LIVE · cybersecurity feed
Live wire
security

Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack?

Polymarket has built an entire business on predicting the future. So how did it manage to spectacularly fail to predict its own hack? Plus, the Google engineer with a million-dollar secret, and the curious case of the airport hairdryer. Mea

zeroday.news · 30d ago

A decentralized prediction market platform, Polymarket, recently experienced a security incident, highlighting a significant failure to anticipate its own vulnerability despite its business model revolving around predicting future events. This incident was discussed on the Smashing Security podcast, episode 474, featuring cybersecurity expert Graham Cluley and special guest Quentyn Taylor, who heads information security, product security, and global response at Canon.

Polymarket's core function is to allow users to bet on the outcomes of future events, ranging from political elections to cryptocurrency prices. The irony of such a company falling victim to a hack, thereby failing to predict its own security breach, was a central point of discussion. Cluley drew a parallel to an astrologer's convention being canceled due to unforeseen weather, emphasizing the embarrassment of a prediction-based entity being blindsided.

The podcast also touched upon another significant security issue: FortiBleed, which has reportedly left approximately 75,000 Fortinet firewall devices vulnerable. This vulnerability is described as having the potential for widespread and long-lasting damage. While the specifics of the FortiBleed exploit were not detailed in the provided material, its scale suggests a broad impact on organizations relying on Fortinet's security appliances.

Quentyn Taylor shared insights into his role at Canon, where he oversees information security, product security, and global response. He noted the unique integration of these functions within his department, suggesting it could be a model for future cybersecurity team structures. Taylor explained the benefit of having product security and cybersecurity under one umbrella, allowing his team to not only secure Canon's own products, such as printers, cameras, and CCTV systems, but also to provide customers with practical, internally tested hardening guides. This approach ensures that security recommendations are based on real-world application and internal defense strategies.

Taylor elaborated on how this integrated approach fosters a feedback loop between security and product development. Previously ad hoc, this process is now formalized, enabling his team to influence product design by identifying and advocating for security improvements, such as making ubiquitous encryption a default feature on devices and restricting access to potentially exploitable functionalities.

The discussion also briefly mentioned other cybersecurity news items that were *not* covered in depth on the podcast, including a Danish privacy activist doxxing his prime minister, a UK hospital reporting unauthorized access to a child's medical records, and an attacker named Snoopy being imprisoned for hacking a fantasy sports betting website.

The podcast episode was sponsored by several companies, including CoreView, Proton, LastPass, and Vanta. Proton Pass, a password manager from the creators of ProtonMail, was highlighted for its end-to-end encryption, open-source nature, Swiss jurisdiction, and nonprofit backing, positioning it as a secure solution for businesses to manage and share credentials, particularly in light of common insecure practices like using spreadsheets or Post-it notes. The service is noted for its adherence to compliance standards like NIS 2 and DORA.

ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.

vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]