meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, February 18th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 18 February 2022

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. MSFT Teams Malware; Thunderbird Patch; Cisco DANE Vuln; GitHub Code Scanning

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, February 18, 2022 edition of the Sansanet Storm Center's Stormcast.

0:08.5

My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:14.5

Yesterday I talked about an FBI warning that business email compromise schemes are now migrating in part to conference platforms,

0:25.7

and we now have a new note about this from Vanon, which is part of Checkpoint.

0:31.4

They observe the distribution of malware in particular via Microsoft Teams.

0:37.1

The overall strategy is very similar to this business email compromise.

0:42.4

They are compromising one user's account.

0:46.5

Use that account in order to connect to a company's Microsoft Teams environment,

0:53.4

and then they are offering malicious EXE files for download.

1:00.1

Interesting, the EXE file that Avanon here did see is always called usercentric.exe.

1:09.0

Of course, nothing would prevent any attacker from using any kind of name for

1:15.2

that file. Also, there's absolutely no reason why this attack couldn't happen via Slack Discord

1:22.1

or any other popular messaging platform. But of course, in particular, the sort of internal corporate

1:29.3

messaging platforms are often considered more trusted. So also make sure that you're using

1:36.2

strong authentication for your message platform. Just sticking with messaging here, we also have

1:43.6

a new version of Thunderbird.

1:45.8

I usually don't mention Thunderbird updates, but as anything, you should keep it updated.

1:51.5

Mozilla is pretty good in automatically updating it just like Firefox and only one high

1:59.4

vulnerability is being patched here.

2:01.8

CVE 2022-0566 and out-of-bound right.

2:08.2

But well, you may have a secure email gateway in order to protect yourself from attacks like this.

2:14.1

Those you have to patch as well.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.