meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, March 21st, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 21 March 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Movable Type; SolarWinds Web Help Desk; MGLNDD Scans; CAPTCHA Phishing; Browser in Browser

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, March 21st, 2020 edition of the Sandsenet Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.4

Got a couple of interesting diaries from this weekend and Friday. First one is about a very massive really increase in scans for movable type vulnerabilities.

0:27.4

This particular vulnerability is being looked for here is really easy to exploit.

0:32.3

It's a code injection vulnerability in the XML API.

0:37.4

It was patched late last year.

0:40.5

There was a little bit scanning for it,

0:42.7

but nothing really all that significant.

0:45.0

Late last week,

0:46.1

we really saw the scans for it going through the roof

0:48.7

from one particular IP address.

0:52.5

So be aware if you're running movable type update, make sure that you're not already

0:58.2

compromised.

0:59.8

You don't even have to expose this particular XML API in most cases.

1:05.9

So that may be the easiest fix here to just remove that CGI script.

1:12.0

Movable type, for those of you not familiar with it, is a content management system,

1:16.9

similar to like, you know, Triple WordPress and similar issues,

1:20.1

but movable type is not sort of free open source, but a commercial product.

1:28.6

And Solar Winds is warning that there is a possible vulnerability in its WebHelpdesk product,

1:37.3

version 1275.

1:39.7

They note that a customer reported that they did see an attempt to attack their web help desk,

1:48.7

the endpoint protection software, blocked the attempt, but it's possible that there is some form of unauthenticated remote code execution vulnerability in this product. They're recommending that

2:02.9

you limit access to it. So again, no confirmed vulnerability, just a possible vulnerability.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.