Research Saturday

Research Saturday

By N2K NetworksNewsTechnologyTech News
Download on the App Store

Research Saturday episodes

  • Sodinokibi aka REvil connections to GandCrab.

    Researchers at McAfee's Advanced Threat Research Team have been analyzing Sodinokibi ransomware as a service, also known as REvil. John Fokker is head of cyber investigations for McAfee Advanced Threat Research, and he joins us to share their findings.

    The research is here:

    https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us/

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    20 min
  • Monitoring the growing sophistication of PKPLUG.

    Researchers from Palo Alto Networks' Unit 42 have been tracking a Chinese cyber espionage group they've named PKPLUG. The group mainly targets victims in the Southeast Asia region. Ryan Olson is VP of threat intelligence at Palo Alto Networks, and he joins us to share their findings.

    The original research is here:

    https://unit42.paloaltonetworks.com/pkplug_chinese_cyber_espionage_group_attacking_asia/

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    24 min
  • Usable security is a delicate balance.

    Until recently, usability was often an afterthought when developing security tools. These days there's growing realization that usability is a fundamental part of security. Lorrie Cranor is director of the CyLab Usable Privacy and Security lab (CUPS) at Carnegie Mellon University. She shares the work she's been doing with her colleagues and students to improve security through usability.

    The research can be found here:

    https://www.cylab.cmu.edu/news/2019/07/29-usability-history.html

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    21 min
  • Masad Steals via Social Media.

    Researchers at Juniper Networks have been tracking a trojan they call Masad Stealer, which uses the Telegram instant messaging platform for part it its command and control infrastructure. (Telegram wasn't hacked; it's the innocent conduit.) Mounir Hahad is head of Juniper Threat Labs at Juniper Networks and he joins us to share their findings

    The original research is here:

    https://forums.juniper.net/t5/Threat-Research/Masad-Stealer-Exfiltrating-using-Telegram/ba-p/468559

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    21 min
  • Hoping for SOHO security.

    Researchers at Independent Security Evaluators (ISE) recently published a report titled SOHOpelessly Broken 2.0, Security Vulnerabilities in Network Accessible Services. This publication continues and expands previous work they did examining small office/home office (SOHO) routers, network-attached storage devices (NAS), and IP cameras. 

    Shaun Mirani is a security analyst at ISE, and he joins us to share their findings. 


    The original research is here:

    https://www.ise.io/whitepaper/sohopelessly-broken-2/

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    18 min
  • Decrypting ransomware for good.

    Michael Gillespie is a programmer at Emsisoft, as well as a host of the popular ID Ransomware web site that helps victims identify what strain of ransomware they may have been infected with, and what decryptors may be available. He's written many decryptors himself, most recently for the Syrk strain of ransomware. 

    Links to the research and Michael's work:

    https://blog.emsisoft.com/en/33885/emsisoft-releases-a-free-decryptor-for-the-syrk-ransomware/

    https://id-ransomware.malwarehunterteam.com/

    https://www.youtube.com/user/Demonslay335

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    23 min
  • The fuzzy boundaries of APT41.

    Researchers at FireEye recently released a report detailing the activities of APT41, a Chinese cyber threat group notable for the range of tools they use, their origins in the world of video gaming, and their willingness to shift from seemingly state-sponsored activity to hacking for personal gain. 

    Nalani Fraser and Fred Plan contributed to the report, and they join us to share their findings.

    The original research is here:

    https://www.fireeye.com/blog/threat-research/2019/08/apt41-dual-espionage-and-cyber-crime-operation.html

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    26 min
  • Focusing on Autumn Aperture.

    Researchers at Prevalion have been tracking a malware campaign making use of antiquated file formats and social engineering to target specific groups. 


    Danny Adamitis and Elizabeth Wharton are coauthors of the report, and they join us to share their findings.

    The research can be found here:

    https://blog.prevailion.com/2019/09/autumn-aperture-report.html

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    21 min
  • Leaky guest networks and covert channels.

    Many users of inexpensive internet routers use guest network functionality to help secure their home networks. Researchers at Ben Gurion University have discovered methods for defeating these security measures. Dr. Yossi Oren joins us to share their findings.

    The original research is here:

    https://www.usenix.org/system/files/woot19-paper_ovadia.pdf

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    18 min
  • Bluetooth blues: KNOB attack explained.

    A team of researchers have published a report titled, "KNOB Attack.

    Key Negotiation of Bluetooth Attack: Breaking Bluetooth Security." The report outlines vulnerabilities in the Bluetooth standard, along with mitigations to prevent them. 

    Daniele Antonioli is from Singapore University of Technology and Design, and is one of the researchers studying KNOB. He joins us to share their findings.

    The research can be found here:

    https://knobattack.com

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    20 min

About Research Saturday

From the publisher's feed

Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.

More shows like Research Saturday

Risky Business by Risky Business Media

Risky Business

374 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

ChinaPower by CSIS | Center for Strategic and International Studies

ChinaPower

206 Listeners

Smashing Security by Graham Cluley

Smashing Security

317 Listeners

Click Here by Recorded Future News

Click Here

419 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,055 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

191 Listeners

Career Notes by N2K Networks

Career Notes

14 Listeners

Pekingology by Center for Strategic and International Studies

Pekingology

141 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

The AI Fix by Mark Stockley

The AI Fix

32 Listeners

The FAIK Files by Perry Carpenter | N2K Networks

The FAIK Files

18 Listeners