meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, August 19th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 19 August 2019

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. VoIP Vulnerabilities; AV Sandbox Leaks; Trend Micro Password Manager; Firefox Password Manager;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, August 19th, 2019 edition of the Sandsenet Stormsendors Stormcast.

0:07.9

My name is Johannes Ulrich.

0:09.4

I'm recording from Jacksonville, Florida.

0:14.0

Got a little bit of public service announcement to start out with and nothing really new,

0:18.5

but it keeps coming up that users are uploading confidential

0:23.4

documents to various antivirus sandboxes. These tools like most prominently Virus Total will

0:31.4

scan your document for malware and then of course well they will keep a copy of that document and make it

0:40.7

available to researchers not always is the public allowed to search the database

0:46.4

of all of these documents but it usually requires very little authentication

0:51.8

sometimes you just have to pay some money to get full access

0:55.3

to all documents being submitted to these sandboxes. And that's not really bad on part of the

1:02.5

sandbox here. That's sort of part of what they're doing, they're sharing potential malware.

1:08.6

That's being submitted by users.

1:11.6

Just be very careful what you share.

1:14.6

Quite often you have the option to just submit a hash of a particular file.

1:20.6

Now, that's not always as telling of course and can still tip off, for example, an attacker that you intercepted a document and

1:30.6

analyzed it, but still it's much less likely going to cause any problems than uploading

1:38.2

the full document. If you are fairly sure that this malware, you're just not sure what

1:44.0

kind of malware it is,

1:46.0

then by all means use the systems and of course share any samples that you have gotten that

1:53.3

way.

1:54.5

And wasn't it just Friday where I talked about the ongoing problem with in and of things devices. Just to confirm this,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.