ISC StormCast for Thursday, December 21st, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 21 December 2023
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, December 21st, 2003 edition of the Sands and its Storm Center's Stormcast. |
| 0:08.8 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:14.5 | Today I wrote quickly about an increase that we're seeing in exploit attempts for Lation Confluence Server CVE 2020-1218. |
| 0:26.8 | The vulnerability being exploited here, or at least attempted to be exploited, here is an authentication bypass for the setup restore feature. |
| 0:45.9 | This vulnerability would allow an attacker to basically upload a configuration to your Confluence server and with that, of course, gain full access, including arbitrary code execution |
| 0:52.4 | on the Confluence server. |
| 0:55.2 | Now, this is not a new vulnerability. |
| 0:57.6 | Was revealed very early first few days of November. |
| 1:02.3 | And we have seen some attacks against this vulnerability. |
| 1:06.1 | Actually, we saw a pretty high number. |
| 1:08.1 | Again, very specific sensors early on. |
| 1:11.3 | But these early attacks, they were more targeting sort of known confluence servers. |
| 1:17.3 | What we see now is a lower overall level of attacks, but against more targets, |
| 1:24.0 | indicating that they're probably just basically hitting random web servers, hoping that they are actually confluence servers that got missed in these initial scans. |
| 1:35.8 | Given the severity of the vulnerability, this is certainly something that you should take serious. |
| 1:41.4 | Now, a lot of organizations that use these Adelation tools don't necessarily |
| 1:45.7 | run them on-premise. They may actually use some cloud-based solutions by Adelation, so then |
| 1:53.2 | they'll take care of patching for you. But certainly something to take a quick look at the IP |
| 1:59.7 | address doing the scanning is sort of your |
| 2:02.1 | random digital ocean IP address. I believe it is located in England. What's sort of a little bit |
| 2:09.5 | concerning about this particular IP address is it does appear to be running Adelaide's software |
| 2:15.6 | itself. So it's likely a compromised system. It appears to be running adhesion software itself. So it's likely a compromised system. It appears to |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

