Three Buddy Problem

Cisco firewall zero-days and bootkits in the wild


Listen Later

Three Buddy Problem - Episode 65: We zero in on one of the biggest security stories of the year: the discovery of a persistent multi-stage bootkit implanting malware on Cisco ASA firewalls. Details on a new campaign, tied to the same threat actors behind ArcaneDoor, exploiting zero-days in Cisco’s 5500-X series appliances, devices that sit at the heart of government and enterprise networks worldwide.

Plus, Cisco’s controversial handling of these disclosures, CISA's emergency deadlines for patching, the absence of IOCs and samples, and China’s long-term positioning. Plus, thoughts on the Secret Service SIM farm discovery in New York and evidence of Russians APTs Turla and Gamaredon collaborating to hit Ukraine targets.

Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.

Links:

  • Transcript (unedited, AI-generated)
  • Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors
  • Mandiant Brickstorm Scanner
  • Cisco advisory: Continued Attacks Against Cisco Firewalls
  • NCSC report on Cisco ASA bootkit in the wild
  • U.S. government scrambles to stop new hacking campaign blamed on China
  • US Secret Service Statement on SIM Farm Discovery
  • NYTimes: Cache of Devices Capable of Crashing Cell Network Is Found Near U.N.
  • Airport chaos: Ransomware hits airport check-in systems
  • NCSC statement: Incident impacting Collins Aerospace
  • Gamaredon X Turla collab
...more
View all episodesView all episodes
Download on the App Store

Three Buddy ProblemBy Security Conversations

  • 4.9
  • 4.9
  • 4.9
  • 4.9
  • 4.9

4.9

61 ratings


More shows like Three Buddy Problem

View all
Hacked by Hacked

Hacked

185 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

370 Listeners

Risky Business by Patrick Gray

Risky Business

371 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

649 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Smashing Security by Graham Cluley

Smashing Security

320 Listeners

Click Here by Recorded Future News

Click Here

422 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,086 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

178 Listeners

Hacking Humans by N2K Networks

Hacking Humans

316 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

186 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

73 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

139 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

44 Listeners

The 404 Media Podcast by 404 Media

The 404 Media Podcast

389 Listeners