Research Saturday

Research Saturday

By N2K NetworksNewsTechnologyTech News
Download on the App Store

Research Saturday episodes

  • VOIP phone system harbors decade-old vulnerability.

    Researchers at McAfee's Advanced Threat Research Team recently published the results of their investigation into a popular VOIP system, where they discovered a well-know, decade-old vulnerability in open source software used on the platform. 

    Steve Povolny serves as the Head of Advanced Threat Research at McAfee, and he joins us to share their findings.

    The original research can be found here:

    https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/avaya-deskphone-decade-old-vulnerability-found-in-phones-firmware/

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    29 min
  • Emotet's updated business model.

    The Emotet malware came on the scene in 2014 as a banking trojan and has since evolved in sophistication and shifted its business model. Researchers at Bromium have taken a detailed look at Emotet, and malware analyst Alex Holland joins us to share their findings.

    The research can be found here:

    https://www.google.com/url?q=https://www.bromium.com/resource/emotet-a-technical-analysis-of-the-destructive-polymorphic-malware

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    26 min
  • Gift card bots evolve and adapt.

    Researchers at Distil Networks have been tracking online bots targeting ecommerce gift card systems of major online retailers. The threat actors show remarkable resourcefulness and adaptability. Jonathan Butler is technical account team manager at Distil Networks, part of Imperva, and he joins to share their findings.

    The research can be found here:

    https://resources.distilnetworks.com/all-blog-posts/giftghostbot-attacks-ecommerce-gift-card-systems

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    26 min
  • Detecting dating profile fraud.

    Researchers from King’s College London, University of Bristol, Boston University, and University of Melbourne recently collaborated to publish a report titled, "Automatically Dismantling Online Dating Fraud." The research outlines techniques to analyze and identify fraudulent online dating profiles with a high degree of accuracy.


    Professor Awais Rashid is one of the report's authors, and he joins us to share their findings.

    The original research can be found here:

    https://arxiv.org/pdf/1905.12593.pdf

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    28 min
  • Unpacking the Malvertising Ecosystem.

    Researchers at Cisco's Talos Unit recently published research exploring the tactics, technics and procedures of the global malvertising ecosystem. Craig Williams is head of Talos Outreach at Cisco, and he guides us through the life cycle of malicious online ads, along with tips for protecting yourself and your organization.

    The research can be found here: 

    https://blog.talosintelligence.com/2019/07/malvertising-deepdive.html

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    29 min
  • Package manager repository malware detection.

    Researchers at Reversing Labs have been tracking malware hidden in software package manager repositories, and it's use as a supply chain attack vector. Robert Perica is a principal engineer at Reversing Labs, and he joins us to share their findings. 

    The research can be found here:

    https://blog.reversinglabs.com/blog/suppy-chain-malware-detecting-malware-in-package-manager-repositories

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    14 min
  • Day to day app fraud in the Google Play store.

    Researchers at bot mitigation firm White Ops have been tracking fraudulent apps in the Google Play store. These apps often imitate legitimate apps, even going so far as to lift code directly from them, but instead of providing true functionality they harvest user data and send it back to command and control servers.

    Marcelle Lee is a principal threat intel researcher at White Ops, and she shares their findings. 

    The original research can be found here —

    https://www.whiteops.com/blog/another-day-another-fraudulent-app

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    23 min
  • Nansh0u not your normal cryptominer.

    Researchers at Guardicore Labs have been tracking an unusual cryptominer that seems to be based in China and is targeting Windows MS-SQL and phpMyAdmin servers. Some elements of the exploit make use of sophisticated components previously associated with nation-state actors.

    Ophir Harpaz and Daniel Goldberg are members of the Guardicore Labs team, and they join us to explain their findings.

    The research can be found here - 

    https://www.guardicore.com/2019/05/nansh0u-campaign-hackers-arsenal-grows-stronger/

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    21 min
  • Opportunistic botnets round up vulnerable routers.

    Researchers at Netscout's ASERT Team have been tracking the growth of botnets originating in Egypt and targeting routers in South Africa. The payload is a variant of the Hakai DDoS bot.

    Richard Hummel is threat intelligence manager at Netscout, and he joins us to share their findings.

    The original research is here:

    https://www.netscout.com/blog/asert/realtek-sdk-exploits-rise-egypt

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    21 min
  • Giving everyone a stake in the success of Open Source implementation.

    Synopsys recently published the 2019 edition of their Open Source Security and Risk Analysis (OSSRA) Report, providing an in-depth look at the state of open source security, compliance, and code quality risk in commercial software.


    Tim Mackey is principal security strategist within the Synopsys Cyber Research Center, and he joins us to share their findings.

    The research can be found here:

    https://www.synopsys.com/software-integrity/resources/analyst-reports/2019-open-source-security-risk-analysis.html

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    25 min

About Research Saturday

From the publisher's feed

Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.

More shows like Research Saturday

Risky Business by Risky Business Media

Risky Business

374 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

ChinaPower by CSIS | Center for Strategic and International Studies

ChinaPower

206 Listeners

Smashing Security by Graham Cluley

Smashing Security

317 Listeners

Click Here by Recorded Future News

Click Here

419 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,055 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

191 Listeners

Career Notes by N2K Networks

Career Notes

14 Listeners

Pekingology by Center for Strategic and International Studies

Pekingology

141 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

The AI Fix by Mark Stockley

The AI Fix

32 Listeners

The FAIK Files by Perry Carpenter | N2K Networks

The FAIK Files

18 Listeners