meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, August 26th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 26 August 2022

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. URL Shorteners; PyPi Phishing; Oktapus; Genshin Impact Driver; LastPass; Bitbucket Vuln;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, August 26, 2020 edition of the Sands and a

0:06.9

Stom Center's Stormcast.

0:09.2

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:15.3

In today's diary Rob addresses a common issue of URL shorteners.

0:20.7

They sure are handy and, yes, very commonly used,

0:24.5

but some users are concerned about not knowing where the link will exactly lead them.

0:30.7

If you want a bit more transparency,

0:34.6

Rob has a quick shell script for you to figure out where the journey goes after

0:39.7

clicking the link. The script will use curl to extract the location header in the response.

0:46.1

This header then, of course, will tell you what the next URL will be. Could of course be

0:51.8

another URL shortener. And then I mention that I'm going to talk

0:57.4

less about malicious packages. Well, we got some news from Pi Pi and I think it was still worth

1:06.0

mentioning and it isn't all good news. Pi Pii announced that they observed how several package maintainers credentials were compromised in a fishing attack.

1:19.2

The credentials were then used to inject malware into the packages that the victim owned and had control over.

1:28.1

The fishing message was actually quite cleverly done, I think.

1:32.1

It claimed to come from Pi Pi and it asked the developer to complete a mandatory

1:36.7

validation to avoid having their packages removed.

1:41.3

Now, there was a lot of talk lately about requiring things like to factor

1:46.3

authentication and such. So somewhat plausible to a developer that they may receive a message like

1:52.7

this, even though Pi Pi states that they will never remove a package just because you

1:58.0

didn't respond to an email like this.

2:01.6

Given all the news, so developers did click on the link,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.