meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, February 26th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 26 February 2021

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Forensicating Azure VMs; FriarFoxi; JSON Parsers; MacOS 11.2.2

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, February 26, 2021 edition of the Sandcent Storm Center's Stormcast. My name is Johannes Ulrich.

0:10.1

And I'm recording from Jacksonville, Florida again.

0:15.0

Imagine that even after you move applications into the cloud, there is still a chance that they get compromised.

0:24.2

Daniel's diary today talks about how to do forensics on Asia virtual machines.

0:31.9

Daniel talks you step by step through using the command line interface to, first of all, of course, create a snapshot

0:38.9

of the disk, then move it to a different storage account, and finally, mounting it in your

0:46.5

SIFT virtual machine, so you can then do traditional forensics on the image. As Daniel points out, it's of course highly preferred to have some kind of endpoint detection

0:59.8

and response tool installed in the virtual machine to save yourself the time and do direct

1:07.0

forensics or instant response within the virtual machine, but well, that's of course

1:13.1

not always present.

1:16.5

And lately when we talked about malicious browser extensions, it was often Google Chrome

1:22.3

extensions that were doing the bad work.

1:26.4

Well, it's not just Google Chrome that supports browser extensions.

1:30.7

There are browser extensions, and with that malicious browser extensions,

1:34.9

pretty much for every browser.

1:37.8

And ProofPoint has an interesting write-up about Firefox browser extension

1:43.0

that they're calling Fryer Fox that apparently is used to target

1:49.4

Tibetan organizations.

1:52.0

You have quite often seen how a Chinese government-sponsored Malver is kind of using Tibetan

1:59.5

organizations a little bit as its proving ground back

2:03.5

in 2008, 2009, I believe it was. Martin Hornbeck, for example, wrote extensively about that.

2:10.7

In this latest incident that ProofPoint is discussing, the user is first tricked to go to a website u-dashube.tv, which of course

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.