Privacy, Remote access

EMOTET Disrupted, “Ghost” Hackers, & Why Privacy is ‘Like Bubblewrap’ – PSW #681

In the Security News, why privacy is like bubble wrap, South African government releases its own browser just to re-enable flash support, former Lulzsec hacker releases VPN zero-day used to hack hacking team, how a researcher broke into Microsoft VS code’s Github, & how criminals use a deceased employee’s account to wreak havoc!

Full episode and show notes

Announcements

  • Don't miss any of your favorite Security Weekly content! Visit https://securityweekly.com/subscribe to subscribe to any of our podcast feeds and have all new episodes downloaded right to your phone! You can also join our mailing list, Discord server, and follow us on social media & our streaming platforms!

  • If you missed Security Weekly Unlocked, you can now access all of the content on-demand, whether you registered before the live event or not, by visiting https://securityweekly.com/unlocked and clicking either the button to register or the button to login!

Hosts

Paul Asadoorian
Paul Asadoorian
Founder at Security Weekly
  1. 1. Stack Overflow 2019 hack was guided by advice from none other than… Stack Overflow - It's called "hacking" for a reason (we're not experts in ALL software LOL): ''the attacker successfully logged into the StackOverflow development environment, using a crafted login request that bypassed access controls, and then successfully escalated privileges. They then got access to TeamCity, the JetBrains continuous integration product...Although not having secrets in source code seems like a no-brainer, developers sometimes find this hard to avoid How does TeamCity work? “The attacker is clearly not overly familiar with the product so they spend time looking up Q&A on Stack Overflow on how to use and configure it"
  2. 2. Ghost hack – criminals use deceased employee’s account to wreak havoc - We go after accounts when people are on vacation, and apparently permanent vacation too: "The account of the late employee wasn’t shut down because various internal services had been configured to use it, presumably because the deceased had been involved in setting up those services in the first place. Closing down the account, we assume, would have stopped those services working, so keeping the account going was probably the most convenient way of letting the dead person’s work live on."
  3. 3. From zero to your first Penetration Test - Best advice in this article is here: "You have to make sacrifices, you have to put in the hard work and the grind, to become a good Penetration Tester. Practice, practice, and practice! Sometimes, it will be hard to see all of your friends partying and feeling good on Social Media, while you are staying home, trying to crack that HackTheBox machine, practicing for OSCP or learning about SQL Injections, but remember how worth it will be in the end. Think about the long-term."
  4. 4. Nvidia Squashes High-Severity Jetson DoS Flaw
  5. 5. Maritime port cybersecurity
  6. 6. Remote Attackers Can Now Reach Protected Network Devices via NAT Slipstreaming
  7. 7. For Microsoft, cybersecurity has become bigger than business – CyberScoop
  8. 8. Sudo Heap-Based Buffer Overflow – Exploitalert
  9. 9. TikTok vulnerability left users’ private information exposed
  10. 10. Why Privacy Is Like Bubble Wrap - A really long article that takes its time to get to this mediocre point: "In a sense, we should think of privacy not as something that resides in an individual, but something that surrounds them. This is where the bubble wrap metaphor comes in - a layer that’s transparent enough to allow you to be seen but also a protection against harmful intrusion. The more bubble wrap, the more protection, but also the greater the degree of constriction: sure I can bubble wrap my experience online (no cookies, no tracking, ProtonMail account, etc) but it’s going to be a slower, more plodding experience, which has its own costs."
  11. 11. TeamTNT group adds new detection evasion tool to its Linux miner
  12. 12. Microsoft releases Application Guard for Office to M365 customers
  13. 13. Crypto Tools like Signal and Bitcoin Don’t Harm Democracy. They Help It - https://flip.it/wU3y34
  14. 14. South African government releases its own browser just to re-enable Flash support - "The South African Revenue Service has released this week its own custom web browser for the sole purpose of re-enabling Adobe Flash Player support, rather than port its existing website from using Flash to HTML-based web forms."
  15. 15. New campaign targeting security researchers
  16. 16. Former LulzSec Hacker Releases VPN Zero-Day Used to Hack Hacking Team - So, not an 0day: "This story and its headline have been updated to clarify that this exploit was not a zero-day, as SonicWall had patched it."
  17. 17. Oracle WebLogic Server 14.1.1.0 Remote Code Execution ? Packet Storm
  18. 18. Hacker leaks data of 2.28 million dating site users
  19. 19. SonicWall firewall maker hacked using zero-day in its VPN device
  20. 20. SonicWall says it was hacked using zero-days in its own products - https://flip.it/4RCDFm
  21. 21. Phishing scam had all the bells and whistles—except for one
  22. 22. Nmap project becomes latest victim of Google’s ‘wrongful blocking’ of cybersecurity resources - This is the best way to fix this problem, but unfortunately it's not available to everyone: "The tweet was fired to 130,000 followers and an associate at Google Security spotted the message. The issue was then personally escalated, although the developer added that others may have seen the tweet and helped, too."
  23. 23. Here’s how a researcher broke into Microsoft VS Code’s GitHub - I believe this is the real vulnerability: "Since actions/checkout was executed in the step before the vulnerable workflow file is used, there was a GitHub token with write permission to the repository. So I made a plan to use this token"
  24. 24. Oracle WebLogic Server 14.1.1.0 Remote Code Execution ? Packet Storm
Jeff Man
Jeff Man
Information Security Evangelist at Online Business Systems
Tyler Robinson
Tyler Robinson
Director of Offensive Security & Research at Trimarc Security, Founder & CEO at Dark Element
prestitial ad