1
00:00:05,160 --> 00:00:08,760
Welcome to Crying Out Cloud. 
The podcast will make you laugh,

2
00:00:08,880 --> 00:00:12,440
cry and reconsider all of your 
cloud security fears. 

3
00:00:12,880 --> 00:00:16,239
I'm Eden. 
I'm here with my amazing Co host

4
00:00:16,400 --> 00:00:18,560
Amitai. 
Howdy. 

5
00:00:19,160 --> 00:00:20,440
We're back. 
It's been a while. 

6
00:00:20,440 --> 00:00:25,120
We didn't do a news episode, but
we're going to fill you in on 

7
00:00:25,280 --> 00:00:29,560
everything you need to know. 
What are we going to tell them 

8
00:00:29,560 --> 00:00:32,640
about Amitai? 
So today, First off, we have a 

9
00:00:32,640 --> 00:00:36,520
guest, Romney McCarthy from the 
Wiz Research team, who's going 

10
00:00:36,520 --> 00:00:40,160
to come and talk about his 
research into VS Code extension,

11
00:00:40,160 --> 00:00:43,760
supply chain attacks and the 
work he did there, which is 

12
00:00:43,760 --> 00:00:47,560
really cool. 
Next, we'll be talking about a 

13
00:00:47,560 --> 00:00:50,200
Redis vulnerability, also 
discovered by Wiz Research at 

14
00:00:50,200 --> 00:00:52,640
POM 2. 
On that we called a Redis shell.

15
00:00:54,000 --> 00:00:56,440
Then we're going to talk about a
security incident that happened 

16
00:00:56,440 --> 00:00:59,880
to F5 and try to figure out what
that's about. 

17
00:01:00,560 --> 00:01:04,560
We're going to talk a bit about 
how attackers are sort of 

18
00:01:04,560 --> 00:01:10,640
incorporating AI into their 
malware and using AICLIS that 

19
00:01:10,640 --> 00:01:14,320
they find on target machines and
why they might be doing that and

20
00:01:14,320 --> 00:01:17,360
what it might mean. 
And then we'll do a new section 

21
00:01:17,360 --> 00:01:19,040
that we're calling. 
Cricket. 

22
00:01:19,440 --> 00:01:22,080
Like cricket? 
Take note that Amita has 

23
00:01:22,080 --> 00:01:23,800
wonderful activities for his 
children. 

24
00:01:23,840 --> 00:01:25,960
Play DoH. 
Chalkboard. 

25
00:01:26,840 --> 00:01:28,120
How do you know these are for my
children? 

26
00:01:28,120 --> 00:01:30,440
Maybe I like to play with Play 
DoH in my spare time. 

27
00:01:30,680 --> 00:01:34,440
Yeah, we should write out the 
the volumes on the chalkboard 

28
00:01:34,680 --> 00:01:36,120
like it's. 
Oh, I can do that. 

29
00:01:36,680 --> 00:01:38,560
I can do that next time. 
I'll do that next time, OK? 

30
00:01:38,880 --> 00:01:43,320
For our next topic, we have the 
VS Code extension supply chain 

31
00:01:43,440 --> 00:01:48,720
attack. 
Rami is on the pod today to talk

32
00:01:48,720 --> 00:01:51,040
about it. 
Rami is the head of Risk 

33
00:01:51,040 --> 00:01:54,360
Research at Wiz. 
Welcome back to the pod. 

34
00:01:54,440 --> 00:01:57,760
Thrilled to be a frequent fire. 
Let's just start with what did 

35
00:01:57,760 --> 00:01:59,320
you find? 
Tell us. 

36
00:01:59,640 --> 00:02:02,640
Yes, this is something we shared
out from the Wiz Research blog 

37
00:02:02,640 --> 00:02:04,760
recently. 
It was actually a relatively 

38
00:02:04,760 --> 00:02:08,919
long research process for what I
would say is an issue with a 

39
00:02:08,919 --> 00:02:12,880
really simple root cause. 
Fundamentally what we found was 

40
00:02:12,880 --> 00:02:16,680
that VS Code extension 
marketplaces, so VS Code being 

41
00:02:16,680 --> 00:02:20,120
most popular developer IDE that 
has extensions that add 

42
00:02:20,120 --> 00:02:21,920
functionality. 
These are distributed through 

43
00:02:21,920 --> 00:02:24,720
both the official VS Code 
marketplace run by Microsoft and

44
00:02:24,720 --> 00:02:29,480
the open VSX marketplace that is
tied to AI enabled ID ES like 

45
00:02:29,600 --> 00:02:32,920
for example cursor. 
Those extensions were frequently

46
00:02:32,920 --> 00:02:34,920
leaking secrets from their 
publishers. 

47
00:02:34,920 --> 00:02:37,840
So publishers were shipping out 
these bundles of code. 

48
00:02:37,840 --> 00:02:40,040
And with any bundle of code that
gets shipped out to the 

49
00:02:40,040 --> 00:02:42,600
Internet, it tends to leak 
secrets. 

50
00:02:42,600 --> 00:02:45,040
And that was the initial 
insight. 

51
00:02:45,040 --> 00:02:47,920
We actually started by looking 
for malware, and then we 

52
00:02:48,000 --> 00:02:51,840
stumbled on this problem of 
secrets and decided to take a 

53
00:02:51,840 --> 00:02:54,480
deeper look there. 
And secrets on their own are 

54
00:02:54,480 --> 00:02:57,880
problematic, but we have a lot 
of cases of secrets leaking 

55
00:02:57,880 --> 00:02:59,240
these days. 
I mean, Wiz has published 

56
00:02:59,240 --> 00:03:02,000
research on how AI has 
contributed to increased secrets

57
00:03:02,000 --> 00:03:03,840
leakage. 
We've seen secrets in MPM and 

58
00:03:03,840 --> 00:03:07,560
Pypy on GitHub. 
Of course, the bigger issue came

59
00:03:07,560 --> 00:03:10,520
when we made another connection,
which was a lot of the secrets 

60
00:03:10,520 --> 00:03:13,240
that were leaked were actually 
publishing tokens for these 

61
00:03:13,240 --> 00:03:16,600
marketplaces. 
So what you'd have is you'd have

62
00:03:16,600 --> 00:03:20,400
a very popular extension that 
was distributed that carried 

63
00:03:20,400 --> 00:03:23,720
with it ability to update that 
extension across the entire user

64
00:03:23,720 --> 00:03:25,960
base. 
So extensions in BS code are 

65
00:03:25,960 --> 00:03:28,440
auto updating. 
If you ship a new version, it 

66
00:03:28,440 --> 00:03:30,040
gets pushed out to everyone's 
laptop. 

67
00:03:30,440 --> 00:03:33,720
And in the end, we figured out 
that we could push malware 

68
00:03:33,720 --> 00:03:39,120
directly to somewhere around 
185,000 developer laptops who 

69
00:03:39,120 --> 00:03:42,280
were using vulnerable extensions
across both marketplaces. 

70
00:03:42,760 --> 00:03:46,360
So imagine if you found it, 
who's nice and lovely and 

71
00:03:46,360 --> 00:03:49,440
awesome, But if an attacker 
found these tokens, like, what's

72
00:03:49,440 --> 00:03:51,520
the scope of what they could 
have done with this? 

73
00:03:51,960 --> 00:03:54,240
Yeah. 
So there are two references I'd 

74
00:03:54,240 --> 00:03:56,320
make here when we talk about the
scope of impact. 

75
00:03:56,520 --> 00:04:00,360
So the first is that we recently
had a worm bull attack on NPM 

76
00:04:00,360 --> 00:04:03,080
happen. 
This was, you know, a recent 

77
00:04:03,080 --> 00:04:05,680
incident where NPM packages were
compromised and once 

78
00:04:05,680 --> 00:04:09,000
compromised, poisoned additional
NPM packages. 

79
00:04:09,400 --> 00:04:13,480
That incident, you know, made 
made the news, was far reaching,

80
00:04:13,760 --> 00:04:16,240
had a pretty severe impact 
across the landscape and was 

81
00:04:16,240 --> 00:04:20,040
eventually centrally stopped by 
NPM and by GitHub. 

82
00:04:20,720 --> 00:04:22,920
So we could worm this malware, 
right? 

83
00:04:22,920 --> 00:04:26,360
If we're able to distribute to 
185,000 desktops, we could 

84
00:04:26,640 --> 00:04:30,480
immediately perpetuate that 
malware on to other supply 

85
00:04:30,480 --> 00:04:32,800
chains. 
But that's NPM packages where 

86
00:04:32,800 --> 00:04:35,160
that's extensions that are 
published by victims of the 

87
00:04:35,160 --> 00:04:39,000
initial attack. 
So that's just like one recent 

88
00:04:39,000 --> 00:04:41,560
incident that leveraged a 
similar capability on a much 

89
00:04:41,560 --> 00:04:44,160
smaller scale. 
The NPM attack, the worm was 

90
00:04:44,160 --> 00:04:46,560
seated with three or four 
packages, I think. 

91
00:04:46,560 --> 00:04:51,080
And so here we have well over 
100 different extensions, a 

92
00:04:51,080 --> 00:04:54,880
really diverse user base that 
gives you no more legs to it. 

93
00:04:55,240 --> 00:04:57,680
The other issues that shortly 
after I published this research,

94
00:04:57,680 --> 00:05:00,400
actually someone attempted 
something very similar 

95
00:05:00,400 --> 00:05:03,160
maliciously in the Open VSX 
marketplace. 

96
00:05:03,400 --> 00:05:07,080
This reported by a couple firms,
but there was a attempted worm 

97
00:05:07,080 --> 00:05:09,320
through Open VSX. 
It doesn't seem to be 

98
00:05:09,320 --> 00:05:11,960
particularly well crafted or 
particularly successful. 

99
00:05:12,200 --> 00:05:16,840
And in that case they used one 
leaked token to publish at least

100
00:05:16,840 --> 00:05:20,640
one, maybe 3 or 4 to publish a 
malicious the Open VSX 

101
00:05:20,640 --> 00:05:24,280
extension. 
And so that may have impacted, 

102
00:05:24,800 --> 00:05:27,120
you know, a handful of real 
world users. 

103
00:05:27,120 --> 00:05:30,320
The possible scope of install 
base was relatively low. 

104
00:05:30,320 --> 00:05:35,080
It was in the few thousands. 
And so that didn't give enough 

105
00:05:35,080 --> 00:05:37,680
leverage, enough attack surface 
for a worm to get off the 

106
00:05:37,680 --> 00:05:38,680
ground. 
That's when we're looking at 

107
00:05:38,680 --> 00:05:41,720
some of these worms. 
There is a a tipping point where

108
00:05:41,720 --> 00:05:44,480
if you can get broad enough 
distribution initially, it 

109
00:05:44,480 --> 00:05:47,280
becomes really hard for the 
industry to react and outpace 

110
00:05:47,280 --> 00:05:49,040
it. 
It tends to spread 

111
00:05:49,040 --> 00:05:51,680
exponentially. 
And so the larger the starting 

112
00:05:51,680 --> 00:05:54,160
population, the larger the 
eventual impact. 

113
00:05:54,400 --> 00:05:56,160
Is this affecting Enterprise 
Oregon? 

114
00:05:56,160 --> 00:06:00,400
Is it affecting Just like anyone
can install this, these these 

115
00:06:00,400 --> 00:06:01,640
extensions, right? 
So it. 

116
00:06:01,800 --> 00:06:03,520
Impacts everyone, enterprise or 
not. 

117
00:06:03,800 --> 00:06:07,560
There are a few ways it's 
specifically impactful to 

118
00:06:07,560 --> 00:06:10,240
enterprises and I think a lot of
enterprises or who cares about 

119
00:06:10,240 --> 00:06:13,080
these issues, individual 
developers obviously have have a

120
00:06:13,600 --> 00:06:16,400
less rigor around their security
than enterprise would. 

121
00:06:16,960 --> 00:06:20,480
So a few things we've seen 
recently in the Shihalud and 

122
00:06:20,480 --> 00:06:24,200
Singularity attacks, we've seen 
developer accounts leaking 

123
00:06:24,200 --> 00:06:26,640
enterprise secrets, and that 
similar could have happened 

124
00:06:26,640 --> 00:06:28,400
here. 
If you have a developer who has 

125
00:06:28,400 --> 00:06:32,120
enterprise credentials mingled 
with a personal IDE instance, it

126
00:06:32,120 --> 00:06:34,240
would have been very easy for 
those lines to blur. 

127
00:06:34,600 --> 00:06:38,680
The second thing is that there 
are actually many impacted 

128
00:06:38,680 --> 00:06:41,160
extensions here that are 
internal to companies but 

129
00:06:41,160 --> 00:06:45,480
distributed publicly. 
So you know, for example, Acmico

130
00:06:45,600 --> 00:06:48,000
has a internal developer 
efficiency extension. 

131
00:06:48,080 --> 00:06:50,320
And the easiest way to get it 
out to people is to just put it 

132
00:06:50,320 --> 00:06:51,680
on the marketplace, right? 
Download. 

133
00:06:51,680 --> 00:06:54,840
It will owe off you as soon as 
you download the extension and 

134
00:06:54,840 --> 00:06:57,600
log in. 
So, you know, we're not risking 

135
00:06:57,600 --> 00:07:01,120
anyone else using this extension
but internal and some of those 

136
00:07:01,120 --> 00:07:03,480
extensions had leaked secrets as
well. 

137
00:07:03,480 --> 00:07:06,080
So those were companies where 
you could immediately attack 

138
00:07:06,080 --> 00:07:09,160
their developers in a really 
targeted way, including one we 

139
00:07:09,160 --> 00:07:13,080
make reference to anonymized of 
course, is a $30 billion Chinese

140
00:07:13,080 --> 00:07:16,600
mega core had a internal 
developer extension with 

141
00:07:16,840 --> 00:07:20,080
hundreds of users using it. 
So that's like a company that's 

142
00:07:20,080 --> 00:07:23,520
sort of really at risk where 
this to have been discovered and

143
00:07:23,520 --> 00:07:26,480
weaponized by an attacker. 
It's crazy. 

144
00:07:26,640 --> 00:07:29,600
First of all, what has been the 
response? 

145
00:07:29,600 --> 00:07:31,920
Like obviously you have a mega 
company and they have a 

146
00:07:31,920 --> 00:07:34,840
different response than maybe 
like just the average person on 

147
00:07:34,840 --> 00:07:36,520
the Internet. 
But what has been the response 

148
00:07:36,520 --> 00:07:38,280
to the finding from the 
community? 

149
00:07:38,280 --> 00:07:41,920
And then I'd also love to hear 
from Microsoft and working with 

150
00:07:41,920 --> 00:07:42,920
them. 
Yeah. 

151
00:07:42,920 --> 00:07:47,480
So we, we were very careful when
disclosing and eventually when 

152
00:07:47,480 --> 00:07:51,000
publishing this finding to be as
responsible as possible to give 

153
00:07:51,000 --> 00:07:54,800
the most time for the industry 
to respond, for vulnerable folks

154
00:07:54,800 --> 00:07:57,400
to respond. 
I will say we've seen a similar 

155
00:07:57,400 --> 00:08:00,840
pattern with secrets leakage, 
where in any form of mass 

156
00:08:00,840 --> 00:08:05,520
disclosure, it can be hard to 
get disclosure acknowledged and 

157
00:08:05,520 --> 00:08:08,280
remediated by the victims 
themselves, the publishers, 

158
00:08:08,280 --> 00:08:10,080
right? 
Some of these publishers put up 

159
00:08:10,080 --> 00:08:12,880
a popular extension five years 
ago and don't have access to the

160
00:08:12,880 --> 00:08:14,960
e-mail anymore. 
However, we also spent six 

161
00:08:14,960 --> 00:08:18,120
months working with Microsoft 
centrally to address this and 

162
00:08:18,120 --> 00:08:20,800
that took a few forms. 
So one is Microsoft is much 

163
00:08:20,800 --> 00:08:24,040
better quick than me personally 
to do a notification campaign to

164
00:08:24,040 --> 00:08:27,080
VS Code Marketplace publishers. 
And so they did a mass 

165
00:08:27,080 --> 00:08:29,520
notification campaign multiple 
rounds. 

166
00:08:30,000 --> 00:08:33,520
They also removed extensions 
where there was no response. 

167
00:08:33,520 --> 00:08:36,360
So if you were exposing a secret
and they couldn't get in touch 

168
00:08:36,360 --> 00:08:39,480
with you, they would proactively
protect you by taking down that 

169
00:08:39,480 --> 00:08:42,159
extension in some cases. 
And finally they added server 

170
00:08:42,159 --> 00:08:44,360
side prevention here for leaking
future secrets. 

171
00:08:44,360 --> 00:08:48,160
So Microsoft owns GitHub, right?
They have a long history of 

172
00:08:48,160 --> 00:08:51,160
secrets detection and awareness.
Like the GitHub Secret scanning 

173
00:08:51,160 --> 00:08:53,280
program. 
They've now applied that to the 

174
00:08:53,280 --> 00:08:55,280
BS Code Marketplace. 
So when you go to publish an 

175
00:08:55,280 --> 00:08:58,920
extension, you will get stopped 
and warned if there's a secret, 

176
00:08:58,920 --> 00:09:01,600
and in fact they block it. 
There's no opting into leaking 

177
00:09:01,600 --> 00:09:03,640
secrets in your BS code 
extensions anymore. 

178
00:09:04,160 --> 00:09:08,840
So what should people using BS 
code extensions and orgs do to 

179
00:09:08,840 --> 00:09:11,120
protect themselves? 
I think if you're an enterprise,

180
00:09:11,120 --> 00:09:13,880
you have two ways of doing 
security here. 1 is you can 

181
00:09:13,880 --> 00:09:16,720
limit what extensions are run 
centrally, manage it. 

182
00:09:17,080 --> 00:09:19,200
Or two, you can limit the impact
of a single developer 

183
00:09:19,200 --> 00:09:22,240
workstation being packed. 
Those are both hard problems. 

184
00:09:22,440 --> 00:09:25,480
I think some companies have done
a really strong push on the 

185
00:09:25,480 --> 00:09:27,040
latter, right? 
They're they're moving to 

186
00:09:27,040 --> 00:09:30,200
Chromebooks for many roles. 
They're removing credentials 

187
00:09:30,200 --> 00:09:31,600
from machines. 
They're using virtual 

188
00:09:31,600 --> 00:09:34,040
development environments, right?
There's hardening you can do 

189
00:09:34,360 --> 00:09:38,200
that makes this less of an issue
when it happens, but maybe a 

190
00:09:38,200 --> 00:09:40,640
more targeted approach would be 
extension. 

191
00:09:40,640 --> 00:09:43,840
Allow listing and management 
centrally and and this applies 

192
00:09:43,840 --> 00:09:45,600
to all extensions. 
The importance of the supply 

193
00:09:45,600 --> 00:09:48,120
chain attack here is that it 
doesn't matter how complicated, 

194
00:09:48,120 --> 00:09:51,320
risky, interesting the extension
is. 

195
00:09:51,320 --> 00:09:53,760
We found a lot of cases where we
found the leaked tokens to 

196
00:09:53,760 --> 00:09:57,520
themes, and themes are just like
configuration bundles for colors

197
00:09:57,520 --> 00:10:00,560
in your VS Code instance. 
They don't even have codes. 

198
00:10:00,560 --> 00:10:03,120
So as a security team, you're 
inclined to allow that sort of 

199
00:10:03,120 --> 00:10:04,680
thing, right? 
Like it's not as scary as 

200
00:10:04,680 --> 00:10:07,360
something with code, but there's
nothing stopping someone taking 

201
00:10:07,360 --> 00:10:11,000
a theme and hijacking the 
developer account and pushing 

202
00:10:11,000 --> 00:10:12,800
out malware. 
There's nothing actually 

203
00:10:12,800 --> 00:10:14,720
limiting themes on the code 
execution front. 

204
00:10:15,000 --> 00:10:18,240
So another example of really 
where you have to be relatively 

205
00:10:18,240 --> 00:10:21,920
restrictive and also consider 
whether auto updates are are the

206
00:10:21,920 --> 00:10:23,400
best fit for your organization 
or not. 

207
00:10:23,640 --> 00:10:27,000
And what in terms of like what 
like just individuals can do, 

208
00:10:27,000 --> 00:10:30,760
are there any like open source 
tools that they can use to sort 

209
00:10:30,760 --> 00:10:34,840
of scan their extensions or just
in terms of best practices like 

210
00:10:34,840 --> 00:10:36,040
what that what should they be 
avoiding? 

211
00:10:36,320 --> 00:10:38,560
If the features aren't in the 
platform, individuals are gonna 

212
00:10:38,560 --> 00:10:40,240
really struggle always. 
That's my belief. 

213
00:10:40,240 --> 00:10:42,240
Right. 
Like if a platform has security 

214
00:10:42,240 --> 00:10:44,360
hardening, you can always talk 
about like the Apple App Store, 

215
00:10:44,600 --> 00:10:46,200
right? 
Apple is responsible for review.

216
00:10:46,200 --> 00:10:48,160
They are ensuring that only safe
things go through. 

217
00:10:48,480 --> 00:10:51,840
I think Step 1 is gauge your 
trust in the marketplace. 

218
00:10:51,840 --> 00:10:55,120
Like if you're using open VSX, 
there's a set of security 

219
00:10:55,120 --> 00:10:56,480
controls. 
If you're using the official 

220
00:10:56,480 --> 00:11:00,360
VSXVS code marketplace, there's 
a higher bar right now for 

221
00:11:00,360 --> 00:11:02,320
security. 
And so considering where you 

222
00:11:02,320 --> 00:11:05,560
source your extensions is part 
of your risk math. 

223
00:11:06,000 --> 00:11:11,400
I think also we, we talked about
how to measure risk in 3rd party

224
00:11:11,400 --> 00:11:18,000
packages, extensions in generic 
way, popularity history, recency

225
00:11:18,000 --> 00:11:19,840
right there. 
All these metrics you can use as

226
00:11:19,840 --> 00:11:22,840
sort of a, a thumb in the wind. 
And So what I would say is the 

227
00:11:23,640 --> 00:11:27,080
active malware we've seen, 
barring the supply chain 

228
00:11:27,080 --> 00:11:30,000
takeovers, which are impossible 
for a user to defend themselves 

229
00:11:30,000 --> 00:11:32,240
against, frankly, right? 
Like there's don't use any 

230
00:11:32,240 --> 00:11:35,480
extension because if it gets 
taken over, like you can't do 

231
00:11:35,480 --> 00:11:39,080
anything, right. 
Instead what I would say is 

232
00:11:39,560 --> 00:11:42,360
focus on very popular 
extensions. 

233
00:11:42,360 --> 00:11:44,840
Look at the publishing date, 
look at how many downloads it 

234
00:11:44,840 --> 00:11:47,120
has. 
Look at how many reviews people 

235
00:11:47,120 --> 00:11:50,160
will pump fake downloads to make
sure it's not just a brand new 

236
00:11:50,160 --> 00:11:52,000
version. 
People do typo squatting. 

237
00:11:52,200 --> 00:11:54,600
Go directly to the marketplace. 
Don't follow Google search 

238
00:11:54,600 --> 00:11:56,400
results. 
We know people do SEO poisoning 

239
00:11:56,400 --> 00:11:58,800
as part of attacks. 
They'll put fake ads in. 

240
00:11:59,200 --> 00:12:03,480
Don't go and follow some sort of
AI hallucinated slop squatted 

241
00:12:03,520 --> 00:12:08,480
extension name and really just 
consider that these are part of 

242
00:12:08,480 --> 00:12:10,400
your tax service. 
I think it's, we've gotten 

243
00:12:10,400 --> 00:12:13,360
really comfortable, same thing 
in NPM with JavaScript packages,

244
00:12:13,520 --> 00:12:17,000
just like Willy nilly expanding 
our tax service by adding on 

245
00:12:17,000 --> 00:12:19,640
other people's code, other 
people's exposure. 

246
00:12:19,880 --> 00:12:22,680
And every VS Code extension you 
bring means you're not just 

247
00:12:22,680 --> 00:12:24,600
trusting the code as it 
currently is, but if you're 

248
00:12:24,600 --> 00:12:27,840
having auto updates, you're 
trusting the publisher and their

249
00:12:27,840 --> 00:12:30,400
personal security and and just 
keeping that in mind. 

250
00:12:30,760 --> 00:12:35,360
When you found this and you had 
your big moment of glory, what 

251
00:12:35,360 --> 00:12:38,560
did you do to celebrate and 
what'd you have for dinner that 

252
00:12:38,560 --> 00:12:40,520
night? 
I did not. 

253
00:12:40,680 --> 00:12:43,400
Here's the fun part about 
research like this is you don't 

254
00:12:43,400 --> 00:12:46,120
get to celebrate until you 
publish, because you know you're

255
00:12:46,120 --> 00:12:48,560
in for a long road of 
responsible disclosure. 

256
00:12:49,720 --> 00:12:54,240
And so in fact, I I flew to the 
US the night after finally 

257
00:12:54,240 --> 00:12:58,960
publishing this blog and really 
turned off my laptop and closed 

258
00:12:58,960 --> 00:13:02,200
myself down for comments. 
Attended a beautiful wedding, so

259
00:13:02,200 --> 00:13:03,960
we'll call that the celebration 
but and. 

260
00:13:04,200 --> 00:13:06,440
It's closing your laptop is a 
celebration. 

261
00:13:06,440 --> 00:13:08,640
Anytime my laptop is closed, 
it's a good day. 

262
00:13:09,080 --> 00:13:11,400
Amazing. 
OK, Thank you for coming. 

263
00:13:11,400 --> 00:13:14,560
Thank you for sharing. 
Come back soon. 

264
00:13:14,720 --> 00:13:17,440
We appreciate all of your work 
and all of your insight. 

265
00:13:17,760 --> 00:13:19,000
Thank you. 
Give me nine months to find 

266
00:13:19,000 --> 00:13:20,960
something else interesting. 
I'll be right back. 

267
00:13:21,080 --> 00:13:26,120
All right, reddest 
vulnerability, a significant new

268
00:13:26,120 --> 00:13:27,680
vulnerability has been 
discovered. 

269
00:13:28,000 --> 00:13:30,520
So what do we know about this so
far, Amitai? 

270
00:13:31,960 --> 00:13:33,960
Well, I mean, we know a lot 
because I mean, it was 

271
00:13:33,960 --> 00:13:37,480
discovered by Wiz. 
I will say that some of the 

272
00:13:37,480 --> 00:13:41,240
details aren't public yet. 
Reason being that we're trying 

273
00:13:41,240 --> 00:13:46,720
to give people some time to 
patch before we reveal to the 

274
00:13:46,720 --> 00:13:49,280
world how this vulnerability 
actually allows. 

275
00:13:49,280 --> 00:13:53,800
RC Benny, a researcher from 
Wizard Research who discovered 

276
00:13:53,800 --> 00:13:56,800
it recently, gave a talk at 
Hexicon about this. 

277
00:13:57,320 --> 00:14:00,440
So if you were at Hexicon, you 
probably know the answer. 

278
00:14:00,440 --> 00:14:03,360
And if not, then you'll have to 
wait for our blog post or ask 

279
00:14:03,360 --> 00:14:06,080
someone who was a hexagon. 
We have to give him a tease on 

280
00:14:06,080 --> 00:14:07,640
the podcast. 
A little tease. 

281
00:14:07,840 --> 00:14:12,400
Well, I can say that it 
definitely allows RC, which is 

282
00:14:12,400 --> 00:14:15,200
not obvious because it was very 
difficult to do so from what I 

283
00:14:15,200 --> 00:14:16,840
hear. 
Do we know how many 

284
00:14:16,840 --> 00:14:19,200
organizations were potentially 
affected by this? 

285
00:14:19,200 --> 00:14:23,000
So this affected all past 
versions because it was part of 

286
00:14:23,000 --> 00:14:25,920
the Lua engine which is which 
has has always been part of 

287
00:14:25,920 --> 00:14:30,360
Redis as far as I know. 
And this probably existed for 

288
00:14:30,360 --> 00:14:34,000
around 13 years. 
And Redis is used, according to 

289
00:14:34,000 --> 00:14:36,320
our data, in around 75% of cloud
environments. 

290
00:14:38,520 --> 00:14:40,800
And this affected all of them. 
And it's really, really 

291
00:14:40,800 --> 00:14:43,680
widespread. 
A lot of people install Redis as

292
00:14:43,680 --> 00:14:46,200
part of their products. 
As a lot of people have Redis in

293
00:14:46,200 --> 00:14:48,040
their environment, then they 
don't even know about it just 

294
00:14:48,040 --> 00:14:52,040
because it comes packaged 
alongside other software that 

295
00:14:52,040 --> 00:14:55,200
uses Redis. 
So Redis is is very prevalent 

296
00:14:55,200 --> 00:14:57,840
which makes this vulnerability 
very important to batch. 

297
00:14:58,920 --> 00:15:02,800
OK so if I am listening and I 
want to know what to do, what do

298
00:15:02,880 --> 00:15:06,120
I do? 
So First off, you need to find 

299
00:15:06,840 --> 00:15:09,400
where this vulnerability is 
likely to be exploited. 

300
00:15:10,080 --> 00:15:13,520
Which means that you need to 
search for cases where it it's 

301
00:15:13,520 --> 00:15:16,480
publicly exposed, where Redis is
actually exposed to the Internet

302
00:15:17,680 --> 00:15:21,680
and running in a way that allows
you to anyone to authenticate. 

303
00:15:22,400 --> 00:15:26,440
Which means either have no 
authentication or have like a a 

304
00:15:26,440 --> 00:15:30,240
weak or default password. 
Now interestingly, Redis does 

305
00:15:30,240 --> 00:15:33,960
actually have in its default 
configuration. 

306
00:15:33,960 --> 00:15:37,240
It doesn't allow anyone to 
authenticate anonymously. 

307
00:15:37,560 --> 00:15:39,960
It doesn't even allow you to 
expose it to the intranet by 

308
00:15:39,960 --> 00:15:43,680
default. 
However, there are many flavours

309
00:15:43,680 --> 00:15:47,640
of Redis and many different ways
to install Redis, and in some of

310
00:15:47,640 --> 00:15:52,320
them, some of them which are 
really common, authentication is

311
00:15:52,320 --> 00:15:56,440
actually set to allow anonymous 
access by by default. 

312
00:15:58,120 --> 00:16:01,280
So depending on how you install 
Redis, you are either affected 

313
00:16:01,280 --> 00:16:03,720
by this or not. 
So our suggestion is again, 

314
00:16:03,720 --> 00:16:05,880
focus on publicly exposed 
instances. 

315
00:16:05,880 --> 00:16:08,440
They're misconfigured to allow 
anonymous authentication. 

316
00:16:09,200 --> 00:16:12,520
OK, next topic is the F5 
security incident. 

317
00:16:12,520 --> 00:16:16,920
So there's a network device 
manufacturing company F5. 

318
00:16:17,360 --> 00:16:19,560
They had a breach by a Chinese 
threat actor. 

319
00:16:20,800 --> 00:16:25,560
F5 makes like products like big 
IP. 

320
00:16:25,560 --> 00:16:29,760
They serve things like as a 
firewall or a router. 

321
00:16:31,280 --> 00:16:33,680
What's crazy about this, and 
we'll get into a little bit more

322
00:16:33,680 --> 00:16:37,400
details in a minute, but the 
TLDR is the threat actor was in 

323
00:16:37,400 --> 00:16:42,600
their network for two whole 
years and F5 isn't exactly clear

324
00:16:42,600 --> 00:16:45,200
on what they did in the 
environment, but they did access

325
00:16:45,200 --> 00:16:48,960
their source code. 
Yeah, I, I guess this, this 

326
00:16:48,960 --> 00:16:53,480
could be classified as infosec 
drama in some ways, although the

327
00:16:53,480 --> 00:16:57,040
drama is, is sort of between F5 
and and China. 

328
00:16:57,040 --> 00:17:03,480
I guess it's also sort of 
between F5 and like the legal 

329
00:17:03,480 --> 00:17:08,160
system and their customers and 
the rest of the community 

330
00:17:08,200 --> 00:17:12,280
because F5 took a while to 
disclose this. 

331
00:17:12,520 --> 00:17:16,319
Many times it takes a while to 
disclose these things just 

332
00:17:16,319 --> 00:17:18,160
because it takes a while to 
determine if there's actually 

333
00:17:18,160 --> 00:17:21,720
been any material impact and 
material impact, at least in the

334
00:17:21,720 --> 00:17:24,640
states, kind of determines 
whether you, whether you 

335
00:17:24,640 --> 00:17:26,599
actually need to disclose this 
publicly. 

336
00:17:27,839 --> 00:17:31,240
So there were two delays here. 1
is it took them a while to even 

337
00:17:32,040 --> 00:17:33,520
realize that they had been 
breached. 

338
00:17:33,640 --> 00:17:36,760
And once they realized this, it 
took them a while to reach the 

339
00:17:36,760 --> 00:17:39,440
point where they felt 
comfortable sharing this with 

340
00:17:39,440 --> 00:17:41,640
the world, telling people what 
happened. 

341
00:17:44,040 --> 00:17:48,480
One thing that they did, which 
was I, I, I think it made a lot 

342
00:17:48,480 --> 00:17:52,880
of sense before they went 
public, was they enlisted the 

343
00:17:52,880 --> 00:17:55,680
help of a few companies to 
basically check their source 

344
00:17:55,680 --> 00:18:02,080
code and figure out if it was 
likely that the actor inserted 

345
00:18:02,080 --> 00:18:04,640
anything malicious into their 
source code during the time that

346
00:18:04,640 --> 00:18:07,160
they were there. 
The simplest explanation is they

347
00:18:07,160 --> 00:18:09,440
just wanted the source code to 
have it. 

348
00:18:10,520 --> 00:18:13,240
Maybe they were trying to steal 
other things, like personal 

349
00:18:13,240 --> 00:18:14,640
information about their 
customers. 

350
00:18:15,280 --> 00:18:17,800
Maybe they were trying to steal 
like their documentation. 

351
00:18:18,120 --> 00:18:21,840
We know that they managed to 
gain access to information about

352
00:18:21,840 --> 00:18:24,720
vulnerabilities that hadn't been
published yet, which in theory 

353
00:18:24,720 --> 00:18:27,320
could have been like really cool
for the threat actor. 

354
00:18:27,320 --> 00:18:30,360
But in actuality, these 
vulnerabilities, when you look 

355
00:18:30,360 --> 00:18:32,840
at them, they don't really seem 
to be very interesting and of 

356
00:18:32,840 --> 00:18:36,040
themselves. 
But if they were there for for a

357
00:18:36,040 --> 00:18:39,480
while, then any vulnerability 
published over the past few 

358
00:18:39,480 --> 00:18:43,000
years, in theory they might have
had advanced notice about. 

359
00:18:43,840 --> 00:18:47,440
However, just stealing source 
code and just feeling 

360
00:18:47,440 --> 00:18:51,920
documentation doesn't seem like 
it would be worth the effort. 

361
00:18:53,960 --> 00:18:57,800
And it it kind of makes sense 
that they'd want to do a bit 

362
00:18:57,800 --> 00:19:03,400
something more. 
So I think everyone's sort of 

363
00:19:03,400 --> 00:19:05,760
wondering what they were doing 
there. 

364
00:19:06,040 --> 00:19:10,040
But what's interesting is or 
interesting depends who you are,

365
00:19:10,040 --> 00:19:13,520
but I find fascinating, we find 
fascinating is the Chinese like 

366
00:19:13,600 --> 00:19:19,120
operations aspect of this. 
Like we've seen a trend of 

367
00:19:19,120 --> 00:19:23,840
Chinese operations as of late. 
Where does this tie into it? 

368
00:19:23,840 --> 00:19:28,080
What does it tell us about their
larger maybe motives or what we 

369
00:19:28,080 --> 00:19:31,960
should be looking for for other 
things they might get themselves

370
00:19:31,960 --> 00:19:36,280
into? 
Saying that Chinese productors 

371
00:19:36,360 --> 00:19:40,000
or China in general has an 
interest in edge devices like a 

372
00:19:40,000 --> 00:19:43,680
5 big IP, that that makes a lot 
of sense. 

373
00:19:43,760 --> 00:19:50,280
Like it makes sense that they'd 
want information or the means of

374
00:19:50,520 --> 00:19:53,440
conducting a supply chain attack
or stealing vulnerabilities 

375
00:19:54,040 --> 00:19:56,920
about relevant to edge devices 
like big IP. 

376
00:19:58,680 --> 00:20:02,240
The idea is that this lets them 
get into get initial access into

377
00:20:02,240 --> 00:20:04,760
networks without requiring any 
interaction with victims. 

378
00:20:04,760 --> 00:20:08,040
Like you don't need to do social
engineering, so the attacker can

379
00:20:08,040 --> 00:20:09,760
kind of just control the 
situation. 

380
00:20:11,240 --> 00:20:13,920
It's the equivalent of like a 
zero click vulnerability on on 

381
00:20:13,920 --> 00:20:17,840
an iPhone. 
Like you decide when you get 

382
00:20:17,840 --> 00:20:21,600
into the organization and, and 
nobody can stop you because you 

383
00:20:21,600 --> 00:20:24,160
have a zero day vulnerability 
and these things are sort of 

384
00:20:24,160 --> 00:20:27,160
meant to be exposed. 
You can't not expose them. 

385
00:20:27,840 --> 00:20:30,840
And also edge devices are very 
comfortable for productors 

386
00:20:30,840 --> 00:20:33,200
because there's not a lot of 
visibility on them. 

387
00:20:33,200 --> 00:20:38,400
Usually can't install any sort 
of EDR or, or, or sensor or 

388
00:20:38,400 --> 00:20:40,320
anything like that. 
So it becomes a bit of a blind 

389
00:20:40,320 --> 00:20:42,840
spot. 
So you could deploy malware on 

390
00:20:42,840 --> 00:20:46,680
there and sort of conduct your 
operation from there without 

391
00:20:46,920 --> 00:20:51,480
anyone being the wiser. 
Other than that, China has been 

392
00:20:51,480 --> 00:20:54,480
a very aggressive in their 
pursuit of vulnerabilities. 

393
00:20:54,560 --> 00:20:57,600
They don't just research like 
they steal vulnerabilities, they

394
00:20:57,600 --> 00:21:00,400
steal information from 
vulnerability researchers. 

395
00:21:00,400 --> 00:21:04,000
They steal information from 
companies that have information 

396
00:21:04,000 --> 00:21:08,320
like F5 has about big IP. 
And there are also rumors 

397
00:21:08,320 --> 00:21:14,040
circulating that that China has 
also stolen, basically Chinese 

398
00:21:14,040 --> 00:21:18,400
offensive organizations have 
stolen or abused Chinese 

399
00:21:18,400 --> 00:21:21,400
defensive and organizations 
access to early information 

400
00:21:21,400 --> 00:21:23,960
about vulnerabilities in order 
to weaponize them and use them 

401
00:21:23,960 --> 00:21:26,760
against their their own targets,
which is one of the reasons that

402
00:21:26,760 --> 00:21:29,920
a few Chinese companies have 
have been blocked from from 

403
00:21:29,920 --> 00:21:33,640
these early access feeds. 
OK, well if we learn more we'll 

404
00:21:33,640 --> 00:21:38,400
tell you more. 
Next topic, emerging use of 

405
00:21:38,400 --> 00:21:45,840
malware invoking AI, termed 
living off the LLM, which is a 

406
00:21:45,840 --> 00:21:47,920
great theme. 
I'll start there. 

407
00:21:48,080 --> 00:21:51,560
We get a lot of questions about 
how AI is changing the game in 

408
00:21:51,560 --> 00:21:55,400
cyber attacks, reasonably so. 
Very trendy topic. 

409
00:21:55,920 --> 00:22:00,240
And while some people may argue 
that AI attacks are over hyped, 

410
00:22:00,240 --> 00:22:03,200
there's really a clear trend 
over the past year where we see 

411
00:22:03,200 --> 00:22:07,960
actors that are leveraging AI 
tooling found on workstations. 

412
00:22:09,280 --> 00:22:12,440
Some examples? 
Lame hug Amazon Q developer 

413
00:22:12,440 --> 00:22:18,440
extension compromise singularity
dot dot dot amitai. 

414
00:22:18,440 --> 00:22:22,000
What is living off the LLM? 
I also really like that name. 

415
00:22:23,320 --> 00:22:28,360
I think we took it from a 
article from Oak Ridge National 

416
00:22:28,360 --> 00:22:30,800
Laboratory, I think. 
I don't know if they coined 

417
00:22:30,800 --> 00:22:33,360
this, but I think that's where I
sort of saw this this recently. 

418
00:22:35,000 --> 00:22:37,760
And yeah, the idea is that you 
have like living off the land, 

419
00:22:37,760 --> 00:22:40,480
which is a term that's been 
around for a while where instead

420
00:22:40,480 --> 00:22:43,800
of fed actors sort of bringing 
their own tooling into the 

421
00:22:43,800 --> 00:22:46,200
environment which it which has a
higher likelihood of being 

422
00:22:46,200 --> 00:22:50,920
detected, they basically live 
off the land in the sense that 

423
00:22:50,920 --> 00:22:52,760
they use things that are already
there. 

424
00:22:53,160 --> 00:22:59,400
So on all of our computers and 
in servers in in our company 

425
00:22:59,400 --> 00:23:03,240
networks, there is already 
tooling that they can use or 

426
00:23:03,240 --> 00:23:06,280
abuse for their own means for 
their own ends. 

427
00:23:07,800 --> 00:23:10,680
So the idea is that they have to
be smart about how they do this.

428
00:23:10,680 --> 00:23:13,880
And but it's things that are 
like already running things that

429
00:23:13,880 --> 00:23:18,800
are already generating a lot of 
noise that they can hide in. 

430
00:23:20,160 --> 00:23:26,000
And now with the advent of 
people installing CL is for the 

431
00:23:26,000 --> 00:23:31,200
various AI services like like 
Claude and, and, and open AI and

432
00:23:31,200 --> 00:23:35,040
Gemini. 
So with those things being 

433
00:23:36,160 --> 00:23:39,560
installed by people on their 
laptops, attackers are now 

434
00:23:39,560 --> 00:23:40,960
starting to take advantage of 
that. 

435
00:23:41,600 --> 00:23:44,400
And it's, it's really 
interesting because like like in

436
00:23:44,400 --> 00:23:49,600
the examples you mentioned, 
basically attackers are are 

437
00:23:49,680 --> 00:23:52,240
building in functionality into 
the malware that they're 

438
00:23:52,240 --> 00:23:57,080
deploying on Victor machines to 
take advantage of those CL is if

439
00:23:57,080 --> 00:24:01,840
they are present on the machine.
In this case, the prompt becomes

440
00:24:01,840 --> 00:24:03,640
the indicator of compromise, 
right? 

441
00:24:03,640 --> 00:24:07,240
So what kind of monitoring needs
to be put in place to capture? 

442
00:24:07,240 --> 00:24:09,960
Be aware of that this is 
happening to detect it. 

443
00:24:10,840 --> 00:24:13,800
So what you're going to see in 
these cases is you're going to 

444
00:24:13,800 --> 00:24:18,720
see basically, let's say a 
script that the malware is using

445
00:24:18,720 --> 00:24:22,200
when the attacker puts it on the
machine once they gain access. 

446
00:24:22,200 --> 00:24:25,240
And that script is going to be 
invoking the LLM through the 

447
00:24:25,280 --> 00:24:29,680
AICLI and it's going to be 
prompting things like help me 

448
00:24:29,680 --> 00:24:32,560
find all of the sensitive data 
on this laptop. 

449
00:24:32,640 --> 00:24:37,240
Those prompts in and of 
themselves can be IOCSI want to 

450
00:24:37,240 --> 00:24:41,600
reference the project called 
Nova, developed by Thomas. 

451
00:24:41,600 --> 00:24:44,280
I hope I'm saying his name 
correctly, Thomas Rosia for 

452
00:24:44,280 --> 00:24:47,880
Microsoft. 
And he built this project that's

453
00:24:47,880 --> 00:24:55,160
sort of a a way to sort of make 
these sort of IO CS actionable 

454
00:24:55,480 --> 00:24:58,760
by sort of scanning the logs of 
a ICLIS, for example. 

455
00:24:58,760 --> 00:25:01,440
And you can look for prompts 
that are known to be associated 

456
00:25:01,440 --> 00:25:05,000
with specific malware because 
the prompt itself might be like 

457
00:25:05,000 --> 00:25:07,280
a specific string. 
It might always be the exact 

458
00:25:07,280 --> 00:25:12,080
same sentence. 
Often times before doing that 

459
00:25:12,080 --> 00:25:14,640
sort of thing like helping find 
all of the sensitive thousands 

460
00:25:14,640 --> 00:25:17,040
machine, they first need to 
jailbreak the LLM. 

461
00:25:17,960 --> 00:25:22,200
And those jailbreak prompts are 
also sort of recognizable 

462
00:25:22,200 --> 00:25:24,080
because they often repeat 
themselves and they're often 

463
00:25:24,480 --> 00:25:28,200
phrased the exact same way. 
So you can use like similar to 

464
00:25:28,640 --> 00:25:31,600
scanning for hashes or scanning 
for certain strings that they 

465
00:25:31,600 --> 00:25:34,240
might indicate. 
So in the malware you can also 

466
00:25:34,240 --> 00:25:37,800
scan for specific prompts. 
We can ask you a naive question 

467
00:25:37,800 --> 00:25:40,200
that can I tell if something 
happened to my personal 

468
00:25:40,200 --> 00:25:42,800
workstation or just as an 
organization, can I do 

469
00:25:42,840 --> 00:25:45,880
monitoring? 
So that that's a good question. 

470
00:25:46,120 --> 00:25:51,720
I think if you are using NAICLII
think you have logs in some 

471
00:25:51,720 --> 00:25:54,120
cases. 
However, in many cases those 

472
00:25:54,120 --> 00:25:57,760
logs will cost a bit more money 
or a lot more money depending on

473
00:25:57,760 --> 00:26:01,080
how much you use them. 
So for this to be done at scale,

474
00:26:01,080 --> 00:26:07,160
an organization does need to 
have that logging enabled in 

475
00:26:07,160 --> 00:26:09,080
their in their cloud account, 
for example. 

476
00:26:09,320 --> 00:26:12,480
However, you can do these scans 
locally like you can scan your 

477
00:26:12,480 --> 00:26:16,000
machine for the malware for the 
prompt like in the malware 

478
00:26:16,000 --> 00:26:17,880
binary, for example. 
So like there are two different 

479
00:26:17,880 --> 00:26:20,560
places you can do this scam. 
For the attackers that are 

480
00:26:20,560 --> 00:26:23,840
pursuing this, like why are they
using this mechanism? 

481
00:26:23,840 --> 00:26:25,960
What does it give on? 
I think our leading theory right

482
00:26:25,960 --> 00:26:29,600
now is that they're doing this 
for for stealth, for operational

483
00:26:29,600 --> 00:26:35,040
security, just because this 
means that when you scan the 

484
00:26:35,040 --> 00:26:38,920
malware itself, it doesn't 
appear necessarily malicious 

485
00:26:39,400 --> 00:26:43,800
because again, it just contains 
a prompt, which is just works, 

486
00:26:43,880 --> 00:26:46,360
right? 
It contains a sentence and that 

487
00:26:46,360 --> 00:26:50,000
isn't something that Ed Rs or 
malware scanners are are looking

488
00:26:50,000 --> 00:26:53,200
for yet at scale. 
But again, if we start doing 

489
00:26:53,400 --> 00:26:58,120
things like what Nova sort of 
allows you to do at scale, then 

490
00:26:58,120 --> 00:27:00,760
that might make this technique a
bit more a bit more difficult to

491
00:27:00,760 --> 00:27:02,880
implement. 
Interesting. 

492
00:27:03,280 --> 00:27:06,840
If you want to learn more about 
this, there's a wonderful blog 

493
00:27:06,840 --> 00:27:12,120
post by Scott Piper on malware 
invoking AI and highly 

494
00:27:12,120 --> 00:27:14,200
recommend. 
We will link it, check it out. 

495
00:27:15,840 --> 00:27:19,000
OK, to close off, we have a new 
section, Quick Hits. 

496
00:27:19,560 --> 00:27:23,240
It is to cover things you cannot
do anything about, but we've 

497
00:27:23,240 --> 00:27:27,880
decided you should know about #1
the Crimson Collective threat 

498
00:27:27,880 --> 00:27:30,160
actor. 
This is great. 

499
00:27:30,400 --> 00:27:34,240
This is by, well, great, 
depending on who you are. 

500
00:27:34,320 --> 00:27:36,200
Just like the the F5 incident is
fun. 

501
00:27:36,480 --> 00:27:38,480
It's it's great in the same 
sense that it was fun. 

502
00:27:38,760 --> 00:27:41,840
It is a group that appears to be
related to Lopsys and Scattered 

503
00:27:41,840 --> 00:27:46,400
Spider, IE the Calm Teenagers, 
and they seem to target 

504
00:27:46,400 --> 00:27:51,520
companies only with red logos 
like Red Hat and Nintendo. 

505
00:27:52,240 --> 00:27:56,280
Now it's unclear if they only 
target red logo companies or 

506
00:27:56,280 --> 00:28:01,520
when they successfully hit a red
logo company they claim it by 

507
00:28:01,520 --> 00:28:03,840
the Crimson Group. 
Do you think red is their 

508
00:28:03,840 --> 00:28:05,600
favorite color? 
How do you think they got to 

509
00:28:05,600 --> 00:28:08,240
this? 
I'm sure this is some like in 

510
00:28:08,240 --> 00:28:10,600
this is some inside joke. 
I mean it, it has to be. 

511
00:28:11,360 --> 00:28:14,840
I mean that I don't, I don't, I 
don't see what else it could be.

512
00:28:15,160 --> 00:28:19,200
Maybe this is opposed to the end
of the section, but what could 

513
00:28:19,200 --> 00:28:20,720
you do about this? 
Yeah. 

514
00:28:20,720 --> 00:28:23,400
So I think the only thing you 
could do is potentially change 

515
00:28:23,400 --> 00:28:25,720
your logo. 
I mean, if they're going after 

516
00:28:25,720 --> 00:28:29,720
red, red logo companies, then if
you go to red logo, you know 

517
00:28:29,720 --> 00:28:31,360
what you need to do. 
Get creative. 

518
00:28:31,920 --> 00:28:36,840
So our second quick hit was a 
crazy bug in Inter ID discovered

519
00:28:36,840 --> 00:28:41,920
by Dirk Chan and Malema, who's a
great Azure researcher. 

520
00:28:42,320 --> 00:28:46,320
And this vulnerability was a 
cross tender vulnerability that 

521
00:28:46,320 --> 00:28:50,040
could have allowed any attacker 
with relatively minimal effort 

522
00:28:50,320 --> 00:28:53,760
to gain admin privileges on any 
Azure customer. 

523
00:28:53,920 --> 00:28:56,680
And Microsoft has fixed it. 
So you don't need to do anything

524
00:28:56,680 --> 00:29:00,600
about it. 
I think he did write up a few 

525
00:29:00,600 --> 00:29:04,680
ideas on how you could 
potentially verify for yourself 

526
00:29:04,680 --> 00:29:05,800
whether you were exploited by 
this. 

527
00:29:05,800 --> 00:29:08,640
So do check out his blog post 
which we will link to. 

528
00:29:08,760 --> 00:29:11,120
And then tell us in the comments
if you liked quick hits. 

529
00:29:11,120 --> 00:29:12,960
We could keep it running or we 
could kill it. 

530
00:29:12,960 --> 00:29:16,920
So let us know. 
And on that note, if you enjoyed

531
00:29:16,920 --> 00:29:20,040
the show, be sure to subscribe 
and share a link to the podcast,

532
00:29:20,040 --> 00:29:23,840
but not your cloud keys. 
And as always, if your cloud 

533
00:29:23,840 --> 00:29:26,400
security strategy is making you 
cry, don't worry. 

534
00:29:26,400 --> 00:29:27,360
Just cry out. 
Cloud security. 

535
00:29:28,120 --> 00:29:28,480
Security.
