Trends in Threat Research and Vulnerabilities with Bharat Jogi | Qualys QSC 2023
Bharat Jogi, director of security and threat research at Qualys, talks about Looney Tunables & trends in threat research and vulnerabilities Qualys has been seeing.
Transcript
This is Textron tv. All right, welcome back to the Qualys Security Conference for the Americas. I'm here with Barat Yogi, who is a researcher for Qualys, and we're gonna be talking about Loony Tunables.
And right now, everybody's gone. What the heck did he just say? So please explain what Looney Tunables are.
Yeah. So Looney Tunes is a, uh, privilege escalation, vulnerability that my team, my, uh, team discovered. It affects all the major Linux, uh, uh, distributions.
Uh, what it basically does is it allows an attacker with least privileges to exploit the vulnerability and get super rude privileges on the Linux asset. Uh, the interesting thing about Lunes vulnerability is it affects all popular distributions. So the attack surface, it's pretty huge.
And, um, it's so trivial to exploit. You won't believe like the, like we, once we, you know, made the disclosure, uh, within less than 24 hours, we saw researchers dropping proof of concept exploit for the, uh, exploit for it in less than 24 hours. So, you know, really critical vulnerability, giving it attackers admin privileges and, you know, trivial to exploit.
It's a toxic combo. And the fix for this is, Um, so fixes for this vulnerabilities are out already. Uh, you basically, you know, update your GDC to a specific version.
You don't have to do anything else other than that. Uh, but the vulnerability, you know, it's real to patch. It's not too difficult to patch, but just because, you know, it affects like a large fleet of your environment, you know, organizations need to prioritize it and, you know, quickly update that.
I've yet to see the trivial patch. I've heard about it, its existence, but I'm not so sure that anybody believes that it will be there. And I'll wager that we will have tax against this vulnerability nine months from now, because somebody will have not done something.
Mm-Hmm. As a matter of fact, as of early this week, there is a threat actor who is exploiting uni tools, vulnerability to on, and especially the cloud infrastructure to deploy crypto, uh, miners. So exploit for this already out.
The threat actor goes by the name kinin, and it is using this for their malware, uh, techniques, uh, taking, I mean, uh, exploiting the vulnerability for deploying crypto miners, uh, credential, uh, uh, hijacking, et cetera. Right? A lot of folks don't take, uh, crypto mining seriously 'cause they think it's a nuisance crime, but essentially that's the gateway that people start using for more serious exploits later, right?
Yeah. In cloud environment, this, especially what we are observing in, in the wild is more and more crypto mining, uh, athletics are deploying crypto miners to, so basically they're consuming your resources to benefit them. Mm-Hmm.
So basically they use your resources mind, crypto, make money out of it. This is, I believe, when we are looking at the cloud threat landscape, this is one of the, you know, like the top problems that we see that is in, in the cloud environment today. There was a stat tossed out earlier today, I think, that said that only 3% of vulnerabilities have been actually exploited.
And, but now we're making it easier to find these things as we go along. So how many exploits do you think they're gonna be in the future? And how much, how many vulnerabilities will there be poked at?
So overall, in the past years, and I think the trend to be continuing is we'll see a large number of CVSs. You know, as organizations become more mature, as vendors have more, uh, resources to find vulnerabilities, organizations taking cybersecurity as their, you know, top level, uh, uh, to things that they need to consider. What is going to happen is, like, what I believe is overall there will be a large number of CVEs, but the vulnerabilities that post a significant threat, that percentage would be low.
I would expect anywhere between three to 7% or so. So these are the vulnerabilities that pose maximum risk and should be prioritized whenever you are considering de patching, you know, which vulnerabilities to patch, so on and so forth. I think you kind of have hit at the heart of the problem, and I think we talked about it with the risk assessment stuff that you guys have come out with, but it seems like we have a massive number of these vulnerabilities, but not all these vulnerabilities are actually exploitable in a particular IT environment, but we don't seem to know which ones they are.
And so what is best practice these days for managing vulnerabilities? That's a really great question. Um, all vulnerabilities, like I believe are not created equal, even though the technical severity of vulnerability may look like the same, that, hey, this is a, you know, remote code execution should be prioritized.
But overall, if you look at, especially if you are relying, if an organization is relying on CVSs for patching or prioritizing what one is need to patch more or less, every other CV that gets released falls into this high or critical scoring. So that's too much. You know, as we, as we look at, you know, already there are 20, close to 25,000 CVEs that are released this year, and we are not in the end of the year yet.
So overall, uh, if let's say, you know, 50% of vulnerabilities or every other vulnerability that comes out is high or critical, it is too much of an effort for an organization to patch. What we need is identify the small set of critical vulnerabilities that really pro significant risk to your organization based on, you know, the threat feeds that we consume. Like if the vulnerability has an exploit, is it actively being exploited or it's just a proof of concept is available?
If there is a, it is a part of csaw cab, is it a ransomware associated with those vulnerabilities? These are the vulnerabilities that organizations need to take and have a process where these vulnerabilities are getting passed sooner than they're, they're like one of the, like when we were looking at all the vulnerabilities that have a patch, you know, and increasingly, as I ex also mentioned about the Looney tune vulnerability, once we release the vulnerability, just imagine 24 hours after this was disclosed, there are several proof of concept already available. Any attacker in any threat actor can take this readily available proof of concept and just turn them into an active export.
Mm-Hmm. So organizations really need to focus on this, a small subset of vulnerability that pose significant risk, but ensure for those vulnerabilities, they have a really good patching process. Uh, like you look at the, the time to exploit or creative exploit.
Once the vulnerability is out, it's now nine days. Just a few years ago, this was around a hundred days plus. So attackers are constantly bringing down the time to exploit is constantly decreasing, and organizations need to keep up with this.
Otherwise they'll be keep falling behind. And attackers would have like, you know, a huge window from the time that the vulnerability is released to attack, you know, the vulnerable systems. And thanks to the wonders of AI that might be nine minutes someday soon.
Right. I'm, I'm sure I, I, I have a feeling that going forward there would be, there, there is a, there would be a large, uh, you know, a portion of vulnerabilities or exploits that will be leveraging AI to, to, you know, speed, like increase, like, you know, speed up the process of exploitation. Right.
I'll throw the exploit in a vector database, show it to the LLM, and away we go. Right. Yeah.
All right. Um, what other tactics and techniques are changing out there? 'cause I think that my sense of it, at least with the attackers is there's not a lot of like totally net new stuff.
They're more inclined to just tweak stuff as they go along, but each time they tweak something, it becomes a little, little more evasive. Yeah. How do we keep track of that cycle of events and, and 'cause it seems like every day there's something new, but it's only a little bit new.
Yeah. So obviously every day there's something new, but a large portion of, you know, breaches that happen, they do not like happen because of, you know, completely novel vulnerabilities or completely novel techniques. These are happening because of, you know, like basic, you know, you might have like a good coverage or maybe a very solid, uh, you know, patching cycle.
But what about, you know, some very basic misconfiguration, like a large number of vulnerabilities that, you know, ransomware exploits are basic misconfigurations, you know, RDP open s three buckets that are open. So while, you know, there are a lot of breaches that happen, not every, like, even just, uh, when, earlier this year when Csaw announced like the top routinely exploited vulnerabilities, these are not the latest vulnerabilities. These are vulnerabilities that had patches for over years.
Mm-Hmm. So I think that basic hygiene is missing, which is, you know, the, uh, now obviously there is a component of, uh, nation state actors, which are, you know, developing nowhere zero days, but a large number of breaches that happen, they do not happen because of zero days. They happened because of, you know, basic mix on, uh, basic cybersecurity hygiene that were not followed up.
And I think that is what the, uh, you know, Seesaw and the Biden administration is trying to do with the directive, binding directive of reducing the risk of known vulnerability, of exploitation of those normal vulnerabilities. A lot of times you'll see research come out and they'll say, you know, we've identified this exploit. And then you look into it and, you know, it can be used on the second Tuesday of a month for about an hour or something.
And it's very narrow window thing. Do you think the bad guys are kind of laughing at us? 'cause they're like, why would I go to so much trouble?
I'm just gonna use some of this easy stuff and I'm not gonna work that hard. Yeah. So exactly.
You know, looking at, you know, from, again, from the example of the Loony tunes, exploits proof of concept gets released, and the attacker, you know, it's not going to wait on to say, Hey, you know, let me find a zero day and then try to export this organization. There are already readily available proof of concepts, they're just gonna take it off the shelf, you know, may customize it a bit to, you know, start there in in start using that in their operations. Do we need to be more thoughtful about how we disclose these things?
Because it seems like sometimes, uh, a lot of people are caught unaware. They're not just sitting there waiting for the next new update, and then the next thing you know, they hear about it on the internet and they're like, oh my God. And they might not hear about it at all.
So, um, is there a smarter way to think about the whole disclosure process? Um, I think with terms of vulnerability disclosure, at least for vulnerabilities, I think we, the, the industry is, you know, the organization are quite mature, I would say, than what we were like a few years ago. Probably 90 days is sort of now a defecto standard in terms of, you know, responsible disclosure.
Like we engage with, uh, whenever my team finds a new vulnerability and zero date, we engage with the, uh, you know, the vendor or, uh, with the vendor. And 90 days is what we recommend. And in our experience, 90 days is something that is good enough time for a vendor to fix the vulnerability and also to make the reasonable disclosures around it.
Mm-Hmm. So I think in terms of that, we have come a long way where, you know, like the number of zero days that were, you know, just dropped by a security researcher, uh, has gone down. However, I think, um, there is, there is a fine balance, you know, like, and what, what can we shared?
And I think one of the trends that I would like to see, uh, you know, in with, you know, coming days is, you know, that the, that there is a fine balance and it the, whenever, if a, uh, a security research is dropping a proof of concept, you know, it gives not, it's, it's in a form which is a bit neutered so that, you know, it cannot be taken out of shelf, just off the shelf. And, you know, can be, can be, can be used by a threat actor to, you know, expert vulnerability. There's also a good chance that somebody maybe working for a nation state has already discovered this thing.
And so when we say discover, we're discovering it in the same way Columbus discovered America. There's still a lot of people there already. Yes.
Yes, absolutely. Uh, yes, that is definitely the case. Uh, but I think overall I see the things are moving in the right direction, you know, in the, the, even the, uh, vendors who are trying to fix this vulner already, they are more upfront as to what they are fixing.
They are constantly, you know, look at Microsoft, I think I kudos to them. They have, you know, I've streamlined this process, you know, organized past Tuesdays. They have given industry a sort of consistency, some sort of, you know, work that the, uh, that organization can, I, I know many organizations what they do is they deploy more resources the day after patch Tuesday, so that they ensure that, you know, their organization are patched quickly.
So I think having that sense of predictability is helping the organi, uh, helping, helping the industry. What does it take to be a cybersecurity researcher these days? I mean, what are you looking for?
What are the attributes? So in terms of, uh, that's a pretty good question. You know, like, and I, I constantly look for the right talent to be a part of our college global security research team.
And to be honest, when, you know, when I started this, we did not have a lot of, uh, resources online. There were not a lot of, uh, training institutes, only a handful of them out there. Uh, from that point to what I see today, there are like ample of, uh, you know, training free courses, et cetera, that are available to anyone who wants to, you know, get into the cybersecurity industry.
There are like ample of courses available in Udacity. There are many organizations that give out free cybersecurity courses. So I think there is a lot of, from like, from few, several years ago to the point that we are today, there's a lot of content that is out there that anyone who wants to get into the industry that they can consume, but at the same time, cybersecurity, I feel it's still a, it's sort of an art, right?
When you do like a pen test, et cetera. You know, just because one organization was not able to find any vulnerabilities, that does not mean your entire app or your organization is secure. You know, there will always be some smarter people out there.
And this is a constant game where, you know, we, we, that, you know, keeps evolving. So we need to be on top of that to understand what is going on, take that feedback, you know, improve, learn from them, and, you know, constantly move forward. Mm-Hmm.
So that's, that's one thing which I love about cybersecurity is, you know, it always keeps you challenged. It always, there's always some new threat actor out there. There's always a new vulnerability.
There is always something that you, you know, you, you have to be on top of your game in order to keep it, keep your organization secure. Some countries like North Korea are lining up the 11 year olds to figure out who's gonna be a hacker. So Yeah.
Do we need to kinda have a similar thing for the defenders and, you know, looking for researchers? Yeah, I, I think, you know, not to that extreme level of when, you know, putting everyone from 10, 11, 11, 11 years old into this, but, but ensuring that, you know, organizations are taking cybersecurity more a proactive approach to cybersecurity when we are dealing, you know, like cybersecurity is not something that is thought as a after afterthought, right? You make security built in as a part of your development cycle, your QA cycle, your deployment cycle, because, you know, attackers are getting more and more sophisticated supply chain attacks might be aware.
And, and we need to be on top of this to, you know, uh, ensure that the, our systems are more robust than ever. When you discover vulnerability and you go to share that with somebody, how do they typically react? Um, so I have had, you know, different experiences, uh, but overall, whenever we discover vulnerabilities, and my team basically focuses primarily on, uh, targets which have a wider impact, typically open source, Linux kernel, so on and so forth.
And our experience has been phenomenal. Like kudos to, you know, rad hat team, the Linux distributions, they have been phenomenal. They, they have, and it is always been in our experience, like a two way street.
It's not just that, you know, we find something, we just drop it on them and you know, they take care of it. It's always a two way street. We'll find, share our findings, they will have some questions, they will share their patches.
Sometimes we have helped them build patches. So overall, it has been a very wonderful experience in most cases. Mm-Hmm.
Uh, So ultimately, you've been at this a while. You've seen both sides. What's your best advice to the security teams out there and the IT teams that work with them?
What should they be focused on? And you know, kind of what makes you shake your head a little bit these days and go, guys, we can be better than this. Yeah, yeah, Yeah.
Certainly. I think, I think to a lot of times when you, I talk with organizations and defenders especially, they feel, they feel a bit overwhelmed because, you know, there's a constant inflow, vulnerabilities are not going to stop. They constantly keep coming in.
Um, the defenders have limited resources, and I, I think, you know, they, they, they need the right set of tooling, not siloed tools. We need the right set of tooling. They, we where we, they can, you know, prioritize things better.
And more importantly, like I personally believe patching is the, is the only way, like once there is a exploitable vulnerability, and until I have patched that I won't be very comfortable. So having this automated process of patching vulnerabilities or reducing your risk is the need of the arm, constant inflow of vulnerabilities. It's not going to stop.
And if you have manual processes around dealing with, you know, this constant inflow of vulnerability and patching and you dealing with, you know, multiple teams to get one thing patched that is not scalable, you need to automate, you need to be better, you know, identify things that are, uh, real risk and find a automated way of reducing those risk is what something that is needed. All right, folks, they say sunshine is the best disinfectant and fact of the matter is, the only thing worse than a vulnerability is the one you don't know about. So thanks for coming by.
Thank you very much, Mike. Thanks for having me here.





