Research Saturday

Research Saturday

By N2K NetworksNewsTechnologyTech News
Download on the App Store

Research Saturday episodes

  • New exploits are tricking Chrome.

    Dor Zvi, Co-Founder and CEO from Red Access to discuss their work on "New Chrome Exploit Lets Attackers Completely Disable Browser Extensions." A recently patched exploit is tricking Chrome browsers on all popular OSs to not only give attackers visibility of their targets’ browser extensions, but also the ability to disable all of those extensions.

    The research states the exploit consists of a bookmarklet exploit that allows threat actors to selectively force-disable Chrome extensions using a handy graphical user interface making Chrome mistakenly identify it as a legitimate request from the Chrome Web Store.

    The research can be found here:

    • New Chrome Exploit Lets Attackers Completely Disable Browser Extensions

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    16 min
  • The next hot AI scam.

    Andy Patel from WithSecure Labs joins with Dave to discuss their study that demonstrates how GPT-3 can be misused through malicious and creative prompt engineering. The research looks at how this technology, GPT-3 and GPT-3.5, can be used to trick users into scams.

    GPT-3 is a user-friendly tool that employs autoregressive language to generate versatile natural language text using a small amount of input that could inevitably interest cybercriminals. The research is looking for possible malpractice from this tool, such as phishing content, social opposition, social validation, style transfer, opinion transfer, prompt creation, and fake news.

    The research can be found here:

    • Creatively malicious prompt engineering

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    26 min
  • Implementing and achieving security resilience.

    Wendy Nather from Cisco sits down with Dave to discuss their work on "Cracking the Code to Security Resilience: Lessons from the Latest Cisco Security Outcomes Report." The report describes what security resilience is, while also going over how companies can achieve this resilience.

    Wendy talks through some of the key findings based off of the report, and after surveying 4,751 active information security and privacy professionals from 26 countries, we find out some of the top priorities to achieving security resilience. From there the research goes on to explain from the findings which data-backed practices lead to the outcomes that can be implemented in cybersecurity strategies.

    The research can be found here:

    • Cracking the Code to Security Resilience: Lessons from the Latest Cisco Security Outcomes Report
    • Achieving Security Resilience
    • Learn more about your ad choices. Visit megaphone.fm/adchoices

      21 min
    • Knocking down the legs of the industrial security triad.

      Pascal Ackerman, OT Security Strategist from Guidepoint Security, joins Dave to discuss his work on discovering a vulnerability in the integrity of common HMI client-server protocol. This research is a Proof of Concept (PoC) attack on the integrity of data flowing across the industrial network with the intention of intercepting, viewing, and even manipulating values sent to (and from) the HMI, ultimately trying to trick the user into making a wrong decision, ultimately affecting the proper operation of the process.

      In this research, they are targeting Rockwell Automation’s FactoryTalk View SE products, trying to highlight the lack of integrity and confidentiality on the production network and the effect that has on the overall security of the production environment.

      The research can be found here:

      • GuidePoint Security researcher discovers vulnerability in the integrity of common HMI client-server protocol

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      20 min
    • Can ransomware turn machines against us?

      Tom Bonner and Eoin Wickens from HiddenLayer's SAI Team to discuss their research on weaponizing machine learning models with ransomware. Researchers at HiddenLayer’s SAI Team have developed a proof-of-concept attack for surreptitiously deploying malware, such as ransomware or Cobalt Strike Beacon, via machine learning models.

      The attack uses a technique currently undetected by many cybersecurity vendors and can serve as a launchpad for lateral movement, deployment of additional malware, or the theft of highly sensitive data. In this research the team raising awareness by demonstrate how easily an adversary can deploy malware through a pre-trained ML model.

      The research can be found here:

      • WEAPONIZING MACHINE LEARNING MODELS WITH RANSOMWARE

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      19 min
    • Flagging firmware vulnerabilities.

      Roya Gordon from Nozomi Networks sits down with Dave to discuss their research on "Vulnerabilities in BMC Firmware Affect OT/IoT Device Security." Researchers at Nozomi Networks has revealed that there are thirteen vulnerabilities that affect BMCs of Lanner devices based on the American Megatrends (AMI) MegaRAC SP-X.

      The research states "By abusing these vulnerabilities, an unauthenticated attacker may achieve Remote Code Execution (RCE) with root privileges on the BMC, completely compromising it and gaining control of the managed host." As well as mentioning what patches could be in the future to help fix these vulnerabilities.

      The research can be found here:

      • Vulnerabilities in BMC Firmware Affect OT/IoT Device Security – Part 1

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      16 min
    • Billbug infests government agencies.

      Brigid O. Gorman from Symantec's Threat Hunter Team joins Dave to discuss their report "Billbug - State-sponsored Actor Targets Cert Authority and Government Agencies in Multiple Asian Countries." The team has discovered that state-sponsored actors compromised a digital certificate authority in an Asian country during a campaign in which multiple government agencies were also targeted.

      The research states they believe Billbug, which is a long-established advanced persistent threat (APT) group has been active since about 2009. They say "In activity documented by Symantec in 2019, we detailed how the group was using a backdoor known as Hannotog (Backdoor.Hannotog) and another backdoor known as Sagerunex (Backdoor.Sagerunex). Both these tools were also seen in this more recent activity."

      The research can be found here:

      • Billbug: State-sponsored Actor Targets Cert Authority, Government Agencies in Multiple Asian Countries

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      15 min
    • DUCKTAIL waddles back again.

      Mohammad Kazem Hassan Nejad from WithSecure joins Dave to discuss the team’s research, “DUCKTAIL returns - Underneath the ruffled feathers.” DUCKTAIL is a financially motivated malware operation that targets individuals and businesses operating on the Facebook Ads and Business platform.

      The research states “The malware is designed to steal browser cookies and take advantage of authenticated Facebook sessions to steal information from the victim's Facebook account.” WithSecure has found that after a short hiatus, DUCKTAIL has returned with slight changes in their mode of operation.

      The research can be found here:

      • DUCKTAIL returns: Underneath the ruffled feathers

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      22 min
    • Stealer malware from Russia.

      Marisa Atkinson, an analyst from Flashpoint, joins Dave to discuss a new blog post from Flashpoint’s research team about “RisePro” Stealer, malware from Russia, and Pay-Per-Install Malware “PrivateLoader.” “RisePro” is written in C++ and appears to possess similar functionality to the stealer malware “Vidar.” It's also a newly identified stealer, that began appearing as a stealer source for log credentials on the illicit log shop Russian Market on December 13, 2022.

      The research states, "Samples that Flashpoint analysts identified indicate that RisePro may have been dropped or downloaded by the pay-per-install malware downloader service “PrivateLoader” in the past year." Analysts identified several sets of logs uploaded to the illicit underground Russian Market, which listed their source as “RisePro.”

      The research can be found here:

      • “RisePro” Stealer and Pay-Per-Install Malware “PrivateLoader”

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      18 min
    • Encore: LemonDucks evading detection.

      Scott Fanning from CrowdStrike's research team, joins Dave to discuss their work on "LemonDuck Targets Docker for Cryptomining Operations." LemonDuck is a well-known cryptomining botnet, and the research suggests attackers are attracted to the monetary gain from the recent boom in cryptocurrency.

      LemonDuck was caught trying to disguise its attack against Docker by running an anonymous mining operation by the use of proxy pools. Scott shares how its unknown which organizations have been targeted and just how much cryptocurrency has been stolen.

      The research can be found here:

      • LemonDuck Targets Docker for Cryptomining Operations

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      16 min

    About Research Saturday

    From the publisher's feed

    Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.

    More shows like Research Saturday

    Risky Business by Risky Business Media

    Risky Business

    375 Listeners

    CyberWire Daily by N2K Networks

    CyberWire Daily

    1,028 Listeners

    ChinaPower by CSIS | Center for Strategic and International Studies

    ChinaPower

    206 Listeners

    Smashing Security by Graham Cluley

    Smashing Security

    317 Listeners

    Click Here by Recorded Future News

    Click Here

    420 Listeners

    Darknet Diaries by Jack Rhysider

    Darknet Diaries

    8,058 Listeners

    Cybersecurity Today by David Shipley

    Cybersecurity Today

    179 Listeners

    Hacking Humans by N2K Networks

    Hacking Humans

    314 Listeners

    CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

    CISO Series Podcast

    191 Listeners

    Career Notes by N2K Networks

    Career Notes

    14 Listeners

    Pekingology by Center for Strategic and International Studies

    Pekingology

    141 Listeners

    Cybersecurity Headlines by CISO Series

    Cybersecurity Headlines

    138 Listeners

    The AI Fix by Mark Stockley

    The AI Fix

    32 Listeners

    The FAIK Files by Perry Carpenter | N2K Networks

    The FAIK Files

    18 Listeners