ISC StormCast for Monday, March 18th, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 18 March 2024
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Monday, March 18, 2020, |
| 0:04.2 | for edition of the Sandin and Storm Center's Stormcast. |
| 0:08.1 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:13.7 | Eging has an update on the 5G-Huler, 5-gul vulnerabilities. |
| 0:20.2 | Ewing is part of the group that did some of the research on these vulnerabilities, and |
| 0:25.1 | the update does show how some of the phones were updated and also the lack of updates |
| 0:32.8 | for phones, in particular for some older models. |
| 0:36.9 | This is an ongoing problem for Android where older |
| 0:40.1 | models are often no longer receiving updates. And in this particular case, of course, the update |
| 0:47.9 | does affect the 5G modem. So often the cooperation and validation of these new firmware versions by the |
| 0:57.4 | telecom operator has to be done first before they can be pushed out to the end user. |
| 1:05.9 | And DDA has a post explaining how to not just decode hexadecimal payload, but also how to work |
| 1:14.9 | around some of the pitfalls that may run into, like in this case the encoding not being |
| 1:20.5 | identified correctly. So DDA walks you through this particular sample, how to eliminate |
| 1:27.2 | some of the additional characters |
| 1:29.3 | that were inserted for obfuscation after removing them. The file pretty straightforwardly decodes |
| 1:37.6 | back to a cobalt strike beacon. And researchers from Salt looked into some interesting vulnerabilities in chat GPT related to plugins. |
| 1:49.5 | The problem here is that, of course, you have to connect the plugin to chat GPT, and it uses |
| 1:57.4 | OAuth in order to accomplish this. |
| 2:00.9 | Normally, what happens is that chat GPPD sends you to the website that you would like to |
| 2:06.3 | authenticate with, and then that website sends you back a token that's then being used |
| 2:11.8 | for authentication. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

