ISC StormCast for Monday, October 3rd, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 3 October 2022
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, October 3, 2022 edition of the Sansonet Storm Center's Stormcast. |
| 0:08.1 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:13.7 | Friday, I mentioned a new Microsoft Exchange server, Saturday vulnerability. |
| 0:19.6 | There has been no substantial news about this vulnerability over the weekend. |
| 0:25.4 | Microsoft now published version two of its Exchange on-premises mitigation tool to make it easier |
| 0:33.3 | to apply the workaround, to block the attack. The mitigation is applied automatically |
| 0:39.5 | if you are taking advantage of Microsoft's |
| 0:42.8 | Exchange Emergency Mitigation Service |
| 0:45.5 | that was created about a year ago. |
| 0:49.0 | And just to recap, this new vulnerability exploits |
| 0:52.1 | essentially the same proxy log logon vulnerability or proxy shell |
| 0:56.1 | vulnerability that has been exploited since March last year. |
| 1:01.8 | The original vulnerability was patched in March, but the patch only patched the unauthenticated |
| 1:08.7 | version. |
| 1:09.6 | This new exploit does require user credentials, which will hopefully help protect some |
| 1:17.0 | exchange servers. |
| 1:17.9 | So at this point, the best you can do is apply the workaround that Microsoft recommended, |
| 1:25.9 | and then of course take a look at any post-exploit activity. |
| 1:32.1 | Microsoft also published analysis of attacks they have been seeing. |
| 1:38.1 | Apparently, they saw attacks against about 10 organizations. |
| 1:42.2 | These were sort of targeted attacks that started around August. |
| 1:48.5 | And SISA is warning that CVE 2020-22-36-804, that's a vulnerability in Elation |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

