Discover this podcast and so much more

Podcasts are free to enjoy without a subscription. We also offer ebooks, audiobooks, and so much more from just $11.99/month.

Using global events as lures. [Research Saturday]

UNLIMITED

Using global events as lures. [Research Saturday]

FromCyberWire Daily


UNLIMITED

Using global events as lures. [Research Saturday]

FromCyberWire Daily

ratings:
Length:
22 minutes
Released:
Aug 22, 2020
Format:
Podcast episode

Description

The goal of malicious activity is to compromise the system to install some unauthorized software. Increasingly that goal is tied to one thing: the user. Over the past several years, we as an industry improved exploit mitigation and the value of working exploits has increased accordingly. Together, these changes have had an impact on the threat landscape. We still see large amounts of active exploitation, but enterprises are getting better at defending against them.
This has left adversaries with a couple of options, develop or buy a working exploit that will defeat today's protections, which can be costly, or pivot to enticing a user to help you. In today's threat landscape, adversaries are always trying to develop and implement the most effective lures to try and draw users into their infection path. They've tried a multitude of different tactics in this space, but one always stands out — current events.
Joining us on this week's Research Saturday from Craig Williams from Cisco's Talos Outreach team to walk us through how current events are used as lures.
The research and blog post can be found here: 
Adversarial use of current events as lures

The CyberWire's Research Saturday is presented by Juniper Networks.
Thanks to our sponsor Enveil, closing the last gap in data security.
Released:
Aug 22, 2020
Format:
Podcast episode