Risky Business

Risky Business #799 -- Everyone's Sharepoint gets shelled

11 snips
Jul 23, 2025
David Cottingham, CEO of Airlock Digital, shares insights on building robust security management platforms for critical systems. He delves into evolving allow listing software and the challenges of securing user permissions in diverse environments. The discussion also covers recent cyber threats, including vulnerabilities in SharePoint servers and a significant hacking incident in Brazil. Cottingham emphasizes the importance of automation and identity management in enhancing security, while also addressing the need for timely system updates.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

Sherpa-Guided Unix Host Reviews

  • Adam Boileau shared an experience where he had to perform Unix host reviews with a Sherpa typing commands for him due to security constraints.
  • The process was slow, involved multiple handovers, and took weeks, but he still managed to execute his tasks effectively.
ADVICE

Use Reverse Proxies for Safety

  • Use reverse proxies to restrict access to vulnerable web applications like SharePoint, ensuring authentication before any access.
  • Remove exposed services from the public internet to drastically reduce attack surface and mitigate exploitation risks.
INSIGHT

Few Drive Much of Scattered Spider

  • The malicious activity attributed to the hacker group Scattered Spider is mostly driven by a very small number of highly skilled individuals.
  • Law enforcement targeting these key actors can significantly disrupt the group's overall operations.
Get the Snipd Podcast app to discover more snips from this episode
Get the app