meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, January 12th, 2024

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 12 January 2024

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. OpenSSH Removing DSA; Juniper Patches; ManageEngine Update; Atomic Stealer;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Friday, January 12, 2024 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida.

0:15.0

Well, I had the links in yesterday's show notes, but forgot to mention it in the podcast itself.

0:21.5

Mark Baggett started producing a new YouTube series.

0:26.2

I think it's pretty good.

0:27.6

And the first episode that was made life yesterday.

0:30.7

Looks really exciting.

0:33.2

It's origin stories for your favorite infosec tools.

0:37.7

The first episode covers Security Onion and interviews the creator of Security Onion.

0:44.7

That's sort of the theme of these videos.

0:48.0

Mark will always interview the creator of sort of no one of those legendary Infosec tools, I think Medasploid with

0:56.3

H.D. Moore is next. For links, just check the IC website or yesterday's show notes.

1:05.6

And for anybody using OpenSH, take a look and make sure that you stop using DSA as a key algorithm for

1:17.0

OpenSH. OpenSH today announced that they will be removing DSA support from OpenSH over the next

1:26.1

year. Now, there are good reasons for that.

1:28.9

DSA is known to be weak.

1:31.4

It's based on Shah 1 Digest,

1:34.3

and, well, as they say in the announcement,

1:36.5

only has about an 80-bit worth of symmetric encryption equivalent security,

1:42.5

which certainly doesn't cut it anymore.

1:44.9

These days hasn't really been sort of the default in S-H forever, I think.

1:50.8

So definitely make sure that you are not using any DSA keys.

1:56.1

Juniper released 27 security bulletins fixing numerous vulnerabilities. A couple highlights that I

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.