meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, January 20th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 20 January 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Popular Domains and SPF/DMARC; Sysmon Exploit; ManageEngine Exploit; Netcomm Patch; Outdated Office Check

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Friday, January 20th,

0:04.3

2000, 23 edition of the Sands and at Storm Center's Stormcast.

0:09.7

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:15.7

Jan today took another look at SPF and DMARC records and this time

0:21.1

Jan focused on the top 100,000

0:24.9

domains to see how well

0:27.0

DMR SPF and these other technologies

0:29.6

are implemented. Well it turns out

0:32.3

not a big surprise here but the popular domain

0:35.9

the more likely it does have useful records

0:40.7

installed here, but still even for the top 1,000 of these domains, there are still a lot of

0:49.1

gaps left. One problem that you may be seeing here with these very popular domains is that they are often associated with very large organizations.

0:59.5

And the larger organization, the more difficult it tends to be to limit what mail servers are allowed to send email.

1:09.0

And that, of course, is what these SPF and DMark records are typically

1:13.5

all about. And remember December patch Tuesday long, long time ago, but Microsoft announced

1:21.9

a vulnerability in Sysmon, and this was certainly an interesting vulnerability, as Sysmon is often used sort of to instrument the network to detect Sysmon and this was certainly an interesting vulnerability as Sysmon is often used sort of to instrument

1:29.7

the network to detect security issues, but in this case due to this vulnerability, Sysmone could

1:36.8

be sort of turned against you. Now thanks to Jay for pointing out that exploit has been

1:44.0

released for this vulnerability.

1:46.9

The exploit comes courtesy of the individual who actually found this particular vulnerability,

1:53.7

reported it to Microsoft back in June last year.

1:58.3

And with this exploit being available now,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.