Tenable
Podcasts
Foxy Zero Days and MSSP Misery
In this episode Bill and Gavin talk about a Firefox Zero Day, organizations facing bankruptcy due to ransomware, MSSP's as an attack vector and C&C Slack. The guys are also joined by Matt Everson and Justin Brown from Tenable Research team.
- Breaches costing real money.
- Paying Ransom & other fees
- Firefox has a 0-day
- https://objective-see.com/blog/blog_0x43.html
- CVE-2019-11707
- Help software is the vulnerability
- Slack - is more than useful
- Gangs attacking MSSPs
Eternally Blue about Ransomware
Bill and Gavin talk about Baltimore City being hit with Ransomware, yet another leak of hundreds of millions of personal details, and the chaps are joined by Claire Tills to discuss how the media drive remediation efforts for popular vulnerabilities.
- Baltimore City
https://www.welivesecurity.com/2019/05/17/eternalblue-new-heights-wannacryptor/ - First American Title
https://krebsonsecurity.com/2019/05/first-american-financial-corp-leaked-hundreds-of-millions-of-title-insurance-records/ - SandboxEscaper
- https://kb.cert.org/vuls/id/119704/
- https://www.bleepingcomputer.com/news/security/new-windows-10-zero-day-bug-emerges-from-bypassing-patched-flaw/ (this one has all the other bugs discovered)
- ICS in Poland
https://medium.com/@woj_ciech/state-of-industrial-control-systems-in-poland-and-switzerland-656e2e363fe3 - Old vulns and bad habits
CSuperhost Spycams and Compromised CMSes
In this episode Bill and Gavin discuss dodgy Superhost spying on their guests, SharePoint issues and weaknesses affecting the elderly. Gavin also interviews the delightful Jenny Radcliffe, the People Hacker, about social engineering.
- Airbnb Superhost’s creepy spycam sniffed out by sleuthing infosec pro
- SharePoint servers under attack through CVE-2019-0604
- Open source bug poses a threat to sites running multiple CMSes
- Dhound Chatbot: open domains, IP addresses
- Unless you want your payment card data skimmed, avoid these commerce sites
- EXPLOITING 10,000+ DEVICES USED BY BRITAIN’S MOST VULNERABLE