meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, February 2nd 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 2 February 2018

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Adobe Flash 0-Day; Adaptive Phishing Kit; Crypto Miners Replace Ransomware

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, February 2, 2018 edition of the Santernut Storm Center's Stormcast.

0:07.0

My name is Johannes Ulrich, and the time I'm recording from Jacksonville, Florida.

0:13.0

The South Korean cert got a surprise for us, a new Adobe Flash Saturday exploit that apparently has already been used in some targeted

0:23.6

attacks.

0:24.6

Attacks that were seen in Korea did deploy this particular exploit via Excel spreadsheets

0:31.6

that included the Flash file.

0:34.6

Now other office documents would work as well and of course you could always get

0:39.9

someone to go to a malicious website that will then launch the malicious flash file. This exploit has been

0:48.0

used to target researchers in South Korea that deal with North Korea. Other than that, no public sightings yet.

0:56.8

The earliest references to the exploit have been found back in November.

1:04.1

Now Adobe has released a statement that they have a patch ready that will be deployed on Tuesday as part of the regular monthly

1:15.4

update.

1:16.9

So not too much really to worry about it at this point, in particular since probably the

1:22.3

one thing you should worry about is why you're still using Flash and just as Tuesday comes along, apply the patch as it becomes

1:32.0

available. And Xavier came across a really interesting fishing site. This fishing site sort of adapts

1:40.5

itself to the victim. Now, typical fishing sites are trying to mimic well-known sites

1:47.5

like Gmail or hotmail, but in this particular case, the design of the fishing site changes

1:54.7

depending on the domain part of the victim's email address. The link that you're clicking on if you're falling for this type of fishing site does include

2:05.2

your email address and then it essentially just takes the domain part of the email address,

2:11.9

it then downloads logos from the respective website and displays them as part of the fishing site. It also uses

2:21.0

the first part of the domain in order to mimic a company name. So in this case, Xavier used

2:29.0

ISC.sense.edu as an email domain and then it inserted ISC into various parts of the page where you

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.