meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, August 22nd, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 22 August 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Astaroth Malware targeting Brazil; Android Ring App XSS;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, August 22nd, 22nd, 22 edition of the Sands and its Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:15.0

Brad on Friday posted a diary about an Astoroth-Malver infection. case Pratt is investigating here actually happened that same day.

0:26.1

So hot off the malware process, so to speak.

0:29.7

The email in this case was in Portuguese and impersonating a Brazil-based company.

0:36.0

The attacker even registered a custom domain

0:39.2

within the dot link top-level domain

0:42.0

to make the link more plausible.

0:45.2

Once the user clicks on the link,

0:47.5

they will receive the malware

0:49.7

in the form of a sipped batch file.

0:52.5

The badge file will then trigger download of the actual malware.

0:57.3

And as always, Brad offers additional details,

1:00.8

indicators of compromise,

1:02.4

and probably most valuable,

1:04.2

links to the packet captures,

1:06.2

allowing you to actually redo the analysis

1:08.9

and to learn by following in Brad's footsteps.

1:14.3

An Amazon patched a vulnerability in its Ring Android app that could expose users' camera recordings.

1:22.5

The vulnerability was originally identified by checkmarks, and it is interesting because it shows how

1:29.7

native applications may be affected by cross-site scripting, even though you don't often think

1:36.1

about them as web applications or rendering HTML, but that's in part sort of what's often

1:42.9

happening here. The problem was rooted in the deep linking activity.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.