meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, July 20th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 20 July 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. #SigRed Update; Cloutflare Outage; ZeroShell; Zone.Identifier; Forgotten tcpdump

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, July 20th, 2020 edition of the Sansonet Storm Center's Stormcast.

0:07.7

My name is Johannes Ulrich.

0:09.3

And then I'm recording from Jacksonville, Florida.

0:13.6

Well, first, a quick update on Cigrette.

0:16.0

And the good news, at least as of me recording this here Sunday evening, is that there is no real

0:23.5

news regarding cigarette, so no new exploits, and actually the news overall has been

0:30.4

dying down a little bit about cigarette. Still pay attention to it, keep patching your

0:37.0

systems if you're not done with it yet.

0:40.1

John Bambenik did publish a quick post with a couple ways how you may be able to detect exploitation.

0:49.8

And on Friday, Cloudflare suffered a significant outage lasting about half an hour and, of course,

0:56.8

with Cloudflare's business being in part DNS.

1:00.1

Some people, of course, immediately pointed to Cigrette, but appears to be totally unrelated.

1:07.4

Cloudflare did publish a very detailed and I think actually a really good blog post about the outage, what exactly happened, and essentially it went back to a router misconfiguration that caused the outage.

1:24.2

The outage wasn't complete, but did affect major parts of Cloudflare's network.

1:30.2

And of course, with so many websites relying on Cloudflare, it did affect a large number

1:37.3

of high traffic websites. The lesson here is that even cloud services go down occasionally and this is not the first time.

1:46.0

So if you are relying on cloud services, then certainly you have to be ready for this.

1:53.1

And of course, once they are down, there isn't really much you can do other than hope that they'll get it fixed pretty soon, which Cloudflare to some extent did.

2:05.6

And pretty regularly, I do talk in this podcast about vulnerabilities in routers,

2:11.6

and particularly in web-based admin interfaces of routers.

2:16.8

So kind of nice, I guess, in some ways to see today's

2:20.7

blog post by Guy who has detected exploitation of one of these router vulnerabilities, so-called

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.