Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Jack Rhysider

๐Ÿ‘ค Speaker
944 total appearances

Appearances Over Time

Podcast Appearances

Darknet Diaries
174: Pacific Rim

Can you come in and do other work?

Darknet Diaries
174: Pacific Rim

Can you update to a different firmware that has malware on it or something?

Darknet Diaries
174: Pacific Rim

Like, could you do things that, you know, and, you know, you start, your mind starts going like, could you do things that the NSA wants you to do and go and spy on this customer or something like that, right?

Darknet Diaries
174: Pacific Rim

And so when you're a firewall admin, you're like, no, I have to make sure that this is, no other person in the planet can access this but me and other people on my team.

Darknet Diaries
174: Pacific Rim

because you can't risk a backdoor.

Darknet Diaries
174: Pacific Rim

I could just imagine the headlines at this point.

Darknet Diaries
174: Pacific Rim

My question is, did any bad news come out to be like, Sophos found vulnerable, tens of thousands of customers impacted, huge vulnerability, hacker has complete control over their firewalls patch immediately.

Darknet Diaries
174: Pacific Rim

That could make the stock tumble.

Darknet Diaries
174: Pacific Rim

That could really hurt business.

Darknet Diaries
174: Pacific Rim

As the Sophos team investigated this more, they learned that whoever did this attack had to have really in-depth knowledge of Sophos firewalls.

Darknet Diaries
174: Pacific Rim

Like there's no way they should have discovered this bug unless they had access to the source code, which wasn't publicly available.

Darknet Diaries
174: Pacific Rim

And that's when the pieces started clicking into place.

Darknet Diaries
174: Pacific Rim

The part of this firewall that was vulnerable was code from the CyberRome firewall that was moved over to the Sophos firewall.

Darknet Diaries
174: Pacific Rim

And two years before this, as you know, there was an attack on CyberRome.

Darknet Diaries
174: Pacific Rim

And what server did the attackers get access to?

Darknet Diaries
174: Pacific Rim

The one with the source code for their firewall.

Darknet Diaries
174: Pacific Rim

So they started to think, holy crap, this is a very serious threat actor who's been attacking us for years.

Darknet Diaries
174: Pacific Rim

They spent tons of effort getting into CyberRome's network to steal the source code only to study it for bugs and then launch a massive attack on our Sophos firewalls.

Darknet Diaries
174: Pacific Rim

Whoa, what do you even do with this information?

Darknet Diaries
174: Pacific Rim

To think your products are the target for a major cybersecurity campaign like this?