
Loading summary
A
Foreign.
B
And welcome to Risky Business. My name's Patrick Gray. We've got a great show for you this week. We're going to jump into it in just a moment with Adam Barlow and talk about all of the week's cyber security news. And then we'll be hearing from this week's sponsor. And this week's show is brought to you by Authentic, which is an open source idp. Now, of course you can get it with some paid for enterprise sort of features, but the whole thing is sort of inspectable, open source goodness. And the CEO of Authentic, Fletcher Heisler, will be joining us a little bit later on to talk about, I guess, some new features that they've introduced. One of them is, you know, and it's been a process to get this one working, but one of the new features is you can, you know, enter your SSO creds into your workstation to unlock your workstation. So that sort of unified single sign on, which is actually single sign on. So that's cool. And we'll talk to him about how it was a little bit trickier developing that feature for Windows as compared to, say, Linux. That one's coming up later. But first up, of course, it is time for a check with the week's security news with Adam Boileau. And I guess the big news this week, especially for those of us who've been in the industry for so long, Adam, is that Marianne Davidson, the nemesis in many ways of the hacker community, is no longer at Oracle. She is out and it's not really clear why. But her departure did come very shortly after that massive incident affecting the Oracle's cloud. And you do wonder if those two things are connected.
A
I mean, it would make sense that they would be connected. And like that particular incident with Oracle, Cloud was also not handled particularly well. There was quite a bit of, oh, it was our, it wasn't our real cloud, it was our backup cloud or our, you know, it was a legacy cloud.
B
That's what they called it, legacy cloud. First of all, they denied the incident. So there was that. They were bullshit. They were bull. And I'm sorry to production people for having to beep that, but that's what they were doing when this happened. They said, oh, no, our cloud was not owned. And then later on it turned into, well, our, you know, our real, yeah, our real cloud wasn't owned, but there was some legacy cloud. But, you know, you and I talked about that. And if they left old rotting boxes hanging around in their cloud environment and people were able to own Them that would have given them, you know, perhaps better access to even the more modern cloud bits and pieces. So it was, yeah, it was a bad incident and the comms and handling of it were terrible. And you do wonder, well, is that what maybe led to her departure here?
A
Yeah, yeah. I mean, that certainly kind of makes sense. And I mean, she had also a pretty long history with Oracle. And as you suggested in the, you know, in the intro there, like, we weren't super fond of Oracle's, you know, kind of positioning around, you know, full disclosure and around how bugs should be handled. And even, you know, she made a blog post once upon a time about, you know, how we shouldn't reverse engineer Oracle products. We are violating their licenses or their intellectual property or whatever by looking at it.
B
Yeah. She was like, don't go looking for bugs in our products. That's our job. And we will pursue legal action against people who are reverse engineering our products. And keep in mind, like, this is when Oracle's products are just like every, every time anyone would pick one up and shake it around a little bit, like just CVSS10s flying out of them, right? And they're like, no, don't go looking for bugs. We've got that, it's under control. So, I mean, in some ways though, this counts against the theory that her departure is linked to this incident because it would be the first time Oracle actually took any concrete step in result, you know, in response to something bad going on with security.
A
Right, yeah, yeah, exactly, exactly. And you know, you know, she's been there a long time, like 40 years. You know, this is not like, you know, we're not a giant Japanese zaibatsu where you work for life. You know, this is. Computers tend to be. People don't stay there for 40 years. So she's worked her way up and I imagine she has done many good things. But Oracle, and especially when they introduced that unbreakable as their sort of tagline for their Linux. I remember that just being the butt of the industry's jokes for such a long time because the Oracle stuff very clearly was not. And then they also aggravated us by buying and killing sun, which, you know, all us old UNIX nerds liked Sun Microsystems and did not like Oracle and then them, you know, killing the sun, you know, the sun vision of the network computer. You know, lots of us were still salty about that for a long time. So maybe, maybe she's not the only old person that's interested, needs to go. I don't know.
B
Well, I mean, I'm just remembering back to the unbreakable stuff where David Litchfield, who I believe now works at Apple, David Litchfield, back in the day, you know, he's, he's very well known, was very well known back in the day for being the guy who would find Oracle bugs, right, like in their, in their database stuff. And I think he managed to find something like 20 CVEs in an Oracle product, like during the first 24 hours after they announced their unbreakable thing, you know, which just, just to point out how ridiculous of a, of a whole idea that is. So I guess it's not controversial to say that, you know, among security researchers and the, you know, know, security community, as it was 20 years ago, she's a pretty controversial figure and a lot of people are like, literally going to be dancing on a, on a professional grave here. Like, you know, it's unfortunate, I guess, but it is what it is.
A
I mean, it certainly is. You know, and I know when, you know, I found bugs and Oracle products over the years and the idea of responsibly disclosing them to Oracle as opposed to just like using them and then putting them on the shelf or selling them live on stage during a keynote, which I did once in Canberra, which is fun, you know, that kind of relationship with researchers, it does cost you if you burn it. And at the same time, if you have a good relationship and, like, it helps you, you know, get those bugs out of the community, maybe not pay such top dollar for them. I mean, but hang on, hang on.
B
Counterpoint, right? You say, well, it does damage you. How was Oracle damaged? I mean, Oracle is just to the moon, right? Oracle's done fine. So I think that the lesson here could be you can treat security researchers like absolute trash. Over 27 years there where she was the CISO and nothing bad happens.
A
Yeah, that's very true. Yeah. Maybe they get to buy a TikTok and everyone can live happily ever after in the Oracle future.
B
So, yeah, I mean, look, it's entirely possible that Marianne Davidson has just decided to retire. She's been the CISO over there for 27 years. It's entirely possible that's the case. But it does come very shortly after this cloud incident. And I do sort of think, I mean, you know, you and I, when we spoke about this incident, sort of said, you know, we agreed, right, that it was sort of unforgivable that they had such ancient boxes running in their cloud environment. Like, what was it? It was like oracle 11.
A
It was sunos tenos ten sorry, sorry, sorry.
B
Yeah, yeah, yeah, that's what I mean. So, yeah, like, just sort of unforgivable. And we were sort of saying, like, it's pretty obvious that they weren't doing any sort of asset discovery in their cloud environment, and that's like, what, like, that is just completely insane. So, yeah, who knows? Might have just retired, but either way, Marianne Davidson is no longer at Oracle.
A
So, yeah, I guess we'll see. We'll see who replaces her and whether they are worse.
B
Introducing our new CEO, Satan. Let's see. Maybe it's a little bit unfair to compare her to Satan, but, you know, you never know. All right, so maybe a little unfair. So let's move on now and talk about a lawsuit in the US that's been kicked off by New Yorker Attorney General Letitia James. So this is a lawsuit against Zelle, the payment platform in the US and this was the payment platform that was spun up by some of the major banks when they were facing, you know, instant payments competition from the likes of, like, I don't know, Cash app or whatever, I'm not American, you know, those apps. So they started their own one. And the. The lawsuit alleges that they really didn't do anything about fraud just to prioritize growth. And if you click through and read the lawsuit document. So we're going off a story written by John Greig over at the Record, but you can click through to the actual lawsuit, and what it says is that Zelle actually came up with a whole suite of protections in 2019 that would have really helped to combat some of the easiest fraud that was taking place, and they just never implemented them because they wanted to prioritize growth. They wound up implementing them in 2023. And despite Zelle just growing like mad, fraud actually went down by hundreds of millions of dollars a year. So the lawsuit is basically alleging that what they did in 2019 by not introducing these very reasonable controls was, you know, wrong and bad. And they're going to sue them and I imagine go after them for huge fines or something.
A
Yeah. Which I guess, you know, kind of makes sense if you're going to build a big payment platform or any kind of big platform these days, you know, security isn't a thing that you can bolt on afterwards and hope. Right. I mean. Well, the irony is it is exactly what everybody does. But, you know, in the ideal world, in the world that the, you know, the Attorney General's office would like to create and is tasked with creating that's, you know, fair and reasonable and equitable and all those kinds of things. You know, you shouldn't be able to just yolo your security and your fraud and all of your other controls in favour of getting enough market share to become too big to fail. Which, you know, you look at the rise of Uber and the rise of a bunch of other companies where they, you know, that's sort of the concept of regulatory escape velocity where you just got to outrun the regulators and the, you know, SEC and investors and everybody else so that you get so big so quick it doesn't matter. And that's kind of what this lawsuit I think has taken aim at is that sort of growth hacking.
B
Now look, staying with the theme of fraud, Brian Krebs has an excellent write up on this, I guess fraud fraud organization that he has been tracking for a while, based out of China. So this was the group that was doing a lot of like Apple Wallet, mobile wallet payments fraud and stuff. And even those relay attacks, we've spoken about it a couple of times, apparently they've now pivoted pretty hard into obtaining access to people's brokerage accounts so that they can dump all of their blue chip stocks and then use it to buy penny stocks for adding flated co costs that these attackers already have, you know, owned, right? They, so they go and they buy a bunch of penny stocks and then they hack brokerage accounts and buy the penny stocks from them at inflated prices. And it, it looks like, I mean, this is a feature, right, that, that Brian's written here. But I mean, what's amazing about this is like every time he writes about this group, the amazing thing here is the industrial scale that they're operating at. And I think if you work in risk at one of the, one of the brokerage companies, like you've got to have a pretty solid look at this one.
A
Yeah, yeah, it's a really good kind of write up of a story that we've seen. You know, we've covered it as it sort of bubbled up over the last, you know, kind of three months or so as various brokerages and, you know, exchanges and stuff have had, you know, weird fraudulent activity. But kind of tying it together into a big picture is what Brian's good at. And this group, he says it was doing kind of industrial scale fishing of like bank accounts and other financial institutions. But as the security controls around those have become more robust, they've pivoted towards using brokerage accounts as a way to kind of turn computers into money and also by kind of using the brokerage Accounts to, as you said, buy cheap stocks or, you know, sell people's existing stocks, buy cheap ones that they already own, they can kind of decouple themselves from it in the like as a sort of alternative to money laundering, I guess, because you've got that level of indirection that, that the stock market is providing you that kind of reduces some of the money laundering complexity. But there that tied in.
B
Well, I don't know, man. I mean, it's pretty easy to trace some of this back. I mean, I mean, I think that's why they're using like, you know, Chinese penny stocks for this sort of thing. So I guess, I guess, yes. But it's always going to be very clear what happened and who done it. It's just like, well, what's your legal remedy? I guess.
A
Yeah, yeah. So it does provide sort of a degree of indirection, I suppose, is what Brian says. But yeah, these are also the group that has been, you know, selling preloaded mobile phones with, you know, online banking, you know, electronic payment loaded on them and that kind of thing. So they're a pretty flexible and diverse and as you say, industrial scale financial fraud operation. And, you know, that's a thing that, yeah, if you work in not just core finance industry, but anything kind of on the edge, you know, probably you need to be aware of what's going on.
B
Well, and you know, once this gets under control, it seems like these are the sort of people who are just going to pivot into the next thing. Right. Because they are operating their cybercrime group like a proper business.
A
Yeah. They're agile and responsive and they are.
B
Now, let's talk about T on her because a while ago, a while back, we spoke about this breach at an app called T, which is the, the app that allowed women to share, I guess, intelligence on men that they were dating or planning to date or whatever. They could find out if a guy was a creep or if he was like really nice or whatever. Obviously this is the sort of app that made like, you know, incel losers feel really sad. So some incel loser actually cobbled together a opposing app, you see, called T on Her. You get it? You get it? It's very clever, you see, and they did a wonderful job with the security here. Adam. Like as good, if not better than the actual tea app.
A
Yes. So TechCrunch, Zachwide DeGriver. TechCrunch had written up the story of this tea on their app when it broke. And they started looking into it because there had been obviously vulnerabilities with tea and information leaking. So they went to go look at this thing to see how it was built, and it turned out to be not only at least as bad, if not worse, they found bugs in the first 10 minutes of looking at it that were, you know, pretty catastrophic. And this, you know, Zach writes up that process that they went through, the core guts of it was, you know, clearly this guy had Vibe coded it together on the weekend. There was an API server that basically implemented all the functionality of the app and it just had no auth. You could just connect to the APIs and do as you please. And all of the data that people were submitting when they signed up, the identity scans, because they did the same thing as TE in terms of how they, you know, we're trying to validate that all the users were men's, so they, you know, did the same sort of thing and even worse, except that at least, you know, people were using T T on her, you know, not so much. There was, you know, much smaller.
B
Well, because the sort of people who are going to sign up to a service like that are probably not the sort of people who actually date a lot. I'm going to just go out on a limb here, you know, I mean.
A
You know, we got.
B
No, it's going to be full of a bunch of Redditors complaining about women who never called them back. I suspect it's going to be the core complaints among this particular population.
A
But, yeah, the funny thing was that when TechCrunch tried to report the issues to the guy that wrote it, he was like, no, no, you must be confusing us with the actual Tapp, because the bugs were so similar and they're like, nobody, have you tried, like, did you have to enter a password at any point in the development of this thing? And he was like, oh, so, yeah, funny.
B
Yes, yes. Bit of a. Bit of a. Yeah, bit of a comedy story for the week. Now, look, here's a really weird yarn this week and it's doing the rounds everywhere. We're going with the Guardian version here because I think they did a good job. Their headline is, UK has backed down on demand to access US Apple user data. Spy Chief said. Now that is a very tightly scoped headline because really this whole thing hinges on a tweet by Tulsi Gabbard, who's the. What is she? The Director of National Intelligence or whatnot in the. In the United States? And she has said, you know, now Apple will, you know, will no longer be, you know, the UK government is no longer demanding that Apple expose the encrypted data of American citizens. And that's the interesting part. So all of this goes back to, I think there was a technical capability notice issued by the Brits to Apple, which Apple are apparently fighting. But it did result in Apple turning off advanced data protection for new accounts in the UK and rolling out a plan to actually disable it for people who already had it. I don't know if that's still the plan, but that was, that was what happened at the time. So. And then it was very controversial because Gabbard was like saying, oh, you know, the Brits want to be able to have a capability to reach in and get Americans data where, I mean, we haven't seen the tcn, so we can't say. But I would imagine that if this is the status quo, where it's wound up, which is that ADP has just turned off for Brits, they don't need that TCN to be acted on. So it might have just, you know, all of this might have just come down to the fact that Apple is just going to leave ADP turned off for Brits and that's where this is settled. And now Gabbard is trying to turn this into some huge victory. So I don't know, I don't know what the actual story is here. Like, I think perhaps it was like the Brits saying we need to be able to access this sort of information and Apple saying, well, we're not going to build that for you, but we can turn off adp. And the Brits said okay. And that's just where it landed. And now they've dropped the request to have like a capability developed that would allow them to break E2E, you know, backups or whatnot. Anyway, my point is it's really unclear what's happened here and there's a lot of reporting based on a single tweet. And I think the Guardian has done the best job here of just saying, you know, of looking at the tightly scoped wording that Gabbard's used and actually pulling that into the headline. So good job, Guardian.
A
Yeah, it doesn't make a whole bunch of sense because a UK technical capability notice wouldn't result in Americans data being collected anyway. I mean that the point of it is it would be a British jurisdiction thing and I guess Americans in the UK maybe there's some edge cases there, but as a general kind of thing, it didn't make a whole, the American angle to. It didn't make a whole bunch of sense Here and as you say it's not clear what has changed and what the backing down would be so.
B
Exactly.
A
It feels like political talky talky and not actual thing happened but you know, I don't know. And then you know, there's also the added wrinkle that Apple's advanced data protection is one aspect of their end to endedness and so things like iMessage and FaceTime and so on are E2EE independently from the ADP feature set. Like that was about something some specific data types that get stored in icloud but there are other things that are stored in icloud that are still end to end encrypted that weren't covered by adp. So like the whole, you know, in terms of what does it mean for the average Apple user in Britain? Probably not a whole bunch. And then what Americans have to do with it, who knows?
B
Yeah, yeah. So the whole thing is just really weird. I mean maybe we'll find out more later but who knows? Now let's talk about a announcement from Workday where they've had an interesting incident where someone has owned their staff's accounts at their upstream CRM and they're using that to then attack their customers. So this is interesting. This is one of those security breaches affecting, you know, it's a security breach affecting Workday that didn't touch their systems at all. Sign of the times. And it's. And it's like a comm adjacent, you know, scattered spider slash slash shiny hunters thing, you know and they're the sort of people who are doing this sort of social engineering and in this case like going after tickets in their CRM platform.
A
Yeah, I think this is part of that larger campaign that we reported on. I think a few companies having their Salesforce accounts compromised. That is social engineering. Someone with that access and then leveraging that into Salesforce harvesting the data out and then attempting to ransom the organization whose data it is for some kind of payment. And that we saw Google reported on the group that were doing it and also said by the way our Salesforce, Google Salesforce got data compromised out of it as well. And the nature of the data that got taken from Workday, Salesforce and a bunch of the other ones is pretty much like customer contact information which if you are trying to turn it into fraud can be useful because you can target those, you know, phishers or whatever else more effectively.
B
Yeah, but it's not like ransom gold. Right? Like it's not the sort of stuff people are going to pay to Stop leaking.
A
No, and I don't know, you know, we don't know how many organisations may have paid them. Presumably they wouldn't be shaking people down for it if it was actually, if it wasn't working at all. They must have got some. Perhaps. But I think, you know, probably there is a reasonable amount of, you know, there's so much data extortion going on, people don't want to be in the media and, you know, even when it smells like, oh, God, this could look terrible, let's just pay them. They're not asking for much. Make it go away. Maybe that's enough to make it worthwhile doing. And then on the other hand, maybe us covering people who are getting compromised like this is actually helping the scammers, you know, apply leverage and get. And get paid. So it's always, you know, this kind of like extortion, you know, data extortion is just kind of weird like that. Especially when you have to report on it.
B
Yeah, yeah. I mean, nowhere in this is meant is Salesforce mentioned, by the way. So I'll just point that out. It just says CRM. But there has been a lot of activity targeting Salesforce. But, I mean, are you just making an assumption there or have you heard something?
A
I'm making an assumption because the actors sound the same. The wording third party CRM platform is pretty much what a bunch of the other Salesforce customers have used when they've been talking about it.
B
So probably Salesforce asking them to use that.
A
That's the kind of vibe that I get. Yes. Yeah.
B
Now, a couple of weeks back, we had our colleague Amberly Jack on the show talking about Max messenger, which is rush's answer to WeChat. And you know, we predicted when we had that conversation that, that Russia was going to start making WhatsApp unreliable, start restricting it, trying to squeeze more people onto this Max platform that is now happening. So we've got some reporting here from Darina Antoniuk over at the Record, which looks at what Russia is doing to curb WhatsApp and Telegram use. And you've got to love the pretext here, which is they're saying they are curbing access to these applications because of cybercrime.
A
Yeah, that's sort of some irony there, isn't there?
B
I mean, I'm surprised they're not saying, you know, WhatsApp and Telegram have, have WMDs. Right. Like, it's like such an obviously bogus pretext.
A
Yeah, yeah, exactly. So people have been reporting that call setup has been failing across some of those messages or the quality of the call has been degraded to the point that it's just gobble, gobble, you know, compression artifacts. Whereas, of course, MAX works flawlessly and is easily available and will soon be installed by default on every phone in Russia.
B
So, yeah, and there's no cybercrime happens on it. Absolutely zero crimes happen on max.
A
Yes. See, it's a little, little bit transparent there, Russia, but hey, what are we going to do about it?
B
That's.
A
That's how Russia rolls.
B
Yeah. And I just want to say one thing about the WMD joke there, because it's funny. I don't know if you've noticed this, but when you talk to people who are just a bit younger than us, like not even a lot younger than us, just a bit younger than us, they remember the invasion, you know, they know about the invasion of Iraq and that the pretext was wrong. What they don't know is that everybody in the world knew that the pretext was bullshit at the time. And it's amazing how this is a bit of. This is a key aspect to the history that's just been lost, which is everybody knew There were no WMDs in Iraq and that it was just a pretext. It's sort of like Trump's stuff about tariffs on Canada being about fentanyl, which they're clearly not. It's just a. It's a silly pretext that everybody knows is a lie. It was the same way in 2003 and I don't know why I felt I needed to get that off my chest. But it's so that you understand the joke, you see, it's so that you understand the joke.
A
Jokes playing for the children who are listening.
B
Yeah, exactly. Right. And by children, we mean people who are like 35 and younger. Yeah, I've got it. Yeah. Anyway, Anyway, anyway, speaking of Canada, there has been a compromise at the House of Commons, apparently through a Microsoft vulnerability. We're going to go ahead and guess that's a SharePoint, you know the SharePoint on prem bug.
A
Yeah. That seems like they said it was like something that was passed recently. And yeah, we've had a good set of Microsoft bugs lately. Could be anything. The nature of the data taken was employee details or job titles and locations and emails, but also information about their managed computers and devices. So that kind of feels like they've landed probably in a SharePoint site that was involved in device management and so on. So, you know, we. I think this has been sort of attributed. Ish towards China. Like we haven't seen a concrete attribution but you know, China attacking parliaments of five eyes countries is a thing that both your country and my country have experienced. So it makes sense that Canada would be on that list as well.
B
So I mean it's not, it's not exactly advanced Cluedo, is it? You know, it was, it was China with the SharePoint bug in the drawing room, you know, like it's just. Come on, who else? Who else? Now let's turn our attention to Norway and the police there believe that pro Russian hackers were behind an attack against a dams industrial control systems. Now this attack didn't really result in anything terribly bad happening because it was a well designed system but nonetheless you got hacktivists starting to flip switches and open valves at dams. Kind of newsworthy.
A
Yeah, it's not, it's certainly not great and I don't know that. I think when we originally talked about this, you know, it wasn't attributed to anyone but it certainly felt like it was probably hacktivists of some sort. And Russia link totally makes sense. So no real surprises there. The dam in question was not hydro, it was like fishing related I think. And you know, the operator of the dam said there wasn't much particular impact but as you say. Yeah, like when you've got people busted in and just you know, flipping switches, opening stuff, trying to cause damage even when it's not effective. Yeah, it's, it's not great.
B
Now speaking of operational technology, industrial control systems and whatnot, CISA and a bunch of other agencies, not just American agencies, the Australia's own signals directorate was involved for example. They've released a 31 page document and it's guidance on, on OT asset inventorying. So how to discover how to catalog, how to, you know, how to think about, you know, maintaining an asset inventory of IoT systems. I think this is like people underestimate the degree to which guidance like this is actually necessary because so many of the operators of critical infrastructure don't even have security teams, you know, or if they do, it's like one person I'm thinking about like municipalities in, and you know, in Australia we call them local governments where you know, you and I both know someone who works for one of these, one of these local governments and you know, it's like one person who's all of a sudden being told, oh by the way, you know, all of this critical infrastructure, you know, make that secure while they're also trying to, you know, run the desktop environment and whatever. So I think this is A good move. I've had a thumb through the guidance. It looks pretty sensible.
A
Yeah, yeah. I mean, I know, you know, guidance like this is just really helpful to put in front of your leadership when you're trying to secure some budget or present a plan for how you're going to address the high level goals of let's not get hacked, let's not be insecure. But the actual concrete steps of that are quite involved. And this document is good because it's a blend of high level guidance. But also they've got a bunch of examples, like worked examples of here's how we worked through this with an electricity provider and here's how he did it with a water provider and just kind of give you some good ideas to look at. And things as simple as like what data should an asset register for an OT environment contain? Like what things do we need to collect and how important are they? And that's the kind of stuff that, you know, if you have to work on that stuff from scratch, you know, you spend three months coming up with a taxonomy before you even started doing any actual useful work. Here is a thing that you can basically kind of pull off and start applying straight away. And that's just really helpful guidance. It's useful, you know, it's more useful than immediately regulating the crap out of everyone with no guidance or giving them token amounts of money to go spend with commercial providers that are going to, you know, incentivize to not necessarily help them but to sell them things. So this is a good approach and applies, you know, from small up to very big organizations.
B
Now we're going to talk about something we never ever, ever talk about.
A
This is brand new, very exciting. I've never seen this before for It's a Fortinet bug.
B
Hey, Fortinet bug. Yay.
A
Woohoo. Oh dear. Man. This bug. So it's called Fort majeure. Fort majeure, which I think is a very good name for a Fortinet bug. And the person who found it has written it up on written up a blog post about it. It's auth bypass leading to access in 40 web.
B
What's a Forti web?
A
So that's the web app management interface for their web app firewall. I guess that's what I'm trying to say. And as you said, we have had so many fortinet bugs and in that respect it is no different than any other Fortinet bug. It's just trash. The reason I wanted to talk about this one is that this bug is Basically, in one of the authentication headers, there is a value which is used to look up some encryption keys in a table in memory. So there's an array in memory of encryption keys and there is an index which tells it which encryption key this particular message is going to be, this cookie is going to be encrypted with. You could just provide very big values for that and read off the end of that array into other memory which might in fact be zeros. And then at that point, you've zeroed out the crypto keys and you can write your own cookies and auth bypass them onwards. And that's an interesting kind of bug. But the thing that aggravated me is that is trivially discoverable through fuzzing.
B
Yeah.
A
And this means that Fortinet did not fuzz their web app firewalls, authentication functions. And that offends me in that kind of, you know, security, deep security place.
B
Yes.
A
That us old curmudgeons have the way we feel like people ought to be doing things properly. And then you see something that just prove to you that, no, they really don't do it properly. They really don't.
B
They do not.
A
Yeah. It's just aggravates me. And I wanted to vent about it on the show, and here I am.
B
Do you feel better?
A
I feel better now.
B
Okay, excellent. Now, we're just going to touch on this briefly because it's, you know, there's been a bit of a scandal around Black Hat, which is an Israeli citizen who apparently works for the Israeli government in some sort of cyber, you know, important cyber role. His name is Tom Artyom Alexandrovich. He was arrested in Las Vegas after some sort of sting involving child sex crimes. I think it was one of those things where you have the FBI pretending to be someone underage and someone organizes a meeting or whatever. And he got arrested, he was bailed and went back to Israel. There was some reporting, not, I can't really say from incredibly credible sources, or at least sources that I'm aware of, that the Trump administration intervened to get this guy bailed and back on a plane to Israel. Now we've got the State Department actually denying it, saying he did not claim diplomatic immunity and was released by a state judge pending a court date. Any claims that the US government intervened are false. So, I mean, this has got everything right for online controversy, which is, you know, allegations of White House impropriety. Senior Israeli official, given, you know, the relationship between the US and, and Israel has a huge spotlight. I mean, like, it's just I mean, it's like a controversy sandwich, this one.
A
Yeah, yeah, it's headline bait is what it is.
B
Yes. Yeah. Crazy. And look, we've got another story here. We're getting towards the end, but Matt Burgess and Lily Hay Newman have a write up here from Wired about how these Southeast Asian, like, pig butchering and scam compounds are now being linked to sextortion against children, which in my view is, you know, the worst online crime. It results in suicide. Horrible, horrible. I think, you know, there's an argument to be made for the death penalty for people who engage in this sort of thing. And now it looks like it's happening at industrial scale. Thanks to these. Thanks to these compounds.
A
Yeah. So the Wired reporting is based on some work by the International Justice Mission that looked at cases where online fraud was happening. And they had IP address records and things. And they tried to correlate where on the Internet the people carrying out these. The fraud campaigns were coming from. And they tied it back to, I think, 40 out of 44 scam compounds in Cambodia, Myanmar and Laos and linked them to cases where young people, vulnerable people were being extorted. You know, typically this is the kind of thing where they, you know, get involved in some online relationship, get convinced to send, you know, compromising pictures or whatever else, and then extorted to not, you know, share those with their family and friends or social media or whatever else. So they tied them back to, you know, source IP addresses and used that to kind of cluster. And the conclusion is that, like, this isn't just one or two scam comments, that this is really widespread amongst those scamming communities, scamming businesses, I guess, because this is not just recreational and that that's a thing that we should take into account when we think about how we regulate them. And of course, as scam compounding spreads to other parts of the world. Right. That it's not just financial crime, it's not just crypto. You know, that sort of the pig butchering stuff doesn't necessarily just stop there. Right. There are other types of scamming that they're doing. And yeah, it's pretty gross stuff when.
B
You think about the human misery that these compounds are responsible for. Now, whether that's old people being fleeced out of their life savings, which is horrible, whether it's this stuff which is somehow manages to be even worse, or the fact that the people who are perpetrating these crimes are being held against their will and forced to do it under threat of violence. My Lord, you know, the people really at the top of this stuff, you know, I, I, I, I wish for the most horrible things imaginable to happen to them because they're the ones doing this, you know, making a business decision to pivot into these types of crimes. It's a business decision, it's for money. It's. Yeah, it's the sort of thing that just, you read about it. You want to have a shower.
A
Yeah, yeah. No, it really is, it really is pretty gross. And I think the research here said that, like, although they've managed to tie something like 500 reports of child sex torsion to these organizations, the data suggests that there is actually so, so much more because, like, there's so many areas where the data is incomplete and they're doing things like relying on data from ad brokers and stuff to try and tie things together. So, like, the data, the source data is already patchy and incomplete. But, you know, we've already talked, we've talked at length about kind of like the sheer scale of these compounds. And of course it makes sense that this is also scaled far, far beyond that. I think the IJM team said something like 18,000 cases they reckon they could probably tie together based on the data they've got, which, you know, given they've tied five, they can actually come more concretely attribute 500. It kind of gives you a sense for how big the actual iceberg is, you know.
B
Yeah, yeah, hard. All right, Palette cleanser. Now let's follow this up with a happy chaser, which is that it's FRAC's 40th anniversary edition is out. The legendary Frack e Zine. Adam.
A
Yes. Yeah, FRAC 72. I think this is the 72nd issue. They started in 1985 and as usual, it's, you know, much the same kind of format text, you know, zine. Although there's some, some more artwork these days. It's not just ascii and yeah, good, good collection of stories. I haven't read through everything in this drop yet, but it's always a great read and an important part of our hacker history. So good job, FRAC team and good job all the contributors.
B
Now we're going to wrap up this week's news section by talking about an acquisition that just happened in Australia. And it is an interesting one and it is directly relevant to you because Accenture has bought the Australian cyber security firm Cyber cx. Now, what makes Cyber CX interesting is it was like a public, a private equity driven roll up of a whole bunch of pen testing and consulting firms. In Australia, including Insomnia, which you worked for for a long time and part owned, in fact. So the idea was they got all of these consultancies, I think like something like a dozen of them, rolled them together, pumped it full of money to expand and grow the business with the idea of turning it into a real force, and they did this. Cyber CX today apparently has 1400 staff. And yeah, it's, it's just been. Apparently there's been an acquisition agreement inked with Accenture for around a billion Australian dollars, which I think at the moment is, you know, US$650 million or so, which means that all of the founders of those pen test companies, people like yourself, are now actually getting paid. Right, because this was part of it, there was a bit of upfront money. And then the idea was eventually when this thing is built and is sold, everybody gets, gets paid quite well. So congratulations to you, first of all. Also congratulations to all of the people I know who are a part of this, because there's a lot of them. Right. So this is, this is very good news for an awful lot of people who worked very hard to make this happen. But I guess the reason I wanted to talk about it on the show and the reason it has sort of relevance for audience outside of Australia and is this is the first time I can think of where a pay roll up like this has actually worked. Because what would happen, what would happen previously is people that bundled together a few of these consultancies, do some sort of deal, then all of the founders would hit their earn outs, leave, start new consultancies, and the other thing would just wither and die. I think what, what CyberCX has successfully done here is grown to such a scale that it's not going to be threatened by a bunch of people leaving now that they're getting their earn out to spin up boutique consultancies. This isn't going to damage or harm or threaten Cyber CX or Accenture, I don't think. I mean, let's see how it plays out. But I can't think of another one of these that has done this.
A
Well, yeah, I mean, I am pleased to be involved in a thing that has actually worked out. And I know when we were originally in conversation with the mergers and acquisitions team that the private equity firm behind CyberSecX had put together together, there was a bit of doubt as to whether we would be able to pull it off, whether it was going to work, because, as you say, there are so many examples of this not working out well. And I think to my mind the thing that they got right here is so they rolled up a bunch of pen test firms, but they also rolled in incident response firms, managed security services and SOC operating teams, some cloud people. And they got to the point where they had built a thing that could combine all those disciplines. Because when we started Insomnia back in the day, we thought we're going to be just hacking, we're not going to do any fixing, we're not going to do any building. All we're going to do is here is a report about the things that we found, the technical evidence that supports your risk decision making and that's the only thing we'll do. And we'll do one thing, we'll do it well. And after 10, 15 years of doing that, it became clear that it needed more than that. And we would have customers that would phone us up that we had a long relationship with saying, hey, we've been hacked, we need what do. And we would have to say, despite us knowing your infrastructure really well and knowing your software and knowing your stack, we don't do instant response and you don't want us to come in and do a half assed job, go get someone else. And the thing that CCX got right, in my opinion is by blending those things together they were able to deliver good value. Right. And by integrating the managed security people and the same company doing all of those things, it worked out pretty well. And it also means that no one founder now released from their, you know, their handcuffs is going to be able to go build something that can do all of those things. One part of it maybe like maybe instant response, maybe managed security service, but no one's going to do the whole thing and security is now sufficiently important that you have to get all of those parts together. And that's kind of why I felt like it worked this time as opposed to, you know, the ones that didn't work because they were a bit too limited in their ambition and in their scope.
B
Yeah, I mean it was a big play and it's, I mean it's been many years now. Right. And I think you, you sold off insomnia in what, 2020, just as the pandemic was kicking off. I think.
A
Yeah, just going into the pandemic was when we started, like when we inked the original deal and then of course we had a, you know, many years before. You can move onwards.
B
Yeah, well, and it's really sad for you I guess because you joined Risky Business Media a little while ago full time and I bet you're really disappointed because you could be working at Accenture soon if you had have stayed.
A
I'm not sure that I can contractually, at this point in time answer that question or comment on that subject.
B
No, but I mean, look, it's a, it's a different discipline now, right? Like, it is a more serious thing. You know, the days of beardy hacker dudes like you, you know, running, running the serious consultancies. I don't know, maybe it's better we get the big companies to do it now, you know, I don't know. Maybe we've moved on from that era, I guess, is what I'm saying.
A
Yes. Yeah, absolutely. Like, so much has changed. And, you know, I look back to how it was when we started infosec consultancies and like, not just us and Swami, but all around the world, like the hacker kids that kind of grew up in the 90s and early 2000s, then went homewards to start consultancy businesses. You know, we had a lot of fun and we did a lot of good work, but ultimately security didn't matter until, you know, real crime, you know, real espionage, real like, until serious business got involved. And to be honest, you know, solving these problems takes more serious business than, you know, a bunch of hoodie wearing Bogan T shirt wearing nerds who just like computer hacking, you know.
B
Well, look, congratulations again. I want to say a special congratulations in particular to Alastair McGibbon who has been kicking around in Aussie infosec for a long time. He was originally with the Australian Federal Police and then bounced out. He worked for Malcolm Turnbull for a while, you know, as a sort of national cyber security adviser or whatnot. And you know, he was really one of the driving forces in pulling this whole thing together. And I just know how insanely hard he has worked over the last, you know, half a decade plus to make this all happen. So, Al Mac, congratulations to you. But Adam, that is actually it for the week's news news. Big thanks for, for joining me to talk through all of that and we'll do it all again next week. Cheers.
A
Thanks much, Pat. We certainly will. I'll see you then.
B
That was Adam Boileau there who is just taking a break from shopping for his new set of ivory back scratches in wake of the Cyber CX acquisition to slum it with the rest of us to talk about the week's cybersecurity news. Big thanks to him for that. Okay, it is time for this week's sponsor interview now with Fletcher Heisler. Who's the chief executive at Authentic? Authentic is an open source based idp. So you know, entra, octa, ping, whatever you got. Authentic, which is open source, you know, most of it's free, there's some enterprise features that you'll pay for. But the point is, the core of it is open source and you can go and inspect it, you can extend it, you can integrate other things with it, it's much more flexible and you can run it on prem, which is a huge thing for a lot of people. So Fletcher joined me for this conversation though, about the work that they've had to do to unify their IDP with Windows logins, right? So a user can go to their workstation, enter in their IDP creds and bang, unlock their workstation and go through and add true sso. So here's Fletcher Heisler talking about all of that. Enjoy.
C
It is a very tough journey. We try to be very standards compliant and vendor agnostic. And when you get into the OS level of things, that could be pretty.
B
Tough because you guys are all like, hey, we're in the cloud, it's all SAML and blobs of JSON and browsers and stuff. And now all of a sudden, and.
C
Then you're using some Win32 API from the 90s.
B
Yeah, exactly. You're up to your ears in Windows internals. And how is that?
C
Man, it was tough. I mean, so we developed this individually, very much so for Windows for Mac and for Linux in terms of registration and login and so forth, and the custom credential provider for Windows. These are all still a work in progress, but it's taken months of some pretty tough work and a couple restarts to decide what is the best way to do this. How do we even do this? Some uncharted territory there for sure. The Mac version we already integrated with Shared Cycles framework for Apple Business Manager and so forth. So we kind of had a foot in the door of how should this be done. That took a couple weeks. Jens came back with a Linux PAM integration after a weekend. So that was a nice, refreshing little jaunt through a hackathon after the challenge of the Windows side. But we figured that would be the challenging one, but would have, you know, a lot of interest on the enterprise side for so many Windows desktops that you want to secure once and not have to do that extra hop.
B
Well, I mean, that's the thing. Like the Linux one was easy. Yay. That's great for the thousand people in the world who actually use Linux on the desktop. Right. Unfortunately, that ain't where the market is. So, you know, I mean, God, I just don't even know where you would begin when trying to put something like this together. Why don't you give us a rough idea about how that process actually works? Because I wouldn't have the foggiest of where to begin. How does this work? Like what directory has to be working? Is it like, are you doing something based on the Windows that Windows login from a lock screen? Is it then kicking off some other process that is doing the SSO for the more Webby stuff in the background? Or are you actually changing that log on screen and that's some sort of custom binary your own application which is then handling the unlock? I can't imagine that's the case, but walk us through the way that would even work because I don't know, I.
C
Am not the one who's developed this, so I may not be the one to get too deep into the internals. But we did bring out a couple contractors who are experts in the various parts of Windows API internals. It was even a question of what language do we write this in. We ended up somewhere between C C. But to have the flexibility of authentic so that you can say at the desktop we want you to enable biometrics or use your Yubikey or whatever that means we needed a few different executables packaged up because we needed to launch an iframe essentially at the end of the day that is authentic and that is your login portal from there. The mess that led up to getting to there, I still don't totally understand. But Jens can can rehash that over the next few hours probably in terms of the internals on the Windows side.
B
So was this something where there was like a lot of customer demand for this or like what actually spurred on the idea of like, oh yes, maker. And you know, it's really funny that you're talking about this because people listening might think, oh, okay, well, you're just saving people from having to, you know, put their creds in a couple of times. Right. Like, big deal. Yeah, it's amazing what a barrier to sales for like certain like security products that I know of, where there might be a clunky second step or something right. Involved and they won't do the deal because there's executives who don't want to have to put in two passwords or something like that. It is absolutely a deal killer. Was that why you decided to prioritize this?
C
We've Had a lot of interest on the federal side in terms of air gapped instances and so forth, where every step of the way that you can lock down more is a major improvement. I'll give a specific example though. One of our customers is the 911 center for the State of Washington. So that's a whole Windows environment where everybody is swapping around workstations. They have biometric requirements, lots of specific compliance based requirements that they have to meet. And these are usually older folks swapping around to a new machine every day, need to log in and start taking calls. And that's literally life and death sometimes that they need to be able to get into that machine and not go where did I keep my post it note? Why isn't my fingerprint scanner working? Whatever the problem happens to be there. So every step of the way that you can condense that and make it easier and more streamlined for them is a huge win.
B
Yeah. I mean I'd imagine that this would be already pretty popular in the Microsoft ecosystem, right? Like for people who are using Windows and Entra, it would already do this, right? Yeah.
C
The challenge is bridging across those different ecosystems. If you are wholly bought 100% into the Microsoft ecosystem, there are a lot of interesting things you can do with Windows plus, Entra plus, et cetera. If you have any other devices or applications that don't speak as well, that's often when we come into the conversation as well to say let's be that final mile to get you integrated with everybody else.
B
Well, I mean I can't think of too many enterprises of any scale either that are purely Microsoft. Right. Like there's always going to have been a merger and acquisition. There's always going to have been some weird project that took off over here and then wound up becoming a department or something like that. And they're doing it a little bit differently, I'd imagine. That's where this stuff is going to plug in, right?
C
Definitely. And sometimes vice versa. Like we acquired something that's all AD and we can't quite get rid of it, but we're not sure how to talk with it with our existing systems.
B
Yeah, right.
C
That's why we try to be very broad in terms of what can we talk to, how can we dynamically situate that in your existing IDP ecosystem? Because that's really what it is when you get to a big enough enterprise.
B
Now, is this all open source? Free and open source this stuff as well, like the rest of authentic, it.
C
Will definitely be source available. We're deciding basically what to do about it in terms of what. What makes the most sense.
B
Well, that's what I was wondering because this is a pretty enterprise y sort of deal, right? Like is that a part of it that you want to give away or is that a part of it you want to license?
C
Yeah, we've had a pretty clear black and white so far of this makes sense for HomeLab users, these features. You're probably a pretty big company with these sorts of compliance needs and so forth, and we've been really fortunate to be able to draw that line really clearly. I think we might just need some community feedback as well. If folks say, here's a really clear reason why I need this particular feature integration. We took the remote access control and moved that to community because we saw more homelab users interested in it. And so that made sense to move that to open source. So it also might be something that we kind of explore over time too.
B
Yeah, I mean like the Linux PAM integration bit, like yeah, you might community that, but the Windows bit, eh, yeah, you can pay for that.
C
You know what, you've convinced me that sounds pretty straightforward to say Linux pam. You're probably a Home Lab user. I just got back from DEF Con and speaking to the many dozens of Linux desktop users who are running Authentic in their Home lab. So I'm sure they'd enjoy that.
B
Yeah, yeah. So I guess the other reason I asked if it was open source is because you're dealing with something that you've developed in C C that handles authentication and plumbs into Windows internals. The other reason I asked if it was open source, you said it is going to be code available is like I imagine like auditing slash, pen testing slash, you know, like red teaming. A feature like this is going to be fraught. Like have you actually done that yet or is that pending?
C
We have engaged some experts who know that area very well, specifically that they're going to take a look as well. Because, you know, even if it doesn't seem like there are practical avenues because this is a thing running on your machine, it's pretty core and important. So we want to make sure we don't have any loose ends there. For sure.
B
You need like Windows internals, Rain man, basically to look at something like this. It's not for normal people. Right. You need to have a certain type of mind to look at this and see where the pitfalls might be. So is that through a security firm or is it just a contractor? I'm just curious how you even begin to look at a thing like this.
C
Yeah, through a firm who I know has those sorts of experts. I don't know if we've signed anything officially yet, but we basically publish the results of all of our tests as well. So we're getting up on our annual pen test as well, hopefully with the same firm. So we'll have that all published in another month or two. We'll see how it goes.
B
All right, now we're getting towards the end here, but I did want to ask you about backchannel Logout. Like this is another thing that you've now got in Authentic. Great idea, but only works if app providers actually integrate it. The idea here is it's like universal logout, right, for sessions. And this is one of the big problems with web based SSO is a user exits a session, the SaaS apps don't know to invalidate their sessions, so they just stay open. Right. And this could be a really big problem, particularly around things like incident response, where you've got an attacker who's managed to hijack a bunch of authenticated sessions and there's not really an easy way to invalidate them. Backchannel logout's one way to do that. I think Okta's got their own as well. So it seems like there's, there's, you know, there's a couple of ways for SaaS providers to do this. The problem is more that they're not doing it, you know. So you've now done back channel logout. Like what's the reception been among the actual app makers and SaaS providers to you doing this? Have you had any conversations with them?
C
So Okta's universal logout, I believe, is limited to applications that the application or Okta has integrated with in some way and written that logout flow. So you can also already do that in authentic, just with expression policies and so forth. That was why, in part, we were dragging our heels a bit on implementing backchannel logout that's actually up and coming with our next release later on this month. Because as you say, there aren't a whole lot of applications that support it. I think one of the few IDPs that also does so is Keycloak. And so that was one of the applications we were testing against was Authentic plus keycloak and logging you out of each system with each system. So there are a few important ones. I would love there to be more in the world as well because it is a great standard and should be implemented for the security reasons you mentioned. We'll also be implementing SAML single logout, but the idea that you can log out of your IDP and have that transfer to all of your other applications is just a no brainer. Should be the way that things happen. Similarly, you have some sort of signals of someone left, a group or some other suspicious signal, maybe even a login from a an unexpected location. Those should also dynamically be able to send out those logout requests on your behalf through the backchannel. So we'd love to see that happen more.
B
I remember having one of the Okta people on the show talking about this and from what they were saying, this is not rocket science. Invalidating these sessions when a user is logged out. It's not rocket science. The problem is really that the application providers aren't integrating them. I think there was one thing they were pushing on pretty hard, which is they were begging the Risky Business audience to start putting this as a requirement into procurement documents, which I think it would. I think that is the smart way to fix this. Yeah.
C
Yeah. Well, we're going to be heading out to DjangoCon next month and thinking about some various hackathon ideas of helping people work on Authentic. If you have your own application, I'd love to help you implement backdata log out there. So that might be a good push that way to get it out in the community.
B
All right, Fletcher Heisler, thank you so much for joining me from a very late recording session in London. A pleasure to chat to you my friend. I look forward to doing it again soon.
C
Thanks so much.
B
That was Fletcher Heisler there from Authentic. Big thanks to them for that. And that is it for this week's show. I do hope you've enjoyed it. I'll be back this Friday with a fresh edition of the Wide World of Cyber podcast with Chris Krebs and Alex Stamos. But until then I've been Patrick Gray. Thanks for listening.
Podcast: Risky Business
Host: Patrick Gray
Guest: Adam Boileau
Date: August 20, 2025
Episode Theme: An eventful week in cybersecurity news, dominated by the abrupt and mysterious departure of Oracle CSO Mary Ann Davidson, with in-depth discussion of associated industry impacts, plus a run through major security incidents, policy controversies, and product updates.
This episode covers the surprise exit of Mary Ann Davidson, Oracle’s long-time CSO, speculates about her legacy and the possible reasons for her departure, and pivots into a comprehensive review of the week’s most significant cybersecurity happenings. It blends sharp industry analysis, irreverent humor, and direct commentary on current events.
| Topic | Timestamps | |---------------------------------------------|-----------------| | Oracle CSO Mary Ann Davidson Departs | 00:06 – 07:13 | | Zelle Lawsuit and Fraud Controls | 07:13 – 09:47 | | China Brokerage Account Fraud | 09:47 – 12:34 | | “T on Her” App (Security Disaster) | 12:50 – 15:23 | | UK-Apple Encryption Controversy | 15:23 – 19:02 | | Workday CRM Account Breach | 19:02 – 21:47 | | Russia Restricts WhatsApp/Telegram | 21:49 – 24:06 | | Canada House of Commons Hack | 24:06 – 25:15 | | Norwegian Dam ICS Attack | 25:15 – 26:30 | | CISA OT Asset Guidance | 26:30 – 29:00 | | Fortinet “Fort majeure” Bug | 29:00 – 31:04 | | Israeli Official Black Hat Scandal | 31:04 – 32:21 | | SE Asian Scam Compounds & Sextortion | 32:21 – 36:17 | | FRAC’s 40th Anniversary | 36:17 – 36:58 | | CyberCX Roll-Up & Accenture Acquisition | 36:58 – 43:46 |
Guest: Fletcher Heisler (CEO, Authentic)
This episode balances a deep, experience-based breakdown of the Mary Ann Davidson/Oracle saga with a global roundup of urgent infosec stories and industry trends. It offers a rare blend of jaded wisdom, genuine technical critique, pointed humor, and meaningful industry congratulations, making it essential listening for cybersecurity professionals seeking both actionable analysis and the unvarnished reality of security culture.