The Cloud Pod

146: The Google CyberCAT is Out of the Bag


Listen Later

On The Cloud Pod this week, Oracle finally has some news to share. Plus Log4j is ruining everyone’s lives, AWS suffers a massive outage post re:Invent, and Google CAT releases its first threat report. 

A big thanks to this week’s sponsors:

  • Foghorn Consulting, which provides full-stack cloud solutions with a focus on strategy, planning and execution for enterprises seeking to take advantage of the transformative capabilities of AWS, Google Cloud and Azure.
    • JumpCloud, which offers a complete platform for identity, access, and device management — no matter where your users and devices are located. 
    • This week’s highlights
      • A critical vulnerability in Apache Log4j wrought havoc over the weekend. Cloud platforms and developers alike are racing to fix the bug, which gives hackers an opportunity to take control of systems remotely. 
      • On the heels of re:Invent, AWS suffered a major outage last Tuesday in its US-EAST-1 region, which had staggering repercussions across the cloud. 
      • Google Cybersecurity Action Team (CAT) releases its first Threat Horizons report, revealing its top three concerns threatening cloud users today.  
      • Top Quotes  

        • “It’s amazing how much of our infrastructure and applications live on these open source contributions of one or two people, and how critical they are to the entire ecosystem. And when they break or they’re vulnerable, it becomes a huge issue for us very quickly.”
        • “Think about what Microsoft did: They started signing device drivers and signing applications that run in Windows, and everyone thought Oh, they’re just exerting control, what a terrible idea. They’re just trying to corner the market. And now, of course, 15 years later, binding authorization is probably the most critical next step in securing the cloud.”
        • General News: The Log4j Vulnerability is COVID for Tech
          • In light of the critical Apache Log4j 2.0 vulnerability that gives attackers the ability to to execute arbitrary code on other systems, AWS has released a hotpatch for the logging platform. The aim is to help developers mitigate risk as they work to update their systems to 2.15 or newer. 
          • VentureBeat reminds us that while the Log4j debacle is bad, at least organizations now have tools and processes in place to respond quickly to zero-day bugs. 
          • GCP has released a set of recommendations for those who are investigating and responding to the Log4j 2.0 vulnerability. 
          • To help customers detect whether their systems have been compromised by the Log4j bug, Google has updated its IDS signature to automatically scan for any Log4j exploit attempts. 
          • Google creates a new Web Application Firewall (WAF) rule to detect and block Log4j exploit attempts by attackers. 
          • AWS: What Better Way to Follow Up re:Invent Than With a Giant Outage?
            • On the Tuesday after re:Inv
            • ...more
              View all episodesView all episodes
              Download on the App Store

              The Cloud PodBy Justin Brodley, Jonathan Baker, Ryan Lucas and Matthew Kohn

              • 4.9
              • 4.9
              • 4.9
              • 4.9
              • 4.9

              4.9

              33 ratings


              More shows like The Cloud Pod

              View all
              Software Engineering Radio - the podcast for professional software developers by se-radio@computer.org

              Software Engineering Radio - the podcast for professional software developers

              272 Listeners

              Risky Business by Patrick Gray

              Risky Business

              360 Listeners

              SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

              SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

              627 Listeners

              The Changelog: Software Development, Open Source by Changelog Media

              The Changelog: Software Development, Open Source

              283 Listeners

              Freakonomics Radio by Freakonomics Radio + Stitcher

              Freakonomics Radio

              32,212 Listeners

              Heavy Networking by Packet Pushers

              Heavy Networking

              325 Listeners

              The Cloudcast by Massive Studios

              The Cloudcast

              153 Listeners

              The Vergecast by The Verge

              The Vergecast

              3,667 Listeners

              LINUX Unplugged by Jupiter Broadcasting

              LINUX Unplugged

              265 Listeners

              Software Engineering Daily by Software Engineering Daily

              Software Engineering Daily

              624 Listeners

              AWS Podcast by Amazon Web Services

              AWS Podcast

              202 Listeners

              Kubernetes Podcast from Google by Abdel Sghiouar, Kaslin Fields

              Kubernetes Podcast from Google

              181 Listeners

              The Stack Overflow Podcast by The Stack Overflow Podcast

              The Stack Overflow Podcast

              63 Listeners

              Hard Fork by The New York Times

              Hard Fork

              5,420 Listeners

              Oxide and Friends by Oxide Computer Company

              Oxide and Friends

              47 Listeners