It was only a matter of time. [Research Saturday]
CyberWire Daily25 Heinä 2020

It was only a matter of time. [Research Saturday]

On April 29, 2020, the Salt management framework, authored by the IT automation company SaltStack, received a patch concerning two CVEs; CVE-2020-11651, an authentication bypass vulnerability, and CVE-2020-11652, a directory-traversal vulnerability. On April 30, 2020, researchers at F-Secure disclosed their vulnerability findings to the public, with an urgent warning for Salt users - patch now. Before the weekend was out, criminals were deploying malware and targeting vulnerable Salt installations, successfully affecting operations at Ghost, DigiCert, and LineageOS. The malware is a cryptominer, but there is an additional component, a Remote Access Tool written in Go called nspps. Researchers at Akamai have also observed in-the-wild attacks on Salt vulnerabilities. Joining us on this week's Research Saturday is Larry Cashdollar, Senior Security Response Engineer at Akamai, to discuss this issue. The research can be found here: SaltStack Vulnerabilities Actively Exploited in the Wild

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(3717)

Ring around the ransom.

Ring around the ransom.

Vishing attacks target hedge funds. Metabase Cloud breached by zero-day flaw. Cyberattack disrupts North Carolina Ports operations. The Chinese government has launched a security review of Palo Alto N...

7 Elo 24min

AI without adult supervision.

AI without adult supervision.

Meta’s AI models join the sandbox escape club. China’s telecom footprint in the U.S. may be larger than expected. The White House keeps its AI safety playbook under wraps. AI coding tools introduce ne...

6 Elo 25min

SAFE and sound.

SAFE and sound.

The White House lays out its AI strategy at Black Hat. Researchers spotlight rogue AI behavior. CISA warns of an actively exploited N-able flaw. TP-Link patches 15 Omada vulnerabilities. Apple fights ...

5 Elo 35min

NPM? Not my problem.

NPM? Not my problem.

New Shai-Hulud campaign compromises popular npm packages. Easterly says small municipalities shouldn’t have to fend for themselves. Chinese threat groups accelerate exploits. Samsung bans smart TV app...

4 Elo 29min

Water you waiting for?

Water you waiting for?

Cyberattacks hit U.S. water systems. CISA tackles open source security. China’s surveillance machine is exposed. Hotel Wi-Fi gets riskier. Healthcare and police data spill online. Fake SQLite vulnerab...

3 Elo 26min

The hidden risks in space supply chains. [T-Minus: Space-Cyber Briefing]

The hidden risks in space supply chains. [T-Minus: Space-Cyber Briefing]

As the space ecosystem continues to expand, the sector has become increasingly filled with new suppliers, manufacturers, and operators. However, while this development has led to the introduction of n...

2 Elo 19min

Black Hat preview: "Vulnerability Research in the Agentic Age." [Special Edition]

Black Hat preview: "Vulnerability Research in the Agentic Age." [Special Edition]

In this special edition, guest Yan Shoshitaishvili, Associate Professor, University of Arizona, joins host ⁠Dave Bittner⁠ to share a preview of his Black Hat USA 2026 keynote "Vulnerability Research i...

2 Elo 24min

The driver's seat to ransomware. [Research Saturday]

The driver's seat to ransomware. [Research Saturday]

This week, we are joined by Marcus Hutchins, Principal Threat Researcher at Expel, sharing their work on "Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable...

1 Elo 23min

Suosittua kategoriassa Politiikka ja uutiset

uutiscast
aikalisa
politiikan-puskaradio
ootsa-kuullut-tasta-2
rss-ootsa-kuullut-tasta
rss-seksicast
otetaan-yhdet
rss-podme-livebox
tervo-halme
aihe
rss-vaalirankkurit-podcast
rss-pinnalla
linda-maria
eevan-politiikkapodi-totuuksia-suomesta
politbyroo
rikosmyytit
rss-suoraan-asiaan
rss-asiastudio
the-ulkopolitist
rss-girls-finish-f1rst