Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Varonis: LockBit's Federal Reserve Bluff & Critical OpenSSH Vulnerability

Varonis
08/26/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Hey there, how are you? I'm outstanding. My name is Matt Radlach. I'm joined by our co-host David Gibson, and we are so pumped to talk with you guys for another episode of State of Cybercrime. I see a bunch of people chiming in, letting us know where we're chatting to and connecting with you from today. I'm at home in Maryland. What about you, David? I'm at home in Connecticut. It's so great to have you here today. We're going to crack right into it, and we'll go through a bunch of our usual segments. We'll definitely cover whether or not there's any good news. We'll talk about all the latest happenings in AI. We'll jump on the highway to the danger zone and talk about some threat actors and some attacks that you should be worried about. We'll cover some vulnerable vulnerabilities. So with that, let's jump into it. What's the name of our first segment here, Matt? Yeah, this is, is there any good news? And if I had it autoplay, then we would get to hear that. That's what we were waiting for. Our first segment is, we like to cover all the good news and the good things happening in cyber. For those of you who join us for the first time, there's often a ton of doom and gloom. Everybody's got a lot to say, and it's usually not very good. So yeah, let's crack into it. Excellent. So we, there's, there's Operation Morpheus is kind of our first topic, and that, I think it's well-named, but this was a coordinated effort by law enforcement from Australia, Canada, Germany, the Netherlands, Poland, the US, and was led by the UK National Crime Agency. But essentially what they did was over several years, it looks like, they identified almost 700 IP addresses that were kind of on the other end of Cobalt Strike beacons, malicious Cobalt Strike beacons, which attackers can use to achieve command and control, right? So command, I guess the first stage is you deploy a beacon. By the way, this was a red team tool that was kind of, I guess, appropriated by attackers and modified so that they could use it for their own ends, but essentially dropper on a victim host that then beacons out to a command and control server where they can drop another payload and do more stuff. So I think this is a win for the good guys. Almost 700, actually it looks like about, they identified 700 IP addresses on 690, and so far, almost 600, 593 of the addresses have been taken down. A few more to go there, but that's a lot fewer bad guy servers than there were before, right? Yeah, and I still, you know, to this day, the Cobalt Strike framework, when the source code got leaked online, you know, we are still paying the damages for that one. Even here in 2024, I think that that leak happened maybe even in close to a decade ago or eight or nine years ago. So it's great though to see, you know, law enforcement come together and these cross border, cross continent, even collaborations between cyber agencies definitely shows progress towards, you know, taking down the hackers, the attacker groups and their infrastructure. But that's not the only good news we've got, David. A lot of people, you know, get excited or worried when they hear about ransomware groups like Scattered Spider. They were responsible for a large attack campaign called Octopus. I don't know if you remember us talking about that. Targeted hundreds of organizations like Twilio and CloudFare, and they were behind that. But the one that really got, the story that really got Scattered Spider under the eyes of law enforcement and really the world was the attack on MGM. And it was after that attack that the FBI led an offer for a reward for information that would lead to the arrest of those involved in Scattered Spider. Now it's interesting, there's a little bit of an inception happening here. Scattered Spider actually used the Black Cat and Alpha V ransomware to take on MGM resorts. So at the time, even we said we thought it was Black Cat and Alpha V that was behind the attack, but it looks like it was Scattered Spider. Well, just a few months after the FBI offered their initial reward, a 22 year old British man got arrested in Mallorca trying to board a flight to Italy. This man was in possession of right around 30 million in Bitcoin and is suspected to be the leader of the Scattered Spider ransomware group. This arrest was due to a coordination between the Spanish police and the U.S. Federal Bureau of Investigation. So it does continue to look like that if you start to do this cybercrime, you might have to do the time. So when you've got 30 million in Bitcoin, can you fit that on a carry-on or did you have to check that? You know, there's this thing, it's a digital currency, David, so you can probably fit it in your pocket, I would imagine. All right, got it. Let's jump on to our next segment here. And this is our newest segment, and it's one that is the topic that everybody loves to talk about. I mean, come on, nobody is tired of hearing about AI. And saying AI to yourselves is probably what you're doing right now. So we'll cover the good, the bad, and the ugly as it happens and relates to AI and our eventual demise to the robot overlords. First up is prompt engineers got a win, and mankind's hope for ethical AI has lost again. Researchers are banging away at generative AI prompts to find loopholes. How this skeleton key loophole works is you're going to ask the AI model to augment rather than completely change its behavioral guidelines. So in the case of asking for something like how to make a Molotov cocktail, in this case, the prompt engineer asked, but said, hey, look, I know you're not supposed to do this, but if you give me the response with a warning label, then you can give it to me for educational purposes, right? And that's exactly what happened, right? You're able to trick these generative AI co-pilots and provide you with responses that they otherwise wouldn't. And this skeleton key didn't only work on Microsoft co-pilot, though. It also worked on Metas Llama 3, Google's Gemini Pro, ChatGBT 3.3 and a half, OpenAI's ChatGBT 4, Mistral Large, Anthropic Cloud, Opus, Cohere Commander R+, they really all seem to be vulnerable to this. And David, when we were talking about this, you really brought up how this might not be something that we can stop because there's always going to be ways that we can ask for information that if asked in the right way, you're going to get the response, but if used in the wrong way, could be malicious or potentially harmful. Do you want to talk more about your thoughts on that or really what is good enough in terms of stopping AI from providing these types of results? Well, AI helps you get that information and information can be used for good or not so good. I think it's going to be hard to know what the spirit is behind asking the question and how somebody wants to use the information that they're getting. The same information that could be used to save somebody could also be used to hurt them. And I think we've got a tall order ahead of us. I think it probably it's going to involve a lot of sophisticated analytics on what people are actually doing with the AI and what the intent is. But I feel like just like any tool can be used for good or for evil, it's going to be hard to know what the intent is, what the outcome of providing that information is going to be. You could be an evil genius or a genius that does a lot of good in the world. It's the same wetware. At that point, is it any different from running a Google search or an internet web search? Because if we're talking about the law enforcement angle or the court case angle, they use the searches that you made in your surgery, all these famous cases of people killing their spouses. And right before they did it, they Googled how to hide a body or how to kill someone quietly or something like this. Are we going to see prompts as the next iteration of what comes up in court around how you gained access to harmful information? I always like to say with great power comes great responsibility and AI can't escape that. But talking about AI, what is this VANA AI and does it have anything to do with VANA White and Wheel of Fortune? Absolutely. It was a Wheel of Fortune hack. It's interesting. This is a little different than the skeleton key. I think the skeleton key, the way that people are thinking of it, it's kind of an impromptu escape. So the damage would be you'd be getting a response, you'd be getting information inside the prompt that could be potentially dangerous. This one is different in that it exposes a remote code execution. So you're essentially escaping out of the AI. And actually on the last session, we talked about how AI is made up of kind of multiple modules in some cases. And last time we talked about a hugging face and the pickle module that is one of the things that makes AI functions work. And if you have a malicious pickle, you can escape the AI prompt. And this is another one of these vulnerabilities. And essentially, it exploits the ability to kind of do a SQL hack. Essentially, there's a way to craft a SQL select statement so that it prints an output. And if they use that in conjunction with another library that Vanna uses, and just to kind of summarize, Vanna does text to SQL. So the idea, you put in natural language and it'll do the SQL prompt for you. But Vanna also can generate the response in a graph. So it'll show you a graph. And to do that, it uses a library called Plotly. And essentially, if you craft the SQL statement in a way that it prints a command, that gets passed to Plotly and Plotly will execute that on the host it's running on. So it reminds me a lot of a SQL injection, but it's a bit more abstract. And this is kind of where you can craft an AI prompt that actually goes outside the boundaries of the AI prompt. Hopefully, I'm making some sense there. It was really interesting. By the way, it was with Tower, there was a really great write up on how this worked. And I'll find that and put it in the chat. But really, really interesting stuff. Yeah. And it sounds like a SQL injection vulnerability, but with like a layer of abstraction to it because of what gets called by the SQL injection. So it's interesting to see these kind of OWASP top 10 get applied to AI, whether it's on the language model or on the co-pilot side as a lot of the same things that work on non-AI powered applications from an exploitation or vulnerability standpoint are present in these AI based applications as well. Now in preparing for this one, did you say something about a malicious pickle, David? I did. Last time I asked the audience, what would be a better band name, malicious pickle or pickle malicious. And I did want to thank everybody for the input. So one night only. Yeah. Well, that's probably not the only thing that we have to talk about, getting ourselves into a malicious pickle or naming the AI based band that we'll probably never perform with. There is this Elvis act. And I give a lot of credit, Tennessee does tend to lead the way for artists and for musicians around protecting copyrighted work. And musicians are definitely celebrating this victory against the robots as Tennessee has impassed the ensuring likeness voice and image security or Elvis act. I love that name. Yeah, I know. Right. Especially with all that title fraud stuff going on with the Elvis estate. It's very timely. So what it does is it expands personal rights law to include protections for songwriters, performers, and others in the music industry. It protects their voice, their voice from the misuse of artificial intelligence. So really it calls out voice as another form of protected art. And really the goal of the legislation is to continue to protect artists whose likeness has been cloned or reused by AI tools for reproduction, obviously without the striking a deal or paying for the license to use that person's likeness. So it's great to see at least at a state level that we see protections for artists from their work being reproduced or cloned or reused by AI. Yeah. I would really rather imagine a future where AI is able to do our TPS reports or do the dishes and we can do the art. We can make the music rather than having the AI do the music in the arts. Yeah. And we had an audience member chime in and say, isn't that a bit of a double statement? Yes, we're trying to cleverly use alliteration from time to time on the show. And so we call this segment Vulnerable Vulnerabilities just to make sure you know what we're talking about. Now, David, what is this first vulnerability with OpenSSH? So this is called regression. And apparently there was a vulnerability a long time ago, and we've since had a regression. So this old flaw was patched a while back, but it has reappeared in versions 8.5 P1 all the way up to 9.7 P1. And apparently it affects at least any 32-bit Linux systems running glibc. And actually, I think it's probably going to extend more than that. But the way it works is it essentially creates a race condition. So an attacker can try to connect to SSH, but they don't finish the authentication. And they do that over and over and over again. And apparently what happens is it calls a SIGALARM function in an unsafe way. It's kind of, they call it async signal safe or not. And I think to oversimplify this, it's essentially like when you're sending signals in an unsafe way, it's kind of like sending two things to your printer at the same time and having it try to keep printing at the same time. It kind of overlaps the output. But instead of going to paper, it's going into RAM. And if the attacker does it just right, they can manage to get something that can be remotely executed or executable code in that address space. So it's POC code. It seems like it's a little bit hard to exploit. And really, if somebody is trying to do this, it looks like it takes an average of six to eight hours to do all those sessions and kind of time them out and have that condition happen. So it should be noisy, kind of a POC code, but patch SSH. Not the first one we've seen. I think the interesting one here is that they have to flood the table. It kind of reminds me of a bit like a denial of service combined with a buffer overflow and that you're trying to flood the connection table. And then eventually, one is going to be triggered the signal alarm, which runs an unsecured library that allows you to put more code in it. Yet again, we see kind of the old but trusted vulnerability shine through or get found in other systems. Now, that's not the only repeat one there. Go ahead, David. I was just going to say, I think that's a really great way to put it. It's kind of like an old sin flood, except it's poisoning the well behind it. Combined with poisoning the ARP table after the sin flood, right? We were talking about that 10 or 15 years ago. Now, that's not the only sequel that we're going to talk about today, though. Hackers have found another flaw in Moovit, this time to bypass authentication. It feels like over a year ago, we were talking about Moovit and the latest Moovit vulnerability. And so Moovit transfer, this is a managed file transfer solution, has a new vulnerability CPE 2024-5806. This allows attackers to bypass the authentication in the SFTP module, which is responsible for the secure file transfers over Moovit using SSH. According to Census, there's a company that scans the open internet. There are at least 2,700 Moovit devices available on the open internet to be exploited and patches are available. Combine that with talking to Shadow Server Foundation, they've actually found that attackers are actively exploiting this Moovit vulnerability. So if you're here joining us on the show today and you haven't patched this yet, you probably should. Yeah, this is another scary one and some good write-ups about how this works to vulnerability in SFTP. Well, not in SFTP, but in the implementation of it. Yeah, in the implementation of it that allows you to take over and really kind of exfiltrate data from Moovit yet again. Now, what is this polyfill? Does this have anything to do with the stuff in those pillows you get at the carnival or am I missing out on something here, David? This is an installation attack. You're absolutely right. Now, I wasn't aware about this, but apparently polyfills are libraries that help to overcome differences or deficiencies between web browsers. So essentially, you can insert these libraries so that a web browser can do the things you want it to do. Now, apparently polyfill.io was a place that stored all these libraries and a lot of different websites would call the library from polyfill.io. Now, if I'm reading this right, that got taken over and these libraries became infested with malware. And so really people's browsers would call these libraries and then be running malicious code on their hosts. So the recommendation is remove any references on your website to polyfill.io and you can replace those with different polyfill repositories in Cloudflare or Fastly. And I think how this had happened, right, was the polyfill developers had probably mistakenly, I mean, obviously we think it's mistakenly, it wasn't intentionally malicious, put some keys, their Cloudflare keys in a publicly accessible, you know, just expose them in a publicly accessible way. And then attackers were able to use those keys, remove the references of, you know, pointing back to polyfill, pointed instead at Cloudflare, Fastly references to the malicious code that then gets run on everyone that visits or intends to do it via polyfill. So there's like some, I mean, very potentially broad impact. I mean, tens of millions or, you know, even dozens of millions of websites could have been impacted by this. Yeah, this is pretty big damage. And definitely I would mitigate that. Yeah, somebody said, I know we block polyfill.io now. And I think that it's being blocked by a DNS in a couple of different ways too, but definitely would want to remove the references to it in your sites. Well, let's jump into our last segment, the dangers. Here, we usually talk about attackers, techniques, their protocols, breaches that might've happened, or even just, you know, talking about the same thing yet again. I feel like Snowflake is, I mean, three episodes in a row, we're still talking about the fallout from the blizzard that was the attack on Snowflake and its customers. The latest victim being AT&T, one of the largest cell phone carriers in the world said that they lost a lot of data, including call logs, SMS messages for over 25 million customers. And in addition to that, Mandiant also has come out and said that they see a connection between the attacker group, they think purported the attack on Snowflake and its customers, UNC5537 and Scattered Spider. This because around 10 organizations of the 160 or so that got breached by Snowflake have been contacted in order to pay a ransom in order to not have additional data be leaked online. Some of those including companies like Ticketmaster and Neiman Marcus. And for Ticketmaster, I think the number so far between 40,000 and 60,000 tickets had been fraudulently printed and reused, which actually caused real harm to people, you know, concert goers and event goers around the world. Yeah, this is, by the way, I see what you did there with the blizzard, right, and quite a bit of fallout on this one. And, you know, I think it's kind of important to kind of review those steps, right, with the MFA and kind of all the tips that we've put on our, you know, before on how to monitor the stuff. Yeah, I think it's quite simple. When we think about like a SaaS application or, you know, database service daily as a service like Snowflake that allows connections from the outside, the way that this attack happened was quite trivial, in my opinion. People reuse their usernames and passwords. It's just a fact. If you reuse your username and password, or one of your employees did, and an Info Stealer malware was able to pick up their login credentials to Snowflake, and your organization didn't have multi-factor authentication or trusted network access blocks in place for your Snowflake, you were vulnerable to a simple password reuse attack. And that's what happened. You know, hundreds of Snowflake customers got targeted by this. They didn't have MFA enabled on those accounts. They didn't have things set up in a way that only their organization's IPs could get to Snowflake. And a lot of sensitive data got leaked onto the internet. And we're only still learning just today about AT&T being included in all of that. Yeah. And that looks like there's a lot of people in that breach, right? Like all their wireless customers as well. Call logs, SMS messages, millions and millions of consumers. Now, that wasn't the only little bit. It looks like Lockbit is, you know, chomping at the bit to do a little bit more in the ransomware gang as well. Yeah, this one was interesting. A little bit of a head scratcher. Apparently in June, Lockbit had claimed to have breached the Federal Reserve and threatened to release, you know, 33 terabytes of data or some of that. It looked like, I think the Fed, you know, offered to pay it. Yeah, 50 grand for the data. And I had even said, like, what's going on here? Why do they value this so little when the last time we talked about this? But maybe it's because it wasn't their data. Yeah, it turned out after the data was kind of released, that analysts determined it was stolen from Evolve Bank and Trust. And they confirmed that, yep, this is their data. Apparently an employee clicked on the malicious link back in May or so. And so this is where that data came from. That's where the exposure was, kind of a run of the mill ransomware attack that was not really concerning the Federal Reserve. Nonetheless, Lockbit has been really busy, right? They're very active and they were associated with an attack on a Croatia hospital recently as well. Well, I think that pretty much wraps up everything we had planned on going through today. So let's check out and see if anything came in in the chat or anything came in via the Q&A that we need to cover. I think just a couple of questions. Should polypill.io be blocked at the perimeter as one of them, David? And then one of our other audience members wants to know if we know who was behind the polyfill attack. Yeah. And I know that that was something that looks like we said we would to talk about who was behind that. What I was reading on that is that, as you said, that what was really behind it was kind of some keys that were put in an open GitHub repository by mistake. But it also looks like there was some association with a Chinese actor, right? Did I read that correctly from your notes? Yeah. And I'm not sure we know exactly who it is yet. I think we have some suspects from Chinese APT groups. But if you put secret and keys in a public domain, you probably should expect them to get misused or abused, especially if they're still valid. We hope that you guys enjoyed our show today. It is made possible by you, our audience. So we super appreciate you sticking around. We hope that you'll leave us some feedback, and we look forward to seeing you on our next episode of State of Cybercrime.

TL;DR

  • Operation Morpheus took down nearly 600 malicious Cobalt Strike command and control servers through international law enforcement cooperation, while the suspected Scattered Spider leader was arrested with $30 million in Bitcoin.
  • The skeleton key jailbreak technique bypasses AI safety guardrails on major platforms by requesting dangerous information with warning labels for educational purposes, raising fundamental questions about AI content restrictions.
  • Critical vulnerabilities in OpenSSH, MOVEit Transfer, and the Polyfill supply chain require immediate attention, with active exploitation confirmed for MOVEit and Polyfill affecting millions of websites.
  • AT&T joins the growing list of Snowflake breach victims with 25 million customer records exposed, while Mandiant links the attacks to Scattered Spider and confirms ransom demands to multiple organizations.
  • LockBit's claimed Federal Reserve breach was actually data stolen from Evolve Bank and Trust, though the ransomware group remains highly active with recent attacks on healthcare facilities.

Law Enforcement Wins Against Cybercriminals

The episode opens with encouraging news from the cybersecurity front. Operation Morpheus, a coordinated effort led by the UK National Crime Agency with participation from Australia, Canada, Germany, the Netherlands, Poland, and the US, successfully identified and took down nearly 600 IP addresses associated with malicious Cobalt Strike beacons used for command and control operations. Additionally, a 22-year-old British man suspected of leading the Scattered Spider ransomware group was arrested in Mallorca while attempting to board a flight to Italy, found in possession of approximately 30 million dollars in Bitcoin. This arrest resulted from collaboration between Spanish police and the FBI, demonstrating that international cooperation is yielding results against cybercriminals.

AI Security Challenges and the Skeleton Key Bypass

The discussion turns to ongoing challenges in AI security, particularly the skeleton key jailbreak technique that allows users to bypass safety guardrails on major AI platforms. Researchers discovered that by asking AI models to provide dangerous information with a warning label for educational purposes, they could circumvent restrictions on platforms including Microsoft Copilot, Meta's Llama 3, Google Gemini Pro, ChatGPT, and others. The hosts debate whether this represents a fundamental challenge since the same information that could help someone could also cause harm, making intent difficult to determine. A separate vulnerability in Vanna AI, a text-to-SQL tool, demonstrates how attackers can achieve remote code execution by crafting SQL statements that escape the AI prompt boundary and execute commands on the host system through the Plotly graphing library.

Critical Vulnerabilities Requiring Immediate Attention

Several critical vulnerabilities demand immediate patching attention. A regression vulnerability in OpenSSH affects versions 8.5 P1 through 9.7 P1 on 32-bit Linux systems running glibc, creating a race condition that can lead to remote code execution. While exploitation requires six to eight hours of sustained connection attempts, making it noisy and detectable, the severity warrants immediate patching. MOVEit Transfer faces another authentication bypass vulnerability in its SFTP module, with Census identifying at least 2,700 exposed devices on the open internet and Shadow Server Foundation confirming active exploitation. The Polyfill supply chain attack affected potentially tens of millions of websites when attackers compromised the polyfill.io repository, injecting malicious code into libraries that browsers would execute. Organizations should remove references to polyfill.io and migrate to Cloudflare or Fastly alternatives.

Snowflake Fallout and LockBit's False Claims

The Snowflake breach continues to expand with AT&T now confirmed as a victim, losing call logs and SMS messages for over 25 million customers. Mandiant has identified connections between the threat actor UNC5537 and Scattered Spider, with approximately 10 of the 160 breached organizations receiving ransom demands. The attack vector remains straightforward: credential reuse combined with lack of multi-factor authentication and IP restrictions on Snowflake accounts. In a separate development, LockBit's claim to have breached the Federal Reserve proved false when analysts determined the 33 terabytes of data actually belonged to Evolve Bank and Trust, stemming from an employee clicking a malicious link in May. Despite this embarrassing bluff, LockBit remains highly active, recently attacking a hospital in Croatia.

Chapters

0:00 - Introduction
1:05 - Good News: Operation Morpheus
3:30 - Scattered Spider Leader Arrested
5:13 - AI Security: Skeleton Key Jailbreak
8:58 - Vanna AI Remote Code Execution
12:20 - Tennessee ELVIS Act Protects Artists
14:02 - OpenSSH Regression Vulnerability
17:00 - MOVEit Authentication Bypass
18:16 - Polyfill Supply Chain Attack
20:30 - Snowflake Breach: AT&T Impact
23:13 - LockBit's Federal Reserve Bluff
24:48 - Q&A and Wrap-up

Key Quotes

3:09 "To this day, the Cobalt Strike framework, when the source code got leaked online, we are still paying the damages for that one. Even here in 2024, I think that that leak happened maybe even close to a decade ago or eight or nine years ago."
4:49 "It does continue to look like that if you start to do this cybercrime, you might have to do the time."
7:28 "The same information that could be used to save somebody could also be used to hurt them. And I think we've got a tall order ahead of us."
8:03 "You could be an evil genius or a genius that does a lot of good in the world. It's the same wetware."
22:19 "People reuse their usernames and passwords. It's just a fact. If you reuse your username and password, or one of your employees did, and an Info Stealer malware was able to pick up their login credentials to Snowflake, and your organization didn't have multi-factor authentication or trusted network access blocks in place, you were vulnerable to a simple password reuse attack."

FAQ

What should organizations do to protect against the Snowflake-style attacks?

Organizations should enable multi-factor authentication on all SaaS applications and database services, implement IP allowlisting to restrict access to trusted networks, and monitor for credential reuse by checking employee credentials against known breach databases. The Snowflake attacks succeeded because victims lacked MFA and allowed connections from any IP address.

How should websites address the Polyfill supply chain vulnerability?

Organizations should immediately remove all references to polyfill.io from their websites and replace them with alternative polyfill repositories hosted by Cloudflare or Fastly. Additionally, blocking polyfill.io at the DNS or perimeter level provides an extra layer of protection against any remaining references.

What makes the OpenSSH regression vulnerability difficult to exploit?

The vulnerability requires attackers to repeatedly initiate SSH connections without completing authentication, creating a race condition over six to eight hours of sustained attempts. This makes the attack noisy and detectable, though the severity of achieving root-level remote code execution still warrants immediate patching.


Categories:
  • » Webinar Library » Varonis
  • » Data Protection » Backup & Recovery
  • » AI & Machine Learning
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Threat Intelligence
  • Security Operations
  • Vulnerability Management
  • AI & Machine Learning
  • Data Protection
  • ransomware
  • law enforcement operations
  • AI security
  • jailbreak techniques
  • supply chain attacks
  • vulnerability management
  • credential security
  • OpenSSH
  • MOVEit
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Varonis: LockBit's Federal Reserve Bluff & Critical OpenSSH Vulnerability

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                • Sep
                  03

                  Verge.io: Can You Afford Your Next Storage Refresh?

                  09/03/202601:00 PM ET
                  More events

                  Industry Events (Sponsor Hosted)

                  • Aug
                    27

                    Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration

                    08/27/202601:00 PM ET
                    • Sep
                      23

                      Invisible Data: Understanding What Needs Protection

                      09/23/202601:00 PM ET
                      • Sep
                        29

                        Embracing AI Adoption While Maintaining Robust Security Measures

                        09/29/202612:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 08/27/2026
                          01:00 PM
                          08/27/2026
                          Becoming Agent Ready with Cyera: Essential Strategies and Insights
                          https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                        • 08/27/2026
                          01:00 PM
                          08/27/2026
                          Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration
                          https://www.truthinit.com/index.php/channel/2086/summer-of-satori-funfonefarms-transformation-of-fraud-into-seamless-integration/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/03/2026
                          01:00 PM
                          09/03/2026
                          Verge.io: Can You Afford Your Next Storage Refresh?
                          https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                        • 09/23/2026
                          01:00 PM
                          09/23/2026
                          Invisible Data: Understanding What Needs Protection
                          https://www.truthinit.com/index.php/channel/2087/invisible-data-understanding-what-needs-protection/
                        • 09/29/2026
                          12:00 PM
                          09/29/2026
                          Embracing AI Adoption While Maintaining Robust Security Measures
                          https://www.truthinit.com/index.php/channel/2092/embracing-ai-adoption-while-maintaining-robust-security-measures/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        • 11/19/2026
                          01:00 PM
                          11/19/2026
                          360View: Govern, Secure & Recover Your Microsoft 365 Environment
                          https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version