meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, April 27th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 27 April 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Hunting Phishing Sites; RSA Top Attack Panel; @sans_edu research journal

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, April 27, 2020, 3 edition of the Sandsenet Storm Center's

0:08.1

Stormcast. My name is Johannes Ulrich and I'm recording from San Francisco, California.

0:15.0

Today we've got a quick diary from I Ching about the fishing sites.

0:20.3

I Ching likes to hunt down those fishing sites,

0:23.9

in particular if they affect Singapore, where he is from. In this particular case, it was a tax

0:31.4

filing website. So it's not just here in the U.S. where we had, of course, just April 15th. The big

0:37.2

tax filing deadlines.

0:39.0

Other countries are similar effect, in particular around important dates like deadlines

0:44.9

to file your taxes. More details in E Ching's diary.

0:51.6

And of course, the reason I am here in San Francisco is the RSA conference, and today we had

0:57.9

our annual panel about the top most dangerous attack techniques. Ed Skotis led the panel this

1:06.6

year, and we had Katie Nichols, we had Steven Sims, Heather Mahalick and myself.

1:13.8

The techniques we talked about was, well, first of all, Katie talked about some of the

1:20.2

search engine optimization, but also the malicious ads, the malvertising that the hackers are

1:27.0

doing in order to trick users into installing

1:30.4

malicious software, believing that Google or other search engines would return actually only

1:37.2

good links, which of course is far from right in particular if attackers are willing to pay

1:43.6

for ads in order to prioritize their malicious links.

1:48.5

Katie also mentioned that today Midor added malvertising as one of the attack techniques to their attack framework.

1:57.9

I talked about attacks against developers, something I have of course talked on the

2:02.2

podcast here before, in particular things like malicious plugins or just the vulnerable software

2:08.5

running on developers' workstations, but also code that may be running in order to infect

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.