Risky Business #666 -- The msdt RTF of DOOM
Risky Business #666 -- The msdt RTF of DOOM

Risky Business #666 -- The msdt RTF of DOOM

Lord Sky

52 min
News
Play

Description

<p>On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:</p> <ul> <li>The msdt/office lolbinapalooza</li> <li>Microsoft to introduce sensible defaults to Azure</li> <li>Twitter fined $150m for sms 2fa spam</li> <li>It turns out npm got owned in that Heroku/Travis CI thing</li> <li>AWS cred-stealing supply chain attack was research your honour, I swear!</li> <li>Much, much more</li> </ul> <p>We’ll be chatting with Airlock Digital co-founder and CTO Daniel Schell in this week’s sponsor interview. He’ll be walking us through some of his own research into how to own Microsoft boxes via document-embedded office add-ins.</p> <p>Links to everything that we discussed are below and you can follow <a href="https://twitter.com/riskybusiness">Patrick</a> or <a href="https://twitter.com/metlstorm">Adam</a> on Twitter if that’s your thing.</p> <div class="panel panel-default"> <div class="panel-heading"> <h3 class="panel-title">Show notes</h3> </div> <div class="panel-body"> <ul> <li><a href="https://twitter.com/nao_sec/status/1530196847679401984">nao_sec on Twitter: &quot;Interesting maldoc was submitted from Belarus. It uses Word&#39;s external link to load the HTML and then uses the &quot;ms-msdt&quot; scheme to execute PowerShell code. https://t.co/hTdAfHOUx3 https://t.co/rVSb02ZTwt&quot; / Twitter</a></li> <li><a href="https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e">Follina — a Microsoft Office code execution vulnerability | by Kevin Beaumont | May, 2022 | DoublePulsar</a></li> <li><a href="https://twitter.com/gossithedog/status/1531608245009367040?s=21&t=5tw1j6eearOCQ7A0nodYdQ">Kevin Beaumont on Twitter: &quot;Additional Follina iss

Uploader

angie_roads

angie_roads

Risky Business #666 -- The msdt RTF of DOOM - Listen Free | WowFM