Research Saturday

Research Saturday

By N2K NetworksNewsTechnologyTech News
Download on the App Store

Research Saturday episodes

  • The Chameleon attacks Online Social Networks.

    The Chameleon attack technique is a new type of OSN-based trickery where malicious posts and profiles change the way they are displayed to OSN users to conceal themselves before the attack or avoid detection. Joining us to discuss their findings in a new report entitled "The Chameleon Attack: Manipulating Content Display in Online Social Media" is Ben-Gurion University's Rami Puzis. 

    The research can be found here:

    The Chameleon Attack: Manipulating Content Display in Online Social Media

    Demonstration video of a Chameleon Attack

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    19 min
  • Tracking one of China's hidden hacking groups.

    Operation Wocao (我操, “Wǒ cāo”, is a Chinese curse word) is the name that Fox-IT uses to describe the hacking activities of a Chinese based hacking group.

    We are joined by Fox-IT's Maarten van Dantzig who shares his insights into their new report entitled "Operation Wocao: Shining a light on one of China’s hidden hacking groups".

    The Research can be found here:



    Operation Wocao: Shining a light on one of China’s hidden hacking groups

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    20 min
  • Know Thine Enemy - Identifying North American Cyber Threats.

    The electric utility industry is a valuable target for adversaries seeking to exploit industrial control systems (ICS) and operations technology (OT) for a variety of purposes. As adversaries and their sponsors invest more effort and money into obtaining effects-focused capabilities, the risk of a disruptive or destructive attack on the electric sector significantly increases.

    Selena Larson from Dragos joins us to discuss their new report North American Electric Cyber Threat Perspective.

    The report can be found here:

    North American Electric Cyber Threat Perspective

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    29 min
  • Clever breaches demonstrate IoT security gaps.

    Some of our favorite and most trusted IoT devices help make us feel secure in our homes. From garage door openers to the locks on our front doors, we trust these devices to recognize and alert us when people are entering our home. It should come as no surprise that these too are subject to attack. 

    Steve Povolny is head of advanced research at McAfee; we discuss a pair of research projects they recently published involving popular IoT devices. 

    The research can be found here:

    McAfee Advanced Threat Research demo McLear NFC Ring

    McAfee Advanced Threat Research Demo Chamberlain MyQ

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    24 min
  • Profiling the Linken Sphere anti-detection browser.

    Multiple e-commerce and financial organizations around the world are targeted by cybercriminals attempting to bypass or disable their security mechanisms, in some cases by using tools that imitate the activities of legitimate users. Linken Sphere, an anti-detection browser, is one of the most popular tools of this kind at the moment.

    Staffan Truvé is the CTO and Co-Founder of Recorded Future, he joins us to discuss their new report on the browser. 

    The research can be found here:

    Profiling the Linken Sphere Anti-Detection Browser

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    14 min
  • A Jira vulnerability that’s leaking data in the public cloud.

    Unit 42 (the Palo Alto Networks threat intelligence team) released new research on a Jira vulnerability that’s leaking data of technology, industrial and media organizations in the public cloud. The vulnerability (a Server Side Request Forgery -- SSRF) is the same type that led to the Capital One data breach in July 2019.

    Jen Miller-Osborn is the Deputy Director of Threat Intelligence for Unit 42 at Palo Alto Networks, and she joins us to share their findings.

    The research can be found here:

    https://unit42.paloaltonetworks.com/server-side-request-forgery-exposes-data-of-technology-industrial-and-media-organizations/

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    17 min
  • Inside Magecart and Genesis.

    Dan Woods is VP of the intelligence center and Shape Security. He shares insights on two noteworthy attacks tools, Genesis and Magecart. Before joining Shape Security Dan served as assistant chief agent of special investigations at the Arizona attorney general's office, where he investigated complex fraud. Prior to that, he spent 20 years with federal law enforcement agencies and intelligence organizations, including the CIA and FBI, where he specialized in information operations and cybercrime.

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    21 min
  • WAV files carry malicious data payloads.

    Researchers at BlackBerry Cylance have been tracking ordinary WAV audio files being used to carry hidden malicious data used by threat actors. 

    Eric Milam is VP of threat research and intelligence at BlackBerry Cylance, and he joins us to share their findings.

    The research can be found here:

    https://threatvector.cylance.com/en_us/home/malicious-payloads-hiding-beneath-the-wav.html

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    20 min
  • Targeting routers to hit gaming servers.

    Researchers at Palo Alto Networks' Unit 42 recently published research outlining attacks on home and small-business routers, taking advantage of known vulnerabilities to make the routers parts of botnets, ultimately used to attack gaming servers.

    Jen Miller-Osborn is the Deputy Director of Threat Intelligence for Unit 42 at Palo Alto Networks. She joins us to share their findings.

    The research can be found here:

    https://unit42.paloaltonetworks.com/home-small-office-wireless-routers-exploited-to-attack-gaming-servers/

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    19 min
  • Mustang Panda leverages Windows shortcut files.

    Researchers at Anomali have been tracking China-based threat group, Mustang Panda, believing them to be responsible for attacks making clever use of Windows shortcut files. 

    Parthiban is a researcher at Anomali, and he joins us to share their findings.

    The research is here:

    https://www.anomali.com/blog/china-based-apt-mustang-panda-targets-minority-groups-public-and-private-sector-organizations

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    15 min

About Research Saturday

From the publisher's feed

Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.

More shows like Research Saturday

Risky Business by Risky Business Media

Risky Business

374 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

ChinaPower by CSIS | Center for Strategic and International Studies

ChinaPower

206 Listeners

Smashing Security by Graham Cluley

Smashing Security

317 Listeners

Click Here by Recorded Future News

Click Here

419 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,055 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

191 Listeners

Career Notes by N2K Networks

Career Notes

14 Listeners

Pekingology by Center for Strategic and International Studies

Pekingology

141 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

The AI Fix by Mark Stockley

The AI Fix

32 Listeners

The FAIK Files by Perry Carpenter | N2K Networks

The FAIK Files

18 Listeners