meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, July 14th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 14 July 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Honeypot Logs; MSFT Outlook 365 compromise; Fake PoC; Ghostscript PoC;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Friday, July 14th, 2023 edition of the Sandinert Storm Center's

0:08.4

Stormcast. My name is Johannes Ulrich and today I'm recording from Washington, D.C.

0:15.4

Well, first of all, thank you to everybody who attended my keynote here at Sands Fire earlier this week, either online or here in person.

0:24.5

Talked a little bit about, in a storm center and such.

0:27.2

We do have a great sort of follow-up diary to this from Jesse today, where he talks a little bit about the honeypot and how to manage some of the logs that it retains and how to basically get more

0:39.2

value out of this little Raspberry Pi or virtual machine honeypot. So check it out if you are

0:46.9

already or if you're planning to run our honeypot. And there was a lot of news, also some

0:54.0

confusion about a Chinese APT actor,

0:57.5

apparently gaining access to the Outlook 365 accounts of a number of different US federal

1:05.4

agencies.

1:06.1

The problem in this case was not a vulnerability per se as stated by a blog post from Microsoft

1:13.8

as well as a blog post from the cybersecurity infrastructure, security agency SISA.

1:20.9

This particular threat actor apparently got a hold of a signing key used by Microsoft.

1:28.6

How did he got a hold of it?

1:29.9

That's really the big, big question here,

1:32.8

whether it was leaked, stolen, purchased, or how they got to it.

1:38.2

But this signing key then allowed them to essentially authenticate as arbitrary users.

1:46.2

They use this access to access various sensitive email accounts and then exfiltrated emails. This was discovered about a month

1:55.8

ago, however apparently was going on for quite a while. This is one of those tricky events to figure

2:04.3

out and really detect because you do have someone using what looks like valid credentials. Apparently

2:11.9

these respective agencies did note the odd app ID being used in order to access these email accounts.

2:21.2

Microsoft mitigated this problem by now by invalidating this signing key that was used here.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.