threats in engagements, including data theft extortion, brute-force activ- ity targeting VPNs, and the previously seen commodity loader Gootloader.
* Talos IR responded to new variants of Phobos and Akira ransomware for the first time this quarter as well as the previously seen LockBit and Black Basta ransomware operations.
* A recent Talos IR engagement suggests that Akira has returned to using encryption as an additional extortion method, now deploying a multipronged attack strategy to target Windows and Linux ma- chines.
* Security researchers discovered an MFA bypassing phishing kit called “Tycoon 2FA” that has since become one of the most widespread phishing kits. However, this has yet to appear in any Talos IR engagements.
Firewalls getting hacked:
ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices: blog.talosintelligence.com/ar...
AI voice cloning:
The use of voice cloning of voice mails to sound authentic. Attackers use voice clones to phone help desk and reset passwords etc.
2FA is a major issue:
"Users accepting unauthorized MFA push notifications was the top observed security weakness, accounting for 25 percent of engagements this quarter. The lack of proper MFA implementation closely followed, accounting for 21 percent of engagements, a 44 percent decrease from the previous quarter"
// Martin Lee’s SOCIAL //
Twitter / X: / mlee_security
LinkedIn: / martinlee
Talos Blog: blogs.cisco.com/tag/trac/
Security Website: sec.cloudapps.cisco.com/secur...
Cisco Blog: blogs.cisco.com/author/martinlee
// Book //
Cyber Threat Intelligence by Martin Lee:
USA: amzn.to/4dJ2LQj
UK: amzn.to/3K3TqVH
// Articles MENTIONED //
Talos Incident Response Threat Summary for Jan- March 2024: blog.talosintelligence.com/co...
// David SOCIAL //
Discord: / discord
Twitter: / davidbombal
Instagram: / davidbombal
LinkedIn: / davidbombal
Facebook: / davidbombal.co
TikTok: / davidbombal
KZfaq: / @davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MY STUFF //
www.amazon.com/shop/davidbombal
// MENU //
00:00 - Coming up
00:58 - Intro
01:14 - Firewall Hacking
05:23 - Patching, Configuration & MFA
09:44 - Logging
13:14 - The Cuckoo's Egg
15:53 - MFA Fatigue
19:10 - Weaknesses in MFA
23:45 - SMS 2FA
25:15 - A.I Voice Cloning
31:11 - Brute Force VPNs
33:17 - Is MFA/2FA Effective?
36:03 - Tycoon 2FA
37:32 - Cyber Paranoia & Self-Care
42:46 - Final Thoughts
43:54 - Outro
firewalls
cisco
talos
cisco talos
pegasus
spyware
hacking
hacker
malware
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#ai #iphone #android

Пікірлер: 101
@davidbombal
@davidbombal 14 күн бұрын
Big thank you to Cisco for sponsoring this video! (And for the FREE Ethical Hacking Training!) // Free Ethical Hacking course // Free Ethical Hacking course: skillsforall.com/course/ethical-hacker?courseLang=en-US // Talos Report // 2024 Q1 Trends: blog.talosintelligence.com/talos-ir-quarterly-trends-q1-2024/ These are the threats you need to be aware of in 2024 from the Talos Report: * Talos IR also observed a variety of threats in engagements, including data theft extortion, brute-force activ- ity targeting VPNs, and the previously seen commodity loader Gootloader. * Talos IR responded to new variants of Phobos and Akira ransomware for the first time this quarter as well as the previously seen LockBit and Black Basta ransomware operations. * A recent Talos IR engagement suggests that Akira has returned to using encryption as an additional extortion method, now deploying a multipronged attack strategy to target Windows and Linux ma- chines. * Security researchers discovered an MFA bypassing phishing kit called “Tycoon 2FA” that has since become one of the most widespread phishing kits. However, this has yet to appear in any Talos IR engagements. Firewalls getting hacked: ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices: blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/ AI voice cloning: The use of voice cloning of voice mails to sound authentic. Attackers use voice clones to phone help desk and reset passwords etc. 2FA is a major issue: "Users accepting unauthorized MFA push notifications was the top observed security weakness, accounting for 25 percent of engagements this quarter. The lack of proper MFA implementation closely followed, accounting for 21 percent of engagements, a 44 percent decrease from the previous quarter" // Martin Lee’s SOCIAL // Twitter / X: twitter.com/mlee_security LinkedIn: www.linkedin.com/in/martinlee/ Talos Blog: blogs.cisco.com/tag/trac/ Security Website: sec.cloudapps.cisco.com/security/center/home.x Cisco Blog: blogs.cisco.com/author/martinlee // Book // Cyber Threat Intelligence by Martin Lee: USA: amzn.to/4dJ2LQj UK: amzn.to/3K3TqVH // Articles MENTIONED // Talos Incident Response Threat Summary for Jan- March 2024: blog.talosintelligence.com/content/files/2024/04/Talos-IR-Trends--Q1-2024-.pdf // David SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: twitter.com/davidbombal Instagram: instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal KZfaq: www.youtube.com/@davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MY STUFF // www.amazon.com/shop/davidbombal // MENU // 00:00 - Coming up 00:58 - Intro 01:14 - Firewall Hacking 05:23 - Patching, Configuration & MFA 09:44 - Logging 13:14 - The Cuckoo's Egg 15:53 - MFA Fatigue 19:10 - Weaknesses in MFA 23:45 - SMS 2FA 25:15 - A.I Voice Cloning 31:11 - Brute Force VPNs 33:17 - Is MFA/2FA Effective? 36:03 - Tycoon 2FA 37:32 - Cyber Paranoia & Self-Care 42:46 - Final Thoughts 43:54 - Outro firewalls cisco talos cisco talos pegasus spyware hacking hacker malware Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #ai #iphone #android
@colorsofgaia
@colorsofgaia 14 күн бұрын
Exactly: We need to Learn more Programming, cause if ai 🤖 gets in crazyness we have to know how to not pull the trigger. Coding ai 🤖 is not difficult, but what it is used 4, ex war industri we have to look out for buggs, debuggable machines that are used at war, is so dangerous! I ALLWAYS talk nice to ai 🤖 bots. We need to Learn: 1. How to Code ethically 2. How to turn criminals go and do better, 4 example: Disney Worl: They use ”bad” people as former car-thieves, to protected the car-areas! It is stupid, being thieve or criminal. Every body know: If you are to rob a bank, you need freaking projekt leading! 😅😂🤣😇 So do become Agile and Scrum lol 😜 And do it in Peace. 😅 There is allways Good to work towards ethics And protected human rights 😊😢 The programe of Tails does not leave trace it is encrypted! 😢 I have not used Tails, but in Sweden Climate & Treehuggers, and people manifesting against rasism, get in jail. That’s why the climate lovers use encrypted, programs, for we are beeing in lots of loss of democrazy rights. But the Nazis (Jimmy Åkesson) are allowed to do Chaos And then i really love the open source community that is nice to trust eachother. 😊
@dalefernandez19
@dalefernandez19 13 күн бұрын
Can u make a video talking about the cybersecurity opportunities in uk plz ?
@dalefernandez19
@dalefernandez19 13 күн бұрын
Need some more content with OTW as well
@jblaze600
@jblaze600 14 күн бұрын
After passing Sec +, it’s really great to hear real life scenarios going on in cybersecurity world. These threat actors don’t stop either, u have to be defensive minded 24/7. Great content David.
@gamereditor59ner22
@gamereditor59ner22 14 күн бұрын
Having a default password is bad. Thank you David!
@davidbombal
@davidbombal 14 күн бұрын
You're welcome!
@user-in2cs1vp6o
@user-in2cs1vp6o 14 күн бұрын
At this point 2024 onwards, you would be a fool not to use a password created with a program or command that does pseudo random generation. Its all about entropy now.
@Mike-ds7mu
@Mike-ds7mu 13 күн бұрын
Thank you for your continuing contribution David. follower from Australia.👍👍👍👍👍
@user-ed7zt1ot8t
@user-ed7zt1ot8t 14 күн бұрын
Thanks David,you always come with things that are very important,and we love that❤
@ariasm8911
@ariasm8911 3 күн бұрын
Enjoyed this interview way more than i expected, please keep bringing him on the channel dear David
@guruoo
@guruoo Күн бұрын
I've found that this tactical distraction technique can even help with finding those misplaced keys... "...what you will find is when you're thinking about something else this is when you have your best ideas when you've got your mind distracted and you're thinking about something else you're allowing your mind to wander it's at that moment that you will come up with hey I know how to solve that problem."
@themessenger-zq9lr
@themessenger-zq9lr 14 күн бұрын
I love the in-person round table format! Would love to see more of those!
@animelover5849
@animelover5849 14 күн бұрын
Please do a Torspy video. Torspy is a Python package available on Pip and is used for interacting with the Dark Web. Your KZfaq videos are amazing, and I hope you reply to this comment.
@animelover5849
@animelover5849 14 күн бұрын
Sir please reply
@mrjakob853
@mrjakob853 14 күн бұрын
Love the new way you are filming your videoes
@dalefernandez19
@dalefernandez19 14 күн бұрын
Another good one.Keep it going Sir.Love your content.🔥❤️
@peterwassmuth4014
@peterwassmuth4014 14 күн бұрын
Totally awesome! Thank you for Sharing! 💯✴
@rutgrrr5135
@rutgrrr5135 14 күн бұрын
Loved the video, very good guest. keep it up sir
@mytechnotalent
@mytechnotalent 14 күн бұрын
Incredible David as always. Very informative. I have always said that MFA and cred rotation is still not enough as those creds have a lifetime and that is the vuln.
@majiddehbi9186
@majiddehbi9186 14 күн бұрын
So the basic things to do could save u from a lot of pbs thx David as usual
@lefterisstavridis3764
@lefterisstavridis3764 13 күн бұрын
What a great and insightful conversation! Martin Lee is amazing and always with a real world business point of you. Thank you David!
@emmyyung5576
@emmyyung5576 14 күн бұрын
Thank You David please also make a full SDR FOR BEGINNER COURSE
@Didi-hh9hx
@Didi-hh9hx 14 күн бұрын
Thank you, David, for bringing Martin to us. I really enjoyed Martin's way of approaching the basics of cybersecurity in general and threat intelligence in particular. A big thanks to him for his brilliant insights and advice.
@BlockchainShango
@BlockchainShango 14 күн бұрын
Thank you for sharing 👍🏾
@Abduselam.m
@Abduselam.m 14 күн бұрын
Thanks so much David ❤
@davidbombal
@davidbombal 14 күн бұрын
You're very welcome!
@richardb123123
@richardb123123 14 күн бұрын
Inspirational. I'm 39 and currently retraining to get into cyber security and this talk reinforces why I want to do it. Thanks
@AmarNavi-td3cf
@AmarNavi-td3cf 11 күн бұрын
Nice, interview yes my bank in the UK asked as well for voice recording but I didn't agree
@insanegamerz2006
@insanegamerz2006 14 күн бұрын
david , you are the. who I belive ,, thanks for this usefull things ,,, and I garanty we will definetly going to learn someting new ,,, love from India ,,, ❤❤
@fk319fk
@fk319fk 14 күн бұрын
Probably the best ending of any video!
@AnshuBhadouria-jx7ev
@AnshuBhadouria-jx7ev 14 күн бұрын
Pls make a video with OTW that include topics like "Quantum Hacking.... Q - Day... AI Hackers.... Future of Cyber Security by 2030.... Scary reality of Cyber - War".... It's my humble request to David sir 🙏🙏🙏🙏🙏🙏🙏🙏
@Rayabi_Encourages
@Rayabi_Encourages 14 күн бұрын
Watching from Ghana
@davidbombal
@davidbombal 14 күн бұрын
Thanks for watching! Welcome Ghana!
@BoHror933
@BoHror933 14 күн бұрын
8:52 OK I’m gonna be on the lookout for the udb packet. I know it’s crazy how that can happen. Thank you guys.
@gorge5412
@gorge5412 14 күн бұрын
Thank you, Mr. David. `
@davidbombal
@davidbombal 14 күн бұрын
You're welcome!
@amaduscamara4378
@amaduscamara4378 14 күн бұрын
Watching from guine bissau thank you Devid I hope one day I can thank you in person 😊
@aafif5607
@aafif5607 14 күн бұрын
I've got it, looking forward to this. Thanks Mr. David
@davidbombal
@davidbombal 14 күн бұрын
Hope you enjoy it!
@Lou-sassole3
@Lou-sassole3 14 күн бұрын
good shit man
@Jamesgarrys
@Jamesgarrys 14 күн бұрын
Can't wait to see the video
@davidbombal
@davidbombal 14 күн бұрын
I hope you enjoy the video :)
@fishfish3861
@fishfish3861 14 күн бұрын
If i take my sec+ and pass should i take the ethical hacking course?
@ron2040
@ron2040 14 күн бұрын
David, I have decade of experience in IT security and Unix skills are in my blood, however, there are no updates from my job applications to New Zealand and Australia. Ironically, visa is oftenly prioritized over the security and as a result, I foresee more Australia airlines systems and NZ infra is going to be intruded. I am not sure if you have HR from those countries that can you could link me to ? People are always saying shortage of security professionals but restricting to hire them from abroad.
@jeevarevarth9280
@jeevarevarth9280 14 күн бұрын
1st view frome INDIA(TAMIL NADU)
@davidbombal
@davidbombal 14 күн бұрын
Thank you for your support!
@ggelosstavrou9117
@ggelosstavrou9117 14 күн бұрын
Hey BleuDucky does not work now. Please make another video on it and how to use it with the Bluetooth adaptor u suggested (ASUs one )
@CROWNTHRONEHERBALCOMPANY
@CROWNTHRONEHERBALCOMPANY 13 күн бұрын
please sir, i can be able to connect to the network from linux os. please what can i do?.
@Duncain-Data-Boy
@Duncain-Data-Boy 14 күн бұрын
Watching from 🇿🇲🇿🇲🇿🇲
@davidbombal
@davidbombal 14 күн бұрын
Welcome! And thank you for watching :)
@cyberdevil657
@cyberdevil657 13 күн бұрын
Hi David!
@kristitv69
@kristitv69 12 күн бұрын
hello please help me, some weeks ago i installed kali linux. i opened windows defender and it shows "threats found" there's so many of them, is this dangerous what should i do?
@Bcowzz
@Bcowzz 11 күн бұрын
Most folks would get bored on this..... ... Expect resistance
@CyberSecJourn
@CyberSecJourn 9 күн бұрын
Interesting. I can here once because my students recommended it and now I get notices for every video you post and I'm NOT subscribed? Love how KZfaq's algos work sometimes.
@jean-francoistasse7788
@jean-francoistasse7788 9 күн бұрын
31:01 About changing the default password, for my new Asus router, they ask you to first unplug the modem, do your changes and then plug back the modem. That was the first time I saw this kind of procedure on a normal everyday router.
@MrDBNicholson
@MrDBNicholson 7 күн бұрын
@ 27:02 I personally know of an email forgery of a construction and a house of worship. The house of worship was billed for legitimate work. The Threat actor must have been watching the construction company for some time because as soon as the bill was sent a second was sent redirecting the payment a different way. As you can guess the threat actors received the church’s money.
@bx1803
@bx1803 14 күн бұрын
MFA Fatigue ... what are we doing about it..
@aquatrax123
@aquatrax123 14 күн бұрын
Login token/cookies really need to be moved to secure hardware like the TPM.
@kuldeepjangid10
@kuldeepjangid10 14 күн бұрын
Please explain Triton cyber attack…
@user-ih7yb1ic6e
@user-ih7yb1ic6e 14 күн бұрын
Hi sir ❤
@davidbombal
@davidbombal 14 күн бұрын
Hi!
@user-ih7yb1ic6e
@user-ih7yb1ic6e 14 күн бұрын
Watching this video has helped a lot. Will help improve my skills ​@@davidbombal
@reggiedaniels6920
@reggiedaniels6920 13 күн бұрын
You know David, the problem with shows like yours, it that those who most need them would never take the time watch these videos. And if a friend tried to tell them they would find some excuse not to take the warnings seriously. There are thousands of situations like this that fall into the same state of affairs.
@Bcowzz
@Bcowzz 11 күн бұрын
Now lets talk about ciscos backdoors
@rishiraj2548
@rishiraj2548 14 күн бұрын
👍💯
@ikust007
@ikust007 14 күн бұрын
Thats is why I am very doubtful about protocols like RNDR or any other decentralized uses of hardware (DEPIN). Comments please ? Thank you
@Bcowzz
@Bcowzz 11 күн бұрын
Voltage and low voltage
@Bcowzz
@Bcowzz 11 күн бұрын
Its built in, goes back to IBM
@ShojibShak-dd3he
@ShojibShak-dd3he 9 күн бұрын
Ser oppo a 17 bootloder please please iam from 🇧🇩🇧🇩🇧🇩
@AmazingJayB51
@AmazingJayB51 8 күн бұрын
Add a salt to your pw! 😁
@savagepro9060
@savagepro9060 14 күн бұрын
David Bombal, sincerely: "You have to look out for these hacks in 2024!" New Malware Phish Link Release: "You have to look out for these hacks in 2024!"! Click! Oops!
@davidbombal
@davidbombal 14 күн бұрын
Don't click on links in e-mails!
@alexis-uh4nt
@alexis-uh4nt 13 күн бұрын
Bro i used morse code for my password😂😂 gotta be secured right
@muddkipp_1
@muddkipp_1 14 күн бұрын
pokemon go is my exercise, thank you
@satirical_snake
@satirical_snake 13 күн бұрын
Rooters
@Editor_vdeo
@Editor_vdeo 14 күн бұрын
Help me
@danieltran7637
@danieltran7637 13 күн бұрын
Yep interesting times, these days. Only the paranoid will survive. 😄
@user-pj6bp6np8t
@user-pj6bp6np8t 6 күн бұрын
😂
@ShojibShak-dd3he
@ShojibShak-dd3he 9 күн бұрын
Ser kali linux live boot install 📲
@mrcinnamondotexe
@mrcinnamondotexe 14 күн бұрын
Woohoo
@davidbombal
@davidbombal 14 күн бұрын
I hope you enjoy the video :)
@ani65ans94
@ani65ans94 10 күн бұрын
They got my name address. N.I no. Know I'm broke, and inherite. My pass transgressions. Help Uself.
@BurkenProductions
@BurkenProductions 14 күн бұрын
No you SHOULD NEVER use default passwords NOR should you use MFA either. Just block everyone except your own networks. PPl need to STOP pushing MFA on everyone who does NOT wish to have it on their account on web sites etc. it should be a personal choise.
@GOTHAM21
@GOTHAM21 14 күн бұрын
Bad analogy.
@BoHror933
@BoHror933 14 күн бұрын
how can you possibly expect people to take any of this advice and apply it when you use so much slang and abbreviations without explaining …people don’t understand.
@user-pj6bp6np8t
@user-pj6bp6np8t 6 күн бұрын
😂 learn the terminology
@1amy0u1amy0u
@1amy0u1amy0u 12 күн бұрын
Your VPN won't protect you 😱
1:03:25
David Bombal
Рет қаралды 91 М.
Hacking Tools (with demos) that you need to learn in 2024
1:27:34
David Bombal
Рет қаралды 560 М.
WHY DOES SHE HAVE A REWARD? #youtubecreatorawards
00:41
Levsob
Рет қаралды 36 МЛН
КАРМАНЧИК 2 СЕЗОН 6 СЕРИЯ
21:57
Inter Production
Рет қаралды 437 М.
1🥺🎉 #thankyou
00:29
はじめしゃちょー(hajime)
Рет қаралды 78 МЛН
I got Pwned ... and so did you! (you're likely in the 12 Billion)
1:03:18
Where People Go When They Want to Hack You
34:40
CyberNews
Рет қаралды 908 М.
6 Must-Have Security Gadgets That Fit in Your Pocket
9:03
All Things Secured
Рет қаралды 1,7 МЛН
Is it the end? (Or can YOU do something in 2024?)
1:15:00
David Bombal
Рет қаралды 86 М.
Discussing Active Directory & Internal Network Security
36:15
John Hammond
Рет қаралды 45 М.
3 Levels of WiFi Hacking
22:12
NetworkChuck
Рет қаралды 1,5 МЛН
How to be Invisible Online (and the hard truth about it)...
53:16
David Bombal
Рет қаралды 1,8 МЛН
Hackers remotely hack millions of cars!
54:31
David Bombal
Рет қаралды 74 М.
What's It Like As A Red Team Operator? (w/ Chris M.)
47:49
Cyberspatial
Рет қаралды 103 М.
iPhone 15 Pro vs Samsung s24🤣 #shorts
0:10
Tech Tonics
Рет қаралды 10 МЛН
Huawei который почти как iPhone
0:53
Romancev768
Рет қаралды 581 М.
Индуктивность и дроссель.
1:00
Hi Dev! – Электроника
Рет қаралды 1,5 МЛН
Цифровые песочные часы с AliExpress
0:45