Research Saturday

Research Saturday

By N2K NetworksNewsTechnologyTech News
Download on the App Store

Research Saturday episodes

  • Hackers come hopping back.

    Ori David from Akamai is sharing their research "Frog4Shell — FritzFrog Botnet Adds One-Days to Its Arsenal." FritzFrog takes advantage of the fact that only internet facing applications were prioritized for Log4Shell patching and targets internal hosts, meaning that a breach of any asset in the network by FritzFrog can expose unpatched internal assets to exploitation. 

    The research states "FritzFrog has traditionally hopped around by using SSH brute force, and has successfully compromised thousands of targets over the years as a result." Over the years Akamai has seen more than 20,000 FritzFrog attacks, and 1,500+ victims.

    The research can be found here:

    • Frog4Shell — FritzFrog Botnet Adds One-Days to Its Arsenal

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    19 min
  • Ransomware is coming.

    Jon DiMaggio, Chief Security Strategist for Analyst1, is discussing his research on "Ransomware Diaries Volume 4: Ransomed and Exposed - The Story of RansomedVC." While there is evidence to support that RansomedVC runs cybercrime operations, Jon questions the claims it made regarding the authenticity of the data it stole and the methods it used to extort victims.

    The research states "I uncovered sensitive information about the group's leader, Ransomed Support (also known as Impotent), relating to secrets from his past." In this episode John shares his 6 key findings after spending months engaging with the lead criminal who runs RansomedVC.

    The research can be found here:

    • Ransomware Diaries Volume 4: Ransomed and Exposed - The Story of RansomedVC

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    29 min
  • Weathering the internet storm.

    Johannes Ullrich from SANS talking about the Internet Storm Center and how they do research. Internet Storm Center was created as a mix of manual reports submitted by security analysts during Y2K and automated firewall collection started by DShield.

    The research shares how SANS used their "agile honeypots" to "zoom in" on events to more effectively collect data targeting specific vulnerabilities. Internet Storm Center has been noted on three separate attacks that were observed.

    The research can be found here:

    • Jenkins Brute Force Scans
    • Scans for Ivanti Connect "Secure" VPN Vulnerability (CVE-2023-46805, CVE-2024-21887)
    • Scans/Exploit Attempts for Atlassian Confluence RCE Vulnerability CVE-2023-22527
    • Learn more about your ad choices. Visit megaphone.fm/adchoices

      24 min
    • Hooked on pirated macOS applications.

      Jaron Bradley from Jamf Threat Labs is sharing their work on "Jamf Threat Labs discovers new malware embedded in pirated applications." Jamf Threat Labs has detected a series of pirated macOS applications that have been modified to communicate to attacker infrastructure.

      The research states "These applications are being hosted on Chinese pirating websites in order to gain victims." The discovery marks new and advanced malware, similar to the ZuRu malware, first discovered by Objective-See in 2021 within the iTerm2 application.

      The research can be found here:

      • Jamf Threat Labs discovers new malware embedded in pirated applications

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      21 min
    • A firewall wake up call.

      Jon Williams from Bishop Fox is sharing their research on "It’s 2024 and Over 178,000 SonicWall Firewalls are Publicly Exploitable." SonicWall published advisories for CVE-2022-22274 and CVE-2023-0656 a year apart after finding that NGFW series 6 and 7 devices are affected by two unauthenticated denial-of-service vulnerabilities.

      The research states "Our research found that the two issues are fundamentally the same but exploitable at different HTTP URI paths due to reuse of a vulnerable code pattern." They also found that when they scanned SonicWall firewalls with management interfaces exposed to the internet, they found that 76% are vulnerable to one or both issues.

      The research can be found here:

      • It’s 2024 and Over 178,000 SonicWall Firewalls are Publicly Exploitable

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      22 min
    • Dual Russian cyber gangs hit 23 companies.

      Ryan Westman, Senior Manager, Threat Intelligence, eSentire's Threat Response Unit (TRU), is discussing their research "Two Russian-speaking cyber gangs attack employees from 23 different companies." They are using malicious Google ads, promoting popular business software such as Zoom, Slack, and Adobe.

      The customers targeted are companies in the manufacturing, software, legal, retail and healthcare industries. The attacking threat actors belong to the Russian-speaking Malware-as-a-Service (MaaS) groups called BatLoader and FakeBat.

      The research can be found here:

      • Two Competing, Russian-Speaking Cybercrime Groups Attack Employees from 23 Companies in the Manufacturing, Software, Legal, Retail, and Healthcare Sectors Using Malicious Google Ads

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      17 min
    • Diving deep into Phobos ransomware.

      Guilherme Venere from Cisco Talos joins to discuss their research on "A deep dive into Phobos ransomware, recently deployed by 8Base group." Cisco Talos discovered that 8Base’s Phobos ransomware payload contains an embedded configuration, which is a significant difference between 8Base’s Phobos variant and other Phobos samples that have been observed in the wild since 2019. 

      In this 2-part research series, Talos conducts a deep dive into the Phobos ransomware, including its affiliate structure, activity and capabilities, as well as the one private key that could enable decryption of all the samples analyzed. 

      The research can be found here:




      • A deep dive into Phobos ransomware, recently deployed by 8Base group



      • Understanding the Phobos affiliate structure and activity



      • Learn more about your ad choices. Visit megaphone.fm/adchoices

        23 min
      • Encore: What malicious campaign is lurking under the surface?

        Israel Barak, CISO from Cybereason, sits down with Dave to discuss their research, "Operation CuckooBees: Cybereason Uncovers Massive Chinese Intellectual Property Theft Operation." Cybereason researchers recently found an attack lurking beneath the surface which was assessed to be the work of Chinese APT Winnti. Cybereason briefed the FBI and the DOJ on the investigation into the malicious campaign.

        The research states, "For years, the campaign had operated undetected, siphoning intellectual property and sensitive data." The team quickly made two reports on the campaign, one sharing an examination on the tactics and techniques. The second gives a detailed analysis of the malware and exploits used.

        The research can be found here:

        • Operation CuckooBees: Cybereason Uncovers Massive Chinese Intellectual Property Theft Operation

        Learn more about your ad choices. Visit megaphone.fm/adchoices

        22 min
      • Encore: Compromised military tech?

        Dick O'Brien from Symantec's threat hunter team, joins Dave to discuss their work on "Stonefly: North Korea-linked spying operation continues to hit high-value targets." Stonefly specializes in mounting highly selective targeted attacks against targets that could yield intelligence to assist strategically important sectors.

        Symantec found that The attackers breached an engineering firm in February 2022, most likely by exploiting the Log4j vulnerability, Their research describes who these high value targets are and ways to prevent this malware from breaching any more companies as well as indications that you could be compromised.

        The research can be found here:

        • Stonefly: North Korea-linked Spying Operation Continues to Hit High-value Targets


        Learn more about your ad choices. Visit megaphone.fm/adchoices

        20 min
      • Shedding light on fighting Ursa.

        Host of the CyberWire Daily podcast segment Threat Vector, David Moulton sits down with Mike "Siko" Sikorski from Palo Alto Networks Unit 42 to discuss their research on "Fighting Ursa Aka APT28: Illuminating a Covert Campaign."

        Unit 42 just published new threat intelligence on Fighting Ursa (aka APT28), a group associated with Russia's military intelligence, on how they are exploiting a Microsoft Outlook vulnerability (CVE-2023-23397) to target organizations in NATO member countries, Ukraine, Jordan, and the UAE. These organizations are of strategic importance in defense, foreign affairs, economy, energy, transportation, and telecommunications.

        The research can be found here:

        • Fighting Ursa Aka APT28: Illuminating a Covert Campaign

        Learn more about your ad choices. Visit megaphone.fm/adchoices

        21 min

      About Research Saturday

      From the publisher's feed

      Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.

      More shows like Research Saturday

      Risky Business by Risky Business Media

      Risky Business

      375 Listeners

      CyberWire Daily by N2K Networks

      CyberWire Daily

      1,028 Listeners

      ChinaPower by CSIS | Center for Strategic and International Studies

      ChinaPower

      206 Listeners

      Smashing Security by Graham Cluley

      Smashing Security

      317 Listeners

      Click Here by Recorded Future News

      Click Here

      420 Listeners

      Darknet Diaries by Jack Rhysider

      Darknet Diaries

      8,058 Listeners

      Cybersecurity Today by David Shipley

      Cybersecurity Today

      179 Listeners

      Hacking Humans by N2K Networks

      Hacking Humans

      314 Listeners

      CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

      CISO Series Podcast

      191 Listeners

      Career Notes by N2K Networks

      Career Notes

      14 Listeners

      Pekingology by Center for Strategic and International Studies

      Pekingology

      141 Listeners

      Cybersecurity Headlines by CISO Series

      Cybersecurity Headlines

      138 Listeners

      The AI Fix by Mark Stockley

      The AI Fix

      32 Listeners

      The FAIK Files by Perry Carpenter | N2K Networks

      The FAIK Files

      18 Listeners