CyberWire Daily

Managing machine learning risks. [Research Saturday]

Jun 17, 2023 · 18 min · Season 7 · Episode 286Bonus
0:00-18:34

Streams straight from the publisher. podnod never proxies or re-hosts episode audio.

Our guest, Johannes Ullrich from SANS Institute, joins Dave to discuss their research on "Machine Learning Risks: Attacks Against Apache NiFi." Using their honeypot network, researchers were able to collect some interesting data about a threat actor who is currently going after exposed Apache NiFi servers.

Researchers state “On May 19th, our distributed sensor network detected a notable spike in requests for ‘/nifi.’” Investigating further, they instructed a subset of their sensors to forward requests to an actual Apache NiFi instance and within a couple of hours the honeypot was completely compromised.

The research can be found here: