meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, January 8th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 8 January 2018

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Weblogic Flaw Exploited by Cryptominer; More Spectre and Meltdown news;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, January 8, 2018 edition of the Sands and its Storm Center's Stormcast.

0:07.0

My name is Johannes Ulrich and I'm recording from Jacksonville, Florida.

0:12.0

Last week, Renato came across a pretty concerning incident that actually later turned out to be more than really what he initially saw.

0:21.6

What Renato originally saw was an affected Oracle WebLogic system that had a crypto miner running.

0:29.6

Okay, so at first nothing really all that big and scary, just yet another crypto miner.

0:35.6

But what it turned out later was that this is actually a very

0:39.1

recently publicized vulnerability in Oracle WebLogic and we found a few hundred additional

0:47.2

systems that were affected by this same event.

0:52.2

Now we came across a log actually that listed around 900 infected systems,

0:58.2

many of them running PeopleSoft. And the concern, of course, here is that companies typically

1:04.2

keep an awful lot of personal identifiable information in PeopleSoft. In this particular case, you may have been lucky because the goal,

1:13.5

as I said, of this particular attack was installing this crypto coin miner. We went ahead and we

1:20.3

tried to notify the victims here. Not sure how well this worked at this point yet, but we got feedback from a couple of the victims that, yes, they were looking into this.

1:32.9

If you are running WebLogic, if you are running PeopleSoft, please take a look at the diary and make sure you're not affected.

1:40.9

If you are affected by this crypto coin miner, well, maybe you're lucky and that's

1:45.9

the only thing that happened, but this is a very easy, exploitable vulnerability. So you definitely

1:52.1

do want to take a second look at the system and make sure it didn't get exploited by anything

1:58.3

else in addition to this crypto coin miner.

2:01.6

We're not going to make the full list of infected IP addresses public at this point, but

2:07.6

if you have any questions about this, let us know.

2:10.6

To identify systems, Val Renato is giving you some indicators of compromise here.

2:16.6

Also, we do have this new threat feed that

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.