Episode 370: Hidden in Plain Sight




TechSNAP show

Summary: <p>We explain how the much hyped VPNFilter malware actually works, and its rather surprising sophistication.</p> <p>Plus a clear break down of the recent Kubernetes news, how a 40 year old tel-co protocol is being abused today, and a Git vulnerability you should know about.</p><p>Sponsored By:</p><ul> <li> <a rel="nofollow" href="http://techsnap.ting.com">Ting</a>: <a rel="nofollow" href="http://techsnap.ting.com">Save $25 off a device, or get $25 in service credits!</a> Promo Code: Visit techsnap.ting.com</li> <li> <a rel="nofollow" href="http://ixsystems.com/techsnap">iXSystems</a>: <a rel="nofollow" href="http://ixsystems.com/techsnap">Get a system purpose built for you.</a> Promo Code: Tell them we sent you!</li> <li> <a rel="nofollow" href="https://do.co/snap">Digital Ocean</a>: <a rel="nofollow" href="https://do.co/snap">Apply our promo snapocean after you create your account, and get a $10 credit.</a> Promo Code: snapocean</li> </ul><p>Links:</p><ul> <li><a title="Hiding Information in Plain Text - IEEE Spectrum" rel="nofollow" href="https://spectrum.ieee.org/tech-talk/computing/software/hiding-information-in-plain-text">Hiding Information in Plain Text - IEEE Spectrum</a></li> <li><a title="Remediating the May 2018 Git Security Vulnerability – Microsoft DevOps Blog" rel="nofollow" href="https://blogs.msdn.microsoft.com/devops/2018/05/29/announcing-the-may-2018-git-security-vulnerability/">Remediating the May 2018 Git Security Vulnerability – Microsoft DevOps Blog</a></li> <li><a title="When to use git subtree? - Stack Overflow" rel="nofollow" href="https://stackoverflow.com/questions/32407634/when-to-use-git-subtree">When to use git subtree? - Stack Overflow</a></li> <li><a title="Ghostery Email Incident Update - Ghostery" rel="nofollow" href="https://www.ghostery.com/blog/ghostery-news/ghostery-email-incident-update/">Ghostery Email Incident Update - Ghostery</a></li> <li><a title="Surprise! Student receives $36,000 Google bug bounty for RCE flaw – Naked Security" rel="nofollow" href="https://nakedsecurity.sophos.com/2018/05/23/surprise-student-receives-36000-google-bug-bounty-for-rce-flaw/">Surprise! Student receives $36,000 Google bug bounty for RCE flaw – Naked Security</a></li> <li><a title="SS7 routing-protocol breach of US cellular carrier exposed customer data | Ars Technica" rel="nofollow" href="https://arstechnica.com/information-technology/2018/05/nefarious-actors-may-have-abused-routing-protocol-to-spy-on-us-phone-users/">SS7 routing-protocol breach of US cellular carrier exposed customer data | Ars Technica</a></li> <li><a title="SnoopSnitch - Apps on Google Play" rel="nofollow" href="https://play.google.com/store/apps/details?id=de.srlabs.snoopsnitch&amp;hl=en_US">SnoopSnitch - Apps on Google Play</a></li> <li><a title="Kubernetes Containerd Integration Goes GA - Kubernetes" rel="nofollow" href="https://kubernetes.io/blog/2018/05/24/kubernetes-containerd-integration-goes-ga/">Kubernetes Containerd Integration Goes GA - Kubernetes</a></li> <li><a title="Hackers infect 500,000 consumer routers all over the world with malware | Ars Technica" rel="nofollow" href="https://arstechnica.com/information-technology/2018/05/hackers-infect-500000-consumer-routers-all-over-the-world-with-malware/">Hackers infect 500,000 consumer routers all over the world with malware | Ars Technica</a></li> <li><a title="FBI seizes domain Russia allegedly used to infect 500,000 consumer routers | Ars Technica" rel="nofollow" href="https://arstechnica.com/information-technology/2018/05/fbi-seizes-server-russia-allegedly-used-to-infect-500000-consumer-routers/">FBI seizes domain Russia allegedly used to infect 500,000 consumer routers | Ars Technica</a></li> <li><a title="Singapore ISP Leaves 1,000 Routers Open to Attack | Threatpost | The first stop for security news" rel="nofollow" href="https://threatpost.com/singapore-isp-leaves-1000-routers-open-to-attack/132315/">Singapore ISP Leaves 1,000 Routers Open to Attack | Threatpost | The first stop for security news</a></li> <li><a title="Don't let Frank near the server" rel="nofollow" href="https://pastebin.com/sM9QicJE">Don't let Frank near the server</a></li> <li><a title="Dave decides to move some plugs... " rel="nofollow" href="https://pastebin.com/PCNtN439">Dave decides to move some plugs... </a></li> </ul>