meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, November 18th, 2024

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 18 November 2024

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Ancient Vulns; GitHub Impersonations; PaloAlto and Fortinet still not secure

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, November 18th, 2024 edition of the Sandtonet Storms and this

0:07.6

Stormcast. My name is Johannes Orich and I'm recording from Singapore. Due to the recording from

0:14.2

Singapore this week, the time the podcast will be published, will be off sometimes, even show up a day early in some

0:22.5

of the listing.

0:23.5

So sorry for any confusion this will cause, but we should have our full five podcast week

0:30.4

this week.

0:32.2

Today's diary was a little bit of a reminder that sometimes attackers are reaching back to old or outright ancient vulnerabilities.

0:42.3

Specifically, a vulnerability in TP link routers that's going back about 12 years was discovered

0:48.7

back then by Polish researcher Mikhail Zydak and well it's not really clear if it was ever patched

0:58.3

there is no CVE number associated with it. Mikhail was in contact with TPLink even though

1:05.9

there were some issues and makes of the initial connection here. So not really clear if this particular

1:11.6

vulnerability was ever addressed. On the other hand, if it was addressed and all TPLink

1:19.8

routers in the last 10 years were patched, then this may not really be a big issue. Still

1:26.5

interesting that attackers all of a sudden

1:28.3

discovered this vulnerability start scanning for it even though we have not really seen any scans

1:35.1

for these vulnerabilities before. Just as a little side note, I've also seen some scans for an

1:43.1

ancient Cisco vulnerability. That was the, I think it's iOS 11.2

1:48.5

vulnerability, so pretty much 20-year-old vulnerability, all of a sudden being scanned again. This

1:54.6

vulnerability definitely has been exploited back in the day, so not necessarily something that just shows up now.

2:03.6

And Bleeping Computer has a good summary of recent attempts to impersonate security researchers

2:10.6

and submit poll requests with obviously malicious code. In my opinion, this is likely someone who is not necessarily

2:21.7

trying to exploit these GitHub repostories. The code actually would not, as it was deposited,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.