meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, March 12th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 12 March 2021

⏱️ 16 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Piktochart Phishing; ProxyLogon Public PoC; Win10 Crashes; Rob Upchurch: SMHNR DNS Leakage @sans_edu

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, March 12, 2021 edition of the Sandcent Storm Center's Stormcast.

0:08.3

My name is Johannes Ulrich.

0:09.8

And today I'm recording from Jacksonville, Florida.

0:14.2

Fishing, of course, is still going strong, and attackers are coming up with new ways to present the user with malicious content.

0:25.0

Of course, including it directly in the email often fails because of mail filters.

0:30.5

More recently, we have seen at hackers use various cloud services,

0:35.1

but those cloud services are also getting better in filtering

0:40.3

this content.

0:42.3

So they have to keep coming up with new services to host malicious content.

0:48.0

And according to a guest diary that was submitted by J.B. Bowers. We do have a new service that's being used here.

0:58.8

Picto chart. I actually didn't hear about it, but apparently it's a somewhat popular service

1:04.1

that allows you to create infographics and distribute them among colleagues. Well, these infographics are often distributed as

1:13.2

PDFs and that's what the attacker is abusing here. The PDF that they will offer via pictogram chart

1:21.9

is not an infographic. It's just a simple text document with a link that then links to the actual

1:29.9

fishing site. And of course, they're claiming that in order to view whatever fancy infographics

1:36.4

they offer, you first have to log in to Outlook 365. And that's how they are stealing

1:43.3

your Outlook 365 credentials.

1:46.4

So overall a pretty ingenious use of this service.

1:50.9

Not sure what Picta chart can do about this other than being more careful in filtering

1:57.3

content, maybe trying to proactively discover these fishing documents.

2:04.6

And yes, Microsoft Exchange, of course, still a problem and being exploited now by multiple groups.

2:14.3

While we also get a little bit more detail about the actual exploits being used.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.