meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, April 29th, 2024

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 29 April 2024

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Credential Stuffing Increase; Fake Payment Cards; USPS Phishing; Chrome Post Quantum TLS Issues;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, April 29th, 2004 edition of the Sands and at Storms Center's

0:06.9

Stormcast. My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida.

0:13.7

Octa did release an advisory stating that they are seeing a search in credential stuffing attacks. Credential stuffing is notoriously difficult to defend against

0:24.5

because, well, it uses leaked credentials, so it's not like classic brute forcing. Aarne

0:32.4

attacker needs to send lots and lots of requests. It requires much less requests than you have something classic

0:40.2

brute forcing. Also, Octa states that they observed this credential stuffing originating from

0:47.3

anonymizing proxies. They're a media coincidence here, but Octa also came out with a feature to block anonymizing proxies.

0:56.9

Credential stuffing itself has been an ongoing issue.

1:00.0

Cisco alerted of it a month ago.

1:02.1

I remember last year, Cisco also released another advisory about these kind of credential stuffing brute force attack.

1:10.2

It's definitely something that you need to be ready for.

1:13.5

Blocking anonymizing proxies may help a little bit,

1:16.3

but in the end, two-factor off the occasion,

1:19.5

or you'll likely fall for it at some point.

1:24.4

And police in Japan has come up with an interesting trick to hopefully disrupt some of the

1:32.2

sort of small-scale ransomware and help desk scams that are in particular targeting elderly

1:39.9

people. What it is that in convenience stores that often sell gift cards, they did offer

1:48.4

specific gift cards that are labeled as a virus, Trojan Horse removal fee payment card or

1:56.0

unpaid charges, delinquent charges payment cards. So essentially they're labeled in such a way that someone

2:02.7

who has been infected by some fake malware or fake anti-malware in some cases may be tempted to

2:11.2

buy these cards in order to pay the fee of some kind of help desk scam.

2:21.0

Interestingly, this has apparently worked.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.