Listen to this episode

Can Hackers Turn Your Xbox Against You?

0:0043:05

Recorded March 2022. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

Craig, Erin, Blake, and BJ of Petronella Technology Group open with Microsoft's March 2022 Patch Tuesday, which plugged at least 70 security flaws, including the first Xbox bug. Craig explains how compromised consoles could be enslaved in botnets and aimed at a single target in distributed denial of service attacks, noting bad actors also use them for extortion.

He says managed SOC monitoring and services like CloudFlare help detect such attacks, and that Xbox owners are largely at the mercy of Microsoft for patches, with reboots breaking botnet connections. The conversation widens to inflation at a 40-year high at the time of recording, cost pressures on small businesses, and the reported possibility that Elon Musk could disable Teslas remotely, which Craig finds alarming. Craig recalls Stuxnet, nation-state malware he says caused the first human casualties, while BJ describes a rare reverse tunnel technique not yet linked to any group, cites ransomware intelligence on persistence and lateral movement, and argues AI may ultimately balance these dangers. The episode closes with crypto regulation, leverage trading restrictions in force at the time of recording, and Bitcoin's resilience.

Worth remembering

Key takeaways

  1. Craig warns that attackers treat each month's Microsoft patches as a roadmap for exploiting the flaws, making slow-patching networks, like medical systems, especially exposed.
    “and yet we know from experience that attackers are already trying to work out how to turn these patches into a roadmap for exploiting the flaws they fix.”
  2. Craig explains that large numbers of compromised Xboxes could be enlisted as bots to flood one target with traffic and knock it offline.
    “So if a bunch of X-Box is, are compromised, they could use them as slaves to launch a distributed denial of service attack.”
  3. Craig says watching where a device's traffic comes from, and spotting huge masses of traffic, is how a SOC detects a machine turned into a bot.
    “You have to monitor the device to see the traffic where the traffic's coming from. And if you see a huge mass of traffic then you know, what's happening”
  4. Craig advises rebooting after patching and rechecking for updates until none remain, because each reboot breaks the connection between an infected device and a botnet.
    “Usually after you patch something like that, you reboot and then you check for updates again. And then if there's any more updates you reboot again, until it says there's no more updates available.”
  5. BJ cites ransomware intelligence reporting that 82 percent of infections gain persistence through scheduled tasks and 82 percent of attacks perform lateral movement.
    “82% of infections. Gained a persistence through scheduled tasks. And startup code at execution. So they're using automated tasks to gain persistence and then 82%. Of ransomware attacks. Performed lateral movement.”
  6. BJ argues that new technologies like electric vehicles and global satellite internet become one big danger zone if cybersecurity is not secured first.
    “if cybersecurity is not secure first, then all of that is just one big danger zone.”
  7. BJ argues that because exchanges can be regulated so quickly, keeping crypto where it cannot be touched means a hardware device that is offline.
    “there's only a few safe ways to, have your crypto where it can't be touched and that would be on a hardware device that's offline.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

An exploit found on Microsoft's Patch Tuesday had us wondering... Could hackers turn your Xbox against you? And if so, would we ever know?

Host: Craig Guests: Erin, BJ and Blake

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.