ISC StormCast for Monday, March 15th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 15 March 2021
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, March 15th, 2021 edition of the Sandcent Storm Center's Stormcast. |
| 0:08.3 | My name is Johannes Ulrich. |
| 0:09.9 | I'm recording from Jacksonville, Florida. |
| 0:14.0 | Not a lot happening this weekend, which is probably good after two weeks of too much excitement. |
| 0:20.8 | Exchange servers, of course, |
| 0:22.2 | are still being exploited, and now you sort of have the more commodity type of malware, like |
| 0:29.3 | ransomware hitting exchange servers that are still vulnerable. But we do have an interesting |
| 0:37.0 | vulnerability in Wireshark. |
| 0:40.0 | And, well, it's interesting, not really quite as serious as it sounds. |
| 0:43.9 | I think it's referred to as code execution vulnerability, which it is. |
| 0:49.4 | But essentially, what it comes down to is that if you're observing traffic in VyrShark URLs are rendered as clickable. |
| 0:59.1 | And this does not just include HTTP and H.T.PS URLs, but also, for example, file URLs or schemas like DAF. |
| 1:16.9 | And if a user now clicks on one of these URLs, it may open and in some cases even execute the particular file. So as usual, well, if you're looking at a malicious |
| 1:22.6 | traffic capture or traffic capture of a possible exploit, There's a reason why you call it malicious or |
| 1:29.7 | exploit and sometimes the exploit could be directed at the analyst, so always treat these packet |
| 1:37.2 | captures with care. And yes, an update has been released and this has been a pretty old vulnerability about for the last |
| 1:47.7 | 17 years, I believe it says in the Git commit, this behavior has been present in Vyershark. |
| 1:57.0 | And we also have another update for Google Chrome. And now this is the second time in about as many weeks that we have a remote code execution |
| 2:07.3 | vulnerability that's being fixed in Google Chrome, which is already exploited in the wild. |
| 2:14.2 | So make sure Google Chrome is doing its thing and updating itself. And NetLab |
| 2:20.3 | 360 ran into an interesting new malware that is going after IoT devices. They're using |
| 2:27.7 | a number of well-known exploits. What's really different here is what they're doing to these devices after they infect |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

