Risky Business Podcast
August 25, 2021
Risky Business #635 -- Owned via telnet? Must be "highly sophisticated attackers"!
Presented by
CEO and Publisher
Technology Editor
On this week’s show Patrick Gray and Adam Boileau discuss recent security news, including:
- T-Mobile owned hard
- USA no fly list winds up on unsecured ElasticSearch in Bahrain… because reasons
- Facebook scrambles to secure Afghani accounts
- Hacker steals and returns $600 from de-fi platform
- Healthcare sector struggles with ransomware attacks
- A very sweet TCP-based amplification technique that will be A Problem
- Much, much more
Evan Sultanik and Dan Guido will be joining us to talk about Fickling – a tool developed by Trail of Bits to do unnatural things to the Python Pickle files that are heavily used as a means to share machine learning models. The machine learning supply chain is really quite wobbly, and they’ll be joining us later to talk about that.
Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.
Brought to you by Trail of Bits
We don't just fix bugs, we fix software
Show notes
T-Mobile breach climbs to over 50 million people
T-Mobile: Breach Exposed SSN/DOB of 40M+ People – Krebs on Security
1.9 million records from the FBI's terrorist watchlist leaked online - The Record by Recorded Future
Facebook, other platforms scramble to secure user accounts in Afghanistan
This $600 Million Crypto Heist Is the Most Bizarre Hack in Recent Memory
A Hacker Stole and Then Returned $600 Million
Japanese crypto-exchange Liquid hacked for $94 million - The Record by Recorded Future
Hospitals hamstrung by ransomware are turning away patients | Ars Technica
The pandemic revealed the health risks of hospital ransomware attacks - The Verge
Ransomware hackers could hit U.S. supply chain, experts warn
Ransomware hits Lojas Renner, Brazil's largest clothing store chain - The Record by Recorded Future
RansomClave project uses Intel SGX enclaves for ransomware attacks - The Record by Recorded Future
Wanted: Disgruntled Employees to Deploy Ransomware – Krebs on Security
Japan's Tokio Marine is the latest insurer to be victimized by ransomware
Cyber insurance market encounters ‘crisis moment’ as ransomware costs pile up
White House to tackle cyber challenges with Apple, IBM, insurance CEOs | Reuters
FBI sends its first-ever alert about a 'ransomware affiliate' - The Record by Recorded Future
Multiple ransomware gangs pounce on 'PrintNightmare' vulnerability
Peterborough NH Cyberattack: Town Loses $2.3M in Taxpayer Money – NBC Boston
Almost 2,000 Exchange servers hacked using ProxyShell exploit - The Record by Recorded Future
ALTDOS hacking group wreaks havoc across Southeast Asia - The Record by Recorded Future
Apple reopens legal fight against security firm Corellium, raising concerns for ethical hackers
SNIcat: Circumventing the guardians | mnemonic
Realtek SDK vulnerabilities impact dozens of downstream IoT vendors | The Daily Swig
Accellion Kiteworks Vulnerabilities | Insomnia Security
Exhaustive study puts China’s infamous Great Firewall under the microscope | The Daily Swig
Never a dill moment: Exploiting machine learning pickle files
PrivacyRaven: Implementing a proof of concept for model inversion
GitHub - trailofbits/fickling: A Python pickling decompiler and static analyzer