Research Saturday

Research Saturday

By N2K NetworksNewsTechnologyTech News
Download on the App Store

Research Saturday episodes

  • Middleboxes may be meddling with TLS connections.

    Researchers at Cloudflare have been examining HTTPS interception, a technique that weakens security, and have developed tools to help detect it. 

    Nick Sullivan is head of cryptography at Cloudflare, and he joins to us share their findings.

    The research can be found here:

    https://blog.cloudflare.com/monsters-in-the-middleboxes/

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    25 min
  • Apps on third-party Android store carry unwelcome code.

    Researchers at Zscaler have been tracking look-alike apps in third-party Android app stores that carry malicious code. Deepen Desai is VP of security research and operations and Zscaler, and he joins us to share their findings. 

    The original research can be found here:

    https://www.zscaler.com/blogs/research/third-party-android-store-sms-trojan

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    15 min
  • Xwo scans for default credentials and exposed web services.

    Researchers at AT&T Alien Labs have been tracking a new malware family they've named "Xwo" that's scanning systems for default credentials and vulnerable web services. 

    Tom Hegel is security researcher with AT&T Alien Labs, and he share their findings.

    The original research is here:

    https://www.alienvault.com/blogs/labs-research/xwo-a-python-based-bot-scanner

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    17 min
  • Blockchain bandits plunder weak wallets.

    Adrian Bednarek is a senior research analyst at Independent Security Evaluators. He and his colleagues looked at weak private cryptocurrency keys on the Ethereum blockchain in an attempt to discover how and why they are being generated as well as how bad actors are taking advantage of them.

    The original research is here:

    https://www.securityevaluators.com/casestudies/ethercombing/

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    22 min
  • A fresh look at GOSSIPGIRL and the Supra Threat Actors.

    Chronicle researchers Juan Andres Guerrero Saade and Silas Cutler recently published research tracking the development of the Stuxnet family of malware, which ultimately led them to the GOSSIPGIRL Supra Group of threat actors. 

    Juan Andres Guerrero Saade joins us to share their findings.

    The research can be found here:

    https://medium.com/chronicle-blog/who-is-gossipgirl-3b4170f846c0

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    32 min
  • Elfin APT group targets Middle East energy sector.

    Researchers at Symantec have been tracking an espionage group known as Elfin (aka APT 33) that has targeted dozens of organizations over the past three years, primarily focusing on Saudi Arabia and the United States. 

    Alan Neville is a principal threat intelligence analyst at Symantec, and he joins us to share their findings.

    The research can be found here:

    https://www.symantec.com/blogs/threat-intelligence/elfin-apt33-espionage

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    18 min
  • Steganography enables sophisticated OceanLotus payloads.

    Researchers at Blackberry Cylance have been tracking payload obfuscation techniques employed by OceanLotus (APT32), specifically steganography used to hide code within seemingly benign image files.


    Tom Bonner is director of threat research at Blackberry Cylance, and he joins us to share their findings.

    The original research can be found here:

    https://www.cylance.com/en-us/lp/threat-research-and-intelligence/oceanlotus-steganography-malware-analysis-white-paper-2019.html

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    20 min
  • Sea Turtle state-sponsored DNS hijacking.

    Researchers at Cisco Talos have been tracking what they believe is a state-sponsored attack on DNS systems, targeting the Middle East and North Africa. This attack has the potential to erode trust and stability of the DNS system, so critical to the global economy.

    Craig Williams is director of Talos Outreach at Cisco, and he joins us to share their findings. 

    The original research can be found here:

    https://blog.talosintelligence.com/2019/04/seaturtle.html

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    26 min
  • Deep Learning threatens 3D medical imaging integrity.

    Researchers at Ben Gurion University in Israel have developed techniques to infiltrate medical imaging system networks and alter 3D medical scans within, fooling both human and automated examiners with a high rate of success. 

    Yisroel Mirsky is a cybersecurity researcher and project manager at Ben Gurion University, and he joins us to share what his team discovered.

    The original research can be found here:

    https://arxiv.org/pdf/1901.03597.pdf

    A video demonstrating the exploit is here:

    https://youtu.be/_mkRAArj-x0

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    24 min
  • Undetectable vote manipulation in SwissPost e-voting system.

    Researchers have discovered a number of vulnerabilities in the SwissPost e-vote system which could allow undetectable manipulation of votes. 

    Dr Vanessa Teague is Associate Professor and Chair, Cybersecurity and Democracy Network at the Melbourne School of Engineering, University of Melbourne, Australia. She joins us to explain her team's findings.

    The original research is here:

    https://people.eng.unimelb.edu.au/vjteague/SwissVote

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    29 min

About Research Saturday

From the publisher's feed

Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.

More shows like Research Saturday

Risky Business by Risky Business Media

Risky Business

374 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

ChinaPower by CSIS | Center for Strategic and International Studies

ChinaPower

206 Listeners

Smashing Security by Graham Cluley

Smashing Security

317 Listeners

Click Here by Recorded Future News

Click Here

419 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,055 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

191 Listeners

Career Notes by N2K Networks

Career Notes

14 Listeners

Pekingology by Center for Strategic and International Studies

Pekingology

141 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

The AI Fix by Mark Stockley

The AI Fix

32 Listeners

The FAIK Files by Perry Carpenter | N2K Networks

The FAIK Files

18 Listeners