meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, September 20th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 20 September 2019

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Agent Tesla; Apple Updates; SAMBA disables SMB1; GitHub Updates

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, September 20th, 2019 edition of the Santernut Storm Center's Stormcast.

0:07.9

My name is Johannes Ulrich.

0:09.6

And then I'm recording from Stockholm, Germany.

0:13.9

Xavier today looked at a recent sample of Agent Tesla.

0:19.4

That's a Trojan that typically then exfiltrates data from its victims.

0:25.0

What was sort of a little bit special about this particular sample was that it was

0:29.0

exfiltrating data via SMTP, but it used the submit port, Port 587.

0:36.6

Unlike Port 25, which is often blocked in corporate networks and also

0:41.0

by isps port 587 is specifically designed to connect to your own mail server and port 587

0:50.2

typically does require authentication so this is why this particular Trojan used Port 587 to send its emails instead of the Port 25.

1:02.5

That's usually sort of associated with SMTP.

1:07.2

And of course, one of the big non-security tech news items today is the release of iOS 13 from Apple.

1:17.0

Now, with these feature releases, we also get a number of security improvements and fixes.

1:24.3

As I'm recording, this Apple has not yet made available.

1:28.3

The security details for iOS 13, Safari 13, which was also released as well as WatchOS 6.

1:37.3

So don't have any real details here, but for Safari 13, we do have the release nodes and they do list some new

1:48.1

security and privacy features that were added to this latest version of the browser.

1:53.4

Part of the one that sticks out the most to me is Fido2 support.

1:58.2

So if you have a USB security key, it should be working now with Safari. Have to play with this a little bit myself. I don't think it's supporting the older U2F format, which is actually something we do support on the ISC website. We'll probably have to wait a couple days until I get to play with this.

2:22.3

And then we got a new release of Samba, the open source implementation of the SMB file sharing

2:29.0

protocol.

2:29.8

And yeah, it's particularly popular with Linux distributions.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.