ISC StormCast for Monday, December 14th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 14 December 2020
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, December 14th, 2020 edition of the Sandcent Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:13.7 | Well, I actually already had this podcast recorded and sort of ready to go when we had some late breaking news related to the Fire Eye incident |
| 0:23.6 | of last week. Turns out that this particular incident was actually part of a larger problem. |
| 0:31.9 | Turns out that the root of the compromise of Fire Eye was actually a compromise of Solar Winds. |
| 0:40.3 | Solar Winds is a company that makes monitoring software and management software for networks |
| 0:47.3 | and their Orion product apparently was compromised and used to infect selected customers with backdoors. |
| 0:58.3 | This compromise happened between March and July and looks like not all customers of Solar |
| 1:05.7 | Wind are affected, but instead only specific customers were supplied with tailored back doors. |
| 1:16.5 | The basic backdoor was used here was of course good old Cobalt strike, but some of the details |
| 1:23.9 | like for example the exact DLL being injected, |
| 1:28.3 | changed from customer to customer. |
| 1:31.3 | And right now it's not clear how many customers are affected. |
| 1:35.3 | But it looks like the targets are either government networks |
| 1:39.3 | or networks of related, again, suppliers, |
| 1:43.3 | like for example, Fire Eye. Now, this is still very much |
| 1:48.5 | a developing story and I put up a quick diary with what we essentially know at this point. |
| 1:57.0 | There will be very likely a special webcast on Monday evening, Eastern time, |
| 2:04.5 | likely around 5.30 p.m. Eastern, but that's still being exactly worked out. |
| 2:12.6 | So watch our website, watch our Twitter feeds for any updates. |
| 2:19.0 | Now sticking with Fire Eye here for another story, one of the issues with Fire Eye's release |
| 2:26.8 | regarding the breach last week was that they didn't really specify how they exactly got |
| 2:33.4 | compromised. I guess now we know a little bit more |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

