meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, November 11th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 11 November 2019

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Misused MSFT Apps; Pwn2Own Summary; State of Javascript Security; Honeypot Update

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, November 11th, 2019 edition of the Santernat Storm Center's Stormcast.

0:08.1

My name is Johannes Ulrich.

0:09.9

And I'm recording from Jacksonville, Florida.

0:13.9

Many of our diaries are talking about how standard Microsoft software can be abused by malicious code in order to essentially

0:24.3

assist the code to, for example, download further malicious content.

0:29.6

That's often not detected well because these applications are whitelisted and the malicious

0:35.8

code is really just using features that these applications

0:41.3

provide. On Friday our handler Xavier wrote about how all of this can be done and also how, for example,

0:50.3

you can use your standard Excel to download a file or to execute PowerShell. And

0:58.0

attackers that live off the land like this, they of course try to avoid detection. So

1:04.2

Xavier is outlining some techniques to detect these misuses of standard Microsoft software.

1:14.2

And our handler Jan Kopriva took a look at how the recent use of the blue key vulnerability

1:20.9

to install crypto miners affected patching practices.

1:25.9

Yan's somewhat sad but probably unsurprising conclusion is that the use of the vulnerability

1:33.4

in such a highly publicized way did not significantly affect the rate at which systems

1:40.0

are patched.

1:41.6

Microsoft patched this vulnerability back in May and in the five months since then, there has

1:47.9

been a quite strong effort from Microsoft and other organizations to convince people to

1:54.6

apply this patch.

1:57.1

And well, it's likely that five months into it, the systems that are still not patched

2:02.6

are either unmaintained or intentionally unpatched for whatever reasons where administrators

2:09.7

figured it's too risky to patch or just too much work.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.