meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, November 27th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 27 November 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. DShield Birthday; Mirai Exploits; OVA Files; OpenCart Vuln; Holiday Hack Challenge

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, November 27, 2020,

0:05.0

edition of the Sandin and Storm Center's Stormcast.

0:09.0

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.0

So back after the Thanksgiving week that I took off and, well, was lucky here.

0:21.3

No major event during this week.

0:24.8

A little bit sort of some of your usual stuff that we need to kind of talk about today.

0:30.3

So a little bit catching up here.

0:32.4

Also, just want to mention that Thanksgiving is always sort of the anniversary of DeShield.org, the data collection

0:40.2

engine behind the Internet Storm Center, which was originally released Thanksgiving weekend

0:46.4

of 2000, so about 23 years old now.

0:51.6

And then we got a couple new exploits that are being integrated into the

0:56.9

Mirai and similar botnets. Mirai, of course, originally just used the weak passwords,

1:03.8

but over the year sort of has added a number of web application vulnerability. One of them, CBE 2023, 1389, is a vulnerability that

1:16.8

one of our undergraduate students, Yona Latmar, looked a little bit closer into, and

1:22.6

well, this vulnerability was originally discovered and made public in March.

1:28.7

Then later in April, we saw some first hits against our honeypots.

1:34.3

But starting September, it really sort of has taken off since it then has been incorporated into some of these botnets, which of course made the vulnerability much more noisy at this point.

1:48.5

The vulnerability is a relatively easy to exploit, command injection vulnerability does not require any authentication.

1:55.8

You need to expose the admin interface for the router to be vulnerable and apparently the TP Arger

2:04.6

AX21 and AX-800 firmware is vulnerable to this. Wouldn't be surprised if other devices are

2:13.0

vulnerable as well. And Akamai also wrote a blog post about some new war on abilities. They're seeing

2:20.8

exploited by Mirai variants. They're calling it infected slurs. Now, this appears to be in part

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.