Risky Business #750 -- Why Microsoft's Recall is an attacker's best friend
May 29, 2024
auto_awesome
This podcast delves into a major ransomware attack on a Russian delivery company, a supply chain attack targeting US courts, and the risks associated with Microsoft's Recall AI tool. They also discuss a cyber insurance company's findings on the vulnerability of Cisco ASA, along with hacking incidents on Checkpoint firewalls and an Aussie telco. Additionally, the episode covers a healthcare data breach, backdoored software, and the impact of attacking AI models.
RDP and ASA Vulnerabilities Linked to Increased Insurance Claims
Companies with RDP exposed to the internet were 2.5 times more likely to file an insurance claim due to attackers targeting RDP. Additionally, running Cisco's ASA in 2023 made companies five times more likely to make a claim. Fortinet users had a 200% higher chance of experiencing a breach according to insurance data.
PC Tattletail Stalkerware Company Experiences Major Data Leak
PC Tattletail, a Stalkerware app primarily for Windows, experienced a major data leak after a bug was found in their system. The leak exposed screenshots and data of their customers, highlighting poor security practices. A backdoor in the PHP code and token mismanagement added to the company's security woes.
TikTok Attempts to Disrupt Influence Operations Revealed in a Report by TikTok
TikTok published a report detailing their efforts to disrupt influence operations, including campaigns linked to Iran and China. The report identified and addressed several inauthentic behavior campaigns. While TikTok aims to showcase transparency and action, its impact on its current challenges remains uncertain.
Reversing Ban on TikTok and Commuting Sentences
Talks about the potential reversal of the TikTok ban with Trump's promise to commute the sentence of Ross Ulbricht of Silk Road, generating mixed reactions but potentially popular with a certain section of the US voting public.
Security Concerns with LLMs in AI
Discusses the challenges and risks associated with large language models (LLMs), focusing on prompt injection attacks, complex permission models, system vulnerabilities in inference servers, and the need for robust network access controls to mitigate security threats.
On this week’s show Patrick and Adam discuss the week’s security news, including:
Russian delivery company gets ransomware-wiper’d
A supply-chain attack targets video software used in US courts
Checkpoint firewalls get hacked, details as clear as mud
Microsoft Recall delights hackers
Aussie telco Optus gets told its IR report isn’t legal advice
Cyber insurer says you’re 5x more likely to get rekt if you have a Cisco ASA
And much, much more.
This week’s episode is sponsored by Kroll Cyber. Alex Cowperthwaite, Kroll’s technical director research and development for offence joins to talk about how his team attacks AI models, in ways both classic and new.