meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, July 17th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 17 July 2020

⏱️ 14 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Twitter Compromise; SIGRed PoC; Apple Updates; SAP PoC; @sans_edu : Aaron Elyard

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, July 17th, 2020 edition of the Sandinet Storm Center's Stormcast. My name is Johannes

0:08.7

Ulrich, and today I'm recording from Jacksonville, Florida. And yes, top of the news, of course,

0:15.9

is a major compromise of a number of high profile Twitter accounts late yesterday.

0:23.6

Now at this point we don't know a lot about the nature of this compromise, but apparently

0:29.6

it involved an insider. What isn't quite clear is if this insider willingly contributed or

0:36.6

if it was more some type of social engineering or spearfishing

0:40.8

attack that led to an insider relinquishing credentials in order to help the perpetrators of this

0:48.5

attack. Not much really to take away from this other than yes insider attacks are difficult to defend against and

0:56.5

you probably shouldn't believe everything that you see written on Twitter.

1:00.6

And yes, we do have a smaller update for the Cigred vulnerability Microsoft DNS server

1:08.0

vulnerability CVE 2020-201350.

1:11.6

And the update here is that there is now a proof-of-concept exploit out there

1:17.6

that does trigger a denial of service attack,

1:21.6

so it crashes the vulnerable Microsoft DNS server.

1:25.6

In that respect, this is probably sort of a best case as far as proof of concept exploits

1:31.2

go for this vulnerability.

1:33.5

It allows you to experiment with the vulnerability, test your defenses, test your

1:39.1

detection capabilities for this particular attack, and it doesn't reveal anything that was not already

1:47.6

widely known. Of course, a full remote code execution exploit is still widely expected and, well,

1:55.7

I wouldn't put my hopes up for a quiet Friday afternoon.

2:06.0

And of course, this week wouldn't be complete with a few more patches.

2:09.0

Apple updated pretty much everything.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.