惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Stack Overflow Blog
Stack Overflow Blog
量子位
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
美团技术团队
小众软件
小众软件
aimingoo的专栏
aimingoo的专栏
Recent Announcements
Recent Announcements
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Microsoft Security Blog
Microsoft Security Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
酷 壳 – CoolShell
酷 壳 – CoolShell
J
Java Code Geeks
V
V2EX
大猫的无限游戏
大猫的无限游戏
D
DataBreaches.Net
博客园 - Franky
爱范儿
爱范儿
T
Tailwind CSS Blog
A
About on SuperTechFans
Google DeepMind News
Google DeepMind News
博客园_首页
B
Blog RSS Feed
博客园 - 司徒正美
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知

Risky Business

Risky Business #840 -- Microsoft walks back researcher threats Risky Business #839 -- TeamPCP stole GitHub's internal repos Risky Business #838 -- GitHub investigates possible breach Soap Box: Where does AI fit into cloud security? Risky Business #837 -- GitHub Actions footgun claims TanStack Risky Business #836 -- You can't patch the bugpocalypse Snake Oilers: Ent AI, Spacewalk and Mondoo Risky Business #835 -- Why the Fast16 malware is badass Risky Business #834 -- Vercel gets owned, Mozilla dumps hundreds of Mythos bugs Risky Business #833 -- The Great Mythos Freakout of 2026 Snake Oilers: Burp AI, Sondera and Truffle Security Risky Business #832 -- Anthropic unveils magical 0day computer God How the World Got Owned Episode 2: The 1990s, Part One Risky Business #831 -- The AI bugpocalypse begins Soap Box: Red teaming AI systems with SpecterOps Risky Business #830 -- LiteLLM and security scanner supply chains compromised Risky Business #829 -- Sneaky lobsters: Why AI is the new insider threat Risky Biz Soap Box: It took a decade, but allowlisting is cool again Risky Business #828 -- The Coruna exploits are truly exquisite Risky Business #827 -- Iranian cyber threat actors are down but not out Risky Business #826 -- A week of AI mishaps and skulduggery Risky Biz Soap Box: The lethal trifecta of AI risks Risky Business #825 -- Palo Alto Networks blames it on the boogie Risky Business #824 -- Microsoft's Secure Future is looking a bit wobbly Risky Business #823 -- Humans impersonate clawdbots impersonating humans Risky Business #822 -- France will ditch American tech over security risks Risky Business #821 -- Wiz researchers could have owned every AWS customer Risky Business #820 -- Asian fraud kingpin will face Chinese justice (pew pew!) How the World Got Owned Episode 1: The 1980s Risky Business #819 -- Venezuela (credibly?!) blames USA for wiper attack
Risky Business #774 -- Cleo file transfer appliances unde...
Patrick Gray · 2024-12-11 · via Risky Business

Risky Business Podcast

December 11, 2024

Presented by

Patrick Gray

Patrick Gray

CEO and Publisher

Adam Boileau

Adam Boileau

Co-host at large

On this week’s show, Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:

  • Cleo file transfer products have a remote code exec, here we go again!
  • Snowflake phases out password-based auth
  • Chinese Sophos-exploit-dev company gets sanctioned
  • Romania’s election gets rolled back after Tiktok changed the outcome
  • AMD’s encrypted VM tech bamboozled by RAM with one extra address bit
  • Some cool OpenWRT research
  • And much, much more.

This week’s episode is sponsored by Thinkst, who love sneaky canary token traps. Jacob Torrey previews an upcoming Blackhat talk filled with interesting operating system tricks you can use to trigger canaries in your environment. You wont believe the third trick! Attackers hate him!

This episode is also available on Youtube.

Your browser does not support the audio element.

Risky Business #774 -- Cleo file transfer appliances under widespread attack

0:00 / 62:28

Logo

Show notes

Cleo Software Actively Being Exploited in the Wild CVE-2024-50623 | Huntress

Blue Yonder investigating data leak claim following ransomware attack | Cybersecurity Dive

Snowflake to phase out single-factor authentication by late 2025 | Cybersecurity Dive

Treasury Sanctions Cybersecurity Company Involved in Compromise of Firewall Products and Attempted Ransomware Attacks | U.S. Department of the Treasury

Another teenage hacker charged as feds continue Scattered Spider crackdown | The Record from Recorded Future News

Germany arrests suspected admin of country’s largest criminal marketplace | The Record from Recorded Future News

FCC, for first time, proposes cybersecurity rules tied to wiretapping law | CyberScoop

Russian state hackers abuse Cloudflare services to spy on Ukrainian targets | The Record from Recorded Future News

Cloudflare’s pages.dev and workers.dev Domains Increasingly Abused for

Romania annuls presidential election over alleged Russian interference | The Record from Recorded Future News

EU demands TikTok 'freeze and preserve data' over alleged Russian interference in Romanian elections | The Record from Recorded Future News

Research Note: Meta’s Role in Romania’s 2024 Presidential Election - CheckFirst

Key electricity distributor in Romania warns of ‘cyber attack in progress’ | The Record from Recorded Future News

Backdoor slipped into popular code library, drains ~$155k from digital wallets - Ars Technica

AMD’s trusted execution environment blown wide open by new BadRAM attack - Ars Technica

New dog, old tricks: DaMAgeCard attack targets memory directly thru SD card reader – PT SWARM

Telegram partners with child safety group to scan content for sexual abuse material

Apple hit with $1.2B lawsuit after killing controversial CSAM-detecting tool - Ars Technica

Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection - Flatt Security Research

How do I turn on the Do Not Track feature? | Firefox Help