

Risky Business #774 -- Cleo file transfer appliances under widespread attack
18 snips Dec 11, 2024
Jacob Torrey, an expert from Thinkst Canary, dives into the critical flaws in Cleo file transfer appliances and the ongoing exploitation by ransomware groups. He also discusses Snowflake's upcoming shift to mandatory multi-factor authentication to combat credential theft. With a focus on innovative cybersecurity techniques, Torrey reveals fascinating operating system tricks, including canary tokens that can trigger alarms in your environment. Plus, he delves into the complexities of enhancing security in Windows, keeping attackers at bay!
AI Snips
Chapters
Transcript
Episode notes
Cleo File Transfer Appliance Attack
- Termite ransomware exploits Cleo file transfer appliances.
- This mirrors past intrusions like CLOP ransomware attacks.
Snowflake MFA
- Snowflake is phasing out single-factor authentication by late 2025.
- Use multi-factor authentication like certificate pairs or federated authentication.
Sophos Counter APT Operation
- Sophos' counter APT operation led to sanctions against a Chinese company.
- This company offered exploit development and "public sentiment suppression" services.