Defensive Security Podcast Episode 320

 
Links to stories:

https://securityaffairs.com/181430/security/after-sharepoint-attacks-microsoft-stops-sharing-poc-exploit-code-with-china.html

https://www.cybersecuritydive.com/news/software-vulnerabilities-breaches-checkmarx-report/75779…

Czech cyber agency NUKIB flags Chinese espionage risks to critical infrastructure

Czech cybersecurity agency NUKIB warns of Chinese cyber threats to critical infrastructure, citing the cyberespionage group APT31 and risky devices. The Czech Republic’s National Cyber and Information Security Agency (NUKIB) warns of growing risks from Chinese-linked technologies in critical sectors like energy, healthcare, transport, and government. The agency warns of risks from Chinese-made devices (phones, […]

MeetC2 – A serverless C2 framework that leverages Google Calendar APIs as a communication channel

MeetC2 is a PoC C2 tool using Google Calendar to mimic cloud abuse, helping teams test detection, logging, and response. Background: Modern adversaries increasingly hide command-and-control (C2) traffic inside cloud services. We built this proof of concept (PoC) to study and demonstrate those techniques in a controlled way, emulating those tactics so red and blue teams […]

China to Ban Hidden Car Door Handles by 2027

Chinese automotive journalists are discussing a potential 2027 ban on defective door handle designs due to high failure rates. 但是,不管是哪一种全隐藏式门把手其便利性和安全性都不如传统的门把手。根据媒体报道,有SAE论文数据显示,隐藏式门把手对轿车风阻系数改善仅0.005-0.01Cd,远低于车企宣称的0.03Cd。而在成本上,单个电子门把手成本是机械式的3倍,但故障率却是…