Crying Out Cloud

#8 - GameOverlay โ€“ privilege escalation vulnerabilities in Ubuntu


Listen Later

๐Ÿฟ๐Ÿค Everything you need to know about this month's cloud security drama in the latest "Crying Out Cloud" episode!

In this edition, we explore THREE captivating stories ๐Ÿ“š๐Ÿ”
1๏ธโƒฃ "GameOverlay" unveiled: Ubuntu's privilege escalation vulnerabilities ๐Ÿ˜ฑ โ€” Wiz Research uncovered a pair of vulnerabilities that's affecting 40% of Ubuntu cloud machines! We've got the scoop on what you must know.
2๏ธโƒฃ Unmasking "P2PInfect": The botnet targeting Redis! ๐Ÿค– โ€” Ever wondered how a botnet hijacks your exposed Redis instances? Let's get into the nitty-gritty of this attack and find out how to defend your environment.
3๏ธโƒฃ Jumpcloud's dance with North Korea: A supply chain saga ๐Ÿ•Š๏ธ -โ€”Join us as we uncover the tale of Jumpcloud's breach and its uncanny link to North Korea. Dive deep into the investigation with us.


Important links:

1. https://www.wiz.io/blog/ubuntu-overlayfs-vulnerability
2. https://ubuntu.com/security/CVE-2023-2640
3. https://ubuntu.com/security/CVE-2023-32629
4. https://www.cadosecurity.com/redis-p2pinfect/
5. https://unit42.paloaltonetworks.com/peer-to-peer-worm-p2pinfect/
6. https://www.mandiant.com/resources/blog/north-korea-supply-chain
7. https://www.sentinelone.com/labs/jumpcloud-intrusion-attacker-infrastructure-links-compromise-to-north-korean-apt-activity/
8. https://jumpcloud.com/blog/security-update-incident-details
9. https://jumpcloud.com/support/july-2023-iocs
10. https://github.blog/2023-07-18-security-alert-social-engineering-campaign-targets-technology-industry-employees/
11. https://blog.phylum.io/sophisticated-ongoing-attack-discovered-on-npm/

...more
View all episodesView all episodes
Download on the App Store

Crying Out CloudBy Wiz

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

21 ratings


More shows like Crying Out Cloud

View all
This American Life by This American Life

This American Life

91,297 Listeners

Hidden Brain by Hidden Brain, Shankar Vedantam

Hidden Brain

43,687 Listeners

Risky Business by Risky Business Media

Risky Business

371 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

651 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

The Daily by The New York Times

The Daily

113,121 Listeners

Screaming in the Cloud by Corey Quinn

Screaming in the Cloud

92 Listeners

Hacking Humans by N2K Networks

Hacking Humans

315 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

195 Listeners

Practical AI by Practical AI LLC

Practical AI

212 Listeners

Three Buddy Problem by Security Conversations

Three Buddy Problem

61 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

45 Listeners

Prof G Markets by Vox Media Podcast Network

Prof G Markets

1,480 Listeners