Risky Business

Risky Business #774 -- Cleo file transfer appliances under widespread attack

18 snips
Dec 11, 2024
Jacob Torrey, an expert from Thinkst Canary, dives into the critical flaws in Cleo file transfer appliances and the ongoing exploitation by ransomware groups. He also discusses Snowflake's upcoming shift to mandatory multi-factor authentication to combat credential theft. With a focus on innovative cybersecurity techniques, Torrey reveals fascinating operating system tricks, including canary tokens that can trigger alarms in your environment. Plus, he delves into the complexities of enhancing security in Windows, keeping attackers at bay!
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

Cleo File Transfer Appliance Attack

  • Termite ransomware exploits Cleo file transfer appliances.
  • This mirrors past intrusions like CLOP ransomware attacks.
ADVICE

Snowflake MFA

  • Snowflake is phasing out single-factor authentication by late 2025.
  • Use multi-factor authentication like certificate pairs or federated authentication.
INSIGHT

Sophos Counter APT Operation

  • Sophos' counter APT operation led to sanctions against a Chinese company.
  • This company offered exploit development and "public sentiment suppression" services.
Get the Snipd Podcast app to discover more snips from this episode
Get the app