Research Saturday

Research Saturday

By N2K NetworksNewsTechnologyTech News
Download on the App Store

Research Saturday episodes

  • Encore: Vulnerabilities in IoT devices.

    Dr. May Wang, CTO of IoT Security at Palo Alto Networks, joins Dave Bittner to discuss their findings detailed in Unit 42's "Know Your Infusion Pump Vulnerabilities and Secure Your Healthcare Organization" research. Unit 42 recently set out to better understand how well hospitals and other healthcare providers are doing in securing smart infusion pumps, which are network-connected devices that deliver medications and fluids to patients. This topic is of critical concern because security lapses in these devices have the potential to put lives at risk or expose sensitive patient data.

    Unit 42's discovery of security gaps in three out of four infusion pumps that they reviewed highlights the need for the healthcare industry to redouble efforts to protect against known vulnerabilities, while diligently following best practices for infusion pumps and hospital networks. May walks us through Unit 42's work.

    The research can be found here:

    • Know Your Infusion Pump Vulnerabilities and Secure Your Healthcare Organization

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    23 min
  • Hijacking holiday spirit with phishing scams.

    Or Katz from Akamai sits down with Dave to discuss research on highly sophisticated phishing scams and how they are abusing holiday sentiment. This particular threat, most recently has focused on Halloween deals, enticing victims with the chance to win a free prize, including from Dick’s Sporting Goods or Tumi Backpacks. It then requests credit card details to cover the cost of shipment.

    From mid-September to the end of October 2022, Akamai's research were able uncover and track this threat. This kit mimics well known retail stores in hopes to hijack credit card information, feeding off of people's holiday spirit.

    The research can be found here:

    • Highly Sophisticated Phishing Scams Are Abusing Holiday Sentiment

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    20 min
  • Cybersecurity during the World Cup.

    AJ Nash from ZeroFox sits down with Dave to discuss Cybersecurity threats including social engineering attacks planned surrounding the Qatar 2022 World Cup. The research shares some of the key threats we might see while the World Cup is happening this year.

    Researchers say "During the World Cup, there will likely be threat actors aiming to acquire personal information or monetary value through phishing and scams." In the research we can find how the venue host is preparing for these claims of attacks.

    The research can be found here:

    • Qatar 2022 World Cup Event Assessment

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    26 min
  • Old malware returns in a new way.

    Jeremy Kennelly and Sulian Lebegue from Mandiant sit down with Dave to discuss their research "From RM3 to LDR4: URSNIF Leaves Banking Fraud Behind? One of the oldest and most successful banking fraud malwares, URSNIF, which caused an estimated “tens of millions of dollars in losses”, has been discovered by researchers to have been re-tooled into a generic backdoor, dubbed “LDR4”.

    This new variant was first observed in June 2022. Mandiant researchers believe that the same threat actors who operated the RM3 variant of URSNIF are likely behind LDR4. They say "given the success and sophistication RM3 previously had, LDR4 could be a significantly dangerous variant—capable of distributing ransomware—that should be watched closely."

    The research can be found here:

    • From RM3 to LDR4: URSNIF Leaves Banking Fraud Behind

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    25 min
  • Encore: The secrets behind Docker.

    Alon Zahavi from CyberArk, joins Dave Bittner on this episode to discuss CyberArk's work in conjunction with Patch Tuesday. CyberArk published about how Docker inadvertently created a new vulnerability and what happens when it's exploited.

    CyberArk's research concluded that an attacker may execute files with capabilities or setuid files in order to escalate its privileges up to root level. CyberArk found the new vuln in some of Microsoft’s Docker images, caused by misuse of Linux capabilities, a powerful additional layer of security that gives admins the ability to assign capabilities and privileges to processes and files in the Linux system

    The research can be found here:

    • How Docker Made Me More Capable and the Host Less Secure

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    21 min
  • Another infection with new malware.

    Larry Cashdollar, Principal Security Intelligence Response Engineer from Akamai Technologies, joins Dave to talk about their research on "KmsdBot: The Attack and Mine Malware." Akamai's Security Research team has found a new malware that infected their honeypot, which they have dubbed KmsdBot. 

    The research states "The malware attacks using UDP, TCP, HTTP POST, and GET, along with a command and control infrastructure (C2), which communicates over TCP." The botnet targets weak login credentials and then infects systems via an SSH connection.

    The research can be found here:

    • KmsdBot: The Attack and Mine Malware

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    20 min
  • An in-depth look on the Crytox ransomware family.

    Deepen Desai from Zscaler sits down with Dave to talk about the Crytox ransomware family. First observed in 2020, Crytox is a ransomware family consisting of several stages of encrypted code that has fallen under the radar compared to other ransomware families. While other groups normally use double extortion attacks where data is both encrypted and held for ransom, Crytox does not perform this way.

    The research says "The modus operandi of the group is to encrypt files on connected drives along with network drives, drop the uTox messenger application and then display a ransom note to the victim." It also shares how you may be compromised with this ransomware and goes through each stage in depth.

    The research can be found here:

    • Technical Analysis of Crytox Ransomware

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    14 min
  • Over-the-air 0-day vulnerabilities.

    Roya Gordon from Nozomi Networks sits down with Dave to discuss their work "UWB Real Time Locating Systems: How Secure Radio Communications May Fail in Practice." Ultra-wideband (UWB) is a rapidly-growing radio technology that, according to the UWB Alliance, is forecasted to drive sales volumes exceeding one billion devices annually by 2025.

    In an effort to strengthen the security of devices utilizing UWB, Nozomi Networks Labs conducted a security assessment of two popular UWB RTLS solutions available on the market. Their research reveals 0-day vulnerabilities and other weaknesses that, if exploited, could allow an attacker to gain full access to all sensitive location data exchanged over-the-air.

    The research can be found here:

    • UWB Real Time Locating Systems: How Secure Radio Communications May Fail in Practice

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    22 min
  • Bugs and working from home.

    Federico Kirschbaum from Faraday Security sits down with Dave to discuss their research on "A vulnerability in Realtek's SDK for eCos OS: pwning thousands of routers." The team at Faraday found a vulnerability that made it to DEFCON 30, labeling it high severity. With more and more people working from home for their companies, the research team went looking for where there may be vulnerabilities as employees are working from home.

    The research states that the team was "seeking and reporting security vulnerabilities in IoT devices, which led to the finding of an exploitable bug in a consumer-grade router popular in Argentina." They also stated in the research that it was escalating quickly and shares about how protecting home networks is important while working remotely.

    The research can be found here:

    • A vulnerability in Realtek´s SDK for eCos OS: pwning thousands of routers

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    28 min
  • New tools target governments in Middle East?

    Dick O'Brien from Symantec's Threat Hunter team sits down with Dave to discuss their work on "Witchetty - Group Uses Updated Toolset in Attacks on Governments in Middle East." Their research has found that the group known as Witchetty aka LookingFrog, has been progressively updating its toolset, including the new tool, backdoor Trojan (Backdoor.Stegmap) to launch malware attacks on targets in the Middle East and Africa.

    The research states "The attackers exploited the ProxyShell and ProxyLogon vulnerabilities to install web shells on public-facing servers before stealing credentials, moving laterally across networks, and installing malware on other computers. The researchers describe more on the new tool being used and why this new group is a threat.

    The research can be found here:

    • Witchetty: Group Uses Updated Toolset in Attacks on Governments in Middle East

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    18 min

About Research Saturday

From the publisher's feed

Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.

More shows like Research Saturday

Risky Business by Risky Business Media

Risky Business

375 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

ChinaPower by CSIS | Center for Strategic and International Studies

ChinaPower

206 Listeners

Smashing Security by Graham Cluley

Smashing Security

317 Listeners

Click Here by Recorded Future News

Click Here

420 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,058 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

191 Listeners

Career Notes by N2K Networks

Career Notes

14 Listeners

Pekingology by Center for Strategic and International Studies

Pekingology

141 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

The AI Fix by Mark Stockley

The AI Fix

32 Listeners

The FAIK Files by Perry Carpenter | N2K Networks

The FAIK Files

18 Listeners