1
00:00:12,280 --> 00:00:14,280
Hello and welcome to the 
Decipher Podcast. 

2
00:00:14,280 --> 00:00:17,080
I'm Dennis Fisher. 
Lindsay is travelling this week,

3
00:00:17,080 --> 00:00:19,360
so it's just me talking into a 
microphone. 

4
00:00:19,760 --> 00:00:21,600
It was another busy week in 
security. 

5
00:00:21,600 --> 00:00:25,520
So there were a few quick things
that I wanted to mention just to

6
00:00:25,520 --> 00:00:27,480
get them on the record for this 
week. 

7
00:00:27,480 --> 00:00:34,400
So we talked about last week 
this CLOP extortion campaign 

8
00:00:34,400 --> 00:00:38,920
that was targeting customers of 
Oracle's e-business Suite with 

9
00:00:38,920 --> 00:00:45,120
some extortion emails that were 
sort of varied in the amount of 

10
00:00:45,120 --> 00:00:48,040
money they were asking for and 
the amount of or the kinds of 

11
00:00:48,040 --> 00:00:50,960
data that the attacker said that
they had. 

12
00:00:51,800 --> 00:00:56,840
A lot of times it was customer 
data or even HR and payroll data

13
00:00:56,840 --> 00:00:59,800
for the internal employees of 
the victim organization. 

14
00:01:00,200 --> 00:01:03,040
Some of the ransom demands that 
we saw were upwards of in the 

15
00:01:03,040 --> 00:01:08,080
10s of millions of dollars. 
And this just started to get 

16
00:01:08,160 --> 00:01:13,320
publicized last week. 
But we found out earlier this 

17
00:01:13,320 --> 00:01:17,200
week that it turns out that this
campaign went much farther back 

18
00:01:17,200 --> 00:01:21,160
than that. 
Google and Mandy and put out 

19
00:01:21,160 --> 00:01:24,560
some interesting research 
towards the end of the week that

20
00:01:24,680 --> 00:01:27,800
showed that the attacks actually
started back in July. 

21
00:01:28,320 --> 00:01:31,960
So this has been going on for 
the better part of three months 

22
00:01:31,960 --> 00:01:34,880
now. 
It's not clear whether the 

23
00:01:35,400 --> 00:01:39,360
extortion demands only started 
in the in the last couple weeks 

24
00:01:39,360 --> 00:01:41,520
and that's why this became 
public. 

25
00:01:42,640 --> 00:01:46,560
What the Google researchers say 
is that the campaign and the 

26
00:01:46,560 --> 00:01:51,960
data thefts intrusions were, 
were happening back in the 

27
00:01:51,960 --> 00:01:55,400
summer, back in July and August.
So it may be just that the 

28
00:01:55,400 --> 00:01:59,520
emails started in the, in the, 
you know, more recent time 

29
00:01:59,520 --> 00:02:01,200
frame. 
And that's why everybody started

30
00:02:01,200 --> 00:02:04,400
hearing about it once some 
executive started to come 

31
00:02:04,400 --> 00:02:08,080
forward with this. 
But I thought it was interesting

32
00:02:08,080 --> 00:02:11,960
that this has been going on for 
several months before it became 

33
00:02:11,960 --> 00:02:14,600
public knowledge. 
A lot of times there are smaller

34
00:02:14,600 --> 00:02:18,440
scale campaigns like these that 
go under the radar because 

35
00:02:18,440 --> 00:02:22,360
they're not targeting high 
profile companies or they're not

36
00:02:22,360 --> 00:02:26,960
targeting high profile 
applications and they're not 

37
00:02:26,960 --> 00:02:29,800
widespread enough to really gain
huge notice. 

38
00:02:30,520 --> 00:02:33,600
But the Oracle e-business Suite 
obviously is used by a lot of 

39
00:02:33,600 --> 00:02:37,280
large organizations. 
And these attacks that 

40
00:02:37,920 --> 00:02:41,840
apparently began as as early as 
about mid-july, I think they say

41
00:02:41,840 --> 00:02:47,000
July 10, you know, when this 
vulnerability in, in E-business 

42
00:02:47,000 --> 00:02:52,440
Suite was a zero day. 
This is obviously you got plenty

43
00:02:52,480 --> 00:02:56,880
of attention. 
It's a large, large customer 

44
00:02:56,880 --> 00:02:59,480
base, plenty of targets, 
potential victims. 

45
00:02:59,840 --> 00:03:03,520
So the attackers had, you know, 
plenty of time to get their 

46
00:03:03,640 --> 00:03:07,040
their act together and get this 
rolling before anybody really 

47
00:03:07,040 --> 00:03:11,960
noticed it. 
And I think Mandiant said that 

48
00:03:12,080 --> 00:03:15,600
the threat actor was likely 
exploiting this vulnerability as

49
00:03:15,600 --> 00:03:19,440
early as August 9th. 
So that was several weeks before

50
00:03:19,440 --> 00:03:22,040
this patch was available, which 
was only very recently. 

51
00:03:22,400 --> 00:03:25,920
So the window of exposure for 
this vulnerability was pretty 

52
00:03:25,920 --> 00:03:30,600
large and there are still many, 
many exposed instances of 

53
00:03:30,600 --> 00:03:34,000
e-business Suite out there. 
Gray Noise has some good data on

54
00:03:34,000 --> 00:03:35,480
this if you want to go look at 
that. 

55
00:03:36,000 --> 00:03:40,720
So this is something that's 
ongoing and we know now is was 

56
00:03:40,720 --> 00:03:44,080
going on for a couple of months 
before everybody really noticed 

57
00:03:44,080 --> 00:03:48,960
it, which is kind of concerning,
especially when you think about 

58
00:03:48,960 --> 00:03:54,160
the potential for follow on 
attacks and ransomware 

59
00:03:54,160 --> 00:03:56,160
deployments that could come from
this. 

60
00:03:56,520 --> 00:03:59,800
You know, we may only sort of be
at the at the beginning of this,

61
00:04:00,160 --> 00:04:06,280
but hopefully the public notice 
of this and the public or the 

62
00:04:06,280 --> 00:04:10,160
publicity surrounding it will 
drive some more patching and 

63
00:04:10,160 --> 00:04:13,120
more awareness and get 
organizations to really pay 

64
00:04:13,120 --> 00:04:15,800
attention to it. 
That at least that's the that's 

65
00:04:15,800 --> 00:04:18,360
the hope. 
Another story that I wanted to 

66
00:04:18,360 --> 00:04:21,399
mention that has some 
interesting connections to some 

67
00:04:21,399 --> 00:04:27,200
previous work that we did on the
site is Gray Noise released some

68
00:04:27,200 --> 00:04:31,640
data towards the end of this 
week as well about some surges 

69
00:04:31,640 --> 00:04:38,840
in scanning for Fortinet, Palo 
Alto Networks and Cisco devices 

70
00:04:38,880 --> 00:04:44,720
in for various reasons. 
If you remember, Cisco notified 

71
00:04:44,720 --> 00:04:47,920
customers about two zero day 
vulnerabilities that were being 

72
00:04:47,920 --> 00:04:50,280
exploited in their ASA 
appliances. 

73
00:04:50,360 --> 00:04:54,360
Recently, you know attackers 
have been targeting those very 

74
00:04:54,360 --> 00:04:59,880
popular product. 
So plenty of attacks surface 

75
00:04:59,880 --> 00:05:03,960
there and so there's been 
ongoing scanning for that. 

76
00:05:04,120 --> 00:05:08,560
And at the same time, Grain 
always noticed some pretty large

77
00:05:08,560 --> 00:05:14,160
upticks in scanning for various 
Fortinet and Palo Alto network 

78
00:05:14,920 --> 00:05:17,560
instances. 
In some cases, they're the 

79
00:05:17,560 --> 00:05:22,640
attackers are looking for login 
portals and trying to brute 

80
00:05:22,640 --> 00:05:27,760
force, you know, the logins for 
these for these products. 

81
00:05:28,120 --> 00:05:30,560
This is, you know, kind of a 
constant thing that happens on 

82
00:05:30,560 --> 00:05:33,560
the Internet all the time. 
And there are various ups and 

83
00:05:33,560 --> 00:05:37,480
downs with this all the time. 
But there's some pretty large 

84
00:05:37,480 --> 00:05:40,680
spikes in the scanning for these
in the last couple of days. 

85
00:05:41,600 --> 00:05:46,920
You know, Gray noises data show 
like a massive spike in scanning

86
00:05:46,920 --> 00:05:52,480
for Fortinet SSLVPNS in the last
couple of days of this week. 

87
00:05:52,480 --> 00:05:56,560
So it's one of those things that
organizations should definitely 

88
00:05:56,560 --> 00:05:58,160
be aware of. 
If you're deploying these 

89
00:05:58,160 --> 00:06:00,600
devices, you probably are aware 
of this already, but it's 

90
00:06:00,600 --> 00:06:02,760
something to to keep keep in 
mind. 

91
00:06:03,720 --> 00:06:07,480
This kind of activity, as I 
said, is ongoing almost all the 

92
00:06:07,480 --> 00:06:09,560
time. 
And it, you know, it has its ups

93
00:06:09,560 --> 00:06:15,840
and downs based on, you know, 
new disclosures, various 

94
00:06:15,840 --> 00:06:19,960
vulnerabilities, or just kind of
when attackers feel like getting

95
00:06:19,960 --> 00:06:23,120
around to it when they don't 
have other priorities. 

96
00:06:23,120 --> 00:06:26,760
But it's definitely something to
keep in mind if you're using 

97
00:06:26,760 --> 00:06:29,440
these devices. 
And as I said, there were also 

98
00:06:29,440 --> 00:06:33,520
spikes for Palo Alto network 
scanning as well. 

99
00:06:33,520 --> 00:06:37,200
So these are things just to to 
keep in mind as you're going 

100
00:06:37,200 --> 00:06:41,400
about your, your work. 
And kind of the last thing I 

101
00:06:41,400 --> 00:06:46,680
wanted to mention, describe my 
attention towards the end of the

102
00:06:46,680 --> 00:06:49,880
week as well. 
Apple put out a relatively rare 

103
00:06:49,880 --> 00:06:50,920
blog post. 
They don't. 

104
00:06:51,040 --> 00:06:53,880
They don't do very much on the 
Internet, as everybody knows, 

105
00:06:53,880 --> 00:06:55,240
especially in the security 
world. 

106
00:06:55,720 --> 00:07:01,200
They're pretty, pretty tight 
with their words when it comes 

107
00:07:01,200 --> 00:07:06,760
to their security work and the 
way that they handle 

108
00:07:06,760 --> 00:07:09,480
vulnerability disclosure and 
various other things. 

109
00:07:09,480 --> 00:07:14,720
But they released a long blog 
post on Friday morning 

110
00:07:15,680 --> 00:07:19,600
describing some changes and 
modifications to their bug 

111
00:07:19,600 --> 00:07:23,280
bounty program. 
And I would encourage everybody 

112
00:07:23,280 --> 00:07:25,480
to go read it if you're 
interested in bug bounties and 

113
00:07:25,480 --> 00:07:28,760
the way that companies handle 
vulnerability disclosure and 

114
00:07:28,760 --> 00:07:33,240
encourage research on their 
products, which can vary widely 

115
00:07:33,640 --> 00:07:36,880
from vendor to vendor. 
As I'm sure you all know, it can

116
00:07:37,040 --> 00:07:42,200
vary from actively discouraging 
researchers to to disclose 

117
00:07:42,880 --> 00:07:47,560
vulnerabilities to actively 
encouraging it and offering 

118
00:07:47,760 --> 00:07:49,600
large bug bounties. 
And there's a broad middle 

119
00:07:49,600 --> 00:07:52,920
ground there. 
A lot of security companies and 

120
00:07:52,920 --> 00:07:55,320
other tech companies are kind of
in that middle ground. 

121
00:07:57,160 --> 00:08:01,160
Apple was has had a bug bounty 
program in various forms for 

122
00:08:01,160 --> 00:08:06,000
quite a while. 
It wasn't the broadest one at 

123
00:08:06,000 --> 00:08:09,080
the beginning. 
It was relatively narrow and 

124
00:08:09,080 --> 00:08:14,440
it's still not super broad, but 
they announced some really large

125
00:08:14,920 --> 00:08:18,000
payout changes to what they do 
have. 

126
00:08:18,400 --> 00:08:23,560
So previously they had had some,
even the previous payouts were 

127
00:08:23,560 --> 00:08:25,840
very large. 
Let's be clear about that. 

128
00:08:25,840 --> 00:08:30,320
Apple pays a lot of money for 
significant vulnerability 

129
00:08:30,320 --> 00:08:33,159
disclosures that fit their their
parameters. 

130
00:08:33,159 --> 00:08:38,120
So the highest level they had 
previously was a win $1 million 

131
00:08:38,240 --> 00:08:42,600
maximum payout and that was for 
a zero click exploit chain. 

132
00:08:42,960 --> 00:08:46,240
So, you know, a remote 
compromise of a device with no 

133
00:08:46,240 --> 00:08:49,000
user interaction. 
These are the kinds of attack 

134
00:08:49,000 --> 00:08:53,040
chains that you see from 
mercenary spyware vendors. 

135
00:08:53,080 --> 00:08:56,920
These are the things that those 
companies pay very large amounts

136
00:08:56,920 --> 00:09:01,000
of money for and also develop 
themselves in a lot of cases, 

137
00:09:01,000 --> 00:09:04,600
but sometimes they buy them from
third parties as well. 

138
00:09:06,040 --> 00:09:12,600
So Apple is doubling that 
maximum bug bounty to $2,000,000

139
00:09:12,640 --> 00:09:15,880
for a zero click chain, which is
an enormous amount of money 

140
00:09:15,880 --> 00:09:19,400
obviously. 
And I'm not aware of any other 

141
00:09:20,720 --> 00:09:24,800
bug bounty that that is that 
high, at least not a public one.

142
00:09:25,640 --> 00:09:28,240
There may be them, but I'm not 
aware of them. 

143
00:09:29,360 --> 00:09:36,960
And Apple also changed several 
other of their payouts. 

144
00:09:37,880 --> 00:09:42,240
So for a one click exploit 
chain, you know, which just 

145
00:09:42,240 --> 00:09:45,040
takes one small user 
interaction, the previous 

146
00:09:45,040 --> 00:09:48,840
maximum was 250K. 
That's gone up to $1,000,000. 

147
00:09:50,240 --> 00:09:53,080
Wireless proximity attack, you 
know, where you need to be 

148
00:09:53,680 --> 00:09:58,400
within, you know, sort of close 
physical proximity of the target

149
00:09:58,400 --> 00:10:01,400
device. 
That also went up from 250K to 

150
00:10:01,400 --> 00:10:05,800
$1,000,000. 
An attack with that requires 

151
00:10:05,800 --> 00:10:10,120
physical device access to a lock
device. 

152
00:10:10,360 --> 00:10:15,120
It goes from 250K to 500K. 
You know, still a huge amount of

153
00:10:15,120 --> 00:10:20,840
money and an app sandbox, 
sandbox escape, easy for me to 

154
00:10:20,840 --> 00:10:27,640
say, goes from 150K to 500K. 
These are obviously huge amounts

155
00:10:27,640 --> 00:10:30,840
of money, and obviously Apple 
has a huge amount of money and 

156
00:10:30,840 --> 00:10:35,040
they can afford this. 
And what's interesting to me, 

157
00:10:35,440 --> 00:10:40,680
obviously the money is 
interesting, but the other part 

158
00:10:40,680 --> 00:10:45,160
that really grabs my attention 
and should be something that 

159
00:10:45,400 --> 00:10:49,520
outside researchers should look 
at is where Apple is choosing to

160
00:10:49,560 --> 00:10:54,280
invest this money in these 
specific areas is a pretty good 

161
00:10:54,280 --> 00:10:58,840
indicator of where they're 
seeing attackers invest their 

162
00:10:58,840 --> 00:11:02,160
time and money. 
They know how the mercenary 

163
00:11:02,160 --> 00:11:10,040
spyware vendors operate, what 
parts of iOS they typically have

164
00:11:10,040 --> 00:11:12,800
success targeting with their 
exploit chains. 

165
00:11:13,160 --> 00:11:15,360
And that's where Apple is 
focusing a lot of their 

166
00:11:15,360 --> 00:11:20,400
attention because that's where 
those are the exploit attempts 

167
00:11:20,480 --> 00:11:28,520
or and actual exploit successes 
that get the most attention from

168
00:11:29,400 --> 00:11:33,680
vendors like Apple, because 
those are the ones that are the 

169
00:11:33,680 --> 00:11:38,440
most difficult to find in the 
wild and also the most difficult

170
00:11:38,440 --> 00:11:43,600
to defend against because they 
typically come from extremely. 

171
00:11:43,640 --> 00:11:46,520
You know, I hate the word 
sophisticated because it's it's 

172
00:11:46,880 --> 00:11:48,600
kind of a catch all in the 
security world. 

173
00:11:48,600 --> 00:11:54,080
But you're talking about the top
tier of adversaries that have 

174
00:11:54,200 --> 00:12:00,360
large budget, large budgets, a 
lot of technical resources, time

175
00:12:00,920 --> 00:12:04,000
and other things to invest in 
these things. 

176
00:12:04,280 --> 00:12:07,800
So they know what they're doing 
is the bottom line. 

177
00:12:07,800 --> 00:12:12,960
So Apple is focusing their 
attention on these parts of iOS 

178
00:12:13,400 --> 00:12:16,560
to harden those. 
And it's also a good indication 

179
00:12:16,560 --> 00:12:23,600
of where Apple thinks there's 
things that maybe they haven't 

180
00:12:23,600 --> 00:12:26,000
found and maybe outside 
researchers can find. 

181
00:12:26,000 --> 00:12:28,760
There might be a soft spot that 
maybe they overlooked and maybe 

182
00:12:28,760 --> 00:12:32,800
the researchers can get to. 
So there's a, there's a ton of 

183
00:12:32,800 --> 00:12:36,280
money at stake here. 
And obviously they don't, these 

184
00:12:36,280 --> 00:12:39,040
are not rewards that they're 
going to be paying out on a very

185
00:12:39,040 --> 00:12:42,360
frequent basis. 
You know, they're, they're rare 

186
00:12:42,360 --> 00:12:45,880
enough that when they do pay 
them out, you, you probably hear

187
00:12:45,880 --> 00:12:50,240
about them. 
But I think it's an interesting 

188
00:12:50,240 --> 00:12:53,760
change from Apple because, as I 
said, they're often not very 

189
00:12:53,760 --> 00:12:56,760
public about what they do, 
especially when it comes to 

190
00:12:57,320 --> 00:12:59,320
device and operating system 
security. 

191
00:12:59,800 --> 00:13:03,160
So it's something to pay 
attention to when they do make a

192
00:13:03,160 --> 00:13:05,520
change like this. 
So just one of those things I 

193
00:13:05,520 --> 00:13:07,440
wanted to flag for everybody. 
There's also a bunch of 

194
00:13:07,440 --> 00:13:11,080
different, other changes that 
they're making to the program as

195
00:13:11,080 --> 00:13:15,800
well For Mac OS Gatekeeper, 
they're offering some new 

196
00:13:15,800 --> 00:13:20,160
bounties there as well in, in 
some different bounty category. 

197
00:13:20,160 --> 00:13:21,880
So it's worth everybody checking
it out. 

198
00:13:21,880 --> 00:13:25,200
I'll, I'll put the link in the 
show notes so folks can go go 

199
00:13:25,200 --> 00:13:28,960
check it out. 
But those, those dollar figures 

200
00:13:28,960 --> 00:13:31,840
really grab my attention. 
Even for a company like Apple, 

201
00:13:32,320 --> 00:13:35,120
putting a $2,000,000 maximum 
bounty on something is not 

202
00:13:35,120 --> 00:13:36,360
something that they would do 
lightly. 

203
00:13:36,360 --> 00:13:41,160
So it's worth having a look at. 
Anyway, that's it for this week.

204
00:13:41,160 --> 00:13:46,120
Thank you all for for listening.
And Oh yeah, or, or just to 

205
00:13:46,120 --> 00:13:48,840
update everybody on the the new 
weekly segment. 

206
00:13:49,120 --> 00:13:51,840
Does Dennis have a dog yet? 
No, I do not. 

207
00:13:52,920 --> 00:13:56,080
Still very sad, but maybe one 
day. 

208
00:13:56,400 --> 00:13:58,000
But thanks everybody for 
listening. 

209
00:13:58,000 --> 00:13:58,680
Have a great week.
