meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, April 28th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 28 April 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Veeam Vuln Ransomware; Google Authenticator Sync; Keycloak Vuln;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Friday, April 28, 2020, 3 edition of the Sands and its Stormtunters Stormcast.

0:08.9

My name is Johannes Ulrich.

0:10.6

And today I'm recording from Jacksonville, Florida.

0:13.5

Just got back home earlier today.

0:17.6

Yesterday's episode was a lot about RSA, so want to step back a little bit and try to cover some of the things that we may have missed yesterday.

0:26.4

First story actually brought back memories of RSA like a couple of years ago when I talked about vulnerabilities in backup systems.

0:35.9

That has come up occasionally. The latest instance is a vulnerability

0:41.3

in VIM backup that I did mention actually in March when it came out. There was a proof of

0:47.8

concept exploit. It was made public later in March, I think around the 20th, and now we do have ransomware being deployed

0:57.3

using this vulnerability. The vulnerability in question here is CVE 2023, 27532, and again, a patch

1:07.5

was made available March 7th. The CVSS score of this vulnerability is 7.5.

1:15.4

With secure attributes, these attacks to the Fin 7 group has been around for quite a while and

1:21.6

has sort of been in the ransomware business, in particular targeting enterprises and using whatever sort of the vulnerability of

1:30.1

the day is.

1:31.4

To quickly check if you may be vulnerable, do a quick port scan on port 9,401.

1:37.3

This is where the meme backup service listens.

1:41.6

It is exposed via SSL, but definitely should not be exposed to the internet.

1:50.3

I may have mentioned in a recent podcast that Google Authenticator now supports

1:55.8

syncing of the embedded secrets across different devices using Google accounts.

2:02.4

This was sort of one of the big shortcomings of Google Authenticator for quite a while

2:06.6

because whenever you got a new device, you had to essentially transfer, sort of re-register

2:12.7

all of these secrets with the respective websites, which was quite cumbersome and a lot of competitors

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.