1
00:00:11,400 --> 00:00:14,920
Hello and welcome to the 
Decipher podcast, Lindsay. 

2
00:00:14,920 --> 00:00:18,560
It's it's never a dull moment in
the security industry. 

3
00:00:18,560 --> 00:00:22,080
Like we had our first named 
vulnerability in a while last 

4
00:00:22,080 --> 00:00:26,440
week and this week it not 
another named vulnerability, but

5
00:00:26,440 --> 00:00:29,760
some other bugs that came out of
that React vulnerability 

6
00:00:29,760 --> 00:00:32,200
disclosure, which sometimes 
happens. 

7
00:00:33,120 --> 00:00:37,320
Actually it happens quite a lot,
especially with critical bugs. 

8
00:00:37,320 --> 00:00:40,920
People start poking around at 
the patch or other areas around 

9
00:00:40,920 --> 00:00:43,720
where that bug was and all of a 
sudden find other 

10
00:00:43,720 --> 00:00:46,000
vulnerabilities, which is 
essentially what happened in 

11
00:00:46,000 --> 00:00:48,040
this case. 
Yeah, Yeah. 

12
00:00:48,080 --> 00:00:52,960
I was not super surprised when 
you sent me that link earlier 

13
00:00:52,960 --> 00:00:56,720
about, yes, that React, there's 
a couple new React flaws. 

14
00:00:56,720 --> 00:01:01,280
I think that it was like a high 
severity denial of service 

15
00:01:01,480 --> 00:01:03,880
vulnerability. 
And then the other one was 

16
00:01:05,200 --> 00:01:08,120
source code exposure. 
I think so. 

17
00:01:08,360 --> 00:01:12,120
And like you said, basically 
this is just kind of what 

18
00:01:12,120 --> 00:01:17,120
happens if there's a, a really 
massive kind of critical flaw, 

19
00:01:17,440 --> 00:01:21,240
you know, people start to poke 
and prod and researchers will 

20
00:01:21,240 --> 00:01:24,160
try to, you know, exploit the, 
the patches or what not. 

21
00:01:24,160 --> 00:01:27,840
And that's, that will ultimately
lead to them finding other 

22
00:01:27,840 --> 00:01:31,040
vulnerabilities in, in these 
products. 

23
00:01:31,440 --> 00:01:34,200
So that that seems to be the 
case with with this specific 

24
00:01:34,200 --> 00:01:37,120
one. 
Yeah, I think as you said, these

25
00:01:37,120 --> 00:01:39,520
weren't exactly the most 
critical things in the world. 

26
00:01:39,520 --> 00:01:43,640
A denial of service, which I 
think every software product on 

27
00:01:43,640 --> 00:01:47,600
earth probably has like 3 or 4 
DOS bugs just sitting there that

28
00:01:47,600 --> 00:01:51,160
if you looked hard enough you 
could you could probably find 

29
00:01:51,160 --> 00:01:53,520
the source code. 
Exposure is like is a weird one.

30
00:01:53,520 --> 00:01:58,720
You don't typically see that 
listed as a CVE and I'm not 

31
00:01:58,840 --> 00:02:03,480
totally sure how you somebody 
would have found that. 

32
00:02:04,200 --> 00:02:07,960
They don't really go into that, 
but that used to be the biggest 

33
00:02:07,960 --> 00:02:13,760
fear on Earth, especially in the
in the early, not early, but you

34
00:02:13,760 --> 00:02:17,080
know, like 20 years ago, the 
idea that like the Windows 

35
00:02:17,080 --> 00:02:19,920
source code, if that ever got 
out there, the world would end 

36
00:02:19,920 --> 00:02:23,880
or, you know, the source code 
for Chrome or something like 

37
00:02:23,880 --> 00:02:26,240
that. 
And those have leaked over the 

38
00:02:26,240 --> 00:02:28,680
years and nothing, we're all 
still here. 

39
00:02:29,320 --> 00:02:32,440
Like essentially, source code is
not the magic key that everybody

40
00:02:32,640 --> 00:02:35,120
you know sort of feared it might
be, right? 

41
00:02:35,840 --> 00:02:41,600
Yeah, it says like the the 
security advisory for it lists 

42
00:02:41,600 --> 00:02:46,600
it as a medium severity bug 5.3 
on the CBSS scale. 

43
00:02:47,520 --> 00:02:52,640
It says malicious HTTP request 
sent to a vulnerable server 

44
00:02:52,640 --> 00:02:55,840
function may unsafely return the
source code of any server 

45
00:02:55,840 --> 00:02:58,600
function, and then exploitation 
requires the existence of a 

46
00:02:58,600 --> 00:03:02,760
server function. 
It's basically it's, it's 

47
00:03:02,760 --> 00:03:06,200
pretty. 
It's not something that seems as

48
00:03:06,200 --> 00:03:07,560
serious as. 
No. 

49
00:03:08,320 --> 00:03:11,840
Anything else like the the DOS 
bug but then obviously not the 

50
00:03:12,600 --> 00:03:15,440
the initial React bug that kind 
of kicked all of this off? 

51
00:03:16,120 --> 00:03:17,920
Yeah. 
I mean, we're going to talk 

52
00:03:17,920 --> 00:03:22,040
about this in a larger context 
in terms of just the 

53
00:03:22,320 --> 00:03:25,160
proliferation, the continued 
proliferation of vulnerabilities

54
00:03:25,160 --> 00:03:27,760
and how difficult it is for 
organizations to manage this 

55
00:03:27,760 --> 00:03:30,480
stuff. 
But this week we also saw 

56
00:03:31,000 --> 00:03:33,960
continued and I would say 
expanded exploitation of those 

57
00:03:33,960 --> 00:03:40,200
initial React server component 
bugs, Gray noise, shadow server,

58
00:03:40,200 --> 00:03:46,640
you guys at Huntress, I saw so 
many different analysis of the 

59
00:03:46,720 --> 00:03:50,480
exploit activity, the POC's that
were out there. 

60
00:03:50,480 --> 00:03:55,040
There's much more sharpened and 
sophisticated PO CS out there, I

61
00:03:55,040 --> 00:03:58,240
would say now than, you know, 
even just a week ago when we 

62
00:03:58,240 --> 00:04:01,640
last recorded, because as we 
said last week, some of those 

63
00:04:01,640 --> 00:04:06,360
were sort of red herrings or 
just didn't work very well, 

64
00:04:06,640 --> 00:04:09,680
which happens all the time. 
But now it seems like there's 

65
00:04:09,760 --> 00:04:13,160
much more sophisticated PO CS 
out there available for 

66
00:04:13,160 --> 00:04:15,800
everybody, and lots of people 
are taking advantage. 

67
00:04:16,880 --> 00:04:20,880
Yeah, it is funny like in the 
first few days after, you know, 

68
00:04:20,880 --> 00:04:25,920
this this flaw was disclosed, we
like I feel like we initially 

69
00:04:25,920 --> 00:04:29,520
just saw you know, kind of 
smattering of PO CS, but then 

70
00:04:29,520 --> 00:04:33,600
also like the just a couple of 
like crypto miners and those 

71
00:04:33,640 --> 00:04:35,680
types of things and now. 
It seems like it's. 

72
00:04:36,320 --> 00:04:39,200
Yeah, it's classic. 
But now it seems like it's 

73
00:04:39,200 --> 00:04:42,680
definitely escalated. 
We're seeing new types of, 

74
00:04:42,960 --> 00:04:47,800
excuse me, you know, malware 
droppers, new types of kind of 

75
00:04:47,800 --> 00:04:50,800
cross-platform, you know, 
threats. 

76
00:04:50,800 --> 00:04:55,360
So I think that you know this it
will be interesting to see kind 

77
00:04:55,360 --> 00:04:58,880
of the the longer tail of of 
this, the exploitation of this 

78
00:04:58,880 --> 00:05:01,560
flaw. 
And I know, you know, I don't 

79
00:05:01,560 --> 00:05:05,400
know if you saw this, but Gray 
Noise came out with this really 

80
00:05:05,400 --> 00:05:09,840
interesting analysis report that
looked at all the different 

81
00:05:09,840 --> 00:05:12,960
attack sessions and the 
countries where exploitation's 

82
00:05:12,960 --> 00:05:16,440
been observed and all of this. 
We can probably drop this in the

83
00:05:16,440 --> 00:05:20,920
show notes, but it shows attack 
volume over time and it's really

84
00:05:20,920 --> 00:05:26,120
great breakdown of kind of the 
the bits and pieces that have 

85
00:05:26,120 --> 00:05:30,560
gone into this exploitation. 
So there's a lot more of an 

86
00:05:30,560 --> 00:05:33,640
understanding now of like how 
this is being exploited. 

87
00:05:34,000 --> 00:05:37,600
I think I would be curious to 
talk to people and get a better 

88
00:05:37,600 --> 00:05:41,000
understanding of how defense 
teams feel that they're being 

89
00:05:41,000 --> 00:05:43,760
able to handle this. 
And like have they been able to,

90
00:05:43,760 --> 00:05:47,160
you know, effectively roll out 
the patches and find where these

91
00:05:47,160 --> 00:05:49,400
components are in their 
environments and everything 

92
00:05:49,400 --> 00:05:52,600
else? 
Because like you said, this is 

93
00:05:52,720 --> 00:05:55,880
this is also been a really crazy
week in terms of disclosed 

94
00:05:55,880 --> 00:05:57,760
vulnerabilities in general. 
So. 

95
00:05:57,760 --> 00:05:59,800
Yeah. 
Yeah. 

96
00:06:00,240 --> 00:06:03,600
I mean the I have not read that 
Gray noise report, but they do 

97
00:06:03,640 --> 00:06:06,880
some of the best stuff around on
that kind of thing. 

98
00:06:06,880 --> 00:06:12,160
And what one thing I did notice 
is that both the geographic 

99
00:06:12,160 --> 00:06:17,920
breakdown and the types of hosts
that we're trying to exploit 

100
00:06:17,920 --> 00:06:20,400
this were not exactly what I 
might have expected. 

101
00:06:20,720 --> 00:06:24,200
I think we said last year that 
last year last week, good God, 

102
00:06:25,480 --> 00:06:31,600
time is a flat circle. 
We said last week that what we 

103
00:06:31,600 --> 00:06:36,160
were seeing at the time were 
mostly APT groups from, you 

104
00:06:36,160 --> 00:06:39,200
know, China, that that's what 
you would expect, right? 

105
00:06:39,440 --> 00:06:42,280
Because they have the resources 
to quickly build exploits and 

106
00:06:42,280 --> 00:06:45,240
find vulnerable hosts and get 
down to business. 

107
00:06:46,200 --> 00:06:49,280
And that that's still happening.
But there's also plenty of other

108
00:06:49,280 --> 00:06:53,160
groups trying to exploit this 
bug from all over the world. 

109
00:06:53,240 --> 00:06:57,160
And some of them, some of the 
activity is coming from 

110
00:06:57,160 --> 00:07:00,760
previously compromised hosts, 
you know, which is typical too. 

111
00:07:00,760 --> 00:07:04,400
But some of it is just like 
infrastructure used by these APT

112
00:07:04,440 --> 00:07:09,080
groups all the time, just like 
here's our go to, you know, 

113
00:07:09,080 --> 00:07:12,560
server infrastructure. 
We're coming at you because we 

114
00:07:12,560 --> 00:07:15,240
know that you guys have all 
these vulnerable apps, so try 

115
00:07:15,240 --> 00:07:17,400
and stop us. 
Right. 

116
00:07:17,480 --> 00:07:20,080
Yeah, It is interesting to see 
how that's kind of spread out. 

117
00:07:20,120 --> 00:07:24,360
And this, the report has a 
geographic distribution as well.

118
00:07:25,080 --> 00:07:28,680
And I, I think this is for, I'd 
assume for victims. 

119
00:07:28,680 --> 00:07:32,680
But surprisingly it looks like 
Poland is right now at the top, 

120
00:07:33,360 --> 00:07:37,280
which is very odd. 
And then Czech Republic, Brazil,

121
00:07:37,920 --> 00:07:43,360
Netherlands, and then the US So 
it's kind of it's, there's some 

122
00:07:43,360 --> 00:07:46,320
really cool data there to try to
figure out, you know, what the 

123
00:07:47,160 --> 00:07:49,760
escalation of attacks has looked
like and everything else. 

124
00:07:49,920 --> 00:07:55,640
That's so odd. 
I wonder what you, I remember in

125
00:07:56,280 --> 00:08:03,200
there was a supply chain attack 
a few years ago and the IT was 

126
00:08:03,200 --> 00:08:06,160
like an account or a tax 
software that was used by 

127
00:08:06,240 --> 00:08:08,080
everybody. 
I think I want to say it was in 

128
00:08:08,080 --> 00:08:11,400
Romania. 
I cannot remember the name of 

129
00:08:11,400 --> 00:08:13,680
the software. 
It was like 4 or five years ago 

130
00:08:13,680 --> 00:08:17,840
now, but essentially everybody 
in that country used this tax 

131
00:08:18,000 --> 00:08:22,160
prep software and that got 
compromised and the downstream 

132
00:08:22,160 --> 00:08:24,760
effects were terrible for that 
one, but nobody else. 

133
00:08:25,440 --> 00:08:28,920
It didn't exist anywhere else. 
So I wonder if there's some app 

134
00:08:28,920 --> 00:08:32,760
that's used really widely in 
Poland that has the vulnerable 

135
00:08:32,760 --> 00:08:39,679
Reacts framework in it that is 
just getting hit all the time. 

136
00:08:39,679 --> 00:08:44,360
Because almost always in a 
widespread bug like this, it's 

137
00:08:44,360 --> 00:08:48,960
the US, the UK, you know, maybe 
Brazil, like big, big countries 

138
00:08:48,960 --> 00:08:51,880
that have a lot of computers 
that get hit. 

139
00:08:52,800 --> 00:08:55,800
You don't typically see, you 
know, Poland at the top of the 

140
00:08:55,800 --> 00:08:59,120
victim list. 
Yeah, that's it is interesting. 

141
00:08:59,160 --> 00:09:02,680
I'd I'd have to double check 
that this is geographic 

142
00:09:02,680 --> 00:09:08,560
distribution of victims versus 
like other like parts and pieces

143
00:09:08,560 --> 00:09:12,000
of the attack. 
But, and I think also like 

144
00:09:12,000 --> 00:09:17,080
visibility in terms of, but you 
know, it's, it's interesting 

145
00:09:17,080 --> 00:09:20,960
when you see analysis like that,
like every, every vendor, every 

146
00:09:20,960 --> 00:09:23,360
company is going to have a 
different level of visibility 

147
00:09:23,440 --> 00:09:25,320
given what their, you know, 
customer base is. 

148
00:09:25,320 --> 00:09:26,880
Exactly right. 
Yeah. 

149
00:09:27,880 --> 00:09:30,760
But it it is interesting to be 
able to kind of look at all the 

150
00:09:30,760 --> 00:09:34,880
different aspects of kind of how
this is playing out right now, 

151
00:09:34,880 --> 00:09:37,440
so. 
Yeah, it could also be a hosting

152
00:09:37,440 --> 00:09:40,800
provider or some large platform 
in that country. 

153
00:09:40,800 --> 00:09:45,920
That's, you know, the the the 
sort of underlying issue there, 

154
00:09:46,440 --> 00:09:51,840
but. 
Yeah, but the I also wanted to 

155
00:09:51,840 --> 00:09:56,360
just like in terms of people who
are dealing with this right now,

156
00:09:56,360 --> 00:09:59,440
I wanted to read some of these 
like news headlines off for 

157
00:09:59,440 --> 00:10:01,480
context of like where we're at 
this week. 

158
00:10:03,840 --> 00:10:06,520
Fortnet patches critical 
authentication bypass 

159
00:10:06,520 --> 00:10:11,000
vulnerabilities, Avanti EPM 
updates update patches critical 

160
00:10:11,000 --> 00:10:14,600
RCE flaw. 
Microsoft fixes 57 flaws, 

161
00:10:14,600 --> 00:10:18,680
including three zero days and 
Adobe patches 140 flaws. 

162
00:10:18,720 --> 00:10:26,520
And that's not even all of them.
The Adobe ones, Adobe and 

163
00:10:26,520 --> 00:10:32,240
Oracle, you can't just read 
those things out of context 

164
00:10:32,240 --> 00:10:35,600
because you look at them and 
Oracle does them quarterly, not 

165
00:10:35,760 --> 00:10:38,160
not monthly. 
So you look at the Oracle patch 

166
00:10:38,160 --> 00:10:43,360
updates, there are always 
hundreds of vulnerabilities and 

167
00:10:43,360 --> 00:10:46,400
a lot of them are critical 
because Oracle has tons of 

168
00:10:46,400 --> 00:10:49,840
products same way Adobe does 
that are used all over the 

169
00:10:49,840 --> 00:10:53,040
place, right? 
Like everybody has some Adobe 

170
00:10:53,040 --> 00:10:55,840
product on their computer 
whether they use it or not. 

171
00:10:56,520 --> 00:11:01,680
And 145 or what are you, 
whatever you said is just it's 

172
00:11:01,680 --> 00:11:04,760
wild. 
Imagine if we were talking about

173
00:11:04,760 --> 00:11:10,920
this is the larger context how 
an organization, even one that 

174
00:11:10,920 --> 00:11:13,960
has a good vulnerability 
management and patching program 

175
00:11:14,440 --> 00:11:19,320
and a well funded security team,
how do they deal with this on? 

176
00:11:19,320 --> 00:11:22,000
I mean, we've talked to a lot of
people that this is their job, 

177
00:11:22,000 --> 00:11:24,840
but dealing with this on a 
monthly basis, even though you 

178
00:11:24,840 --> 00:11:29,680
know the timing of it, OK, the 
second Tuesday of every month 

179
00:11:30,640 --> 00:11:31,920
we're going to get our teeth 
kicked in. 

180
00:11:31,920 --> 00:11:33,920
We got to be ready. 
Let's plan this and that and 

181
00:11:33,920 --> 00:11:35,280
downtime and all that kind of 
stuff. 

182
00:11:36,000 --> 00:11:39,800
Trying to fix 145 Adobe bugs. 
I mean, obviously you're just 

183
00:11:39,800 --> 00:11:43,160
updating software packages, but 
on, you know, thousands or 10s 

184
00:11:43,160 --> 00:11:48,720
of thousands of endpoints and 
possibly servers and trying to 

185
00:11:48,720 --> 00:11:52,680
figure out how people can still 
do their jobs while you're 

186
00:11:52,680 --> 00:11:55,480
fixing this along with the 
Windows bugs. 

187
00:11:55,480 --> 00:11:59,280
I mean, 30 days, that would have
been like the biggest headline 

188
00:11:59,280 --> 00:12:01,120
10 years ago. 
You know, Windows. 

189
00:12:01,360 --> 00:12:03,960
Now it's just like, hey, it's 
Tuesday, it's December. 

190
00:12:04,320 --> 00:12:06,480
Good luck. 
Like go get them, Tiger. 

191
00:12:08,480 --> 00:12:11,520
I know, and it's just it's 
what's wild to me is that 

192
00:12:11,760 --> 00:12:15,320
they're you know, we're dealing 
with that on top of this already

193
00:12:15,320 --> 00:12:21,120
like insane vulnerability that 
teams are already kind of wrap 

194
00:12:21,120 --> 00:12:23,800
trying to wrap their heads 
around and deal with there. 

195
00:12:23,800 --> 00:12:27,800
So it's like just feeling 
overwhelmed, I think by 

196
00:12:27,800 --> 00:12:30,800
everything. 
But like, even without react, 

197
00:12:31,000 --> 00:12:35,960
like how are people like what 
you know, there, there's always 

198
00:12:35,960 --> 00:12:39,680
the discussion about how do you 
best prioritize vulnerability 

199
00:12:39,680 --> 00:12:42,640
management and things like that.
And there's so many different 

200
00:12:42,640 --> 00:12:45,800
factors in it. 
And you know, we have, you know,

201
00:12:45,920 --> 00:12:49,240
the ability to look at, you 
know, the CVSS score. 

202
00:12:49,240 --> 00:12:51,920
But then also there's like, is 
it actually being exploited? 

203
00:12:51,920 --> 00:12:57,400
How easy is it to exploit? 
Like is it in a product that is,

204
00:12:57,760 --> 00:13:00,880
you know, potentially impacts 
other things and all these 

205
00:13:01,000 --> 00:13:04,960
different questions. 
And I think it's, it's not just,

206
00:13:05,120 --> 00:13:08,000
you know, black and white issue.
No, not at all. 

207
00:13:08,000 --> 00:13:13,360
Everything requires some kind of
context and prioritization 

208
00:13:13,360 --> 00:13:17,320
because even some of these bugs,
even if they are exploited, a 

209
00:13:17,320 --> 00:13:20,920
lot of times it doesn't matter 
to a given organization if the 

210
00:13:20,920 --> 00:13:24,920
attacker can't get anywhere with
that or there's no sensitive 

211
00:13:24,920 --> 00:13:30,080
data exposed after exploitation,
if it just causes a crash or a 

212
00:13:30,080 --> 00:13:33,360
DOS or something like that. 
Those are ones that you, you 

213
00:13:33,360 --> 00:13:35,320
know, can be farther down the 
list. 

214
00:13:35,320 --> 00:13:40,040
But I would just like me 
personally, if I had one of 

215
00:13:40,040 --> 00:13:44,360
those jobs, I would be like, my 
brain would just never stop 

216
00:13:44,360 --> 00:13:49,440
spinning trying to figure out, 
you know, it's like, how do you 

217
00:13:49,440 --> 00:13:53,400
even ever take a deep breath and
like go away for the weekend or 

218
00:13:53,400 --> 00:13:56,200
something? 
Or just, you know, go to the 

219
00:13:56,200 --> 00:13:59,960
movies without feeling like your
server farm might fall over 

220
00:13:59,960 --> 00:14:04,080
while you're, you know, out of 
touch. 

221
00:14:04,080 --> 00:14:08,720
It's it, it seems like, and it 
honestly is just kind of a, a 

222
00:14:08,720 --> 00:14:12,160
vicious cycle that you you never
really can get out of. 

223
00:14:13,360 --> 00:14:18,160
Yeah, no, I agree. 
I think it's it's every every 

224
00:14:18,160 --> 00:14:20,320
month. 
The fact that there's like this,

225
00:14:20,400 --> 00:14:24,600
the cadence of this too, I think
is, is tough because this is all

226
00:14:24,600 --> 00:14:27,320
falling on everyone's lap like 
over the course of like a couple

227
00:14:27,320 --> 00:14:29,320
days. 
And I understand, you know why 

228
00:14:29,320 --> 00:14:32,880
that has to happen. 
But yeah, it makes it pretty, 

229
00:14:32,880 --> 00:14:36,120
pretty tough, I would say. 
And it's also, you know, two 

230
00:14:36,120 --> 00:14:39,520
weeks before Christmas in the 
middle of the holiday season. 

231
00:14:39,520 --> 00:14:43,320
Yeah, yeah. 
Everybody kind of trying to wind

232
00:14:43,320 --> 00:14:47,720
down and plan for, you know, 
time away from the office in and

233
00:14:47,960 --> 00:14:53,000
all those sorts of things. 
And when more fires are being 

234
00:14:53,000 --> 00:14:57,640
piled on top of existing ones 
every week, I would just, you 

235
00:14:57,640 --> 00:15:03,400
know, it would be really hard to
enjoy a little family time with 

236
00:15:03,400 --> 00:15:04,600
all this in the back of your 
head. 

237
00:15:05,200 --> 00:15:08,120
I know yeah, it's tough. 
I I also saw it too. 

238
00:15:08,120 --> 00:15:12,560
I don't know if you saw this, 
but the, the list of top most 

239
00:15:12,560 --> 00:15:16,080
dangerous security weaknesses 
was just released by later. 

240
00:15:16,080 --> 00:15:21,000
That was Oh, no resting too. 
Yeah, just, I know they release 

241
00:15:21,000 --> 00:15:24,520
it every year and it's, it's 
always funny to me because you 

242
00:15:24,520 --> 00:15:28,240
know, a lot of these, you know, 
once again, cross site 

243
00:15:28,240 --> 00:15:32,800
scripting, like no surprise 
there, but it's, it's always 

244
00:15:32,880 --> 00:15:36,360
interesting. 
Like I'm, I'm curious, you know,

245
00:15:36,840 --> 00:15:40,800
how they pull that, that list 
together in terms of measuring 

246
00:15:41,120 --> 00:15:45,160
the level of danger, 'cause 
there's so many factors I think 

247
00:15:45,160 --> 00:15:46,800
that go into that and everything
is so. 

248
00:15:47,200 --> 00:15:49,000
That's a good question. 
Yeah. 

249
00:15:49,040 --> 00:15:52,920
And it says they scored each 
weakness based on its severity 

250
00:15:52,920 --> 00:15:59,160
and frequency after analyzing 
CBE records for for flaws that 

251
00:15:59,160 --> 00:16:01,240
were reported over the past year
or so. 

252
00:16:01,440 --> 00:16:05,800
And so it's, it's just really 
hard though, because you know, 

253
00:16:05,800 --> 00:16:11,440
if you have a even just like a 
react to shell type of situation

254
00:16:11,440 --> 00:16:16,560
like that is going to be what 
much more have much more of a 

255
00:16:16,560 --> 00:16:21,160
widespread kind of downstream 
impact than a different type of 

256
00:16:21,160 --> 00:16:24,120
flaw under a different 
categorization that might be on 

257
00:16:24,120 --> 00:16:26,360
here. 
So anyways, I it that must be a 

258
00:16:26,360 --> 00:16:29,920
really tedious and tough process
to kind of work through and 

259
00:16:29,920 --> 00:16:32,640
understand kind of how these 
weaknesses work. 

260
00:16:33,080 --> 00:16:35,480
Right. 
Yeah, I assume that they look at

261
00:16:35,880 --> 00:16:40,360
publicly disclosed Cves over the
course of the year, sort of 

262
00:16:40,520 --> 00:16:46,560
group them by, you know, the 
CVSS score along with maybe some

263
00:16:46,560 --> 00:16:50,560
public exploitation activity, 
things like that, and put it 

264
00:16:50,560 --> 00:16:56,440
into a soup and, you know, ask 
Chachi PT what what's the most 

265
00:16:56,440 --> 00:16:58,800
dangerous? 
Like give me a list of the worst

266
00:16:58,800 --> 00:17:02,840
things in this group. 
Actually I I assume they do not 

267
00:17:02,840 --> 00:17:07,040
do that with AI, but actually I 
hope not. 

268
00:17:08,319 --> 00:17:14,640
Yeah, but it says too they they 
so they brought in the CV ES in 

269
00:17:14,640 --> 00:17:18,119
the cab, the known exploitation 
vulnerability catalog too. 

270
00:17:18,119 --> 00:17:21,440
So like they're they're 
factoring in, you know, if these

271
00:17:21,440 --> 00:17:26,200
are being exploited as well. 
And, you know, it's like I said,

272
00:17:26,200 --> 00:17:30,040
cross site scripting, sequel 
injection, like just these 

273
00:17:30,040 --> 00:17:33,840
things that are not, you know, 
it's really a surprise to anyone

274
00:17:33,840 --> 00:17:38,960
path traversal, but then they 
missing authorization and it 

275
00:17:38,960 --> 00:17:42,680
looks like missing 
authentication, like also ranked

276
00:17:42,680 --> 00:17:46,200
up words after a few years. 
So I don't know, I, I think like

277
00:17:46,200 --> 00:17:49,120
with all the conversations 
people have been having over the

278
00:17:49,120 --> 00:17:53,360
past year or two around like, 
you know, secure by design, like

279
00:17:53,360 --> 00:17:57,960
trying to figure out like, how 
can we actually take this list 

280
00:17:57,960 --> 00:18:00,640
that comes out every year and 
like make it actionable. 

281
00:18:00,640 --> 00:18:06,880
Like I, I think I would like to 
still kind of better understand 

282
00:18:06,880 --> 00:18:10,080
that. 
Those, you know, Secure by 

283
00:18:10,080 --> 00:18:15,120
Design and SDLC and all those 
software security initiatives 

284
00:18:15,120 --> 00:18:19,600
are great and I love them and 
you know, people should pay 

285
00:18:19,600 --> 00:18:22,880
attention to those. 
But when you look at the reality

286
00:18:22,880 --> 00:18:28,480
of most modern apps, they're 
literally built on foundation of

287
00:18:28,480 --> 00:18:32,280
a pile of open source code that 
maybe hasn't been reviewed by a 

288
00:18:32,280 --> 00:18:36,440
human in six years, if it ever 
was. 

289
00:18:36,720 --> 00:18:39,320
There might be some libraries in
there that have critical bugs 

290
00:18:39,320 --> 00:18:42,800
that nobody ever updated. 
You know, and this is no knock 

291
00:18:42,800 --> 00:18:45,640
on open source maintainers. 
That's most of them are doing 

292
00:18:45,640 --> 00:18:54,640
this for free, as you know, has 
side projects and those that's 

293
00:18:54,640 --> 00:18:58,920
the foundation of most of the 
modern Internet and even 

294
00:18:58,920 --> 00:19:02,320
enterprise apps. 
You know, there's just hundreds 

295
00:19:02,320 --> 00:19:05,000
and hundreds and hundreds of 
open source projects and 

296
00:19:05,000 --> 00:19:07,880
libraries in every enterprise 
app. 

297
00:19:08,800 --> 00:19:13,200
And there's no real way to to, 
you know, shore that up. 

298
00:19:13,200 --> 00:19:18,920
It's it's the XKCD meme of like 
the giant unwieldy building that

299
00:19:18,920 --> 00:19:21,240
has all the apps and then 
there's one little stick holding

300
00:19:21,240 --> 00:19:23,840
it up. 
That's like OSS libraries. 

301
00:19:24,200 --> 00:19:28,960
Yeah, yeah, I know. 
I think it's like the fact that 

302
00:19:28,960 --> 00:19:32,240
it's just how it's this, it's a 
systemic thing, you know, and 

303
00:19:32,240 --> 00:19:36,120
it's just how like I, I don't 
understand how that can really 

304
00:19:36,120 --> 00:19:39,080
be changed, unfortunately. 
There's no way to unwind it. 

305
00:19:39,560 --> 00:19:42,800
Yeah. 
And honestly like it it it could

306
00:19:42,800 --> 00:19:47,000
potentially introduce new other 
types of risks if if that was 

307
00:19:47,000 --> 00:19:48,640
unwinded. 
Absolutely. 

308
00:19:49,320 --> 00:19:51,160
Yeah. 
It's, it reminds me a little bit

309
00:19:51,160 --> 00:19:53,120
of, I mean, on a different 
scale. 

310
00:19:53,120 --> 00:19:56,080
But what we were talking about 
last week with like the telecom 

311
00:19:56,080 --> 00:20:00,560
infrastructure, you know, a lot 
of it is so old and, you know, 

312
00:20:00,560 --> 00:20:03,360
purpose built and there's no 
real way to upgrade some of 

313
00:20:03,360 --> 00:20:06,400
those things without breaking 
the entire network. 

314
00:20:06,840 --> 00:20:09,800
It's sort of that. 
But software like you can't, 

315
00:20:10,720 --> 00:20:13,680
there's no, there's, there's no 
way to change the way that apps 

316
00:20:13,680 --> 00:20:16,520
are built at this point. 
It's just, you know, we're too 

317
00:20:16,520 --> 00:20:18,920
far down the road. 
Yeah, I know. 

318
00:20:19,200 --> 00:20:26,080
Well, that kind of is a segue I 
guess into one other news item 

319
00:20:26,080 --> 00:20:31,360
too in terms of when you look at
operational technology and 

320
00:20:31,440 --> 00:20:32,520
that's. 
Always. 

321
00:20:32,680 --> 00:20:34,720
Fun to talk about. 
Always. 

322
00:20:35,240 --> 00:20:35,840
Good. 
Always good. 

323
00:20:35,840 --> 00:20:37,000
Yeah. 
The the only. 

324
00:20:37,000 --> 00:20:39,480
Yeah. 
This, the other thing I saw that

325
00:20:39,480 --> 00:20:43,680
was interesting this week was, 
you know, Sisa came out with a 

326
00:20:43,680 --> 00:20:50,080
new advisory basically warning 
of Russian hacktivists that were

327
00:20:50,080 --> 00:20:54,320
conducting attacks against US 
critical infrastructure, which 

328
00:20:54,320 --> 00:21:00,000
is absolutely not new at all. 
But it also came out in tandem 

329
00:21:00,000 --> 00:21:04,600
with the Justice Department 
charging a Ukrainian national 

330
00:21:04,760 --> 00:21:08,240
who had conducted some cyber 
attacks on various critical 

331
00:21:08,240 --> 00:21:11,360
infrastructure organizations 
worldwide. 

332
00:21:12,840 --> 00:21:16,120
Basically, it was part of it was
linked to Russian state 

333
00:21:16,120 --> 00:21:19,840
sponsored hacking operations 
that were targeting, you know, 

334
00:21:19,840 --> 00:21:23,440
all these kind of critical 
infrastructure orgs like water 

335
00:21:23,440 --> 00:21:27,040
utilities and like food 
processing facilities, 

336
00:21:27,040 --> 00:21:31,080
government networks, things that
we've really we've seen bubble 

337
00:21:31,080 --> 00:21:36,560
up in the past couple years that
over over a variety of different

338
00:21:36,560 --> 00:21:41,960
incidents. 
But it, it just kind of brings 

339
00:21:41,960 --> 00:21:45,560
up the same conversation around,
you know, operational technology

340
00:21:45,560 --> 00:21:50,480
security and the risks and 
potential impact that these 

341
00:21:50,480 --> 00:21:53,320
types of attacks could have 
downstream. 

342
00:21:53,400 --> 00:21:56,640
So. 
Yeah, it's always those kind of 

343
00:21:56,640 --> 00:21:59,480
things. 
It's easy for me and you to look

344
00:21:59,480 --> 00:22:03,200
at those and be like, yeah, we 
know this is what they like. 

345
00:22:03,200 --> 00:22:05,960
Hackers going to hack type thing
like this is what they do. 

346
00:22:06,480 --> 00:22:11,320
But for a lot of people, and 
especially, you know, the 

347
00:22:11,320 --> 00:22:13,400
government, like as 
administrations change and 

348
00:22:13,400 --> 00:22:15,440
personnel changes and people 
have different jobs and 

349
00:22:15,440 --> 00:22:20,920
different responsibilities, like
there is sort of a recurring 

350
00:22:20,920 --> 00:22:23,720
cycle of people becoming aware 
of this activity. 

351
00:22:23,720 --> 00:22:28,880
And how, how I don't 
sophisticated is not the right 

352
00:22:28,880 --> 00:22:34,560
word, but how maybe persistent 
and pervasive it is and how much

353
00:22:34,560 --> 00:22:37,640
of it goes on every single day 
all the time. 

354
00:22:38,120 --> 00:22:43,920
And the amount that we uncover 
privately or exposed publicly is

355
00:22:44,160 --> 00:22:47,440
really small, a really small 
percentage of the total 

356
00:22:47,440 --> 00:22:51,440
activity. 
You know, it's the the thing of 

357
00:22:51,560 --> 00:22:54,280
like the duck swimming on the 
surface and then all the legs 

358
00:22:54,320 --> 00:22:56,440
like underneath, like paddling 
furiously. 

359
00:22:56,440 --> 00:22:59,240
It's just like we're only seeing
a little bit of what's going on 

360
00:22:59,240 --> 00:23:02,280
here. 
Right, which is definitely 

361
00:23:02,880 --> 00:23:04,680
scary. 
Oh, it's terrifying. 

362
00:23:04,680 --> 00:23:06,560
Yeah. 
I mean, yeah. 

363
00:23:06,560 --> 00:23:09,640
And that that kind of leads into
the last thing I wanted to 

364
00:23:09,640 --> 00:23:14,000
mention, which is the a podcast 
that we published this week that

365
00:23:14,000 --> 00:23:16,320
I recorded a couple weeks ago 
with a woman named Aaron 

366
00:23:16,320 --> 00:23:21,080
Whitmore, who works for a 
company called Cypher now and 

367
00:23:21,080 --> 00:23:24,680
does sort of executive risk in 
strategic intelligence type 

368
00:23:24,680 --> 00:23:29,120
stuff, which sounds really cool.
And but her background, she was 

369
00:23:29,120 --> 00:23:34,440
a CIA operations officer. 
She worked in the office of the 

370
00:23:34,440 --> 00:23:36,960
Director of National 
Intelligence on cybersecurity 

371
00:23:36,960 --> 00:23:40,480
for a while. 
She supported the Defense 

372
00:23:40,480 --> 00:23:45,320
Intelligence Agency and the NGA 
is a civilian in the private 

373
00:23:45,320 --> 00:23:47,640
sector. 
She has this really fascinating 

374
00:23:48,640 --> 00:23:55,280
back story and sort of group of 
experiences and that it was one 

375
00:23:55,280 --> 00:23:57,640
of the most fascinating 
conversations I've had in a long

376
00:23:57,640 --> 00:24:03,000
time on or off a podcast. 
And she talked a lot about that,

377
00:24:03,440 --> 00:24:06,840
you know, sort of in broad 
terms, as you might expect being

378
00:24:07,480 --> 00:24:13,760
a former CIA officer, but about 
how there are threats going on 

379
00:24:13,760 --> 00:24:16,520
all the time that most people 
have no concept of and don't 

380
00:24:16,520 --> 00:24:20,160
need to know about. 
And you just, you know, the 

381
00:24:20,160 --> 00:24:23,640
things that you hear about are 
the tiny, tiny percentage of 

382
00:24:23,760 --> 00:24:27,080
what the government thinks you 
should know about, which I mean,

383
00:24:27,280 --> 00:24:28,600
maybe that's good or bad, I 
don't know. 

384
00:24:29,040 --> 00:24:33,080
But the, the entire conversation
was was just amazing. 

385
00:24:33,080 --> 00:24:36,040
It's really it's it's longer 
than most of the podcast we do. 

386
00:24:36,040 --> 00:24:39,520
It's like an hour and a half. 
And I thought about splitting it

387
00:24:39,520 --> 00:24:42,600
up, but I couldn't really find 
like a good point to stop it. 

388
00:24:42,600 --> 00:24:45,160
So I was like, the hell with it.
Here's an hour and a half of 

389
00:24:45,160 --> 00:24:49,360
this fascinating woman talking 
and me asking like 4 questions. 

390
00:24:49,400 --> 00:24:51,760
Which is It was great. 
It was like the easiest kind of 

391
00:24:51,760 --> 00:24:53,600
podcasting. 
That's great. 

392
00:24:53,600 --> 00:24:56,320
Yeah, No, definitely everyone 
should go listen to that one 

393
00:24:56,320 --> 00:25:00,600
because I feel like they just 
like it's, it's really good 

394
00:25:00,600 --> 00:25:04,040
conversation given, you know, 
all the the different things 

395
00:25:04,040 --> 00:25:06,520
that are happening today. 
So yeah. 

396
00:25:06,880 --> 00:25:10,720
It is. 
It's also heartening because she

397
00:25:10,720 --> 00:25:15,920
talks a lot about how her family
has this military background and

398
00:25:16,000 --> 00:25:20,040
sort of a history of service, 
whether it's in the military or,

399
00:25:20,040 --> 00:25:24,800
or other parts, and how she felt
this kind of pull to go do that 

400
00:25:24,800 --> 00:25:28,800
in one way or another. 
And not just, you know, go make 

401
00:25:28,800 --> 00:25:31,920
money somewhere. 
And, you know, which is 

402
00:25:32,320 --> 00:25:35,320
something that you don't hear 
about all that much anymore. 

403
00:25:36,240 --> 00:25:39,600
You know, it, it was just kind 
of like, ow, there are people 

404
00:25:39,600 --> 00:25:41,600
out there that are thinking 
about other people and not just 

405
00:25:41,600 --> 00:25:42,880
themselves. 
That's nice. 

406
00:25:44,200 --> 00:25:45,960
Yeah. 
It's good to know for. 

407
00:25:46,280 --> 00:25:47,560
The holidays, yeah. 
Heartwarming. 

408
00:25:48,120 --> 00:25:49,320
Story. 
Yeah. 

409
00:25:49,640 --> 00:25:51,680
We don't get enough of those, 
especially in this business. 

410
00:25:51,680 --> 00:25:53,680
I. 
Know, yeah. 

411
00:25:54,800 --> 00:25:59,120
All right, well, it's good to 
see you as always, and I'm sure 

412
00:25:59,120 --> 00:26:01,200
we'll have plenty to talk about 
next week. 

413
00:26:01,200 --> 00:26:03,800
I think we're going to hopefully
get the Home Alone podcast done 

414
00:26:03,800 --> 00:26:06,600
next week, so we'll have 
something for you guys to listen

415
00:26:06,600 --> 00:26:10,200
and watch, listen to and watch 
while you're avoiding your 

416
00:26:10,200 --> 00:26:12,200
family over the holidays. 
Yeah. 

417
00:26:13,360 --> 00:26:15,040
All right, have a good weekend. 
Talk to you soon.

