ISC StormCast for Thursday, August 19th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 19 August 2021
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, August 19th, 2021 edition of the Sansonet Storm Center's Stormcast. |
| 0:08.6 | My name is Johannes Ulrich, and today I'm recording from Stockholm, Germany. |
| 0:14.0 | Today I wrote a quick diary with some of the issues that you may need to consider as you're moving back to a real office from |
| 0:22.6 | your home office like VPN configurations or considering, for example, some of the cloud |
| 0:29.5 | migrations that may have happened while you were at home and how they may affect, for example, |
| 0:35.2 | firewalls and such as you're moving back to your office. |
| 0:39.2 | If you are about to start working from a real office again, if you're not lucky enough to continue |
| 0:45.2 | working from home, take a look at the list, then maybe let me know what I missed or any comments |
| 0:51.3 | that you may have. |
| 0:54.1 | Then we got updates from Adobe for Adobe Bridge, |
| 0:57.8 | Captivate Media Encoder, Photoshop, and the XMP toolkit SDK. |
| 1:04.3 | Probably most northworthy here is Media Encoder and Photoshop, |
| 1:09.2 | as these vulnerabilities will allow for arbitrary code execution. |
| 1:15.1 | And probably Photoshop here is the more likely target. |
| 1:21.0 | An import P3 has a great block regarding some surveillance software that they're calling Tetris that's entirely |
| 1:29.7 | implemented in JavaScript. |
| 1:32.4 | Reminds me a little bit in its capabilities of beef, the browser exploitation framework, but |
| 1:38.6 | was found in two different Chinese language websites, apparently targeting Chinese users in that it does check |
| 1:48.8 | the language of the browser and only acts if it is set to Chinese. Real nice and detailed |
| 1:56.6 | write-ups, I definitely recommend you read it in order to learn more about how this really |
| 2:02.0 | works. Not much a user can really do about this particular spyver as far as detection goes. |
| 2:08.9 | At this point, at least when the blog was written, and high virus didn't really detect it. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

