In this episode, Bill and Gavin talk about a Firefox Zero Day, organizations facing bankruptcy due to ransomware, and MSSP's as an attack vector and C&C Slack. They are also joined by Matt Everson and Justin Brown from Tenable Research team.
- Breaches costing real money.
- https://krebsonsecurity.com/2019/06/collections-firm-behind-labcorp-quest-breaches-files-for-bankruptcy/
- Paying Ransom & other fees
- https://nypost.com/2019/06/20/florida-city-pays-hackers-600k-in-bitcoin-to-get-computer-systems-back/
- https://www.youtube.com/watch?v=wQjR3NWXqgk
- https://www.helpnetsecurity.com/2019/06/24/eurofins-ransomware-attack/
- Firefox has a 0-day
- https://objective-see.com/blog/blog_0x43.html
- CVE-2019-11707
- Help software is the vulnerability
- https://safebreach.com/Post/OEM-Software-Puts-Multiple-Laptops-At-Risk
- Slack - is more than useful
- https://www.coalfire.com/The-Coalfire-Blog/June-2019/Introducing-Slackor
- https://www.tenable.com/blog/slack-patches-download-hijack-vulnerability-in-windows-desktop-app
- Gangs attacking MSSPs
- https://www.informationsecuritybuzz.com/expert-comments/hacker-gang-deploys-ransomware-on-customer-systems-by-hacking-msps/