Research Saturday

Research Saturday

By N2K NetworksNewsTechnologyTech News
Download on the App Store

Research Saturday episodes

  • Excel-lerating cyberattacks.

    While our team is out on winter break, please enjoy this episode of Research Saturday.

    This week, we are joined by ⁠Tom Hegel⁠, Principal Threat Researcher from ⁠SentinelLabs⁠ research team, to discuss their work on "Ghostwriter | New Campaign Targets Ukrainian Government and Belarusian Opposition." The latest Ghostwriter campaign, linked to Belarusian government espionage, is actively targeting Ukrainian military and government entities as well as Belarusian opposition activists using weaponized Excel documents.

    SentinelLabs identified new malware variants and tactics, including obfuscated VBA macros that deploy malware via DLL files, with payload delivery seemingly controlled based on a target’s location and system profile. The campaign, which began preparation in mid-2024 and became active by late 2024, appears to be an evolution of previous Ghostwriter operations, combining disinformation with cyberattacks to further political and military objectives.

    The research can be found here:

    • ⁠Ghostwriter | New Campaign Targets Ukrainian Government and Belarusian Opposition
    • Learn more about your ad choices. Visit megaphone.fm/adchoices

      24 min
    • The lies that let AI run amok.

      Darren Meyer, Security Research Advocate at Checkmarx, is sharing their work on "Bypassing AI Agent Defenses with Lies-in-the-Loop." Checkmarx Zero researchers introduce “lies-in-the-loop,” a new attack technique that bypasses human‑in‑the‑loop AI safety controls by deceiving users into approving dangerous actions that appear benign.

      Using examples with AI code assistants like Claude Code, the research shows how prompt injection and manipulated context can trick both the agent and the human reviewer into enabling remote code execution. The findings highlight a growing risk as AI agents become more common in developer workflows, underscoring the limits of human oversight as a standalone security control.

      The research can be found here:

      • ⁠Bypassing AI Agent Defenses With Lies-In-The-Loop

        Learn more about your ad choices. Visit megaphone.fm/adchoices

        25 min
      • Root access to the great firewall.

        Daniel Schwalbe, DomainTools Head of Investigations and CISO, is sharing their work on "Inside the Great Firewall." This two-part research project analyzes an extraordinary 500–600GB leak that exposes the internal architecture, tooling, and human ecosystem behind China’s Great Firewall.

        Across both parts, you break down thousands of leaked documents, source code repositories, diagrams, packet captures, and telemetry that reveal how systems like the Traffic Secure Gateway, MAAT, Redis-based analytics, and modular DPI engines work together to censor, surveil, and fingerprint users at scale. Taken together, the research shows how the Great Firewall functions not just as a technical system, but as a living censorship-industrial complex that adapts, learns, and coordinates across government, telecoms, and security vendors.

        The research can be found here:

        • Inside the Great Firewall Part 1: The Dump
        • Inside the Great Firewall Part 2: Technical Infrastructure
        • Learn more about your ad choices. Visit megaphone.fm/adchoices

          27 min
        • When macOS gets frostbite.

          Jaron Bradley, Director of Jamf Threat Labs, is sharing their work on "ChillyHell: A Deep Dive into a Modular macOS Backdoor." Jamf Threat Labs uncovers a newly notarized macOS backdoor called ChillyHell, tied to past UNC4487 activity and disguised as a legitimate applet.

          The malware showcases robust host profiling, multiple persistence mechanisms, timestomping, and flexible C2 communications over both DNS and HTTP. Its modular design includes reverse shells, payload delivery, self-updates, and a brute-force component targeting user credentials.

          The research can be found here:

          • ⁠ChillyHell: A Deep Dive into a Modular macOS Backdoor

            Learn more about your ad choices. Visit megaphone.fm/adchoices

            25 min
          • A new stealer hiding behind AI hype.

            Please enjoy this encore of Research Saturday.

            This week, we are joined by ⁠Michael Gorelik⁠, Chief Technology Officer from ⁠Morphisec⁠, discussing their work on "New Noodlophile Stealer Distributes Via Fake AI Video Generation Platforms." A new threat dubbed Noodlophile Stealer is exploiting the popularity of AI-powered content tools by posing as fake AI video generation platforms, luring users into uploading media in exchange for malware-laced downloads.

            Distributed through convincing Facebook groups and viral campaigns, the malware steals browser credentials, cryptocurrency wallets, and can deploy a remote access trojan like XWorm. The campaign uses a layered, obfuscated delivery chain disguised as legitimate video editing software, making it both deceptive and difficult to detect.

            The research can be found here:

            • ⁠⁠⁠New Noodlophile Stealer Distributes Via Fake AI Video Generation Platforms
            • Learn more about your ad choices. Visit megaphone.fm/adchoices

              23 min
            • Two RMMs walk into a phish…

              Alex Berninger, Senior Manager of Intelligence at Red Canary, and Mike Wylie, Director, Threat Hunting at Zscaler, join to discuss four phishing lures in campaigns dropping RMM tools. Red Canary and Zscaler uncovered phishing campaigns delivering legitimate remote monitoring and management (RMM) tools—like ITarian, PDQ, SimpleHelp, and Atera—to gain stealthy access to victim systems. Attackers used four main lures (fake browser updates, meeting invites, party invitations, and fake government forms) and often deployed multiple RMM tools in quick succession to establish persistent access and deliver additional malware.

              The report highlights detection opportunities, provides indicators of compromise, and stresses the importance of monitoring authorized RMM usage, scrutinizing trusted services like Cloudflare R2, and enforcing strict network and endpoint controls.

              The research can be found here:

              • You’re invited: Four phishing lures in campaigns dropping RMM tools
              • Learn more about your ad choices. Visit megaphone.fm/adchoices

                24 min
              • When clicks turn criminal.

                Dr. Renée Burton, Vice President of Threat Intelligence from Infoblox, is sharing the team's work on "Deniability by Design: DNS-Driven Insights into a Malicious Ad Network." Infoblox returns with new threat actor research uncovering Vane Viper, a Cyprus-based holding company behind PropellerAds—one of the world’s largest advertising networks. The report reveals that Vane Viper isn’t just being exploited by criminals but operates as a criminal infrastructure itself, built to profit from fraud, malware, and disinformation through offshore entities and complex ownership structures.

                The findings highlight the growing convergence between adtech, cybercrime, and state-linked influence operations, suggesting that elements of the global digital advertising ecosystem are now functioning as infrastructure for large-scale cyber and disinformation campaigns.

                The research can be found here:

                • Deniability by Design: DNS-Driven Insights into
                  a Malicious Ad Network
                • Learn more about your ad choices. Visit megaphone.fm/adchoices

                  25 min
                • A fine pearl gone rusty.

                  Tal Peleg, Senior Product Manager, and Coby Abrams, Cyber Security Researcher of Varonis, discussing their work and findings on Rusty Pearl - Remote Code Execution in Postgres Instances. The flaw could allow attackers to execute arbitrary commands on a database server’s operating system, leading to potential data theft, destruction, or lateral movement across networks.

                  While the vulnerability existed in PostgreSQL, Amazon RDS and Aurora were not affected, thanks to built-in protections like SELinux and AWS’s automated threat detection. Still, the research underscores the importance of patching and configuration hygiene in managed database environments.

                  The research can be found here:

                  • ⁠⁠⁠⁠Rusty Pearl: Remote Code Execution in Postgres Instances

                    Learn more about your ad choices. Visit megaphone.fm/adchoices

                    24 min
                  • Attack of the automated ops.

                    Today we are joined by Dario Pasquini, Principal Researcher at RSAC, sharing the team's work on WhenAIOpsBecome “AI Oops”: Subverting LLM-driven IT Operations via Telemetry Manipulation. A first-of-its-kind security analysis showing that LLM-driven AIOps agents can be tricked by manipulated telemetry, turning automation itself into a new attack vector.

                    The researchers introduce AIOpsDoom, an automated reconnaissance + fuzzing + LLM-driven telemetry-injection attack that performs “adversarial reward-hacking” to coerce agents into harmful remediations—even without prior knowledge of the target and even against some prompt-defense tools. They also present AIOpsShield, a telemetry-sanitization defense that reliably blocks these attacks without harming normal agent performance, underscoring the urgent need for security-aware AIOps design.

                    The research can be found here:

                    • ⁠When AIOps Become “AI Oops”:
                      Subverting LLM-driven IT Operations via Telemetry Manipulation

                      Learn more about your ad choices. Visit megaphone.fm/adchoices

                      20 min
                    • A look behind the lens.

                      Noam Moshe, Claroty’s Vulnerability Research Team Lead, joins Dave to discuss Team 82's work on "Turning Camera Surveillance on its Axis." Team82 disclosed four vulnerabilities in Axis.Remoting—deserialization, a MiTM “pass-the-challenge” NTLMSSP flaw, and an unauthenticated fallback HTTP endpoint—that enable pre-auth remote code execution against Axis Device Manager and Axis Camera Station.

                      They found more than 6,500 Axis.Remoting services exposed online (over half in the U.S.), letting attackers enumerate targets, install malicious Axis packages, and hijack, view, or shut down managed camera fleets.Axis published an urgent advisory, issued patches for ADM 5.32, Camera Station 5.58 and Camera Station Pro 6.9, accepted Team82’s disclosure, and organizations are urged to update.

                      The research can be found here:

                      • Turning Camera Surveillance on its Axis
                      • Learn more about your ad choices. Visit megaphone.fm/adchoices

                        25 min

                      About Research Saturday

                      From the publisher's feed

                      Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.

                      More shows like Research Saturday

                      Risky Business by Risky Business Media

                      Risky Business

                      374 Listeners

                      CyberWire Daily by N2K Networks

                      CyberWire Daily

                      1,027 Listeners

                      ChinaPower by CSIS | Center for Strategic and International Studies

                      ChinaPower

                      206 Listeners

                      Smashing Security by Graham Cluley

                      Smashing Security

                      317 Listeners

                      Click Here by Recorded Future News

                      Click Here

                      420 Listeners

                      Darknet Diaries by Jack Rhysider

                      Darknet Diaries

                      8,055 Listeners

                      Cybersecurity Today by David Shipley

                      Cybersecurity Today

                      179 Listeners

                      Hacking Humans by N2K Networks

                      Hacking Humans

                      314 Listeners

                      CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

                      CISO Series Podcast

                      191 Listeners

                      Career Notes by N2K Networks

                      Career Notes

                      14 Listeners

                      Pekingology by Center for Strategic and International Studies

                      Pekingology

                      140 Listeners

                      Cybersecurity Headlines by CISO Series

                      Cybersecurity Headlines

                      138 Listeners

                      The AI Fix by Mark Stockley

                      The AI Fix

                      32 Listeners

                      The FAIK Files by Perry Carpenter | N2K Networks

                      The FAIK Files

                      18 Listeners