This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Le monde selon Cyber Citoyen et PolySécure

Download resources

About this session

A live taping of the eighth collaboration between the Cyber Citoyen and PolySecure podcasts, recorded in front of an in-person and online GoSec audience, with an unnamed host and co-host Catherine covering roughly ninety minutes of recent cyber news and running commentary. They open on an extortion coalition of ransomware and data-theft groups that reportedly obtained Google-related data through a third-party Salesforce breach and is demanding the firing of specific researchers rather than a ransom, then widen out to the broader Salesforce supply-chain breach and how a weak third-party vendor, not end users, became the failure point exposing many large customers' data. A long stretch covers UK and US online age-verification laws, which the hosts argue are technologically clumsy and privacy-invasive, contrasting them with lower-tech, less invasive identity-check ideas. The second half turns to misinformation and conspiracy theories: why premature information sharing fuels speculation, how the extortion coalition itself may already be fracturing along the lines of political coalitions like MAGA, and how a post-truth environment leaves people unsatisfied by official answers regardless of their accuracy, illustrated with the Epstein case as an example of a story that keeps generating theories.

Cyber Citoyen et PolySécure vous donnent rendez-vous pour leur 8e collaboration, cette fois-ci en direct devant public au GoSec ! Fidèles à leurs habitudes, nos animateurs vont explorer les dernières actualités cyber, débusquer quelques théories conspirationnistes et aborder les sujets qui font débat. Et comme toujours, attendez-vous à quelques "rants" passionnés ! Rejoignez-nous en virtuel ou en présentiel ! Que vous suiviez les échanges depuis chez vous ou que vous soyez sur place, vous pourrez participer à l'expérience. Les participants en présentiel auront la chance de poser leurs questions directement, d'enrichir le débat avec leurs perspectives et d'interagir en temps réel avec nos animateurs. Pour les plus prudents d'entre vous, le chapeau d'aluminium reste optionnel ! 😉

Key takeaways

  • Treat third-party and supply-chain vendors as a primary breach risk; the Salesforce-linked incident exposed many large customers because a weaker third party, not end users, was compromised.
  • Expect extortion tactics to keep evolving beyond ransom demands toward targeted, personal pressure such as demanding named employees be fired.
  • Weigh online age-verification proposals against their privacy cost; measures that strip encryption or require invasive identity checks can be disproportionate to the harm they target.
  • Resist publishing unverified details during a breaking incident; premature information sharing creates a vacuum that speculation and conspiracy theories fill.
  • Watch for fracture lines inside threat-actor coalitions the same way you would in political ones; alliances built on convenience rarely hold under pressure.

Resources

Tags

More from GoSec 2025

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.