Crying Out Cloud

#8 - GameOverlay โ€“ privilege escalation vulnerabilities in Ubuntu


Listen Later

๐Ÿฟ๐Ÿค Everything you need to know about this month's cloud security drama in the latest "Crying Out Cloud" episode!

In this edition, we explore THREE captivating stories ๐Ÿ“š๐Ÿ”
1๏ธโƒฃ "GameOverlay" unveiled: Ubuntu's privilege escalation vulnerabilities ๐Ÿ˜ฑ โ€” Wiz Research uncovered a pair of vulnerabilities that's affecting 40% of Ubuntu cloud machines! We've got the scoop on what you must know.
2๏ธโƒฃ Unmasking "P2PInfect": The botnet targeting Redis! ๐Ÿค– โ€” Ever wondered how a botnet hijacks your exposed Redis instances? Let's get into the nitty-gritty of this attack and find out how to defend your environment.
3๏ธโƒฃ Jumpcloud's dance with North Korea: A supply chain saga ๐Ÿ•Š๏ธ -โ€”Join us as we uncover the tale of Jumpcloud's breach and its uncanny link to North Korea. Dive deep into the investigation with us.


Important links:

1. https://www.wiz.io/blog/ubuntu-overlayfs-vulnerability
2. https://ubuntu.com/security/CVE-2023-2640
3. https://ubuntu.com/security/CVE-2023-32629
4. https://www.cadosecurity.com/redis-p2pinfect/
5. https://unit42.paloaltonetworks.com/peer-to-peer-worm-p2pinfect/
6. https://www.mandiant.com/resources/blog/north-korea-supply-chain
7. https://www.sentinelone.com/labs/jumpcloud-intrusion-attacker-infrastructure-links-compromise-to-north-korean-apt-activity/
8. https://jumpcloud.com/blog/security-update-incident-details
9. https://jumpcloud.com/support/july-2023-iocs
10. https://github.blog/2023-07-18-security-alert-social-engineering-campaign-targets-technology-industry-employees/
11. https://blog.phylum.io/sophisticated-ongoing-attack-discovered-on-npm/

...more
View all episodesView all episodes
Download on the App Store

Crying Out CloudBy Wiz

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

21 ratings


More shows like Crying Out Cloud

View all
This American Life by This American Life

This American Life

90,963 Listeners

Hidden Brain by Hidden Brain, Shankar Vedantam

Hidden Brain

43,594 Listeners

Risky Business by Risky Business Media

Risky Business

376 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

649 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,026 Listeners

The Daily by The New York Times

The Daily

112,191 Listeners

Screaming in the Cloud by Corey Quinn

Screaming in the Cloud

92 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

192 Listeners

Practical AI by Practical AI LLC

Practical AI

213 Listeners

Three Buddy Problem by Security Conversations

Three Buddy Problem

61 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

45 Listeners

Prof G Markets by Vox Media Podcast Network

Prof G Markets

1,486 Listeners