
Sign up to save your podcasts
Or


Researchers at McAfee's Advanced Threat Research Team recently published the results of their investigation into a popular VOIP system, where they discovered a well-know, decade-old vulnerability in open source software used on the platform.
Steve Povolny serves as the Head of Advanced Threat Research at McAfee, and he joins us to share their findings.
The original research can be found here:
https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/avaya-deskphone-decade-old-vulnerability-found-in-phones-firmware/
Learn more about your ad choices. Visit megaphone.fm/adchoices
The Emotet malware came on the scene in 2014 as a banking trojan and has since evolved in sophistication and shifted its business model. Researchers at Bromium have taken a detailed look at Emotet, and malware analyst Alex Holland joins us to share their findings.
The research can be found here:
https://www.google.com/url?q=https://www.bromium.com/resource/emotet-a-technical-analysis-of-the-destructive-polymorphic-malware
Learn more about your ad choices. Visit megaphone.fm/adchoices
Researchers at Distil Networks have been tracking online bots targeting ecommerce gift card systems of major online retailers. The threat actors show remarkable resourcefulness and adaptability. Jonathan Butler is technical account team manager at Distil Networks, part of Imperva, and he joins to share their findings.
The research can be found here:
https://resources.distilnetworks.com/all-blog-posts/giftghostbot-attacks-ecommerce-gift-card-systems
Learn more about your ad choices. Visit megaphone.fm/adchoices
Researchers from King’s College London, University of Bristol, Boston University, and University of Melbourne recently collaborated to publish a report titled, "Automatically Dismantling Online Dating Fraud." The research outlines techniques to analyze and identify fraudulent online dating profiles with a high degree of accuracy.
Professor Awais Rashid is one of the report's authors, and he joins us to share their findings.
The original research can be found here:
https://arxiv.org/pdf/1905.12593.pdf
Learn more about your ad choices. Visit megaphone.fm/adchoices
Researchers at Cisco's Talos Unit recently published research exploring the tactics, technics and procedures of the global malvertising ecosystem. Craig Williams is head of Talos Outreach at Cisco, and he guides us through the life cycle of malicious online ads, along with tips for protecting yourself and your organization.
The research can be found here:
https://blog.talosintelligence.com/2019/07/malvertising-deepdive.html
Learn more about your ad choices. Visit megaphone.fm/adchoices
Researchers at Reversing Labs have been tracking malware hidden in software package manager repositories, and it's use as a supply chain attack vector. Robert Perica is a principal engineer at Reversing Labs, and he joins us to share their findings.
The research can be found here:
https://blog.reversinglabs.com/blog/suppy-chain-malware-detecting-malware-in-package-manager-repositories
Learn more about your ad choices. Visit megaphone.fm/adchoices
Researchers at bot mitigation firm White Ops have been tracking fraudulent apps in the Google Play store. These apps often imitate legitimate apps, even going so far as to lift code directly from them, but instead of providing true functionality they harvest user data and send it back to command and control servers.
Marcelle Lee is a principal threat intel researcher at White Ops, and she shares their findings.
The original research can be found here —
https://www.whiteops.com/blog/another-day-another-fraudulent-app
Learn more about your ad choices. Visit megaphone.fm/adchoices
Researchers at Guardicore Labs have been tracking an unusual cryptominer that seems to be based in China and is targeting Windows MS-SQL and phpMyAdmin servers. Some elements of the exploit make use of sophisticated components previously associated with nation-state actors.
Ophir Harpaz and Daniel Goldberg are members of the Guardicore Labs team, and they join us to explain their findings.
The research can be found here -
https://www.guardicore.com/2019/05/nansh0u-campaign-hackers-arsenal-grows-stronger/
Learn more about your ad choices. Visit megaphone.fm/adchoices
Researchers at Netscout's ASERT Team have been tracking the growth of botnets originating in Egypt and targeting routers in South Africa. The payload is a variant of the Hakai DDoS bot.
Richard Hummel is threat intelligence manager at Netscout, and he joins us to share their findings.
The original research is here:
https://www.netscout.com/blog/asert/realtek-sdk-exploits-rise-egypt
Learn more about your ad choices. Visit megaphone.fm/adchoices
Synopsys recently published the 2019 edition of their Open Source Security and Risk Analysis (OSSRA) Report, providing an in-depth look at the state of open source security, compliance, and code quality risk in commercial software.
Tim Mackey is principal security strategist within the Synopsys Cyber Research Center, and he joins us to share their findings.
The research can be found here:
https://www.synopsys.com/software-integrity/resources/analyst-reports/2019-open-source-security-risk-analysis.html
Learn more about your ad choices. Visit megaphone.fm/adchoices
From the publisher's feed

374 Listeners

1,028 Listeners

206 Listeners

317 Listeners

419 Listeners

8,055 Listeners

179 Listeners

314 Listeners

191 Listeners

14 Listeners

141 Listeners

138 Listeners

32 Listeners

18 Listeners