Lock and Code

If only you had to worry about malware, with Jason Haddix


Listen Later

If your IT and security teams think malware is bad, wait until they learn about everything else.

In 2024, the modern cyberattack is a segmented, prolonged, and professional effort, in which specialists create strictly financial alliances to plant malware on unsuspecting employees, steal corporate credentials, slip into business networks, and, for a period of days if not weeks, simply sit and watch and test and prod, escalating their privileges while refraining from installing any noisy hacking tools that could be flagged by detection-based antivirus scans.

In fact, some attacks have gone so "quiet" that they involve no malware at all. Last year, some ransomware gangs refrained from deploying ransomware in their own attacks, opting to steal sensitive data and then threaten to publish it online if their victims refused to pay up—a method of extracting a ransom that is entirely without ransomware.

Understandably, security teams are outflanked. Defending against sophisticated, multifaceted attacks takes resources, technologies, and human expertise. But not every organization has that at hand.

What, then, are IT-constrained businesses to do?

Today, on the Lock and Code podcast with host David Ruiz, we speak with Jason Haddix, the former Chief Information Security Officer at the videogame developer Ubisoft, about how he and his colleagues from other companies faced off against modern adversaries who, during a prolonged crime spree, plundered employee credentials from the dark web, subverted corporate 2FA protections, and leaned heavily on internal web access to steal sensitive documentation.

Haddix, who launched his own cybersecurity training and consulting firm Arcanum Information Security this year, said he learned so much during his time at Ubisoft that he and his peers in the industry coined a new, humorous term for attacks that abuse internet-connected platforms: "A browser and a dream."

"When you first hear that, you're like, 'Okay, what could a browser give you inside of an organization?'"

But Haddix made it clear:

"On the internal LAN, you have knowledge bases like SharePoint, Confluence, MediaWiki. You have dev and project management sites like Trello, local Jira, local Redmine. You have source code managers, which are managed via websites—Git, GitHub, GitLab, Bitbucket, Subversion. You have repo management, build servers, dev platforms, configuration, management platforms, operations, front ends. These are all websites."

Tune in today.

You can also find us on Apple PodcastsSpotify, and whatever preferred podcast platform you use.

For all our cybersecurity coverage, visit Malwarebytes Labs at malwarebytes.com/blog.

Show notes and credits:

Intro Music: “Spellbound” by Kevin MacLeod (incompetech.com)

Licensed under Creative Commons: By Attribution 4.0 License

http://creativecommons.org/licenses/by/4.0/

Outro Music: “Good God” by Wowa (unminus.com)

LLM Prompt Injection Game: https://gandalf.lakera.ai/

Overwhelmed by modern cyberthreats? ThreatDown can help.

The 2024 ThreatDown State of Malware report is a comprehensive analysis of six pressing cyberthreats this year—including Big Game ransomware, Living Off The Land (LOTL) attacks, and malvertising—with strategies on how IT and security teams can protect against them.

Read the report here.

...more
View all episodesView all episodes
Download on the App Store

Lock and CodeBy Malwarebytes

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

48 ratings


More shows like Lock and Code

View all
Freakonomics Radio by Freakonomics Radio + Stitcher

Freakonomics Radio

32,320 Listeners

Fresh Air by NPR

Fresh Air

38,605 Listeners

Marketplace by Marketplace

Marketplace

8,796 Listeners

On Point with Meghna Chakrabarti by WBUR

On Point with Meghna Chakrabarti

3,994 Listeners

WSJ Tech News Briefing by The Wall Street Journal

WSJ Tech News Briefing

1,653 Listeners

Science Friday by Science Friday and WNYC Studios

Science Friday

6,469 Listeners

Click Here by Recorded Future News

Click Here

421 Listeners

Stay Tuned with Preet by Preet Bharara

Stay Tuned with Preet

32,379 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,114 Listeners

Sean Carroll's Mindscape: Science, Society, Philosophy, Culture, Arts, and Ideas by Sean Carroll

Sean Carroll's Mindscape: Science, Society, Philosophy, Culture, Arts, and Ideas

4,195 Listeners

Unpacking Israeli History by Unpacked

Unpacking Israeli History

1,212 Listeners

Call Me Back - with Dan Senor by Ark Media, Ilan Benatar

Call Me Back - with Dan Senor

3,263 Listeners

On with Kara Swisher by Vox Media

On with Kara Swisher

3,480 Listeners

Main Justice by MS NOW, Andrew Weissmann, Mary McCord

Main Justice

7,078 Listeners

Ask Haviv Anything by Haviv Rettig Gur

Ask Haviv Anything

891 Listeners