Ep6: After CrowdStrike chaos, should Microsoft kick EDR agents out of Windows kernel?
Description
Three Buddy Problem - Episode 6: As the dust settles on the CrowdStrike incident that blue-screened 8.5 million Windows computers worldwide, we dig into CrowdStrike’s preliminary incident report, the lack of transparency in the update process and the need for more robust testing and validation. We also discuss Microsoft's responsibility to avoid infinite BSOD loops, risks of deploying EDR agents on critical systems, and how an EU settlement is being blamed for EDR vendors having access to the Windows kernel.
Other topics on the show include Mandiant's attribution capabilities, North Korea’s gov-backed hacking teams launching ransomware on hospitals, KnowBe4 hiring a fake North Korean IT worker, and new developments in the NSO Group surveillance-ware lawsuit.
Hosts: Costin Raiu (Art of Noh), Juan Andres Guerrero-Saade (SentinelLabs), Ryan Naraine (SecurityWeek)
Links:
Episode transcript (Unedited, AI-generated)Official CrowdStrike preliminary post-mortemMicrosoft VP David Weston on CrowdStrike outageMicrosoft VP John Cable on the path forwardMatt Suiche: Bob and Alice in Kernel-landRe-learning Lessons from the CrowdStrike OutageEp5: CrowdStrike's faulty updateMandiant Report on North Korea's APT45CISA Advisory on North Korea APT45KnowBe4 Hires North Korean Fake IT WorkerIsrael’s attempt to sway NSO/WhatsApp spyware case
Three Buddy Problem - Episode 22: We discuss Volexity’s presentation on Russian APT operators hacking Wi-Fi networks in “nearest neighbor attacks,” the Chinese surveillance state and its impact on global security, the NSA's strange call for better data sharing on Salt Typhoon intrusions, and the...
Published 11/22/24
Three Buddy Problem - Episode 21: We dig into an incredible government report on Iranian hacking group Emennet Pasargad and tradecraft during the Israel/Hamas war, why Predatory Sparrow could have been aimed at deterrence in cyber, and the FBI/CISA public confirmation of the mysterious Salt...
Published 11/15/24