ISC StormCast for Friday, August 13th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 13 August 2021
⏱️ 3 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, August 13th, 2021 edition of the Sandcent Storm Center's Stormcast. My name is Johannes Ulrich. |
| 0:09.9 | And today I'm recording from a parking lot close to Sevalde, Germany. Due to limited internet access, today's podcast will be a little bit short. |
| 0:21.9 | Well, it looks like we are not going to wake up from Brent Nightmare anytime soon. |
| 0:27.9 | Microsoft published yet another advisory related to Brent Spoor vulnerabilities, |
| 0:34.7 | even though the impact isn't quite clear and a little bit disputed. According to |
| 0:40.0 | the advisor, at least as originally released, this does indicate remote code execution |
| 0:48.9 | vulnerability, but apparently according to others like Will Dorman, who is usually right about these things, |
| 0:55.6 | this may be sort of a copy-paste mistake, and it's really only a local privilege escalation |
| 1:00.7 | vulnerability. This one is a little bit different than some of the prior vulnerabilities. The prior |
| 1:06.9 | vulnerabilities relied on the attacker, installing a malicious printer driver on the print server. |
| 1:12.8 | In this case, a victim would be a client connecting to a malicious print server, |
| 1:18.6 | that print server would then copy the malicious code to the client and execute it with system privileges. |
| 1:26.8 | Proof-of-concept code has already been made available. |
| 1:32.5 | And according to Crowdstrike and others, print nightmare, at least the prior vulnerabilities |
| 1:37.5 | that were patched, well, back in June, July, and August are already being used by |
| 1:43.4 | ransomware gangs. No real surprise here, |
| 1:46.2 | given that ransomware often does sort of rely on these lateral movement kind of attacks and |
| 1:53.4 | exploits. So a print nightmare fits right near a playbook. It's a relatively straightforward |
| 1:58.8 | vulnerability to exploit at this point, so no big surprise |
| 2:03.3 | that it's used for ransomware. |
| 2:06.5 | Then a couple stories related to cryptocurrencies. |
| 2:09.6 | First of all, you may have heard about it already. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

