meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, November 13th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 13 November 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Gafgyt Update; ScreenConnect Healthcare Breach; Fake Assessment Websites

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, November 13, 2023 edition of the Sansonet Storm Center's Stormcast.

0:08.1

My name is Johannes Ulrich, and then I'm recording from Jacksonville, Florida.

0:13.9

On Friday, we got a quick diary by Austin Long, a student in the Sands.edu Bachelor's program.

0:21.6

Now, in his diary, it looks basically at, well, what's going on currently with Gaffet.

0:28.8

We often sort of overlook these old, long-going threats, so always good to check in with them occasionally to see what's happening.

0:37.4

Not really has changed much with this particular bot over the last 10 or so years that it's going around.

0:46.1

It's still looking for default passwords.

0:49.6

Had it a couple sort of HTTP vulnerabilities to its arsenal.

0:53.8

Apparently the one particular sample that

0:56.8

was captured here by Austin is looking for some Huawei routers with specific vulnerabilities.

1:06.3

Best defense against these kind of threats is keep up to date on your router firmware. Remember

1:12.7

once a month check-in if your router is still up to date and of course avoid default passwords.

1:20.8

And then we got an interesting post by Huntress Lab with details regarding attacks against a number of healthcare, particular,

1:29.5

pharmaceutical companies.

1:32.0

The common denominator here appears to be a software called Screen Connect.

1:38.1

Screen Connect is used by transaction data systems, according to Huntress, and that company

1:44.0

actually was recently purchased

1:47.0

by a company called Outcomes. These companies are also known for their RX30 and computer RX

1:54.4

software, so if you're running that software, you may be running Screen screen connect as well.

2:03.4

Once connected to the systems,

2:05.6

the attacker then installed in some cases additional screen connect instances,

2:08.6

but also installed any desk,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.