meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, October 10th 2016

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 9 October 2016

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. Hurricane Matthew Phish; KNOXOut Vulnerability; Win 10 Improves XSS Protection

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, October 10th, 2016 edition of the Sands and its Storm Center's Stormcast.

0:08.0

My name is Johannes Orich, and the time recording from Jacksonville, Florida.

0:12.9

Probably not a big surprise, but we got our first Hurricane Matthew-related fishing attempt

0:20.4

pretty much before the hurricane actually hit

0:24.1

Florida itself. This particular attempt actually also played a little bit of

0:29.0

new spin on this in claiming that it came from a credit card processing company

0:35.2

Stripe and telling users that because of systems at Stripe

0:41.3

were affected by the hurricane, they should please turn off the two-factor authentication and

0:49.3

then it would redirect the victim to a fishing site asking them for their stripe credentials.

0:56.0

Now I must say that the stripe actually reacted really well to this and if you did happen to fall for this fish and then were redirected to the actual stripe site. That's what this fishing form did.

1:13.1

You were warned by Stripe that you just came from a fishing site and, well, should contact

1:21.1

them promptly.

1:23.1

Overall, I would say that this particular fish wasn't done very well, so doubt a lot of people

1:28.5

fell for it.

1:29.5

Also, Google blocked it pretty quickly in its safe browsing system.

1:34.1

So if you clicked on the link after Google did that, then you got the famous red warning

1:40.8

screen in your browser.

1:42.7

If you see any other fishing attempts or any other scams around this hurricane,

1:48.9

please let us know in the past we have seen a lot of, for example, fake donation sites and such.

1:55.0

But not so much in the last few disasters.

1:57.9

I think a lot of the state attorney generals and such went after these fake

2:04.0

donation sites very quickly.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.