meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, June 30th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 30 June 2023

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. From Adobe Remcos RAT; ArcServe PoC Exploit; Sysmon Update; Drone Security

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Friday, June 30th, 2020,

0:04.8

edition of the Sanchez Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm

0:10.8

recording from Stockholm, Germany. Remco's rat is malware that Brad found this week in an email

0:19.1

attachment. Actually, well, the email attachment led them to the malware.

0:23.4

It started out as so often with an email to that included a link to a PDF.

0:30.8

The interesting part here is that the link went to acrobat.

0:35.3

Dot Adobe.com.

0:37.2

This is a legitimate Adobe.com URL, but it's used for

0:43.4

acrobat users to publish documents. So it's user-provided content that's not provided or in any way

0:51.2

vetted by Adobe, which of course can then be easily used to do what the attacker did here, publish a PDF document with a link that then leads the victim to a zip file.

1:04.4

And then the usual circus starts where you have the zip file being downloaded.

1:09.9

A password is being used to decrypted,

1:12.9

so that way it's more difficult to inspect the payload as part of any kind of proxy or so that

1:20.3

you have, which will then eventually lead to the malware. Also, all the communication happens

1:26.5

to be if I saw this right over HDPS,

1:30.3

so you do need to do TLS inspection to see anything here. As usual, Brad is providing

1:37.3

packet captures and malware samples or links to that in order for you to be able to follow along with Brad's

1:47.4

analysis. And if you're a user of ArcServe backup product, you may have seen a patch being

1:55.9

released earlier this week fixing a single vulnerability. It's an off bypass CVE 2023-26258. Researchers from MD

2:08.0

SEC originally discovered this vulnerability and a notified arc serve of this vulnerability. It's actually

2:15.3

very trivial to exploit and these researchers also have now

2:19.4

published a blog post with a proof of concept for this exploit. The problem is that the

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.