meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, July 13th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 13 July 2020

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Excel Starts Formbook; Zoom Update; Digicert Mass Revoke; OAUTH Consent Phishing

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, July 13th, 2020 edition of the Sandton, Storm Center's Stormcast. My name is Johannes Ulrich,

0:10.0

and then I'm recording from Jacksonville, Florida. And while I'm recording from Jacksonville,

0:16.6

well, well, I'll actually be teaching virtually in Europe this week.

0:22.8

So recording of the podcast will be a little bit of off hours based on the European schedule,

0:30.5

but the podcast should still go live at the regular schedule time.

0:35.9

On Friday, Brad took a look at the latest example of the form book Malvair.

0:43.9

Now, form book has been around since 2016-ish, according to Braddy's quoting Fire Eye on this one.

0:52.9

But while it's still going around and the sample

0:55.7

that Brad is analyzing, actually, he just came across on Thursday. So still a current sample,

1:04.0

still using the old Excel macro trick to install itself. And if you want to walk through this particular sample and how it

1:14.5

did its job of downloading then formbook using the Excel macro, well, take a look at the packet

1:22.3

capture that Brad is linking to from his diary post.

1:28.3

As Brad says in his diary that this type of malware should really not be a problem anymore.

1:34.3

If you're running Windows 10 with default security settings, well, then this should not really be happening,

1:41.3

but apparently it's still worthwhile for the bad guys to send out

1:47.7

emails spreading form book. Typically, this sample arrives like as one of those fake invoice emails.

1:57.9

And talking about reasons to run up-to-date versions of Windows last week, we had a vulnerability

2:05.2

in Zoom.

2:06.5

I didn't really mention it because it only affects you if you are still running Windows

2:12.5

7.

2:13.7

There is an update available for this now, so if you do see an update for Zoom today,

2:20.0

that's the reason to patch this particular vulnerability.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.