

Risky Business #783 -- Evil webcam ransomwares entire Windows network
55 snips Mar 12, 2025
Rob Joyce, former Special Assistant to the US President and cybersecurity director at the NSA, shares his insights on national security challenges. He discusses groundbreaking cyber threats, including a ransomware attack using a Linux webcam to infiltrate Windows networks. Lee Chagolla-Christensen, Principal Security Researcher at SpecterOps, dives into the vulnerabilities of NTLM authentication in Active Directory and the potential of Bloodhound to address these issues. The conversation highlights the evolving landscape of cybersecurity and the importance of robust defense mechanisms.
AI Snips
Chapters
Transcript
Episode notes
Passkey Vulnerability
- Passkeys, touted as phishing-proof, are vulnerable to Bluetooth proximity attacks.
- Attackers exploit implementation details to phish passkeys, highlighting the complexity of modern authentication.
Post-Breach Actions
- Change passwords after data breaches, especially those involving password managers like LastPass.
- Consider re-homing cryptocurrency funds to a new wallet for enhanced security.
Ransomware via Webcam
- Attackers bypassed EDR by using a Linux-based webcam to encrypt a Windows network.
- They exfiltrated files onto the webcam, encrypted them, and then returned them, highlighting the vulnerability of IoT devices.