Federal Tech Podcast:  for innovators, entrepreneurs, and CEOs who want to increase reach and improve brand awareness

Ep. 34 Weaponized Files and Federal Security


Listen Later

In today's interview, Darin Curtis from Menlo Security gives an overview of how to protect against these kinds of threats. To describe this new category, he uses a curious acronym HEAT, Highly Evasive Adaptive Threats.

Malicious actors leave no stone unturned in creative ways to attack federal technology. We all know that the perimeter has been breached and we must rely on Zero Trust Architecture.

The next level of attack is to attack the word "trust" itself.

Traditionally, file formats like PDFs have been viewed as unbreakable. When most people get an email from a colleague with a PDF file, they would normally trust it. This is also true with Excel or Word documents that are transferred on a normal business day.

Today, these files can have malicious code injected into them.

Another approach is to take advantage of that "trust" in HTML code. Some malicious actors will disguise malware into HTML code, called HTML Smuggling. This time, instead of a PDF in an email, it may be an innocent link. This is made possible by HTML5's ability for download capability.

During the interview, Darrin reinforces the concept that compliance does not ensure an agency is secure. Some studies show ransomware is one of the biggest single threats to government networks; the delivery mechanism can include these HEAT files.

If this interview piques your interest in Menlo Security, then you can download the free report titled "Modernizing Secure Access Through Zero Trust"

...more
View all episodesView all episodes
Download on the App Store

Federal Tech Podcast:  for innovators, entrepreneurs, and CEOs who want to increase reach and improve brand awarenessBy John Gilroy

  • 5
  • 5
  • 5
  • 5
  • 5

5

6 ratings


More shows like Federal Tech Podcast: for innovators, entrepreneurs, and CEOs who want to increase reach and improve brand awareness

View all
Global News Podcast by BBC World Service

Global News Podcast

7,728 Listeners

Tech Talks Daily by Neil C. Hughes

Tech Talks Daily

198 Listeners

The Daily by The New York Times

The Daily

112,574 Listeners

Practical AI by Practical AI LLC

Practical AI

212 Listeners

This Day in AI Podcast by Michael Sharkey, Chris Sharkey

This Day in AI Podcast

209 Listeners

The AI Daily Brief: Artificial Intelligence News and Analysis by Nathaniel Whittemore

The AI Daily Brief: Artificial Intelligence News and Analysis

586 Listeners