meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, March 8th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 8 March 2021

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. MSFT Exchange; Excel 4 Macros (XLM) AMSI; Apple Find My Device Privacy Leak

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, March 8th, 2021 edition of the Sandcent Storm Center's Stormcast.

0:08.2

My name is Johannes Ulrich.

0:09.7

I'm recording from Jacksonville, Florida.

0:13.8

Let's start with an update on the Microsoft Exchange vulnerability.

0:18.5

The part that I think has not really been made very clear is that before the

0:26.4

patch was released. The group that started with some of these target exploits apparently

0:31.8

did scan off the internet and exploited all exchange servers that they were able to find in the couple

0:39.8

days before Microsoft was able to release a patch. So what this means is that first of all,

0:46.1

there are tens of thousands of exploited exchange servers out there that has also been

0:52.9

confirmed by traffic observed to some of the command control servers.

0:58.0

And if you have an exchange server that was exposed to the internet, chances are it got exploited.

1:05.0

So one of the things you definitely should do today, even if you already patched, if you already checked, double check, make sure that

1:11.9

your exchange server has not been compromised. Microsoft published a PowerShell script to help with

1:17.8

this. Also, the NCC group published a list with known good hashes for exchange servers with

1:25.8

different patch levels. So that's really helpful to sort of

1:29.4

find odd different binaries that may have been left behind that are not listed in these

1:35.8

common indicators of compromise lists that you may have found. And then please double check that

1:41.4

the patch actually got applied. Apparently in particular, if you're

1:46.0

using user account control on your exchange server, it's very important that you do run the

1:53.6

patch as administrator. If you applied manually, if you don't run it as administrator, and if you're

2:00.2

using user account control,

2:02.1

then the patch appears to apply, but it does not correctly update all the files. So you may still

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.