meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, July 22nd, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 22 July 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Non ASCII VBA; Cisco Update; Odd Outlook 365 Warnings; Windows RDP and Office Macro Updates

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, July 22nd, 2022 edition of the Sandtonet Storm Center's Stormcast.

0:08.4

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:13.9

The user of non-asky characters in programming languages is becoming more common.

0:20.3

For example, Apple's Swift language supports

0:24.1

full Unicode and some vulnerabilities around the use of Unicode and editors have already been

0:30.1

reported in recent months. But DDA's diary from today is about a bit a different issue.

0:39.0

DDA took a look at Visual Basic for Application, VBA code, using non-asky variables.

0:46.3

Well, first of all, surprise for an older language like this, it actually works.

0:50.6

Now, there's still one-bite characters.

0:53.4

They're not a Unicode per se.

0:56.0

Just the first bit of the bite is set, making them sort of non-standard asky characters.

1:03.0

By default, DDA's Oli Dumb script is creating somewhat unreadable output in these cases,

1:09.0

and this may be one of the goals here, making

1:12.0

reverse analysis more difficult. But of course, DDA came up with a decoder plugin and

1:18.9

options to help. The decoder plugin will at least find statements that make it easier

1:25.0

to find important features like URLs that are being used to

1:29.2

download additional malware, which of course we often have in these macros. Plus, with the new

1:35.6

option added by the data, the code will also be easier to read. And Cisco yesterday published

1:43.5

seven new security bulletins.

1:46.0

Out of these seven, the bulletin disclosing three vulnerabilities in Cisco's Nexus dashboard

1:53.2

was the only bulletin rated critical.

1:56.8

It is a bulletin that you should pay attention to if you are running this software.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.