Go offline with the Player FM app!
S6, E261 - The Red Line: Salt Typhoon, Temu Spyware & The 'Side Door' Attack
Manage episode 522709069 series 3237552
A week where the lawful intercept backdoor became the front door, a supply chain hop hit 200+ companies, a bargain app faced a malware lawsuit, and a university breach turned into a donor-targeting roadmap. We share simple moves to lower risk fast and set guardrails that actually hold.
• Salt Typhoon abusing CALEA at major US telecoms
• Negligence, unpatched routers and weak passwords
• Why SMS is transparent and how to switch to Signal
• Kill SMS 2FA and use authenticators or YubiKey
• Gainsight-to-Salesforce island hopping at scale
• Audit connected apps and revoke stale API keys
• Arizona AG lawsuit calling Timu malware
• Shop via browser sandbox and use masked payments
• UPenn donor data leak and Oracle exploit
• Whaling protections with voice verification and data scrubbing
• Practical recap: trust nothing, verify everything
Please follow us or subscribe on your podcast app, and watch the video on our YouTube or at theproblemlounge.com. If you have topics or guest ideas, we would love to hear from you
Support the show
Chapters
1. S6, E261 - The Red Line: Salt Typhoon, Temu Spyware & The 'Side Door' Attack (00:00:00)
2. Welcome And Red Line Theme (00:02:13)
3. Lawful Intercept System Exploited (00:03:09)
4. Negligence And Regulatory Fight (00:04:54)
5. Protect Yourself From Carrier Breaches (00:05:46)
6. Supply Chain Attack Via Gainsight (00:06:23)
7. Arizona AG vs Timu App (00:07:43)
8. Audit And Revoke Risky Integrations (00:07:49)
9. Safer Shopping And Payment Hygiene (00:09:14)
10. UPenn Double Breach Fallout (00:09:14)
11. Whaling Risks And HNW Defenses (00:10:14)
12. Recap And Community Invitation (00:11:20)
263 episodes
Manage episode 522709069 series 3237552
A week where the lawful intercept backdoor became the front door, a supply chain hop hit 200+ companies, a bargain app faced a malware lawsuit, and a university breach turned into a donor-targeting roadmap. We share simple moves to lower risk fast and set guardrails that actually hold.
• Salt Typhoon abusing CALEA at major US telecoms
• Negligence, unpatched routers and weak passwords
• Why SMS is transparent and how to switch to Signal
• Kill SMS 2FA and use authenticators or YubiKey
• Gainsight-to-Salesforce island hopping at scale
• Audit connected apps and revoke stale API keys
• Arizona AG lawsuit calling Timu malware
• Shop via browser sandbox and use masked payments
• UPenn donor data leak and Oracle exploit
• Whaling protections with voice verification and data scrubbing
• Practical recap: trust nothing, verify everything
Please follow us or subscribe on your podcast app, and watch the video on our YouTube or at theproblemlounge.com. If you have topics or guest ideas, we would love to hear from you
Support the show
Chapters
1. S6, E261 - The Red Line: Salt Typhoon, Temu Spyware & The 'Side Door' Attack (00:00:00)
2. Welcome And Red Line Theme (00:02:13)
3. Lawful Intercept System Exploited (00:03:09)
4. Negligence And Regulatory Fight (00:04:54)
5. Protect Yourself From Carrier Breaches (00:05:46)
6. Supply Chain Attack Via Gainsight (00:06:23)
7. Arizona AG vs Timu App (00:07:43)
8. Audit And Revoke Risky Integrations (00:07:49)
9. Safer Shopping And Payment Hygiene (00:09:14)
10. UPenn Double Breach Fallout (00:09:14)
11. Whaling Risks And HNW Defenses (00:10:14)
12. Recap And Community Invitation (00:11:20)
263 episodes
All episodes
×Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.