meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, August 5th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 5 August 2022

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. TLP 2.0; Cloudflare Mail Routing Bug; rsync vuln; Kaspersky VPN Vuln;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, August 5th, 22 edition of the Sansonet Storm Center's Stormcast. My name

0:08.2

is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. Jan today wrote a brief diary

0:15.6

about version 2.0 of the Traffic Light Protocol or TLP assets sometimes abbreviated. The TLP was defined by

0:25.2

first the forum for incident response and security teams. It makes it easier to attach

0:31.8

guidance how information may be shared. So really important if you are, for example, sharing threat intelligence.

0:40.3

The protocol is pretty straightforward.

0:42.2

The original defined four different colors, from white to red, indicating how information

0:48.2

may be shared.

0:49.5

But as so many things, once it was used more, some issues really became clear with it.

0:56.3

One particular issue was the definition of the color amber.

1:00.0

Amber information may be shared within a participant's organization, but, well, people had sort of issues with what does it really mean?

1:09.3

Organizations these days are often a little bit fluent.

1:12.1

You have, for example, virtual CSOs or other consultants.

1:16.2

Are they allowed if they learn about vulnerability or an indicator of compromise to share

1:21.1

it with their customers?

1:22.4

That was a question that often came up.

1:25.0

So now we got the version 2.0 of the TLP and it now uses Amber and Amber Strict.

1:33.5

For Amber Strict, this means no, you cannot share the information if you are providing security services for the recipient.

1:43.2

So this will also include vendors, for example,

1:46.7

that may want to share that information, not just sort of one-person consultants and the like.

1:52.9

In version one of the TLP, we also had white as sort of the lowest color. That's now clear.

2:00.1

And in the past, I sometimes found that people didn't quite sort of understand a difference

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.