meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, September 19th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 19 September 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. CustomXML Word Doc; 2FA on Locked Phones; Spellcheck Password Leak; Reflected Content

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, September 19th, 2020 edition of the Sands and at Storm Center's Stormcast.

0:09.3

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:15.4

Friday we got yet another interesting office document taken apart by DDA.

0:21.3

Of course, one thing that PICDDA's interest is the Visual Basic for applications of VBA code

0:28.4

included with the document.

0:30.7

But beyond that, the custom XML part attracted to his attention.

0:36.5

This custom XML part contained a good amount of hexadecimal

0:40.7

content starting with the classic MZ header, well, the hexadecimal representation of these

0:48.6

two ASCII codes for PE files. DDA was able to pull the hexadecimal part out with one of his famous tools and

0:58.8

converted to a binary file.

1:01.3

No surprise, you ended up with Windows executable at which part did he kind of lost interest in it.

1:09.6

Apparently, he is on a well-deserved holiday,

1:13.3

but well, what better to relax to at the beach with some nice malware? And I can't find it right now,

1:20.7

but I think someone responded on Twitter that they saw a similar piece of malware last week,

1:25.4

so this may be part of a larger malware run.

1:32.4

Gaps in the implementation of two-factor authentication have made big news recently, like

1:38.4

bombing victims with pop-up notification.

1:41.2

That's a trick that was heavily used by the lapses group, if you remember,

1:48.2

and of course since then others have picked up on that same trick.

1:54.0

A different issue comes up with second factor authentication tokens that are sent to the phone

1:59.6

as a message, either via SMS or via specific

2:03.7

messaging apps. Some users will allow these messages to be displayed on their lock screen.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.