HOSTED BY CODY Threat Aware // PRIVILEGE ESCALATION // EP01

Half a Second From Disaster

In the inaugural episode of Privilege Escalation, Galactic's Director of Security Research, Cody Kretsinger, details a backdoor that came within days of reaching nearly every Linux computer on earth. One engineer caught it by accident, when he noticed his logins were half a second slow. The attacker spent three years volunteering on the project, earning the trust he needed to plant the backdoor.

WATCH / LISTEN

One attack, told properly. Each episode takes a single breach or backdoor apart: how it was built, who caught it, and what almost happened instead. Part of Galactic's Threat Aware.

Transcript

Auto-generated transcript, apologies for any errors. Download as text

Cold open

For almost three years, this guy was the best thing that ever happened to the project. He was reliable, did the boring work that nobody else wanted, fixed the bugs, answered emails, and took a load off a maintainer who was drowning. If you were that maintainer, he was a gift. Then in February 2024, that gift shipped a backdoor into software that runs underneath a huge chunk of the internet. The kind of access where you log into machines anywhere on the planet like you own them. And we didn't catch it because we were good. We caught it because one engineer at Microsoft was chasing a totally unrelated slowdown.

He noticed his logins were running about half a second, yes, half a second slow, and got annoyed enough to really dig in. Half a second. That's The whole time, the whole margin. That's the difference between a normal day of the week and the worst thing that could have ever happened to us.

Narrator

This is Privilege Escalation. Part of the Threat Aware Podcast Network. Incidents get reported. They rarely get explained. Each episode takes one attack apart from the inside, delivered with a perspective of someone who has spent time on both sides of an attack. How they got in, and how you stopped them. Here's your host, Cody Kretsinger.