Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Andrew Brandt

πŸ‘€ Speaker
451 total appearances

Appearances Over Time

Podcast Appearances

Darknet Diaries
174: Pacific Rim

It's amazing to me.

Darknet Diaries
174: Pacific Rim

It's now 2020.

Darknet Diaries
174: Pacific Rim

You know, we now have the team up and running.

Darknet Diaries
174: Pacific Rim

I've got a couple of people working with me.

Darknet Diaries
174: Pacific Rim

We're publishing a few blogs a week.

Darknet Diaries
174: Pacific Rim

And I find out from internal people within the company that there's a security incident.

Darknet Diaries
174: Pacific Rim

And the security incident started with a tech support call

Darknet Diaries
174: Pacific Rim

where someone sent an email to their support technician and said, hey, my firewall is showing this URL in the user interface, and I didn't put it there, and I don't know why it's there.

Darknet Diaries
174: Pacific Rim

So the Sophos has a firewall called the XG firewall.

Darknet Diaries
174: Pacific Rim

At this point, it was just called the XG firewall.

Darknet Diaries
174: Pacific Rim

And the firewall has its own operating system.

Darknet Diaries
174: Pacific Rim

It's running a version of Linux in it.

Darknet Diaries
174: Pacific Rim

It has a UI that's running on the front of it so that you can manage it.

Darknet Diaries
174: Pacific Rim

This is not good at all.

Darknet Diaries
174: Pacific Rim

And they found that essentially every firewall that was facing the public internet was affected by this bug.

Darknet Diaries
174: Pacific Rim

they pushed out a hotfix to these firewalls.

Darknet Diaries
174: Pacific Rim

A hotfix is like a little software patch that can run in real time.

Darknet Diaries
174: Pacific Rim

They can live update all the firewalls remotely with these hotfixes.

Darknet Diaries
174: Pacific Rim

It doesn't require the firewall to reboot to be enabled.

Darknet Diaries
174: Pacific Rim

And they felt like they had analyzed the attack and figured out exactly how the threat actors were leveraging their access.