Security Serengeti

SS-NEWS-081: Malicious OAuth Apps and Poor Crypto Returns


Listen Later

Malicious OAuth apps are coming for your Exchange admins!  Oh noes!  Also, Powerpoint gets in the malware delivery game and it turns out that hackers are not considering the efficiency of spinning up AWS boxes to run cryptominers.  Not very considerate of them.  David has a particularly nasty twist on the Powerpoint one.  
Article 1 - Exchange servers abused for spam through malicious OAuth applicationsSupporting Article:OAuth app policies
Article 2 - Hackers Using PowerPoint Mouseover Trick to Infect Systems with Malware
Article 3 - Cryptominers hijack $53 worth of system resources to earn $1Supporting Article:Configure Amazon EC2 Dedicated Hosts
If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!
...more
View all episodesView all episodes
Download on the App Store

Security SerengetiBy David Schwendinger and Matthew Keener

  • 5
  • 5
  • 5
  • 5
  • 5

5

1 ratings