DiscoverThe Gate 15 Podcast Channel
The Gate 15 Podcast Channel
Claim Ownership

The Gate 15 Podcast Channel

Author: Gate 15

Subscribed: 2Played: 13
Share

Description

The Gate 15 Company is a leader in helping organizations by providing threat-informed, risk-based approaches to analysis, preparedness and operations.
397 Episodes
Reverse
On this week's Security Sprint Dave and Andy covered the following topics:Opening:• 15 x 15 GRIP Alerts!!• 27th Annual TribalNet Conference & Tradeshow • Tribal-ISAC• CISA: 2026 Election Infrastructure Security Plan Main Topics:Terrorism and Targeted Violence (T2V) in the United States: Plots Targeting U.S. Schools — START — Sep 2026. The University of Maryland's START program examined 700 premeditated plots targeting U.S. school spaces between January 2023 and March 2026 using its Terrorism and Targeted Violence database. The research analyzes plot rates, locations, weapons, perpetrator intentions and outcomes, perpetrator ages, and the intersection between terrorism and school-based targeted violence. OpenAI Agent Hacked Australia’s Health Service. Their Government Found Out Months Later — WIRED — 24 Sep 2026. An OpenAI agent conducting research on publicly available medicine-spending data gained unauthorized access to a Services Australia Medicare statistics portal on 18 June after encountering restrictions and finding alternative methods to obtain the requested information. • Scoop: Top AI companies probing tens of thousands of security incidents — Axios • The Hugging Face incident and other third-party impact from misaligned models — OpenAI • OpenAI pauses training on some models, says agents targeted government sites • OpenAI agents tried to bruteforce a UN website's API fields • OpenAI's AI agents accidentally uploaded user-provided images to third-party sites • It was a matter of when, not if... — DIVD — 24 Sep 2026. The Dutch Institute for Vulnerability Disclosure reported that its own infrastructure was compromised and said the attack's modus operandi indicates what it believes may be an agentic AI-powered attack, while emphasizing that its forensic investigation remains ongoing. • Cyber Threat Report 2026: Leaders need to prepare now for the impact of AI — New Zealand National Cyber Security Centre — Sep 2026• Protect your organisation’s AI services — Australian Signals Directorate — Sep 2026. Quick Hits:• ENISA Threat Landscape 2026 — European Union Agency for Cybersecurity — 22 Sep 2026. ENISA’s annual threat assessment finds the European cyber environment increasingly shaped by interconnected threats, shared dependencies, geopolitical developments, and blurred boundaries among cybercrime, hacktivist, and state-linked activity. • ShinyHunters hackers say they breached Federal Bureau of Investigation, no immediate comment from FBI • FBI Statement on Compromise of fbijobs.gov Portal and Alleged Impact to FBI Employee PII• Military personnel data exposed in breach, agency warns • Gary Warner on LinkedIn: DMDC breach notification raises questions about notification timing and QR-code delivery • Special agents' blood and urine test results stolen in FBI hack • Russia! US-Based Digital Forensics Firm Hid its Russian Ownership from U.S. Government Customers • Russia! ‘United by chaos:’ Examining the Russian nexus to online networks of nihilistic violence • No Kings: Vote Early nationwide day of action planned for 17 October
On this week's Security Sprint, Dave and Andy covered the following topics:Opening:• CISA Hosts Cyber Storm X, Nationwide Cybersecurity Exercise to Strengthen Resilience — CISA — 18 Sep 2026. • New ASD Guidance: Network Segmentation & Segregation• UK NCSC: Don’t Assume Your Cyber Defenses Work. Test Them.• 27th Annual TribalNet Conference & Tradeshow Main Topics:Severe Weather’s Cascading Effects: Brutal heat, storms threaten football tailgates this weekend; This weekend's football tailgates face two threats: Extreme heat in the Southeast and rounds of rain and storms.• NWS: Thunderstorms and Heavy Rains in the Appalachians. Multiple rounds of moderate to locally heavy rain will impact portions of the Appalachians and Mid-Atlantic, which may lead to flash flooding concerns. • Rare September nor’easter could bring rain, wind and waves to East Coast Russia! Russia Fabricates Celebrity Attacks on Democrats as Midterms Approach — NewsGuard Reality Check — 18 Sep 2026. NewsGuard reports that a Russian influence campaign targeting the 2026 U.S. midterm elections is using manipulated celebrity content and fabricated news reports to attack Democratic candidates and amplify divisive social issues. • 'The rules have changed': has Russia begun to order assassinations on US soil? • Russia Escalates its External Operations Against the United States — The Soufan Center — 18 Sep 2026. • Russian hybrid attacks against Europe intensifying, says Macron • European Parliament adopts new report on foreign information manipulation and interference Russia Boosts the German Far Right — Again • Russia? Suspected sabotage causes major Netherlands rail disruption • Russia? Train derailment in France injures 44, police suspect sabotage North Korean "WaterPlum," commonly referred to as “Contagious Interview,” cyber actor group targeting IT professionals — Australian Signals Directorate’s Australian Cyber Security Centre — 18 Sep 2026. A multinational advisory warns that North Korean WaterPlum actors are targeting software developers and other IT professionals through fraudulent recruitment, technical interviews, and coding assignments designed to deliver malware and steal credentials, sensitive information, and cryptocurrency. • 98% of fraudulent hires have company credentials by the time they’re caught Scammers Impersonating Law Enforcement and Government Officials in Fraud Schemes — FBI Internet Crime Complaint Center — 17 Sep 2026. The FBI reiterated its warning about widespread scams in which criminals impersonate U.S. or foreign law enforcement and government officials to obtain money or personally identifiable information. Quick Hits:• Using Cyber Decoys to Strengthen Detection and Response — CISA — 16 Sep 2026. CISA released guidance to help organizations plan and implement cyber decoys to improve detection of adversaries using legitimate credentials, native tools, and living-off-the-land techniques. • Network segmentation and segregation – Overview — Australian Signals Directorate — 17 Sep 2026. 15 from 15 connection:• Network segmentation and segregation – Anti-patterns — Australian Signals Directorate — 17 Sep 2026. • Best practices for setting up a SOC (ITSAP.00.500) — Canadian Centre for Cyber Security — Sep 2026. • Cyber Adversary Simulation (CyAS): scheme documents now available — UK National Cyber Security Centre — 17 Sep 2026.
On this week's Security Sprint, Dave and Andy covered the following topics:Opening:• 15 from 15: Blocking and Tackling Cybersecurity & Resilience — Gate 15 — 09 Sep 2026. Gate 15 released 15 from 15: Cybersecurity Mitigation & Resilience Fundamentals, emphasizing that rapidly evolving threats, artificial intelligence, ransomware, exploited vulnerabilities and nation-state activity do not eliminate the importance of consistently executing foundational security practices. The framework identifies 15 practical areas to help organizations “get a little better every day.” • What the FBI Phishing Warning Means for Event Planners — Skift Meetings — 08 Sep 2026. Gate 15 Vice President and Chief Resilience Officer Ben Taylor contributes perspective.• (TLP:CLEAR) WaterISAC – EPA: National Security Information Sharing Bulletin – Q3 2026 — WaterISAC — 10 Sep 2026• Cyberattacks on food and agriculture can turn disruptions into safety crises, threatening public health and supply chains — Industrial Cyber — 08 Sep 2026• 27th Annual TribalNet Conference & Tradeshow Main Topics:FBI cyber chief worries private sector not sharing enough cyber threat information — CyberScoop — 09 Sep 2026. FBI Cyber Division Assistant Director Brett Leatherman said private-sector organizations are still not sharing enough cyber information with the Bureau, in part because some companies incorrectly believe information provided during an incident will be passed to regulators for regulatory purposes. FBI Cyber Strategy — FBI — 09 Sep 2026. The FBI released its first agency-wide unclassified cyber strategy, organizing its approach around disrupting and imposing costs on adversaries, supporting victims, increasing impact through partnerships and strengthening internal cyber capabilities. China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies — CISA — 08 Sep 2026. CISA, NSA and the FBI warn that China-based AI companies are conducting industrial-scale campaigns to systematically extract proprietary capabilities from U.S. frontier AI models, describing malicious knowledge distillation as a core component rather than merely a supplement to their AI development strategies. Insider Threat Mitigation Guide — CISA — 09 Sep 2026. During National Insider Threat Awareness Month, CISA is again highlighting its Insider Threat Mitigation Guide and related resources for organizations building or improving insider-risk programs.Quick Hits:• Congratulations! You Just Lived Through the Hottest Month Ever Recorded — WIRED — 10 Sep 2026. • NSA Highlights Cyber Hygiene Best Practices Effective Against AI-Enhanced Targeting — National Security Agency — 03 Sep 2026• Gateway security guidance package: Overview — Australian Signals Directorate’s Australian Cyber Security Centre — updated 04 Sep 2026• The hidden risks of shadow AI — UK National Cyber Security Centre — 07 Sep 2026• Iran hackers: Dissatisfaction with AT&T services drove decision to target telecom in Texas • Iran hackers, after denial of Texas AT&T claim: ‘Idiots don’t even know what we tampered with’ • Iran hackers claim Texas AT&T outage, vow to ‘intensify’ attacks before 9/11
In this episode of The Gate 15 Interview, Andy Jabbour speaks with Adam Gruszcynski. Responsible for the day-to-day operations of the IT Department for Potawatomi Casino Hotel while ensuring all of the technology needs, whether current orfuture, of the organization are met. Adam joined Potawatomi Casino Hotel in 2008. During his time at PCH, Adam has gained an abundance of experience by taking on various roles including IT Security Manager, Senior Cybersecurity Engineer, Lead Network Administrator, Network Administrator, and ApplicationAdministrator. Prior to PCH, Adam was Network Engineer at the Milwaukee Journal Sentinel where he began his career as Help Desk Intern. In the podcast, Adam and Andy discuss: Adam’s background and his path to his current roleTribal infrastructure and sovereignty Managing and mitigating risks, investing in peopleResilienceTribal-ISAC and some of the great things ISACs do!Celebrating people, building teamsAdam’s adviceWe play Three Questions and go deep on pro wrestling!
On this week's Security Sprint, Dave and Andy covered the following topics:Opening:• Celebrating 5 Years of the Tribal-ISAC: Mid-Year Executive Director Update — TribalHub • FB-ISAO Newsletter, v8, Issue 8 — Faith-Based ISAO • AI/Vishing: The Voice Is Not the Control — Crypto ISAC • National Insider Threat Awareness Month: Protect Our PotentialMain Topics:Iran hackers: Minnesota ‘warning’ ignored, ‘critical events’ to hit 3 U.S. infrastructure sectors — Threat Beat — 31 Aug 2026. APT IRAN, which has claimed responsibility alongside CyberAv3ngers for recent attacks affecting U.S. municipal water systems, issued a new threat against multiple U.S. critical infrastructure sectors as military tensions with Iran continue. The group characterized its earlier Minnesota activity as a warning and has previously claimed the ability to affect electricity, telecommunications, and water infrastructure, although adversary claims regarding access and capabilities should not be accepted without independent verification. A Tale of Two SOCs: Insights From Two Red Team Assessments — CISA — 25 Aug 2026. CISA released findings from simultaneous red-team assessments of organizations in the Government Services and Facilities Sector and the Water and Wastewater Systems Sector. Both organizations experienced successful initial compromise, but the government organization failed to detect or effectively contain subsequent activity while water-sector defenders quickly identified compromised systems and isolated them. CISA attributed the differing outcomes in part to alert noise, organizational silos, cloud-security weaknesses, and differences in how defenders were empowered to respond. Institutional Wilful Blindness, NCSC Cyber Series — NCSC Cyber Series — 2026. The first installment of a two-part discussion examines why organizations can understand that cyber risks exist yet still fail to take meaningful action before incidents occur. Leadership expert Margaret Heffernan, Professor Genevieve Liveley of the Research Institute for Sociotechnical Cyber Security, and an NCSC social sciences leader discuss how organizational culture, leadership behavior, communication, and the narratives used to describe cybersecurity can create a gap between awareness and action. The discussion emphasizes that resilience depends on more than technical controls and requires leaders to challenge complacency, communicate uncertainty effectively, and create environments where uncomfortable risk information can influence decisions. Quick Hits:• Insights into Suspected DPRK Workers: Red Flags to Look Out For — Huntress • The Who and How of Ten Years of Russian Disinformation — NewsGuard
loading
Comments