meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, February 8th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 8 February 2021

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. VBA Macros vs. Application Menus; Great Suspender Malware; Chrome 0Day; Plex DDoS

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, February 8, 2021 edition of the Sandcent Storm Center's Stormcast.

0:08.4

My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:14.1

And if you have been watching exploits and malware for a while, you probably noticed that even old attacks often still work and

0:23.6

tend to come back occasionally.

0:26.6

Xavier ran into an interesting piece of macro malware that actually tried to revive a technique

0:34.6

that had been used by the Melissa Worm back in March of 1999.

0:41.4

The technique here is to use Visual Basic for Applications or VBA to disable certain menus in the application,

0:51.0

to alter the applications menu.

0:53.6

Now, the malware that Xavier ran into it tried to disable certain security features that a user

1:00.6

could possibly enable. Apparently that didn't work, but Xavier kept playing with it and was able

1:07.7

to at least disable selected menus,

1:11.1

like for example, copy and cut,

1:14.4

which often is disabled in order to prevent people

1:18.4

from copying data from a spreadsheet into another document.

1:25.2

I've got an update to a story that I believe I originally covered back in January about a month ago, but it has been coming back, so I figure good to update you on it.

1:37.8

It's related to the Google Chrome extension Great Suspender. This particular extension is supposed to suspend activity in

1:48.4

windows that are currently not visible. And the goal here, of course, is to save battery, save

1:55.7

CPU power. But as it has happened, sadly, quite frequently, this was a very popular extension, over 2 million downloads,

2:05.6

and well, the developer then sold it to a new entity, and the new entity that purchased the extension started to add malicious features to the extension, essentially exfiltrating data.

2:21.3

And actually, that was first noted in a GitHub comment to the crate suspender back in November.

2:29.3

Well, the update now is that Google finally got around to mark this extension officially as malicious,

2:37.8

so it should no longer be downloadable.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.