meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, February 13th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 13 February 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Latest ursniff sightings; Safe Documents; Wordpress GDPR Cookie Again; Apple Joins FIDO2 @fidoalliance

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, February 13th, 2020 edition of the Santernet Storm Center's Stormcast.

0:07.8

My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:14.1

Well, Brad wrote up what he's currently seeing with password-protected zip files, not the latest trick,

0:20.2

to actually get people to install

0:22.7

malicious code on their system.

0:25.0

But apparently still working, he found 66 different password-protected SIP archives just

0:31.8

for Tuesday this week.

0:34.7

And, well, they sort of all do the same thing.

0:37.1

Once you unsip the archive and the password

0:40.6

is usually three digits like one one one or two two two and you have to of course enable macros

0:47.4

and what you'll end up with is you are sniff which is known for stealing passwords and banking information and connecting back

0:55.9

to a command and control server.

0:59.2

Also interesting that these particular emails were written in Italian.

1:03.7

Of course, we have seen this where the bad guys are venturing out into various languages

1:09.3

in order to find new pools of users that may not

1:13.3

be quite as used to these tricks. Sadly, these documents with macros still continue to be a huge

1:23.8

problem even though, well, everybody should know that this is how a lot of compromise is

1:28.8

happening by now, but a lot of companies still use macros, so users can't just not enable

1:36.3

them to help with this.

1:38.1

Microsoft is starting to experiment with a feature they're calling safe documents.

1:43.3

Essentially the way it works is if a user

1:45.9

does open a document in protected view, this feature will scan the macros in the document and

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.