ISC StormCast for Thursday, February 18th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 18 February 2021
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, February 18th, 2021 edition of the Sandcent Storm Center's |
| 0:07.1 | Stormcast. My name is Johannes Ulrich. And today I'm recording from Jackstville, Florida. |
| 0:14.2 | Many social networks have a feature where if you receive a message within the social network, |
| 0:20.2 | it will send you a notification via email. |
| 0:24.3 | The idea kind of is, of course, to get you to go back to the social networking website and |
| 0:29.9 | sometimes a little bit sold as a more secure way to exchange messages because you avoid some |
| 0:36.1 | of the issues with exchanging emails. |
| 0:40.4 | However, this is only true if the link actually leads to the particular social network. |
| 0:45.8 | And we have a nice guest diary by J.B. Bowers showing how this can be abused and is being abused by the bad guys in this case by impersonating |
| 0:58.7 | LinkedIn. |
| 1:00.1 | Now, they're sort of claiming that there is a LinkedIn secure message, which doesn't actually |
| 1:06.5 | exist in that form, and they send you a private shared document. |
| 1:12.4 | Clicking on the link gets you then to a phishing page that solicits your LinkedIn credentials. |
| 1:19.9 | So why are people going after LinkedIn credentials? |
| 1:22.7 | Well, a couple reasons. |
| 1:23.9 | First of all, you may use the same credentials on other sites, in particular your main email |
| 1:29.8 | provider as well. |
| 1:31.7 | And secondly, once they do have your LinkedIn credentials, they can then leverage them to |
| 1:38.0 | reach out to your contacts. |
| 1:41.5 | JV's diary also has a good number of indicators of compromise from this particular |
| 1:46.8 | attack, but points out how difficult it can be to find and detect these attacks, since they're |
| 1:54.7 | pretty much using very well-known and frequently used cloud services, so an attack like this easily disappears |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

