
Loading summary
A
Foreign and welcome to the Risky Business podcast. My name's Patrick Gray. This week's show is brought to you by PUSH Security. Big thanks to them for that. And a little bit later on we'll be hearing from PUSH Security's very own Jacques Lowe about a LinkedIn based phishing campaign that they were able to detect and disrupt. Very interesting campaign targeted at chief executives in a particular vertical. And yeah, PUSH has built some new bells and whistles that have been really useful in helping people walk back those campaigns, discover where phishing links have come from and whatnot. Jacques will be a little along a little bit later on to talk through all of that. But before all of that, of course it is time for a check of the week's security news with Adam Boileau. And Adam, of course the F5 hack is the talk of the town. We've already published a podcast on that. I spoke with Alex Stamos and Chris Krebs yesterday in a Wide World of Cyber edition of that. But let's just, for the listeners who have not heard that, let's just recap the guts of the story here. It looks like the Chinese were rattling around inside F5's like, you know, dev network, well, their network, their whole network for a couple of years.
B
Yeah, it's not, it's not a great look for a security vendor that is for sure. The reporting seems to be that they filed or they spotted this incident I think around August this year, filed some notices with the SEC as they're required to. And then since then it's become clear that the attackers have probably been in there a good couple of years now. Some of the stories we've seen say that it's probably China. We, I don't know, we've seen like a concrete attribution there.
A
But like it's, I mean all signs point to at this point, right.
B
And it seems like initial entry was probably through vulns in their own products which, you know, I guess they eat their own dog food. So that's nice. But yeah, ATT and CK has got in there, have been rummaging around with source code access and build environment access for F5 big IP, which of course is their, you know, one of their key products that people use on the edge of their network. And that's the thing that I think has, you know, got a bunch of people pretty concerned because you know, devices that are on the network perimeter that implement security controls, that is a place that attackers love to go. And being in the supply chain for that, even just being able to see the source code. There's some reports that they took the attackers, took vulnerability reports and stuff.
A
Oh man. It looks like, yeah, they were all over the internal bug tracker. Right. Which is why as soon as this has all come to light, F5's dropped like 44 patches or something. It was interesting too. Like, one thought that I had though is like, I mean, surely there's not that many big IP management interfaces on the Internet, right? So how can this be a big deal? And then you start reading the advisories and it's all like, unspecified traffic crossing the device could cause this service to terminate. And you're like, oh, okay, right. So that's a DOS condition, but they all read like the sort of things where if you put in the research, you might actually get them to be exploitable just by getting packets to transit the device. So I get why people are freaked out.
B
Yeah, yeah, absolutely. Of course, once you're in a position, like if you compromise an edge device like this, like they are by design break and inspect ssl, like they're front end proxies that are terminating tls, They've got credentials and access for onwards movement. They're on the edge of the network without edr, without other controls, like, it's just the perfect place to be. And stealing the source, looking for new bugs, stealing vulnerability information, and maybe turning doses into actual weaponizable things. Like, that's just smart hacking and, you know, it kind of got to hand it to them. I think, like, that's just like, good work, China. That's. I mean, I'm. I'm jelly. That would be a great thing to have.
A
One thing I found interesting though is they did have access to the part of the network where the patches were sort of signed and distributed. And it doesn't look like they pulled the trigger on that. Whether or not, you know, I mean, we sort of speculated on that in yesterday's podcast with Chris and Alex. You know, maybe they were going to drop, you know, pull the trigger on that later, they just hadn't got around to it. Or maybe they were worried they were going to get caught or, you know, I don't know.
B
But yeah, it seems like the sort of thing you would save for a special occasion. Like that's not just a let's do that on Tuesday. That's a, like, you know, preparing the battle space kind of thing rather than a, you know, let's just pull the trigger because we can.
A
Yeah. Now, a big part of yesterday's conversation was really about what to do about these Mid tier vendors that, you know, aren't really taking appropriate care of their products. I mean, I got some sympathy for F5 to be honest, because they make a fairly unique set of products, right? Some less unique than others. Like there's plenty of wafs and stuff out there. But try finding a solid replacement for like a big IP load balancer, you know, like they are just the industry standard and people are buying them. So where's the motivation to actually fix the product right, when you're kind of unique in the market? And along those lines, like CSO magazine has done this great feature. The journalist's name is Lucian Constantin and it he's covering sort of like stuff we've spoken about a fair bit over the last year or two, which is, yeah, these edge devices are just crap and no one really seems motivated to work for them, to, to improve them. You know, yesterday Alex and Chris made a good point though, which is that at least now with some of these AI tools emerging, these mid tier vendors that want to improve their code quality, they can actually do it. Now it's becoming much more economically viable to do that. But I have a feeling that there's plenty of these, you know, private equity controlled companies where they won't even get the budget to do that. Right. So. But walk us through this feature by Lucian here because I think it's very interesting.
B
Yeah, it's a really great piece. He's kind of written up this kind of whole scene where there's, you know, security, critical devices that ultimately, you know, have been getting people owned. And he's pulled together interviews with the boss of Watts Tower, the guy from Voln, check some other people from like Veracode, I think, Chris Weiss, Opel. So like pulled together a bunch of really smart people to talk to, the guy from Bishop Fox even. And like it's just a really great survey and it's got like a list of, you know, here's a whole bunch of products that are in this category. The bugs they've had, the kind of things that have gone wrong with them. And it's just, you know, it's a really good, you know, sort of state of the world as far as network edge devices go.
A
Yeah, just solid work there. Now I probably massacred your name by the way, Lucian. Or is it Lucien? And is it Konstantin? Or Konstantin? I have no idea. I'm very sorry. I'm just going to put that out there. Now. Look, one of the reasons. Look, there's some reporting from Reuters too. Just going Back to the F5 thing for a second, there's reporting from Reuters that people familiar with the investigation are pointing the finger at China, which would suggest to me that that attribution is more than likely correct. But another thing that points to actually having been behind all of this is the fact that they are now accusing NSA of doing a whole bunch of stuff which is like, you know, every time they get accused of hacking something like, they usually put out a release saying, you know, the Americans are the worst cyber terrorists in the world, they suck, blah, blah, blah, blah, blah. A little bit more often though, over the last few years they'll attach some claims of, you know, American hacking against their interests. This piece is from the Record, written by Alexander Martin. Very funny that. Up the top there's an editor's note which says this article was updated at 2:45pm EST with a comment from an NSA official. And the comment is just a gloma which says we don't confirm or deny, which is like, ok, really glad you got that detail in there. Even getting a glomar though out of NSA is an achievement. But yeah, like what's the go here? China's accusing America of going after some central timekeeping authority that has pretty significant military applications. So like, this is the other funny thing is when China tends to whinge about the Americans hacking them, it's always like universities that are doing like missile research and military timekeeping departments. Is that what we're looking at here again?
B
Yeah, that seems to be. It's their National Time Service center, which Alexander Martin kind of compares to the US Naval Observatory in terms of functions or provides kind of ground based timing information or timing services for a whole bunch of users, including the military. And yet it totally seems like a legitimate target. The China's National Cert has put out a release that we are really reading the machine translated version because it's in Chinese obviously. And it has a bunch of details about a particular intrusion which they say started with mobile phones of people who worked at this particular organization and then escalated into, you know, kind of compromise and onwards from there they kind of attribute it to NSA based on a bunch of like this looks similar to things we'd seen in some of the previously leaked NSA tools. They draw a bunch of parallels between Dander Spritz, which was an NSA tool that we saw I think in the Snowden docs, or maybe the shadow brokers dumped, I can't remember which one it was.
A
Well, you notice also that every time China's trying to dox an NSA operation, they're linking it to like decade old tools. Right. Which is how old is this operation?
B
Well, I think in this case they are saying that there's a bunch of similarities in like the tool that they are seeing looks like a modernized replacement for Dan the Spritz.
A
Okay.
B
So they draw some parallels which are honestly a little bit flimsy. I mean some of it's like, you know, this just sort of generic good hacking tradecraft as opposed to specific. Like this was compiled on the same workstation by Dave from, you know, Maryland or whatever. So yeah, a little bit, you know, you know how China is with their attributions. It can be a bit, a bit flowery sometimes.
A
A little bit vibes based.
B
Yeah, yes, yeah, exactly. But yeah, it's very much like, you know, those capitalist imperialist pigs are all up in our timing systems and you know, how dare they. Et cetera, et cetera.
A
Yeah, and how dare they accuse us of like. Anyway, kudos too to Alexander Martin for this paragraph in the story. Although the MSS described the US as repeatedly trampling on international norms governing cyberspace, the activity it described, the specific targeting of a service with military applications would not necessarily be considered a breach of non binding cyber norms agreed to at the United Nations.
B
Yeah, yeah, but I mean look, we're.
A
Not, we are not their audience for this sort of stuff, right? The audience is the wider public and indeed policymakers who are not subject matter experts and don't necessarily have a good grasp on norms. And you know, if they can influence people to say, well, you know, they're just doing to us what we do to them, which is the, you know, what you really want out of an information campaign like this, then they have succeeded. Okay, now let's take a look at a couple of stories out of 404news written by Jo Cox. These scattered lapses hunters, comm adjacent kids who've been raiding Salesforce for data, they've actually managed to dox hundreds of dhs, ice, FBI and DOJ officials using the information they've obtained from Salesforce. But they say they have the data on thousands more. This would seem to be somewhat of a provocation, Adam. And I don't think this, you know, given most of these kids tend to be based either in the United States or like European countries where they will happily extradite these kids to the United States. This just strikes me as suicidal. Like what are they thinking?
B
Yeah, it's definitely not a well thought through plan and you know, the comm is a bunch of kids doing dumb stuff and I think you Know, you're sitting there on a trove of, what do they say, like, billions of records that they've looted out of various Salesforce users. You know, mining that for whatever topic of the day, and then, you know, starting to dump some data around, trying to make some. You know, in the end, like, these kids want publicity more than anything else. So I assume probably also they want money. But, yeah, like, making a big mess using the data you've got without really thinking through the consequences. Seems pretty on brand, but I do feel like, you know, winding up the NSA in particular is probably not a smart move, and various agencies, NSA is.
A
Not really in much of a position to do anything about this. I mean, FBI certainly are, but you're also looking at a. At a climate in the United States going after ICE when this current admin is in power. Like, that's how you get declared a terrorist in America right now.
B
Yeah, yeah. And, you know, they are not going to be particularly shy. I mean, I suppose the only saving grace is the US Government's going to half shut down at the moment, so that might slow down response a little bit. But I don't think the shutdown affects.
A
This sort of stuff, man. Like, you know, that's just. Yeah.
B
Anyway, it just seems like winding, you know, it's very much like, you know, kicking the hornet's nest for really no good reason.
A
Yeah.
B
So, yeah, I don't know what they're thinking, and I guess the answer is not much.
A
Now, look, speaking of ice, I did just want to quickly mention this piece from the Washington Post, which has taken a look at the surveillance technology being procured by the United States Immigration and Customs Enforcement Agency. It's a part of dhs. They are just going on a spending spree at the moment. Of course, they've had $170 billion allocated to them through the big beautiful bill. Now, the reason I wanted to mention this is I've had quite a few people over the last six months ask me if I think NSA is going to go rogue and present some sort of huge problem. You know, that they're going to step out of the bounds of their authorized activity and start surveilling their own citizens, perhaps, you know, surveilling people outside of America just for political purposes. And honestly, I don't see it. But if you want to know where the problem is going to be, it's going to be ice. Right. Because at this point, ICE is sort of being empowered to investigate people who oppose ice. I think the funniest tweet on all of this I saw was like, oh, well, I don't have to worry about this anti. Antifa stuff. Says person who doesn't realize they're antifa. This is, this is sort of how it's going. So I've dropped a link in to this week's show notes, but I feel like, you know, some of the numbers here are they've spent 3.4 million on Clearview AI, man. Tip of the iceberg. They've got the money, they're going to spend it, they are going to ramp up their domestic enforcement agencies. Even these kids who are doing the doxxing, like I can imagine ICE going after them for doxxing their personnel because they are being empowered to protect themselves as an organization. So that's just my two cents on that. I don't think Americans need to be worried about NSA quite yet because abuses are going to follow the path of least resistance. And the path of least resistance runs right through DHS and into ice. So, you know.
B
Yeah, now that seems like a fair take to me, man.
A
Now look, just speaking of another look, this is a really interesting story. Kim Z has done a great write up on this for her Zero day blog. But she's taken a look at the indictment against John Bolton and it really looks like, so he was, he was Trump's national Security advisor in the, in the first, in his first term. It really looks like there's a case here. So we've seen a bunch of investigations and you know, that look like retribution launched by this White House. But the one, this one against John Bolton, I mean, sure, it might be politically motivated, but you walk through this report, Adam, and it certainly looks like John Bolton was acting extremely foolishly with information he should have known was classified.
B
Yeah, I think this is a great example of like, it can be both retribution and also like legitimate. Like this guy probably did some bad stuff here. The story has a bunch of details about him sharing classified information with his family members in like a, in a group chat and a bunch of work that he was doing to prepare for writing a memoir once, you know, he was out of the Trump administration. And I guess he probably never particularly thought Trump was going to come back around again.
A
Every day he was writing 15, 25 pages of notes, he was transcribing the notes and then using his personal email address to email them to his wife and daughter every day. Now, these were not like marked classified documents, but obviously when you are making notes about classified meetings and whatever, like, obviously a lot of that's going to be going to be covered. So he emailed all of that from his personal email address to. To his wife and daughter. Now, indeed, when he wrote his book, he submitted the book to the National Security Council to review it. They did identify a whole bunch of classified information in his book, which he removed. But then he published the book without getting sort of final clearance, which was also a no, no. But it looks like the information that was deemed to be classified was stuff that he had emailed his wife and daughter from his personal email account, which is the stuff that it looks like Iranian hackers got their hands on and they were trying to blackmail him with this stuff. So all in all, not a great look for John Bolton.
B
No, no, really not. And you know, there's been lots of mishandling of classified information cases, but this one does seem a little worse than average. You know, I don't know if it's, you know, mar a lago bathroom kind of standard, but it's certainly not good.
A
Yeah, I mean, it's hard to feel sorry for John Bolton, though, who, for those of us who are old enough, would remember as one of the architects of the second Gulf War. So, you know, sucks to be you, the walrus. Moving on. And a US court has ordered NSO Group to no longer target WhatsApp. Which is pretty funny, isn't it? It's like, you know, okay, spyware company, you can no longer target WhatsApp. Here's an injunction. Like what?
B
Yeah, it's pretty funny. The NSO group was challenging the result of its court case against Meta, where they were. Meta got a whole bunch of damages awarded to it from NSO. NSO got that, talked that down from 167 million down to 4. So that's a good result. But then, yeah, this injunction where NSO said, like, but, but you can't tell us not to target WhatsApp because what else would we do? That's what we do. We, you know, we are a spyware company. We can't not hack meta accounts or WhatsApp accounts or whatever else. Like, that's, you know, what else are we going to sell our customers? So, yeah, a little bit of QQ more there in a group because, yeah, it's just a funny outcome, you know, and if they do, what's the remedy? Like, is Meta going to sue them a second time if they violate this, you know, this particular thing? I don't know.
A
Well, I don't know. I mean, I think the point is, with the news we spoke about, what last week, you know, things have Just not really been going NSO groups. Well, which is, you know, and look, staying with sort of spyware related news, Lorenzo over at TechCrunch has a story of intrigue, Adam, where it has chronicled the story of this guy. I think they've given him a fake name for the, for the story, but they've given him the name Jay Gibson. He was apparently fired from L3. Harris Trenchant, which is a, which was a big part of like Azimuth and what was it, Linchpin Labs as well. They got bought into Trenchant and whatever. So, you know, they were doing, you know, exploit development for like iOS and whatnot. So this story talks about this guy who got fired by Trenchant because they thought he was leaking exploits. And then he gets a message from Apple saying that his phone was being targeted by sophisticated state backed adversaries and whatnot. And he's making the case now through Lorenzo that he was improperly fired because clearly it was the hackers what done it and got access to those, to those exploits. So just an interesting little peeling back of the curtain into, I don't know, you know, the sort of problems you have when you work for these companies.
B
Yeah, I mean, yeah, it's an interesting, like, interesting insight, I guess. And Lorenzo's talked to a few other people that are kind of, you know, worked at, or maybe still work, I'm not quite sure at Trenchant and I've kind of corroborated some aspects of the story. But it's just an interesting insight and, and I guess a reminder that, you know, if you're someone who does have to work in this field, like, it can just get a little bit weird because you end up mixed up in all sorts of, you know, like, life can get complicated being a, you know, being an exploit dev for the military, for the government. It's not all, you know, money and, and Ferraris.
A
Well, I mean, you know, this is the second time today we've spoken about attackers going after bugs. Right. Because this is something that has happened as long as bugs have existed is people would, you know, go to the source. And you know, we heard about people knocking over F5's bug tracker. This is a similar sort of thing. You want some sweet iOS exploits, you get them from the people who create sweet iOS exploits.
B
Yeah, yeah, absolutely. Yeah. It's a good methodology.
A
Now look, we're going to talk about this Dan Gooden piece that originally appeared in Ars Technica about a technique used to steal MFI codes, like numerical codes out of Android devices. This is academic research. I can't imagine it's terribly practical in the wild, but it's still cool. And you wanted to talk about this one?
B
Yeah, I just really liked it because it's a great example of turning academic research into something that's legitimately end to end interesting, even if not necessarily practical in the world. It kind of tickled my fancy. So this is research that uses GPU side channels to kind of extract data about what's being rendered to the screen. And this is implemented on Android where you get a malicious app onto an Android device and then it can, through the like Android Intent system, et cetera, open other apps. Now you can't see the contents of those other apps, but what this technique does is like if you open the two factor code generating app, like a Google Authenticator or whatever, and then the original app tries to overlay something on the screen and then times how long that takes to go through the GPU rendering pipeline and by kind of crafting that, you can end up extracting pixel data essentially out of that timing side channel and from that recover the contents of a two factor auth code or something. And that's kind of a cool application of a timing side channel. And that combined with the way Android works I thought was pretty cool research. And it's certainly not the first GPU rendering side channel that we've seen. But it's just, I thought it was good kind of lateral thinking to apply that to stealing two FA codes or whatever else.
A
Yeah, I just don't understand the workflow of how this is supposed to work from the attacker's side, which is what you've got. A user has their phone unlocked, screen on, and then you're trying to pop their authenticator app and then scrape the screen. Users may be going to notice that. And like the malicious app that you've got them to install, can that actually run in the background on Android? It can't on iOS. Right. So I'm just sort of thinking, yeah.
B
I think in this case, like those concerns, I think you can get around like you'll be able to, you know, maybe if the thing you're overlaying on top of it really completely hides it maybe. And you know, you can open other apps through intents in ways that, you know, don't require permissions on Android. So like it's just a. Yeah, I thought it was an interesting, like normally you would look at this side shell and go, hey, that's interesting. But what are you, what, what use is it? And kind of chaining all of the other bits and pieces together to turn this into something that is useful. And the history of this particular graphical, graphical rendering side channel was that it was originally they tried to use it in a browser context to steal stuff between browser tabs. And then the amount of isolation and complexity that made that difficult. And then so reapplying it to where else can we use this primitive. And turns out Android as an OS actually is a great place to do that. So yeah, yeah, that was my thinking.
A
Now I think this is one of the most awesome stories of the week which is this VS code, this VS code worm, but it's a VS code extension available on the open VSX marketplace. It's a worm man. It's knocked over tens of thousands of boxes. It's designed to steal crypto, but it is brutal, man. You're reading this just going oof.
B
Yeah, this is good stuff. So this worm showed up in one of the VS code extension marks marketplaces, both the official one I Think and the OpenVSX one. And when it gets, when you, you know, when you have an extension that is infected, they get auto updated. So your VS code automatically picks it up, deploys it onto you and then it will, it uses the solana blockchain for C2. So it reaches out to the blockchain, pulls in a C2 URL. So that's, that's already interesting. It has backup C2 via Google Calendar and then the next stage brings in a cryptocurrency stealer. So it rummages around, supports something like 49 different cryptocurrency wallets. So it will steal crypto. It will also scrape for credentials for GitHub for the VSX extension marketplaces and then use that to propagate itself. So that's kind of the worm part of it. And then it also drops like a socks proxy and a WebRTC peer to peer based kind of COMMS mechanism for access to those proxies. It drops a VNC server so that the attackers can use it to interact with your desktop or graphical applications. Like this is pretty polished honestly. And whoever, like this is not, whoever did this, this is not their first rodeo. Like they, they, you know, they work and they're definitely working this pretty hard. And yeah, like it's just going to be hard to shut down because of the, the way that the C2 works and the self propagating stuff. Like it's out there live right now. Like people are getting infected as we are speaking, which is pretty cool work honestly.
A
I mean that Was my reaction as well as I'm reading this going, my God. Like, this is. This is brutal, but sort of impressive. And it feels old school in a bunch of ways, right? Like it doesn't feel like, yeah, this doesn't feel like com kids. This feels like someone of our vintage.
B
I mean, honestly, it does. And far be it from us to say that our way of, you know, old school hacking, like, we did it, it is the only way to do good hacking. But it does have that kind of like someone really thought about this and they did. Good job, Good job.
A
There was some engineering in this one.
B
Basically, just quickly we forgot one cool thing. The code it injects into the things that it uses to propagate. It uses invisible Unicode characters. So when you look at it in a text editor, you can't see it. Like just Chef.
A
Yes, it is. Yeah. Chef Kiss. 100%. What was the GIF that I dropped is my reaction into Slack today? It's the American Psycho. Ooh.
B
Exactly, exactly.
A
Very, very Chef Kiss just quickly wanted to mention we're going to link through to Darina Antonio's version of this story on the record, but police in Europe. I think it was Latvia, wasn't it? They knocked over another one of these SIM farms. So they got something like 40,000 active SIM cards, 1200 SIM box devices. The reason I think this is interesting is of course we saw a few weeks ago a similar operation getting taken down in New York where the, you know, there were rumors that Chinese intelligence services had been using those SIM farms for various things, although they were, you know, predominantly like fraud, you know, was fraud infrastructure, but also being used by foreign state actors. So interesting to see a similar operation getting rolled up very quickly after that. So I just sort of wonder if that's part of the same thing. Could just be a coincidence. I've got no idea. I got no insider information there, but just thought it was worth flagging. Now we're going to talk about an interesting technique that's been observed in the wild, Adam. Some good old fashioned UNIX persistence techniques that popped up in an incident response investigation. And the guy has posted about it on X and there's a blog post and whatnot.
B
Yeah, so this is an attacker in the wild using a Unix trick for long term backdooring. So once you've gained privileged access to a system and at some point in the future you might want to come back and regain privileged access. One of the old school ways you might do this is you might make a sewered root binary, a binary that Whenever it's executed, runs as the root user, not as the user who is executing. So it provides you a way for privilege escalation. This particular attacker is using a trick where you can use Unix capability or Linux kernel capabilities to do the same thing. So you can essentially market a binary file to run with elevated privilege in a way that most people did not realize that you could do this. I wouldn't necessarily know to look for it when you are hunting. And in particular, I feel like I know quite a bit about Unix local privilege escalation and ways to escalate privilege in Unix boxes. I didn't know this was a thing. My mental model of how Linux kernel capabilities worked and interacted with file system perms was wrong, wrong. And this post showed me that I was wrong. And I feel like that doesn't happen super often. And so in that respect, like I was just, it's super cool. I tested it out this morning. Like it legitimately works. Like the guy describes, you set the cap SETUID capability on a file and yeah, in the future you come back and you gain root, which is just, yeah, super cool. And one more thing for people doing instant response on Unix boxes to hunt for.
A
Oh, now bug of the week. This one again. Oof. There's a remote code execution in wsus, which is what is a Windows Server Update service. What do they call it? Windows Software Update Service. Is that right?
B
Server Update service.
A
Yeah, Server update. Anyway, wsus. Right. Which is how you get, you know, if you want to control patch rollouts via Windows into your internal organization, like that's how you do it. Yeah, this is like a full straight up remote RCE due to a deserialization bug, which is a very big deal. I think the other thing that's a big deal about this is since COVID and a lot of people started working from home, even though the best advice is you shouldn't expose your WSUS server to the Internet. If you go and look through forums and Q&As and whatever and people are like, how do I update my my home users? They're like, man, just bung her on a fully qualified domain name, she'll be right. So I asked you to go to Census and see how many WSUS boxes there might be out there on the Internet. What did you find, like 7,000 of them?
B
Yeah, yeah, 7,8000ish, you know, based on certificate names that look like WSUs. So yeah, like certainly in the thousands, which, I mean, I'm not that surprised. I've seen, you know, a lot of people do put this stuff on the outside for the reasons that you describe like managing distributed systems and work.
A
But hang on, hang on, hang on. Could some of those certificates have just come from transparency logs and it's a fully qualified domain name but it's actually firewalled off. It's like in a DMZ somewhere that could.
B
No, this is from Census actually connecting out and collecting the certificate. So this is not from ct. Yeah, okay.
A
Okay. Anyway, walk us through the bug. This is a clanger.
B
So this was a CV that Microsoft disclosed this month and it's as you described, straight up remote code exec via HTTP into wsus. But the thing that's particularly beautiful about this is that it's deserialization through. NET binary formatter which if you can put untrusted data in front of it, you get codexec. Microsoft itself says there is no way to make binary formatters safe. Do not use this ever. You can't fix it. And it's been marked obsolete in. Net since 2020 and they actually fully ripped it out. It's not even there anymore in the most recent releases of. Net. So this is very much Microsoft not following their own advice and getting everybody owned as a result. Now at least it's been patched. So that's good. And hopefully people who have WSUs are the sort of people who patch regularly. So the idea that you would have a WSUS that doesn't then itself auto patch I guess is not particularly likely. But yeah, it's just the irony of Microsoft getting owned by binary formatter in its own stuff. It's just rude. So rude. Microsoft so rude.
A
I mean but this is like this is an old style bug, right? Like this is, this is the sort of advisory you expected to see in 2005, not 2025.
B
I mean kind of, yeah, pretty much.
A
Well, I mean deserialization wasn't really a bug class in 2005. But I just mean from a perspective of like crafty Microsoft code in a core product like you know, you don't.
B
Expect, you don't necessarily expect this from Microsoft. The only saving grace here I guess is that and the reason perhaps it hasn't been seen in the past is that the data that gets decrypted by or that gets processed by binary formatter is encrypted using a hard coded crypto key. And so somebody had to go figure this out and extract the key, which of course has now happened. And I think it's the end result bug is like CVSS 9.8 or something. Which in WSUS and Internet facing WSUS. Oh boy. Good times.
A
Yeah. Now we're going to wrap it up this week, Adam, with a discussion of another cve. It's been given a name and I'll allow it because it's a cool name. Tarmageddon. So we got a TAR bug. You love TAR bugs because you are an old beardy UNIX guy. Walk us through Tarmageddon.
B
Yeah. So this is a bug in an implementation of TAR in Rust. So the quite popular Async TAR rust library. And it's not the world's worst bug. This is the kind of a thing where you can craft a TAR file that when it's untarred by this particular rust implementation of tar, then you get different results than if it's untarred by some other TAR process. Process, which is a problem in environments where the tars are initially checked by some other some process and then later processed by Rust. And it's not straight up code exact like previous TAR bugs that we've seen, but it is just kind of interesting. And the complexity here is also that the Rust ecosystem, like Rust, is very popular because of its good security properties. Right. You, you're not going to get memory corruption bugs. There's a whole bunch of things that make Rust ecosystems more resilient. But the kind of open source lineage of this particular TAR fork made patching this very, very difficult because there's a number of downstream forks and the middle fork between the original upstream code and the downstream ones that people actually use is abandoned. So getting it patched was quite complicated. So it's kind of cool bug. And it is used in, for example, the Python UV package manager thing, which is very popular in modern environments. So yeah, it's just an interesting bug in a place that's not great. And an ecosystem that, whilst security robust, generally a good, you know, Rust is generally a good thing. This is a great example of where that ecosystem is not delivering a great quality outcome for everybody. So plus, I just love Tarbucks.
A
You do. Now we actually have a moment just before we roll onto the sponsor interview. I just wanted to get your thoughts on a couple of other things in the news. AWS outage. Oh my God, we pushed that podcast yesterday. It does not have a video with no video on YouTube because Riverside, which is what we use to record, you know, video based interviews, was down completely from aws. So much stuff was down, including security tools, which I, you know, it's just fascinating, isn't it, that you'll use the, you Lose US east one and everything just stops.
B
Yeah, like it really is the center of the world for cloud because so much stuff is dependent on US east one eventually even if it's through you know, 47 intermediate dependencies. Like we were talking in Slack whilst that author was going I couldn't paste a GIF in Slack.
A
Yeah, I tried to post a Screenshot of Like AWS's like support account's most recent tweet being two weeks old or whatever. I took a screen cap, tried to post it couldn't.
B
Yeah, yeah. It's just funny how much stuff did in order because USD US east one. So yeah that was a hell of a, it was a hell of a time watching that, that status post update with more and more Amazon services falling over as they tried to figure it out and in the end it was all DNS. So was it?
A
I think in the end they sort of worked out that there might have been a bit more to it than that actually.
B
I think like it started with DNS and then they like ended up where they couldn't launch easy 2 instances fast enough or something. So yeah, yeah, yeah, fallout from DNS.
A
So I guess the main lesson there is maybe have a look at your failovers people and you know, don't take it for granted that US East 1 is going to be completely up all the time. I did appreciate Elizabeth Warren, the us, you know, politicians saying oh this is proof that we need to break these companies up because the Internet shouldn't fail because of one company. It's like oh my God, if only you knew how bad it is and how many individual points of failure there are. Also hilarious that it took down a bunch of the crypto world considering their whole thing about decentralization. It's like yeah, decentralization, it seems to involve a lot of centralization on US East. US East 1. The other thing I just wanted to quickly get your thoughts on because we've got time is, is chat GPT OpenAI. They've released a browser today, the so called Atlas browser. You know I think agentic browsers are going to be a big thing, but I don't think they're nearly ready for prime time from a security perspective. I think they're going to turn into a problem for enterprise enterprises out there when their users are going to be bringing their own browsers in, logging into accounts with them and then getting prompt injected and company data spilling that way. I mean, I mean I know I'm pretty sure pretty black pilled sort of person but was this your Reaction as well when you heard about this.
B
Yeah, I mean, we've been talking about how the browser is the OS these days and now we're saying we're going to have an OpenAI OS. Like that sounds like a terrible idea. If you said let's replace macros with some OpenAI operating system for Apple hardware, you would be like, hell to the no. But that's kind of what we're talking about if they're going to make a browser as well. Like all of the complexity of a browser plus all of the complexity of AI, plus how fast modern AI stuff is moving, like, it just does not make me feel good. And as you say, like end users being involved in this makes it worse. And like all of the other AI enabled browsers we've seen have had challenging times with prompt injection and just gluing a browser to an LLM just gives me the willies and I'm not happy about it.
A
Yeah, and the whole you can't actually separate code and data issue with LLMs, you know. Yeah, let's back that in a browser. Like that little thing. Yeah, let's just whack her in a browser. She'll be right. That's fine. All right, let's get on to this week's sponsor interview. Now, Adam and I know you actually listened to this one as well because I asked you to QA it yesterday. But it's with Jacques Lowe, who is one of the, one of the team over at Push Security. Push Security. Of course, it's mostly a browser plugin based product which will prevent your users from being able to be phished. This is the better way to deal with phishing than just an email gateway these days, because phishing messages can come in through teams, they can come in through LinkedIn, they can arrive in taxis for all you know, they can arrive in an envelope printed on paper. Right. Your, your email security product ain't going to be able to do anything about that. So the nice thing about Push is it sees the final payload that the user sees. And in that vein, they actually managed to unpack a LinkedIn phishing campaign which was targeted towards CEOs in a specific vertical. Vertical. So that's interesting. But the even more interesting bit is the way that they are now tracking and they started doing this for internal use and it's something they're now making available for their, for their customers. They actually track the user's whole journey to a phishing page. Right. So you can actually say, oh, okay, they hit this phishing link. But trying to go back and actually figure out where that link came from can actually sometimes be hard. Right. So something that it sounds like it should be simple and it isn't. So what push have done is now you actually get the full sequence in a nice little diagram in the product and you can step back and you can say, okay, well, user tried to enter their password here. We stopped them. You know, there might be a couple more chains back higher, which is. They hit this page, which looks sauce, but then you can keep walking it back and actually get to the. To where that link where that whole, you know, problem initiated, even including redirects and whatnot. I just want to wonder what you thought of that because I know you thought it was, was, you know, I'm pretty sure you thought it was cool.
B
Yeah, yeah. I mean, I think, you know, trying to do investigations in a browser centric world without access to the browser is already super difficult. And I think, you know, anytime you're investigating an incident and you've got like full packet dumps from the network, like it's super valuable, you've got a point of truth that you can, you know, in terms of dates and times and sizes and so on that you can try and correlate activity. Even if you can't see inside encrypted communications, you've got some data points having that for the actual inside the browser. Being able to TCP dump in my old UNIX way of thinking about things and see the ground truth of what's going on in the browser in front of the user's eyes. How good is that? So it just sounds like a godsend for investigating any incident that involves a web browser, which is all of them these days.
A
You got your adr, your ndr and you know, as Jacques explains in this interview is like this is sort of is that bit in the middle which has been blocked. I mean, what would you call it? A browser detection response. Bdr, did we just coin a new one? All right, so we're going to roll on to that interview now. And here is Jacques Lowe talking about that LinkedIn campaign that they rolled up. Enjoy.
C
This attack was really very targeted. So the malware they were using, very off the shelf. But the link delivery and how they were getting people to that malware, extremely targeted. So in this case, they were targeting CEOs at tech companies. So these are the kinds of tech companies where you will recognize the. You'll definitely recognize the name. And what we found is that they were actually compromising a direct contact of those CEOs with which they had been having a conversation. Use that compromised LinkedIn account to deliver a link through LinkedIn messenger. That link then goes through to a legitimate google.com domain where there's a hosted document with a link. You click that link, you go through to a legitimate document hosted on a Microsoft domain. And only then once you've gone through Google and Microsoft do you end up on the actual phishing page. So very interesting in terms of, like, how people got to the phish kit. But the phish kit itself, fairly off, fairly stock standard.
A
Yeah. Right. Okay, so how did you first get wind of this one? How did you detect it? Because I understand that when someone, when a user, when a push user tries to enter, like their SSO password, for example, into their browser, into anything that isn't their sso, they will be prevented from doing that and there will be an alert flagged. I mean, is that how you caught this one? Was it going to succeed and push detected that password entry or were there other signals? Like, how did you first become aware of this?
C
Yeah, there's a couple of layers. So in this case, we detected the cloned login page. So we're detecting that there's something that looks like, in this case, the first attack was a Google login page customer, is a Google workspace customer. And then obviously when they tried to enter their password, so we caught the cloned login page, the actual phish kit that was being used, they clicked through two warnings and then we ended up blocking them on the password entry, which is great for us. The security team immediately got in touch with us and told us, oh, wow, we just turned on that block mode like four hours ago. We're so happy.
A
Oh, my God. Yeah, yeah. But I mean, I'm a little bit worried for that customer of what happened four hours prior. Right. And in the time leading up to that. But the interesting thing is here, so we're talking about this as being a LinkedIn phishing campaign. I guess one of the interesting things is here that the reason, you know, the link was delivered through LinkedIn is because you're actually capturing enough sort of session information to be able to walk it back. Right. And I've, I've seen the blog post that you did. You can actually see where, you know, you could see the full chain of events and user clicking from here, clicking from here, clicking from here. Oh, then you get an alert, then you get another alert, then you get a blocked password going in. So, I mean, is this something that you've always done? You've always Offered the ability for people to walk back through the chain and see where that link first popped up.
C
And this is how a lot of our detections work. But having that data, that context available at the point of detection is something we released a couple of weeks, weeks ago or a couple of months ago, maybe now, probably a little while back.
A
Time is a blur. I know what you mean.
B
We're moving quick.
C
Yeah. So no, no, and it's been really interesting, like just the kinds of things we're seeing as soon as that context becomes available. We've just recently started doing these click fix attack detections and like a bunch of them are popping up and like it's very interesting to see where they're originating. So unlike, you know, the phishing attacks that are coming from, you know, typically, okay, there are still a bunch coming through email, but then typically like Twitter, DMs, LinkedIn, DMs, this kind of thing, the click fix stuff is malvertizing and pop WordPress, like that seems to be the go to. So the guys are like vibe coding some kind of website that is specifically targeted to nail one search result, paying a little bit to boost that. And that is how they're delivering this campaign.
A
Yeah, yeah. So now that you've been able to, okay, so in this case you walked it back and detected that the links landed through LinkedIn, you were able to. Or the incident responders, that your customers were able to go to the CEO and say you, you know, you got this message here like like the Link came from LinkedIn, like can you go back through your messages? And like where did you get that link? And then I'm guessing they've discovered that, you know, that their contact must have been breached or whatever. Like were you have you heard through them? Because I'm guessing they're the ones chasing the incident. Like who the attackers were and what they were trying to do. Do they have any idea? And, and, and have you seen this same crew elsewhere or was this just an isolated incident?
C
We saw multiple versions of like an identical campaign. So it's not just this company, multiple tech companies, multiple C levels getting hit in exactly the same way. We ran that blog post. As soon as we put the blog post up, a lot of other people got in touch and got like, oh yeah, same thing hit us. Obviously less information about whether it succeeded or not in that case. So I don't know how many of these attacks succeeded, but like obviously hyper targeted and, and all in the same vertical. So very interesting from that perspective.
A
So now you've Developed this stuff which allows you to walk back the sequence of events, find the origin point of a malicious link. What is the main interest there from users in wanting to be able to walk back these sessions and discover the origin point for links?
C
When you know something bad is happening and it's targeting specific people in your org, that is something to pay attention to, different kind of attention to when it's just like Scattergun and just randomly hit someone, happen to hit someone in your org. So I think there's a little bit of, yeah, there's something actionable there, but I think to a larger degree, a lot of this sort of tracing this, this discovery, this metadata collection is built there so that we can improve the detections. I mean, that's the core of why we built this stuff. Right. So once you start.
A
Well, obviously. So some of these, some of these, some of these chains themselves will become detection, right?
C
Absolutely. And that context, often when you're investigating these things. So let's say you're looking at things like an OAuth app or a browser extension. It's very hard to tell bad or not bad based on the permissions that it's asking for, et cetera, et cetera. You need a lot more data and context. The second you have the entire flow of how this thing came to be installed or approved, that often makes the difference. And it will jump out at you very, very quickly when you start looking at this browser extension is called HubSpot. And you installed it by going to the HubSpot website. Yeah, good. This one. You clicked on a link in Reddit and went through these.ru websites and then ended up installing this thing called HubSpot. Probably not. Okay, so it jumps out at you quite quickly when you start looking at that extra context.
A
Yeah. Now we should mention too that this is something that you are doing, which is new, which is you are able to pull extension information from the endpoints now from the browsers. Are you actually able to do any blocking or enforcement or is it more informational at this point?
C
Informational at this point. The blocking is coming right around the corner. That feature released last week. So we are right around the corner of getting that out. Jam.
A
Excellent. Now you also mentioned just then, intriguingly, Jacques OAuth. So are you actually able to now work these OAuth events into those like timelines?
C
Absolutely, yeah. I mean, detecting an OAuth event is actually a lot easier than you expect. It is like once you just start looking at some of the network traffic, you pull out indicators from that, it's very easy to make that generic. So that's something we're very actively pursuing as well. But I think ultimately we're pursuing everything that happens in the browser. Any kind of attack that's happening in the browser, whether that is like some kind of social engineering getting you to consent to something, approve something, share something, whether that is something like getting you to download malware, especially through the clipboard, as we've seen with these recent click fix attacks that are so effective for reasons I still don't quite understand, but yeah, I mean, they're certainly working and they're effective. So, yeah, every time a new technique comes out, this is the tooling, this is the backend that we're using to basically get on top of that and make sure we get detections out very, very quickly. The second we have this capability, we're using it in a very defined way. We're trying to cover broad attacks that are happening every day. But every time you speak to a customer, they're like, oh, we had these four or five problems that this is the exact data we need to solve those problems. So, you know, we have this weird attack that is targeting our employees by, you know, they're buying AdWords for this exact internal tool that we're using and basically using that to get into our estate. Or we have this use case where this user shared something, accessed something, did something. We want to know who did it. It's where did it happen, when did it happen? So, like all those things are very easily queryable when you have this metadata available.
A
Yeah, right. Man, that's funny. Right? Because the killer use case for PUSH has always been anti phishing and for finding, you know, preventing phishing when the mail gateway has failed or is not in a position to find the link or blow up the link. Right. And even now, obfuscations got so good that quite often mail gateways will see the link but they can't get the payload. They don't know it's malicious. Right. So. So that's always been in my mind the number one selling case for Push. But I can absolutely see how the metadata stuff, it's catnip for more advanced teams. So this is mostly user driven, is it, that you're developing this?
C
Yeah, I mean, it was developed internally, but then we realized, oh, there's actually a lot of people that are willing to invest the time and learn how to use the stuff because the data is very, very valuable. I mean, can you imagine you're in a situation now where you have proxy lock and you have EDR logs. Something is happening on a website somewhere, and then the EDR lights up. But what is happening in between? There's kind of like a missing middle layer there. And this is exactly the data that fills in that gap.
A
Now, this isn't, you know, like we're a Push customer. It's not just like you automatically get this. You sort of have to reach out. This is kind of in early access at the moment, is that right?
C
Correct, yeah. I mean, we're using it internally, but we want to make that available to customers and we have a list of customers that have expressed interest in that. So if you're one of those and this is something you want to get your hands on, please join or have a look at the link. Come have a chat with me. Would love to hear your use cases.
A
All right, Jacques Lowe, thank you so much for joining me to talk about that. I mean, I'm a big Push fan, as you know, and this is really cool, actually. I think. I think it's really cool. But great to see you, mate. Great to chat to you and I'll look forward to doing it again soon. Cheers.
C
Love it. Thanks. Just bet.
A
That was Jacques Lowe from Push Security there. Big thanks to them for that. And big thanks to Push Security for being a risky business sponsor. That is it for this week's show. I do hope you enjoyed it. I'll be back soon with more security news and analysis, but until then, I've been Patrick Gray. Thanks for listening.
C
It.
Date: October 22, 2025
Host: Patrick Gray
Co-host: Adam Boileau
In this episode, Patrick Gray and Adam Boileau break down the ongoing fallout from the F5 breach, exploring the broader issue of insecure edge devices and the chronic state of "crap software" that underpins much of today's security infrastructure. The news segment covers major stories from the infosec world, including China’s finger-pointing at the NSA, Salesforce data breaches, a brutal VS Code worm, vulnerabilities in WSUS and Rust tar libraries, as well as reflections on the dependency on AWS. The episode also features an interview with Push Security’s Jacques Lowe about detecting a sophisticated LinkedIn phishing campaign and new browser-based investigation tooling.
The F5 Breach as Symptom of a Bigger Problem
The hack of F5—the prominent provider of network edge devices—by suspected Chinese threat actors is used as a lens to examine the wider, industry-wide problem of inadequate security practices and lackluster software maintenance among "mid-tier" vendors supplying core network infrastructure. This episode questions the sustainability of “unique” yet poorly maintained products in critical network positions and explores whether the emergence of AI tooling can help reverse the quality rot, as well as the market forces (like private equity) that dampen progress.
Recap of the Attack ([00:00] - [04:24]):
Broader Theme—Crap Software on the Network Edge ([04:24] - [06:20]):
Detecting and unraveling a LinkedIn-based, multi-stage phishing campaign targeting tech CEOs, and the importance of session context and browser-centric detection.
Engaged, knowledgeable, and laced with both dry and overt humor. The hosts repeatedly praise clever/brazen hacking efforts—even when malicious—as “good work.” There’s significant gentle ribbing (“Chef Kiss”, “my God”, “so rude, Microsoft”), and a pragmatic, systems-level view of security reality threaded throughout.
This episode paints a stark picture of the persistence of software rot at the critical edges of the Internet, the complex interplay of state actors in cyberspace, and the growing sophistication of both attackers and defenders. The feature on Push Security’s browser-level visibility and detection reiterates that while prevention is hard, rapid detection and forensics are advancing. All this—plus a healthy dose of InfoSec insider banter—further solidifies Risky Business as a must-listen security news digest.