Risky Business #755 -- SSH 0day! Polyfill drama! Entrust crushed!
Jul 3, 2024
auto_awesome
Discussion on polyfill JavaScript supply chain attack, MacOS supply chain disaster, OpenSSH remote code execution, Google distrusts Entrust CA, South Korean telco malware attack, Microsoft disappoints, TeamViewer data breach, ransomware incidents, and more cybersecurity news.
OpenSSH server remote code execution vulnerability discovered.
Entrust faces CA business distrust by Google for security concerns.
Deep dives
Challenges with Dynamic IPs in Tracking Badness
Detecting bad behaviors behind carrier-grade NAT or IP address rotation requires looking beyond source IPs. Factors like user agents, HTTP headers, and network artifacts help distinguish unique devices despite changing IPs. Utilizing active honeypots allows testing fake user agents and identifying consistent patterns to attribute malicious activities accurately.
Leveraging Asymmetry in Gaming
Leveraging asymmetric advantage, defenders actively identify misleading behaviors, test for foreign accents in traffic, recognize consistencies, and spot lies. By actively engaging false user agents, defenders control and test every response, distinguishing genuine versus deceptive activities efficiently.
Enhanced Disambiguation Strategies
Utilizing active measures to assess unconventional traffic, defenders decode network behaviors and identify patterns to categorize devices despite IP variations. By evaluating unique characteristics like MTU, window sizes, and egress behaviors, defenders develop an expert system for accurate threat attribution.
Communal Security Practices with Grey Noise Sensors
Grey Noise offers virtual sensor deployment to enrich threat intelligence based on communal contributions. Interested parties can deploy honeypots to capture and analyze incoming traffic, supplementing their own data with collective insights to improve security posture and bolster threat detection capabilities.
Expanded Sensor Deployment Program
Grey Noise's initiative encourages user participation in deploying virtual sensors for enhanced threat intelligence collection. Users can leverage these sensors to detect emerging threats, analyze malicious activities, and contribute to a collective security approach by sharing insights and correlating attack patterns across shared IP space.
Engagement with Grey Noise Sensor Deployment
Interested individuals can engage with Grey Noise to deploy virtual sensors, contribute to widespread threat intelligence, and enhance security monitoring capabilities. Participation allows users to benefit from shared insights, increased threat detection efficiency, and improved defense strategies through communal security practices.
On this week’s show, Patrick Gray and Adam Boileau discuss the week’s security news, including:
Widely used polyfill javascript gets hijacked by its new owners
MacOS supply chain disaster bullet dodged
That OpenSSH remote code exec OH MY <3
Entrust gets its CA business kicked to the kerb by Google
South Korean telco intentionally viruses 600k customers
Microsoft continues to deeply underwhelm
And much, much more.
This week’s episode is sponsored by Greynoise. Founder Andrew Morris joins to talk about ways to track attackers across NAT and VPNs, as well as how you can join in the fun of running an internet-scale honeypot network.