meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, August 31st 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 30 August 2018

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Cryptocoin Miners Rule; Android Privacy Weakness; Mimecast EMail Stats

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, August 31st, 2018 edition of the Sandinert Storm Center's Stormcast.

0:08.2

My name is Johannes Ulrich, and I am recording from Sevalde, Germany.

0:14.3

Xavier today wrote up a diary summarizing some of his recent experiences threat hunting and he produced some nice

0:24.1

statistics really confirming what we have been seen for the last year or so and others have been

0:30.9

writing about as well crypto coin mining is probably the number one payload that you will see deployed via exploits.

0:39.3

What's important to keep in mind here is that these payloads are really sort of what's

0:45.3

used in more generic exploits, more widespread exploits.

0:50.3

These are not targeted attacks.

0:53.3

We do however see them being used very quickly after a new exploit is released.

1:00.0

Just to make the point here, the recent struts vulnerability was exploited very quickly within a couple of days to deploy crypto coin miners.

1:10.0

Whenever you see a crypto coin miner installed

1:13.5

on a system via an exploit like this, well, the exploit was really easy, so there is a good chance

1:20.4

that a more targeted attack fared out the same vulnerability and did something more sinister to your system.

1:30.3

So whenever you see that crypto coin miner, double check, take a quick look at the system.

1:35.3

This may not be the only thing that happened to the system.

1:40.3

But because crypto coin miners are rather easy to find, use them as a canary to really identify systems that have some blatant vulnerabilities left unpatched.

1:52.9

And as far as the current struts to warnably goes, that's CVE 2018 11776, which was patched on August 23rd so about a week ago

2:05.2

Welllexity for example is reporting about seeing active exploitation of this

2:10.7

vulnerability to deploy crypto coin miners as usual these crypto coin miners will also

2:16.5

try to delete competing miners.

2:19.3

Now, they can't patch struts too for you, so they really rely on trying to infect your system often enough

2:28.3

and kicking off competing miners.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.