<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	 xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>Threat Intelligence-arkiv - IT-säkerhetspodden</title>
	<atom:link href="https://www.itsakerhetspodden.se/tag/threat-intelligence/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.itsakerhetspodden.se/tag/threat-intelligence/</link>
	<description>IT-säkerhet med Erik och Mattias som varvar kändisintervjuer med säkerhetssnack i tiden</description>
	<lastBuildDate>Sun, 12 Jun 2022 16:50:38 +0000</lastBuildDate>
	<language>sv-SE</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.3</generator>

<image>
	<url>https://www.itsakerhetspodden.se/wp-content/uploads/2020/04/cropped-sitelogo-32x32.jpg</url>
	<title>Threat Intelligence-arkiv - IT-säkerhetspodden</title>
	<link>https://www.itsakerhetspodden.se/tag/threat-intelligence/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">171781042</site>	<item>
		<title>#173 &#8211; Kaja Narum</title>
		<link>https://www.itsakerhetspodden.se/173-kaja-narum/</link>
					<comments>https://www.itsakerhetspodden.se/173-kaja-narum/#respond</comments>
		
		<dc:creator><![CDATA[Erik Zalitis]]></dc:creator>
		<pubDate>Sat, 11 Jun 2022 17:00:00 +0000</pubDate>
				<category><![CDATA[ShowNotes]]></category>
		<category><![CDATA[Sponsrat Nordlo]]></category>
		<category><![CDATA[Erik Zalitis]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[Kaja Narum]]></category>
		<category><![CDATA[Mattias Jadesköld]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<category><![CDATA[X-Force]]></category>
		<guid isPermaLink="false">https://www.itsakerhetspodden.se/?p=5380</guid>

					<description><![CDATA[<p>Kaja Narum arbetar på IBM som just släppt en rapport on cybersäkerhetshoten i världen. Och hon säger till Mattias och Erik att Sverige halkat på efterkälken vad det gäller cyberförsvaret. Varför är det så?</p>
<p>Inlägget <a href="https://www.itsakerhetspodden.se/173-kaja-narum/">#173 &#8211; Kaja Narum</a> dök först upp på <a href="https://www.itsakerhetspodden.se">IT-säkerhetspodden</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="683" src="https://www.itsakerhetspodden.se/wp-content/uploads/2022/06/173_wide-1024x683.jpg" alt="Kaja Narum i bild med vår logga bredvid." class="wp-image-5379" srcset="https://www.itsakerhetspodden.se/wp-content/uploads/2022/06/173_wide-1024x683.jpg 1024w, https://www.itsakerhetspodden.se/wp-content/uploads/2022/06/173_wide-300x200.jpg 300w, https://www.itsakerhetspodden.se/wp-content/uploads/2022/06/173_wide-768x512.jpg 768w, https://www.itsakerhetspodden.se/wp-content/uploads/2022/06/173_wide-1536x1024.jpg 1536w, https://www.itsakerhetspodden.se/wp-content/uploads/2022/06/173_wide.jpg 1800w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption>Kaja Narum i IT-säkerhetspodden.</figcaption></figure>



<p class="wp-block-paragraph"><strong>Avsnittet</strong>: <a href="https://www.itsakerhetspodden.se/podcast/172/" target="_blank" rel="noreferrer noopener">173 &#8211; Kaja Narum</a><a href="https://www.itsakerhetspodden.se/podcast/142-metaverse-och-sakerhet/" target="_blank" rel="noreferrer noopener"><br></a><strong>Inspelat</strong>: 2022-06-09 (publicerat 2022-06-12)<br><strong>Deltagare</strong>: Mattias Jadesköld, <a href="https://erik.zalitis.se/" target="_blank" rel="noreferrer noopener">Erik Zalitis</a> och Kaja Narum.<br>Detta avsnitt är ett samarbete med Nordlo.</p>



<h2 class="wp-block-heading" id="h-lyssna-pa-avsnittet-kaja-narum">Lyssna på avsnittet  &#8211; Kaja Narum</h2>



<iframe title="Libsyn Player" style="border: none" src="//html5-player.libsyn.com/embed/episode/id/23385248/height/90/theme/custom/thumbnail/yes/direction/forward/render-playlist/no/custom-color/000000/" height="90" width="100%" scrolling="no"  allowfullscreen webkitallowfullscreen mozallowfullscreen oallowfullscreen msallowfullscreen></iframe>



<h2 class="wp-block-heading" id="h-medan-du-lyssnar-kaja-narum">Medan du lyssnar &#8211; Kaja Narum</h2>



<p class="wp-block-paragraph">I dagens avsnitt av IT-säkerhetspodden har vi Kaja Narum med oss i studion, som jobbar på IBM i rollen Security Service leader i Norra Europa. Nyligen släppte hon och hennes kollegor Threat intelligence rapporten X-Force.</p>



<p class="wp-block-paragraph">Denna identifierar de största hoten just nu. Det som kanske sticker i ögonen är det faktum att Kaja ser att Sveriges cyberförsvar har halkat efter vårt kära grannland. Så vad är det Norge gör rätt? Och hur kan vi i Sverige komma ikapp?</p>



<p class="wp-block-paragraph">Som vanligt är det snabba ryck. Jag fick veta att hon var försenad på grund av flyget, vilket inte borde förvåna någon givet kaoset just nu. Så det blev en intervju via länk, men det har vi gjort förut och vi kunde få igång allting i tid och utan problem ändå.</p>



<p class="wp-block-paragraph">Känslan är att Sverige och Norge har två helt olika sätt att tänka på cyberrisker. I Sverige sköter samma myndigheter sina uppgifter i kris- som i normal tid, medan Norge har ett nationellt cyberförsvar, vilket inte gäller oss. Men Kaja säger att hon känner till att vi är på väg att få en sådan organisation även här.</p>



<p class="wp-block-paragraph">Så varför räcker det inte med att MSB och cert.se hanterar situationen, enligt henne. Lyssna på intervjun, så kommer det klarna.</p>



<p class="wp-block-paragraph">Det är ett knepigt läge för hela Europa just nu och då är det helt klart en bra strategi att skapa ett bättre cyberförsvar för oss, medan Norge redan är där.</p>



<h2 class="wp-block-heading">Länkar – Kaja Narum</h2>



<ul class="wp-block-list"><li><a href="https://nordlo.com/" target="_blank" rel="noreferrer noopener sponsored nofollow">Nordlo</a></li><li><a href="https://www.linkedin.com/in/kajanarum/" target="_blank" rel="noreferrer noopener">Hennes LinkedIn-profil</a></li><li><a href="https://it-kanalen.se/tank-till-tank-nytt-tank-sakert/" target="_blank" rel="noreferrer noopener">Tidigare intervju med henne i IT-kanalen</a>.</li><li><a href="https://www.aktuellsakerhet.se/halla-dar-kaja-narum-head-of-ibm-security-nordics/" target="_blank" rel="noreferrer noopener">Tidigare intervju i Aktuell Säkerhet</a>.</li></ul>



<h2 class="wp-block-heading">Felaktigheter</h2>



<ul class="wp-block-list"><li>Inget att rapportera denna gång. Kommentera gärna om ni&nbsp;<s>inte håller med om</s>&nbsp;hittar fel i något vi sagt.</li></ul>
<p>Inlägget <a href="https://www.itsakerhetspodden.se/173-kaja-narum/">#173 &#8211; Kaja Narum</a> dök först upp på <a href="https://www.itsakerhetspodden.se">IT-säkerhetspodden</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.itsakerhetspodden.se/173-kaja-narum/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">5380</post-id>
		<media:thumbnail url="https://www.itsakerhetspodden.se/wp-content/uploads/2022/06/173_wide-150x150.jpg" />
		<media:content url="https://www.itsakerhetspodden.se/wp-content/uploads/2022/06/173_wide.jpg" medium="image">
			<media:title type="html">173_wide</media:title>
			<media:thumbnail url="https://www.itsakerhetspodden.se/wp-content/uploads/2022/06/173_wide-150x150.jpg" />
		</media:content>
	</item>
		<item>
		<title>#170 &#8211; Sig Security about the practical use of Threat Intelligence</title>
		<link>https://www.itsakerhetspodden.se/170-sig-security-about-the-practical-use-of-threat-intelligence/</link>
					<comments>https://www.itsakerhetspodden.se/170-sig-security-about-the-practical-use-of-threat-intelligence/#respond</comments>
		
		<dc:creator><![CDATA[Erik Zalitis]]></dc:creator>
		<pubDate>Sun, 22 May 2022 16:00:01 +0000</pubDate>
				<category><![CDATA[ShowNotes]]></category>
		<category><![CDATA[Christoffer Strömblad]]></category>
		<category><![CDATA[Erik Zalitis]]></category>
		<category><![CDATA[Jesper Olsen]]></category>
		<category><![CDATA[Palo Alto Networks]]></category>
		<category><![CDATA[SIG Security Shownotes]]></category>
		<category><![CDATA[Sponsrat]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<category><![CDATA[TrueSec]]></category>
		<guid isPermaLink="false">https://www.itsakerhetspodden.se/?p=5250</guid>

					<description><![CDATA[<p>Erik Zalitis, Jesper Olsen and Christoffer Strömblad talk about Threat intelligence - the capability to know yourself and the enemy. How do they work, how do you look to them and are you up to the task of being on the network at all.</p>
<p>It used to be a bit suspicious with security people quoting Sun Tzu, as it was more bravado than actual product. But here, and in this warlike state of business that is the Internet, it fits very well. We are in the middle of a coevolution between hackers and defenders.</p>
<p>Inlägget <a href="https://www.itsakerhetspodden.se/170-sig-security-about-the-practical-use-of-threat-intelligence/">#170 &#8211; Sig Security about the practical use of Threat Intelligence</a> dök först upp på <a href="https://www.itsakerhetspodden.se">IT-säkerhetspodden</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="683" src="https://www.itsakerhetspodden.se/wp-content/uploads/2022/05/170_wide-1024x683.jpg" alt="Threat intelligence illustreras av några mönster i grönt och IT-säkerhetspoddens och SIG Securitys logos." class="wp-image-5248" srcset="https://www.itsakerhetspodden.se/wp-content/uploads/2022/05/170_wide-1024x683.jpg 1024w, https://www.itsakerhetspodden.se/wp-content/uploads/2022/05/170_wide-300x200.jpg 300w, https://www.itsakerhetspodden.se/wp-content/uploads/2022/05/170_wide-768x512.jpg 768w, https://www.itsakerhetspodden.se/wp-content/uploads/2022/05/170_wide-1536x1024.jpg 1536w, https://www.itsakerhetspodden.se/wp-content/uploads/2022/05/170_wide.jpg 1800w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph"><strong>The episode: </strong><a href="https://www.itsakerhetspodden.se/podcast/170/" target="_blank" rel="noreferrer noopener">170 &#8211; Sig Security about the practical use of Threat Intelligence</a><a href="https://www.itsakerhetspodden.se/podcast/142-metaverse-och-sakerhet/" target="_blank" rel="noreferrer noopener"><br></a><strong>Recorded:</strong> 2022-05-17 (publicerat 2022-05-22)<br><strong>Participants: </strong><a href="https://erik.zalitis.se/" target="_blank" rel="noreferrer noopener">Erik Zalitis</a>, Jesper Olsen and Christoffer Strömblad<br>This episode is made in cooperation with SIG Security.</p>



<h2 class="wp-block-heading" id="h-listen-to-the-episode-now-threat-intelligence">Listen to the episode, now &#8211; Threat intelligence</h2>



<iframe title="Libsyn Player" style="border: none" src="//html5-player.libsyn.com/embed/episode/id/23128628/height/90/theme/custom/thumbnail/yes/direction/forward/render-playlist/no/custom-color/000000/" height="90" width="100%" scrolling="no" allowfullscreen="" webkitallowfullscreen="" mozallowfullscreen="" oallowfullscreen="" msallowfullscreen=""></iframe>



<h2 class="wp-block-heading" id="h-while-listening-to-this-episode-threat-intelligence">While listening to this episode &#8211; Threat intelligence</h2>



<p class="wp-block-paragraph">English, again? Yes. I thought it would make it easier to pull together with two Swedes and a Danish. I talk about nationalities here, not food, just pointing that out. Anyways, we have a old friend, Christoffer Strömblad, who was in this podcast in 2019 and a new one, Jesper Olsen. Christoffer has since left the Swedish Police and joined TrueSec, a Swedish IT-security focused company.</p>



<p class="wp-block-paragraph">Jesper is Danish and works for Palo Alto Network, a very welknown creator of security appliances.</p>



<h3 class="wp-block-heading">IT-admin, know thyself!</h3>



<p class="wp-block-paragraph">The subject is interesting, and simple goes:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow"><p>&#8221;If you know the enemy and know yourself, you need not fear the result of a hundred battles. If you know yourself but not the enemy, for every victory gained you will also suffer a defeat. If you know neither the enemy nor yourself, you will succumb in every battle.&#8221;</p></blockquote>



<p class="wp-block-paragraph">It used to be a bit suspicious with security people quoting Sun Tzu, as it was more bravado than actual product. But here, and in this warlike state of business that is the Internet, it fits very well. We are in the middle of a coevolution between hackers and defenders.</p>



<p class="wp-block-paragraph">Christoffer and Jesper talks about what the properties of common victims are and have three rules to go by to assess the situation:</p>



<ul class="wp-block-list"><li>Archetypes &#8211; who gets attacked?</li><li>Vulnerabilities &#8211; How to they get attacked?</li><li>Recognizance &#8211; How to they find you?</li></ul>



<p class="wp-block-paragraph">This may seem like the same discussion like it always was, and yes, to a certain point it is. But it&#8217;s 2022 and the methods they describe are pretty new as in &#8221;a new way of doing the same&#8221;. In the IT-security business, this counts. Brand new, never seen attacks are few. But new takes on old tricks, is what we see all the time as attackers try to remain in control. They crawl around our latest defences. Right now, TrueSec has seen an uptick in USB-drive attacks. Why? Listen to the podcast. It&#8217;s around 19 minutes into the show.</p>



<p class="wp-block-paragraph">But don&#8217;t worry, we also got a new development for you:</p>



<h3 class="wp-block-heading">Initial Access Brokers</h3>



<p class="wp-block-paragraph">At 20:57 I ask Jesper about IABs. That is hackers selling access to organizations instead of data. As the business of hacking matures, it gets more specialized as I wryly note. This is at least new for me and the big development is not how something appears for the first time. Rather when it becomes a thing. You can&#8217;t go full hipster and say &#8221;I knew about that attackvector before everyone did! Dude, like they sold out!&#8221;.</p>



<h3 class="wp-block-heading">Worse than the decease &#8211; the Therac 25</h3>



<p class="wp-block-paragraph">On or about 19:00 I mentiod an X-ray machine killing a patient. It was a device known as Therac-25 and had a bug that sometimes, very uncommonly delivered deadly doses of radiation. The software bug was eventually found, but it was nearly impossible to reproduce the conditions until you knew them. The device had multiple failsafe, but in the end, it did not matter. I&#8217;ll add a link in the bottom of this page, where you can read the story. But this qoute should scare you:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow"><p>What they found was shocking. The software appeared to have been written by a programmer with little experience coding for real-time systems. There were few comments, and no proof that any timing analysis had been performed. According to AECL, a single programmer had written the software based upon the Therac-6 and 20 code. However, this programmer no longer worked for the company, and could not be found.</p></blockquote>



<h2 class="wp-block-heading">Links –  Threat intelligence</h2>



<ul class="wp-block-list"><li><a href="https://nordlo.com/" target="_blank" rel="noreferrer noopener sponsored nofollow">Nordlo</a></li><li><a href="https://hackaday.com/2015/10/26/killed-by-a-machine-the-therac-25/" target="_blank" rel="noreferrer noopener">Killed by a machine &#8211; the Therac-25 incidents</a></li></ul>



<h2 class="wp-block-heading">Errors and omissions</h2>



<ul class="wp-block-list"><li>Nothing to report at this time.</li></ul>
<p>Inlägget <a href="https://www.itsakerhetspodden.se/170-sig-security-about-the-practical-use-of-threat-intelligence/">#170 &#8211; Sig Security about the practical use of Threat Intelligence</a> dök först upp på <a href="https://www.itsakerhetspodden.se">IT-säkerhetspodden</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.itsakerhetspodden.se/170-sig-security-about-the-practical-use-of-threat-intelligence/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">5250</post-id>
		<media:thumbnail url="https://www.itsakerhetspodden.se/wp-content/uploads/2022/05/170_wide-150x150.jpg" />
		<media:content url="https://www.itsakerhetspodden.se/wp-content/uploads/2022/05/170_wide.jpg" medium="image">
			<media:title type="html">170_wide</media:title>
			<media:thumbnail url="https://www.itsakerhetspodden.se/wp-content/uploads/2022/05/170_wide-150x150.jpg" />
		</media:content>
	</item>
	</channel>
</rss>
