{"version":1,"type":"rich","provider_name":"Libsyn","provider_url":"https:\/\/www.libsyn.com","height":90,"width":600,"title":"Boston Scientific Can't Ship a Single Box, and Nobody Will Officially Say Why","description":"A friend of Jim's at Boston Scientific told him the company has come to a complete stop: nothing shipping, nothing receiving, product sitting in the warehouse untouched. Nobody at the company would say who's behind it. Craig's read: this fits a pattern he's now seeing constantly, with both Russia and Iran running AI-assisted attacks against U.S. contractors \u2014 including military suppliers whose cybersecurity, despite the assumption, is often not what it should be. Craig had his own live example from the day before. A client \u2014 a parts distributor supplying components that end up in military equipment \u2014 had his phone light up twice with a prompt: was he trying to log into the company VPN right now? He said no both times, so Craig's team immediately invalidated the password. Tracing the login attempt, what first looked like a New York data center turned out, on closer inspection, to be a narrow slash-24 address block registered all the way back to Hong Kong. The attacker already had the username and password; the multi-factor prompt was the only thing that stopped them. Running the client's email through the free tool Have I Been Pwned turned up his username, email and password already circulating on the dark web. Craig's practical advice, twice over: run your own email through haveibeenpwned.com now, for free, and if you're still relying on your browser's built-in password manager, move to a dedicated one like 1Password \u2014 browser managers have been breached before, even if none currently are. Also in this segment:  An extended, opinionated exchange about Canadian tax policy, media coverage of the U.S.-Canada trade dispute, and Canadian broadcaster CBC \u2014 flagged below for Craig's review before publishing The running bit about Craig's citizenship (&quot;blue card,&quot; not a green one \u2014 a joke Jim initially bought) and his trip to Montreal this weekend to help his mother Windows Update's blind spot on print servers, which Craig says is now driving active attacks on law firms, schools and manufacturers, covered in that week's newsletter  Free newsletter and Insider Session announcements: CraigPeterson.com ","author_name":"Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity","author_url":"https:\/\/cptt.libsyn.com\/podcast","html":"<iframe title=\"Libsyn Player\" style=\"border: none\" src=\"\/\/html5-player.libsyn.com\/embed\/episode\/id\/42934157\/height\/90\/theme\/custom\/thumbnail\/yes\/direction\/forward\/render-playlist\/no\/custom-color\/88AA3C\/\" height=\"90\" width=\"600\" scrolling=\"no\"  allowfullscreen webkitallowfullscreen mozallowfullscreen oallowfullscreen msallowfullscreen><\/iframe>","thumbnail_url":"https:\/\/assets.libsyn.com\/secure\/item\/42934157"}