ISC StormCast for Friday, March 20th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 20 March 2020
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, March 20th, 2020 edition of the Sandtonet Stormsendos Stormcast. |
| 0:07.1 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:13.0 | Xavier today took a look at another piece of malware that uses the coronavirus as its lure. |
| 0:20.6 | Now, this, of course, is becoming quite common now. |
| 0:24.6 | This email claims to come from the World Health Organization, |
| 0:27.9 | but actually uses info at who.org as from address. |
| 0:34.3 | This particular domain actually has an SPF entry that it will never be used to send |
| 0:38.8 | email, and the valid domain or the official domain for the World Health Organization is wh.h. |
| 0:46.3 | It includes the usual word attachment with macro that's then used to download additional malware, |
| 0:57.5 | and Xavier will be talking more about this particular malware in a future post. |
| 1:04.3 | And Cisco today fixed five vulnerabilities in its SD-WAN products. |
| 1:09.2 | Three of these vulnerabilities are rated high, allowing approach escalation, command injection, |
| 1:15.6 | and then also a buffer overflow vulnerability. |
| 1:19.6 | Now, teaching our defending web application class right now, it's also nice to note that |
| 1:25.6 | the two medium vulnerabilities are a cross-side |
| 1:28.9 | scripting and, yes, a SQL injection vulnerability. |
| 1:33.8 | Now, the reason why the first three vulnerabilities are only rated high, not critical, is in |
| 1:39.8 | part that they do require authentication and attacker, for example, first needs command line access |
| 1:47.0 | in order to, for example, launch the command injection vulnerability. |
| 1:52.0 | So no need to panic yet, but certainly something you do want to patch. |
| 1:59.0 | Now that it's part of the last patch, |
| 2:01.6 | use the Microsoft Fix CVE 2020-0881. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

