内容由Risky.biz and Patrick Gray提供。所有播客内容(包括剧集、图形和播客描述)均由 Risky.biz and Patrick Gray 或其播客平台合作伙伴直接上传和提供。如果您认为有人在未经您许可的情况下使用您的受版权保护的作品,您可以按照此处概述的流程进行操作https://zh.player.fm/legal。
Player FM -播客应用
使用Player FM应用程序离线!
使用Player FM应用程序离线!
Risky Business #755 -- SSH 0day! Polyfill drama! Entrust crushed!
Manage episode 426902850 series 3234705
内容由Risky.biz and Patrick Gray提供。所有播客内容(包括剧集、图形和播客描述)均由 Risky.biz and Patrick Gray 或其播客平台合作伙伴直接上传和提供。如果您认为有人在未经您许可的情况下使用您的受版权保护的作品,您可以按照此处概述的流程进行操作https://zh.player.fm/legal。
On this week’s show, Patrick Gray and Adam Boileau discuss the week’s security news, including:
- Widely used polyfill javascript gets hijacked by its new owners
- MacOS supply chain disaster bullet dodged
- That OpenSSH remote code exec OH MY <3
- Entrust gets its CA business kicked to the kerb by Google
- South Korean telco intentionally viruses 600k customers
- Microsoft continues to deeply underwhelm
- And much, much more.
This week’s episode is sponsored by Greynoise. Founder Andrew Morris joins to talk about ways to track attackers across NAT and VPNs, as well as how you can join in the fun of running an internet-scale honeypot network.
Show notes
- Polyfill, Cloudflare trade barbs after reports of supply chain attack threatening 100k websites
- 3 million iOS and macOS apps were exposed to potent supply-chain attacks
- regreSSHion: RCE in OpenSSH's server, on glibc-based Linux systems (CVE-2024-6387)
- Google Online Security Blog: Sustaining Digital Certificate Security - Entrust Certificate Distrust
- TeamViewer: Hackers copied employee directory data and encrypted passwords
- South Korean telecom company attacks customers with malware — over 600,000 torrent users report missing files, strange folders, and disabled PCs | Tom's Hardware
- CDK eyes service restoration for all car dealers by Fourth of July
- ‘I don’t see it happening’: CISA chief dismisses ban on ransomware payments
- Patelco Credit Union ransomware attack halts banking services for nearly half a million members
- LockBit claims cyberattack on Croatia’s largest hospital
- Inside a Violent Gang's Ruthless Crypto-Stealing Home Invasion Spree
- Suspected Chinese gov’t hackers used ransomware as cover in attacks on Brazil presidency, Indian health org
- Nearly 4,000 arrested in global police crackdown on online scam networks
- USD 257 million seized in global police crackdown against online scams
- Microsoft alerts additional customers of state-linked threat group attacks
- Midnight Blizzard Microsoft Email Data Sharing Request: Legit? : r/Office365
- Polish Parliament strips official of immunity, clearing path for prosecution in spyware scandal
- Stolen credentials could unmask thousands of darknet child abuse website users
- WA man set up fake free wifi at Australian airports and on flights to steal people’s data, police allege
- Bytecode Breakdown: Unraveling Factorio's Lua Security Flaws
- iOS 17 lockdown mode blocking CarPlay? : r/ios
129集单集
Manage episode 426902850 series 3234705
内容由Risky.biz and Patrick Gray提供。所有播客内容(包括剧集、图形和播客描述)均由 Risky.biz and Patrick Gray 或其播客平台合作伙伴直接上传和提供。如果您认为有人在未经您许可的情况下使用您的受版权保护的作品,您可以按照此处概述的流程进行操作https://zh.player.fm/legal。
On this week’s show, Patrick Gray and Adam Boileau discuss the week’s security news, including:
- Widely used polyfill javascript gets hijacked by its new owners
- MacOS supply chain disaster bullet dodged
- That OpenSSH remote code exec OH MY <3
- Entrust gets its CA business kicked to the kerb by Google
- South Korean telco intentionally viruses 600k customers
- Microsoft continues to deeply underwhelm
- And much, much more.
This week’s episode is sponsored by Greynoise. Founder Andrew Morris joins to talk about ways to track attackers across NAT and VPNs, as well as how you can join in the fun of running an internet-scale honeypot network.
Show notes
- Polyfill, Cloudflare trade barbs after reports of supply chain attack threatening 100k websites
- 3 million iOS and macOS apps were exposed to potent supply-chain attacks
- regreSSHion: RCE in OpenSSH's server, on glibc-based Linux systems (CVE-2024-6387)
- Google Online Security Blog: Sustaining Digital Certificate Security - Entrust Certificate Distrust
- TeamViewer: Hackers copied employee directory data and encrypted passwords
- South Korean telecom company attacks customers with malware — over 600,000 torrent users report missing files, strange folders, and disabled PCs | Tom's Hardware
- CDK eyes service restoration for all car dealers by Fourth of July
- ‘I don’t see it happening’: CISA chief dismisses ban on ransomware payments
- Patelco Credit Union ransomware attack halts banking services for nearly half a million members
- LockBit claims cyberattack on Croatia’s largest hospital
- Inside a Violent Gang's Ruthless Crypto-Stealing Home Invasion Spree
- Suspected Chinese gov’t hackers used ransomware as cover in attacks on Brazil presidency, Indian health org
- Nearly 4,000 arrested in global police crackdown on online scam networks
- USD 257 million seized in global police crackdown against online scams
- Microsoft alerts additional customers of state-linked threat group attacks
- Midnight Blizzard Microsoft Email Data Sharing Request: Legit? : r/Office365
- Polish Parliament strips official of immunity, clearing path for prosecution in spyware scandal
- Stolen credentials could unmask thousands of darknet child abuse website users
- WA man set up fake free wifi at Australian airports and on flights to steal people’s data, police allege
- Bytecode Breakdown: Unraveling Factorio's Lua Security Flaws
- iOS 17 lockdown mode blocking CarPlay? : r/ios
129集单集
所有剧集
×欢迎使用Player FM
Player FM正在网上搜索高质量的播客,以便您现在享受。它是最好的播客应用程序,适用于安卓、iPhone和网络。注册以跨设备同步订阅。