The Cyber Exposure Podcast

Foxy Zero Days and MSSP Misery


Listen Later

In this episode, Bill and Gavin talk about a Firefox Zero Day, organizations facing bankruptcy due to ransomware, and MSSP's as an attack vector and C&C Slack. They are also joined by Matt Everson and Justin Brown from Tenable Research team. 

  1. Breaches costing real money.
    1. https://krebsonsecurity.com/2019/06/collections-firm-behind-labcorp-quest-breaches-files-for-bankruptcy/
  2. Paying Ransom & other fees
    1. https://nypost.com/2019/06/20/florida-city-pays-hackers-600k-in-bitcoin-to-get-computer-systems-back/
    2. https://www.youtube.com/watch?v=wQjR3NWXqgk
    3. https://www.helpnetsecurity.com/2019/06/24/eurofins-ransomware-attack/
  3. Firefox has a 0-day
    1. https://objective-see.com/blog/blog_0x43.html
    2. CVE-2019-11707
  4. Help software is the vulnerability
    1. https://safebreach.com/Post/OEM-Software-Puts-Multiple-Laptops-At-Risk
  5. Slack - is more than useful
    1. https://www.coalfire.com/The-Coalfire-Blog/June-2019/Introducing-Slackor
    2. https://www.tenable.com/blog/slack-patches-download-hijack-vulnerability-in-windows-desktop-app
  6. Gangs attacking MSSPs
    1. https://www.informationsecuritybuzz.com/expert-comments/hacker-gang-deploys-ransomware-on-customer-systems-by-hacking-msps/


...more
View all episodesView all episodes
Download on the App Store

The Cyber Exposure PodcastBy Tenable