meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, February 16th, 2024

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 16 February 2024

⏱️ 13 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. AWS SNS Smishing; Linux CVEs; Pulse Secure Issues; Rogue Ethernet Switches; @sans_edu @sansinstitute

Transcript

Click on a timestamp to play from that location

0:00.0

And welcome to the Friday, February 16, 2024 edition of the Sands and its Storm Center's Stormcast.

0:07.2

My name is Johannes Ulrich.

0:09.2

And today I'm recording from Jacksonville, Florida.

0:13.4

Sentinel 1 has an interesting update on fishing or guest-mission campaigns that are using SMS messages in order to impersonate the United

0:23.8

States Postal Service.

0:26.0

You probably, at least if you're living in the U.S., have seen these SMS messages that claim

0:31.9

to come from the Postal Service.

0:35.0

Very popular, very common here.

0:41.1

In the past, they often have used compromised accounts of business-to-consumer services like Twilio. And we have written in the past about scans looking

0:48.1

for, for example, Twilio configuration files that include credentials. The latest target here appears to be

0:55.9

AWS SNS service. The SNS service or simple notification service also allows the sending

1:02.9

off-SMS messages. This move main part be due to services like Twilio clamping down on mass sending of SMS messages.

1:14.7

They have over the last year, I know with Twilio, because I've used that myself,

1:19.5

implemented a number of measures in order to either apply rate limits or other measures

1:25.2

to limit how many messages you are able to send using their

1:30.2

service.

1:31.3

And this may make these accounts less valuable, which is why they're now moving on to the

1:37.3

AWS SNS service.

1:41.6

And the Linux kernel project is attempting to become more transparent about vulnerabilities.

1:48.0

They're fixing.

1:49.0

They have been criticized in the past for not really labeling properly.

1:54.0

All the vulnerabilities being fixed in various updates.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.