meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, January 30th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 30 January 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. MSFT Exchange Patching Hints; FCC vs. Twilio; PlugX Spreads via USB

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, January 30th, 2023 edition of the Sands Internet Storm Center's Stormcast.

0:10.1

My name is Johannes Ulrich and I'm a recording from Jacksonville, Florida.

0:16.9

Microsoft's Exchange Server is still one of the favorite targets for a wide range of attackers.

0:24.6

Even with all the patches apply, it may well just be a matter of time for new vulnerabilities to be discovered.

0:32.4

In response, Microsoft published a blog post that should help administrators to keep exchange up to date with future updates or even help you install the current updates if you haven't gotten around to that yet.

0:47.1

Some may disagree with one of the statements in the blog post that updating exchange servers is straightforward.

0:56.2

But maybe after you are reading Microsoft's guidance, it will at least be easier. The blog post also highlights the exchange

1:03.0

server health checker tool that you can use to identify exchange servers that are missing

1:10.2

any of the updates.

1:12.5

Exchange updates are not part of the Windows server updates, so make sure you apply both.

1:20.3

You need the exchange update and the server update.

1:23.3

The exchange update you usually download separately.

1:26.9

And remember that mitigations that you may have seen only by you time,

1:32.9

they're not meant to replace patches.

1:35.6

So always apply your patches.

1:39.0

And we have seen, of course, some high-profile compromises that happened because people sort of relied too much on these

1:47.1

mitigations. You may have been receiving a large number of automated phone calls offering

1:54.6

real estate and mortgage services recently. Well, in response now, the United States Federal Communication Commission,

2:02.8

the FCC, has taken a somewhat unusual step to send a cease and desist letter to Twilio.

2:11.8

Twilio, if you're not familiar with that, it's a very popular choice to implement sort of automated

2:16.3

calling services due to the

2:18.8

relatively simple API. I've used it like for some multifactor authentication and such, but it

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.