Research Saturday

Research Saturday

By N2K NetworksNewsTechnologyTech News
Download on the App Store

Research Saturday episodes

  • Triofox and the key to disaster.

    This week, we are joined by John Hammond, Principal Security Researcher at Huntress, who is sharing his PoC and research on "CVE-2025-30406 - Critical Gladinet CentreStack & Triofox Vulnerability Exploited In The Wild." A critical 9.0 severity vulnerability (CVE-2025-30406) in Gladinet CentreStack and Triofox is being actively exploited in the wild, allowing remote code execution via hardcoded cryptographic keys in default configuration files.

    Huntress researchers observed compromises at multiple organizations and confirmed hundreds of vulnerable internet-exposed servers, urging immediate patching or manual machineKey updates. Mitigation guidance, detection, and remediation scripts have been released to help users identify and secure affected installations.

    The research can be found here:

    • ⁠CVE-2025-30406 - Critical Gladinet CentreStack & Triofox Vulnerability Exploited In The Wild
    • Learn more about your ad choices. Visit megaphone.fm/adchoices

      20 min
    • Pandas with a purpose.

      This week, we are joined by Deepen Desai, Zscaler's Chief Security Officer and EVP of Cyber and AI Engineering, taking a dive deep into Mustang Panda’s latest campaign. Zscaler ThreatLabz uncovered new tools used by Mustang Panda, including the backdoors TONEINS, TONESHELL, PUBLOAD, and the proxy tool StarLoader, all delivered via phishing.

      They also discovered two custom keyloggers, PAKLOG and CorKLOG, and an EDR evasion tool, SplatCloak, highlighting the group's focus on surveillance, persistence, and stealth in cyberespionage operations.4o.

      The research can be found here:

      • Latest Mustang Panda Arsenal: ToneShell and StarProxy | P1
      • Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2
      • Learn more about your ad choices. Visit megaphone.fm/adchoices

        18 min
      • Leveling up their credential phishing tactics.

        This week, Dave speaks with Max Gannon of Cofense Intelligence to dive into his team's research on "The Rise of Precision-Validated Credential Theft: A New Challenge for Defenders."

        Threat actors continuously develop new tactics, techniques, and procedures (TTPs) to bypass existing defenses. When defenders identify these methods and implement countermeasures, attackers adapt or create more sophisticated approaches.

        This research explores how cybercriminals are leveling up their credential phishing tactics using Precision-Validated Phishing, a technique that leverages real-time email validation to ensure only high-value targets receive the phishing attempt.

        The research can be found here:

        • The Rise of Precision-Validated Credential Theft: A New Challenge for Defenders⁠⁠⁠⁠⁠

          Learn more about your ad choices. Visit megaphone.fm/adchoices

          18 min
        • Hijacking wallets with malicious patches.

          This week, we are joined by Lucija Valentić, Software Threat Researcher from ReversingLabs, who is discussing "Atomic and Exodus crypto wallets targeted in malicious npm campaign." Threat actors have launched a malicious npm campaign targeting Atomic and Exodus crypto wallets by distributing a fake package called "pdf-to-office," which secretly patches locally installed wallet software to redirect crypto transfers to attacker-controlled addresses.

          ReversingLabs researchers discovered that this package used obfuscated JavaScript to trojanize specific files in targeted wallet versions, enabling persistence even after the malicious package was removed. This incident highlights the growing threat of software supply chain attacks in the cryptocurrency space and underscores the need for vigilant monitoring of both open-source repositories and local applications.

          The research can be found here:

          • ⁠⁠Atomic and Exodus crypto wallets targeted in malicious npm campaign

            Learn more about your ad choices. Visit megaphone.fm/adchoices

            18 min
          • When AI gets a to-do list.

            This week, we are joined by ⁠Shaked Reiner⁠, Security Principal Security Researcher at ⁠CyberArk⁠, who is discussing their research on"Agents Under Attack: Threat Modeling Agentic AI." Agentic AI empowers LLMs to take autonomous actions, like browsing the web or executing code, making them more useful—but also more dangerous.

            Threats like prompt injections and stolen API keys can turn agents into attack vectors. Shaked Reiner explains how treating agent outputs like untrusted code and applying traditional security principles can help keep them in check.

            The research can be found here:

            • ⁠Agents Under Attack: Threat Modeling Agentic AI
            • Learn more about your ad choices. Visit megaphone.fm/adchoices

              22 min
            • China’s new cyber arsenal revealed.

              Today we are joined by Crystal Morin, Cybersecurity Strategist from Sysdig, as she is sharing their work on "UNC5174’s evolution in China’s ongoing cyber warfare: From SNOWLIGHT to VShell." UNC5174, a Chinese state-sponsored threat actor, has resurfaced with a stealthy cyber campaign using a new arsenal of customized and open-source tools, including a variant of their SNOWLIGHT malware and the VShell RAT.

              Sysdig researchers discovered that the group targets Linux systems through malicious bash scripts, domain squatting, and in-memory payloads, indicating a high level of sophistication and espionage intent. Their evolving tactics, such as using spoofed domains and fileless malware, continue to blur attribution and pose a significant threat to research institutions, critical infrastructure, and NGOs across the West and Asia-Pacific regions.


              The research can be found here:
              • UNC5174’s evolution in China’s ongoing cyber warfare: From SNOWLIGHT to VShell

              Learn more about your ad choices. Visit megaphone.fm/adchoices

              23 min
            • Crafting malware with modern metals.

              This week, we are joined by Nick Cerne, Security Consultant from Bishop Fox, to discuss "Rust for Malware Development." In pursuit of simulating real adversarial tactics, this blog explores the use of Rust for malware development, contrasting it with C in terms of binary complexity, detection evasion, and reverse engineering challenges.

              The author demonstrates how Rust's inherent anti-analysis traits and memory safety features can create more evasive malware tooling, including a simple dropper that injects shellcode using lesser-known Windows APIs. Through hands-on comparisons and decompiled output analysis, the post highlights Rust’s growing appeal in offensive security while noting key OPSEC considerations and tooling limitations.


              The research can be found here:
              • Rust for Malware Development

              Learn more about your ad choices. Visit megaphone.fm/adchoices

              18 min
            • The new malware on the block.

              This week, we are sharing an episode of our monthly show, Only Malware in the Building. We invite you to join Dave Bittner and cohost Selena Larson as they explore "The new malware on the block."


              Welcome in! You’ve entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today’s most interesting threats. Your host is Selena Larson, Proofpoint intelligence analyst and host of their podcast DISCARDED. Inspired by the residents of a building in New York’s exclusive upper west side, Selena is joined by N2K Networks Dave Bittner —and our newest totally unbiased co-host, Archy, a highly sophisticated AI robot who swears they have no ulterior motives (but we’re keeping an eye on them just in case).

              Being a security researcher is a bit like being a detective: you gather clues, analyze the evidence, and consult the experts to solve the cyber puzzle. On this episode, we talk about the latest shake-ups in the fake update threat landscape, including two new cybercriminal actors, fresh Mac malware, and the growing challenge of tracking these evolving campaigns.

              Learn more about your ad choices. Visit megaphone.fm/adchoices

              34 min
            • Bybit’s $1.4B breach.

              Zach Edwards from Silent Push is discussing their work on "New Lazarus Group Infrastructure, Acquires Sensitive Intel Related to $1.4B ByBit Hack and Past Attacks." Silent Push analysts uncovered significant infrastructure used by the Lazarus APT Group, linking them to the $1.4 billion Bybit crypto heist through the domain bybit-assessment[.]com registered just hours before the attack.

              The investigation revealed a pattern of test entries, VPN usage, and fake job interview scams targeting crypto users, with malware deployment tied to North Korean threat actor groups like TraderTraitor and Contagious Interview. The team also identified numerous companies being impersonated in these scams, including major crypto platforms like Coinbase, Binance, and Kraken, to alert potential victims.


              The research can be found here:
              • Silent Push Pivots into New Lazarus Group Infrastructure, Acquires Sensitive Intel Related to $1.4B ByBit Hack and Past Attacks

              Learn more about your ad choices. Visit megaphone.fm/adchoices

              33 min
            • Breaking barriers, one byte at a time.

              This week, we are joined by Jon Williams, Vulnerability Researcher from Bishop Fox, discussing "Tearing Down (Sonic)Walls: Decrypting SonicOSX Firmware." Bishop Fox researchers reverse-engineered the encryption protecting SonicWall SonicOSX firmware, enabling them to access its underlying file system for security research.

              They presented their process and findings at DistrictCon Year 0 and released a tool called Sonicrack to extract keys from VMware virtual machine bundles, facilitating the decryption of VMware NSv firmware images. This research builds upon previous work, including techniques to decrypt static NSv images and reverse-engineer other encryption formats used by SonicWall.


              The research can be found here:
              • Tearing Down (Sonic)Walls: Decrypting SonicOSX Firmware

              Learn more about your ad choices. Visit megaphone.fm/adchoices

              20 min

            About Research Saturday

            From the publisher's feed

            Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.

            More shows like Research Saturday

            Risky Business by Risky Business Media

            Risky Business

            374 Listeners

            CyberWire Daily by N2K Networks

            CyberWire Daily

            1,027 Listeners

            ChinaPower by CSIS | Center for Strategic and International Studies

            ChinaPower

            206 Listeners

            Smashing Security by Graham Cluley

            Smashing Security

            317 Listeners

            Click Here by Recorded Future News

            Click Here

            420 Listeners

            Darknet Diaries by Jack Rhysider

            Darknet Diaries

            8,055 Listeners

            Cybersecurity Today by David Shipley

            Cybersecurity Today

            179 Listeners

            Hacking Humans by N2K Networks

            Hacking Humans

            314 Listeners

            CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

            CISO Series Podcast

            191 Listeners

            Career Notes by N2K Networks

            Career Notes

            14 Listeners

            Pekingology by Center for Strategic and International Studies

            Pekingology

            140 Listeners

            Cybersecurity Headlines by CISO Series

            Cybersecurity Headlines

            138 Listeners

            The AI Fix by Mark Stockley

            The AI Fix

            32 Listeners

            The FAIK Files by Perry Carpenter | N2K Networks

            The FAIK Files

            18 Listeners