Risky Business

Risky Business #755 -- SSH 0day! Polyfill drama! Entrust crushed!


Listen Later

On this week’s show, Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Widely used polyfill javascript gets hijacked by its new owners
  • MacOS supply chain disaster bullet dodged
  • That OpenSSH remote code exec OH MY <3
  • Entrust gets its CA business kicked to the kerb by Google
  • South Korean telco intentionally viruses 600k customers
  • Microsoft continues to deeply underwhelm
  • And much, much more.
  • This week’s episode is sponsored by Greynoise. Founder Andrew Morris joins to talk about ways to track attackers across NAT and VPNs, as well as how you can join in the fun of running an internet-scale honeypot network.

    Show notes
    • Polyfill, Cloudflare trade barbs after reports of supply chain attack threatening 100k websites
    • 3 million iOS and macOS apps were exposed to potent supply-chain attacks
    • regreSSHion: RCE in OpenSSH's server, on glibc-based Linux systems (CVE-2024-6387)
    • Google Online Security Blog: Sustaining Digital Certificate Security - Entrust Certificate Distrust
    • TeamViewer: Hackers copied employee directory data and encrypted passwords
    • South Korean telecom company attacks customers with malware — over 600,000 torrent users report missing files, strange folders, and disabled PCs | Tom's Hardware
    • CDK eyes service restoration for all car dealers by Fourth of July
    • ‘I don’t see it happening’: CISA chief dismisses ban on ransomware payments
    • Patelco Credit Union ransomware attack halts banking services for nearly half a million members
    • LockBit claims cyberattack on Croatia’s largest hospital
    • Inside a Violent Gang's Ruthless Crypto-Stealing Home Invasion Spree
    • Suspected Chinese gov’t hackers used ransomware as cover in attacks on Brazil presidency, Indian health org
    • Nearly 4,000 arrested in global police crackdown on online scam networks
    • USD 257 million seized in global police crackdown against online scams
    • Microsoft alerts additional customers of state-linked threat group attacks
    • Midnight Blizzard Microsoft Email Data Sharing Request: Legit? : r/Office365
    • Polish Parliament strips official of immunity, clearing path for prosecution in spyware scandal
    • Stolen credentials could unmask thousands of darknet child abuse website users
    • WA man set up fake free wifi at Australian airports and on flights to steal people’s data, police allege
    • Bytecode Breakdown: Unraveling Factorio's Lua Security Flaws
    • iOS 17 lockdown mode blocking CarPlay? : r/ios
    • ...more
      View all episodesView all episodes
      Download on the App Store

      Risky BusinessBy Patrick Gray

      • 4.6
      • 4.6
      • 4.6
      • 4.6
      • 4.6

      4.6

      352 ratings


      More shows like Risky Business

      View all
      Security Now (Audio) by TWiT

      Security Now (Audio)

      1,961 Listeners

      SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

      SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

      634 Listeners

      Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

      Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

      368 Listeners

      Hacked by Hacked

      Hacked

      176 Listeners

      CyberWire Daily by N2K Networks

      CyberWire Daily

      1,008 Listeners

      Smashing Security by Graham Cluley & Carole Theriault

      Smashing Security

      312 Listeners

      Click Here by Recorded Future News

      Click Here

      386 Listeners

      Malicious Life by Malicious Life

      Malicious Life

      923 Listeners

      Darknet Diaries by Jack Rhysider

      Darknet Diaries

      7,840 Listeners

      Cybersecurity Today by Jim Love

      Cybersecurity Today

      141 Listeners

      CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

      CISO Series Podcast

      182 Listeners

      Hacking Humans by N2K Networks

      Hacking Humans

      309 Listeners

      Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

      Defense in Depth

      71 Listeners

      Cyber Security Headlines by CISO Series

      Cyber Security Headlines

      120 Listeners

      Risky Bulletin by risky.biz

      Risky Bulletin

      33 Listeners