meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, February 23rd, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 23 February 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Confluence Scans; Apple Advisories Updates; Odd 2FA Apps in Apple Appstore; VMware Carbon Black Vuln

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, February 23rd, 2003 edition of the Sansonet Stormsternus Stormcast.

0:08.5

My name is Johannes Ulrich, and then I'm recording from Jacksonville, Florida.

0:14.5

Just a quick reminder to be careful that you patch various tools your developers are using.

0:19.8

Don't have any real numbers for it yet,

0:22.7

but at least it feels like we are seeing

0:24.4

sort of an increase in attacks against developer tools,

0:28.4

in particular over the last few months.

0:30.4

Today I wrote up a scan

0:33.7

that's trying to fingerprint vulnerable Confluence servers.

0:38.2

Confluence is sort of a wiki-like collaboration system that's part of the Elation suite of

0:46.1

tools.

0:47.0

And we saw one particular IP address that basically was looking for a set of URLs that could be used to exploit CVE 2021-26.84.

1:00.3

This is an OG&L injection vulnerability that leads to arbitrary code execution. It's an older

1:06.0

vulnerability, but of course no telling if there are some vulnerable servers still out there.

1:13.0

The test, the fingerprint they're sort of doing is quite simple

1:16.5

and it's part of actually a widely distributed exploit tool for this vulnerability.

1:24.0

It just tries to sort of solve a little math problem.

1:26.8

If the correct answer comes back,

1:28.7

then of course the attacker knows that your server is vulnerable. Let me have a little bit

1:35.1

an odd thing happening here with Apple security advisories. Two of the advisories released in

1:40.9

January, one for iPad OS and iOS, and then the second one for Mac OS. They both

1:47.7

sort of received a silent update by adding three more vulnerabilities to these advisories.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.