Research Saturday

Research Saturday

By N2K NetworksNewsTechnologyTech News
Download on the App Store

Research Saturday episodes

  • InnaputRAT exfiltrates victim data.

    Researchers with Arbor Networks ASERT team have been tracking a malware campaign targeting commercial manufacturing, and have uncovered various samples dating back to at least 2016.


    Richard Hummel is Threat Intelligence Manager for Arbor Networks' ASERT Team, and he takes us through what they've discovered.

    https://www.arbornetworks.com/blog/asert/innaput-actors-utilize-remote-access-trojan-since-2016-presumably-targeting-victim-files/

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    23 min
  • Energetic Dragonfly and DYMALLOY Bear 2.0.

    Researchers at Cylance recently uncovered the malicious use of a core router in a campaign aimed at critical infrastructure around the world. 


    Kevin Levelli is Director of Threat Intelligence at Cylance, and he takes us through what they've discovered. 

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    22 min
  • Crypto crumple zones.

    In their recently published paper, "Crypto Crumple Zones: Enabling Limited Access Without Mass Surveillance," coauthors Charles Wright and Mayank Varia make their case for an alternative approach to the encryption debate, one based on economics as a limiting factor on government overreach and surveillance. 


    Crypto Crumple Zones: Enabling Limited Access Without Mass Surveillance

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    39 min
  • Chasing FlawedAMMYY.

    FlawedAMMYY is a newly discovered remote access trojan (RAT) that’s been used in malicious email campaigns, as far back as 2016.

    Ryan Kalember is Senior Vice President of Cyber Security Strategy at Proofpoint, and he takes us through their research. 

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    24 min
  • Code comments cause SAML conundrum.

    Researchers at Duo Security recently unearthed a new vulnerability class that affects SAML-based single sign-on (SSO) systems. This vulnerability can allow an attacker with authenticated access to trick SAML systems into authenticating as a different user without knowledge of the victim user’s password.

    Kelby Ludwig is a Senior Application Security Engineer at Duo security, and he takes us through his discoveries. 

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    20 min
  • Cryptojacking injections heat up.

    There's been an epidemic of cryptojacking code injections recently, as bad actors attempt to cash in on the cryptocurrency craze through unauthorized cryptomining operations on unsuspecting users. 

    Marcelle Lee is a threat researcher at LookingGlass, and she takes us through her recently published research, Cryptojacking — Coming to a Server Near You. 

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    26 min
  • Dark Caracal APT steals out of Lebanon.

    Researcher from Lookout and the EFF have discovered an APT group operating out of Lebanon they've named Dark Caracal. The group is running a global espionage campaign, targeting journalists, military personnel, activists, lawyers, medical professionals and educational institutions. 

    Mike Murray is VP of Security Intelligence at Lookout, and he's our guide through their research.

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    40 min
  • Lebal malware phishes for victims.

    Researchers at Comodo Security Solutions have been tracking a recently discovered strain of malware named Lebal. The malware uses several clever techniques to attempt to hide itself, and once installed targets credentials and cryptocurrency wallets. 

    Fatih Orhan is VP of Threat Labs at Comodo, and he takes us through their research.

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    18 min
  • Phishing for holiday winnings.

    Or Katz is principal lead security researcher for Akamai's Enterprise Security Business Unit, and the research he’s sharing today is a widespread phishing campaign targeting users using an advertising tactic. The research is titled, “Gone Phishing for the Holidays."

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    24 min
  • The uncanny HEX men.

    The research we’re discussing today is called, “Beware the Hex Men”, and it tracks multiple attack campaigns conducted by a Chinese threat actor. The GuardiCore Labs team identified three attack variants that they named Hex, Hanako and Taylor, targeting SQL servers.

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    26 min

About Research Saturday

From the publisher's feed

Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.

More shows like Research Saturday

Risky Business by Risky Business Media

Risky Business

374 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

ChinaPower by CSIS | Center for Strategic and International Studies

ChinaPower

206 Listeners

Smashing Security by Graham Cluley

Smashing Security

317 Listeners

Click Here by Recorded Future News

Click Here

419 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,055 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

191 Listeners

Career Notes by N2K Networks

Career Notes

14 Listeners

Pekingology by Center for Strategic and International Studies

Pekingology

141 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

The AI Fix by Mark Stockley

The AI Fix

32 Listeners

The FAIK Files by Perry Carpenter | N2K Networks

The FAIK Files

18 Listeners