It was only a matter of time. episode artwork

EPISODE · Jul 25, 2020 · 14 MIN

It was only a matter of time.

from Research Saturday · host N2K Networks

On April 29, 2020, the Salt management framework, authored by the IT automation company SaltStack, received a patch concerning two CVEs; CVE-2020-11651, an authentication bypass vulnerability, and CVE-2020-11652, a directory-traversal vulnerability. On April 30, 2020, researchers at F-Secure disclosed their vulnerability findings to the public, with an urgent warning for Salt users - patch now. Before the weekend was out, criminals were deploying malware and targeting vulnerable Salt installations, successfully affecting operations at Ghost, DigiCert, and LineageOS. The malware is a cryptominer, but there is an additional component, a Remote Access Tool written in Go called nspps. Researchers at Akamai have also observed in-the-wild attacks on Salt vulnerabilities.  Joining us on this week's Research Saturday is Larry Cashdollar, Senior Security Response Engineer at Akamai, to discuss this issue.  The research can be found here:  SaltStack Vulnerabilities Actively Exploited in the Wild

Episode metadata supplied by the publisher feed · Published Jul 25, 2020

Embed this episode

NOW PLAYING

It was only a matter of time.

0:00 14:58

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Research Saturday?

This episode is 14 minutes long.

When was this Research Saturday episode published?

This episode was published on July 25, 2020.

Can I download this Research Saturday episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!