meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, May 11th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 11 May 2020

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. YARA 4 Released; vRealize Salt; Samsung Android MMS RCE; MacOS 2FA Trojan

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, May 11th, 2020 edition of the Sansonet Storm Center's Stormcast.

0:07.3

My name is Johannes Ulrich.

0:08.9

And I'm recording from Jacksonville, Florida.

0:13.6

Well, we got a new version of Yara, Yara version 4.

0:18.2

Now, Yara is the language that's developed by virus total order to essentially

0:24.2

sort of write simple signatures to find files, kind of like an open source anti-virus language.

0:31.6

And in version 4, we now have the ability to match base 64 strings.

0:38.3

The main result here is that it's easier to write rules that contain BAS-D-4 encoded strings.

0:44.3

Of course, in the prior version of Yara, you could just do the encoding yourself and then

0:50.3

essentially match the resulting ASCII string.

0:53.3

And in case you wonder, the acronym, Yara just stands for yet another ridiculous acronym or Yara

1:00.1

another recursive acronym.

1:03.3

And one thing I have talked about in the last couple of weeks is the vulnerability in Saltstack.

1:09.7

Well, we now got a patch from VMware in there.

1:14.5

We realized product that apparently does integrate with Saltstack,

1:19.1

so they had to fix this vulnerability as well.

1:23.9

Two actual vulnerabilities.

1:25.6

One is the critical authentication bypass vulnerability, and then

1:30.1

a directory traversal vulnerability that affect this V-realized product.

1:37.5

And if you are using a Samsung Android phone, you probably want to pay attention to the

1:43.3

May update for Android that was released

1:46.3

by Samsung.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.