meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, December 10th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 10 December 2018

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Analyzing Malicious Docker Images; Sextortion Ransomware; WebKit Exploit;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, December 10th, 2018 edition of the Sandcent Storm Center's Stormcast.

0:07.4

My name is Johannes Ulrich.

0:08.8

And then I'm recording from Jacksonville, Florida.

0:13.3

Recently, we have seen a large number of attacks against unprotected Docker instances.

0:19.4

The attack is usually just going against the Docker API on Port 2375.

0:26.6

I've talked about this before, but Remko looked a little bit deeper into this and looked at

0:32.7

the images that are being installed via this particular attack.

0:37.1

And what he found was a particular Docker hub account that was used to provide these

0:43.3

malicious images.

0:44.3

Now, some of these images had download numbers in the 100,000 times.

0:50.3

The particular account has been disabled by now. And it looks like the main reason that these images would be installed is this attack against the Docker API.

1:01.0

I don't think that anybody would sort of install these images by mistake, but it had somewhat sort of innocent names like, for example, Java 123.

1:11.6

Ramco is showing how he investigated these malicious images, so if you're running into any

1:16.6

suspect Docker images, it shows some of the tools that you can use in order to analyze them.

1:24.6

And you probably heard of the arrest of the Huawei CFO in Canada last week.

1:31.5

Well, we are seeing some advance fee scams that are trying to trick people into paying some kind of bribe

1:40.0

in order to have her released with the suggestion that of course if you do so you will be rewarded.

1:49.0

So really just sort of yet another variation of the Nigerian prince style scam, you're usually

1:55.0

asked to transfer of the order of $2,000 to $5,000 to dollars to a particular bank account which the message explains is

2:03.2

owned by this particular corrupt prison guard who will then release Ms. Meng.

2:08.3

So far these messages are all in Chinese targeting Chinese destinations either via SMS or

2:14.9

WeChat.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.