Mikrotik and Cisco Active Exploits

Episode 387 –

This week on the podcast, we analyze a set of actively exploited vulnerabilities in Mikrotik's RouteOS followed by a pair of actively exploited vulnerabilities in Cisco's Firewall Management Center. After that, we review a phishing attack against Trezor hardware cryptocurrency wallet users that originated with their third party marketing email provider.

View Transcript

Marc Laliberte  0:00  
Hey everyone, welcome back to the 443 Security Simplified. I'm your host, Mark Laliberte, and joining me today

Corey Nachreiner  0:07  
is Corey "I'm inside your control plane", Nachreiner

Marc Laliberte  0:11  
That's well, I mean, probably could be. You still have some hacker credit. It's possible,

Corey Nachreiner  0:19  
or maybe all the stories today instead of being other people's third-party vulnerabilities or control plane-related vulnerabilities. That's very good point.

Marc Laliberte  0:28  
On today's episode, we will discuss a very popular consumer slash SMB router under Active Exploit. After that, we'll discuss a very popular firewall manufacturers management center being under active exploit, and then we will end with a marketing platform under active exploit, targeting

Marc Laliberte  0:48  
users of a very popular hardware cryptocurrency wallet.

Marc Laliberte  0:52  
But with that, I don't know. Let's go ahead and hack our way in.

Marc Laliberte  1:03  
I guess to start, Corey, you want to give a quick update on one of the stories we just chatted about last week with a bunch of stolen driver's licenses? I think something new popped up. Yeah, yeah. I guess I'll spend 60 minutes just to give a couple. 60 minutes. So 60 minutes. Wow, 60 seconds. We're not a we're not a popular TV show, but yeah, the first thing everyone remembers that the the research of all the driver's license and many other forms of identification that were lost, and Krebs did very good research showing that it probably came from IDScan.net. But basically, at the beginning of September, they said they had no knowledge of it. The main change is they've now taken accountability and said they they acknowledged for the first time that it was their systems that the hackers had got the credit cards from. So that's one big update. People are probably sick of hearing us talk about OpenAI and Hugging Face. I won't go into all of that, but I will say it's a huge discussion this week, and it will keep going. We have some inquiries happening in Senate around that, and we were talking like one of the big things we talked about is just how crazy it was that these agents swarmed together and found back channels, and beyond. Like we focused a lot on the artifactory stuff, but 10 more sites were disclosed where they had active back channels: a GitHub PasteBin, a German language wiki, university linkshwarteners, a teacher's AP Chemistry site. Oh my God! So

Corey Nachreiner  2:33  
swarms are definitely finding back channels all over the internet. So two updates from last week, but let's get into this week, Mark. Well, I wonder how many students use that as an excuse for why their homework wasn't turned in. Oh, sorry, OpenAI hacked the AP Chemical website, wasn't able to submit it. But anyways, how how are they not turning in homework now when they're just getting AI to do it? I figure turning in homework becomes super easy. I mean, it's funny. Quick tangent on that. Like my kid's school has transitioned from doing like take-home essays that you bring in to much smaller condensed ones that you are required to do in class itself, just to prevent kids from going back and getting ChatGPT to write it all for them.

Marc Laliberte  3:14  
But yeah, anyways, this episode is not about AI, and instead it's about everyone having supply chain issues and companies under attack, but I guess this one is probably maybe less supply chain issues and more. I call them control plane issues, issues in their products. Yeah, let's talk about the first story though. Earlier this month, Microtick, which is a really popular, I would normally call them like consumer or at least like small business router and networking equipment company,

Marc Laliberte  3:43  
but they published a security blog post titled "September 2026 Vulnerability, where they directed customers to upgrade to the latest available firmware with a pretty vague, just important security update statement. They said to give time to update our systems, we're not currently publishing any detailed information. They instead just gave some instructions to upgrade to the latest firmware version. Check for this like status flag called flagged, and if you find that, take a few additional actions. But like they don't seem to have updated this since, right? We we record this on September 11th. By the way, wow! There's an anniversary. Hearts out to all those folks. But this is

Corey Nachreiner  4:27  
still active. Like by the time you hear this podcast, it'd be Monday. But it still looks like this is their only vulnerability page for this particular thing, which people probably see on the video right now. They did one small update on the fifth, and it was only driven because of

Marc Laliberte  4:43  
Cert PL, so I think it was like the Polish Cert organization, where the real story is. Yeah, where they went and reverse engineered the firmware updates for Microtix routers and basically discovered a whole suite of vulnerabilities, including a couple that are currently under active exploits.

Marc Laliberte  5:00  
Linked to that security advisory that Microtek put out, and we'll get into the vulnerabilities in a second. And I think I understand why Microtek probably didn't want to discuss the vulnerabilities because just even the short form description

Marc Laliberte  5:14  
is like it's obvious where the issue is and how to potentially exploit it. Yeah, when we get into crypto one, it's pretty it's pretty crazy crypto mistake. Yeah. So CertPL put out a blog post and published a bunch of advisories under their own label. They're a certified numbering authority for the CVE system, so they're the ones that publish these, not Microtick.

Marc Laliberte  5:35  
And they listed out a couple of very serious looking ones. One of them was CVE 2026 67276 is described as a SSH authentication bypass, where they even say in the description here the router doesn't compare the entire public key assigned to a user if they're using public key to for authentication, and instead just looks at the modulus, so like one piece of the key material that is not designed to be a secret,

Marc Laliberte  6:04  
and basically an attacker can craft a different key that uses that same modulus and use that to log in as any arbitrary SSH user.

Marc Laliberte  6:13  
So this one is like I understand why Microtek didn't want to talk about this. They should have some transparency, but I can see why they might have been like convinced not to give specific. Yeah, like to me, this is a crazy cryptography. It's like you have a key and you're checking to make sure the key is made from the right brand that you get the lock from, and even has a picture of the the right say person that the key is supposed to unlock a door to, but you never actually check if the key fits the door. Exactly, that's a great analogy. Crazy.

Marc Laliberte  6:49  
I'm trying to think of like

Marc Laliberte  6:51  
it's interesting that this flaw could even exist. Like most networking equipment is typically built off Linux. You've got some other folks like Cisco that have their own operating system, but I'm willing to bet that Router OS, which is their operating system, is probably built on Linux or Unix. Those have very standard libraries for handling SSH and handling SSH authentication. And this sounds like they rolled their own crypto, or at least their own authentication library, to introduce this issue. Because I'm not aware of any like OpenSSH

Marc Laliberte  7:23  
or OpenSSL or like any OFD issues that could have caused this. So it's interesting seeing this pop up in a router that, in my opinion, I mean without knowing the specifics, but more often than not they use standard libraries. So that was interesting. It's the easiest way to do it for something as common as this type of check. Yep, another issue: CV 2026 86 060, which was a SSH session privilege manipulation issue. Basically, it sounds like router OS doesn't handle usernames that start with invalid characters during the SSH login well enough, and attackers can basically use a specially crafted username to gain additional privileges on the system. When you look at the actual CVE and some of the IOCs they gave,

Marc Laliberte  8:13  
it they show like negative two as the user authenticating. So it looks like if you've got like a negative number prepended to the username, it's handled differently if it authenticates, and it can be used to manipulate the privileges that account has.

Marc Laliberte  8:28  
That one's kind of interesting.

Corey Nachreiner  8:29  
And by the way, all of these chain together to make things worse. But basically, the first two are what give unauthenticated

Corey Nachreiner  8:38  
like root access. Root access. I mean, those two together get you the full admin and access without actually logging in as anything, or at least access without the right secrets in order to get in. Yeah,

Marc Laliberte  8:54  
they listed another one in their blog post. They actually had six vulnerabilities they published for Microtick, but the third they highlighted in their post was a memory disclosure and crash. It's like a memory corruption issue

Marc Laliberte  9:06  
in the bandwidth test utility within Microtek routers. Basically, allows them to leak sensitive memory and create a denial of service by crashing the process. So an attacker could use this to like. There's a lot of sensitive data that might exist only in memory, like other secrets on the device, and they could use this to potentially steal information off of it. So,

Marc Laliberte  9:28  
Cert. PL put out a lot of details, or at least the vulnerabilities themselves, in their blog posts. Some additional indicators of compromise

Marc Laliberte  9:36  
for Microtick. They gave like this interesting set of instructions to look for a new like status parameter they added called flagged, where if you have that parameter set on your device, like it when it boots, it checks for a potential compromise. If it finds a potential compromise, it sets this flag, and it actually disables some functionality if it does that, like that vulnerable bandwidth checker.

Corey Nachreiner  10:00  
Sox proxies, you know, any sort of our our VPN really is disabled. Even things like Windows file sharing over the network seems to be disabled. Seems I thought that was an interesting mitigation step for them to add. This is this is the only good news. This is them essentially adding some firmware security. I will say, although

Corey Nachreiner  10:24  
Cert Polska and us have a probably have an opinion on it, the flag doesn't mean you're compromised for sure. It means it's running in a state that's not 100% recognized. And I think everyone would agree that if you ever have that status, you gotta assume you're compromised, and that means a lot of things. So I do like that they added this. It's not like locked out, which

Corey Nachreiner  10:49  
completely, but at least it does lower things. I also like I don't know if you're going to get into it, but to revert this state, you actually have to have physical access to the box.

Corey Nachreiner  10:59  
So which is a good thing. It kind of forces the administrator to go and handle things before just turning this off and continuing with business as normal. So I would say this is a good step to take when you have these sorts of issues in a router, a routing device. Yep.

Marc Laliberte  11:17  
Sir Polska gave a few other IOCs. They said look for a highly privileged user named Ops on the device, but one other thing that stood out to me in their post at the very end, they basically yeah they said that they used GPT 5.5 Cyber and GPT 5.6 Soul as a part of OpenAI's trusted access for government and other agencies

Marc Laliberte  11:39  
to find these vulnerabilities, and it was interesting. Like they even gave a bit of a write-up about how difficult it was and what they had to do to use multiple stages of prompts to get there. Yeah, they're they're basically. It seemed like their feelings were,

Corey Nachreiner  11:54  
we couldn't have done this as fast without the AI. But it's the people that think AI just finds everything. They they seem to say that's wrong. They still had to do work.

Corey Nachreiner  12:05  
I I don't know how true that is because they I think is the basically the GT GPT Cyber Five Five is the same mid middle ground frontier model that we use to test code too now right is is it or is is that the full cyber? That's the full cyber one, so it should be even better. But yeah, I found one. I to me just just shows that AI assisted discovery is going to accelerate things. Even though I part of their takeaways was we still needed humans to figure stuff out. Yep, and they even mentioned like why are they specifically published this two days later, I suspect there's some undertones in here that they thought that Microtix Post, like, well, I'm going to say I thought that Microtix Post was lacking some information to help

Marc Laliberte  12:52  
help their admins actually like mitigate the risk if they couldn't upload or update immediately, like knowing that it was exposed over SSH, even without saying like the exact vulnerability would be useful information to have, but it looks like Cert PL was saying like the firmware is already out. Other people are already doing a comparative analysis to find the vulnerabilities, so they want to at least give some information to help defenders that maybe couldn't do that themselves, which I thought was appropriate as well. Yeah.

Corey Nachreiner  13:23  
By the way, besides getting patches, this is a class of attack where if you have if you cannot verify whether you're affected or not, you need to reset all your keys,

Corey Nachreiner  13:34  
and and lock down your configuration. It you know we know that people were looking for this a day before even Microtix first alert, let alone three days until the the Cert Polska one. So just make sure if you are a Microtek user,

Corey Nachreiner  13:52  
it's time to reset your secrets.

Marc Laliberte  13:54  
And it's also a class of attack that goes after exposed management interfaces on networking equipment, which should never be exposed to the internet. Yeah,

Corey Nachreiner  14:03  
I wonder what the next story is. I'm sure even after our own

Corey Nachreiner  14:08  
issue with management interfaces, where we never wanted them to be exposed, I'm sure you're not going to see big vendors have those problems anymore. Of course not. Let's transition to the next story. The next story, where Cisco Talos, just this last week, a couple days ago, actually at the time of us recording, published a threat advisory about a pair of actively exploited vulnerabilities in their Secure Firewall Management Center or FMC software. It was two vulnerabilities. One was CV 2026 20,079, which is a authentication bypass vulnerability that ultimately grants root level access to the operating system where the software is installed. The other was CB 2026 20,003 16, which was static credentials that let an attacker log in with a low privileged account, which.

Marc Laliberte  15:00  
Cisco Talos noted is almost always paired with a privilege escalation vulnerability to gain elevated access on the system.

Marc Laliberte  15:08  
In their post, they talked about three distinct clusters of state-sponsored or crimeware threat actors exploiting these vulnerabilities to deploy web shells, or command executors, or just use get credential theft or steal the configurations off of these systems.

Marc Laliberte  15:25  
The first threat actor, UAT 12 197, was a unattributed threat actor. They haven't linked it to like some widely known

Marc Laliberte  15:35  
like state sponsored or

Marc Laliberte  15:38  
cyber crime organization yet, but it was a distinct cluster of activity that I think is at least one group of threat actors, where they were deploying a JSP-based web shell to ultimately steal the user database and steal credentials off of these vulnerable systems.

Marc Laliberte  15:54  
The second threat actor, UAT 11 823, they say overlaps with Sandworm, which is our best friend, over in the Russian GRU-backed nation-state threat actor,

Marc Laliberte  16:07  
where they were exploiting that first vulnerability and the static credentials to gain access. They would gain persistence by updating a file called license.temp on the disk

Marc Laliberte  16:18  
to replace it with a netcat-based reverse shell back to their own command and control infrastructure,

Marc Laliberte  16:24  
and

Marc Laliberte  16:25  
they ultimately deployed a Cyclops Blink variant, which was a Linux-based implant

Marc Laliberte  16:32  
that uses like init d scripts to stay persistent, DNS over HTTPS to hide some of its communications, could gain steal credentials off the device, download or upload arbitrary files, and whole suite of different tools.

Marc Laliberte  16:47  
For those that aren't in the know, Cyclops Blink was the incident. What five years ago now? Six years ago now,

Corey Nachreiner  16:53  
where is it that long feels like yesterday? But it's been a while. It has been a while, which was the latest evolution at the time of the VPN filter malware that Sandworm was deploying to edge networking equipment in SMBs and mid-sized enterprises?

Marc Laliberte  17:11  
Cyclops Blink is the one that originally affected WatchGuard and Asus devices at the time, and it looks like they're continuing to evolve their capabilities and now going after. By the way, if I remember,

Corey Nachreiner  17:23  
we knew they affected us. Obviously, we were working with the FBI.

Corey Nachreiner  17:28  
The FBI couldn't really share the second vendor, but we later learned there it was ASIS. I remember learning of a small amount of a third vendor, and I feel like the vendor from the story just before might have been the one we suspected at the time, but the one thing I mean, the main thing I want to take away here is it does go to show that things like Cyclops Blink aren't just targeted at WatchGuard. I mean, you should because of VPN filter, because of so many of the firewall related targets lately with VPNs and other things.

Corey Nachreiner  18:02  
Yes, we're part of this vendor ecosystem, and we need to do our we need to do our work to secure and are doing our work to secure our operating systems against these attacks. But this is clearly something that they're targeting across the industry more around networking devices and network security devices in general.

Marc Laliberte  18:21  
Absolutely, and if you haven't updated your networking equipment in the last six years, now is probably the time to do

Corey Nachreiner  18:30  
it. Yeah, I guess I'll go on that. In that, it has nothing to do with Cyclops Blink, but just in December we

Corey Nachreiner  18:37  
shared a VPN vulnerability that we actually, you know, had found long before people were exploiting it. I believe for the December one. Either way, it's been patched for months, and it looks like

Corey Nachreiner  18:51  
Cert or not Cert. CISA and ShadowServe have been scanning to see how well our customers are patching. And there's still 9000 devices out there that don't have that update, you know, it's on us to fix our vulnerabilities. We'll take absolute credit for or accountability, I should say, for that. At this point, this has been out for a while. If you're running a firewall on the internet and and you have not updated in six months, no, wait, nine months.

Corey Nachreiner  19:22  
Please go update so that you're not, you know, victim of this kind of thing.

Marc Laliberte  19:28  
The back to the story for Cisco's FMC software. The third threat actor was a chillin ransomware operator where they were using the static credentials to gain access and then ultimately elevate privileges. They then used that as kind of a bastion to do network reconnaissance of the networks that

Marc Laliberte  19:46  
the firewall management server had access to. They staged a reverse SOX proxy and tunnel for persistent access, and then ultimately deployed antivirus killers and then the Chillin ransomware family to affected systems.

Corey Nachreiner  20:00  
I'm glad you pronounced that. I still would don't default to the right "chilling" with the queue.

Marc Laliberte  20:06  
It's. I think it's an. Oh, I don't actually know if "chilling" is a word in Chinese. That is the way you would pronounce it. But I always thought, you know, they're just chilling.

Corey Nachreiner  20:16  
They're chilling, waiting for their ransom to pay off. Exactly.

Marc Laliberte  20:21  
So if you have a Cisco firewall management server or center, make sure you update that

Marc Laliberte  20:28  
as quickly as possible if you haven't already, and look for some of the indicators of compromise that Cisco Talos shared in their their blog post on september 9.

Marc Laliberte  20:38  
Moving on to

Corey Nachreiner  20:39  
it might also be worth mentioning all the living off. Like we talk a lot about living off the land in context of endpoint attacks. They seem to be doing it on on attacks against devices too.

Corey Nachreiner  20:52  
So just something interesting here.

Corey Nachreiner  20:56  
Anyways, yeah, can move on now.

Marc Laliberte  20:59  
Moving on to the last story, and this one actually, there's some news posts that we'll talk about. But I first became aware of this when one of our

Marc Laliberte  21:06  
coworkers posted it on our team's channel that he thinks he he thought he saw a fish from Trezor pop into his mailbox. If you're not familiar with Trezor, it's a really popular hardware cryptocurrency wallet. It's for folks that you know don't want to keep their cryptocurrency in a software-based wallet on their computer, which is more prone to potential theft by by social engineering or other accidents. Hardware wallets are like a USB tool, or sometimes not even USB, just totally separate from a computer, where you can generate a crypto wallet and use that to store the private keys associated with it offline from your machine.

Marc Laliberte  21:46  
Well, they sent had a security incident last week involving nearly 350,000 of their users that had signed up for their newsletter,

Marc Laliberte  21:55  
where these users received an email with the subject line "Critical Security Alert SMT 32 Entropy Vulnerability. which contained a link that prompted them to download a malicious app and enter in their wallet backup, which would allow the attacker to gain access to the wallet and drain anything of value out of it. By the way, before we even go deeper, I the people who watch the video too might see us showing the Trezner

Corey Nachreiner  22:21  
blog post with that email, but the title of it is "Security Incident at Brevo. We're going to get into that, and there's definitely truth in that. But I gotta say,

Corey Nachreiner  22:34  
if you're reporting a security incident that ultimately comes from you,

Corey Nachreiner  22:40  
I feel like you should take a little bit of accountability before sharing the detail of how it involved a third party. It it it feels right away to me like, even though their systems were the ones sending the scam email, and we'll get into how

Corey Nachreiner  22:54  
that they they

Corey Nachreiner  22:56  
like moved to someone else almost immediately. Yeah, let's get into how the incident occurred, because I think what you're hinting at is there was some involvement from at least one Trezor employee in here for this to attack to have even worked.

Marc Laliberte  23:09  
So basically, they pointed to their third-party marketing email provider, Brevo, as the source of the issue, and Brevo later put out a statement with some additional information on what happened. They said attackers exploited a flaw in how they handle Saml single sign-on to gain access to 138 different accounts, six of which were used to send phishing emails, and 43 of which had their contacts harvested out of it. And basically, how the attackers got in is they created their own Brevo account and set up single sign-on to a Saml identity provider. They then invited legitimate Brevo users in other accounts into their tenant. If those Brevo users accepted the invite, the the attacker could use Saml single sign on from their IDP that they controlled to log in as that other user. Where the issue was is that should have let them log in as that user in their tenant, the attacker's tenant, but due to some scoping issues, it allowed them to log in as that user in any tenant that that user had access to. And to be fair, that was completely a brevo vulnerability in the way they were setting up these tenants in the single sign-on. Yep, exactly. Says it makes sense if you control the IDP, you control being able to log in as that user in the IDP. If someone has linked their account to it, makes sense that you could log into them in your tenant.

Marc Laliberte  24:35  
But basically, the attackers, let's say they set up attacker.brevo, linked it all up, and then they could log into the user's account in the Trezor tenant, and then send out these phishing emails. But in order for this to succeed, at least one Trezor employee had to accept that invite into this malicious tenant within Brevo. So they were social engineered to gain access to their account. So it was a call.

Marc Laliberte  25:00  
Of like a security vulnerability and still very targeted social engineering against

Marc Laliberte  25:06  
corporate users on Brevo, which gave that access.

Marc Laliberte  25:11  
And to Brevo's credit, they actually they resolved the issue within two hours and actively logged out everyone that was still had access to the platform.

Marc Laliberte  25:20  
But I think to your point, Corey, like

Marc Laliberte  25:23  
there's a couple pieces in here. First off, someone at Trezor got social engineered and tricked into joining this malicious tenant that they shouldn't have joined. And then B, there is still a piece of this where you need as a vendor like accountability for the vendors that you work with, especially when they affect your customers like this. Like this is the whole reason that we do third-party validation like SwatchGuard, just to limit the like try and limit the crappy vendors that we work with where this could be an issue.

Corey Nachreiner  25:50  
Yeah, and it's not going to catch all. We do strong third-party validation, and we still have had vendors that have suffered breaches, but because of all the work we do in validating them, including making sure we have signed agreements for knowing when things like that happen, we get full access to work with them and see if their issue actually affects our customers. So, third-party validation. I I think as much as I love Trevor's Trezor's blog post, not not Trevor, our fantastic security analyst Trezor.

Corey Nachreiner  26:25  
For all we know, maybe they do third-party validation. So I don't want to sell it as something that means you always have vendors that don't have their issues. It just gives you more understanding of the data. It gives you the ability to add your own monitoring on your side. So when they have incidents with it, you can have some sort of catch where you can start an incident, and it gives you lots of agreements where,

Corey Nachreiner  26:46  
if they are breached or if your data is lost, they have to get to you quickly to to talk about it so that you can do what you need for your customers. So, absolutely agree 100% on the vendor validation. Just want to make sure people know it doesn't mean that a vendor, like even the best vendors, have stuff that happens. So it's not going to prevent that. It just gives you all the right governance controls to start finding it. Yep. So when it comes to a Trent Reznor, or sorry, Trezor,

Marc Laliberte  27:16  
they noted in their blog post that around two and a half 1000 people actually clicked the link before they were able to take it down. They actually managed to submit an abuse report on the DNS level and get the malicious domain taken offline within 20 minutes of identifying this incident happen, which is pretty quick from all parties involved there. But two and a half 1000 people did at least click the link, and they are still investigating if any of them ended up actually downloading the malicious app and becoming compromised,

Marc Laliberte  27:46  
but go ahead.

Corey Nachreiner  27:49  
Oh, I didn't know if we're still at talking points for this. Yeah, or

Corey Nachreiner  27:53  
I would say one interesting thing is there's so many SaaS services out there similar to Brevo,

Corey Nachreiner  28:00  
where you tie in your infrastructure and often emails from you to another service, but

Corey Nachreiner  28:06  
you can do that in many ways. Sometimes the email comes from

Corey Nachreiner  28:10  
maybe your users or partially your domain, but through their domain. And and I think one of the things with the kill switch is how when you make these sort of email sending provider connections. Do you control the domain? Meaning, when something like phishing happens, is it just a DNS change you can make that kills it immediately before more and more stuff gets sent, or are the

Corey Nachreiner  28:37  
connections you're sending through with your email provide with whatever the email services make it so it's still going to happen until the third party does something. So I thought that is an interesting think about thing to think about as you're doing these services. Maybe stick with ways to implement them where you still control the domain

Corey Nachreiner  28:57  
and have the ability to disable things in flight when they start to happen.

Marc Laliberte  29:03  
Yeah,

Marc Laliberte  29:04  
and I thought this was another just interesting story in general, where there's clearly targeted phishing still going on against like the cryptocurrency ecosystem. Because absolutely, for better or worse, there is still a ton of money tied up in that ecosystem, and if you can get after even a handful of people's hardware crypto wallets and drain them. That could be a pretty big return on investment for an attacker. So, like, if anyone's listening that does have a quote unquote investment in cryptocurrency still, like, hopefully you already understand that anything related to that is high risk, very high risk, and take every single email you get from your wallet providers,

Marc Laliberte  29:46  
the the marketplaces you work with, with a very big grain of skepticism before taking any action. Because, like the funny enough, like our our coworker Ryan, who's been on the podcast a couple times, that has the the.

Marc Laliberte  30:00  
Trezor wallet. He said, like this phishing email soon after it came with like a snail mail notification from Trezor about like an actual security incident involving their their shipping supplier, and like there's a lot of I guess mixed signals going on where it's tough to understand what's real and what's not, and it's best just to take the safest approach of maybe not entering your wallet backup information into a random website you got absolutely

Corey Nachreiner  30:26  
adding a little to the trying to figure out what's real or not one of the ways about the way they phished coming through a known invalidated provider meant that these phishing emails completely passed DKIM you know their DMARC and SPF they had all the right markings because this Brevo connection was a legitimate one. So

Corey Nachreiner  30:48  
you know that just makes it harder to find certain types of advanced fish when they're actually taking

Corey Nachreiner  30:54  
control of your own infrastructure through

Corey Nachreiner  30:57  
really an identity issue, a credential issue, but one that was exposed through SSO,

Corey Nachreiner  31:02  
so

Corey Nachreiner  31:04  
definitely I'm glad that even our original analyst noticed this was fishy mail so long ago.

Corey Nachreiner  31:11  
Was there also something weird about I didn't follow the story as much as you, but Shipmunk? Some of the stuff in that, like I think

Corey Nachreiner  31:19  
I don't know if it's between Trezor and Brevo. Keep on thinking, or something in the email that Trezor shouldn't still have. But it seemed like there was a contract associated with retention and data that should be deleted wasn't and ended up getting stolen. Seems like it was just shipping info, like basically

Marc Laliberte  31:41  
the think the address and names of people that received orders from Trezor. It was like 80,000 of them got leaked because of a breach at a shipmunk. But it does. It makes me think. My understanding was they weren't supposed to still have that data that they had told you know somewhere in their materials they said at some point we'll get rid of that, so we won't have your edge. And that just speaks to me. I mean, maybe it was negligence and accident, but what are the point of all these privacy agreements and those sort of things if you're not actually going to delete the data you say you're not going to collect or store for that long? Data minimization is a very real thing that can help limit the impact of a security incident if you have one. If you don't need to keep 60,000 or whatever customers' records from shipments you've already made, maybe it's time to delete them. I don't know,

Marc Laliberte  32:33  
but either way, I'm going to chalk this up to one more reason to exit the cryptocurrency ecosystem if you're still an active participant in it, but that's just me and my lack of faith in humanity when it comes to cryptocurrency. Maybe one day we'll have a digital currency that might be based on blockchain but has some sort of trusted backing.

Corey Nachreiner  32:55  
I do want digital currency one day.

Corey Nachreiner  32:58  
I hear there's a trust crypto yet?

Marc Laliberte  33:01  
Isn't there like a Trump Trump coin that you can buy into if you really want that right now?

Corey Nachreiner  33:06  
Didn't I say the word trust? I guess that might work for some people. That's not going to be my coin of choice. Touche.

Marc Laliberte  33:15  
I think a good place to end.

Marc Laliberte  33:21  
Hey everyone, thanks again for listening. As always, if you enjoyed today's episode, don't forget to rate, review, and subscribe. If you have any questions on today's episode or suggestions for future episode content, you can reach out to us on Blue Sky. I'm at it's mark.me. Corey's at Second Ept, and the both of us are on Instagram at WatchGuard underscore Technologies. Please send your vacation photos and food recipes, or whatever else you use Instagram for.

Corey Nachreiner  33:46  
Need high protein, low calorie, though. Only those recipes will be accepted.

Marc Laliberte  33:51  
I'm looking for cinnamon roll recipes, so those work too. Thanks again for listening, and you will hear from us next week.