Brandon: Welcome to the latest episode of the Registers Kettle Podcast. I'm your host, Brandon Vigliarolo, and this week we have some rather interesting security stories to talk about concerning yet another Salesforce data breach affecting a whole bunch of companies, ⁓ the new extortion gang behind them, and the trouble the whole thing has spelled for one of the first companies to point the whole thing out. ⁓ this week I'm joined by US editor Avram Pilch and security editor Jessica Lyons to talk about this whole mess and more. Welcome to you both. JESSICA: Good to be here. Avram Piltch: Hey. Brandon: Yeah. So Jess, let's start with that sales force supply chain attack that you wrote about this week. I understand there was a market intelligence connector of some sort that was behind the incident, right? JESSICA: Right. So there's this company named Clue, and they provide market intelligence to more than 250,000 users worldwide. ⁓ and they integrate with Salesforce. And so apparently what happened in around June 11th, you know, sometime around that that period of time, ⁓ somebody used compromised legacy credentials linked to the Salesforce integration, and then Brandon: Mm-hmm. JESSICA: by that they were able to obtain OAuth tokens ⁓ and then were able to access customers Salesforce data, clue customers Salesforce data from that. So they Brandon: Okay, so it was it was clue it was data that Clue had on their customers in their Salesforce environment or they pivoted to the customers' environments as well? JESSICA: It they pivoted right. It was it was through it was the integration with with the Salesforce ⁓ databases. Yeah. No, no, not Brandon: Okay, gotcha. Wow. So that's not great. I mean a lot of companies were exposed, right? And a lot of them I think in your article you mentioned were were security companies. Is that right? JESSICA: There a ton of security ones, right. And then LastPass, this huge password manager. ⁓ we don't know how many they didn't include Huntress, which is one of the security companies who was involved in this and and who came out kind of on the forefront and said, Yeah, we were one of the compromised organizations, said it was hundreds. So and again, out of you know, 250,000 users, it it could be pretty comprehensive. Brandon: Mm-hmm. Right. 'Cause I I Avram Piltch: Do you think this makes them look good? Do you think this makes Huntress look good? JESSICA: I think it was admirable that they came out, especially as a security company, and said we were one of the companies who were victimized. So I think I think that's how any company should respond if if they're among the companies affected. And especially if you're a security firm, I think yes, you have an obligation to be transparent and tell your customers what happened. Brandon: Yeah, legally, right, in the United States at least. I mean you've you if you've got it you've got to report breaches, you've got to report these kinds of things to the government. There's all kinds of cybersecurity reporting standards in place. But they're there. ⁓ what kind of data was exposed, Jess? JESSICA: So it was a it was basically CRM data. So ⁓ it wasn't any of the company's you know, in internal IP or anything like that. It was a lot of CRM data and pretty much every single company involved. I mean, it was it was that across the board. They the organiz or not the organization, the cybercrime group behind this hack did leak the Huntress data ⁓ a few days later. And we've heard that they're actually deleting the stolen data from LastPass. It's that's what LastPass is saying. So we don't know ⁓ if this data is actually not going to exist anymore or if they're just handing it off for other attacks or two other organizations. ⁓ but yeah, it it involves CRM data. Brandon: So CRM data then we can assume, you know, customer data from the affected companies too. Yeah, not not of I'm assuming no financial information was exposed then or JESSICA: Ca right. Customers, leads, uhhuh, yeah. No, no no financial information. Brandon: Right. So Avram Piltch: So relatively not that bad ⁓ for Huntress's reputation when you think about JESSICA: No, it's no. It's like it's it's the it's Huntresses. They they actually specifically said it's our business contacts, price quotes, and other sales related data and messaging. And they said no, threat data, passwords, payment card information, or engineering data related to Huntress agent or telemetry are affected. And essenti ⁓ I was gonna say that's that's pretty that's pretty standard across the board. The companies who Brandon: What about ⁓ go ahead. JESSICA: did get more specific in their disclosures about what was taken, it it's basically this this business data, ⁓ leads, contacts, that type of thing. Brandon: What about ⁓ I know you said Last Pass was affected as well. But I thought I heard something about telling customers to reset passwords, so JESSICA: Mm-hmm. Right. Yes. Yes. So yeah, you you definitely always want to do that if you have a major password manager that's been compromised. ⁓ and and in this too, like they they immediately they they disconnected all these integrations. and again you wanna reset anything associated with your integrations if you're one of the customers too. Brandon: Yeah, for sure. But sh but like LastPass customers, like individual consumers of their password manager, don't necessarily need to be worried about this. Okay, that's that's good to know at least for for those people. ⁓ now again we talked about there's a new gang behind this, so Shiny Hunters is kind of the the one that has been really hitting Salesforce hard recently. ⁓ Sure, what's up? JESSICA: Right. ⁓ wait, I Wait, can we can we pause for a second? ⁓ I misspoke about LastPass. Yeah, so no, it cust it is customers it it's their personal information and case records. So Brandon: Okay, so there was some personal data that was involved for for LastPass. Okay. ⁓ yeah, let's back up to then when I asked about ⁓ JESSICA: Yes. Okay. Okay. Yeah, here's the yep, here's the blog. Brandon: about that. So okay, so give me a quick pause here so we can I got space to edit around. So ⁓ LastPass was it just ⁓ CRM records or were customer ⁓ you know, consumers of their password managers are there were they affected too? JESSICA: No, so that sorry, yes, last pass customers data was affected. It it was some of the sales related data, but also the intruders took customers' names, phone numbers, email addresses, and physical addresses, plus you got some case support data and then also sales related data. So Brandon: Right. So if you're a Last Pass customer basically, you might want to go in and reset that Master Vault password now. Yeah. So this didn't involve Shiny Hunters, from what I understand, who's kind of been the the de facto kings of Salesforce attacks recently. ⁓ they weren't involved, right? JESSICA: Big yes, yes, definitely. Right. No, they they weren't involved in that. I think it was what everybody assumed is that you've got Salesforce and you've got OF tokens and that just screams Shiny Hunters. They weren't involved. It was a new group called Icarus. They're a new data theft and extortion crew, and they're modeled in the the same mold here as Shiny Hunters and Scattered Spider. ⁓ and I even I I was wondering though, is Was is this just a front? ⁓ according to Shiny Hunters, no, they were not involved. They told me that they ⁓ were kind of bummed that this other group was able to do this. And if it had been them, they would have definitely publicized the fact that it was Shiny Hunters who did this. So right, no there. Brandon: Yeah, they're not exactly publicity shy. So and I I I love the fact that we've got an inside line to them too, that you can be like, Hey, was this you guys in any way? And they're like, No, no, we wish it was. ⁓ JESSICA: Yeah, yeah, I I think the actual response was we wish. Brandon: Yeah. Yeah, but so so not much is known about Icarus, right? Like at at all really. I think even you mentioned a couple of different coun ⁓ countries that their IPs might have been linked to, but those very well could have been Tor or VPN exit nodes too. So we don't even know where they're located at or anything. JESSICA: Right, right. Right. No, we we we don't really know much about them. Their their leak site has been active since late April. and ⁓ we've seen different IP addresses in Europe, but really don't know much about this group at all. Brandon: Mm-hmm. Yeah, and that's you know, these groups change and move so rapidly. I mean, who knows, right, who they are or or or what they're you know are they ransoming this data? Do we know? Like are they JESSICA: Mm-hmm. They yes, they were they were ransoming ⁓ and then leaking some of the data outright. Brandon: Okay, so that's standard MO for a lot of these groups. So so, you know, speaking of ⁓ we we talked a little bit about Huntress's ⁓ you know, kind of early identification of this. ⁓ and that kinda opened up a bit of a Pandora's box for them, it seems, because they had a ⁓ a Jilted X employee who decided that they ⁓ weren't too thrilled with with the response, ⁓ which you also wrote about, I understand, the the kind of problems this has created for for Huntress. So what what happened there? JESSICA: Mm-hmm. Right. Right. So after Huntress came out and and they said Huntress believes in radical transparency about security incidents, including when it affects our company. That was about the clue breach. They said that in their blog. A former security operations analyst ⁓ posted their response on his LinkedIn page along with a Pinocchio GIF. And that just kind of started this whole mess. Brandon: Mm-hmm. Yeah. JESSICA: He says that he was threatened by the company with legal actions. He made it very clear this has nothing to do with the clue incident. ⁓ He says this stems from an earlier incident that he found out about in December. And because of that incident, he resigned from the company. And so what he's alleging, ⁓ and again, this is all allegations at this point, is that another Huntress employee who still works for the company. Pass communications from US law enforcement to a cyber criminal. And now this cyber criminal, according to the the ex-employee, is actively targeting his family and him. And so he says that it's, you know, he he can no longer work at Huntress because of this. ⁓ he says in the next few weeks he's going to provide more proof, in including communications and phone calls. ⁓ about what happened here. And he says also that this alleged insider he says was caught by the FBI. I don't know if that means arrested. I don't know if that means questioned, ⁓ but still continues to work at Huntress. Brandon: Huh, and there's no I'm assuming there's no like DOJ notice of anything that ties to ⁓ an arrest or anything of ⁓ someone who could be involved. Yeah. ⁓ so what is Huntress had to say about this whole thing? JESSICA: Not at Hunters. No, not at Hunters. So the CEO responded to me, and he also responded on a Reddit post, and he says, you know, he acknowledges the concerns that are raised by this former employee. And he said that because of our work as researchers, sometimes we need to communicate with possible cyber criminals to gather intel that supports our partners and customers. and he says that he appreciates the former employees' concerns. ⁓ And he will, you know, continue to investigate the instance. he said a little bit more directly on Reddit that he doesn't understand and he firmly disagrees with these accusations and the whole insider narrative. ⁓ and there also the another thing too that the the former employee brought up is that Contras is prioritizing an IPO over the safety of its partners and customers and team members. ⁓ And he said that Sure AF isn't the case. So ⁓ he's made it very clear that that the company disagrees with all of these accusations ⁓ and they're continuing to work with law enforcement. He said some of the some of this involves legal proceedings, so they can't completely be public about everything that's going on. But it it sounds like it's a it's a continuing story. I think we're gonna learn more about this in the dates and weeks ahead. Brandon: Yeah. Yeah, it seems like, you know, if this if this ex employee has documents to prove his allegations, I mean that's pretty serious, right? Like obviously, yes, you do have to at a security firm interact with some of the people that you're defending against. But passing, you know, law enforcement communications to them, I mean, I don't really see a very good reason for that. JESSICA: Right. Mm-hmm. Right. No, that that's a Avram Piltch: Could this be a misunderstanding? Could this be a misunderstanding about what the employee was doing? Brandon: Was that? JESSICA: I mean it potentially could, but if he has these communications between law enforcement and the huntress employee, I don't know how that could be a misunderstanding. ⁓ it's it's one thing to talk with cyber criminals, ⁓ but it's a it's a whole nother thing to be passing them information about any legal proceedings or yeah. So Brandon: Yeah, potential operations and Yeah. Huh. Well, we'll see what comes of that, right? Yeah, it's gonna be interesting to kind of follow that thread. So, you know, these two stories aside, it seems like we've got a really ⁓ a busy w what usually is a lull, right? It's been a pretty busy cybersecurity summer so far. I think Jesse were talking about that with someone, right? JESSICA: We'll see. Right. Mm-hmm. ⁓ right, one of my sources. I mean, normally everything slows down in the summer. And I was talking to the source and they said, Yeah, we're we're already calling it the summer of hell. And I feel like for all the security folks out there, that's that's pretty accurate. And I think a lot of that has to do with AI, to be perfectly honest. Brandon: Yeah, right. I mean what, Squidbleed? You wrote about that recently. It was ⁓ a mythos discovered vulnerability that was old and potentially serious, right? I mean JESSICA: Mm-hmm. Right. Right, right. Definitely potentially. I it's it's been around since 1997. It was discovered by Mythos, but then it was also discovered even before then by ⁓ IL Security. It's a it's a European startup, and they have their own model that they said also found this before Mythos did. ⁓ and so yeah, you've got this 29 year old vulnerability. It's existed since 1997. It's in Squid, which is this open source web proxy server. it's a it's a parsing bug bug parsing bug and it essentially allows users to access the proxy's active memory. There's a couple key points here. You it's it's only unencrypt unencrypted traffic. So it's just clear text, HTTP HTTP, and it also requires that Squid has the file transfer protocol, FTP server gateway features turned on. So you kind of have to be using this older vintage technology and protocols here. ⁓ FDP's pretty outdated at this point. But it's it's kind of Brandon: So, you know, it's yeah, it's it's a vulnerability, but maybe not a serious one. Still JESSICA: It's it's it's serious if if these two conditions are met. Then it's serious. Cause then yeah, you can it's gonna expose your password, session tokens, API keys. So Brandon: Right. Right. We Yeah, I would say I would say hopefully there's not too many environments where this is the case, but we know from from writing about stories like this that every time you say, ⁓ no, no, this is a very rare case on old software, you can easily go out there and JESSICA: Right. Right. Avram Piltch: If you're still if you're still using FTP and HTTP on your servers, then you're kind of you know, you're letting yourself in for a big security problem. So that probably isn't your only problem. JESSICA: Ha ha Brandon: Yeah. Yeah, you don't wanna say asking for it, but ⁓ yeah. So it basically it's like it's it's interesting to think about like, well, yeah, AI might be discovering these and other problems. I mean, we've seen multiple open source projects basically shut down bug reports because they're getting flooded with AI discovered issues, some of which are completely legitimate. But I mean, yeah, it it feels like this is kind of like the summer of ⁓ of AI and cybersecurity convergence, right? Mythos Mythos getting shut down. The Trump administration is now harringing JESSICA: Mm-hmm. Mm-hmm. Mm-hmm. Brandon: open AI just as much as they've been kind of putting pressure on Anthropic to not go public with with models that could be a threat. I mean it feels like a big moment, right, for cybersecurity and a lot of it's being driven, like everything, by AI. I mean, what do you guys think about the current moment of this kind of pairing? JESSICA: Right. Yeah, it's kind of a it's kind of a perfect storm because you have these models that are really, really good at finding vulnerabilities and developing exploits. And that's leading to a bunch of work internally with security companies finding finding their own own bugs and pushing out patches that then you have all the sysadmins needing to work extra hard on that. Plus open source, which is a huge issue here. You have all of these bug hunters. looking for and finding all kinds of vulnerabilities on open source projects and they push those to maintainers who a lot of times are volunteers themselves and they're not getting paid and there's maybe one of them for this huge project. And they have this huge backlog too of AI enabled threat reports that that they need to deal with. So it's it's just coming at people I feel like Brandon: Mm-hmm. JESSICA: from all ends here and yeah, a lot of that's because of the AI models. Brandon: I mean, is is NIST still backed up with the national vulnerability database? I haven't even checked on that recently. But last I heard they were some months behind. And that's even you know, yeah. So like not only that, but right, we've got a lot of big threats out there that might just not be being made public because they're buried too. It's quite the mess. JESSICA: They ⁓ yeah. They are I Brandon: So before we wrap up, I did wanna touch on, like, you know, like you mentioned, Jess, and and we've seen this in a number of stories that Avram's written recently for the Pwned Column. you know, at the end of the day, right, yes, AI is creating a headache for a lot of people, but pe there's still a group of people that are stuck dealing with this and it's sysadmins, right? It's the security professional, it's the sysadmins, you know, and and human human problems can still be kind of the root of this. Avram, you wrote Like there was a number of stories in your Pwn column that it was it was like all these problems, these security problems come back to bad password hygiene, you know, administrator laziness. I mean, what are some of the things you've kind of seen? Hubris. Avram Piltch: Hubris. Hubris. There you know, there's a JESSICA: Mm-hmm. Avram Piltch: CEO that wanted to make sure that he could get in and change anybody in the company's email. Now, we could talk about whether or not that's a good policy in the first place, but his method of doing it was to have an Excel file on his desktop with all of the usernames and passwords of all the employees so that if he sent out an email that he shouldn't have sent out and he wanted to delete it, he could go into all the employees' ⁓ inboxes and delete. Brandon: Mm-hmm. JESSICA: Yeah. Avram Piltch: It or but conversely that was a wonderful target for people outside the company to find all the names and passwords that they needed, even though there's software out there that will just allow an admin to go into somebody's inbox anyway, so this was completely unnecessary, right? But things like that are constantly happening. Or we had another incident where somebody hadn't deleted a former employee's Brandon: Right. Avram Piltch: username and password and perhaps their password was in a breach somewhere or somebody guessed it. But ⁓ Greg from auditing who hadn't worked there in like ten years, somebody used his credentials to break into a city's water system and start trying to burn off like things having to do with the water supply. So All these things, the best AI in the world isn't needed to find them and couldn't be used to prevent them. Because it's a h the human element is still I think the biggest problem in security. The biggest problem in security is is people, right? Now maybe AI maybe when I have my agent talk to your agent, they will be much better behave than when people get involved. But ⁓ you know, news flash JESSICA: Mm-hmm. Avram Piltch: ⁓ coming up in a future pond, I talked to a red teamer who said that he's basically able to break into almost any facility by acting like he belongs there. Brandon: Yeah, that's a classic trick, right? I mean, it it kind of is the same thing I've I've said for a long time about security. It's like you've got new tricks that come up. You've got new things like AI, but it's there's nothing new under the sun at the end of the day. The best way to get this stuff, you know, best way to gain access to a system isn't to, you know, swordfish your way in a la Hugh Jackman, right? It's you know, it's it's it's it's a con. It's it's lying, it's putting on a reflective vest and having a clipboard. JESSICA: Yeah. Mm-hmm. Brandon: It's ⁓ relying on password breaches and people being bad about their password how you I mean, that's what happened with the clue issue, right? I it was basically, you know, ⁓ an old password that was in a breach somewhere that someone used to get into this system. Nothing new under the sun. JESSICA: Mm-hmm. Yeah, we see that all the time. Avram Piltch: Yeah. Brandon: Yep. And it's probably gonna keep being that way, and I bet we are probably going to be talking about it on the kettle for months and years to come. Yeah, yeah, inevitably, if invariably, until AI fully takes over the computer world and we're all just sitting in our WALL-E couches zooming along and being, you know, perpetually entertained by all these sentient machines. But until then, we will be here on the kettle to talk about these things. Thanks for joining me guys, and we will see you all again soon. JESSICA: Year I was yeah, I was gonna say years. Yeah. Bye.