meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, January 10th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 10 January 2020

⏱️ 11 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Another Word Maldoc; SHA1 Update; Cisco Update; Girls Go Cyberstart @GGCyberStart

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, January 10th, 2020 edition of the Sandstone Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:13.2

Unlike most people, we really like it if our readers and listeners are sending us Malaver. Latest example is David.

0:23.5

He sent us a very sort of classic Word document, claimed to be a UPS invoice, but of course

0:30.1

the macro in the Word document turned out to be malicious.

0:35.4

Xavier took a quick look at it and you can read more about his analysis.

0:40.3

What I sort of found interesting is from a detection point of view is that it uses a very

0:46.9

obviously fake user agent for some of its HTTP requests, just a sequence of seven capital letters.

0:56.0

Looks sort of random to me, not actually sure where they come from, but I wouldn't be surprised

1:01.0

if they change from infection to infection.

1:05.0

Also, the server that these requests are being sent to, with the server header cowboy which is also

1:13.7

somewhat unusual so these are typical anomalies to look for user agent headers server headers

1:20.2

should be pretty easy to spot malware like this and it's a renewed effort in finally getting rid of the Shah 1 algorithm to sign digital documents.

1:34.3

The latest output of this effort is that KnewPG, probably the most popular implementation of GPG,

1:43.3

will no longer trust Shah 1-based signatures if they were

1:47.7

created after January 19th last year. What this means for you is, well, double-check your

1:54.2

software that it's not using Shaw 1 signatures, as of course they may fail if someone uses up-to-date software to verify them.

2:03.4

In particular, new PG version 1.4 does default to Shaw 1. So make sure you're no longer using

2:12.9

that. And Cisco released 14 security updates, none of them critical, two rated high, the rest

2:21.7

medium.

2:22.7

What's sort of a bit notable here is that many of these vulnerabilities are cross-site

2:28.4

scripting vulnerabilities.

2:30.2

They're actually often underestimated, so be careful, definitely patch this.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.