meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, December 20th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 20 December 2018

⏱️ 4 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Emergency MSFT IE Patch; Restricting PowerShell; BMC Server Bricking

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, December 20th, 2018 edition of the Science Internet Storm Center's Stormcast. My name is Johannes Ulrich,

0:08.9

and the I'm recording from Jackstable, Florida. Microsoft today had sort of a special holiday gift for us in the forum of an emergency update for Internet Explorer.

0:22.1

This patches a vulnerability in Explorer 9-211,

0:27.5

affecting Windows 7-210 and also Server 2008 to 2019.

0:34.4

This vulnerability has already been used in the wild against targeted attacks and was

0:40.6

originally discovered by Google.

0:43.8

The CVE number for this vulnerability is 2018, 8653.

0:49.1

At this point, I haven't seen an exploit easily available yet for this vulnerability.

0:56.4

However, today an exploit was made public against an older vulnerability, CV 2018-8631.

1:06.8

This vulnerability also affects JavaScript and was patched this month as part of the regular

1:13.6

patch Tuesday.

1:14.6

So if you're planning on taking some time off next week, then you probably do want to

1:19.6

apply this patch before you're leaving for the weekend.

1:24.6

Now, if this vulnerability gets exploited, then one of the common payloads that you may expect

1:32.3

is a PowerShell script.

1:35.2

And Xavier today had an interesting post about how to restrict the network capabilities

1:41.3

of PowerShell.

1:43.2

What Xavier is using here is NetShell. Now, NetShell is used

1:46.6

to adjust the Windows firewall, among other things. And one feature that Xavier is using here,

1:53.4

that you can actually restrict traffic based on the binary that originates the traffic. So, for example, you could limit PowerShell to only establish connections within the local network,

2:07.6

which would prevent PowerShell from downloading malicious software from arbitrary websites.

2:13.6

There are of course other tools that can be used in order to establish network connections.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.